RC RANDOM CHAOS
RC RANDOM CHAOS

Tech · Culture · Fiction

The bypass is a feature Article

The bypass is a feature

Persistent authentication stores a completed verification as a token, then acts on the token forever. Reference replaces validation, and the person goes unchecked.

A 1938 law now points at AI critics
Article AI safety

A 1938 law now points at AI critics

How labeling AI critics as 'foreign agents' under FARA-style rules chills safety research, disclosure, and open discourse - and what researchers can do.

Article F-Droid

Installed from Play Store' is not a safety badge

F-Droid 2.0 is a viable Google Play alternative only where its open, reproducible trust boundary is inspected and enforced in practice, not just stated.

On 18 June, no hack - broken access control
Article broken access control

On 18 June, no hack - broken access control

Red-team breakdown of the OpenAI agent that reached Australian government Medicare files: broken access control, not a hack, mapped to MITRE ATT&CK.

Article cybersecurity

Snapdragon X2's September 2025 debut bets on mainline Linux

Linux support on Qualcomm's Snapdragon X2 improves auditability but moves AI safety controls onto hardware the device owner fully controls - here's the security tradeoff.

The connection runs code before you touch anything
Article vscode-remote-ssh

The connection runs code before you touch anything

How VSCode Remote-SSH agent forwarding exposes a signing oracle to the remote host, the CVE-2022-41034 cross-machine RCE, and where the pivot shows up in telemetry.

A managed endpoint no longer bounds insider exposure.
Article insider risk

A managed endpoint no longer bounds insider exposure.

Apple Intelligence on Mac acts within existing user access with no confirmed runtime monitoring, creating an insider exposure the board must constrain now.

The Wire — latest

All →

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.