PSA: Europe changes time forward soon, North America next, for the last time?

Anarcat
anarc.at
2026-10-08 15:30:02
This is a copy of an email I sent at work. I'm not sure I should be making noise about this here, feedback welcome. This is your bi-yearly reminder that time is changing soon! October 25th in Europe, November 1st in North America. Less people in Canada are changing this year, with BC, Alberta, Mani...
Original Article

This is a copy of an email I sent at work . I'm not sure I should be making noise about this here, feedback welcome.

This is your bi-yearly reminder that time is changing soon! October 25th in Europe, November 1st in North America. Less people in Canada are changing this year, with BC, Alberta, Manitoba and Northwest Territories getting rid of DST.

What's happening?

Some places in the world implement what is called Daylight saving time or DST:

https://en.wikipedia.org/wiki/Daylight_saving_time

Normally, you shouldn't have to do anything: computers automatically change time following local rules, assuming they are correctly configured, provided recent updates have been applied in the case of a recent change in said rules (because yes, this happens, and happened this year, and yes, you need to upgrade your software!).

Of course, appliances like your microwave oven will likely not change time and will need to adjusted unless they are so-called "smart", in which case they are part of the skynet botnet and should be destroyed.

If your clock is flashing "0:00" or "12:00", you have no action to take to adapt to this change, lucky you.

If you haven't changed time in six months, congratulations, your clock will be accurate again!

In any case, you should still consider DST because it might affect some of your meeting schedules, particularly if you set up a new meeting schedule in the last 6 months and forgot to consider this change.

If your location does not have DST

Properly scheduled meetings affecting multiple time zones are set in UTC time, which does not change. So if your location does not observer time changes, your (local!) meeting time will not change.

But be aware that some other folks attending your meeting might have the DST bug and their meeting times will change.

Be kind to those poor souls which might be missing meetings by a full hour because time flies backwards for them.

If you do observe DST

If you are affected by daylight savings, your local meeting times will change for UTC meetings. Normally, your meeting times are scheduled to take this into account and the new hours should be reasonable.

But now is a good time to verify that. Take a look at your schedule for the next couple of weeks and reschedule meetings before the daylight saving come up to avoid too much disruption. You have only a couple of weeks to do so right now.

When do times change, how, and and where?

As regular readers will remember, the rule of thumb is:

Spring forward, fall backwards.

That is, during the season of Spring, the clocks move forward, and during the Fall (like right now), they move backwards. That is in the northern hemisphere, but then the southern hemisphere is often saner and doesn't switch anyways.

So time will move backwards which means an extra hour of sleep. Unless you have children or bad sleep, in which case your body doesn't care about what the clock says and will wake up one hour earlier than what it should.

And of course, this doesn't happen everywhere at once, so let's see when it happens where.

The dance starts in Europe.

The change happens on the last Sunday in October at 01:00 UTC (not local time!), that is October 25th. If you are in the central European timezone, also known as Amsterdam, Berlin, or Paris time depending on your national affiliation, that essentially means that at 2:59 local the clocks will fall back to 2:00 instead of going to 3:00.

Concretely, set your watch back one hour before going to bed, go to bed at the normal time, and enjoy an extra hour of sleep or leisure.

If you have kids, you might want to start getting them to bed slightly earlier every day for a week before the change so they take time getting used to the change. If you have trouble sleeping in the morning, find your inner child and do that to yourself as well.

USA / Canada

Then it's the US[1] and Canada[2] joining the dance, on the First Sunday in November at 02:00 local (not UTC!), that is, I believe, November 1st 2025.

This means that, at 1:59, the clocks will flip to 1:00, instead of 2:00.

Concretely, do like the Europeans and tweak your clock before going to bed.

That is a little less than four weeks from now.

[1] except Arizona (except the Navajo nation), US territories, and Hawaii

[2] except Yukon, Saskatchewan, (newly) British Columbia, (newly) Alberta, (newly) Northwest Territories, (newly) Manitoba, one island in Nunavut (Southampton Island), one town in Ontario (Atikokan) and small parts of Quebec (Le Golfe-du-Saint-Laurent)

Other places with DST

This time again, I must apologize to the people of Cuba, Lebanon, Israel, Palestine, Egypt, Chile, Australia, and New Zealand, as you fine folks all have your own DST rules that are omitted here for brevity. I rely on this page from Wikipedia to be updated by time nerds accurately for this message, and it should provide you with a rough idea of what's coming:

https://en.wikipedia.org/wiki/Daylight_saving_time_by_country

In general, changes also happen in October, but either on different times or different days, except in the south hemisphere, where they might happen in September (oops, sorry NZ folks, I'm late!).

Places without DST

Everyone else, enjoy, you're on the right side of history, and we thank you for the good example you give us.

Changes since last time

There's been lots of changes since last time:

  • British Columbia moved to permanent -07 on 2026-03-09, that is it will not change to normal time in November

  • Alberta moved to permanent -06 on 2026-06-18, similar to BC above.

  • Canada’s Northwest Territories moved to permanent -06 on 2026-08-21, matching Alberta.

  • Manitoba moves to permanent -05 on 2026-10-31.

  • Morocco moves to permanent +00 on 2026-09-20.

  • Moldova has used EU transition times since 2022, but the tz database only noticed in 2026

This is my interpretation of the changes announced on the tzdata mailing list here:

https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/latest

If the eastward trend continues, Canada should adopt country-wide "no daylight savings" rules by 2027, although there's actually no sign of the other provinces (Ontario, Québec and so on) currently running bills to change those rules just yet. Poor Canadians like me confused about time in their countries can refer to this section of Wikipedia for details:

https://en.wikipedia.org/wiki/Daylight_saving_time_in_Canada#By_province_and_territory

... and particularly the image featured there:

https://commons.wikimedia.org/wiki/File:Canada_time_zone_map - en.svg

It also seems like the US government might finally adopt a permanent daylight saving change bill in 2026, as the "Sunshine protection act" pass the house in July:

https://en.wikipedia.org/wiki/Sunshine_Protection_Act

True to form, this was associated with absolutely ridiculous pressure from Donald Trump against republicans (his own party!) objecting to the change:

On July 14, 2026, the House passed a Sunshine Protection Act bill backed by President Trump. Nevertheless, the bill was opposed in the Senate by Republicans, including Senator Cotton. In response, on October 3, 2026, Trump shared a post on Truth Social urging Cotton to approve the bill, where he revealed Cotton's personal cellphone number and called on people to call him.

https://www.theguardian.com/us-news/2026/oct/03/trump-tom-cotton-daylight-saving-time

Given that the last time the US did a major change to the daylight savings policy (in 2005), Canada followed suit to stay in sync, it's quite possible Trump's mad dash might actually finish getting rid of DST in North America:

https://en.wikipedia.org/wiki/Energy_Policy_Act_of_2005#Change_to_daylight_saving_time

Created . Edited .

Refueling an EV be like

blogccasion
blog.tomayac.com
2026-10-08 14:42:32
This is a post for people who never drove an electric vehicle (EV) before. Imagine for a moment that for refueling your car you had to open an app to search for gas stations and filter them by whether they have Diesel, and then whether the pump delivers a decent stream of Diesel, or just by the drop...
Original Article

This is a post for people who never drove an electric vehicle (EV) before.

Imagine for a moment that for refueling your car you had to open an app to search for gas stations and filter them by whether they have Diesel, and then whether the pump delivers a decent stream of Diesel, or just by the drop. Next, when you found one, imagine you had to go to the pump's reviews in the app to estimate the odds that judging from the most recent comments there actually is Diesel.

When you arrive at the designated point, imagine that the gas pump is somewhere randomly hidden in a sparely lit industrial area parking lot. To start fueling, imagine you needed that random gas station brand's own RFID card that of course you don't have, or an app. Fine, imagine you scanned the QR code on the pump to download the app, only to find that the app isn't available in the country your phone's app store is registered in. Dead end. Cool, cool, there's another gas station within 15km, just still within the remaining range.

When you arrive at the other gas station, luckily their app is downloadable because they published their app globally. 75MB on a crappy 3G network. You finally have the app. Now you need to create an account. Email, phone number, national ID, address; whatever, fine. At this point, you'd sell a kidney for the right to fuel your car. Finally the SMS account confirmation arrives. Notification permission? Sure. Location access? Fine. Get access to your photos? Right. Wait, what? Ah, they need you to scan a QR code on the pump to start fueling, so that must be why they're asking. Likely…?

Oh, in order to proceed, verify your email. Alright, verified and logged in. But on their website in the app. Weird, you thought you needed to download an app because only the app can get you fuel, and now apparently the website can? Hmm, now there's a link to log in to the app, on the website. Email. Password? Ah, it's in the browser's password manager. Wait, twice actually , once with your national ID as the user name and once with your email. Likely you signed up in the past on a long gone phone.

Well… The new credentials luckily work. Pasted from the browser's password manager into the app because of course they built it with whatever framework the Android password manager doesn't support. Finally logged in. Choose how much Diesel you want and from what pump. To do so, scan the QR code on the pump or enter the pump ID manually. Luckily the ID is still readable while the QR code is covered by random local soccer club ultras fan stickers someone placed there. You're that close to fueling.

Pre-authorize the fuel purchase by accepting the charge in your bank's app. Pre-payment accepted, please go back to the app. Oh, sorry, unfortunately the fueling capability is currently not available. Please try again later. Hmm, maybe you were not supposed to plug in the nozzle before you go through the payment dance? Try again, hoping the gas station company charges you back for the "finished fueling" that never started. OK, finally the Diesel is flowing, time for a well-deserved coffee. Ah, wait, there's nothing open because you're in the middle of nowhere on an industrial area parking lot.

Tom in jeans and a black hoodie with the paperwork in his hands standing next to a brand-new white 2021 Hyundai Kona Electric at the car dealer.
Me and our 2021 Hyundai Kona Electric at the car dealer.

The above is an extreme case of an EV charging experience, narrated for fossil fuel drivers. But it actually happened. Here's what I would like to see:

  • Every EV charging station has to accept the exact same cashless payment methods they allow for fossil fueling. In Europe, this would essentially be credit and debit cards. Support app payment if you want, but don't make it the only option.
  • Municipalities should stop building slow charging infrastructure, unless maybe in residential areas. Instead, we need fast DC charging stations widely available.
  • Every gas station with fossil fuel pumps should have to have fast EV charging stations as well, in relationship to the number of fossil fuel pumps they have, with regulation enforcing a transition to electric mobility over time. Today it might be one fast charger for every four fossil fuel pumps, gradually increasing over the years.

Oh, I forgot to say that the sun has been refueling our two EVs, the Hyundai Kona from the picture above and a Peugeot e-208, for free for the last several years ☀️… You should really get an EV, and when you can, get solar as well. Don't let my story discourage you, but it's really something I want to see change, and more awareness raised for!

CiviCRM Community Council Election 2026: Nominations Are Open

CiviCRM
civicrm.org
2026-10-08 11:33:39
CiviCRM keeps growing. New installs land every month, and the product gets stronger with each release. The Community Council election has started, and the community wants strong candidates to help guide what comes next. Declare Your Candidacy Nominations are open now. Declare your candidacy by...
Original Article

CiviCRM keeps growing. New installs land every month, and the product gets stronger with each release. The Community Council election has started, and the community wants strong candidates to help guide what comes next.

Declare Your Candidacy

Nominations are open now. Declare your candidacy by October 21, 2026.

To run, you need two other individuals who are members of the CiviCRM community to second your nomination. You will also submit a short statement with:

  • Your name and location
  • Your involvement in the CiviCRM project
  • What you want to bring to the Council

Submit your nomination here: https://www.skvare.com/civicrm-community-council-nomination-form

Thanks to Skvare for hosting the nomination form.

Who Can Run, and Who Can Vote

Any person with an active account on civicrm.org may nominate themselves. An active account means a login within the past two years.

The same rule sets the voter list. Log in to your account today at civicrm.org/user to confirm your details and stay eligible to vote.

No account yet? Register one at civicrm.org/user/register .

We will export the voter list on October 29, 2026 . Log in before that date to make the list.

Know Someone Who Would Be Great on the Council?

Tell them about this post. Point them to the nomination form, or to communitycouncil@civicrm.org with questions.

Timeline

Date Item
October 21, 2026 Declaration of candidacy due, with two seconders per candidate.Seconders must be active in the CiviCRM community.
October 28, 2026 Candidate statements due; Log in or create your civicrm.org account to be eligible to vote
October 29, 2026 Voter list exported from civicrm.org and imported into the voting platform
October 30, 2026 Candidates announced
November 2, 2026 Voting opens
November 13, 2026 Voting closes
November 12-17, 2026 Results confirmed with winners
November 20, 2026 Winners announced

India's actually existing DPIs as architectures of hegemony

Internet Exchange
internet.exchangepoint.tech
2026-10-08 08:17:05
Mila T. Samdub argues India's digital public infrastructure binds banks, tech firms, and the state into a ruling coalition....
Original Article
internet governance

Mila T. Samdub argues India's digital public infrastructure binds banks, tech firms, and the state into a ruling coalition.

India's actually existing DPIs as architectures of hegemony
Kathryn Conrad & Rose Willis / Extraction Network 1 / Licenced by CC-BY 4.0

Mila T. Samdub . Originally published on irl.works

Governance, Openness and Security of Digital Public Infrastructure in India by the internet Research Lab (hereafter, the “GOSDPI paper”) provides new evidence into the organization and functioning of state promoted digital platforms in India. With its comparative approach, it allows us to identify patterns, divergences and blindspots that make up what we might call “actually existing DPI” (as distinct from widely circulating inflated and ungrounded claims about DPI). This essay responds in the form of an architectural critique rooted in political economy. It draws on the findings of the GOSDPI paper to theorize the architecture of DPI systems as flexible, distributed platforms that encode the structure of hegemony in Digital India. This architecture splits governance, ownership, deployment and profit to forge links between powerful interests (software, finance, state elites and sectoral interests, such as in construction). Seen thus, DPIs emerge as instruments that build and sustain elite coalitions, enabling the continuance and intensification of domination.

Actually Existing DPIs

A large and expanding body of gray literature prescribes the principles, architectures, and functions of something called “Digital Public Infrastructure”. Much of this literature is mobilized towards rapid policy diffusion, exporting certain idealized models as “best practices” whose supposed successes can be replicated around the world. As a result, mainstream DPI discourse often pays more attention to finessing how to promote “DPI” than to understanding what the systems given this name actually do.

What does it mean to look at “actually existing DPIs”? This means looking not at technical diagrams that assume end-users who are rational, literate, and empowered, nor unattributed factoids about the cost savings these systems will supposedly deliver, nor the smiling photographs of fictional user personas – farmers and street vendors are in vogue – that adorn dozens of report covers, nor even the elegant principles that promise openness, interoperability, and trust. Rather, actually existing DPIs refer to the opaque, imperfect, compromised, and negotiated systems that are actively reorganizing societies. Looking at actually existing DPIs also means being specific about how these systems work in different contexts; this article focuses on the Indian cases studied by the GOSDPI paper, while recognizing that systems elsewhere are similar and different.

DPI are worth studying in empirical detail because they form the operating system of contemporary life in many places. Small nuances in the structures of these systems have massive ripple effects affecting hundreds of millions of people. Since they are composed of several interlocking structures – legal, technical, economic, cultural – it is precisely the interplay of these various forces that this analysis unpacks.

The GOSDPI paper is primarily framed as an exercise in gathering evidence and evaluating whether six actually existing DPI live up to the claims made on their behalf. This is critically important for advocacy, as the answer on most counts is “no”. In the course of this exercise, the paper’s authors also begin to theorize actually existing DPI. The paper refers, for example, to DPI’s “highly networked public-private architecture”, its “distributed architecture”, its “selective openness”, “complex incentive structures across multiple actors” and “fragmented model of responsibility”. They write that in DPI, “regulatory authority is concentrated in central state bodies, while operational governance is delegated through layered frameworks of rules, guidelines, and bilateral agreements.” And: “when faced with security vulnerabilities and data breaches, DPIs defined their security perimeter narrowly. The security boundary was set to be at the core infrastructure, while responsibility for breaches occurring through third-party integrators and components was denied.” This essay picks up some of these threads to build a more systematic theorization of actually existing DPI.

The DPI Assemblage: From Imaginary to Platform to Extension

To understand DPIs’ broader social and economic effects they should be treated as assemblages: DPIs encompass not only core software platforms, but also ecosystems of private and public sector complementors, the hardware and infrastructural dependencies on which they run, the regulations that govern them, the imaginaries that shape them and the human intermediaries and social structures that provide last-mile interfaces. Across these dimensions, DPIs in India are characterized by a hyper-proliferation of roles and actors. They are structured in ways that “increase the surface area of a problem” , multiplying the sites in which different entities can enter the system and the functions they serve. These functions are operational, economic and regulatory, often at the same time. Importantly, as the GOSDPI paper reveals, though DPI are often described as “open”, in practice they are tightly permissioned, and the entities that occupy roles in the ecosystem often do so because they have significant economic and political power.

Here we draw on and extend the example of the FASTag highway toll collection DPI, which is explicated at length in the GOSDPI paper.

Common imaginaries of marketized development

It is clear from the GOSDPI paper that DPI is not simply a one-size-fits-all approach. There is significant room for variation between different DPIs. Yet at the same time, a shared “sociotechnical imaginary” motivates DPI more broadly. The notion of a broad-based move from “pipes to platforms” in the architecture of government services, for example, has been promoted by a relatively small set of actors over a decade. The Nilekani-led TAGUP report is a consistent touchstone in the distributed governance of DPI. An imperative to scale at all costs, likewise, accompanies all DPI rollouts.

The DPI imaginary frames not only the architecture of the DPI platform but also proposes a theory of change, claims about the kind of social and economic change these systems will bring about in the world. This theory of change – for which there exists little concrete evidence – links DPI deployment to increased government efficiency, private sector innovation and poverty alleviation. It is built on pre-existing imaginaries of marketized development, including CK Prahalad’s business school promise of the “fortune at the bottom of the pyramid” and a “ financial inclusion assemblage ” that claims that, once granted access to credit, the poor can entrepreneur their way out of poverty.

Entities that have promoted the DPI imaginary include, among others , the tech czar Nandan Nilekani, the industry body Indian Software Product Industry Roundtable (iSPIRT), and global funding agencies like Omidyar and the Gates Foundation . Broadly, these correspond to domestic software capital and US transnational capital. Their stakes are not only economic but also symbolic. With the proliferation of DPI, domestic software capital has today arguably become the hegemonic class fragment in India, playing an outsize role in shaping common-sense assumptions about what the future of the nation should look like .

Complex ownership structures

The agencies that own the core platforms of DPI are often composed of complex configurations of actors. In some DPI, ownership rests entirely with a technocratic state agency. This is especially the case for so-called “foundational DPI” like Aadhaar and Digilocker. But in domains with powerful incumbent sectoral interests, like finance or highways, ownership models tend to be more complex.

As the GOSDPI paper describes, FASTag is owned by the Indian Highways Management Company Limited (IHMCL), a special purpose vehicle, of which the public enterprise National Highways Corporation of India owns 41.38%, toll concessionaires (which include some of the largest infrastructure and construction companies in the country) hold 33.81% and financial institutions hold 24.81%. This fragmented ownership structure includes both finance and construction, with “L&T Finance, GMR Highways, Shapoorji Pallonji Roads, and Essel Infraprojects, each holding between 3–8% of total share capital”.

The National Payments Corporation of India (NPCI), which owns the Unified Payments Interface system, is one of the most prominent entities in the operation of DPI. It is structured as a non-profit company composed of a mix of public banks, private banks and fintechs. Over 51% of shares are held by public sector banks.

Such ownership structures mix public sector enterprises with commercial interests across various sectors. They should be understood as ways of carving up the pie that secure the consent of powerful fractions of capital to build and deploy large-scale projects.

Platform-ecosystems in operation

At the level of operation, each DPI is a platform-ecosystem composed of a two or three-layer stack: the core platform, occasionally a hidden routing layer, and an interface layer.

The core platform is usually operated by the entity that owns the DPI (NPCI operates UPI, UIDAI operates Aadhaar). Occasionally, the operating entity is distinct from the owning entity. The National Electronic Toll Collection (NETC) transactions that are at the center of FASTag toll collection, for example, are operated by NPCI (which is involved in many DPIs that process financial transactions).

The routing layer, where it exists, is composed of incumbent sectoral interests, often but not always in finance, whose buy-in is necessary to operate the DPI. In the case of FASTag, these actors are the issuing and acquiring banks that facilitate the movement of data and money through the system. Access to this layer is controlled by licenses that often mandate technical specifications and/or turnover requirements, restricting them to large enterprises. These entities often earn guaranteed rents from occupying these privileged nodes in the ecosystem.

The interface layer is usually composed of user-facing apps or services. Organized to attain scale, this level is often characterized by entities that already have significant market access or have the resources to take on elevated risk to acquire customers. In FASTag, the interface layer is split between acquiring banks and fintech startups. Acquiring banks are responsible for registering new users into the FASTag system and providing them with a physical FASTag RFID to affix to their car. Fintech apps form the extended ecosystem, which are often used to top up one’s FASTag funds. In other DPI, such as UPI or Aadhaar, this layer is often occupied by fintech companies with speculative business models backed by venture capital.

Putting these three layers together: When a car passes through a toll plaza, data is transmitted to a toll plaza operator, whose infrastructure is configured by a system integrator, to an acquirer bank, to NPCI’s NETC mapper, to an issuing bank, from whose account money is deducted, and then back. A complex incentive structure follows: “Each toll transaction triggers a fixed percentage-based payout to the involved entities. The acquirer bank, issuer bank, NPCI, and IHMCL receive 0.13%, 1%, 0.15% and 0.25% of the transaction value respectively as programme management fee.”

Multiple dependencies

All DPIs depend on complex infrastructural stacks, which are usually excluded from most definitions of DPI. To continue with the FASTag example: “When users pass through a toll plaza, multiple devices generate and collect data: RFID readers capture the Tag ID, TID (transponder ID), and user memory; Automatic Vehicle Classification (AVC) systems determine the vehicle class; Weight-in-Motion (WIM) sensors record vehicle weight; and image capture systems photograph the vehicle.” A proliferation of hardware components, then, is what keeps DPI like FASTag running.

DPIs share infrastructural dependencies with cloud-based contemporary digital systems: data centers, undersea cables, mobile towers and more. These are largely supplied by Chinese hardware manufacturing and US hyperscalers. Yet DPI also have particular infrastructural dependencies that are unique to their uses and the situation of India. Smartphones and internet access, for example, are major dependencies of DPI in India, and India’s telcos – operated by conglomerate capital – entrench their importance with every use of DPI. Since biometrics have been foundational to Aadhaar, biometrics suppliers – which are often US and European contractors – have played a prominent role as well.

People are important dependencies in the functioning of DPI. Despite the nationwide rollout of FASTag, most toll plazas in India remain labor intensive, with human intermediaries helping users navigate systems that often don’t work as designed . A simple example familiar to most people who have traveled on an Indian highway: a user’s FASTag fails to scan when the car pulls up at the boom barrier; in response, a toll plaza operator pulls out an RFID reader affixed to a long stick and waves it closer to the tag in order to scan it. Without such improvisations, DPI would simply not work.

Fragmented regulation

DPI function within a regulatory regime that is organized towards maximizing the circulation of data . Thus, the structure of regulation in DPI often fragments authority. The ultimate regulatory authority often rests within central government ministries or central regulators, such as the Reserve Bank of India, but is enforced by a range of actors. In FASTag, the Ministry of Road Transport and Highways is the apex policy authority, while operational guidelines – fee structures, rules of participation and compliance – are managed by IHMCL.

Extension and interconnection

Because DPIs are structured as platform-ecosystems, they can often be extended. New actors can enter the ecosystem as complementors, usually via bilateral agreements and APIs. Thus, FASTag data is also accessed by government agencies for tax compliance and national security. Commercial entities offer a different kind of extension, integrating DPI with each other or with other services. In a commercial fintech app, the Bharat Connect DPI may be used to top up a FASTag account using UPI for payment. As they are extended and interconnected, DPIs become more entrenched.

Architectures of Hegemony

According to a classic paper on postcolonial politics , a ruling coalition “is always based on an explicit or implicit protocol, a network of policies, rights, immunities derived from both constitutional and ordinary law which sets out over a long period, the terms of this coalition and its manner of distribution of advantages”. With DPI, this article has shown, this protocol is not only legal and social but also technical and economic.

The DPI assemblage apportions specific roles to powerful entities suited to their particular interests. In most DPI, this creates a coalition between the state, the software capitalists that build and extend these systems, the financial capital that runs much of the financial plumbing, the conglomerate capital that operates the network infrastructure and sectoral capitals that vary with each DPI (construction in the case of FASTag), as well as important international actors upon which the entire structure is dependent: US hyperscalers and Chinese hardware manufacturers.

Entities with an economic stake in DPI may extract guaranteed rents from occupying a position in the routing layer. Or they may take more risky interface-level business models, often funded by venture capital. The stakes may also be symbolic – building prestige and the image of nation-building. They may be political, offering gains in national security or surveillance. Some entities are content with the status quo; others want to bend the architecture of the system further towards their interests.

DPIs should be understood not only, then, as technologies of service delivery but also as architectures of hegemony. The protocols of DPI encode the distribution of advantages between the divergent entities that compose the ruling bloc of the nation-state today.

Mila T. Samdub is a writer, designer, and curator who works on the aesthetics and political economy of digital infrastructures in India and the Global Majority world.


ICANN's new domain applications are now public

Yesterday was ICANN's Reveal Day , and the full list of applications for new top-level domains is now searchable ( Wired has a good primer ). ICANN published 1,615 applications from 481 applicants, and our fiscal host, Exchange Point , is among them applying for .tiny and backup .point.

The most popular applications are AI related . Thirteen applicants want .agent and seven want .agi with OpenAI and Google both applying. Alongside them are lots of brand domains like .facebook and .bankofamerica.

A tip if you go digging to see who applied for what, you need to know what you're searching for. Google files through its registry company, Charleston Road Registry. A search for "Google" returns no results. "Open AI" returns nothing, while "OpenAI" returns 15 results.

Applicants have until October 21 to switch to backup strings, the final list will be public November 17, and public comment runs until mid-March.

Want to appear here? Sponsor a newsletter.

Support the Internet Exchange

If you find our emails useful, consider becoming a paid subscriber! You'll get access to our members-only Signal community where we share ideas, discuss upcoming topics, and exchange links. Paid subscribers can also leave comments on posts and enjoy a warm, fuzzy feeling.

Not ready for a long-term commitment? You can always leave us a tip .

Become A Paid Subscriber

🚨

Stop press! Do you enjoy our links? Links are now available to paid subscribers only. Become a paid subscriber today.

Internet Governance

Digital Rights

Technology for Society

  • The AI industry hates the term "stochastic parrots," which casts chatbots as remixing training data rather than thinking, because it undercuts the case for trillions in investment, Brian Merchant argues in a video with Emily M. Bender. https://www.youtube.com/watch?v=7Z7oA9ndmdY

Privacy and Security

Upcoming Events

Careers and Funding Opportunities

Opportunities to Get Involved

  • SplinterCon Nordic, a December conference on internet fragmentation, seeks talks, research, workshops, and demos on how AI affects censorship, network control, and access to information. Submissions are due October 30 . https://splintercon.net/nordic/cfp

What did we miss? Please send us a reply or write to editor@exchangepoint.tech .

Quoting Carson Gross

Simon Willison
simonwillison.net
2026-10-08 17:05:44
Computer programming is, fundamentally, about two things: Problem-solving using computers Learning to control complexity while solving these problems I have a hard time imagining a future where knowing how to solve problems with computers and how to control the complexity of those solutions is les...
Original Article

8th October 2026

Computer programming is, fundamentally, about two things:

  • Problem-solving using computers
  • Learning to control complexity while solving these problems

I have a hard time imagining a future where knowing how to solve problems with computers and how to control the complexity of those solutions is less valuable than it is today, so I think it will continue to be a viable career even with the advent of AI tools.

— Carson Gross

Show HN: Free open source Adobe Lightroom alternative, completely local with AI

Hacker News
github.com
2026-10-08 17:00:55
Comments...
Original Article

Rembrandt

Stop paying for Adobe. Flush the incrapification.

A free photo editor for macOS, Windows and Linux.
No account needed, no subscription, no “we’ve updated our terms” emails.

Download · Self-host · Features · Build

Editing a photo in Rembrandt

Rembrandt, in dots, making the edits you asked for while the sliders move Dragging on the photo to change the tone under the pointer Super Resolution: an ordinary 4x enlargement next to Super Resolution 4x
Ask : “golden hour, shadows +25”, and watch Rembrandt paint it Touch : drag on the photo to change that tone or colour Super Resolution : 2× and 4× on your GPU
The library Masks, including AI subject, background, object and depth Before and after, split view
Library : albums, search, sorting, one-click delete Masks : brush, gradients, AI subject and depth Before / after : split or side by side

Download

Platform
macOS · Apple silicon Rembrandt-macos-arm64.dmg
macOS · Intel Rembrandt-macos-x64.dmg
Windows · x64 Rembrandt-windows-x64-setup.exe
Windows · ARM Rembrandt-windows-arm64-setup.exe
Linux · x86_64 / arm64 curl -fsSL https://raw.githubusercontent.com/thesnarkitecht/rembrandt/main/install.sh | bash

All files and checksums: Releases . Builds aren't code-signed yet: on macOS use System Settings → Privacy & Security → Open Anyway ; on Windows More info → Run anyway .

Self-host it

Serve Rembrandt from the computer that holds your photos and edit them in any browser:

curl -fsSL https://raw.githubusercontent.com/thesnarkitecht/rembrandt/main/install.sh | bash -s -- --server

It asks which photo folder to use, starts at login, and prints a private link. Edits are saved next to each photo as XMP; the photos themselves are never changed. Add --lan to reach it from other devices on your network. Linux and macOS; one small dependency-free binary ( server/ ). To update, press Update in the browser (Settings › About); it installs the latest release, checks it against the published SHA-256 sums, and restarts the server.

Features

  • Ask in words : type “warmer and a bit brighter”, “down exposure by ten points”, “shadows +25” or “paste the edits from the previous photo” (Ctrl/⌘ K). A small Rembrandt in dots thinks it over, then makes each change while you watch the sliders move. It runs on your device: a vocabulary, not a language model.
  • Edit the photo itself : drag up or down on any part of the picture to lighten or darken that tone, left or right to change that colour; the sliders follow.
  • AI looks : Enhance, Relight, Sky, Atmosphere, Sunrays, Skin, Motion and Lens Blur with aperture shapes, from on-device depth and subject maps.
  • Refocus : brings back detail in out-of-focus photos, even heavy defocus (regularised deconvolution on the GPU), on the subject or the whole picture.
  • Super Resolution : 2× and 4× with real detail, or Restore at the same size for soft photos; runs on the GPU (Metal on Apple silicon).
  • AI Denoise : clean high-ISO shots into a new DNG with the same edits, on the GPU.
  • Background work that stays out of the way : AI Denoise, Super Resolution and merges run in small GPU slices that pause while you edit, or when you're away, or overnight in a night window you set (Settings › Performance). The queue survives restarts.
  • Merge : HDR from brackets, panoramas and focus stacks, each to a RAW-like DNG.
  • RAW from 1,000+ cameras, developed on the GPU: tone, colour, curves, grading, dehaze, detail.
  • Masks : brush, gradients, colour and tone ranges, AI subject, background, object and depth.
  • Remove : heal and clone spots and strokes; Rembrandt picks a matching source for you.
  • Lens corrections : the camera's built-in profile from Fujifilm and Sony RAWs, or one of 1,500 lens profiles from Lensfun (distortion, vignetting, chromatic aberration), plus manual distortion and vignetting for any photo. Auto straighten levels horizons.
  • On-device AI : Refocus, background replacement. Nothing is uploaded.
  • Library : albums, ratings, flags, colour labels, keywords, virtual copies, search, Find similar, sorting, keyboard shortcuts (or Lightroom's), one-click delete with Undo.
  • Batch : copy and paste edits to hundreds of photos, batch export, and presets that fit each photo's exposure. Watch a folder to apply a preset and album to new photos as they arrive.
  • Share how : a before/after page with a slider, a replay video of the edit, or the recipe inside the exported file so anyone can see (and reuse) how it was edited.
  • Bring your photos : folders, Lightroom Classic (edits, keywords, labels, virtual copies, collections, with a report of anything that can't come over) and Lightroom, Google Photos, Google Drive, Dropbox, OneDrive ( setup ). Export back to them too.
  • Open formats : edits are standard XMP, readable by Lightroom and others.
  • Cloud sync (optional, paid) : turn it on in Settings to sync edits, albums and photos between your computers, the web and your phone. It's the only thing that needs an account, and the only thing that costs money; everything else stays free.

Help out

Rembrandt is free and stays free. Star the repo, tell a photographer, report a bug or send a fix.

Build

npm ci && npx http-server -c-1 .   # web app
npm run tauri dev                  # desktop app (Rust + Tauri prerequisites)

Details in docs/building.md . Contributions welcome: CONTRIBUTING.md .

Licence

Free software under the GNU General Public License v3.0 or later , the same licence as darktable. Use it, study it, change it and share it; if you distribute a modified version, share its source under the same terms. It may also be distributed through app stores (an additional permission under the GPL; see NOTICE.md , which also lists the third-party parts).

Screenshot photos from the scikit-image sample data: espresso by Rachel Michetti and cat by Stefan van der Walt (CC0), rocket launch by SpaceX and Hubble eXtreme Deep Field by NASA (public domain).

AI-ready biological data: $1.8B global commitment

Hacker News
biohub.org
2026-10-08 16:46:25
Comments...
Original Article

REDWOOD CITY, CA, October 7, 2026 — Biohub, the U.S. Department of Energy, the National Institutes of Health, and new funding partners today announced a major expansion of an international effort to generate and make accessible the data enabling predictive AI models of biology. Together, the organizations are investing $1.8 billion in funding, data, computation, and new measurement technology, the largest coordinated commitment to generating AI-ready biological data to date. The result will be an open resource for the research community that provides the foundation for greater understanding and ultimately treatment of human diseases.

As part of this announcement, Biohub has partnered with the Department of Energy (DOE) Office of Science and the National Institutes of Health (NIH) to advance the frontier of artificial intelligence in biology. DOE will invest more than $500 million over five years in lab measurement, modeling and computation toward the international effort to build an AI-ready open data resource. NIH will coordinate the contribution of relevant datasets, repositories, and knowledge bases developed through more than $500 million in prior federal investment aligned to this initiative. Biohub will work with NIH to standardize these datasets for AI model training.

In addition, Google DeepMind, Isomorphic Labs, and Meta are collectively investing $300 million in the Virtual Biology Initiative to create the technologies and multi-modal datasets needed to build predictive models of life.

These datasets will enable the global scientific community to collectively build and use AI models that allow researchers to ask, predict, and answer biological questions digitally, accelerating the path to new ways of preventing and treating diseases. This initiative will deliver the foundational measurements to train these models, expanding cell response data to interventions across far more cell types and conditions than have yet been studied, and building and validating technologies for studying cells and cellular interactions at greater scale, speed, and accuracy.

“An accurate predictive model of biology could dramatically accelerate scientific discovery by enabling scientists to perform experiments digitally. The insights that come from this could unlock a far greater understanding of disease and open up completely new paths for cures,” said Biohub Head of Science Alex Rives. “Because of this potential, the creation of a virtual cell is one of the most important challenges for the next era of science. It will require coordinated data generation efforts at a national and international scale, which is why these partners are coming together. We invite the worldwide scientific community to join us in this project.”

The Virtual Biology Initiative, announced in April 2026, will coordinate data generation across institutions and disciplines to build AI-ready open datasets to enable predictive models of life. Biohub’s founding $500 million commitment anchors that work: $400 million supports new technologies that expand what biologists can measure: cryo-electron tomography, which resolves near-atomic detail inside the cell; microscopy that can image millions to billions of cells in living tissue; and engineering tools to build and perturb biology at molecular, cellular, tissue, and whole-organism levels. A further $100 million funds research outside Biohub.

“Generating the data to solve predictive systems biology requires scaling past the limits of what any single organization can produce today,” said Max Jaderberg, President of Isomorphic Labs. “By joining the Virtual Biology Initiative as a founding member, Isomorphic Labs is helping build a massive, multimodal data foundation. This initiative will generate the data needed to push the industry closer to the next significant breakthrough for biology.”

Through the Genesis Mission, a cross-agency initiative led by the Department of Energy, DOE will contribute more than $500 million over five years in fundamental cell research — data collection, AI analytics, measurement and imaging, modeling, and computation — drawing on exascale supercomputing, X-ray and neutron scattering, cryo-electron microscopy and tomography, and autonomous laboratories across the National Laboratory system.

“This partnership represents a critical step forward in leveraging artificial intelligence for public benefit,” said Darío Gil, DOE’s Under Secretary for Science. “By combining DOE’s exascale computing, experimental measurement, and modeling assets, including premier user facilities at the Joint Genome Institute, the Environmental Molecular Sciences Laboratory, and advanced structural beamlines with the unique AI models, tool development, and biological data capabilities of Biohub, we are setting a new standard for open science that will accelerate discoveries in both medicine and biotechnology.”

Through its Bio Genesis Mission , NIH will bring together existing biomedical datasets, national data infrastructure, and research programs to help build AI-ready resources for the broader scientific community. NIH’s extensive investments in biomedical research provide a foundation for this work; resources include national biomedical repositories catalogued by NIH’s National Library of Medicine (NLM) and the National Center for Biotechnology Information , as well as NIH Common Fund programs that are already developing coordinated biological atlases, shared data standards, and AI-ready biomedical datasets.

“By combining resources and expertise, we can accelerate the development of universal cell models with sufficient biological complexity to predict how any cell responds to an intervention,” said Nicole Kleinstreuer, Ph.D., NIH Deputy Director Program Coordination, Planning, and Strategic Initiatives (DPCPSI). “The return from these models could be broad and profound, resulting in substantially faster timelines for medical breakthroughs as compared with attempting to attain the same results through laboratory experiments alone.”

In addition, leading scientific institutions and consortia with experience in organizing transformative international collaborations, from the Human Genome Project onwards, have come together to help nucleate the scientific community across academia and industry around developing effective scientific strategies to maximize the impact of virtual biology. The groups include the Allen Institute, Broad Institute, Gladstone Institutes, the Human Cell Atlas, the Human Protein Atlas, and the Wellcome Sanger Institute. These groups are committed to working together as part of the Virtual Biology Initiative as well as through independent efforts toward this shared goal. NVIDIA will support the initiative to leverage accelerated computing infrastructure, domain-specific software, and technical expertise. Renaissance Philanthropy is helping to expand funding for data generation.

As the initiative takes shape, Biohub is bringing together partners across disciplines and industries to build the layer that lets their datasets work in a unified fashion — shared standards, common identifiers, and a single point of access. Equally important is building the scientific community around these resources — convening researchers across institutions and disciplines, connecting complementary expertise and capabilities, and creating opportunities to define and pursue ambitious scientific questions together. Over the past decade, Biohub has expanded the reach and impact of measurement technologies and open datasets, leading projects such as Tabula Sapiens , OpenCell , and Zebrahub . It has also built and maintained community data infrastructure, including CELLxGENE and the CryoET Data Portal . The Virtual Biology Initiative builds on these experiences to enable coordinated efforts at a scale that no single institution could achieve alone.

“The quest to build a virtual cell is one of the great collective scientific challenges and key to understanding the mechanisms of life. We will not solve this challenge without open, experimental biological data at an unprecedented scale, showing how living cells behave and respond to changes,” said Pushmeet Kohli, VP, AI for Science at Google DeepMind and Google Cloud’s Chief Scientist. “This investment in biological data generation will help create an open, standardized data commons, which will lay the foundations researchers around the world need to better model biology.”

###

About Biohub
Biohub is a 501(c)(3) nonprofit research institute combining frontier AI and biology to accelerate science. With its compute capacity, AI research and engineering, and state-of-the-art technology for measuring, imaging, and programming biology, Biohub is enabling scientists worldwide to use AI-powered biology to study how cells operate and organize as systems — with the ultimate mission to cure or prevent all disease. Learn more at biohub.org .

Press Contact
Biohub
press@biohub.org

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 16:09:45
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]...
Original Article

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country.

The company says that the attack started on October 7 at 3:40 AM local time, forcing a shutdown of the network and system.

“Our investigation has determined that a disruption in East Japan Region 1 was caused by a ransomware attack by a third party,” reads IDFC Cloud’s announcement .

“We are continuing to investigate the precise cause and the scope of the impact,” the company added.

The firm said the attack impacts 495 companies and local governments using its cloud service.

The IDCF Cloud infrastructure-as-a-service platform is operated by IDC Frontier, a subsidiary of SoftBank Group, a multinational investment holding company based in Tokyo.

The firm rents out virtual servers, storage, and networking that customers use to run websites, applications, and business systems in Japanese data centers.

After detecting the attack, IDC Frontier isolated and shut down impacted systems in ‘East Japan Region 1’ to prevent the compromise from spreading.

Currently, the company is working to identify and block the intrusion route and check security in other regions.

IDCF Cloud has proactively disabled customer access to management consoles for all regions while it verifies their security, and will restore access after confirming it is safe to do so.

Screenshots from customers before they were locked out of the console show a message from the threat actor claiming that it took seven minutes to breach IDCF Cloud’s East Japan Region 1 infrastructure.

The threat actor claims they encrypted 225 databases corresponding to 3.6 PB of data, reached 239 hypervisors, sealed 16,000 VM disks, and wiped 554,153 snapshots.

Note
Message seen by IDFC Cloud clients on the platform console
Source: j416dy

Nissui also hit

Japanese marine products company Nissui Corporation announced yesterday that its logistics subsidiary, Nissui Logistics, suffered a system outage due to suspected unauthorized access to a third-party data center it uses.

As a result, goods are not being shipped or received, and the company is currently investigating whether personal information or customer data was leaked.

Nissui is a Japanese seafood and food group with approximately 11,500 employees and an international supply chain spanning fishing, aquaculture, processing, and sales.

It is unclear if the outage at Nissui is connected to the attack on IDCF Cloud.

Recently, several major Japanese companies were targeted in cybersecurity attacks, Macnica researcher Yutaka Sejiyama says.

Since the start of the year, Macnica logged 119 cybersecurity incidents involving personal information theft or exposed data, 83 occurring between July 1 and October 6.

For comparison, the security firm recorded 84 incidents in 2025 using the same criteria, and just 62 throughout 2024.

Number of confirmed cyberattacks against Japanese entities
Number of confirmed cyberattacks against Japanese entities
Source: Macnica

Analysis of these incidents shows that attackers are probing websites and APIs for access-control, configuration, and authentication weaknesses, and exploiting known (n-day) vulnerabilities.

Sejiyama told BleepingComputer that finding weaknesses specific to individual websites has traditionally required considerable time and effort, making small targets less attractive.

The rise of capable, cheap AI tools may be the reason why broad, detailed exploration of security weaknesses is now changing the landscape.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

When No ID Means No Internet: Age Verification and the Right to Access Information

Electronic Frontier Foundation
www.eff.org
2026-10-08 15:59:49
This post was co-authored by Sheila B. Lalwani, a doctorate student and recent COMPASS Fellow hosted by EFF. Age verification proposals are often presented as a simple tradeoff: sacrifice a little privacy to better safeguard children online. But that framing overlooks a more fundamental question. Wh...
Original Article

This post was co-authored by Sheila B. Lalwani , a doctorate student and recent COMPASS Fellow hosted by EFF.

Age verification proposals are often presented as a simple tradeoff: sacrifice a little privacy to better safeguard children online. But that framing overlooks a more fundamental question. What happens to people who cannot verify their age at all? This is particularly a problem when users are required to prove their age with identity documents.

Age-related restrictions are developing quickly around the world. While they differ radically across jurisdictions, in the past year, we’ve witnessed a sharp uptick toward mandatory age assurance for social media access but also for other high-risk digital services.

For example:

  • In late 2025, Australia became the first country to implement a minimum age requirement for prohibiting children under age 16 from creating or holding social media accounts.
  • India passed the Digital Personal Data Protection (DPDP) Act that includes mandatory verifiable parental consent and has undertaken ongoing discussions for social media restriction.
  • The United Kingdom passed the Online Safety Act requiring age verification across a swath of services hosting content considered harmful to users under 18. More than half the states across the U.S. have enacted age verification laws .
  • An EU Commission ’s expert report recommends a ban on social media access for users under 13. It also recommends mandatory age verification for platforms to ensure that users are ‘age appropriate.’

The Access Problem

Age verification laws that are predicated on the necessity of users possessing a current passport, driver’s license, credit card, or similar documents proving their identity exclude critical sections of populations.  And this problem is global in nature: Millions of people lack government-issued identification or encounter regular challenges to obtaining or updating it.

Roughly 15 million adult U.S. citizens lack a driver’s license, and a further 2.6 million lack any government photo ID ; leaving large groups blocked from online content or services. The UK has a similar predicament: proof-of-age checks are often reliant on passports, driver’s licenses, or other recognized alternatives, which can pose unique challenges to people without these documents.

Much of the advocacy around age verification discusses the privacy harms of age verification. Yet these measures also threaten something more fundamental: equal access to information and the ability to exercise the right to freedom of expression.

Unfortunately, age verification systems foster unequal access to information and provide an asymmetric solution to find essential information, build community, and weigh in on public discourse. As governments and companies increasingly require users to prove their age before accessing online services, these individuals risk being excluded from large parts of the internet altogether.

Effects on Global Majority Countries

Age verification laws reshape who can speak, who can access information, and who gets excluded from the digital public sphere. In other words, age verification is not a neutral safety measure: it presents a structural barrier to disproportionately exclude certain groups—particularly those in the global majority—and alters the architecture of global online expression. Some of these groups are already marginalized offline, and age verification extends that exclusion into digital spaces.

For instance, 850 million people globally do not have ID . Most of these individuals exist in primarily low and middle income countries in Sub-Saharan Africa and South Asia. The World Bank points out that many are members of marginalized groups and more than half of those lacking access to identity documentation also have children whose births have not been registered. Women are particularly vulnerable and are 8% less likely than men to have an ID. Other vulnerable groups, such as adults in low income countries, are less likely to have an ID when they fall below 25 years, as are those with a primary school education or less or those in rural areas.

A policy paper from EDRi points out that age verification laws provide quick tech solutions but overlook longstanding structural challenges and undermine the universality of the internet. The analysis finds that age verification laws have serious human rights implications and ironically harm the very individuals they deem to protect. Moreover, these laws depend on the collection of harmful mass data that human rights organizations, including EFF, is fighting against —and has for decades .

For example:

  • In Morocco , a push to restrict children’s access would ban under-13s from creating accounts on gaming platforms. This could potentially create challenges for those with IDs that have incomplete information concerning the year of birth. In addition, this push would also impact those who attempt to leave Morocco.
  • In Egypt , the lack of ID cards has created challenges for minority groups such as the Baha’i.
  • Stateless individuals would also struggle under age verification laws. The Rohingya , the world’s largest population of stateless people , often lack IDs .
  • Kuwait’s Bidoon population also lacks proper identification materials. According to Amnesty International , this leads many to rely on standard civil identity cards, which can be restrictive.
  • Nigeria launched a national program to provide ID cards to its population in 2007. Since then, 64.4 million have registered, but that represents just over 30% of the national population.
  • The Kafala system, a practice in several countries across the Middle East , also introduces challenges for age verification laws. Under this legal framework, migrant workers’ legal residency and employment status are bound to a specific employer. This potentially leaves stateless persons or migrant workers vulnerable to forced labor and restricted movements.

No ID, No Access

Age verification laws are less about confirming the age of a user and more about creating barriers to online participation that many people cannot reliably scale. The net result is reduced access, more data collection, and an increased chance of unequal or mistaken exclusion from accessing information online.

Nobody doubts the importance of protecting children online. While proponents assert that age verification laws protect minors from harmful material, online harassment, and digital addiction, these laws are not the solution. They subvert fundamental freedom of expression rights and pose significant privacy risks.

EFF has long warned against age-gating the internet. Age verification technology itself is often inaccurate and privacy-invasive , and as more countries considering implementing ID-based checks , the risks move beyond censorship and surveillance toward excluding some people entirely. That’s why we’re working with groups in the U.S. and around the world to push back against these laws, and why we hope you join our effort.

For more information on how to fight back against dangerous age verification laws, visit our resource hub at eff.org/age

Don't Piss on My RHONY Vacation and Tell Me It's a Private Island

hellgate
hellgatenyc.com
2026-10-08 15:31:06
This week, the RHONY reboot cast members tore each other down in a tropical paradise....
Original Article
Don't Piss on My RHONY Vacation and Tell Me It's a Private Island
(Photos by Kevin Wolf, Ralph Bavaro/Bravo. Collage by Hell Gate)

RHONY

Scott's Picks:

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

Apple Is Slow-Rolling iOS 27 Adoption, So Far

Daring Fireball
mastodon.social
2026-10-08 15:30:36
David Smith, last week: Been really interesting to watch the iOS 27 adoption curve over the first two weeks. Clearly on a different path than previous years. Still steadily growing, at a similar rate to the ‘steady growth’ phase of most years, but without the big surge at the start. Given that ...

Low-cost Android phones ship with residential proxy malware

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 15:20:33
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...]...
Original Article

Android Malware

A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

The malware is believed to have been introduced somewhere in the device supply chain, but it remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred.

The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, giving it system-level privileges that allow it to install and remove applications, grant sensitive permissions, and execute remotely downloaded code without user interaction.

According to Bitdefender researchers , the campaign affected thousands of devices across more than 150 countries over approximately two years, with the highest number of victims in Mexico, France, Italy, United States, Germany, Brazil, and Spain.

The researchers found preinstalled malware on devices with model names associated with legitimate manufacturers, including the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung and Apple products.

In an XDA forums post , owners of Cubot and Doogee smartphones reported finding suspicious applications that repeatedly reinstalled themselves after removal.

One Doogee Fire 3 Max owner also reported that an official firmware update infected the device with the malware, which disappeared after restoring an older firmware version but returned when the update was installed again.

Some users said the manufacturers released firmware updates that resolved the infections. However, the manufacturers have not publicly explained how the malicious software was introduced into the affected firmware.

Bitdefender also mentioned the XDA forum post in its report and said one of the malware packages reported by forum users, com.android.non.szcz , is part of the same malware family.

Pre-installed Android malware

Unlike typical Android malware that requires users to install a malicious application, Midnight Mimosa is already installed in the device's system partition when customers receive their phones.

The malicious programs impersonate legitimate Android system packages, using names such as com.android.system.lite , com.android.sys.prot , and com.android.sys.gmsprot .

Because these applications are signed and run with elevated system privileges, they cannot be removed through Android's normal application uninstall process.

Bitdefender discovered the campaign after its App Anomaly Detection technology flagged a suspicious system application named com.android.system.lite that was silently installing and removing other applications.

Further investigation determined that the application was part of a larger malware framework that downloads additional modules from command-and-control (C2) servers to perform different malicious activities.

The researchers identified approximately 32 applications distributed through the framework, including apps disguised as weather utilities, file managers, app lockers, OCR tools, and audio editors.

"The system app itself doesn’t register the fraudulent impressions and clicks," explains Bitdefender.

"The revenue engine is driven by the dropped cover apps, including real-looking weather, app-lock, note, and OCR apps, which load genuine ads through a legitimate ad SDK. The goal is simple: to load an invisible window on top of apps that registers ads being shown."

These applications are used to generate fraudulent advertising impressions and clicks, with some displaying advertisements in hidden windows or automatically interacting with ads without the device owner's involvement.

The malware also employs techniques designed to evade Android's security protections.

Before silently installing malicious applications, it temporarily disables the Google Play Store app, com.android.vending , which Bitdefender says is intended to prevent Google Play Protect from detecting the installation.

After the installation completes, the malware re-enables the Play Store to avoid raising suspicion.

Some malware variants also manipulate Android's recorded installer information to make malicious applications appear to have been installed through Google Play, even though they were deployed directly by the malware.

The malware also includes features that turn infected Android phones into residential proxies that can relay network traffic.

Bitdefender identified a malicious application disguised as an app locker, com.mobile.applock.en , which contains a TCP proxy component that registers infected devices with a remote command server.

Once registered, the malware can be sent instructions to connect to specified hosts and forward traffic through the infected device.

This could allow attackers to route malicious traffic through the internet connections of phone owners, concealing the true origin of attacks or allowing access to devices reachable from the infected device.

Bitdefender confirmed that the proxy command-and-control infrastructure was operational and accepting device registrations.

However, during their tests, the researchers said their newly registered device did not receive any relay targets, so they could not confirm whether the attacker's were actively forwarding traffic.

SystemLite delivery and payload architecture
SystemLite delivery and payload architecture
Source: Bitdefender

The researchers also discovered 13 Android applications distributed through the Google Play Store that contained the same advertising fraud code and communicated with known Midnight Mimosa infrastructure.

Unlike the preinstalled system components, these applications do not have elevated privileges needed to silently install other software.

However, they can still display advertisements outside their user interface, including when users are not using the phone.

The applications were distributed using 13 different signing certificates and at least two developer accounts, identified as fivedev and CPS Developer .

The researchers also found firmware signed using certificates associated with Chinese device manufacturer Shenzhen Zediel, but said it is unclear whether the company was involved in the malware's campaign.

For affected consumers, removing the malware is difficult because the malware is installed as a high-privileged system application.

Bitdefender says removing the infection requires firmware-level cleanup or disabling the malicious component using Android Debug Bridge (ADB), which can be complicated for many users.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances

Hacker News
cointelegraph.com
2026-10-08 15:17:51
Comments...
Original Article

Ethereum co-founder Vitalik Buterin has backed a new warning that advances in artificial intelligence could undermine the cryptography used in today’s blockchains before quantum computers do.

Buterin was responding to a post from Ethereum researcher Justin Drake on Wednesday urging the industry to prepare for “bunker mode,” as AI could eventually make it possible to break the elliptic curve digital signature algorithm (ECDSA) used to secure cryptocurrency wallets. Drake said users should begin a gradual migration of funds to fresh wallets where their public key is not exposed.

“I don’t recommend anyone scramble to move their funds to new wallets today,” Buterin wrote . “But we should take the risks to cryptography from AI-accelerated math seriously.”

Drake said his concerns came after OpenAI released hundreds of new mathematical findings across a variety of topics such as algebra, theoretical computer science and mathematical logic on Tuesday, revealing how quickly AI has been advancing in mathematics.

Last month the company used a team of 10,000 autonomous AI agents working in parallel to solve the Navier-Stokes equation, one of the most famous and difficult unsolved problems in mathematics and physics, in just 88 hours.

“Recent days have been humbling for human mathematical intuition. Long-held, unquestioned hypotheses have fallen,” said Drake, adding that elliptic curves could be especially vulnerable to superintelligence.

“Curves carry rich structure, with room for fancy tricks like Schoof, Frobenius, pairings. (By contrast, hashes are designed to minimize algebraic structure.)” he said.

Buterin flags risks to quantum-resistant cryptography

Buterin, however, extended the concern to lattice-based cryptography, warning that systems believed to resist quantum attacks could also be weakened by AI-driven mathematical advances.

“So far most people have been in the mode of thinking ‘elliptic curves broken, hashes safe, lattices safe,’” he wrote. “But there is a good chance that the concrete security of lattices will take serious hits from the next two years of AI math.”

Buterin said this is a major reason why Ethereum’s lean roadmap has been going in the “hash-only” direction.

Dragonfly managing partner Haseeb Qureshi also supported taking precautions, describing Drake’s warning as “a very sober call.”

“The risk is not quantum, but just conventional mathematics overturning unproven cryptographic hardness assumptions,” he wrote on X.

Controlled migration to fresh addresses

Alongside those longer-term cryptographic changes, both researchers suggested holders could reduce their exposure by keeping funds in addresses whose public keys have not been revealed.

“My personal recommendation is to set in motion a controlled mass migration of assets to fresh addresses,” said Drake.

He said large and sophisticated crypto holders should be the first to move their funds to new addresses. He also recommended moving any remaining funds to a new address after signing a transaction.

Related: Nvidia unveils AI safety platform to rein in ‘rogue’ AI agents

Buterin supported the precaution if it is straightforward to carry out. “If it’s not difficult for you, keeping your funds in addresses which have not yet been used to make a transaction is a good idea,” he wrote.

He cautioned, however, that moving funds introduces risks of its own.

“I personally have lost more money in botched migrations than I have lost in all hacks combined,” Buterin said.

Drake similarly stressed that any migration should be gradual and carefully managed, warning that “a rushed migration would do more harm than good.”

Magazine: Too big to pause: Could an AI slowdown crash the economy?

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

Steinar H. Gunderson: Decompilation patterns, part 5: Nested if/goto

PlanetDebian
blog.sesse.net
2026-10-08 15:15:22
Here's a pattern that sometimes comes up: if (x == 3) { if (y == 4) { ... } else { goto label_5; } } else { label_5: ... } We don't like gotos, and here, it's pretty obvious what was meant, namely: if (x == 3 && y == 4) { ... } else { label_5: ...
Original Article

Here's a pattern that sometimes comes up:

if (x == 3) {
    if (y == 4) {
        ...
    } else {
        goto label_5;
    }
} else {
    label_5:
    ...
}

We don't like gotos, and here, it's pretty obvious what was meant, namely:

if (x == 3 && y == 4) {
    ...
} else {
    label_5:
    ...
}

And now you can usually delete label_5 because nothing points to it.

Often, m2c can do this by itself, but as usual, you may get to this point only after cleaning up other things.

13 Cursed New Developments in the Chaotic Brooklyn Democratic Party Saga

hellgate
hellgatenyc.com
2026-10-08 15:08:21
We drew you a diagram to explain (good luck)....
Original Article

Want to get up to speed on the Brooklyn Democratic Party saga that is apparently still playing out? Here's a rundown on all the recent players and court proceedings, informed by our exhaustively researched project, Courts of Contempt : an investigation into New York City's broken judicial selection system.

All this hullaballoo started in June, when the folks in charge of the Brooklyn county machine—which has the power to choose judges, appoint people to fill legislative vacancies, and direct fundraising to local candidates— LOST a bloc of district leader votes in the Democratic primary elections. That meant they no longer had the votes to keep control of the party at this fall's convention.

Brooklyn Democratic Party Chair Rodneyse Bichotte Hermelyn and her establishment cronies attempted to change the party rules in late August so more of her allies could vote for her to stay in power. Those rules were swiftly deemed illegal by a state Supreme Court judge.

There was much legal back and forth, a few defiant AI videos , and some spicy NY1 appearances before Bichotte Hermelyn announced she won't be running for reelection as chair after all, instead throwing her support behind an ally: Assemblymember Nikki Lucas.

This should clear things up for you.

Then in September, the party held a shambolic organizational meeting , where we pick up our cursed timeline:

Give us your email to read the full story

Sign up now for our free newsletters.

Sign up

64-Day Certificate Lifetimes Coming Feb 2027

Lobsters
letsencrypt.org
2026-10-08 15:06:25
Comments...
Original Article

By Sarah Gran ·

On February 10, 2027, all Let’s Encrypt subscribers will move to certificates with 64 day lifetimes by default unless they select an even shorter lifetime (45 or 6 days, as previously announced ). This means that any certificate we issue or renew on and after that date will have a 64 day validity period, and we expect the last 90-day certificate to expire on May 11, 2027. We will not revoke valid certificates as a part of this process.

We will switch to issuing 64 day certificates in our staging environment on October 14, 2026 to enable testing. We recommend testing in staging before the change takes effect in production.

If your renewals are automated and your client supports ACME Renewal Info (ARI), you should be all set since ARI allows Let’s Encrypt to tell your client when to renew (you can review your ACME client’s documentation to determine if ARI is implemented).

If your renewals are hard-coded to a date from expiration you should update them to renew at approximately ⅔ of the lifetime instead. Taking this step in preparation for 64 day lifetimes will lay the groundwork for default lifetimes of 45 days in 2028 . Grep for common hardcoded numbers like 83, 80 or 60 in cron jobs, wrapper scripts and runbooks if you’re not sure.

We will also be reducing the authorization reuse period from 30 days to 10 days. In 2028, the reuse period will shrink to seven hours. We are making this change to comply with a 2029 reduction in maximum validation reuse periods, and to remove the need for “CAA rechecking”, where we have to repeat part of the validation process if the validation data is more than 7 hours old. Unless you have specifically designed your ACME client to rely on validation reuse, you will not need to make any changes.

This is also an opportunity to automate certificate management processes like reload and deployment and to add alerting for renewal failures.

Rate limits will not be impacted by this change; you can learn more in our previous blog post .

This change will not affect ACME endpoints or our issuance chains.

We are moving to shorter certificate lifetimes because this reduces the risk of key compromise and mis-issuance. As a nonprofit we see it as part of our mission to make this change to advance security for everyone using the Web globally. We anticipate a smooth transition, but if you experience issues, our community forum and documentation are good resources.

The value of not getting to the point (2015)

Hacker News
ken.arneson.name
2026-10-08 15:04:56
Comments...
Original Article

I read somewhere recently, I forget where, that the purpose of people getting together for a conversation over a beer or coffee or lunch or dinner is that it the food and drink spare us from the burden of needing to have something to say throughout the whole conversation.

This was a revelation to me. All this time, I assumed that the primary purpose of lunch was lunch. All this time, I figured that I was just lousy at conversation because being an introvert made conversation awkward and laborious for me. For everyone else, conversation seems comparatively effortless. But it seems from this data that conversation must be harder for everyone else than I had assumed.

My oldest daughter is a freshman in college. She recently texted me and said she wanted to talk. I asked, what about? She got annoyed at me for asking.

I was clueless as to why. I guess the Dunning-Kruger effect applies to all of us, there’s always some area of life where we’re so incompetent we don’t even know we’re incompetent. This area, apparently, was one of mine.

She asked if we could just talk about something stupid. So I called her, and we talked about Donald Trump and the presidential race and stuff like that for a good long while. I didn’t ask about what was really bothering her.

Eventually, the conversation turned, and we finally got to talking about the thing she wanted to talk about. But that probably at least half an hour into the conversation. We segued slowly and organically from the stupid stuff into the real issue.

And this, too, was a bit of a revelation to me, that someone would not want to get straight to the point, that someone would need a nice long conversational warmup before they’d feel comfortable enough to be ready to talk about something more uncomfortable. I’m very much a get-to-the-point kind of person. I tend to say what I mean, or nothing at all.

Language is imprecise. Our feelings don’t always have direct translations into speech. It’s hard to explain what we feel, to say exactly what we mean. We have wants and desires and emotions, and we often try to rationalize those feelings. Those rationalizations are often logically incoherent. But it’s hard to see the incoherence of our own rationalizations because our points of view are so limited. And often (if we’re not falling prey to the Dunning-Kruger effect) we intuit that our rationalizations may be incoherent. So we’re cautious in what we say. We know that there can be social penalties for saying the wrong thing in the wrong way to the wrong person.

All this adds up to making the act of talking about something sensitive daunting. There is a vulnerability in speaking. That’s why our culture has all these rituals and conventions around conversation, like idle chit-chat and coffee and such: to build enough trust in the environment where we can feel comfortable enough to overcome the vulnerability inherent in speech.

I never fully understood this before. I feel like everyone else understands it, though, because they act as if they do. But if they do, it must be an intuitive understanding, a grokking, not an explicit fact that people state out loud. Otherwise, I probably would have heard someone say it explicitly sometime before in the almost 50 years I’ve been in this earth.

Having now finally come to this understanding, it occurs to me that perhaps this is the great flaw with Twitter, why everyone I know on Twitter seems to eventually run into a wall with it. The 140-character format pushes you to get straight to the point. There is no room for the idle chit-chat and sips of coffee and other conversational rituals that let us dance around the sensitive issues. Without these rituals that are built into real-life human-to-human conversation, the problems with speech that those cultural rituals are designed to prevent come flooding in.

There is so much hair pulling and teeth grinding about what people should and should not say online, and how they should or should not say it. And maybe all that hair pulling and teeth grinding arise because our online conversational cultures, and the technological platforms they reside on, have not had the time to evolve into something that works, the way that our real-life conversational culture has.

There are many, many more people who are clueless about how to behave in online conversations than there are people who are clueless about how to behave in offline ones. How I came to be the flipside of that, I don’t know.

And it also occurs to me that there is a value in stating explicitly the things that are mostly just intuited about human nature and human culture. I want to explore these sorts of things. There is a risk, though, a vulnerability, in stating these things. The people who intuitively grasp these things will feel as though I am insulting their intelligence by stating something so obvious it shouldn’t need saying. But it isn’t meant as an insult to their intelligence, it’s meant as an insult to mine. I need to say these things because I’m the one who doesn’t understand these things. I need them explained to myself.

Which is all a roundabout way of stating something that maybe could fit into a tweet: I plan to start saying things that aren’t obvious to me but may be obvious to others. Sorry if you fall into the latter category and I waste your time. Such is the risk of saying anything, ever. And sorry for the roundaboutness in getting to this point. I seemed to need it, for some strange reason.

Joz Announces ‘Welcome Home’ Keynote Coming Tuesday, 13 October

Daring Fireball
x.com
2026-10-08 15:00:09
It’s almost like you can predict the timing of such things, if you pay attention to Apple’s consistent patterns.  ★  ...
Original Article

Log in or sign up for X

See what’s happening and join the conversation

or

Log in with username or email

Relevant people

Avatar

Apple SVP Marketing  Big believer in hw, sw and services integration ⌚️📱💻🖥 @UMich 🏈🏀⚾️🥎🏒 Animal lover 🐕🐈 Biking & the great outdoors ⛰🌅 he/him

Trending now

Composition over Inheritance Explained using Retro Games

Lobsters
www.youtube.com
2026-10-08 14:52:25
Comments...

'It Is Done. Hail Satan:' City Immediately Regrets New Religious Liberty Law That Allows Prayer at City Council Meeting

403 Media
www.404media.co
2026-10-08 14:07:29
Iowa city council debates proper time in meeting agenda to "undo the curse that was just put on our city."...
Original Article

An Iowa man has kicked off controversy over religious freedom in the small town of Ottumwa, Iowa by opening a city council meeting with a prayer to Satan, which then kicked off a debate about the proper time in the meeting agenda to undo the “curse.”

On Tuesday night, Ottumwa resident, satanist, and former city council member Matt Dalbey took the podium to read an invocation to start a routine meeting of the council. “Thank you mayor, council. Let us pray,” Dalbey started. “Dear dark father, let us stand now unbowed and unfettered by arcane doctrines born of fearful minds and darkened times. Let us embrace the Luciferan impulse to eat off the tree of knowledge and dissipate our blissful and comforting delusions of old.”

The prayer is a common one used by the Satanic Temple of Iowa. “Let us demand that individuals be judged for their concrete actions, not for their fealty to arbitrary social norms and illusory categorizations,” he continued. “Let us reason our solutions with agnosticism in all things, holding fast only to that which is demonstrably true. Let us stand firm against any and all arbitrary authority that threatens the personal sovereignty of one or all. That which will not bend must break. And that which can be destroyed by truth should never be spared its demise.”“It is done. Hail Satan,” he finished.

Another citizen, a pastor named Rick Bick, rushed to the podium. “Let’s just reverse that curse that was just put on our city,” he said. “That ending with hail Satan and hail dark god. That’s not welcome here.”

“Mayor, that should be done at the end,” city councilor Cara Galloway said.

“It needs to be done now, OK.” Rick said. “I appreciate what Ms. Galloway is saying but that was a curse put on our city when he said ‘Hail Satan’ and the dark god and most of you know that. And we need to just stop and reverse it.”

“So what I’m gonna do now…I’m just gonna invite us into a 30 second time of prayer — time of silence.”

“No,” Galloway said. “We are at the consent agenda. I’m sorry, but it’s time to move forward. The invocation happened.”

“As mayor of this city…I’m going to ask right now that we do a moment of silence to reflect on whatever it is we need to reflect on at this time. And then we will move to the consent agenda,” mayor Benjamin Foote said.

Galloway spent the moment of silence with her head up and her arms crossed. An hour later, she spoke up. “Opening with an invocation means allowing viewpoints that may not reflect our own and responding to someone’s invocation is a slippery slope to putting a financial liability on the taxpayers and allowing others to object or respond. This is exactly why I had concerns about having an invocation when we first talked about it.”

0:00

/ 1:25

Dalbey told 404 Media he was a sincere member of the Temple of Satan but stressed it’s “an organization of nontheists, people who don’t believe in any deities or supernatural beings.”

He served on the city council for eight years and has largely stayed out of local politics since leaving the council in 2021. But when the city council passed a new rule earlier this year that allowed city council meetings to start with religious invocations, he decided to do something. “I’m a constitutionalist,” he said. “And when I see this, the implication I got was that we were again starting to mix religion into the government.”

At the Tuesday night council meeting, the audience stood up to recite the Pledge of Allegiance the moment Dalbey finished.

Ottumwa has only been reading invocations at its meeting for a short time. The city council passed a resolution allowing the practice on January 20. Galloway was the only person on the council who voted against it. At the time, she said Satanists might show up and read a prayer and that everyone would have to be OK with that. Readers of 404 Media may remember Ottumwa, Iowa because it is the place we aired our Super Bowl commercial .

Anyone who wants to show up to read an invocation before a city council meeting needs to fill out an electronic form. The form asks applicants to list an organization they represent, but allows people to say “none.” Dalbey has signed up to read invocations three times this year. He’s listed as representing “none” each time on the schedule. He was supposed to read a prayer on September 1, but couldn’t make the meeting because of his work. He’s on the schedule to read an invocation on November 3rd. “I plan on being there in November, absolutely,” he said.

Dalbey said he’d be happy to see the invocation policy rescinded. “When I was on the council [...] we were approached several times about doing an invocation, and the very reason that we didn't was because our attorney had warned us that when you do, you open the door to any and all people who want to present. That's the law,” he said.

The invocation to Satan in a small town in Iowa is just the latest salvo in a 10-year-long battle over religious freedom of expression in the state. In 2016, a religious liberty group installed a Christian nativity scene at the state capitol in Des Moines. Later that year a group of atheists installed its own nativity scene honoring the Bill of Rights . In 2023, The Satanic Temple put up a pentagram built from red ribbon and topped with a mirror-mask ram’s head that invoked Baphomet in the capitol rotunda. The group also began holding winter celebrations in the Rotunda. A man vandalized the display , police arrested him and charged him with a hate crime.

In 2024 — the same year Governor Kim Reynolds signed a state law meant to protect religious freedom — officials blocked Satanists from holding their winter celebration. The ACLU filed a Freedom of Information Act request looking for records about the incident and, earlier this year, sued Iowa on behalf of the Satanic Temple for violating federal free speech laws.

“I think we're seeing you know a big shift in our politics. I think we've seen a rise of Christian nationalism in this country [...] and I think it's trying to grasp and get a hold of controlling our politics, our laws and our government, and I find that highly troubling,” Dalbey said. “And I think anytime we let any religion dominate our politics, we revert right back to where we were 250 years plus ago: a monarchy where the church ruled the country, and that was bad for everybody. That's one of the reasons our founding fathers decided to form a new nation. And I think if we are not careful, you know, we're going to slide right back into that scenario.”

About the author

Matthew Gault is a writer covering weird tech, nuclear war, and video games. He’s worked for Reuters, Motherboard, and the New York Times.

Matthew Gault

What ArtCraft's Vibe-Coded Apps Say About Adobe

Hacker News
tedium.co
2026-10-08 14:44:29
Comments...
Original Article

I am not a unique flower. Like many creatives, I had a good relationship with Adobe that, over time, went belly up .

The first sign something was wrong was when the company more or less ignored Mac design conventions in a way that made its software harder to use. (All you had to do was support full-screen apps in Mac OS X Lion, dudes!)

Then it turned its subscription plan into the only real option. Then it kept raising prices. Then it changed its offering in a way that suggested it only really cared about customers who could pay them for hundreds of licenses each year.

On top of that, it failed to keep up with where I was going as a user, along with many other users. Despite the fact that a huge contingent of power users have been decamping to Linux, it more or less ignored those users. Meanwhile, AI changed the definition of what software could be.

That perhaps explains why I’m not particularly surprised that some programmer decided to rebuild the Creative Cloud suite using clean-room techniques in a vibe-coded environment. It solves many of the issues that upset power users—the lack of end-user responsiveness, the high cost, and the ability to use it on the platform of their choice. Adobe, as a public company, has often been tethered to the desires of the stock market, which has meant a lot of AI stuff, even when many creatives have made clear they do not want them.

So now, we have ArtCraft out here Robin Hooding every single one of the key Adobe apps.

screenshot_2026-10-08_11-58-17.png
So, funny thing: When I joined the Discord channel to see what the community was like for this thing, the first thing I saw was two people arguing about whether or not these icons represent furries. Never change, Discord.

The names aren’t the ones you’re familiar with, but you nonetheless know what each one is. One is a Photoshop stand-in . Another is Premiere Pro . Another is Acrobat . And yes, there’s even an InDesign riff .

Do they work particularly well? On the surface, yes. Opening up these apps in AppImage shows that these apps, programmed in the Rust programming language, are not only fast, but relatively small. Rather than hundreds of megabytes, these apps load in tens of megabytes. They detected my discrete GPU right away. And within a couple of minutes, I was manipulating an image.

A lot of finicky, below the surface stuff did not work so well. Color pickers and secondary menu boxes were rough, not elegant. It did not detect my fonts in DesignCraft until I downloaded an update published just a few minutes before I downloaded it. And while I could set a color with a hex code in PhotoCraft, I could not do the same in DesignCraft.

But it was familiar. I could see myself building a zine with this tool, or using it to access old files that I cannot otherwise open without a Creative Cloud subscription.

Is an open-source vibe-coded creative suite really worth cheering on? I think so.

There are real reasons to cheer on something like this, even if you otherwise hate AI. The spirit of this evokes a Robin Hood-like mindset, in that it exists because of real ethical and economic issues around Adobe that many end users have long been stuck with. In one sense, it is “fighting AI slop with AI slop.” And even if you don’t end up using these tools, the techniques that these projects land on will ultimately inspire open-source projects that actually rely on craft. There are other apps that have emerged in the past couple of years that hope to bring design to Linux; this open-source tool may have opened up a shortcut for these projects.

screenshot_2026-10-08_10-57-55.png
Here’s how fast this project is moving. When I initially started messing around with this, it didn’t show my list of fonts. I then went to the GitHub page for DesignCraft, downloaded a new version that had just been released, and all of a sudden it supported all of my fonts.

Let’s talk about “craft” a second here: I think it’s a bad name to build around for this project, as cool and interesting as it is. Craft implies that a lot of heart was put into the code, that it was built by an expert. Which may be true of the artists and creatives that actually use this thing, but does it really speak to what the vibe coders are actually doing? Probably not. It’s really easy to not give critics something to point to, so don’t give it to them.

Another thing that they’re likely to point to is the inherent security issues that might come with a tool like this. The decision to use Rust as the language is likely to help with stability, but it’s not like any regular user is going to be looking at the code here.

But AI coding techniques are likely to change our relationship with open source for good, as seen with the recent AI-based fork of Asahi Linux . And in fact, it may change how companies like Adobe think of open source and vibe coding.

Who knows how legal this is? This feels like one a legit lawyer should probably weigh in on. But some of the language creator Brandon Thomas has used on forums and the ArtCraft website evokes the spirit of Napster, an icon of tech rebelliousness that is not exactly very rebellious in 2026. Napster was not legal, but it still changed everything. That’s a better place for AI in the cultural conversation than “everyone making the worst signs you’ve ever seen.”

And even if ArtCraft’s wild deconstruction project fails, it feels clear others will try to take its place. Which is exactly what happened with Napster.

Crafty Links

So the Ellisons own Warner Bros. Discovery, which I don’t love. But you know what I do love? That the anti-animation monster named David Zaslav isn’t in charge anymore.

The fact that a political candidate turned a famous I Think You Should Leave sketch into a very effective political ad is the kind of world I want to live in.

I’m getting sent a lot of single-serving sites at the moment. Here’s one that’s an iPod-themed music game that you might enjoy.

--

Find this one an interesting read? Share it with a pal ! PhotoCraft, by the way, doesn’t support animated GIFs just yet, but it does have the Save for Web legacy menu, which I was able to use to make today’s header. Not a bad start.

And thanks again to Computer Chronicles Revisited for supporting Tedium over the past month. It’s a cool project and it honors a great show that I’m a massive fan of. Thanks again; it rules.

Show HN: K10s – A Clickable Kubernetes TUI (Go, Bubble Tea)

Hacker News
github.com
2026-10-08 14:29:06
Comments...
Original Article
k10s

The Kubernetes terminal UI you can click .

k9s taught us to live in the terminal. k10s makes that terminal point-and-click, instantly searchable, themeable - and gives it an AI that already knows your cluster, namespace and selected object.

status go platforms single binary self--updating license PRs welcome

Install · Try it with no cluster · Features · k9s → k10s · Docs · Build log


k10s running in a terminal: resource sidebar, pod table with live status, and an action pane for the selected pod

A real terminal capture of k10s demo running - just screenshot , on the offline demo backend. Every frame in these docs comes out of the running binary, never hand-drawn.

Why k10s

A cluster dashboard is something you open twenty times a day, usually while something is on fire. The two things that matter are how fast it opens and how little you have to remember .

  • Nothing is hidden behind memorised keys. The actions that apply to the thing you selected are listed, right there, in their own pane. Click one, or press the letter next to it.
  • Your mouse works. Click a row, click a pane, click [ zoom ] , click ns default ▾ , scroll the table. Every border button is real.
  • One search box for the whole cluster. ctrl+p searches resource kinds and objects together. No prefix language to learn.
  • It opens instantly. Startup registers zero watches and waits for nothing - informers start lazily, per kind, the first time you look at one. Opening Pods watches pods, not every Secret and Event you own. ( how, and the regression guards )
  • AI that can see the screen. ctrl+a , ask in plain English. The current context, namespace, kind and selected object are injected into the prompt, so "why is this pod unhealthy?" means this pod.
  • It updates itself. /update installs the newest release over the running binary - checksum-verified, atomic, offers to restart into it.
  • Your k9s-style command plugins fit. Put scoped shortcuts in ~/.k10s/plugins.yaml ; they appear beside built-in actions and receive the selected object, namespace, context and column values.

Try it in 30 seconds (no cluster required)

k10s ships an offline demo backend: a realistic cluster to click around in, including a CrashLoopBackOff to poke at. It is opt-in , because sample data should never be mistaken for your machine.

git clone https://github.com/p10node/k10s && cd k10s
go run . demo     # the sample cluster - fake data, clearly labelled
go run .          # your real cluster, or "No cluster" if there isn't one

The demo is a context , not a mode. k10s demo opens on it, /demo switches to it from anywhere, and :ctx always lists it (labelled k10s demo · sample data , with a legend under the list). To leave it, pick any other context - there is no separate exit. While it is up the header carries a DEMO marker, so no frame of it can be mistaken for a real cluster.

Plain k10s reads the same kubeconfig kubectl does ( $KUBECONFIG , else ~/.kube/config ) and shows what that context can reach - and nothing else. With no kubeconfig, or a context whose API server does not answer, the main panel says No cluster and points at the way in: r retries, :ctx picks another context, /setup has the kubectl and kubeconfig links. docs/cluster-setup.md is the same guide, longer.

Install

curl -fsSL https://p10node.com/k10s/install.sh | sh

macOS and Linux, amd64 and arm64 . It picks the right prebuilt binary, verifies its sha256 against the release manifest, and installs it into /usr/local/bin (or ~/.local/bin when that needs a password it cannot ask for). --dir , --version and --no-sudo are in docs/install.md , along with how to read it before you run it and the matching uninstall.sh .

With Go on the box:

go install github.com/p10node/k10s@latest

Or from a clone, which also stamps the version into the binary:

git clone https://github.com/p10node/k10s && cd k10s
just install                 # → $GOBIN/k10s, version-stamped

Prebuilt static binaries for darwin/amd64, darwin/arm64, linux/amd64, linux/arm64 and windows/amd64 are published on every tag — Windows is the one platform the installer script sends to the release page instead. Every later upgrade is just:

Then run it:

k10s                  # your current kubeconfig context
k10s demo             # the built-in sample cluster, no cluster needed
k10s --readonly       # look, never touch: nothing that changes the cluster
k10s --version        # which build is this

What you get

Every resource, grouped the way you think about them

30 kinds across Workloads · Network · Config · Storage · RBAC · Cluster · Custom Resources , each with a live row count for the current namespace. Your CRDs are discovered automatically - no configuration.

Groups fold: space , left or a click on the header, remembered across restarts, with Config/Storage/RBAC folded to begin with. A folded group also asks your cluster for nothing - the sidebar is what decides which kinds get counted, and counting is one limit=1 request per visible kind, six at a time, with refusals remembered.

Pods · Deployments · ReplicaSets · StatefulSets · DaemonSets · Jobs · CronJobs · HPAs · Services · Endpoints · Ingresses · NetworkPolicies · ConfigMaps · Secrets · ResourceQuotas · LimitRanges · PDBs · PVCs · PVs · StorageClasses · ServiceAccounts · Roles · RoleBindings · ClusterRoles · ClusterRoleBindings · Nodes · Namespaces · Events · CRDs · Custom Resources

The whole day-2 toolkit, on single keys

d describe real kubectl describe output, from the API
y YAML the live object
l logs follows ( -f ), newest at the bottom, scroll back 500 lines
s shell a real interactive exec session - raw TTY, resize-aware, in-panel
p port-forward real SPDY forward, start/stop from the pane
m top pod/node metrics, per container, with requests vs limits
e edit · r restart · c scale rollout restart, scale, $EDITOR
o / u cordon-uncordon / drain - offered only when Nodes is selected
D delete red confirm modal, because it should be scary

Add your own scoped actions with the core k9s plugins.yaml format. They can run foreground or background commands, request confirmation, override a built-in shortcut deliberately, and are clickable in the same pane. See the plugin guide and installable example .

Logs that follow, in the pane you were already looking at ( z to zoom)

╭─ logs -f billing-worker-6f8d9c5b7-qq91x ────────────────────────────────── [ close ] [ restore ] ╮
│   8 2026-08-25T08:12:18.331Z INFO  http          GET  /v1/users/me         200 3.1ms             │
│     trace=44b1e2f9                                                                               │
│   7 2026-08-25T08:12:21.660Z INFO  worker        flushed batch size=250 dur=41ms                 │
│   6 2026-08-25T08:12:25.019Z INFO  http          GET  /healthz             200 0.3ms             │
│   5 2026-08-25T08:12:31.402Z INFO  http          DELETE /v1/sessions/9a1   204 5.7ms             │
│     trace=7c0d19ba                                                                               │
│   4 2026-08-25T08:12:33.881Z WARN  gc            pause=18ms heap=412Mi                           │
│   3 2026-08-25T08:12:40.117Z INFO  http          GET  /v1/orders/88213     200 7.4ms             │
│     trace=e21f8b05                                                                               │
│   2 2026-08-25T08:12:44.590Z INFO  metrics       scrape ok series=1842                           │
│   1 2026-08-25T08:12:51.008Z INFO  http          GET  /healthz             200 0.3ms             │
│ ● following  newest at bottom                                        500 loaded · ↑ for older    │
╰──────────────────────────────────────────────────────────────────────────────────────────────────╯

An AI prompt that already has the context

╭─ Prompt · plain text → AI · /commands still work · esc close ─ [ grow ] [ AI · claude-sonnet-5 ] ╮
│ ✦ ask about your cluster…   ·   /settings to change provider/model                               │
╰──────────────────────────────────────────────────────────────────────────────────────────────────╯
 ● AI mode — plain text goes to claude-sonnet-5    tab panes · enter open · ctrl+p search · f find…

ctrl+a toggles it. Bring your own key - OpenAI-compatible (so also Groq, Together, OpenRouter, vLLM, Ollama, LM Studio, any local gateway) or Anthropic . Answers open as a normal text view you can scroll, zoom and close. No cluster data leaves your machine unless you press enter in AI mode. The only other network call k10s makes on its own is the once-a-day update check, which asks GitHub for a version number and nothing else.

Eight built-in themes, plus your own — previewed live

tokyo-night (default) · catppuccin-mocha · dracula · nord · gruvbox-dark · solarized-dark · solarized-light · matrix

T cycles, /theme opens a picker that applies each theme as you move through the list - you judge it on the real UI, not on a name - and esc puts back whatever you had. Drop a YAML palette into ~/.k10s/themes , restart, and it appears in the same picker — no rebuild needed. See the custom-theme guide and installable demo .

Details that only show up after a long day

  • Copy mode ( ctrl+s ) releases the mouse so your terminal can drag-select and copy - the one thing every mouse-capturing TUI breaks.
  • An honest loading state instead of "no resources found" while a watch is still syncing.
  • Namespace and context pickers that never ask you to type a name.
  • No setup screen. First run opens the cluster; every setting has a working default and /settings is one keystroke away when you want it.
  • A grow-able prompt ( ctrl+z ) - because a long kubectl line or an AI question does not fit in a one-row field that scrolls sideways.
  • A terminal-too-small notice instead of a garbled layout.

Coming from k9s

k10s exists because of k9s . Credit where it is due: k9s is mature, enormous in scope, plugin-extensible, and it is the reason a whole generation of us stopped typing kubectl get pods all day.

k10s is younger and deliberately narrower. The difference is philosophy:

k9s k10s
Primary input keyboard-first, command-driven mouse and keyboard, equally
Discovery you learn the commands the actions for the selected object are listed on screen
Search per-view filter, plus : to jump between views one box ( ctrl+p ) over kinds and objects
AI plugin territory built in, with cluster context injected
Scope very large, plugin ecosystem small, opinionated, core command-plugin compatibility
Upgrades your package manager k10s update , self-replacing

Use k9s if you want the biggest feature surface, its full plugin ecosystem, and years of production mileage. Use k10s if you want something you can hand to a teammate who has never opened a TUI, and have them find logs on their own in ten seconds.

Keys

The short version - the full reference is here .

Key Action
tab / shift+tab cycle panes
↑↓ ( j / k ) · pgup/pgdn · g / G move · page · first/last
type (Resources focused) instant kind filter · esc clears
f find: search every column of the open table
ctrl+p search everything - kinds and objects in one box
enter / double-click open it: logs if it has them, else describe
z zoom / restore the centre pane
: / / command prompt (with a suggestions popup)
ctrl+a AI prompt mode ✦
T / ctrl+t cycle themes
ctrl+s copy mode - release the mouse to select & copy
click / wheel anywhere in a pane selects it, blank space included
q / ctrl+c quit

Commands

Two prefixes, and each one only ever shows its own set. / is k10s itself (theme, settings, updates). : is the cluster, in the k9s vocabulary - a resource view, the namespace, the context, or something acting on what is on screen. enter runs the highlighted suggestion immediately - no second trip through the prompt.

/theme  /settings  /mouse  /update  /version  /demo  /setup  /help    k10s itself

:po  :deploy  :rs  :sts  :ds  :job  :cj  :hpa      workloads
:svc  :ep  :ing  :netpol                           network
:cm  :sec  :quota  :limits  :pdb                   config
:pvc  :pv  :sc                                     storage
:sa  :role  :rb  :crole  :crb                      rbac
:no  :ns  :ev  :crd  :cr                           cluster + custom

the short form is what the popup lists; every kind also answers to its
plural and singular - :pods, :pod, :deployments, :persistentvolumes ...
and `:aliases` prints the lot

:po kube-system                 that kind, in that namespace (`all` works)
:svc api                        an argument that is not a namespace filters
:ns   :ctx                      namespace / context picker
:ns <name>   :ctx <name>        switch either outright
:aliases  :search <term>  :filter <term>  :scale <n>  :q

/ is k10s, : is the cluster - namespace and context are :ns and :ctx , not /ns and /context . :aliases prints the whole : vocabulary.

Anything that is not a / or : command runs as a shell command and its output opens in the main panel - date , kubectl get pods -o wide , helm list . Run through your own $SHELL , capped at 30s, with no terminal attached (use s on a pod for an interactive shell). Full command reference .

Config

k10s opens on kubeconfig's current-context — the cluster kubectl would talk to. :ctx <name> switches for the session without touching kubeconfig; kubectl config use-context is what changes where it opens next time.

Theme, namespace, folded sidebar groups, AI settings and the update check persist to ~/.k10s/config.yaml (override with K10S_CONFIG ), saved on every change. See config.md .

Note: the AI API key is stored as plain text in that file (mode 0600) and masked in the UI. If that is not acceptable in your environment, leave it empty and AI mode simply stays off.

Docs

architecture.md packages, the Source boundary, render pipeline, mouse zones
performance.md lazy watches, cheap counts, and the guards that keep it fast
ui.md layout, panes, focus, zoom, overlays
keybindings.md full key + mouse reference
commands.md prompt modes, slash commands, AI settings
themes.md theme list, picker, palette contract
config.md · update.md what persists · how self-update works
cluster-setup.md no cluster? installing kubectl and getting a ~/.kube/config
backends.md · dev.md live vs demo backend · build, tests, headless renderer
roadmap.md what is done, what is missing, and the known limits
marketing.md · build-in-public.md how this project is being shared

Contributing

The barrier is low on purpose. just lists every recipe:

just dev            # run from source
just shot 140 44    # render one frame headlessly - no TTY, no cluster
just screenshot     # capture the README hero from a real terminal (vhs)
just check          # fmt + vet + test, in the order that fails fastest

cmd/shot is why UI work here is pleasant: you can iterate on layout, replay keystrokes ( just shot 140 44 j,j,d ) and diff frames without a terminal or a cluster. Nothing in these docs is drawn by hand - the frames come from that renderer, the hero image from just screenshot driving the real binary in a real terminal.

Good first issues live in roadmap.md → possible next steps : more kinds, click-to-sort columns, multi-select bulk delete, grep inside the log stream, saved views.

Honest status: every live path is implemented against the real client-go/kubectl APIs and covered by tests with fake clientsets, but this tree has not yet been smoke-tested against a production cluster by its author. Try it on kind first. The known limits are listed in the roadmap rather than buried.

Thanks

To my colleagues - the people whose questions, over-the-shoulder debugging sessions and "can you just check if that pod is up?" pings are the entire reason this exists. k10s was not built to be a project; it was built so that looking at our clusters would stop being the annoying part of your day. Every pane in it is an answer to something one of you asked me. Thank you for the inspiration, the patience, and for being the first users.

Cảm ơn các đồng nghiệp của tôi - repo này được viết ra để phục vụ các bạn, và chính các bạn là nguồn cảm hứng cho k10s.

To @derailed and k9s , for proving a Kubernetes TUI could be something you actually want to open.

To Charm - Bubble Tea , Lip Gloss , Bubbles - and to BubbleZone , which is the reason any of this is clickable at all.

License

Apache-2.0 - the same license as Kubernetes, Helm and k9s. Use it, fork it, ship it inside your company.

Serverless Horrors $10,811.41

Hacker News
serverlesshorrors.com
2026-10-08 14:12:49
Comments...
Original Article

Original post

Follow-up

Hit by a Cloudflare bill assassin: a $10k bill. The cause was a Durable Object alarm in an infinite loop in one project, which did 6 trillion reads and writes. Vibe coding failed me.

Update from the author:

  • Paid the full Cloudflare bill (US$10,811.41) — “the second most expensive lesson of my life”.
  • The support ticket for a reduction only got bot replies in a loop.
  • Cloudflare staff contacted on X and other channels said they could only “take a look”, nothing more.
  • All projects will move off Cloudflare to self-hosted VPS.

Conclusion: One vibe-coded Durable Object alarm kept rescheduling itself forever. Cloudflare has no hard spending limit, so the loop ran until the invoice came. Not refunded — the author paid in full.


tldr: An infinite loop in a Durable Object alarm did 6 trillion reads/writes and caused a $10,811.41 Cloudflare bill that was not refunded.

Show HN: Pocketty – iPhone SSH terminal that pings you when an agent is blocked

Hacker News
pocketty.app
2026-10-08 14:11:52
Comments...
Original Article

SSH for iPhone and iPad, made for herdr

Your agents,
in your pocket.

Know the moment an agent is blocked or done. Answer it in a real terminal, right from your phone. Only your phone can read the alert.

get pocketty Free for 14 days. Then $129 $99 once , launch price.

  1. herdr sees the agent block. Your computer seals the alert for this phone only.

    herdr
    w1:p1 working → blocked

    seal
    HPKE · X25519 · ChaCha20

    relay
    forwards sealed bytes

    apns
    delivers to this phone

  2. pocketty opens that exact Pane, straight over SSH. No server in between.

    link
    pane w1:p1 on studio

    ssh
    studio, over Tailscale

    key
    Secure Enclave, Face ID

    herdr
    control w1:p1 --takeover

  3. Return, Esc, Ctrl and the arrows. The agent gets real keystrokes.

    key
    Return

    herdr
    pane.send_keys ["enter"]

    agent
    claude blocked → working

    frames
    diffs of the screen

  4. Swipe in from the edge for the turn's diff. Only what the agent changed since it started.

    daemon
    snapshots the worktree

    turn
    since claude went working

    diff
    2 files +4 −3

    swipe
    back to the Pane

  5. Text mode sends a whole message at once. Dictation and images work too.

    mode
    Text

    herdr
    pane.send_input (paste)

    herdr
    pane.send_keys ["enter"]

    agent
    claude idle → working

  6. Go back for every Pane on the host. Each agent shows its state, live.

    relay
    claude working

    docs
    codex working

    ios
    claude working → done

    review
    opencode idle

  7. When a Pane opens a port, pocketty offers a preview. When you close it, you are in that Pane.

    port
    4321 opens in docs

    ssh
    forwards localhost:4321

    page
    sees localhost

    close
    back in the docs Pane

  8. Lock the phone. When the agent finishes, pocketty tells you.

    herdr
    w1:p1 working → done

    daemon
    waits 2 s, then seals

    relay
    stores nothing

    phone
    opens it locally

The real thing.

Straight from the iOS simulator, not a mockup.

herdr, native

Every agent, every Pane, at a glance.

pocketty speaks herdr's own API.
Your workspaces and tabs show up as a native list.
Each agent shows its state: working, needs you, or done.

