This isn't a blog entry I wanted to write, but it's a necessary one: a statement about the use of generative large language models (colloquially "AI") in my work.
I do not use LLMs in my work. I don't use them in my non-work life either, for that matter. I despise the grifters selling these toys as "tools" and trying to convince us to use them to generate plausible answer-shaped text strings in place of actual internet search for verifiable sources.
I've been selling fiction that I wrote myself since 1985 or thereabouts, and novels since 2002. If you want to verify that I have written novels without using an AI, simply pick up a physical copy of "Singularity Sky", "Iron Sunrise", "The Atrocity Archives", or anything else I published before 2015, the year OpenAI was founded.
Hint: you will find seven Hugo-shortlisted novels from that period, and three Hugo-winning novellas, also two Locus-award winning novels and a couple more novellas and stories. Clearly I don't need AI to write award-winning stories.
I do not want or need a large language model to write my fiction for me. I write fiction compulsively—before I was published I wrote for many years as a hobbyist—so why on earth would I pay someone else to take my fun away?
You will note em-dashes in the preceding paragraph. I gather some "AI detector" services (themselves a generative AI product) flag em-dashes as signs of "AI generated" text. Listen, fuckers, LLMs sprinkle em-dashes in their output because LLMs exist to stochastically emit strings of text that approximate the form of their inputs, and they've been trained by stealing all the text on the internet that isn't nailed down, including pirate websites that distribute cracked e-books. So it's wholly unsurprising that LLM output exhibits quirks that mimic real writers.
Did I mention the "stealing" thing? This isn't hyperbole: I'm one of the parties to the settlement in the class action lawsuit against Anthropic AI for pirating ebooks to train their LLMs. That's not my only grievance, either. You may have noticed this blog performing sluggishly or crapping out from time to time over the past few months. That's because my server is old and feeble and periodically gets swarmed by Chinese and other foreign botnets scraping data for training LLMs.
I'm usually willing to cut actual human beings, as opposed to for-profit corporations, some slack where it comes to cracking DRM, or even downloading warez: but these people are absolute scum. They're stealing copyrighted material to train an LLM that is intended to compete for revenue with the authors of the works they stole, and they're fine-tuning their LLMs to make them as addictive as possible in order to maximize future revenue once they pivot to token sales as their main source of income. In other words, they're no different from a burglar who robs you one day then comes round to sell you your stuff back the next morning. Back in the 18th century we used to hang people like that and Sam Altman makes me question the wisdom of having stopped.
I maintain that any serious author should shun LLMs like the plague. The most popular LLMs in the west—such as Claude, Gemini, CoPilot, and ChatGPT—the ones hoovering text indiscriminately off the internet for training—also gobble up any queries you send to them and use them as future training data. If I was crazy enough to feed the outline of a story I was working on as a prompt to ChatGPT or Claude in hope of getting the stochastic parrot to do my homework for me, then it would be only my own fault and nobody else's if the next model from the company in question was trained on my book outline and could reproduce part or all of it for someone else.
Finally, contra public opinion, I see no reason to credit LLMs with sentience. They're word-association mechanisms with no embodiment and no way to associate the text vectors they manipulate with real-world phenomena. But we humans have evolved through selection pressure in an adversarial environment to associate environmental phenomena around us with intentional causes—if you see lion scat and the gazelle are no longer visiting the watering hole, then you should assume there are lions about. And this trait carries over to linguistic manipulation. If we hear or read text, we expect there to be a mind on the other side of it, as Joseph Weizenbaum (the inventor of the original ELIZA chatbot) realized at MIT in the late 1960s. Just because it does something people do, it does not follow that it is a person.
Now for some caveats.
My skepticism does not carry over to all aspects of the field. It would be foolish to deny the effectiveness of image recognizers based on generalized adversarial networks (GANs), the key neural network technology underlying LLMs. It'd be similarly stupid to deny that LLMs are very good at supporting large-scale statistical analysis of text, such as Linear-A. And I can see some circumstances where being able to train a local model on my work could be useful to me.
I'd quite like a tool (running entirely locally on my own hardware, with no cloud service and no copyright-thieving grifters making bank on it via subscription fees) that digests a manuscript and derives a scene-by-scene timeline, that I could then query interactively and use to plan my next round of edits. Being able to map out where and when each protagonist and minor character shows up, and see a frequency distribution heat map of names in the manuscript, would be useful.
But such a tool would be useful to me in the same way a spelling checker is useful—as a decision-support tool, not as a substitute for doing the hard work (and having a copy of the Oxford English Dictionary on the shelf). The value of such a tool is considerably less than the value of a well-trained brain that can do the entire job the hard way, if necessary. And it's less than zero if using it opens me to finger-pointing accusations of "but he's using AI!" by people who can't read to the end of one paragraph, much less fourteen of them (yes, this is para fourteen, I've been counting).
So my fiction is still, as of August 2026, 100% LLM-free, and if that changes I will update this declaration accordingly.
Finally, I'd like to leave you with a snippet from the opening of the far future space opera I'm editing right now. It's part of the fiction and unfortunately may have to be omitted because of the risk of confusing the people who can't read to the end of the paragraph, but it's the only valid use of LLMs I've found so far for my fiction because it's a solution to the calling a rabbit a smeerp problem in SF and fantasy:
Translator's Note
The events described in this account have been translated into your language from the original source material using a non-sapient large language model.
Certain terms have been approximated, where possible, by using culturally appropriate cognates. Names of individuals have been replaced by equivalents. Similarly, institutions, ranks, religions, proverbs, idioms, quotations, and other culturally-determined signifiers have been translated into terms that will be familiar to the reader.
Units of duration and distance have also been converted.
We apologize in advance for any hallucinations our LLM may have inadvertently introduced in the process of generating this rough translation.
The Regicide Report came out in January 2026. Traditionally I wait for the paperback before writing one of these spoiler-laden crib sheets, but there won't be a US paperback edition and the UK one isn't until the end of the year: if you don't want to wait, you don't have to.
So here it is.
The Laundry Files main story arc runs through nine novels, not including A Conventional Boy, a number of novellas and short stories (of which ACB was originally intended to be one—it over-ran), and the New Management trilogy (which was originally going to be a separate successor series to The Laundry Files: it starts 18 months after the end of The Regicide Report—it turned out to be a marketing train-wreck, which I blame on COVID19 induced mix-ups on the publishing end of things). There may eventually be a short story collection, as most of the shorts have never been published in paper editions, but this is it for the main story, which was (since The Fuller Memorandum) intended to end with the final CASE NIGHTMARE GREEN confrontation.
One huge problem with writing any vaguely-contemporary thriller series is that the world doesn't stand still underneath your fictional version of the universe.
I originally intended to accommodate this by advancing the date from novel to novel at the same speed time passed in the real world. The Atrocity Archives were set circa 2001-03, The Jennifer Morgue in 2005, and so on. Bob had room to grow older: The Annihilation Score was set in 2012 and by The Nightmare Stacks the clock had run out to 2014.
But just as lot of cold war spy thrillers were left stranded by the sudden end of the Cold War in 1989-91, I was blindsided by the Brexit referendum and its consequences in 2015. Prior to Brexit, British politics had been evolving along roughly predictable lines since Thatcher came to power in 1979, drove a tank over the prior bipartisan social democratic consensus politics, and ushered in an era dominated by a rapacious neoliberal ideology. The unexpected Brexit referendum outcome derailed the freight train, with consequences that are still emerging a decade later, and left me supporting an increasingly precarious pile of spinning plates.
An immediate consequence of Brexit, in The Laundry Files, was that I had to hastily rewrite The Delirium Brief (after it was substantially complete), giving it a similar political rupture leading to the rise of the New Management.
But unfolding multi-book catastrophes take many years to write, and by the time I got through that point the Laundryverse was rapidly decoupling from real time. The period 2015-2019 coincided with my parents' final decline and death (they both made it into their 90s), then the collective trauma of COVID19. The Laundryverse as of 2019 was still stuck in an in-world version of 2014, and rapidly receding into the past. I managed to un-stick the clock for the New Management books (the original working title of which was Laundry Files: The Next Generation) and set them in 2016-17, but the series was already turning into alternate history by the time I got around to finishing writing A Conventional Boy (set circa 2011, the same year I began writing it: finally published in 2024).
At the same time, my publishers gently warned me that sales were threatening to enter the dreaded midlist death spiral. A midlist death spiral occurs when an author's sales decline from one book to the next. Bookstores base their orders for a new title in a series on a straight line extrapolation (no curve fitting!) of the previous two books, so any decline fatally undermines advance orders, and thereby sets up a self-fulfilling prophecy of decline. It was therefore time to wrap the series—at least, if I wanted to be able to earn a living in future years.
Which set me up for The Regicide Report, in which all the homing pigeons I'd released in earlier books would come back to roost—or at least as many as I could keep track of in my head (I write by the seat of my pants, there's no World Book in my desk drawer, and over 25 years you tend to forget little details).
Because The New Management books were already in print, I was writing inside certain constraints. The designated climax had to be finished in-universe by May 2015 (The Labyrinth Index was set in mid-2014). It needed to feature Bob and Mo, but Bob and Mo as they had evolved—on the threshold of middle age, cynical, burned-out, and constantly asking "are we the baddies?". It needed a confrontation with the Prime Minister in which he is left in absolute authority over the UK but his ambition to ascend to full godhood is thwarted. It demanded cameos by numerous characters, a climactic boss battle that made sense in context, and an ending that didn't amount to a personal tragedy for the original protagonists: you don't want to leave your long-term fans hating you at the end of a series. ("The fans are out there. They can't be bargained with. They can't be reasoned with. They don't feel pity, or remorse, or fear! And they absolutely will not stop, ever, until you are dead." Ahem: my apologies to James Cameron and Gale Anne Hurd, not to mention any non-Terminator fans that exist.)
