RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The tools developers trusted were copying their keys
supply chain riskdeveloper credentials

The tools developers trusted were copying their keys

Compromised Microsoft open-source AI tools exposed developer credentials - and showed that trusted toolchains can operate outside standard security controls.

7 min read
Your browser obeys someone else
systems driftsoftware supply chain

Your browser obeys someone else

Chrome disabling uBlock Origin was not a vendor choice to escape but a structure to see: software resolved by reference, executed without revalidating trust.

7 min read
Apple's June 2024 withholding just became standing policy
centralized AI riskDigital Markets Act

Apple's June 2024 withholding just became standing policy

Apple's EU Siri withdrawal is an availability failure in centralized AI architecture: one regulatory ruling, one vendor flag, total regional shutdown.

7 min read
Let's Encrypt enforces sanctions no browser checks
web pkisanctions compliance

Let's Encrypt enforces sanctions no browser checks

Let's Encrypt's sanctions restriction gates issuance by geography, not risk. The Web PKI validates by reference, so only the issuer field changes.

7 min read
npm v12 flips the breaker on silent installs
npm v12supply chain security

npm v12 flips the breaker on silent installs

npm v12 deprecates older versions and hardens security defaults. What the moved enforcement points expose and what must be true before the release lands.

8 min read
Silicon never saw the world
systems driftindustrial control

Silicon never saw the world

The Siloxane affair shows how industrial systems trust a sensor's address, not its truth, and execute on references that outlive the facts they certify.

8 min read
Your API breach was working as designed
api securityauthentication

Your API breach was working as designed

API authentication failing at the request level is a trust boundary failure. Inadequate identity validation makes lateral movement a design outcome.

7 min read
Between knowing and telling
breach disclosuresystems failure analysis

Between knowing and telling

Breach disclosure clocks measure the interval after an organization notices, never the months of compromise before it. The proxy is not the fact.

7 min read
Mandatory ID is the breach, not the fix.
OSINTprivacy

Mandatory ID is the breach, not the fix.

The FCC prepaid ID mandate produces a centralized identity-resolved communications graph inside carriers with documented breach history.

7 min read
OpenCV 5.0 made adversarial perturbations transferable
adversarial-mlopencv

OpenCV 5.0 made adversarial perturbations transferable

OpenCV 5's bit-exact numerics and expanded encoder control shrink the attacker's modelling error against deepfake detectors. The exposure is structural.

6 min read
Refusal bypass isn't the scary part
claude-codeagent-observability

Refusal bypass isn't the scary part

What broke when I ran a self-modifying pen test agent through Foundry's harness: $47 burned in 3 hours, a strategy ossification loop, and the registry fix.

6 min read
Sixty-three days to patch a forked parser
vulnerability researchsupply chain security

Sixty-three days to patch a forked parser

Technical breakdown of the FrontierOS RCE: a forked XML parser, an unpatched two-year-old CVE, and the fork-tracking failure that shipped it.

6 min read