RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

Microsoft's new default is Rust
Rustmemory safety

Microsoft's new default is Rust

Microsoft made Rust a tier-1 language because memory-safety bugs drove ~70% of its yearly security patches. Here is what the shift means.

7 min read
The model kept no receipts
AI safetyprovenance

The model kept no receipts

The "OpenAI stole my proof" fight is really a provenance gap in AI, and that gap is a safety problem, not just a credit dispute.

7 min read
Turning off training does not protect your data
LLM engineeringdata governance

Turning off training does not protect your data

OpenAI keeps re-enabling 'allow training.' Why a UI toggle is not a data control, and the gateway-and-contract architecture that makes training exposure impossible by design.

10 min read
Desert Ant Labs puts inference inside the loop
local LLMsAI pipeline architecture

Desert Ant Labs puts inference inside the loop

Fast local models turn inference into a near-zero-cost function call - here is the tiered pipeline pattern, a real support-desk example, and where it breaks.

9 min read
SWE-2 is the wrong model for almost everything
SWE-2agentic pipelines

SWE-2 is the wrong model for almost everything

SWE-2 is a code-execution node, not a generalist replacement. How to eval it against your own repos and where it actually fits in production pipelines.

10 min read
The weaker model matters more than the smarter one
LLM engineeringDeepSeek v4.1 Flash

The weaker model matters more than the smarter one

DeepSeek v4.1 Flash cuts token cost, not the need for validation - use it in cascades, verification loops, and long-context pipelines that hold up in production.

10 min read
Your defenses are now executing for the attacker.
forgejorce

Your defenses are now executing for the attacker.

Forgejo 16.0.3 and earlier carry a critical RCE. The vulnerable version is the exposure, and running a build above the range is the only confirmed mitigation.

7 min read
A helpful AI agent cannot be a private one
cybersecurityAI safety

A helpful AI agent cannot be a private one

Meta's Muse personal AI agent is only useful because it reads your messages, contacts, and habits. What that access costs your privacy and safety.

7 min read
iPhone Duo is not a convenience feature
iPhone Duomulti-device authentication

iPhone Duo is not a convenience feature

iPhone Duo's shared access and multi-device authentication expand who can authenticate and access, collapsing resource security to the weakest device and party.

7 min read
Open problems are running out
AI safetycryptography

Open problems are running out

Terence Tao calls open math problems a non-renewable resource. Why AI mining them threatens encryption, AI safety benchmarks, and how to respond.

6 min read
Ranking is not vetting
malvertisinggoogle ads

Ranking is not vetting

Attackers buy top Google Ads placement and use cloaking to deliver trojanized installers; ad review validates the submission, not the file you download.

7 min read
Resignations are signals, not scandals
AI safetyAnthropic

Resignations are signals, not scandals

How to read a high-profile resignation from an AI safety lab like Anthropic - what it signals, what to ignore, and what to watch in the months after.

7 min read