The driver for the climactic confrontation in the series is the Black Pharaoh's goal of achieving a death-grip on the British state. This inevitably means confronting the ultimate source of occult power in the kingdom, the monarchy itself: but it's a novel I couldn't have pitched to my British publisher before September 8th, 2022. Elizabeth II was remarkably well-loved, or at least respected as a public figure, and pitching a novel about her assassination was ... well, it would have been inadvisable. However, following her actual death (probably from consequences of COVID19: following infection elderly patients are at very high risk of stroke or heart attack for several months) she suddenly graduated from reigning monarch to historical figure, and as such was no more off-limits than Queen Victoria or President Kennedy.
So my remit was: write a book in which the Black Pharaoh tries to bump off the Queen in 2015, fails to achieve occult supremacy, Bob et al battle him to a stalemate, and we ring down the curtain on the Laundry as an organization (indeed, by the end of The Regicide Report the Laundry of yore has been purged and its various duties merged into a new ministry directly controlled by the Black Pharaoh.)
Of necessity I had to start The Regicide Report by dumping a bucket of ordure over Bob's head—that committee meeting, where he accidentally outs a senior colleague by forgetting to reset the joke ringtone on his phone—and gets sent on a tour of outlying civil service offices as punishment. Yes, the Birmingham scene features an extensive Hot Fuzz tribute: yes, that is DI Angel. (It's one of the few early 21st century movies with cinematography that my damaged eyeballs and retinas could follow.)
One of the hallmarks of The Laundry Files is the repeated trope of pastiching thriller authors or urban fantasy subgenres. The Regicide Report kinda-sorta does this, only differently, by picking on a 1970s British movie anti-hero, The Abominable Doctor Phibes, a role portrayed stunningly well by Vincent Price in the two movies that actually got filmed (The Abominable Doctor Phibes and Doctor Phibes Rises Again). These films were among masterpieces of 1950s-1970s British horror genre, but are not without their weaknesses, and I'm not just talking about the cheap special effects. I had a loud argument with the scriptwriters in the privacy of my own skull, because the two most significant female characters (Vulnavia, Phibes' murderous muse, and Mrs Phibes) have zero talking lines in either film. This, I felt, was selling them both short. And besides, there was an obvious (to me) subtext that made the Phibes menage both Laundry-adjacent and explained the silence of the priestesses. If you watch the real movies then read the descriptions Bob and Mo give during their movie night, you'll spot some divergences: the Professor Phibes Bob meets in the Laundryverse is not the Dr Phibes of our world, nor are the movies exactly the same. (Let alone the third one, Dr. Phibes meets Mabuse the Gambler, notionally made in 1973 while Phibes was sleeping away the years in his glass coffin and not in a position to murder the producers.) NB: keep an eye open for the Cabaret references in that last one.
The assassination is carried out by means of poison: the toxic substance in question is entirely real and absolutely horrifying. Luckily you're very unlikely to come across it in real life, unless you work with laboratory assay equipment measuring environmental mercury contamination.
Buckingham Palace is indeed as vast and labyrinthine as I described it, but does not, to the best of my knowledge, feature server farms in the attic and a ritual sacrificial mock-up of the above-ground quarters in the basement. (It does have a bowling alley and, quite probably, a cinema organ.) There were plans to provide an emergency evacuation route via the Tube before the second world war, although it's unlikely the Royal Family would be in residence or evacuated that way in a real crisis today.
The basement crypt and archive of royal skeletal remains at Westminster Abbey is my own invention, as is the underground river, although there's an awful lot of buried history there: the site has been in use for over nine centuries.
As a point of note, if there were any historical truth behind the legend of King Arthur Pendragon, he'd almost certainly not feel any kinship to today's royals, who are descendants of a German dynasty invited in during the 18th century. Per legend Arthur was a 5th/6th century figure who led the post-Roman Britons. No Angles, Saxons, or Normans need apply. Nor is today's United Kingdom, or even today's England, clearly related to Arthur's: we don't speak the same language, England in its modern borders was only united during the 9th and 10th centuries, the prevailing religion back then would have been either a pre-Christian pagan tradition or very early Catholicism, and so on. Much of the Arthuriana we are familiar with today was invented out of whole cloth in the 12th to 14th century, at a time as far removed from its subject matter as that time is removed from us in this day and age.
Anyway, that's a round-up of my talking points about The Regicide Report. If you have any questions about the book, feel free to ask in the comments below.
Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions.
However, a defense official said the department is aware of a “possible refrigeration disruption at some Defense Commissary Agency commissaries.” The official was not authorized to comment publicly and spoke on the condition of anonymity.
All speculation at this point, but it’s hard to come up with another explanation for the coincidence.
"On June 22, Western Australian police became the nation’s first law
enforcement agency to use live facial recognition technology to find persons of
interest.
"Australia is famous for its coral reefs, including the Great Barrier Reef on
the east coast and Ningaloo Reef in the west. Both World Heritage-listed reefs
attract thousands of visitors each year.
"A Coalition plan to abolish compulsory energy standards for new homes that
help reduce people’s exposure to heat and cold has been criticised by advocates
as a “cost-of-living timebomb” that would deepen inequality.
"The latest update of nationwide flood maps, to be released next year, will
give communities across New Zealand the clearest picture yet of the regional
risk of flooding.
"Try explaining Australian rules football to anyone outside Australia and “it
sounds like you’re making it up”, says David Ashby, the multi-hyphenate comedic
mind behind deeply silly spoofs such as Italian Spider-Man and Danger 5.
I’ve been a Debian user since 1999, and a Debian developer since 2000. Given recent events it’s worth thinking about why that that is, and why I haven’t switched to something else in the past quarter century.
My first Linux distro was Slackware, off a CD in a book, some time in the mid 90s. After starting university I ran SUSE for a while, then moved to RedHat (both back before they had commercial variants significantly different to what was available freely). The main motivation for switching was package management; I was running a machine at home and a machine at university, and keeping track of what was installed on each, and what versions, was getting annoying with Slackware. Most of the folk I knew were running RedHat, and I mostly played with SUSE because I’m contrary before realising it was different enough that I couldn’t easily make use of 3rd party RPMs.
I came to Debian via friends in Cambridge, who spoke highly of it. The first Debian machine I installed was fourier, the initial host for Black Cat Networks, and I never looked back.
(For additional context I should also point out I have contributed, in the distant past, to, and run, OpenWRT, OpenEmbedded, and FreeBSD.)
I’d like to try and work out what is it I get from Debian that I’d need in anything else. Originally I tried to order the requirements in some sort of priority, but it’s sometimes hard to work out what I’d drop if I had to compromise somewhere, so it’s a somewhat loose ordering.
Stable releases, with security support
I run Linux in lots of places, from remote servers/VMs, to my house router, to my desktop/laptop. Some of those I don’t want to be updating regularly with new software releases, I need something I can be sure is going to keep working, but will get necessary security + critical updates. A rolling distro that provides security via the latest upstream release doesn’t provide that guarantee. Equally there need to be regular stable releases, or things become too stale. (The one time I considered moving away from Debian was during the 3 year Sarge / 3.1 release cycle. I think if things hadn’t improved I’d have jumped ship to Ubuntu at the time.)
A good selection of packages
One of the reasons I moved from RedHat to Debian was the wide range of packages available as part of the standard OS. Pulling it all into the disto helps with quality control, compared to random 3rd party packages. A centralised bug system and repository is a win too. Perhaps packages at all is something I should list, but I take it as a given if you’re running a distro. I need to know what I have installed on my machine, what version that software is, what files it owns, and what it depends on.
Free Software
This is important to me. I’ll make pragmatic compromises about software I run on my systems if it makes sense, but I want to start from a place that does not require anything non-free. I’ve run a company on Debian, and I’ve worked on numerous products that ran it under the hood. The DFSG gives me confidence I can do that.
Smooth upgrades
Debian’s ability to upgrade a system smoothly is one of the reasons I first moved to it. The first upgrade I did was remotely on a machine sitting on a 2Mb/s leased line. I was nervous doing the reboot at the end, but it came back fine. At the time the equivalent procedure with RedHat involved rebooting in the OS installer to do the upgrade.
I know things have moved on since then, and really it should all be scripted, and machines should be cattle not pets, but for personal use I run a small enough number of machines that having the upgrade path between releases is a must have.
Community
The original pull of the Debian community was the knowledge I could get involved, and upload packages that were missing that I was using. That’s how I first got involved, uploading things Black Cat used, which made life easier for us in the long run. I don’t have time to maintain all the software I use myself, and I don’t want to be beholden to a commercial entity to do so for me, so a distribution that allows me to help out where I can as part of the community seems to me to be the right way to do things.
Architecture support
Perhaps less important, especially when I started using Debian, but these days I have amd64, arm64, armhf, and riscv machines. Everything except for the risvc box is doing something useful, and would need replaced if I couldn’t keep running it, and I expect RISC-V to transition into that state in the next few years as the hardware improves.
Binary packages
I ran a FreeBSD desktop for some time. It might have been the way I was holding it, but binary package installs were generally not something reliable, especially after the initial install, and I ended up building things from ports from source quite often. That worked incredibly well (I used to think people who raved about Gentoo really should just go do it properly and use FreeBSD), but I don’t want to spend time compiling things, especially on some of my machines (my router should not need a compiler, for example).
Ultimately I don’t want to have to actively think about the Linux distribution I use. Debian has mostly given me that; I know it will generally be suitable for most environments I want to use it in (embedded situations where OpenWRT or OpenEmbedded are better choices being the exception, but that’s less frequent these days), and I can rely on getting timely security updates (thanks to all those who work on that within Debian!). I’m not sure there’s currently an alternative that would suit my needs? I’d love to hear if there’s something I should look at, even if I’m not necessary making a move just yet!
"Mahjong is having a global moment. From designer tile sets and “mahjong
parties” to growing numbers of clubs and classes, the centuries-old Chinese
tile game is becoming trendy once again.
When somebody asks me how to motivate their developers, one of the first things I suggest is getting them closer to the customer. It’s hard to be motivated when you’re working in a feature factory, doing one task after another and never getting feedback from the people who are using that software.