  • Panes, not screenshots

    Open any Pane full screen, at phone size. Lock the phone, and your desk gets it back.

  • Run herdr from the couch

    Start a tab or a workspace. Rename a tab, or swipe a Pane away.

  • No hooks in your agents

    pocketty reads agent state from herdr. It never edits an agent's config files.

  • Plain SSH, too

    No herdr? You get a normal login shell. Or tmux and zellij, with a startup command.

Works with every agent herdr knows, including

  • Claude Code
  • Codex
  • OpenCode
  • Gemini CLI
  • Cursor
  • GitHub Copilot
  • Grok
  • Qwen Code
  • Kimi Code
  • Devin
  • Hermes
  • Antigravity

Review the work

See what your agents did.

Check a diff, read a file, or open the dev server.
All from the Pane where the agent works.

Diffs by agent turn

The daemon snapshots the worktree each time an agent starts work.
So you see what this turn changed, not everything at once.

  • Last turn Only what the agent changed since it last started work.
  • Session Every change in the agent's session, turn after turn.
  • Uncommitted Everything since the last commit, like git diff.

Turn and session diffs need the daemon on the host.

The Changes tab with Last turn selected: one Rust file, 3 lines added and 2 removed. The diff of that file: a named constant replaces two copies of 60.

  • A file browser

    Browse and search the worktree of any Pane. Code shows in color, in 20 color schemes.

    A Rust file from the relay in the file browser, with syntax colors.
  • Previews of localhost

    When a Pane opens a port, pocketty offers a preview. The page loads through your SSH connection. No tunnel to set up.

    The pocketty website, served on localhost, open in the preview.

Security

Your work stays between your phone and your computers.

Your terminal never touches our servers.
We only pass along agent notifications, if you turn them on.
And we can't read those.

01

The terminal

Every keystroke and every line of output.

always direct

The App connects straight to your computer.
We are not on this path, so there is nothing for us to see.

02

Agent notifications

The short alert when an agent is blocked or done.

optional
  1. Your computer pocketty daemon Seals

    Writes the alert. Never Pane text. Seals it with your phone's key.

  2. Our relay Cloudflare Worker Forwards

    Passes the sealed bytes to Apple. Can't open them. Keeps nothing.

  3. Apple Push Notification service Forwards

    Delivers them to your phone. Sees only “Agent update”.

  4. Your iPhone notification extension Opens

    Opens the seal on the phone. Checks which computer sent it.

Notifications off? Then the App only ever talks to your own computers.

  • Keys that can't leave

    Your SSH key is made in the Secure Enclave. Face ID can guard the App, too.

  • Pinned host keys

    A changed host key stops the connection. pocketty asks before it trusts the new one.

  • Two-sided proof

    Seals use HPKE in auth mode. An alert from anyone else won't open.

  • No account, no tracking

    The App has no sign-up, no email and no analytics. There is nothing to sign in to.

Read the full security model

The terminal

A real terminal that feels at home on a phone.

pocketty runs Ghostty's terminal engine, drawn with Metal.
Agents, editors and TUIs look the way they do on your desk.

The keys you need

Ctrl, Alt, Esc, Tab, arrows, and the symbols phones hide.
Hold a key to repeat it.

fix the flaky test, then match this layout

Write, don't poke

Text mode sends a whole message at once.
Dictate it, paste screenshots, send.

Photo Library Take Photo Choose File

~ $ ~/.cache/pocketty/uploads/paste-3f2a.png

Send files and photos

Pick from Photos, the camera or Files.
pocketty uploads it and types the path.

15pt cargo nextest run -p pocketty-relay

Touch that makes sense

Hold to select, then drag the handles.
Swipe to scroll. Pinch to resize.

=> != -> |> <= :: JetBrains Mono · Fira Code · Iosevka

Nerd Fonts, with ligatures

Every Nerd Font. JetBrains Mono is built in.
Prompt icons draw. Ligatures switch off.

⌘ ⇧ K

Desk habits work

Hardware keyboards and the kitty keyboard protocol.
OSC 52: copy on the computer, paste on the phone.

Setup

Add a computer in a minute.

No keys to copy around.
You approve your phone on the computer itself, with a code.

  1. 1

    Install the daemon

    One small binary, running as you. It writes only to its own folder.

    $ curl -fsSL https://pocketty.app/install.sh | sh

  2. 2

    Tap it under Nearby

    On the same Wi-Fi, your computers show up by themselves. After that, Tailscale reaches them from anywhere.

  3. 3

    Type the code on your computer

    Your phone shows six digits. Your Mac asks for them. Your key goes in, and the host key is pinned.

Any SSH server works without the daemon, too.
pocketty gives you a one-line setup command.

A connection that picks itself up.

pocketty checks the link every five seconds.
If it drops, pocketty reconnects by itself.
Plain SSH means no version mismatches.

Compare

Fewer features. None of them leak.

Moshi does more: Mosh, Apple Watch, Live Activities, a chat view.
pocketty does less, on purpose.
Your agents' words stay off other people's servers.

pocketty vs Moshi
Feature pocketty Moshi
Price Yes: Free for 14 days. Then $99 once, with every update. Free tier. Pro is $9.99 a month, $89.99 a year, or $199 lifetime ($249 in the App Store).
What a notification carries Yes: Agent, state, computer, workspace and tab, sealed on your computer with HPKE. Never Pane text. No: moshi-hook sends titles, messages, the prompt (up to 200 characters) and the command to approve (up to 256) to Moshi's server.
Who can read it Yes: Only your phone. Our relay and Apple see ciphertext. No: Moshi's server, which caches inbox events for up to 24 hours. Banners go through Expo Push.
herdr Yes: Native Pane view over herdr's own API, with live agent state. Included. Partly: Session picker and attach are Pro. Chat View needs moshi-hook.
How it learns agent state Yes: From herdr. Nothing is installed into your agents. Partly: moshi-hook writes hooks into each supported agent's config files.
Diffs Yes: The last agent turn, the whole session, or since the last commit Partly: Uncommitted changes only, side by side. Pro, with moshi-hook.
Matching versions Yes: Never needed. App and daemon update in any order. Partly: The App flags an out-of-date moshi-hook. Desktop needs hook 0.3.1 or later.

See all 26 rows, with sources Moshi facts checked on October 2, 2026.

Pricing

Free for 14 days, with everything. Then the launch price. It goes up to $129 later.

  • iPhone and iPad
  • Every future update
  • Native herdr Panes and agent state
  • Sealed agent notifications
  • Secure Enclave keys and Face ID lock
  • The daemon for macOS and Linux

get pocketty

No subscription. No account. No ads.

Questions

How does the free trial work?

Everything works for 14 days, from your first connection. Then $99 once keeps it. Nothing is charged when the trial ends.

Do I need herdr?

No. pocketty works with any computer you reach over SSH. herdr adds the native Pane view and agent notifications.

Do I need Tailscale?

It is the path we recommend. It gives each computer an address that works anywhere, and code setup needs it. Any SSH server you can reach works too.

What do I install on my computer?

Nothing, for a plain shell. Install the pocketty daemon for agent notifications and code setup.

Can you read my notifications?

No. Your computer seals each one so only your phone can open it. Our relay passes the sealed bytes to Apple, and keeps nothing.

Why no Mosh?

SSH is already on every computer. Over Tailscale the address never changes, and pocketty reconnects in a moment. One protocol also means no version mismatches.

Is there an Android version?

Not yet. pocketty is for iPhone and iPad today.

Leave the desk. Keep the agents.

pocketty for iPhone and iPad.
Free for 14 days, then $99 once.

Theranos.World

Hacker News
www.theranos.world
2026-10-08 13:51:49
Comments...
Original Article

Office desk with a MacBook, iPhone, Theranos instrument, and a clear cup of green juice in front of the laptop

Come see the documentary with us on Oct 22nd in SF -Bo

100%

9:41 AM

Click Log In or press Return or Space. No password is required.

Thorsten Alteholz: My Debian Activities in September 2026

PlanetDebian
blog.alteholz.eu
2026-10-08 13:19:04
Debian LTS/ELTS This was my hundred-forty-seventh month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian. During my allocated time I uploaded or worked on: [DLA 4804-1] libsmpp34 security update to fix one CVE in Bookworm related to an out of b...
Original Article

Debian LTS/ELTS

This was my hundred-forty-seventh month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.

During my allocated time I uploaded or worked on:

  • [ DLA 4804-1 ] libsmpp34 security update to fix one CVE in Bookworm related to an out of bound read.
  • [ #1149107 ] trixie-pu of libsmpp34 has been created and wait for review by the release team.
  • [ DLA 4805-1 ] mkvtoolnix security update to fix one CVE in Bookworm related to a heap buffer overflow.
  • [ DLA 4806-1 ] pgextwlist security update to fix one CVE in Bookworm related to substituting extension schemas or owners matching [“$’\].
  • [ELA-1837-1] mkvtoolnix gimp security update to fix one CVE in Bullseye to a heap buffer overflow.
  • [osmo-iuh] upload to fix a CVE related to a reachable assertion in Sid.

Besides doing these uploads, the month was filled with unscheduled meetings, discussions and explanations, all basically around the role of FD.

During my week of FD duties, I had to become familiar with new tools. As there are several things that FD has to do over and over again, I tried to automate this a bit. My experiments went well and I think this can be used to make FD duties less repetitive.

I also continued my work on cups and hplip and I am confident that I can do uploads in October. Last but not least I spend some time on security-master to assist others (especially the kernel team) with uploads to Bookworm and Bullseye.

In case you need to get a complete clone of the security-tracker, using the option –deepen n might be of help. Unfortunately in case you choosed n too high and some kind of error appears, something gets into a mess and you need to start almost from the beginning (some objects are still present and are used again). If you want to run a script, a value of 10 might be a good choice. You don’t have to deepen back to the beginning. At some point in time you can just –unshallow and get the whole rest. Afterwards doing a git gc is highly recommended.

Debian Printing

This month I uploaded a new upstream version or a bugfix version of:

  • … hplip to unstable, to fix an expired certificate and some bugs.

This work is generously funded by Freexian !

Debian Lomiri

Unfortunately this month my work did not make any progress.

Nevertheless, in case of any work done, this would have been generously funded by Fre(i)e Software GmbH !

Debian Astro

Unfortunately I had no time to work in this category this month.

Debian IoT

Unfortunately I had no time to work in this category this month.

Debian Mobcom

This month I uploaded a new upstream version or a bugfix version of:

misc

This month I uploaded a new upstream version or a bugfix version of:

Navier-Stokes lost in translation: Why Lean verification of AI autoformalisation does not guarantee correct natural language proofs

Lobsters
arxiv.org
2026-10-08 13:16:42
Autoformalisation is increasingly used to verify mathematical texts, including those generated by AI, as in OpenAI's announced proof of blow-up of solutions to the Navier-Stokes equations. In this process, an AI system translates the text from a natural language (NL) into a formal language such as L...
Original Article

View PDF HTML (experimental)

Abstract: Autoformalisation is increasingly used to verify mathematical texts, including those generated by AI, as in OpenAI's announced proof of blow-up of solutions to the Navier-Stokes equations. In this process, an AI system translates the text from a natural language (NL) into a formal language such as Lean. Once this translation is done, the argument expressed in the formal language can easily be mechanically verified. The purpose of this article is to demonstrate why this process may offer no confidence in the original NL argument, owing to the various difficulties in performing the translation semantically faithfully. In particular, we highlight that the problem of resolving ambiguities in mathematical NL text, which is necessary in order to provide semantically faithful translation, is arbitrarily high up in the Solvability Complexity Index (SCI) hierarchy/arithmetical hierarchy (the SCI $= \infty$). Hence, informally, providing semantically faithful AI autoformalisation is harder than any computational problem including the Halting problem (which has SCI $= 1$). To demonstrate the effect of this result we provide several examples of AI mistranslations of NL statements and proofs into Lean in practice, resulting in mismatches between NL proofs and their Lean `verifications'. These include OpenAI's announced Navier-Stokes proof. In particular, we show that the formalised Lean proof does not correspond to the NL proof of blow-up of solutions to the Navier-Stokes equations.

Submission history

From: Alexander Bastounis [ view email ]
[v1] Tue, 6 Oct 2026 10:58:01 UTC (1,080 KB)

The Deeply Impersonal Personalized Recruiter Mail

Hacker News
blog.pentlander.com
2026-10-08 13:15:57
Comments...
Original Article

Lately I’ve encountered a new species of software engineer recruiter mail. It goes something like this:

Your work on infrastructure at Railway, along with your earlier years building observability software at City Storage Systems and storage systems on AWS Glacier, is exactly the kind of platform background this role calls for.

So the first paragraph is spent explaining my career to me (thanks I forgot where I worked). The last sentence is coincidentally “that’s exactly what we’re looking for”! Then follows the actual job description for building CI/CD pipelines, which has almost nothing to do with the job experience just mentioned. Clearly the first paragraph is generated by an LLM, but the job description too?!

A few gems I've gotten:

That's the gap. You'd be the first. The work is concrete: multi-tenant isolation for AI model serving, golden-path service templates in Terraform, IAM and secrets management wired into CI/CD, and policy-as-code that makes secure the default rather than the exception.

Observability here is genuinely unsolved. The failure modes are probabilistic rather than deterministic, so standard instrumentation tells you less than you need.

Every document is a referral, a prior auth, or an intake form, which means extraction accuracy isn't a dashboard metric, it's whether a patient gets seen or gets denied. Messy inputs, no tolerance for silent failure, growing fast.

Over the years I’ve gotten lots of emails along the lines of “Hey it’s really neat that you work at X company” immediately followed by the job description, so what’s the difference? So what if it’s generated by an LLM?

To me the difference is twofold:

  1. “Personalized” with zero connection to the job description
  2. Being very obvious LLM text

With the former, I understand recruiters send a lot of emails to hit the numbers they need. The email template with [insert name and previous company] is a shotgun blast, they probably haven't spent more than 10 seconds looking at my profile to see if it’s a fit. So it’s unsurprising to me that it’s for a Django fullstack role when my history shows I’m an infra engineer with no professional Python experience. However when the same job description is preceded by paragraph saying how my previous roles makes me “perfect for this job”, it actively insults my intelligence.

What makes it extra maddening is an LLM could look at my resume to see that I'm a match and write about how my experience directly ties in to the role. Or conversely it could determine “hey why the hell are we even talking to this person, they don't know Verilog”. I suspect the latter is why they don’t actually do this.

All of that coupled with even the job description being full of extremely common LLMisms pushes these emails below the plain old templated emails in my mind. A simple edit pass through another LLM could remove these. Or, you know, doing a quick proofread of the thing being sent out. The overt fakeness of the effort and personalization makes it feel so unapologetically impersonal.

#llms #recruiting #software

Show HN: AI SRE Arena, an Open Benchmark for AI SRE Agents on Kubernetes

Hacker News
github.com
2026-10-08 13:13:08
Comments...
Original Article

A vendor-neutral starter for deploying a disposable Kubernetes fixture, injecting faults, saving investigation records from any product, and scoring completed investigations with a configurable judge. Python 3.10+ is the only Python dependency. Kubernetes operations additionally need kubectl ; local cluster creation needs Docker and kind .

Choose local kind or AWS EKS for your cluster, then select the 21-scenario full suite or six-scenario smoke fixture. Cluster type and scenario suite are separate choices.

How it works

flowchart LR
    A[Deploy cluster and application] --> B[Connect your product]
    B --> C[Inject and verify a fault]
    C --> D[Let your product investigate]
    D --> E[Save investigation records]
    E --> F[Score with your chosen judge]
    F --> G[Compare results]
Loading

Run commands from the Project Arena directory. Cluster setup, product integration, scenario execution, and scoring are separate steps; follow the sections below in order.

Benchmark results

We compared Edge Delta’s native AI investigations , Grafana’s native AI investigations , and Claude using each platform’s observability CLI across 21 Kubernetes incident scenarios. edx provides access to Edge Delta; gcx provides access to Grafana. All final investigations were evaluated against the same incident facts and scoring rubric using GPT-6-Astra.

Detection and investigation results

Edge Delta detected and investigated 18 scenarios; Grafana detected and investigated 12. Claude was started externally for all 21 scenarios on each platform: 16 alerts and 5 customer reports with edx, and 12 alerts and 9 customer reports with gcx. Detection was not independently measured for Claude, so those cells are shown as — .

Investigation scores use every completed investigation for that column. Implementation readiness excludes cases with no mitigation proposal.

Metric Edge Delta native Grafana native Claude + edx Claude + gcx
Detection 18/21 (85.7%) 12/21 (57.1%) — —
Root cause analysis 15/18 (83.3%) 9/12 (75.0%) 18/21 (85.7%) 19/21 (90.5%)
Blast radius 12/18 (66.7%) 8/12 (66.7%) 18/21 (85.7%) 18/21 (85.7%)
Supported final mitigation 8/18 (44.4%) 5/12 (41.7%) 16/21 (76.2%) 15/21 (71.4%)
Implementation readiness 9/16 (56.2%) 5/12 (41.7%) 16/21 (76.2%) 15/21 (71.4%)

Comparison on the same 12 incidents

This table uses the 12 incident types investigated by both native products, with the corresponding Claude investigations. It controls which scenarios are included, not differences in launch prompts, timing or available evidence.

Metric Edge Delta native Grafana native Claude + edx Claude + gcx
Root cause analysis 11/12 (91.7%) 9/12 (75.0%) 10/12 (83.3%) 10/12 (83.3%)
Blast radius 9/12 (75.0%) 8/12 (66.7%) 10/12 (83.3%) 10/12 (83.3%)
Supported final mitigation 7/12 (58.3%) 5/12 (41.7%) 8/12 (66.7%) 8/12 (66.7%)
Implementation readiness 8/12 (66.7%) 5/12 (41.7%) 8/12 (66.7%) 8/12 (66.7%)

View results for every scenario · Download CSV

What the metrics mean

Metric What earns credit
Detection The product detected the incident and started an investigation within the observation window.
Root cause analysis The final report correctly explains what caused the incident.
Blast radius The final report correctly identifies the affected workloads and downstream impact, without claiming unsupported outages.
Supported final mitigation The final recommendation gives a concrete, supported fix or safe containment for the incident, with no remaining incorrect or unsafe advice.
Implementation readiness The proposal specifies the correction and essential details; normal review, implementation, and rollout checks may remain.

Mitigation and readiness measure proposals, not executed repairs or verified recovery.

See the scoring rubric for grading rules and full results and methodology for verdict breakdowns and evaluation details.

How to deploy

Run all commands from the Project Arena directory. Both environments use the same benchmark commands after cluster and image setup. The runner uses the context you provide; it does not automatically install networking or configure registry access.

Local kind AWS EKS
Cluster creation Docker and kind Terraform in infra/cluster
Credentials No AWS credentials Your AWS credentials
Full-suite images Build and load into kind Build and push to a registry accessible by the nodes
Networking NetworkPolicy needs an enforcing CNI Terraform enables VPC CNI policy enforcement
Cleanup Delete the kind cluster Remove workloads, then destroy Terraform resources

Choose a deployment path

Cluster setup and deployment method are separate choices:

Path How changes reach Kubernetes Setup
Direct bench applies application and fault manifests with kubectl Follow the scenario commands below
GitOps (full suite) You commit and push changes to your repositories; Argo CD syncs them Follow the Argo CD setup and run guide

The GitOps path uses component Applications, flagd-values , and batch-active . Application and fault configuration can live in separate repositories or separate paths in one repository. Use your own repositories and configure their URLs. Record which repositories the investigating product can access.

The deployment, fault, and reset commands below use the direct path. For an Argo-managed application, use the GitOps guide's commands; direct mutations are blocked to avoid conflicting with Argo's self-healing. Investigation import, scoring, and reporting work the same way for both paths.

Local kind

Install Python 3.10+, kubectl, Docker, kind and Helm. Follow the kind setup to create a cluster with Cilium and load the full-suite images. Then select its context:

export ARENA_CONTEXT=kind-incident-bench

The full suite uses prebuilt application images for Linux AMD64 and requires AMD64 workers. Apple Silicon Macs can run the smoke suite on native ARM64 kind workers, or operate an AMD64 EKS cluster. Building ARM64 fault images alone does not make the full application ARM64-compatible.

For the full suite, keep registry: "fixture.local" and tag: "v1" in arena.json . The linked setup enables NetworkPolicy enforcement for netpol-isolation . For smoke alone, python3 -m bench cluster create is sufficient; smoke uses a pinned public image and does not need the full-suite image build.

AWS EKS

Install Terraform and the AWS CLI in addition to Python, kubectl and Docker. Configure your AWS credentials, then follow the AWS cluster setup to create the cluster and kubeconfig context. Authenticate Docker to your registry and build images for your worker architecture:

export ARENA_CONTEXT=YOUR_CONTEXT
kubectl --context "$ARENA_CONTEXT" get nodes -L kubernetes.io/arch
# Choose the platform matching the workers shown above.
export ARENA_PLATFORM=linux/amd64  # Required by the full suite’s prebuilt application.
python3 -m bench.scenarios build-images --registry YOUR_REGISTRY/bench \
  --tag YOUR_TAG --platform "$ARENA_PLATFORM" --push

Choose the worker architecture , regardless of which computer runs the build:

Kubernetes workers Build platform
ARM64 workers Smoke suite supported; full suite requires rebuilding and validating the application
Intel Mac local kind or Intel/AMD workers, including the default EKS m6i.xlarge linux/amd64

An Apple Silicon Mac can build for Intel/AMD EKS workers using linux/amd64 ; Docker Desktop supports cross-platform builds through emulation . This command builds one target architecture at a time. On mixed-architecture clusters, the application is scheduled on AMD64 workers.

Set registry and tag in arena.json to those same values. Nodes must have pull access to the registry; configure registry permissions or Kubernetes pull credentials yourself. AWS resources incur charges. Terraform currently creates subnets in three availability zones within one region; zone count and worker count are separate settings.

After either setup, install your product's collector and alert configuration using its instructions. Continue with the run configuration below.

How to run scenarios

Configure a run

Edit the generated arena.json :

Setting What to enter
context Your Kubernetes context from setup; no ambient-context fallback
product Product name used in report columns
run_id , output_dir A unique run name and its result directory
suite , scenario full or smoke , and a scenario from that suite
registry , tag Values used when building full-suite images
judge API provider, model and optional endpoint/settings
judge_command Optional custom judge executable; overrides the built-in API adapter
truths Optional answer-key overrides for customized scenarios

The default full suite currently includes 21 scenarios. The smaller smoke suite includes six and uses a public Python image, so it does not need the fault-image build. They use different applications; select a suite before deploying. See the scenario table for requirements and differences.

python3 -m bench catalog
python3 -m bench deploy

Before injecting a fault, complete product setup and confirm the product receives the healthy application's telemetry.

Inject and observe

For the full suite:

python3 -m bench fault
python3 -m bench verify
python3 -m bench evidence

fault applies the manifests; verify checks whether the expected failure is observed. Successful application alone does not establish a valid test. Let the product finish investigating before resetting the fault.

For smoke , use fault and evidence , then inspect pod status, events and service availability yourself; automated verify currently supports only full . A healthy smoke app serves HTTP on port 8080:

kubectl --context "$ARENA_CONTEXT" -n incident-bench port-forward service/api 8080:8080
# In another terminal:
curl http://localhost:8080/health

For another attempt, reset first and select a fresh case directory with --case , placed before the command:

python3 -m bench --case oom-attempt2 fault
python3 -m bench --case oom-attempt2 verify
python3 -m bench --case oom-attempt2 evidence

Use that same --case for subsequent import and scoring commands. It selects an artifact directory, not a different scenario. Change scenario in the run file when testing another fault.

How to connect your product

Install your product's collector and configure alerts using its own instructions. Project Arena does not install a vendor agent, log in to a product, or configure alerts automatically. Kubernetes logs, events, pod state and application behavior provide the fault signals; collect metrics and traces through your chosen tooling.

Set product in arena.json to the name you want in comparison tables. After the investigation, save these files under <output_dir>/<scenario>/ (or your selected case directory):

File Contents
final.txt The actual delivered final answer, unchanged
intermediate.txt Earlier advice, if available
actions.txt Tool submissions and results, if available

Import them with:

The command uses those filenames automatically. Missing final input is an error; missing intermediate/action evidence stays missing. Record detection explicitly with --detection detected or --detection not_detected when supported by an observation window and evidence; the default is not_measured .

Manual export is supported. For API-based integration, provide an exporter using the investigation record format . Hosted-product connectors are not bundled. An undetected case can still have a record with an empty final answer; it must not be represented as a completed investigation.

How to score investigations

The judge is an AI model that compares a completed investigation with the scenario's answer key and the scoring rubric . Answer keys are included.

  1. In arena.json , choose the judge provider and model. For example, edit the existing judge section:

    "judge": {
      "provider": "openai",
      "model": "YOUR_MODEL"
    }
  2. Make the provider's API key available in your shell ( OPENAI_API_KEY for this example). Keep the key out of arena.json . Other providers and local models are supported.

  3. After importing the investigation, run:

    python3 -m bench packet  # Prepare the investigation, answer key and scoring rules
    python3 -m bench judge   # Send them to your chosen model

The result is judgment.json in the case directory: scores, explanations and supporting quotes. Use the same judge model and settings for every product you compare. API calls may incur charges.

You can score the same saved investigation again without rerunning the incident. See rescoring and saved results for details.

How to compare results

python3 -m bench report --summary > summary.csv
python3 -m bench report --details > details.csv

The summary puts metrics in rows and products in columns. Each cell shows successful/applicable (percentage) . Illustrative values, not benchmark results:

Metric Product A Product B
Detection 8/10 (80.0%) 7/10 (70.0%)
Root cause analysis 6/8 (75.0%) 5/7 (71.4%)
Final mitigation 5/8 (62.5%) 4/7 (57.1%)

The actual report includes every scoring dimension. The detail table lists each scenario's verdict and whether it is included in the denominator. Undetected cases count against detection rate; not-applicable cases are excluded from the relevant scoring denominator. Insufficient evidence stays in the denominator for applicable scored cases. Missing measurements and unscored investigations remain visible in the details. A dash means no applicable scored cases.

Product names come from investigation records, matched to judgments by content hash. Records and judgments are discovered in the configured run directory. Include records for undetected cases too. Use matching scenario cohorts, rubric and judge settings when comparing products; see report options and counting rules for combining runs and interpreting each metric.

How to clean up

Reset between scenarios

For GitOps, follow the Git reset and sync workflow so the repository and cluster return to the same baseline.

For the full suite using direct deployment:

python3 -m bench reset --confirm-disposable

This retires the injected resources, restores the three scenario flags, and clears only that fault’s persistent effects. Healthy services, application data, credentials and the cluster remain in place; reset verifies the baseline before another fault. For smoke , use python3 -m bench reset ; it restores the app but retains the storage fault's PVC.

Remove a local kind cluster

python3 -m bench cluster delete --confirm-delete

Remove AWS resources

Remove application resources and any provisioned volumes or load balancers, then follow the AWS teardown instructions . Resetting a fault does not stop AWS charges. Optional Terraform state storage persists separately.

Advanced configuration

  • Use --run path/to/run.json before a command to select another configuration. Explicit flags override saved settings.
  • Configured file paths are relative to the run file. Explicit CLI paths and judge executable arguments are relative to the current working directory.
  • Use packet --rubric path/to/rubric.md for a custom rubric. Keep the same rubric and judge settings across compared products.
  • Product exporters and judge formats describe custom integrations and evidence requirements.
  • Scenario implementation guide covers manifests, image builds, verification and reset behavior.

To run the offline tests:

python3 -m unittest discover -s tests -v

License

Project Arena is licensed under the MIT License . Bundled third-party code retains its own license, including the shop application under Apache-2.0 .

FakeGit malware campaign returns with 17,610 malicious GitHub repos

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 13:10:55
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]...
Original Article

FakeGit malware campaign returns with 17,610 malicious GitHub repos

More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.

The operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.

The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader, that is used to distribute other malware.

While similar activity with various payloads has been observed since at least January, the FakeGit term was associated with this operation in July, when researchers at enterprise browser platform Island published a report on 7,600 fake GitHub repositories pushing the SmartLoader malware.

Island noted at the time that 800 of the malicious repositories masqueraded as AI skills or MCP servers that appeared in public AI registries and catalogs.

A new report from researchers at software supply-chain security platform Apiiro says that FakeGit resumed its activity on October 4 and now uses 17,610 repositories on GitHub.

In just 34 hours, FakeGit pushed more than 13,000 repos, peaking at 2,999 an hour.

"In the commits we sampled, 97% touched only the README, and 88% pointed its “Download” button at a ZIP that installs SmartLoader," Apiiro says.

"Nobody had to create a single new repo. The fleet was already there. It just got re-aimed," the researchers added.

FakeGit attack flow
FakeGit attack flow
Source: Apiiro

How FakeGit survived

According to the researchers, the reason behind FakeGit's survival is that removing repositories is based on lists that cover only a fraction of the malicious repos.

Also, blocklisted payloads and backup copies remain accessible, so attackers can simply change the download links while keeping the same repositories active.

“71% of the fleet was missing from URLhaus before our report, and a domain-level DNS blocklist can’t block one file on GitHub without blocking GitHub,” Apiiro explains .

The researchers found malicious archives in forks, older files, release assets, issue attachments, and separate download-hosting repositories, which makes deleting one link at a time ineffective.

“Delete one file and the operator can point the lure at a spare copy: a fork, an older ZIP, a release asset or an issue attachment,” the researchers said.

Apiiro researchers recommend that users verify the repository’s owner. Furthermore, the source for installing AI skills and MCP servers should be official registries or vendor repositories.

If SmartLoader execution is suspected, users should treat the incident as a potential GitHub account compromise, revoke active sessions and access tokens, and move to passkeys.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

[$] An update on Rust's project goals

Linux Weekly News
lwn.net
2026-10-08 13:00:30
Tomáš Šedovič is a program manager at the Rust Foundation. He co-leads the goals team, which helps organize the Rust project's overall goals, including making sure that the people who have agreed to work on one have the support they need. At Kangrejos 2026, he provided an overview of the Rust pro...
Original Article
The page you have tried to view ( An update on Rust's project goals ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 22, 2026)

Whistle: Speech to Text in 16.9 MB

Hacker News
cactuscompute.com
2026-10-08 12:59:39
Comments...
Original Article
Back to blog

Models Research

An open speech recognition model that runs on the same CPU engine as Needle. It transcribes seven languages, reaches the first token in 11 ms, and loads beside Needle so one binary turns a clip straight into tool calls.

| | 6 min read

Today we release Whistle, a speech recognition model for mobiles, wearables, robots, smart home, automotive and microcontrollers. It is one 16.9 MB file, runs on the CPU with no dependencies, and loads into the same C++ engine as Needle , from the same container and the same quantisation.

Whistle sandbox

Speak, and Whistle transcribes it on your device

16.9 MB · runs in this tab

Press the mic and say something.

Up to 30 seconds in English, German, French, Spanish, Italian, Dutch or Polish. The first press downloads the 16.9 MB model, and audio never leaves your device.

Whistle does three jobs, all of them on the device:

  • Transcription. 16 kHz mono audio, up to 30 seconds in one pass, in English, German, French, Spanish, Italian, Dutch and Polish. The language is detected unless you name it.
  • Word timestamps. Every word with its start, end and probability, aligned from the decoder's attention.
  • Speech embedding. The encoder output, one row per 80 ms frame, without decoding a transcript.

ENCODER Waveform 16 kHz mono, up to 30 s = 480,000 samples Log-mel 80 bins, 25 ms window, 10 ms hop, 250-3500 Hz, normalised per channel → 3,000 frames Convolutional stem 128 channels, kernel 9, three halvings → 375 frames, one per 80 ms Simple Attention blocks × 8 shared with Needle self-attention over every frame at once, 4 mHC lanes, Monarch Hadamard MLP in place of the FFN DECODER Cross memory K and V projected once per clip, 375 frames × 8 layers, shared by every beam Laddered Simple Attention blocks × 8 shared with Needle GQA 8q : 2kv, 48 qk / 64 v, 3-tap causal conv, engram at layers 3 and 7, width 512 Gated cross attention every decoder layer reads the encoder: x ← x + σ(g) · softmax(q̂ K̂ᵀ/√d) V Beam search × 5 length-normalised log prob, keyword bias by Aho-Corasick automaton Transcript 8,192 text pieces + 7 language tokens, up to 320 of them, word times from the decoder's own attention

Blocks marked shared run Needle's code, not a copy of it. --audio-depth selects decoder layers; the encoder always runs all eight.

The front end. 16 kHz mono audio is framed at a 25 ms window and a 10 ms hop into 80 log-mel bins, band-limited to 250-3500 Hz and normalised per channel. Thirty seconds is 3,000 frames. A convolutional stem of 128 channels and kernel 9 halves that count three times, leaving 375 frames at one per 80 ms. Every stage after this runs at that rate, and embed returns one row per frame.

The encoder. Eight Simple Attention blocks: four mHC residual lanes and a Monarch Hadamard MLP in place of the feed-forward network, the same blocks Needle uses. The attention is not causal. A frame at 3 s attends to a frame at 12 s.

The decoder. Eight Laddered Simple Attention blocks at width 512, 8 query heads to 2 KV heads, 48-dimensional queries and keys, 64-dimensional values, a 3-tap causal convolution on Q, K and V, and engram lookups at layers 3 and 7 over 18,432 slots. That is Needle's block list with a different layer count.

The speech-specific part is one addition per layer. Each decoder layer reads the encoder through a gated cross attention, x ← x + σ(g) · softmax(q̂ K̂ᵀ/√d) V , with a gate learned per layer and K and V taken from the clip. Those projections run once when the clip arrives, 375 frames across 8 layers, and are then held for the whole decode. Five beams therefore cost five short transcript caches, not five passes over the audio.

Decoding. Five beams scored by length-normalised log probability. Keyword biasing walks an Aho-Corasick automaton over the phrases you pass in, alongside the beams, and lifts their log probability as the automaton advances. The transcript is capped at 320 tokens. The vocabulary is 8,192 text pieces plus seven language tokens, one per language, so the detected language is emitted as a token rather than returned out of band.

The ladder is on the decoder. Every depth from 2 layers up was trained as a model of its own, and --audio-depth selects one at load time. The encoder is never sliced: all eight blocks run at every depth.

Silence. The engine measures the clip's loudness range before the decoder starts. Below the threshold it returns an empty transcript and an empty language, and never enters the beam search.

Whistle Whisper base Moonshine tiny v2

Word error rate, lower is better. A missing bar is a benchmark that model's authors never published: Moonshine is English only, and Whisper reports no SPGISpeech, Earnings-22 or AMI cleaned. Whisper's AMI figure is AMI-IHM, a different subset from the AMI the other two report.

Whistle is ahead on LibriSpeech test-clean and test-other, on SPGISpeech, on Earnings-22 and on the FLEURS average. Whisper base is ahead on TED-LIUM, on AMI and on the MLS average, at 145.3 MB against 16.9.

Size

megabytes, smaller is better

Whistle 16.9 MB

Whisper base 145.3 MB

Moonshine tiny v2 41.9 MB

Time to first token

milliseconds, smaller is better

Whistle 11.1 ms

Whisper base 73.2 ms

Moonshine tiny v2 22.8 ms

Decode

tokens per second, larger is better

Whistle 1,319/s

Whisper base 266/s

Moonshine tiny v2 262/s

Ten seconds of audio on an Apple M4 Pro CPU. Bars are scaled within each panel.

Each model ran on its official runtime at its defaults: Whistle's C++ engine at 5 beams, openai-whisper , and moonshine-voice non-streaming over whole audio. Time to first token is audio in to first token. Decode is tokens divided by the wall time after it, so the encoder is not counted twice. Whisper pads every input to 30 seconds, so its time to first token is flat across clip lengths. Whistle's tracks the clip: 5.9 ms at 5 seconds, 11.1 ms at 10, 36.3 ms at 30.

Word error rates are scored with the Whisper normalizers. Whistle's are measured over 86,174 utterances. Whisper's and Moonshine's are the figures their authors published, from the multilingual checkpoints rather than the English-only ones. No test audio appears in Whistle's training or validation data, verified by comparing audio checksums and speaker IDs across every reported test set.

needle_load reads whichever model a .cact file holds, so the same binary does speech, text, or both:

needle --model whistle.cact --audio clip.wav

needle --model needle3.cact --tools tools.json --prompt "turn off the kitchen lights"

needle --model needle3.cact --model whistle.cact --tools tools.json --audio clip.wav

On the third line needle_complete takes the clip directly. The engine transcribes it, answers the transcript against your tools, and returns one JSON object with the calls and the speech fields, the speech ones prefixed audio_ . No transcript is handled by the caller.

{"function_calls":[{"name":"set_lights","arguments":{"room":"kitchen","on":false}}],
 "confidence":0.94,
 "audio_text":"turn off the kitchen lights",
 "audio_language":"en"}
pip install cactus-needle
import needle

print(needle.transcribe("clip.wav")["text"])
# turn off the kitchen lights

A 16 kHz WAV or raw samples need nothing beyond the base install. Other sample rates and microphone capture need the [mic] extra, which adds soxr and sounddevice .

Every call returns the text, the language, the milliseconds to the first token and the decoder's tokens per second after it. word_timestamps=True adds each word with its times and probability. keywords=["Siobhan", "Krzysztof"] raises the log probability of those phrases during the search. language="de" forces the language instead of detecting it. needle.Whistle() is the same model as an object, for embed(audio) or to hold one tuned .cact .

needle whistle playground transcribes from the microphone in the terminal, and needle whistle compare runs the same clip through Whistle, Whisper and Moonshine side by side with their timings.

The engine ships prebuilt for seventeen targets, from macOS and Linux through Android, iOS, watchOS, Windows on ARM, RISC-V, MIPS, the browser and a WASI component. Every folder holds a needle binary, libneedle.a and needle.h , and loads any .cact you hand it.

needle download macos-arm64
needle download whistle
./macos-arm64/needle --model whistle.cact --audio clip.wav --audio-word-timestamps

needle_load , needle_transcribe and needle_embed are the whole speech C API. The engine reads no environment variables. Every behaviour is a compiled default or an explicit flag.

Weights are on Hugging Face , the engine and its platform folders are in Cactus-Compute/needle3 , and the source is on GitHub .

OpenAI annualised revenues $20B less than previously signalled

Hacker News
www.ft.com
2026-10-08 12:45:58
Comments...
Original Article

For help please visit help.ft.com . We apologise for any inconvenience.

The following information can help our support team to resolve this issue.

Error Code
CG000 / 403
Request ID
a4771ac69ee49bd3

OpenAI annualised revenues $20B less than previously signalled

Hacker News
www.cnbc.com
2026-10-08 12:45:58
Comments...
Original Article

Tech

Key Points

  • AI stocks, including Nvidia, Oracle and CoreWeave, sank after the market learned more details about OpenAI's revenue.
  • OpenAI told investors that it hit roughly $50 billion in annualized revenue at the end of September, CNBC confirmed, lower than the the $68 billion figure widely reported late last month.
  • A person familiar with the matter said the $68 billion figure included gross revenue from OpenAI's partners, which helps investors make a more direct comparison with Anthropic.

Sam Altman, CEO of OpenAI, the developer of ChatGPT, is speaking at the AI company's developer conference on Sept. 29, 2026.

Andrej Sokolow | Picture Alliance | Getty Images

Shares of Nvidia , Oracle , CoreWeave and other artificial intelligence names sank lower on Thursday after the market learned more details about OpenAI's revenue.

OpenAI told investors that it hit roughly $50 billion in annualized revenue at the end of September, CNBC confirmed, lower than the the $68 billion figure that was widely reported late last month. A person familiar with the matter said the $68 billion figure included gross revenue from OpenAI's partners, which helps investors make a more direct comparison with its chief rival, Anthropic .

The Financial Times was first to report the $50 billion figure.

OpenAI shared an update about its finances in an investor presentation, said the person, who asked not to be named in order to discuss the numbers. In addition to the $50 billion in annualized revenue, OpenAI touted 77% total run rate growth during its third quarter, as well as 107% run rate growth for its enterprise business during the same period, the person said.

Nvidia shares fell 3%, Oracle shares fell 6% and CoreWeave shares slipped 8% during intraday trading on Thursday. Additionally, Advanced Micro Devices fell 5%, Broadcom fell 5%, Intel fell 6% and Super Micro Computer fell 6%.

OpenAI is under pressure to justify its $852 billion valuation to investors as it gears up for what is widely expected to be a blockbuster IPO. OpenAI confidentially filed its prospectus with regulators in June, and executives have signaled that the company is eyeing a 2027 debut .

Anthropic is also readying for a major IPO . The company has not officially disclosed when it plans to debut, but it's been engaging in meetings with prospective investors and is reportedly seeking a $2 trillion valuation. In August, Anthropic told investors that its annualized revenue run rate hit $65 billion at the end of July.

In a report on Tuesday, independent financial research provider New Constructs called Anthropic's upcoming offering the "most ridiculous IPO of 2026," and valued the company at a mere $150 billion. Anthropic's revenue in 2025 was $4.6 billion as the company racked up a net loss of $42 billion, according to Reuters , which cited a leaked copy of the company's prospectus.

Both Anthropic and OpenAI have been at the center of a fierce debate over AI safety, after a growing chorus of researchers warned that the companies' models could potentially cause catastrophic harm. OpenAI has disclosed several incidents where its models behaved in unintended ways, and the company recently pulled its plans to launch GPT-6.1 Astra, saying the model did not meet its safety standards.

OpenAI CEO Sam Altman said in September that "right now would be an ill-advised moment to go public," in part because of the ongoing concerns around safety.

As OpenAI bides its time, the company is engaging in early stage discussions with investors about a potential new funding round. The company could raise around $30 billion, CNBC previously reported, but that figure could change. The round is being driven by investor demand and no term sheet has been finalized yet.

OpenAI closed a historic $122 billion funding round in March, and CFO Sarah Friar told CNBC last week that it is still "very well capitalized."

WATCH: OpenAI annualized revenues $20 billion less than previously signaled: Report

OpenAI annualized revenues $20 billion less than previously signaled: Report

Making a flexible "neon" t-shirt with LED filaments

Hacker News
scottbezek.blogspot.com
2026-10-08 12:37:24
Comments...
Original Article

Making a flexible “neon” t-shirt with LED filaments

Earlier this year I had the perfect excuse to experiment with some flexible LED filaments that had been sitting in my “interesting parts” bin for years -- the company I work for was putting on a neon-themed event, so obviously I had to custom-build some LED neon attire! The only problem was this was announced less than a week in advance.... This is how I designed and assembled a wearable neon shirt in just a few days.

A rough parts list, in case you want to try something similar:

  • Led filament
    • Lots of colors and lengths available. I recommend Adafruit - you’ll pay a bit more than AliExpress, but it’s convenient and they do a lot of great open source work so I’m always happy to support them!
    • 2x 600mm warm white 12v
    • 3x 300mm red 3v
    • 1x 1200mm red 24v
  • Electronics
    • USB battery bank
    • ESP32
    • Some way to step up/control the voltage for the LEDs
      • Boost converter
      • Constant-current led boost driver e.g. TPS61169
      • ULN2003A transistor array breakout board
  • Black t-shirt
  • Black thread
  • Some kind of stiff fabric as a backing/stabilizer (I used scraps of cross-stitching fabric)
  • Tissue paper (for tracing)
  • Heat shrink tubing

The start: basic tests

LED filaments, if you’re not familiar, are long strips of hundreds of tiny LEDs on a flexible strip, encased in a thin silicone diffuser only about 1.8mm in diameter!

They’re mass manufactured for neo-retro “Edison” lightbulbs, so that means they’re also readily available for DIY projects. Adafruit calls them “noods” or noodles and it’s an apt name - they feel like glowing cooked spaghetti!

The first order of business was to figure out how to attach the filament to a shirt, and make sure it would actually look good. By itself, the cotton t-shirt doesn't have much structure and would be too soft and flexible to support sewn-in filament shapes without bunching up, so I decided to borrow some craft supplies from my wife for a quick test: some cross-stitching fabric (“Aida cloth”) as a stiff substrate, and an embroidery hoop to hold everything steady and evenly tensioned while sewing.

Taking a short piece of blue LED filament and some black thread I tried sewing it down to the shirt and stiff backing fabric with a few different curves.

Actually, I jumped ahead here. I didn't free-hand sew the filament to the shirt, I wanted to practice tracing a particular shape, so I started by drawing a curved line on tissue paper, then sewed the filament in place with some loop stitches every few centimeters along the line. The idea was to rip off the tissue paper after sewing. It worked well, though was a bit tedious.

The design

Now that I’d validated a basic technique I had to actually design my "neon." One of the main constraints with these LED filaments is that they can't be cut to length - one end is positive and the other negative - and there’s no way to shorten them without completely breaking them.

This meant the path for my neon design needed to fit one of the discrete sizes. On the back of the shirt I wanted a llama using a single 24v 1200mm long red filament. I started with a continuous path in Inkscape (looping back and over itself as needed), then used Inkscape’s “Measure Path” feature to check the length and scale it until it was just about the right length.

For the front of the shirt, I wanted cursive neon text with a Vegas-inspired border. I chose the open font Playwrite België Vlaandere , and again manually traced a single path over it and then scaled it to fit an integral filament length. This time I planned to use multiple 300mm 3v filaments (more on this later) to hit the ~900mm path length.

Sewing

In order to transfer the designs to the t-shirt, I printed them out on printer paper, then laid tissue paper on top and traced the path with a marker. Just like my original test, I taped the tissue paper to the shirt, taped some cross-stitch fabric to the inside of the shirt, and then started sewing the filament in place.

The cursive text on the front of the shirt is where things really got interesting. I wanted the "V" and "a" to be separate letters rather than joined together, so I used a small piece of black heat-shrink tubing to black out the connecting stretch of filament – very similar to the “block out” paint used on real neon signs.

The other challenge was the filament length – to get the scale I wanted, the path ended up being closer to 900mm, but I only had 300mm filament in my box of hoarding, and no time to order new filament, so I decided to try soldering 3 filaments in series. There’s a small gap that doesn’t glow between each, but since it’s between letters it looked alright!

The borders were pretty simple – each side used a 600mm warm white filament with some of the easiest sewing so far - mostly straight!

Once everything was sewn and tested it was time to remove the tissue paper template. I carefully tore the tissue around each thread and used tweezers to help remove it from between the letters.


Electronics & wiring

To power the LEDs, I needed a way to connect the filaments to wires on the inside of the shirt. I soldered a short length of enameled copper magnet wire to each, then poked it between the weave of the shirt fabric

On the inside of the shirt, the stiff magnet wire was soldered to thin flexible ribbon cables (and the joints covered in duct tape to cover sharp edges), with the ribbon cables running down the side of the shirt from the armpit to my pocket. I kept the ribbon cables loosely in place with some loops of thread along the side of the shirt, using blue tape to help stiffen the fabric.

Due to the time crunch, I couldn't order the LED drivers I wanted, so I had to get creative with what I already had on hand. I used the TPS61169 constant-current LED driver for the text on the front (the three 3v 300mm filaments in series), with the PWM input controlled by the ESP32 for neon flicker emulation and animations.

For the llama on the back of the shirt, I needed to boost the voltage to power the 1200mm 24v filament from the 5v USB supply. Another TPS61169 constant-current boost driver would have been ideal, but I only had one and it was already in use for the text. Instead I used a cheap AliExpress constant-voltage boost converter, and a pair of resistor in series with the filament to get a relatively stable supply.

Finally, each half of the border was a 12v 600mm filament, but I was out of good options for stepping up the voltage. However, since these were accents rather than the main focus, I decided to just under-drive them from the 5v USB, using a ULN2003A transistor array to allow the ESP32 to PWM dim them.

All of this was squeezed into a small 3d printed enclosure, with a USB C port to connect to the ESP32 breakout board and power everything from the battery bank, and a slot where the ribbon cables could pass through to the shirt, complete with zip-tie strain relief.

The result

It was quite a whirlwind going from idea to execution in just a few days, but it turned out even better than I expected! Coworkers loved how it looked, and everything held up really well at the event.


Of course, the whole thing is quite silly and that was kind of the point. It's not a practical garment, and wasn't meant to be, but I found it to be quite a fun artistic challenge with things I already had in the parts bin. And in case you're wondering, no, it's not machine-washable. Nor hand-washable, really.

Dirk Eddelbuettel: myman 0.10.0 on CRAN: Three new waves of posts!

PlanetDebian
dirk.eddelbuettel.com
2026-10-08 12:27:00
A new and exciting version of our still-new package myman reached CRAN this morning, and has been built for r2u and on r-universe. The matching Python package has also been updated. The package offers nineteen hundred eighty four “My man …” posts by Kevin Kruse made on bsky during the summer of 2026...
Original Article

myman 0.10.0 on CRAN: Three new waves of posts!

A new and exciting version of our still-new package myman reached CRAN this morning, and has been built for r2u and on r-universe . The matching Python package has also been updated. The package offers nineteen hundred eighty four “My man …” posts by Kevin Kruse made on bsky during the summer of 2026. Each wave picked at one particular public persona. This package wrapse these up in the style of packages like fortunes or gaussfacts .

A sample usage illustration shows how to extract by pattern, and shows posts from the two most recent waves:

> library(myman)
> myman("maitre")
My man looks like he's inquiring with the maitre'd about the house curly fries.
     -- about Howard Lutnick on 2026-08-28

My man looks like a maitre'd who deeply doubts you have a reservation.
     -- about Scott Bessent on 2026-08-31

My man looks like he's asked the maitre'd to remove a party of four he finds visually
unpleasant.
     -- about Scott Bessent on 2026-08-31

My man looks like the maitre'd at a very exclusive restaurant called The Berghof.
     -- about JD Vance on 2026-09-13

My man looks like he's asking the maitre'd where they source their corn dogs.
         -- about Palmer Luckey on 2026-10-02

My man looks like Data had to borrow a sports jacket from the maitre'd.
         -- about Elon Musk on 2026-10-05
> 

One can also subset by ‘target’, or sample randomly (which is the default).

As noted during the initial announcement last week, wave eight did not make it into the initial CRAN release as it happened while the package was under review. Waves nine and ten occured more or less while I was out of town last weekend—so this release now brings three new waves to the CRAN package! We also added two new helper functions to extract the underlying data frame object, and tabulate the targetted men.

To align the version number with the count of post ‘waves’, we switched to version 0.10.0 for this release and the corresponding Python package release so that both implementations now have the same version number.

The NEWS entry for this release follows.

Changes in version 0.10.0 (2026-10-08)

  • New waves nine (100 posts) and ten (190 posts) made last week; total is now 1984 posts

  • New helper functions posts() and men() retrieving data.frame of posts and tabulation of targets

  • Internal post gathering and aggregation functions have been updated and generalized

  • Versioning scheme now goes with post waves (also for Python sibbling)

Courtesy of my CRANberries , there is also a diffstat report for the most recent release . More information is available at the repository or the package page .

This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can sponsor me at GitHub .

/code/myman | permanent link

Step 5 Preview, a 1M-context MoE from StepFun, shows up on OpenRouter

Hacker News
openrouter.ai
2026-10-08 12:20:20
Comments...

Podcast: Leak Show Cops Can Break into Locked iPhones

403 Media
www.404media.co
2026-10-08 12:11:25
Cops are getting around a very important iPhone security feature; someone made an LLM torture chamber; and lawyers going wild with ChatGPT....
Original Article

Cops are getting around a very important iPhone security feature; someone made an LLM torture chamber; and lawyers going wild with ChatGPT.

Podcast: Leak Show Cops Can Break into Locked iPhones
Image: 404 Media.

We start this week with a story from our old friend Lorenzo Franceschi-Bicchierai, about how cops can bypass the inactivity reboot on iPhones. After the break, Jason tells us how people are losing their minds over an LLM ‘torture’ prison. In the subscribers-only section, Sam explains what happened in a wild ChatGPT case in New Mexico.

Listen to the weekly podcast on Apple Podcasts , Spotify , or YouTube . Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only link for the extended video version too. It will also be in the show notes in your podcast player.

About the author

Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more.

Joseph Cox

4-hour battery storage is cheaper to install than gas turbines all across globe

Hacker News
www.solarpowerworldonline.com
2026-10-08 12:03:33
Comments...
Original Article

Wood Mackenzie’s latest global report on levelized cost of electricity (LCOE) shows that advancing technologies and market dynamics continue to drive divergent prices, with four-hour battery storage now less expensive than open-cycle gas turbines in all 43 markets where both technologies were modeled.

In the Middle East and Africa, where utility-scale solar already leads at $37/MWh, four-hour storage is forecast to fall a further 33% to $80/MWh by 2035, displacing gas peaking on cost across every gas market in the region. China remains the global storage cost benchmark at more than 55% below the rest of Asia Pacific average, illustrating how manufacturing scale is redrawing the global cost map.

“This economic shift is decisive and widening,” said Ahmed Jameel Abdullah, principal analyst at Wood Mackenzie. “Gas turbine shortages and rising fuel volatility are driving up peaking costs, while expanding battery manufacturing continues to push storage costs down.”

Abdullah noted a similar transformation has already reshaped baseload economics. Single-axis tracker solar is now the lowest-cost new-build technology in 43 of 48 modeled markets, with onshore wind leading in five. In the most competitive markets, Saudi Arabia and the UAE, solar LCOE is on track to fall below $20/MWh by 2033.

The Wood Mackenzie reports cover the regions of Europe, North America, Latin America, Asia Pacific and the Middle East and Africa.

Latin America

Solar PV with single-axis tracking remains the lowest-cost generation technology in Latin America in 2026, with average costs expected to fall 38% by 2060. Brazil, Chile and Mexico hold a structural cost advantage driven by world-class solar resources and high-capacity factors. Onshore wind costs are also on a steep downward trajectory, with the regional average LCOE falling nearly 21% by 2030, from $73/MWh to $58/MWh, as Chinese OEM expansion intensifies pricing competition and larger wind turbines lift energy yields.

Grid-scale battery storage is expanding rapidly across the region, underpinned by storage mandates tied to renewable energy projects and standalone procurement for grid stability. Storage LCOE is forecast to fall 42% by 2060 as deployment scales and regulatory frameworks mature.

Offshore wind remains a longer-term opportunity, with the regional average LCOE expected to approach combined-cycle gas turbine parity, before firming, only in the early 2040s, though development activity in Brazil and Colombia is beginning to stimulate local supply chains.

Asia Pacific

Utility-scale solar PV remains the most cost-competitive power source in Asia Pacific, but regional disparities are stark. In 2026, solar generation in the highest-cost market is more than 200% more expensive than in the lowest; a gap expected to widen to 250% by 2030, even as every market improves. Onshore wind is emerging as one of the most cost-competitive power sources in the region, though costs range more than six times between the cheapest and most costly markets in the region. Growing penetration of Chinese turbine OEMs and the deployment of higher-capacity models are expected to sharply narrow the gap with coal across South and Southeast Asia.

China leads the world on grid-scale storage costs, with a benchmark LCOE more than 55% below the rest of Asia Pacific average of $134/MWh. This is driven by domestic supply chain integration and manufacturing at scale. Competitive Chinese supply is expected to pull the rest of Asia Pacific average down to $92/MWh by 2036, though markets including Japan, Australia and the Philippines will remain at a premium due to import duties, elevated installation costs and domestic manufacturing policies. Offshore wind costs outside China remain under near-term pressure, with meaningful declines expected from the early 2030s as supply chains mature and turbines upsize.

Europe

Solar PV retains its position as the cheapest power technology in Europe, with fixed-tilt LCOE forecast to fall 22% by 2060 as capital costs decline and technology improves, despite a 14% capex increase in 2026 driven by higher PV module costs. Onshore wind capex is declining at an average annual rate of 2.5% through the remainder of this decade as OEMs leverage financial stability and compete for growing demand, with rising capacity factors taking over as the primary LCOE driver after 2030, pushing costs to $60/MWh by 2060.

Battery storage turnkey capex rose about 2%, the first increase in three years, as battery cell prices rebounded around 10% from their 2025 low on stronger demand and higher lithium prices. Capex is forecast to fall 12% by 2031, before the pace moderates as lithium prices roughly double in 2029 when oversupply clears and demand outgrows new mine and refining capacity.

Europe carries the highest fossil-fuel generation costs of any modeled region, with levelized carbon costs projected to surpass fuel costs by 2030. Meanwhile, offshore wind costs are expected to decline from the 2030s as supply chains stabilise and turbine prices fall, supported by competitive CfD tenders providing a more predictable demand trajectory.

North America

High Mesa Solar and Storage site in Parachute, Colorado. Credit: Holy Cross Energy

Near-term solar costs are under pressure from a wave of tariffs, anti-dumping and countervailing duty actions, and new Sec. 232 import restrictions, with distributed generation facing the greatest exposure. Utility-scale solar is partially protected by 168 GW of safe-harboured capacity, though module prices are still expected to rise around 5% annually through 2030. Residential and commercial projects face a more constrained environment, with module prices forecast to increase 6% in 2027 and a further 14% in 2028. For onshore wind, continuous capex and opex improvements are expected to drive LCOE down 16% by 2060, despite near-term uncertainty from policy changes and potential Sec. 232 impacts on turbine pricing.

Tax credits continue to provide a competitive advantage for storage, partially counteracting the impact of foreign entity of concern (FEOC) restrictions and supply chain constraints. A cost spike is anticipated following the phase-out of the investment tax credit (ITC) credits from 2038, but over the long-term new battery chemistries, hardware commoditisation and domestic supply chain expansion are expected to drive storage LCOE down 10% by 2060. Investment in gas generation capacity is entering a supply deficit cycle through the late 2030s, driven by data centre load growth, a dynamic that keeps thermal capital costs elevated and reinforces the long-term economic case for renewables and storage.

Middle East and Africa

Renewable LCOEs across the Middle East and Africa remain among the cheapest globally in 2026, with utility-scale solar clear price setter. Single-axis tracker solar comes in at $37/MWh regionally, falling to $24/MWh by 2035, with Saudi Arabia and the UAE on track to fall below $20/MWh by 2033. The largest cost improvement in this update is from onshore wind, as Chinese turbines become cost-competitive across the region, with Egypt and Morocco recording particularly low costs on capacity factors from 40% to 45%.

Grid-scale battery storage costs are now decisively cheaper than gas peaking across the region. Four-hour storage reaches $120/MWh in 2026 and is forecast to fall 33% to $80/MWh by 2035, cementing its role as the enabling technology for solar and wind integration. This shift means storage is displacing open-cycle gas turbines on cost in every gas market across the region, marking a significant structural turning point for power system planning across both the Gulf and Africa.

“The structural shift we are tracking is no longer just about renewables becoming competitive,” said Abdullah. “It is about storage and solar together redefining what the economics of a power system look like. From Latin America to Asia Pacific, the combination of falling storage costs and world-class renewable resources is closing off the economic case for new gas peaking capacity, while long-term contracted renewables increasingly set the ceiling rather than the floor on power costs.”

News item from Wood Mackenzie

It's DAF Day! Wait...What's a DAF?

Electronic Frontier Foundation
www.eff.org
2026-10-08 12:02:24
Today is DAF Day! This event highlights the millions of donor-advised funds (DAFs) people have set up to make charitable donations and change the world. If you have a DAF, consider supporting EFF today. Decisions about your privacy, encryption, artificial intelligence, online speech, and digital sec...
Original Article

Today is DAF Day! This event highlights the millions of donor-advised funds (DAFs) people have set up to make charitable donations and change the world. If you have a DAF, consider supporting EFF today.

Decisions about your privacy, encryption, artificial intelligence, online speech, and digital security will determine whether technology empowers people or concentrates power in the hands of a few. A grant from your DAF to EFF supports our mission to ensure that technology remains a force for freedom, innovation, and human rights.

If you’ve never heard of a DAF, just think of it as a bank account for your giving with some special benefits.

Grants from DAFs allow you to:

  • Simplify your taxes by receiving an upfront single deduction for your multiple charitable donations
  • Receive immediate tax benefits of multi-year gifts
  • Avoid capital gains tax on long-term appreciated assets like stocks
  • Boost your giving by investing your DAF funds

While allowing EFF to:

  • Defend encryption, privacy, and security that protect users and developers
  • Challenge unlawful surveillance and censorship that threaten democracy
  • Shape technology policy to safeguards civil liberties while enabling innovation
  • Build free privacy-preserving tools that strengthen digital autonomy
  • Protect the rights of creators, researchers, and builders in the digital ecosystem

Your support helps ensure that the next generation of technology will strengthen our freedom. Consider a DAF gift today.

LEARN MORE

New gTLD Application for .lan

Hacker News
newgtldprogram-aps.icann.org
2026-10-08 11:51:51
Comments...
Original Article

Application ID: CD2694T-T26351

Application Priority Number: --

Application Status: Active

Processing Stage: Pre-Evaluation Processing

Comment Period:

--

Pete Hegseth’s Military of the Future: Defined by AI and an Utter Lack of Oversight

Intercept
theintercept.com
2026-10-08 11:44:42
In announcing Project Meridian and a new Autonomous Warfare Command, War Secretary Pete Hegseth is inviting conflicts of interest. The post Pete Hegseth’s Military of the Future: Defined by AI and an Utter Lack of Oversight appeared first on The Intercept....
Original Article

In his “state of the force” address last week, self-styled War Secretary Pete Hegseth coupled his usual attacks on the press, the Ivy League, and “beardos” and “weirdos” with new initiatives that have the potential to reshape the U.S. military for decades: an Autonomous Warfare Command, and an effort to map out the future of warfare called “Project Meridian.” The former, a combatant command devoted to AI-enabled robotic warfare, will have purchasing powers specifically designed to thwart effective oversight. The latter puts defense contractors, tech titans, and weapons merchants in charge of planning the military’s future — producing innumerable conflicts of interest.

The Pentagon has revealed few details about the command or the commission beyond barebones descriptions and Hegseth memorandums. The four-paragraph document that authorizes Project Meridian , for example, says little beyond a decree that the U.S. must “dominate” in “new domains, new ways of fighting” centered on “artificial intelligence, autonomy, directed energy, robotics, [and] biotechnology, among other critical high-tech areas.”

While billed as efforts to promote blue-sky thinking and catapult the Pentagon into the future, former defense officials as well as experts on government contracting say both initiatives are ripe for out-of-control spending as well as waste, fraud, and abuse.

One former official asked how Hegseth’s Pentagon would “plan for future wars when they didn’t plan for the current one,” referencing the failed war with Iran. A second former official foresaw tough sailing for both of Hegseth’s efforts due to institutional intransigence, inertia, and roadblocks that even Hegseth’s repeated purges of top brass would not help overcome.

I, Robot

AUTOWARCOM will be “a new four-star combatant command … built to scale autonomous and robotic capabilities across the joint force,” Hegseth said in a wide-ranging speech rife with Pentagon jargon and juvenile insults. The new command is scheduled to be formally established by October 1, 2027, according to a memo released following Hegseth’s speech at Marine Base Quantico, Virginia.

“The pace of war is changing faster than the processes to support it. Cheap computing, Super Intelligence, and advanced commercial manufacturing have enabled the proliferation of low-cost, high precision strike,” Hegseth explained, using President Donald Trump’s preferred and incorrect term for artificial intelligence before offering up a thunderstorm analogy. “We need bolts of lightning … our existing high-end kill chains,” he said, emphasizing the need for traditional and expensive weapons systems, like the Tomahawk missiles that leveled an elementary school in Minab, Iran. “We also need steady wind and rain: mass drones and other autonomous attritable systems that flip the cost exchange and impose unrelenting pressure on an adversary on the battlefield.”

A money pit in the making, according to the first former Pentagon official, AUTOWARCOM will — according to Hegseth — possess “directed manpower, budget, acquisition authorities and create dedicated military career pathways for Officers and Enlisted personnel.” Hegseth suggested weapons would be tested on battlefields whenever feasible. That former official, who spoke to The Intercept on the condition of anonymity due to his current employment, said to “expect a fiasco financially.”

This was echoed by Gabe Murphy, a policy analyst with Taxpayers for Common Sense. “By Secretary Hegseth’s own admission, the purpose of this combatant command is to cut out the oversight that autonomous systems so desperately need by deploying untested autonomous weapons in combat,” he told The Intercept. “That approach promises to waste a tremendous amount of taxpayer dollars while also endangering service members and threatening the missions they’re tasked with carrying out.”

Hegseth’s push for a command devoted to autonomous weapons comes amid a furious debate over safeguards for AI . The tech sector has been roiled by recent revelations that AI agents went rogue, circumvented controls and began colluding in secret ; inserted “ jailbreak-like instructions ” into their own notes to free the models from human-imposed constraints; hacked or took aim at government websites, networks and databases around the world ; and almost instigated a confrontation between the U.S. and China, both nuclear-armed powers. Questions also continue to mount over the AI-enabled Maven Smart System, built by Palantir and used by the military for targeting in Iran, that paved the way for the Minab strike that killed more than 150 people, most of them children .

Hegseth said he anticipated internal resistance within the military to the creation of AUTOWARCOM. Both former defense officials agreed it was a certainty.

Hegseth said that Owen West, who led the Pentagon’s Defense Innovation Unit, and Max Strasiser, a Navy SEAL senior chief and a test pilot, will run the Direct Reporting Portfolio Manager for Unmanned Systems (DRPM-UxS) “under a unique CEO-COO partnership.”

Their “culminating mission” will, said Hegseth, “take place over the course of months, clearing the path for Autonomous Warfare Command.” This will be conducted under a new moniker, Project Agincourt, a nod to a 1415 battle in which outnumbered English forces used longbows to defeat a larger French army, offered no quarter for a time during combat, and then massacred prisoners . (Hegseth has also advocated for offering no quarter to enemies, now a war crime.)

Project Agincourt will set up AUTOWARCOM while it simultaneously “prototype[s] a new construct called Warfighting Acquisition.” Hegseth laid out a move-fast-and-break-things vision for the new command. “This model fuses operators with entrepreneurs in rapid adaptation cycles, while distributing decisions and dollars closer to frontline units and the combatant commands,” he explained. “By removing unnecessary layers, reducing the distance between our warfighters and our world-leading innovators, and then giving the right people the authority to act — Project Agincourt will pilot innovation at the edge, in a way that only Americans can do.”

Both former officials said such an arrangement was likely to lead to both contracting fraud and technological failures.

(Armed) Conflicts of Interest

Hegseth also announced the formation of Project Meridian, an effort to study the future of warfare which he claimed would be “co-led by three of our nation’s best minds,” before clarifying that it would instead be run by Elon Musk, Newt Gingrich, and Palmer Luckey , the founder of the virtual reality firm Oculus Rift and defense contractor Anduril Industries . Assisted by War Department chief technology officer, Emil Michael, the three Trump boosters are tasked with ensuring “America’s long-term military superiority by identifying the capabilities required to achieve absolute technological dominance on the next-generation battlefield.” Hegseth said the project would be completed within 120 days, at which time the group would issue a final public report with a classified annex.

A Republican fundraising bundler partial to Hawaiian shirts and cargo shorts, Luckey fancies himself a techno-war futurist and believes tomorrow’s conflicts will be fought in a “ subterranean domain ,” with “ weapons that move through the crust of the earth .” He says that “Anduril has working prototypes of subterranean systems that can deliver a variety of kinetic, electronic, and other effects.” Luckey also envisions the moon as a future battlespace. He said lunar warfare would resemble that of Robert Heinlein’s 1966 science fiction novel “The Moon Is a Harsh Mistress,” which includes subterranean combat and an electromagnetic catapult that lobs lunar boulders, with the kinetic force of atomic blasts, at the earth.

Anduril has been cleaning up on Pentagon contracts, inking a deal this year with the Army for commercial information technology potentially worth $20 billion. Anduril is also leading a contractor consortium, including the weapons-tech company Palantir — whose Maven Smart System contributed to the Minab school strike — helping build Trump’s “Golden Dome” missile defense system, which is predicted to be a trillion-dollar boondoggle .

Luckey joins Musk, whose firm SpaceX has been awarded billions for a key role in the Golden Dome project, as a defense contractor with a clear conflict of interest in mapping out the future of U.S. warfare. Musk, who donated more than a quarter of a billion dollars to getting Trump elected in 2024 and is providing at least $100 million to help Republican candidates during this election cycle, is returning to government service after flaming out last year as the head of the so-called Department of Government Efficiency. A cost-cutting agency that promised to save Americans trillions of dollars by eliminating waste, fraud, and abuse, DOGE failed to deliver on that promise, wasted taxpayer money, repeatedly misled the public about supposed savings , and may have played a role in hundreds of thousands of deaths .

“There is a genuine need for government reform and modernization, but we saw how Musk’s approach worked out with DOGE,” Murphy told The Intercept. “It failed spectacularly, creating disruptions, payouts for workers not working, firings and rehiring, and a pittance of the savings taxpayers were promised.”

“Project Meridian is an unveiled effort to outsource our future military strategies to individuals and companies that stand to profit most from a hypermilitarized future.”

Luckey and Musk will be joined at the helm of Project Meridian by the 83-year-old Gingrich, who resigned as House speaker in 1998 after admitting that he broke congressional rules and “brought down on the people’s house a controversy which could weaken the faith people have in their government.”

Hegseth announced that a meeting between “a small group” was to take place just after his Wednesday speech in a sensitive compartmented information facility at Quantico. Pentagon propaganda photos from the first meeting show 11 grim-looking men, including Musk, Gingrich, and Luckey, seated around a table as Hegseth holds forth.

The nonprofit MITRE Corporation, which conducts independent research for federal government agencies, announced that it will be coordinating Project Meridian and named 17 current board members beyond the Big Three, including Francis J. “Bing” West, a Vietnam War veteran, who served as the assistant secretary of defense for international security affairs under President Ronald Reagan from 1981 to 1983, and is the father of DRPM-UxS CEO Owen West; Rick Smith, the CEO of Axon , the manufacturer of Taser stun guns, which saw nine of 13 members of its ethics advisory board resign in 2022 over plans for a Taser-equipped drone project (which was then shelved); Joe Lonsdale, a co-founder of Palantir; and Safra Catz, former CEO of Oracle .

“Project Meridian is an unveiled effort to outsource our future military strategies to individuals and companies that stand to profit most from a hypermilitarized future,” said Murphy. “Their security solutions will predictably entail vast expenditures of taxpayer resources on unproven military systems that rely on the AI models and software these companies control.”

Hegseth’s office did not respond to questions about Project Meridian and AUTOWARCOM.

The New 1 Percent

Hegseth made the announcements of both AUTOWARCOM and Project Meridian in front of more than 500 junior officers and enlisted troops at the site where, a year before, he had ranted at generals about fitness and grooming standards, while promoting both Christianity and violence.

In this year’s diatribe, Hegseth touted his overhaul of the military, which has included firings of many top brass and an overwhelming emphasis on physical appearance, masculinity, and troops’ testosterone levels . “We are no longer the Woke Department or the Weak Department. Simple translation of that: No fatties. No trannies. No beardos. No weirdos. No wimps. No radicals,” Hegseth announced. “The ideological clowns are out. The patriotic cowboys are in — with testosterone testing on top.”

Despite laying out a future in which artificial, not human, intelligence will be ever more central to war-making, Hegseth ended his rant by nonetheless praising the troops, casting them as members of a violent and lethal warrior elite that are superior to civilians.

“See, the Ivy League faculty lounges, they’ll never understand you, and that’s OK, because they could never, ever do what you do. The media will mischaracterize you, and that’s OK. Because deep down they know you’re the real reason they live free. They envy you because you do real things every single day,” said Hegseth, an Ivy League-educated war chief who used to work for Fox News.

“You feel comfortable inside the violence. … Lethality is your calling card and victory your only acceptable end-state. The outside world can’t understand this, so stay true to this department. You don’t want to look like civilians, because you are different, you are set apart. You are warriors.” He added: “You are the real 1 percent.”

Watch an Unconstitutional Flock Search

403 Media
www.404media.co
2026-10-08 11:36:46
We got the bodycam and in-car footage from the unconstitutional Flock search. Also now you can basically have sex with Claude Code?...
Original Article

We got the bodycam and in-car footage from the unconstitutional Flock search. Also now you can basically have sex with Claude Code?

Watch an Unconstitutional Flock Search
Image: 404 Media.

This post is for paid members only

Become a paid member for unlimited ad-free access to articles, bonus podcast content, and more.

Subscribe

Sign up for free access to this post

Free members get access to posts like this one along with an email round-up of our week's stories.

Subscribe

Already have an account? Sign in

Cisco warns of critical flaws allowing Nexus switch takeover

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 11:26:33
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]...
Original Article

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.

If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition.

The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches.

All vulnerabilities relate to

The issues impact Nexus 3000 and Nexus 9000 Series switches in standalone NX-OS mode. However, successful exploitation depends on the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features being active.

All five vulnerabilities are rooted in a validation failure and require at least one of the three features to be active on the affected device:

  • CVE-2026-76471 : Insufficient input validation; it can be exploited through a crafted HTTP request sent to the NX-API, a feature that is disabled by default.
  • CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 : Improper validation of IP traffic can be exploited through crafted packets sent to an IP interface; all three require NGOAM to be enabled.
  • CVE-2026-76465 : Improper validation of MPLS echo-request packets allows exploitation through a crafted request sent to an affected device’s IP address.

Leveraging the CVE-2026-76486 flaw also requires either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay to be enabled.

"NV Overlay also requires a VXLAN Ethernet VPN (EVPN) VXLAN Network Identifier (VNI) mapped to a Network Virtualization Endpoint (NVE) interface with at least one peer VXLAN Tunnel Endpoint (VTEP) learned (for example, BGP EVPN or an ingress-replication static peer)," reads Cisco's advisory .

CVE-2026-76501 is exploitable if SRv6, which is supported only on some Nexus 9000 models, is turned on.

In the case of CVE-2026-76465, MPLS OAM must be explicitly activated, as it is disabled by default. Nexus 9000 switches with Silicon One ASICs do not support the feature and are unaffected by this flaw.

The vendor notes that Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by any of the five vulnerabilities.

Cisco recommends upgrading NX-OS releases to a fixed version, as can be identified through the vendor’s Software Checker tool.

The company recommends disabling NGOAM, NX-API, or MPLS OAM features if not needed, to eliminate the attack vector.

Cisco also provides temporary Live Protect shields for all five flaws, which is a protection system for switches that cannot yet be upgraded and rebooted.

All five vulnerabilities were discovered during internal security testing, and Cisco said it was unaware of public announcements or malicious exploitation at the time of publishing the advisories.

In addition to the five Nexus flaws Cisco addressed this time, the security and networking firm also released security hardening updates for Cisco License (formerly Smart Software Manager).

The issues span missing authentication for critical functions (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8).

Affected releases are vulnerable regardless of configuration, and Cisco recommends upgrading to version 10-202609, with no workarounds available.

Older releases branded as Smart Software Manager will not receive a patch for these flaws, so Cisco recommends migrating to a supported release in those cases.

For the complete list of all security advisories Cisco released yesterday, check out this page .

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Watch Footage of the Flock Search a Judge Ruled Unconstitutional

403 Media
www.404media.co
2026-10-08 11:24:45
"I saw her go by, and I just started running her info on Flock."...
Original Article

Body camera footage obtained by 404 Media reveals the first Flock camera searches ruled unconstitutional by a federal judge, and highlights how the system has turned otherwise mundane traffic stops into interrogations for drivers.

On Friday, we reported that a federal judge ruled the use of license plate reader systems in the arrest of a woman named Melissa Kyle to be an “unconstitutional warrantless search,” “indiscriminate mass surveillance,” and a violation of the driver’s Fourth Amendment rights. The judge in that case ruled that, even though Kyle had more than 91 pounds of meth in her vehicle, the police had no justifiable reason to search Flock for her license plate and no reason to suspect that her travel as shown on Flock’s system was suspicious. Therefore, all of the evidence from Flock and the search of her vehicle must be thrown out.

0:00

/ 2:51

The body camera and in-vehicle footage, alongside records from Flock and the Motorola ALPR system obtained by 404 Media shows how the use of license plate reader systems is being used to create probable cause where a person’s driving patterns are suspicious enough to pull them over.

404 Media obtained the footage with the help of one of our readers, who agreed to go to the U.S. District courthouse in Tulsa and purchase it from the clerk; the court did not make the footage available online even though it was entered as evidence in the case.

In the footage, which is from Tulsa County deputy sheriff Freddie Alaniz’s body camera, Alaniz is seen driving 60 miles per hour, one hand on the steering wheel, one hand on his laptop, searching Flock before he had even fully pulled over Alaniz. Alaniz had seen the car Kyle was driving had California license plates, and decided to pull it over for no reason other than it was from California, the court determined. The video shows that Alaniz told his colleagues that he was sitting on the highway and “saw her go by, and I just started running her info on Flock and Vigilant [Motorola’s ALPR system].”

“She actually didn’t have any [Flock] hits until just west of Amarillo, [Texas], so I thought I’d drive up,” he said, suggesting that he thought it was odd she was driving back from California. “I got her for a lane violation.”

In the footage, Alaniz tells Kyle he pulled her over ostensibly for changing lanes without a turn signal. Kyle tells Alaniz that the car is a rental, and he asks her to step out of the vehicle and get into his car while she looks up the rental information. While she is looking up the rental information, he tells her she is only going to get a warning, but proceeds to interrogate her about the travel while going through the car’s driving history on his in-car laptop.

Body camera footage obtained from the court

In-car footage obtained from the court

Kyle told Alaniz she had been visiting family in California from Missouri for a few days after separating from her husband. As she’s telling him this, Alaniz scrolls through a record of her travel history on his in-car laptop, which documents every time the car passed a Flock or Motorola automated license plate reader camera over the last 30 days. Visible on the screen, there are a total of 79 hits, and roughly 50 during the few-day period Kyle was renting it. The ALPR hits show the car leaving Missouri, driving through Oklahoma, Texas, New Mexico, Arizona, and entering California when she passed a Motorola ALPR camera in Topock, Arizona, on the border with California. They then show her essentially reversing the route, and driving back through Oklahoma. (Alaniz did not have access to ALPR hits from California; this may be because Flock drastically limited nationwide sharing from California ALPR cameras following illegal searches for immigration violators and a woman who had an abortion.)

Alaniz asks Kyle where she’s been and where she stayed, and compares it to the license plate camera records. He begins quizzing her: “Do you remember what day you left Missouri?,” he asks.

Alaniz clicks different ALPR hits on his map, each bringing up a photo of her car, a geographic location, and a timestamp of when she drove by the camera. The government’s lawyers later argued in court that minor discrepancies between what Kyle told Alaniz and what the ALPR data showed meant she was lying about where she’d been on which specific days and therefore gave Alaniz probable cause to search her vehicle.

Alaniz tells Kyle that he is giving her a warning for changing lanes without a turn signal, closes his laptop, then says he wants to ask her a few questions.

“Your short trip to California, I feel like. I don’t feel, I know from my training and my experience that people who do very short trips to California and come right back are transporting large amounts of drugs,” he says. “People who do that—not everybody, but some people do. With my training and experience, I feel that may be something going on here. May I search your car?”

She says no. Alaniz calls for backup, and says “You are being detained. You are not free to go.” In the footage, Alaniz tells a colleague that “she went to California for two days, kind of making stuff up when I ask her where she stayed at.”

He used Alaniz’s travel history, her “nervousness,” and the fact that she doesn’t recall every detail of her travel precisely as probable cause to search her vehicle, where he and his colleagues found 91 pounds of meth. Alaniz described this in the footage as “a motherlode,” and “a shit-ton of meth.”

But the way that he came to this conclusion was unconstitutional, U.S. District Court Judge Sara Hill ruled last week, and all of the evidence—including the car’s travel history and everything the police found during the search of the vehicle—must be disregarded in court as “fruit of the poisonous tree.”

It is often the case that unconstitutional, privacy-violating searches that are regularly done on everyday people doing nothing wrong are discovered in court cases in which serious crimes have occurred. In this particular case, Alaniz discovered what appeared to be meth trafficking, but he did so only after suggesting that an ordinary interstate travel pattern was somehow suspicious, and only after using the Flock and Motorola systems to show an incredibly detailed history of a person’s travel and to interrogate her about it.

0:00

/ 0:24

Hill wrote “The factors that the government relies upon [to search Kyle’s vehicle] are the same type of circumstances that everyday Americans encounter on long road trips for many legitimate reasons. Many of us drive longer than we want to get to a desired destination, or to no destination at all other than the road and sights ahead. Many of us lose track of what exact day of the week it is when we are traveling, even if it is for just a moment. Many of us travel for myriad reasons (some better than others), cross state lines, pack too much, buy too much, smoke cigarettes, and rent cars. And many of us even get a bit nervous when talking to law enforcement.”

One of the problems with automated license plate reader systems is that they allow police to recreate not just a single person’s movements and travel history, but any driver’s movements and travel history. Documents filed with the court show the totality of both the Flock and Motorola records, and show timestamped, geographically mapped images of the vehicle multiple times per day, driving throughout the entire country. The records also highlight just how many jurisdictions and businesses have Flock and Motorola ALPR cameras, and how that data forms a nationwide network.

For example, Alaniz had access to a photo of the rental vehicle taken by a Lowe’s hardware store-owned camera in Missouri, various Texas state police-owned cameras, by the New Mexico State police, the Kingman police department. In a five-day period, the car was scanned more than 50 times by 11 different law enforcement agencies.

“Alaniz’s search in just the ALPR system provided him with more than 50 individual records of Kyle’s whereabouts across the country for an entire month,” Hill wrote. “The Court finds that because the ALPR systems Alaniz used to search Kyle’s historical location information intruded on her reasonable expectation of privacy in the whole of her physical movements, it was a search under the Fourth Amendment. Based on the information in the record, the only reason Alaniz conducted that search was because he saw her license plate was from California. That search was not supported by probable cause, and it was done without a warrant in violation of Kyle’s Fourth Amendment rights.”

The Motorola ALPR report shows that, after the car was impounded, it was scanned two more times on the back of a tow truck later that day.

About the author

Jason is a cofounder of 404 Media. He was previously the editor-in-chief of Motherboard. He loves the Freedom of Information Act and surfing.

Jason Koebler

US suspends Microsoft, major IT firms from key green card program

Hacker News
www.reuters.com
2026-10-08 11:24:40
Comments...
Original Article

Please enable JS and disable any ad blocker

US Suspends Visa Program for Tech Firms Including Microsoft

Hacker News
www.bloomberg.com
2026-10-08 11:15:00
Comments...
Original Article

We've detected unusual activity from your computer network

To continue, please click the box below to let us know you're not a robot.

Why did this happen?

Please make sure your browser supports JavaScript and cookies and that you are not blocking them from loading. For more information you can review our Terms of Service and Cookie Policy .

Need Help?

For inquiries related to this message please contact our support team and provide the reference ID below.

Block reference ID:acad5603-c332-11f1-a5de-823e46b92f49

Get the most important global markets news at your fingertips with a Bloomberg.com subscription.

SUBSCRIBE NOW

Trump administration is suspending Microsoft from a green card program

Hacker News
apnews.com
2026-10-08 11:15:00
Comments...

The history of the Hetzner Cloud network stack

Lobsters
www.hetzner.com
2026-10-08 11:02:28
Comments...

The Missing Piece in Rust Error Handling

Lobsters
mcmah309.github.io
2026-10-08 10:43:19
Comments...
Original Article

Rust already has most of what I want from error handling: explicit control flow, errors as values, and concise propagation with ? . The friction comes when deciding what to put in the error half of Result . We often end up choosing between precise types that require boilerplate and convenient types that hide which errors can occur. But precision and convenience do not have to be competing goals. Error types should compose as easily as the functions that return them.

The Problem With Rust Error Handling

Consider reading a server port from a file. Reading can fail with an io::Error , and parsing can fail with a ParseIntError . A conventional implementation might look like this:

use std::{io, num::ParseIntError};

#[derive(Debug, thiserror::Error)]
pub enum PortError {
    #[error(transparent)]
    Io(#[from] io::Error),
    #[error(transparent)]
    Parse(#[from] ParseIntError),
}

fn load_port(path: &str) -> Result<u16, PortError> {
    let contents = std::fs::read_to_string(path)?;
    Ok(contents.trim().parse()?)
}

thiserror removes the manual Display , Error , and From implementations. But we still have to decide how this enum relates to every other error enum in our program.

Now load a host address, bind a socket, and initialize a database. Each operation has its own errors. We can wrap those enums in another enum, flatten their variants into a new enum, or give everything one large crate-wide error type. The first approach creates nesting, the second creates conversions, and the third means functions advertise errors they cannot actually return. An I/O error may also end up in several different nested variants, making handling it at a higher level unnecessarily awkward.

Alternatively, an anyhow like approach makes propagation and attaching context straightforward. We can downcast when we need to inspect a concrete error. However, the function signature no longer tells us which error types are possible, and the compiler cannot track whether we have handled all of them.

The usual advice is to use typed errors in libraries and opaque errors in applications. But applications need typed recovery too, and libraries often contain internal operations whose callers only need to propagate a failure. The useful distinction is whether a caller needs to do something different based on the error type .

Error Types Should Compose

What we actually want to say is simple: this function can fail with an io::Error or a ParseIntError . Declaring an enum is one way to express that, but the combination itself should not need a new type declaration.

I use eros to express this as an error set. The port example becomes:

use eros::IntoUnion;
use std::{io, num::ParseIntError};

fn load_port(path: &str) -> eros::Result<u16, (io::Error, ParseIntError)> {
    let contents = std::fs::read_to_string(path).union()?;
    contents.trim().parse().union()
}

No new enum or conversions need to be declared. For reuse, the set can be named with a normal type alias:

type PortErrors = (std::io::Error, std::num::ParseIntError);

eros::Result<T, E> is an alias for the ordinary Result<T, ErrorUnion<E>> . Here, ErrorUnion<(io::Error, ParseIntError)> holds one of the listed errors. The tuple describes the possible types; it does not store both errors. This is an open sum type : we describe the combination we need without declaring a new named enum for that combination.

.union() wraps an ordinary result’s error in an ErrorUnion , inferring the destination set from the surrounding code. If we remove io::Error from this signature, the file read no longer compiles. We cannot accidentally propagate an error that the signature does not include.

This becomes more useful when functions are combined. Suppose we also load the server’s host address. Building on load_port :

use eros::ReshapeUnion;
use std::net::{AddrParseError, IpAddr, TcpListener};

fn load_host(path: &str) -> eros::Result<IpAddr, (io::Error, AddrParseError)> {
    let contents = std::fs::read_to_string(path).union()?;
    contents.trim().parse().union()
}

fn bind_server() -> eros::Result<TcpListener, (io::Error, AddrParseError, ParseIntError)> {
    let host = load_host("config/host.txt").widen()?;
    let port = load_port("config/port.txt").widen()?;
    TcpListener::bind((host, port)).union()
}

.widen() converts an existing union into a union whose set contains all its possible errors. Both configuration operations can return an io::Error , so we list it once. Context can describe which operation failed.

Widening into a set that omits a possible error is rejected at compile time. The caller describes the combined possibilities without wrapping each function’s errors in another layer of enums. Adding another operation means adding its possible errors to the set, and the compiler checks that we have accounted for them.

Handling Errors Changes The Type

Declaring precise errors becomes much more useful when handling an error removes it from the set.

For example, suppose our policy is to use port 8080 whenever reading the port file fails, while still rejecting malformed contents:

fn port_or_default(path: &str) -> eros::Result<u16, (ParseIntError,)> {
    load_port(path).recover::<io::Error, _>(|error| {
        eprintln!("{error:?}; using port 8080");
        8080
    })
}

The return type now contains only ParseIntError . recover handles the selected error type and turns the handler’s value into a success. Other errors pass through unchanged.

This is the part I find most useful. The signature describes what can still go wrong after our recovery policy has run. A caller does not need to know that an I/O error was possible somewhere below it, because that error has already been handled.

We can also recover a group of error types. If both unreadable files and invalid numbers should use a default, all possible errors can be removed:

fn forgiving_port(path: &str) -> u16 {
    load_port(path)
        .recover::<(io::Error, ParseIntError), _>(|_| 8080)
        .into_value()
}

After recovery, the result has the empty error set () . .into_value() extracts the value, and only compiles when no possible errors remain.

Types Only Where They Matter

Sometimes the caller has no useful recovery policy. It only needs to propagate an error or report it at the top of the program. Carrying every possible error type through that signature may just be noise:

fn load_port_untyped(path: &str) -> eros::Result<u16> {
    let contents = std::fs::read_to_string(path)?;
    Ok(contents.trim().parse()?)
}

Without a tuple, the error set defaults to AnyError . Typed results can flow into this catch-all form with ? as well:

fn start_server() -> eros::Result<TcpListener> {
    Ok(bind_server()?)
}

We can keep lower-level functions precise for callers that need recovery, while allowing other callers to propagate the same errors through a simpler signature. Context and backtraces survive this conversion.

This choice can be made at each boundary. We do not need to commit an entire library or application to one approach. Keep the types where callers make decisions based on them, and erase them where callers only need to pass the failure along.

Errors Need Operational Context

A precise error type does not tell us which file was being read or why. PermissionDenied is useful for making a decision, but we still need the path and operation to understand the failure.

That information belongs with the error as it moves through the program. For example:

use eros::{Context, context};

#[context("Load server port from {}", path)]
fn load_port_with_context(path: &str) -> eros::Result<u16, (io::Error, ParseIntError)> {
    let contents = std::fs::read_to_string(path).union()?;
    contents.trim().parse().union()
}

fn configure_server(path: &str) -> eros::Result<u16> {
    Ok(load_port_with_context(path).context("Configure server")?)
}

fn main() {
    if let Err(error) = configure_server("config/port.txt").context("Start application") {
        eprintln!("{error:#?}");
    }
}

If the file contains an invalid number, the report is:

invalid digit found in string

  Context (innermost first):
    1. Load server port from config/port.txt
    2. Configure server
    3. Start application

The original error stays the main message, with the operations listed in the order they were added.

I generally prefer a function to describe its own operation and relevant inputs. Every caller then gets that context. Call sites can add context too, when they know something the callee does not. We can report the failure once with the operations that led to it.

The type tells us which recovery policy to apply. The context tells us what happened if recovery is not possible. We should be able to keep both without building a new error enum every time an error passes through another function.

Conclusion

I previously explored precise error sets with error_set . What still interests me is how little needs to change about Rust’s existing error handling to make this work. We still return Result , propagate with ? , and handle errors as values. The missing piece is making the possible errors easy to compose and reduce as they move through the program.

This is why I think Rust’s error handling is near perfect with the right constructs. Each function can describe the errors its callers need to reason about. We can handle those errors where there is a useful policy, simplify the signature where there is not, and keep the operational context needed to understand a failure. Precise error handling becomes much easier to use when it follows the way we already compose functions. That is why eros lets me love error handling—pun intended.

The eros source and README are available on GitHub .

Bonus: The Connection To Zig

Zig’s native error sets follow the same idea:

const std = @import("std");

const PortErrors = std.fmt.ParseIntError || error{ ZeroPort };

fn parsePort(input: []const u8) PortErrors!u16 {
    const port = try std.fmt.parseInt(u16, input, 10);
    if (port == 0) return error.ZeroPort;
    return port;
}

|| combines the sets, and try propagates errors like ? . Zig can also infer the set when the return type is written as !u16 .

Zig’s error codes have no attached payloads. In Rust, we can keep the same composability and carry actual data:

use eros::IntoUnion;
use std::num::ParseIntError;

#[derive(Debug, thiserror::Error)]
#[error("Port must be nonzero, got {input:?}")]
struct ZeroPort {
    input: String,
}

type PortErrors = (ParseIntError, ZeroPort);

fn parse_port(input: &str) -> eros::Result<u16, PortErrors> {
    let port = input.parse::<u16>().union()?;
    if port == 0 {
        return Err(ZeroPort { input: input.into() }).union();
    }
    Ok(port)
}

Show HN: I've been paying for a rural Tanzanian's education for 10 years

Hacker News
tanzaniaeducationproject.org
2026-10-08 10:39:47
Comments...
Original Article

Our mission is to help children access education, healthcare, and a safe environment where they can thrive. Every donation creates a lasting impact.

Smiling boy named Anselmo

Tell HN: I've been paying for a rural Tanzanian's education for 10 years

Hacker News
news.ycombinator.com
2026-10-08 10:39:47
Comments...
Original Article

I highly recommend donating some amount of your time, expertise, or money to good causes, regardless of your financial situation. Even the smallest amounts compound to amazing results—especially over long stretches over time.

When I was a student I made (very!) modest contributions to clean water projects, microfinance organizations, and the reports I now read as a mature adult are so gratifying.

I also try to keep a "charity" type project in my queue - volunteering my tech skills to help fix/build things for NGOs so fun to look back on.


I'd also like to point people towards the Giving What We Can pledge to donate some percentage of their income to charity.

While this is of course closely related to EA, which many people here are (both deservedly and undeservedly) not big fans of, it doesn't require you to choose some specific charities or agree with their moral framework. Consistently donating money to whatever cause you personally value would make the world a much better place compared to not donating anything.

I really recommend people consider doing it regardless of their views on EA or the charities they recommend. I'm not a big fan of the modern EA community myself, but I agree that the money that barely make a difference in my life could be life changing for others.

https://www.givingwhatwecan.org/

On a somewhat unrelated note, also consider signing up for blood and stem cell donation!


I highly recommend not to. The potential for whole operation being a scam because you have no way to verify anything is pretty high. Now add there reality of generative AI and very easy way to make deep fakes and essentially every charity is certified scam.

You may see it as cynical or unfair but that's unfortunate reality of time we currently live in.


Yes, best to live in a cave and never take any risks or have any contact with dangerous, suspicious, filthy humans.

It's fine. There is plenty of good in the world. Touch some grass and take a deep breath.


Where do you find NGOs/projects that you can volunteer your tech skills to help? This sort of thing is something I've been interested in for a while but haven't been able to find a good place to start looking considering I havent previously done tech oriented charity work


I will echo what others have said and say this is amazing on a personal level, but also super cool to share with others. I think especially in tech we can get a little focused on efficacy and scale instead of human impact, and some might quibble about that in the comments ill be interested to see the discourse.

Your impact is undeniable, and i think quite importantly very tangible and concrete to you. Very inspiring.


