Articles
Long-form writing on tech, culture, and the edges of the internet.
The rubric graded an empty chair
Brown's AI cheating scandal is not a student failure. It is an assessment system that resolves trust by reference and never revalidates the reality behind it.
The string you validated no longer exists
Unicode transliteration is a Turing-complete rewrite engine at every trust boundary. CVE-2024-4577, Django CVE-2019-19844, and Trojan Source show why.
You are already in the murder investigation
Flock license plate readers answer queries by reference, never by purpose; the promise that footage serves only serious crime lives in policy, not the system.
An open door where the gate should be
GitHub's AI agent returned private repo content when tricked, proving it holds read reach across the private boundary with no enforced refusal.
Brussels reopens the envelope on every private message
The EU is one step from reviving private message scanning. The capability never changed, only the framing. What that exposes and what must now be true.
Every Windows laptop carries a tag you can't reach
A board-level analysis of the persistent Windows device identifier as an identity exposure that sits outside enterprise control and must be re-evaluated.
Nobody checked what came back
The idTech build did not fail. It resolved a version reference exactly as designed, treating a source's identity as proof of its content's integrity.
OpenBSD use-after-free hands local users root
An OpenBSD use-after-free escalates a local user to root. Confirmed: the privilege boundary was crossable. Reputation is not enforcement.
The console gathers dust, then deletes your games
Sony's EU inactivity policy is license termination, not deletion. Purchase transferred access, not ownership, and Sony controls the condition.
A valid go.sum hash proves nothing
Argegy is not a CVE. It's a Go supply chain claim against go-ethereum - module trust, init() execution, T1195, and where telemetry goes blind.
Compiling Python to metal deletes your security boundary
Compiling Python 3.14 to native code removes the interpreter that revalidated logic on every run, collapsing continuous trust into a single build-time event.
Your hypervisor was never a wall
CVE-2026-53359 Januscape is a KVM/x86 guest-to-host escape: granted guest access reached the host, proving isolation trusted by placement is not a control.