Articles
Long-form writing on tech, culture, and the edges of the internet.
ZFS does not keep your data secure
ZFS gives Ubiquiti's enterprise NAS strong data integrity, but RAID-Z, snapshots, and cloud accounts each fail in ways the filesystem won't fix.
It measures conformity, not security
Volkswagen blocks GrapheneOS while admitting baseline devices. The gate measures configuration identity, not security posture.
Social engineering weaponized an Anthropic model
The Anthropic Mythos event involving a Korean telecom was a failure of identity and access control against known social engineering vectors, not a data leak.
speed ships the flaw
AI generates code, config, and infrastructure faster than validation can check it. The gap between production rate and validation rate is the attack surface.
The cache we enabled was a 25% surcharge.
A broken prompt-cache config charged Foundry a 25% input premium for 11 days. The fix, the batch ratio, and why RAM prices set your token bill.
The same AI you're shipping wrote the malware
10,000 trojan GitHub repos weren't a malware breakthrough - they prove LLM safety lives in the model while abuse happens in the unguarded pipeline.
Zero-Touch OAuth strips the 2025-06-18 MCP mandate
Zero-Touch OAuth for MCP fails as a trust-on-first-use design: unauthenticated dynamic client registration and unbound bearer tokens enable session hijack.
GitHub's scanners cleared 10,000 trojan repos
10,000 GitHub repositories distributed trojan malware because platform presence was treated as validation. The control was assumed, not enforced.
MITRE already filed your detection bypass as AML.T0015
ML malware detection is a deterministic classifier with a mappable decision boundary. Attackers exploit its learned bias. That demands more engineering.
Certified is not secure
Volkswagen blocking GrapheneOS shows what it costs when one attestation flag replaces a real risk decision, and why orchestration beats a longer blocklist.
DeepSeek dodged the Entity List, not your pipeline
US regulators listed 100+ firms but held off on DeepSeek. The real exposure: third-party AI weights and inference as a trusted security supply chain.
demand is not a control
Stop Killing Games gathered 13 million signatures and produced no EU law. The proposed approach lacked granular data access control and identity verification.