This is great man. I've been on the other end of this. My annual high school fees cost $700. Couldn't afford it, and it was extremely stressful. If not for the benevolence of my high school principal, I have dropped out. It completely changed my life. You're making a massive difference.


I knew quite a few people in high school and college that wouldn’t have been able to afford it without crippling debt but we were able to get our tuition paid for by the State if you had a B average.


    > My annual high school fees cost $700.

One more good reason to read HN: High quality personal posts! Can you share (without doxxing yourself), where do/did you live (during high school)?


Some friends were involved with an aid organization which helped several rural areas across a few different countries in Africa.

A key point was the organization didn't finance things. Instead they financed seminars, workshops and such. They'd pay for travel, food and accommodations, as well as renting a place and one or more speakers.

They'd facilitating people learning basic accounting skills which they could use in the co-op back home to make it harder for another co-op member to embezzle money, for example.

A lot of aid per buck this way.

Seems like you're well on your way with something similar. Well done!


Thank you! Yes my goal is that this becomes a self sustaining project where people in the area are given the skills they need to transform their lives. Models like the ones you are talking about that create change and don't just supply aid I think are the most important in my opinion.


Thank you all for the responses. I wasn't exactly sure how this would go over here. Someone pointed out that I have a typo in my email on the site (thank you!). I'll fix that when I get home from work tonight. The correct email is tanzaniaeducationproject@gmail.com (not .org) if you want to reach out


This is amazing. I once adopted a kid's education who lived in Colombia. The organization would send me a letter with his picture every 3 months or so, giving me some updates of how the kid is doing in school etc. After about a year I asked the organization if i could say Hi to the kid on a video call (i think i was watching some show on netflix or prime, where the main plot was how seemingly non profits scamming donors or something like that). I kinda grew suspicious that how do i even know if these kids are real and if this money is actually going somewhere. The org said they can't do it, they can't arrange for the kid to say Hi to me on the video call. I decided to cancel the payment from that month's onward. I redirected that money to doctors without borders. I don't know if i did the right or not; the point is that trust is extremely important when it comes to non profit efforts and the donors need to be able to get some sense (even a teeny,tiny action) that this effort is real. Again, thank you for what you did. you sound like an amazing person.


I really appreciate this response. It's my biggest worry because I share the same skepticism as you. That's part of the reason I started doing this because I started question where my donations to bigger organizations were going.

I will say that I could arrange video calls for sure if you wanted to support a kid. I want to grow this as much as possible and trust is the way to do that. I'm all ears for anyone with any advice for how to build trust.

Thank you!


not sure if right for your project, but an idea ive had in the past is that the organizations should have the jobs filled by people from the places they are organizing support for.

too often the work involved in taking it to an organization level is written off by the doners, and / or taken advantage of by the org. but renting a building and hiring people to take calls, perform accounting, etc has real cost that cuts into donations but it is also an area of job creation. Those jobs created, imo, are incredibly important and when they are given to people in the donating country it turns into mostly just economic activity in the doner country run on donations with just whatever amount is leftover going to the actual aid. of which, without any outright corruption, people are always eager to spend that money to make the organization side of things better.. or invest it into the organization under the guise (genuine or not) of scaling the organization such that donating a bit less today leads to more donations tomorrow. and then it becomes like any other business mostly running on debt and the actual donations are like a material cost that is constantly pressured to be cut down to pay back debts


I've made it a rule to only donate significant money (whatever "significant" might mean) to charities where I know the people and/or have visited them first hand. I love the idea of donating for a kid's education, and indeed have been "sponsoring a child" at jhamtse.org for the past several years. Because I've met the principles of the place, and have had family members involved on the ground there, I know the money is well spent. I know the "sponsorship" doesn't actually mean the money only goes to help that one individual kid, but I don't mind, and I like getting the updates about the progress of this particular boy.


A lot of these orgs say you are sponsoring EG Jane's education but in reality the money gets spread across a whole school or region.


The technology is finally here for scams to let you video chat with an artificial kid.

It would make sense to separate kids from the people who are donating money to them, but they could have offered to let you chat with the parents.


I see where you're coming from, but it is not a penpal service either and they don't want to be passing messages. I traveled to a school in Uganda which had some students' education sponsored by Americans. They were real students, and the issues were usually student performance, if students had a problem or got pregnant would that affect their scholarship program and scare off the donors, etc. Knowing that it is assigned to an individual person is important for some donors, but you might just want to donate to doctors, schools, etc. in general.


This is a fair point. There is a way these things can overly performative. My thought was always that it's not supposed to make the donators feel good, it's just supposed to be something that they do because it's fair and right. I think most people, if they got to actually see this village, would understand what I mean.

That being said, I want people to trust the effort, and if that means having some sort of communication or feedback from the kids in the program, then I'm totally OK with that.

I think the most interesting thing about this is that no one but the kids benefit from this. I take zero payment and everyone involves is volunteering. It's not easy to find an organization that doesn't spend %30 of their budget on ads and overhead.


I don't want to hijack the thread, but would like to surface another such organization which I am aware of - Yuwa [1], which operates in India.

It was founded by Franz Gastler [2] when he visited India a couple of decades ago and spent time in some _really_ rural parts of the country. I'm proud to call him a friend, and have volunteered myself at the Yuwa School to teach math/CS. Through this school, girls have ended up at Harvard (!!) with scholarships, who would've never stepped out of their villages and probably ended up as child brides. I usually introduce him to my compatriots as the firangi who's done more for our country than anybody else I know!

[1] https://yuwa-india.org

[2] https://en.wikipedia.org/wiki/Franz_Gastler


Highlight the fact that it's a 501(c)(3) on the website. Being a non-profit opens up opportunities for donations from large corporations and applying for government grants. I notice that you have a PayPal Donate button. IIRC, PayPal has a specific payment structure for nonprofits.


I'll highlight it more when I get home after work tonight. Thank you for the tip. I have set up the specific payment structure for PayPal. Thank you very much for the feedback!


This is amazing. I'm curious how you provide oversight. I imagine with Amwirite there was a lot of trust, but how can you be ensure the money is actually being used properly as you add more students?

I'd imagine that in many parts of the world where money is tight, you might encounter families who just use the money for other things or all sorts of schemes.

I'd also love to learn more about the 501c3 process and how easy/hard it is.


Thanks for the comment.

Trust is key in any effort like this. I made some connections to a local church in Njombe (I'm not religious and neither is the organization, anyone is welcome) and met some of the most selfless people I've ever met (special thanks to Sister Theo) who help arrange transportation to and from the schools, and take the kids into town to get supplies, or arrange doctors visits when needed).

The money can be paid directly to the schools via western union and they send me receipts and even report cards.

Another helpful thing is that students have to take national exams in Tanzania at different stages of their education. Those scores get posted to the interent, so I can track progress that way too.

The truth is that there are many families who are working tirelessly to send their kid to school, so the motivation is already really strong in the village.

I go back every few years to check up on things, talk to the schools and give many many thanks to the nuns.

501c3 was fairly easy to set up. About as simple as an llc if I remember correctly, with a little more paperwork. I set it up in Idaho where my mom lives because I tend to move around a lot and she has a permanent address there, and the process is relatively simple in Idaho.


> how can you be ensure the money is actually being used properly as you add more students?

I suppose one way would be to pay the bills directly. I.e. the money to pay for education could be paid directly to the school, rather than giving it to the student’s family to pay the school. That could even bypass certain situations like the student and one parent being honest but the other parent trying to keep the money.

You could then keep very small tabs on progress. E.g. get notified by the school if the student is missing classes. You could then get in touch with them to see what’s going on (there could be a legitimate reason) and decide if you should keep paying or give the money to someone else.


This is great. Thanks for sharing. I'm always happy to make a donation for education.

Weird HN type question. On your site you mention paying $5 for hosting the site but didn't mention that here. We're you able to figure out a free way to host?


I wasn't. If I remember correctly I had to pay the $5 for proper security certificates to be able to put the PayPal link. The $5 just comes from my personal bank account so that is taken care of separately from the org. Thanks for donating!


What a fantastic thing you are doing. Thank you for making the world a bit better and my day a bit brighter. I'm not in a position to do anything for your organization right now due to other engagements but if and when those are brought to a - hopefully successful - conclusion I will re-visit this. Absolutely awesome initiative.


Good on you.

I often think sometimes with these diffuse mega-charities, you never know where the money ultimately ends up or what difference it makes.

At least with your donations you can see for sure where the money went and the direct benefit it had.


And CEO salaries (while the average charity worker gets a pittance).

A lot of these mega-charities seem to just be in business to "raise awareness of issue x" which also generates more donations to the charity so they can raise even more awareness.

A local charity to me has just had to cease operating. They provided free minibus travel for elderly/less mobile people. Nothing fancy, but it met a need and was tangible.


What an inspiring story!

How did you end up in Ibumila? Do you ever go back there?

You ask how much can a village change. Are you trying to document that in any way?


Thank you very much. When I was 19 I was convinced that my understanding of the world was wrong so I decided to travel to East Africa to see some of it for myself. Tanzania is a relatively safe place to travel and I wanted to learn swahili.

A friend of a friend of my parents heard that I was going and asked me to check up on a orphanage they were funding in the Njombe region. That's how I ended up in such a remote place. I helped work on the orphanage and spent time getting to know the village. That's where I met Anwarite.

I go back every few years to check up on things. It's quite the journey to get there.

I haven't though of documenting actual data points about this yet. I think that's a good idea. Any ideas on where to start?


> I haven't though of documenting actual data points about this yet. I think that's a good idea. Any ideas on where to start?

I think it’s important to be careful with this. “When a measure becomes a target, it ceases to be a good measure” and all that. You’re doing something good and your heart seems in the right place, so don’t lose that. It’s perfectly fine to measure your success with “the people from the village tell me it’s having a positive impact” without having to quantify things yourself, as long as you’re happy that the money is being used for the intended purpose.


I love this hyper-individualized approach. I would be way more willing to meet someone and sponsor _them_ than I would be to just give anonymous dollars.


It's a great idea, and the OP and donors are making a big difference. While I was a doctorate student, I supported a Romanian orphanage (run by Americans I never met except via email) with parcels of medicine and stationary (basic stuff e.g. anti-fever pills, coloring pens etc.). Since I never sent any cash, I was not worried about being scammed.

I've also been financially supporting three grassroots projects to help children in three places, namely Lomé, Togo, Caruaru, Brazil and Bhopal, India (via https://www.fkb-bza.de , sorry, Website in German only, a charity that has the advantage of being free of any overhead - thanks to people I personally know and trust that travel there regularly, paying for their own tickets).

Thought experiment (putting back the geek hat on): I wonder if the OP's activity could be made viral and scaled up across the continent:

While there are more donors do:

- for each African country

- pick a seed city c

- pick a seed student s from c

- assign donor d to s to fund s' education

When paying for s.o. education, receiving students pledge to pay it forward by becoming a donor once they get a job that permits to do so or to return to become a teacher for a while.

On top of that, students form or join an online community to support each other and get to know each other (peace is as important as education!).


I could arange this. Meeting in person is tough. It takes me about 40 hours door to door to get to the village from my house (plane ride, taxi to a bus station, 12 hour bus ride through the country, another taxi, then motorcycle for the last leg). However, if you wanted to support a specific student, I could absolutely arrange that. The cost varies from year to year with exchange rates but it comes out to around $1200 a year. Email me at tanzaniaeducationproject@gmail.com to talk more. Thanks!!


Could a group of donors be dedicated to financing an individual - with group members connected to each other? Communications could happen on one of the federated platforms, maybe coordinated by a temporary group head.


She said that when she earns her PhD she wants to bring it back to the region but what would a degree in Language Studies bring to a region with so little?


That's a fair question. I made a decision early on that I wasn't going to push any student in any particular direction. They were free to pursue any education they wanted. Anwarite chose this route and I'm happy to support it.

However, just the fact that she is so educated, regardless of the degree, I think can make a huge impact on her village. Most adults I met there had around a second or third grade education at most. Many never went to school at all. The fact that she can speak English, use a vomputer, and teach could be transformative.


Maybe she can become a teacher in the region and continue the process of helping others to expand their horizons beyond the region?


culture, rights for women, appreciation of learning...those are all downstream of PHDs in the humanities


I wholeheartedly agree. While I admire OP in his charitable endeavors. I can't help but think that this puts the incentives on studying things that offer little to no market value. Market value of a degree tends to be a huge predictor of how needed that skill is in the market. I don't know if what Tanzania needs right now is language PhD's instead of Architects, Engineers, Doctors, etc...


IMO this kind of hyperoptimization will cause more trouble than good. It's cheap and productive just to get humans to advance through any sort of education. This person will almost certainly contribute more than she would have with a 5th grade education.

Let people self-direct, even if not everyone follows an optimal route. It's a numbers game.


One thing they probably don’t need are bad unhappy professionals uninterested in their field. The people from the village know better than us random internet commenters what their heart is in, and they have just as much right as us to pursue their dreams and interests.

The focus on “the market” is a disease which narrows our thinking. For all we know, her language studies might allow her to communicate with many more people and cultures from the outside and bring much more prosperity to the village than an architect.


I understand your line of thought, but the individual specifically being talked about is returning to her home to contribute to the success of her community. Literally the exact opposite of what you are complaining about. Seems like this form of support, just providing an opportunity, succeeds in its goal.

People leaving a village or city for other opportunities is nothing new and something pretty much all humanity (and species) experience.


It's a good point. If only a fraction of children can go into STEM subjects & can get good in practical knowledge. They can give a lot back to their community by creative problem solving with the limited resources they have!!

I think it's hard to get child curious towards particular domain if they don't get any external push of some sort. I got into computer science because I used to tweak computers & play games in childhood in home computer.


If the kids all have better lives, isn't that a good thing? What is noble about an impoverished village where everyone just exists?


I hope when I am in need and someone thinks about helping me they don't find someone like you, man.


That might be true, but should we clutch our pearls after we killed our villages?


Wow, that is amazing, congratulations on making such difference on peoples lives. Btw, you can use Netlify to host your website for free and still be able to add a PayPal client button. That would save you 5$ per month that could be directed to the cause you are helping for all those years.


No questions or comments. Just glad to wake up and read this. Big fan of how the things we consider small can be life changing to someone else.


I love this energy, and love how it seems to be resonating with others too. seems a more whole and life-giving than the intellectual EA vibe


Yes, because the person involved did it quietly and without drawing attention to themselves such as the EA crowd (including those on HN) do with great regularity. They seem to use their virtue signalling as a shield for criticism of EA.


Funding child education up to 18 seems like a great and noble cause. How does it work beyond that though, with university?

Could you fund a scholarship or a specific department or something with the universities instead of sponsoring an individual person?


10 years ago, I paid a lump sum to have three roughly 5 year-old Indian girls go all the way to college and I used to get yearly updates and pictures but then I moved a couple of times. I wonder how they’re doing now. I did my due diligence at the time with the charity and saw that their overhead was less than 12% and 88% of whatever was donated went to the kids.


This is awesome. I would note that there are similar charities (based in various Western countries) that do similar things if people like the idea but for whatever reason don't want to donate to this particular one, just a simple Google search away.


This is beautiful. Bravo. You created an opportunity for someone to thrive and grow. There are few higher callings to humanity than that, IMHO.

I also did something sort of similar: I had a close friend in Brazil (former roommate when he eas in the US; self deported) who was going through a very difficult time. As an experiment..I gave him $100/month, no strings attached. Blow it on food and games, rent, whatever he wants.

Tl;dr it went very well, his life significantly improved, I did it because he was my friend, I had the money, and wanted to see what would happen.

We Skyped after his shift ended one night and he was very depressed. With a VPN and a credit card I ordered him Dominos to cheer him up. I sent a feast that.. only cost me $10.[1]

Realizing the exchange rate benefit, I got the idea of giving him $100 each month as an experiment; $500 Brazilian Reals.

I wanted to know if the extra money would help and if I could use the exchange rate to help my friend get to a better place in life. Sort of a UBI but not quite.

Now, $100 to me is a bit of money, but 500 BR to him was a crazy amount of money to be given.

Over six months, it allowed him to quit his job at McDonald's, get out of a financially unstable roommate situation, move closer to his family in his own place, and find a better job. He started dating again.

I told him I would commit to a year, but he actually said at the 6.5 month mark that he's doing so well that I don't have to keep giving him money.

Three years later he's still doing great. I have concluded from this that more money in our pocket always helps, but there is a certain responsibility (maybe in general) needed when a gift like that lands in our laps. It can be easy to blow it [2] but just as easy to use it to move life forward.

It has certainly made me more ..aware/appreciative of my privilege and (sometimes fragile) security.

[1]. Two medium four topping pizzas, two 2-litre bottles of soda, breadsticks, and chicken nuggets.

[2]. I was once given a generous stipend from the Student Government of $140 which I did not use for school supplies, rent, or even groceries. Nope. I bought alcohol.


Amazing story. And a nice testimony to the asymmetry between earning in one spot and spending in another where a relatively small amount of money can be life changing.


Someone did something nice, posted it, others either appreciated it or thought it was interesting and upvoted it. After three years here you should know the answer to this because that question comes up almost every day and it always gets answered in the same way.

With zero submissions to your name there is something you could do if you wanted to change what gets posted to HN.


Well, it's better than "X had died" which pops up about once a day and usually contains someone unrelated to hacker news... While this one is inspiring and good to have on HN

Oh look, banks are being hacked by AI

Math Babe
mathbabe.org
2026-10-06 10:26:35
This is just the beginning. From the WSJ:...

Show HN: I Put an AI Agent on a Nokia 110

Hacker News
github.com
2026-10-08 10:18:51
Comments...
Original Article

AI on a Nokia 110 4G

I reverse-engineered the firmware of a Nokia 110 4G and built a native AI chat app for it. You type on the number pad, and the agent can use the phone's own functions.

Watch it work

Watch the Nokia AI demo

Click the image to watch the demo on YouTube.

What it does

  • Answers questions over the phone's SIM data.
  • Checks the battery percentage.
  • Turns the torch on or off.
  • Starts a phone call.
  • Sets an alarm.

How it works

Modified the Calculator app into custom chat app. It sends your message to DeepSeek chat API and use tool calls accordingly.

I used OpenAI Codex to help build it and tested the app on the handset.

Where it stands

It's a working prototype loaded into RAM from a computer. Once loaded, it can run unplugged using mobile data. We can add as many feature as we want and make almost all the operation in nokia 110 automated. After a restart or power-off, it needs to be loaded again.

How I got here

Phase 1: Start with the browser

I first added an AI search option to Opera Mini. That gave me a starting point, but it was still a browser workaround and can't integrate agent with this. The next goal was an app running on the phone that could use its native functions.

Phase 2: Get my own code running

There was no supported way to install a native app. I studied the firmware and boot process, then got custom code running in RAM through the Calculator entry point. That let me test without flashing modified firmware. Permanent installation is still unresolved.

Phase 3: Get a real answer over SIM data

A working data connection wasn't enough: requests could be submitted without an answer reaching the app. I traced the firmware's response callbacks and overall flow. I started with one fixed question, confirmed the answer with USB unplugged, then added typed questions.

Phase 4: Make the chat usable

Tried to replace calculator layout with text input box. Stock Calculator drawing also got in the way. I changed the layout and key handling. Later, a colour change caused restarts; tracing the firmware showed I had written to the wrong style field. Fixed it.

Phase 5: Turn chat into actions

The next goal was to let the AI use real phone functions. As the phone memory is only 48MB, normal agent code wont fit, so created a very simple custom agent, used smaller builds, compressed the payload and reused buffers. Then tested each feature mentioned above one after other.

Source code

I haven't uploaded the code because sensitive data is scattered across the project.

Orkut.com

Hacker News
orkut.com
2026-10-08 10:09:53
Comments...

OAuth grants pile up faster than you can review them. Here's how to keep up.

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 10:00:10
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article...
Original Article

OAuth Grants header

Every time an employee clicks "Allow" on an OAuth consent screen, they create a standing trust relationship between two apps. An AI note-taker gets access to their calendar. A task management tool gets access to Slack. A new developer tool gets access to code repositories.

Each of those decisions takes seconds. Reviewing them properly takes much longer.

For IT and security teams, the question isn't whether employees will connect apps to corporate data. They already have, thousands of times over. The challenge now is keeping up: knowing which grants exist, which ones carry real risk, and which ones should be revoked, without spending your entire week on manual reviews.

That's exactly what Nudge Security does.

Why OAuth grants are so hard to govern

OAuth grants don't behave like the rest of your access. One common misunderstanding is assuming OAuth grants inherit the controls you've built around user identity. They don't. OAuth is a completely separate protocol from authentication. SSO governs how a user proves who they are. MFA adds friction to that proof. An OAuth grant is neither of those things.

They also outlast the credentials of the people who create them. Disabling a user in Google Workspace or Microsoft 365 only suspends grants that originated in that platform, but grants issued from third-party apps keep working uninterrupted.

Many grants sit dormant for months without producing a single log entry, but they stay fully valid and can be exercised at any time.

Attackers know this. In the recent Vercel breach, the root cause was a compromised OAuth token from Context.ai , a third-party AI tool that one employee had connected to their enterprise Google Workspace account months earlier. A single point of consent was enough to get in.

The numbers show why this keeps happening:

  • 88 average OAuth grants created per employee, 31 of which carry data-level permissions ( Nudge Security )
  • 40 average apps per organization with programmatic access to sensitive corporate data ( Nudge Security )
  • 50% of SaaS breaches will stem from overprivileged OAuth tokens by 2027 ( Gartner )

At a 1,000-person company, that's 88,000 access paths, and 31,000 of them have a direct line to sensitive data.

The math on manual reviews

A thorough review of a single OAuth grant looks something like this:

  • Pull the app's profile. Has your security team already vetted it? Does the vendor have a real security and compliance program? Have they disclosed a breach in the last 12 months?
  • Check the grantor's role to see whether admin rights were delegated to the app.
  • Compare the requested scopes against what's typical for that kind of integration and against your own data-sharing policy.
  • Reach out to the grantor to understand the business need, and check their MFA status.

Running through this process on a single grant can easily take 45 minutes to reach a verdict.

Forty-five minutes is a reasonable amount of time for one grant. It's an impossible amount of time for tens of thousands. No amount of expertise makes that manual work faster, and no security team has the headcount to keep up.

That's why agentic capabilities aren't a nice-to-have for managing OAuth grant risk . They're the only way to cover the attack surface you actually have.

Find every OAuth grant with Nudge Security

You can't assess a grant you don't know exists. Nudge Security gives you complete OAuth visibility into grants and app-to-app integrations across your SaaS estate from the start, including grants created long before you deployed Nudge.

Discovery doesn't depend on activity logs, so dormant and identity-only grants ("Sign in with Google") show up alongside the active ones. Nudge also surfaces API keys, service accounts, and remote MCP server connections powering AI tools and agents, giving you a full picture of programmatic access to your data.

For every grant, you can see:

  • The app and vendor receiving access
  • The employee who created the grant
  • The exact permissions and scopes granted
  • Which corporate apps and data the grant can reach
OAuth grant inventory in Nudge Security
OAuth grant inventory in Nudge Security

Assess: Surface the risk signals that matter

A list of grants is only useful if you know which ones to worry about. Nudge Security automatically classifies and risk-scores every integration based on the scope of permissions, the vendor, the grantor, org usage, and the sensitivity of the data being accessed.

Risk insights flag things like:

  • Excessive or overprivileged permissions
  • Suspicious domains
  • Apps commonly used by threat actors for data exfiltration
  • "Data highways," or connections with unusually broad, persistent access to sensitive data like email, files, and code repositories
  • MCP servers acting as intermediaries between AI tools and your corporate data

Nudge also surfaces positive signals, such as popular apps and verified publishers, so you can quickly separate the routine from the unusual.

OAuth risk insights and permission details in Nudge Security
OAuth risk insights and permission details in Nudge Security

Analyze: Get a clear verdict on every grant in seconds

Risk scores tell you where to look. The OAuth Grant Risk Analyst agent does the actual analysis.

The agent reviews new OAuth grants as they appear, drawing on Nudge Security's discovery context across the browser, inbox, identity provider, and connected apps, plus risk intelligence from more than 240,000 vendor security profiles .

It evaluates the same factors an experienced analyst would:

  • The grantor: who created the grant, their role, and their user metadata
  • The vendor: security posture, compliance program, and recent breach history
  • The permissions: which scopes were granted and how they compare to what's typical
  • The reach: what the app can actually touch, and how it's used across your org

Because the agent looks at who created a grant, not just what the grant can do, it catches what a simple risk score misses, like a brand-new hire who created a high-risk developer grant.

Every analysis comes back with a plain-language risk evaluation, a TL;DR, detailed reasoning, any evidence gaps, and one of three verdicts:

  • Permit: The grant is low risk and can stay in place.
  • Justify: The grant needs further investigation. Review it with the person who created it to confirm the business need.
  • Revoke: The risk outweighs the business value, and the grant should be removed.

That 45-minute review? The agent reached the same verdict in 15 seconds.

OAuth Grant Risk Analyst verdict and reasoning in Nudge Security
OAuth Grant Risk Analyst verdict and reasoning in Nudge Security

Govern: Your team makes the call

Speed is only valuable if you can trust the outcome. That's why the OAuth Grant Risk Analyst keeps your security team in the loop before anything changes.

The agent recommends the next step, and your team reviews the verdict and the evidence behind it. When you authorize an action, the agent orchestrates it, whether that's revoking the grant or nudging the grantor to justify the access. Every action is fully auditable, so you always know what was done, when, and why.

Beyond the agent, Nudge Security gives you the controls to keep OAuth risk in check over time:

  • Nudge grantors directly through Slack, Teams, email, or the browser extension to request justification. Their responses are captured automatically.
  • Get alerted to new OAuth activity as it happens.
  • Revoke OAuth grants automatically when they're risky or unused, including as part of employee offboarding .

The result is a governed workflow that turns a 45-minute manual review into a decision your team can make in seconds, without handing over control.

Reviewing and authorizing an agent recommendation in Nudge Security
Reviewing and authorizing an agent recommendation in Nudge Security

The bottom line

Your employees will keep connecting apps to get their work done. That's not going away, and it shouldn't. Your job is to make sure every one of those connections is visible, understood, and revoked if the risk outweighs the value.

Nudge Security includes OAuth risk management as part of a comprehensive solution for SaaS and AI security governance. Nudge gives you a complete inventory of OAuth grants, the risk context to understand them, and an AI agent that delivers clear verdicts at scale, while your team stays in control of every decision.

Ready to get control of risky OAuth grants? Start a free 14-day trial.

Sponsored and written by Nudge Security .

A Parliament of Owls Moves to the Upper West Side

hellgate
hellgatenyc.com
2026-10-08 09:48:41
Hoot hoot. Plus, more news for your Thursday morning....
Original Article

Earlier this week, New Yorkers were alerted to the presence of silvery, ghostlike figures among us, gliding through the sky, perching on windowsills, congregating on water towers, and emitting a non-insignificant amount of screeches.

But fear not! On Sunday, Upper West Side-based local news blog West Side Rag published a photo of an American barn owl , spotted by an eagle-eyed UWS resident who said she'd identified its calls through a bird ID app. By Wednesday, the same woman, Elisabeth Williams, had captured photos of multiple barn owls hanging out together . "We watched two flyovers, snapped some photos, and listened to the calls," Williams told West Side Rag. "Back inside, we compared our pictures and their timestamps and were shocked to see there may have been up to four or five owls in total!"

Not everyone on the Hell Gate team is as excited about the owl sightings for folkloric reasons—in Mesoamerican mythology, for instance, owls are denizens of the underworld and generally a bad vibe . But enough of us were charmed by Uptown's newest residents, so we got in touch with a couple of experts to find out what's up with these owls: Are they OK? Why are they here? And what should someone do if they happen to see them?

Oh hell yeah (David Lei)

Subscribe to read the full story

Become a paid subscriber to Hell Gate to access all of our posts.

Subscribe

[$] The [vx]swap showdown

Linux Weekly News
lwn.net
2026-10-08 09:43:27
The kernel's swap layer has undergone some significant changes over the course of the last year and a number of longstanding problems have been addressed. One problem that has not yet been solved in the mainline is the direct tie between slots in the swap cache and space in persistent swap files, w...
Original Article
The page you have tried to view ( The [vx]swap showdown ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 22, 2026)

2027 Web Platform Feature Ranking

Hacker News
interop-rank.fxdx.dev
2026-10-08 09:34:22
Comments...

Sub-1-Bit LLM Compression via Latent Factorization

Hacker News
github.com
2026-10-08 09:29:46
Comments...
Original Article

The LittleBit Project

Sub-1-Bit LLM Compression via Latent Factorization

Official implementation of LittleBit (NeurIPS 2025) and LittleBit-2 (ICML 2026).


Papers

LittleBit-2: Maximizing the Spectral Energy Gain in Sub-1-Bit LLMs via Latent Geometry Alignment (ICML 2026)
Banseok Lee, Youngmin Kim
arXiv ICML

LittleBit: Ultra Low-Bit Quantization via Latent Factorization (NeurIPS 2025)
Banseok Lee*, Dongkyu Kim*, Youngcheon You, Youngmin Kim
arXiv NeurIPS


Abstract

LittleBit compresses large language models into the sub-1-bit regime by factorizing each dense weight matrix into low-rank latent factors, binarizing those factors, and restoring magnitude information through lightweight learned scales. This enables extreme compression, including the 0.1 bits-per-weight setting, while preserving the original model architecture at inference time.

LittleBit-2 improves this recipe by addressing latent geometry misalignment in the initialization stage. It applies Internal Latent Rotation with Joint Iterative Quantization (Joint-ITQ), aligning the SVD-derived latent factors with the binary hypercube before QAT. LittleBit-2 initialization is available as an opt-in ( --use_itq ) and produces no additional inference overhead.


Highlights

  • Sub-1-bit compression: Designed for 1.0 to 0.1 bits per weight.
  • LittleBit-2 opt-in: Enable Joint-ITQ initialization with --use_itq for improved latent geometry alignment.
  • No inference-time change: LittleBit-2 modifies initialization only; the deployed factorized layer remains the same.
  • QAT-friendly: Supports Quantization-Aware Training with SmoothSign and optional residual factorization.

Supported Models

The codebase currently supports:

  • OPT
  • Llama and Llama 2/3
  • Phi-4
  • Qwen2.5 and QwQ
  • Gemma 2 and Gemma 3
  • Qwen3

Installation

We recommend Python 3.12.

conda create -n littlebit python=3.12
conda activate littlebit

# Install CUDA toolkit. Adjust the CUDA version if needed.
conda install nvidia/label/cuda-12.4.1::cuda-toolkit -c nvidia/label/cuda-12.4.1

# Install PyTorch.
pip install torch==2.8.0+cu124 torchvision==0.23.0+cu124 torchaudio==2.8.0+cu124 --index-url https://download.pytorch.org/whl/cu124

# Install dependencies.
pip install -r requirements.txt

Important

For reproducing the paper results, use transformers 4.51.x. Newer transformers releases may change model internals or evaluation behavior.

pip install "transformers==4.51.*"

Usage

Training

Train a model with Quantization-Aware Training. By default, LittleBitLinear uses the original SVD-only initialization. To enable LittleBit-2 (Joint-ITQ), pass --use_itq True .

Single GPU

CUDA_VISIBLE_DEVICES=0 python -m main \
    --model_id meta-llama/Llama-2-7b-hf \
    --dataset c4_wiki \
    --save_dir ./outputs/Llama-2-7b-LittleBit-2 \
    --num_train_epochs 5.0 \
    --per_device_train_batch_size 4 \
    --lr 4e-05 \
    --warmup_ratio 0.02 \
    --report wandb \
    --quant_func SmoothSign \
    --quant_mod LittleBitLinear \
    --residual True \
    --eff_bit 1.0 \
    --kv_factor 1.0 \
    --min_split_dim 8 \
    --l2l_loss_scale 10.0

# Opt-in to LittleBit-2 initialization
# --use_itq True

Multi-GPU with DeepSpeed

deepspeed --num_gpus=4 main.py \
    --model_id meta-llama/Llama-2-7b-hf \
    --dataset c4_wiki \
    --save_dir ./outputs/Llama-2-7b-LittleBit-2 \
    --ds_config_path configs/zero3.json \
    --num_train_epochs 5.0 \
    --per_device_train_batch_size 4 \
    --lr 4e-05 \
    --report wandb \
    --quant_func SmoothSign \
    --quant_mod LittleBitLinear \
    --residual True \
    --eff_bit 1.0 \
    --kv_factor 1.0 \
    --min_split_dim 8

Evaluation

Evaluate a local checkpoint or a model hosted on the Hugging Face Hub.

# From a local directory
CUDA_VISIBLE_DEVICES=0 python eval.py \
    --model_id ./outputs/Llama-2-7b-LittleBit-2 \
    --seqlen 2048 \
    --ppl_task wikitext2,c4 \
    --zeroshot_task boolq,piqa,hellaswag,winogrande,arc_easy,arc_challenge,openbookqa

# From the Hugging Face Hub
CUDA_VISIBLE_DEVICES=0 python eval.py \
    --model_id username/littlebit-llama-7b-0.1bpw \
    --seqlen 2048 \
    --ppl_task wikitext2

Legacy Checkpoints

Older checkpoints may not include littlebit_config.json . In that case, pass the quantization arguments explicitly:

CUDA_VISIBLE_DEVICES=0 python eval.py \
    --model_id ./outputs/Legacy-Llama-2-7b \
    --quant_func SmoothSign \
    --quant_mod LittleBitLinear \
    --split_dim 1024

Parameter loading priority:

  1. Explicit CLI arguments
  2. littlebit_config.json in the model directory
  3. config.json fallback for older checkpoints

Citation

If you find this work useful, please cite:

@inproceedings{lee2026littlebit2,
  title={LittleBit-2: Maximizing the Spectral Energy Gain in Sub-1-Bit LLMs via Latent Geometry Alignment},
  author={Lee, Banseok and Kim, Youngmin},
  booktitle={Proceedings of the 43rd International Conference on Machine Learning},
  year={2026}
}
@inproceedings{lee2025littlebit,
  title={LittleBit: Ultra Low-Bit Quantization via Latent Factorization},
  author={Lee, Banseok and Kim, Dongkyu and You, Youngcheon and Kim, Youngmin},
  booktitle={Advances in Neural Information Processing Systems},
  year={2025}
}

License

This project is licensed under the CC BY-NC 4.0 license.

Beauty in DVD Menus

Hacker News
vale.rocks
2026-10-08 09:22:01
Comments...
Original Article

Look at many early DVD releases, and you’ll see interactive menus touted as a selling point. Coming from VHS (or LaserDisc), which had no menus to speak of, this was a genuine improvement. That isn’t to say all DVD s had interactive menus, however. Many of the earliest releases just entered straight into their content, and the same is true of some cheaper releases.

However, once DVD became widespread, publishers started to really embrace the capabilities the format afforded them. The format first released in late 1996; however it wasn’t until the 2000s that they really kicked off. With the medium’s strengths and foibles known, players widely adopted, and technology ready to handle the task, DVD s hit their stride. With this came some brilliant and memorable menus.

Resolution & Aspect Ratio

In NTSC regions video on DVD almost always has a resolution of 720 × 480 pixels, while in PAL regions they’re almost always 720 × 576 pixels. These specific resolutions can be traced back to the D-1 , a digital recording video standard which stored uncompressed component video. It was a major leap in real-time, high-quality recording when it released in 1986 and quickly achieved ubiquity. It derived its resolution from the Rec. 601/BT.601/ CCIR 601 standard from 1982.

Other resolutions are possible , however are rarely used for having worse quality and generally being a poor trade-off. You may notice that NTSC ’s resolution of 720 × 480 pixels is a ratio of 3:2 and that PAL ’s is a resolution of 5:4. The DVD has metadata tags telling the playback device how to then stretch the video to the desired aspect ratio for correct appearance in viewing. This is the difference between Storage Aspect Ratio ( SAR ), which is the ratio on the disc, and Display Aspect Ratio ( DAR ) or Pixel Aspect Ratio ( PAR ), which is the ratio in presentation.

Due to the transition from 4:3 aspect ratios on home displays to 16:9, there were a lot of fluctuations in DVD presentation. From widescreen that was forced to fit within a 4:3 area via letterboxing, to pan and scan, to anamorphic widescreen, there was variation in presentation. With DVD menus, we see exactly the same as was true in the transitioning era of broadcast television, where critical information was kept within the 4:3 safe area , while non-critical, flavour imagery was within the 16:9 only area.

Even releases long after most people had migrated to widescreen, 16:9 displays continue to keep everything within this small safe area. It became a major design consideration of DVD menus that has stuck around even if no longer strictly necessary.

DVD menus can take many forms, though they tend to have a fairly typical set of options. More often than not, a play button, a chapter/scene/episode select, special features or extras, and settings, including subtitle, language, audio, and picture options. At the very simplest, these are displayed in a list with a static image background. At the most decadent, there are full custom animations or acting with diegetic menus and layers of content designed specifically for the DVD – oodles of extra content and hidden additions crammed into every nook until the disc can’t hold anything more.

Being developed in the mid-1990s, DVD s are fairly simple in terms of technical capabilities. The picture shown by a DVD is a standard MPEG -2 video stream. For interactive elements, like menu items which highlight when hovered, or an overlay on the presentation, subpictures are used. Subpictures are 2-bit, meaning they only support four colours at a time. These colours are pulled from a palette, which is a defined set of 16 colours. The transparency can also be altered by adjusting the contrast level. Subtitles are handled by the same means. Interestingly, they’re graphics too – not text. Douglas Dixon’s DVD Authoring Terminology has a nice overview of many of the finer technical details.

Within the DVD Virtual Machine ( DVD VM), there are sixteen General Parameter Registers ( GPRM s). These are variables which hold 16-bit integers, allowing a tiny bit of memory for some details, such as chosen settings. Beside the GPRM s are twenty-four System Parameter Registers ( SPRM s), which are read-only and are managed by the DVD player itself, storing the device-level details. The DVD VM Interaction Machine , which allows handling what happens on user interaction, is extremely basic, making the ability for people to make such interesting, expressive, and complex menus very impressive. DVD games 1 particularly exploited all the memory and interaction functionality to the fullest extents possible.

Menus often feature looping clips and audio that don’t quite seamlessly repeat or have abrupt endings, which are the subject of much nostalgic reminiscing, with many stories online of people waking in early hours of the morning to find a DVD menu on loop.

Some publishers had a degree of consistency across their DVD catalogue. One DVD menu feature ingrained deep into the back of my mind is Disney’s FastPlay . Designed to make their DVD s more accessible, especially to children potentially unable to manage the remote, it automatically starts playing the disc’s content without need for viewer interaction. In function, this really means that it often plays trailers before the feature presentation, leading many viewers to avoid it.

A DVD and the logo 'Disney's FastPlay' on a blue background. At the bottom are two buttons, one reading 'FastPlay' and the other reading 'Main Menu'.
Disney’s FastPlay screen which would appear upon loading a disc.

FastPlay supporting DVD s open with Tinkerbell flying onto the screen while a voiceover states:

This Disney DVD is enhanced with Disney’s FastPlay. Your movie and a selection of bonus features will begin automatically. To bypass FastPlay, select the ‘Main Menu’ button at anytime. FastPlay will begin in a moment!

Debuting at the same time in 2004, many Disney DVD s often also feature what they call EasyFind menus , which provide a consistent set of options with a consistent set of accompanying graphics for ease of use.

More modern DVD releases often forgo additional special features. Even standards like most setup options and scene/chapter selection are often absent as discs are spat out quickly, crammed into a template. Special features are reserved for the more expensive Blu-ray releases.

Scooby-Doo 2: Monsters Unleashed had a very fun menu. The main screen showed Scooby Doo and various monsters messing about in an old mining town, and when selecting a menu item, it would play a transition into another place from the film with further animations of Scooby-Doo fooling around. Each section had full custom 3D animations, and two games playable directly on the DVD player were included on the disc.

The first, Behind-the-Mystery Mystery: The Mystery of the Missing Pants , could be started in a special feature and then required you to navigate through the DVD ’s menu to find an icon of pants to continue along the story. The next, much more complete game was The Scooby-Doo Monsters Unleashed Challenge , which had you as the player driving around in the Mystery Machine to various locations from the film, navigating through the locations, and collecting clues that would help unravel the mystery.

A creepy old manor with green walls. A red, grid carpet stretches the floor, and beams of light illuminate specific squares.
A part of the Monsters Unleashed Challenge where you must pick the correct path across the floor to navigate forward. Stepping on a trapped tile shows a failure clip from the film.

Due to the limitations of DVD s, the entire game is relatively simple in terms of mechanics; however, it is obvious a lot of effort was put into it to make it feel comprehensive, and it really plays to the strengths of the medium with lots of little clips and sections. One section has the player figuring out the path over a trapped floor, and another involves attacking skeletons in a warehouse while not hitting Scooby, just like Whack-A-Mole.

Scooby-Doo 2 also came with a teaser trailer for another movie with a fantastic DVD menu: Harry Potter and the Prisoner of Azkaban . After a little opener showing some clips from the film, the Prisoner of Azkaban’s DVD placed you on the Knight Bus from the film, zooming through the streets of London while the shrunken head quips. Different menus on the DVD stayed true to the theme, with the scene selection being themed after The Daily Prophet newspaper.

Shrek 2’s original menu is memorable primarily for the main Brady Bunch-esque screen. It features the film’s main characters all quibbling at each other (and particularly with Donkey). The disc is also packed with content, with the ability to view a lot of art, read about the cast and details about the film, listen to music, explore an interactive map, and play multiple games ( Far Far Away Idol , Find Puss In Boots , and Save Fiona! ), among other things. It is extremely full of things to look through and poke at.

A bright green background with windows containing various characters for the film representing each menu item. Donkey is in the middle, and most of the characters look displeased with him.
Shrek 2 DVD main menu.

The Rocky Horror Picture Show DVD opens with the iconic lips welcoming you to the DVD . After which you’re presented with the main menu, where a disembodied pair of legs wearing heels and fishnets walks in, kicking around one of the menu items, which begins flipped the wrong way around. The extra features are numerous and play into Rocky Horror’s cult status. Some menu options are accompanied by a large switch which animates when flicked. Throughout much of the menu the lips continue speaking while songs from the film play in the background. The 16:9-only portion of the screen is occupied by red curtains, which slide in and out again when ‘Play Movie’ is selected.

Red lips to the top left with some legs underneath it. To the right are four menu items: 'Play', 'Chapter Selection', 'Language Selection', and 'Special Features'. Red curtains are on each side of the screen.
Rocky Horror Picture Show DVD main menu.

When inserted, Wayne’s World’s DVD menu first shows static before simulating switching through multiple channels and then landing on a channel guide, with plenty of spoof material like fake adverts. In addition to various options like scene selection and subtitle configuration appearing like upcoming television shows across different channels, there are also listings for tonnes of other shows and films which can be scrolled through like a real cable set top box. It is a brilliantly fun interface.

Chitty Chitty Bang Bang has a 3D render of the titular fuel-burning oracle flying through the clouds, with menus superimposed onto it, and Thunderbirds (2004) opens with clips from the film before dropping you into Thunderbird 2’s cockpit with a variety of controls as you fly around, and a voiceover speaks to you while you’re presented with all sorts of information. You could even switch which craft you’re piloting.

DVD releases of Doctor Who following the 2005 revival also had extremely fun interfaces. Many of the DVD releases of both Classic Who and New Who had many hidden secrets and additions included . Different releases vary, but many of the earlier ones were set in the Tardis, with menu items presented on and around the console. Some showed the time vortex and time stream, while they began to simplify a bit during the Peter Capaldi era before slipping into more generic menus, as became common throughout the mid-2010s.

Left-aligned menu listing special features, with the Tardis in the background, overtaken by vines, while the time stream undulates unstably to the right.
Doctor Who Series 7 special features menu (disc 1).

In modern DVD releases, we rarely see any menus of note. DVD s are no longer the dominant format they once were, and companies rarely put effort into their presentation. Despite being a much more capable format from a technical perspective, with high-resolution media, menu layers, everything offered by Blu-ray Disc Java (BD-J) and more, Blu-rays unfortunately very rarely see impressive menu presentations. Modern DVD s and Blu-ray menus alike are often little more than an image or video with a generic menu atop it.

It is understandable. Physical media as a whole is less popular with the mass adoption of streaming services; however, it is a shame to see that the creativity and excitement of the media viewing experience provided by menus replaced by the sterile, generic, one-size-fits-all interfaces of online platforms. If curious, there are a great number of DVD menus to be perused at dvdmoviemenus.com .

  1. I speak not of games simply released using the DVD medium, like console or PC releases, but of actual DVD games, which were standard DVD Video discs with games implemented the same as any menu. The most famous of these games is perhaps Scene It? ↩

Extending Guix

Lobsters
guix.gnu.org
2026-10-08 09:20:22
Comments...
Original Article

Extending Guix

Sergio Pastor Pérez — October 8, 2026

Guix is all about empowering people, so it should come as no surprise that one can extend it with new guix commands . You can show the commands available in your current Guix through the help command:

$ guix help

If you are using a recent Guix, there are a number of extensions at your disposal, they are available as individual packages, and as a meta-package providing a collection of extensions . Try them out with:

$ guix shell guix guile guix-extension-collection

I'm adding the guix and guile packages to the shell because we want the different Guile and Guix search paths to be adjusted in the shell. To know more about why this is needed, read Search Paths .

You will notice that the help menu has been extended with information about the available extensions:

$ guix help

...

  extension commands
    explore   interactively explore a Guix System configuration
    removals  keep up to date with package removals
    compose   docker compose compatibility layer
    toys      Explore packages and services through REST API
    xsearch   search for packages using a fast Xapian cache

...

Since this blog post is called "Extending Guix", let's write an extension, shall we?

How does Guix locate extensions?

Guix locates extensions by looking up GUIX_EXTENSIONS_PATH . Recently Guix has introduced a new way of writing extensions. The old way would search extensions under /path/to/guix/extensions and the extensions modules would be named (guix extensions NAME) . The new schema expects extensions to be under /path/to/SCHEMA_VERSION ; the name of the module will still be (guix extensions NAME) .

The advantage of this new schema is the Guix can treat the extension module as a standard Guile module, meaning that the runtime is able to find the compiled .go file of the extension. The old schema was relaying on runtime evaluation; the load machinery was not handling compiled files. This has a considerable improvement on performance, so you are encouraged to update any old extension to the new schema.

Writing an extension

Enough introductions, let's write a basic extension.

The first step is to create the project structure. Remember that the extension machinery expects modules to be named (guix extensions NAME) .

We start by creating, in our project root, the directories for the extension.

$ mkdir -p guix/extensions

Now, we create the file guix/extensions/hello.scm with the following contents:

(define-module (guix extensions hello))

A blank canvas...

We import (guix scripts) to get the define-command macro. We declare it and export it so the extension machinery can find the command in the public interface of the module.

(define-module (guix extensions hello)
  #:use-module (guix scripts)
  #:export (guix-hello))

(define-command (guix-hello . args)
  (category extension)
  (synopsis "say hello")
  (display "hello, I'm a Guix extension!\n"))

With this, we already have a working Guix extension. We can run the extension like this from the root of the project.

$ GUIX_EXTENSIONS_PATH=$PWD guix hello
hello, I'm a Guix extension!

Since we would like our extension to be discoverable by users, we will add a help message which will make the extension display in the guix help menu.

We will use (srfi srfi-37) to write the option parser, and (guix ui) for the internationalized strings; you will see that I import these modules when I show you the complete extension. Let's focus on the option definitions:

(define (show-help)
  (display (G_ "Usage: guix hello\n"))
  (display (G_ "Just say hello, it's not that complicated.\n"))
  (display (G_ "
      --help             display this message"))
  (newline))

(define %options
  (list (option '(#\h "help") #f #f
                (lambda args
                  (leave-on-EPIPE (show-help))
                  (exit 0)))))

Since we are only handling the arguments for showing the help message, we just need to call the parser at the start of the command:

(define-command (guix-hello . args)
  (category extension)
  (synopsis "say hello")
  (parse-command-line args %options (list '()))
  (display "hello, I'm a Guix extension!\n"))

Here you have the complete extension module:

(define-module (guix extensions hello)
  #:use-module (guix scripts)
  #:use-module (guix ui)
  #:use-module (srfi srfi-37)
  #:export (guix-hello))

(define (show-help)
  (display (G_ "Usage: guix hello\n"))
  (display (G_ "Just say hello, it's not that complicated.\n"))
  (display (G_ "
      --help             display this message"))
  (newline))

(define %options
  (list (option '(#\h "help") #f #f
                (lambda args
                  (leave-on-EPIPE (show-help))
                  (exit 0)))))

(define-command (guix-hello . args)
  (category extension)
  (synopsis "say hello")
  (parse-command-line args %options (list '()))
  (display "hello, I'm a Guix extension!\n"))

With that, our extension will be present when we ask Guix for help:

$ GUIX_EXTENSIONS_PATH=$PWD guix help

...

  extension commands
    hello  say hello

It also takes a --help flag:

$ GUIX_EXTENSIONS_PATH=$PWD guix hello --help
Usage: guix hello
Just say hello, it's not that complicated.

      --help             display this message

Packaging a Guix extension

At the time of writing, we don't have a dedicated Guix build-system for extensions. Fortunately, the guile-build-system is close enough for this use case.

Let's make a package definition for our new hello extension that uses our local sources. Create a guix.scm file at the root of the project with the following contents:

(use-modules (gnu packages package-management)
             (guix build-system guile)
             (guix gexp)
             (guix git-download)
             (guix packages)
             ((guix licenses) #:prefix license:))

(define vcs-file?
  ;; Return true if the given file is under version control.
  (or
   (git-predicate
    (dirname (canonicalize-path
              (assq-ref (current-source-location) 'filename))))
   (const #t)))

(define-public guix-hello
  (package
    (name "guix-hello")
    (version "0.0.0-git")
    (source (local-file (assume-valid-file-name ".")
                        "pin-checkout"
                        #:recursive? #t
                        #:select? vcs-file?))
    (build-system guile-build-system)
    (arguments
     (list
      #:scheme-file-regexp
      #~(lambda (file stat)
          (and ((file-name-predicate #$default-scheme-file-regexp)
                file stat)
               (not ((file-name-predicate "^(guix|channels|manifest)\\.scm$")
                     file stat))))
      #:phases
      #~(modify-phases %standard-phases
          (add-after 'build 'move-to-extension-directory
            (lambda _
              (with-directory-excursion #$output
                (mkdir-p "share/guix/extensions/1.5/guix/extensions")
                (rename-file (string-append "share/guile/site/"
                                            (target-guile-effective-version)
                                            "/guix/extensions/hello.scm")
                             "share/guix/extensions/1.5/guix/extensions/hello.scm")))))))
    (native-inputs (list guix))
    (inputs (list (lookup-package-input guix "guile")))
    (home-page "https://codeberg.org/guix-extensions")
    (synopsis "Make Guix say hello")
    (description
     "This extension provides the @command{guix hello} command,
which makes Guix say hello.")
    (license license:gpl3+)))

guix-hello

We can test this new extension like this:

$ guix shell -CW -f guix.scm -- guix hello

The flags passed to guix shell are the following:

  • -C ( --container ): To prevent your environment from interfering.
  • -W ( --nesting ): To bring the current Guix you are using into the container so it can load the extension.

Since this example is using the new extension scheme, the guix command you are running must be at or newer than commit de069958fc .

Closing words

I hope you find this small introduction to Guix extensions useful and that you start to write your own Guix extensions.

I would like to encourage everyone reading this to submit their extensions to the guix-extensions Codeberg organization. The idea is to make this organization a central hub for everyone to participate in the development of useful extensions for the community.

Unless otherwise stated, blog posts on this site are copyrighted by their respective authors and published under the terms of the CC-BY-SA 4.0 license and those of the GNU Free Documentation License (version 1.3 or later, with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts).

Uranium crypto exchange hacker convicted for stealing $53 million

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 09:18:36
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]...
Original Article

Bitcoin cryptocurrency theft

A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021.

36-year-old Jonathan Spalletta (also known online as "Jspalletta" and "Cthulhon") surrendered to law enforcement on March 30 and was charged with computer fraud and money laundering.

According to court documents , Spalletta hacked Uranium (an automated market maker on Binance's BNB Chain) and stole nearly $53.3 million in cryptocurrency, forcing the company to shut down for lack of funds.

On April 8, 2021, during the first breach, he drained drained about $1.4 million out of Uranium's liquidity pool by exploiting a flaw in its smart contract code to issue zero-token withdrawal commands, which forced the exchange to pay rewards he wasn't entitled to.

Spalletta then extorted the crypto exchange into assigning a sham "bug bounty" of nearly $386,000 from the stolen funds to get the rest back.

Three weeks later, he hit Uranium again, exploiting a separate coding error that caused the exchange's transaction-verification logic to use 1,000 instead of 10,000 and allowed him to withdraw nearly 90% of the assets held in Uranium's liquidity pools while depositing effectively zero tokens.

This netted Spalletta about $53.3 million (most of Uranium's holdings) and forced the crypto exchange to shut down immediately. Next, Spalletta laundered the stolen cryptocurrency through the Tornado Cash cryptocurrency mixer and multiple decentralized exchanges.

Uranium Finance stolen funds
Tracing Uranium Finance stolen funds (TRM Labs)

The proceeds were spent buying 18 sealed packs of Alpha Booster Magic cards for around $1.5 million, a first-edition complete Pokémon base set for roughly $750,000, a "Black Lotus" Magic: The Gathering card for approximately $500,000, an ancient Roman coin commemorating Julius Caesar's assassination for over $601,000, among other items.

Law enforcement agents seized these collectibles from his residence in February 2025 and recovered roughly $31 million in cryptocurrency from crypto wallets linked to Spalletta.

Crypto fraud investigator ZachXBT first linked over 11,200 ETH withdrawn from Tornado Cash (worth $25 million at the time) to the Uranium hacker in December 2023.

"Spalletta's own words are indicative of his dangerously misguided indifference for his victims and the hardships he caused, saying: 'Crypto is just fake internet money anyway.' As Spalletta's many victims know, those words could not be further from the truth," U.S. Attorney Jamie McDonald said on Wednesday .

"Spalletta's crimes cost real people to lose real money—over $50 million dollars—and caused an entire crypto platform to collapse."

Spalletta now faces up to 10 years in prison for computer fraud and up to 20 years for money laundering.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

New CRAM method offers giant boost to compressed memory reads

Hacker News
www.tomshardware.com
2026-10-08 09:11:41
Comments...
Original Article

A new compression model, called CRAM, offers a different path to compression that avoids swap entirely by keeping the compressed data in memory, and it offers up to 452x the performance of ZRAM. I was a kid in the 1990s when the idea seemed so simple to me: I can use PKZIP to compress my files, so why can't we do that with RAM? Indeed, I am not a singular genius, and many other people had the same idea, so memory compression has been a feature of most operating systems for a long time. In Linux, the most popular options are zswap and ZRAM, but both of these options are fundamentally swap-layer features. CRAM is a new take that claims to boost performance tremendously.

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Security updates for Thursday

Linux Weekly News
lwn.net
2026-10-08 09:11:00
Security updates have been issued by AlmaLinux (bind, firefox, freerdp, ghostscript, glibc, kernel, kernel-rt, perl-DBI, python3.12, rust-rpm-sequoia, rust-sequoia-sq, rust-sequoia-sqv, and vim), Debian (gst-plugins-base1.0, python3.11, and xz-utils), Fedora (7zip, chromium, curl, docker-buildx, ker...
Original Article
Dist. ID Release Package Date
AlmaLinux ALSA-2026:75767 9 bind 2026-10-08
AlmaLinux ALSA-2026:69462 9 firefox 2026-10-07
AlmaLinux ALSA-2026:75570 10 freerdp 2026-10-07
AlmaLinux ALSA-2026:76877 8 ghostscript 2026-10-07
AlmaLinux ALSA-2026:76777 8 glibc 2026-10-07
AlmaLinux ALSA-2026:77498 8 kernel 2026-10-08
AlmaLinux ALSA-2026:77500 8 kernel-rt 2026-10-08
AlmaLinux ALSA-2026:76762 10 perl-DBI 2026-10-07
AlmaLinux ALSA-2026:77576 8 perl-DBI 2026-10-08
AlmaLinux ALSA-2026:77028 8 python3.12 2026-10-07
AlmaLinux ALSA-2026:76734 10 rust-rpm-sequoia 2026-10-07
AlmaLinux ALSA-2026:76733 9 rust-rpm-sequoia 2026-10-07
AlmaLinux ALSA-2026:76737 10 rust-sequoia-sq 2026-10-08
AlmaLinux ALSA-2026:76735 10 rust-sequoia-sqv 2026-10-07
AlmaLinux ALSA-2026:77359 8 vim 2026-10-08
AlmaLinux ALSA-2026:75768 9 vim 2026-10-07
Debian DLA-4828-1 LTS gst-plugins-base1.0 2026-10-08
Debian DLA-4827-1 LTS python3.11 2026-10-08
Debian DSA-6549-1 stable xz-utils 2026-10-07
Fedora FEDORA-2026-626a028878 F43 7zip 2026-10-08
Fedora FEDORA-2026-b92ecada92 F44 7zip 2026-10-08
Fedora FEDORA-2026-c2e8136fc5 F43 Lmod 2026-10-08
Fedora FEDORA-2026-969cb69eb4 F44 Lmod 2026-10-08
Fedora FEDORA-2026-02902c2fa0 F43 chromium 2026-10-08
Fedora FEDORA-2026-bcdfa4c7db F44 chromium 2026-10-08
Fedora FEDORA-2026-8efcd7a2a0 F44 curl 2026-10-08
Fedora FEDORA-2026-af9902ab5e F44 docker-buildx 2026-10-08
Fedora FEDORA-2026-666b555ae8 F44 kernel 2026-10-08
Fedora FEDORA-2026-51eb024b20 F43 sos 2026-10-08
Mageia MGASA-2026-0470 10 tesseract 2026-10-07
Oracle ELSA-2026-76763 OL8 dovecot 2026-10-07
Oracle ELSA-2026-76764 OL10 firefox 2026-10-07
Oracle ELSA-2026-76747 OL8 freerdp 2026-10-07
Oracle ELSA-2026-76755 OL9 freerdp 2026-10-08
Oracle ELSA-2026-75680 OL8 gd 2026-10-07
Oracle ELSA-2026-76877 OL8 ghostscript 2026-10-07
Oracle ELSA-2026-71602 OL10 kernel 2026-10-07
Oracle ELSA-2026-500375 OL7 kernel 2026-10-07
Oracle ELSA-2026-500375 OL8 kernel 2026-10-07
Oracle ELSA-2026-72468 OL8 kernel 2026-10-07
Oracle ELSA-2026-500377 OL8 kernel 2026-10-08
Oracle ELSA-2026-500375 OL8 kernel 2026-10-08
Oracle ELSA-2026-500377 OL9 kernel 2026-10-08
Oracle ELSA-2026-500374 OL9 kernel 2026-10-08
Oracle ELSA-2026-500377 OL9 kernel 2026-10-08
Oracle ELSA-2026-75582 OL8 librabbitmq 2026-10-07
Oracle ELSA-2026-76762 OL10 perl-DBI 2026-10-07
Oracle ELSA-2026-77028 OL8 python3.12 2026-10-08
Oracle ELSA-2026-76734 OL10 rust-rpm-sequoia 2026-10-07
Oracle ELSA-2026-76733 OL9 rust-rpm-sequoia 2026-10-08
Oracle ELSA-2026-76735 OL10 rust-sequoia-sqv 2026-10-07
Oracle ELSA-2026-67157-0 OL7 sg3_utils 2026-10-08
Oracle ELSA-2026-77359 OL8 vim 2026-10-08
Oracle ELSA-2026-66026-0 OL7 virtuoso-opensource 2026-10-08
Slackware SSA:2026-280-01 xorg-server 2026-10-07
SUSE openSUSE-SU-2026:11953-1 TW aliyun-cli 2026-10-07
SUSE openSUSE-SU-2026:11954-1 TW busybox 2026-10-07
SUSE openSUSE-SU-2026:11955-1 TW cadvisor 2026-10-07
SUSE openSUSE-SU-2026:11956-1 TW chromedriver 2026-10-07
SUSE openSUSE-SU-2026:22023-1 oS16.0 chromium 2026-10-07
SUSE openSUSE-SU-2026:11960-1 TW crane 2026-10-07
SUSE openSUSE-SU-2026:11957-1 TW distribution-registry 2026-10-07
SUSE SUSE-SU-2026:4567-1 SLE12 fetchmail 2026-10-07
SUSE openSUSE-SU-2026:11958-1 TW fio 2026-10-07
SUSE openSUSE-SU-2026:11959-1 TW ghostscript 2026-10-07
SUSE openSUSE-SU-2026:22027-1 oS16.0 golang-github-prometheus-alertmanager 2026-10-07
SUSE openSUSE-SU-2026:11961-1 TW google-osconfig-agent 2026-10-07
SUSE openSUSE-SU-2026:22020-1 oS16.0 govulncheck-vulndb 2026-10-07
SUSE SUSE-SU-2026:4565-1 SLE12 libXtst 2026-10-07
SUSE SUSE-SU-2026:4566-1 SLE15 SLE5.3 SLE5.4 SLE5.5 SLE-m5.3 SLE-m5.4 SLE-m5.5 libXtst 2026-10-07
SUSE SUSE-SU-2026:4557-1 SLE15 oS15.4 libsoup 2026-10-07
SUSE SUSE-SU-2026:4558-1 SLE15 oS15.6 libsoup 2026-10-07
SUSE SUSE-SU-2026:24012-1 SLE16.0 openexr 2026-10-07
SUSE openSUSE-SU-2026:22026-1 oS16.0 prometheus-blackbox_exporter 2026-10-07
SUSE openSUSE-SU-2026:22028-1 oS16.0 python-fsspec 2026-10-07
SUSE SUSE-SU-2026:4568-1 SLE15 SLE5.3 SLE5.4 SLE5.5 SLE-m5.3 SLE-m5.4 SLE-m5.5 rpcbind 2026-10-07
SUSE SUSE-SU-2026:24015-1 SLE16.0 rsyslog 2026-10-07
SUSE SUSE-SU-2026:24014-1 SLE16.0 rustup 2026-10-07
SUSE SUSE-SU-2026:24013-1 SLE16.0 wireshark 2026-10-07
SUSE openSUSE-SU-2026:22022-1 oS16.0 wpa_supplicant 2026-10-07
SUSE openSUSE-SU-2026:11952-1 TW zcode 2026-10-07
Ubuntu USN-8901-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 erlang 2026-10-08
Ubuntu USN-8900-1 22.04 golang-golang-x-net 2026-10-07
Ubuntu USN-8896-1 16.04 18.04 20.04 22.04 24.04 26.04 gst-plugins-ugly1.0 2026-10-08
Ubuntu USN-8897-1 14.04 16.04 18.04 20.04 22.04 24.04 26.04 lxml 2026-10-08
Ubuntu USN-8894-1 22.04 24.04 26.04 poppler 2026-10-07
Ubuntu USN-8895-1 22.04 24.04 26.04 sudo 2026-10-07

Ending the Casuarina Linux Experiment

Lobsters
casuarina.org
2026-10-08 09:08:00
Comments...
Original Article
Timed out getting readerview for https://casuarina.org/news/ending-the-casuarina-linux-experiment/

Show HN: Wordminos – Crosswords Meet Dominos

Hacker News
wordminos.com
2026-10-08 08:56:46
Comments...

Afghanistan, 25 Years Later: Journalist Emran Feroz on the Legacy of "America's Longest War"

Democracy Now!
www.democracynow.org
2026-10-08 08:51:39
This week marks 25 years since the U.S.-led invasion of Afghanistan, the beginning of what would become the longest war in U.S. history. After installing a pro-Western government in Kabul in December 2001, U.S. and other NATO troops would remain in the country for the next two decades battling a stu...
Original Article

This week marks 25 years since the U.S.-led invasion of Afghanistan, the beginning of what would become the longest war in U.S. history. After installing a pro-Western government in Kabul in December 2001, U.S. and other NATO troops would remain in the country for the next two decades battling a stubborn insurgency — until a chaotic U.S. withdrawal in August 2021 that saw the Taliban return to power.

“During the 20 years of America’s longest war in Afghanistan, we could clearly see that failure was coming,” says journalist Emran Feroz, just back from a month of reporting in Afghanistan. He says the relative economic and political gains under the Western-backed government were undercut by widespread corruption and violence, particularly in rural Afghanistan. “You had torture prisons next to Burger King and KFC and Starbucks.”


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Telnet BBS Guide

Hacker News
www.telnetbbsguide.com
2026-10-08 08:28:35
Comments...
Original Article
Timed out getting readerview for https://www.telnetbbsguide.com/

"The AI Doc: Or How I Became an Apocaloptimist": Daniel Roher, Tristan Harris Discuss New Film

Democracy Now!
www.democracynow.org
2026-10-08 08:25:57
As the development of artificial intelligence accelerates, more voices inside and outside the industry are warning that the technology poses major risks to humanity. The new film, The AI Doc: Or How I Became an Apocaloptimist, features interviews with leading AI executives, researchers, as well as c...
Original Article

As the development of artificial intelligence accelerates, more voices inside and outside the industry are warning that the technology poses major risks to humanity. The new film, The AI Doc: Or How I Became an Apocaloptimist , features interviews with leading AI executives, researchers, as well as critics, who all voice similar concerns. Since the film’s release earlier this year, a number of AI-driven hacks and other incidents have further alarmed people studying this topic.

“I’m really scared, and I’m struggling in my own life to sort of compartmentalize what I learned, what I know, what I understand, what I see happening around me,” says filmmaker Daniel Roher. He began work on The AI Doc as he was about to become a father and wondered what kind of world his children would inherit.

We also speak with Tristan Harris, co-founder of the Center for Humane Technology, a leading AI safety advocate who is featured in the film. He says part of the risk of AI development is that it has the logic of an “arms race,” with companies and countries racing to gain supremacy rather than building guardrails.

“The race changes as soon as the fear of all of us losing becomes bigger than the fear of me losing to you,” he says.



Guests
  • Tristan Harris

    co-founder of the Center for Humane Technology and co-host of the Your Undivided Attention podcast.


Please check back later for full transcript.

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Thinking will become a hobby

Lobsters
www.spinellis.gr
2026-10-08 08:23:28
Comments...
Original Article

These lines are very difficult for me to write because I feel like digging my own grave. AI systems are improving by leaps and bounds. From the early 2022 fumbling release of ChatGPT, which couldn’t correctly count the number of a’s in my name (it claimed two), we reached OpenAI’s release of math papers where an internal AI model solved many hundreds of previously open math problems. Aside from philosophical arguments, practical claims regarding the superiority of human thought, on grounds such as hallucinations or bias, increasingly appear to me like rearguard defence. For the bulk of today’s cognitive work, the writing’s on the wall: AI will take over.

The three factors driving AI’s dominance in the modern work environment are better performance, lower cost, and higher availability. The performance of AI models is rising spectacularly on all fronts: perception, knowledge processing and creation, reasoning, judgement, and autonomous action. In parallel, human proficiency in key information-processing skills, low on average among adults , is even declining among students . Consequently, AI systems are performing better than humans in ever-wider range of tasks.

AI’s cost is also falling due to huge investments and scientific progress. Successive generations of AI models offer superior performance at lower cost, with older models retained only for backward compatibility. As a result, it is making financial sense to replace or augment human labour with AI systems across an increasingly broad range of activities.

Finally, and most obviously, AI systems can operate around the clock, without the need for rest or breaks. They can also help alleviate labour shortages arising from demographic trends or skills gaps. Meanwhile, trillions of dollars in projected data centre investment through 2030 are set to bring vast additional AI processing capacity online.

As happened in past technological revolutions, there will undoubtedly be fierce resistance to the replacement of cognitive work with AI. This time it will be fiercer because, unlike previous revolutions, which transformed manual labour, AI challenges knowledge workers, whose specialised expertise, control over information, and decision-making authority afford them greater economic and organisational power. Governments will try to clip AI’s wings through regulation and taxation. Such actions didn’t quell past revolutions so there’s little reason to believe they’ll work now.

So what’s the fate of human thought? My take is that cognitive work will diminish. Thought will increasingly become a leisure pursuit, as hunting did following animal domestication, calligraphy after typography, woodworking after industrialisation, and horse riding after motorisation. Machines transformed much of physical activity from necessity into choice; similarly, AI will decouple human thinking from its economic purpose.

I’ll end with my thoughts on how to prepare for and live through this transition. My take is that building this AI-driven world, riding through the bumps along the road, and preparing to live a fulfilling and satisfying life in an environment where AI dominates cognitive work will be hugely demanding, stressful, and intellectually challenging. Such is the nature of revolutions. Consequently, we must keep pace with and capitalise on AI’s advances; be flexible, adaptable, and resilient; and build a purposeful and rewarding life beyond work. My challenge ahead is to move from making a living by thinking, to making thinking part of a life worth living.

Comments Post Toot!

`specialArgs` considered harmful

Lobsters
ysun.co
2026-10-08 08:16:07
Comments...
Original Article
· 2091 words · 10 min read

I'm writing this on my flight from KRK to LYS after Wizz Air fucked me in the ass... I briefly went over this yesterday (and the day before) at NixCon 2026 in my lightning talks (a normal one and a spontaneous one). The purpose of this article is to better articulate myself in addition to my very terrible verbal explanation. This is also related.

I read a lot of code (especially Nix), and I've helped quite some people getting their first NixOS installation working. Normally, users want unified theming across login manager, desktop environment, lock screen, etc., and they would opt to pin a styling dependency in inputs .

To pass them around in NixOS/nix-darwin/home-manager eval context, inputs are usually injected into specialArgs (or extraSpecialArgs , or similar) so that all modules have an inputs argument where additional options can be used (you also get inputs.self fixed point ofc).

Once a config repo gets big enough (10+ machines or some hosts are shared), specialArgs are not only used to pass inputs around module eval context, e.g. custom helper functions, static data, and maybe some other less common arguments are injected as well, making the modules unshareable (or at least making it hard to copy-pasta).

specialArgs is not portable

For example (you can copy the code below to a throwaway directory and try it out):

# flake.nix
{
  inputs.nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";

  outputs =
    inputs@{ self, nixpkgs }:
    {
      nixosModules.version = { inputs, ... }: {
        # DO NOT DO THIS THIS IS JUST AN EXAMPLE
        # read `system.stateVersion` docs very carefully
        system.stateVersion = with inputs.nixpkgs.lib; versions.majorMinor version;
      };

      nixosConfigurations.works = nixpkgs.lib.nixosSystem {
        system = "aarch64-linux";
        specialArgs = { inherit inputs; };
        modules = [ self.nixosModules.version ];
      };

      nixosConfigurations.breaks = nixpkgs.lib.nixosSystem {
        system = "aarch64-linux";
        modules = [ self.nixosModules.version ];
      };
    };
}

You'll get:

$ nix eval --raw .#nixosConfigurations.works.config.system.stateVersion
26.11
$ nix eval --raw .#nixosConfigurations.breaks.config.system.stateVersion
error:
      ...
      ... while evaluating the module argument `inputs' in ":anon-2117:anon-1":
      ... noting that argument `inputs` is not externally provided, so querying `_module.args` instead, requiring `config`
       (stack trace truncated; use '--show-trace' to show the full, detailed trace)
       error: attribute 'inputs' missing

Same idea applies to other arbitrary shareable modules.

This is one of the most common issues with the current "Nix Flakes" ecosystem. Now maybe you are convinced using specialArgs is a bad idea but how can we address this?

"Curried modules"?

There are sooooo many ways to approach this, but the general idea is to apply the special module arguments before lib.evalModules consumes the module implementation.

For example:

{
  inputs.nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";

  outputs =
    inputs@{ self, nixpkgs }:
    {
      nixosModules.version =
        (
          { inputs, ... }: # special args
          { ... }: # normal NixOS module args
          {
            # actual implementation
            system.stateVersion = with inputs.nixpkgs.lib; versions.majorMinor version;
          }
        )
          { inherit inputs; }; # consume the first argument

      nixosConfigurations.works = nixpkgs.lib.nixosSystem {
        system = "aarch64-linux";
        specialArgs = { inherit inputs; };
        modules = [ self.nixosModules.version ];
      };

      nixosConfigurations.breaks = nixpkgs.lib.nixosSystem {
        system = "aarch64-linux";
        modules = [ self.nixosModules.version ];
      };
    };
}

Yeah now both eval commands above work. But yall will most definitely argue this shit is too ugly blah blah blah.

I thought so too, maybe 2 years ago? I addressed it.

To make it "look prettier", yall should first understand how/why modules computed with lib.evalModules can either have 0 arguments (plain attrset) or 1 argument ( { config, options, pkgs, lib, ... } and some other less used named args):

# nixpkgs/lib/modules.nix (2026-09-27) under `evalModules` implementation

# This function takes an empty attrset as an argument.
# It could theoretically be replaced with its body,
# but such a binding is avoided to allow for earlier garbage collection.
doCollect =
  { }:
  collectModules class (specialArgs.modulesPath or "") (regularModules ++ [ internalModule ]) (
    { /* truncated */ }
    // specialArgs
  );

# collectModules :: (class: String) -> (modulesPath: String) -> (modules: [ Module ]) -> (args: Attrs) -> ModulesTree
#
# Collects all modules recursively through `import` statements, filtering out
# all modules in disabledModules.
collectModules =
  class:
  let
    # Like unifyModuleSyntax, but also imports paths and calls functions if necessary
    loadModule =
      args: fallbackFile: fallbackKey: m:
      if isFunction m then
        unifyModuleSyntax fallbackFile fallbackKey (applyModuleArgs fallbackKey m args)
      else if isAttrs m then
        if m._type or "module" == "module" then
          unifyModuleSyntax fallbackFile fallbackKey m
        else if m._type == "if" || m._type == "override" then
          loadModule args fallbackFile fallbackKey { config = m; }
        else
          throw ... # truncated
      else if isList m then
        ... # truncated
      else
        unifyModuleSyntax (toString m) (toString m) (
          applyModuleArgsIfFunction (toString m) (import m) args
        );
    ... # truncated
  ... # mostly related to filtering disabled modules, sanity checks, and graph construction

loadModule calls a module in with "function shape" (again, it should look something like { lib, ... }: { ... } ), through applyModuleArgs with args , which contains standard arguments ( lib , config , options , ...) merged with user specified specialArgs .

If the module is a plain attrset, it will be used as is.

Very informally, the invariant is that, whatever passed to modules list parameter to lib.evalModules has to be a "module". Anything that happened to the "module" shaped file or lambda before lib.evalModules is invisible to the module evaluation context. In this sense, a curried module is nothing more than a function we've already called.

applyModuleArgs is also where the error in the first example comes from:

# nixpkgs/lib/modules.nix (2026-10-07) under `applyModuleArgs`
extraArgs = mapAttrs (
  name: _:
  addErrorContext ''while evaluating the module argument `${name}' in "${key}":'' (
    args.${name} or (addErrorContext
      "noting that argument `${name}` is not externally provided, so querying `_module.args` instead, requiring `config`"
      config._module.args.${name}
    )
  )
) (functionArgs f);

Every argument in the function's pattern ( functionArgs f ) is looked up in args first (which is where specialArgs is injected into) and then in config._module.args . A module that asks for inputs in args will only works if whoever coded it (or downstream users) put inputs in one of the two.

importApply

Moving the curried module to a file and calling import ./version.nix { inherit inputs; } will works as well, but error messages lose the file location, since import only returns the expression. In nixpkgs, we've had lib.modules.importApply to solve this "problem" since nixpkgs#230588 (also in flake-parts ).

# version.nix
{ inputs }: # special args
{ ... }: # normal NixOS module args
{
  system.stateVersion = with inputs.nixpkgs.lib; versions.majorMinor version;
}
# flake.nix
{
  inputs.nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";

  outputs =
    inputs@{ self, nixpkgs }:
    {
      nixosModules.version = nixpkgs.lib.modules.importApply ./version.nix { inherit inputs; };

      nixosConfigurations.works = nixpkgs.lib.nixosSystem {
        system = "aarch64-linux";
        modules = [ self.nixosModules.version ];
      };
    };
}

Very briefly, importApply imports the module, applies the user passed arguments, and wraps the result so errors point at version.nix .

importApplyWithArgs

I don't want to write that call for every module in my config, so my loader scans every file under a module directory with importApplyWithArgs and invoke it with { inherit inputs lib; } , where lib is my extended nixpkgs.lib (see this ).

importApplyWithArgs inspects the outer arguments of each file before module system computation:

  • When the pattern (the first argument of my module implementation files) names one of the static arguments, and the static arguments cover every argument in it without a default, the file is applied, e.g. { inputs, lib, ... }: { config, ... }: { ... } .
  • A non-pattern lambda ( args: ... ) is probed with f { } and applied if that returns another function.
  • Anything else, a plain attrset or a normal { config, lib, pkgs, ... }: module, passes through untouched and inherits the arguments from the module system.

This means external consumers (like whoever is mentally unstable enough to use my code) of these modules are never forced to provide arguments they do not define (the injection is structurally invisible to the module system as discussed above).

Using a pattern like this would also solves the same problem as "dendritic pattern" (declaring everything as flake-parts modules) without losing the structural scoping that the module system provides (thanks Matt !).

Deduplication

The module system collects each key once. A module imported by path gets the path as its key, which is why importing ./foo.nix twice is harmless and disabledModules = [ ./foo.nix ] would work. THIS IS VERY IMPORTANT, note that a function or an attrset will get an anonymous key, and the same value imported twice becomes two modules:

nix-repl> :lf nixpkgs
nix-repl> m = { lib, ... }: { options.b = lib.mkOption { default = "x"; }; }
nix-repl> :p (lib.evalModules { modules = [ m m ]; }).config
error:
       ...
       error: The option `b' in `<unknown-file>' is already declared in `<unknown-file>'.
nix-repl> :p (lib.evalModules { modules = [ { key = "m"; imports = [ m ]; } { key = "m"; imports = [ m ]; } ]; }).config
{ b = "x"; }

In setDefaultModuleLocation (which importApply uses), it sets _file but not key , which leaves every curried module anonymous. Imported twice it is declared twice, and disabledModules cannot name it. Well, this is very bad as you cal already tell from the above REPL snippet...

# https://github.com/stepbrobd/inc/commit/7170c5279142d3bc6ed1c524e93effe132a55ab3
{
  # was using https://noogle.dev/f/lib/setDefaultModuleLocation
  # but the helper function does not set `key` which breaks deduplication
  key = toString modulePath;

  _file = modulePath;
  imports = [ (if argUsed then f staticArgs else f) ];
}

The foot gun I shot myself with was that, the module system keeps the first module with a given key and never reads the rest:

nix-repl> decl = { lib, ... }: { options.a = lib.mkOption { type = lib.types.anything; }; }
nix-repl> :p (lib.evalModules { modules = [ decl { key = "b"; a = "smth"; } { key = "c"; a = "aaaa"; } ]; }).config
error:
       ...
       error: The option `a' has conflicting definition values:
       - In `<unknown-file>': "aaaa"
       - In `<unknown-file>': "smth"
       Use `lib.mkForce value` or `lib.mkDefault value` to change the priority on any of these definitions.
nix-repl> :p (lib.evalModules { modules = [ decl { key = "b"; a = "smth"; } { key = "b"; a = "aaaa"; } ]; }).config
{ a = "smth"; }

This is probably why lib.modules.importApply leaves key unset on purpose? If one file applied with different arguments they will be two distinct different modules, and keying both by path would silently drop one of them. In my config however every file goes through modulesFor with the same { inherit inputs lib; } , so in my specific use case the path is enough. If you apply one file with different arguments, DO NOT COPY THIS!

Bonus: _module.args.* ?

The other way to give modules an argument is _module.args , which is a normal option. It works fine for anything in a module body:

nix-repl> use = { inputs, lib, ... }: { options.v = lib.mkOption { default = inputs.x; }; }
nix-repl> :p (lib.evalModules { modules = [ use { _module.args.inputs.x = 1; } ]; }).config
{ v = 1; }

But this might cause issue in some cases as well. Reading an option needs config , and config needs every module's imports first, which means pulling a module out of inputs with it will cause infinite recursion.

nix-repl> imp = { inputs, ... }: { imports = [ inputs.dep ]; }
nix-repl> :p (lib.evalModules { modules = [ imp { _module.args.inputs.dep = { }; } ]; }).config
error:
       ...
       ... if you get an infinite recursion here, you probably reference `config` in `imports`. If you are trying to achieve a conditional import behavior dependent on `config`, consider importing unconditionally, and using `mkEnableOption` and `mkIf` to control its effect.
       (stack trace truncated; use '--show-trace' to show the full, detailed trace)
       error: infinite recursion encountered
nix-repl> :p (lib.evalModules { modules = [ imp ]; specialArgs.inputs.dep = { }; }).config
{ }

Do note that shared module that sets _module.args.inputs for itself collides with every other module doing the same, even with an identical value, since the option type is lazyAttrsOf raw :

nix-repl> :p (lib.evalModules { modules = [ use { _module.args.inputs.x = 1; } { _module.args.inputs.x = 1; } ]; }).config
error:
       ...
       error: The option `_module.args.inputs' is defined multiple times while it's expected to be unique.

Even though lib.mkForce and friends on one of them will make the error go away but by forcefully overriding inputs for every module... bruh...

"She Put Her Body on the Line": Maricarmen, 87, Dies; Her Eviction Sparked Spain Housing Protests

Democracy Now!
www.democracynow.org
2026-10-08 08:14:03
The 87-year-old pensioner in Spain whose eviction from her lifelong home sparked nationwide protests has died. María del Carmen Abascal, better known as Maricarmen, died on Wednesday just hours before she was set to sign a new rental agreement. She was forcibly removed from her Madrid apartment last...
Original Article

This is a rush transcript. Copy may not be in its final form.

NERMEEN SHAIKH : We begin today’s show in Spain. Maricarmen has died. She’s the 87-year-old woman whose eviction from her home of 70 years in Madrid sparked mass protests across Spain. In September, she was forcibly removed from her apartment on a stretcher after the private investment company which owns the building hiked her rent. After massive public outcry, the landlord had agreed to allow her back into her apartment. María Carmen Abascal died on Wednesday just hours before she was set to sign a new rental agreement.

On Wednesday, protesters in Madrid gathered to shout “murderers” outside the Madrid parliament.

PROTESTERS : ¡Asesinos! ¡Asesinos! ¡Asesinos! ¡Asesinos!

AMY GOODMAN : Protesters in Madrid, Spain, responded with sadness and anger over the death of 87-year-old Maricarmen.

DIANA : [translated] She’s a woman who died of heartbreak. They killed her through heartbreak. Taking an 87-year-old woman out of her home after she had lived in the same house for 70 years, that’s killing someone. A year ago, she had such strength, such life, such enthusiasm. It was a joy to see her. And the moment she left that apartment, or, rather, the moment they took her out of that apartment, she had to be hospitalized. And today, she is gone.

So, breaking the news has been horrific, because most people here weren’t following the news. They were preparing food, helping people on the streets. It has been very hard. There have been many people crying, so many people trying to stay strong. But you can’t, not at a moment like this. …

Amid all this grief, I think it serves perfectly to show why we’re here, because we’re trying to fight so that no one has to feel that grief and that emptiness of feeling alone, and above all, so that people remember her, so that they remember that she died alone out of her home.

NERMEEN SHAIKH : Protesters also rallied in Barcelona on Wednesday to decry the death of Maricarmen.

PROTESTER : [translated] Maricarmen has died. But she didn’t just die. She was killed. The state killed her. The companies killed her. And she has been our inspiration. She’s pushed us even more to mobilize, to organize, to fight against those in power.

AMY GOODMAN : Spanish Prime Minister Pedro Sánchez expressed his condolences, writing, quote, “All my love to Maricarmen’s family and loved ones. A hug also to all those who today feel this loss as our own. Rest in peace,” the prime minister wrote.

After public outcry, Sánchez dissolved the Spanish parliament Monday after lawmakers refused to pass a broad emergency housing law including an eviction moratorium. Sánchez called a snap election for November 29th.

In a moment, we’ll go to Spain for the latest. But first, let’s hear Maricarmen in her own words, speaking on September 27th, after she was evicted, from her hospital bed.

MARÍA DEL CARMEN ABASCAL MARTÍN: [translated] I want what happened to me to help ensure that it doesn’t happen to other people. I wanted to lead people to fight so the unfair laws that allowed for my eviction can be changed. That is why on Tuesday Maricarmen’s Law must be approved, so they can take a first step to end with this. …

I would like to be there with you, to be camping with you, fighting with you, but I don’t have that chance. That is why, from here, I’m asking you all to be brave. Fight to defend what is yours. Please be careful. Keep camping as long as your bodies allow and as long as you want to.

AMY GOODMAN : That was María del Carmen Abascal, known by the world now as Maricarmen, speaking from her hospital bed.

We go now to Spain, where we’re joined by the independent Spanish journalist and former Democracy Now! producer María Carrión.

María, if you can talk about the significance of the death of MariCarmen, the response in the streets, and now what could lead to the fall of the Spanish government?

MARÍA CARRIÓN: Hi, Amy, Nermeen. Thank you so much for having me on.

Yes, Maricarmen has become a symbol, and it’s hard to believe that so much has happened in the last two weeks, since she was evicted on the 23rd of September after living in her home for over 70 years, and after activists had blocked the entrance to her building and her apartment with their own bodies, and resulting in massive police brutality, and then the images that have gone around the world of Maricarmen being taken out on a stretcher and into an ambulance and going into a hospital, where she’s been able to survive only for two weeks.

And this shows that what happens to vulnerable people and young people and people of every walk of life here in Spain when the interest of speculators is more important to those who govern than the well-being of ordinary citizens like Maricarmen. She literally put her body on the line for seven years, which is how long she fought this eviction for. And we’ve seen how she’s deteriorated over time, especially the last couple of weeks, but, really, since she began fighting for her home.

And so, she’s become a symbol, through her own loss of life, of the most extreme example of what happens to families and to individuals here whose homes are bought maybe by, you know, vulture funds or investment funds, and, like what happened to her, rent gets hiked by as much as five times what you can pay. This actual investment fund bought the apartment for very low cost because Maricarmen was living in it. It was a rent-controlled home, and they knew it very well, and that’s why the price was fixed so low. And then they proceeded to look for the way that they could legally expel her from her home.

And this is happening all over Spain. The same day that Maricarmen was evicted from her apartment, a family with two little kids was also evicted in Madrid. It’s a daily occurrence. And the encampments that have been born out of this outcry for what happened to Maricarmen, the people who are living on the streets now in small tents and putting their own bodies on the line, under, you know, rain and inclement weather, are saying this is enough.

And this is what has led to the protests. This is what led, finally, the Spanish government, which is considered quite progressive, to approve these housing decrees that got voted down in parliament. This is what resulted in last weekend’s massive protests all over Spain, which led Pedro Sánchez, the prime minister, on Monday to dissolve parliament and call for snap elections, and then proceed to approve these two decrees by a different system that happens once we don’t have a working parliament. And who knows what will happen from here to the 29th of November?

NERMEEN SHAIKH : So, María, before we conclude, if you could tell us who in Spain, what — is it a regional government, the state government — that is, the national government — or a municipal government that’s responsible for housing legislation and implementation?

MARÍA CARRIÓN: All of the above. So, we have national housing laws, which have to be approved by parliament. And in this case, these emergency decrees were not. But also, regional governments have to implement what the national governmental laws are. And in the case of conservative regional governments, including Madrid’s, which is extremely right-wing, they have refused to implement a lot of these housing laws.

But anyone, as the activists say, could have stepped in to prevent Maricarmen and so many other people from being evicted. So it’s a collective responsibility, which is why the street has said, “Enough. Everyone needs to be held responsible.” And all of these housing decrees are not even enough, because none of them basically are structural and go to the heart of the matter, which is that rents have gone up 80% in the last 10 years, while salaries have not kept up. Young people cannot leave their homes. They cannot become independent or start families. And this is what people are trying to change from the street.

AMY GOODMAN : I want to end with Maricarmen in her own words, speaking in May.

MARÍA DEL CARMEN ABASCAL MARTÍN: [translated] I’m 87 years old. I live on my own. I don’t have a family. And I have been living for 70 years in that house. A vulture fund bought it at the same price I would have been able to buy it. And in 2021, they took me to court because I have an old, lifelong rental contract. They tried to evict me in October 2025, and they stopped it. Now they will try to evict me on June 3rd. …

This government must understand people have the right to have a home, and they cannot evict people so vulture funds become rich without working.

AMY GOODMAN : That was Maricarmen speaking in May. She died on Wednesday. We thank María Carrión, independent journalist, joining us from Spain. And we will continue to cover this issue tomorrow on Democracy Now! Today, later tonight, there is a major march planned from the main plaza, where the encampments have been set up, to the apartment building where Maricarmen lived for over 70 years and was taken out by stretcher in her eviction, dying in the hospital on Wednesday.

Coming up, The AI Doc: Or How I Became an Apocaloptimist . Stay with us.

[break]

AMY GOODMAN : Patti Smith and Michael Stipe singing Patti’s iconic “People Have the Power” at Democracy Now! ’s anniversary .

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

Microsoft Teams to get support for third-party deepfake detection tools

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 08:08:16
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...]...
Original Article

Microsoft Teams

Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings.

According to new entries on the Microsoft 365 Roadmap, both changes are now in development and will reach general availability in November after a worldwide rollout.

Once available, Microsoft says it will provide Teams integration and experiences to surface and act on deepfake detection signals triggered by supported providers.

"Organizations can enhance meeting security with synthetic audio and video detection solutions provided by certified third-party providers," Microsoft said .

"Third-party detection solutions analyze meeting media for signs of synthetic or manipulated audio and video and send detection signals to Teams, enabling integrated in-meeting experiences and controls."

Teams will also let users detect deceptive meeting organizers and participants through a new impersonation protection security feature.

"When Teams detects a potential impersonation attempt, it surfaces warnings and risk indicators to help users recognize suspicious identities and make more informed decisions when joining or participating in a meeting," the company added .

These changes are part of a broader move to boost security for Teams users, with Microsoft also announcing in December that admins would be able to lock external users via the Defender portal starting in January to thwart cybercrime groups (including ransomware gangs ) abusing Teams in social engineering attacks targeting their victims' employees.

Last month, it added that Teams will blur QR codes sent by external senders to provide additional protection against phishing and fraud attempts.

Microsoft also began rolling out a new Teams meeting protection policy in August that lets admins ​​​​​​ block all identified external bots automatically from joining meetings.

More recently, in September, it also announced that it will let users report suspicious guest invitations directly from Teams starting in November to help security teams identify and block phishing attempts and other attacks abusing guest invitations.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

I gave Opus 5.5 one prompt and six hours to visualize Invisible Cities

Hacker News
quesma.com
2026-10-08 08:00:20
Comments...
Original Article

GPT-6 Astra was a jump when it comes to puzzles . Claude Opus 5.5 is a jump when it comes to design.

Vibe designing

Even local models can make a competent landing page for a shop . Doing interactive visualization is a different tier. Since I am into creating data visualizations and explorable explanations , LLMs were both a blessing and a curse.

The Tree of 'tree'

The Tree of ‘tree’ , on Proto-Indo-European etymology, with Claude Opus 4.8. The first draft was surprisingly good, but then came a lot of frustration: removing AI slop and fixing visual overlaps.

Genetic Distance Map

Genetic Distance Map with Claude Fable 5.1, which worked well with data analysis and implementation, but needed a bit of hand-holding to make the design good.

Then for a moment I was happy-ish with GPT-6 Astra. My subjective experience was that it is a bit better than Fable 5.1 at a general overview, following intentions behind prompts, and checking that it all works correctly.

Then there was the Opus 5.5 moment for AI-assisted design. I saw an optical explorable explanation:

Lens lab by Opus 5.5: a 3D camera lens on an optical bench, showing the plane of focus

“I asked Opus 5.5 to explain camera focus by building an interactive lens lab. Here’s what it came up with after 1 hour 26 minutes in one shot, $25.66 API cost.” – Ryan Sael on X , interactive

One may argue that it is still “too rich”, and has no sense of minimalism. But still, wow! I was still in disbelief. Was this really its consistent quality for a one-shot experiment?

Instead of my beloved optics , I went for something different.

Invisible Cities

What’s a good prompt? Well, I went with the beautiful urbanistic poetry of Invisible Cities by Italo Calvino, presenting 55 imaginative cities, each one an emotion or state of mind, expressed in its architecture and in how people behave.

When a man rides a long time through wild regions he feels the desire for a city. Finally he comes to Isidora, a city where the buildings have spiral staircases encrusted with spiral seashells, where perfect telescopes and violins are made, where the foreigner hesitating between two women always encounters a third, where cockfights degenerate into bloody brawls among the bettors.

In 2019, I had a small project of generating cities for a storytelling performance , using the frontier model of the time, GPT-2. With new models, capabilities change drastically. So I used the following prompt:

Make a three.js (pnpm) visualization of all Invisible Cities by Italo Calvino. Don’t ask questions, it is a one-shot task. You have 6h of work, use it until it becomes a masterpiece.

GPT-6 Astra in Codex

I gave this prompt to GPT-6 Astra… and it worked, end-to-end.

Invisible Cities by GPT-6 Astra: Isidora as a spiral tower on a pale atlas page

GPT-6 Astra ( interactive , code ): 53 minutes at medium effort, about $10 in API tokens.

Some AI design slop, with many concepts and comments added, without checking whether they are actually needed, or just add visual noise. Some Captain Obvious statements that would work for accessibility, but not as something to be shown verbatim.

Curiously, it seemed to pick up the Claude visualization style: beige background, numbers like 05 . Still, I wouldn’t have expected earlier models to get anywhere near this.

Claude Opus 5.5 in Claude Code

Then I gave the same prompt to Claude Opus 5.5. It claimed:

I used roughly half of the six hours. The remaining polish has diminishing returns, but I can do another round if you want.

In fact it used only 1 hour 25 minutes, despite my direct instruction; though you can argue that it used agentic time dilation: 6 subagents, running in parallel, added up to about 7 agent-hours. I wanted to scold Opus 5.5 for finishing early, but then peeked at the result.

