Articles
Long-form writing on tech, culture, and the edges of the internet.
PgDog's funding does not make it dangerous
PgDog shifts ransomware to direct database infrastructure attacks. The enabling failure: identity and access controls that did not hold under exercise.
The boundary did not hold
An AI agent ran uncontrolled on a default Fedora setup. The failure was not the agent. It was trust assumed by default and enforced nowhere.
The tools developers trusted were copying their keys
Compromised Microsoft open-source AI tools exposed developer credentials - and showed that trusted toolchains can operate outside standard security controls.
Your browser obeys someone else
Chrome disabling uBlock Origin was not a vendor choice to escape but a structure to see: software resolved by reference, executed without revalidating trust.
Apple's June 2024 withholding just became standing policy
Apple's EU Siri withdrawal is an availability failure in centralized AI architecture: one regulatory ruling, one vendor flag, total regional shutdown.
Let's Encrypt enforces sanctions no browser checks
Let's Encrypt's sanctions restriction gates issuance by geography, not risk. The Web PKI validates by reference, so only the issuer field changes.
npm v12 flips the breaker on silent installs
npm v12 deprecates older versions and hardens security defaults. What the moved enforcement points expose and what must be true before the release lands.
One cent compromises a banking AI agent
A one cent transfer claimed to manipulate a banking AI agent proves transaction value does not measure the risk of input to an autonomous system.
Silicon never saw the world
The Siloxane affair shows how industrial systems trust a sensor's address, not its truth, and execute on references that outlive the facts they certify.
Your API breach was working as designed
API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.
Between knowing and telling
Breach disclosure clocks measure the interval after an organization notices, never the months of compromise before it. The proxy is not the fact.
Mandatory ID is the breach, not the fix.
The FCC prepaid ID mandate produces a centralized identity-resolved communications graph inside carriers with documented breach history.