Articles
Long-form writing on tech, culture, and the edges of the internet.
Microsoft's new default is Rust
Microsoft made Rust a tier-1 language because memory-safety bugs drove ~70% of its yearly security patches. Here is what the shift means.
The model kept no receipts
The "OpenAI stole my proof" fight is really a provenance gap in AI, and that gap is a safety problem, not just a credit dispute.
Turning off training does not protect your data
OpenAI keeps re-enabling 'allow training.' Why a UI toggle is not a data control, and the gateway-and-contract architecture that makes training exposure impossible by design.
Desert Ant Labs puts inference inside the loop
Fast local models turn inference into a near-zero-cost function call - here is the tiered pipeline pattern, a real support-desk example, and where it breaks.
SWE-2 is the wrong model for almost everything
SWE-2 is a code-execution node, not a generalist replacement. How to eval it against your own repos and where it actually fits in production pipelines.
The weaker model matters more than the smarter one
DeepSeek v4.1 Flash cuts token cost, not the need for validation - use it in cascades, verification loops, and long-context pipelines that hold up in production.
Your defenses are now executing for the attacker.
Forgejo 16.0.3 and earlier carry a critical RCE. The vulnerable version is the exposure, and running a build above the range is the only confirmed mitigation.
A helpful AI agent cannot be a private one
Meta's Muse personal AI agent is only useful because it reads your messages, contacts, and habits. What that access costs your privacy and safety.
iPhone Duo is not a convenience feature
iPhone Duo's shared access and multi-device authentication expand who can authenticate and access, collapsing resource security to the weakest device and party.
Open problems are running out
Terence Tao calls open math problems a non-renewable resource. Why AI mining them threatens encryption, AI safety benchmarks, and how to respond.
Ranking is not vetting
Attackers buy top Google Ads placement and use cloaking to deliver trojanized installers; ad review validates the submission, not the file you download.
Resignations are signals, not scandals
How to read a high-profile resignation from an AI safety lab like Anthropic - what it signals, what to ignore, and what to watch in the months after.