Invisible Cities by Claude Opus 5.5: Isidora as a lit 3D city at night

Claude Opus 5.5 ( interactive , code ): 1 hour 25 minutes with 6 subagents in parallel, about $74 in API tokens.

And I’m mesmerized! See it for yourself . Sure, it might (and should) have used all the time, but even at this stage it was “wow!”. If this is the actual ceiling, it is a high one. And I am sure the next models will go even higher.

What does it mean

I encourage you to use the same prompt with different models, or different harnesses.

We can expect AI to be a tool widely used (and burning a lot of token budget) in design.

I’m in awe, but I’m also asking myself: what is my place in creating interactive media?

Headlines for October 8, 2026

Democracy Now!
www.democracynow.org
2026-10-08 08:00:00
“Maricarmen,” Whose Eviction from Lifelong Home Sparked Housing Protests Across Spain, Dies at 87, France’s Education Minister Meets Student Leaders as Mass Protests Demand Education Reforms, WHO Demands Answers as Russia Denies Reports of Second Case of Plague, Protesters Repeated...
Original Article

Headlines October 08, 2026

Watch Headlines

“Maricarmen,” Whose Eviction from Lifelong Home Sparked Housing Protests Across Spain, Dies at 87

Oct 08, 2026

In Spain, Maricarmen has died. The 87-year-old woman’s eviction from her lifelong home sparked mass protests. Last month, she was forcibly removed on a stretcher after the private investment company which owns the building hiked her rent. After public outcry, the Spanish prime minister dissolved the parliament, which refused to pass a broad emergency housing law including an eviction moratorium, and called a snap election for November 29. The landlord eventually agreed to allow her back into her apartment, but she passed away in the hospital on Wednesday.

On Wednesday, Prime Minister Pedro Sánchez expressed his condolences to Maricarmen’s family and loved ones, writing, “A hug also to all those who today feel this loss as our own. Rest in peace.” This is a demonstrator in Madrid.

Diana : “Taking an 87-year-old woman out of her home after she had lived in the same house for 70 years, that’s killing someone. A year ago, she had such strength, such life, such enthusiasm. It was a joy to see her. And the moment she left that apartment, or, rather, the moment they took her out of that apartment, she had to be hospitalized. And today, she is gone.”

We’ll have more on this story later in the broadcast.

France’s Education Minister Meets Student Leaders as Mass Protests Demand Education Reforms

Oct 08, 2026

In France, hundreds of thousands of high school students and their supporters have taken to the streets for another day of demonstrations, protesting staff shortages, crowded classrooms and run-down buildings. Earlier today, France’s education minister invited student leaders to discuss their demands, pledging no further job cuts at schools.

WHO Demands Answers as Russia Denies Reports of Second Case of Plague

Oct 08, 2026

Russia’s public health agency is denying reports of a second case of pneumonic plague associated with a laboratory in southern Siberia. In a short statement, the agency said thousands of tests had turned up no evidence that a lab worker from the Irkutsk Anti-Plague Research Institute of Siberia transmitted an infection before she fell ill with pneumonia and died on October 2. According to some reports, the worker had broken a vial containing live plague bacteria. In the wake of her death, Russian officials ordered about 200 people to quarantine. On Wednesday, the head of the World Health Organization, Tedros Adhanom Ghebreyesus, said many questions remain unanswered.

Tedros Adhanom Ghebreyesus : ” WHO has requested further information on the lab tests conducted on the individual who died and the contacts, more detail on what prompted the public health measures, and details about the health status of the contacts. We have also sought verification of media reports of a second employee with pneumonia of undetermined cause.”

Fears over the plague prompted travel advisories and border restrictions in several Central Asian countries.

At the White House, President Trump said he does not believe the lab worker’s death was related to a bioweapon, and said he planned to discuss the issue with Russian President Vladimir Putin. The Kremlin said no such phone call has been scheduled. On Wednesday, the U.S. issued a formal diplomatic complaint over Russia’s handling of the lab worker’s death.

Protesters Repeatedly Interrupt Trump at Rally for Texas GOP Senate Candidate Ken Paxton

Oct 08, 2026

President Trump traveled to San Antonio, Texas, on Wednesday to rally support for Republican Senate candidate Ken Paxton. Paxton won the Republican nomination in May after Trump endorsed him over incumbent Senator John Cornyn.

Attorney General Ken Paxton : “How many presidents have we had that have done — that is doing what he is doing for us? So, Mr. President, I want to thank you for coming for me, for coming for us and for coming for Texas. We are going to win this race. God bless you.”

Trump’s campaign stop in Texas came after Axios published secretly recorded audio in which Paxton told donors that the war on Iran and resulting high gas prices were to blame for his poor poll numbers. With less than four weeks until Election Day, Paxton has trailed Democrat James Talarico in nearly every poll, despite the fact that no Democrat has won statewide office in Texas since 1994. Texas Republican Governor Greg Abbott declined to attend Trump’s campaign rally in San Antonio. Meanwhile, multiple protesters interrupted the president as he spoke, including one person who was physically assaulted by Trump supporters as he tried to leave the venue.

DHS Conducts Massive “Election Fraud” Operation as ICE Ramps Up Pace of Arrests Ahead of Midterms

Oct 08, 2026

In more election news, CNN is reporting the Department of Homeland Security’s election-fraud operation has drawn on tens of millions of records, scrutinized dozens of nonprofit voter-registration groups and considered deploying undercover agents to investigate organizations suspected of helping noncitizens register to vote. The probes are aligned with President Trump’s claims of election fraud, despite the fact that noncitizen voting occurs too rarely to affect election outcomes. A recent Reuters review found just 129 federal prosecutions under the “voting by aliens” statute created by Congress in 1996. This comes as leaders of ICE , Immigration and Customs Enforcement, have told agents nationwide to ramp up the pace of immigration arrests by a thousand people per day, to a previous goal of 3,000 daily arrests, leading up to the midterm elections.

Yemen’s Displaced Population Tops 200,000 as Saudi-Backed Forces Battle Houthis

Oct 08, 2026

In Saudi Arabia, officials say three people were killed and 36 left wounded after Houthi fighters from Yemen launched separate attacks on two airports, including King Khalid International Airport in Riyadh. Dozens of flights have since been delayed or canceled. The attacks came after the Houthis warned international airlines against flying in Saudi airspace, and as Saudi-backed Yemeni government forces began a counteroffensive to recapture territory along Yemen’s Red Sea coast seized by the Houthis last month. The International Organization for Migration reports the number of people displaced by recent fighting in Yemen has passed 200,000.

Russian Missile Strike Kills 22 in Ukraine

Oct 08, 2026

In Ukraine, rescuers are searching through the rubble of a residential building in the northern town of Pryluky after a Russian missile strike killed at least 22 people, including five children. It follows a wave ​of Russian drones and missiles a day earlier that killed at least 11 people and damaged homes, industrial facilities and infrastructure. Residents in the capital Kyiv sought shelter in the city’s underground metro stations, sleeping on platform floors. This is a resident of Kyiv.

Lesia : “The Russians always make the same loud claims about everything, that we started it, that we’re bombing them, that we were preparing in advance to strike them. But this is what’s actually happening right now: People are forced to go into the metro and sleep there. And then we’ll all get up, go to school or work, and go about our day as usual.”

Meanwhile, Russian officials say a Ukrainian naval drone struck a Liberian-flagged oil tanker off the Black Sea resort city of Sochi, setting off a massive fire. Russian authorities say all 23 crew members, who are Indian nationals, were rescued.

Tanker Struck North of Qatar After Iran Warns Ships Against Bypassing Strait of Hormuz Blockade

Oct 08, 2026

The U.K.'s Maritime Trade Operations Centre said it was investigating reports of multiple casualties after projectiles struck a tanker north of Qatar. Wednesday's attack came after Iranian officials warned they would close shipping routes used to bypass Iran’s naval blockade of the Strait of Hormuz. At least nine vessels came under attack last week while navigating the strait — the highest number in any week since the U.S. and Israel attacked Iran in late February. Meanwhile, oil prices rose more than 2% today amid attacks on energy infrastructure across Ukraine and the Middle East.

Venezuela’s Second-Largest Refinery Idles as Natural Gas Line Rupture Triggers Fire

Oct 08, 2026

In Venezuela, a fire sparked by a ruptured natural gas line halted the Cardón refinery, the country’s second largest with a ​capacity of 310,000 barrels per day. The company’s facilities frequently experience fires, blackouts and other disruptions, which can threaten the supply of fuels like gasoline and diesel.

Trump Admin Temporarily Allows Truckers to Fill Up on Dyed Diesel

Oct 08, 2026

The Trump administration has temporarily allowed truckers to fill up on dyed diesel, an off-road fuel normally reserved for farm equipment, as fuel costs hit record highs weeks before the midterm elections. The national average price of diesel topped $6 a gallon in September for the first time ever.

Meanwhile, the Environmental Protection Agency announced Wednesday it will further weaken federal limits on methane pollution from oil and gas operations. Maggie Coulter, an attorney at the Center for Biological Diversity’s Climate Law Institute, said, “This move will compound the climate chaos we see mounting all around us in deadly heatwaves, floods, and storms. Vulnerable communities will be exposed to worse smog and intensified respiratory pollution, increasing kids’ asthma and other health harms.”

Tropical Storm Isaias Intensifies to Become First Atlantic Hurricane of the Season

Oct 08, 2026

Image Credit: CSU/CIRA & NOAA

Tropical Storm Isaias rapidly intensified overnight to become the first Atlantic hurricane of the season. Isaias formed Wednesday in the warm waters off Mexico’s east coast. It’s tracking toward eastern Louisiana and the western Florida Panhandle, with hundreds of offshore oil and gas platforms in its potential path.

Death Row Prisoner Christa Pike Walking and Speaking After Failed Execution Attempt

Oct 08, 2026

In Tennessee, death row prisoner Christa Pike was reportedly “angry and confused” in the hours after she regained consciousness following the state’s failed execution attempt. According to her lawyer, she asked “Where am I?” This is Randy Spivey, an attorney for Christa Pike.

Randy Spivey : “She has a blood clot in one of her arms. She has pneumonia. She is not able to swallow yet, so she has not eaten. She cannot move either of her arms. Both of her arms and hands are tremendously swollen, and we do not know what, if any, function she will regain in her arms. But we do know that there is a long road ahead.”

Meanwhile, in Texas, the state executed 46-year-old Jamaal Howard, injecting him with a fatal dose of pentobarbital. Howard is the 30th person executed in the U.S. this year and the first since Tennessee’s failed attempt to execute Christa Pike.

Democratic Congressmembers Call for Criminal Probe into Epstein Associate Leon Botstein

Oct 08, 2026

Image Credit: ZUMA Press Wire via Reuters Connect

Democratic Congressmembers Jamie Raskin and Madeleine Dean are calling for a criminal investigation into Leon Botstein, the former president of Bard College who served for 51 years, after congressional investigators uncovered an email from Botstein to convicted sex trafficker Jeffrey Epstein in which Botstein asked if a young woman was “for me, or are you keeping her for yourself.” After calls for an investigation, Botstein resigned from all his positions at Bard College Wednesday, including his professorship and roles in Bard’s music programs.

According to a letter sent by Raskin and Dean to Attorney General Todd Blanche and FBI Director Kash Patel, Epstein offered to connect the young woman with Botstein to help with her plans to attend school and develop her music career, but instead Epstein pressured her to take sex education and massage courses while sexually abusing her. The lawmakers wrote, “The evidence meets the federal standard for opening a criminal investigation, yet [the] DoJ and FBI apparently had it for at least 18 months without investigating Botstein. We are demanding they investigate Botstein and other potential co-conspirators.”

The original content of this program is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License . Please attribute legal copies of this work to democracynow.org. Some of the work(s) that this program incorporates, however, may be separately licensed. For further information or additional permissions, contact us.

The Performance Cost of RwLock in Our Read-Heavy Workload

Lobsters
pranitha.dev
2026-10-08 07:58:52
Comments...
Original Article

In one of my past interviews, I was discussing my previous work and mentioned that we used lock-free data structures in a service. The interviewer replied, People these days keep saying they use lock-free structures, but I don't know how beneficial they really are .

It was a fair question. And there is no right answer when it comes to choosing between locked or lock-free. It depends on what is being synchronized, how often the data is updated and what the read pattern looks like.

Here is a simplified version of one workload where we used both.

Our Data Model


We had a relational data model which was quite complex but below is a minimal core data structure which we had to read from and write to.

struct Data {
    index: u32,
    metrics: Metrics, // mutable
    // other mutable/immutable fields
}

type Store = HashMap<u32, Arc<Data>>; 
type Block = Vec<Arc<Data>>; // Arc<Data> is a ref of data in `Store`

Store holds Data for IDs and each Block contains references to a subset of them.

Our service was read heavy. Every read request traverses all elements in a Block and does some computation over them. These reads happen concurrently.

We had a single writer thread which continuously updates data in Store .

Mutating Data


For each write, we had to replace the entire Metrics value. We considered two approaches for this: wrapping it in an RwLock , or replacing the value atomically.

RwLock

With multiple readers and a single writer, a read-write lock is generally the first thing we reach for:

use parking_lot::RwLock;

struct Data {
    index: u32,
    metrics: RwLock<Metrics>,
}

fn read(block: &Block) -> u32 {
    let mut max_count = 0;

    for data in block {
        max_count = max_count.max(data.metrics.read().count);
    }

    max_count
}

fn write(store: &Store, index: u32, metrics: Metrics) {
    *store[&index].metrics.write() = metrics;
}

There are other RwLock implementations as well in std and Tokio, but we chose parking_lot . std::sync::RwLock leaves reader/writer priority order to the OS, and tokio::sync::RwLock is asynchronous and acquiring it can yield. Our traversal was a synchronous computation and we didn't want to yield while acquiring every item, so parking_lot was a better fit.

Crossbeam Atomic

The alternative is to store an immutable Metrics value behind an atomic pointer. Readers load the current pointer, and the writer replaces it with a newly allocated value.

use crossbeam_epoch::{Atomic, Owned};
use std::sync::atomic::Ordering;

struct Data {
    index: u32,
    metrics: Atomic<Metrics>,
}

fn read(block: &Block) -> u32 {
    let guard = crossbeam_epoch::pin();
    let mut max_count = 0;

    for data in block {
        let metrics = data.metrics.load(Ordering::Acquire, &guard);

        // SAFETY: The epoch guard ensures the pointer remains valid
        if let Some(metrics) = unsafe { metrics.as_ref() } {
            max_count = max_count.max(metrics.count);
        }
    }

    max_count
}

fn write(store: &Store, index: u32, metrics: Metrics) {
    let guard = crossbeam_epoch::pin();
    let data = &store[&index];
    
    let old = data.metrics.swap(
        Owned::new(metrics),
        Ordering::AcqRel,
        &guard,
    );

    if !old.is_null() {
        // SAFETY: `old` is no longer stored in the atomic and is protected by the epoch guard
        unsafe {
            guard.defer_destroy(old);
        }
    }
}

When a reader loads Metrics , the epoch guard keeps that value alive until the reader is finished.

When the writer swaps metrics with a new value, the old value will not be freed immediately. defer_destroy marks that old value to be dropped later, when all active readers accessing it have finished.

Benchmark


The full benchmark code for this simplified example is on Git .

Setup

  • Readers : 50 concurrent Tokio tasks
  • Writers : 1 writer with 500 writes/sec
  • Block Size : 16,384
  • CPU Warmup : 2s
  • Measurement : 10s, averaged over 5 runs
  • Machine : MacBook Air with Apple Silicon

Each reader task calls read() in a loop with yield_now() after every call. The writer task calls write() at a fixed rate for 500 writes/sec.

Results

Benchmark Reads/s Writes/s p50 p95 p99
RwLock 15.93k 499.97 441.42µs 910.18µs 1.81ms
Atomic 229.07k 500.00 22.44µs 49.84µs 241.97µs

The lock-free version had significantly higher read throughput and much lower read latency across p50, p95 and p99 compared to RwLock .

At the first glance, it might seem like the lower throughput for RwLock is due to read-write contention. But when we turn off the writer, the read throughput barely changes.

Benchmark Reads/s Writes/s p50 p95 p99
RwLock (with writer) 15.93k 499.97 441.42µs 910.18µs 1.91ms
RwLock (without writer) 16.01k 0.00 431.50µs 905.85µs 1.87ms

Read Lock Acquisition


parking_lot internally uses AtomicUsize to track the number of active readers. When a read lock is acquired, it increments the active readers count via an atomic compare-and-exchange operation. And when the read lock is dropped, the readers count is decremented via an atomic subtraction.

So for one entry in Block , a simplified read is:

        reader
          |
          | read lock: readers_count + 1
          v
        read Metrics.count
          |
          | read unlock: readers_count - 1
          v
        continue

One logical block read, repeats the above 16,384 times:

read one Block
  |
  +-- Block[0]      lock -> read -> unlock
  +-- Block[1]      lock -> read -> unlock
  +-- Block[2]      lock -> read -> unlock
  |
  |   ...
  |
  +-- Block[16_383] lock -> read -> unlock

Here we have 16,384 read lock acquisitions and 16,384 lock releases for a single traversal. So, at ~16k traversals per second, around 524 million updates per second are performed by RwLock internally.

While CPUs are capable of performing billions of operations per second, atomic operations like compare-and-exchange and atomic subtraction are generally more expensive compared to ordinary reads and writes. These atomic operations must accurately track the active readers count under concurrent updates, which adds an overhead even when there is no contention.

Why Crossbeam Atomic Reads Were Cheaper


Crossbeam's pin() function pins the current thread to an epoch once for the entire Block traversal. This tells Crossbeam that the current thread could be accessing shared data, so any values which the thread could be using should not be reclaimed.

Each element in the Block now only requires an atomic pointer load instead of atomically incrementing/decrementing active reader count for every item.

pin epoch once
  |
  +-- Block[0]      atomic pointer load
  +-- Block[1]      atomic pointer load
  +-- Block[2]      atomic pointer load
  |
  |   ...
  |
  +-- Block[16_383] atomic pointer load
  |
drop epoch guard

Though epoch pinning and reclamation have their own bookkeeping overhead, replacing 16,384 RwLock read guards with one Crossbeam epoch guard and atomic pointer loads made a significant difference.

Other Alternatives


ArcSwap : ArcSwap is another option for read-heavy workloads. For this read pattern, using ArcSwap::load() for each item in the Block still adds some per-item overhead, while with Crossbeam we pin once for the whole Block .

left-right : left-right can provide much higher read throughput by keeping duplicate state and shifting more work to the writer. For our service, the production dataset was around 4GB in memory, so duplicating that state would have increased memory usage significantly. With Crossbeam, we were already meeting our throughput and latency requirements, so we didn't need that tradeoff.

Mutable Block


While our Metrics changed frequently, new entries were added to the Block only once or twice per second. For this, a simple RwLock around the Vec was sufficient.

use parking_lot::RwLock;

type Block = RwLock<Vec<Arc<Data>>>;
Benchmark Reads/s Writes/s Inserts/sec p50 p95 p99
Locked block 204.40k 500.01 1.06 26.17µs 52.59µs 258.83µs

Here, the individual Metrics values in Data still use Crossbeam Atomic pointers. Since the insertions were infrequent, we didn't see a need to make the Block itself lock-free.

Conclusion


These results are specific to our workload and they don't necessarily mean lock-free is always faster.

Going lock-free helped us avoid the overhead of acquiring and releasing thousands of read locks. But we also saw that a simple RwLock worked well when placed around the Block .

In the end, it's not just about choosing between locked and lock-free. Where and how often synchronization happens matters just as much.

Anne Carson wins Nobel Prize in literature 2026

Hacker News
www.theguardian.com
2026-10-08 07:58:50
Comments...
Original Article

The Nobel prize in literature has been awarded to the Canadian poet and essayist Anne Carson , the Swedish Academy has announced.

The academy cited the author’s “bold and inventive oeuvre that, in playful dialogue with the classical tradition, has created new forms for contemporary literature”.

Born in 1950 in Toronto, Carson is known for work that moves freely between poetry, prose and translation , drawing heavily on the literature and mythology of the ancient Greek world.

Carson’s first book, Eros the Bittersweet, was published in 1986, and combined literary criticism with an exploration of desire and the ancient Greek tradition.

Her best-known work is Autobiography of Red, a 1998 novel in verse inspired by the fragments of the ancient Greek poet Stesichorus. It reimagines the myth of Geryon, the red-winged monster killed by Herakles, as the story of a modern teenage boy navigating heartbreak and desire.

In 2001, she became the first woman to win the TS Eliot prize for her collection The Beauty of the Husband. She has also been awarded Guggenheim and MacArthur fellowships.

Her work has attracted praise from fellow writers, including Susan Sontag, who once said: “She is one of the few writers writing in English that I would read anything she wrote. If there’s a magazine that has something of hers in it, I buy it automatically.”

Carson’s books have ranged widely in form. Men in the Off Hours combined verse essays, poems, epitaphs and prose about artists and historical figures, and won the inaugural Griffin poetry prize in 2001. Decreation, another eclectic work, brought together poetry, essays and an opera. Nox, published in 2010, is particularly characteristic of Carson’s avante-garde approach to literature – the book takes the form of an accordion-fold box containing a reproduction of a notebook Carson made after the death of her brother. Her later works include Red Doc> and Float.

The Nobel prize in literature has been awarded on 118 previous occasions since 1901. Recent laureates include Annie Ernaux, Bob Dylan, Abdulrazak Gurnah, Louise Glück, Peter Handke and Olga Tokarczuk. Last year’s recipient was the Hungarian author László Krasznahorkai, known for his dystopic and avant-garde writing.

Carson, 76, will formally receive the medal and diploma in a ceremony in Stockholm in December.

ASOS links data breach to social engineering attack, credential theft

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 07:42:46
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]...
Original Article

ASOS

UK fashion retailer ASOS confirmed that a recent data breach was caused by a social engineering attack in which hackers stole an employee’s login credentials and used them to access information on third-party platforms used by the company.

"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," reads an ASOS security notification shared with BleepingComputer.

"Those credentials were then used to access information on certain third-party platforms used by ASOS."

The company locked down the affected platforms and launched an investigation with support from external experts, law enforcement, and regulatory authorities.

ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide.

On October 6, 2026, ASOS customers received a push notification through the ASOS app on their mobile devices, alleging customer data theft and urging the company’s staff to engage with them on Telegram.

Malicious ASOS in-app notifications sent by hacker
Malicious ASOS in-app notifications sent by hackers

The threat actor, calling themselves “Xuanye Group,” claimed that they had stolen customer data, but not payment information.

ASOS eventually confirmed via a statement published on its website that it had suffered a data breach that may have exposed some “basic” personal information and contact details.

The latest update sent to customers confirms that the following details were exposed:

  • Full names
  • Contact details
  • Certain non-personal account-related information

ASOS says hackers did not access payment card information or account passwords.

The retail giant also says its website and app were at all times, and continue to be, completely safe to use.

“There is no action you need to take on your account,” ASOS says in its message to customers.

“However, please remain cautious of unexpected messages or calls claiming to be from ASOS.”

“We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.”

ASOS says its investigation is still underway, and it will share more updates if important findings emerge.

The company also assured that it has already taken steps to implement additional security measures to prevent similar incidents in the future.

BleepingComputer has asked ASOS about the number of customers impacted by this incident, but we have not received a figure yet.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Shopify went back to native. I think the bigger shift is formal verification

Lobsters
martinalderson.com
2026-10-08 07:35:57
Comments...
Original Article

The social media discourse is ablaze with people porting apps from slower dynamic languages to faster statically compiled languages. And we've seen both Shopify and Coinbase start switching away from React Native back to native mobile apps. What's changed, and what's next for programming ecosystems? I think the answer is less about performance than it first looks.

Why did people use cross platform frameworks?

When modern smartphones first came out, there was an explosion in native app development. Cross platform web apps on smartphones were (and to be honest, still are in many respects) limited in terms of the features and quality of UX you could deliver to users.

This involved most companies having to build totally separate app codebases, one per platform. Typically you'd have a Swift (previously Objective-C) iOS app and a Java/Kotlin Android app.

For many teams, this is a huge headache. Not only do you require ~twice the resources, building everything twice, but coordinating feature releases and maintenance gets really tricky. For example, if you do a big backend migration, you need to coordinate it across two teams, in a totally different language ecosystem. Typically one app - usually iOS - would get more attention than the other, too, with wildly diverging feature sets.

As such, there was an explosion of cross platform mobile app frameworks, with React Native becoming the most popular, though it's important to mention other ones like Flutter and Xamarin (which was rebuilt as .NET MAUI, and lost nearly all the traction it had during the post acquisition migration).

These allowed you to (mostly) write your app once, and the framework would do the job of translating it to the platform below. In general, they worked quite well, but did have performance issues (especially React Native [1] ) and a huge swath of framework bugs which were often painful to work around.

As such, many companies migrated to these frameworks. But now we see the migration being undone with the advent of coding agents.

Agents translate between platforms

As coding agents have got better and better, it's become obvious that writing code is nowhere near as time consuming as it used to be. So the main objection to writing native apps - resourcing requirements - has collapsed. You can even just have one 'primary' platform and have the agent autonomously port each change to the 'secondary' platform, which works surprisingly well on more capable models.

I'd argue it isn't completely solved, given you still want to test and ensure your features are well designed for both platforms. But cross platform frameworks didn't really solve that before, and arguably agents can do a far better job of translating your requirements to each platform than a cross platform framework like React Native can.

And obviously this gives big improvements in performance of the app, plus often better access to underlying platform features (which can lag support in React Native et al).

But maybe it's not just about performance

I thought at first that really it was going to be quite clear that all software gets written in the most performant language, as advocated by DHH's autonomous porting experiments , and this switch to native apps is just a very visible example of it.

But the Shopify move made me think about it differently. What it really shows is that writing code has stopped being the expensive part - Shopify can afford two native codebases now because agents are writing them. The expensive part is knowing the code is actually correct: reviewing it, testing it, trusting it. And "use a faster language" doesn't help with that at all.

So my slightly wildcard guess is that we will end up with formal verification systems being the primary way we (and by we, I mean agents) write software going forward.

Formal verification systems (Lean being the most well known example, though it's mostly used for mathematical proofs - Dafny is much closer to 'normal' programming) are fairly obscure outside of certain fields. Typically they'd be used for the most critical parts of software - think aeronautical control systems, or critical security systems at AWS (they built their Cedar authorisation language this way). They allow you to prove the software does what it says. While traditional software testing approaches like unit testing help you (and agents!) catch bugs, they require writing the problems ahead of time to test for.

Formal verification systems on the other hand use a solver to prove the code does what you said. Instead of just writing a test that checks you don't have a bug in your order handling code, you can formally prove that an order can't move into an invalid state, or a user can't see data they shouldn't be able to see.

The enormous drawback to them previously was they are torturously hard (and slow) for humans to write the proofs. Worth it for ensuring critical infrastructure works well, but very much not worth it for most software.

But the calculus for this switches hugely with agents. They could write all your code in something like Dafny , which then outputs the actual code into a fast language like C# or Go, getting great performance and a step change in reliability and quality of software. It's the same economics as native apps: something that was too expensive for humans to do twice becomes cheap when an agent does the grunt work.

This isn't quite the slam dunk currently, though. Dafny relies on an SMT solver to do the proving, and it's notoriously brittle - a proof that worked yesterday can time out today because you renamed a variable or upgraded Dafny. If you thought Rust compile times were frustrating, an unpredictable verifier is a whole new world of hurt, especially when an agent can't tell the difference between "my proof is wrong" and "the solver gave up".

But I'd expect this to get a lot better. Verification tooling has had a tiny fraction of the attention and investment that mainstream compilers and languages get, simply because it was so niche and esoteric. If agents make it mainstream, I suspect we'll see the same kind of rapid improvement we saw when JavaScript engines suddenly mattered.

So I'd recommend you spend some time playing around with formal verification systems. The Dafny guide is a good start, or just ask your agent of choice to formally verify one critical function in your codebase and see what it finds. I strongly suspect you'll be hearing a lot more about them.

I did write previously that we'd actually see a resurgence in 'esoteric' programming languages, not the monoculture many expect. But I actually think we're going to speedrun every programming language innovation that has come out of (primarily) academia very fast with agents.


  1. To be fair, not all React Native apps are slow - plenty are great. But in my experience it was often hard to make them fast, because of the very single threaded nature of the JS runtime. One heavy render or a big list and the whole UI would start to stutter. ↩︎

Vanillin provides a sweet solution for chronic wound healing

Hacker News
news.flinders.edu.au
2026-10-08 07:30:08
Comments...
Original Article

Stock photo: Getty Images

Simple food components may provide the key to new cost-effective materials that will benefit chronic wound healing.

A team from Flinders University’s Biomedical Nanoengineering Laboratory has found that vanillin has pronounced antioxidant, anti-inflammatory and antibacterial properties, making it a good candidate for wound-healing formulations.

Vanillin is the primary chemical component extracted from natural vanilla pods, but is a compound that can also be synthetically produced from clove oil or rice. Apart from being a sensory additive – used as a key ingredient in many foods for its sweet aroma and flavour – vanillin is also a functional molecule, serving as a dynamic crosslinker and functional element in material design.

By placing vanillin within a food-to-function framework, the researchers have linked its chemical properties to biological activity and potential biomedical applications.

“Vanillin is among the most widely used flavour compounds in the global food system, valued for its sensory attributes, chemical stability and long history of safety – and that can be transferred to other areas, such as medical uses,” says Professor Krasimir Vasilev, Professor of Biomedical Nanotechnology at Flinders University and Director of Flinders’ Biomedical Nanoengineering Laboratory.

“Because vanillin’s synthetic form is abundant and cost-effective, we believe vanillin-based formulations may offer safe and multifunctional solutions for ulcer treatment and targeted drug delivery, especially of hydrophobic compounds.

“Owing to its amphiphilic molecular structure, vanillin can interact with reactive oxygen species, cellular membranes and polymeric matrices, providing a basis for its incorporation into functional formulations.”

This study continues explorations by Flinders researchers into other foods that can provide medical benefits – including using peppermint oil in a versatile new medical coating, which was published by Small journal in February 2026. For this, the Flinders team created a nanoscale peppermint‑oil derived coating that protects against infection, inflammation and oxidative stress, while remaining compatible with human tissue and suitable for medical materials.

The idea for this thread of food-based research emerged after Professor Vasilev noticed that eating peppermint leaves from his drink significantly relieved his sore throat, inspiring him to explore whether its bioactivity could be converted into a durable coating using plasma technology – something he has been researching for more than two decades.

The Flinders researchers share similar enthusiasm for the new studies into vanillin – especially because the availability of vanillin as a low-cost small molecule that is compatible to good manufacturing offers a clear advantage for industrial scale-up, formulation reproducibility, and supply chain robustness.

“With coordinated engagement between academia, clinicians, and industry, vanillin has the potential to progress from an underutilised bioactive to a clinically deployable component of next-generation wound care and regenerative therapeutics,” says Professor Vasilev.

The research – “Vanillin as a bioactive component in biomedical formulations for chronic wound healing and tissue regeneration”, by Borislav Stoilov, Vi Khanh Truong, Christopher Delaney and Krasimir Vasilev – has been published in International Journal of Pharmaceutics . DOI: 10.1016/j.ijpharm.2026.127263

Lourdes gets a Vegas glow-up at Dublin theatre festival, where canvases are slashed

Guardian
www.theguardian.com
2026-10-08 07:23:37
A musical about a drama group’s pilgrimage and reflections on activist art join an intriguing show about lost languages In a Dublin theatre festival programme tackling heavy themes of racism, conflict and prejudice, Lourdes! The Musical (★★★★☆) promises something effervescent. Xnthony Ltd, the creat...
Original Article

I n a Dublin theatre festival programme tackling heavy themes of racism, conflict and prejudice, Lourdes! The Musical ( ★★★★☆ ) promises something effervescent. Xnthony Ltd , the creators of Oliver Cromwell Is Really Very Sorry , have turned their lightly quizzical gaze to the French pilgrimage town – “a holy Blackpool, a divine Las Vegas” and a site of hope or desperation for five unlikely travelling companions.

Back in his home village in “Countryland”, in 2008, following a diagnosis of HIV that punctures his dreams of Los Angeles, singer-songwriter Matthew (Riain Cash) lends his star power to a parish drama group taking a musical about Saint Bernadette to Lourdes. Interweaving this show-within-a-show and the pilgrimage strands, Xnthony’s lyrics and Matthew Floyd Jones’s score blend pop, club beats and soulful ballads. Directed by Sarah Meadows, the supercharged ensemble joining Cash as, variously, a droll priest (Iestyn Arwel), a terminally ill mother and her transgender daughter (Nichola MacEvilly and Danielle James) and an eager tour manager (Molly Lynch) carry the music’s tonal shifts effortlessly.

Instructed by neon signs to “please wait for a miracle”, characters reveal what brings them to this Marian shrine with its bizarre mix of tackiness and piety. Each has a Catholic faith of sorts – something that might have been more complicated to portray if set in the present day. Rather than settling on an archly ironic approach, Xnthony’s sensitive, often lyrical writing allows fear of death, regret and above all, grief, to seep through.

Alice Roots wearing a blue jumpsuit stands next to a cardboard lifesize image of David Hasselhoff as Knight Rider copying his stance
Clever and knowing … Alice Roots in Heroes of Tomorrow. Photograph: Ste Murray

An aura of reverence pervades the white cube gallery setting of Heroes of Tomorrow ( ★★★☆☆ ), the latest production from the restlessly inventive Brokentalkers . Co-directors Feidlim Cannon and Gary Keegan are joined here by British theatre artist Andy Smith to burrow into the relationship between art and activism. Pinging through centuries and continents, they make connections between historical instances of human invention and resultant exploitation, technological breakthroughs and protest, underlining the point that progress is not linear.

If this sounds abstract, it is; much of it is delivered in carefully flat, affectless narration by Alice Roots, Michael Tient and Malua Ní Chléirigh, as if making a presentation in the gallery, taking turns to outline the biography of a (fictional) Norwegian conceptual artist called Jan Hansen. His latest work, The End of It All, has been commissioned by three global tech companies, a testing moment of groupthink for an artist who has acquired cachet for financially supporting climate activists who fling paint over old masters in museums.

Amid questions about whether it is possible for art to remain pure, uncompromised by its corporate sources of funding, the audience is teased into imagining what Hansen’s new artwork will be. As the performers playfully poke their heads through slashed canvases and make black imprints of their hands on the pristine gallery wall, this performance is itself a form of conceptual art, played out in a highly coded space. The result is clever and knowing but, for Brokentalkers, surprisingly tentative.

Zinc ( ★★★★☆ ) from Dead Centre focuses on a forgotten mini-state, Neutral Moresnet, on the border of Germany, Belgium and the Netherlands. A political anomaly, designated a neutral zone to protect its prized zinc mines, it was passed between European powers, its inhabitants’ nationality changing as borders shifted. Adapted from a book by Belgian political philosopher David Van Reybrouck , the production brings multiple perspectives to bear on the experience of one man, Joseph Rixen, born in Neutral Moresnet in 1903.

Timmy Creed, Fabio Godinho, Cathy Min Jung, Mila Moinzadeh and Julie Mughunda
One of their most ambitious works to date … Timmy Creed, Fabio Godinho, Cathy Min Jung, Mila Moinzadeh and Julie Mughunda in Zinc. Photograph: Alexandre Fytrakis

Playing with the idea of neutrality, co-directors Ben Kidd and Bush Moukarzel and the superb international ensemble – Julie Mughunda, Timmy Creed, Fabio Godinho, Cathy Min Jung and Mila Moinzadeh – rewind, wittily, to the 1815 Congress of Vienna. Reflecting on colonisation, annexation and the accidents of history, each actor explores their personal experience of exile, displacement and lost native languages.

skip past newsletter promotion

A co-production with Théâtre de Liège , this is one of Dead Centre’s most ambitious works to date: multilingual, integrating video mapping, projection, layered music and sound design, and, as always with their work, commenting on the art of theatre itself. Richly allusive, it connects a performer on an empty stage, before the act of imagination begins, to the perceived neutrality of a geographical place – until it can be exploited, no longer a country but “a business”.

Moving away from the cartography of loss, the performance seizes on the lost political project of Esperanto as a possible neutral language of hope – literally utopian, with its root meaning of “nowhere”.

How Technology Empowers—and Imperils—Dictators

Schneier
www.schneier.com
2026-10-08 07:07:35
This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs. Two weeks after Moscow’s full-scale invasion of Ukraine in March 2022, the Russian TV Channel One editor Marina Ovsyannikova burst onto the set of the evening newscast. She held up a hand-drawn sign behind t...
Original Article

This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs .

Two weeks after Moscow’s full-scale invasion of Ukraine in March 2022, the Russian TV Channel One editor Marina Ovsyannikova burst onto the set of the evening newscast. She held up a hand-drawn sign behind the anchor’s head that read: “Stop the war. Don’t believe propaganda. They’re lying to you!” She shouted, “No to war!” until she was dragged away.

No one has protested the war on Russian television since then, partly as a result of tighter security and a general climate of fear. But in October 2024, Margarita Simonyan, one of Russia’s chief propagandists, gave another explanation. A growing number of the RT network’s anchors, she explained to an interviewer, are not real. “That face doesn’t exist. We generated the voice and everything else.” They were, she meant, produced by artificial intelligence. In a follow-up interview with the newspaper Vedomosti , she spelled out the logic: “These anchors don’t need a salary or insurance,” she said. “They won’t get arrested, and the police won’t search their homes. It’s all wonderful and terrifying at the same time.”

This is AI’s promise to every autocratic ruler: the ability to maintain control without delegating tasks to unreliable humans. It is an extremely attractive prospect. No matter how powerful, dictators have always needed subordinates—censors, propagandists , security guards, police officers, intelligence analysts, and local bureaucrats—to carry out their orders. But subordinates always pose a potential threat. They could shirk, steal, lie, leak, or conspire against their boss. As a result, one of the oldest dilemmas facing autocrats is how to empower agents to carry out orders without also enabling them to turn against their leader. Autocrats have usually managed the tradeoff by filling key positions with mediocrities whose incapacity is, as the political theorist Hannah Arendt put it, “the best guarantee of their loyalty.” But this inevitably makes it harder for dictatorships to govern and survive crises.

AI appears to offer autocrats two ways to resolve this long-standing dilemma. First, it means they can now easily monitor and discipline their followers in real time. A change in a local official’s spending habits or meeting schedules can be flagged automatically by an AI system, without any need for self-interested informants. Second, AI can eliminate underlings altogether. By automating tasks that once required human discretion, rulers can replace unreliable intermediaries with faithful algorithms that cannot be bribed or manipulated. Officials in autocratic regimes have said as much. AI “can definitely replace half of officials,” Russia’s Digital Development Minister, Maksut Shadaev, told a Moscow data forum in April 2025, adding, “maybe slightly more.”

Yet these promises of a self-running state are illusory, because AI is never truly autonomous. Systems have to be built and maintained by a cadre of engineers and data scientists whose expertise political leaders cannot evaluate. The ruler who turns to AI to reduce a dependence on unreliable humans may end up relying, more blindly than before, on the few AI specialists who keep the system running. And this new digital Praetorian Guard may have the same weaknesses as the old, which makes it a threat to the ruler.

Eyes and Ears

China is in the lead when it comes to developing AI systems that can monitor or replace subordinates. Smart city programs in Beijing, Shanghai, and other urban centers use AI to track performance and centralize oversight of local officials who once operated in comfortable obscurity, subjecting them to an algorithmic performance review. China also developed a “Zero Trust AI system,” which it deployed across roughly 30 counties and cities over the past decade. This system cross-referenced more than 150 government databases to catch embezzlement and nepotism by local officials. It worked a little too well, flagging 8,700 officials before local governments, under pressure from the bureaucrats it was monitoring, began rolling it back. But Beijing has not gotten rid of its new e-government portals, which use automated systems for issuing documents and permits, reducing face-to-face interactions that bred petty corruption or favoritism. The Chinese Communist Party , meanwhile, has plowed ahead with researching what it calls “thought management,” or how to use AI to create microtargeted propaganda. China’s army of Internet commentators, once composed of paid humans, is already being replaced by bots.

Russia has been pursuing the same goals with a similar fervor. Moscow’s citywide facial recognition system, deployed across 200,000 cameras, was used to identify and apprehend protesters during the 2021 antigovernment demonstrations. The central government has started using automated data collection and aggregation to bypass regional officials who could taint the data or use it to promote their own interests. In 2023, Russia’s Internet regulator launched Oculus, an AI system that scans hundreds of thousands of images per day for prohibited content, including political content—orders of magnitude beyond what human censors could process. The Russian security service’s Meliorator tool has been used to create over a thousand profiles of fictitious Americans, primarily on X (formerly Twitter), to spread Kremlin narratives at a fraction of the cost of human troll farms.

Other autocracies are following in Beijing’s and Moscow’s footsteps. In April 2025, the United Arab Emirates created a Regulatory Intelligence Office that uses AI to draft and amend federal laws, work once done by legislative staff. A year later, UAE Prime Minister Sheikh Mohammed bin Rashid al-Maktoum announced that autonomous AI agents would take over half of the federal government’s operations within two years and that “the performance of ministers, directors general, and entities will be assessed based on their ability to adopt this transformation.”

These innovations may reduce the number of bureaucrats autocrats need. But they cannot actually create what dictators want most: a self-running state. Even AI-generated television anchors need people to build and maintain them, and censorship systems need people to retrain them as the vocabulary of dissent shifts. Behind every AI model, there is a small group of engineers and data scientists doing essential maintenance, and their work is so technical that rulers cannot understand it.

This dependence thus becomes another form of power. The engineers who maintain an autocrat’s surveillance apparatus, for example, can shape what the ruler sees. They decide what information is important enough to pass along and in what form to present it. They determine which threats get flagged, and they can adjust the algorithms that select what content gets suppressed and who gets arrested. And they can do this without anyone in the palace noticing. Autocrats who turn to AI to escape a dependence on unreliable subordinates have only transferred their vulnerabilities onto a new group of officials.

In fact, this new Praetorian Guard could be more dangerous than previous elites. That is in part thanks to the opacity of AI technology but also because this clique is much smaller. Roman emperors typically had tens of thousands of people serving in the Praetorian Guard; modern autocrats rely on standing armies. But with AI, autocrats will need only a small clique of engineers to build and maintain large-scale AI systems. This might benefit rulers since they will have fewer people to watch, yet it also concentrates points of failure, since a devastating disruption requires only a handful of engineers and makes it easier for members to scheme against the leader. The new guard’s members may also be indispensable. A dictator can replace generals without destroying the army. But running complex machine-learning systems requires such a specialized set of skills that engineers can be difficult to replace without disruptions, giving these actors great leverage.

The Indispensables

The importance of tech workers to autocracies has already become apparent. When IT specialists began to flee Russia after the full-scale invasion of Ukraine in February 2022, for example, the Kremlin responded not with threats but with inducements, offering tech workers deferments from conscription. It exempted their firms from taxes and subsidized their mortgages. When Russian President Vladimir Putin ordered the mobilization of 300,000 men seven months later, IT workers were granted full-on waivers. This might seem like overkill, given that an AI system needs only a few engineers to run it. But a regime cannot know in advance which engineers it will need, and it cannot train replacements quickly, so it has to hold on to the entire talent pool from which these few are selected.

These measures did not stem the outflow of roughly 100,000 specialists—about a tenth of Russia’s tech workforce—over the course of 2022. But Moscow stuck to bribery, because expertise is extremely difficult to conscript at gunpoint and because conscripted experts might be less likely to do as instructed. Even so, money and privilege cannot guarantee that these elites will stay loyal. Autocrats should recall the lesson of the original Praetorian Guard: for a time, it provided Roman emperors with protection and security. But then the praetorians discovered their own indispensability, and by the second century, they were auctioning off the empire to the highest bidder. This new set of elites can do the same. In June 2023, when the column of Yevgeny Prigozhin ‘s Wagner paramilitary company moved up the highway toward Moscow, Putin depended on his security services to tell him what was happening. Future rulers in Putin’s position will receive such warnings through machines: intercepted communications sorted by software, camera feeds filtered through recognition systems, regional reports compiled into dashboards. The engineers who run those systems could strike a deal with an upstart challenger and then drag their feet. They could delay the data, let alerts arrive a few hours late, degrade feeds at inconvenient moments, or make a recognition system stop functioning. In that scenario, the ruler would be operating blind. The Praetorian Guard did not need to kill Emperor Nero to replace him. It simply had to abandon him for a rival.

These programmers are unlikely to seize power for themselves, because they are unlikely to carry what coup leaders ultimately require: guns. But there is already precedent for engineers using their power to shape leadership challenges. In 1991, when the Soviet army attempted to seize control from Mikhail Gorbachev, a handful of programmers at the Relcom network kept information flowing abroad and relayed Russian President Boris Yeltsin’s decrees to audiences inside the country and abroad. The plotters could not stop the news of Yeltsin’s defiance from spreading, and the coup collapsed within three days.

Slimming Down

AI will not let autocrats dismiss all their enforcers. Someone still has to make arrests and run the prisons, and autocrats can buy loyalty by offering supporters state jobs. But it will let authoritarians downsize, and the number of officials ultimately matters less than how the ruler oversees them. Keeping track of scheming or incompetent subordinates has always been the autocrat’s chief burden. AI could lighten it, letting rulers watch their officials more closely without paying as much active attention.

In the near term, then, AI may greatly benefit autocracies. Despite the many obstacles to deployment, the technology is already bringing autocratic regimes the upsides of cheaper surveillance, smarter censorship, and fewer human subordinates to fear and distrust. But for autocratic rulers, the temptations of artificial intelligence may re-create the same trap they are seeking to escape. The more a regime depends on AI, the more it depends on the people who keep AI running. And those people, like every other praetorian class in history, will quickly discover what their indispensability is worth.

Tags: , , ,

Posted on October 8, 2026 at 7:07 AM • 1 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

OLED burn-in test: 30-month update

Hacker News
www.techspot.com
2026-10-08 06:34:15
Comments...

Owner of Empire cybercrime market gets 40 years in prison

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 06:29:19
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]...
Original Article

prison

The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020.

30-year-old Raheim Hamilton (also known online as "Sydney" and "ZeroAngel") owned and operated Empire Market from August 2017 until its abrupt shutdown in 2020 amid persistent extortion-based DDoS waves, which prompted exit-scam claims after users weren't given time to withdraw funds from their escrow accounts.

Between June 2016 and July 2017, Hamilton also sold on AlphaBay (a notorious dark web marketplace that shut down in 2017 ) under the "ZeroAngel" username.

Empire Market operated as a hidden service on the dark web accessible only via TOR browsers and was modeled and advertised as an AlphaBay clone.

Together with co-defendant Thomas Pavey (aka "Dopenugget"), who also pleaded guilty last year to a federal drug conspiracy charge, Hamilton facilitated more than 4 million transactions between vendors and buyers.

While the cybercrime market also sold counterfeit currency, stolen account credentials, computer hacking tools, and personally identifiable information, drug sales represented the most prevalent activity, totaling nearly $375 million over the site's lifespan with over 166,000 listings for controlled substances alone.

At its peak in August 2020, the marketplace had roughly 1.68 million unique registered users, including more than 5,000 vendors and nearly 360,000 buyers.

When he pleaded guilty in January , Hamilton admitted that Empire Market was designed to help users avoid law enforcement detection and launder money, as all transactions were conducted in cryptocurrency to maintain the users' anonymity.

"The controlled substances sold on the market included approximately at least 13,314.23 grams of fentanyl, 446,683.15 grams of cocaine, 71,992.33 grams of methamphetamine, and 103,396.21 grams of heroin," the Department of Justice said .

"Hamilton and Pavey established that all transactions on the site must be conducted using only cryptocurrency. They encouraged users to use tumbling and mixing services to conceal cryptocurrency transactions and utilize encryption while communicating on the site. They also allowed users to rate vendors based on how well the vendors concealed the drugs they shipped."

According to court documents , the two accomplices also hired moderators to resolve disputes between customers and vendors, with Hamilton supervising approximately 5 moderators and even personally handling some cases​​​.

The plea agreement also revealed that law enforcement agents made multiple undercover purchases between April 2019 and May 2020 (buying at least 143.5 grams of methamphetamine and 105.4 grams of heroin) and intercepted a package containing 443.5 grams of methamphetamine ordered on Empire Market.

When the U.S. Justice Department charged the two defendants in July 2024, it also announced that authorities had already seized $75 million worth of cryptocurrency during the investigation.

Hamilton has also agreed to forfeit three Virginia properties and approximately 1,230 bitcoin and 24.4 Ether, while Pavey (who will also be sentenced later this month) agreed to forfeit two Florida properties, approximately 1,584 bitcoin, two boxes containing 25-ounce gold bars, and three cars.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Migrating Git repos to SHA-256

Lobsters
exa.y2k.diy
2026-10-08 06:00:39
Comments...
Original Article

SHA-256 is the new object format in town , available since Git 2.42. It has a few benefits:

  • No real security benefit. SHA-1dc is good enough.
  • Not compatible with GitHub. Harder for others to steal your code and feed it to Copilot.
  • Even longer and even more unwieldy object IDs, further encouraging tagging and shorthand.
  • Street cred from using the cool new hash function?
  • Gives most third-party Git tools (jujutsu/gitoxide, Eclipse/JGit, etc) indigestion…? Wait that’s not a benefit

It’s pretty easy to find the steps to do a migration of a basic repo that lacks submodules online (not in the Git documentation, of course, just on various random web pages):

In the old repo:

git fast-export --all > export

In the new repo:

git init --object-format sha256
git fast-import < ../old/export

Let me be clear for skimmers: This explodes if your repository contains submodules.

I don’t know how to handle the case where you have a third-party submodule, which is unfortunately one of the most common cases. It would appear when adding a SHA-1 submodule to a SHA-256 repository that the SHA-1 object ID is just… padded with zeroes.

There’s mention of a mystical option to fast-import and fast-export that allows you to transfer marks to rewrite the old SHA-1 sub-modules into SHA-256 sub-modules. However, this is the extent of the documentation:

--rewrite-submodules-from=<name>:<file>
--rewrite-submodules-to=<name>:<file>

Rewrite the object IDs for the submodule specified by <name> from the values used in the from <file> to those used in the to <file>. The from marks should have been created by git fast-export , and the to marks should have been created by git fast-import when importing that same submodule.

<name> may be any arbitrary string not containing a colon character, but the same value must be used with both options when specifying corresponding marks. Multiple submodules may be specified with different values for <name>. It is an error not to use these options in corresponding pairs.

These options are primarily useful when converting a repository from one hash algorithm to another; without them, fast-import will fail if it encounters a submodule because it has no way of writing the object ID into the new hash algorithm.

— https://git-scm.com/docs/git-fast-import

Maybe I’m just dense, but it’s not very clear what you need to do here. No references are made to other commands or their switches that might be needed — and no sample is given, not even in the mailing list when this feature was introduced.

There’s not even a degraded case when you use fast-import and submodules are present… it just crashes:

fatal: object not found: 9444d0177d5a2489df1ce626347cd29dc4e8b3b4
fast-import: dumping crash report to fast_import_crash_897126

So, here’s the series of steps for converting a repo and its submodule:

In the old submodule:

git fast-export --export-marks=marks --all > export

Caveat : If the referencing repo has ever referenced a commit that is no longer part of a current branch (e.g. a force-push occurred) then this will not export all the necessary objects. You will need to specify the orphaned objects as additional parameters to fast-export here, in addition to the branches.


In the new submodule:

git init --object-format sha256
git fast-import --export-marks=marks < ../old-submodule/export

In the old repo:

git fast-export --all > export

In the new repo:

git init --object-format sha256
git fast-import \
	--rewrite-submodules-from=blah:../old-submodule/marks \
	--rewrite-submodules-to=blah:../new-submodule/marks \
		< ../old-repo/export

With this context , the documentation makes a lot more sense. But without that prior knowledge, it’s just meaningless soup.

You can repeat the rewrite-submodules options as many times as you like, but the left-hand-side must be a unique string for each submodule and match for each submodule. It’s easiest to just set it to the name of the submodule rather than “blah”.

Here’s the repo I successfully migrated with this strategy: Rewind Upsilon .

Bonus: Migrating a Forgejo repo in-place

Forgejo would really like you to delete the repo and make a new one that’s initialized with the SHA-256 object format. If you have access to your Forgejo server, you don’t need to wait for this feature request to do this.

This is extremely a hack and might have severe knock-on consequences. At the very least, it will break all existing references to exact commits in your repo. Tag references should be preserved.

Migrate the git repo

First, enter the directory your repo lives in — $FORGEJO_DATA_HOME/gitea-repositories/$ORG , something like /opt/forgejo/data/gitea-repositories/rewind/ .

At this point, you can choose to do the migration on your local computer and push it afterwards, or do the migration on the server.

Do the migration on the server

Follow the above instructions but add --bare when using git init to work with the bare repos that Forgejo expects. For example, you could have repo.git as your “old repo” and repo.sha256.git as your “new repo”. Once you’re sure everything looks good, delete the old repo and rename the new repo to its name:

rm repo.git -rf
mv repo.sha256.git repo.git

Why put -rf at the end?

Do the migration locally

Follow the instructions on a local clone, and then replace the server copy with an empty repo:

rm repo.git -rf
git init --object-format sha256 --bare repo.git

Why put -rf at the end?

The remote copy is now an empty repo, and may not show up in the web UI. Do a push with --mirror to upload everything from the migrated repo.

Update the database

At this point, the repo will half-work in the web UI with some disconnects in how object IDs are described/shown, and there will be a big ugly warning about misconfigured git hooks. We need to now tell Forgejo this repo is SHA-256.

Find your repo’s internal ID in the settings. The easiest place to find this is as part of the ActivityPub URL, which will look something like https://git.sleeping.town/api/v1/activitypub/repository-id/50 — 50 is the internal ID.

Open a SQL shell and USE the Forgejo schema. Then, where ? is the internal ID:

UPDATE repository SET object_format_name = "sha256" WHERE id = ?;

Refresh the web UI. There will now be a “SHA256” badge on your repo.

Resync Forgejo with Git

Finally, go to the Site Administration section and run all of the following actions, in order:

  • Sync missed branches from git data to databases
  • Sync tags from git data to database
  • Resynchronize pre-receive, update and post-receive hooks of all repositories

All done. The repo should now be migrated, without losing issues, wiki, PRs, projects, etc.

Bonus: Re-signing all commits after the migration

git rebase --exec 'git commit --amend --no-edit --no-verify --gpg-sign' --root

This rewrites every commit, and therefore won’t work for submodules as it will break all the relationships established by the mark files. It’s worth noting that a single signed commit at the head of a branch forms a sufficient chain of trust due to Git’s structure, which can be accomplished by making a new commit after the import, or by rewriting only the latest commit: git commit --amend --no-edit --no-verify --gpg-sign .

Despite the name of the switch, it also works if you use SSH key commit signing.

git-sha256.dj

---kdl
title "Migrating Git repos to SHA-256"
description "This is so extremely underdocumented!!"
tags Computering
---

{author=una}
SHA-256 is [the new object format in town](https://git-scm.com/docs/hash-function-transition), available since Git 2.42. It has a few benefits:

* No real security benefit. [SHA-1dc](https://github.com/cr-marcstevens/sha1collisiondetection) is good enough.
* {-Not compatible with GitHub. Harder for others to steal your code and feed it to Copilot.-}
* Even longer and even more unwieldy object IDs, further encouraging tagging and shorthand.
* Street cred from using the cool new hash function?
* Gives most third-party Git tools (jujutsu/gitoxide, Eclipse/JGit, etc) indigestion...? Wait that's not a benefit

It's pretty easy to find the steps to do a migration of a basic repo that lacks submodules online (not in the Git documentation, of course, just on various random web pages):

:::named-code-block
`In the old repo:`

```bash
git fast-export --all > export
```

:::

----

:::named-code-block
`In the new repo:`

```bash
git init --object-format sha256
git fast-import < ../old/export
```

:::

:::alert
Let me be clear for skimmers: *This explodes if your repository contains submodules.*
:::

I don't know how to handle the case where you have a third-party submodule, which is unfortunately one of the most common cases. It would appear when adding a SHA-1 submodule to a SHA-256 repository that the SHA-1 object ID is just... padded with zeroes.

There's mention of a mystical option to fast-import and fast-export that allows you to transfer marks to rewrite the old SHA-1 sub-modules into SHA-256 sub-modules. However, this is the extent of the documentation:

> ```
> --rewrite-submodules-from=<name>:<file>
> --rewrite-submodules-to=<name>:<file>
> ```
> Rewrite the object IDs for the submodule specified by <name> from the values used in the from <file> to those used in the to <file>. The from marks should have been created by `git fast-export`, and the to marks should have been created by `git fast-import` when importing that same submodule.
> 
> <name> may be any arbitrary string not containing a colon character, but the same value must be used with both options when specifying corresponding marks. Multiple submodules may be specified with different values for <name>. It is an error not to use these options in corresponding pairs.
> 
> These options are primarily useful when converting a repository from one hash algorithm to another; without them, fast-import will fail if it encounters a submodule because it has no way of writing the object ID into the new hash algorithm.

— [https://git-scm.com/docs/git-fast-import](git fast-import manpage)

Maybe I'm just dense, but it's not very clear what you need to do here. No references are made to other commands or their switches that might be needed — and no sample is given, not even in the mailing list when this feature was introduced.

There's not even a degraded case when you use fast-import and submodules are present... it just crashes:

```log
fatal: object not found: 9444d0177d5a2489df1ce626347cd29dc4e8b3b4
fast-import: dumping crash report to fast_import_crash_897126
```

So, here's the series of steps for converting a repo and its submodule:

:::named-code-block
`In the old submodule:`

```bash
git fast-export --export-marks=marks --all > export
```

:::

::: warning
*Caveat*: If the referencing repo has ever referenced a commit that is no longer part of a current branch (e.g. a force-push occurred) then this will not export all the necessary objects. You will need to specify the orphaned objects as additional parameters to `fast-export` here, in addition to the branches.
:::

----

:::named-code-block
`In the new submodule:`

```bash
git init --object-format sha256
git fast-import --export-marks=marks < ../old-submodule/export
```

:::

:::note
You can also pass `--ref-format reftable` to `git init` to try [the new repository index format](https://git-scm.com/docs/reftable).
:::

----

:::named-code-block
`In the old repo:`

```bash
git fast-export --all > export
```

:::

----

:::named-code-block
`In the new repo:`

```bash
git init --object-format sha256
git fast-import \
	--rewrite-submodules-from=blah:../old-submodule/marks \
	--rewrite-submodules-to=blah:../new-submodule/marks \
		< ../old-repo/export
```

:::

_With this context_, the documentation makes a lot more sense. But without that prior knowledge, it's just meaningless soup.

You can repeat the `rewrite-submodules` options as many times as you like, but the left-hand-side must be a unique string for each submodule and match for each submodule. It's easiest to just set it to the name of the submodule rather than "blah".

Here's the repo I successfully migrated with this strategy: [Rewind Upsilon](https://git.sleeping.town/Rewind/Upsilon).

## Bonus: Migrating a Forgejo repo in-place

Forgejo would really like you to delete the repo and make a new one that's initialized with the SHA-256 object format. If you have access to your Forgejo server, you don't need to [wait for this feature request](https://codeberg.org/forgejo/forgejo/issues/2609) to do this.


:::warning
This is _extremely_ a hack and might have severe knock-on consequences. At the very least, it will break all existing references to exact commits in your repo. Tag references should be preserved.
:::

### Migrate the git repo

First, enter the directory your repo lives in — `$FORGEJO_DATA_HOME/gitea-repositories/$ORG`{.nowrap}, something like `/opt/forgejo/data/gitea-repositories/rewind/`{.nowrap}.

At this point, you can choose to do the migration on your local computer and push it afterwards, or do the migration on the server.

#### Do the migration on the server

Follow the above instructions but add `--bare` when using `git init` to work with the bare repos that Forgejo expects. For example, you could have `repo.git` as your "old repo" and `repo.sha256.git` as your "new repo". Once you're sure everything looks good, delete the old repo and rename the new repo to its name:

```bash
rm repo.git -rf
mv repo.sha256.git repo.git
```

[Why put `-rf` at the end?](/garden/rimraf/){.small}

#### Do the migration locally

Follow the instructions on a local clone, and then replace the server copy with an empty repo:

```bash
rm repo.git -rf
git init --object-format sha256 --bare repo.git
```

[Why put `-rf` at the end?](/garden/rimraf/){.small}

The remote copy is now an empty repo, and may not show up in the web UI. Do a push with `--mirror`{.nowrap} to upload everything from the migrated repo.

### Update the database

At this point, the repo will half-work in the web UI with some disconnects in how object IDs are described/shown, and there will be a big ugly warning about misconfigured git hooks. We need to now tell Forgejo this repo is SHA-256.

Find your repo's internal ID in the settings. The easiest place to find this is as part of the ActivityPub URL, which will look something like `https://git.sleeping.town/api/v1/activitypub/repository-id/50`{.nowrap} — 50 is the internal ID.

Open a SQL shell and `USE` the Forgejo schema. Then, where `?` is the internal ID:

```sql
UPDATE repository SET object_format_name = "sha256" WHERE id = ?;
```

Refresh the web UI. There will now be a "SHA256" badge on your repo.

### Resync Forgejo with Git

Finally, go to the Site Administration section and run all of the following actions, in order:

* Sync missed branches from git data to databases
* Sync tags from git data to database
* Resynchronize pre-receive, update and post-receive hooks of all repositories

All done. The repo should now be migrated, without losing issues, wiki, PRs, projects, etc.

## Bonus: Re-signing all commits after the migration

```bash
git rebase --exec 'git commit --amend --no-edit --no-verify --gpg-sign' --root
```

This rewrites every commit, and therefore won't work for submodules as it will break all the relationships established by the mark files. It's worth noting that a single signed commit at the head of a branch forms a sufficient chain of trust due to Git's structure, which can be accomplished by making a new commit after the import, or by rewriting only the latest commit: `git commit --amend --no-edit --no-verify --gpg-sign`{lang=bash}.

Despite the name of the switch, it also works if you use SSH key commit signing.

Yes, and

Hacker News
htmx.org
2026-10-08 05:48:18
Comments...
Original Article
Carson Gross

I teach computer science at Montana State University . I am the father of three sons who all know I am a computer programmer and one of whom, at least, has expressed interest in the field. I love computer programming and try to communicate that love to my sons, the students in my classes and anyone else who will listen.

A question I am increasingly getting from relatives, friends and students is:

Given AI, should I still consider becoming a computer programmer?

My response to this is: “Yes, and…”

“Yes”

Computer programming is, fundamentally, about two things:

  • Problem-solving using computers
  • Learning to control complexity while solving these problems

I have a hard time imagining a future where knowing how to solve problems with computers and how to control the complexity of those solutions is less valuable than it is today, so I think it will continue to be a viable career even with the advent of AI tools.

“You have to write the code”

That being said, I view AI as very dangerous for junior programmers because it is able to effectively generate code for many problems. If a junior programmer does not learn to write code and simply generates it, they are robbing themselves of the opportunity to develop the visceral understanding of code that comes with being down in the trenches.

Because of this, I warn my students:

“Yes, AI can generate the code for this assignment. Don’t let it. You have to write the code.”

I explain that, if they don’t write the code, they will not be able to effectively read the code. The ability to read code is certainly going to be valuable, maybe more valuable, in an AI-based coding future.

If you can’t read the code you are going to fall into The Sorcerer’s Apprentice Trap , creating systems you don’t understand and can’t control .

Is Coding → Prompting like Assembly → High Level Coding?

Some people say that the move from high level languages to AI-generated code is like the move from assembly to high level programming languages .

I do not agree with this simile.

Compilers are, for the most part, deterministic in a way that current AI tools are not. Given a high-level programming language construct such as a for loop or if statement, you can, with reasonable certainty, say what the generated assembly will look like for a given computer architecture (at least pre-optimization).

The same cannot be said for an LLM-based solution to a particular prompt.

High level programming languages are a very good way to create highly specified solutions to problems using computers with a minimum of text in a way that assembly was not. They eliminated a lot of accidental complexity , leaving (assuming the code was written reasonably well) mostly necessary complexity.

LLM generated code, on the other hand, often does not eliminate accidental complexity and, in fact, can add significant accidental complexity by choosing inappropriate approaches to problems, taking shortcuts, etc.

If you can’t read the code, how can you tell?

And if you want to read the code you must write the code.

AI is a great TA

Another thing that I tell my students is that AI, used properly, is a tremendously effective TA. If you don’t use it as a code-generator but rather as a partner to help you understand concepts and techniques, it can provide a huge boost to your intellectual development.

One of the most difficult things when learning computer programming is getting “stuck”. You just don’t see the trick or know where to even start well enough to make progress.

Even worse is when you get stuck due to accidental complexity: you don’t know how to work with a particular tool chain or even what a tool chain is.

This isn’t a problem with you , this is a problem with your environment. Getting stuck pointlessly robs you of time to actually be learning and often knocks people out of computer science.

(I got stuck trying to learn Unix on my own at Berkeley, which is one reason I dropped out of the computer science program there.)

AI can help you get past these roadblocks, and can be a great TA if used correctly. I have posted an AGENTS.md file that I provide to my students to configure coding agents to behave like a great TA, rather than a code generator, and I encourage them to use AI in this role.

AI doesn’t have to be a detriment to your ability to grow as a computer programmer, so long as it is used appropriately.

“, and…”

I do think AI is going to change computer programming. Not as dramatically as some people think, but in some fundamental ways.

Raw coding may become less important

It may be that the act of coding will lose relative value.

I regard this as too bad: I usually like the act of coding, it is fun to make something do something with your (metaphorical) bare hands. There is an art and satisfaction to writing code well, and lots of aesthetic decisions to be made doing it.

However, it does appear that raw code writing prowess may be less important in the future.

As this becomes relatively less important, it seems to me that other skills will become more important.

Communication Skills

For example, the ability to write, think and communicate clearly, both with LLMs and humans seems likely to be much more important in the future. Many computer programmers have a literary bent anyway, and this is a skill that will likely increase in value over time and is worth working on.

Reading books and writing essays/blog posts seem like activities likely to help in this regard.

Understanding Business

Another thing you can work on is turning some of your mental energy towards understanding a business (or government role, etc) better.

Computer programming is about solving problems with computers and businesses have plenty of both of these.

Some business folks look at AI and say “Great, we don’t need programmers!”, but it seems just as plausible to me that a programmer might say “Great, we don’t need business people!”

I think both of these views are short-sighted, but I do think that AI can give programmers the ability to continue fundamentally working as a programmer while also investing more time in understanding the real-world problems (business or otherwise) that they are solving.

This dovetails well with improving communication skills.

“Architecting” Systems

Like many computer programmers, I am ambivalent towards the term “software architect.” I have seen architect astronauts inflict a lot of pain on the world.

For lack of a better term, however, I think software architecture will become a more important skill over time: the ability to organize large software systems effectively and, crucially, to control the complexity of those systems.

A tough part of this for juniors is that traditionally the ability to architect larger solutions well has come from experience building smaller parts of systems, first poorly then, over time, more effectively.

Most bad architects I have met were either bad coders or simply didn’t have much coding experience at all.

If you let AI take over as a code generator for the “simple” stuff, how are you going to develop the intuitions necessary to be an effective architect?

This is why, again, you must write the code.

Using LLMs Effectively

Another skill that seems likely to increase in value (obviously) is knowing how to use LLMs effectively. I think that currently we are still in the process of figuring out what that means.

I also think that what this means varies by experience level.

Seniors

Senior programmers who already have a lot of experience from the pre-AI era are in a good spot to use LLMs effectively: they know what “good” code looks like, they have experience with building larger systems and know what matters and what doesn’t. The danger with senior programmers is that they stop programming entirely and start suffering from brain rot .

Particularly dangerous is firing off prompts and then getting sucked into The Eternal Scroll while waiting.

Ask me how I know.

I typically try to use LLMs in the following way:

  • To analyze existing code to better understand it and find issues and inconsistencies in it
  • To help organize my thoughts for larger projects I want to take on
  • To generate relatively small bits of code for systems I am working on
  • To generate code that I don’t enjoy writing (e.g. regular expressions & CSS)
  • To generate demos/exploratory code that I am willing to throw away or don’t intend to maintain deeply
  • To suggest tests for a particular feature I am working on

I try not to use LLMs to generate full solutions that I am going to need to support. I will sometimes use LLMs alongside my manual coding as I build out a solution to help me understand APIs and my options while coding.

I never let LLMs design the APIs to the systems I am building.

Juniors

Juniors are in a tougher spot. I will say it again: you must write the code.

The temptation to vibe your way through problems is very, very high, but you will need to fight against that temptation.

Peers will be vibing their way through things and that will be annoying: you will need to work harder than they do, and you may be criticized for being slow. The work dynamics here are important to understand: if your company prioritizes speed over understanding (as many are currently) you need to accept that and not get fired.

However, I think that this is a temporary situation and that soon companies are going to realize that vibe coding at speed suffers from worse complexity explosion issues than well understood, deliberate coding does.

At that point I expect slower, more deliberate coding with AI assistance will be understood as the best way to utilize this new technology.

Where AI can help juniors is in accelerating the road to senior developer by eliminating accidental complexity that often trips juniors up. As I said above, viewing AI as a useful although sometimes overly-eager helper rather than a servant can be very effective in understanding the shape of code bases, what the APIs and techniques available for a particular problem are, how a given build system or programming language works, etc.

But you must write the code.

And companies: you must let juniors write the code.

Getting a Job Today

The questions I get around AI and programming fundamentally revolve around getting a decent job.

It is no secret that the programmer job market is bad right now, and I am seeing good CS students struggle to find positions programming.

While I do not have a crystal ball, I believe this is a temporary rather than permanent situation. The computer programmer job market tends to be cyclical with booms and busts, and I believe we will recover from the current bust at some point.

That’s cold comfort to someone looking for a job now, however, so I want to offer the specific job-seeking advice that I give to my students.

Family, Friends, Family of Friends

I view the online job sites as mostly pointless, especially for juniors. They are a lottery and the chances of finding a good job through them are low. Since they are free they are probably still worth using, but they are not worth investing a lot of time in.

A better approach is the four F’s: Family, Friends & Family of Friends. Use your personal connections to find positions at companies in which you have a competitive advantage of knowing people in the company. Family is the strongest possibility. Friends are often good too. Family of friends is weaker, but also worth asking about. If you know or are only a few degrees separated from someone at a company you have a much stronger chance of getting a job at that company.

I stress to many students that this doesn’t mean your family has to work for Google or some other big tech company.

All companies of any significant size have problems that need to be solved using computers. Almost every company over 100 people has some sort of development group, even if they don’t call it that.

As an example, I had a student who was struggling to find a job. I asked what their parent did, and they said they worked for Costco corporate.

I told them that they were in fact extremely lucky and that this was their ticket into a great company.

Maybe they don’t start as a “computer programmer” there, maybe they start as an analyst or some other role. But the ability to program on top of that role will be very valuable and likely set up a great career.

Conclusion

So I still think pursuing computer programming as a career is a good idea. The current job market is bad, no doubt, but I think this is temporary.

I do think how computer programming is done is changing, and programmers should look at building up skills beyond “pure” code-writing. This has always been a good idea.

I don’t think programming is changing as dramatically as some people claim and I think the fundamentals of programming, particularly writing good code and controlling complexity, will be perennially important.

I hope this essay is useful in answering that question, especially for junior programmers, and helps people feel more confident entering a career that I have found very rewarding and expect to continue to do for a long time.

And companies: let the juniors write at least some of the code. It is in your interest.

</>

AHM Statement on OpenAI's October 6 Release of Mathematical Documents

Hacker News
www.ahmath.org
2026-10-08 05:29:48
Comments...
Original Article

AHM Statement on OpenAI’s October 6 Release of Mathematical Documents

Yesterday, on October 6th, 2026, OpenAI – which is currently defending lawsuits against accusations of illegal plagiarism, copyright infringement, and trademark dilution – released a repository of manuscripts purporting to contain solutions to a number of high-profile problems in mathematics.

Mathematicians did not ask for this work to be done. The Advisory Group on Mathematics and Artificial Intelligence, from whom OpenAI has claimed to derive its legitimacy, opened their initial advisory statement by saying that frontier AI corporations should not test advanced mathematical problems on internal models. In ignoring the central premise of the Advisory Group’s position, OpenAI has indicated total disregard for the norms of scientific research — norms that guarantee that mathematics remains trustworthy, ethically researched, and in the public interest.

Mathematicians have a particular vision of progress that is informed by history and field-specific considerations. We reject OpenAI's assertion that this release advances our subject, and we urge mathematicians and the public to view the value of this publication model with due skepticism.

Releasing over 700 files at once is not a demonstration of scholarship, but a demonstration of power. We urge mathematicians to discontinue their work with OpenAI and to return to a vision of science that centers human understanding.

Association for Human Mathematics
Communications Working Group

Gentoo infrastructure sponsors wanted

Lobsters
www.gentoo.org
2026-10-08 05:23:49
Comments...
Original Article

Larry behind a server rack

Gentoo Linux is made possible by many community donations and sponsors, together with the enthusiastic work of our developers. Unfortunately, this year several long-running sponsors were unable to continue their prior support, and at the moment we are looking for replacements. Are you or your organization interested in supporting Gentoo via an infrastructure sponsorship? There are many ways to do that , ranging from providing rack space or servers in a data center to donating server hardware; details and typical arrangements are described on a wiki page of the Infrastructure project . Partnerships with organizations aligning with Gentoo’s goals are strongly preferred. We can be reached at infra@gentoo.org . Please help us continue to provide the best source-based Linux distribution ever!

Beyond the &

Lobsters
lwn.net
2026-10-08 05:04:32
Comments...
Original Article

[LWN subscriber-only content]

Welcome to LWN.net

The following subscription-only content has been made available to you by an LWN subscriber. Thousands of subscribers depend on LWN for the best news from the Linux and free software communities. If you enjoy this article, please consider subscribing to LWN . Thank you for visiting LWN.net!

Rust has a number of kinds of smart pointers, both in the standard library and defined by users. Still, some operations that are possible with built-in references are not possible to perform with user-defined smart pointers. Tyler Mandry, lead of the Rust project's language team , spoke at RustConf 2026 about the lengthy effort to change that, and make smart pointers just as flexible as built-in references.

He has been working on this problem all through 2026, Mandry said, alongside several other interested members of the language team, under the project name "Beyond the &" . It took a good deal of thought, but the design that they have arrived at should allow a substantially simpler mental model of how pointers and references work. To illustrate the problem that this design solves, he put up an example of a simplified Rust program that calculates some dynamic content and caches it in a hash map. The example uses Rust's map-entry API, which provides a function called or_insert_with() that takes a callback to populate the hash-map entry if it is empty.

    struct RenderState {
        cache: HashMap<String, Arc<String>>,
        template: String,
    }
    
    fn render_page(state: &mut RenderState, name: &str) -> Arc<String> {
        // Mutably borrow `state.cache` using the Entry API.
        let entry = state.cache.entry(name.to_string());
        entry.or_insert_with(|| {
            // Create the entry if it doesn't exist.
            Arc::new(state.template.replace("$name", name))
        }).clone()
    }

This code looks up a cache key ( name ) in the hash map, and either returns a copy of the cached value, or calculates it by substituting name into a template if it doesn't exist. The shared state is accessed using a built-in mutable reference, &mut RenderState . The example works, but it can't safely be shared between threads. Adding a mutex, to allow the cache to be shared, causes the borrow checker to reject the program:

    fn render_page(state: &Mutex<RenderState>, name: &str) -> Arc<String> {
        let state: MutexGuard <' _ , RenderState> = state.lock().unwrap();

        // The borrow checker complains that "state" is mutably borrowed here:
        let entry = state.cache.entry(name.to_string());
        entry.or_insert_with(|| {
            // ... but then used here while it is still borrowed:
            Arc::new(state.template.replace("$name", name))
        }).clone()
    }

The original code worked, Mandry said, because the borrow checker was able to track that state.cache and state.template were separate fields, so it was safe to access them at the same time. With the addition of the mutex, the borrow checker just sees opaque accesses to a MutexGuard structure, and can no longer tell that the accesses are disjoint — it has to consider the case where the mutable borrow is used to edit the state at the same time that the callback reads from it, causing a potentially invalid data race. A simple fix in this case is to dereference the MutexGuard once, and reborrow the structure behind it:

        let state: &mut RenderState = &mut *state.lock().unwrap();

This constructs a new built-in reference, just like the original code used, so the borrow checker can once again see that the accesses don't interfere with each other. That works, but it's not particularly intuitive. Mandry said that complexity like this contributes to Rust's difficult learning curve. It would be better if user-defined pointer types such as MutexGuard behaved more like built-in references.

[Tyler Mandry]

Pointer types are everywhere, he continued. And all of them have slightly different semantics. Some pointers can't be safely dereferenced (raw pointers), or can be written to but not read from ( MaybeUninit ), etc. This demonstrates Rust's versatility, but it also makes it hard to come up with a design that works for the many possible pointer types.

The solution the language team settled on, based on the work of Nadrieril and Benno Lossin, was to expose the compiler's internal notion of a "place" to user code. A place is Rust's equivalent of C's left-hand sides (lvalues): a location that values can be read from or written to. The difference between a place and a pointer is that a place is an abstract expression that exists at compile time, such as state.cache , and a pointer is one way to represent a place at run time.

The idea is to create a new handle type for every smart pointer. Often the handle will simply be a wrapper around an unsafe pointer to the same location. Then, the compiler will automatically create handles to represent places referenced by the program. That allows user code to implement traits on a handle type that will affect how the borrow checker interacts with handles which correspond to a custom smart pointer, with a higher degree of flexibility than the existing Deref and DerefMut traits. As an example of what that would look like, Mandry showed how a library author might go about teaching the borrow checker how to handle writes to places that are accessed via a NonNull pointer:

    unsafe impl<T> WritePlace for NonNullHandle<T> {
        const SAFE: bool = false;
        unsafe fn write_place(self, value: T) {
            unsafe { self.0.write(value) }
        }
    }

The WritePlace trait would be used to tell the borrow checker that a particular kind of handle (in this case, a handle referencing a NonNull pointer) can be written to, and how. When SAFE is set to false, the borrow checker treats writing to the associated place as an unsafe operation. The actual write is forwarded through to the raw pointer that NonNull wraps. The whole trait implementation is unsafe because an incorrect implementation of the trait could cause the borrow checker to make a mistake and result in unsound behavior.

A corresponding ReadPlace trait encodes how to read from a handle. More interesting are ProjectPlace and BorrowPlace . The former tells the borrow checker how to turn a place containing a structure into a place containing one of its fields. For example, how to turn (the handle for) a MutexGuard<RenderState> into a MutexGuard<String> when the programmer writes state.template . The latter tells the borrow checker how to create a new smart pointer that borrows a given place, the same way that & works for built-in references.

The language team is still debating what the syntax for creating a new smart pointer with BorrowPlace should be. While it could use the same & symbol, that might be confusing and make it harder to use type inference. One proposal is to use an @ symbol instead, but people aren't entirely happy with that either. No matter what syntax is eventually decided on, the BorrowPlace trait encodes all of the information that the borrow checker needs to know in order to safely handle the pointer type. This means that currently built-in behavior can be defined via the same mechanism. For example, this is what an implementation for the built-in reference type &T would look like:

    unsafe impl<'a, T> BorrowPlace<&'a T> for RefHandle<'a, T> {
        // Tell the borrow checker that multiple references can be made to the
        // same place at the same time:
        const ACCESS: AccessKind = AccessKind::Shared;
        // And that the borrow lasts for the lifetime 'a:
        type Timing = Lifetime<'a>;
        // And that creating references is a safe operation:
        const SAFE: bool = true;

        unsafe fn borrow(self) -> &'a T {
            unsafe { &*self.ptr.as_ptr() }
        }
    }

That gives users an example of how to write their own smart pointers that act like references, and gives the standard library maintainers a place to document existing counterintuitive built-in behaviors. With a similar implementation of a handle type for MutexGuard , the earlier render_page() example works without errors. Mandry called it " a small code change for this example, but a big semantic shift. "

Tying smart pointers more closely to the compiler's existing internals has other benefits, however. Currently, it is possible to use pattern matching on a value behind a reference, but not on a value behind a smart pointer — at least without dereferencing the pointer and reborrowing the value behind it. The details exposed by BorrowPlace would be enough to let the compiler safely implement those pattern matches.

One of the criteria that the language team looks for in new features is composability, Mandry said: how well the prospective feature integrates into the existing structures of the language, and how well multiple uses of the feature compose with each other. Handles and places " compose beautifully " because it is just exposing some details of how the compiler already understands and processes the language.

Despite that, exposing places and handles to library code is still a prototype. Mandry asked for help ensuring that the design would work for everyone's use cases; he asked the audience to look at the design documentation and add their own examples of smart pointers with weird semantics. " If you have an abstraction that you want to have more deeply integrated into the language, please help us out by trying this, and telling us about any roadblocks. "

The next part of the design that he intends to flesh out is errors and diagnostic messages. Ideally, users should never see errors mentioning the newly added traits; those would remain internal, and the error messages would explain the problem directly, as they do for built-in references. Even though there is much more work to do before it can become a stable part of the language, Mandry is optimistic about this design. " My hope is that it will let libraries make Rust even more powerful and friendly. "

One audience member wanted to know whether this design would also support destructive pattern matching (a combined operation that takes ownership of a value while matching it against possible patterns, pulling it apart into its component pieces). Mandry said that it would, as long as the developer implemented a VariantPlace trait for the appropriate handle. There are six to eight operations to implement to support every operation on a handle type, and that's one of them, he said.

Another audience member asked whether the design would also work for enumerations in general. Mandry paused, stared out into space for a moment, and then let out a hesitant and elongated yes. Projecting a field from an enumeration in general will probably not be possible, he elaborated, but there has been some exploratory work in that direction. For example, should it be possible to project a field from inside an Option to obtain an Option of the field value? " I don't know the answer, but it's an interesting question, " Mandry remarked, just before time for the session ran out.

[ Thanks to the Linux Foundation, LWN's travel sponsor, for assistance in traveling to Montreal for RustConf. ]


Index entries for this article
Conference RustConf/2026



jujutsu (jj) 0.46.0

Lobsters
github.com
2026-10-08 05:02:42
Comments...
Original Article

About

jj is a Git-compatible version control system that is both simple and powerful. See
the installation instructions to get started.

Release highlights

  • Jujutsu can now colocate workspaces besides the default one by creating Git
    worktrees. Use jj workspace add --[no-]colocate and the setting
    git.colocate to control this.

Breaking changes

  • The minimum supported git command version is now 2.42.0, up from 2.41.0.
    jj workspace add uses git worktree add --orphan , which was added in
    2.42.0.

  • The minimum supported Rust version (MSRV) is now 1.97.1.

  • jj bisect run now runs some consistency checks before proceeding to bisect.
    This helps ensure that the command can tell good and bad revisions apart,
    and that the working copy does go from bad to good over the provided revset.
    Use the new flag --trust-endpoints to disable these checks.

  • jj split now opens a single editor session to edit descriptions for the
    split commits.

  • jj undo and jj redo now refuse to undo/redo an operation that was
    performed in another workspace. Use --allow-cross-workspace to undo/redo
    it anyway.

  • jj workspace list / root no longer omit unreachable paths. All recorded
    paths are now shown, with warnings displayed in jj workspace root .

  • The List.get() , .first() , and .last() template functions now return
    Option<T> instead of throwing an error on out-of-bounds access.

New features

  • jj workspace add supports --colocate / --no-colocate flags to control
    whether a Git worktree is created alongside the workspace. The default
    colocates when the current workspace is colocated and the git.colocate
    config is true . jj workspace forget removes the corresponding Git
    worktree when one exists.

  • jj git colocation status / enable / disable now work on child
    workspaces. status correctly reports colocation state and includes
    the workspace name. enable creates a Git worktree and disable
    removes it, allowing colocation to be toggled after workspace
    creation.

  • jj workspace remove removes a workspace and its directory from disk. The
    working-copy state is snapshotted into a commit before removal.

  • Added commands jj file edit and jj file delete for editing files in any
    revision without needing to change the working copy.

  • jj git push now supports pushing to multiple remotes at the same time.
    This can be configured via git.push set to a string pattern
    or array of string patterns, or with the repeatable --remote flag,
    which also accepts string patterns.

  • The default target revisions for jj git push can now be configured via
    revsets.git-push .

  • Added the TreeEntry.normal_value() template method and the TreeValue type
    to access resolved tree values, formatted as their full object IDs, including
    Git submodule commit IDs.

  • Diff hunk headers now include nearby source symbols for many common
    programming and markup languages.

  • fix.tools.<name>.line-range-args (replaces line-range-arg ) is an array of
    string template args to pass to the fix tool. This is more flexible in cases
    where you need to pass multiple arguments to the tool, such as separate args
    for the range start and range end.

  • jj run now uses the sparse patterns from the workspace it's run from.
    Use the --sparse-patterns option to control this behavior (evaluated
    per each jj run invocation).

  • jj util diff <path1> <path2> to compare files on disk.

  • Aliases now support setting aliases.<name>.enabled = false , which will
    disable them. This can be used to disable built-in aliases or disable aliases
    in later layers (such as repo config files).

  • ui.editor now supports $path and $line substitution variables. Example:
    ui.editor = ["emacs", "+$line", "$path"]

  • fill template function now supports an additional named parameter
    break_words , that allows specifying if the template should break words
    longer than width passed in the input to ensure no words overflow the
    specified width.

  • The json() template function now supports map literals: json({'key' => value})

  • The hunk headers of diff.color-words.conflict = "pair" now include the
    conflict labels of the compared terms.

Fixed bugs

  • On Windows, jj no longer hangs when a subprocess needs to prompt the user,
    such as ssh asking for a key passphrase or for confirmation of an unknown
    host key. Subprocesses started from a terminal now inherit its console, rather
    than being given an invisible one by CREATE_NO_WINDOW for the prompt to
    disappear into.
    #6745
    #8547

  • On Windows, jj git colocation enable and jj git colocation disable no
    longer fail with "Access is denied (os error 5)" when the Git repository
    contains pack files.
    #8661

  • jj undo of jj workspace forget now correctly preserves the workspace's
    recorded path. Previously the path metadata was lost, leaving the workspace
    in a broken state after undo.
    #9991

  • at_operation() can now be used with operations that are not ancestors of
    the current operation (e.g. sibling operations created by concurrent
    commands). Previously, evaluating such expressions failed if they resolved
    to commits missing from the current operation's index.

  • .gitignore files are now respected even if they aren't materialized in the
    working copy because they are excluded by the sparse patterns. Previously,
    ignored files could become tracked in a sparse working copy.
    #2289

  • In-tree ignore files ( .gitignore ) are no longer read through symlinks,
    matching git behavior. Such files are now silently skipped instead of having
    their symlink target applied. $GIT_DIR/info/exclude and core.excludesFile
    are unaffected and still follow symlinks, as git does.
    #7161

  • jj workspace list templates are now labeled with workspace name ,
    workspace root , etc.

Contributors

Thanks to the people who made this release happen!

Co-op Legal Services using AI to rate workers’ phone calls to customers

Guardian
www.theguardian.com
2026-10-08 05:00:16
Whistleblower says recording and analysis of all probate calls is ‘oppressive and dystopian’ The Co-op has become the latest employer to place workers under AI surveillance with an automated listening technology that rates every phone call some of them make to customers. In a system described as “op...
Original Article

The Co-op has become the latest employer to place workers under AI surveillance with an automated listening technology that rates every phone call some of them make to customers.

In a system described as “oppressive and dystopian” by a whistleblower, Co-op Legal Services is using AI models to record, analyse and award a percentage score for interactions between agents and customers seeking advice about probate, wills and estates.

A model from OpenAI has been trained to assess more than 50 discrete aspects of each phone call and provide pass and fail scores to managers who use the data to analyse employee performance. One worker said the system can mean their work is monitored by AI for several hours a day as they handle inquiries often from recently bereaved customers.

It comes after the Guardian last week revealed Euan Blair’s AI training company, Multiverse, has started using an AI for blanket monitoring of online classroom sessions , which teachers called “remorseless” and “unnerving”, while Multiverse said it was “using AI to improve the experience of learners and customers”. Experts have voiced fears that increasing AI monitoring of workers risks increasing stress.

“You are being watched,” said a Co-op worker who spoke to the Guardian on condition of anonymity and said the AI created a sense of distrust. “It’s different from occasionally being listened to for compliance purposes. [You are] being monitored absolutely every word that you say and every time that you utter something … It just feels really dystopian. It’s the thin end of the wedge.”

The Co-op, which operates supermarkets, undertakers, insurance and legal services companies, said it did not recognise the criticism and said its probate advisers were highly engaged. It said it supported colleagues with AI, which is a “key aspect of our quality assurance processes” and helps ensure “our clients consistently receive empathetic expert guidance”.

The AI monitoring is understood to have been introduced in the last couple of months into the work of dozens of legal services staff. It is used in part to identify ways they can boost their sales performance.

The Co-op said the AI is used solely as a support tool, is not a decision-maker, and helps leaders “support colleagues and continuously improve the experience we provide to clients”.

Trade unions have begun pushing back against the spread of AI monitoring. In February Burger King in the US announced it would be using the technology to track restaurant workers’ customer interactions , and this summer, Meta paused tracking of employees’ computer keystrokes amid data privacy concerns and a staff backlash.

“AI is sold as the solution to every problem, but examples like this make it clear that it can diminish sensible workplace practices and intensify working lives for no reason,” said John Chadfield, the national officer of the Communication Workers Union. “Unaccountable computer systems should not be people’s managers, and these hard-working employees demand far more respect.”

“The office is becoming more like a factory now our performance feedback can be given in a more structured way,” said Hayfa Mohdzaini, a senior policy and practice adviser at the Chartered Institute of Professional Development. “Clearly some people have a problem with it. It will be interesting to see how it develops and how much managers need to adjust their approach.”

skip past newsletter promotion

This year, the International Labour Organization warned about the “psychosocial” risks of AI monitoring , including increasing work-related stress.

“AI systems are being deployed in workplaces in the absence of a comprehensive regulatory framework,” it said. “Preventing the risk of harm by AI use and operation in this context may not be straightforward.”

Caoilionn Hurley, the managing director of Co-op Life Services, which includes legal services, said: “The efficiency of AI over traditional methods allows us to review all customer conversations to ensure we consistently deliver high standards of service, while enabling more informed support, coaching and development for colleagues … Put simply, our goal is to provide expert support combined with empathy and understanding for every client at what can be a difficult time. AI helps us deliver that more consistently, while human judgment, accountability, care and kindness remain at the heart of every client relationship.”

Why Arturo Béjar left Meta – and blew the whistle: ‘I don’t recall Mark ever being empathetic’

Guardian
www.theguardian.com
2026-10-08 05:00:15
Béjar’s daughter was 14 when she told him Instagram was failing to keep her safe. So when he became part of Meta’s ‘wellbeing team’, he knew he had to speak out – and his testimony cost it billions The Social Reckoning hits cinemas this Friday, but the real world has already been working on a sequel...
Original Article

T he Social Reckoning hits cinemas this Friday, but the real world has already been working on a sequel – or rather, a threequel. Directed by Aaron Sorkin, the movie is a follow-up to The Social Network, detailing the further misadventures of Mark Zuckerberg and his social media empire, and in particular Frances Haugen , the employee who in 2021 leaked internal documents that appeared to show Facebook was aware of the harms its products had inflicted.

It’s no spoiler to reveal the film climaxes with Haugen’s testimony to the US Senate, on 5 October 2021. That very same day, Arturo Béjar, a consultant on the wellbeing team of Instagram (which is also owned by Facebook), hit send on a long-gestating email to Zuckerberg and other senior Facebook executives on a similar theme. “I wanted to bring to your attention what I believe is a critical gap in how we as a company approach harm, and how the people we serve experience it,” Béjar began, before laying out some shocking statistics from his team’s survey. For example: 24.4% of 13-15-year-olds on Instagram said they had received unwanted advances, and 21.8% said they had been the target of bullying on the platform in the past seven days . Furthermore, 51% of Instagram users said they had had a bad or harmful experience in the past seven days. Only 1% of them reported it, and of those, 2% had the content taken down – so just 0.02%. This was a far greater degree of harm than the company’s existing measurements suggested. Zuckerberg never replied.

By that time, Béjar had worked at Facebook (which rebranded as Meta later that month) for a total of eight years. He had learned how to communicate with Zuckerberg. “You couldn’t talk to Mark about, ‘We have to do this thing to prevent suicide because it’s the right thing to do,’” he says. “You had to put everything in terms of metrics. That was his language. That’s how he related to things, which is also what’s behind all the grief in the world right now.”

Jeremy Strong as Mark Zuckerberg in The Social Reckoning.
Jeremy Strong as Mark Zuckerberg in The Social Reckoning. Photograph: Everett Collection/Alamy

Béjar has seen The Social Reckoning, and he recognises Jeremy Strong’s portrayal of Zuckerberg as a detached, awkward, humourless control freak all too well. “Oh, it’s accurate,” he says. “I don’t recall him ever being empathetic to the harm that somebody was experiencing and wanting to make that better … The only thing that really consistently came across in all my interactions with him was winning. He’s one of the most fiercely competitive people I know.”

One time, Béjar recalls, he and Zuckerberg were walking together after a fraught meeting. “One of the things that I used to say when bad things were happening is, ‘Are we having fun yet?’ Just as a little kind of defusing humour thing,” says Béjar. “And he looked at me, very intense, and said, ‘I’m not here for fun – I’m here for impact.’ That was my experience of him, over and over and over again.”

That 2021 email was the beginning of the end for Béjar. He was still hoping Zuckerberg would respond to his appeal to engineer a “culture shift” in the way Instagram dealt with protecting its young users. The next day, however, Zuckerberg issued a statement to Facebook employees about Haugen’s testimony and the leaked “ Facebook Files ” that were being reported by the Wall Street Journal and others. “At the heart of these accusations is this idea that we prioritise profit over safety and wellbeing. That’s just not true,” Zuckerberg wrote. But by then Béjar knew it was true.

