RC RANDOM CHAOS

Articles

Long-form writing on tech, culture, and the edges of the internet.

The rubric graded an empty chair
systems failure analysistrust delegation

The rubric graded an empty chair

Brown's AI cheating scandal is not a student failure. It is an assessment system that resolves trust by reference and never revalidates the reality behind it.

7 min read
The string you validated no longer exists
unicode-securityencoding-attacks

The string you validated no longer exists

Unicode transliteration is a Turing-complete rewrite engine at every trust boundary. CVE-2024-4577, Django CVE-2019-19844, and Trojan Source show why.

6 min read
You are already in the murder investigation
surveillancesystems failure analysis

You are already in the murder investigation

Flock license plate readers answer queries by reference, never by purpose; the promise that footage serves only serious crime lives in policy, not the system.

7 min read
An open door where the gate should be
ai-agent-securityaccess-control

An open door where the gate should be

GitHub's AI agent returned private repo content when tricked, proving it holds read reach across the private boundary with no enforced refusal.

7 min read
Brussels reopens the envelope on every private message
private message scanningeu surveillance

Brussels reopens the envelope on every private message

The EU is one step from reviving private message scanning. The capability never changed, only the framing. What that exposes and what must now be true.

7 min read
Every Windows laptop carries a tag you can't reach
identity governanceboard oversight

Every Windows laptop carries a tag you can't reach

A board-level analysis of the persistent Windows device identifier as an identity exposure that sits outside enterprise control and must be re-evaluated.

8 min read
Nobody checked what came back
software supply chaindependency management

Nobody checked what came back

The idTech build did not fail. It resolved a version reference exactly as designed, treating a source's identity as proof of its content's integrity.

8 min read
OpenBSD use-after-free hands local users root
openbsdprivilege-escalation

OpenBSD use-after-free hands local users root

An OpenBSD use-after-free escalates a local user to root. Confirmed: the privilege boundary was crossable. Reputation is not enforcement.

6 min read
The console gathers dust, then deletes your games
digital rightslicense termination

The console gathers dust, then deletes your games

Sony's EU inactivity policy is license termination, not deletion. Purchase transferred access, not ownership, and Sony controls the condition.

5 min read
A valid go.sum hash proves nothing
supply-chain-securitygo-ethereum

A valid go.sum hash proves nothing

Argegy is not a CVE. It's a Go supply chain claim against go-ethereum - module trust, init() execution, T1195, and where telemetry goes blind.

6 min read
Compiling Python to metal deletes your security boundary
systems drifttrust models

Compiling Python to metal deletes your security boundary

Compiling Python 3.14 to native code removes the interpreter that revalidated logic on every run, collapsing continuous trust into a single build-time event.

7 min read
Your hypervisor was never a wall
CVE-2026-53359KVM security

Your hypervisor was never a wall

CVE-2026-53359 Januscape is a KVM/x86 guest-to-host escape: granted guest access reached the host, proving isolation trusted by placement is not a control.

7 min read