RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Distillation makes fast followers, never frontier leaders
model distillationopen-weight AI

Distillation makes fast followers, never frontier leaders

Distilling frontier models is a real, cheap fast-follow strategy for small labs - but only for verifiable tasks and legally usable teachers.

9 min read
Keepalive packets bypass Android lockdown
Android securityVPN lockdown

Keepalive packets bypass Android lockdown

Android NAT-T keepalive offload egresses UDP/4500 below the VPN lockdown firewall, leaking the device's real IP outside the tunnel. Mechanism and detection.

7 min read
Remote access is not an operating system function
hardware securityremote access

Remote access is not an operating system function

JetKVM Mini moves the access boundary off the host onto a networked hardware device the OS cannot see, making the KVM the real security perimeter.

7 min read
Zoom reads your clipboard uninvited
X11 clipboardZoom Linux

Zoom reads your clipboard uninvited

On Linux, the Zoom client reads everything written to the X11 clipboard because trust on the selection channel is granted at connection, not per read.

6 min read
Android leaks keepalive packets past its VPN kill switch
android securityvpn lockdown

Android leaks keepalive packets past its VPN kill switch

Android VPN lockdown leaks NAT-T keepalive packets on UDP 4500 outside the tunnel. Why the kill switch is partial and how to verify egress off-device.

7 min read
Google quietly broke the search-scraping stack
AI pipelinesweb scraping

Google quietly broke the search-scraping stack

Google's 2025 anti-scraping update killed cheap SERP scraping. How to rebuild AI search pipelines on sanctioned APIs, validation, and budget controls.

9 min read
You depended on access you never owned.
web scrapingaccess control

You depended on access you never owned.

Google's anti-scraping update changed a control scrapers never owned, exposing the structural risk of building on an interface you cannot see or govern.

9 min read
A claim, not a control
GrapheneOSmobile security

A claim, not a control

GrapheneOS rewrote its Messages app under a privacy and security claim, but the enforcing controls are not named or independently verifiable.

8 min read
Forty lines freeze your Mac
macOS securitydenial of service

Forty lines freeze your Mac

How the Deathray technique lets an untrusted website freeze an entire Mac by overloading WindowServer, why the browser sandbox can't stop it, and what to do.

7 min read
Google Ads became a malware distribution channel
malvertisinggoogle-ads

Google Ads became a malware distribution channel

Malvertising turns Google's top search ad into a malware delivery channel. How the attack works, why review misses it, and the steps that stop it.

7 min read
HuggingFace serves a disclosure channel, not a control
security.txtvulnerability disclosure

HuggingFace serves a disclosure channel, not a control

HuggingFace's security.txt defines a disclosure channel, not a security control. Publishing it expanded the commitment surface, not the platform's defenses.

8 min read
Keep the two claims apart
AI ethicsdata privacy

Keep the two claims apart

Consumer AI trains on your chats by default. How to tell the real consent problem from unprovable 'secret breakthrough' claims - and what you can control.

7 min read