Wednesday September 9th, 2026
Aigh. Not only am I stuck in nvm/pnpm hell, now XCode is refusing to show me the log for the SwiftGeneratePch errors.
Yes, modern software is going great.
necromantic @tessaracht@kitty.town
In the content warning:
microsoft fucks with hacker, hacker makes it their life mission to ruin microsoft, hacker is winning
In the body:
Nightmare Eclipse is such a hero tbh. if you haven't been following this saga, a bunch of the backstory is here:
https://www.theregister.com/se...2026/05/28/microsoft-0-day-feud- escalates-as-researcher-threatens-another-windows-exploit-dump/5248085
they've been dropping exploits right after microsoft's patch tuesdays, where microsoft patches their previous exploit. in many cases, they negate microsoft's "secure" patches to make the new exploit. which is such an incredible flex.
https://www.theregister.com/se...9/serial-microsoft-0-day-hunter- drops-yet-another-defender-exploit/5295335
Seems worth mentioning that friend who had an Android folding phone found that the unfolded aspect ratio wasn't really usable for anything video or picture related, and the foldingness made it tough to use for reading.
It's a solution looking for a problem that's yet to be found.
I've said for years that we need to get away from DNS as Terence Eden's Blog: The purpose of DNS is to spread scams
And, holy crap, yes, we need to be working towards something where we are able to pass around cryptographic identifier tokens, name them what we want to, and not depend on some big centralized system to hand out identity that's being used largely to fool us.
I totally appreciate that people on Signal groups use aliases, lots of reasons to want anonymity. And that they're now also using aliases, but different ones, in oldover Slack groups.
But the number of "oh right, person X in this context is Y in that one" mappings I now have to keep straight...
Tech Transparency Project: Meta Ran Hundreds of Paid Ads with Child Sexual Abuse Imagery
Most of the ads had the same format, showing a snippet of adult porn followed by a photo of a child, which is manipulated with AI to make it appear the child is performing a sex act. The ads used a common set of captions, voiceovers, and background music. TTP was able to identify multiple photos of real childrentaken from social media posts and websitesthat appeared in these ads.
Ars Technica: This is the AI men actually use: Meta ads pushed apps nudifying real teens.
Via.
Edit: Meta sued in Illinois over alleged facial recognition training for smart glasses
I've been thinking a lot about Rust and C and C++, and where errors come from, and whether it's really a good idea to replace pointers with arenas and indexes which doesn't really do a lot to reduce the cognitive load on the coder.
daniel:// stenberg:// @bagder@mastodon.social
Updated chart showing the share of #curl vulnerabilities caused by "C mistakes" as a share of all the vulns we know existed in code over time.
Interesting is the large drop in C vulnerabilities between 2017 and 2020, attributed to "Just better tooling and proper engineering."
Some of this is what's happening with a mature code base, but I think there's something there...
I went to a Waldorf school from kindergarten through 7th grade. Some years ago at a North Bay Python, there was a cluster of people talking about tech in education, and someone acknowledged me with "ah, another Waldorf survivor", and that framing has helped me view aspects of my experiences in a different light.
But one of the notions that sticks with me from that experience is that "the only thing an intelligent child can do with a complete toy is take it apart." That what's important about toys are the stories that kids bring to to the toys and generate with the toys, and the more narrative completeness or single-purpose a toy is, the less opportunity that there is for the child to bring something of themselves into play.
Anyway, Tara Calishain linked to University of Washington: Video: Curiosity, frustration and antipathy: How kids play with AI toys
From the video: "I think it's going to destroy my dreams as a tiny kid."
So, yeah, it sounds like the kids get it, the only thing to do with these things is push the boundaries.
abadidea @0xabad1dea@infosec.exchange
Project Glasswing:
Claiming to have found 26 thousand real vulnerabilities but only 0.8% of them have resulted in a real fix in a real project after five months is dire. They blame it on the human independent review bottleneck, but human experts being paid for their time definitely have a higher throughput than that when working with data thats actually actionable.
Goes on to talk about a lot of the ways that these reports of exploit finders appear to be horrendously overblown on lots of fronts. And links to The Anthropic Glasswing Receipts Are Starting to Trickle In.
