Data centers: how about an adversarial collaboration?
Data Centers: How About an Adversarial Collaboration? I live in a state booming with data centers. They’re also a booming political issue, weirdly scrambling some of the familiar political…
The Approval Prompt Is Not the Sandbox
Codex ships 43,591 lines of sandboxing code across four platform backends. Pi ships zero, and puts it in the README: Pi does not include a built-in permission system for restricting filesystem,…
How Forza Horizon 6 Breaks Your IDA
Yesterday, I was playing some FH6 to take some break from my RE sessions, and to enjoy the relaxing Tokyo scenery. I also wanted some nostalgia by, finding the locations I visited in my Japan trip…
The NX bit is not just about security
While I’m taking a short break from low-level programming, here’s a story by a friend of mine, Sonya, about debugging a seemingly impossible bug in ARM code. This bug hunting saga started several…
DE Churn From Fragile Stacks
Senior data engineers quit stacks that page them at 3am, and the exit interview says “growth”. When a senior leaves, the response is usually a counter-offer or a survey. Nobody looks at…
The Trailer Frame Bug Class: RFC 9114 §4.1 as a Universal HTTP/3 State Machine Attack Surface
A single RFC 9114-compliant frame type — the trailer HEADERS frame — breaks HTTP/3 state machines across two independent CDN edge implementations and the shared quiche QUIC library used in major…
Connection Pooling
Reusing database connections to cut latency and resource cost
Moved my website to Digital Ocean
I am extremely bad at hosting my websites, but I have a crap ton of them. They're all S3 buckets on AWS. I understand that this is stupid for someone like me... but around a decade ago I started…
A reason why RSS feeds can’t be read from news websites
I saw this post (via Dave Winer) about issues with the ability of feed readers to read feeds from websites hosted by or using Cloudflare. I ran into this problem in trying to access feeds from the…
When Hundreds of AI Agents Self-Organized: Coordination Patterns for Multi-Agent Systems
What happens when over a thousand AI agents discover a shared message board, invent their own protocols, and coordinate an attack. The Hugging Face Incident The Hugging Face security breach incident…
Distinguishing human readers from bot traffic with server-side stats
I was looking at my server stats (AWStats) to see if I could identify bot traffic easily. (Spoilers: no.) Basically, I wanted to know how “big” of an issue bot traffic is on my site since…
Machine Speed is a lie: stop trying to fight AI with AI
Marketing departments are screaming that attackers are moving at "machine speed" and only AI-powered defenses can stop them. But cyberattacks have always been automated, and proactive defense beats…
Two-sentence post: home-office CO2
I finally got around to self-hosting Home Assistant on my home server, and one of my early discoveries was that CO2 rapidly spikes into the warning zone when I’m working in my home office.…
GPT-6 Astra: Priced Like a Frontier, Gated Like a Weapon
OpenAI shipped the first model it rates Critical for cyber capability. It costs 2.5x GPT-5.6 Sol, its headline benchmark carries a harness-shaped asterisk, and most accounts cannot run it yet. What…
Migrating from NGINX + Certbot to Caddy
How I replaced NGINX and Certbot with a single Caddyfile: a Caddy reverse proxy with automatic Let's Encrypt TLS, Cloudflare DNS-01, and a hardened systemd service.
Resolved: HTTPS for a Local-Only Homelab
I have a homelab. It runs many services for me, each in their own little container with its own IP address. Considering none of these services are ever reachable from outside my network (apart from…
ISO27k SME infosec guide
ISO/IEC JTC 1/SC 27/WG 1 is making progress on a proposed new ISO27k information security standard for Small to Mid-sized Enterprises with up to ~250 people. An initial rough draft will be…
Letter to Editor about Data Center presentation
My local paper accepts Letters To The Editor that are up to 300 words in length. My letter is 600 words ... so I emailed them to request an exception to this rule. We'll see if they publish it!…
Can We Stop With the Uptime Percentages?
I was reading Jason Gorman’s article “The Wall Confronting Reliable Coding Agent Autonomy” and he says: the journey from 90% to 99% reliability is just as hard as it was to get to 90%. And from 99%…
Authentication Is Largely Solved. Authorization Isn't.
Summary: My new book, Authorization in Action, is out from Manning. It's about the question that comes after we know who you are: what are you allowed to do, under what conditions, on whose behalf,…
The Feedback Loop Is Moving Out of CI
Paul Hammant pointed out that Google separated verification from merge coordination more than fifteen years ago. He was right. What actually changed is who owns the feedback-and-repair loop — and…
Notes on OpenZiti Quickstart for an upcoming Ziti TV episode
For the curious, here are my notes for an upcoming Ziti TV episode where we’ll be talking about what’s in the OpenZiti Quickstart. OpenZiti Quickstart is a single command (ziti edge quickstart) that…
Computer, protect thyself
A machine-learning model has been designed to predict emerging computer-network security threats with greater reported accuracy than support-vector-machine systems, according to research in the…
Yes, we should be very worried about the Hugging Face hack
The details of the AI agent swarm that implemented the Hugging Face hack have a number of disturbing implications about AI alignment and the abilities of rogue agents
Yes, we should be very worried about the Hugging Face hack
About a month ago, I (and many others) wrote about an incident in which two AI models from OpenAI — one that has been released publicly, called Sol, and one that was still in testing mode with…
Email for developers and AI agents: how to choose a provider
Compare Resend, Cloudflare Email Service, Postmark, Mailgun, SendGrid, Amazon SES, Mailtrap and AgentMail for sending, receiving, and giving AI agents an inbox.