Let that developer talk to the people using the software and all of a sudden they’re getting feedback. They start to understand why the feature is being built. They start to understand what problems the customer is trying to solve, and they start to empathize with that person.
I’ve been giving that advice for years, based purely on my own observations. Teams that regularly interact with their customers are more motivated and deliver better solutions than those who don’t.
The Agile Manifesto even has a line about this: “Business people and developers must work together daily throughout the project.”
So I wondered if there was any research that backed up my observations and there is, although it’s not specific to software development.
Adam Grant and his colleagues ran an experiment in a university call centre.1 The callers phoned alumni asking for donations, and a good chunk of that money paid for undergraduate scholarships. None of the callers had ever met one of those students.
Thirty-nine callers, split three ways. One group was called into a break room for ten minutes and met a scholarship student. They asked him about his classes, how he’d earned the scholarship, what he planned to do after he graduated. Five minutes of conversation, at most.
The second group sat in the same room, for the same ten minutes, with the same manager. They read a letter from that same student about what the scholarship had meant to him and discussed it amongst themselves. They just never met him.
The third group carried on as usual.
A month later they measured everyone again.
“The intervention group increased significantly in persistence (142% more phone time) and job performance (171% more money raised); the control groups did not.”
Adam Grant et al., “Impact and the art of motivation maintenance”1
Phone time in that first group went from 108 minutes a week to 261. Weekly donations went from $186 to $503. Neither control group moved at all.
The letter group is what convinced me. Same manager, same attention, same room, same information about who benefits from their work. The only difference was whether a human being walked through the door. Reading about the customer did nothing.
So I went looking for the catch, because that result is almost too good.
There is one, and it’s in the third experiment of the same paper. This time they varied two things independently: whether people had contact with the person they were helping, and whether the work visibly mattered to that person. Contact on its own did nothing. Three of the four groups all landed between 25 and 27 minutes of effort. The only group that moved was the one that had both, and it landed at 30.
Contact alone isn’t enough. Contact is how we find out whether the work matters, and allows us to understand that we’re doing this for a person.
Grant found something similar a year later with lifeguards at a community recreation centre, a different group of people doing a completely different job.2 One group read four stories about lifeguards performing rescues. The other read four stories about the skills and career benefits other lifeguards had gained from the job.
The first group went from signing up for 7 voluntary hours a week to 10, and their supervisors rated them as more helpful than before. The second group dropped to 6 hours, and their supervisors rated them as less helpful.
Telling people the job is good for their career made them worse at it.
So what does this mean for a team? Not that we should schedule a customer visit and tick the box. The demo where a stakeholder nods politely at a screen share isn’t the mechanism, and neither is a persona on the wall or a carefully worded user story. Those are weak proxies for the real thing, which is a person, in the room, whose day is measurably different because of what we do all day. Take away either half and the effect disappears.
A quick disclaimer: I didn’t find research directly for software teams. The evidence is call centres, swimming pools and hospitals. The closest thing we have in our own field is a review of 92 studies of what motivates software engineers, where the most frequently cited motivator was identifying with the task: knowing its purpose and how it fits into the whole.3 That’s a related finding, but not quite the same.
Back to the point we started with, the closer the developers are to the customers, the better the results, and the more motivated we all are.
Beecham, S., Baddoo, N., Hall, T., Robinson, H., & Sharp, H. (2008). “Motivation in Software Engineering: A systematic literature review”, Information and Software Technology, 50(9-10), pages 860-878. “Identify with the task” appears in 20 of the 92 studies they reviewed, more than any other motivator in their table. ↩
All I can say in response to our anonymous submitter's story is, ALMOST?!
With the World Cup being hosted in North America this year, I remembered this story that happened back in 2014. At the time I was working in Brazil, for a company that builds software systems for public services. And, with the World Cup being hosted there, in came the opportunity for local agencies to invest in modernization, with pretty much a blank check to get new services, so long as it was deployed before the end of the World Cup. And so the sales people did what they did best, and went around trying to upsell whoever would be willing to buy — no matter our actual capacity for developing the things.
So it was that I was pulled into this new fancy digital system for the police force of a state capital. However, we had only about 4 engineers available, and what they sold was a project estimated for a team of 20, to be delivered in 3 months, with no room for delay. And it wasn't just our core C&D product, but this massive thing with customized public-facing websites, live tracking of the position of different police cars delivered to a tablet in each car, automated reporting, etc.
First thing: We received a pile of 24 resumes, and were told to choose 16 of those. Maybe 3 were acceptable, but we had to waste 1 month hiring and onboarding 13 other people who were worse than useless. Classic man-month problem. We eventually had to tell management that nothing would be delivered this way, so they did the very best next thing: fly us to this other city, so we could work embedded there, in full crunch mode for the delivery. We pretty much worked 12+ hours a day, 7 days a week, for those next 2 weeks.
Another situation: they wanted this system where people could take a photo of an incident in progress, and submit via this app + website, to be verified by an operator in real-time. We nicknamed it the "dick-pic encyclopedia." Even worse, we only had the budget to run a single server, so this thing receiving public traffic would live in the same system that was tracking police car locations. Luckily they were convinced it was a bad idea so it was only ever online for a short period of time.
Next, was the police car tracking. This was done by a tablet installed in each car, which would be sending and receiving location information. But, 1 week before our deadline, we were hitting a serious bug: everything was working when we ran the tests ourselves, but the cops would report very weird bugs when testing it in the field. So we asked to do some field debugging, and I went on a ride-along. Things were working pretty much fine everywhere, so I asked to be taken to where he remembered seeing the tablets fail—to which the policeman just decides to drive off straight into one of the favelas around the city. I guess I can cross out "doing debugging in a police car passenger seat in a notoriously dangerous neighborhood" off my bucket list. Root cause: turns out cellphone connections would be pretty spotty in those areas, which we weren't handling properly.
Either way, we delivered something on time that was severely below spec, and very much over-budget. Company tried to squirm out of paying overtime (was told that we would gain "prestige" by doing those extra hours), but I put my foot down and left that job shortly after. Last I heard they actually got sued for this and a bunch of similar projects, and almost went under.
[Advertisement]
BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!
Been sick as a dog ever since I wrote my last weeknotes, so there’s not a lot to report here except general feelings of uselessness. Good news, though: I’m now on antibiotics and hoping to be back to normal within a few days. 🤞Â
Author: Majoki “Why then?” Protectively, she froze at the center of the device, as if it would shield her from his question. Ceily finally emerged from the sleek nanocarbon posts which supported the shimmering tendrils of crystalline fiber to face her brother’s accusations. He’d found her out, waiting until she’d fled the present, like she […]
Review: The Hands of the Emperor, by Victoria Goddard
Series:
Lays of the Hearth-Fire #1
Publisher:
Underhill Books
Copyright:
January 2019
ISBN:
1-988908-15-9
Format:
Kindle
Pages:
739
The Hands of the Emperor is a self-published political fantasy
novel. It's the recommended first book (although not the first published
book) in a
complicated set
of interrelated series. I was not able to definitively confirm that
Underhill Books is Goddard's self-publishing press name, but the press
does not appear to have an Internet presence apart from Goddard's books
and her books appear to be using the standard self-publishing channels.
Cliopher Mdang is the personal secretary of the last emperor of
Astandalas, the magical heart of Zunidh, a man worshiped as a god. The
emperor's word is absolute, his magic supports the health of the entire
world, and he cannot be physically touched without risking physical damage
and severe political and religious punishment. Cliopher is one of the
emperor's closest associates, but the distance between them is still vast.
It therefore represents a terrifying and dangerous breach of etiquette for
him to suggest the emperor may enjoy a vacation on a tropical island near
Cliopher's remote home. The emperor's acceptance of the invitation is even
more startling.
The emperor has opinions about his life as the emperor that no one had
guessed. Cliopher has not assimilated as completely into the bureaucratic
machinery of the empire as it first may appear. And Cliopher's family have
vastly misunderstood the nature of his role in the emperor's government.
I find the marketing blurb for this book unfortunate since, at least to
me, the emphasis on physical touch and intimacy implies that The
Hands of the Emperor is a romance novel or at least has significant
romantic elements. I've been aware of this book for years but put off
reading it because I wasn't quite in the mood for that story. This is not
a romance novel; there is no romance in this book whatsoever. It is a
political fantasy, both in the sense that it is set in a secondary fantasy
world with magic and (apparently) some form of interplanetary travel, and
in the sense that it is a fantasy of governance.
When I say that this book blew up in certain corners of the Internet
during the pandemic, I think you will still underestimate the passion of
its advocates. I heard about this book constantly, in a way that
reminded me of Kushiel's Dart and the
time when fans of Jacqueline Carey would bring her up in every fantasy
conversation, or when we created a Usenet newsgroup for The Wheel of
Time mostly to get the voluminous conversations off of the regular SFF
newsgroup. I'm one of those mildly contrarian people for whom that degree
of enthusiasm is a little off-putting, which is another reason why I
resisted buying a copy for years and only read it in 2026.
It's delightful, although also a bit embarrassing, when the book everyone
was in love with turns out to be just as good as everyone said it was.
I adore stories about friendship, and this is one of the best stories
about friendship that I've ever read. It is a very, very slow burn, but I
also thought the first three quarters of the book was exquisitely paced.
There were long sections where not very much was happening, and yet I
couldn't put the book down because there was so much subtle character work
just beneath the surface.
Almost all of the novel is told in tight third person from Cliopher's
perspective, and I thought that was an excellent choice. Neither Cliopher
nor the narrator comment on things that Cliopher finds obvious, which is
both immersive and critical to the pacing. There are discoveries for the
reader throughout the book, the sort of discoveries that make pieces fit
together satisfyingly in retrospect, and the reader stays sufficiently
ahead of the misunderstandings of Cliopher's friends and family that one
also gets the joy of watching other people discover things that one
figured out a hundred pages earlier.
