Articles
Long-form writing on tech, culture, and the edges of the internet.
A meditation app shipped a switch statement as AI
Whether a product 'really uses AI' is unanswerable and beside the point. What predicts reliability is system design: validated inputs, constrained outputs, fallbacks.
Access is the breach
The EU chat control mandate concentrates standing access to private messaging into a single point of compromise that no implementation quality can fix.
Age verification does not verify age
The KIDS Act conditions access on collecting identity artifacts, converting every covered service into a standing target the control itself does not protect.
An hour-old account drops forty working exploits
A coordinated dump of forty anonymous 0-days breaks your triage queue, not your servers. Engineer response throughput and pre-authorized action before the burst.
I reverse-engineered a 2002 GameCube before doing it legally
Decomp Academy turns matching decompilation into a teachable, verifiable skill, which exposes why compiled opacity was never a real security control.
Mirai's hardcoded logins still answer on 554
Open webcams indexed by Shodan and Censys are not a privacy footnote - they map insecure OEM firmware, exposed services, and supply chain risk.
Mythos AI cleared for distribution, no validation report
REDLINE breaks down the security risk in releasing Mythos AI to trusted US organizations: not the model, the missing adversarial validation and zero prompt-level telemetry.
Springer Nature unpinned two papers, no log
Springer Nature removed two Max Planck studies. The real exposure is a research supply chain with no integrity log - the same trust gap as CI/CD poisoning.
The breach was the network working as intended
The 2015 Polish S incident: lateral movement from inherited permissions and automated escalation, where access was granted by position not verified at use.
The camera on the pole has a login screen
Flock cameras are credentialed endpoints inside a trust boundary. The exposure is not surveillance. It is credential stuffing against a standardized fleet.
The surveillance doesn't have to be real
An author alleges Meta surveilled her for 12 months. The act is unconfirmed; the capability is structural and built into centralized identity.
A crafted sprite overflows the blitter's heap
Attack-surface analysis of OpenTTD 160beta1: integer overflow in sprite decoding, untrusted savegame and packet parsing, and why EDR stays blind.