RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The host dials out, the internet walks in
quick tunnelspenetration testing

The host dials out, the internet walks in

Cloudflare Quick Tunnels grant internet reachability to internal hosts over trusted outbound sessions, bypassing the inbound firewall by direction, not by flaw.

7 min read
Two failures are not one attack.
heap overflowsso misconfiguration

Two failures are not one attack.

A heap overflow and SSO misconfiguration compromised OpenAI internal repos. Two controls named as present, neither enforced in effect.

6 min read
Your Git history is already in the cloud
privacygit security

Your Git history is already in the cloud

ZCode transmits local Git history to the cloud with no consent prompt and no notification. A post-incident breakdown of the boundary that was never enforced.

7 min read
AWS confirms unrecoverable data loss after Iran strike
disaster recoverycloud resilience

AWS confirms unrecoverable data loss after Iran strike

AWS cannot restore some data from Iran-struck Mideast facilities. A recovery copy that shares a failure domain with the primary is not recovery.

7 min read
May 2024's Bend is no proof assistant
AI safetyformal verification

May 2024's Bend is no proof assistant

Bend is a parallel language, not a proof assistant. What proof-based programming actually does for AI safety, and the errors it can't touch.

7 min read
Permanent by default
technical debtsoftware supply chain

Permanent by default

A temporary PHP fix reached 20M installs because a label is not a control. The mechanism, the pattern, and what must now be true in production.

7 min read
Rust for CUDA won't make your models faster
Rust GPU programmingCUDA

Rust for CUDA won't make your models faster

Nvidia's native Rust support for GPU programming is a reliability shift at the systems layer, not a speedup - it matters only if you write custom device code.

10 min read
Zhipu built its own inference stack for GLM
LLM inferenceAI infrastructure

Zhipu built its own inference stack for GLM

GLM built its own inference infrastructure to serve LLMs cheaply on constrained, mixed hardware. Here's what breaks in generic stacks and what to copy.

10 min read
A 4B model outplans Postgres
postgres optimizationllm engineering

A 4B model outplans Postgres

A 4B model proposes faster Postgres query plans, but the validation gate and fallback - not the model - are what make the 81% speedup safe to run.

10 min read
A patch waits eleven days at the gate
Google PlayAndroid security

A patch waits eleven days at the gate

Google Play reviews now take a week or more. The real risk isn't malware slipping the gate - it's droppers that mutate after approval and slowed security patches.

6 min read
Gemini 3.8 Live broke two security assumptions
AI safetyprompt injection

Gemini 3.8 Live broke two security assumptions

Gemini 3.8 Live and Extended Thinking make ambient audio and video an untrusted AI input, reshaping prompt injection, logging, and privacy risk.

7 min read
Rubble where the records used to be
cloud resilienceboard risk

Rubble where the records used to be

A cloud provider states some Middle East data cannot be restored after a strike - what permanent loss means for board-level accountability and recoverability.

8 min read