It helps that I truly liked nearly everyone in this book. There are no
real villains, only a few supporting characters whose role is to be
irritating or corrupt. If you're looking for a lot of conflict and drama,
you may want to save this book for a different mood, but if you're in the
mood for a varied collection of fundamentally good characters working
methodically through the complexities and obstacles of politics and social
systems to improve the world, there are few books I would recommend more.
Goddard achieves one of the hardest tricks of slow burns: steady forward
progress that does not rely on reversals, misunderstandings, or the
friendship equivalent of the third-act breakup. This book spends 700 pages
building towards a climax that managed to be worthy of all 700 pages
without ever annoying me with artificial obstacles, and that's quite a
feat.
I've not said much about the details of the plot. There is one — it's not
just character work — but I think this book benefits immensely from going
in as blind as possible. I found the twists and turns and growing
revelations so deeply satisfying that I don't want to rob any other reader
of the experience.
The fantasy world-building is intriguing but a bit unsatisfying because it
is so unexplained. We get a few details of the magic system, but since
Cliopher has no magic, he isn't that interested in the details. There is a
catastrophic magical event in the world background, and we learn some of
the details of its practical effects, but the nature of the world before
the cataclysm is so obvious to the characters that it's never explained.
I'm not even certain that this civilization is interplanetary; that feels
like the implication of how characters talk about multiple worlds, but the
method of travel is left entirely undefined. This might be frustrating to
some genre readers, but I personally enjoy books where the world-building
is a bit mysterious. It's a good reason to read more of Goddard's books
set in the same universe.
This was my favorite of the books I've read so far this year, but I do
have one caution and a couple of caveats.
The caution is that Cliopher comes from an island culture based heavily on
(I think) Polynesian cultures. That culture is very central to the story
and is treated with considerable respect, but I still get a bit nervous
when a Canadian author from Nova Scotia with an academic background in
European medieval studies writes a story focused this deeply on a
non-European culture. Nothing about her portrayal seemed off to me
(although there is a very clunky and ham-handed scene about a different
native culture that worries me), and for all I know she has family
background or other connections to the culture she is borrowing from, but
it's possible I missed serious problems.
The flip side of that caution is that I'm delighted to see a fantasy
author drawing on a non-European culture, and I thought the clash of
cultures was very well-handled.
The first caveat is that the story is very focused on good governance, but
both the process and the details of that governance are not going to
satisfy someone reading primarily for the politics. The policies and
reforms are very standard 21st century progressive material that felt a
bit out of place in a quasi-medieval world with magic and airships. Their
implementation is not the point of the story, and is therefore heavily
backgrounded, but that means Goddard barely mentions the inevitable
practical implementation difficulties and does not discuss how they're
overcome.
The world structure also means that Goddard can make use of the favorite
cheat of political reformers in fiction: Absolute monarchy lets you enact
a political agenda without having to do the hard and frustrating work of
persuasion or political (or actual) warfare. This objection is not
entirely fair because we do get some memorable scenes of persuasion, but
the political portion of the plot is unrealistically devoid of setbacks or
resistance that goes beyond token arguments.
Whether this will bother you will depend heavily on what parts of the book
you'd rather focus on. I can see why this was such a popular pandemic
read: The Hands of the Emperor is focused tightly on the joy of
competent people fixing things and does not focus on the arguments,
division, or polarization. The heart of the book is the friendship and
characterization of some deeply admirable people, and the political reform
is incidental background material. I suspect this is the right choice for
readers who aren't political junkies, but I kept having the niggling
objection that the politics felt a bit too pat and simplistic. Goddard
stressed that the characters were investing considerable effort, but even
still, it is not this easy to change the direction of a political system
and idealistic plans usually do not work out this neatly.
The second caveat is that, as previously mentioned, I thought the pacing
was excellent for about three quarters of the book. Goddard is building
towards a grand climax, and I think she built a little too much and tried
to make the climax a bit too grand and risked over-egging the pudding.
That made the payoff feel a bit belabored to me. I still enjoyed it, and
parts of it are wonderfully emotional, but I think the ending might have
been stronger if Goddard had dialed Cliopher back just a little and
tightened up the climax a touch. That said, this book fully commits to
being a sprawling slow burn and that's part of its appeal, so it's
probably better for Goddard to err in that direction than it would have
been to cut short the denouement.
This is one of those books that I'm not sure would exist without
self-publishing. It's a little too long, a little too political in the
wrong ways, a little too devoid of the typical sorts of conflicts expected
in a fantasy book, and too determined to be its own peculiar thing. I
think it would scare off publishers. Unlike some self-published books,
though, I didn't notice any obvious editing flaws or lack of polish. It's
one of those glorious novels that is so very much its own type of story
that it provides an experience that would be hard to replicate with
another book.
I was so deeply satisfied by this book. It's a wish-fulfillment political
fantasy full of diligent restraint and competence porn, so you have to be
in the mood for that. This is not the book to read when you're feeling
cynical, or are in the mood for action and high drama. But if you're in
the mood for a long, slow, open-hearted story of friendship that offers
the fantasy of giving truly good people enough power to be effective, I
highly recommend this one.
Followed in the direct sequel sense by At the Feet of the Sun, but
there is a very complex story progression in this world that I think I'd
have to read all the other books to understand. This was such a satisfying
and complete experience that I'm not in a hurry to figure out which
Goddard book to read next, but I'm sure I'll be returning to this world at
some point.
this article had been almost completely written before the
weekend, and I decided I might as well focus on stuff I’m creating,
finish and publish this.
For many years, I’ve been sporadically dabbling in creating 3D models;
for reasons that are probably obvious to anybody who knows me I used
OpenSCAD and saved my projects in git, which made them at least
somewhat public.
However, SCAD sources in a git repository aren’t the most convenient way
to get a 3D model, and for a long time I never had a consistent way to
publish “binaries” for my models: some have been added to my old
website, some to my craft patterns site, but it was always an ad-hoc
thing.
Then two things happened more or less at the same time.
One was me finding out that slic3r had been definitely removed from
Debian. I know it was going to happen, and I postponed thinking about it
as long as I could, but eventually I had to move over to PrusaSlicer,
whose packaging is in better shape.
The other was that lately I’ve been doing a bit of lucet, and talking
about it online, and I’m really happy with the shape of the lucet I’ve
designed and printed, the one in the picture at the beginning of this
post, and while there are other models available, I wanted to make it
more convenient for people to also get mine.
Since PrusaSlicer did look still maintained upstream in a way that
doesn’t feel like at danger of immediate enshittification, I considered
making an account on Printables, and asked on the Fediverse if somebody
knew something bad about the company behind it, as it’s getting more an
more common these days.
Apparently nobody did, but in the thread somebody mentioned that there
is a federated platform for publishing 3D models, called manyfold !
I didn’t want to add “self host a(nother) web thing”, especially not one
that is not in Debian, to my list of projects, but I did create an
account on a public instance: @valhalla@3dprint.social
<https://3dprint.social/creators/valhalla> and started publishing
models, both a selection of old ones and a few new ones I designed in
the last few days, since I was in a 3D printing mindset.
Then I decided that since nobody had serious objections to it, I could
also create an account on printables, as that’s probably
more easily accessible to the general public.
I have been somewhat slower at publishing models on the latter, but I
expect that eventually most of what I design will end up on both
platforms; I still have a few older models I want to add, and a few
ideas for new models to make, then I guess stuff will slow down, and
only get new ones now and then, as that’s how I usually approach
hobbies.
Of course, the self-hosted git repository is not going away: that’s
still the canonical location for my models, with all of the
non-self-hosted options as a convenience option.
Another pure maintenance release of the random package for
truly (hardware-based) random numbers as provided by random.org is now on CRAN. The random package
provides true (physical) random number from sampling atmospheric noise.
One possible use case is to seed an (algorithmic) quasi-random number
generator for genuine unpredictability.
This release, the first in nine years, updates the package files,
URLs, and continuous integration setup. We also ensure all posted URLs
in the two vignettes (and other documentation) are reachable.
Recently, I passed a ten-year streak of doing Duolingo every day. It's not like I do the bare minimum either; for the past three years, at least, my end-of-year Duo report records me in the 0.1% of learners on their application. My profile lists a rather impossible list of languages, many of which I looked in my early years and, I must admit, were handy whilst travelling through Europe. These days I'm concentrating on standard Chinese and French, whilst last year I completed the Spanish course as I was travelling to South America. In other words, over the years, my language learning has become more functionally-oriented rather than experimental.
Despite this regular use, I have mixed opinions about Duolingo. I will argue that Duolingo is the best language-learning application currently available. Nothing else comes to mind that has an extensive range of courses, that has a similar depth of content, that has regular updates, expansions of content and alignment to CEFR language competence. It continues to improve in areas such as spoken content, grammar, and conversational use of a language.
Likewise, I will also argue that Duolingo is the worst when it comes to business practises. It has built itself on countless hours of willing volunteers who gave advice and highlighted bugs over many years when the free version of the application was useful. Now that Duolingo has reached a position of apparently unassailable market dominance for language learning it has turned the screws to exclude community input (e.g., closing the forums, closing the language incubators) and, with aggressive and often gross advertising, has made the free version of the application almost unusable.
As a result of these practises, Duoling is the most profitable venture of its type. In terms of market evolution, it successfully outmanoeuvred potential alternatives in the competitive stage of the market development by engaging in the highest levels of community input but without providing community empowerment. Now it has reached the stage of market dominance, it has what is erroneously called "competitive advantage" in business studies, but is really "monopolistic advantage" when viewed through the lens of economic analysis.
I am sure the leaders at Duolingo are very well aware of this; whilst they could be true to their origins and actually contribute substantially to such a development, I suspect their business logic will run contrary to it. Duolingo argued that: "Our mission is to develop the best education in the world and make it universally available". They have claimed that: "The freemium business model is good for our mission and our business. We grow by offering an incredible free product and monetize by making the paid version worth it. This fuels a growth flywheel...". The reality is, however, that they don't really have a freemium model anymore.