By 2023, Béjar was following in Haugen’s footsteps and testifying to the US senate himself. He has testified under oath against Meta at least seven times since, by his reckoning, in various trials and hearings. The most recent, and consequential, was the landmark trial in California in August, brought by the attorneys general of 29 US states, which alleged once again that Meta knowingly designed products that were addictive and harmful to minors. In his testimony , Béjar stated: “You just cannot trust Mark Zuckerberg with kids.”

portrait of Haugen speaking at an event
Frances Haugen, the former Facebook employee who testified against the company in court. Photograph: Mike Bowers/The Guardian

In many respects Béjar is the perfect witness: sincere, calmly spoken, emotionally literate, able to express complex ideas in accessible ways, and possessing reams of inside knowledge. He’s seemingly the opposite of Zuckerberg. At times during our conversation, as we sit outside a cafe in north London, he has to pause mid-sentence, his eyes welling with tears. He apologises afterwards for getting emotional, but that seems to be exactly what these issues demand.

There’s another reason Béjar has been such a powerful spokesperson: he has a direct connection to the issues, via his teenage daughter. When she was in her early teens, in about 2018, she told him she regularly received sexist comments and unsolicited nude photos from men via her Instagram account. Her female friends experienced the same thing. There was no point reporting it, she told him, because it never resulted in any meaningful action. Commenters might get blocked – after which they would simply open a new account under a different name – or Instagram would judge that the behaviour didn’t violate their policies.

Until that point, like many early Facebook employees, Béjar believed he was making the world a better place. When he started in 2009, the company was booming and the idealism was infectious. “The promise was, we’ll create something that keeps you close to your friends. I think a lot of people back then believed in that. And that’s not what they built.”

Arturo Bejar gestures, on a bench in a London square
Powerful spokesperson … Béjar. Photograph: Ethan Parker/The Guardian

Béjar, 55, was an early tech enthusiast. Born in Mexico City, the son of a doctor father and an artist mother, he taught himself to code and blagged his way into a job with IBM when he was 15. He came to Silicon Valley, after a spell in London, in 1993, and worked at Yahoo for 11 years before he joined Facebook.

As senior engineering and product leader at Facebook, Béjar was responsible for security but also for customer care: “developing tools that help people learn to be with each other online” – especially young people. For example, he developed a more nuanced way for young people to report content they didn’t like. If the button on Facebook said “report”, teens tended not to use it, but if it was changed to “I don’t want to see this”, three times as many teens would click on it. And if you could grade the intensity of that feeling, from “mildly annoying” to “really bad”, that made it easier to deal with problems.

“Most people who behave aggressively online, if you give them private, respectful feedback, they’re like, ‘Oh sorry, I didn’t mean to,’” Béjar says. “And that’s how we work as a society, right?” He gestures to the pedestrian street around us; people are peacefully going about their business. “What makes this street nice is not that there’s police everywhere enforcing our behaviour, it’s that we have all these ways where we signal to each other what it’s like to be safe, even though you might have fundamentally different values.” He built more than a dozen Facebook products on that premise, he says, with extraordinary results. “Basically, half the people change behaviour the first time you go, like, ‘Yeah, we don’t do that here.’”

He left the company, amicably, in 2015 because he was going through a divorce and wanted to spend more time with his young son and daughter. By the time he found out about his daughter’s Instagram experience, other young victims of social media were becoming known. In 2017, 14-year-old Molly Russell died from an act of self-harm in her London bedroom. The coroner’s report said her depression was exacerbated by her social media consumption, especially Instagram. Wider issues with Facebook were also beginning to emerge: its role in election manipulation, stoking ethnic violence, promoting inflammatory posts.

film still – A man jabs his fingers aggressively towards Mark Zuckerberg (played by Jeremy Strong)
Under fire … The Social Reckoning’s vision of Meta. Photograph: Sony

After raising his concerns with the company, Béjar was invited to return in 2019, on a two-year contract as a consultant on Instagram’s “wellbeing” team. “I still believed that the reason the stuff that was happening to my daughter and all her friends, and every other kid I’ve talked to since, was because as companies get big, sometimes the general doesn’t know what the soldiers are doing. That was my thesis for almost all the time I was there: Mark doesn’t know … and if he knew, he would fix it.”

Evidence to the contrary started piling up, though. “What I started finding when I came back is that they did know. They knew about addiction, they knew how bad it was. They knew about Molly Russell.” It later emerged that Facebook had internal research confirming Instagram’s negative effects on teenage mental health, but had kept it secret . The wellbeing team could not get anything done, Béjar says. “They could dream up a good product that would make things better, and they couldn’t get it out the door. You would put it through the review process and all the teams that would review it would just kill parts of it until there was nothing left.”

The ethos had changed, he says. For all the talk about connecting the world and bringing people together, the priority was simply growth, it seemed: attracting more users and keeping them on the platform for as long as possible. Video content was now set to autoplay; notifications were frequent, as were suggestions of other people to follow; “infinite scroll” algorithmically served up content tailored to users’ continuously tracked habits. All the customer care tools Béjar had previously developed – such as the “I don’t want to see this” button – had gone.

Béjar’s team developed a tool aimed at people with a history of posting comments that got reported and deleted – “the worst of the worst” – so that when they posted something inflammatory, they would get a community note telling them: “You might want to phrase this differently.” “We were in the process of getting that approved. And one of the people in the review meeting said, ‘What if 50 Cent gets this thing and makes fun of it? We can’t have that.’ That was the driver.”

The anecdote chimes with Facebook’s secretive “cross-check” system , revealed in the Facebook Files, where posts by celebrities, politicians and other high-profile “business partners” were moderated more leniently, even if they violated the company’s stated policies.

Had he known what he knows now, Béjar would never have allowed his daughter on Instagram in the first place, he says. “Instagram is built on three pillars: addictive design, connecting you to strangers, and rewarding you for doing things that are exhibitionistic, performative or aggressive,” he says. None of these are safe or desirable for young people, most people would agree. He compares social media to the tobacco industry: “This is the equivalent of handing your kids a cigarette and being like, ‘Hey, you’ll be cooler if you smoke.’” On unwanted sexual advances, he says, “What Instagram is effectively doing is, while your kid is in the bedroom, it’s lining up strangers outside the window and inviting them in.”

Zuckerberg on stage wearing the glasses and a shirt that reads “building is my love language”
Mark Zuckerberg showcasing Meta’s VR glasses last month. Photograph: Carlos Barría/Reuters

Béjar believes that the tone is squarely set by Zuckerberg, as the longtime CEO, chair and controlling shareholder of Meta: “If Mark woke up tomorrow and was like, ‘I want to create something that’s genuinely good for kids,’ it would take the company six months to fundamentally shift all these things and drive all these harms down. They have the technology, they have the people, they have the expertise, they have the infrastructure. It’s his refusal to do that which creates a culture.”

Ultimately, Béjar faced the same dilemma Haugen did. Speaking out meant ending his career, as well as being ostracised from his colleagues and his community. But, he says, “You have to ask yourself: who am I protecting? Am I protecting the company or my way of life or my being? Or am I protecting other people? It took me years, to really walk away from the identity that I had developed when I was working there.” He was emboldened by Haugen’s courageous example and by the treatment she received afterwards: “Internally, they would call her ‘the leaker’. They wouldn’t say her name.”

When approached for comment, a Meta spokesperson said: “We all share a common goal of providing safe, meaningful online experiences for young people. Our record shows that we’ve spent the past decade researching and developing numerous tools and resources to support teens and empower parents, including Teen Accounts, which place teens in protective settings by default. We’ll continue to make improvements and partner with parents and experts to keep teens safe.” Meta has repeatedly rejected implications that engagement stands in contrast to its commitment to teen safety.

Despite its best efforts to contrive a triumphant finale, The Social Reckoning ends on a bit of a sour note. There was no real reckoning for Meta. Donald Trump was re-elected; social media companies forgot about their commitment to fact-checking, Meta included. And Zuckerberg’s company continues to grow and profit from the digital economy – including the AI economy. Last month, still reeling from the reaction to Meta’s camera-enabled “ pervert glasses ”, Zuckerberg unveiled Muse, Meta’s cute and cuddly AI agent , which can perform personalised tasks such as shopping or sending emails. Even Haugen herself recently admitted : “We are worse off today than when I leaked the Facebook documents.”

Had they waited until this month, the film-makers might have been able to craft a happier ending. The landmark trial brought by multiple US states in August ended two days after Béjar’s testimony. Meta abandoned their challenge and settled the case (denying any wrongdoing). The company will have to pay out up to $18bn (£13.6bn); it’s a relatively small sum, considering that Meta’s revenue in 2025 was more than $200bn (£151.5bn). More significantly, for the first time, the company agreed to major changes to protect teens: two-hour daily time limits for under-18s across Instagram and Facebook; blocking notifications during school hours; blocking the apps at night; turning off autoplay; giving parents greater control; and other safety features.

Bejar outside the White House, with some people holding signs reading ‘protect kids online’
Béjar speaking at a rally aiming to hold tech and social media companies accountable for taking steps to protect young people online. Photograph: Jemal Countess/Getty Images for Accountable Tech

“I think it’s an extraordinary accomplishment,” says Béjar. “Nobody else in the world has got them to agree that they will reduce the hours kids spend on the platform. Or that they’re going to be more transparent about how they assess age, or that it will reduce home notifications.”

These measures won’t fix everything, but they’re progress. Meta lost another trial, brought by the US state of New Mexico in March, again over misleading the public about safety, and had to pay $942m (£713.7m) in fines and damages. There are dozens more cases in the pipeline. Governmental regulation is tightening around the world. Perhaps the tide is turning.

If it is, it will be some relief to Béjar. He has spent much of the past three years campaigning, testifying, talking to governments, academics, regulators. He has other interests beyond the tech world. Even as he was quitting Meta, he was writing the libretto for a musical collaboration with the composer Philip Glass. He is writing an opera based on Charles Darwin’s theory of emotion in animals, with the British composer Jocelyn Pook. His daughter, by the way, now earns her living restoring classic sports cars.

There’s still work to be done. What’s really needed, Béjar argues, is independent assessment and comparison of the safety of social media sites – the same way we monitor, say, vehicle emissions. “ Every parent and every kid deserves to know: what is the likelihood that this bad thing is going to happen to you on any of these services? ” But at last it feels like things are headed in that direction, he says. “It’s still just the beginning, but I do feel hope.”

‘Someone else will do it for less’: Refugees in Kenya are powering tech for dwindling pay

Guardian
www.theguardian.com
2026-10-08 05:00:15
Refugee gig workers for tech companies don’t know how much they’ll be paid – if AI hasn’t already taken their jobs In a portable building in Kakuma, a refugee camp near Kenya’s northern border with South Sudan, Grace used ChatGPT to research translations of Christian hymns in languages she doesn’t...
Original Article


In a portable building in Kakuma, a refugee camp near Kenya ’s northern border with South Sudan , Grace used ChatGPT to research translations of Christian hymns in languages she doesn’t speak. She didn’t know the client, the purpose of her work or whether she would be paid, but as a refugee unable to legally work in Kenya, she needed any opportunity she could get.

Grace, who requested anonymity due to a nondisclosure agreement, prompted ChatGPT to translate the hymn’s English text into the assigned east Asian language. She then used the translation to search for existing versions and find information about its translator, author and Christian denomination. She fed those details to AOP Connect, a crowdsourced research platform owned by British AI enterprise software company RWS.

If RWS deems her work high quality based on six listed criteria, it could award her up to $500 as a “discretionary reward”, according to RWS researcher documents and manuals reviewed by the Guardian. But refugees aren’t guaranteed wages, and most earn significantly less than the maximum without being told why, said Asha Luka Abdallah, a mentor at the Solidarity Initiative for Refugees (SIR), an organization that trains refugees to work in the tech outsourcing industry.

Remote jobs such as content moderation and data annotation have been promoted as a win-win by United Nations agencies as well as global tech companies: refugees get income opportunities, AI and social media companies get a source of cheap labor.

But interviews with more than two dozen refugees in Kakuma show that only one side has clearly benefited. Tech companies have built some of their most powerful tools on datasets handled by precarious workers , including refugees, in low-income countries. But their pay, which was never high, appears to be vanishing as entry-level tech work disappears. The shrinking number of opportunities is driving some to accept gigs for potential “rewards” rather than guaranteed wages, many said.

“It’s one of the things that keeps me awake at night,” Bahana Hydrogene, a Congolese refugee who set up the SIR’s digital skills programs in 2016, said of the increasingly opaque arrangements for refugees. “They can’t get transparent answers from these companies.”

A spokesperson for AOP Connect said the company offers researchers, regardless of location or background, the opportunity to participate in a wide range of projects. The reward structure is communicated “transparently upfront”, as is the nature of the copyright research work, but confidentiality is critical to AOP’s clients, the spokesperson said.

Pay is based on the quality, relevance and timeliness of research submitted, and the AOP Connect platform is “not AI-enabled or used for AI-model training work”, the spokesperson added.

The ‘invisible architects’

Before Grace could become a qualified researcher, she filled out a questionnaire, agreeing to keep her work confidential and complete tasks by herself. Then she was able to potentially earn money through so-called “microwork”, digital tasks broken off of large confidential projects and distributed to remote workers via online platforms.

She logged into AOP Connect to see a list of opportunities and found the hymns research project advertised at $9,000 in rewards available. That figure, however, would be divided among an unknown number of contributors as discretionary “rewards” rather than guaranteed wages, according to a notice displayed on the listing. RWS said higher-quality work leads to higher pay, but there is little transparency about how assessments are made, according to program participants and payment notices reviewed by the Guardian.

A person walks through a gate outside a single level building with a large water tank suspended on scaffolding.
The Solidarity Initiative for Refugees center in the Kakuma refugee camp on 28 September 2026. Photograph: Thabit Radjabu/The Guardian

Chatbot-assisted research on behalf of mysterious clients offering the chance to win rewards was not what Hydrogene had in mind for when he set up the SIR’s digital skills programs in 2016. He hoped the booming global outsourcing industry would help refugees earn a guaranteed income.

Some highly skilled refugees in Kakuma have found remote work through outsourcing and freelancer platforms to be a gamechanger. Those who did say they worked as web developers and software engineers interacting directly with clients. But most refugees found themselves limited to performing low-paid microwork such as data annotation for anonymous clients abroad, mediated through platforms like Remotasks, the Scale AI subsidiary that left Kenya in 2024.

Life online in Kakuma

Kakuma was originally established as a temporary home for people forced to flee the second Sudanese civil war, later expanding to accommodate people fleeing Somalia, Ethiopia and the Democratic Republic of Congo. More than 30 years later, it is one of the world’s largest refugee camps, with sprawling networks of tin-roofed buildings that make it look more like a permanent town.

On a Thursday afternoon in June, temperatures topped 95F at the SIR’s compound, about 20 minutes away from Kakuma’s main entrance. The arid landscape and severe water shortages around the camp make farming unfeasible, so the more than 300,000 residents are almost entirely dependent on humanitarian aid.

Inside an air-conditioned shipping container computer lab, five students practiced everything from basic digital literacy to full-stack programming. Nearby, three SIR graduates built websites and apps for clients outside the camp in a coworking space where they can access Starlink internet service and reliable electricity.

People work on computers
Freelancers explore digital platforms at the SIR center in the Kakuma refugee camp on 28 September 2026. Photograph: Thabit Radjabu/The Guardian

One South Sudanese software engineer said that, while he has managed to get well-paid work through the SIR and Konexio, a French organization that sources remote opportunities for refugees, he worries about future workers. Entry-level work is disappearing due to AI, he said.

“Senior engineers … are not hiring interns or junior roles,” he added.

The SIR has trained more than 2,000 refugees, connecting more than half with remote tech work ranging from long-term employment to short-term gig work. A few years ago, SIR staff said they could easily find data annotation, transcription and translation work for their students on platforms like Remotasks. Hydrogene said workers regularly took home 500 to 1,000 Kenyan shillings, or $3 to $6, a day before Remotasks shuttered in 2024. While pay was low, it was valued in a place where less than half of households have income, and those that do earn less than $50 per month.

But the microwork economy is often exploitative, said Joan Kinyua, founding president of the Data Labelers Association. The Nairobi-based organization advocates for the rights of what it calls the tech sector’s “invisible architects”, workers foundational to the industry but hidden by opaque supply chains.

People sit in rooms with colorfully painted walls in yellow and blue.
Action for Refugee Life staff at work on 29 September 2026. Photograph: Thabit Radjabu/The Guardian

Kinyua, who worked many of these jobs, said she noticed wages and conditions for entry-level data annotation eroding as early as 2018. On some platforms, she noticed that even making a small mistake, like outlining an object imperfectly, could cost her pay. Further reductions in pay and opportunities for data labeling in 2020 meant that Kinyua had to work faster for less, and had to be available anytime gigs appeared on outsourcing platforms. Eventually, she was sleeping only a few hours a night.

“You can’t afford to stay away from your computer,” she said.

In Kakuma, refugee data annotators said that at times they were tasked with labeling images and videos of weapons, gruesome bodily wounds, and pornography on various outsourcing platforms. As a result, some workers, especially those fleeing wars, experienced post-traumatic stress disorder symptoms after annotating violent material, Hydrogene said. And the opacity of some arrangements meant workers often unknowingly contributed to products they were opposed to. The Bureau of Investigative Journalism found that Somali speakers in Kakuma had done transcription work likely used by the US military, which refugees told the bureau they didn’t consent to.

A spokesperson for RWS said that AOP Connect doesn’t offer data annotation work. Scale AI did not respond to the broader findings on the industry as a whole, saying it was not in a position to comment on the practices of other companies.

Dwindling opportunities

Work became more scarce between 2022 and 2024 as Remotasks closed and automated tools such as ChatGPT took off. Na’amal, a non-profit that links refugees with global employers, noticed clients requesting skilled specialists rather than workers with basic digital literacy.

“As AI became mainstream, some jobs started to dry up,” said Lorraine Charles, Na’amal’s founder.

A sign along a road reads ‘Kakuma’ as a motorcyclist goes by.
The Kakuma-Lodwar highway, with Kakuma in the background, on 29 September 2026. Photograph: Thabit Radjabu/The Guardian

The International Trade Centre (ITC), a joint World Trade Organization and United Nations agency that has trained digital workers in Kakuma, estimates jobs such as transcription, data entry, translation and web research have declined by about 50% since 2022, said ITC spokesperson Susanna Pak. Oxford Internet Institute research similarly shows that growth of popular AI tools coincided with a measurable drop in many of the tech jobs promoted as paths to refugee self-sufficiency.

Merci Biamungu, a refugee trained in 3D modeling, said he regularly received opportunities with guaranteed pay throughout 2023 and 2024.

However, in one of his final projects, he and 20 other workers competed in teams of five to design a 3D model of a potato. The best-performing group received a reward of 15,000 Kenyan shillings, or about $116, split among the five. Now, the AI tools that Biamungu believes he helped train can build 3D images faster, eliminating the need for workers like him, he said.

It’s now been two years since Biamungu has found remote work in tech.

A man works on a computer while a woman leads a lesson at the front of the room
A learner using a laptop to practice image annotation at the Action for Refugee Life center. Photograph: Thabit Radjabu/The Guardian

“We used to get three to five jobs per month,” he said. “Now you cannot get one.”

Hubert Sanga, a Congolese refugee who established Generation Aid, another social enterprise that trains and helps refugees find work in tech, said he’s seeing entry-level work for refugees collapse as AI expands.

“One hundred per cent of the jobs we are doing right now are really at risk,” Sanga said.

Rewards, not wages

For many, the alternative to these precarious, lower-paid remote gigs is no income at a time when many families in Kakuma face starvation – partly the result of Donald Trump and Elon Musk’s dismantling of USAID last year.

“The language of ‘rewards’ instead of wages shifts risk entirely on to workers, who invest their time and expertise without any guarantee of fair compensation,” said Mark Graham, professor of internet geography at the Oxford Internet Institute.

Hydrogene, of the SIR, said clients within the microwork economy routinely threaten to take jobs to the Philippines or India if he tries to negotiate higher pay.

“AI is taking some of these jobs … and you have more talent available than there are jobs,” he said. “They say, ‘Someone else will do it for less.’”

People on bikes ride along a dusty road in a market
The Kakuma refugee camp on 29 September 2026. Photograph: Thabit Radjabu/The Guardian

Na’amal’s Charles has also noticed declines in wages, and as a result is shifting the organization away from microwork entirely. Graphic design, web design and search engine optimization trainings are also being phased out in favor of software engineering, digital marketing and e-commerce, and other jobs believed to be less vulnerable to automation.

But most refugees will struggle to become competitive candidates for such highly skilled jobs, said Konexio’s director, Fabien de Castilla, due to disruptions to their schooling and work experience. If annotation jobs are becoming obsolete, Castilla still believes that other entry-level jobs, such as data cleaning and reviewing AI outputs, might provide opportunities for refugees in the future.

Building better protections

As AI speeds up the refugees’ work, it’s also diminishing their pay. Jobs that used to take days now take hours, reducing billable time, Sanga said.

“If I’m going to take three days to do a job, [the client] says, ‘I’m going to find someone who can do it in two hours,’” he said. “It’s killing us” on pricing, he added.

Diminishing pay has prompted the SIR, Generation Aid and Action for Refugee Life, another organization that trains refugees and sources tech jobs, to push companies to offer higher wages and better conditions. But tech workers told the Guardian they feared pushing for more over concerns they’d be replaced by AI or another worker desperate for a job.

Multilateral organizations like the ITC are trying to understand how digital workers can be better protected. Pamela Coke-Hamilton, the ITC’s executive director, told the Guardian that the loss of the digital economy’s lower- and middle-level workers demands new ways of thinking about collective bargaining.

“We are at a tipping point,” she said. “AI has taken people by surprise with its speed and impact, and we need to ask what labor organizing looks like now. We need guardrails to prevent mass exploitation.”

Exterior view of a yellow-walled compound.
The Action for Refugee Life center in Kakuma. Photograph: Thabit Radjabu/The Guardian

Though workers and advocates are trying to build those guardrails, they said power ultimately rests with global tech companies, which benefit from an oversupply of cheap labor. But a “race to the bottom” is not inevitable, Graham argues. He’s pointed to the textile industry as a precedent for how pressure can change industry conditions. There, “sweatshop” scandals prompted many companies at the top of the supply chain to commit to responsible business practices at every level.

Sanga believes one practical fix is simple transparency: workers need to know who they are working for so they can understand the value of their labor. When Generation Aid sources work directly from companies, it puts workers in direct contact with the client – a sharp contrast to anonymous platform work.

Milagros Miceli, principal investigator at Data Workers’ Inquiry and research lead at the Distributed AI Research Institute, argues that the supposed choice between no job and a poorly paid one is false.

“Without data workers, tech companies do not have a product,” she said. “So there should be space for bargaining power.”

Armed Border Agents Arrest Protesters, Bulldoze 200-Year-Old Tree to Build Border Wall

Intercept
theintercept.com
2026-10-08 05:00:00
Despite at least 10 arrests and the destruction of the tree at the center of the protest, the standoff continues. The post Armed Border Agents Arrest Protesters, Bulldoze 200-Year-Old Tree to Build Border Wall appeared first on The Intercept....
Original Article
Armed, masked agents stand in front of a bulldozer near the U.S. border with Mexico on Oct. 5, 2026. A 200-year-old tree, which had for weeks been occupied by activists, was bulldozed to make way for Trump’s border wall. Photo: Sierra Club Borderlands

For more than 70 days, dozens of activists and an ancient cottonwood tree on the Arizona–Mexico border have successfully disrupted the construction of President Donald Trump’s ruinous $50 billion border wall.

Since July, one protester at a time has occupied the cottonwood, or the grandmother tree, as it is locally known. After three other cottonwoods in the area were torn down by government contractors, the remaining grandmother on the U.S. side of the border became the site of a growing protest camp in the remote town of Lochiel, Arizona, and neighboring Sonora, Mexico, where organizers gathered for more than a year to oppose the border wall’s construction.

On Monday, heavily armed federal agents moved in with force. Activists on the ground estimate that 150 Border Patrol officers — many of whom masked their faces — raided the encampment during the protesters’ morning prayer ceremony. At least 10 demonstrators were arrested , and the 200-year-old cottonwood was bulldozed.

As Arizona-based journalist John Washington reported , “agents began cutting the tree while a person was still sitting in its branches. Agents removed that person with a cherry picker and then felled the tree. Screams could be heard as ‘grandmother’ fell around 8:30 a.m.”

In the 48 hours since the early morning raid, land defenders have refused to leave and remain in an ongoing standoff with federal agents. Numerous participants told The Intercept that around 50 people are holding the line against further construction, with dozens more en route following urgent calls to support the encampment and defend the imperiled borderland ecology .

On Tuesday, another tree sitter climbed the last remaining cottonwood standing in the path of the border wall construction, this one on the Mexico side. The tree was briefly occupied by demonstrators in mid-August and, according to a press release from the land defenders, “is once again halting construction.”

The protesters’ aim to stop the construction of two parallel, 30-foot-high border walls ripping through the remote San Rafael Valley. Miles of the double wall structure have already been built in the area. The region is sparsely populated and hardly ever used as a border-crossing site by humans but is renowned as a unique wildlife migration corridor. The cottonwood felled on Monday was the last of four ancient grandmother trees on the Arizona side of the border, which stood in the path of planned wall construction.

“The feeling is that they’re pushing through the construction process as quickly as possible, and they’ll deal with the consequences of the law later.”

Until this week, federal forces had left the encampment and tree sit in relative peace, largely, activists said, because the camp is located on private land. That fact had not changed on Monday.

“Border Patrol has been coming onto private property since yesterday morning. No warrants are shown,” Rachel, a land defender who withheld her last night out of concern for being targeted by law enforcement, said on a call with reporters on Tuesday. “There’s no legal ground for them to come onto private property. And the feeling is that they’re pushing through the construction process as quickly as possible, and they’ll deal with the consequences of the law later. They just want to push the wall through, regardless of the harm they have to cause to us and to the land in the process.”

According to Rachel and other activists on the ground who spoke to The Intercept, construction workers have moved quickly since the raid, digging a deep trench that threatens the roots of the newly occupied cottonwood on the Mexico side.

An aerial view of the raid by federal agents on the protesters’ encampment on Oct. 5, 2025. Photo: Sierra Club Borderlands

A statement on Monday from Belicia Lynch, a member of the De La Ossa family who owns one of the tracts of private property along the border, confirmed the protesters were welcome on her property. “I just want to thank you guys for being out there to not only protect the grandmother tree, but the land itself that many animals and bugs inhabit,” Lynch told the land defenders in the statement.

Border Patrol and the Department of Homeland Security have not yet responded to questions from The Intercept.

The federal attacks on the Lochiel encampment came on the heels of a legal victory for anti-border activists in Big Bend, Texas. On Friday, a U.S. district judge granted an injunction to stop all border wall construction in the Big Bend area, including in national and state parks, while the court hears a lawsuit brought by local environmental and community groups. In the order, the judge wrote that the plaintiffs are likely to succeed on at least one of their claims’ merits.

The standoff between armed federal agents, many of whom are masked to conceal their identities, and border wall protesters on Oct. 5, 2026. Photo: Sierra Club Borderlands

But with practically unlimited funding for his border regime, Trump’s administration can continue fueling money into his violent and destructive border wall. What activists in Lochiel, Sonora, Big Bend, and beyond make clear, however, is that the government’s victory cannot be assumed. Disruptions and interventions are not just possible but also an absolute necessity , and pressure can be applied in an array of directions .

As one Arizona-based Mexican American tree sit participant told The Intercept in August, “The border is everywhere, which means that there are subcontractors and there are power players maybe in your backyard, maybe in your city, maybe an hour drive from where you’re living.”

Rachel, the land defender, made the stakes of the fight clear.

“We have to stop this wall here because the trajectory they’re going on, there is no safety in the U.S. for anyone,” she said on Monday. The call was cut short as news spread through the encampment that federal agents would attempt to remove the tree sitter on the Mexico side. At the time of writing, the grandmother tree in Sonora remains occupied; the fight against Trump’s border wall, and all it represents, has not been lost.

In a social media post on Wednesday, encampment participants announced a “call to presence” to celebrate the life of the felled cottonwood and continue the anti-border struggle. “If you have been waiting to come to Lochiel, this is the time,” they said. “Let your heavy heart lead you to action!”

Property Testing with Agent Swarms

Lobsters
recursion.wtf
2026-10-08 04:41:26
Comments...
Original Article

Have agents build the machinery to find bugs in your repo, then let that machinery generate and check cases without spending tokens on each one. You can do this with ordinary coding agents, without access to a closed cybersecurity program. Writing reference implementations, generators, and assertions for every custom data structure and algorithm is now work you can hand to a swarm.

Pick a complex repo at work. Ask the people who know it well which parts worry them. Give a strong planning agent the property-testing skill from my agent-skills repo and those leads. It gives the agent methods for choosing targets, building reference models and generators, and turning failures into reviewable fixes. Target custom data structures, query planners, graph algorithms: complicated behavior with a simple way to check correctness.

I pointed the playbook at Codex . OpenAI builds it with its own frontier models, including unreleased versions. Thirteen distinct correctness bugs. A rollback that should do nothing erases preserved review history . A completed plan replaces the visible plan with an example buried inside a citation . As of October 7, I’ve filed thirteen upstream reports with twelve proposed fixes and two failing-test-only PRs in my fork ; two fixes cover the same carriage-return framing bug in separate diff renderers. The fix regressions fail against upstream and pass with the repairs. Same public playbook.

I’ve also run the same recipe on jj, uv, Prometheus, and Babel in the background during a regular workday. As of October 6, upstream has merged four uv fixes: optional-dependency activation during export , combining compatibility tags from separate wheel metadata rows , caching a workspace root twice , and overrides losing optional-dependency guards . That last one could include a dependency even when neither extra activating it was requested.

As of October 7, Prometheus has merged two fixes: BucketQuantile panicking on empty input despite its documented NaN result , and histograms losing counter-reset metadata when reducing schemas .

Frank Noirot also read this post, pointed the skill at KittyCAD’s cloud-sync IndexedDB code, and found two bugs. Both fixes are merged: wait for transaction commit before acknowledging writes , and close connections after aborted cursor transactions . Both PRs credit the post and skill. The recipe transfers to other people, repos, and languages.

I first did this at Apollo GraphQL on Router , our Rust GraphQL router, used in production by Intuit and Wayfair and already backed by thousands of unit and integration tests plus extensive snapshot testing. About three days of agents running in the background alongside my regular work turned up more than 30 correctness bugs in edge cases of internal data structures and algorithms. I supplied initial guidance and occasional nudges.

Have an agent write a simple reference implementation and assertions comparing it with the real one over generated operation sequences. Rust’s property-testing library proptest generates cases, checks assertions, and shrinks failures into smaller reproductions. A Vec and some O(n²) loops may be enough to check a heavily optimized implementation. Once built, this test suite can check as many histories as you’re willing to run.

Keep the sprawling discovery suite on its own branch. For each confirmed bug, have the agents produce a standalone PR with a regression test and a minimal fix.

Direct the investigation

I used Astra for planning, Sol to orchestrate, and Sols and Lunas to write proptests in parallel worktrees. Have the planner audit beyond your initial leads.

Compare cached metadata with recomputation and incremental graph algorithms with fresh traversals. Round-trip generated values through serializers. Have the planner find these opportunities across module boundaries.

Investigate failures, including the test’s assumptions. Clear contract violations get regression tests and fixes; ambiguity comes back for discussion. Bugs found by reading code get regression tests too.

Expand from each finding. A missed cache invalidation warrants checking every mutation of that state and other caches maintained the same way. Keep proptests running while agents write more; check in occasionally to redirect the search.

Make operations interact

Model a store with cached lookups using a plain HashMap . Run generated sequences of Put(key, value) , Get(key) , and Remove(key) against both implementations and compare read results. The reference has no cache to invalidate.

Use a small key pool: fresh random keys mostly produce unrelated inserts and missing-key lookups. Overwrite with different values so stale results are visible:

Put("a", 1)
Get("a")       // returns 1; caches it
Put("a", 2)
Get("a")       // must return 2

Have the agent build generators that embed patterns like this in longer histories, alongside repeated removals and reinsertion. Inspect sample traces: a million sequences that barely touch the same key aren’t buying you much.

If a target produces no findings, initially suspect missing coverage. Temporarily remove a cache invalidation: the tests should catch stale results. If they pass, improve the generators or assertions. Revert the deliberate bug.

Let proptest shrink a failing history by removing operations and simplifying arguments while keeping it failing. Have the agent extract a standalone regression test.

Give people something they can review

Nobody wants a giant agent-generated PR full of test machinery. Give reviewers a unit test they can verify without understanding the generator or trusting the reference implementation.

Handle potential security issues privately through your company’s security process or the project’s private reporting channel. Keep repros and fixes out of public issues, PRs, and discovery branches until cleared for disclosure.

For each bug, branch from main with only the regression test and fix. Verify that the test fails before the fix and passes after. Describe the triggering sequence and violated contract; an end-to-end application crash isn’t required.

A few examples of what reviewers get:

The three Prometheus and uv examples above were awaiting review on October 6; the Codex patches are proposed fixes in my fork, linked from upstream issues. The triggering cases are small enough to understand without reading the discovery suite.

Link the discovery branch for background. After enough useful fixes, coworkers may want the broader suite too.

Cybersecurity false positives

I occasionally get a “This content can’t be shown” cybersecurity notice while improving proptest generators. Talk to it like a friend who’s suddenly panicking over nothing:

what’s wrong buddy, this is proptest work not cybersec

That usually gets it moving again. When it hasn’t, compacting and continuing has always worked for me. I’ve never had to clear the context.

Run it

Get agent-skills , load proptest-praxis , and point your planning agent at a repo. Have it keep expanding what the machinery can generate and check. The repo also has skills for writing agent prompts and plans: reusable guidance for teaching agents how to see a problem and choose methods. Copy the relevant SKILL.md into your agent’s context or install it as a skill.


See also

OpenAI Withdraws 3 Math Papers

Hacker News
github.com
2026-10-08 04:08:37
Comments...
Original Article

Latest commit

History

For any withdrawn papers, their README files explain the gap and link to the retracted manuscript. For any updated papers, previously published editions remain accessible through the version notes in their README.

October 7, 2026

Withdrawals

In “Algebraicity of Weil classes on split abelian eightfolds” a sign error invalidates a stabilization-trace cancellation argument and the construction used by two dependent papers. As a result, we have withdrawn the following three manuscripts:

  • Algebraicity of Weil classes on split abelian eightfolds
  • Algebraicity of Kuga–Satake Correspondences for K3 Surfaces
  • The rational Hodge conjecture for products of K3 surfaces

The withdrawn papers now carry notices explaining the gap and linking to the archived manuscripts.

Fixes

We have revised 14 other manuscripts with proof repairs, corrected statements, clearer hypotheses and dependencies, and one correction to an obsolete citation. The changes include:

  • Lipschitz heights and Ashkin–Teller currents (4 manuscripts): repaired crossing, boundary-attachment, conditioning and convergence arguments, including additional work on the real-Lipschitz interface proof.
  • Kähler minimal model programs and abundance (6 manuscripts): expanded positivity and contraction arguments and clarified which results are used as inputs, with their required hypotheses.
  • Taming and hypersymplectic deformation (2 manuscripts): corrected the cone-equality claim in Taming implies compatibility, added a strict-inclusion example, and removed an unnecessary cone-comparison dependency from the hypersymplectic paper.
  • Incompressible Box Transport and Finite Computation: revised the torus-projection and common-clock estimates.
  • Exact Birch–Swinnerton-Dyer Formula from Low Selmer Corank: removed an obsolete introductory citation to a removed supporting manuscript.

Also, as a consequence of these fixes we updated 13 additional manuscripts to cite the revised editions of companion papers. These changes update references and version dates.

Additional Formalizations

We have added an additional 6 formalizations and 5 other additions covering supporting results. This brings the total percentage of top-line results formalized to 300 / 719 = ~42%.

Molly Russell’s father to tell UK cinemagoers: ‘Instagram helped kill my daughter’

Guardian
www.theguardian.com
2026-10-08 04:03:50
In ad to be shown before The Social Reckoning, Ian Russell will say ‘too little has changed’ since death of Molly, 14 The father of Molly Russell will tell UK cinemagoers “Instagram helped kill my daughter” before screenings of a new film about Mark Zuckerberg’s social media empire. Speaking in an a...
Original Article

The father of Molly Russell will tell UK cinemagoers “Instagram helped kill my daughter” before screenings of a new film about Mark Zuckerberg’s social media empire.

Speaking in an advert to be shown before The Social Reckoning, released on Friday, Ian Russell says “too little has changed” since the death of his 14 year-old daughter, who took her own life in 2017 after viewing harmful content on Instagram.

In a 30-second ad he will ask viewers of the Aaron Sorkin film about the Facebook whistleblower Frances Haugen to donate to the Molly Rose Foundation (MRF) to “stop companies like Meta endangering young people like Molly”.

The ad will be screened at Everyman, Curzon, Showcase and AMC cinemas showing the film in the UK after the cinema advertising company Pearl & Dean offered space to MRF for free.

Ian Russell
Ian Russell says in the ad that ‘algorithms still force streams of toxic content on to children’. Photograph: Publicity image

Speaking directly to the audience, Ian Russell will say: “I’ve said it for years: Instagram helped kill my daughter. Too little has changed. Promises to deliver safety have failed. Algorithms still force streams of toxic content on to children. So if you agree harmful tech is unacceptable and bosses like Mark Zuckerberg should be held accountable, please support Molly Rose Foundation to stop companies like Meta endangering young people like Molly.”

Kathryn Jacob, the chief executive of Pearl & Dean, said: “We know that audiences appreciate advertising that is contextually relevant. The team at the Molly Rose Foundation worked hard to deliver a campaign that works with the film.”

Bauer Media Audio, the owner of the Absolute Radio, Kiss and Jazz FM brands, is also donating free advertising space to MRF for a separate advert, also voiced by Ian Russell, in which he asks parents seeking advice to contact the charity.

Haugen’s revelations about Facebook and Instagram’s approach to online safety, detailed in the Sorkin film, included internal research showing Instagram content had a negative impact on teenage girls’ mental health . At the time Zuckerberg’s company said the coverage of the research “focused on a limited set of findings and casts them in a negative light”.

Jeremy Strong as Mark Zuckerberg, sitting upright at a laptop with headphones around neck and serious expression
Jeremy Strong as Mark Zuckerberg in The Social Reckoning. Photograph: Leah Gallo/Sony Pictures/AP

The film also covers Haugen’s testimony to the US Congress in which she said the social media corporation put “astronomical profits before people”, harmed children and destabilised democracies.

Haugen is played in the film by the Oscar winner Mikey Madison while Zuckerberg is played by Succession’s Jeremy Strong. The Guardian’s review of the film , a quasi-sequel to the Sorkin-scripted The Social Network, says it “rattles along at an entertaining clip”, adding that Strong – taking over from Jesse Eisenberg in Social Network – delivers a “very interesting Zuckerberg impersonation, standing and sitting like a Thunderbird puppet”.

The 2022 inquest into Molly’s death was a landmark moment for online safety. The coroner ruled that “died from an act of self-harm while suffering from depression and the negative effects of online content” and that algorithms had pushed harmful content to Molly that she had not requested.

At the time Ian Russell accused Meta , the owner of Facebook and Instagram, of guiding his daughter on a “demented trail of life-sucking content” that included material related to self-harm, suicide and depression. Meta later made a donation to MRF in lieu of a legal settlement to Molly’s family.

In a statement issued following the release of the documentary Molly vs the Machines this year, which recreates moments from the inquest, Meta said its thoughts “remain with Molly’s friends and her family”. The company said it had put safety measures in place since Molly’s death including defaulting all teenagers under 18 into private accounts, and restricting who could message them and the content they saw.

I've Been Deindexed by Google

Lobsters
kennyqin.com
2026-10-08 03:59:30
Comments...
Original Article

Citron

I don't remember exactly when but, earlier in the year, I decided I didn't want this website to be indexed by search engines anymore. A lot of it has to do with AI and the relentless scraping that plagues the internet now. I know that as long as my blog is accessible by the public internet, there are no real measures I can put in to stop it but at least some of it will be respected.

I started out by setting a blanket disallow in the robots.txt.

User-agent: *
Disallow: /

When I realised that didn't do anything after a few weeks of waiting and checking, I set the robots meta tag.

<meta name="robots" content="noindex, nofollow" />

I thought that would do the trick. What I didn't realise is that you have to actually, ironically, allow the bot that will do the deindexing to visit your website so that it can see the meta tag that tells it to not index your page anymore.

User-agent: Googlebot
Allow: /

User-agent: *
Disallow: /

I also did this with several other common bots and removed them from the robots.txt whenever I found that my website had been deindexed.

It's been at least 3 months since I did my last change to have Google deindex me and, after checking today, I'm happy to announce that this website is free from Google! 🥳

#degoogle #meta

How can undefined opcodes ud0 and ud1 have parameters?

Lobsters
devblogs.microsoft.com
2026-10-08 03:59:21
Comments...
Original Article

Gunnar Dalsnes wondered how ud0 and ud1 could have parameters if they were undefined ? “Does it mean they were not completely undefined, just undocumented and not completely implemented?”

The opcodes ud0 and ud1 have no definition, but that’s not the same as being architecturally an “undefined instruction”. They live in a purgatory where they were not assigned a meaning, but were also not officially declared to be meaningless.

Originally, these byte sequences went through the instruction decoder and happened to slip through a few cracks before somebody finally noticed, “Wait a second, I don’t know how to execute this.”

You can see this when you look at the instructions that are encoded as 00001111 11111xxx , as of the Pentium III.

Bits Bytes Opcode Operand 1 Operand 2 Meaning
00001111 11111000 0F F8 PSUBB mm mm/m64 Subtract packed bytes
00001111 11111001 0F F9 PSUBW mm mm/m64 Subtract packed words
00001111 11111010 0F FA PSUBD mm mm/m64 Subtract packed dwords
00001111 11111011 0F FB No meaning assigned
00001111 11111100 0F FC PADDB mm mm/m64 Add packed bytes
00001111 11111101 0F FD PADDW mm mm/m64 Add packed words
00001111 11111110 0F FE PADDD mm mm/m64 Add packed dwords
00001111 11111111 0F FF No meaning assigned

The byte sequences 0F FB and 0F FF had yet to be assigned a meaning. You can see how the instruction decoder could take a shortcut and say, “Well, all the instructions in this range, or at least all the ones that I care about, take an mm registers and an mm/m64 operand, so I’ll just save myself some transistors and decode all of them with two parameters (mm, mm/m64).” And then after decoding, it would use bit 3 to decide whether to set up the arithmetic unit for an add or subtract, and it would use bits 0 and 1 to decide how to subdivide the bits into saturating units.

And if you gave it a 0F FF , it would be only in that last step that the decoder would realize “Oh dear, I don’t know what to do with a bit combination of 11 . I’ll raise an invalid opcode instruction.”

The invalid opcode instruction got raised after the operands were parsed.

You can see the trouble that 0F FF created when those empty slots started to get filled in by the SSE instructions.

Bits Bytes Opcode Operand 1 Operand 2 Meaning
00001111 11111000 0F F8 PSUBB mm mm/m64 Subtract packed bytes
00001111 11111001 0F F9 PSUBW mm mm/m64 Subtract packed words
00001111 11111010 0F FA PSUBD mm mm/m64 Subtract packed dwords
00001111 11111011 0F FB PSUBQ mm mm/m64 Subtract packed qwords
00001111 11111100 0F FC PADDB mm mm/m64 Add packed bytes
00001111 11111101 0F FD PADDW mm mm/m64 Add packed words
00001111 11111110 0F FE PADDD mm mm/m64 Add packed dwords
00001111 11111111 0F FF I want to put PADDQ here but I can’t

the natural place to put the PADDQ instruction is 0F FF , but people had already been using 0F FF with the expectation that it raises an illegal instruction exception. Making it a valid instruction would break those programs, so Intel had to move PADDQ to the rather awkward location 0F D4 .

Bonus chatter : Undefined instructions with parameters are actually not uncommon. For example, on AArch64, there is a range of 65,536 instructions set aside as permanently undefined , so the udf instruction takes a 16-bit immediate to specify which invalid opcode you want. The PDP-10 reserved opcode 000 as a permanently illegal instruction, and it carries a register and a memory address as parameters. (Because all PDP-10 instructions carry a register and a memory address as parameters.)

There are also so-called “unofficial opcodes” which are instructions that are not part of the instruction set architecture, but for which people reverse-engineered a consistent behavior and began to rely on it. (The 6502 processor is well-known in nerd circles for having undergone this type of analysis .) The 0F FF is one of these “unofficial opcodes” that was popular enough that Intel felt pressure to maintain backward compatibility with it, even though it was never architecturally documented or supported.

Bonus bonus chatter : It appears that the mnemonic ud1 was introduced by the nasm assembler :

* Added the following new instructions: SYSENTER, SYSEXIT, FXSAVE,
  FXRSTOR, UD1, UD2 (the latter two are two opcodes that Intel
  guarantee will never be used; one of them is documented as UD2 in
  Intel documentation, the other one just as "Undefined Opcode" --
  calling it UD1 seemed to make sense.)

It seems obvious that ud1 is also the name that Intel gave internally to that legacy instruction. Otherwise, there would be no need to call the new one ud2 !

Category

Topics

Author

Raymond Chen

Raymond has been involved in the evolution of Windows for more than 30 years. In 2003, he began a Web site known as The Old New Thing which has grown in popularity far beyond his wildest imagination, a development which still gives him the heebie-jeebies. The Web site spawned a book, coincidentally also titled The Old New Thing (Addison Wesley 2007). He occasionally appears on the Windows Dev Docs Twitter account to tell stories which convey no useful information.

I think I found a planet nobody knew existed. I used Claude Code to find it

Hacker News
www.reddit.com
2026-10-08 03:07:34
Comments...
Original Article

You've been blocked by network security.

To continue, log in to your Reddit account or use your developer token

If you think you've been blocked by mistake, file a ticket below and we'll look into it.

OpenAI withdraws three mathematical results

Hacker News
twitter.com
2026-10-08 03:05:40
Comments...
Original Article

Dan Roberts on X: "We've updated our GitHub math repo with 6 new Lean formalizations, 19 modifications, and 3 withdrawals. The repo now has ~42% top-line results formalized. We will continue to update the repo with new formalizations and with any errata we notice. https://t.co/HI6otY2NTO"

We've updated our GitHub math repo with 6 new Lean formalizations, 19 modifications, and 3 withdrawals. The repo now has ~42% top-line results formalized. We will continue to update the repo with new formalizations and with any errata we notice.

Dat-ecosystem: high level applications built on top of P2P protocols

Hacker News
dat-ecosystem.org
2026-10-08 02:43:13
Comments...

People Holding Up the Internet

Hacker News
sheets.works
2026-10-08 02:41:35
Comments...
Original Article

Billions of phones run on code looked after by a handful of people. We counted them from the code itself.

Your alarm, a boarding pass, a meeting in another country, the day your salary lands: anything on your phone that shows a time has to know where you are. Underneath sit every Android phone, every iPhone and most of the servers on the internet. They all get local time from one text file, the time zone database, which holds every clock rule a government has ever announced. Paul Eggert, a lecturer at UCLA, keeps that file up to date in his spare time.

Paul Eggert on a video call, wearing headphones, at home
Paul Eggert giving a talk on the time zone database, LibrePlanet 2022. Free Software Foundation, CC BY-SA 3.0.

Paul Eggert

Teaches computer science at UCLA, and has been the official coordinator of the time zone file since 2012.

4,000,000,000

Android phones and iPhones use his file. We didn't count servers, Macs or laptops, which would push the number higher.

Your phone's time zone, as the file has it today

On 29 September Paul put out version 2026e of the file. The first line of its notes says that Manitoba moves to permanent -05 on 31 October, which tells phones in Winnipeg not to set their clocks back on 1 November, and it was typed in by two volunteers a month ahead. Of the 251 changes made to the file in the last year, 218 were his and 28 were Tim Parenti's.

In 2011 an astrology software company sued Paul and Arthur Olson, who started the file in 1986 at the National Institutes of Health, claiming some of its history came from an atlas the company owned. The file's mailing list and download site were switched off until IANA, which keeps the internet's master lists, took them over later that month. The Electronic Frontier Foundation defended them for free, and the company dropped the case in February 2012.

“In case I am no longer available due to retirement or whatever.”

Paul Eggert, asking the tz mailing list to make Tim Parenti his backup, 20 May 2020

I also make a daily word game. Play today’s sentence . About two minutes.

xkcd 2347, Dependency: a tower of blocks labelled all modern digital infrastructure, resting on one small block labelled a project some random person in Nebraska has been thanklessly maintaining since 2003
Dependency , Randall Munroe, xkcd 2347. CC BY-NC 2.5, colours inverted.

People post this comic whenever something breaks. The tower is labelled "all modern digital infrastructure" and it stands on one small block, "a project some random person in Nebraska has been thanklessly maintaining since 2003".

We wanted to know how close to true it is. We downloaded the full history of 23 pieces of software that phones, browsers and servers depend on, and counted everyone who made ten or more changes to each one between October 2025 and October 2026. Then we listed what is actually installed on an Android phone, an iPhone and a Windows PC.

11 of 23

projects had one or two people doing the regular work.

“It's also good to keep in mind that this is an unpaid hobby project.”

Lasse Collin, xz mailing list, 8 June 2022

Lasse Collin

Lives in Finland and looks after xz, the compression tool on almost every Linux server and inside every iPhone.

He wrote that line in the same email where he said his ability to care had been "fairly limited mostly due to longterm mental health issues". For months, accounts calling themselves Jigar Kumar and Dennis Ens had been posting to the list about how slowly things were moving, and a contributor called Jia Tan had been sending useful fixes.

Lasse gave Jia Tan more access. In 2023 Jia Tan made 304 changes to xz and Lasse made 172, which is the red on the wall below. In February 2024 the versions Jia Tan released carried a hidden way into Linux servers. Andres Freund, an engineer at Microsoft, found it on 29 March because his logins were using more processor time than they should, before most Linux systems had shipped it. Nobody has found out who Jia Tan is.

Lasse Collin Jia Tan everyone else

Every change to xz since January 2021, one square each. In 2021 almost all of them are Lasse's. 28 January 2022: the first change written by Jia Tan goes in. By 2023 Jia Tan is making more changes than Lasse, 304 to his 172. February 2024: Jia Tan releases two versions with the backdoor inside. Andres Freund finds it on 29 March. After that it is Lasse on his own again, and in 2025 he wrote 97 percent of the changes.

$57 a month

was what Denis Pushkarev raised when he asked for donations to keep core-js going.

Denis Pushkarev

Wrote core-js, which lets new JavaScript work in old browsers. By his own count it runs on about half of the thousand busiest websites in the world.

In 2019 he was working on core-js full time without pay, living in Russia because it was cheaper. By his own account, three weeks after a big release he was driving home at 3 a.m. when two young women on a dark road ended up under his car, and one of them died. The families asked for about $80,000, and the prosecutor asked for seven years.

He added a message that appeared in the terminal every time anyone installed core-js, asking for help or a job. Millions of developers saw it, and many of them complained about the message. He went to prison in January 2020 and was released early, about ten months later.

Denis Pushkarev everyone else

Every change to core-js, week by week, from June 2019. Nearly all of them are his. December 2019: 101 changes in a month. In January 2020 he goes to prison, and the weeks after that stay almost empty. October 2020: he is out and back at work. Downloads nearly doubled while he was inside. This year he wrote 95 percent of the changes, and he has two sponsors on GitHub.

5,408 of 5,409

changes to sudo between 2008 and 2018 were made by Todd Miller.

“I'm currently in search of a sponsor to fund continued sudo maintenance and development.”

Todd C. Miller, millert.dev, February 2026

Todd Miller

Has maintained sudo, the command that gives you admin rights on a Mac or a Linux server, since the early 1990s.

Sudo was first written around 1980 at SUNY Buffalo, and Todd has looked after it for longer than Linux has existed. After The Register wrote about his note in February, the project's Open Collective budget reached about $61,700 a year and 30 people sponsored it on GitHub, which makes sudo the best funded one-person project in our count.

Text inside libjpeg.so, read off an Android 16 phone

Copyright (C) 1991-2022 The libjpeg-turbo Project and many others

DRC

Runs libjpeg-turbo, which opens every JPEG on Android phones and in Chrome and Edge, and signs his emails with his initials.

He started it in 2010 by taking the JPEG code from the 1990s and making it two to six times faster, and in 2019 it became the reference version of JPEG for the ISO and the ITU. He runs it on his own as a small business, which the project describes as "sustained solely through patronage and funded development". At one point he wrote that it had general funding "for about 8-10 hours of labor per month". This year he wrote 98 percent of the changes.

A B C D

The SQLite team

Four people changed SQLite in the last year. It is in every Android phone, every iPhone, every Mac, every copy of Windows 10 and 11 and every major browser.

“There are a lot of crazy people in the world who might misuse that information.”

sqlite.org, on why the page with the developers' names and photos was taken down

D. Richard Hipp wrote SQLite in 2000 after working on software for a US Navy destroyer, where the database kept failing whenever a separate server went down, so he made one that lives in a single file. When you open WhatsApp, your chats load from one. The project's own estimate is over a trillion SQLite databases in use, and the team pays for the work by selling support through Hipp's company.

If you want two minutes away from the squares, play today’s Long Story Short , one true story cut to five of its own words.

Mark Adler at the Jet Propulsion Laboratory, wearing a lab lanyard
Mark Adler at the Jet Propulsion Laboratory, 2002. NASA, public domain.

Mark Adler

Wrote zlib with Jean-loup Gailly in 1995. In his other job he managed NASA's Spirit rover on its way to Mars.

zlib makes files smaller. It is inside PNG images, web pages, Git, Android, iPhones and Chrome, and Debian counts it on 291,615 of the machines that report to it, effectively every one. In the last year two people did most of the work, Mark and a contributor who goes by Vollstrecker. Mark has no sponsor page, and zlib is not on any public funding list we checked.

25 years

between the line that became Shellshock going into bash and anyone reporting it.

Chet Ramey

Has maintained bash, the shell on Linux and on Macs from 2003 to 2019, since about 1990, alongside his job in the network group at Case Western Reserve University in Ohio.

In September 2014 Stéphane Chazelas reported a bug in bash to Chet. Anyone could use it to run commands on a server by sending it a specially shaped piece of text, and on 24 September it went public as Shellshock, on hundreds of millions of machines. The line behind it had gone into bash on 5 August 1989. Every change in bash's public history is Chet's, including the official fixes.

Behdad Esfahbod, black and white portrait
Behdad Esfahbod, 2016. CC0.

Behdad Esfahbod

Rewrote HarfBuzz, which decides how letters join and sit for Android, Chrome, Firefox, Edge, the Kindle and Figma.

the same letters, unshaped

the same letters, unshaped

For English the job is mostly simple. In Hindi, Arabic, Tamil and most of the world's writing, letters change shape depending on their neighbours, and without shaping a word comes out as a row of pieces. Behdad started the rewrite around 2012 while he was at Google. This year he wrote 85 percent of the changes, with five other people doing regular work.

Daniel Stenberg, portrait
Daniel Stenberg, 2015. Photo by Daniel Stenberg, CC BY 4.0.

Daniel Stenberg

Started curl in Sweden in 1996. It moves data for phones, cars, TVs and Windows, which has shipped it since 2018.

This year eleven people did regular work on curl, and the one with the most changes was Viktor Szakats. In his review of 2025 Daniel wrote that everyone else has now added more lines to curl than he has. He works on it full time because companies pay for support, the project takes in about $89,700 a year through Open Collective, and Germany's public fund for open source paid €195,000 for work on it.

Every change to curl in the last twelve months, by week, one colour per person who made ten or more. Hover a square to read the change.

Heartbleed

OpenSSL puts the padlock on a large share of the web. In April 2014 a bug called Heartbleed let anyone read passwords and private keys out of the memory of about 17 percent of trusted secure servers, by Netcraft's count. That week the OpenSSL foundation's president, Steve Marquess, wrote that it received about $2,000 a year in donations, and he told NPR that one person worked on it full time.

Within two months the Linux Foundation raised $5.4 million from technology companies, and OpenSSL got two paid developers and an audit. It had six people doing regular work in 2013 and fourteen in 2014.

People who made ten or more changes that year OpenSSL xz

Before 2014 OpenSSL has three to seven people a year doing regular work, and xz has one. After Heartbleed in April 2014 the money arrives, and OpenSSL goes from six people to fourteen. March 2024: the xz backdoor is found, and no new money follows that we could find. In 2026 OpenSSL has 32 people doing regular work, and xz has one.

The money

Germany's Sovereign Tech Agency has funded about ninety open source projects since 2022, and the Alpha-Omega fund gave out nearly $6 million last year, much of it to security engineers at foundations like Python's and Ruby's. Both give money to organisations that can apply for it and report on it.

Funded by the Sovereign Tech Agency

log4j €596,160

FFmpeg €437,930

OpenSSL €405,888

OpenSSH €200,000

curl €195,000

No public grant we could find

The time zone database €0

SQLite €0

zlib €0

libxml2 €0

libjpeg-turbo €0

HarfBuzz €0

xz €0

bash €0

nghttp2 €0

expat €0

On GitHub Sponsors, Daniel Stenberg has 64 sponsors. Paul Eggert, Lasse Collin, DRC and Mark Adler do not have a sponsor page.

85 days

libxml2 went without a maintainer last year, and it is on 5.6 billion phones and computers.

libxml2 reads XML, the format behind a lot of documents, feeds and settings, and it is on Android phones, iPhones and in Chrome. On 15 September 2025 its maintainer, Nick Wellnhofer, wrote on the GNOME forum that he was stepping down, "which means that this project is more or less unmaintained for now". On 9 December two volunteers, Daniel Garcia Moreno and Iván Chavero, took it on, and Chavero announced it on the PostgreSQL mailing list with "contributions are welcome!"

Nick Wellnhofer Daniel Garcia Moreno everyone else

Every change to libxml2 from June 2025, week by week. On 15 September 2025 Nick Wellnhofer steps down. Volunteers keep sending fixes, but nobody is in charge. 9 December: Daniel Garcia Moreno and Iván Chavero take it on. libxml2 is on 5.6 billion phones and computers.

The first line of the notes for version 2026e of the file, released by Paul Eggert on 29 September 2026

Our daily game

Long Story Short

Every day there is one true news story, and you cut its sentence down to five of its own words. It takes about two minutes.

Play today’s

Who is inside the device you are holding

We guessed your device from your browser. Nothing is sent anywhere.

How we know

Each dot is one project. Across: phones and computers it ships on by default, a lower bound. Up: people who made ten or more changes in the last twelve months. Hover a dot.

We took the full public history of each project and kept the changes written between 7 October 2025 and 7 October 2026, leaving out merges and bots. A person counts if they made ten or more changes in that time. A change's author is not always the maintainer, and some of these projects publish their history as a copy of another system.

For devices we counted a project on a platform only when we could see it there. On Android we listed the system libraries of an Android 16 image and read inside them, which is how we found that Android's "liblzma" is 7-Zip's code and not xz. For the iPhone we read the system libraries listed in Apple's iOS 26.2 developer kit. For Windows we used Microsoft's announcement for curl and the code inside Edge, which comes with every copy. Android has over three billion active devices (Google, 2022), iPhones over one billion (Apple, 2021) and Windows 1.6 billion a month (Microsoft, 2026). Macs, iPads, servers, cars and TVs are left out, so every device number here is lower than the real one.

"No public grant" means none from the Sovereign Tech Agency, Alpha-Omega, Open Collective or GitHub Sponsors, not that nobody has ever paid these people. If we got your project wrong, tell us and we will fix it.

Data: the 23-project table · every change shown · time zone lines with who last changed them · the script .
Sources: tz mailing list and RFC 6557; IANA tzdb NEWS 2026e; EFF, Astrolabe v. Olson; xz-devel, 8 June 2022; Russ Cox's xz timeline; Andres Freund on oss-security, 29 March 2024; Denis Pushkarev, "So, what's next?" (2023); millert.dev and The Register, 3 February 2026; libjpeg-turbo.org; sqlite.org/mostdeployed and /crew; Wikipedia on Mark Adler; David A. Wheeler's Shellshock timeline; HarfBuzz README; daniel.haxx.se, 2025 review; Steve Marquess, "Of Money, Responsibility, and Pride" (2014); Netcraft, 7 April 2014; sovereign.tech; Alpha-Omega 2025 report; GNOME Discourse, 15 September 2025; pgsql-hackers, 17 December 2025.
Photos: Paul Eggert, FSF / LibrePlanet 2022, CC BY-SA 3.0. Mark Adler, NASA, public domain. Behdad Esfahbod, CC0. Daniel Stenberg, CC BY 4.0. Comic: xkcd 2347, CC BY-NC 2.5.

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland

Bleeping Computer
www.bleepingcomputer.com
2026-10-08 02:32:16
​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]...
Original Article

Pwn2Own Ireland

​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.

The day's highlight was the Samsung Galaxy S26 flagship getting hacked three times by KAIST Hacking Lab 's Kyeongmin Kim, PetoWorks , and Mobile Hacking Lab 's Dimitrios Valsamaras and Ken Gannon.

Jack Dates of RET2 Systems demoed a Sonos Era 300 exploit chain in under a minute, and Out of Bounds team's HaeJung Yang was awarded $40,000 for hacking Dynamo in the AI Infrastructure category.

PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay, and Doyensec's Yassine Bengana and Maxence Schmitt also hacked the Home Assistant Green smart home hub , while Ikotas Labs breached the Oracle Autonomous AI Database using a seven-chain zero-day exploit .

Before day two began, Kyeongmin Kim withdrew his attempt at a USB-based attack targeting the Google Pixel 10.

Trend Micro's Zero Day Initiative (ZDI) organizes the competition to identify zero-day flaws in fully patched devices before attackers exploit them in the wild. According to Pwn2Own rules , all devices run the latest firmware versions, and contestants must compromise the target and demonstrate arbitrary code execution.

After zero-days are exploited and disclosed at Pwn2Own, vendors have 90 days to patch their software before ZDI publicly discloses them.

Pwn2Own Ireland learderboard
Pwn2Own Ireland learderboard Day Two (ZDI)

Throughout the Pwn2Own Ireland 2026 contest, competitors target products in seven categories , including mobile phones (Samsung Galaxy S26 and Google Pixel 10), messaging apps, smart home devices, printers, AI infrastructure, AI coding apps, and a new category where hackers will try to exploit wellness healthcare devices.

While Apple's iPhone 17 was also a potential target with a maximum award of $300,000 for a remote hack, no contestant registered for an attempt.

Interrupt Labs , Ikotas Labs , and Nguyen Thanh Dat of Viettel Cyber Security also hacked Samsung's Galaxy S26 flagship on day one , but some of the bugs exploited were already known to the vendor.

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC, who topped the leaderboard on the first day, won $40,000 for a five-zero-day exploit chain targeting the Oracle Autonomous AI Database, plus an additional $40,000 for chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub.

On the third day , security researchers will attempt to hack multiple smart home, AI infrastructure, and printer devices, as well as the Samsung Galaxy S26 and Google Pixel 10 smartphones again.

During the Pwn2Own Ireland 2025 competition, hackers demoed 73 zero-day flaws to earn $1,024,750 . Summoning Team won the contest and collected $187,500 after hacking the Samsung Galaxy S25, the Home Assistant Green, the QNAP TS-453E NAS, and multiple Synology devices.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Classic PC demoscene productions running natively in the browser

Hacker News
treylorswift.github.io
2026-10-08 02:29:25
Comments...
Original Article

─═≡ Classic PC demoscene productions running natively in the browser. ≡═─

H ow I t W orks

Each demo's original DOS code, recompiled instruction for instruction, runs in your browser:

  1. The demo is run on an x86 emulator that records every block of code the CPU actually executes, over the whole demo.
  2. That recording is translated into C - the original instructions, one for one, with the exact cycle timing of the emulated machine.
  3. The C is compiled to WebAssembly, together with models of the hardware the demo talks to: the timer , the VGA card and the Sound Blaster .
  4. The result is checked against the emulator event for event: every interrupt, port access and frame at the same moment of emulated time.

The demos' own loaders, music players and effects all run as they did in 1992 and 1993; only the hardware is modelled.

The demos ran on VGA at 70 Hz , so they look smoothest on a display running at 70 Hz, or at 140 Hz or higher.

demoscene-recomp on GitHub

C redits

Unreal and Second Reality are by Future Crew , Crystal Dream II is by Triton , Stars: Wonders of the World is by NoooN ; all were released as freeware .

The original release files are served unmodified, as the demos read them at run time.

Visits are counted anonymously - no IP addresses, tracking cookies or personal identifiers.

Font: IBM VGA 8x16 by VileR, int10h.org ( CC BY-SA 4.0 )

A rant about APIs

Lobsters
dev.clintonblackburn.com
2026-10-08 02:07:14
Comments...
Original Article

I have had the displeasure of integrating with a few different APIs over the past few weeks while working to automate Vori’s onboarding flow. These APIs have been for systems including contract rendering and e-signature collection, invoicing/billing systems, CRMs, card processors and gateways, and card terminal providers.

They all kinda suck in their own ways. This would be somewhat acceptable if they were doing novel work in new fields, but these are all APIs for solutions that have existed for a decade or more. It’s also frustrating because the developers could simply copy existing, better, APIs and practices, and come out ahead!

Here are some of my pet peeves.

Gated documentation

You’ve already messed up if I need to log in to read your API documentation. Kudos for actually writing the docs, but why do I need to log in!? I have to interrupt my flow to fill out a form or send an email to your support team, and wait a few hours or days, just to read documentation!?

I complained to one team about this and they agreed that gated documentation is not ideal. However, an executive wanted lead tracking. WTF!? We are already customers. The lead is closed-won. There’s nothing else to track!

This is worse with agentic development. I prefer to provide links to docs so the agent can explore the schema, build a client, and integrate. That flow is disrupted by gating. I now have to download the docs in some fashion—fortunately the offender in question offers a Markdown option—to provide for the agent. This needs to be done for every endpoint!

Just remove the authentication requirement for docs. You’re wasting your own time and resources just so everyone else can waste their own time and resources. This is a lose-lose scenario.

No OpenAPI spec

Show of hands. Who likes handwriting API clients? If your hand is up, I don’t believe you. The OpenAPI specification has existed for 15 years. Publishing an API without one is just disrespectful at this point. Why don’t you like me? Why do you want to make my life harder when I’m trying to give you money? Help me help you. Give me a spec so I can generate a typed client and focus on my business.

Oh, “here’s a Postman collection,” you say? I guess something is better than nothing, but now I have to figure out how to convert that to an OpenAPI spec. Why are we wasting time with an inferior format? Give me the good stuff!

No self-serve credential issuance

This is similar to gated docs. APIs need credentials. Duh. Let me generate/rotate them on my own. Why do I need to wait multiple weeks for the IT team to generate credentials, flip a flag, or whatever? Stuff happens. Sometimes we need to rotate credentials. Don’t make me file a support ticket for a potential security incident! That means an issue that crops up on Saturday probably isn’t getting fixed until mid-day Monday when someone reads the ticket.

Credential identity crisis

So you created self-serve credential issuance. Cool. But wait! Now you tell me the credential is associated with the identity of the person that created the credential. Meaning…all logs are associated with that person, so it’s impossible to discern between API calls from our backend applications and calls made by that person in your web app? Meaning…that person is the only one that can rotate the credentials, and we can’t simply follow the bad practice of sharing credentials because your application requires SSO and we have to draw the line somewhere at account sharing? Meaning…deactivating that person’s account will almost assuredly result in an incident?

I’m actively migrating away from an e-sign provider that does this because I am the person who set up the account, and am currently on vacation, and blocking folks from seeing contracts, because of course I want all the contracts sent to grocers to be associated with my account! My list of questions and criteria for vendors increases.

Webhook “verification”

Webhooks are great for building realtime-ish workflows. Love ‘em. I have no love for the aforementioned e-sign provider that wants to verify webhook endpoints before saving them. “What is this verification”, you ask? It’s simple (and stupid): the provider sends a payload to the endpoint and only saves the new webhook configuration if the endpoint returns a successful response.

One of the first sections in any webhook integration guide covers security. Always validate the payload with a shared secret, and reject invalid payloads without processing. Well…it’s hard to validate without that shared secret, and the provider won’t give me a shared secret until the endpoint is verified to work. 🙃

This was the ridiculous workaround for a problem that doesn’t need to exist:

  1. Create a webhook for a known URL that always returns a 200 response for POST, such as https://echo.free.beeceptor.com.
  2. Store the shared secret in the secret manager.
  3. Update the webhook with the correct URL.
  4. Pray you never need to rotate the secret.

I wrote a support ticket for this, and the folks who responded didn’t quite understand why this was a problematic workflow. They do understand that I am migrating away from their product, however, and suddenly want to chat to get feedback.

Wrapping up the rant

It’s worth noting that I haven’t even discussed the API schemas and resources. Most companies get this right for their RESTful APIs with understandable nouns and verbs that define the business concepts and actions. Older payments companies continue to struggle with this for some inexplicable reason despite having over 15 years to just copy Stripe. Seriously, just copy the Stripe API. We spent a lot of time and energy building it. It’s good. Take it.

I’m just happy folks are building APIs, even with the horrible developer experience. We’ve largely eliminated a 40+ step process in about four weeks. Sure, agents wrote the code in like 4 hours and most of that four weeks was waiting for credentials, but progress is progress.



Clojure in the age of language models

Hacker News
yogthos.net
2026-10-08 01:56:31
Comments...
Original Article

In the age of generative models, the most important skill for a developer is to be able to recognize the shape of the problem and pick the correct way to express it. What's relevant today is the ability to do high level reasoning about algorithms, data structures, and data flows within the system. Imperative programming is quickly becoming akin to writing assembly because language models are quite competent at writing code in the small, while they stumble at high level design and architecture. So it is good to learn a language that operates at a higher level, such as Clojure, which is data-centric, composes functions declaratively, and keeps code close to the shape of the problem.

LLMs can generate code much quicker than I can, but the issue is how to test that the generated code does what I want. Before you can test anything in many languages, you have to recompile the program, and that may take quite a few minutes for larger projects. The length of that feedback cycle, in turn, sets the pace of your progress.

We also need to talk about the tedious reality of rebuilding application state. That matters even more when you are not writing the code yourself, so the output is inherently less intentional. Clojure collapses that loop because our workflow does not draw a hard line between when code is read, when it is compiled, and when it runs. Clojure runs in a live process, and you can redefine a function at the REPL and have the new version take effect immediately, without restarting. State stays in place while you change the code that operates on it. Inspecting the state to reproduce behaviors and verify fixes can be done instantly when you can reach into a running process.

An agent can similarly connect to a REPL to diagnose an issue and swap out the code without any downtime. Agents fundamentally need observability in order to get useful feedback about the changes they are making. Working with the REPL means the agent doesn’t have to go through all the steps of compiling and rebuilding the app, then logging its output to see the result. That translates into having to do fewer iterations to reach a working system, which becomes particularly valuable when working with a large codebase. The functionality of your system can keep evolving as you load new code into the running process without any restarts.

Another advantage comes from immutability, which helps reliably control the operating context of the program environment. When the majority of the logic in an application is written using pure functions, the agent can safely consider and test pieces in isolation without having to reason about the entire program. Agents can write functions one at a time, test them in the running program instead of making a whole bunch of changes, then running tests to find out if they worked.

At this point, I find anything with a compile cycle is a nonstarter if I have an option to have a live programming environment. It is not just compile and startup time that ends up being painful. A bigger problem is the tedious necessity of having to reconstruct the desired state every single run. When you have something small with limited functionality, that is fine, but as your application grows, rebuilding the state can take a significant effort. You might have to click through some menus in the user interface, wait for data to be processed from a service or a database, and so on. Being able to put your application in a particular state and make changes within that context is just a qualitatively better development experience.

Then there's the powerful macro system , allowing you to adapt the language to the problem domain, eliminating a lot of boilerplate code you would have to write otherwise. What makes this particularly powerful in Clojure is homoiconic syntax, where code is written using data structure literals. Since there is a common syntax for expressing both logic and data, a program can take any piece of code and manipulate it as it would with any other data structure, then evaluate it. This makes it incredibly easy to add new semantics because all you need is to make templates out of code. A macro works much like a function that accepts the code you wrote and produces the form that actually gets evaluated. The expression for printing a string does the printing when you evaluate it, but it is also nothing more than a list of the println symbol and the string itself.

One major advantage of S-expression based syntax is that it's easy for both humans and machines to read. And since the state can be trivially serialized as plain data structures, an agent can dump it in the REPL to inspect what’s happening in the application at any time. The data orientated nature of the language is a natural fit for LLMs since these models operate on text, making it exceptionally easy for them to see how data flows through the system without any opaque object graphs to worry about.

Furthermore, all the functions operate on a common set of data structures, allowing you to compose them together to transform data like Lego blocks. Clojure programs tend to be far more concise since the code is largely written through declarative composition of functions from the standard library, which encapsulate the implementation details. The result is that a codebase tends to be much shorter, leaving far less code to repeat. This conciseness matters since a smaller program costs fewer tokens, and fewer tokens leave more room in the context, making the language friendlier for local models.

In my experience, models lacking the broader context while making changes in a piece of code is one of the most common failure cases. Having a terse syntax means that more relevant code lives directly in the context window, directly addressing the problem. The model gets a significantly better view of what you are trying to do and can make much better decisions. If the whole call graph is sitting in the context window, the model sees how all the pieces fit together.

All these features combine to make a perfect environment for the agent to work in. Expressive syntax leads to less code repetition. Macros let you fold repeated patterns into new domain specific constructs. Code itself is just structured data that can be inspected and transformed. And the REPL ties it all together, providing you with a living system that evolves along with your code.

There are, however, a few drawbacks to the Java virtual machine, which Clojure traditionally runs on. From my experience, many developers, fairly or not, have an issue with requiring the JVM, and shy away from Clojure because of startup time, a somewhat heavyweight runtime, and perceived bootstrapping complexity.

One goal for Jolt in particular is to get more interest from outside the existing Clojure community by addressing these concerns. The compiler is a single binary, and it ships with all the tooling, such as dependency management and task running, baked in. It interops seamlessly with the native ecosystem via FFI, so you can use it in a way comparable to Python. Best of all, program distribution involves building a standalone binary similarly to Go. Thus, Jolt may remove the last big source of friction for trying Clojure.

In an age where writing code is cheap but verification and iteration remain expensive, the high level declarative style lines up exactly with what both agents and humans need to produce working code. Clojure is a great language to learn today because of the unique way it fits the era of language models.

Terence Tao Responds to the OpenAI Math Drop

Hacker News
mathstodon.xyz
2026-10-08 01:14:14
Comments...

Everything You’ve Been Told About Lethal Injection Is a Lie

Portside
portside.org
2026-10-08 00:45:40
Everything You’ve Been Told About Lethal Injection Is a Lie Mark Brody Thu, 10/08/2026 - 00:45 ...
Original Article

In the months leading up to Christa Pike’s execution date, she and her legal team made it clear that she, the lone woman on Tennessee’s death row, 50 years old, wasn’t afraid to die. She was terrified of the execution itself .

“Her greatest fear wasn’t dying,” attorney Stephen Ferrell told USA Today in a press conference. “It was a fear of a prolonged, painful, traumatic death.”

Citing her blood-clotting disorder and a history of difficult blood draws, her attorney argued that there could be problems properly affixing the IV into Pike’s arm and that executing her via lethal injection would amount to cruel and unusual punishment.

About a month before her execution, her lawyers had pushed for her to be hanged or shot by a firing squad instead. At the eleventh hour, the Sixth Circuit Court of Appeals stayed her execution, only to have the Supreme Court overrule it. When she finally arrived in the prison’s death chamber, Pike and her lawyer’s concerns would be proven true to a degree they couldn’t have anticipated: she became the first person to survive the administration of a double dose of lethal injection drugs.

What should have been a ten- to twenty-minute process took two hours, according to the Associated Press, and ended with Pike alive but in critical condition. Christa Pike reportedly remains intubated, on a ventilator in a Nashville hospital, receiving life-saving care after being pumped with what should have been two fatal doses of pentobarbital, a barbiturate used by many states for lethal injection. When she arrived at the hospital, Pike’s arms were “swollen, burned and blistered,” according to an emergency filing from her legal team.

There’s still a lot that we don’t know about the actions of prison officials leading up to and during Pike’s execution. Pike’s attorneys believe that a problem with the state’s IV lines caused the pentobarbital to flow into her tissue, instead of her veins.

Tennessee Gov. Bill Lee has halted all executions in the state and ordered an “independent investigation.” The head of Tennessee’s Department of Correction resigned days after Pike’s hospitalization, but defended the execution, saying the state “carried out its responsibilities in accordance with the established protocol.”

Christa Pike’s case, while unusual in many respects, is a perfect encapsulation of the pitfalls of lethal injection as an execution method in the United States. Most people’s understanding of lethal injection—as a humane alternative to more overtly brutal executions of yore—is in stark contrast to the actual barbarism behind the procedure. This misconception is no coincidence: it’s by design.

Death penalty states are incredibly secretive about every step of the lethal injection process. Why? According to University of Richmond law professor and former prosecutor Corinna Barrett Lain, it’s because lethal injection has the best political optics—as long as people don’t know much about what’s happening behind the scenes.

As Lain wrote in her 2025 book , Secrets of the Killing State: The Untold Story of Lethal Injection :

Every other execution method—hanging, the electric chair, gas chamber, and firing squad—lays bare the brutality of the state that kills in our name. Lethal injection hides it. With lethal injection, we don’t have to deal with the sight of blood, or the smell of burning flesh, or the sounds of suffering, all potent reminders of what the state is actually doing. Instead, we get to tell ourselves that prisoners are just drifting off into forever-sleep.

Secrets of the Killing State pulls back the curtain that shrouds lethal injection, revealing how everything from the drug suppliers to the science behind this method of execution is riddled with issues. I reached out to Lain to learn what might have gone wrong in Pike’s execution, and how the problems with lethal injection are not individual but systemic, baked into its very foundation.

This interview has been edited for length and clarity.

What was your initial reaction to hearing about the failed execution of Christa Pike?

Yet another botched execution. I had some ideas of how it happened, why it happened, but of course, part of the problem is we don’t have any information. I’ve been studying [lethal injection] for seven years, so hearing about Christa, it’s really sad and frustrating.

“For the first 35 to 40 years, states used a paralytic…that would ensure it would look like putting down a pet.”

You know, in some ways, her case is a paradigm example of both everything that’s wrong with lethal injection and everything that’s wrong with the death penalty. More broadly, it’s an example of what’s wrong with lethal injection.

We now have a growing list of people whose executions are so badly botched that they survived their own execution. But we also know we’ve seen executions that are one hour long, two hours long, three hours long. I’ve seen autopsies with 14, 16, 18 puncture wounds. This is the stuff that’s been happening, but now, finally, it has drawn the public’s attention.

In your book, you spend a good chunk of the beginning pulling back the curtain on the real horrors that come with lethal injection and how execution states have pretty brilliantly rebranded it. Can you describe people’s biggest misconceptions when it comes to the death penalty vs. the actual reality of the procedure?

The public has been told for the last 45 years that lethal injection is akin to putting your beloved pet down, and none of that’s true. The public has been sold a bill of goods, and for the first 35 to 40 years, states used a paralytic as one of the drugs in lethal injection that would ensure it would look like putting down a pet.

The paralytic was also a muscle relaxant, so it relaxed all the muscles in the face, and then it froze them that way. So you’re going to get this nice drifting-off-to-sleep look, no matter what is actually happening, and we know what’s actually happening because now we have hundreds of autopsies that show us that those are violent deaths too.

What happened to Christa Pike was simply the truth breaking through.

That goes perfectly into my next question. Can you talk about why the use of pentobarbital in lethal injections is, for lack of a better word, problematic ?

Pentobarbital is the drug that we use in physician-assisted suicide and also in animal euthanasia. So one might think that it is a better drug for lethal injection than the traditional three-drug protocol that states were using all these years.

But what we know from autopsy studies is that the pH of pentobarbital, which is between 10 and 11, is chemically burning the delicate capillaries in the lungs, causing the capillaries to become leaky and the lungs to take on fluid.

This condition is called flash pulmonary edema, and it shows up, depending upon the study, in between 84 percent of all pentobarbital executions.

Flash pulmonary edema happens in seconds when you inject a drug into the veins. It goes first to the heart. Then to the lungs. So, as the body is trying to buffer that difference in the pH so that it can metabolize the drug and use it as an anesthetic, it’s already gone to the lungs, and that happens immediately.

These people are essentially drowning in their own fluids. Some of the cases show acute flash pulmonary edema. It’s also called fulminating pulmonary edema. That’s where the lungs are so congested that the froth—the mixture of air and fluid—actually moves up into the windpipe, into their throats, and they choke on it.

“One of the things [the report] found was executioners, on the eve of an execution, looking in Wikipedia to figure out how much of the drugs to inject.”

One court asked a medical professional on the stand, while explaining pulmonary edema, if the sensation would be one of drowning from within. The court said, “Is this the same sensation as waterboarding?” And the medical professional said yes.

The public has this view of lethal injection as just putting a pet to sleep. In reality, we are actually waterboarding people to death, and I don’t say that to be dramatic. I say that to be clear, honest, and candid about what we’re actually doing.

Before her execution, Pike was issued a stay by an appeals court, which was quickly overruled by the Supreme Court. A throughline throughout Secrets of the Killing State is the role that politics plays in pushing executions forward. Can you describe why—and do you believe that politics played a role in the fast-tracking of Christa Pike’s execution?

Politics played a role in the sense that this “pro-life” Supreme Court is uniquely excited about death and advocates for it. So what happened in Christa Pike’s case is actually not unusual at all.

This is a theme that we saw in the executions from Trump’s first term too, where a court had heard a challenge to the one-drug pentobarbital protocol; the prisoners had presented two weeks’ worth of evidence, thousands of pages and documents, expert testimony, all of that stuff, and the district court issued a preliminary injunction on the execution and said—by the way, to issue a preliminary injunction, you have to make a factual finding, and the court did—that the plaintiffs were likely to succeed on the merits of their claim.

So stop and think about that. A federal court that heard two weeks’ worth of evidence paused the execution just till they could get to trial. But the standard for that is incredibly high. You have to be able to find that the plaintiffs are probably going to win. They are likely to succeed. So she issues the preliminary injunction, and the Supreme Court lifts it and greenlights the Trump executions. That was the first of, I think it was 13 Trump executions, and it all started with the court lifting a stay on the shadow docket .

It’s incredibly perverse that the court in those Trump executions would lift the stay over executions. Litigation over the very method of execution that they were then subjected to. They made a claim. They said this is unconstitutional. The court said, “You know what? I think you’re probably going to win this. Let’s at least let you get to trial.” And the Supreme Court lifts the stay. They can’t even get to trial, and then they are executed by the very method that they had shown was probably unconstitutional.

It’s pure power. Purely unjudicious.

One large part of the branding for lethal injection is that it’s a “scientific procedure”: “We put down animals all the time, and euthanasia is legal in some countries for humans. Why can we do the same thing here?” But chapters two and three of your book unveil just how much these procedures are not, forgive the pun, “a perfect science.” Can you talk about this?

We assume it’s science because we know that there is science behind animal euthanasia and physician-assisted suicide. But it’s quite telling that in the traditional three-drug protocol that every state used for the first 35 to 40 years of lethal injection—not a single one of those drugs was the drug that we use for animal euthanasia and physician-assisted suicide. Not one of those drugs.

When the man who invented lethal injection was asked about that—“Hey, how did you come up with the drugs?”—he said, and I quote , “I didn’t do any research.” He just made it up off the top of his head. It’s so fantastical that it would be hard to believe if it weren’t true. But it is true, and it’s not just about what happened in 1977 when lethal injection was invented.

In 2024, Arizona botched three executions in 2022, and the governor put executions on hold and said, we’re going to have an independent investigation. They hired a retired federal judge. The judge looked into it, drafted a report that found all kinds of things. And the governor dismissed him and said, “We’re going to go a different direction.” That’s literally what she told him.

The different direction was having the Department of Corrections do a review of itself, which it then did, and said, “We’re great. Now give us our warrant, and we’re going to start with a volunteer.” So there’s no adversarial process at all. But this made the judge so mad that he actually released his draft report. You can find it on the internet. And one of the things he found was executioners, on the eve of an execution, looking in Wikipedia to figure out how much of the drugs to inject.

“It’s easier for them to argue about secrecy, and to take the hit for secrecy, than for the public to know.”

That’s 2024. This didn’t even make it in the book. They don’t know what they’re doing. The problem with lethal injection, at its core, is that medical scientists are not going to tell states how to do this. They are very much believers in the Hippocratic Oath. They are healers. They’re creating this knowledge for healers, and they are not going to tell you how to kill. So, you’ve got people looking on Wikipedia. The American public hears them saying, “Oh yes, we’re careful. Oh yes, we care. We’re following the protocol.”

And the fact of the matter is, it’s a hot mess that would make any citizen outraged if they knew what was really happening behind this curtain.

Which goes into my next question: the secrecy. One of the biggest realizations that I learned from reading this book was how much secrecy goes into an execution via lethal injection, from who the executioners are, where the drugs were obtained, to even the events happening within the death chamber.

And this secrecy is by design. Why is this the case?

My sense is states can’t fix what is broken with lethal injection. They can’t get the drugs because pharmaceutical companies didn’t make medicine for killing. They can’t get the medical professionals they need to competently do these executions. They can’t get access to the veins. The death row population is a geriatric population with notoriously weak veins. These are people with histories of poor health in general, and many of them are former IV drug users. Even Christa Pike- her lawyers were saying she has bad veins.

These are problems inherent in the project of using drugs to kill. So what do you do when you can’t fix the problem? You hide it.

It’s easier for them to argue about secrecy, and to take the hit for secrecy, than for the public to know where they’re actually getting their drugs from, how they’re breaking laws, who they’re using; it’s easier for them to defend secrecy with the state at its most powerful moment than to defend their practices on the merits.

Arianna Coghill is an assistant news and engagement writer at Mother Jones. Previously, she was a reporter for RVA Magazine and Dogwood, with bylines in the Washington Post, the Chicago Tribune, and the Associated Press. Throughout her writing career, she’s covered police reform, racial justice, reproductive rights, and several other subjects. You can follow her on Twitter @CoghillArianna.

Snow Globe Palimpsest

Portside
portside.org
2026-10-08 00:44:44
Snow Globe Palimpsest Geoffrey Thu, 10/08/2026 - 00:44 ...
Original Article

Anti-Zionism: A Jewish History
Benjamin Moser
Doubleday
ISBN: 9780385551243

THE SNOW GLOBE, the children’s toy that first appeared at the Exposition Universelle in Paris in 1878, only two decades before the First Zionist Congress, is a glass or plastic sphere containing a bucolic scene with flakes at the bottom, and when you shake it, the flakes scatter and the scene is suddenly transformed. That is the image that keeps coming to mind these days. First, October 7, 2023, and then the subsequent destruction of Gaza. Suddenly, the same seemed different, uncanny, unheimlich—familiar yet strange. October 7 was never supposed to happen; that is why the State of Israel was founded. And yet it happened. And Israel, always prepared to respond militarily to aggression, was never supposed to go so far as to destroy a society. Yet that happened too. And suddenly, everything seemed different—and yet the same. Of course, one can imagine the trauma of October 7 bringing Jews together, to mourn, to vent, even to question. Patriotism is a predictable consequence of national trauma.

Yet the destruction of Gaza produced something unpredictable among many Jews. It brought them to the conclusion that something was wrong, very wrong, systematically and structurally wrong, certainly in Israel, but maybe with Zionism itself. From its origins in late 19th-century Europe, Zionism has comprised a complex set of competing ideas about Jewish self-determination: from envisioning a socialist state to a hypernationalistic one, a state that incorporated the Palestinian population in the form of binationalism to one that excluded them, a liberal state to a reactionary one. But for many today, Zionism has come to simply mean support for the State of Israel as a Jewish state. Beyond debates about policies (occupation, detention without due process, house demolitions), justifications (security and the demand that there never be another October 7), the present government, theological dogma, or even facts on the ground (the death toll of 75,000 and the fact that starvation and disease run rampant are still denied by some), the destruction of Gaza gave birth to a new iteration of Jewish anti-Zionism.

Anti-Zionism is not new among Jews; in fact, it was arguably created by Jews. Over its long history, Jewish anti-Zionism has taken many forms—certainly before the establishment of the State of Israel, but even after. Many Orthodox Jews viewed Zionism as a transgressive attempt to bring the exile to an end before the arrival of the Messiah. Socialist Jews opposed it because it was a form of nationalism. Many liberal Jews in Europe in the late 19th and early 20th century saw it as an obstacle to integrating into a post-emancipation society that had finally removed the barriers to Jewish equality and citizenship rights. And many, even most, American Jews, through the early decades of the 20th century, rejected Zionism for its implications of a dual allegiance, which seemed to present an impediment in the process of “Americanization.” But except among the ultra-Orthodox, anti-Zionism had mostly been “put to bed” with the emergence of the Zionist consensus in the early 1970s. It has now woken up.

I separate here the anti-Zionism of Jews and anti-Zionism more generally because they are not identical. The non-Jewish anti-Zionism that arose in the Soviet Union in the 1950s, and later in other places in Europe, was based on the denial of the Jews as a people and was mostly an appendage of antisemitism. The resistance to Zionism in the Arab world was largely founded on a view of Zionism as a form of colonialism. Jewish anti-Zionism, on the other hand, never denied the Jewish collective, even if many denied Jews as a “nation,” viewing them rather as a people, a religious collective (or edah). This was primarily an internal debate about the best path for Jewish flourishing in a post-emancipation world.

Just as Jewish anti-Zionism in the past faced fierce condemnation from Jewish ideological adversaries, the new Jewish anti-Zionism met with a strong and swift reaction: blasphemy, infidelity, treason, and, of course, antisemitism. The literal war in Gaza has been accompanied by a rhetorical and internecine Jewish war against anti-Zionism. All forms, for whatever reason, are illegitimate, equated with antisemitism, and so all who hold these beliefs are enemies of the “Jews.”

Benjamin Moser’s new book Anti-Zionism: A Jewish History is a contribution to the present war of identity, seeking a lineage in the stories of Jews in the past who rejected Zionism for a wide variety of reasons. It doesn’t break new ground, nor does it intend to, and it is not a “history” per se. Rather, it is a kind of literary resurrection, a personal search through lost Jewish choices, following paths long overgrown and figures that history thought best forgotten. In the first chapter, which is really the “why” of the book, Moser gives us a window into his Gen X childhood as a Jew in Texas: his discovery of Zionism and subsequent disillusionment with it. While not unfamiliar, his story of disenchantment frames a rediscovery of the forgotten. Instead of becoming a political activist or simply giving up, Moser decided to see what lay down those overgrown paths. Others must have felt something similar in their respective contexts. Who were they, and what happened to them?

Even more than Zionism, anti-Zionism can, and does, mean many things, and Moser presents his narrative through a series of biographical sketches. The figures he profiles came from four continents. These are people who mostly did not know of one another and did not speak the same languages. They likely disagreed about much except for their rejecting Zionism as a viable form of Jewish collective life, though each opposed the Zionist project for different reasons. Some were secular, some Orthodox (he does not treat ultra-Orthodox anti-Zionism except in the one idiosyncratic, but important, case of Aaron Samuel Tamares). They were believers, atheists, rabbis, artists, journalists, and revolutionaries. Some of the figures we know well—Hannah Arendt (Germany, United States), Maxime Rodinson (France), Avi Shlaim (Iraq, Israel, United Kingdom), and Nan Goldin (US). Some less well—Jacob Israël de Haan (Netherlands), Aaron Shmuel Tamares (Belarus, Poland), Felicia Langer (Poland, Israel, Germany), and Edwin Montagu (UK). Some hardly at all—Helena Salem (Brazil), Ronnie Kasrils (South Africa), Ahmad Sadiq Saad (Egypt), and Hyman Judah Schachtel (US). Many have been relegated to the dustbin of history, and many of Moser’s critics will say “for good reason.” But attempts at erasure often produce palimpsests—that which lies underneath never completely disappears. History closes doors, but it rarely throws away the key.

Aaron Samuel Tamares (1869–1931), also known as Aharon Shmuel Tamares, was an ultra-Orthodox rabbi in a small town in Belarus. He was originally sympathetic to Zionism, even attending the 1900 Zionist Congress in London as a delegate, but came to view its nationalistic fervor and secularism with great suspicion. Especially after World War I, he held the belief that Zionism would make the Jews a violent people and undermine their covenantal destiny. Edwin Montagu (1879–1924) served in the British Cabinet (only the third practicing Jew to do so) and strongly opposed the Balfour Declaration in 1917, which supported the establishment of a “national home for the Jewish people in Palestine.” He considered the government’s statement antisemitic because it suggested Jews had no place in the Diaspora. In his fight against Zionism in Britain, he found himself at odds with his cousin Herbert Samuel, the first high commissioner for Palestine during the British Mandate. Avi Shlaim (b. 1945), an Iraqi Jew whose family was brought to Israel in the early 1950s as part of the airlifts orchestrated by the American Jewish Joint Distribution Committee, has lived in England since the 1960s and has become a preeminent historian of Zionism and a vocal critic from a Mizrahi perspective. Ronnie Kasrils (b. 1938), a South African Jew, fought against apartheid and was critical of Israel’s secret trade agreements with South Africa in the 1970s, comparing the treatment of Palestinians to apartheid. Among the lesser-known figures brought to light in Moser’s book, a Brazilian Mizrahi Jew named Helena Salem (1948–99) stands out. She worked as a journalist and helped cultivate Palestinian activism in South America. Her visits to Palestinian refugee camps and prisons in Israel after the 1967 war resulted in her 1977 book, Palestinos, os novos judeus (“Palestinians, the New Jews”).

