Articles
Long-form writing on tech, culture, and the edges of the internet.
Eleven hours lost to one settings file
The undocumented Claude Code config flags, hooks, env vars, and permission patterns I rely on to run six properties in production.
EY Canada's 2026 report cited papers that don't exist
EY Canada published a cybersecurity report with mostly hallucinated citations. Here's what that means for how you should read threat intelligence.
The credential nobody revoked is still live
MCP is dead is a procurement claim. Until integrations are removed and trust artefacts revoked, runtime exposure is unchanged.
Hy3 is quietly winning production
Hy3 is topping OpenRouter rankings with no public lineage. NovaMind breaks down what its dominance means for pipelines, automation, and team design.
Liquid AI's 8B-A1B drop rewrites inference math
Liquid AI's 8B-A1B MoE trained on 38T tokens shifts LLM inference economics. What it means for engineering pipelines and workforce planning.
One billion fire, eight billion sit in memory
Liquid AI's 8B-A1B MoE frees compute and latency, not memory. How to match sparse-model architecture to the real constraint in your deployment.
The bottleneck moved past the model
Notes from the Mistral AI Now summit on what the new enterprise stack means for automation pipelines and workforce transformation.
800 servers gone, the scans kept coming
Dutch FIOD seized 800 servers from AS209847. One week later the scan rate is unchanged. What that signal actually means.
One PIN unlocks the vault
Vaultjacking turns one captured PIN into full retrieval of a Google Password Manager vault. Operator breakdown of the control collapse.
Opened the dashboard at 23:47
Microsoft cancelled Claude Code subscriptions. Here's the production audit one indie operator ran on $847/mo of Anthropic spend.
The word "toad" hijacked a Chrome VPN
A single keyword handed full control of Chrome's most popular VPN extension to any website. The failure is trust by string, not a bug.
CERT-IN's 12-hour patch window is not arbitrary
CERT-IN's 12-hour patch window for internet-facing flaws responds to AI-compressed exploitation timelines - what the threshold means operationally.