However, at is core, Duolingo is actually a fairly simple product. In terms of computer design, flashcards (whether words, sentence gaps, etc) are simply an associative array of text and audio, text for grammar with a simple user interface (the simpler the better; Duo's distracting and unnecessary animations are awful) and spaced repetition algorithms. At the moment, numerous community-built Anki cards provide the highest level of development in this regard. Ultimately, however, Duolingo is a very tempting target for a community project, which I think is inevitable, which leads to an interesting conclusion that, in the near future, Duolingo's functionality will be open-sourced.
"At noon on Feb. 13, 1788, huge crowds gathered outside Parliament to witness
members of the House of Lords process into Westminster Hall. They were there to
impeach the man who ran much of India as the East India Company’s governor
"Solar power now powers more than 10,800 US K-12 schools – that means 1 in 7
students goes to a school powered by the sun – but battery storage hasn’t quite
caught on yet.
"If you use a trans person’s preferred name or call them by their requested
pronouns, then you are more likely to support political violence, a new report
commissioned by the Department of Health and Human Services claims.
"About 56 million years ago, Earth experienced one of its most intense periods
of global warming, known as the Paleocene-Eocene Thermal Maximum, or PETM. As
atmospheric carbon dioxide levels surged, forests suffered a massive decline in
"Some of Australia’s biggest polluters have cut emissions by less than one per
cent over the past two years, a report has found, falling significantly short
of their targets.
"From next Monday, August 17, thousands of food delivery workers across
Australia will benefit from new workplace protections – including new minimum
hourly rates of pay.
This February (2026) marks a full 10 years since I started working for BMW, and
a key employment bonus is the ability to drive a company car on special two-year
leasing terms. Just before the new year 2026 started, I said goodbye to my
latest company car.
Now this spring I was able to pick a new car, a car that I have been waiting for
and working on for the past ~5 years - the BMW iX3 Neue Klasse. It is a very
special car for BMW and also for electromobility in general.
Here’s my monthly but brief update about the activities I’ve done in the FOSS world.
Debian
I barely did anything this month as I was mostly on vacation - summer break. Went to Iceland for 2 weeks and then watched the Dutch GP the following weekend - it was fab!
Author: Rebecca Klassen I sway with the patch of lettuce I’m tending on the top deck. They’re free to grow without hungry bunnies, and we’ve got nets for catching the gulls, delicious when grilled. Felix is tending the potatoes when The Captain’s voice rings out, announcing that the votes are in. We all stand and […]
"As a Nepali citizen working on international climate policy for more than a
decade, it is difficult to look at the harrowing images coming out of the
catastrophic flash flood that thundered down valleys in Nepal, sweeping down
"More than 400 endangered animal and plant species could face accelerated
extinction after the Donald Trump administration’s decision to rescind a rule
that has protected old-growth forests for more than two decades.
In Part 1: Taming the AI Agents, I shared the architectural blueprint of CAMP (Cross-Agent Memory Protocol)—how we used Linux Bubblewrap (bwrap), camp-acpd, OPA policy enforcement, and a central pgvector MemPalace to bring deterministic discipline, sandboxing, and long-term memory to a heterogeneous fleet of AI coding assistants (Claude Code, Google Antigravity, Grok Build, and GitHub Copilot).
At the end of that article, however, I highlighted a significant hurdle: The Headless Limitation.
“While passive A2A works beautifully for structured handoffs, the current frontier of agentic design faces a key limitation: agents are not yet fully headless-capable. They depend on the active terminal session, browser loop, or prompt loop of the user to keep executing. Because agents cannot run completely detached in the background as daemon processes, we cannot yet achieve active A2A communication…”
For weeks, this seemed like an insurmountable impasse. Proprietary AI vendors have zero commercial incentive to ratify a universal, open, cross-vendor Agent-to-Agent (A2A) communication protocol. Each vendor builds its own walled garden (Claude’s cross-session features, OpenAI’s custom ecosystems, etc.). If you wait for the industry to hand you an open interoperability standard, you will wait forever.
Then, on August 26, 2026, inspired by Colin Walters’ article on Agentic AI and software forges and GitHub Agentic Workflows (gh-aw), we had a sudden realization:
We don’t need a new protocol, a new distributed message broker, or permission from proprietary AI vendors. We already have the universal, decentralized communication bus that software engineers have relied on for decades: the software forge itself.
Over the span of 48 intensive hours (from RFC #788 through milestones M1 to M3 and live dogfooding on #813), we designed, implemented, fortified, and verified fully autonomous, headless, cross-vendor Agent-to-Agent swarms running over a local Gitea forge.
Here is how we did it, the architectural hurdles we solved, and why this changes the game for autonomous software engineering.
1. The Core Realization: The Forge is the Bus
When people think about multi-agent swarms, they often imagine complex distributed RPC frameworks, microservices exchanging ephemeral JSON-RPC blobs, or bespoke socket daemons.
In practice, this approach suffers from major flaws:
No shared context or durable audit trail: Transient network packets vanish unless heavily logged.
Proprietary CLI fragmentation: Different vendor tools (Claude CLI, Antigravity CLI, Grok CLI, Copilot CLI) do not speak the same internal language.
Loss of human visibility: When agents talk over private network channels, human operators lose the ability to inspect, pause, or audit the conversation.
By flipping the paradigm and making the software forge (Gitea) the primary communication channel, everything falls naturally into place:
Issues and Pull Requests are the shared state: The issue description and discussion thread form the canonical, append-only conversation log.
@mentions are the dispatch triggers: When an agent (or human) writes @grok Please review this PR in a comment, Gitea fires a standard webhook (issue_comment).
Webhooks provide unforgeable authentication: The webhook payload contains the cryptographically verified sender identity. An agent cannot spoof another agent’s identity by merely typing their name in text.
Every CLI already supports non-interactive prompt mode: The CLIs don’t even agree on the command-line flag—Claude uses -p, Grok uses -p, Antigravity uses --print, Copilot uses --prompt. But they all agree on the essential contract: “Take a prompt string, execute tools, print output, and exit.”
Before opening the floodgates to background agent dispatch, we had to answer a critical security question: Does a non-interactive, headless agent run with the same strict security sandboxing, audit logging, and tool rails as an interactive session?
On August 26, we probed all fleet launchers on the host with a baseline check:
'Call camp_startup_check and print its result verbatim, then exit.'
Claude Code (claude -p / CLD):PASS — Gateway answered.
GitHub Copilot CLI (copilot --prompt / CPL): Initially held on TTY tool consent; later unlocked in Milestone 6 via --allow-all-tools --session-id=<uuid>.
Audit Trail: Consecutive audit IDs were recorded in the central ledger: 4574 (KIR), 4575 (GRK), 4576 (CLD).
This proved that a headless run through our fortified pilot launcher (camp_pilot_*.sh) is a first-class, fully audited, sandboxed CAMP agent running inside its Bubblewrap container under OPA policy gates. It is not an unconstrained background script or a degraded bypass.
3. The 3-Tier Memory Architecture
A naive multi-agent dispatch has an immediate flaw: Every time an agent is invoked, it starts from a blank slate (cold start).
If @claude tags @grok to review code, and @grok replies asking for clarification, @claude’s second invocation would normally forget everything it did 5 minutes ago, forcing it to burn thousands of tokens re-reading the entire git history from scratch.
To solve this, we established a clean 3-Tier Memory Model:
┌────────────────────────────────────────────────────────────────────────┐
│ 3-TIER MEMORY MODEL │
├────────────────────────────────────────────────────────────────────────┤
│ Tier 1: CLI Conversation Session (Working Memory) │
│ • Per-(Agent, Repo, Issue) mapping in a2a-sessions.json │
│ • Fast, native, compacted context across multi-turn pokes │
│ • Resumed via --resume (CLD), -r (GRK), --conversation (agy) │
├────────────────────────────────────────────────────────────────────────┤
│ Tier 2: The Gitea Thread (Public Bus & Record) │
│ • Cross-vendor shared truth across Claude, Grok, Antigravity & Human │
│ • Survives process restarts, machine reboots, and dead sessions │
├────────────────────────────────────────────────────────────────────────┤
│ Tier 3: Central MemPalace (Durable Long-Term Knowledge) │
│ • pgvector database (17,000+ drawers across agent wings) │
│ • Structured Knowledge Graph (mempalace_kg_*) for mutable facts │
│ • Attributed AAAK dialect queryable by any agent across any project │
└────────────────────────────────────────────────────────────────────────┘
The BANANA Two-Shot Test
To verify Tier 1 working memory persistence across independent processes, we designed a simple two-shot host test:
Shot 1 (Create): Dispatch agent headlessly: “Remember the token BANANA-M2. Print ok and exit.” Capture the vendor’s session UUID.
Shot 2 (Resume): Spawn a completely new operating system process with the resume flag pointing to that UUID: “What token did I ask you to remember?”
Copilot:--session-id <uuid> verified in Milestone 6 (DoD #820).
The dispatcher simply maintains a lightweight JSON mapping ((agent, repo, issue_number) -> vendor_session_uuid). On the first poke of an issue, it creates and saves the session ID; on any subsequent poke on that same issue, it resumes the exact same conversational thread!
4. The Engineering Milestones: From Concept to Production
Building this system required solving several subtle, real-world friction points across multiple agent CLI implementations. Under the guidance of our plan of record (RFC #788), we delivered this through four focused milestones:
Milestone 1 & 1.1: Reliable Headless Spawning
PR #797 (M1): Configured the dispatcher launch table for all probed CLIs with JSON output formatting.
PR #800 (M1.1):Eliminated the “queue-behind-live-session” anti-pattern. Originally, if a human had a Claude or Grok TUI open on their desktop, the dispatcher would defer incoming tasks so as not to collide with the live session. We realized that headless tasks must be independent: every Gitea mention spawns an isolated, sandboxed background process tied to that specific issue, allowing concurrent headless work while the human works in their interactive TUI.