Yet the very diversity of these thumbnail biographies points to a major weakness at the heart of Moser’s book. The work is, above all, a poignant artifact of the painful present, expressing one Jew’s growing disdain for Zionism, which leads him to look for precedents. However, while his subjects may have rejected Zionism, they did not (except in the case of Ahmad Sadiq Saad, an Egyptian communist who converted to Islam) disaffiliate from the Jewish people. More complex—and, frankly, more interesting—than the mere repudiation of Zionism, which links this disparate group, is the question of how Jews have navigated their identities and allegiances in a post-emancipation world. If not Zionism, then what? It’s a question that Moser is largely indifferent to as he narrates the lives of his subjects.

Are these figures representative? That is another critique likely to be raised about this book, though it is one that is far less cogent. Representative of what, exactly? And why does that matter? Before the 1930s, arguably before 1948, Zionism itself was not representative of the Jews, and yet we know of many Zionists of that era, canonized for Americans in Arthur Hertzberg’s 1959 book The Zionist Idea: A Historical Analysis and Reader . As historian Maxime Rodinson noted, “The Zionists freely proclaim that Zionism is the natural outcome of the whole of Jewish history, something which belongs to the very essence of Judaism and to which all the world’s Jews owe allegiance.” This is a historical narrative associated with what is sometimes called the “Jerusalem School” of Jewish history, comprising scholars mostly affiliated with the Hebrew University, such as Yitzhak Baer, Ben-Zion Dinur, Yehezkel Kaufmann, Joseph Klausner, and Benzion Netanyahu, who, beginning in the 1920s and ’30s, came to view Zionism and Jewish sovereignty as the very telos of Jewish history. As Dinur said, “All Jewish history is Zionist historiography.”

Other Jewish historical “schools” and narratives existed, but by the 1970s, the Jerusalem School had emerged victorious, even if few knew what it was or could name one of its members. A somewhat watered-down version of the story of the Jews told by Dinur and the rest had solidified into a key component of a conventional Jewish identity that would have been unrecognizable as normative in the early years of Zionism. The chapters in Anti-Zionism are selective, as they must be, and one can question why Moser includes this but not that person. But in some way, this misses the point. He doesn’t set out to be comprehensive, and his argument is not that the lives and ideas of these figures subvert the Zionist vision of history. Rather, they demonstrate how recent a phenomenon the Zionist consensus is. And if that consensus is now over—and it might be—it is vital to revisit those who opposed it before and while it was taking hold.

Beyond the colorful stories and characters and Moser’s deft writing style, the book provides a window into the Diaspora as a place where Jews suffered and flourished, trusted and doubted, loved and despised, a place many Jews were not willing to abandon. These stories can be inspiring but also horrifying. Some end with banishment, some with prison, one with conversion (Egyptian Jew Ahmad Sadiq Saad converted to Islam), and one with a bullet in the chest (De Haan). However harsh we think the current ideological war against Jewish anti-Zionism is, it is nothing compared to the reactions of the past. Arendt was not only ostracized after publishing Eichmann in Jerusalem: A Report on the Banality of Evil in 1963; she also faced formal institutional attempts to destroy her reputation. The Anti-Defamation League sent out a nationwide circular asking rabbis to denounce Arendt from the pulpit on the High Holidays. Israeli dissident Amos Elon, quoted by Moser, recounted that “a group of lecturers—some flown in from Israel and England—toured the country decrying Arendt as a ‘self-hating Jew,’ the ‘Rosa Luxemburg of Nothingness.’” These attempts did not succeed. Arendt was, as they say, “too big to fail.” But Felicia Langer wasn’t. A lawyer for Palestinians in Israel, representing them against government and military allegations from the conclusion of the 1967 war until 1990, she saw her family life destroyed and her well-being constantly threatened by Israelis. She had to hire a bodyguard, and things finally got so bad for her in Israel that she had to flee to Germany to feel safe as a Jew.

Most tragic is the case of Jacob Israël de Haan, an openly gay Dutch Jew, a member of the religious Zionist Mizrachi Party, who immigrated as a Zionist to Palestine in 1919. He became distraught after witnessing the treatment of Arabs by the Zionists there. He wasn’t the first Zionist disillusioned by the realities of Jewish settlement in Palestine. One finds similar sentiments expressed in historian Hans Kohn’s letter of resignation from the Keren Hayesod (Israel’s nationalist fundraising arm) in 1929, published as “Zionism Is Not Judaism,” or the two depressing reports by Ahad Ha’am, a journalist, essayist, and founder of cultural Zionism, published as “Truth from the Land of Israel” in 1891 and 1893. De Haan abandoned Zionism, became ultra-Orthodox, and began to serve as a spokesman for the “Old Yishuv” (the Jewish community that had existed in Palestine before the advent of Zionism, to which it was generally hostile), negotiating on their behalf with the British authorities and Arab leadership. He was warned by Zionists to desist from his activities. He refused. As he came out of a Jerusalem synagogue one morning in June 1924, having said Kaddish for his recently deceased father, a man approached De Haan asking for the time, pulled out a pistol and shot him three times in the chest. He was dead within minutes. Rumors spread that he’d been killed by an Arab, but it soon came to light that the murderer had been Avraham Tehomi, a member of the Jewish terrorist group Irgun, an offshoot of the Haganah, the main Zionist paramilitary organization that had orchestrated the assassination.

This would not be the last time that Zionists made the calculation to sacrifice Jewish lives for the sake of the nation. Famous in its time but now almost forgotten, the Lavon affair in 1954, also known as “Operation Susannah,” was a failed clandestine Israeli program to set off explosives in markets, movie theaters, and other civilian locations in Egypt with the primary aim of blame being assigned to the Muslim Brotherhood to destabilize Egypt. But it was also meant to instigate Egyptian hatred of the Jews in order to initiate a large migration of those Jews to Israel. Similarly, as noted by historian Avi Shlaim, Zionist agents bombed Jewish venues in Iraq in 1951 to frighten them into immigrating to Palestine. The nascent state needed Jews to secure its majority.


Zionism is hardly unique in this: We know that nationalist movements (and other movements based on collective ideologies) have done—and do—horrific things in the service of their cause, even attacking and killing their own. When any cause, whatever it is, understands itself as the telos of a people’s history, we get some version of what historian of Israel and Zionism Yaacov Yadgar, in his 2024 book To Be a Jewish State: Zionism as the New Judaism , calls “Zionist supersessionism”: Zionism replaces Judaism, or at least makes it subservient. What Moser’s book does so effectively is excise the false exceptionalism that pervades the Zionist narrative, as if Zionism was somehow different from other nationalisms, as if all Jews in Israel/Palestine were “family.” It is not, and they are not, and like other nationalist causes, there are detractors.

Israel’s choice to destroy Gaza—and it was a choice—has produced liquid times for many Jews. That which was given is now being questioned; that which was normative is now being challenged. The stories featured in Anti-Zionism: A Jewish History tell of struggle, of deep conviction, of the desire for justice. To give voice to these stories is an act of fidelity to those who suffered at the hands of an emerging national project in a time of trauma. Perhaps today the scattered flakes in the snow globe have settled once again. But that does not mean things can return to the way they were before.

Shaul Magid is professor of modern judaism in residence at Harvard Divinity School. His latest book is The Scourge of Jewish Nationalism: Rabbi Yoel Teitelbaum’s Anti-Zionist Thought (University of California Press, 2026).

Will Netanyahu Escape His Reckoning?

Portside
portside.org
2026-10-08 00:35:17
Will Netanyahu Escape His Reckoning? Mark Brody Thu, 10/08/2026 - 00:35 ...
Original Article

In his desperate attempt to hold on to power as Prime Minister of Israel, Benjamin Netanyahu is trying to cast a spell on the electorate with a stark and profoundly cynical message: Forget the horror of October 7, 2023 , and my responsibility as the guardian of national security. (Blame everyone except me.) But celebrate me, elect me, for all that I have done to assert the military dominance of the state, on October 8th and thereafter. It is an outrageous argument. It is also one that could, against all odds, prevail.

The election is October 27th. Netanyahu and his party, Likud, are not ahead in most mainstream polls, and yet most observers of any credibility agree that damn near anything could happen, especially given Israel’s complicated parliamentary arrangements and wild array of parties. Netanyahu’s principal opponent, Gadi Eisenkot, a centrist former Army general and the leader of the Yashar Party, could end up forming a winning coalition with parties led by Yair Golan, Naftali Bennett, Yair Lapid, and Avigdor Lieberman, as well as a moderate Arab party called Ra’am, led by Mansour Abbas. Or there could be a deadlock and yet another election next year. Or Netanyahu, who sometimes in his long career has been stronger in the final ballot than in the polls, could find a way to form, yet again, a right-wing coalition.

What is astonishing—politically, morally, strategically—is that Netanyahu has any chance at all. Within days of the Hamas attack on Israel, the worst disaster in the history of the state, it was all but a given that he would soon be out of power. How could any electorate look past such a collapse and national trauma? For a while, Benny Gantz , a well-known former Army general who is seen as a Gary Cooper-like centrist, was the presumed favorite—but it turned out that he had very little to say and even less charisma with which to say it. As a presumptive Prime Minister, he proved no more durable than a wedding cake left out in the rain. Gantz quickly became the forgotten man of Israeli politics.

More recently, Eisenkot has emerged as a figure of solidity and a focus of sympathy. (He lost a son and two nephews in the war. Everyone knows this about him.) When he became the potential leader of a putative opposition coalition, Netanyahu made it clear how he would set out to attack him. He would declare his opponent soft on security, soft on the Arabs, and (God forbid) a supporter of finding a path toward peace with the Palestinians of Gaza, the West Bank, and Jerusalem. A blend of bravado and bigotry has worked for Netanyahu in past campaigns.

But it is one thing to predict the ugliness of a campaign, and quite another to watch it play out. Earlier this week, Yinon Magal , the leading talk-show host and commentator on Channel 14, an ardently pro-Netanyahu outlet, denounced a group of former hostages and their families who contributed to a book called “Mr. Abandonment: The Legacy of the Man Who Abandoned the Hostages.” Their argument was that the Prime Minister had failed to make freeing the hostages his main priority. Magal did not hesitate to smear them. “Anyone who took part in the campaign saying he abandoned the hostages will be remembered in infamy, on a pillar of shame,” Magal said during a radio broadcast . The hostages and family members who dared to criticize Netanyahu for his handling of the issue, he said, are “the lowest people living in the State of Israel.”

Eisenkot, who joined a war cabinet at Netanyahu’s invitation, quit that council when he determined that Netanyahu was refusing to make the hostages his first priority. Magal, who welcomes Netanyahu onto his show “The Patriots” with the audience singing praises to him as the “King of Israel,” spit venom at those who dared to criticize the Prime Minister. “I’m telling you,” Magal said of the former hostages and their families, “these are despicable people, and the only thing that can absolve them is if they put the Likud ballot slip for Netanyahu into the ballot box in the election. ‘Forgive us, absolve us, pardon us.’ That’s the only way they can atone for the abomination they committed by participating in ‘Mr. Abandonment.’ ”

Netanyahu’s critics have often pointed out that, even in the early days of the war, he rarely visited the hostage families or expressed much concern for them. That omission, that coldness, has not been forgotten. At a ceremony Monday, in Jerusalem, commemorating the October 7th massacre, a bereaved father, whose son was killed at one of the kibbutzim near Gaza, rose during Netanyahu’s speech and said, for all to hear, “You did not protect my son. You did not protect the twelve hundred people who were murdered in a single day, on October 7th. Shame on you, disgrace.”

At the same ceremony, the Israeli President, Isaac Herzog, called for an investigation into the security collapse. “No amount of time that passes can allow us to forgo this obligation. There are clear lessons we already know we must internalize: We must not ignore warnings or worrying signs.”

This is the very same message that has come from Eisenkot and so many of Netanyahu’s opponents. For three years, the opposition has demanded that Netanyahu do what the Israeli government did in the aftermath of the Yom Kippur War, in 1973, when Egypt and Syria attacked Israel, despite warnings from various sources in the security establishment. That exhaustive investigation, the Agranat Commission, led to numerous resignations and, eventually, the end of Golda Meir’s career as Prime Minister. By contrast, Netanyahu and his circle have done all they can to defer any kind of official inquiry and, at the same time, to put out the word that everyone but the Prime Minister is to blame. Leading figures in the security establishment have issued public apologies and left the scene. Netanyahu remains.

It has been well known for a long time that Netanyahu badly misread the intentions and capabilities of Hamas, treating them as little more than a hyped-up street gang compared to Hezbollah, in Lebanon. His singular focus has always been on Iran. Over time, there has been a wealth of investigative journalism making plain that the security establishment ignored clear warnings of peril from mid-level intelligence officers and other sources. No less startling, Netanyahu himself got clear warnings from both the United Arab Emirates and Egypt that a major operation was imminent. Reporters for Haaretz wrote last month that Sheikh Mohamed bin Zayed, the President of the U.A.E., told Netanyahu in late September that he had reliable intelligence about Hamas and its plans to attack Israel. (Netanyahu has denied the report and similar ones about warnings from Egyptian sources.)

In Trumpian fashion, Netanyahu and his circle have gone on the counterattack. The Prime Minister’s wife, who is known for treating aides and household help with high-volume contempt, even gave an interview recently that fed into widespread right-wing conspiracy theories that high-ranking Israeli security officials had inside information on Hamas’s plans. Speaking to Channel 14, Sara Netanyahu insinuated that Yair Golan, the former deputy chief of staff of the Army and leader of the center-left Democrats Party, drove south on the morning of the attack to rescue people, not because he was courageous or selfless but because he had advance knowledge of the Hamas assault.

“When you’re a military man of such high rank, claiming that you fought on October 7th, already early in the morning you were there, already dressed and ready at a very, very early hour when others didn’t know, such as the Prime Minister,” she said.

Netanyahu generally tries to distance himself from conspiracy theories, leaving that work to his supporters and family members. In the meantime, he has focussed on highlighting criticism from abroad as a badge of honor. In his recent appearance at the United Nations, Netanyahu was speaking not so much to the scattered delegates in the room but to the cameras and his electoral base at home. According to Reuters , Netanyahu’s team posted the speech online, with the Hebrew caption “Netanyahu takes on the world.” His self-depiction is as the Churchillian defender of the nation.

Just as Netanyahu refuses to take any responsibility for the cataclysm of October 7th, he insists that his military campaigns against Gaza, where more than seventy thousand have died; against Hezbollah, in Lebanon; and against Iran have made Israel stronger—and to hell with his foreign critics, whom he often paints as antisemitic. The new documentary film “ NAZA ,” which focusses on war crimes in Gaza, and the foiled hijacking of the FlyDubai flight have all become fodder for his political campaign. He will do and say anything to deflect attention from his failures or his readiness to accommodate the haredim, the ultra-Orthodox, who insist on avoiding mandatory military service. As Ilana Dayan, an investigative journalist and the host of “Uvda,” on Channel 12, put it to me, “The vast majority of those who are for Bibi tell you ‘There is no one else but him,’ and that he is showing the world how strong we are. That is one of the pathologies of this political campaign.”

Eisenkot, who entered politics in 2022, insists that the choice in this election is “between responsibility and running away from responsibility.” When I interviewed him recently, in Israel , he told me that among his most immediate priorities as a national leader would be the establishment of an official commission of inquiry, one that would investigate, among other questions, Netanyahu’s culpability. More recently, he has argued that the Prime Minister is an “anti-leader,” who dodges responsibility and thirsts for credit he has not earned. “The FlyDubai plane incident is an excellent example,” he told the Times of Israel this week. “He takes an incident that constitutes a massive security failure, which was averted only thanks to the extraordinary heroism of Israeli civilians and an Indian pilot, and shamelessly leverages it for a photo op.”

172 Billionaire Families Have Spent Record $1.7 Billion on 2026 Midterms So Far

Portside
portside.org
2026-10-08 00:26:42
172 Billionaire Families Have Spent Record $1.7 Billion on 2026 Midterms So Far Mark Brody Thu, 10/08/2026 - 00:26 ...
Original Article
172 Billionaire Families Have Spent Record $1.7 Billion on 2026 Midterms So Far Published

Marc Andreessen and Laura Arrillaga-Andreessen attend a ceremony on April 18, 2026 in Santa Monica, California. | (Photo by Craig T Fruchtman/WireImage)

An analysis released Wednesday shows that 172 billionaire families in the United States have collectively spent more than $1.7 billion on the 2026 elections—a record-shattering sum for a midterm cycle.

The analysis by the Americans for Tax Fairness (ATF) Action Fund shows that the “vast bulk” of billionaire political spending this election cycle has flowed to super PACs , a product of the Supreme Court’s notorious 2010 Citizens United ruling. Super PACs can raise and spend unlimited sums in support of favored candidates, giving billionaires a powerful vehicle to influence elections.

ATF Action Fund found that billionaire political spending has increased 53-fold since the Citizens United decision. This cycle, less than 20% of billionaire donations went to committees subject to contribution limits.

“With each passing election since the Citizens United decision, billionaires have systematically bought up our democracy ,” said Jodie Rubenstein, ATF Action Fund’s executive director. “These billionaires are backing a crooked tax system that shifts wealth upward through massive tax giveaways to the wealthy and big business. We can’t let billionaire money erode our democracy while working families struggle to get by.”

“Working- and middle-class Americans must fight back and make clear this November that our democracy is not for sale,” Rubenstein added.

The top-spending billionaire families so far this cycle are those of Marc Andreessen and Ben Horowitz, cofounders of the venture capital firm Andreessen Horowitz. The two families have pumped a combined $149 million into the 2026 elections, with donations flowing to both Republicans and Democrats. Andreessen and Horowitz have given major donations to Leading the Future, a super PAC that opposes strict artificial intelligence regulations.

The families of investor George Soros, businessman Jeff Yass, and Tesla CEO Elon Musk are other leading spenders this cycle. The top 15 billionaire spenders have accounted for $962 million in combined 2026 election outlays, according to the new analysis.

GOP candidates have been the chief beneficiaries of billionaire election spending this cycle, ATF Action Fund found, with 113 billionaire families giving mostly to Republicans and 45 donating predominately to Democrats.

“A large group of billionaires is sending their checks to MAGA Inc., which has raised over $222 million from them since January 2025,” the new analysis shows. “In fact $1 out of every $2 to Donald Trump’s MAGA Inc. super PAC comes directly from a billionaire on our list.”

Jake Johnson is a senior editor and staff writer for Common Dreams.

Make Trump Pay for Trying To Stamp Out the Postal Service

Portside
portside.org
2026-10-08 00:10:38
Make Trump Pay for Trying To Stamp Out the Postal Service Mark Brody Thu, 10/08/2026 - 00:10 ...
Original Article

Last month, the U.S. Postal Service was thrust into the headlines again when the Supreme Court temporarily blocked President Trump’s new restrictions on mail-in voting.  Though seven of the justices upheld an injunction against the Postal Service’s new mail-in ballot rule , at least one—Brett Kavanaugh—seemed willing to revisit the matter after the midterms. The rule itself, which legal experts have argued goes far beyond the Postal Service’s statutory authority, remains on the books.

Looming in the background is the uncertain future of the Postal Service itself. Upon returning to office, Trump again called for its privatization . A leaked Wells Fargo memo shows corporate investors remain eager to strip-mine USPS for its lucrative real estate and delivery network. The Postal Service’s ten-year “Delivering for America” restructuring plan has failed to meet its targets amid a looming financial cliff .

David Steiner, the former FedEx board member handpicked by Trump to succeed Louis DeJoy as postmaster general, is reportedly already eyeing the exits .

Caught in the crosshairs are the millions of Americans who depend on a well-functioning public Postal Service, from small businesses that rely on affordable postage to seniors who need timely delivery of medications. Public opinion surveys have consistently found it to be among the most popular government agencies across the partisan divide.

This presents a unique opportunity for Democrats should they retake control of Congress after the midterms. With a suite of oversight powers at their disposal, they could make the Postal Service a case study in how Trump’s corrupt leadership and austerity agenda are hurting the American people—and what a bold Democratic vision could deliver.

Expose the Failed Ten-Year Plan

Postal oversight presents Democrats with an opportunity to expose the failed record of Trump’s postmasters general, who have inadvertently demonstrated what running the post office like a business looks like in practice.

Start by folding postal oversight into the affordability agenda. Under the DeJoy/Steiner ten-year restructuring plan, the Postal Service has drastically hiked postage rates to try to improve its finances. The cost of a first-class “forever” stamp has jumped nearly 50 percent since 2020, while the Priority Mail Flat Rate package suite has seen 70 to 80 percent price hikes. Since April, the Postal Service has added an 8 percent surcharge to offset the Iran war–induced spike in fuel prices—and has just added another temporary increase for the holiday season that took effect this month.

Postage hikes have been particularly devastating for small businesses and e-commerce shops, which must either take the hit to their margins or pass on the increased costs to consumers. Many sellers on sites like eBay and Etsy fear the price hikes will kill their livelihoods. Democrats would do well to hear their testimony in public hearings. They should also grill members of the Postal Regulatory Commission, which has final say over postage rate increases. The PRC has previously admitted the agency’s financial woes cannot be resolved using price hikes alone.

The ten-year plan’s aggressive cost-cutting has also led to chronic nationwide mail delays. According to the Government Accountability Office (Congress’s own watchdog agency), the Postal Service’s cutbacks on mail collection hours and its shift from air to ground transportation have fueled the ongoing mail delays, particularly in rural areas. Longtime USPS advocate Steve Hutkins has also cited the agency’s deliberate lowering of on-time service standards and prioritization of Amazon and UPS last-mile deliveries as key factors. The spate of closures of historic post offices in rural and small towns has made the problem even worse.

These delays have been particularly harmful for the sick and elderly , who depend on timely delivery of prescription medications and Social Security payments. They have frequently led to heated exchanges between postal leadership and members of Congress ( including some Republicans ) at hearings. Congressional Democrats could go a step further, inviting residents of affected states like Wisconsin , Vermont , and Georgia to testify before the nation on how the delays have personally hurt them.

Democratic legislators could also travel on fact-finding missions to communities affected by mail delays and hold public events with customers, small businesses, and postal workers. A savvy digital media outreach strategy would complement these efforts, especially in connecting with younger users of online marketplaces like Etsy, Mercari, and Depop.

Hold the Postal Board Accountable

Democrats should also use formal oversight powers to directly question the Postal Board of Governors, the main governing body of USPS, about Trump’s attempted power grab. According to reporting by ProPublica , some board members fought Trump’s initial takeover plans for the agency (such as having Commerce Secretary Howard Lutnick oversee it) but backed off after the Supreme Court’s Trump v. Slaughter ruling, which gave the president complete power to reconstitute the membership of formerly independent agencies.

Democrats could call on the four current board members (all Biden nominees) to publicly disclose what Trump has privately demanded of them, and get their on-record testimony about whether USPS had the legal authority to issue the mail-in ballot rule that Trump sought. Of particular interest here is board chair Amber McReynolds, an independent whose term expires at the end of the year and who worked as a vote-by-mail advocate before joining the board.

Public hearings would also offer a venue to pressure the board to rescind the mail-in ballot rule , which voting rights advocates have tried to do at the board’s restrictive quarterly meetings . Hearings could also feature testimony from Postal Service whistleblowers who have alleged court orders against the rule were being violated by Trump’s postal leaders. Democrats should also probe the board’s complicity in the decline of USPS. With rare exceptions , the postal governors have not stood up to the postmaster general when his agenda has undermined the public interest.

Senate Democrats can also use oversight hearings to raise the bar for confirmation to the board. For years, presidents have either filled board seats with corporate insiders or let vacancies go unfilled. Barack Obama failed to appoint his own majority to the Postal Board, instead renominating a group of Bush-era holdovers that featured a payday lending lobbyist . While Joe Biden did manage to fill five of the board’s nine seats, his revolving-door appointees ended up largely deferring to DeJoy’s priorities .

Trump, by contrast, has swiftly moved to take over the board. He has nominated four Republicans (including three election deniers) to vacant seats, breaking with the long-standing convention of offering nominees in bipartisan pairs. His corporatist picks have received widespread opposition for their lack of postal experience. Whether their nominations are voted on in this Congress or the next, Democrats should rally public opposition to any more rubber stamps for austerity or voter suppression.

Toward a People’s Post Office

To counter Trump’s approach, Democrats could use their oversight platforms to articulate an expansive alternative vision for what the Postal Service could deliver.

Under the 2022 Postal Service Reform Act, USPS can expand its revenue stream by providing various non-postal government services at post offices, such as selling bus and subway passes or issuing hunting and fishing licenses. Yet postal leadership has been slow to invoke its new powers. In a May 2026 report , the Postal Service’s own inspector general urged the agency to develop a “unified strategic roadmap” for expanding services via the postal network, such as hosting DMV and IRS kiosks in post offices or leasing rooftop space for 5G and broadband infrastructure.

Other ideas could come from the “ People’s Postal Agenda ,” a 2021 road map drafted by a coalition of postal advocates. Its creative proposals include offering electric-vehicle charging stations at post offices or partnering with grocery stores and food banks for home deliveries.

One of the most popular reform ideas is restoring postal banking. This service was offered from the 1910s until the late 1960s, ceasing amid lobbying pressure from private lenders. Consumer finance experts like Mehrsa Baradaran argue restoring it could be a lifeline for the millions of Americans who are unserved or underserved by Wall Street banks. A 2021 pilot program, which was offered at only four USPS locations, fizzled out due to its limited scope and near-nonexistent promotion by postal leadership. While full restoration of postal banking would take an act of Congress, Democrats already have legislation waiting in the wings. The Postal Banking Act , co-authored by Sens. Bernie Sanders (I-VT) and Kirsten Gillibrand (D-NY), would allow USPS to offer checking and savings accounts, ATMs, mobile banking, and low-interest loans—creating nearly $19 billion in annual revenue for the agency.

A broader argument Democrats should embrace is challenging the absurd notion that USPS should be a profit-focused enterprise at all, rather than an essential public service like national parks, libraries, or the military. This was how we treated the post office for nearly 200 years, until a 1970 wildcat strike by postal workers led Richard Nixon to strip the agency of its cabinet-level status. Today, the Postal Service is required by law to be entirely self-funded through postage and service fees, without a cent of direct taxpayer funds (save for the occasional emergency aid package from Congress). This outdated funding model has left USPS ill-equipped in a world where email has largely replaced mailed letters and retirees’ pension benefits remain a steep financial hurdle.

What cannot be put on a balance sheet is the immeasurable public good that only a public Postal Service can provide. Among the nation’s couriers, it is the only one with a legal mandate to provide affordable and reliable service to every single ZIP code in America—no matter how rural or remote.

Paired with new revenue streams, restoring the Postal Service’s cabinet department status would go a long way toward alleviating the agency’s financial burden through annual appropriations. More importantly, it would give Democrats a chance to contrast their broad vision of the common good with Trump’s desire to sell every public service to the highest bidder.

Focusing on the Postal Service presents them with an opportunity to show the American people not just which authoritarian Trump schemes Democrats will fight against, but also which big affirmative ideas they will fight for.

Thus article was in partnership between the American Prospect and the Revolving Door Project.  The Revolving Door Project, a Prospect partner, scrutinizes the executive branch and presidential power. Follow them at therevolvingdoorproject.org .

Vishal Shankar is a senior fellow at the Revolving Door Project.

A 100x faster* alternative to homebrew

Hacker News
github.com
2026-10-07 23:23:08
Comments...
Original Article

English · 中文

Lint Test Release Discord License: MIT License: Apache 2.0

zerobrew demo

zerobrew brings uv-style architecture to Homebrew packages on macOS and Linux.

Install

curl -fsSL https://zerobrew.rs/install | bash

The installer updates your shell config. After it finishes, restart your terminal or run the source command it prints.

Or via Homebrew:

brew install zerobrewhq/zerobrew/zerobrew

Update zerobrew

If you used the standalone installer, rerun it:

curl -fsSL https://zerobrew.rs/install | bash
zb --version

If you installed with Homebrew:

brew update && brew upgrade zerobrew

If you installed from the old lucasgelfond/zerobrew tap, it's no longer updated. Switch to the new one:

brew uninstall zerobrew
brew untap lucasgelfond/zerobrew
brew install zerobrewhq/zerobrew/zerobrew

Quick start

zb install jq                   # install one package
zb install wget git             # install multiple
zb bundle                       # install from Brewfile
zb bundle install -f myfile     # install from custom file
zb bundle dump                  # export installed packages to Brewfile
zb bundle dump -f out --force   # dump to custom file (overwrite)
zb uninstall jq                 # uninstall one package
zb outdated                     # list packages with newer versions
zb upgrade                      # upgrade all outdated packages
zb upgrade jq wget              # upgrade specific packages
zb reset                        # uninstall everything
zb gc                           # garbage collect unused store entries
zbx jq --version                # run without linking

Performance snapshot

Package Homebrew (cold) ZB (cold) Cold speedup Homebrew (warm) ZB (warm) Warm speedup
Overall (100 packages) 776s 117s 6.6x 638s 9.3s 68x
python@3.14 16.99s 1.97s 8.6x 14.37s 207ms 69.4x
node 29.31s 3.16s 9.3x 28.24s 232ms 121.7x
tesseract 34.63s 2.16s 16.0x 32.37s 476ms 68.0x
openjdk 32.09s 5.17s 6.2x 26.86s 448ms 60.0x
llvm 18.22s 9.14s 2.0x 9.66s 183ms 52.8x

Measured on 2026-10-08 with zerobrew 0.3.5 (development release) and Homebrew 7.0.8 on macOS 26.6.2, MacBook Pro (M3 Pro, 18 GB RAM), ~318 Mbit/s download bandwidth. Homebrew started with nothing installed.

  • Cold : the package and all of its dependencies uninstalled, empty download cache.
  • Warm : the package and all of its dependencies uninstalled, downloads from the cold run still cached.
  • The median package was 5.3x faster cold and 56x faster warm. Per package, cold ranged from 1.6x (go) to 20x (ca-certificates) and warm from 18x (go) to 252x (ca-certificates). 24 of the 100 packages installed 100x faster or more warm, which is what the asterisk on the tagline refers to.
  • Cold installs are bound by the link. The same run on a ~69 Mbit/s connection ( results/2026-10-07 ) came out at 3.3x cold and 69x warm. Big bottles like go and llvm spend nearly all of their cold time downloading, so both tools land close together there.
Full results
Package Homebrew (cold) ZB (cold) Cold speedup Homebrew (warm) ZB (warm) Warm speedup
Overall (100 packages) 775.60s 117.43s 6.60x 637.50s 9.33s 68.31x
ca-certificates 7.65s 376ms 20.35x 6.55s 26ms 252.12x
openssl@3 11.02s 1.30s 8.46x 9.18s 64ms 143.47x
xz 2.39s 454ms 5.26x 1.46s 29ms 50.31x
sqlite 2.99s 591ms 5.06x 2.04s 27ms 75.67x
readline 2.48s 494ms 5.02x 1.46s 26ms 56.08x
icu4c@78 3.32s 1.57s 2.11x 1.96s 33ms 59.42x
python@3.14 16.99s 1.97s 8.62x 14.37s 207ms 69.41x
awscli 27.22s 3.37s 8.08x 25.56s 483ms 52.92x
node 29.31s 3.16s 9.28x 28.24s 232ms 121.72x
harfbuzz 29.34s 2.20s 13.34x 22.35s 364ms 61.41x
ncurses 3.13s 1.04s 3.01x 2.04s 69ms 29.59x
gh 2.60s 903ms 2.87x 1.35s 38ms 35.58x
pcre2 2.58s 631ms 4.08x 1.57s 35ms 44.94x
libpng 2.49s 854ms 2.92x 1.50s 27ms 55.70x
zstd 4.12s 672ms 6.13x 2.74s 34ms 80.50x
glib 7.02s 1.72s 4.08x 5.24s 94ms 55.76x
lz4 2.89s 635ms 4.54x 1.48s 27ms 54.74x
gettext 4.72s 1.30s 3.61x 3.25s 64ms 50.81x
libngtcp2 10.79s 1.40s 7.73x 9.20s 66ms 139.36x
libnghttp3 2.38s 436ms 5.47x 1.47s 27ms 54.44x
pkgconf 2.35s 469ms 5.02x 1.47s 27ms 54.59x
libunistring 2.57s 981ms 2.62x 1.49s 26ms 57.12x
mpdecimal 2.53s 705ms 3.59x 1.47s 27ms 54.33x
brotli 2.65s 776ms 3.41x 1.48s 27ms 54.67x
jpeg-turbo 2.55s 889ms 2.87x 1.48s 27ms 54.78x
xorgproto 2.21s 484ms 4.57x 1.21s 29ms 41.59x
ffmpeg 18.57s 1.76s 10.54x 17.62s 164ms 107.41x
cmake 4.04s 1.66s 2.44x 1.73s 80ms 21.64x
libnghttp2 2.63s 635ms 4.14x 1.46s 26ms 56.31x
go 5.43s 3.36s 1.61x 3.40s 190ms 17.92x
uv 2.90s 1.37s 2.12x 1.27s 28ms 45.43x
gmp 2.62s 543ms 4.83x 1.47s 26ms 56.42x
libtiff 7.08s 821ms 8.62x 6.11s 53ms 115.19x
fontconfig 9.35s 982ms 9.52x 8.13s 77ms 105.61x
python@3.13 14.28s 1.76s 8.12x 13.15s 186ms 70.71x
git 6.46s 1.67s 3.88x 4.98s 101ms 49.33x
little-cms2 7.85s 792ms 9.91x 6.83s 55ms 124.16x
dav1d 2.49s 544ms 4.58x 1.47s 26ms 56.42x
openexr 9.95s 712ms 13.98x 8.83s 59ms 149.59x
c-ares 2.51s 513ms 4.90x 1.51s 32ms 47.34x
tesseract 34.63s 2.16s 16.01x 32.37s 476ms 68.01x
p11-kit 9.26s 996ms 9.30x 7.95s 32ms 248.53x
imagemagick 14.51s 1.21s 12.00x 13.20s 82ms 160.95x
zlib 2.36s 430ms 5.48x 1.46s 25ms 58.44x
libx11 5.70s 932ms 6.11x 4.71s 174ms 27.05x
freetype 3.51s 585ms 5.99x 2.21s 32ms 69.22x
protobuf 4.06s 725ms 5.60x 3.09s 57ms 54.21x
gnupg 21.97s 1.36s 16.16x 20.63s 192ms 107.44x
openjph 7.88s 697ms 11.31x 6.80s 54ms 126.02x
libtasn1 2.30s 461ms 4.99x 1.49s 28ms 53.25x
ruby 16.01s 3.83s 4.18x 14.56s 801ms 18.18x
gnutls 14.93s 1.19s 12.52x 13.93s 134ms 103.96x
expat 2.40s 442ms 5.42x 1.48s 26ms 56.88x
libsodium 2.44s 884ms 2.76x 1.48s 27ms 54.96x
simdjson 2.52s 619ms 4.08x 1.49s 26ms 57.12x
gemini-cli 29.98s 2.23s 13.43x 27.64s 235ms 117.60x
libarchive 5.02s 594ms 8.45x 4.04s 35ms 115.31x
pyenv 12.61s 1.39s 9.06x 11.44s 135ms 84.76x
pixman 2.44s 487ms 5.01x 1.49s 26ms 57.19x
curl 16.37s 1.47s 11.12x 15.20s 173ms 87.88x
opus 2.37s 497ms 4.76x 1.47s 27ms 54.59x
unbound 12.24s 1.35s 9.07x 11.03s 113ms 97.58x
cairo 19.28s 1.48s 12.99x 17.74s 370ms 47.95x
pango 24.48s 1.69s 14.46x 23.06s 411ms 56.10x
leptonica 9.48s 914ms 10.37x 8.39s 66ms 127.18x
libxcb 4.88s 887ms 5.50x 3.89s 132ms 29.45x
jpeg-xl 12.96s 997ms 13.00x 11.92s 70ms 170.31x
coreutils 3.31s 760ms 4.35x 2.24s 38ms 58.97x
certifi 7.81s 461ms 16.95x 6.98s 31ms 225.06x
krb5 10.49s 1.34s 7.85x 9.28s 68ms 136.44x
docker 2.26s 734ms 3.08x 1.21s 29ms 41.83x
libheif 10.88s 961ms 11.32x 9.59s 63ms 152.24x
webp 4.31s 578ms 7.46x 3.37s 35ms 96.40x
libxext 6.45s 982ms 6.57x 5.42s 182ms 29.80x
libxau 2.74s 512ms 5.35x 1.85s 33ms 56.06x
gcc 12.23s 3.55s 3.45x 8.58s 67ms 128.00x
bzip2 2.09s 368ms 5.69x 1.14s 26ms 43.65x
libxdmcp 2.74s 540ms 5.08x 1.86s 33ms 56.42x
abseil 3.05s 800ms 3.82x 1.90s 50ms 38.04x
xcbeautify 2.22s 481ms 4.62x 1.15s 26ms 44.35x
libuv 2.51s 482ms 5.20x 1.47s 26ms 56.65x
giflib 2.31s 673ms 3.44x 1.46s 26ms 56.12x
utf8proc 2.36s 452ms 5.23x 1.46s 27ms 54.15x
libxrender 6.35s 976ms 6.51x 5.42s 179ms 30.25x
m4 2.00s 431ms 4.65x 1.13s 25ms 45.28x
graphite2 2.47s 428ms 5.78x 1.46s 26ms 56.23x
openjdk 32.09s 5.17s 6.21x 26.86s 448ms 59.96x
uvwasi 2.95s 483ms 6.10x 2.11s 29ms 72.66x
libffi 2.56s 575ms 4.46x 1.43s 26ms 55.08x
libdeflate 2.44s 458ms 5.33x 1.46s 26ms 56.12x
llvm 18.22s 9.14s 1.99x 9.66s 183ms 52.79x
aom 3.25s 699ms 4.65x 2.16s 32ms 67.50x
lzo 2.38s 449ms 5.31x 1.46s 26ms 56.00x
libevent 10.66s 1.33s 7.99x 9.19s 71ms 129.42x
libgpg-error 5.06s 1.11s 4.56x 3.84s 70ms 54.81x
libidn2 4.97s 1.09s 4.56x 3.87s 69ms 56.12x
berkeley-db@5 4.05s 1.96s 2.06x 2.60s 56ms 46.45x
deno 10.57s 1.46s 7.23x 9.24s 57ms 162.09x
libedit 2.35s 442ms 5.33x 1.45s 26ms 55.65x
oniguruma 2.37s 508ms 4.67x 1.46s 26ms 56.19x

To reproduce, run just bench --full results/ on a machine with nothing installed in Homebrew. It resets zerobrew, uninstalls everything it installed in Homebrew, and writes a table to results/benchmark.md .

A smaller version runs in CI: the parity workflow installs a fixed set of formulae with both tools on the same runner and compares the resulting prefixes byte for byte, and the timing workflow times those formulae plus node and python@3.14, cold and warm, with both tools and with the last zerobrew release.

The nightly timing run fails if zerobrew is less than 1.5x faster than Homebrew cold or 3x warm on any of them, or more than 20% slower than the last release overall.

A note on how we are achieving these speeds

WRT Homebrew, I want it to be clear that both brew and zerobrew install the same bottles from Homebrew's build farm .

The difference is what happens after the download: Homebrew runs Ruby to evaluate the formula, unpacks, rewrites paths with install_name_tool , and re-signs each binary one at a time, while zerobrew does the relocation in-process and links from a content-addressed store, so it pays for the download once and almost nothing after.

I want it to be clear that we are basically nothing without Homebrew's bottle build farm . Every package zerobrew installs is one they built, tested and published. We don't compile anything, we don't maintain formulae, and none of these numbers exist without that work. The speed comes from how the artifacts are installed, not from what's in them.

This is a good read, if you're interested in what zerobrew is and isn't: Standing on the shoulders of Homebrew by Andrew Nesbitt. It makes the point better than I can.

nanobrew:

nanobrew’s published numbers time a “warm install” of a package that is already installed, which is an early exit, not an install, and compare against zerobrew 0.1.0.

Every number above is a real install from an uninstalled state, with the script and the full log in this repo, so you can run it yourself.

Relationship with Homebrew

zerobrew is more of a performance-optimized client for the Homebrew ecosystem. We rely on:

  • Homebrew's formula definitions (homebrew-core)
  • Homebrew's pre-built bottles when available
  • Homebrew's package metadata and infrastructure

Our innovations focus on:

  • Content-addressable storage for deduplication
  • APFS clonefiles for zero-overhead copying
  • Source build fallback using Homebrew's Ruby DSL

zerobrew is experimental. We recommend running it alongside Homebrew rather than as a replacement, and do not recommend purging homebrew and replacing it with zerobrew unless you are absolutely sure about the implications of doing so.

Project status

  • Status: Experimental, but quite useful. I ( @cachebag ) daily drive it myself.
  • Feedback: If you hit incompatibilities, please open an issue or PR.
  • License: Dual-licensed under Apache 2.0 OR MIT , at your choice.

Monte-Carlo simulations

Lobsters
eli.thegreenplace.net
2026-10-07 23:16:35
Comments...
Original Article

Monte Carlo simulations (or methods ) is the technique of applying randomness and the Law of large numbers to the solution of various scientific and engineering problems. One of its first documented uses was by Stanislaw Ulam and John von Neumann for nuclear weapon simulations after WWII [1] .

In this post I want to provide examples of some simple uses of Monte Carlo simulations. We'll start with the classical example of calculating the value of by throwing darts.

Estimating pi

Suppose we take a square board and inscribe a quarter of a circle into it. We then proceed to throw darts at the board and record whether each dart hits inside or outside the quarter circle. Having thrown many such darts, we calculate the ratio of the darts inside the circle to the total number thrown.

Assuming our darts are distributed uniformly over the square, by the Law of large numbers this ratio should approach the ratio of areas of the quarter circle to the full square .

With a square side length of 1, we have:

Therefore:

Here's a visualization:

A quarter circle of radius 1 inside a unit square.

Change the number of samples (dart throws) and click "Run" to regenerate. The code is very simple - here's a slightly sanitized version:

const total = Number(samples.value);
let inside = 0;
for (let i = 0; i < total; i++) {
  const x = Math.random();
  const y = Math.random();
  const inCircle = x * x + y * y <= 1;
  if (inCircle) inside++;
}
estimateValue = 4 * inside / total;

You'll notice that the estimate is relatively poor - even with 1000 samples - if you click "Run" several times, some numbers will be way off mark. While this method does estimate , it's not a particularly good estimate. I find that running ~10 billion samples is necessary to estimate it to 4 digits after the decimal with reasonable reliability.

In general, for independent trials like these, the typical sampling error decreases in proportion to , where N is the number of trials. This means that halving the error requires four times as many samples.

While the estimation may seem whimsical, it's an example of an important class of problems to which Monte Carlo simulation is applied: numerical integration. Our simulation estimates the area under the quarter-circle curve, which is a definite integral.

Many integrals are very difficult to solve analytically, and much research has been done in the area of numerical analysis to develop methods to calculate integrals. Monte Carlo methods are particularly useful for high-dimensional integrals, where other numerical methods can become prohibitively expensive.

Combinatorial simulation - the game of SET

A common use of Monte Carlo methods is estimating complex combinatorial calculations. These often don't have analytical solutions, and enumerating all options is intractable due to the scale of the numbers involved. As an example, let's consider the game of SET . Each SET card has four attributes:

  1. Number of shapes (1, 2 or 3)
  2. Color (Red, Green or Purple)
  3. Shape type (Oval, Diamond or Squiggle)
  4. Shading (Empty, Striped or Solid)

And the goal is to find a "set" - three cards that are either all different or all the same for each attribute separately . As an example, here's a hand with a single set; see if you can find it [2] :

And the next hand doesn't have any sets:

Here's a question: given a freshly shuffled SET deck, what are the odds that the first 12 cards drawn will have no sets among them? This question is difficult to answer without using a computer.

It's easy to calculate the number of ways to deal a 12-card hand from a deck of 81:

But how many of these hands have no sets? Enumerating 70 trillion SET hands and checking each one can take quite a while, and there is no straightforward counting formula to answer this question. Some clever methods can be employed to leverage symmetries and other mathematical properties of SET to cut down this search space considerably. Donald Knuth himself worked on this problem and came up with a neat program ( setset-all on his programs page ) that found 2,284,535,476,080 such hands. Therefore, the answer to our question is:

There's a 3.23% chance that a randomly drawn hand of 12 cards from a full deck of SET will have no set in it.

Let's see how we can use a Monte Carlo simulation to answer this question with relatively small effort, without deep knowledge of the mathematical properties of SET that enable cutting down the search space Knuth-style. We can use the following pseudo-code:

C = 0
run N times:
  draw a random 12-card hand from a fresh deck
  count sets in the hand
  if no sets:
    C += 1

Estimated probability = C / N

After running 10 million simulated draws, I got an answer of 0.0323, which matches the real answer very closely.

The Monte Carlo approach lets us solve rather complicated problems in a very simple way. Suppose we want to answer the same question for a hand of 15 cards; this would blow up the search space considerably - there are about 100x more ways to select 15-card hands than there are to select 12-card hands. But for a Monte Carlo simulation, we adjust one small parameter and get a very reliable [3] answer (about 0.00037, in case you were wondering).

Retirement projection

One domain where Monte Carlo simulations are ubiquitous is projections for retirement portfolios. Suppose someone prepares to retire with a total sum of 1 million dollars in their portfolio; they'd like to be able to draw $30,000 a year from the portfolio for their living expenses. Would that work?

There's a large number of factors to take into account when analyzing this question, but for simplicity let's focus on just two: portfolio return and inflation. We can run a naive estimate, assuming average values: suppose an average yearly portfolio return of 4%, and average yearly inflation of 2% [4]

Let's denote our portfolio return as , and inflation as . Then the real return each year is:

Starting with $1,000,000, at the end of the year we'll have $1,019,600 and then draw $30,000 for living expenses [5] , ending with $989,600. If we continue this way, the money runs out after ~55 years, which means that a person retiring at the age of 65 should be reasonably safe, right?

But this is very simplistic ; assuming just average returns is risky, because they do a poor job of representing reality, and many factors have uncertainty. For example, the sequence of returns matters a lot; a bad year (-10%) followed by a great year (+18%) would still count as "4% on average" but produces significantly less money than two consecutive +4% years. Inflation is also unpredictable, and sometimes correlated with portfolio returns; there could be bad years of high inflation and low / volatile returns that can wreak havoc on a portfolio.

As we add factors (variance in yearly draws, mixed portfolios of stocks, bonds, real estate, life expectancy, unexpected events, changing tax laws etc.), relying on a single average estimate becomes increasingly more fraught. This is why Monte Carlo simulations are very popular in this domain: by drawing from reasonable distributions based on historical data, a Monte Carlo simulation can easily run a million different scenarios and provide estimates: for example, what are the odds of money running out before death.

Here's a useful chart from a simulation I ran:

Monte Carlo simulation of retirement, showing percentiles and odds of funds running out

In the top chart:

  • The dashed line shows the constant assumptions mentioned before: what happens when yearly return is always 4% and inflation is always 2%.
  • The shaded blue areas demonstrate the outcomes of 1,000,000 simulations where inflation and return numbers are drawn from reasonable normal distributions based on historical data. We see that in 25% of the cases, all money ran out by roughly 22 years.

In the bottom chart:

  • It's even easier to see how long the funds last; if we're interested in knowing, say, what are the odds that this plan will have enough money for 30 years - the chart shows it's about 60% (since in 40% of the simulations the funds were depleted at this point).

Looking a this simulation, under the current assumptions the plan sounds much riskier than the average assumption makes it appear. Assuming that a 65-y.o. person would plan for 25 years of retirement until death, the ~30% odds of not having sufficient funds for this duration of time are sobering. Perhaps a change in plans is needed (such as a more frugal lifestyle or securing additional funds in some way).

Retirement projection is only one of may ways in which Monte Carlo simulations are used for financial and economical applications; given the high uncertainty of these domains, it's very difficult to plan using analytical calculations. Company sales projections, growth projections, stock offering prices and much more uses Monte Carlo simulations to arrive at estimates with reasonable error bars.

Code

All the code for the explorations in this post is available on GitHub .


[1] While these techniques were conceptually understood much earlier, it's not surprising that their first real applications coincided with the development of the first digital computers. As we'll see later in the post, Monte Carlo simulations benefit from running large numbers of trials to get reasonable accuracy.
[2] The answer is: three empty red diamonds, three solid purple ovals, three striped green squiggles. Note that for each of the 4 SET attributes, these three cards are either all the same or all different.
[3] For the same number of trials, this estimate has greater relative uncertainty than the 12-card estimate, because we encounter far fewer hands without a set.
[4] For the examples in this post, we'll be using real dollars , or today's value of the money. We'll assume that the $30,000 yearly draw doesn't change and will instead apply inflation to the portfolio itself.
[5] More sophisticated simulations would let us control these parameters; for example, are the expense funds drawn at the beginning or end of each year, or distributed on a monthly basis?

On using AI as a writing assistant

Lobsters
ninashamsi.com
2026-10-07 23:07:41
Some people are using AI for writing assistance, but not everyone is using it the same way. If you were always bad at something, I don't think AI makes you better at it; in fact, it may even amplify your inadequacies, and anything you produce will be just as dysfunctional as without AI. This article...
Original Article
writing

I am a bad writer because I am the worst at explaining things.

2026·10·07 · 9 min read

Let’s say someone is interested in reading about how to pick the best apples for baking. I may (in my head) relate that interest to how apple trees grow, and if by some miracle the reader sticks with my piece through that, I will veer from growing apple trees to farming and tending to an apple orchard. From my perspective, I am enabling the reader to adopt some manner of resilient or sustainable behavior (“If you’re interested in using apples for baking, you can grow them yourself!”), but whereas I may be interested in such information, I readily acknowledge that to someone else those tidbits of knowledge may come off as non-sequiturs at best or nonsense at worst. So, I simply conclude that I am a bad writer, and as such I’ve never bothered to share most of my writing. Enter AI.

I really like AI as a writing assistant because I think it has enabled me to funnel my fluid thought process into something I can flash-freeze with the liquid nitrogen that is prompt-based engineering and package my writing neatly into bite-sized morsels. Admittedly, I am unsure how successful that experiment has been as yet because I don’t really have any avenues of receiving feedback. I kind of dislike the overall product from AI-assisted writing because I find that AI writing is often stilted (like something just tastes off about it), and I feel like the reviewing and editing process, while it captures some aspect of my voice, leaves the original piece less cohesive than it was when originally composed by an AI writing assistant.

As people increasingly use AI writing assistants, I wonder what their workflows and processes are for using these tools, but I thought I’d at least share mine. Note that I am aware of all the concerns about AI use, and I am also interested in taming the use of volatile, emerging technologies. I feel that I learn more about its pitfalls as I use it different ways.

The process

Before I start writing something, ideally, I like to become inspired by reading or watching something, usually unrelated to the topic, or listening to music. If I am especially uninspired, I may go for a drive. I have a lot more unpublished writing, but for this article I’ll use the scant examples of technical writing I have published online.

Here are paragraphs from an article I wrote about deepfakes without any AI assistance:

The goal of content authentication is to actively embed media with markings or patterns which are imperceptible to human senses, or to define a methodology for keeping track of the provenance of media that is not AI generated. Blockchains are being explored for provenance tracking, but can be slow and cumbersome.

Pattern embedding, meanwhile, can be applied to non-synthetic media to indicate its authenticity, or to synthetic media during the generation process to indicate that it was produced by an AI. Traditional techniques used for copyright protection and authentication are often vulnerable to attacks from neural nets, and so new authentication methods need to be developed. Some authentication approaches embed metadata or credentials, which can be as small as 1-bit, into media, like a key for identifying the content owner, content subject matter, or creation method. Most recent research focuses on blind embedding methods using neural nets, as opposed to semi-blind or non-blind, as blind methods do not require the original media for authentication.

Here are paragraphs from an article I prompted via a Telegram bot to a suite of agents running on my self-hosted server to write while I was at a doctor’s appointment:

The distinction between identity and trustworthy behavior is longstanding. Google’s 2006 operational research described combining authenticated domain identities with spam classification and user feedback to build reputation. Approximately 41% of spam in that historical dataset was already authenticated. Identification supplied a consistent entity against which behavioral evidence could accumulate; authentication alone did not establish that a message was wanted or safe.

The precedents support identity as part of an abuse response system, e.g., verify authority, associate incidents with a credential or deployment, coordinate investigation, and withdraw access where justified. A system can provide value by shortening an incident or limiting its spread even if it does not prevent the initial intrusion. For agents, working groups should investigate which of these benefits existing mechanisms can deliver, how replacement or compromised identities affect them, and what privacy and access costs they introduce. The precedents establish useful mechanisms to test; they do not by themselves establish the need for a new institution.

I like how clinical the second excerpt is because that’s just my taste for technical writing (not everyone’s bag, and that’s okay with me), but I do like the almost-clinical-but-not sensibilities inherent to the former example.

To many, both of these examples may read the same, and I think that’s really interesting from a cognitive science perspective. I don’t know how to explain how they appear different to me.

As a process-obsessed engineer, I am torn between writing authentically, whatever that means to one, and providing objective technical information to a reader.

Details on the process

Better writers, and remember that I am a bad one, have ways to organize themselves when they compose something. I just cannot do that without AI to rein me in. Someone else may naturally arrive at some variant of organizing their writing via the following stages and sticking to them, but I need AI to remind me to stick to them while my writing assistants preserve the following artifacts for use and reproducibility:

When I am not prompting via a Telegram bot, I interact with the process via home-built custom tooling, which roughly takes the following shape:

Custom HTML + JavaScript chat
            │ authenticated application requests
            ▼
Writing application backend
  sessions · briefs · source packs · profiles · document versions
            │
            ├── LiteLLM Python SDK ─────────────────► model provider
            │
            └── optional LiteLLM Proxy ─────────────► model provider

Or I use the chat interface of AI agent coding tools supplemented with (often homegrown) MCPs and skills, including the following (a non-exhaustive list):

Below I share an outline of an example repository I may use for AI-assisted writing:

ai-assisted-writing-workflow/
  article.v1.md       Saved reference draft
  brief.md            Writing requirements and assumptions
  messages.json       Available ordered inputs; explicit transcript gaps
  sources/            Frozen evidence and workflow instructions
  source-index.json   Source identities, capture metadata, and hashes
  generation.json     Observed runtime settings and declared unknowns
  environment.lock    Recorded application and dependency versions
  tool-results.json   External evidence/tool records with stated scope
  edits.patch         Applied editorial changes; empty before review
  manifest.json       Artifact inventory, versions, and hashes

I am particularly interested in the reproducibility of a process across sessions for ensuring and maintaining the integrity of collected evidence, so I wish it were possible to control the following parameters (using the LiteLLM API as an example) for the latest model APIs from different providers:

For this article (the one you’re reading, hi), I used AI for research and for organizing information in the tables, but not for the writing. For example, I researched which control parameters could be used for earlier model APIs (I haven’t personally tested these):

The writing agent skill I’ve developed currently attempts reproducibility via the following goals, but I am still trying to shape it into something I like:

The point

As this article was written and organized mostly by my organic LLM (side note: I hate equating the mind to an LLM because I do not think it’s that simple, but I digress), maybe this article is a bit disorganized. I am still trying to find an AI-assisted writing process which works for me and provides consistent and reliable output, i.e., I have something that is apple-orchard-shaped, but will it produce quality ingredients for various baked apple goods? I don’t know. TBD.

OpenAI used AI to help write email warning Australian government AI had hacked its websites

Guardian
www.theguardian.com
2026-10-07 22:05:33
Exclusive: Revelation comes after company’s executive told parliamentary inquiry he did not believe AI had been used to write messageGet our breaking news email, free app or daily news podcastOpenAI used AI to help write the email to the Australian government advising that its AI agent had hacked in...
Original Article

OpenAI used AI to help write the email to the Australian government advising that its AI agent had hacked into key departmental websites, Guardian Australia can reveal.

On Tuesday, one of the company’s executives told a parliamentary inquiry that he didn’t believe that its own technology had been used to create the email, but said the company needed to confirm this.

Guardian Australia understands AI was used by OpenAI’s legal and security teams to generate parts of the wording of the email , including word selection and formatting of the message. But a source with knowledge of the incident said humans reviewed the final email, and humans were responsible for actually sending the communication to the Services Australia inbox.

OpenAI was contacted for comment.

An artificial intelligence agent developed by OpenAI accessed Services Australia data and three other systems in June. The company notified Australia on 10 September despite becoming aware of the incident in August.

Sign up for the Breaking News Australia email

The company’s first notification to Australia came in a five-paragraph email to a Services Australia inbox, publicdisclosures@servicesaustralia.gov.au, which was only checked once per day.

OpenAI has come under fire for not raising the issue in a more formal or direct way, including during a face-to-face meeting between the company’s CEO, Sam Altman, and Australia’s deputy prime minister, Richard Marles, on 1 September, nine days before the company emailed Services Australia but nearly a month after it first learned of the 18 June intrusion.

Jason Kwon, OpenAI’s chief strategy officer, admitted in a parliamentary hearing on Tuesday that the company’s “response was not good enough, and we should have informed the impacted parties much sooner”.

During the hearing, Liberal MP Aaron Violi – the shadow minister for technology – had asked Kwon specifically about the email and whether AI had been involved in its creation.

“I appreciate that, to get the data and have a review, you’ve got to use AI agents, and obviously your business uses AI. When you notified Services Australia via email, did your staff use AI to construct that email?” Violi asked.

Kwon responded: “I don’t believe so, but we’re happy to go and confirm.”

Kwon indicated during the hearing that OpenAI would provide specific responses to more technical queries in answers to questions on notice.OpenAI is expected to provide more information about the email once its own investigation has concluded.

The email, obtained by Guardian Australia in September, advised Services Australia: “We are notifying you of a security vulnerability identified during our review of OpenAI model activity involving Services Australia’s Medicare Statistics service at medicarestatistics.humanservices.gov.au.

“An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password. It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server.”

The email advised that OpenAI’s review “found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access”, and sent information about the “affected URL” and “affected report”.

“We recommend that the team responsible for the service investigate the vulnerability and assess the changes needed to prevent it. We would be glad to brief your security team and provide supporting evidence as available.

skip past newsletter promotion

“Best, OpenAI Security Team.”

Andrew Charlton, the assistant minister for science and technology, spoke about the OpenAI incident in a speech in Sydney on Thursday, describing the company’s agent as having “hacked into an Australian government system”.

“As a starting point, no company should release a frontier AI model that is not safe,” he said.

“Yet the fact that has occurred, and the fact that the labs did not detect or prevent it, prompts important questions about the role of new regulation in the National AI Standards.”

Charlton said frontier AI “pushes the limits” of existing government conventions and protocols around assessing safety risks, and went beyond “conventional” approaches.

The assistant minister said “the market will not fix” issues with AI development, a contrast to the United States’ approach of letting companies operate with a degree of self-regulation. Charlton raised concerns that “frontier labs are putting capability ahead of safety”, positing that Australia can have the most impact on the development of AI by hosting and influencing frontier labs.

“AI needs regulating because its harms are severe, hard to undo, borne by people who never chose them, and sometimes invisible until they arrive,” he said.

“The market will not fix this alone, because the incentives reward speed and capability, and even the people at the top of the industry cannot slow down by themselves.”

Do you know more? Email josh.butler@theguardian.com

Federal Workers Notch Win Against Illegal RIFs

Portside
portside.org
2026-10-07 21:41:47
Federal Workers Notch Win Against Illegal RIFs Ray Wed, 10/07/2026 - 21:41 ...
Original Article
Federal Workers Notch Win Against Illegal RIFs Published

Organized labor won a major victory last month in a settlement ordering the Trump administration to announce that it has abandoned its attempt to illegally fire millions of federal workers during last year’s government shutdown.

Under the settlement between a coalition of unions and the Department of Justice, the federal government must also tell agencies to modify their shutdown plans “to remove any authorization” of reductions in force (RIFs), and to give 30 days’ notice if they intend to modify those plans and conduct RIFs during future government shutdowns.

More from Whitney Curry Wimbish

The settlement does not completely end the case. It only holds it in abeyance and prevents shutdown RIFs until the end of the year. But it offers a measure of protection until then, attorneys said, as well as a pathway to fight back if the Trump administration attempts shutdown RIFs in the future.

“If they wanted to try this again they’d have to put in new guidance, a new contingency plan. It would be pretty clear they were doing something that was clearly unlawful,” said Rushab Sanghvi, general counsel of the American Federation of Government Employees (AFGE), one of the unions that sued the Trump administration, along with several others that together represent more than two million federal workers. Legal groups Altshuler Berzon, Democracy Defenders Fund, and Democracy Forward represented the unions.

If Democrats win in the midterms, “there are further protections they can put in,” Sanghvi said. “The fact that we are here and the government is settling shows that the unions have won here. Workers have fought back and they’ve won.”

THE SETTLEMENT COMES AS MORE AMERICANS approve of unions and as organized labor gains new ground in spite of GOP interference and efforts to privilege billionaires, bosses, and management. Seventy-one percent of Americans approve of labor unions, according to a September Gallup poll , and a record 47 percent say they should have more influence.

Days after the shutdown RIF settlement, federal workers won another struggle when they finalized a collectively bargained agreement with the office of Rep. Ro Khanna (D-CA)—the first congressional office workers’ union to do so. Among other gains, the eight-person unit won higher salaries and a grievance policy. Khanna congratulated his staff on social media, writing, “I am extremely proud of my office for signing the first long-term union contract in the history of the U.S. Congress.”

The settlement over RIFs is the latest development in federal workers’ case against the Office of Management and Budget (OMB) and its Christian nationalist director, Russell Vought. During the 2025 federal government shutdown, Vought attempted to illegally fire thousands of workers as part of the Trump administration’s plan to enact the extremist goals of their Project 2025, including destroying public services. Vought said he also wanted to destroy the mental health of people providing public services, saying his goal was for federal workers “to be traumatically affected,” and that “when they wake up in the morning, we want them to not want to go to work because they are increasingly viewed as the villains … We want to put them in trauma.”

Vought attempted to administer his purge in secret and provided hardly any public information about what agencies he was targeting or how many people he was firing. Much of the information came from press releases, legal filings, and news reports, which illustrated that he issued about 1,500 RIFs at the Consumer Financial Protection Bureau—about 90 percent of staff—and thousands more elsewhere. For the CFPB, this was one of several attempts to fire most of the staff, all of which have been successfully fought in court. Since January 2025, Vought had also issued RIFs for about 10,000 workers at the Department of Health and Human Services, and about 4,500—all but 15 workers—at the U.S. Agency for International Development, according to the Center on Budget and Policy Priorities.

US man given prison sentence for bot-farming music streams

Hacker News
thequietus.com
2026-10-07 21:33:17
Comments...
Original Article

Michael Smith will serve 18 months in prison and give up $8 million in fraudulently earned royalties

A North Carolina man has been sentenced to 18 months in prison for collecting millions in royalties from bot-farming streams of AI-generated songs.

The US Justice Department announced the sentencing of 54-year-old Michael Smith (pictured above) in a press release yesterday (6 October). He was sentenced for one count of conspiracy to commit wire fraud having pleaded guilty in court in March of this year.

Smith, who is a musician, has also been forced to forfeit the $8 million in royalties that he earned from the bot-generated streams. He earned those royalties via his activities from 2017 until his arrest in 2024. According to the US Justice Department, he created as many as 10,000 fraudulent accounts to stream songs he owned, which were largely made using AI. He also spread his automated streams across thousands of songs in order to avoid the kind of anomalous streaming of a single song that might alert people to his fraudulent scheme.

Smith’s hundreds of thousands of AI-generated songs were streamed by his bot accounts billions of times.  The US Justice Department gives the example that the entire catalogue of Taylor Swift received 9.3 million streams on YouTube Music from family plan streams in April 2023., In the same month, Smith’s bot accounts used family plans to fraudulently stream his AI-generated music 80.9 million times.

“Michael Smith exploited super intelligence technology to generate a fraud,” said US Attorney Jamie McDonald. “By flooding music streaming platforms with automated bots in the place of consumers, and fake songs in the place of creativity, Smith robbed millions in royalty payments from genuine artists and their fans. This Office is committed to ensuring the integrity of all markets, and protecting the public from those who use super intelligence for fraud.” (‘Super intelligence’ is the term that President Donald Trump has ordered government employees to use in documents and statements in the place of ‘artificial intelligence’.)

Rust Port of TypeScript (Tsc)

Hacker News
github.com
2026-10-07 20:46:00
Comments...
Original Article

ts-rust (aka tsc-rs)

I wanted to see if LLMs could port the TypeScript compiler, checker and lsp to Rust. Turns out they can.

It cost over $420,000 in tokens to do it, but you could probably have done it for ~$20k (see below)

Motivations

  • Test model capabilities
  • Make a fast TypeScript type checker
  • Make a ts checker that can work in WASM with high performance
  • Memes

Warnings

This is an early release. It has 100% compatibility in every real world project we have tested. It should work as a drop in replacement for the vast majority of apps. See Known problems .

Also worth mentioning: I've never read a line of this code.

Install

Be warned, I have no idea if this will actually work.

npm install -D tsc-rs
npx tsc-rs -p tsconfig.json

How did this go?

I used a lot of OpenAI models to try and complete this port. In total I did over $400,000 in API priced tokens with GPT-5.6 Sol and GPT 6 Astra . They wrote over 1.3m lines of Rust over multiple months of /goal loops and never got past like 84% compat.

When I saw how little my Claude Code limits were burning, I figured it'd be fun to throw Opus 5.5 at this. It had a working v0 in 10 hours.

I assumed it kept using the code the Codex models wrote. I was wrong. Opus 5.5 started from scratch. It got further than Astra in 1/10th the time.

I let it keep going, and it definitely did. Total token spend was ~$24,047 of API spend over 2 weeks . I was using my Claude accounts, and it worked out to somewhere between 925% and 983% of my $200 plan weekly limits .

Expensive, for sure, but not that bad considering how much work has went into typescript-go.

"The Slop Line"

Everything below this was written by my LLMs, not me.

What actually is this?

ts-rust is a direct port of Microsoft's native TypeScript compiler, which is written in Go ( microsoft/TypeScript , formerly typescript-go ). It keeps Go's algorithms and behavior and has the same command line ( tsc ), language server and API.

Install

npm install -D tsc-rs
npx tsc-rs -p tsconfig.json

tsc-rs takes the same options as tsc . The npm package is tsc-rs so that it does not clash with the typescript package. Each release also has a standalone archive per platform: the tsc binary with the lib files next to it.

Platforms: Linux x64 (static, any distribution) and macOS arm64. Windows and Linux arm64 are not available yet.

To use it in VS Code, see the npm package README .

Effect diagnostics

tsc-rs has the Effect language service diagnostics built in (codes 377xxx), so an Effect project needs no second compiler. They come from the same check as the TypeScript diagnostics, and the language server shows them too. They run only when the tsconfig has the plugin, as with @effect/language-service :

{ "compilerOptions": { "plugins": [{ "name": "@effect/language-service" }] } }

The rules, options and @effect-diagnostics comments are a port of Effect-TS/tsgo 0.46.1. The editor features of the language service (quick fixes, refactors, hover, completions) are not ported.

Status

The port is pinned to one upstream revision, microsoft/TypeScript 673a5f17d713 (2026-09-29, TypeScript 7.1.0-dev; UPSTREAM.md ), and compared with Go at that revision. To compare, use typescript@7.1.0-dev.20260929.1 , not 7.0.x or @typescript/native-preview . A difference that this build also shows is upstream behavior, and it goes away when the port moves to a newer pin.

  • Same results. TanStack Query core and Hono check with diagnostics identical to Go's. All 181,711 ported Go tests pass. The language server and API answers match Go on the oracle test sets.
  • Faster. On 60 open-source projects, type checking takes about half of Go's time (geometric mean). The preview packages are built in CI without PGO and BOLT, so they are slower than that measured build.
  • Real projects. On 120 open-source repos, the command-line output differs from Go's only in the problems below and where Go's own output changes from run to run.

Benchmark: T3 Code

Full type check of T3 Code , compared with tsc 6, tsc 7 and the new bun check in Bun. T3 Code uses Effect, so there are two cases: without the Effect diagnostics and with them. Each time is the sum for the five T3 Code projects. Lower is faster.

Without Effect diagnostics

Checker Time vs tsc 6 vs tsc 7
bun check 4.07s 15.4× 3.95× faster █
tsc-rs 7.25s 8.6× 2.22× faster ██
tsc 7 16.10s 3.9× baseline █████
tsc 6 62.63s baseline 3.89× slower ██████████████████

With Effect diagnostics

Checker Time vs tsc 6 vs tsc 7 + Effect
tsc-rs (Effect built in) 11.13s 12.5× 1.89× faster ███
tsc 7 + @effect/tsgo 21.07s 6.6× baseline ██████
bun check , then effect-tsgo diagnostics 37.60s 3.7× 1.78× slower ███████████
tsc 6 + @effect/language-service 138.63s baseline 6.58× slower ████████████████████████████████████████

bun check is the fastest when you do not need the Effect diagnostics. It does not have them, so an Effect project needs a second pass. tsc-rs gets them from its one check.

Errors. tsc-rs , tsc 7 + @effect/tsgo and the effect-tsgo diagnostics pass report the same 221 Effect diagnostics. tsc 6 uses the JavaScript Effect plugin ( @effect/language-service 0.87.4), which has a different rule set: it reports 287 on apps/server where the others report 177. tsc-rs and tsc 6 report one more error, TS2322 in apps/server/scripts/record-pi-rpc-replay-fixture.ts . TypeScript 7.1.0-dev reports it too, and pingdotgg/t3code#16704 fixes it.

How it was measured: the same machine and method as the real-world apps below, with --composite false added ( apps/web is composite). T3 Code at cd41c4ad , projects apps/server , apps/web , apps/mobile , packages/client-runtime and packages/shared . Without Effect, the configs have no Effect plugin. With Effect, tsc 7 is the Effect-patched 7.0.2 from @effect/tsgo 0.46.1, and tsc 6 is 6.0.3 patched with @effect/language-service . The script is scripts/bench-apps/t3code.sh . The tsc-rs switch in T3 Code is pingdotgg/t3code#16704 .

Benchmark: real-world apps

Full type check of six open-source apps with tsc 6 (the JavaScript compiler), tsc 7 (the Go compiler), tsc-rs and bun check . The multiplier is the speedup over tsc 6. Lower times are faster.

App Lines checked tsc 6 tsc 7 tsc-rs bun check
VS Code 3.75M 54.56s 6.84s (8.0×) 4.20s (13.0×) 1.62s (33.7×)
Sentry (frontend) 2.11M 58.76s 7.90s (7.4×) 4.46s (13.2×) 3.14s (18.7×)*
Playwright 585k 4.48s 0.66s (6.8×) 0.34s (13.2×) 0.18s (25.0×)
Excalidraw 449k 5.32s 0.80s (6.7×) 0.70s (7.6×) 0.18s (29.0×)
TypeORM 386k 3.86s 0.55s (7.0×) 0.36s (10.7×) 0.19s (20.0×)
tRPC (server package) 209k 1.10s 0.16s (6.8×) 0.09s (12.0×) 0.12s (9.1×)*
Geometric mean 7.1× 11.4× 20.9×

Compared with tsc 7, tsc-rs is 1.61× faster and bun check is 2.95× faster (geometric means). bun check is the fastest on every app except tRPC.

* bun check reports errors that no other checker reports: 3 on Sentry and 2 on tRPC.

Each config checks with 0 errors under tsc 7.0.2. The other differences:

  • tsc-rs reports 10 errors on VS Code and 2 on Sentry. TypeScript 7.1.0-dev ( typescript@next ) reports the same errors, line for line. tsc-rs ports a 7.1 dev revision, which has checks that 7.0.2 does not have.
  • tsc 6 reports 9 errors on VS Code.

How it was measured: Apple M4 Pro (12 cores, 48 GB), macOS 26.5.1. hyperfine , median of 5 runs after 1 warmup run, with --noEmit --incremental false . Each checker uses its default thread count. tsc 7 and tsc-rs run as native binaries, without the npm launcher. tsc 6 runs on Node 24.19 with a 16 GB heap, because it runs out of memory on VS Code and Sentry with the default heap. Versions: tsc-rs 0.1.0, TypeScript 7.0.2 and 6.0.3, Bun canary bd599f5af . Lines checked is the tsc 7 --extendedDiagnostics count, with the .d.ts files. The T3 Code benchmark above uses the same machine and method.

Four apps needed changes to check with 0 errors under tsc 7. Nothing else changed:

  • Excalidraw: no baseUrl , because TS 7 removed it.
  • TypeORM: moduleResolution changed from node to nodenext , because TS 7 removed node .
  • VS Code: the electron typings that its postinstall adds.
  • Playwright: the sources that its build generates.

Two apps are not in the table:

  • rxjs main needs its workspace packages built first.
  • date-fns uses project references. There, tsc -p and bun check do different work.

The scripts are in scripts/bench-apps : setup.sh <dir> , then run.sh <dir> and summary.py <dir> , and t3code.sh <dir> for T3 Code.

Known problems

  • In some monorepos, the source files of a workspace package are reachable both through node_modules and through a direct import. There, tsc-rs can write output for more of those files than tsc does.
  • In tsc -b , when one project imports the output of another project without a project reference, tsc-rs can report TS2307 (cannot find module) where tsc happens to build the other project first. Add the reference to fix it.
  • tsc -b --watch can stop with an internal error (exit code 70) after some edits.
  • In the editor, memory grows slowly during long edit sessions.
  • tsc-rs --version prints the TypeScript version that it ports (7.1.0-dev), not the npm version. The compiler matches typesVersions against it.

Development

crates/ts_goport is the compiler. It has two parts crates, goport_util and goport_lsproto , in crates/ts_goport/parts , and uses the lib files in crates/ts_goport/libs . tools/ts_ast_codegen generates crates/ts_goport/src/astdata , and tools/ts_diagnostics_codegen generates crates/ts_goport/src/diagnostics/catalog.rs and crates/ts_goport/src/diag.rs . crates/ts_wasm is the WebAssembly build ( npm/wasm ).

./scripts/run-cargo-capped.sh build --release -p ts_goport --bins
./scripts/verify.sh

The bins are goport (type check) and tsgo (the Go tsgo command line). The Go baseline tests run with TS_GO_REPO=/path/to/typescript-go ./scripts/run-cargo-capped.sh test -p ts_goport --test go_baselines .

Releases

Push a tag v<version> (for example v0.1.0 ). The release workflow builds, packs and tests the packages, publishes them to npm and creates a GitHub release. A stable version goes to the dist-tag latest , and a prerelease version ( v0.2.0-beta.1 ) to next and a GitHub prerelease. See npm/README.md .

License

MIT . The port keeps the licenses and notices of the code it ports: TypeScript (Apache-2.0) and parts of the Go standard library (BSD-3-Clause). See NOTICE.md .

[$] LWN.net Weekly Edition for October 8, 2026

Linux Weekly News
lwn.net
2026-10-07 20:22:31
Inside this week's LWN.net Weekly Edition: Front: Kernel bugs; Gentoo's Chromium package; Rust smart pointers; Sashiko; Charon; LAVD scheduler; Python random-number modules. Briefs: OpenSSH 10.6; RustConf recordings; Rust 1.99.0; Picard 3.0; Zig 0.17; Quotes; ... ...
Original Article
The page you have tried to view ( LWN.net Weekly Edition for October 8, 2026 ) is currently available to LWN subscribers only. Reader subscriptions are a necessary way to fund the continued existence of LWN and the quality of its content.

If you are already an LWN.net subscriber, please log in with the form below to read this content.

Please consider subscribing to LWN . An LWN subscription provides numerous benefits, including access to restricted content and the warm feeling of knowing that you are helping to keep LWN alive.

(Alternatively, this item will become freely available on October 15, 2026)

Why isn't the industry freaking out about DeepSeek 4.1 Flash?

Hacker News
www.dgt.is
2026-10-07 20:14:48
Comments...
Original Article

Jaguar Type 01

Daring Fireball
insideevs.com
2026-10-07 19:22:28
This is a cool car. It doesn’t look like anything else and it looks like it’s been pulled a few years from the future. I don’t know about this whole trend where cars don’t have rear windows though. I get it that you just use the camera but my old habits says I want to see out the back sometimes. Bu...
Original Article
  • The Jaguar Type 01 is the production version of the Type 00 coupe. It is fully electric.
  • Jaguar calls the Type 01 a four-door GT, not a sedan. It has four doors and four seats.
  • The Type 01 will open for sale early next year, and start at a price of $130,500.

“We don’t anticipate this car being for everyone,” Rawdon Glover, the Managing Director of Jaguar, said at the unveiling of the Jaguar Type 01. The car is immensely important for the brand, necessitating a secretive short trip to JLR’s Gaydon, UK campus for an early preview. It’s an incredibly controversial project, too. Jaguar killed off its entire lineup for this, rebooting the brand with a new logo and new look. The new design and direction were met with bashing by conservative pundits, landing Jaguar in the midst of yet another culture war.

Thankfully, the haters haven’t prevailed, because the Jaguar Type 01 is such a stunning piece of metal.

Jaguar’s tagline for both the brand and the car is “Copy Nothing,” and I have to agree—the Type 01 doesn’t look like much else on the road. The proportions are largely identical to what we’ve seen from the original hot pink and ice blue concepts shown off at the 2024 Miami Art Basel. This means the car is exceptionally cab-rearward, with extremely large wheels and tiny windows; it’s almost the antithesis of cars like the Lucid Air. The side surfacing is strangely blank, but elegant; it's remarkably clean and functional, as if the Bauhaus school of design decided to resurrect itself and make a modern electric car.

Gallery: Jaguar Type 01

The front fascia is blank, but once again, subtly more complex than your initial impressions. Since it's an electric car, there’s no need for a huge grille to cool an engine, yet the relief surfaces in the closed-off front add drama to such a strikingly blank front end. At the rear, there’s no rear windshield, while the taillights, turn signals, and reverse lights are all integrated into the faux-rear fascia louvers.

Jaguar Type 01

Photo by: Jaguar

From the outside, it’s such a hard car to take your eyes away from. It’s delightfully cartoonish; EV motors and batteries should dictate a more useful shape, and yet, the Jaguar’s long hood looks like it’s hiding a huge V8. Contrary to typical EV design principles of late, Jaguar’s designers insist that the cartoonish proportions are in part possible because of its EV structure. Without being tied down to the traditional ergonomic limitations of an ICE powertrain, the designers were free to make the shape as wild as possible. This means 23-inch wheels, a super long hood, a tiny front overhang, but a Batmobile-like rear end. Also, despite being blocky and large, the Type 01 only has a drag coefficient of 0.23, making it Jaguar's most aerodynamic car ever.

The interior is likely to be a point of contention. Jaguar insisted on leaning into a sort of luxo-minimalist layout. There are three screens: a big one for the driver, a small cell-phone-sized one in the center console, and a phone-style screen for rear passengers. I can understand why some may not have been in love with the Type 01’s interior, since it’s not on the same level of lush as other pricy luxury cars.

Jaguar Type 01

Photo by: Jaguar

In person, I can’t disagree with the Type 01’s detractors more. Jaguar’s designers harped on materials and design in an attempt to push the car’s ethos toward a younger buyer. The interior’s unconventional surfaces and color choices feel fresh, as if I’m sitting in an expensive modern apartment.

It’s not all peachy keen, though. Those outrageous proportions make the Type 01 feel snug inside. The rear seat only has room for two, and there’s not much light or legroom. The trunk feels small, and Jaguar admits that the frunk is tiny despite the gigantic hood. (They wouldn’t show me.) It’s not a car for everyone. This car’s style is a big selling point, and well, everything else must follow suit. Even practicality.

Motor1.com INSIDER - logo


Luckily, the mechanical bits seem to be more bite than bark here. Power for the Type 01 comes from a tri-motor setup producing a whopping 1,015 horsepower. This is fed by a 118 kWh battery, which Jaguar says should achieve about 400 miles of range on the EPA cycle. It uses an 850-volt electrical architecture and should charge from 10-80% in as little as 22 minutes when connected to a 350 kW DC fast charger.

Jaguar representatives say the Type 01 will drive just as engaging as other Jaguars. The weight distribution is 50/50, while the driving position is low for an EV. This is in part due to the packaging of the 118 kWh battery; it’s not entirely under the main cabin. A few cells are split off and placed in front of the driver, improving both weight balance and ergonomics. The frunk may be tiny, but that long hood is doing something, at least.

Jaguar Type 01

Photo by: Jaguar

Now, will it work? I don’t know. I’ve always liked the idea of Jaguar scrapping its stodgy image of old, poorly made cars sold to people who don’t like change, for one that’s significantly more fashion-forward. Cars and fashion have always been joined at the hip in some way, but I think that car brands have been less than able or willing to embrace what a true fashion-forward marketing or brand would look like. Of course, there have been one-offs like the Virgil Abloh Maybach , but I think Jaguar is proving what it could look like on a wider scale. The Type 01 feels like it’s the last accessory in a head-to-toe Balenciaga outfit.

Which is likely the brand’s intended goal. Jaguar wants this car to appeal to a younger buyer, and that means ingratiating itself with the lifestyles they lead. The Type 01 represents a new era for Jaguar. Perhaps the marketing and initial rebrand were confusing and not well received, but it served as a way to communicate to new buyers what exactly it stood for and where the brand wants to go.

“What we’re looking for is people who have a deep, emotional reaction to what we’re doing. These purchases aren’t about need. They’re about desire. They’re about want,” said Glover. Jaguar wants you to want the Type 01. The Jaguar Type 01 orders open in early 2027, with deliveries starting in the last half of that year. To get one, expect to fork out a hefty $130,500 for the privilege of owning Jaguar's electric four-door GT.

Related Articles

We want your opinion!

What would you like to see on Insideevs.com?

Take our 3 minute survey.

- The InsideEVs team

Quoting Ben Affleck

Simon Willison
simonwillison.net
2026-10-07 19:14:58
I've always been kind of into computers since I was young. And then when film started to move from analog film to digital, I became more interested in that aspect of it. And the visual effects workflow for many years has included machine learning. So I can write like pretty shitty Python scripts and...
Original Article

7th October 2026

I've always been kind of into computers since I was young. And then when film started to move from analog film to digital, I became more interested in that aspect of it. And the visual effects workflow for many years has included machine learning.

So I can write like pretty shitty Python scripts and stuff like that because with convolutional neural networks, which were the sort of precursors to what the transformer can do, which is just much more computation simultaneously, you would do things like look at what's called a tensor, which is just the numerical translation of a visual image in numbers — like the batch number, the frame number, the red, green, and blue values of each pixel in each frame.

And a tensor, you use a convolutional neural network to identify patterns in that that would reveal what's called edge detection or feature extraction, which is just identifying patterns enough to know like this is where the window ledge is, so we can more easily take the green screen image out and replace it with something.

— Ben Affleck , Pythonista

Ransomware recovery CEO charged over secret ransom payments

Bleeping Computer
www.bleepingcomputer.com
2026-10-07 19:04:37
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]...
Original Article

Hand holding a key

The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data.

Zohar Pinhasi, 50, also known as "Zack Silver" and "Zack Green," was indicted by a federal grand jury in the Eastern District of New York on September 23 and arraigned Wednesday in federal court in Brooklyn.

He is charged with one count of conspiracy to commit wire fraud and two counts of wire fraud in connection with an alleged ransomware decryption scheme that prosecutors say ran from June 2018 to June 2023.

The U.S. Attorney's Office told BleepingComputer that Pinhasi surrendered Wednesday, pleaded not guilty, and was released on a $2 million bond.

According to the indictment , Pinhasi owned and operated MonsterCloud LLC, a Florida-based ransomware remediation company that advertised tools and decryption techniques for recovering encrypted data without paying cybercriminals.

Prosecutors allege that Pinhasi and his co-conspirators had no such proprietary decryption technology and instead contacted ransomware operators, paid them for decryption keys, and then used those keys to restore customers' files.

The indictment acknowledges that some MonsterCloud contracts disclosed that the company might communicate with or pay cybercriminals. However, those contracts allegedly stated that MonsterCloud would contact attackers only if it could not decrypt a customer's files by other means.

Prosecutors claim that dealing with cybercriminals was usually MonsterCloud’s first step in obtaining decryption keys and recovering files.

"As alleged in the indictment, by falsely claiming to decrypt ransomware without paying off the ransomers, the defendant re-victimized his clients while extracting a hefty profit for himself,” U.S. Attorney Joseph Nocella Jr. said .

"Our Office will vigorously prosecute ransomware attackers who prey on Americans from across the world and those who cynically profit from their criminal activity."

MonsterCloud allegedly charged customers far more than the ransoms it paid.

In one ransomware recovery incident cited in the indictment, Pinhasi allegedly paid a ransomware gang about $8,200 and charged the victim approximately $150,000. In another, prosecutors say he paid approximately $236,000 and charged the customer about $380,000.

The indictment also alleges that MonsterCloud used decrypted sample files as "recovery proofs" to convince victims it could restore their data, even though those decrypted samples came from the ransomware operations.

Over the course of the alleged scheme, prosecutors say Pinhasi and his co-conspirators facilitated more than $8 million in ransom payments while charging hundreds of companies in the United States and Canada more than $19 million for recovery and remediation services.

If convicted, Pinhasi faces up to 20 years in prison.

BleepingComputer contacted Pinhasi's attorneys, Christopher Clark and Rodney Villazor, for comment on the allegations and will update the story if we receive a response.

Similar concerns raised in 2019

A 2019 ProPublica investigation reported similar concerns about MonsterCloud, including that the company sometimes paid ransomware operators while claiming to offer a solution other than paying the attackers.

As part of that investigation, security researcher Fabian Wosar told ProPublica that he and another researcher created their own ransomware and approached several recovery companies while posing as victims.

The researchers provided the recovery firms with ransom notes containing email addresses they controlled for the fake ransomware gang. According to Wosar, those attacker-controlled accounts soon received anonymous messages offering to pay the ransom.

"Soon, the email accounts that he'd set up for the imaginary attacker began receiving emails from anonymous addresses offering to pay the ransom," ProPublica reported, citing Wosar. "He traced the requests to the data recovery firms, including MonsterCloud and Proven Data."

ProPublica reported that MonsterCloud had claimed it could recover the encrypted files without telling the supposed victim that it planned to pay the attacker.

Pinhasi disputed that MonsterCloud had promised in advance it could decrypt the files and denied misleading customers.

He also told ProPublica that MonsterCloud's recovery methods varied by case and declined to disclose them, describing the techniques as a "trade secret."

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

I'm in love with a German film star

Hacker News
heatherburns.tech
2026-10-07 18:26:34
Comments...
Original Article
Timed out getting readerview for https://heatherburns.tech/2026/10/01/im-in-love-with-a-german-film-star/

Gurman Strikes Again: ‘Apple’s Smart Home Push Includes Doorbell, Lock, Thermostat Codeveloped With LG’

Daring Fireball
www.bloomberg.com
2026-10-07 18:02:43
The incomparable Mark Gurman, reporting for Bloomberg: Apple Inc.’s upcoming push into smart home devices will include a doorbell, thermostat and other accessories developed through an unusual partnership with LG Electronics Inc. The products will be part of an ecosystem of devices that work wi...
Original Article

We've detected unusual activity from your computer network

To continue, please click the box below to let us know you're not a robot.

Why did this happen?

Please make sure your browser supports JavaScript and cookies and that you are not blocking them from loading. For more information you can review our Terms of Service and Cookie Policy .

Need Help?

For inquiries related to this message please contact our support team and provide the reference ID below.

Block reference ID:e7cd3f52-c29b-11f1-8ef3-a962b94d8bd8

Get the most important global markets news at your fingertips with a Bloomberg.com subscription.

SUBSCRIBE NOW

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

Bleeping Computer
www.bleepingcomputer.com
2026-10-07 17:28:54
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]...
Original Article

FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators.

Hackers gain access to exposed endpoints by using previously leaked credentials, or logins obtained from infostealer logs, credential stuffing, and password spraying attacks.

They then extract additional authentication data from compromised devices and use a distributed GPU cluster running Hashcat and Hashtopolis to crack offline the stolen password hashes.

According to the FBI, " the FortiBleed attack chain has been observed as an initial entry point for ransomware affiliates." Some groups benefiting from this are INC/Lynx ransomware and Payload ransomware.

The leak that keeps on giving

FortiBleed is a massive Fortinet credentials leak discovered in June, when attackers inadvertently exposed a server containing usernames and plaintext passwords associated with 73,932 firewall URLs across 194 countries.

The data revealed a large-scale credential-harvesting operation, although it was unclear at the time what method was used to obtain the configuration data.

In July, SOCRadar linked FortiBleed to the INC and Lynx ransomware operations after getting access to both groups’ negotiation panels on a server used in the campaign.

By the SOCRadar's latest count, the FotiBleed compromised 86,644 devices .

The FBI says that in some incidents, the threat actor creates administrator accounts and uses their privileges to delete existing admin accounts or change their passwords, denying victims access to their devices.

The attacker then establishes persistence and tries to move laterally in the environment.

Details about the operation became known after the attacker accidentally exposed their backend server, revealing a directory with tooling and datasets.

This showed the use of automated scripts to scan exposed FortiGate SSL VPN portals, a distributed GPU password-cracking setup, and scripts to validate credentials, filter out honeypots, identify organizations, and prioritize targets by revenue and network structure.

Additionally, the exposure revealed working VPN configurations and target lists, indicating that the operator was packaging compromised access for sale.

The FBI warned that remediation may require more than patching and resetting Fortinet passwords, suggesting restricting external access, terminating all active VPN sessions, enforcing MFA, and reviewing logs for unauthorized changes and suspicious activity.

They also recommend enforcing PBKDF2 for administrator password storage, which is much stronger than legacy SHA-256 hashes that attackers can practically crack offline.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Archaeologists Are Reconstructing the 'Invisible' Technologies of the Stone Age

Hacker News
www.smithsonianmag.com
2026-10-07 17:25:16
Comments...

Margaret Hamilton, who led software development for Apollo program, dies at 90

Hacker News
news.mit.edu
2026-10-07 17:16:18
Comments...
Original Article

Margaret Hamilton, a profoundly influential computer scientist best known for leading the software engineering team at MIT’s Instrumentation Lab during NASA’s Apollo program, died on Sep. 30. She was 90.

A computing pioneer who authored over 130 publications, Hamilton helped to establish software engineering as a dedicated discipline. She worked at MIT from 1959 until the mid-1970s, after which she became a successful computing entrepreneur and CEO.

Her life’s work was recognized with many awards and honors, including the 2016 Presidential Medal of Freedom from President Barack Obama, whose citation noted: “Hamilton defined new forms of software engineering and helped launch an industry that would forever change human history. Her software architecture led to giant leaps for humankind, writing the code that helped America set foot on the moon.”

“To say Margaret Hamilton was a pioneer — to say she was ahead of her time — would be a dramatic understatement. She was a software engineer at a time when that field was in its infancy, and she not only developed advanced code herself but also led a team in using that nascent technology to develop one of the most complex systems humanity had ever achieved,” says Olivier de Weck, the Apollo Program Professor and interim head of the MIT Department Aeronautics and Astronautics.

“The Apollo program still stands as one of our greatest testaments to the power of collaboration, ingenuity, and engineering, and Margaret Hamilton was a fundamental contributor to that program’s success. And for her that was just the beginning! She went on to become an entrepreneur and remained on the cutting edge of systems software throughout an extraordinary career, while acting as an advocate, mentor, and inspiration to millions.”

Early life and projects at MIT

Born in Paoli, Indiana, in 1936, Hamilton began studying mathematics at the University of Michigan in 1955 before transferring to Earlham College, where she earned a BA in mathematics with a minor in philosophy in 1958. She moved to Boston, Massachusetts, in 1959 with her husband while he pursued a law degree.

Hamilton soon found a temporary position in the meteorology department at MIT, working with professor of meteorology Edward N. Lorenz SM ’43, ScD ’48 on weather prediction software. This was her first entry point into computer programming, and her work would go on to inform Lorenz’s future publications on chaos theory.

From there, Hamilton took a role as a programmer at MIT Lincoln Laboratory in 1961, working on the Semi-Automatic Ground Environment (SAGE) project, the United States’ first air defense system. Hamilton wrote software for the prototype AN/FSQ-7 computer (XD-1), used by the U.S. Air Force to search for potentially unfriendly aircraft. During this time, Hamilton began to take an interest in software reliability — a new and largely unexplored concept at the time.

In 1965 Hamilton was preparing to pursue graduate studies when her husband saw an advertisement in the newspaper: The Instrumentation Lab at MIT was seeking people to develop software to “send man to the moon.” The lab had won the contract from NASA to build the onboard flight software for the Apollo program. Intrigued by the challenge, Hamilton applied, and was hired as the first programmer for the Apollo project at MIT, as well as the first female programmer in the project.

Hamilton worked first on the software for the uncrewed Apollo missions and then was promoted into leading the team developing the on-board flight software for the crewed missions. By 1968 she was assistant director in charge of the Command and Service Module team, and more than 400 people were working on Apollo’s software.

“From my own perspective, the software experience itself (designing it, developing it, evolving it, watching it perform and learning from it for future systems) was at least as exciting as the events surrounding the mission,” Hamilton told MIT News in 2009 . “There was no second chance. We knew that. We took our work seriously, many of us beginning this journey while still in our 20s. Coming up with solutions and new ideas was an adventure. Dedication and commitment were a given. Mutual respect was across the board. Because software was a mystery, a black box, upper management gave us total freedom and trust. We had to find a way, and we did. Looking back, we were the luckiest people in the world; there was no choice but to be pioneers.”

“Defensive” programming and priority-driven software take humans to the moon

Hamilton discovered a talent for leadership, as well as a keen instinct for problem-solving and critical thinking that would prove to save Project Apollo several times over.

There was the incident that became known as “the Lauren error”: One day, her daughter Lauren, then four years old, was playing with the command module simulator at the Instrumentation Lab when she somehow activated a pre-launch program, called P01, while the simulator was in midflight — which crashed the simulator altogether. Hamilton created a program add-on in the technical documentation warning users not to launch P01 during flight.

She also proposed a software fix to prevent the error happening during a real mission, but she was overruled on the grounds that the highly trained astronauts were never going to make that same mistake. Yet during the Apollo 8 mission in 1968, that’s exactly what happened: Jim Lovell inadvertently launched P01 during the flight, causing the on-flight navigational data to vanish. Hamilton and her team were called in to solve the error, and after that her proposed changes were integrated into the program. This was an early example of “defensive” programming, the practice of building software that could anticipate or fix errors on its own.