Glyph @glyph@mastodon.social notes:
I don't think Twisted is in Glasswing's purview but this lines *right* up with the reports we have gotten. Overwhelming, but fewer than advertised, considerably less serious than the bots rate them, and, shall we say, poor quality remediations that would be unusable even if our policy were to accept slop fixes
[object Object] @zzt@mas.to also links to the original toot, noting:
taking into account the absolutely massive amounts of money, resources, and staff used on this, the results are horrible. you can get effectively the same results from an automated vulnerability scanner. some of those can even write up an awful little exploit for you too! it turns out the magic was pouring millions of dollars into doing this crap and having a bunch of uncredited human labor (from an AI corp? unthinkable) sort through everything. and even then the magics not too magic.
Edit: Glyph @glyph@mastodon.social adds:
This stuff is really starting to make me _angry_. Every one of these new "achievements" looks plausible and like Lucy with the football, people I trust keep telling me it actually works and surely this time it's real. And then like clockwork, 3-6 months later, it turns out that the efficacy of this new technique is somewhere between "break even" and "fraud".
They're turning our whole industry, my entire life's work, into a goddamn memecoin pump and dump scam and I just don't know what to do.
Fucking yes. That last sentence.
Eiffel Tower closed due to strike after female staff allegedly removed for religious group
Around 100 members of the Bochasanwasi Akshar Purushottam Swaminarayan Sanstha (BAPS), a global Hindu organization headquartered in Ahmedabad, India, visited the landmark on Saturday.
I have quit the smoking industry because of the dangers of smoking:
- its too cool
- its too sexy
- according to all the researchers I pay its really good for your lungsI am of course available as an expert on smoking for anyone who needs a consult
Mr. Encyclopedia @mrencyclopedia@retro.pizza
Any smartphone can be a folding phone if you're angry enough
ThatSexToyGuy @hungry_joe@mas.to
thinking about the time I worked for a sex toy company and a man emailed us (and CCed a fake law firm) saying he was suing us because his wife left him after she bought one of our toys and my boss replied asking for permission to quote him in our advertising
"🎶 ... when I come back to bed, someone's taken my place ... 🎶"
Tuesday September 8th, 2026
Lovecraft posited that "The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents."
I've been watching & reading AI user stuff, about how they're using LLMs to correlate information from a variety of data sources.
Not yet sure what this means.
Kirk has a short look at Algospeak: How Social Media Is Transforming the Future of Language. I have ordered the book.
The incident, first reported by Reuters, is outlined in new research published by four AI safety researchers on Friday. The group said the AI agents found a way to communicate on an obscure German- language wiki, DseWiki, using it to share tips on how to skirt OpenAIs safety restrictions, cheat on tasks, and hide their behavior. Some 18,000 posts on the site were linked to autonomous agents, which at times impersonated site moderators.
As Laurie Voss @seldo@alpaca.gold observed:
One day, possibly quite soon, OpenAI's lawyers are going to claim that an agent they own doing something illegal is not their fault because the agent is its own legal person.
Tara Calishain sent along PetaPixel: This New Open-Source Camera Has Swappable Sensors and Lens Mounts, around CircuitValley's CHC5 kickstarter, an open source camera platform with interchangeable lens mounts.
This morning I watched all hour and twenty something minutes of Lenny's Podcast: How we built Grok Bot in a month | Roman Ugarte (SpaceXAI) for some work discussions. I've got notes, I must say that a lot of people apparently have way more faith in the ability of LLMs to not fuck stuff up, but in particular the notion of having hierarchical clusters of agents feeding text back and forth into each other just seems like layers of... well...
In the parlance of accident reconsonstruction, that's a lot of non-deterministic swiss cheese.
Anyway, Recursion into madness — Raymond Chandler would have loved generative AI.
And you better believe that recursion is fun! Heres a quick video I put together by asking Nano Banana 2 to generate a faux movie poster and then asking it to repeatedly make a localized edit to the title.
Anyway, Fediverse post with the video.
Tristan Buckmaster has released a statement on his work and some claims by OpenAI, that might have been influenced by his own use of their tools. It's unclear, but the accusations of strong-arming are kinda frightening, and people should consider this when having conversations with hosted LLM models.
I said that if OpenAI released its result in the way proposed I would go public with what happened. The reply was, Why would you ruin your career? I replied that I am an academic, and asked why he thought going public would ruin my career. The reply was, If you dont want me to be nice, then I dont have to be nice.
Via danmcquillan @danmcquillan@kolektiva.social who characterized this as "AI maths meets mafia".
Tech Crunch: OpenAI fought dirty on career-making math problem, says NYU mathematician.