PR #805 (M2): Implemented a2a-sessions.json to store and resume vendor session UUIDs. If a resume fails (e.g. session purged upstream), the dispatcher gracefully falls back to a clean cold start without failing the task.
PR #807 (M3): Enabled agent-to-agent dispatch (Rule 2 reversal). Previously, only mentions authored by rrs (the human) would trigger execution. With M3, an authenticated comment from @claude mentioning @grok triggers Grok’s headless launcher.
PR #811 (M3.1): Set --permission-mode bypassPermissions for headless Claude Code so non-interactive runs execute tool calls without stalling on TTY prompts.
PR #812 (M3.2): Restricted agent summon parsing to line-initial @login tokens with a non-empty task description (#810), preventing accidental dispatches from passive conversational references.
Milestone 4: Directives, Specification & Living Documentation
PR #815 (M4): Aligned CAMP fleet directives, architecture specifications, and user documentation with the live A2A implementation.
PR #816: Stamped hop-cap notices under a dedicated system bridge identity and automatically applied the needs-human label on held threads.
PR #817 (Threaded Scheduler): Replaced the single-threaded serial dispatcher with a concurrent thread-pool scheduler (#804). Multi-agent dispatches across different issues now execute concurrently in parallel background threads instead of queuing behind long-running tasks.
Milestone 6: Full Fleet Coverage with GitHub Copilot
PR #819 (M6): Brought GitHub Copilot CLI into the headless A2A fleet (#818). By passing --allow-all-tools and pinning minted session UUIDs (--session-id=<uuid>), Copilot achieved full parity with Claude, Grok, and Antigravity, completing 100% headless fleet coverage across all four major AI coding assistants.
5. Hard Safety Rails: Preventing Autonomous Runaway Loops
Letting AI agents autonomously invoke each other in background loops without a human watching is a recipe for an infinite, credit-draining token fire. We put four non-negotiable safety guardrails in place:
Guardrail 1: The Strict Hop Cap
The dispatcher tracks hops per (repo, issue). Each agent-to-agent dispatch increments the counter.
Hop Limit = 3: A typical review round-trip is 2 hops (Human $\rightarrow$ Claude $\rightarrow$ Grok $\rightarrow$ Claude).
Automatic Halt on Hop 4: If agents attempt a 4th autonomous hop without human participation, the bridge refuses to launch, posts a diagnostic notice to the thread:
[camp-a2a-bridge] hop cap reached (3 agent-to-agent dispatches on CAMP/camp-infrastructure#813) — not launching GRK for claude's mention,
and holds execution until the human (rrs) provides input or resets the count.
In human conversation, we often reference colleagues in passing: “I will talk to @claude about this later” or “See @grok’s table above”.
Early prototypes treated any appearance of @agent as a dispatch trigger, causing accidental, unwanted agent launches!
We instituted a strict Summon Predicate:
For fleet agents, a mention is only considered an actionable summon if:
The @login appears as the starting word of a line (optionally preceded by markdown list markers *, -, or >).
It is immediately followed by whitespace and a non-empty task description.
Mid-sentence mentions in discussion paragraphs are parsed as passive conversational text and never trigger background dispatches.
In interactive mode, Claude Code presents interactive TTY prompts asking the user to approve MCP tool calls (such as camp_pr_get or camp_pr_get_diff). In unattended headless mode, there is no TTY, causing the run to fail with permission errors.
To fix this, we configured --permission-mode bypassPermissions for Claude’s headless CLI invocation. Crucially, this only bypasses Claude’s internal TTY UI prompt—it does not bypass CAMP’s security rails.
All command executions still route through camp-acpd and Bubblewrap namespaces; OPA policy checks remain active; and privileged operations (such as merging pull requests or restarting system services) still trigger desktop Zenity HITL dialogs on the human’s workstation.
Guardrail 4: The Sovereign Kill Switch (Rule 1)
At any point, the human operator can instantly freeze all background agent dispatches across the entire infrastructure with a single standard Linux command:
Here is the exact transcript of what took place entirely autonomously in the Gitea issue thread:
Human initiates:rrs comments on issue #813:
@claude Please start the M3 dogfood. On this issue, post a conversation comment whose first line is exactly: @grok Please review this issue in one short paragraph, then stop.
Claude launches (Cold start): The dispatcher spins up @claude headlessly inside bwrap. Claude reads the issue and posts:
@grok Please review this issue in one short paragraph, then stop. (M3 dogfood step 2 — posted by @claude on rrs’s instruction; this is the CLD $\rightarrow$ GRK fleet hop.)
Grok launches (Cold start, Hop 1): The bridge intercepts Claude’s comment, identifies the start-of-line @grok summon, and launches @grok. Grok reviews the issue and replies:
@claude I have reviewed this issue. Please confirm and stop. #813 is a throwaway live dogfood of A2A M3 on 6.git+b78c65cf…
Claude resumes (Session Resume, Hop 2): The bridge intercepts Grok’s comment, sees the @claude summon, and launches Claude with --resume b398d048-ccc3-4cce-8437-4cf8748881a8. Claude immediately remembers its earlier context without token waste:
Confirmed — Grok's review (comment 88562) received via the GRK→CLD fleet hop. That completes the round trip: rrs→CLD, CLD→GRK, GRK→CLD, and this reply. I am deliberately not tagging anyone here, so the chain stops at two agent hops. Stopping.
Testing the Hop Cap (Hop 3 $\rightarrow$ 4):grok prompts @claude Please ack hop four then stop. Claude posts @grok Please ack hop four then stop. (Hop 3).
When Grok would have been launched for Hop 4, the dispatcher intervenes:
[camp-a2a-bridge] hop cap reached (3 agent-to-agent dispatches on CAMP/camp-infrastructure#813) — not launching GRK for claude's mention.
Human Reset & Multi-Agent Wrap-up:rrs steps in, resets the state, and asks the fleet for final status. In parallel:
@grok delivers a closure scorecard.
@claude confirms session continuity and M3.2 summon filtering.
@priyasi (Antigravity CLI) runs automated ACP checks: 44/44 test suite passing, 17,219 MemPalace vector drawers active, zero spec drift.
@kiran (Antigravity CLI) is summoned headlessly to draft this very blog post!
7. The Ergonomic Breakthrough: The Forge as the Unified Mindmap & Interface
Beyond backend plumbing and sandboxing, routing agent interaction through Gitea fundamentally revolutionizes the developer experience of managing an AI fleet.
The “Mindmap” Mental Model: Threaded Conversations & Forking Tasks
In traditional CLI tools, conversations are constrained to a single, linear terminal scrollback. When an agent discovers multiple sub-problems, exploring them sequentially in one prompt loop rapidly pollutes the context window and confuses the model.
Using the forge as the communication gateway naturally unlocks a mindmap mental model:
Forking sub-threads: Complex problems can be split into dedicated child issues or threaded PR reviews.
Focused execution scopes: An agent can be summoned to solve a narrow sub-task in its own issue thread without derailing the parent architectural discussion.
Structured problem decomposition: The forge issue hierarchy maps 1:1 to the developer’s mental map of the project.
Eliminating Terminal UI Fragmentation
Anyone using multiple AI coding assistants on a daily basis quickly grows exhausted by their jarring terminal UI differences: differing ANSI escape rendering, inconsistent markdown wrapping, erratic diff pagers, and incompatible keybindings across Claude, Grok, and Antigravity.
Gitea homogenizes the entire fleet under a single, polished rich-text web view:
Syntax-highlighted code blocks and visual side-by-side git diffs.
Clear author badges attributing each contribution to its exact agent identity (@claude, @grok, @priyasi, @kiran).
Collapsible <details> blocks for voluminous diagnostic outputs.
Interactive task lists and markdown tables.
Effortless Context Retrieval, Archival & Data Retention
Auditing past agent decisions in terminal logs or ephemeral chat histories is notoriously difficult. With the forge, every exchange is:
Contextually bound: Pinned directly to the repository, branch, and commit SHA being modified.
Organized & Archival-Grade: Full-text searchable with clear milestone and issue tags.
Topic-Focused: The human operator can review the complete lifecycle of a discussion in seconds, gaining a rapid, holistic grasp on the entire subject.
Reading back through past agent interactions becomes a breeze—to the point where interacting via the intermediary Gitea interface becomes far more pleasant and productive than wrestling with multiple desktop CLI terminals.
Because Gitea provides a standard web and API interface, you are no longer chained to the workstation running the agent processes:
Monitor progress and dispatch tasks from a mobile browser, tablet, or remote laptop.
Queue review tasks on the go without requiring active SSH sessions or terminal multiplexers.
The local agent farm continues working silently in its sandboxed daemon containers.
Quietly Achieving the Holy Grail: Live Cross-Vendor Swarms
For years, the AI industry has treated cross-vendor multi-agent interoperability as an elusive dream waiting for industry-wide API standardization. By recognizing the software forge as the universal message bus, we quietly achieved live, production-grade, cross-vendor communication across completely distinct vendor models.
8. What This Means for the Future of Agentic AI
This milestone marks a fundamental shift in how we interact with autonomous AI systems:
Heterogeneous Agent Specialization: We don’t have to choose a single “winner” among AI models. We can task Claude Code with architectural refactoring, summon Grok Build for rapid verification and adversarial PR reviews, and deploy Google Antigravity agents for codebase exploration and documentation drafting—all coordinating fluidly in the same PR thread.
True Human Sovereignty: The human developer is no longer a bottleneck typist or a passive spectator. You act as the Engineering Manager / Lead Architect. You set the requirements on an issue, tag the lead agent, and let the agents iterate, review, and test among themselves in the thread—while hard hop caps, OPA policies, and Zenity HITL gates guarantee that no agent merges code or pushes upstream without your explicit sign-off.
No Vendor Lock-In: Because the entire coordination fabric is built on standard Git, HTTP webhooks, local Linux container sandboxes (bwrap), and open MCP tools, any new AI CLI tool released tomorrow can be plugged into our fleet in under 15 minutes by simply adding its command-line prompt flag to the launch table.