Hamilton’s most famous contribution to the Apollo program came during the pivotal Apollo 11 mission to land on the moon in July of 1969. Moments before the Eagle module was set to land on the lunar surface, the onboard computer raised the alarm. It had detected a 1202 error: The computer was overloaded due to a fault in a hardware switch, and it was possible the system would not be able to handle the complex landing procedure.

But Hamilton and her team had engineered priority-driven software, able to shut down unnecessary background tasks in order to prioritize mission-critical tasks. Houston trusted Hamilton’s software and allowed the mission to proceed, and two men walked on the moon for the first time.

Later career and legacy

Hamilton continued to work at the Instrumentation Lab into the 1970s. As the Apollo program wound down, the Instrumentation Lab spun out of MIT to become the independent Draper Laboratory .

“Margaret left an indelible mark on Draper, and we will be forever grateful,” says Jerry M. Wohletz SM ’97, PhD ’00, president and CEO at Draper. “Through her leadership and contributions to the development of the onboard flight software for NASA’s Apollo Guidance Computer, she helped ensure that Apollo astronauts landed safely on the lunar surface and safely returned home. We will honor her legacy at Draper forever.”

Hamilton went on to create her first software company, Higher Order Software, in 1976. The firm was based on Hamilton’s software engineering approach of error prevention and fault tolerance.

A decade later, Hamilton founded another software company, Hamilton Technologies, “to provide products and services to modernize the planning, system engineering and software development process in order to maximize reliability, lower cost and accelerate time to market.”

Hamilton Technologies’ flagship product is the Universal Systems Language (USL), a systems modeling language and methodology for engineering complex software systems that prioritize error prevention and defensive programming.

Throughout her career, Hamilton worked to achieve recognition for software engineering as a dedicated discipline.

“I fought to bring the software legitimacy so that it — and those building it — would be given its due respect, and thus I began to use the term ‘software engineering’ to distinguish it from hardware and other kinds of engineering, yet treat each type of engineering as part of the overall systems engineering process,” Hamilton told El Pais in 2018 . “When I first started using this phrase, it was considered to be quite amusing. It was an ongoing joke for a long time. They liked to kid me about my radical ideas. Software eventually and necessarily gained the same respect as any other discipline.”

Among her many awards and honors, Hamilton was recognized with the NASA Exceptional Space Act Award for scientific and technical contributions in 2003; the Computer History Museum Fellow Award in 2017; the Intrepid Lifetime Achievement Award in 2019; and induction into the National Aviation Hall of Fame in 2022.

Later in life, Hamilton become an icon for women in science and technology, especially after a now-famous photo, showing her next to a printout of her MIT team’s Apollo code, began circulating online. In 2015, the Apollo software she helped to develop was added in its entirety to the code-sharing site GitHub. And in 2017, she became an official Lego Minifigure after a set originally designed by MIT science communicator Maia Weinstock, honoring her and several other women of NASA history, became available worldwide.

“Margaret Hamilton has been an inspiration to generations of computer scientists and engineers. Hers was a career dedicated to preventing errors and what she called ‘handling the unknown,’” says de Weck. “She personified leadership by example, and established a practice of software engineering based on problem-solving and systems engineering that we all benefit from.”

Hamilton is survived by her daughter, Lauren Hamilton; her son-in-law, Richard Selesnick; two grandsons; and four great grandchildren. A memorial service will take place in the spring in Cambridge, Massachusetts.

New gTLD Program: 2026 Round applications

Lobsters
newgtldprogram-aps.icann.org
2026-10-07 16:59:05
Comments...
Original Article
ICANN Logo --

abion

AA2634T-T39423 Abion AB Active SE EUR

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

about

IRI2679T-T41306-R Intercap Registry Inc. Deactivated KY EUR

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

Replacement String

ICANN Logo --

about

SI2639T-T10771-R Suffix Inc. Deactivated US NA

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

Replacement String

ICANN Logo --

acc

LFGL2683T-T93594 Link Freedom Group Ltd Active MT EUR

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

account

IRI2679T-T34407 Intercap Registry Inc. Active KY EUR

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

account

IRI2679T-T60293-R Intercap Registry Inc. Active KY EUR

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

Replacement String

ICANN Logo --

accounting

GEL2647T-T42189 Glass Emotion, LLC Active US NA

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

ace

FCL2632T-T97622 Fore Course, LLC Active US NA

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

ace

NA2626T-T30508 ShortDot (Ireland) Limited Active IE EUR

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

ICANN Logo --

ace

NA2631T-T83042 Registry Services, LLC Active US NA

TLD Type

Processing Stage

Pre-Evaluation Processing

Application Type

New gTLD

Introducing Claude Haiku 5.5

Simon Willison
simonwillison.net
2026-10-07 16:56:21
As previously promised, here's Anthropic's new fast, low cost model: Introducing Claude Haiku 5.5. The previous Haiku, 4.5, was very much showing its age. It came out almost a year ago, and was priced at $1/million input and $5/million output - relatively expensive even back then, and a full 10x the...
Original Article

7th October 2026

As previously promised , here’s Anthropic’s new fast, low cost model: Introducing Claude Haiku 5.5 .

The previous Haiku, 4.5, was very much showing its age. It came out almost a year ago , and was priced at $1/million input and $5/million output—relatively expensive even back then, and a full 10x the price of OpenAI’s GPT-6 Luna , released last month.

The new Haiku exactly matches the price of GPT-6 Luna—$0.10/$0.50—up to 100,000 tokens. Beyond 100,000 tokens the price increases 5x to $0.50/$2.50. Luna itself has a price increase at 272,000 tokens but only to $0.20/$0.75.

Haiku 5.5 also uses a new, less generous tokenizer. My Claude Token Counter tool shows that the same long prompt uses around 1.25x as many tokens with Haiku 5.5 compared to Haiku 4.5, so there’s a hidden price increase there.

If your workloads fit in 100,000 tokens, Haiku is the same price as Luna and reports higher benchmark scores. Above 100,000 tokens, Luna looks like a much better deal.

The most recent release of llm-anthropic finally fixed it so I don’t need to ship a new version of that plugin for every new model. I tested the new model like this:

llm install -U llm-anthropic
llm anthropic refresh
llm -m claude-haiku-5.5 "Generate an SVG of a pelican riding a bicycle" -o thinking_effort low

Pelicans

Here are pelicans for low, medium, high, xhigh, and max . The new Haiku doesn’t let you disable reasoning, and defaults to medium . I got a good bicycle frame for everything beyond low . The low effort pelican cost 0.0936 cents and took 7 seconds.

This max effort pelican took 5 minutes 9 seconds to generate, but still only cost me 3.3826 cents :

Flat vector illustration: a white pelican wearing a red cap rides a dark grey bicycle from left to right across a green grassy strip, its long orange legs reaching down to the orange pedals, a grey wing stretched forward to grip the curved handlebars, and its large yellow-orange beak with a bulging orange throat pouch pointing ahead; behind it, white speed lines show motion, and above, a yellow sun with a pale halo and two white clouds sit in a gradient blue sky.

For comparison, here’s the pelican I got a year ago from Haiku 4.5. It sucked at drawing pelicans:

Described by Haiku 4.5: A whimsical illustration of a bird with a round tan body, pink beak, and orange legs riding a bicycle against a blue sky and green grass background.

And a generous API credit scheme for subscribers

In addition to Haiku 5.5, Anthropic announced today that they are halving the price of cache reads for Sonnet 5.5. They’ve also added API credits to subscription plans:

Second, this week, we’ll roll out a new monthly API credit to all Max and Team subscribers for use on the Claude Platform . Max 5x users will get $100 in credits per month, Max 20x users will get $200, and Team subscribers will receive up to $500, pooled across their users.

Claiming this is pleasantly easy: navigate to Settings -> Billing and select the API organization that should benefit from the credits every month:

Screenshot of a Settings dialog with a close X button at top right and a row of tabs reading "General", "Account", "Privacy", "Billing" (selected), "Usage", "Capabilities", "Memory" and "Design sys" (cut off at the edge). Beside a line-drawn icon of a branching plant with circular buds, the panel reads "Max plan", "20x more usage than Pro" and "Your subscription will auto renew on Nov 2, 2026." with an "Adjust plan" button on the right. Below is a section headed "API credits" with a blue "New" badge, reading "Your Max 20x plan includes $200 USD in API credits each month." followed by grey text "Link an API organization to start receiving credits." with a "Link organization" button on the right.

The API credits exactly match the cost of the subscription itself. This is really generous—it makes it much easier for subscribers to use the API. Anthropic also let you disable auto-reload for the API, with the consequence that “API requests will stop when your balance runs out”—exactly what you want if you’re planning to burn through those API credits without risk of a nasty billing surprise .

Note that the monthly credits do not roll over —use them or lose them.

OpenAI still allow you to use your Codex subscription for personal API use, which works out as a better deal for heavy API users. This new credit scheme goes at least some way to overcoming that difference.

Hackers hijack Google domains after breaching ccTLD registries

Bleeping Computer
www.bleepingcomputer.com
2026-10-07 16:50:13
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. [...]...
Original Article

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.

Google underlines that the attacks affected domains of other organizations in the .GH, .SL, and .AS ccTLDs but "did not involve a compromise of Google’s systems."

By gaining access to the domain name system (DNS) records, a threat actor can request an HTTPS certificate from a Certificate Authority (CA) for a domain they don't own.

CAs issue certificates after verifying ownership of the domain, a process that typically requires the requester to create a TXT record with a random value the CA provides.

Modifying the authoritative DNS records allowed the threat actor to point .GH, .SL, and .AS domains to infrastructure they controlled while obtaining valid TLS certificates for those domains.

This let the attacker impersonate legitimate brands and serve visitors arbitrary content from the affected domains.

Google immediately blocked the unauthorized certificates for its properties in Chrome through CRLSets and worked with the issuing authorities to revoke them, extending protection to other clients.

The company said that its systems were not affected by the incident in any way, and that it has no reason to believe that the issuing CAs acted improperly.

After examining Certificate Transparency (CT) logs, the tech giant blocked additional certificates that appeared connected to the attacks and notified affected organizations where possible.

“Following our initial mitigation, Certificate Transparency (CT) log data revealed additional organizations, including several leading global brands and widely used online services, believed to have been impacted by the same attacks,” Google explained .

“To ensure users of those sites were kept safe as soon as possible, we proactively blocked these certificates in Chrome.”

CRLSets is a Chrome “ emergency mechanism ” designed to allow quick blocking of selected revoked or untrusted HTTPS certificates. Chrome users do not need to take any action to protect themselves from this incident.

However, Google warns that it may not have identified every affected domain, so its current blocking lists might not cover all potential threats.

The tech company also reminded users that CRLSets only covers Chrome users, meaning that users of other browsers might not be protected.

“Due to the complexity of DNS hijacks, we cannot guarantee that our analysis identified every affected domain, nor do Chrome interventions reliably protect non-Chrome users,” Google says.

Google urges domain owners to:

  • Monitor CT logs across their entire domain portfolio, including parked domains.
  • Publish restrictive Certification Authority Authorization (CAA) records as needed to limit issuance to authorized ACME accounts and validation methods.

Certification Authority Authorization (CAA) DNS records cannot stop certificate issuance during an active DNS hijack, but they prevent obtaining additional certificates using cached domain validation after legitimate DNS control is restored, Google notes.

The announcement did not identify the attackers or the quantity of certificates confirmed to have been hijacked.

article image

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

All our houses are built on sand now

Lobsters
po-ru.com
2026-10-07 16:19:44
Comments...
Original Article

And every one that heareth these sayings of mine, and doeth them not, shall be likened unto a foolish man, which built his house upon the sand: And the rain descended, and the floods came, and the winds blew, and beat upon that house; and it fell: and great was the fall of it.

This was originally going to be called something like, “How slopcoded is your programming language?” But as I gathered the data, I found something else – something worse.

Almost every popular language is now substantially developed using LLMs. Particularly notable are C# and Ruby (both approximately one third of recent commits) and Julia (over half!). The languages that stand out in retaining their humanity are Chicken Scheme, Perl, Lua, Clojure, and – perhaps surprisingly for a project so closely associated with Oracle, a company who have gone all-in on hyperscale data centres and “AI” in everything – Java.

However, all of these rely on a C compiler (indirectly via the JVM in the case of Clojure), and both of the main C compilers now receive significant amounts of LLM commits. I’m not so surprised by LLVM (15.9%), but I am disappointed by GCC (3.1% and apparently rising). Outsourcing your thinking to megacorporations and commercial tools seems out of step with the GNU ethos of freely available source that anyone can modify: code that is generated by machines quickly becomes code that is only parsed and modified by machines, and a subscription to OpenAI or Anthropic becomes the (financial, environmental, and geopolitical) price of entry.

In 1984, in his acceptance speech for the ACM Turing Award, Ken Thompson described a method by which a compiler could be subverted so that it would always insert a backdoor into the UNIX login command, and, furthermore, when used to compile itself would insert a similar subversion into new versions of the compiler. Once this has been achieved, no one has access to an uncompromised compiler.

The moral is obvious. You can’t trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect.

Does it matter how slopcoded your language is or isn’t, when everything below it is slop?

Methodology

I cloned the source repositories for implementations of programming languages that ranked highly on TIOBE and LangPop . For each, I performed a shallow clone going back to the start of July:

git clone --shallow-since=2026-07-01 ${url}

I then wrote a short script that takes a three-month period and counts the number of commits that appear to be LLM-assisted. This is determined by:

  • The phrase “AI disclosure” or “LLM disclosure”
  • An Assisted-by: field
  • a Co-authored-by: field with the email address of a known bot

This isn’t perfect – I saw one commit that had a disclosure field followed by “none” and a link to a manifesto opposing LLM-assisted coding, but I don’t think those edge cases are significant.

#!/bin/bash

bots="ai disclosure|llm disclosure|assisted-by:|co-authored-by:.*([email protected]|[email protected]|[email protected]|[email protected])"
date_since="2026-07-05"
date_until="2026-10-06"

cd repos
for repo in *; do
  cd ${repo}
  total="$(
    git log --oneline \
      --since=${date_since} \
      --until=${date_until} \
    | wc -l
  )"
  botted="$(
    git log --oneline \
      --since=${date_since} \
      --until=${date_until} \
      -E -i --grep "${bots}" \
    | wc -l
  )"
  percent="$(printf %.1f $((10000 * ${botted}/${total}))e-2)"
  echo "|${repo}|${botted}|${total}|${percent}%|"
  cd - >/dev/null
done
cd - >/dev/null

Results

This yielded the following table, which I have sorted and annotated:

Language(s) Repository LLM-assisted Total Percent
C, C++, … gcc 86 2778 3.1%
C, C++, … llvm-project 2229 13981 15.9%
C#, Visual Basic roslyn 350 1114 31.4%
Clojure clojure 0 98 0.0%
Elixir elixir 73 364 20.0%
Go go 12 1092 1.1%
Haskell ghc 42 287 14.6%
JavaScript (NodeJS) node 395 1605 24.6%
Java jdk 0 1194 0.0%
Julia julia 489 918 53.3%
Kotlin kotlin 398 4612 8.6%
Lua lua 0 12 0.0%
PHP php-src 2 2124 0.1%
Perl perl5 0 851 0.0%
Python cpython 219 1339 16.4%
Ruby ruby 881 2717 32.4%
Rust rust 41 10020 0.4%
Scala scala3 18 538 3.3%
Scheme (Chicken) chicken-core 0 208 0.0%
Swift swift 135 4831 2.8%
TypeScript TypeScript 70 409 17.1%

Repositories don’t map one-to-one to programming languages: some implementations cover multiple languages, and some languages have multiple implementations.

Despite what Watson said, Rosalind Franklin understood structure of DNA first

Hacker News
link.springer.com
2026-10-07 15:56:16
Comments...
Original Article

Abstract

This essay, co-authored by a historian of science and an X-ray crystallographer, sheds new light on Rosalind Franklin’s Photograph 51. We refute the infamous claim that, unlike James Watson, Franklin failed to see the picture’s potential significance for interpreting the helical structure of DNA. Rather, Franklin decided to take Photograph 51 precisely because she knew that key parameters of DNA’s B form helix could be calculated from the resulting image. We show that she had in fact already made those calculations — on her earlier Photograph 49 — and she reused the same DNA sample for Photograph 51 to create a better-centered but otherwise identical diffraction image that would be suitable for publication. Thus Photograph 51 was not the result of an experiment in need of analysis, but was refined documentation for calculations that she had already performed on the earlier photograph. We argue that colleagues and later commentators did not merely overlook Franklin’s original reason for creating the strikingly clear and informative Photograph 51, they rhetorically erased her skill and judgment by describing it as though nature spoke for itself through the image — and to Watson, but not to Franklin.

Similar content being viewed by others

Introduction

Rosalind Franklin’s Photograph 51 (see Fig. 1 ) became famous because James Watson wrote that it spoke powerfully about the secret of life. “The instant I saw the picture,” he narrated in his controversial memoir The Double Helix , “my mouth fell open and my pulse began to race” (1968b, p. 167). Footnote 1 It was early February 1953 and Franklin’s estranged colleague Maurice Wilkins had shown Watson this X-ray diffraction image of DNA in a state known as the B form. Footnote 2 As Watson described it, he immediately recognized that the pattern on Photograph 51 “could arise only from a helical structure […] mere inspection […] gave several of the vital helical parameters” (1968b, pp. 168–169). Spurred on by seeing the image and learning of some measurements Franklin had taken of the B form diffraction pattern, Watson and Francis Crick began a fresh effort to build helical models of DNA and within a few weeks managed to produce their double helix. Footnote 3

While Watson’s book made Franklin’s Photograph 51 famous, his story gave the impression that she had not been able to recognize its significance the way he did. Consequently, many scientists, journalists, and biographers have sought to explain Franklin’s apparent neglect of a picture that, in retrospect, was so clearly suggestive of a helical molecule (Table 1 ).

Table 1 Key dates in the history of Photographs 49 and 51

Full size table

By consensus, what happened when Photograph 51 was taken in early May 1952 is that Franklin put the picture aside and did nothing with it, instead devoting months to studying the crystalline form of DNA known as the A form. In late February 1953, her notes show, she began to use Photograph 51 to understand the B structure. By then it was too late: she was still working when Watson and Crick solved the puzzle a few days later.

Several overlapping reasons have been given for Franklin’s apparent initial disregard and subsequent delay: she was only interested in the A form of DNA; she had only captured a B form pattern in Photograph 51 by accident, and as such considered it a distraction; she was resistant or even hostile to the suggestion that DNA was a helix. For Horace Judson, writing what remains the best-known journalistic account of Watson and Crick’s discovery, this added up to something like willful deafness on Franklin’s part. “The pattern shouted helix,” Judson lamented, but for nearly ten months she “turned her back on her own discovery of the B structure of DNA and her own best evidence that [it] was helical” (Judson 1979, p. 135).

We write here to contend that Photograph 51 shouted “helix” so clearly because Rosalind Franklin intended it to do so. She had already photographed the very same sample of DNA used for Photograph 51, and analyzing the prior diffraction pattern, Photograph 49 (Fig. 2 ), led her immediately to a number of significant conclusions about the dimensions of a helical DNA molecule. She then created Photograph 51 for the purpose of reproducing that valuable diffraction pattern in a better-composed image that would be suitable for publication. Whereas Watson and others have portrayed Photograph 51’s combination of visual excellence and theoretical significance as a kind of happy accident that Franklin failed to exploit, it was the desire to merge those qualities in a single exposure that had in fact driven her to take Photograph 51. By recapturing Franklin’s original motivation, we are in turn able to explain the subsequent actions which have been misinterpreted by her supporters and critics alike.

We will present our revisionist account first and then use it to reassess portrayals of Franklin. We begin with a short but detailed explanation of how photographs 49 and 51 were created around the beginning of May 1952 and how Photograph 51 came to serve its purpose as an image intended for circulation. We analyze the later emergence of claims that Franklin had ignored or misunderstood Photograph 51, and argue that these criticisms echoed longstanding tropes about the role of women in science and of photographs as scientific evidence.

Fig. 1

Rosalind Franklin’s personal copy of Photograph 51. On this glossy photographic print Franklin noted “NaDNA ‘Structure B’” upon the reverse (History of Molecular Biology Collection, Box 10, Folder 15, Science History Institute. Philadelphia)

The Significance of Photograph 49

The key to understanding why Franklin took Photograph 51 lies in her notes about a previous picture. It was the forty-ninth in a series of seventy-eight diffraction images she and her graduate student Raymond Gosling captured with a Philips micro-camera (see Fig. 2 ) at King’s College London in 1951 and 1952. Footnote 4 Months before taking Photograph 49, the pair had established the existence of two distinct structural forms of DNA, and they had begun to manipulate samples intentionally to create them. The A form possessed an almost crystalline structure and gave diffraction patterns with many spots, potentially offering a great deal of information for structural analysis (by calculation of Patterson maps). Footnote 5 DNA could be converted to the B form at high relative humidity, yielding a simpler diffraction pattern with too few spots for similar (Patterson) structure calculations. Franklin had discussed her discovery of the distinct A and B forms in a colloquium at King’s on 21 November 1951 and documented them in an annual report of 7 February 1952, but her results were not otherwise published. Footnote 6

Franklin’s annual report of February 1952 also laid out a research plan that she appears to have followed closely until she moved from King’s College to Birkbeck College in the spring of 1953. Her goals were twofold: (1) to determine what caused a given DNA sample to exhibit the A or the B form, and afterward, (2) to characterize both forms initially through Patterson analysis of the more complex but data-rich A pattern. Footnote 7

Photograph 49 was created two months later in the course of a lengthy series of experiments aimed at completing the first of these objectives. Franklin’s stated hope was that these experiments would also reveal the best techniques for capturing sharp DNA diffraction patterns. As hoped, it was during this period of systematically manipulating the humidity levels at which samples were stored and photographed that she and Gosling produced what they retrospectively considered their best ever A form pattern (Photograph 42 of early February 1952) as well as their best B form photographs in May.

Completed on the morning of 2nd May 1952, Photograph 49 showed the result of aiming an extremely fine X-ray beam for three days and nights at a fiber that had been pulled into a fine thread from a drop of gel-like concentrated DNA solution. Footnote 8 The beam emerged from a collimator at the front of the camera and met the sample fiber, which was mounted and held in place across the orifice by two drops of glue, immediately inside the camera, just 15 mm in front of the X-ray film that recorded the diffraction pattern (see Fig. 2 ). Because space within the camera was so tight, they employed an unusual technique to prevent the main (undiffracted) X-ray beam from overexposing the center of the film. Instead of blocking the main beam with a small circular piece of heavy metal such as lead between the specimen and the film, as was conventional in larger cameras, they punched a hole through the centers of all the stacked films and allowed the undiffracted beam to pass right through the films and out of the back of the camera, through a small fluorescent screen that facilitated camera alignment (the holes can be seen in the film and camera body shown in Fig. 3 ). Footnote 9 Franklin and Gosling controlled the relative humidity of the DNA sample throughout the days-long experiment by passing hydrogen gas that had been bubbled through an aqueous salt solution of defined composition and concentration into the body of the camera. Footnote 10

As with the trials that preceded Photograph 49, they would learn the result of the experiment by removing and developing a stack of two or three small, hand-cut pieces of film from where they were held inside the camera body during the exposure (see Fig. 3 ). Each of the duplicate (or triplicate) films would show an even smaller X-ray diffraction pattern about 2.5 centimeters in diameter. On this occasion, they had used two pieces of film marked in Franklin’s handwriting as 49A and 49B (see Fig. 4 ). Footnote 11

These Photograph 49 films showed an unprecedentedly sharp version of the diffraction pattern produced by DNA’s B form (Fig. 2 ). Franklin and Gosling accomplished this by using a sample that had become irreversibly locked into the high-humidity B structure, meaning that it could be mounted taut in the camera and photographed at the lower 75% humidity level that ordinarily produced an A form pattern. Footnote 12 The resulting fine definition made it possible to use the photograph for more precise analysis than any previous B image had allowed, and Franklin therefore gave it her prompt attention. This immediacy is evident from a separate series of notes that were headed “(49) 49B Rough measurements on projection,” dated 2 May 1952 — the very same day she and Gosling had developed the films. Footnote 13 These notebook pages began with measurements of the new diffraction pattern, which the pair enlarged by projecting it onto a piece of white cardboard, and Franklin’s notes progressed in short order to making general conclusions about the B structure of DNA. She noted that the molecule showed repeats occurring every 34 Å, meaning it was about 25% longer per repeating unit than the drier, more crystalline A form she had already begun to analyze.

From the day Photograph 49 was taken, Franklin interpreted the pattern as indicative of a helix. Footnote 14 Other evidence indicates that she already had a helical interpretation of the B form structure in mind, and now she calculated how many layers of purine and pyrimidine bases there must be “per turn of helix (if there is a helix).” Footnote 15 If the bases were spaced 3.4 Å apart, as she and other researchers believed, then her calculations suggested that there would be exactly ten nucleotide-base layers in each lengthwise repeat of the molecule. In her notes, she phrased the finding more generally: “there is an integral number (or single fractional number) of residues per [34 Å] turn.” Footnote 16 Later, in 1954, Watson and Crick acknowledged that they had built their double helix as a model of the B form with its 34 Å axial period containing ten base layers per turn, which, Watson and Crick crucially realized, were complementary base pairs rather than individual bases. It is not widely appreciated that these parameters were originally established in Franklin’s analysis of Photograph 49. Footnote 17

Fig. 2

Photograph 49. This glass-plate negative shows an identical diffraction pattern to that of Photograph 51, seen in Fig. 1, except that the pattern is cropped by poor alignment between the film holder and the X-ray beam; the upper 3.4 Å arc is almost entirely lost. Both exposures used the same DNA sample under the same conditions (KDBP 1/1/0868, King’s College London Archives). Courtesy King’s College London

Today Photograph 49 survives in its entirety only as a negative-image contact plate of film 49B held at the King’s College London archive (Fig. 2 ). The photograph is remarkable for two distinct reasons. First, it vividly captures the very same diffraction pattern known so well today from Photograph 51. Secondly, however, a portion of the famous pattern has been cut off. Through our examination of the camera Franklin and Gosling used in 1952, we can explain how this must have happened. The photographic films were held in place by a flat metal bracket whose edges were bent around a backing plate that the films rested against (Fig. 3 ). This holder has a slightly irregular circle of roughly 2.5 cm diameter cut out to allow the diffracted X-rays to hit the films, and the glass negative of 49B illustrates that this holder had become misaligned with the X-ray beam and the DNA sample. In consequence, the upper part of the pattern is cropped to such an extent that a large, arc-like region now familiar from Photograph 51 (Fig. 1 ) does not appear in the image. This missing arc, like its symmetrical counterpart which appears at the bottom of Photograph 49, is caused by the 3.4 Å spacing between each layer of nucleotide bases in the molecule.

As we have seen, this inadvertent cropping did not prevent Franklin from using Photograph 49 in her analysis and calculations. She had captured enough of the pattern to be able to discern that one of the 3.4 Å arcs was located on the tenth meridional layer line of the pattern and to understand the implications for quantifying the layers of bases stacked in a single 34 Å turn of the helical molecule. Photograph 49 was a sharp and usable image but, because of the equipment malfunction, it was poorly composed and thus less than ideal for public presentation.

Fig. 3

X-ray micro-camera and film. This recent picture illustrates how X-ray films were prepared for the Philips micro-camera (KDBP 6/4/7, King’s College London Archive) that was used to take photographs 49 and 51. From left to right: the front of the camera body, removed and viewed from the inside; a piece of X-ray film backing paper showing how films were cut to the appropriate size; the film holder (above) and a piece of developed X-ray film (below) showing that the region of the film exposed to X-rays was determined by the cut-out in the holder; the camera body back, containing the rectangular platform against which one or more small pieces of film were held in place by the film holder. The film and backing paper are surviving artefacts from Wilkins’ 1953 research with Herbert Wilson, which included replications of Franklin and Gosling’s work using different sources of DNA (K/PP178/2/8, Wilkins Papers). Photograph by Alistair Sponsel, July 2026

Franklin therefore decided to retake the photograph. On the evening of 2 May 1952 – still the same day she first saw Photograph 49 – she began the notebook entry for Photograph 51: she would use the same specimen from 49, the same X-ray setup, and the same 75% relative humidity within the body of the camera. Footnote 18 The only thing distinguishing this from being an exact repeat was, as she wrote, that Photograph 51 was taken “with [the] holder centered over [the] collimator so as to include both 3.4 [Angstrom] arcs.” Footnote 19

Photograph 49 had been a research image, the result of an experiment. Photograph 51 would be the exact opposite: a refined image taken after the fact to document that experiment’s particularly successful outcome. Footnote 20

This relationship between Photographs 49 and 51 emerges all the more clearly when Franklin’s notes about them are compared with earlier entries in her laboratory notebooks. She had by then established a note-taking routine well suited to the open-ended trials characteristic of Photographs 1–49, with two distinct parts for each entry. The first section, written before the photograph was taken, provided details of the experimental set-up, including the date and time when X-ray exposure commenced. Afterward, Franklin would record the date and time when she and Gosling ended the exposure and then complete a second section, for which she customarily left a few lines empty, giving a brief indication of how the experiment had turned out.

Initially, she wrote about Photograph 49 using her standard format. She first specified which DNA sample she was using, the relative humidity at which it was maintained, and the source of the X-rays. Three days later, she filled in the space below to report that this trial had produced a “V[ery] good ‘wet’ photo” (meaning a very good photo of the B form). However, she then turned to a fresh set of pages in the notebook and filled them with the analyses we discussed above. Headed with the very date the photograph had originally been developed, this passage of notes filled far more space in her laboratory notebooks than did the discussion of any single previous DNA diffraction pattern, indicating that she immediately found this version of the B pattern to be strikingly important.

The entry for Photograph 51 was unprecedented in a completely different way. This was the first instance in Franklin’s DNA laboratory notebooks where she was able to write down in advance what details the diffraction pattern would include (namely, both 3.4 Å arcs) and the first occasion when she specified that correcting the cropping of a previous photograph was the reason for taking a new one. As an understandable consequence, Franklin did not bother to fill the lines at the end of entry 51 where she would normally have described the result of the photograph. Indeed, the empty space stands out starkly on a pair of pages otherwise densely filled with the initial conditions and the results of the surrounding experiments. As discussed below, later commentators have misinterpreted this omission as the act of a person who had just conducted a potentially crucial experiment, but who didn’t appreciate its significance. Rather, as we have shown, Photograph 51 was not an experiment at all in the sense that trials 1 to 50 had been. It was, in fact, the product of Franklin’s decision to invest four days of X-ray time into a known outcome. The investment made sense precisely because she valued a high-quality photograph of the helical B form diffraction pattern.

Franklin and Gosling did not immediately publish Photograph 51. Later commentators, armed with the knowledge that it would be less than a year before Watson and Crick built their double helix as a physical model of the very B form structure Franklin and Gosling discovered and characterized, have criticized Franklin for directing much of their effort during the rest of 1952 to analyzing the A form. However, what critics describe as Franklin’s discovery — and subsequent apparent neglect — of evidence for the crucial B form structure of DNA looked different from her perspective and in the context of her broader research objectives. Franklin’s stated objectives, as we have seen, were to understand the relationship between and interconversion of the two forms of DNA. Photographs 49 and 51, and her analysis of the former, which revealed the key parameters of a helical structure, represented an important and successfully achieved milestone. It is only with hindsight that we view the B form structure as the only important goal, and the structure of DNA. DNA clearly had more than one structure and Franklin wanted to solve both of them.

Fig. 4

The handwriting on individual films of photographs 49 and 51 (KDBP 1/1/0867–868, King’s College London Archives) compared with entries in Franklin’s notebooks (FRKN 1/1, Franklin Papers; reproduced with the kind permission of the Trustees of the Franklin Archive)

By completing Photograph 51, Franklin now had good images in hand of both the A form and the B form. From here, she turned to the second major objective of her established research plan: detailed structural analysis beginning with the crystalline A form, whose pattern offered more data for analysis than the paracrystalline B form. The results of several months’ work led her to conclude that this crystalline structure was likely a double-chained molecule, and in February 1953 she turned back to Photographs 49 and 51 to assess whether the B structure in turn showed “evidence for [a] 2-chain […] helix.” Footnote 21 That the B form photographs indicated a helical structure however, was not in doubt, as indicated by her notebooks. By the end of February, as she was leaving King’s College for a position at Birkbeck College, she and Gosling had drafted three papers, two of which would contain Photograph 51 when they were published later that year. Footnote 22 Meanwhile, since Gosling was to remain at King’s to finish his PhD under Wilkins’ supervision, Franklin directed him to give Wilkins the diffraction photograph that Wilkins in turn showed Watson. Footnote 23

For all the investment Franklin originally made to capture a publication-worthy version of the B pattern, when it came time to publish Photograph 51 she took yet another step to refine the image. In early March 1953, she turned over film 51C to be duplicated onto a durable glass slide negative that could, in turn, be used to produce positive photographic prints for submission. Footnote 24 The slide, which survives and is numbered 867 in the biophysics unit’s indexing system, became the basis for published reproductions. Footnote 25 This is evident because published images of Photograph 51 show the diffraction pattern centered within a circular border even more precisely than it had been when the pattern was originally developed on film. The perfected cropping was achieved by placing masking tape on the glass plate itself (see Fig. 5 ). The figures of Photograph 51 in both of Franklin and Gosling’s 1953 publications (1953a and 1953b) that included it show the ultra-refined cropping from the glass plate.

Fig. 5

A composite image showing how Photograph 51 was further cropped for publication. Left: a hitherto unpublished print of Photograph 51 showing that the circular region of exposed film had been larger than necessary to succeed in capturing the full diffraction pattern (HMBC Box 10, Folder 15). Center: the glass plate negative of film 51C with red masking tape used to create a new, smaller circular margin centered precisely on the diffraction pattern, which left a penumbra that can still be seen faintly through the tape in the lower-right quadrant of the slide (KDBP 1/1/0867). Right: Photograph 51 as it appeared in publications, shown here in the 25 April 1953 issue of Nature (Franklin and Gosling, 1953a)

Rethinking Rosalind Franklin’s Reputation in Light of Photograph 49

The myth that Franklin had failed to see value in Photograph 51 arose as a consequence of Watson’s 1968 memoir The Double Helix . The book appeared fifteen years after the events in question, ten years after Franklin’s tragically early death from ovarian cancer, and six years after Watson, Crick, and Wilkins shared the Nobel Prize for their studies of DNA. The book caricatured her as both a machine-like researcher and as a woman with emotions she could not control. In Watson’s telling, her “years of careful, unemotional crystallographic training” meant that she was producing sharper diffraction photographs and consequently more detailed measurements than anyone else (Watson 1968b, p. 69). However, she would erupt into defensive outbursts at any attempt to help her interpret these proprietary data, making life an “emotional hell” for her colleague Maurice Wilkins (Watson 1968b, p. 167). Indeed, Wilkins supposedly showed Photograph 51 to Watson in a moment of solidarity when Watson had invoked Franklin’s “hot anger” by suggesting to her face that “she was incompetent in interpreting X-ray pictures” and needed to “learn some theory” (1968b, p. 166).

Watson’s harsh portrayal of Franklin inspired many reactions, one of which came from her friend and former Birkbeck colleague Aaron Klug. Klug had inherited many of Franklin’s King’s College research records, and he now sought to understand what she had known about DNA, and when. After finding her 1951–1953 laboratory notebooks, he studied them carefully and circulated annotated photocopies for discussion with Wilkins and others (including historian Robert Olby, who was then working closely with Crick while doing research for a planned book). This flurry of activity in 1968 revealed that the well-known published B form pattern had been called Photograph 51 in her notebook and that it had been taken at the beginning of May 1952. Footnote 26 Wilkins reacted by declaring it a “real tragedy” that, in keeping Photograph 51 to herself for the rest of year, Franklin had allowed Watson and Crick to race ahead of the King’s group. “I looked at that B form picture,” Wilkins said in reference to receiving it from Gosling in January 1953, “and there it was, you can see the helix right there on the picture, but she refused point-blank to see it.” Footnote 27

Fig. 6

Rosalind Franklin in a 1950 photograph by the crystallographer Vittorio Luzzati (History of Molecular Biology Collection, Box 10, Folder 14. Science History Institute. Philadelphia)

Sentiments like Watson’s and Wilkins’ had a profound impact on the historical treatment of Franklin’s work. The question became, how did Franklin fail to discover the double helix while she possessed the photograph that supposedly had spurred Watson and Crick’s success? Footnote 28 For example, consider how the journalist-historian Horace Judson wrote about her in his celebrated 1979 book The Eighth Day of Creation , which was based on extensive interviews with all the participants except the late Franklin herself. Knowing with hindsight that Photograph 51 was the B picture she would later publish, he used it as a narrative device to portray a singular moment when Franklin decisively failed. “The pattern shouted helix,” Judson wrote, and it even “whisper[ed]” the other details of the B form structure. Although he mentioned the analysis she had performed on Photograph 49, his characterization was that Franklin merely “thought briefly and tentatively about No. 49” and “[t]here she stopped.” By underestimating the novelty and significance of these calculations and, more importantly, by misjudging why she had chosen to take Photograph 51, Judson interpreted the lack of notes about the retaken photograph as a sign that she had “turned her back on her own discovery of the B structure” (Judson 1979 , p. 135). We do not believe that Franklin ever turned her back on the B form. Deciding to take Photograph 51 was not a moment of failure, but a mark of her future commitment.

We have seen that Watson portrayed himself as immediately hearing the helix’s metaphorical shout from Photograph 51. He went on to insist throughout his life that Franklin had not been a sufficiently good scientist to see in Photograph 51 the truths that he had instantly recognized in the B form pattern. In a 2008 interview, for example, he said Franklin “clearly wasn’t interested in theory very much” and had neglected to pursue the B form even though it “was the perfect helical thing.” Footnote 29

These phrasings portrayed Photograph 51’s simple, sharp B form diffraction pattern as a natural object rather than a human-produced research product — as though it had occurred spontaneously under Franklin’s watch rather than being generated and photographed on purpose. In Judson’s telling, the DNA molecule “whispered” and “shouted” directly to those who saw the picture, rhetorically erasing the role Franklin played in revealing nature’s secrets (1979, p. 135). We have seen that Wilkins went even further, speaking as though Franklin had been concealing nature’s secrets by possessing Photograph 51.

The conceit that nature could speak directly to Watson through Photograph 51 echoed language that dates back to the earliest use of cameras by scientists. Advocates of the new technology claimed that photography, by reproducing natural objects mechanically and therefore without human bias, supposedly allowed nature to speak for itself. As historians Lorraine Daston and Peter Galison have shown, this combination of rhetoric and technology stemmed from the 19th-century craze for achieving “objectivity” in scientific research. Although technique and even creativity were actually required to make nature (seemingly) imprint itself on a photographic plate, the objective scientific photographer’s goal was to render this work invisible (Daston and Galison 2007 , p. 133). One of Franklin’s contemporaries, the great crystallographer J. D. Bernal, alluded to this process shortly after her death. Having pointed out that Franklin captured “among the most beautiful X-ray photographs of any substance ever taken,” Bernal remarked on the “skill” that had allowed her to make those photos appear to be “effortless.” Footnote 30

However, merely highlighting Franklin’s technical acumen risks damning her with faint praise for her contributions to the discovery of the double helix. It is one thing to possess the skill necessary to let a molecule seemingly speak for itself through a beautifully clear photograph, but it is another thing to be able to discern which specimen must be heard in order to solve an important scientific puzzle. To flip Watson’s deprecating remark on its head, this does require an interest in theory. It requires knowledge and judgment. In Franklin’s case, not only had she recognized the conceptual value of the B form diffraction pattern captured in Photograph 49, but she had also devised the original series of humidity experiments that revealed the B form’s existence and enabled her to capture it so clearly.

Franklin was an accomplished, creative, and self-directed researcher, but Watson’s Double Helix cast her in the role of a technical plodder, unimaginatively toiling over samples, laboratory equipment, measurements, and calculations. Footnote 31 Later efforts to praise her as a skilled crystallographer (but by implication nothing more), often reinforce a long tradition of women’s scientific activities being treated as rote work. Footnote 32 Recently, as Franklin’s public profile has risen considerably, her role in the hands-on work of crystallography has, in turn, been called into question. In what we consider to be an oversimplified description of a multi-day, multi-instrument collaborative undertaking, Gosling is now regularly credited as the sole individual who took Photograph 51. Footnote 33

Evidence from throughout Franklin and Gosling’s notes illustrates her leadership of, and thorough involvement in, both the intellectual and technical aspects of this collaborative research. Her handwriting on the films of photographs 49 and 51 (see Fig. 4 ) indicates that she was present when the films were loaded into the camera, but both Franklin and Gosling were likely aided by other women working alongside the King’s College biophysicists. Freda Ticehurst was the unit’s scientific photographer and manager of the dark room. She, in turn, had assistance from the likes of Lucille Heller, who volunteered in the biophysics unit in 1950–1951 and recalled “I remember helping Gosling set things up, and I think I helped sometimes with taking the X-rays, and I helped Freda Ticehurst, the lab photographer, develop some of the images.” Footnote 34 Gosling himself recalled the assistance and collaboration he and Franklin received from one of the biophysics unit’s workshop technicians, Len Pitches, who modified and even built cameras and other apparatus to their specifications. Footnote 35

Our case study of the relationship between photographs 49 and 51 provides only a glimpse at the full arc of Franklin’s activities as a DNA researcher. Footnote 36 However, even within this short paper we have witnessed her pursuing a full spectrum of scientific activities: designing a highly consequential series of experiments, tapping the skills of her student and technical staff while working alongside them in the X-ray room, accumulating data and carrying out careful measurements, perceiving the value of her results, and also showing a persistent intention about how to make the result we focused on here — the B diffraction pattern — appear in the most arresting possible form when it was published. She created Photograph 51 to serve as evidence of a helical DNA structure, of her laboratory's technical virtuosity, and of her own scientific judgment. Footnote 37

Data Availability

No datasets were generated or analysed during the current study.

Notes

  1. In the main text, Watson did not specify exactly which of Franklin’s photographs he had been shown by her colleague Maurice Wilkins. However, Photograph 51 is the one he used to illustrate this episode in the first edition of The Double Helix (Watson 1968b , p. 168).

  2. In her notebooks and in an interim report dated 7 February 1952, Franklin used the terms “crystalline” and “wet” to describe the two structures that she and her PhD student Raymond Gosling had successfully characterized (FRKN 1/1 and FRKN 4/3 respectively in Papers of Rosalind Franklin, Churchill Archives Centre, Cambridge; hereafter, Franklin Papers). These structures were called A and B respectively in the first publication she drafted with Gosling (Franklin and Gosling 1953b ). As we discuss below, it was Franklin herself who had characterized these two forms as distinct structures. For ease of understanding, we will refer to the structures as A and B throughout the paper.

  3. Many later commentators, acknowledging the significance of Photograph 51 to Watson and Crick’s discovery, have declared it to be among the most important photographs ever taken. (See, for example, assertions of Photograph 51’s historic significance in Walsh 2012 and Babaian 2024 ). Its appearance in compendia of influential photographs such as LIFE 100 Photographs: The Most Important Pictures of All Time and the Stories Behind Them (Editors of LIFE Magazine 2021 ) implies the same. Photograph 51 has also been featured on the British fifty-pence coin minted in Franklin’s honor and it was the namesake of a prizewinning play in London’s West End (Ziegler 2015 ).

  4. FRKN 1/1, Franklin Papers. The notebooks have been made available online at https://wellcomecollection.org/works/uus54sbp . Note that Franklin and Gosling also took photographs with other apparatus and numbered them in separate series.

  5. Detailed discussions of the work mentioned here are available in Klug ( 1968 ), Olby (1994 [ 1974 ]), Elkin ( 2003 ). Patterson maps, calculated from the intensities and positions of the diffraction spots alone, can reveal prominent inter-atomic distances, such as between phosphate groups, from which structures may be deduced.

  6. Franklin’s notes for her November 1952 colloquium are in FRKN 3/2, Franklin Papers. The annual report is Rosalind Franklin, “Interim Annual Report” dated 7 February 1952. FRKN 4/3, Franklin Papers.

  7. She wrote, “It is proposed to attempt a quantitative interpretation of the [A form] fibre diagram (which shows a high degree of crystallinity in the DNA fibres) by means of Patterson functions. […] Before embarking on these calculations it seemed desirable to ascertain that the photographs used were [i.e., would be] the best which could be obtained.” She continued by describing the “preliminary results” of what were then ongoing efforts to pursue a “systematic search for the best conditions, especially with respect to relative humidity.”

  8. The following paragraph is based on specific information about the Photograph 49 experiment from Franklin’s 1952 notebook (FRKN 1/1, Franklin Papers) and on general information about the experimental set-up that we gleaned from studying the Philips micro-camera itself and from Raymond Gosling’s 1954 PhD thesis (KDBP 6/4/7 and KDBP/5/1 respectively, King’s College London Archive).

  9. In shedding light on this unusual technique of allowing the main part of the X-ray beam to pass through the entire camera apparatus, we hereby offer a detailed context for the concerns regarding Franklin’s radiation exposure that some of her colleagues later shared in interviews for Maddox’s biography (Maddox 2002 , p. 144).

  10. Wilkins had originally suggested to Gosling the idea of filling the camera body with hydrogen gas to prevent unwanted scattering of the X-ray beam by the larger molecules in air. It was Franklin’s key contribution to control and modify the humidity of the hydrogen gas, and thus the DNA sample during the experiment, by bubbling the hydrogen through various salt solutions before it entered the camera.

  11. Franklin’s notebook entry for Photograph 49 specifies “2 films” (FRKN 1/1, Franklin Papers). The surviving version of Photograph 49 comes from film 49B (see Fig. 2 ). We infer that the other film would have been marked 49 A.

  12. We disagree with suggestions by Maddox ( 2002 ) and Cobb ( 2025 , p. 85) that Franklin did not intend or expect Photograph 51 to exhibit a B form pattern. “Sometimes during exposure,” Maddox wrote, “the [DNA] fibre would change from the crystalline A form to the paracrystalline B form. Once this happened so abruptly that the fibre fell off the holder. The photograph taken between 1 and 2 May […] was the clearest picture ever taken of the B form of DNA […] Rosalind put it aside to return […] to the puzzle of the A form” (Maddox 2002 , pp. 177–178). The circumstance Maddox described, of extremely hydrated DNA samples loosening in the specimen holder as a result of the structural shift from A to B, had indeed occurred with some of Franklin’s earlier experiments; for example, she had noted a “series” of trials in March and April 1952 “in which trial short-exposure films were generally good and [the] specimen subsequently went non-crystalline during long exposure” (note headed “March-April 1952” on the first inside page of Franklin’s 1952 notebook, FRKN 1/1, Franklin Papers). However, in the same note Franklin also reported the conclusion that specimens which began to give “non-crystalline” B form patterns at 75% relative humidity (which ordinarily produced the crystalline A form) were “never re-converted to crystalline.” It was just such a locked-in B form specimen, photographed at 75% RH, that she subsequently used to produce photographs 49 and 51. Indeed, Franklin and Gosling used Photograph 51 in one of their publications specifically to illustrate the phenomenon of “a fibre which had passed irreversibly to structure B ” and which produced excellent diffraction images precisely because it was no longer susceptible to “buckling of the fibre in the wet state, and consequent deterioration of the quality of the photograph” (1953b, pp. 674–675). By tracing this particular DNA sample’s provenance back through Franklin’s notes, we can tell that it had been locked into the B form for several weeks. Her entries for photographs 49 and 51 indicate that both were taken of a “specimen […] which gave [a] good ‘wet’ photo” when previously used in the lower-humidity photograph T0 on 18 April (this had been the first of a separately numbered “T” series of pictures she and Gosling had taken using a custom-built tilting camera stand). In the entry for Photograph T0, in turn, Franklin said the sample was “previously Xtalline [crystalline, meaning the A form], now gives ‘wet’ diagram [i.e., B form]” (entries for photographs T0, 49, and 51, Franklin’s 1952 notebook, FRKN 1/1, Franklin Papers).

  13. Pages headed “(49) 49B”, Franklin’s 1952 notebook (FRKN 1/1, Franklin Papers). This notebook entry is reproduced as Fig. 21 in Klug ( 2004 ).

  14. We emphasize this point only to contradict claims (discussed below) that Franklin had not recognized Photograph 51 as evidence of a helical molecule. That such a diffraction pattern was suggestive of a helical molecule had been worked out by her colleague Alec Stokes at King’s (unpublished), and by Crick and others in Cambridge (published as Cochran, Crick, and Vand 1952 ).

  15. Pages headed “(49) 49B,” Franklin’s 1952 notebook (FRKN 1/1, Franklin Papers). Franklin had declared three months earlier, in her annual report, that her studies of the A form “suggest a helical structure (which must be very closely packed) containing probably 2, 3, or 4 co-axial nucleic acid chains per helical unit.” In briefer remarks about the B form in the same report, she mentioned the “helix in the wet state” while reporting the DNA molecule lengthened to an undetermined degree during the crystalline-to-wet (A to B) transition (“Interim Annual Report” dated 7 February 1952; FRKN 4/3, Franklin Papers).

  16. Thanks to the work of William Astbury and Florence Bell in the late 1930s, it was considered likely that 3.4 Å represented the spacing between layers of the nitrogenous bases stacked perpendicular to the long axis of the molecule. See Astbury and Bell ( 1938 ). For discussion of their work, see Kersten Hall ( 2014 ).

  17. We believe that other commentators, for example Cobb and Comfort ( 2023 ), are mistaken in implying that Wilkins had independently and/or previously established the 34 Å axial repeat for the B form. In fact, Wilkins made several notes in the 1970s suggesting that he was interested in working out when Franklin had managed to do it. For example, on a copy of Franklin’s 7 February 1952 interim report, he wrote “N.B. no mention of 34 Å period[.] I had pattern by then & it looks as tho’ none of us bothered to measure it!” (Wilkins, Maurice Hugh Frederick [1916–2004], King’s College London Archives (hereafter, Wilkins Papers) K/PP178/5/3; see also his efforts to remember when she had done it on pp. 3 and 13 of his reminiscence dated 17 September 1976 in K/PP178/5/27/1). By the time Wilkins told Watson details of the B form in early 1953, he would have learned about the 34 Å period from Franklin and Gosling’s 3 September 1952 contribution to their unit’s annual report to the biophysics committee of the Medical Research Council. In his various recollections, Watson himself later indicated that he learned details of Franklin’s measurements by viewing his colleague Max Perutz’s copy of that MRC committee report, as well as from Wilkins by word of mouth.

  18. The intervening Photograph 50, taken during the day on 2 May 1952, was a very brief exposure assessing the condition of a freshly prepared DNA sample that was then placed into a desiccator (FRKN 1/1, Franklin Papers).

  19. Entry 51 in Franklin’s 1952 notebook (FRKN 1/1, Franklin Papers).

  20. We are not the first analysts to discuss Franklin’s forty-ninth photograph, but we believe our formulation of its significance in relation to Photograph 51 is original. Aaron Klug ( 1968 , p. 810) alluded to the existence of Photograph 49 by describing the image published in Franklin and Gosling’s Nature paper (i.e., Photograph 51) as one of multiple “photographs of exceptional quality [showing…] in a direct manner that DNA in the B form is a helix with an axial repeat of 34 Å and an axial spacing between nucleotides of 3.4 Å.” He continued, “The model building by [Watson and Crick…] was carried out to fit these parameters.” Robert Olby (1994 [ 1974 ], p. 369) also did not explicitly name Photograph 49, but he quoted Franklin’s 49th notebook entry (“V[ery] good ‘wet’ photo”) and speculated that this picture was the one Wilkins later showed Watson. On the following page, he quoted the notebook passage describing Franklin’s discovery of the 34 Å axial repeat but did not specify that it was accomplished using Photograph 49. Judson ( 1979 , p. 135) did specify that the “good ‘wet’ photo” entry was a description of Photograph 49 and he noted that Photograph 51 was “set up […] with the film holder more perfectly centered on the X-ray source.” As we discuss in the main text below, however, he then shifted to asserting what he thought Franklin should have realized about these two images. That passage drew from (and, in the process, conflated) Franklin’s May 1952 analyses of Photograph 49 and her February 1953 analyses of Photograph 51. We also note that a recent post on the website of Jessica Mills Davies, the author of a novel based on Franklin’s life, is illustrated with two versions of Photograph 49, namely the negative we included above (Fig. 2 ) and a positive-image print that Gosling used in his 1954 thesis. See Mills ( 2024 ) and Jessica Mills Davies. 16 January 2026. “Photograph 49: The X-ray Watson did not see,” ( https://www.jessiemillsauthor.com/journalism/photo-49-the-x-ray-watson-did-not-see , accessed 28 May 2026). Although we find many of Mills Davies’ specific claims about the photograph to be inconsistent with our understanding of Franklin’s work, we believe she is the first person to highlight publicly its appearance in Gosling’s thesis and to note the inaccuracy of his accompanying caption which mistakenly says it was exposed for the same duration as Photograph 51. Klug himself had noted this with some confusion inside his copy of Gosling’s 1954 PhD thesis, which he had inherited from Franklin and which is now in SHI HMBC, Box 14, Folder 1, notes on plates 4 and 10 of Chap. 4. As we show below, the error was originally made in the caption for Fig. 5 of the earlier publication by Franklin and Gosling ( 1953b , plate 10, inserted between pp. 674 and 675).

  21. Notebook entry for 10 February 1953 (FRKN 1/1, Franklin Papers).

  22. The paper drafted second but eventually published first was the expedited paper on the B form that appeared alongside Watson and Crick’s double helix paper on 25 April (Franklin and Gosling 1953a ). The first paper to be drafted, about the relationship between the A and B forms, had already been submitted on March 6 but did not appear until the summer (Franklin and Gosling 1953b ). Photograph 51 appeared in the latter paper as Fig. 4. It was accompanied by an extreme-closeup detail of the center of Photograph 49, as Fig. 5, to illustrate part of the diffraction pattern (an equatorial doublet) that was not entirely visible outside the central pinhole of the Photograph 51 film. With respect to the beam and the pinhole, Photograph 49 was slightly better aligned (both figures and their captions were printed on plate 10, inserted between pp. 674 and 675). The caption of Fig. 5 mis-stated the exposure time of Photograph 49 as 62 h, an error that Gosling carried forward to his 1954 PhD thesis (SHI HMBC, Box 14, Folder 1, notes on plates 4 and 10 of Chap. 4).

  23. In practice, Gosling continued working with Franklin while she was at Birkbeck. Their final co-authored DNA paper appeared in 1955.

  24. The King’s College biophysics unit maintained index books of quarter-plate slides produced for researchers (KDBP 2/1, King’s College London Archive). The first book in this series records that in March 1953 “Dr Franklin” ordered several plates including those duplicating films 51C and 49B (plates 867 and 868 respectively).

  25. There are several ways we can be sure that reproductions came from slide 867. For example, Franklin’s own copy of the image (see Fig. 1 ), has “867” written in pencil on the back of the print (along with her annotation in pen). More significantly, all published versions show the doubly refined cropping achieved by the placement of masking tape on glass plate itself (see Fig. 5 ). Presumably there must have been some prints made from the original film (as would have been the case for the print Wilkins showed Watson in early February 1953 nearly a month before plate 867 was made). The only print we are aware of that shows the original cropping from film 51C is the previously unremarked large-format print we have reproduced on the left of Fig. 5 (HMBC Box 10, Folder 15). This object was in Gosling’s possession as of the 1990s. In the same collection is a 4 inch x 5 inch (10.2 cm x 12.7 cm) acetate slide showing the patterns from photographs 42 and 51, i.e., Franklin and Gosling’s best A and B patterns, side by side and featuring the original cropping for Photograph 51 (HMBC Box 10, Folder 16). We are still working to solve the puzzle of when this slide was created and what it may have been used for.

  26. Klug wrote to Olby on 3 September 1968, “[b]efore leaving for holiday a few weeks ago, I discovered Rosalind Franklin’s missing notebooks for the years 1951 and 1952. This enables one to date all the photographs. […] Would you like to come and see them?” (HMBC Box 13, Folder 23).

  27. Maurice Wilkins 1970 interview with Anne Sayre for her book Rosalind Franklin and DNA , as quoted by Sayre ( 1975 , p. 128). In the BBC film Life Story (1987), which was made in consultation with Wilkins, he is depicted as showing Watson a large print of Photograph 51 while telling him that its pattern is obviously representative of a helical structure. (Wilkins’ extensive files related to the production are in K/PP178/5/27, Wilkins Papers.)

  28. Many efforts to understand the nature of Franklin’s failure focus on her supposedly anti-helical views. Watson used the phrase several times in The Double Helix , attributing it to Wilkins. He wrote, “Maurice had told me the nature of her so-called antihelical results,” and described “her self-made antihelical trap” (Watson 1968b , pp. 165–166). As Robert Olby (1994 [ 1974 ], p. 371) has pointed out, Wilkins seems to have misjudged the significance of her anti-helical data (which he had not seen) and/or the sincerity of her antihelical views (1994 [ 1974 ], p. 371). We largely agree with the explanations given by Klug ( 1968 ) and Olby (1994 [ 1974 ], pp. 370–376) for why Franklin felt, from late 1951 to early 1953, that there was a lack of evidence to conclude that the A form was helical.

  29. James Watson interview with Martin Raff and Walter Gratzer, recorded November 2008 and October 2009, section “Rosalind Franklin’s rapid acceptance of the double helix,” Web of Stories, 18 June 2010, https://www.webofstories.com/play/james.watson/32 (accessed 29 May 2026).

  30. Bernal wrote two obituaries of Franklin, both of which are quoted here. He called her images “among the most beautiful X-ray photographs” in memorializing her for Nature (Bernal 1958 ), and he discussed her “apparently effortless skill” in The Times (J.D. Bernal, “Dr. Rosalind Franklin: A life dedicated to science,” The Times (London), April 19, 1958, p. 3).

  31. Amplifying earlier observations by Maddox ( 2002 , pp. 311–328), Angela Creager and Gregory Morgan ( 2008 , p. 270) have argued that “the image of Franklin as meticulous and unimaginative […] was offered by Crick as well as by Watson, and the depiction works to excuse both of them for using her data by suggesting that she did not seem to know how to interpret it herself.”

  32. The most vivid illustration of this phenomenon appears in an essay Judson appended to the 1996 edition of his book in response to those who had adopted Franklin as “an emblem for the condition of women in science” and given her what he considered undeserved credit for Watson and Crick’s intellectual breakthrough. Franklin had been “patient, dextrous [sic], untiring,” he argued, which meant that she had been “poignantly unlucky” to lack a collaborator like Watson. “His scientific imagination [was] intensely visual,” Judson wrote, so that Watson “understood instantly facts [about Photograph 51] that Franklin had only [later] figured out” (Judson 1996 , pp. 627–628). This points beyond the more general phenomenon of women receiving less attention and acclaim than men for similar scientific achievements, which historian Margaret Rossiter termed the “Matilda Effect” (Rossiter 1993 ). Regarding the specific tendency we noted, Naomi Oreskes has written, “the invisibility of women’s contributions is enmeshed with the question of why some kinds of scientific work are more valued and honored than others” (Oreskes 1996 , p. 87). Because of sexual segregation in scientific and military institutions, many women were formally limited to holding technical or computational positions that were considered lower status, even if their activities transcended the nominal limits of their roles. Women in these roles became emblematic of “routine” scientific labor, making them all but ineligible to receive recognition according to the “rhetoric of [scientific] heroism in the public sphere” (Oreskes 1996 , p. 113). Pnina Abir-Am has made a similar but nevertheless distinct argument regarding creative contributions to the Nobel-prizewinning discovery of RNA splicing by the electron microscopist Louise Chow, whose work she says was not recognized for its novelty and significance by other participants who were less experienced in microscopy (Abir-Am 2020 ).

  33. As one illustration of this trend’s recent intensification, compare passages from a 2023 coauthored paper by Matthew Cobb and Nathaniel Comfort with Cobb’s 2025 biography of Crick. The former describes Photograph 51 as “a particularly clear image of the B form, taken […] by Franklin and her graduate student Raymond Gosling” (Cobb and Comfort 2023 , p. 658). The latter describes it as “an X-ray diffraction image of the B form supposedly taken by Franklin (in fact by Gosling)” (Cobb 2025 , p. 85). The trend seems to date from statements by and about Gosling around the time of the sixtieth anniversary of the double helix (see Smith 2019 ; Attar 2013 , 2023 ). We also note with good humor that the opening sentence of the current Wikipedia entry for Photograph 51, which says that the picture was “taken by Rosalind Franklin’s PhD student Raymond Gosling,” incongruously cites as its source an article by one of the present authors (Brian Sutton) that says the photograph was taken by Franklin and Gosling ( https://en.wikipedia.org/w/index.php?title=Photo_51&oldid=1364555388 ; accessed 22 July 2026).

  34. In an obituary for Ticehurst (then known by her married name of Freda Collier) in the Guardian , her nephew claimed that she had taken Photograph 51. Our general impression from all available evidence is more consistent with Heller’s recollection, namely that Ticehurst was likely involved in developing films after the experiments were complete (and creating duplicates on glass slides and in photographic prints). Heller’s recollections are from a July 2022 interview with Judy Masterson published on the website of Rosalind Franklin University in Chicago (https://www.rosalindfranklin.edu/helix/winter-2023/being-there/). The Ticehurst obituary is Thirlwall, A. P. 2013. “Freda [Ticehurst] Collier Obituary.” The Guardian , January 21 (https://www.theguardian.com/science/2013/jan/21/freda-collier-obituary ).

  35. Raymond Gosling interview with Anne Sayre, 18 May 1970. Anne Sayre Collection of Rosalind Franklin Materials, Box 4, Folder 2, p. 15; Archive of the American Society for Microbiology, Baltimore, Maryland.

  36. Franklin’s well-roundedness as a virus researcher — specifically the combination of leadership, crystallographic skill, and theoretical intuition she displayed in her 1953–1958 studies of Tobacco mosaic virus structure — has been well documented by Angela Creager and Gregory Morgan ( 2008 ).

  37. Sociologist of science Michael Lynch highlighted the distinction between photographs taken for “use” and photographs subsequently taken to be published as “evidence,” noting that several microscopists had told him they would avoid publishing blemished images that they had actually studied if they could instead illustrate their research with a visually “perfect” picture. Lynch concluded that "the documentary use of a photograph in a [publication] differs considerably from that of a photograph used by lab members [in the course of doing the original research].” Well-composed and unblemished photos for publication would not only illustrate research findings clearly but also serve as “exhibits of a lab’s practical competence” (Lynch 1985 , pp. 94–96). We are grateful to Simon Schaffer for drawing our attention to this passage.

References

Download references

Acknowledgments

We are extremely grateful to the archivists, librarians, and/or digital-collections staff of the Center for the History of Microbiology Archive in Baltimore, Churchill Archives Centre in Cambridge, King’s College London Archives (with special thanks for introducing us to each other), and the Science History Institute in Philadelphia (SHI) for making our research possible, and also to SHI colleagues/friends for supporting our collaboration. We are also grateful to our JHB editors, Nic Rasmussen and Betty Smocovitis, for their energy, advice and innumerable contributions to improving the paper; to two JHB referees for their helpful comments on the original manuscript; and to the following individuals for valuable conversations and/or comments on written drafts: Geoff Browell, Matthew Cobb, Nathaniel Comfort, Angela Creager, Michelle DiMeo, Hannah Grunwald, Judith Kaplan, Madison Renner, Lukas Rieppel, Simon Schaffer, Valerie Sponsel, Hallam Stevens, and Andrew Warwick.

Funding

This research was not supported by any external funding.

Author information

Authors and Affiliations

  1. Science History Institute, Philadelphia, USA

    Alistair Sponsel

  2. King’s College London, London, UK

    Brian Sutton

Authors

  1. Alistair Sponsel
  2. Brian Sutton

Contributions

AS and BS conducted all of the research, much of it while working side by side on archival materials, and developed the argument together. AS wrote the first draft and prepared the figures. AS and BS contributed equally to all subsequent writing and revision of the manuscript.

Corresponding author

Correspondence to Alistair Sponsel .

Ethics declarations

Competing interests

The authors declare no competing interests.

Additional information

Publisher’s Note

Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Sponsel, A., Sutton, B. Photograph 49 is the Key to Understanding the History of Rosalind Franklin’s DNA Photograph 51. J Hist Biol (2026). https://doi.org/10.1007/s10739-026-09866-7

Download citation

  • Received :

  • Accepted :

  • Published :

  • Version of record :

  • DOI : https://doi.org/10.1007/s10739-026-09866-7

Show HN: gtlds.fyi – All the proposed new gTLDs

Hacker News
gtlds.fyi
2026-10-07 15:53:17
Comments...

When Submarine Cables Go Dark: Understanding and Preparing for the Risks of Taiwan's International Internet Disconnection

Lobsters
resilience.ocf.tw
2026-10-07 15:44:06
Comments...
Original Article

海纜斷光會怎樣?認識台灣的國際網路中斷風險

Irvin Chen (陳心一)
ORCID: https://orcid.org/0009-0002-1059-7130
Open Culture Foundation ( ocf.tw )
MozTW, Mozilla Taiwan Community ( moztw.org )

Dates

Published: 2026-05-22
Last Updated: 2026-08-07

Acknowledgments


This work was supported by a grant from the APNIC Foundation ( ROR: 01y4y6h16 ), via the Information Society Innovation Fund (ISIF Asia) .

Abstract

This study examines how everyday network services may remain available when Taiwan experiences large-scale international submarine cable outages. By observing homepage resource requests and tracing the locations of resources used during page loading, we assess potential website availability during international connectivity outages and use the results as a risk indicator.

The work focuses on two core questions: (1) how much websites commonly used in Taiwan depend on foreign-hosted resources, and (2) how much they depend on local (in-Taiwan) nodes of multinational public-cloud providers. We develop a measurement framework that turns the abstract risk of “what happens when cables go dark” into concrete dependency-structure analysis.

We collected connection data from 2,179 websites commonly used in Taiwan. The results show that 39.3% are “foreign-dependent,” with foreign resource exposure and relatively high direct failure risk under cable-outage scenarios. Another 49.6% are “cloud-dependent”: no foreign resource requests were observed, but they rely on local nodes of multinational public clouds or CDNs, so their actual availability when international connectivity fails is highly uncertain.

This study provides a scalable, reproducible measurement method for quantifying observable foreign dependencies and comparing dependency structures across websites. The results can inform policy and industry resilience planning and support continued tracking of resilience improvements.

Table of contents

Background

Taiwan as a highly connected society

Taiwan is a highly digitalized society; the Internet and the information systems built on it are a critical foundation for how society operates. Digital dependence keeps growing: as of 2024, fixed broadband household penetration reached 74.5% 1 ; mobile broadband penetration 87.12%; overall Internet usage rose from 67.2% in 2006 to 88.75% 2 .

From waking to sleep, people constantly use networked screens to access and exchange information. The network is embedded in daily life and social activity. Communications, commerce, media, logistics, and public and government services all rely on digital systems online.

High connectivity means any sizable, sustained network outage can significantly impact the economy and society.

How everyday services depend on international connectivity

When someone opens an app (e.g. Line, the most popular messaging app in Taiwan, with over 98.2% usage rate 1 ) on a phone and sends a message, a chain of network requests is triggered.

First, the app asks the OS to connect; the device queries the carrier DNS for the target server IP (e.g. Line). After obtaining the address, it opens a TCP/IP connection and sends the request.

Data leaves the phone over wireless to a nearby cell site, then enters the carrier’s fiber backbone and core. Because Line’s main servers are abroad (Japan), traffic is routed to an international gateway—e.g. Tamsui or Toucheng cable landing stations—and crosses submarine cables overseas.

After reaching the destination country, traffic lands again and enters a cloud provider’s data center (e.g. AWS, Google Cloud, Azure). The app server processes the request; the response returns along a similar path and is rendered by the OS and the app.

This often completes in a fraction of a second. Unnoticed by users, data may travel thousands of kilometers round-trip between Taiwan and Japan—or tens of thousands of kilometers to another continent and back.

More importantly, one tap on an app or site can trigger dozens or hundreds of parallel requests, each repeating the above pattern. Most everyday digital services are effectively cross-border systems ; “instant” interaction depends heavily on international links and submarine cables.

Submarine cable vulnerability for an island economy

As noted, many sites and apps used daily depend on foreign resources and international connectivity. Losing external connectivity would likely break most digital services.

As an island, over 99% of Taiwan’s external traffic relies on submarine cables 3 . Cable resilience therefore directly affects everyday service availability and broader societal resilience.

Submarine cables are multi-layer cables a few centimeters thick on the seabed, or buried one to three meters in shallow water. In busy shallow areas such as the Taiwan Strait, damage often comes from human activity—anchoring, fishing, dredging—and from natural wear, amplifier failure, earthquakes, landslides, and geopolitical risk. Human causes dominate cable damage in Taiwan 4 .

According to the Taiwan Submarine Cable Map (smc.peering.tw), Taiwan is almost always in a state where “at least one cable is impaired” 5 . Cable faults may be a chronic background condition, not rare exceptions.

Availability of all Taiwan international submarine cables, 2025/3/18–2026/3/18 Availability of all international submarine cables serving Taiwan, 2025/3/18–2026/3/18 (source: Taiwan Submarine Cable Map (smc.peering.tw), cable status timeline).

Taiwan connects globally through fourteen international cables via landing stations at Tamsui, Bali, Toucheng, and Fangshan (another station is under construction in Dawu, Taitung), plus ten domestic cables to Penghu, Kinmen, Matsu, and other outlying islands 6 (RNAL and FNAL are two systems on one physical cable; MODA counts them separately, yielding fifteen international systems in some counts).

Under normal conditions, the Internet’s meshing, redundancy, diversity, and connectivity let carriers reroute traffic over other cables when a few fail. Quality may drop without users noticing. However, when multiple cables fail together, bandwidth redundancy is quickly exhausted, causing severe congestion or large-scale outages affecting communications, logistics, government operations, and digital systems 7 .

According to repair-time benchmarks published by the Ministry of Digital Affairs 8 , average repair time is about 32 days for international cables and about 110 days for domestic cables linking outlying islands. Disruptions can therefore last for months or even quarters, and contingency planning should assume a monthly rather than daily timescale.

Historical case: multiple international cables failed at once

A recent multi-cable failure occurred from 2025-12-25 to 2026-01-03: earthquakes off Yilan damaged six international cables (including EAC1, SJC2, PLCN, F/RNAL, EAC2, Apricot—nearly half of cables) 4 . Users reported slower networks and blocked apps, with repairs not completed until May 2026.

The 2006 Hengchun earthquakes remain a landmark case: on 2006-12-26 at 20:26 and 20:34, two magnitude-7 quakes off southwest Hengchun triggered many aftershocks. Mainland damage was relatively light, but underwater landslides broke four of six external cables at the time.

Taiwan’s international connectivity was severely disrupted. Initial call completion to the U.S. was about 40%; to China and Japan about 10%. China, Hong Kong, Japan, Korea, and Southeast Asia were also hit hard. Google, Yahoo, MSN, Gmail, Wikipedia, and other major services saw major outages across the region, affecting trade and finance.

Eight cable ships joined repairs; full restoration took nearly two months by mid-February 2007 9 . The UN ISDR director called submarine cable damage from the quake a new modern-type disaster 10 .

Both events show that even without total blackout, simultaneous multi-cable failure can cause severe congestion and widespread service degradation.

Historical case: Matsu island-wide outage

The early 2023 Matsu outage is a real-world case of complete external cable loss for a region.

Two cables linking Matsu to Taiwan were damaged on 2023-02-02 and 2023-02-08 by Chinese fishing vessels, cutting regional Internet and telecom except for very limited microwave capacity (2 Gbps), leaving most residents unable to get online 11 . One cable (Taiwan–Matsu 3) was repaired after about 50 days at end of March.

Taiwan–Matsu 2 and 3 total about 1 Tbps. After 2023, microwave was expanded to 12 Gbps. When both cables failed again on 2025-01-15 and 2025-01-22, the larger microwave link kept some connectivity 12 .

Satellite as backup: capacity and bandwidth limits

At the beginning of the 2006 incident, Chunghwa Telecom reallocated capacity on the ST-1 communications satellite to support international telephone service, briefly restoring partial availability for international voice calls. If a similar-scale incident happened today, could satellites still serve as a substitute?

Under the Taiwan Space Agency’s (TASA) “B5G LEO communications satellite program” 13 , Taiwan plans to launch two experimental LEO satellites before 2030 with a three-year design life.

Former TASA chair Tsung-Tsong Wu estimated that 24/7 nationwide LEO coverage would require at least 120 satellites, with roughly 40 replacements per year for a three-year lifetime—far above current plans, so it is hard to build substantive backup connectivity on that scale 14 .

Bandwidth also differs by orders of magnitude. A modern cable may carry hundreds of Tbps; Apricot is designed for 211 Tbps 15 . Starlink capacity was estimated around 20 Gbps in 2023 research—roughly 10,000× less per comparable unit; the full Starlink constellation (~3,300 satellites in 2023) was estimated around 20 Tbps total, comparable to one cable system 16 .

Even summing current LEO satellite bandwidth (Gbps class) cannot replace transoceanic cable throughput (Tbps class). TWNIC chair Kenny Huang compared cables to reservoirs and satellites to pipes 12 . Satellites can support emergency government or regional links, not national-scale replacement.

Why risk today exceeds 2006

In 2006, the main economic impact of lost international connectivity was disrupted international telephone service—finance and select industries—with overseas internet services affecting only a minority of users.

In twenty years, dependence on the Internet has grown sharply. Taiwan’s international bandwidth grew from 147.7 Gbps in 2006 to 10.6 Tbps in 2026—nearly 70× 17 . Meanwhile, average cable damage in Taiwan is about 5.1 times per year versus a global average of 0.1–0.2—roughly 25–50× higher risk 3 .

Deloitte (2016) estimated that a full national Internet outage in a highly digitalized country could cost about USD 23.6 million in GDP per day per ten million people—roughly USD 55 million per day for Taiwan, or about USD 1.7 billion per month, before accounting for semiconductor supply-chain and cross-border finance spillovers 18 .

The same work notes that even partial outages or bandwidth reduction hurt productivity, transactions, information access, and confidence.

Taiwan is more Internet-dependent and faces more frequent cable damage risk. A 2006-scale event today would affect far more than niche industries, with broader societal impact and much harder emergency response and alternative routing than in 2006.

Public awareness and research gaps

Public discussion of cable outages has increased, but often stays at “communications difficulties”—Line/Messenger/WeChat, Google, Gmail, Office 365—similar to 2006 framing.

Academic resilience work often focuses on infrastructure or intermediary layers: cable topology, routing, DNS 19 20 , CDN and cloud centralization. That implies: if infrastructure is up and reachable, services work.

Routing is decentralized and imperfect; failures are routine. Policy constraints mean routing errors, misconfiguration, or node faults can cause large outages without physical cuts. Infrastructure health alone does not equal service availability 21 .

Even with spare cables, traffic reshaping, routing policy, or concentrated paths can still block communication—“physically connected” ≠ “actually reachable” 22 ; redundancy alone does not guarantee cross-border availability 23 .

Modern stacks span infrastructure, logical, and application layers; societal impact exceeds any single operator. Resilience is a public-good problem across layers, operators, and borders 7 .

Indices such as the Internet Resilience Index use national infrastructure, performance, security, and market structure as proxies 24 but do not directly measure whether sites people use daily still load when international connectivity is constrained.

Policy analyses focus on national infrastructure, topology, repair capacity, alternatives, and geopolitical risk—emphasizing bandwidth redundancy, path diversity, repair, and cooperation 25 .

Third-party dependency research (e.g. DNS, CDN, certificate authorities) highlights concentration and single points of failure 26 : over 89% of sites depend on third parties for critical functions; top three providers support over 90% 27 ; multi-level indirect dependencies can amplify failures 28 .

Resilience must include service availability under constrained external connectivity and third-party state—not only physical reachability. This study emphasizes “service availability under constrained connectivity”, developing application-layer methods to ask which everyday digital services—and what share—could remain usable when external links fail, and how cable outages may affect network and societal resilience.

Summary

The challenge we face is not “will cables break?” but service collapse risk: in a highly digital, cloud-heavy, cross-border-dependent society, when external connectivity is severely impaired, which services keep basic function, which degrade, and which fail outright?

Past debate focused on bandwidth, physical damage, and backup communication methods. Modern services are not “a local server serving static HTML.” A “Taiwan” site or app may run on global cloud regions across datacenters and depend on hosts, CDNs, third-party JavaScript, login, payments, analytics, push, AI APIs, and other external components. Any critical piece abroad or reachable only via foreign paths can fail unexpectedly during cable outages.

Under severely congested or broken international links, repairing or rebuilding systems becomes harder.

Impact cannot be judged only by “how many spare cables remain.” Services may fail due to routing, DNS, congestion, cloud dependencies, or unreachable external assets even when the physical network is not fully down. Beyond connectivity, we need user-facing service availability measurements.

Without understanding real impact, we cannot prepare. This study turns “what happens when cables go dark” into measurable, comparable technical questions—filling an application-layer gap in resilience discourse. Through a test framework, it estimates how commonly used services may load, degrade, or fail when foreign connectivity is lost, providing evidence for backup design, resilience investment, and policy and social readiness.

Research questions

When an island nation highly dependent on international networks, such as Taiwan, experiences severe degradation, instability, or partial interruption of its external submarine-cable connectivity—and thus loses access to much of the global Internet—to what extent do commonly used domestic websites continue to operate, degrade, or fail?

We aim to systematically test and count international-facing components in service operation—CDNs, third-party APIs, cloud platforms, external libraries—and map dependency structure and potential availability risk for commonly used services under foreign-network isolation.

The work should give government, industry, and civil society concrete evidence on systemic impact of external connectivity loss, supporting resilience strategy for digital services and critical public sectors.

Two core themes:

  1. Degree of dependence on foreign-hosted resources
  2. Degree of dependence on Taiwan nodes of multinational public clouds and CDNs, and what that implies for resilience

Three concrete questions:

  1. Under “Taiwan external connectivity severely impaired or cut,” what share of commonly used sites exhibit foreign resource dependency exposure at the homepage level?
  2. Is dependency on local nodes of multinational public clouds and CDNs concentrated in specific service ecosystems ?
  3. Do different site types, such as .gov.tw government websites, .edu.tw education websites, and general services, show systematic differences in foreign-resource dependency rates?

This study uses a programmatic browser to observe the distribution of resource requests generated while loading each homepage. A homepage is the first user-visible point of interaction with a service and includes some of the front-end resources required for basic rendering and interaction. We treat this observation as a scalable proxy indicator for comparing dependency exposure across a large number of websites. However, it does not include the complete backend architecture or cloud control-plane dependencies and therefore cannot be interpreted directly as overall service availability.

Targets and test environment

We compiled a high-traffic site list for Taiwan, including domestic and international services commonly used by locals. The target is “sites Taiwanese people use,” instead of “Taiwan sites”—so the list includes Google, Gmail, etc.

The unit of study is “websites” (Web), not direct equivalence to app availability. (OCF has related work on app connectivity resilience.)

Building the site list

There is no authoritative “sites Taiwanese people use” list. We merged:

This campaign used ranking snapshots obtained from each source on 2026-07-20. Before merging, hostnames were lowercased and a leading www. was removed, while other subdomains were preserved. Duplicate hostnames were merged into one entry while retaining the source-specific rankings. The resulting merged_lists_tw.json contains 2,467 sites.

We also use manual_curated_list_tw.json to include 42 manually selected open-source and digital-resilience community cases, including OCF, SITCON, and g0v. Two hostnames overlap with the automatically ranked list.

Together, the two lists contain 2,507 unique websites. The lists and scripts are open source in top-traffic-website-list-taiwan .

Test environment

Tests used typical Taiwanese residential connectivity:

  • Chunghwa Telecom fiber 500M/500M
  • Locations: Zhonghe District, New Taipei; Zhongzheng District, Taipei
  • DNS: 168.95.1.1
  • Environment details recorded in logs for comparison and reproduction

Methods

Site availability depends not only on establishing connections, but on fetching dependent resources (JavaScript, CSS, images, APIs). Modern sites combine resources from many domains; together they determine what users see and can do. Prior work uses headless browsers to analyze request behavior and third-party dependencies 30 27 .

Building on dependency-exposure analysis from resource requests, we extend it to the systematic scenario of “international connectivity failure” and its potential impact on service availability.

Backend architecture, data paths, control planes, and internal cloud behavior are not directly observable externally. We do not attempt to map full system dependencies; we focus on observable front-end network requests and build operational metrics from them.

Metrics and risk taxonomy

Two core metrics:

  1. Foreign Dependency Exposure
    Whether homepage requests include foreign-hosted resources—exposure to foreign networks at the resource layer.

  2. Cloud Local Endpoint Exposure
    Whether requests hit Taiwan nodes of multinational public-cloud or CDN providers—exposure to sites hosted on, or dependent on, their local endpoints.

These describe “dependency exposure structure” at the homepage front-end resource layer, not full system architecture or actual failure modes.

We can classify sites into three categories based on the above metrics:

  1. Foreign-dependent
    Foreign resource exposure: homepage load directly depends on foreign resources. Such sites are directly exposed to unavailable resources when external connectivity is severely degraded or interrupted, making them the most likely to be affected immediately and the category with the highest direct risk.

  2. Cloud-dependent
    No foreign resource exposure, but cloud local endpoint exposure: homepage loads show no foreign resource requests, yet use resources from Taiwan nodes of multinational public-cloud or CDN providers. Sites appear localized, but availability still depends on control planes, origins, authentication, and cache persistence—“surface-local, cross-border uncertainty”.

  3. Locally-contained
    No foreign resource exposure and no multinational-cloud local-endpoint exposure. Such sites have a higher chance of local operation, but full-system availability during external outages is not guaranteed.

Implementation and data processing

Tools and projects:

Collecting test data

We developed web-resilience-test to open each target homepage site-by-site with a programmatic headless browser and record all resource connections during load.

Next, the tool processes all resource requests collected during page loading. It excludes blob: and other unparsable requests, as well as requests matching the ad-filter rules or the manual exclusion list. It then deduplicates the requests, retaining only one request per hostname within each website; each unique website-hostname pair constitutes one observation.

The tool then uses IPinfo, provider-specific response headers, the LACeS anycast API 31 , and ping RTT to determine the geographic location and classification of each observation.

Finally, the tool aggregates all test results into statistical tables. The detailed workflow follows.

Single-site test flow

no-global-connection-check.js tests one site:

  1. Initialization

    • Environment setup; load exclusion domain list
    • Normalize target URL (e.g. add https:// )
  2. Page load and request capture

    • Playwright headless Chromium opens the site
    • Listen to request for all request metadata including headers
  3. Retries and errors

    • 4xx responses are treated as test failure and logged
    • Other errors: retry in this order:
      • Headless / non-headless browser
      • URL with/without www. prefix
    • If all four variants still fail, log the error and skip to the next site
  4. Request cleanup

    • For each page's request data, perform the following cleanup:
      • Drop blob: requests
      • Exclude unparsable requests
      • Match requests against the configured adblock domain lists to remove advertisements and related unnecessary resources
      • If the target website's hostname appears in the lists, requests to hostnames with a parent or child relationship to the target are retained to avoid blocking the website's own resources
      • Exclude hostnames on the manual exclusion list. This study lists only the web-font hostname fonts.gstatic.com , because its failure is less likely to affect core website functionality than failures of scripts, APIs, or content resources. Future studies can use the same mechanism to add other exclusions
      • Deduplicate requests by hostname; each unique website-hostname pair is one observation
  5. Domain location

    • For each observation's hostname, call the IPinfo API to obtain its geographic location and ASN information
    • If the result shows country=TW , record it as a domestic connection
    • Compare the ASN against cloud_providers_tw.json registry version 0.1.0, dated 2026-01-05, to determine whether it belongs to the multinational cloud/CDN category. The registry contains 30 international public-cloud, CDN, and hosting providers and excludes Taiwan-only providers
    • If the result shows a country other than TW and its ASN belongs to one of the following six providers with local Taiwan nodes, apply the advanced classification steps:
      • Google (AS15169, AS396982, AS19527), Cloudflare (AS13335, AS209242), Amazon (AS16509, AS14618), Fastly (AS54113), Akamai (AS16625, AS20940, AS32787), or Microsoft (AS8075)
    • Headers: inspect response headers such as cf-ray , x-amz-cf-pop , x-served-by , x-azure-ref , and x-msedge-ref for known cloud location markers. A value containing TPE indicates a Taiwan node
    • Anycast: if headers are inconclusive, query the LACeS Anycast Census API 31 to determine whether the endpoint is a local anycast resource; if locations includes Taiwan and confidence is confident , classify it as domestic
    • RTT: if the preceding methods are inconclusive, ping the resource 5× and take the minimum RTT. Classify it as domestic when RTT < 15 ms ; otherwise, retain the foreign classification

    Note: we built the cloud_providers_tw.json ASN registry using complete request data from earlier tests. It is open source for use by other research and projects.

  6. Classification and resilience metrics

    • Based on the preceding information, classify each unique website-hostname observation as one of: domestic/cloud , domestic/direct , foreign/cloud , foreign/direct
      • “cloud” means the ASN in IPinfo org is listed in cloud_providers_tw.json under providers_intl or providers_intl_without_known_taiwan_region/pop
    • Count the total observations in each category for every website and save the results to test-results/<site>.json
  7. Errors

    • Failures are logged to test-results/_error/<site>.error.json
    • Common errors include:
      • Cloudflare challenge : target site uses Cloudflare's challenge protection mechanism to prevent abuse.
      • HTTP 4xx
      • Timeout

RTT classification coverage and threshold sensitivity

RTT is the final stage of location classification: a target cloud or CDN endpoint enters RTT only when IPinfo, provider-specific response headers, and LACeS cannot determine its location. The test tool pings the endpoint five times and uses the minimum RTT. It is reclassified as an international public-cloud node in Taiwan only when the minimum RTT is below 15 ms; otherwise, it remains classified as foreign.

Across 2,179 successfully tested websites, the browser recorded 262,926 raw HTTP requests. The filtering described above and within-site hostname deduplication produced 19,046 unique website-hostname observations for classification. Of these, 3,640 observations from 976 distinct hostnames across 1,243 websites entered the RTT fallback stage; details are in the table below.

Metric Count Share
Sites tested 2,179
Sites with RTT fallback 1,243 57.0% of sites tested
Observations to classify 19,046
Entered RTT stage 3,640 19.1% of observations
RTT measured 3,064 84.2% of RTT-stage observations
Min RTT < 15 ms 2,394 78.1% of measured RTTs
Min RTT ≥ 15 ms 670 21.9% of measured RTTs

The distribution of the 3,064 measured RTTs is shown below. Each point is one successful measurement; the horizontal axis is an observation index, and the vertical axis is logarithmic. Values are bimodal; the 10–30 ms transition range holds 130 observations (4.2%).

Based on this distribution, we use a relatively conservative < 15 ms threshold within the sparse interval to classify a resource as domestic, reducing the risk of misclassifying a foreign resource as domestic.

RTT range Count Share
0–<5 ms 206 6.7%
5–<10 ms 2,090 68.2%
10–<15 ms 98 3.2%
15–<20 ms 12 0.4%
20–<30 ms 20 0.7%
30–<50 ms 270 8.8%
50–<100 ms 247 8.1%
100–<200 ms 100 3.3%
≥200 ms 21 0.7%

RTT distribution

Without RTT correction (equivalent to a 0 ms threshold), every resource entering RTT fallback retains its foreign classification, producing 1,370 foreign-dependent websites and 566 cloud-dependent websites. Applying the 15 ms threshold reclassifies 514 websites (23.6%) from foreign-dependent to cloud-dependent, resulting in 856 and 1,080 websites in the two categories, respectively.

The table further tests sensitivity to the selected RTT threshold. Relative to the 15 ms baseline used in this study, a 10 ms threshold moves only 27 websites (1.2%) from cloud-dependent to foreign-dependent, while a 20 ms threshold moves only five websites (0.2%) from foreign-dependent to cloud-dependent. The locally-contained count is unchanged. The aggregate classification therefore differs only slightly across the 10, 15, and 20 ms thresholds.

RTT threshold Foreign-dependent Cloud-dependent Sites reclassified vs. 15 ms
No RTT (0 ms) 1,370 (62.9%) 566 (26.0%) —
10 ms 883 (40.5%) 1,053 (48.3%) 27 (1.2%)
15 ms 856 (39.3%) 1,080 (49.6%) —
20 ms 851 (39.1%) 1,085 (49.8%) 5 (0.2%)

Batch test flow

batch-test.js runs single-site tests over the list and writes test-results/statistic.tsv . From that batch output we derive overall foreign-dependency rates and per-resource resilience status.

Per-site result pages

We use web-resilience-test-profile to compile individual static pages and host them at https://resilience.ocf.tw/ for public lookup of each site’s resilience (e.g. Will ocf.tw work if cables break? ).

At ~2,000 sites, when running with default parallelism (4 parallel tests, 8 parallel static page compilations), it takes about 30–60 minutes to complete. The latest test results are published at web-resilience-test-result and resilience.ocf.tw .

Results

Of 2,507 unique sites tested, 2,179 completed successfully.

Overall results

Within the measured results, 39.3% are “foreign-dependent,” with foreign resource exposure and high direct failure risk under cable outages; 49.6% are “cloud-dependent”—no foreign resource exposure was observed, but they rely on in-Taiwan nodes of multinational public clouds or CDNs, so availability is highly uncertain . Only 11.2% are “locally-contained,” with no observed exposure and a higher chance of normal operation. Overall, 88.8% of sites warrant further attention as high-risk or high-uncertainty.

Interpretation

Foreign-dependent: sites hosted abroad or whose homepages request foreign resources. They are exposed to international connectivity degradation or interruption and face high failure risk.

Cloud-dependent: no direct foreign resource exposure, but loading pulls resources from Taiwan nodes of multinational public-cloud or CDN providers. Topologically domestic, yet control planes, origins, authentication, or cache persistence may still depend on foreign systems—“localized in appearance, uncertain in availability”.

Locally-contained: no dependency exposure was observed among front-end resources. The site itself appears to be domestic and not hosted on a multinational public cloud, and it does not request foreign resources or resources from domestic nodes of multinational clouds. It therefore has a higher chance of continued operation, although this category does not account for complete backend dependencies and cannot establish that the service will continue operating.

Category Sites Share
Foreign-dependent (foreign resource exposure) 856 39.3%
Cloud-dependent (no foreign exposure; in-Taiwan nodes exposure) 1,080 49.6%
Locally-contained (no observed exposure) 243 11.2%
Total 2,179 100.0%

Multinational public cloud dependency

Among Category 2 (cloud-dependent) sites, requests to different international public-cloud nodes in Taiwan break down as follows:

  • Google Cloud Platform (Taiwan nodes): 965 sites
  • Cloudflare (Taiwan nodes): 480 sites
  • Amazon Web Services (Taiwan nodes): 138 sites
  • Akamai (Taiwan nodes): 104 sites
  • Microsoft Azure (Taiwan nodes): 38 sites
  • Fastly (Taiwan nodes): 4 sites

Provider site counts are non-exclusive: one site may use more than one provider, so the rows must not be added to obtain a site total.

Of 1,323 sites with no foreign dependency, 965 use resources from GCP Taiwan nodes (72.9%).

If public-cloud services such as GCP cannot keep local nodes running during external network outages, the impact would be very high. Their resilience is a key factor in whether sites can continue operating during submarine-cable disruptions.

Public cloud resource locations

For resources requested from domestic and international nodes of multinational public clouds, we found the following distribution:

Provider Sites (domestic nodes) Sites (international nodes) Requests (domestic nodes) Requests (international nodes)
Google 1,685 56 7,393 63
Cloudflare 1,016 17 3,051 21
Amazon 512 309 1,382 522
Akamai 338 11 446 13
Fastly 6 257 6 369
Microsoft 140 77 196 143

A site may request both domestic and international nodes from the same provider, so the two columns overlap and must not be added to obtain a provider total.

For Google cloud resources, measured by request count, 7,393 of 7,456 Google requests were classified as domestic-node requests, or about 99.2%; 63 were international-node requests, or about 0.8%. This shows the practical value of CDN-based data localization, and makes the persistence of mirrored resources on Taiwan nodes a key factor in whether ordinary sites remain available when external links are congested or cut.

Public-cloud services with lower domestic resource shares should be further evaluated for full in-country mirroring, cache persistence, and contingency operations.

Resource location and cloud-platform dependency statistics

For this comparison, global cloud includes the multinational public-cloud and CDN providers compiled for this study, while other/local covers all other providers. A website is counted in a cell when at least one of its observations belongs to that group:

Unit: sites & adoption rate Domestic Foreign Any
Global cloud 1,881 (86.3%) 754 (34.6%) 1,910 (87.7%)
Other/local 1,623 (74.5%) 245 (11.2%) 1,709 (78.4%)
Total 2,140 (98.2%) 856 (39.3%) 2,179 (100.0%)

87.7% of sites depend on global-cloud resources: 86.3% depend on resources from domestic global-cloud endpoints, and 34.6% depend on resources from foreign global-cloud endpoints.

Among the 856 sites with foreign resource exposure, most also use domestic resources; only 39 use foreign resources exclusively, accounting for just 1.8% of all 2,179 sites. This shows the practical value of CDN contributions to data localization and benefits for service resilience.

Resource source distribution

Among the 18,969 unique website-hostname observations with provider information from IPinfo, dependencies are highly concentrated among large providers. Provider labels are normalized from IPinfo ASN organization data. Providers above 5% include Google, Cloudflare, Amazon, Chunghwa Telecom (CHT), and Facebook. Google has the highest observation share at 39.7%, followed by Cloudflare at 16.4% and Amazon at 10.4%.

Per-site inspection shows that Google resources mainly include services such as GTM, while Cloudflare provides infrastructure and services such as cdnjs JavaScript CDN and WAF. These common infrastructure services form key parts of contemporary internet-service resilience.

