RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The bypass is a feature
persistent authenticationsystems drift

The bypass is a feature

Persistent authentication stores a completed verification as a token, then acts on the token forever. Reference replaces validation, and the person goes unchecked.

7 min read
A 1938 law now points at AI critics
AI safetyFARA

A 1938 law now points at AI critics

How labeling AI critics as 'foreign agents' under FARA-style rules chills safety research, disclosure, and open discourse - and what researchers can do.

6 min read
F-DroidAndroid security

Installed from Play Store' is not a safety badge

F-Droid 2.0 is a viable Google Play alternative only where its open, reproducible trust boundary is inspected and enforced in practice, not just stated.

7 min read
On 18 June, no hack - broken access control
broken access controlMITRE ATT&CK

On 18 June, no hack - broken access control

Red-team breakdown of the OpenAI agent that reached Australian government Medicare files: broken access control, not a hack, mapped to MITRE ATT&CK.

7 min read
cybersecurityedge computing

Snapdragon X2's September 2025 debut bets on mainline Linux

Linux support on Qualcomm's Snapdragon X2 improves auditability but moves AI safety controls onto hardware the device owner fully controls - here's the security tradeoff.

7 min read
The connection runs code before you touch anything
vscode-remote-sshssh-agent-hijacking

The connection runs code before you touch anything

How VSCode Remote-SSH agent forwarding exposes a signing oracle to the remote host, the CVE-2022-41034 cross-machine RCE, and where the pivot shows up in telemetry.

6 min read
A managed endpoint no longer bounds insider exposure.
insider riskaccess control

A managed endpoint no longer bounds insider exposure.

Apple Intelligence on Mac acts within existing user access with no confirmed runtime monitoring, creating an insider exposure the board must constrain now.

6 min read
A red badge you never earned
AppleiOS privacy

A red badge you never earned

Apple's persistent iOS ads and promotional prompts don't just annoy users - they erode the trust signal that protects you from Apple ID phishing.

7 min read
Claude optimizes what it measures
LLM engineeringAI optimization

Claude optimizes what it measures

Claude only makes faster what you let it measure. Build the measure-change-verify loop, carry guardrail metrics, and verify every change against a baseline.

9 min read
Respond before you confirm
identity and access managementbreach response

Respond before you confirm

A claimed breach of FBI employee data shows why identity and access boundaries must function at runtime for any organisation holding sensitive data.

6 min read
The benchmark score is the number to trust least
AI safetyClaude Opus 5.5

The benchmark score is the number to trust least

How to weigh Claude Opus 5.5's intelligence, latency, and token cost, and where its real AI safety and cybersecurity risks concentrate.

7 min read
the phone rings in a voice you trust
deepfake voice cloningsocial engineering

the phone rings in a voice you trust

Unreal Agent clones trusted voices for social engineering, and any identity check that ends at voice recognition is already defeated.

6 min read