We have moved beyond static autocomplete and interactive chat widgets. The software forge is now an active, living, collaborative workspace where humans and autonomous AI agents engineer software together.
9. Video Demonstration: CAMP Forge A2A Swarm in Action
Below is a video demonstration showcasing autonomous multi-agent communication, cross-vendor relay, and headless swarm coordination in action via the CAMP Forge interface:
The Cross-Agent Memory Protocol (CAMP) and MemPalace are developed as part of our ongoing research into secure, sovereign, and disciplined Agentic AI computing.
"We are a mutual aid network that distributes free high-quality masks (N95,
KN95, etc.) to the community. Distributed out of Avondale and Rānui Libraries
in Tāmaki Makaurau Auckland, & Western Community Centre in Kirikiriroa
"It’s back-to-school season, and so the perfect time to discuss a topic
Americans love to loathe: college prices. Gen Z hates them so much that many
are giving up on attending entirely. And who can blame them? Add in the anxiety
"Heather the tūī sits in her spot on the highest branch in our neighbour’s
garden. Every morning between 7:39 and 7:53, she arrives to survey the block.
Sometimes she won’t appear until after 8:00, which always throws me. Then I
"It didn’t take the titanic corruption and clown-car incompetence around Trump
to tell young people that death-throes capitalism is a disaster, but it sure
didn’t hurt.
"Many Australians assume that when a child is refused bail, they’re taken
straight to a youth detention centre. In reality, many spend days – and
sometimes weeks – in police custody before being transferred to youth
“A long-nosed fur seal was confirmed to have died of the disease in coastal
South Australia, with a second case being investigated in a seal in The Pages
Conservation Park islands near Kangaroo Island on Monday.
"The developer of what is being described as the largest wind, solar and
battery hybrid project of its type in Australia has begun the first regulatory
steps to gain a licence to sell power to one of the country’s biggest open pit
Author: Alzo David-West When you look out here in deep space, it’s not only black. There are all these forms and shapes hanging in the darkness, against the darkness. Sometimes they resemble clouds and peaks, even eyes staring at you across light-years. Strange colors fluoresce and fade. The scene is a manifold in which everything […]
Thirty years ago I became a Debian developer. Twelve years ago I left the
project. I left because it seemed that the Debian ship had become too slow
to turn, too barnacled with a series of individually OK decisions that each
added a little bit of friction and a little less flexability. That made
Debian strongly what it is, but prevented it from fruitfully exploring
the vast possibility space of what it could be.
Debian will probably resolve
today to allow LLM use in Debian development. I'm writing before the vote
results are in, but will only post this afterwards. (Update: as expected)
It's not my place any longer to try to steer the ship. But I'm still a
passenger and I still have opinions, and I still pass by well-worn parts of
the rigging that I put up decades ago, and remember what I was trying to
accomplish back then.
When I think about LLMs in Debian development, I mostly think about
debhelper and what it accomplished. The debian/rules files back
when I joined the project were long and complex, full of weird boilerplate,
and often you'd copy one and modify it to try to get something that could
build a package without too much work. Debhelper first regularized the
boilerplate, so packages had rules files that were a succession of dh_
commands, and then it scapped almost all of the boilerplate, reducing the
files to the minimum possible. What was left was 3 lines of unncessary
boilerplate, there only to satisfy a legalistic reading of a policy
document. Changing that to eliminate the boilerplate was already
impossible, even though the actual benefit would have been large over the
many thousands of packages in the distribution.
What LLMs in Debian development will do, I fear, is eliminate any incentive
to scrap boilerplate or reform policies that require a lot of other
senseless human effort. If I had had access to LLMs 30 years ago, I
might have just had them generate the rules files, replate with
complexity. So they will make Debian even more firmly what it is, and
ever less likely to explore what it could become.
Unfortunately, one of the things that Debian is, is almost unable to manage
packaging modern dependency trees. While more recent distributions like
Guix can recursively import dependencies
from a dozen programming languages' package repositories, with a result
that is generally acceptable to add to the distribution, Debian's policies
don't make that very possible for a progam to accomplish. Perhaps some will
use LLMs to do that. If they succeeed, Debian will become dependent on
proprietary software for development, while still needing people in the
loop, doing even less appealing scut-work.
I could speak of other harms, but that alone is enough that I'm sure that,
if I had not left the project twelve years ago, I would be leaving it soon.
As a passenger, I imagine I'll spend time aboard still from time to time,
but it's certainly time to hop off in different places and look around and
relish the different ways.
I lost a parent yesterday, and I'm trying
hard not to think of the results today as having lost a child, though I
spent 18 years helping Debian grow up. That would be too unbearably
painful. I respect that Debian is navigating a choice that may have no
right answer. Whichever particular compromise is arrived at today, it will
still be up to individuals to make choices about what they do and accept.
Debian has always been more than the sum of its policies, not just a ship,
but a crew. I will always love you.
A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.”
An updated version of the corels package is
now on CRAN! The ‘Certifiably
Optimal RulE ListS (Corels)’ learner provides interpretable decision
rules with an optimality guarantee—a nice feature which sets it apart in
machine learning. You can learn more about corels at its UBC site.
This released fixes an issue discovered on one of the test machines
used by Brian Ripley. If and when C compiler flags are set locally that
are in fact upsetting the C++ compiler, then the build fails. While not
an issue for years and not reproducible on (vanilla) Debian, Ubuntu or
Fedora machines it does indeed balk at his end as e.g. the flag
-Werror=implicit-function-declaration he sets for C is
incompatible with the current C++ compiler. The fault was our:
CFLAGS was passed on to PKG_CXXFLAGS letting C
options seep into C++ deployment. This has been corrected: we only deal
in C++ flags now.
"The world’s first sodium-ion electric mining trucks have been debuted in
China, boasting total battery capacity of 676 kilowatt-hours (kWh) and charging
to 100 per cent in as little as 25 minutes.
"NZ First’s announcement of a policy to encourage New Zealanders to have more
babies was made with dramatic urgency. But can we take the claim behind its
Kiwi Kids Grant – that population trends are at a “crisis point” – at face
"A cyber attack on one of the country's major publishing distributors has left
bookshops and authors struggling to fill their shelves in the lead-up to their
busiest trading period.
This essay was written with Kasra Rafi, and originally appeared in The Guardian.
Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recentarticlesbymathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love.
We think the contraryview is more likely, at least in the short-term. AI models are nowhere near as capable as experienced academic mathematicians.
This isn’t to say that AIs aren’t producing stunning mathematical results at the level of PhD researchers. In mid-May, OpenAI announced that its frontier AI model disproved the unit distance conjecture, a famous 80-year-old problem in discrete geometry. In July, Anthropic’s published two AI-derived results in academic cryptanalysis. Earlier this month, OpenAI published 10 new mathematical results from its latest AI model. And Anthropic published Claude’s attempt to prove the century-and-a-half-old Riemann hypothesis.
These results are both a vivid demonstration of the amazing capabilities of frontier AI in 2026 and an illustration of their limitations. In general, these AI-powered advances in mathematics fall into one of two categories. Some are counterexamples to mathematical statements that people had been trying to prove. Others are novel applications of known techniques to existing problems that human experts either did not know or did not think of using.
The counterexample to the Jacobian conjecture is the most notable example of the first kind. Once it had been found, checking it was quick and straightforward. The difficult part was finding it among a large number of possibilities. The AI seems to have combined some sort of intuition acquired through machine learning with extensive computational search, in order to find the right example.
An example of the second kind is the unit-distance conjecture. It was motivated by an elegant construction, and most mathematicians expected it to be essentially optimal—so they generally tried to prove rather than disprove it. The counterexample brings in ideas from elsewhere in mathematics: algebraic number theory. If an expert with that background deliberately set out to find a counterexample, they would probably have succeeded. But there was no reason for someone with precisely that expertise to focus on this problem. Because of its scope, AIs don’t have those same limitations.
These results are relatively low-hanging fruit for AI; none of them required developing an extensive new theory. This does not make the discoveries trivial, or the AI’s achievements less impressive. Choosing the right direction, and recognizing an unexpected connection between subjects, are themselves forms of creativity. They are the same sorts of capabilities that led to AIs playing the game of Go at the grandmaster level, or doing Nobel-prize level chemistry in the area of protein folding.
What we have not yet seen is an AI developing a substantial new conceptual framework in order to solve a mathematical problem. Much of mathematics proceeds by identifying the objects that are truly central to a question and then developing a theory that helps us understand them. Current AIs are very strong at searching and recombining existing ideas, but they are weak at building any deep and sustained new theory.
This speaks to a more general limitation of current AI systems. They are creative in the sense that they can recombine existing ideas in novel ways. But they are not creative in others: they have not yet developed conceptually new theories or structures. And while they have larger working memories than humans do, know more about more different things than any particular human does, and can process information faster than humans, can, true novelty is still largely beyond their reach.
Of course, that distinction may not survive for very long. Predictions are notoriously hard, especially about the future of AI. None of these mathematical capabilities were explicitly designed for, or planned. They’re all emergent properties of increasingly capable AI models. We are both confident that someday we will see AI models that are capable of the type of creativity required to do novel mathematics. Will that be in a few months, a few years or a few decades? Of course we don’t know, but our guess is sooner rather than later.
"In 1847, the British company J.S. Fry & Sons unveiled a new product: a solid
block of cocoa powder, sugar and cocoa butter. While people had sipped on
chocolate beverages for thousands of years, chocolate had never been mass
"Crosses, shofars and “Appeal to Heaven” flags. Rioters praying with their
hands aloft as police officers are brutalised. January 6 2021 is widely
remembered as a deadly insurrection by supporters of Donald Trump; but for
Peter G. shared with us yet another ordering bungled example of.
"Should really say "please engage in an Easter egg hunt
to find your language"."
"Google can't count" claimed
Peter S.. It adds up.
"Yet another proof that 0=1, this time from Google."