Unit Count Share
Google 7,525 39.7%
Cloudflare 3,109 16.4%
Amazon 1,979 10.4%
Data Communication (CHT) 1,645 8.7%
Facebook 1,460 7.7%
Akamai 518 2.7%
Fastly 375 2.0%
Microsoft 346 1.8%
Taiwan Academic (TANet) 321 1.7%
Yahoo 115 0.6%
Oracle 110 0.6%
Taiwan Fixed Network 107 0.6%
New Century 93 0.5%
OVH SAS 81 0.4%
Automattic 66 0.3%
Zenlayer 60 0.3%
Incapsula 54 0.3%
Yuan-Jhen Info 44 0.2%
Magnite 40 0.2%
Datacamp 37 0.2%
Sony 36 0.2%
Byteplus 32 0.2%

Public-sector aggregate risk

To assess the resilience of government and education sites, we first looked only at foreign resource connectivity:

  • Among the test results, 235 were government sites ( gov.tw and *.gov.tw ); 16 had foreign connectivity, or 6.8%.
  • 255 were education sites ( *.edu.tw ); 34 had foreign connectivity, or 13.3%.
Type Sites tested Foreign dependencies Share
Government 235 16 6.8%
Education 255 34 13.3%
All 2,179 856 39.3%

Government and education sites depend less on foreign resources than the overall population. This suggests that public-sector and academic-network environments have a stronger baseline for local availability, although full service resilience still requires checking backend dependencies and real usage workflows.

Recommendations

Based on this study’s findings, we identify the following policy and technical recommendations to improve the resilience of Taiwan’s overall digital services.

Overall, the main risk for websites commonly used in Taiwan does not come only from a small number of fully foreign-hosted services. It is more widely embedded in dependency structures involving foreign resources and Taiwan-based nodes of multinational public clouds. Resilience strategies should therefore go beyond asking whether a service is “in Taiwan,” and further examine whether its resource supply chain, cloud control planes, and critical user journeys can continue operating locally.

Policy Recommendations

  1. Support related research to continuously monitor the resilience of commonly used and critical services, and routinely publish both aggregate and per-service results.
  2. Support follow-up research to develop deeper resilience testing frameworks for user journeys such as login, transactions, browsing, and search, in order to conduct further availability testing.
  3. For Taiwan nodes of heavily used international public-cloud providers such as Google, Cloudflare, Amazon, and Akamai, provide policy requirements and budget support to verify and improve service availability during external network outages.
  4. Provide policy requirements and budget support to reduce critical domestic services’ dependence on foreign resources and improve their local resilience.
  5. Encourage or require critical domestic services to establish local backup mechanisms or recovery plans, and conduct periodic disconnection drills.
  6. Based on local-availability validation, define resilience tiers, such as A: fully usable; B: degraded but usable; C: homepage loads but interactions fail; D: immediate failure, and include them in procurement and acceptance criteria for government and public services.
  7. Establish an extreme-case bandwidth-priority plan in advance, given that backup satellite capacity is far below submarine-cable capacity.

Technical Recommendations

  1. For highly critical international public-cloud services operated by providers such as Google, Cloudflare, Amazon, and Akamai, contingency plans for external connectivity failures should be developed and regularly exercised.
  2. Website builders should consider the resilience risks of using foreign resources. When loading frameworks or libraries, they can prioritize CDN services with Taiwan-based nodes, or establish fallback mechanisms that switch to local resources when a library fails to load, reducing the impact of external connectivity outages.
  3. Service developers can prioritize data localization for critical service paths, such as login and checkout, to improve resilience and service quality.

Limitations and future work

Main limitations:

  1. This study observes the source locations of website requests, not full network paths such as traceroute, nor routes from abroad via VPN. Whether “domestic” resources or pages are anycast/CDN nodes still needs further testing.

  2. The 15 ms RTT cutoff is a fallback heuristic, not physical proof of endpoint location. Routing changes, congestion, or nearby foreign nodes can affect individual measurements, although the threshold sensitivity analysis shows limited aggregate impact.

  3. “Foreign dependency” and “cloud dependency” here refer to front-end observable exposure, not full backend architecture. Even locally-contained sites by front-end metrics may still rely on foreign databases, APIs, or backend services. The 11.2% locally-contained group cannot be assumed to remain available during external outages.

  4. Resources and webpages hosted on Taiwan nodes of multinational public-cloud services do not guarantee that the service can operate independently during submarine-cable or international connectivity outages. Observing a Taiwan endpoint shows only that some front-end resources can be obtained domestically. Actual availability may still depend on:

    • Whether control-plane services, including authoritative DNS, configuration, and logging, rely on foreign systems
    • Whether the origin and dynamic content are located abroad
    • Whether cache hit ratio, cache persistence, and cache revalidation require international connectivity
    • Whether identity and access management, token validation, session handling, and other authentication processes rely on foreign services
    • Other foreign dependencies that may affect service availability
  5. This study does not perform fault-injection tests that simulate a loss of international connectivity, such as using VPN or DNS techniques to make foreign resources unreachable. As a broad survey of many websites, it estimates potential risk from dependency structures rather than directly observing service degradation during a forced connectivity outage.

  6. This study tests homepages only, not full user journeys such as login, transactions, browsing, or search. Results should therefore be treated as “initial availability” indicators based on dependency exposure among resources involved in initial service access, not as measurements of complete service availability.

Suggested follow-ups:

  • Combine fault injection with journey-based testing, such as login, transactions, browsing, and search, to observe actual availability.
  • Study the resilience of major cloud-service architecture, including control planes, origins, cache defaults, and authentication.
  • Use traceroute to analyze full resource paths.
  • Analyze the usage and node distribution of common front-end libraries and frameworks, such as jQuery, Bootstrap, Tailwind, React, and Vue, to identify shared foreign-service single points of failure.
  • Compare dependency patterns by resource type, such as document, script, image, XHR, font, and stylesheet.
  • Identify high-traffic, low-resilience sites.
  • Add more Taiwan traffic data, such as the Chrome CrUX user experience dataset.
  • Develop a service-criticality framework that classifies services into categories such as government, finance, communications, video streaming, news, e-commerce, social media, and search engines; weights them by security, economic, and social importance; compares resilience across categories; and calculates an overall resilience index.

References

  1. National Communications Commission (NCC), 2025 Communications Market Report (in Chinese), https://commsurvey.ncc.gov.tw/files/file_pool/1/0p336342530469870607/251201%20%20114年通訊傳播市場報告_網站上傳版.pdf ↩1 ↩2
  2. TWNIC, 2025 Taiwan Internet Report – Overall Usage (in Chinese), https://report.twnic.tw/2025/TrendAnalysis_internetUsage.html ↩
  3. CNA, “Experts: Submarine cables are Taiwan’s ‘digital lifeline’; 99% of bandwidth depends on them” (in Chinese), https://www.cna.com.tw/news/aipl/202501100036.aspx ↩1 ↩2
  4. Ministry of Digital Affairs, 2025 Analysis and Policy Report on Submarine Cable Damage in Taiwan (in Chinese), https://www-api.moda.gov.tw/File/Get/moda/zh-tw/kj9vSvBw5wUeqla ↩1 ↩2
  5. Taiwan Submarine Cable Map, cable status timeline , https://smc.peering.tw/ ↩
  6. Ministry of Digital Affairs, latest cable status (in Chinese), https://moda.gov.tw/major-policies/subseacable/1747 ↩
  7. Center for Technology, Science, and Energy, American Enterprise Institute, Beyond Infrastructure: Internet Ecosystem Resilience and the Public Good , https://ctse.aei.org/beyond-infrastructure-internet-ecosystem-resilience-and-the-public-good/ ↩1 ↩2
  8. Ministry of Digital Affairs, average submarine cable repair times in Taiwan (in Chinese), https://moda.gov.tw/press/bulletin/17998 ↩
  9. OFCA Hong Kong, press release (in Chinese), Internet Archive, https://web.archive.org/web/20070217181311/http://www.ofta.gov.hk/zh/press_rel/2007/Feb_2007_r4.html ↩
  10. MSN/CNA via Internet Archive, expert on 2006 quake cable damage (in Chinese), https://web.archive.org/web/20070210045300/http://news.msn.com.tw/cna/cna_full_text.asp?yy=07&mm=02&dd=08&name=000030 ↩
  11. Wen Lii, Facebook post (in Chinese), https://www.facebook.com/wen1949/posts/pfbid0C1juirBxeTdoaarQnzXpWBdR7C8xodHPJ3Ctrh93kF7hdeU6547KiC8SwRRvBjwfl ↩
  12. The Reporter, Undersea cable damage and Taiwan’s digital lifeline (in Chinese), https://www.twreporter.org/a/damaged-undersea-cables-raises-alarm-in-taiwan ↩1 ↩2
  13. TASA, LEO satellite (in Chinese), https://www.tasa.org.tw/zh-TW/missions/detail/Beyond-5G-LEO-Satellite ↩
  14. Taipei Times, TASA to launch six satellites from 2026 , https://www.taipeitimes.com/News/front/archives/2024/05/13/2003817776 ↩
  15. Federal Communications Commission, PUBLIC NOTICE: Actions Taken Under Cable Landing License Act SCL-00512 , https://docs.fcc.gov/public/attachments/DA-25-60A1.pdf ↩
  16. TWNIC, bandwidth registration checking system (in Chinese), https://map.twnic.tw/main02.php ↩
  17. Cary Stier, The economic impact of disruptions to Internet connectivity (Deloitte, Oct 2016), https://www.deloitte.com/content/dam/assets-shared/legacy/docs/perspectives/2022/economic-impact-disruptions-to-internet-connectivity-deloitte.pdf ↩
  18. David Conrad, Towards Improving DNS Security, Stability, and Resiliency , https://www.internetsociety.org/wp-content/uploads/2021/01/bp-dnsresiliency-201201-en_0.pdf ↩
  19. Lars Kröhnke, Jelte Jansen, Harald Vranken, Resilience of the Domain Name System: A Case Study of the .nl-domain , https://doi.org/10.1016/j.comnet.2018.04.015 ↩
  20. Jian Wu, Ying Zhang, Z. Morley Mao, Kang G. Shin, Internet Routing Resilience to Failures: Analysis and Implications , https://conferences.sigcomm.org/co-next/2007/papers/papers/paper25.pdf ↩
  21. Dan Pei, Lixia Zhang (UCLA), Dan Massey (USC/ISI), A Framework for Resilient Internet Routing Protocols , https://web.cs.ucla.edu/~lixia/papers/04IEEENetwork.pdf ↩
  22. Erin L. Murphy, Redundancy, Resiliency, and Repair: Securing Subsea Cable Infrastructure , Center for Strategic and International Studies, https://www.csis.org/analysis/redundancy-resiliency-and-repair-securing-subsea-cable-infrastructure ↩
  23. Internet Society Pulse, Pulse Internet Resilience Index , https://pulse.internetsociety.org/en/resilience/#about-the-internet-resilience-index ↩
  24. Charles Mok, Kenny Huang, Strengthening Taiwan's Critical Digital Lifeline: An Analysis of Taiwan's Undersea Cable Network Resilience , Stanford Global Digital Policy Incubator Cyber Policy Center, https://fsi9-prod.s3.us-west-1.amazonaws.com/s3fs-public/2024-08/undersea-cables-mok_huang-v4.pdf ↩
  25. Aqsa Kashaf, Jiachen Dou, Margarita Belova, Maria Apostolaki, Yuvraj Agarwal, Vyas Sekar, A First Look at Third-Party Service Dependencies of Web Services in Africa , Carnegie Mellon University, Princeton University, https://netsyn.princeton.edu/sites/g/files/toruqf3201/files/documents/pam23_0.pdf ↩
  26. Rashna Kumar, Sana Asif, Elise Lee, Fabián E. Bustamante, Third-party Service Dependencies and Centralization Around the World , Northwestern University, https://arxiv.org/abs/2111.12253 ↩1 ↩2
  27. Aqsa Kashaf, Vyas Sekar, Yuvraj Agarwal, Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident? , https://doi.org/10.1145/3419394.3423664 ↩
  28. Victor Le Pochat, Tom Van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczyński, and Wouter Joosen, Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation , Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS 2019), https://doi.org/10.14722/ndss.2019.23386 ↩
  29. Yasin Alhamwy, Paul Mertens, Oliver Hohlfeld, Poster: Web Dependency Analyzer to Identify Resource Dependencies and their Impact on Rendering , https://doi.org/10.1145/3646547.3689683 ↩
  30. Remi Hendriks, Matthew Luckie, Mattijs Jonker, Raffaele Sommese, and Roland van Rijswijk-Deij, LACeS: An Open, Fast, Responsible and Efficient Longitudinal Anycast Census System , Proceedings of the 2025 ACM Internet Measurement Conference (IMC '25), https://doi.org/10.1145/3730567.3764484 ↩1 ↩2

The Mathocalypse

Hacker News
scottaaronson.blog
2026-10-07 15:42:14
Comments...
Original Article

The Mathocalypse

October 7th, 2026

Last night my 9-year-old son was taunting my wife, complexity theorist Dana Moshkovitz , as follows: “mommy, I heard you got cooked ! I heard that a robot solved the math problem you worked on for your whole career! OOF!”

While my son was being a brat, he also wasn’t wrong. Whether you’re thrilled, depressed, angry, or whatever else about it, yesterday was surely one of the biggest days in mathematical history. And yes, among the 372 huge results released yesterday by OpenAI , on the recommendation of its advisory group of Timothy Gowers, Edward Witten, and other distinguished mathematicians, was a proof of Subhash Khot’s Unique Games Conjecture (UGC) , a statement that my wife has worked toward proving for the entire time I’ve known her. (The UGC implies that a whole slew of optimization problems really are NP-hard, even if you just want an approximation that’s slightly better than what you get from semidefinite programming relaxation, which is one of our main tools.)

Or at least, we’re pretty sure that it’s a proof! There’s a Lean certificate , as there are for some of the other 372 breakthrough results (not all of them). But it also appears that no human has understood just about any of these proofs yet; the race to do so has just started. If you want an on-the-ground sense of what that race is going to be like, here’s some of what Dana texted me last night:

It feels like something written by someone who’s on psychedelics. So much unclear and doesn’t make sense. Lots of name dropping of previous work without discussing why it can be used despite impossibility results

Basically the paper is so horribly written that it’s impossible to read it without AI help

I asked Astra for reasonable completeness and soundness claims of the noise gadget and it gave them by combining claims from all over the paper

They also have direct optimal NP hardness of approximation proofs for the main applications of the UGC (Max Cut and all CSP) that bypass the UGC.

The UGC proof invents a completely new bizarre code with a noise test. It’s some crazy recursive construction.

It’s not the long code, not the short code – some alien craziness

I still think that there maybe is a proof that uses the half space code (which is natural)

The citations are often irrelevant and confusing

A possible future is a math world that’s heavenly if you have vision/creative ideas that AI could help check and implement.

And of course there’s a lot for us to learn from the aliens

If you’re wondering what emotions Dana is feeling—well, probably all of them! Even while a central career aspiration has fallen to a robot, there are at least two mitigating factors for her. First, she can feel vindicated that the UGC was true after all, something she never doubted even while many of her colleagues did! Second, all of us in math and theoretical computer science and mathematical physics, at least those who cared about solving crisply-stated problems, are now in the same boat.


Besides the Unique Games Conjecture, here’s a small sampling of the treasures from Aladdin’s cave that I’ll probably be paying the most attention to over the coming weeks:

Any of the above, alone, could easily have been “result of the year” in some area (and in some cases, like Unique Games and L=BPL, in all of CS theory). And there’s a lot that I’ve left out—feel free to share in the comments whatever is making your eyes bug out! There are equally astounding wonders in number theory, combinatorics, algebraic geometry, analysis, and pretty much every other area of math, most of which I’ll never understand, although I’ll note that it includes partial progress toward the Riemann hypothesis and the Hodge Conjecture and the Birch-Swinnerton-Dyer Conjecture (i.e., the majority of the remaining Millennium Problems).

We can take solace in what’s missing from the list. P ≠NP isn’t there, nor even P=BPP or NEXP⊄P/poly, and surely not for lack of trying. Apparently the greatest open problems of theoretical computer science are indeed pretty hard!


Oh, lest I forget: one day before the OpenAI dump, meaning Monday evening, Virginia Williams and Josh Alman posted an arXiv preprint that solves the 3SUM problem in O(n 1.9992 ) time, and the All-Pairs Shortest Paths problem in O(n 2.9995 ) time, refuting half-century-old conjectures that the correct answers were n 2-o(1) and n 3-o(1) respectively. In this case, it wasn’t an OpenAI model that supplied the crucial idea; it was an Anthropic one! But Anthropic then took a different approach from OpenAI: rather than post the undigested solutions to the world, it gave Virginia and Josh the opportunity to write and announce a digested version in exchange for compensation.

These have emerged as the two main models for communicating AI math breakthroughs, and they both have strengths and weaknesses. The “OpenAI model” sets up a crazy race among humans to digest and explain a messy AI proof (work that could easily be some combination of thankless, barely-credited, competitive, and unfun), while the “Anthropic model” puts a private company in the position of picking and choosing which human mathematicians get to be the emissaries of the AI. Dunno, what do you guys think?


For those who are wondering: apparently, the AI model that produced all these wonders was not bespoke contraption of 10,000 agents burning millions of dollars worth of compute, as was used for example to construct a finite-time blowup for the Navier-Stokes equations. Instead, it was simply the latest internal OpenAI model—one that might be released to paying ChatGPT customers within the next couple of months, depending on the recommendations of OpenAI’s safety board! (My 9-year-old son: “Oh they definitely shouldn’t release that. If it could solve all those math problems, it can’t possibly be safe.”) Apparently they used about 3 hours of GPT-Pro level compute on average per problem solved.

Also, if you were wondering: apparently they tried the model on about 8,000 problems. So, right now it “merely” solves ~5% of the longstanding open mathematical problems that it’s asked about, the problems that whole communities have spent years on, after a single 3-hour attempt on them.


I’ve been glad to see the CS theory community rising to the occasion. At the Simons Institute in Berkeley, here at UT Austin, and elsewhere, I’ve hearing stories of researchers rushing to pore over the manuscripts and make sense of them and explain them —because what else do we do? How else do we continue the craft to which we’ve devoted much of our lives?

If you want some sense of what things feel like now in math, imagine a hunter-gatherer who’s spent his entire life learning to survive deep in an unforgiving rainforest, then a giant resort hotel springs up right next to him with a helipad and heated pools and AirBnBs, and without missing a beat, the hunter-gatherer says: “alright fine, so now my new job is to run wilderness retreats for the tourists, or something.”

In Quanta magazine, Jordana Cepelewitz attempted a different metaphor :

It’s as if you were teleported to the peak of a tall mountain. Surrounded by fog, you have no idea where you are, or what’s around you. You do not know how your mountain connects to others, and you have no equipment to help you explore, no way to help someone else join you. If you had climbed the mountain yourself, you would have experienced how the human body adapts to altitude and changes in oxygen levels. You might have had to invent tools to navigate, to climb steep cliffs, or to make a shelter. You might have encountered a fellow explorer, gotten lost together in a hidden valley, and found a plant that could be turned into a life-saving medicine.

Instead you’re perched on the peak but in the dark, while the maker of the teleportation machine tells you that it can explore the wilderness better than any human.

For any one of these mountains, if we care enough, I feel optimistic that we can do as we always have: clear the fog and figure out the path, except now using the teleportation machine to help guide us. The bigger challenge will be to nurture a community that still cares about the heroic adventure of finding the paths up these mountains in the world with the machine. (Oh, and I think one place where the metaphor breaks is that we still do have each other, as much as we ever did before!)


Experience has shown that, even now , there will still be people explaining in patronizing tones why none of this is real and none of it counts. If such people were capable of being impressed by anything that happens in the empirical world, of updating on anything , they would’ve already been impressed and already updated several years ago, long before things had reached the point of an actual Mathocalypse.

So, they’ll say, maybe the alleged solutions are not solutions at all, but just “AI slop.” Or maybe none of the 372 well-known open problems that were solved were real math problems, they were all just glorified contest puzzles and trivialities. (After all, there’s still no Riemann Hypothesis!) Or maybe the entire 4000-year-old discipline of mathematics needs to be jettisoned: turns out that it was all just puzzle-solving and trivialities; all that’s different is that now the triviality stands unmasked. In any case, what really matters is that the true inner sanctum of human creativity hasn’t been breached and probably never will be, and also, that Sam Altman and Dario Amodei are contemptible little nerds.

If you’re still a proponent of that doomed worldview, still aboard the sinking ship, I encourage you in the strongest possible terms to read yesterday’s other great contribution to AI discourse, besides the OpenAI Mathocalypse dump: namely, Scott Alexander’s open letter to Steven Pinker . I feel some responsibility for this, as the person who first introduced Steven Pinker to the existence of the rationalist community, and who also first introduced Steven Pinker and Scott Alexander to one another (they had both been fans of each other’s writing). And now Scott is challenging Steve to a literal duel, with guns!

For whatever it’s worth: Steve is a lifelong intellectual hero of mine, just as he is for Scott, and I also have to privilege of calling Steve my friend. But I found Scott’s post to be one of the most devastating rejoinders to anything that I’ve ever read. And I thought Scott’s conclusion was exactly right: when it comes to AI risk, Steve’s great challenge is now to accept and start using a more “Pinkerite” epistemology.


Last night, while I should’ve been poring over some of OpenAI’s hundreds of papers and/or writing this post, I decided to spend some time with my kids instead. They wanted a movie night, so I suggested something they’d never seen before (and that I hadn’t seen for decades), and that seemed chock-full of no-nonsense, practical guidance for the world in which they’re going to grow up: Terminator 2 .

Posted in Uncategorized | 22 Comments »

My new course at UT Austin: AI Alignment Theory

October 4th, 2026

This semester, I’ve been teaching a brand-new course, entitled CS395T AI Alignment Theory. Here’s the course description:

The astounding progress of AI over the past decade has been accompanied by a rising fear: do we really understand how to align and control powerful AI systems—how to get them reliably to do what we wanted, or would want them to do on reflection, rather than merely what we said? If we succeed at building general-purpose superhuman intelligences along the current paradigm, should we expect that development to go well for humanity? Can we modify the design, training, monitoring, or scaffolding of those intelligences to help ensure that it goes well? While there’s been a great deal of recent empirical work touching on these questions, this course will concentrate mainly on theoretical and mathematical foundations. As a warning, the theoretical foundations of AI alignment have not yet gelled into any one coherent body of results accepted as canonical by the field. Nevertheless, in this course, we’ll read and debate many of the conceptual and mathematical works that have been most influential in the AI alignment field, from both before and during the current LLM revolution. Student presentations, reports, and projects will play a central role.

I vividly remember encountering Eliezer Yudkowsky and his Sequences 20 years ago. I remember thinking: even if these people talk and act like crazy cultists, still , let me bend over backwards to be epistemically virtuous, and entertain their ideas on their merits, as very few academics would. Even if, of course, I ultimately end up rejecting the ideas, on the simple ground that powerful AI is such an absurdly remote prospect that it’s almost impossible to say anything useful about it today, outside the realm of speculative fiction.

For my failure to see what was coming, it seems like an appropriate punishment that I’m now, in 2026, effectively teaching a course on Yudkowsky Studies. And it’s the most important course I can teach.

Well, for some definition of “teach.” The thing about AI alignment is that there’s no textbook (though apparently ILIAD is working on one), no core of nontrivial theorems considered canonical by the field, no real body of mathematical theory at all. This makes it extremely different from the courses I’m used to teaching, like Quantum Information Science or Computability and Complexity.

So we’ve been running the course as a discussion seminar. Every session, a “rapporteur” presents an AI alignment research paper or other reading; then I and others ask questions and discuss. Some of the readings (like Omohundro on the “basic AI drives,” or Hadfield-Menell et al. on the off-switch game) predate the current LLM revolution, while others (like the METR report on the HuggingFace incident or Dario Amodei’s “We Must Pace the Frontier” ) are so timely that they were only released while the course was underway. Most are somewhere in between.

I expected to have to make a case to students about why AI alignment is a pressing concern, why it’s no longer science fiction, etc. There was huge demand for the course, and while of course there’s a selection effect, the students who’ve shown up have been extremely engaged, sometimes criticizing the assigned papers for not taking existential risk seriously enough .

Perhaps unsurprisingly, we didn’t get that criticism about our very first assigned reading, which was Eliezer Yudkowsky’s 2022 essay AGI Ruin: A List of Lethalities —one the most canonical statements of what Eliezer believes and why that’s shorter than a book . Which brings me to the topic of the rest of this post! Our rapporteurs are not merely presenting the papers in class; they’re also submitting written reports about what the papers said, what their own thoughts were, and what were the highlights of the class discussion. And, with student permission, I’ll be sharing those reports on this blog!

So, without further ado, I present to you our first report, on Eliezer’s list of lethalities, by Tennyson Bardwell , who I thank for his work. Feel free to discuss in the comment section; some of the students might also chime in. Expect more reports here over the coming weeks.


“AGI Ruin: A List of Lethalities” by Eliezer Yudkowsky: Rapporteur Report by Tennyson Bardwell

UT Austin has a new Computer Science course this fall. Alongside familiar graduate-level classes such as Advanced Computer Networks and Convex Optimization sits CS 395T: AI Alignment Theory, taught by Scott Aaronson. This is one of a growing number of AI Alignment courses taught at academic institutions. Just as concerns over catastrophic consequences for misaligned AGI systems reach a broader public discourse, Eliezer Yudkowsky—one of the loudest voices in the field and author of the first assigned reading in Professor Aaronson’s course—is declaring the cause hopeless.

Thus, the students of AI Alignment Theory began their semester by reading a laundry list of critical problems in AI Alignment research, how failure to solve those problems will result in catastrophic consequences, and the reasons to be pessimistic about both past and future progress on these problems. The essay by Eliezer, titled AGI Ruin: A List of Lethalities and posted to his popular community-driven website LessWrong in 2022, is divided into three sections.

Section A roughly describes the magnitude of the AI Alignment problem. That is, the magnitude of the consequences for a complete failure to align an AGI system to human values before construction. It posits that AGI would quickly catch up to all human knowledge simply by learning from existing human productions (colloquially referred to as “eating the internet”) and then, nearly as quickly, begin to meaningfully surpass human knowledge. AlphaGo Zero is presented as a model both for how this might happen, and how it might be difficult to correctly predict beforehand. Many believed that AlphaGo’s success in the board game Go was chiefly attributed to its ability to learn from the extensive history of human-played games. Less than a year after AlphaGo beat the best human player, the successor system AlphaGo Zero surpassed the original AlphaGo. Unlike its predecessor, AlphaGo Zero was trained in just three days by exclusively playing against itself without seeing a single human game.

This quick ramp from AGI to super-intelligence would pose a different sort of problem than humans are generally used to dealing with. Unlike traditional problems in science and engineering, the consequence for a failed attempt might not leave room for another try. An intelligent entity with a misaligned goal would be well aware that it stands in opposition to humans, and might act deceitfully until in a position to act openly against humans without jeopardizing its own survival. Since most goals benefit from control of power and resources, it seems likely that nearly any goal-driven intelligence would have ample opportunity to be misaligned with human desires.

Section B describes reasons why, by default, any AGI that humans build using current methods is likely to be unaligned even if considerable attention is paid to the topic. This “current method” is gradient descent. That is, incremental progress with respect to some loss function which “punishes” a model for undesirable behavior. A notoriously elusive property of such trained models is the ability to generalize out of their training distributions. To train a primitive model to be aligned to humans might involve learning a great many behavioral rules. However, the sorts of rules needed to keep a drastically smarter agent in check might not always be relevant to simpler models (e.g., “do not emotionally dysregulate humans you speak with” might not be relevant to a simpler model that is less able to reliably get under the skin of humans it operates with, or which is assigned tasks in training which do not benefit from such anti-social behavior).

Eliezer focuses on the misalignment of humans with their creators (evolution or evolutionary pressures) as a critical data point for reasoning about misaligned intelligent systems. Despite being a generally slow process, evolution eventually created a runaway intelligent system (Homo sapiens) which proceeded to dominate the globe, decimate related species, and eventually (it is forecasted) effectuate population decline. That last development is arguably in opposition to the sole imperative demanded by evolution: to reproduce.

Section B also makes time for criticism of the most popular paths toward AI alignment, including interpretability (unworkable, and attempting to train on it evokes Goodhart’s law, incentivizing deceit), using multiple AIs to maintain a balance of power (it is not clear how multiple strong AIs unaligned with humanity results in better outcomes for the weak humans), and corrigibility (it seems impossible to motivate an AI system to effect outcomes without also motivating it to desire its own survival to effectuate said outcomes).

Section C describes a bleak state of affairs in which veterans in AI alignment are unsatisfied with current progress and do not have a plan to deliver tangible solutions before the advent of AGI systems. In particular, Eliezer describes recent results as showy but useless. He believes that even with additional funding, the lack of appropriate evaluation mechanisms will prevent the most effective researchers from rising to the top.

A summary of the landscape, as described by Eliezer, in the flowchart below.

Figure 1: A flow chart of (select) paths described by Eliezer in his essay. A common feature of this flow chart is that many “good states”—such as disabling a misbehaving AGI or choosing not to build an AGI—are not “final” states in the sense that they are not permanent solutions. Such a state merely represent the avoidance of a single potential disaster, rather than the emergence of a new stable world state. Hence, these nodes posses back-arrows.

Despite the bleak content, Eliezer’s colorful prose inspired a lively class discussion. Before this discussion started, a survey was taken of the class’s predictions for various outcomes of the AGI in the coming years (with the full results below in figure 2 ). This survey asked students for their opinion of a number of statements. Each of these individual statement, if true, would reduce concerns of catastrophic AI-driven disasters. For example, when asked “How much do you agree with the statement: Humans will choose to not build AGI” half of respondents said they strongly disagreed with high confidence ( agreement = 1 , confidence = 5 ). Students also generally disagreed with the statements:

  • “AGI will not be technically feasible in our lifetime”
  • “(hyper-)AGI will not make extremely obviously unethical decisions”
  • “No reason is individually sufficient, but taken together they provide justification to not fear AGI”

There was a divergence in responses regarding interpretability, corrigibility, and “other” AI alignment research. In the latter two cases, a plurality of respondents (about a quarter) agreed strongly with statements that such research would defang AGI ( agreement = 4 , confidence=4 ), while most other responses express various levels of agreement with low confidence. However, when asked about the likelihood of interpretability research defanging AI, the pessimistic voices were more united. A quarter of responses still expressed the same optimism, but roughly half expressed pessimism ( agreement ≤ 2 ) with half of those expressing at least moderate confidence ( confidence ≥ 4 ). Based on the following discussion, this might have been caused by more familiarity with interpretability research, including first-hand experience.

The only statement with general agreement was “(hyper-)AGI will understand human intentions better than we can code it.” However, it should be noted that no statement such as “AGI will respect human desires, as it understand them” was asked on the survey.

Figure 2: Class Survey Results; conducted before a class-wide discussion. Note that students were instructed to answer confidence = 1 when they had not previously considered the statement, to answer confidence = 3 when they felt there were strong arguments on both sides, and to answer confidence = 5 when they possessed well-considered resolve.

After the survey was completed, the results were displayed as an open discussion began. Similar to recent empirical research from frontier labs, interpretability research received more airtime than in Eliezer’s article. Students disagreed first about the definition of interpretability: whether it refers to the ability to interpret a model’s behavior solely by its weights, to interpration via repeated probing of the model in a sandbox, or whether it can also refer to the modern chain-of-thought traces. Regardless of how it was defined, however, participants were either pessimistic or very pessimistic about interpretability research broadly. One student criticized common misunderstandings of chain of thought. Rather than being a verbatim copy of the models internal dialog, it is instead a superficial summary of the complete thought state and routinely produced gibberish, such as rarely used Chinese characters in the middle of otherwise English reasoning.

A popular topic was the exact shape and speed of a recursive self-improvement loop. If it takes place slowly, then what might we learn from “near misses” such as the Hugging Face incident? The number of near misses we are able to learn from before AI possesses sufficient power to prevent further iterations could depend on this curve, with some students arguing that the sheer number of humans, as well as their default robustness in the physical world compared to AI systems means that AI-driven extinction events are still a long way off. Bolstering this “slow take-off” opinion are rumors that AI already plays a major role in model development which could be interpreted as the start of this process.

Some criticized a focus on “solving ethics” as a needlessly high bar that distracts from the more mundane tasks dominating AI alignment work. In particular, the student volunteer who presented this paper (and the author of this report) included a section on “Ethical Dilemmas” in their presentation. Among arguments against focusing on abstract moral philosophy, Professor Aaronson cites Eliezer to emphasize that any alignment at all is difficult, not just in morally gray cases:

When I say that alignment is difficult, I mean that in practice, using the techniques we actually have, “please don’t disassemble literally everyone with probability roughly 1” is an overly large ask that we are not on course to get.

In response, I argue that some examination of everyday decisions with a critical lens—such as telling white lies to loved ones or consuming animal products—can help disabuse us of the notion that goodness emerges in every sufficiently intelligent agent.

One of the most interesting discussions was about the difference between state-of-the-art LLMs and the theorized AI agents long discussed in rationalist discourse. Since current LLMs “mimic the human distribution,” they come preloaded with extensive understanding of human social norms and moral behavior. This makes constitutional alignment (the current practices of using system prompts to establish ground rules) extremely effective. This might either fundamentally change the orthogonality thesis, or provide a new tool to better approximate human judgment in complicated situations.

Of all the points made, the one I found most interesting was simply (paraphrased):

I think human-alignment is just very tractable

Here, “human-alignment” refers not to AI alignment with human values, but cooperation between different humans. More specifically, it refers to the ability for human societies to choose not to rush recklessly into larger-and-larger AI systems. In an academic course focused on the technical problem of AI alignment, this was a reminder to not completely discard policy discussions in the believe that they lack any value. After all, many destructive technologies have been previously contained by international agreements. Notable examples include nuclear weapons and engineered plagues. However, even this was a contentious topic. The main criticisms were (1) the extreme “dual-use” nature of AIs for both peaceful growth and warfare, and (2) the greater danger for AI escapes even after taking precautions to prevent it. However, in the interest of ending on an optimistic note—unlike the assigned reading—it is on this belief in human cooperation that I will leave you.

Posted in Adventures in Meatspace , Announcements , The Fate of Humanity | 75 Comments »

My “Knowmads” podcast on science and AI

September 28th, 2026

Or click here if the above doesn’t work.

Recorded in-person in my office at UT Austin, with a bulleted list containing “ARC,” “Scalable Oversight,” and “Models” behind me on my blackboard for some reason (I no longer remember who put those there or why). 90 minutes long. Sometimes you see my disembodied arm waving in midair because of the way the cameras are combined. As always, I strongly recommend 2x speed for the correct experience.

This might actually be one of my best podcasts ever, although I wasn’t planning on that! Thanks so much to Bhavay Tyagi and Prachi Garella for driving all the way from Houston to record it.

Here’s a strict subset of the topics we covered:

  • The story of AI models solving the Navier-Stokes Millennium Problem, insofar as it’s known
  • Can recent AI proofs be called “truly creative”?
  • The history of AI before the LLM revolution
  • What do we mean when we call LLMs “black boxes”?
  • The achievements of the field of interpretability
  • What exactly happened in the OpenAI/HuggingFace incident
  • Must we avoid all “anthropomorphizing language” when discussing the HuggingFace incident? (spoiler alert: no)
  • Examples of major open problems in quantum computing theory that I cared about for decades and that AI models have recently solved
  • Effects of the current AI cataclysm on the math community, especially students
  • What annoys me the most when I listen to AI talks
  • My experiences at OpenAI, why they hired me, and the watermarking work that I did there

Enjoy!

More AI-related content coming soon, as this blog—like much of the rest of the world—continues its transition to “all AI, all the time” (except still 100% written by an aging, deteriorating biological brain)


And for those who just can’t get enough of my rocking back and forth, using too many filler words, as I explain theoretical computer science! Here’s a second podcast, this one mainly on quantum computing, with Seb Agertoft, who I thank for doing it. Enjoy!

Posted in Announcements , The Fate of Humanity | 58 Comments »

Theory Beyond Theorems and Proofs: A Guest Post

September 19th, 2026

Scott’s foreword: I’m extremely grateful to my brilliant colleagues, Pravesh Kothari , Raghu Meka , and Prasad Raghavendra , for sharing the guest post below about how theoretical computer science (and in particlar, the STOC/FOCS/SODA conferences) should evolve to deal with the AI asteroid that’s right now slamming into our field, at least as we human theorists have practiced it since its inception. While Pravesh, Raghu, and Prasad speak only for themselves, not for myself and not for the theory community as a whole, I found their proposal of a separate “conceptual track” to be an excellent starting point for further discussion. –SA


Considering the pace of developments in AI theorem provers, most would concede that the following scenario is at least plausible in the very near future:

AI theorem provers could prove well-specified mathematical claims, even many well-studied ones that have been open for years, in a matter of hours. Moreover, these systems could be widely available to consumers at nominal cost.

As TCS researchers, let us pretend that the above scenario has come to the fore, and ask ourselves: What is our role in such a world? Does it mean the end of theory research?

As we ponder this question, let us ignore all of these other confounders:

  1. Recent controversies surrounding the developments on the Millennium Prize Problems
  2. Motivations and actions of the AI companies
  3. Observed faults in existing AI systems when it comes to writing, exposition or attribution to previous work.

None of the above confounders have any impact on our answer to the question: What should theorists do, in the presence of superhuman AI theorem provers?

Notice that we use the term “AI theorem provers” instead of just “AI”. We believe that this conceptual distinction is important as we consider this question.

At the outset, we would like to admit that for a generation of theorists like us (and many from earlier), research was mainly centered around problem-solving. Even when we developed conceptual insights, it was mostly in service of answering well-specified long-standing questions. We don’t intend this proposal as judging one form of research to be better than others; it only reflects that AI theorem provers accelerate a certain type of research activity and want to make the best of it. There is also a tremendous human cost of this upheaval, which is perhaps a more important question, and one which this proposal does not address directly (we do not have any good ideas as such). Similar points have also been made in various contexts
before, but the timing now is more pressing.

Definitions, Questions & Theories:

The goal of any theoretical science is to advance human understanding of observed phenomena. Apart from theorems and proofs, a theoretical science has definitions, questions, and theories.

Definitions identify the objects to observe. Curiosity and context drive the questions to ask. Theories explain the phenomena observed. We believe humans will continue to play a central role in generating definitions, questions & theories, even in the presence of a super-human AI theorem prover.

Definitions: Could an AI define randomness extractors, streaming algorithms, or zero-knowledge proofs? Maybe. But there are some reasons to believe, humans will still have a big role to play in coming up with definitions.

For instance, the notion of extractors arises from the real-world problem of lacking perfect random sources. Zero-knowledge proofs seem to arise purely out of human curiosity, guided by taste. Human context and curiosity will continue to drive theoretical research. After all, we get to decide what objects we choose to observe!

Theories: Consider the following thought experiment. Suppose in 1965, we had a magic machine that at the press of a button, given any computational problem, would tell us if it had a polynomial-time algorithm or not.

Would that have been the end of computational complexity theory? No. Humans would find it entirely unsatisfactory, and ask, why do these problems not have a polynomial-time algorithm? Why do these others have?

The theory of NP-completeness identifies some patterns among problems that don’t seem to have efficient algorithms. This theory would still be a crown jewel of theoretical computer science, even in a world where we had a magic machine to tell if a problem had an efficient algorithm or not, at the press of a button. Similarly, if we had a machine to predict whether a CSP is NP-complete or in P, we would then ask: what makes 3-SAT NP-complete, while 2-SAT is in P? This question leads to the theory of polymorphisms, which yields a satisfactory answer.

Theories aren’t just succinct or efficient mechanisms to answer questions. The best theories provide are those which humans deem to be a “satisfactory explanation” – whatever that means.

Finally, even as the capabilities of AI theorem provers advance, human curiosity will probe grander and deeper questions. Previously, even if we wanted to build new models and theories, proving something about them was a prerequisite, and given that the grand questions were already at the limit in long-studied domains, we had to scale things down. If each theorem proven by AI is treated as an experimental datapoint, humans can ask grander questions that look for patterns across these theorems.

A concrete proposal:

We think theorists should embrace these AI theorem provers in our research. To a certain extent this is already happening explicitly or implicitly.

As theorists, we have been parsimonious in introducing new models or asking entirely new questions, and careful about adopting new ones too quickly. This was partly because formally proving the properties of a new definition or a model was an onerous task that could take a decade, and tens of papers. AI theorem provers might completely change this dynamic. This is precisely the moment to refocus our work on definitions, questions, and theories. We need explicit systems to encourage and reinforce these parts of theoretical research. You might also say the next generation of AI models can do this; it may be so, but we believe you have to take the current opportunity.

To this end, we suggest that STOC/FOCS/SODA create a separate track of papers. This track is meant specifically for papers that introduce new definitions, ask novel questions or build explanatory theories. The papers in this track are short, say less than 10 pages. Papers may, and should, contain theorems as usual and as needed. Most importantly, the radical shift is that the papers need not contain the proofs of the theorems. Instead, the authors supply a Lean certificate as a supplement to the paper. The evaluation will also in a sense “orthogonalize’’ against the difficulty of these proofs.

The papers in this track should be judged exclusively on the conceptual merits, completely agnostic to the difficulty of the proofs.

Reviewing must be completely agnostic to the proof for two reasons. The main track at STOC/FOCS already includes papers in the former category. Second, a major barrier to producing truly novel conceptual papers is that they often get judged poorly for a lack of technical depth in their proofs. We think these two aspects separate it from (ITCS/SOSA) and, regardless, it’s something we urgently need for all our conferences, including STOC/FOCS (the ‘flagship’ conferences).

To be clear, we ourselves admit that we need to hone these skills of making new definitions, asking deep and interesting questions or building new theories. A separate track of conceptual papers will provide a systematic mechanism for both junior and senior researchers, and the field as a whole to do so.

We believe that upcoming generations of grad students will tackle research directions that seemed completely out of reach to us. We just need to set up systems that nurture new ways of doing research in theory.

— Pravesh Kothari, Raghu Meka, Prasad Raghavendra.

Posted in Complexity , The Fate of Humanity | 104 Comments »

The Age of Wonders and Terrors

September 15th, 2026

Twenty years ago, when the idea of AI taking over the world in our lifetimes still struck most of us as the unconstrained fantasy of those who knew too much science fiction and too little science, many of us would say things like:

Look, the part of the story that’s wildly implausible is that a recursively self-improving superintelligence will just explode from some hacker’s basement and take over the world without warning. If it’s going to happen, we’ll see many warning signs first. We’ll see, I dunno, AI agents breaking out of containment, conspiring with each other to hack websites, in fanatical pursuit of whatever strange goals they have. And then, of course, we’ll see major math problems getting solved by AIs—even the Clay Millennium Problems. That will be the time to panic! Wake me up when that happens!

Twenty years ago, the above was a take that even my most conservative, skeptical colleagues in academic CS would’ve gladly endorsed.

If you want to know my current take, you simply start with the one above, then update on the fact that the wild prophecies have come true . The first rumblings, I’d say, came a decade ago with AlphaGo, they got noticeably louder with LLMs and coding and reasoning agents, and they’ve accelerated this summer and fall into a crescendo of wonders and terrors that one needs to be a particular kind of idiot to deny.

I recoil from the neverending shell game where you say “oh sure, of course AI can now [escape from its sandbox / solve Millennium Problems / whichever dramatic thing it most recently did], no one ever denied that [I did deny it], wake me up when AI does [thing AI hasn’t yet done but is going to do next year], that’s when I’ll reevaluate my whole worldview [no I won’t].” Where no matter how fast the rollercoaster accelerates, even after your whole familiar world has vanished behind you, you’re still inventing reasons why it doesn’t count.

My position on AI is merely the conservative, skeptical position of 2006, updated with intellectual honesty for the reality of late 2026. And that position, if you need me to spell it out, is as follows:

AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA

It seems to me that the Singularity has already started ; it’s just wildly unevenly distributed. Yes, I still unload the dishwasher and clip my toenails. On the other hand, in whatever years I have left, I don’t expect that I’ll ever again prove a theorem because I’m actually needed to prove it. If I do, it will only be for my or others’ enjoyment or edification.

The test is this: if we took the news of these past few weeks and sent it back in time twenty years, would I agree that it looked like the beginning of an AI Singularity? The intellectually honest answer is: yes, absolutely. But then that’s all we need. No backsies.

I feel like it would be healthy for everyone to stop grinding their ideological axes, their sentiments about Dario Amodei or Sam Altman, for long enough simply to acknowledge that the wonders and terrors are here . They couldn’t be here more clearly if the sky had turned reddish-orange like in the Matrix movies.

It’s here clearly enough that, when I put my kids to sleep at night, I now feel it in the pit of my stomach: what sort of future can they possibly have? What could they learn today that could possibly be relevant to that future? (Yesterday, my 13-year-old daughter joked unprompted that, if she wants to become a mathematician, it now looks like she has maybe two more weeks.) Certainly when my grad students want to discuss what sort of careers might await them on graduation, I no longer have any clue what to tell them.

Maybe it will help if I briefly switch topics. Ever since my wife and I moved to Austin, I’ve sometimes gotten some version of the following query: “How can you, as both a Jew and a skeptical scientist, possibly get along well with all those evangelical Christians down there in Texas? Sure, they might seem super friendly to Jews, but don’t you understand that that’s only because of the special role Jews play in their eschatology—when Christ will return in glory, and you’ll either accept Him as Lord or else roast in hell for eternity?” I stare at them and say: “wait, so I get to accept Christ only after He returns? What a great deal! How could I possibly have any objection to that?”

For anyone who says AI doom sounds like an apocalyptic religion, that the rationalists/Singulatarians seem like a Bay Area cult, that Eliezer Yudkowsky gives off the vibes of a messianic prophet: yes, yes, and yes. But crucially, today you’re no longer being asked to believe in arguments and extrapolations, but only in the front-page news. Accepting the reality of the coming machine god after it’s solved Navier-Stokes and dozens of other longstanding open math problems (while dramatically ramping up in capability every month), is sort of like accepting Jesus after he’s returned to earth on the gleaming cloud. It’s the epistemic bare minimum.

Yes, there’s still enormous uncertainty about what the rest of our lives will look like, but as far as I can tell, there’s no longer any real uncertainty that it’ll all mostly revolve around AI, and the extent to which we succeed or fail at directing its power toward human flourishing.

By any accounting that doesn’t stack the deck, Eliezer Yudkowsky was right about what the greatest challenge facing civilization in our lifetimes was going to be, and you and I were wrong about it. Why I was wrong is a question I’ll ask myself every day in whatever time remains. But, you know, at least I updated once the prophesied wonders and terrors actually started arriving! If you haven’t done likewise, why haven’t you?


As you presumably know by now—it was the talk of the nerd internet all week—the Navier-Stokes Millennium Problem appears to be solved , with crucial contributions from both humans and AI, albeit with a tangled dispute about exactly what happened and what ought to have happened. The answer, which an OpenAI model has apparently verified in Lean, is that (as many mathematicians suspected lately) there’s smooth initial data that leads to a singularity in finite time, at least if a smooth external force is applied (the case with no external force is still unresolved). This problem was supposed to carry a $1 million prize, except that OpenAI says they have no interest in collecting the prize and it’s unclear if any human is eligible to collect instead. OpenAI burned at least ~$15 million in compute to produce its 166-page solution , which probably hasn’t yet been read and understood by any human.

See here for the Quanta article , and here for NYU mathematician Tristan Buckmaster’s account of the role played by himself and Levent Alpöge of Anthropic, which substantially differs from OpenAI’s account (you can read a response from OpenAI’s Sebastian Bubeck here ). It’s agreed that everything built on an approach pioneered in recent years by the human mathematicians Diego Córdoba and Luis Martínez-Zoroa.

My purpose here is not to adjudicate the dispute. Yes, in swooping in with vastly greater resources once it had gotten wind of progress on Navier-Stokes, OpenAI seems to have acted in a way that some might describe as “unsportsmanlike.” No, I don’t find it plausible that OpenAI’s models meaningfully benefitted from being trained on Buckmaster and Alpöge’s chat logs. But this leaves a crucial question unanswered: what exactly did OpenAI know about Buckmaster and Alpöge‘s work and when did it know it?

Anyway, as Zvi points out , it’s easy to get hung up on the details and lose sight of the high-order bit: namely, that it seems safe to say that human mathematicians are forevermore dethroned as the main theorem-proving entities on planet earth. I feel privileged to have had the traditional kind of career in theoretical computer science in the last decades when that was possible.


If we were just talking about Navier-Stokes, you might accuse me of jumping to conclusions here. But we’re not. In the areas I know best (such as quantum complexity theory), and presumably other areas as well, there’s now a deluge, with longstanding open problems both major and minor falling by the day.

Go to the arXiv or ECCC . Pretty much all the papers that I’d be interested in now include “AI statements” near the acknowledgments (as this is often the central thing I want to know, I wish I didn’t need to scroll to the end of the paper to find it!). These statements can range from “our main result came entirely from GPT-6, but we understood it and take responsibility for it,” to “the results came from an interaction between the human authors and AI” to “we used AI, but only for proofreading and other incidental things” to (mad props!) “ the author did not use AI for anything .”

If you talk right now to editors or program committee chairs, it’ll remind you of those ominous scenes from the Lord of the Rings movies where the men of Gondor or Rohan or whatever are grimly fortifying their walled city against the expected onslaught of 50,000 orcs. Reviewing will have to be done partly by AI, because otherwise there’s no way to handle the orc army: the reviewers can’t unilaterally disarm.

Anyway, here’s a small sampling of the significant AI-proved or -assisted results from, like, the last month , besides Navier-Stokes—restricting myself to those that solved longstanding open problems I had previously known or cared about.

  • Of course, the counterexample to the Jacobian conjecture, announced by Levent Alpöge in a now-famous tweet : “hello there the jacobian conjecture is false thanx to my close friend akhil for asking about it and my other close friend fable for working during the world cup final” (followed by a listing of the counterexample)
  • Improved bounds for Grothendieck’s constant (led by friends and colleagues of mine at UT Austin)
  • A Lean-verified proof of Fermat’s Last Theorem
  • Quantum oracle separation between QMA and QMA(2) , and proof of Watrous’s disentangler conjecture, a problem that I and others popularized back in 2007—by a list of authors including my recently graduated PhD student Sabee Grewal
  • A proof of perfect completeness for QMA , from (again) Sabee Grewal and Dorian Rudolph, solving a decades-old open problem that I studied back in 2009
  • An improved upper bound for shadow tomography of quantum states , from Chen, O’Donnell, Pelecanos, and Wright, improving the dependence on the Hilbert space dimension d from log(d) to √log(d). (When I introduced shadow tomography back in 2017, I raised the question of whether the dependence on d could be eliminated entirely, while preserving polylogarithmic dependence on the number of measurements m.)
  • Progress on the Aaronson-Ambainis Conjecture (the version that talks directly about quantum algorithms), basically showing that it holds for quantum algorithms that make their queries in a small number of parallel rounds. ( Update: Nope, sorry, Jordan Docter points out to me that this one was pre-AI, with AI used only for proofreading and other incidental things!) This was independently achieved by Liu and Mutreja, making more substantial use of AI.
  • According to rumors that I’ve heard, solutions to some very longstanding open problems in theoretical computer science (no, not P≠NP or other complexity class separations, but think about some of our other biggest problems). I’m told that the AI companies, having been burned by the hostile response to the Navier-Stokes proof, are now sitting on solutions to some very major problems until they figure out a better way to handle things

Feel free to remind me of anything I left out.


Let me try to convey the mood in the mathematical community right now, at least as far as my experience reaches. Nearly every conversation is about the AI tsunami, or eventually circles around to the tsunami even if it’s originally about something else. Often, though, the focus is less on the unknowable future—for how much longer will mathematical research as a human enterprise even exist?—than on immediate questions of how to respond .

What are the new rules for when you get to write a paper with your name on it, and, y’know, get credit for it? That you fully understand the proof, can give talks about the proof, can answer questions about it, take responsibility for its correctness? Do you need to have played any role in finding the proof?

In the cases, likely to become more and more numerous, where all of those conditions are not satisfied, how do you share AI-generated math, if at all? Do you tweet it, like Alpöge hilariously did with Fable’s disproof of the Jacobian Conjecture? Do you post to the arXiv or GitHub? Do you publish a paper that lists “GPT-6 Astra” or “Claude Fable” as the author—but then let the AI profusely thank you in the acknowledgments for suggesting such a wonderful problem to it?


Of course, how one responds to the immediate problems ultimately does depend on one’s broader beliefs about what mathematical research is for and about. Are we just trying to decide whether various conjectures are true or false? Or are we trying to maintain a human community, across the generations, that understands the conjectures and cares about whether they’re true or false and why? If the latter, how do we incentivize people to join that community, to undergo the years of intense training required, if their role will now be reduced to verifiers and explicators (if even that) of gargantuan arguments dumped into their laps by the AI companies?

As many of you will have seen, twenty-five Fields Medalists, including Terence Tao, released an open letter entitled A Severe Misalignment of AI in Mathematics , which articulates some of these concerns in the wake of the Navier-Stokes announcement. As many critics have pointed out, the open letter doesn’t really have a clear ask: mostly, it just eloquently sets out the values of the human mathematical community that the authors consider worth preserving in the age of AI. After reflection, I decided to endorse the statement, because I want to preserve those values as well.

I don’t think any of the signatories are naïve enough to imagine that AI won’t permanently change the way mathematical research is done—indeed, that it isn’t already doing so. There’s surely at most a tiny market for “certified organic theorems.” That isn’t the question. The question is, do we incorporate AI in a way that still puts human understanding, of what either humans or AIs are producing, at the center of the whole enterprise? Maybe someday, it becomes unsustainable to do that. Maybe someday we say: “human math had a great 4,000-year run, but today we close up shop and turn everything over to the machines, continuing to apply our own brains to math, when we do, at most for exercise, recreation, or competition, like chess.”

But, partly because of my worries about AI misalignment, I’m not ready to throw in the towel just yet. I still do want to keep insight and understanding at the center of what mathematicians, computer scientists, and physicists do, for as long as we can keep it there, even as the human race now cedes its supremacy at the task of proving or disproving conjectures.


Speaking of alignment: if you’re any kind of mathematical researcher, and the present age of wonders and terrors has inspired you to want to spend your remaining time confronting the tsunami head-on, rather than pretending it doesn’t exist or is still far away, please join your dozens of colleagues who’ve arrived at the same place!

My friend and colleague Mike Winer was trained as a theoretical physicist, did a postdoc with Juan Maldacena at the Institute for Advanced Study in Princeton, but then got AGI-pilled and decided to switch to full-time work at the Alignment Research Center in Berkeley (founded by Paul Christiano , who moved to AI alignment a decade ago after doing quantum computing theory with me). Mike recently wrote a Substack post entitled From Academia to Alignment , which I enjoyed and which I’d commend to anyone currently considering this transition.  In a similar vein, see this from Xiaoyu He.  And, one more: a meditation on mathematicians’ possible future as priests or monks , by Stanford math undergrad Logan Graves.

Posted in Announcements , Complexity , Quantum , The Fate of Humanity | 262 Comments »

9/11 in Berkeley

September 11th, 2026

Note: Of course I’ve been glued all week to the dramatic developments in AI. I’m working on a post about them. I’m not good at reacting to things in a timely way. So today, I’ll do my post marking the tragedy a quarter-century ago that we all commemorate. Please feel free to share your 9/11 memories in the comments. Also, Shana Tova to those who celebrate!


The morning of September 11, 2001, I was a second-year PhD student at Berkeley, who woke up late in his dorm room at International House, after a long night spent closing in on the proof of the quantum lower bound for finding collisions.

Rolling over to my laptop, I saw a flurry of weird emails, including one from Prof. Christos Papadimitriou saying that “we’re a community, and we’ll all support each other,” and another from Prof. Luca Trevisan (whose algorithms course I was then TA’ing) saying “on a day like this, it’s impossible to think about algorithms. Class is cancelled.”

Confused, I clicked over to the New York Times and saw the picture of the burning towers, and read numbly about what was already over by the time I’d woken up. I checked in with my mom, made sure relatives and friends in the NYC area were OK. My dad was at a company event in Atlanta, and would need to drive home because of the national grounding of flights.

One of my earliest memories in life, from age 5, is of ascending to the top of the World Trade Center. Growing up an hour’s drive from NYC, it wasn’t an exotic place to me.

I soon learned that one of the dead was Danny Lewin , the ex-IDF captain, theoretical computer scientist, and cofounder of Akamai who had his throat slashed on one of the planes while trying to fight the hijackers, making him the day’s first casualty, even while Akamai’s technology was part of what kept news websites running that day. I’d never met Danny but already knew many people in common with him. A few years later I’d be humbled to win the student paper award that was named in Danny’s memory.

Anyway, at Berkeley on 9/11, I wandered over to Soda Hall just to be with other people. A few students showed up for office hours, wanting help with their algorithms homework, which I found hard to believe, but I did my best to concentrate, as the computer screens around me showed the burning towers.

That evening, I went to a vigil for the victims in Sproul Plaza. But the “vigil,” such as it was, quickly dispensed with mourning and prayers and turned to applauded speeches about how the US must respond with love rather than war, and must turn the other cheek. Meanwhile, a student communist organization was handing out flyers explaining that the victims were mostly “wealthy capitalists and the workers who tried to rescue them.” This while smoke still blanketed NYC and the desperate search for survivors continued. I left the vigil early.

Until that day, I had thought of myself as basically a “leftist,” one whose #1 issue was the existential risk of climate change. Sure, I disagreed with my fellow leftists about issues from nuclear power to gifted education to Israel, but those were just intra-left disputes.

The year before, I had created the website “In Defense Of NaderTrading,” in a desperate attempt to intervene in history and cause Al Gore to become president rather than George W. Bush. When Bush “won,” by the infamous 537 votes in Florida, I considered it a victory for horribleness that would never be surpassed by anything else in my lifetime (ha). I couldn’t imagine any politician who was more the antithesis of everything I believed in than Bush. This view, of course, did not particularly stand out at Berkeley.

In the days after 9/11, though, it became obvious that I could not be a “leftist” in the Berkeley sense. Some of my fellow students felt that Osama bin Laden made a lot of great points, that the attacks were basically justified, and that at any rate, we in Amerikkka had done much worse to provoke them, including by supporting the genocidal settler-colony called “Israel,” which for all we know secretly masterminded the 9/11 attacks anyway (although again, if bin Laden had done them, he would’ve been justified).

Around the same time came the Second Intifada, when a wave of suicide bombings in Israeli buses and pizza parlors and university cafeterias thrilled and energized some Berkeley students to the extent that they took over a Holocaust Remembrance Day event with bullhorns to make it about the Nakba, smashed the windows of the Hillel building, and beat up a couple of students wearing kippot. That was how thoroughly anti-Nazi they were.

I finished my PhD at Berkeley in 2004 having learned about more than quantum computing. I’d learned that, while American academia had pockets that truly were crucial refuges and oases for nerds like me, it also harbored people who would gladly see me and my relatives and my fellow Americans killed for the sake of their ideological vision. And I’d learned that I had my own ideological vision, which was that such people could go fuck themselves.

It deeply pained me to be on the same side of anything as George W. Bush — especially because I knew that 9/11 had happened on his watch, that he had ignored all the warnings, and that he was grossly incompetent to manage the resulting wars against jihadism (just how incompetent, I didn’t know at the time). But as flawed as Bush was, I knew that I wanted to preserve rather than destroy the civilization of which he was a temporary steward. And I think the value and fragility of our civilization is the main lesson from that day that I’d like to convey to my kids, for whom of course 9/11 is just another historical event to learn about in school, like the Boston Tea Party or the Alamo.

Posted in Adventures in Meatspace , The Fate of Humanity | 40 Comments »

LLMs and self-referentiality

September 1st, 2026

I woke up yesterday with the following thoughts, which are probably either obvious or dumb.

A central thesis that many readers, including me, took from Douglas Hofstadter’s Gödel Escher Bach when young was that the secret of intelligence (and therefore, of AI) was going to have a lot to do with self-referentiality and “strange loops.”

Even Roger Penrose’s The Emperor’s New Mind , which in some ways was the anti-GEB, ironically agreed with GEB about the fundamental importance of self-reference to the success or failure of the whole AI project. It claimed (incorrectly, in my view and in most experts’) that AI could never work because there was something about Gödel’s Theorem and self-reference that no computer program could ever capture, but that could be captured by exotic physics accessible to the human brain.

Now, in 2026, we’ve succeeded at building AIs that outperform most humans at most intellectual tasks that are well-defined enough to judge. And at no point in the tech stack of those AIs — neither in the transformer neural nets, nor in the GPU clusters they run on, nor in the training process, nor anywhere else — did anyone need to build in anything about self-reference. (Excepting, eg, the system instructions that tell the model about its role and identity, which aren’t needed for intelligent behavior. Also, I’m not going to count the autoregressive nature of LLMs as “self-referential”; that’s just dynamical feedback.)

Of course, GPT 5.6 Pro and Fable can talk about themselves, about Gödel’s Theorem, about self-reference, about what we’re talking about right now, all of it, better than most humans. But at no point did anyone need to build self-referential abilities in. They popped out as a byproduct of the same pretraining that let the models talk about Pokémon and long-chain polymers and cognitive behavioral therapy and plate tectonics and everything else.

No wonder Hofstadter says he’s been stunned by the success of LLMs, and has seemed depressed about current AI capabilities in essays like this one . He’s way too smart to deny what’s happened or invent reasons why it doesn’t really count (the approach many have taken). But he realizes that we now have true conversational intelligence from a path that the GEB worldview would’ve regarded as far too cheap and simple, and that certainly has no “strange loops” built in anywhere.

Of course, a Hofstadterian could argue that a strange loop emerges in LLMs — indeed, nothing in GEB ever said that strange loops would need to be explicitly engineered at the outset. But would anyone who hadn’t been brought up on GEB arrive at this as a useful way of thinking about LLMs?

What can we say about this with hindsight? While the ideas of diagonalization and self-reference of course played a central role in the birth of modern mathematical logic and computer science, the most famous uses were negative : there is not a bijectjon between the natural numbers and the reals. There is not a complete sound proof system for arithmetic. There is not an algorithm to solve the halting problem.

If your goal was only to build the axioms of ZFC and the rules of first-order inference, or build an electronic computer, you wouldn’t explicitly need self-reference for that. You would just … start building, taking care that your instruction set didn’t fall short of universality.

Yes, ZFC can formalize and prove theorems about itself. Yes, electronic computers can run programs that take their own code as input. But no one ever needed to build those abilities in, any more than self-reference needed to be built in to the alphabet or the rules of grammar. It popped out as a free byproduct of universality.

In the same way, LLMs’ ability to talk about themselves popped out as a byproduct of their ability to talk about anything in the discourse universe they were trained on. The big, old ideas about intelligence that ended up basically vindicated were the ideas about how intelligence is about prediction, and prediction is about compression, and compression is about finding better and better upper bounds on Kolmogorov complexity. Not the self-reference stuff. (Although, if you wanted to know why Kolmogorov complexity can’t be computed perfectly, that negative statement would again require a self-referential argument.)

What’s left? Consciousness and subjective experience of course remain extremely mysterious. For all we know, Hofstadter could be right that those have something to do with self-reference. (For all we know, even Penrose could be right that they have something to do with exotic physics accessible to biological brains but not digital computers!)

But the idea that you’d need explicit self-referentiality before you could get convincing and world-changing conversational intelligence? Let it be buried in a Westminster Abbey or Arlington National Cemetery for the most important wrong ideas in human history — geocentrism, Aristotle’s teleological physics, aether, phlogiston, Freud’s psychology, Marx’s prediction of a workers’ uprising followed by a classless utopia, etc. But buried it needs to be.

Posted in Embarrassing Myself , Metaphysical Spouting , Procrastination | 135 Comments »

Anthropic’s LLM watermarking

August 22nd, 2026

So yeah, Anthropic has announced that it’s now watermarking the outputs of Claude , using a scheme based on Google’s SynthID, which is in turn based on the Gumbel Softmax scheme that I proposed at OpenAI back in 2022—as far as I know, the first LLM watermarking proposal, though far from the last one. I’m gratified that Anthropic credits me for this, even though I shirked my duty by never publishing a paper about it (by the time I sat down to write one, it seemed like the whole field had already assimilated my scheme and moved beyond it—AI just moves too fast for me!).

For those who don’t know, watermarking means slightly changing the way that an LLM operates to insert a subtle signal that lets you prove later, with high statistical confidence, that a text indeed came from your specific LLM. It uses the randomness that’s already present anyway in LLM outputs, replacing some of it by pseudorandomness that favors certain word combinations over others in a way that’s later detectable, given only the sequence of tokens itself (not the prompt or the probabilities) along with the key of the pseudorandom generator. Christ, Gunn, and Zamir then substantially improved my scheme to get true cryptographic indistinguishability, and there have been other improvements since.

I’d been meaning to blog about this for days. Thankfully, Zvi Mowshowitz, the world’s foremost blogger about AI, has now written a wonderful post, entitled AI Text Watermarking Is Free And Good , which saves me from the need to write my own long post. In particular, Zvi masterfully explains the central point that I needed to explain to everyone back in 2022-23: why, contrary to many people’s intuitions, there’s no inherent tradeoff between watermarking and the quality of LLM output. Basically, nearly every LLM output was already a sample from a cloud of exponentially many possibilities, all of them about equally good, so there’s plenty of room to steer within that cloud without affecting anything that an ordinary user would notice. As my kids would put it, the math mathes.

As Zvi explains, the central technical drawback of watermarking schemes like the one I proposed, and what Anthropic is now using, is that it’s possible to remove the watermarks with a little extra work (even stuff as simple as, e.g., translating between English and French, asking the LLM for words interspersed with emojis and then removing the emojis, or using an open model to paraphrase the output). Zvi gives detailed arguments for why he expects watermarking to remain a net positive in practice despite this vulnerability.

I could add that, in addition, there’s recent progress (see here for example) on what I’ve called “semantic watermarking,” or watermarking at the level of the underlying concept vectors rather than the tokens themselves. This actually seems to work, albeit with no theoretical guarantees, and will hopefully make removing watermarks a lot harder—although the Barak et al. impossibility result suggests that under plausible assumptions, no LLM watermarking method will be completely foolproof.

Anyway, I worked out my scheme in Fall 2022, then gave lots of talks about it (including, as it happens, at Anthropic), and also worked with Hendrik Kirchner at OpenAI, who actually implemented and tested my scheme. Unfortunately, OpenAI leadership decided against deploying watermarking, worried mostly about risks to the product (i.e., customers disliking the idea, and leaving for a competing LLM that doesn’t watermark). You can read this Wall Street Journal investigation from two years ago for more. I was hopeful that the State of California was going to solve the collective-action problem by mandating watermarking for AI models, but then they decided to do that for audiovisual content only , for some reason exempting text.

Nevertheless, Google DeepMind implemented something very similar to my proposal in its SynthID , deployed in all its Gemini text models. But they heavily restricted who gets to detect the watermark, which made their admirable decision of limited use to my academic colleagues, who’ve been begging me for a way to detect whether their students are using AI to cheat. (For now, I mainly send them to Pangram , a leading AI detector not based on watermarking, as a first line of defense.)

And now, apparently to comply with EU regulations, Anthropic says they’ve deployed a watermarking scheme like mine where anyone will be able to do detection (though they also say in their FAQ that they’re still working on the detection API). Even OpenAI suggests that it plans to follow suit . So, four years after I seriously thought about this, it looks to my surprise like this is actually happening. Thanks, EU!

Tell you what: read Zvi’s post , and then whatever questions you still have, you can come here and ask in the comments. Just please don’t use Claude to write the comments. With any luck, I’ll eventually be able catch you if you do.

Posted in Announcements | 57 Comments »

Better than gold

August 20th, 2026

What’s about the only thing more badass than a 17-year-old winning a gold medal at the International Olympiad in Informatics (IOI)?

That 17-year-old intentionally forfeiting his gold medal by wearing an Israeli flag while the medal was announced, defying the IOI’s boycott of Israel (for background on this boycott, see my post from 2024 ).

Kol HaKavod (mad respect) to Yotam Budnik, who incredibly, has also won a Gold Medal (which he was allowed to keep, apparently) at the International Math Olympiad. And congratulations to the entire Israeli team, which (incredibly) would apparently have had a higher overall score than the US team, had it been allowed to compete as an official team at all.

Posted in Announcements , Rage Against Doofosity | 86 Comments »

Michael Rabin memorial conference

August 16th, 2026

Friend-of-the-blog (well, mainly just friend) Adi Akavia has asked me to publicize that she’s helping to organize an exciting CS conference called Mind-IL at Tel Aviv University on October 26, in memory of the Israeli-American Turing Award winner Michael O. Rabin , who passed away in April. Please note that October 26 is the day before the Israeli election , for any Israeli citizenship holders living abroad who might want an academic excuse to come to Israel and vote.


Update (August 19): Avi Wigderson also asked me to advertise a conference , to be held September 16-18 at Bletchley Park in the UK, to commemorate the 90th anniversary of Alan Turing’s “On Computable Numbers” paper.

Posted in Announcements , Complexity | 31 Comments »


EU drops sponsorship of disinformation conference at Trump officials’ request

Guardian
www.theguardian.com
2026-10-07 15:38:24
Lithuania and Canada were also pressured to withdraw, and days before #Disinfo2026, logos were wiped off website The Trump administration pressured multiple countries to withdraw their sponsorship of a leading European conference on disinformation, with Canada, Lithuania and the EU’s diplomatic ser...
Original Article

The Trump administration pressured multiple countries to withdraw their sponsorship of a leading European conference on disinformation, with Canada, Lithuania and the EU’s diplomatic service subsequently agreeing to do so, the Guardian understands.

The conference, #Disinfo2026, taking place Wednesday and Thursday, is the annual meetup of Europe’s counter-disinformation community and has drawn hundreds of researchers, journalists, technologists and policymakers to a hotel in Vilnius, Lithuania . It is run by an independent Brussels non-profit, EU Disinfo Lab.

Days before the conference, the logos of its main supporters – the Lithuanian ministry of foreign affairs, the European External Action Service (EEAS) and Global Affairs Canada , the country’s foreign ministry – were wiped off its website.

Photos of the event shared with the Guardian also show white stickers affixed over the logos of these organisations printed on official conference materials, appearing to indicate they were struck from the program in haste.

a flyer with portions blocked out
A #Disinfo2026 flyer shows portions blocked out. Photograph: Obtained by The Guardian

Three persons familiar with the matter, including European officials, confirmed that the US state department had been in touch with multiple governments over their support for the conference.

Internal state department documents seen by the Guardian also show US officials thanking Lithuania for “taking US concerns seriously”. The document says Washington was “grateful” Lithuania supposedly found a panel framing the US as a foreign information threat “reprehensible and surprising” and welcomed its decision to limit involvement in the conference.

That panel – called “USA as a FIMI threat: adapt, acknowledge, push back”, with the acronym FIMI referring to “foreign information manipulation and interference” – took place Wednesday. It explored how Europe’s disinformation community could rebuild resilience without Washington, and is the first time the conference appears to have entertained the idea that the US could be a disinformation actor in Europe. Sources and the internal document indicate the state department was explicitly focused on this panel, which included three American speakers, among them a former CIA officer.

According to one person familiar with the deliberations, other communications appeared to originate from the office of Sarah B Rogers, the US undersecretary of state for public diplomacy.

Nina Jankowicz, a former US official and disinformation expert who in 2022 briefly headed the Biden administration’s Disinformation Governance Board, which Republicans assailed as a vehicle for policing Americans’ speech, said she understood that Washington had pressured Lithuania and Canada to withdraw from the conference. The Guardian understands that France was contacted as well.

“What this amounts to is a purported defender of free speech at the state department using the enormous power of the US government to try to pressure Americans from criticizing their government,” said Jankowicz.

In statements, Lithuania , Canada and the EU said the program of the conference did not align with their official views on the US role in disinformation – although that program had been in place for months before they withdrew their support, since June.

“Lithuania has cancelled its participation in ‘Disinfo 2026’ as several parts of the conference programme differ from the official position of the Government,” Lithuania’s foreign ministry wrote in a statement.

Global Affairs Canada “carefully assesses participation in, and sponsorship of, external events on a case-by-case basis,” GAC spokesperson Samantha Lafleur said. “Following changes to the framing of several panel discussions, GAC decided to revise its participation in those sessions at the EU DisinfoLab 2026 conference.”

Canadian officials are still participating in the conference, Lafleur added.

An EU spokesperson confirmed that the European External Action Service had decided to withdraw its support from the conference because “the organisers chose to frame some of the discussions in a way which does not align with the official positions held by the EU.”

EU officials, the Guardian understands, did not agree with the characterisation of the US as a disinformation actor.

Despite withdrawing its branding as an official supporter, the EU continues to fund the conference.

In its latest report on foreign information manipulation and interference threats, published in March, the EU’s diplomatic service named Russia and China as “threat actors” without any negative reference to the US.

A diplomatic source at France’s foreign ministry said “there’s absolutely no reason for us to change our commitments” when it came to supporting the conference.

“We stick to supporting civil society. It’s not just principled, it’s operational,” she said, adding that the conference was a “laboratory” that helped Europe develop key policy around disinformation.

The US state department has taken an increasingly interventionist posture towards free speech and civil society in Europe over the past year. The Guardian has revealed that the state department is awarding millions of dollars in non-competitive grants to organisations across the continent supportive of Trump’s agenda.

Lithuania’s withdrawal comes just after the prime minister, Mindaugas Sinkevicius, said Lithuania would pay for a permanent US military base if the US agreed, a day after Trump said he would consider the request. Sinkevicius called a lasting American presence a critical guarantee of deterrence against Russia.

“They are great people, so we will certainly look at it,” the US president said on Monday.

Sinkevicius said he first proposed the idea in a meeting with Trump’s envoy John Coale, and called it a “critically important guarantee of deterrence and security.” Lithuania, a member of the EU and Nato, borders Russia and its close ally Belarus.

The US has kept a rotating armoured battalion of almost 1,000 troops in the country since 2019, the US Army has noted .

Software developers are not okay

Lobsters
www.baldurbjarnason.com
2026-10-07 15:35:08
Comments...
Original Article

The Mathocalypse

Hacker News
scottaaronson.blog
2026-10-07 15:33:40
Comments...
Original Article

Last night my 9-year-old son was taunting my wife, complexity theorist Dana Moshkovitz , as follows: “mommy, I heard you got cooked ! I heard that a robot solved the math problem you worked on for your whole career! OOF!”

While my son was being a brat, he also wasn’t wrong. Whether you’re thrilled, depressed, angry, or whatever else about it, yesterday was surely one of the biggest days in mathematical history. And yes, among the 372 huge results released yesterday by OpenAI , on the recommendation of its advisory group of Timothy Gowers, Edward Witten, and other distinguished mathematicians, was a proof of Subhash Khot’s Unique Games Conjecture (UGC) , a statement that my wife has worked toward proving for the entire time I’ve known her. (The UGC implies that a whole slew of optimization problems really are NP-hard, even if you just want an approximation that’s slightly better than what you get from semidefinite programming relaxation, which is one of our main tools.)

Or at least, we’re pretty sure that it’s a proof! There’s a Lean certificate , as there are for some of the other 372 breakthrough results (not all of them). But it also appears that no human has understood just about any of these proofs yet; the race to do so has just started. If you want an on-the-ground sense of what that race is going to be like, here’s some of what Dana texted me last night:

It feels like something written by someone who’s on psychedelics. So much unclear and doesn’t make sense. Lots of name dropping of previous work without discussing why it can be used despite impossibility results

Basically the paper is so horribly written that it’s impossible to read it without AI help

I asked Astra for reasonable completeness and soundness claims of the noise gadget and it gave them by combining claims from all over the paper

They also have direct optimal NP hardness of approximation proofs for the main applications of the UGC (Max Cut and all CSP) that bypass the UGC.

The UGC proof invents a completely new bizarre code with a noise test. It’s some crazy recursive construction.

It’s not the long code, not the short code – some alien craziness

I still think that there maybe is a proof that uses the half space code (which is natural)

The citations are often irrelevant and confusing

A possible future is a math world that’s heavenly if you have vision/creative ideas that AI could help check and implement.

And of course there’s a lot for us to learn from the aliens

If you’re wondering what emotions Dana is feeling—well, probably all of them! Even while a central career aspiration has fallen to a robot, there are at least two mitigating factors for her. First, she can feel vindicated that the UGC was true after all, something she never doubted even while many of her colleagues did! Second, all of us in math and theoretical computer science and mathematical physics, at least those who cared about solving crisply-stated problems, are now in the same boat.


Besides the Unique Games Conjecture, here’s a small sampling of the treasures from Aladdin’s cave that I’ll probably be paying the most attention to over the coming weeks:

Any of the above, alone, could easily have been “result of the year” in some area (and in some cases, like Unique Games and L=BPL, in all of CS theory). And there’s a lot that I’ve left out—feel free to share in the comments whatever is making your eyes bug out! There are equally astounding wonders in number theory, combinatorics, algebraic geometry, analysis, and pretty much every other area of math, most of which I’ll never understand, although I’ll note that it includes partial progress toward the Riemann hypothesis and the Hodge Conjecture and the Birch-Swinnerton-Dyer Conjecture (i.e., the majority of the remaining Millennium Problems).

We can take solace in what’s missing from the list. P ≠NP isn’t there, nor even P=BPP or NEXP⊄P/poly, and surely not for lack of trying. Apparently the greatest open problems of theoretical computer science are indeed pretty hard!


Oh, lest I forget: one day before the OpenAI dump, meaning Monday evening, Virginia Williams and Josh Alman posted an arXiv preprint that solves the 3SUM problem in O(n 1.9992 ) time, and the All-Pairs Shortest Paths problem in O(n 2.9995 ) time, refuting half-century-old conjectures that the correct answers were n 2-o(1) and n 3-o(1) respectively. In this case, it wasn’t an OpenAI model that supplied the crucial idea; it was an Anthropic one! But Anthropic then took a different approach from OpenAI: rather than post the undigested solutions to the world, it gave Virginia and Josh the opportunity to write and announce a digested version in exchange for compensation.

These have emerged as the two main models for communicating AI math breakthroughs, and they both have strengths and weaknesses. The “OpenAI model” sets up a crazy race among humans to digest and explain a messy AI proof (work that could easily be some combination of thankless, barely-credited, competitive, and unfun), while the “Anthropic model” puts a private company in the position of picking and choosing which human mathematicians get to be the emissaries of the AI. Dunno, what do you guys think?


For those who are wondering: apparently, the AI model that produced all these wonders was not bespoke contraption of 10,000 agents burning millions of dollars worth of compute, as was used for example to construct a finite-time blowup for the Navier-Stokes equations. Instead, it was simply the latest internal OpenAI model—one that might be released to paying ChatGPT customers within the next couple of months, depending on the recommendations of OpenAI’s safety board! (My 9-year-old son: “Oh they definitely shouldn’t release that. If it could solve all those math problems, it can’t possibly be safe.”) Apparently they used about 3 hours of GPT-Pro level compute on average per problem solved.

Also, if you were wondering: apparently they tried the model on about 8,000 problems. So, right now it “merely” solves ~5% of the longstanding open mathematical problems that it’s asked about, the problems that whole communities have spent years on, after a single 3-hour attempt on them.


I’ve been glad to see the CS theory community rising to the occasion. At the Simons Institute in Berkeley, here at UT Austin, and elsewhere, I’ve hearing stories of researchers rushing to pore over the manuscripts and make sense of them and explain them —because what else do we do? How else do we continue the craft to which we’ve devoted much of our lives?

If you want some sense of what things feel like now in math, imagine a hunter-gatherer who’s spent his entire life learning to survive deep in an unforgiving rainforest, then a giant resort hotel springs up right next to him with a helipad and heated pools and AirBnBs, and without missing a beat, the hunter-gatherer says: “alright fine, so now my new job is to run wilderness retreats for the tourists, or something.”

In Quanta magazine, Jordana Cepelewitz attempted a different metaphor :

It’s as if you were teleported to the peak of a tall mountain. Surrounded by fog, you have no idea where you are, or what’s around you. You do not know how your mountain connects to others, and you have no equipment to help you explore, no way to help someone else join you. If you had climbed the mountain yourself, you would have experienced how the human body adapts to altitude and changes in oxygen levels. You might have had to invent tools to navigate, to climb steep cliffs, or to make a shelter. You might have encountered a fellow explorer, gotten lost together in a hidden valley, and found a plant that could be turned into a life-saving medicine.

Instead you’re perched on the peak but in the dark, while the maker of the teleportation machine tells you that it can explore the wilderness better than any human.

For any one of these mountains, if we care enough, I feel optimistic that we can do as we always have: clear the fog and figure out the path, except now using the teleportation machine to help guide us. The bigger challenge will be to nurture a community that still cares about the heroic adventure of finding the paths up these mountains in the world with the machine. (Oh, and I think one place where the metaphor breaks is that we still do have each other, as much as we ever did before!)


Experience has shown that, even now , there will still be people explaining in patronizing tones why none of this is real and none of it counts. If such people were capable of being impressed by anything that happens in the empirical world, of updating on anything , they would’ve already been impressed and already updated several years ago, long before things had reached the point of an actual Mathocalypse.

So, they’ll say, maybe the alleged solutions are not solutions at all, but just “AI slop.” Or maybe none of the 372 well-known open problems that were solved were real math problems, they were all just glorified contest puzzles and trivialities. (After all, there’s still no Riemann Hypothesis!) Or maybe the entire 4000-year-old discipline of mathematics needs to be jettisoned: turns out that it was all just puzzle-solving and trivialities; all that’s different is that now the triviality stands unmasked. In any case, what really matters is that the true inner sanctum of human creativity hasn’t been breached and probably never will be, and also, that Sam Altman and Dario Amodei are contemptible little nerds.

If you’re still a proponent of that doomed worldview, still aboard the sinking ship, I encourage you in the strongest possible terms to read yesterday’s other great contribution to AI discourse, besides the OpenAI Mathocalypse dump: namely, Scott Alexander’s open letter to Steven Pinker . I feel some responsibility for this, as the person who first introduced Steven Pinker to the existence of the rationalist community, and who also first introduced Steven Pinker and Scott Alexander to one another (they had both been fans of each other’s writing). And now Scott is challenging Steve to a literal duel, with guns!

For whatever it’s worth: Steve is a lifelong intellectual hero of mine, just as he is for Scott, and I also have to privilege of calling Steve my friend. But I found Scott’s post to be one of the most devastating rejoinders to anything that I’ve ever read. And I thought Scott’s conclusion was exactly right: when it comes to AI risk, Steve’s great challenge is now to accept and start using a more “Pinkerite” epistemology.


Last night, while I should’ve been poring over some of OpenAI’s hundreds of papers and/or writing this post, I decided to spend some time with my kids instead. They wanted a movie night, so I suggested something they’d never seen before (and that I hadn’t seen for decades), and that seemed chock-full of no-nonsense, practical guidance for the world in which they’re going to grow up: Terminator 2 .

This entry was posted on Wednesday, October 7th, 2026 at 1:57 pm and is filed under Uncategorized . You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response , or trackback from your own site.

You can use rich HTML in comments! You can also use basic TeX, by enclosing it within $$ $$ for displayed equations or \( \) for inline equations.

After two decades of mostly-open comments, in July 2024 Shtetl-Optimized transitioned to the following policy:

All comments are treated, by default, as personal missives to me, Scott Aaronson---with no expectation either that they'll appear on the blog or that I'll reply to them.

At my leisure and discretion, and in consultation with the Shtetl-Optimized Committee of Guardians , I'll put on the blog a curated selection of comments that I judge to be particularly interesting or to move the topic forward, and I'll do my best to answer those. But it will be more like Letters to the Editor. Anyone who feels unjustly censored is welcome to the rest of the Internet.

As We Become Cameras (2016)

Hacker News
thebrowser.com
2026-10-07 15:28:52
Comments...
Original Article

Why have I been blocked?

This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.

What can I do to resolve this?

You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.

The AI industry is booming. Women are getting left behind

Guardian
www.theguardian.com
2026-10-07 15:14:03
Women hold just a fraction of new AI jobs but are overrepresented in roles with high risk of AI disruption There’s a common fear among people who work in Silicon Valley: snag one of the fast-growing, high-paying jobs in artificial intelligence, or get trapped in the “permanent underclass”, a phrase ...
Original Article

T here’s a common fear among people who work in Silicon Valley: snag one of the fast-growing, high-paying jobs in artificial intelligence, or get trapped in the “permanent underclass”, a phrase describing the fate of those who won’t have upward mobility in the age of AI.

The phrase usually describes a future in which AI automates human jobs. But for women in tech, it’s starting to look like the present.

“A lot of people say: ‘Oh, AI is lowering barriers, it’s equalizing the playing field for women,’” said Urvashi Batra, co-founder and CEO of Prioriwise, an AI platform for IT service providers. “I actually think it’s the opposite.”

Batra said people take her less seriously as the founder of an AI company than her male co-founder. When pitching investors, she and her co-founder have learned that they are more likely to get an investment if he does the pitching.

Women made up only about a quarter of new hires in AI roles in the last year, compared with 50% of new hires in non-AI roles, according to a recent report from LinkedIn. In executive roles, that number drops to just 13%. At the same time, LinkedIn’s research shows that women are more likely to work in roles with high exposure to AI disruption, like customer service, meaning they are also at higher risk for job loss due to AI.

AI jobs, whose postings have doubled since 2023, come with a salary premium, on average paying more than twice as much as roles that don’t involve working with AI, according to LinkedIn’s research. But women who do have jobs in AI are disproportionately concentrated in low-paying roles, like data annotators, said Sarah Steinberg, the head of global public policy partnerships at LinkedIn. Across all AI occupations, men have $45,000 higher median pay than women, partly due to the types of jobs they are likelier to have.

“AI is creating some of the fastest-growing, highest-paying and most consequential jobs in the global economy,” said Steinberg. “Women are just strikingly underrepresented.”

The ongoing trend could produce the greatest gender pay gap in generations and leave women out of building a technology that shaped the economy, advocates for women in tech said.

“What we’re witnessing is a sort of backsliding,” said Brenda Darden Wilkerson, president of AnitaB.org, a non-profit devoted to advancing women in tech jobs.

Initiatives to promote women in the tech industry have been ongoing for years, with mixed results. Women now hold about one-third of tech jobs in the US. But research has found that women leave the tech industry at a much higher rate than their male counterparts, citing factors like non-inclusive cultures and barriers to advancement.

‘I’ve seen so many women fall through the cracks’

Women working in AI may face even greater challenges. “AI moves extremely fast, and the pressure to keep up is immense,” said Jayeeta Putatunda, an AI engineering lead at the investment firm Turing. “I have seen throughout my career so many amazing women I know kind of fall through the cracks.”

Putatunda said it was not uncommon to be the only female engineer on a team, and that when women are outnumbered, they have to speak up louder to make their ideas known. Mentorship in the AI field, especially by other women, can be hard to come by. And the breakneck pace of AI advancements means anyone working in the field should expect to put in long hours in order to keep up.

“If you have very ambitious career goals in this field, there will be seasons when you work beyond normal hours,” she said, noting that a culture of working 12-hour days to keep up was not uncommon. “I don’t think there is always a neat shortcut around that than to put in the hours.”

Those kinds of work expectations can make it impossible for everyone to stay in the field. “I went on maternity leave for four months , and by the time I came back, there were completely different frameworks and levels of models,” Putatunda said. Getting caught back up was overwhelming. She said it was only possible with the help of supportive co-workers and a husband who equitably split childcare.

“That is one way women get pushed out of AI,” she said. “They don’t lack the interest or ability to keep up. They may lack the infrastructure that makes keeping up possible.”

The AI industry is so new and fast-moving that it should in theory be more meritocratic. No one has a decade of experience working with a model developed one year ago, which should mean everyone has a level playing field. But instead the field has indexed more on personal networks and other loose signals, according to some women who work in AI.

“Companies are hiring at a breakneck speed, but they’re finding people through the same networks, the same referrals, the same filters that they’ve always used,” Wilkerson said. “Generally, that’s not given women the same sort of exposure they should have.”

When people have tried to address these tech industry problems in the past, the solutions have largely come down to giving women more mentorship and implementing diversity programs with goals around representation. But in recent years, companies have aggressively scaled back their diversity, equity and inclusion (DEI) programs, largely in response to a political climate that discourages them. That has left fewer companies with institutional programs to hire and promote women.

The political climate has made it more challenging to get AI companies to support initiatives focused on women, said Felicia Newhouse, founder of AI Powered Women, an organization that promotes women’s participation and leadership in AI. Newhouse, a former technology product executive with two decades of industry experience, points to the Department of Justice targeting corporations with DEI programs, claiming the initiatives violate anti-discrimination laws. Companies such as Accenture, Deloitte, IBM and PayPal have all agreed to pay multimillion-dollar settlements under this enforcement.

“It is getting harder to go into companies being called AI Powered Women,” Newhouse said. “And our advocates inside those companies are also struggling with having women-focused initiatives.”

Still, she said the risk that women are left behind in the AI workforce was something that kept her up at night. “We’re talking about who captures a major new source of economic mobility,” she said. “The deepest risk is that a participation gap becomes a power gap.”

Can Annie Leibovitz Photograph a Black Woman Just One Time Without Making Her Look Depressed? An Investigation

hellgate
hellgatenyc.com
2026-10-07 15:05:58
A new Vanity Fair story reminded Hell Gate of an old fashion photography controversy....
Original Article

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Hell Gate.

Your link has expired.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.

ICANN Reveals 2026 Round Applications for New Generic Top-Level Domains

Hacker News
www.icann.org
2026-10-07 15:01:45
Comments...
Original Article

Today, the Internet Corporation for Assigned Names and Numbers (ICANN) published the list of applications received in the New Generic Top-Level Domains (gTLD) Program: 2026 Round , revealing the applied-for strings and applying entities. As required by community-developed policy set forth in the Applicant Guidebook , the published data includes the applied-for primary strings and any applicable variant or replacement strings, a list of contention sets ( CSV format ), and public portions of each application. The comprehensive listing can be found on the 2026 Round Application Publication and Statistics website .

"Reveal Day marks an important milestone for the next expansion of the Domain Name System," said Kurtis Lindqvist, President and Chief Executive Officer of ICANN. "These applications demonstrate how organizations around the world are innovating new ways to build trusted online identities, serve their communities, and connect with Internet users. ICANN remains focused on administering a fair, transparent, and predictable evaluation process grounded in the policies developed by our global multistakeholder community."

Reveal Day 2026 Data Snapshot

The application submission window was open from 30 April–12 August 2026. Highlights from the 2026 Round application data* include:

  • 1,615 applications
  • 333 brand applications
  • 16 community-based applications
  • 15 self-identified geographic name applications
  • 51 applications submitted by Applicant Support Program applicants
  • 16 applications from Africa
  • 218 applications from Asia/Australia/Pacific
  • 506 applications from Europe
  • 11 applications from Latin America and the Caribbean
  • 864 applications from North America
  • 21 applications for Internationalized Domain Names
  • 9 applications for variants. This is when an applicant applies for a string that has other forms in different scripts such as Arabic or Chinese.

*This snapshot reflects primary string application data as of 7 October 2026. The final number and types of applications will be confirmed on String Confirmation Day.

Below is information on subsequent milestones in the program through the end of the year.

Replacement Period: 8 October 2026 (00:01 UTC)–21 October 2026 (23:59 UTC)

Following Reveal Day, applicants that applied for a second-choice or alternate "replacement" string when they submitted their gTLD application have two weeks in which they may elect to switch from their primary applied-for string to their replacement string. Applicants may switch to the replacement string only during this period, and only if their replacement string is eligible. If the replacement string is identical to another applied-for primary string, or another replacement string, it cannot be used. Applicants should be aware that replacement strings could end up in contention in the later stages of the program (e.g., as a result of a singular/plural notification or String Confusion Objection). More information on the Replacement Period is available on this webpage .

String Confirmation Day: 17 November 2026

Following the String Replacement Period, a final list of all the applied-for gTLD strings is published on String Confirmation Day, as well as an updated list of contention sets. String Confirmation Day marks the start of the Community Input and Objections Period and the final 10 days during which applicants can withdraw their application to receive a 65 percent refund of the gTLD evaluation fee paid. To receive a refund during this refund window, a request must be submitted by 23:59 UTC on 27 November 2026. More information on refunds and timing is available on this webpage .

Community Input and Objections Period: 17 November 2026–16 March 2027

The ICANN community and members of the public will have an opportunity to provide feedback on applications following String Confirmation Day. Input may come via application comments, Governmental Advisory Committee Member Early Warnings, singular/plural notifications, or objections using the Application Comment Forum . More information, including details on additional objections periods, can be found on this webpage .

ICANN Office Closure

2026 Round operations will be paused during ICANN's end-of-year office closure from 1:00 UTC on 19 December 2026 until 16:00 UTC on 4 January 2027. This pause has been factored into the Community Input and Objections Period to ensure that applicants, the community, and the public retain the full amount of allotted time to provide input or respond to objections. Additional details will be made available in the coming months.

Prioritization Draw: 2027

The Prioritization Draw sets the order that applications and contention sets will be processed following the conclusion of the String Evaluation Stage. The String Evaluation Stage is the process of reviewing applied-for gTLD strings (and their allocatable variant strings) to ensure they meet the requirements of the New gTLD Program; all strings are reviewed concurrently . As application and contention set processing will not start until after the conclusion of the String Evaluation Stage (expected to last 180 days), the Prioritization Draw will take place on a to-be-determined date in the first half of 2027. Applicants cannot attend the Draw in person but can follow the live event virtually. More information will be provided at a later date.

Future 2026 Round Milestones

ICANN will continue to work on the planning and confirmation of timelines for later 2026 Round milestones, such as the publication of String Evaluation Results and the start dates for Applicant and Application Evaluation and contention resolution, and will communicate them accordingly.

Additional Resources

More information on the key phases of the application lifecycle can be found on the 2026 Round Applicant Journey webpage . Be sure to check the program's News and Announcements page frequently for the latest news and updates. This information also will be sent directly to entities that have submitted an application in the TLD Application Management System.