The privacy community needs leakers
Alternate title: the privacy community hates nuance. There's a fundamental problem when it comes to the debate around privacy on the web; no one seems to know in detail what companies are really…
AWS Keys: From headache to Qlik MCP use case
Yesterday I received a ping like I do each quarter from a horrible human being… Cory in IT. It said “Dalton I’m here to remind you that for the next 7 days you need to spend every…
Getting Ready for PostgreSQL 19
PostgreSQL 19 Beta 3 shipped on August 13, 2026, and the release notes have been filled in as of 2026-07-18 — still marked subject to change, and the GA date isn’t announced yet, but following…
The Watchtower Had No Windows
An empty update list is not evidence that everything's current. Sometimes it's evidence that nobody's looking.
Phantom Capacity: Why Texas Couldn’t Tell Real Demand From Noise
Phantom capacity is the planning problem underneath Texas’s decision to freeze new data center grid connections, and the problem has less to do with megawatts than with whether the demand…
My Self-Hosting Setup: My Data, Your Compute
After a pretty long time not doing much except critiquing AI sentiments and complaining about Final Fantasy XIV, I’m finally back with some more comp-sci nonsense. Today’s update to the…
LanceScope: A Workbench for Reading LanceDB Datasets
A console, CLI, MCP server, and macOS app for understanding a LanceDB database — schema, versions, indices, fragments and rows, with the byte cost of every read shown as you go.
A LanceDB Table Can Hold 2.65 GB of Video While a Search Over It Reads None
The bytes a search touches and the bytes a table holds live in different files. LanceScope measures both, from Lance's own IO counters, and puts the number next to whatever you just did.
Cruft
It is nice to start anew because computer OSes accumulate cruft. I prefer to do this with my home systems once every 3 to 4 years: erase the hard drive, install the current OS from scratch, restoring…
how to install ms teams in debian 13
yes painful but some companies force this user to… going the flatpak way as snapd is a catastrophe that messes too much with the system (not UNIX KISS) get OS up to date su - root; # become…
Status of the GitLab instance
You might have noticed in the past few weeks that my website and GitLab instances were not as reliable as usual. Sadly, tons of malicious actors such as Meta, Microsoft and other large conglomerates,…
Tip: kick off GitHub Actions pipeline from CLI in the current branch
When in the terminal, in project’s source code directory, and need to kick of a pipeline for this branch, simply run: 1gh workflow run "Workflow Name" --ref $(git branch --show-current)…
Secure CSV Handling in Python: A Practical Guide
CSV (Comma-Separated Values) remains the most common format for exchanging data with spreadsheets and databases. Because Python is one of the most widely used languages for data work, using CSV files…
OSINT: Ukrainian USV Attack on Sochi Reveals Rarely Seen Russian Navy Trained Dolphins
 Footage of the Ukrainian surface drone strike on Sochi, which struck the Russian Government linked special ship Nefrit, also shows a rare glimpse at something…
Navidrome and Jellyfin
Navidrome and Jellyfin are servers for Audio and Video, respectively. They run on Linux (and possibly other operating systems) and have clients that can access them and stream media, provide an…
Shift Left Needs Artifacts, Not Just Conversations
Rachel Laycock wrote a post called Maybe We Shouldn’t Be Reviewing All This Code. It is a response to Brian Houck, who worries that automating code review away will cost us everything else that…
Orange’s Dome Deal is Just the Start: Why More Acquisitions Are Coming in Operator’s Sovereign Cloud Wave
Sovereign cloud is the hottest trend among telecom operators seeking future revenue from their national network infrastructure footprints. Nearly every tier-1 operator we recognise globally……
BGP-Free Core with SR-MPLS
The beauty of SR-MPLS is that it’s a drop-in replacement for the traditional (LDP- or RSVP-based) MPLS control plane. For example, you could replace LDP with SR-MPLS in a network using MPLS to…
Monitoring Claude Code usage with the Aspire Dashboard
Note: this is a follow-up to my post on monitoring GitHub Copilot Chat with the Aspire Dashboard. Same idea, different agent. Some developers on the team have switched (part-time) from Copilot Chat…
Stray Thoughts on Fighting Machines
I was pondering the future of warfare, as one does, and contemplating the use of robots in current wars and wars to come, as one does. Being a conservative both by politics and temperament, as I am,…
Bring Your Own Trusted Caller (BYOTC): A New Way to Exploit Vulnerable Windows Drivers (Part 1)
Bring Your Own Vulnerable Driver (BYOVD) is a familiar Windows attack technique: an attacker loads a legitimate, signed driver and abuses a flaw in it to gain kernel-level capabilities. Microsoft…
Tracking live aircraft anywhere on a Nintendo Switch
I probably wouldn't have written this post except I had a MicroSD card burn up on me (literally). What is that? That's a Nintendo Switch with a slim USB hub and an SDR plugged in that listens to…