Articles
Long-form writing on tech, culture, and the edges of the internet.
Distillation makes fast followers, never frontier leaders
Distilling frontier models is a real, cheap fast-follow strategy for small labs - but only for verifiable tasks and legally usable teachers.
Keepalive packets bypass Android lockdown
Android NAT-T keepalive offload egresses UDP/4500 below the VPN lockdown firewall, leaking the device's real IP outside the tunnel. Mechanism and detection.
Remote access is not an operating system function
JetKVM Mini moves the access boundary off the host onto a networked hardware device the OS cannot see, making the KVM the real security perimeter.
Zoom reads your clipboard uninvited
On Linux, the Zoom client reads everything written to the X11 clipboard because trust on the selection channel is granted at connection, not per read.
Android leaks keepalive packets past its VPN kill switch
Android VPN lockdown leaks NAT-T keepalive packets on UDP 4500 outside the tunnel. Why the kill switch is partial and how to verify egress off-device.
Google quietly broke the search-scraping stack
Google's 2025 anti-scraping update killed cheap SERP scraping. How to rebuild AI search pipelines on sanctioned APIs, validation, and budget controls.
You depended on access you never owned.
Google's anti-scraping update changed a control scrapers never owned, exposing the structural risk of building on an interface you cannot see or govern.
A claim, not a control
GrapheneOS rewrote its Messages app under a privacy and security claim, but the enforcing controls are not named or independently verifiable.
Forty lines freeze your Mac
How the Deathray technique lets an untrusted website freeze an entire Mac by overloading WindowServer, why the browser sandbox can't stop it, and what to do.
Google Ads became a malware distribution channel
Malvertising turns Google's top search ad into a malware delivery channel. How the attack works, why review misses it, and the steps that stop it.
HuggingFace serves a disclosure channel, not a control
HuggingFace's security.txt defines a disclosure channel, not a security control. Publishing it expanded the commitment surface, not the platform's defenses.
Keep the two claims apart
Consumer AI trains on your chats by default. How to tell the real consent problem from unprovable 'secret breakthrough' claims - and what you can control.