RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Russian hands on Polish water valves
critical infrastructureboard governance

Russian hands on Polish water valves

A board-level read on Russian-linked activity against Polish water utilities and what it means for directors governing critical services.

8 min read
Your MFA assurance just expired
board governanceauthentication risk

Your MFA assurance just expired

A board-level position on AI-developed 2FA bypass: reduced authentication assurance, category-level exposure, and the conditions required going forward.

8 min read
A new tool is not a replacement
burp suiteopen source security tools

A new tool is not a replacement

An open-source Burp alternative was built. Capability, stability, and handling of intercepted material are not confirmed. Verify before adoption.

5 min read
AI just broke 2FA at scale
2fa bypassai threats

AI just broke 2FA at scale

AI was used to develop a zero-day 2FA bypass deployed at mass scale. The control's economic assumption has been falsified in the wild.

7 min read
arXiv just raised the bar
LLM engineeringAI validation

arXiv just raised the bar

arXiv's one-year ban on unchecked LLM errors signals a shift: validation pipelines, not better prompts, now define competent AI systems.

11 min read
Attackers weaponized AI to bypass 2FA at scale
2fa bypassidentity security

Attackers weaponized AI to bypass 2FA at scale

A reported AI-developed zero-day 2FA bypass in mass use removes the assumption that 2FA terminates the account takeover chain.

7 min read
Complexity theory never said that
LLM engineeringAI systems design

Complexity theory never said that

Complexity theory does not prove human-level ML is impossible. Here is what the theorems actually say and how to design AI systems around real constraints.

8 min read
Your patched Exchange is already compromised
exchange zero-dayvendor trust

Your patched Exchange is already compromised

Microsoft confirms an Exchange zero-day under active exploitation. What the warning establishes, what it does not, and the defender posture required now.

7 min read
Audi wired vehicles into a consumer auth flow
connected vehicle securitymyAudi

Audi wired vehicles into a consumer auth flow

Audi Connected Vehicle security from an operator view: the boundary is no longer the key, it is the identity layer behind the myAudi app.

8 min read
Face ID was never the control
face id bypassbiometric security

Face ID was never the control

A reported Face ID bypass via avatar collapses the liveness assumption. Every downstream control trusting the boolean inherits the failure.

7 min read
Fragnesia is already loose
fragnesialinux privilege escalation

Fragnesia is already loose

Fragnesia Linux privilege escalation has a public PoC. The kernel trust boundary is conditional on patch state. What must now be true.

8 min read
Kernel bug leaks the SSH host key file
linux kernelssh security

Kernel bug leaks the SSH host key file

A Linux kernel flaw disclosed this month can expose SSH host keys. What failed, what it exposes, and what operators must now make true.

7 min read