RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

ZFS does not keep your data secure
ZFSUbiquiti NAS

ZFS does not keep your data secure

ZFS gives Ubiquiti's enterprise NAS strong data integrity, but RAID-Z, snapshots, and cloud accounts each fail in ways the filesystem won't fix.

7 min read
It measures conformity, not security
grapheneosvolkswagen

It measures conformity, not security

Volkswagen blocks GrapheneOS while admitting baseline devices. The gate measures configuration identity, not security posture.

8 min read
Social engineering weaponized an Anthropic model
social engineeringidentity and access control

Social engineering weaponized an Anthropic model

The Anthropic Mythos event involving a Korean telecom was a failure of identity and access control against known social engineering vectors, not a data leak.

7 min read
speed ships the flaw
ai securitysecure development

speed ships the flaw

AI generates code, config, and infrastructure faster than validation can check it. The gap between production rate and validation rate is the attack surface.

8 min read
The cache we enabled was a 25% surcharge.
prompt cachingclaude code cost control

The cache we enabled was a 25% surcharge.

A broken prompt-cache config charged Foundry a 25% input premium for 11 days. The fix, the batch ratio, and why RAM prices set your token bill.

7 min read
The same AI you're shipping wrote the malware
LLM deploymentAI security

The same AI you're shipping wrote the malware

10,000 trojan GitHub repos weren't a malware breakthrough - they prove LLM safety lives in the model while abuse happens in the unguarded pipeline.

11 min read
Zero-Touch OAuth strips the 2025-06-18 MCP mandate
MCPOAuth 2.1

Zero-Touch OAuth strips the 2025-06-18 MCP mandate

Zero-Touch OAuth for MCP fails as a trust-on-first-use design: unauthenticated dynamic client registration and unbound bearer tokens enable session hijack.

7 min read
GitHub's scanners cleared 10,000 trojan repos
supply chain securitygithub security

GitHub's scanners cleared 10,000 trojan repos

10,000 GitHub repositories distributed trojan malware because platform presence was treated as validation. The control was assumed, not enforced.

7 min read
MITRE already filed your detection bypass as AML.T0015
adversarial-mlml-edr

MITRE already filed your detection bypass as AML.T0015

ML malware detection is a deterministic classifier with a mappable decision boundary. Attackers exploit its learned bias. That demands more engineering.

7 min read
Certified is not secure
ai-orchestrationsecurity-architecture

Certified is not secure

Volkswagen blocking GrapheneOS shows what it costs when one attestation flag replaces a real risk decision, and why orchestration beats a longer blocklist.

11 min read
DeepSeek dodged the Entity List, not your pipeline
ai-supply-chainmodel-poisoning

DeepSeek dodged the Entity List, not your pipeline

US regulators listed 100+ firms but held off on DeepSeek. The real exposure: third-party AI weights and inference as a trusted security supply chain.

7 min read
demand is not a control
digital rightsaccess control

demand is not a control

Stop Killing Games gathered 13 million signatures and produced no EU law. The proposed approach lacked granular data access control and identity verification.

8 min read