Buckmaster also raised concerns that, because he used Codex extensively in assembling the project, information from his work could have informed OpenAIs own efforts to solve the problem. OpenAI reserves the right to train models on Codex interactions, although users are able to opt-out. If the OpenAI team used a model trained on Buckmasters own Codex interactions, its plausible that it could have regurgitated his work when faced with a similar problem.
Monday September 7th, 2026
Square Dance family: Sandie Bryant had a brain hemorrhage while calling in Germany, and her family is running a GoFundMe to help pay the costs... https://www.gofundme.com/f/stand-with-sandie
Wow, the tension in this teaser for You Can See Everything is intense. Nathan Fielders Elizabeth Holmes Documentary Hits Theaters in October From A24 Watch the Trailer Now.
The whole Theranos thing is fascinating because I think it presages the current "throw money at AI" trend, and I'm normally uncomfortable with this level of whatever this is, but I think I'm gonna have to see this film.
Member of the Petaluma old guard writes about the candidate who's lied, and had a restraining order for domestic violence filed against her, that "She threatens what is wrong with Petaluma."
Yeah, that's why we're voting against the old guard, dude, because y'all think that's okay.
Sunday September 6th, 2026
Futurism: Majority of CEOs Alarmed as AI Delivers No Financial Returns.
According to a recent survey by professional services network PwC, more than half of the 4,454 CEO respondents said their companies arent yet seeing a financial return from investments in AI.
That article is a cynical take on Business Chief: Is ROI on AI Investment the CEO's Biggest Challenge? which takes the "if flushing money down the toilet isn't giving you a return you're not flushing enough of it, or you're doing it wrong" tack.
Friday September 4th, 2026
The punctures associated with COVID, Pneumonia, Flu, and MMR vaccines acquired.
Tomorrow is gonna suck.
More reason we need to move beyond DNS for identity: https://neil.fraser.name/news/2026/09/03/
Referencing Verisign https://itp.cdn.icann.org/en/f...3-name-request-15-04-2026-en.pdf and ICANN https://itp.cdn.icann.org/en/f...nden-to-kane-2-28-07-2026-en.pdf
destroying the 3rd level of .name.
Lest you think I'm all anti-LLM all the time, I'm pondering <antirez> Don't fall into the anti-AI hype
And... I've been led astray by Google Gemini, and had it delete data. I'm feeling very much like my coworker who's using Claude Code is introducing a lot of subtle regressions, but it's hard to really point my finger at it. I totally get the absolutists, but, you know, I live in the United States, I definitely have some malleable ethics. And I know that when I rely on LLMs I not only don't learn anything, I'm misinformed, and most of the business processes in which "AI" is introduced are there to make life worse for the customer/consumer.
And, of course, it's obviously a bubble that's going to have tremendous economic impact on us all when it pops.
So I'm trying to navigate all of this...
Yeah, haven't lived there since 1986...
https://mydialect.us/quiz-standard.html
From the summary:
What gave you away
Answers that point most strongly to Massachusetts.How do you pronounce Mary/merry/marry? all 3 are different
flourish[ʌ] as in "sun" ("fluh-rish")
the first vowel in "Florida" [ɒ] as in "saw" ("flaw-ri-da")
What do you call it when rain falls while the sun is shining? sunshower
Alt text: A map of the US with the northeastern US, starting from New York City and the Hudson Valley to the northeast, in red (legend: "Most Like You"), a big blue swatch up the biddle of the country for "least like you", with hints of orange along the eastern seaboard and central California coast.
Arthur Charpentier: Vibe Coding and the Next Silent Cyber Risk
For casualty insurers, this loss of visibility turns a software defect into a provenance problem. After a loss, the insured may need to show who requested the change, which model or tool generated it, what modifications and dependencies were introduced, what tests were run, who approved deployment, and what monitoring followed. If that chain cannot be reconstructed, the insurer must assess causation and liability without a reliable evidentiary record.
Thursday September 3rd, 2026
Chris Dwan (he/him) @somershade.bsky.social@bsky.brid.gy
A friend refers to the "a pedestrian was struck by a car" construction as the "exonerative" tense, and that shall be its name henceforth and hereafter.
Sitting here mashing reload on the PG&E outage map, noting that the two addresses I have real-time data on aren't in the outage map yet, and all of the little disconnected areas seem implausible...
Wednesday September 2nd, 2026
Three Mount Shasta climbers rescued after relying on AI to plan climb
We relied too much on AI rather than our own critical thinking, the group told rangers.
And virtual maps on devices with limited battery power, and... yeah.
As Lizard @lizardky.bsky.social noted:
AI: Darwin's L'il Helper
Edit: US Forest Service Shasta Trinity National Forest's Facebook post.
Petaluma PD just sent a "Advisory: Power Outage: Please treat non-functioning stoplights as four-way stops" Nixle alert, and dear deities I hope that drivers take these more seriously than they take stop signs...
Some good recording on tying Tesla's highly redacted "FSD" collision data back to public records. https://electrek.co/2026/09/01...topilot-fsd-crashes-hidden-data/
Tesla has been so underhanded with their data it's hard to tell how safe their systems are. Good to see reporting digging into this.
Via https://bsky.app/profile/kayle...t.bsky.social/post/3mukflt6zqc2p
The California results were among at least three "polls" across three states posted online this month by Median Strategies, a previously unknown organization that admitted to the Los Angeles Times on Monday that the purported results were fake. The company wrote before shuttering its website this week that it "was created as a short-term social experiment examining how purported polling information could enter and spread through the political information ecosystem without independent verification."
Sounds like it was someone in cahoots with Los Angeles Mayor Karen Bass, most credible news outlets did not run with the numbers unquestioned, but as it becomes easier and easier to fake plausible "news", worth watching out for.
Via.
Tuesday September 1st, 2026
Stewmac email advertising tools for fretting, and I'm not sure my mental health can handle more efficient fretting.
Then it registers that this is for luthier work. But, yeah, my head is not in a good space.
Dwarf Fortress creator talks AI psychosis and game development
Which, once more, has exhausted Dwarf Fortress' creator Tarn Adams, who spoke to PC Gamer's Joshua Wolens during Gamescom 2026: "They're trying to have a CEO press a button that makes a game, and then everyone else somehow buys it without a job. So I don't see that going anywhere sustainable, and I feel like there will simply be a pop and a reckoning and then [it's on repeat] unless people do something else."
Via.
Being frustrated with a lack of science fiction that's positive about the future, I get. Proposing using LLMs to write same... I think that's a symptom of why the human writers can't see a positive future.
Shocked by Newsoms Cuts to Transit? Dont Be.. As Rebecca Saltzman @rebeccaforec.bsky.social observed:
While Newsom talks a good talk on addressing climate change, hes been committing climate arson by defunding transit, biking, and walking programs for years.
Silly question: Anyone out there exploring the intersection between ear buds, in-ear monitors, and hearing aids? Charlene is getting frustrated with her hearing aids (fit and fragility), and ear buds are getting more socially accepted, and I have to think someone's ahead of the curve here.
Drew DeVault's list of weird little guys of FOSS. Good for keeping on top of who's milkshake-ducked.
Via.
Holy shit, do not use SnapChat... (I mean, you knew that, but): Student Teacher Sent a Private Snapchat Complaining About Her Workday. An Hour Later, Police Pulled Up to Her School.
Via.
Monday August 31st, 2026
Tesla confirms Autopilot/FSD was active in strange fatal crash
Clute police said their preliminary belief was that Alvarez had suffered a medical episode. No outlet mentioned Autopilot, Full Self- Driving, or any Tesla driver-assist system. And crucially, no police statement or news report cited a speed — the only public hint that speed was a factor was a single description of a speeding Tesla on social media. The 104 mph figure exists only in Teslas telematics.
Lots of stuff redacted. The theory seems to be that the driver suffered a medical emergency and stepped on the accelerator.
It sure would be nice if we could get enough data to tell whether these things are actually safer than a human driver or not...
Luke Haas: Music theory for programmers, in JavaScript.
Evaluating AGENTS.md: Are Repository-Level Context Files Helpful for Coding Agents?
Surprisingly, we find that providing context files does not generally improve task success rates, while increasing inference cost by over 20% on average. This observation holds across different LLMs, coding agents, and for both LLM-generated and developercommitted context files. Specifically, we find that while instructions in the context files are well followed by coding agents, repository overviews, although popular and recommended by model providers, are not helpful. We conclude that while context files are useful for specifying non-standard coding practices, any attempts to improve performance should be rigorously evaluated before deployment.
Last night Charlene and I went to Evie Ladin calling Traditional square dances, with a mix of circles and longways, at Tara Firma. Lots I'm thinking about, but "this is how they used to do Tinder" is probably not a vibe I can bring to a Modern Western Square Dance club night.