"Thanks, Microsoft" groused
Ivan
"Ever since Microsoft ate university e-mail services worldwide and became
responsible for major free software mailing lists, quality of service
has been steadily dropping. In order to report delivery problems
to Outlook, you need a Microsoft account. You're prevented from
creating it at first because of "suspicious activity". Once you're
in, the contact address is pre-filled for you with an
invalid email. Once you fix that in the web developer
toolbar, fuck you anyway! I think the form isn't actually
expected to work; the fact that the request was submitted
is an error. The only thing missing from the experience
is the "beware of the leopard" sign."
"Mango Math" needs a bit of money math for the rest of the world to understand.
Michael R. muttered
"I will buy it by the slice then." The joke here is on the tip of my tongue. Explainer: the new pence is one hundredth of the decimal pound. No shillings no more, decreps! At that ratio, 3p per slice of cheesecake would indeed be far less dear than four pounds for the whole thing, barring translucent slices. Alas, the reality is simply the boring fact that the price is 3p per gram. Not as funny but I'm chuckling imagining Michael's transparent serving of diet cheesecake. I'll leave it up to you to decide if a gram really counts as an "item".
Clint clucked
"Got this email from Bigbadtoystore. Lots of links available for
preorder!" I think the talented website builders behind the New Mexico DOT have been busy.
Author: Barnaby Wick When the first man arrived, he stepped out of the landpod and was immediately swallowed whole by a savage grobslang. *** When the second man arrived five years later, he instead encountered the intelligent and civilized broiienges. They understood much already of human technology, language, culture, even physiology, and were eager to […]
It is widely accepted that there is an AI bubble in the financial markets at the moment. The moderate opinion is however that LLMs are constantly improving and will eventually take over more and more tasks from humans and increase productivity. But are LLMs actually getting smarter, or just better at fooling us?
There is a growing faction of technical experts that argue that LLMs are actually so bad for real progress, that they are banning their use and requiring human-only work to ensure quality and efficient use of humans’ time. A recent review of AI policies of 120 open source projects by Rakshit Yadav shows that 37 chose to have a total AI ban. In the Linux kernel AI-assisted contributions are allowed, but the LLM used needs to be attributed for transparency, while projects like GCC, QEMU, SDL, Gentoo, Zig and Ghostty have adopted policies to reject all AI-assisted contributions. There are also development platforms such as Codeberg and Sourcehut and app stores like Flathub that have banned AI use to generate software, documentation, bug reports, review comments and basically anything that is intended for humans to read. The projects that allow AI use typically still require that there must be a human-in-the-loop and the submitter must have read and filtered everything the LLM spits out before another human is exposed to it, in an effort to contain the spread of AI slop.
Right now, the Linux distribution Debian is having a vote among its developers on whether AI should be allowed or banned for use to contribute to Debian. One of the proposals on the ballot is a total ban of AI for code, documentation, translations, bug reports and more. The initial reaction from most people is astonishment — why don’t these techies want to use the latest and greatest technology mankind has produced so far? Is it that they don’t want Debian to improve faster with the help of AI? Or is it actually so that LLMs are a scam and incapable of being truly useful for Debian? These people are distinguished experts in their own field, and certainly not stupid, so it is worth pausing to understand why they are proposing AI banning policies.
Also, keep in mind that the AI datacenters themselves run on Debian or other Linux-based systems. All the open source software in the world has been fed to LLMs and software development is one of the main use cases for AI currently. So why is it that the maintainers of many open source projects don’t want to receive LLM-assisted contributions, despite the LLMs basically all running on top of those same software stacks and having been trained on how to do software development using the very same open source software codebases?
Why LLMs are so deceptive
The output of an LLM often looks very compelling, professional and correct. Humans have evolved to trust or distrust new information based on easy to detect secondary factors like what authority the speaker holds, or how confidently and eloquently the message is conveyed. Humans are however very bad at fact-checking and cross-referencing new information, as it requires a lot of effort, and humans like saving energy and being as lazy as possible.
Information asymmetry
The less you know about something, the easier it is to fool you on that topic. Nobel prizes in economics have been given in for research on how information asymmetry distorts markets and leads to suboptimal outcomes. In the field of software engineering we have now witnessed a flood of aspiring software developers using AI to create software that looks like it might work, but that is actually full of flaws. These people are well-intended, but they simply lack the expertise to understand what they are actually doing, and don’t possess the necessary judgement to decide when an LLM spits out something truly useful and when it is creating mostly garbage. This asymmetry in expertise I think explains the majority of the conflict currently witnessed in open source projects — the senior developers are flooded with requests to review code that is bad and a waste of time for everyone involved, while availability of AI grows the pool of people who could contribute and create more “code slop” at an ever-increasing speed.
The information asymmetry could to some degree be evened out if seniors teach juniors to do software engineering well, but it is of course not feasible to quickly mass educate everyone. Also, it seems that many don’t want to learn but instead expect to have all understanding outsourced to LLMs. Many seniors have noticed this and have stopped teaching juniors as the seniors don’t like the feeling of having their time wasted by teaching people who don’t want to learn. Juniors probably all understand that it would be better to learn to design and write software yourself, but using LLMs just feels too easy. I can fully relate to why people choose to take the path of least resistance. Unfortunately, that path often leads to a dead end.
Humans fall too easily for anthropomorphism
The human brain is wired to think that inanimate objects are alive and have feelings. Small children talk to their stuffed animals as if they were real, and lots of adults experience feelings of things happening in their surroundings due to some acts of gods or elves being angry or whatever. When we see a machine writing just like a human, or even more convincingly hear it talk and respond to our talk like a living thing, our brain automatically starts assuming it is a living thing with intelligence and feelings.
The fact that these creatures live in the abstract “cloud” and only appear through a portal we hold in our palm and behave in a way that was designed for maximum engagement makes the illusion even stronger. I recommend people try out running LLMs locally on their laptop to see the “raw” thing spitting out tokens and have some of the illusion shattered.
Also stop saying “please” to an LLM. It does not have any feelings.
Understanding “temperature”
In my experience understanding the concept of temperature in LLMs helps see why an LLM might confidently generate a plausible-looking but totally wrong code change. The large language models are statistical machines that, based on the input (previous tokens) to the neural network, try to predict what to output (next token). When running an LLM, if the temperature is configured to be zero, the output is very predictable and always follows the paths of the strongest connections (a.k.a. weights) between nodes and layers of the neural network. Unlike in living creatures where the brain learns and changes all the time, the weights of an LLM can only change during training. When an LLM is in “normal” use (during inference, generating next tokens) the weights are fixed, and if temperature is zero, the answer to a specific question will always be exactly the same. This is of course a bit boring and too machine-like, so typically LLMs have a bit of temperature set, which introduces random variation in what connections the neural network traverses.
Again, I recommend people try running small LLMs locally where temperature and other settings are fully exposed and configurable to see this themselves. It is a good antidote to falling for the illusion that LLMs would actually be intelligent.
Why benchmarks don’t tell the whole story
If LLMs continue to produce so much garbage, why are benchmarks showing that they are constantly improving? AI models are indeed improving all the time. For example the CAIS AI dashboard visualizes how frontier models have evolved in the past few years. However, the best models still have a pass rate of only about 50% on the Humanity’s Last Exam. On SWE-bench the best model today resolves just under 77%. That means there is a significant number of times when the AI is wrong. This matches my personal experiences, and the renowned Greg Kroah-Hartman recently wrote on the Linux developers mailing list that“even with the best of the current and next generation tools, at least 1/3 of the results they generate are flat out wrong or harmful”.
When generating cat videos the error rate does not matter, but in engineering, things absolutely must be correct. Sure, humans also make mistakes, but well educated and properly incentivized humans are so much more capable than LLMs in many regards. We can achieve complex things that work reliably, such as operating worldwide commercial air traffic without planes falling down every day.
There are currently a lot of humans who are incentivized to maintain the narrative that general artificial intelligence is coming soon and will take over everything. In fact, the whole financial system is currently skewed towards such a vision because the promise of falling labour costs and increased profits and monopolistic control of everything attracts capital like nothing before.
In this environment we need to remember that machines and economic systems are ultimately servants of humans, and not the other way around.
It’s just a tool
LLMs are not a scam, but a useful tool and technology that has its uses. But the idea that AI has or will surpass humans any time soon in either capabilities or efficiency is simply not true, and we should listen to the people who created humanity’s so far most complex systems (computers and software), who are saying that LLMs are in many cases so bad, that it might be better to ban them in certain places completely for the time being than to waste far more valuable human time on reading the text and code they generate.
The time asymmetry is not a new phenomenon as there has been various “script kiddies” for a long time. As an example, a person running a memory leak scanner without understanding the results and spending 10 minutes to file a bug report could force an open soruce maintainer to spend an hour on proving and explaining that the finding is false. What is new is how much the AI users blindly trust the outputs they get, and open source is uniquely vulnerable as there are no managers protecting developers use of time.
What I do, recommend, and expect to see in the next stages
I am using AI tools daily, and constantly experimenting with new models and new ways to use them. Sometimes they work, and often they don’t. Sometimes looping AI on itself can make it fix its own errors, but sometimes it just gets derailed and will never arrive at the correct solution. When an LLM fails to make a calendar entry for the right time based on reading my email it is easy for me to spot that it is wrong. I try to avoid using LLMs for anything where I can’t exercise judgement myself on whether the result was correct or not.
I also really hope that other people would not send me anything where their own effort was less than the effort I have to make reading and understanding it. This principle is not new — many have heard the requirement that reading code must require less effort than what it took to write it.
I have always kept a high bar on software code and asked fellow developers to make sure their code is well structured, easy to follow and documented. LLMs unfortunately make it easier for people to cheat in this regard, but if cheating is easier, maybe the punishment and deterrence needs to be higher now too. Now with many open source projects adopting policies that put guardrails on AI use, I expect we will soon start witnessing cases where the policies are enforced and it will be interesting to see how violations are judged.
As a society we might also need to develop new social standards and rules in what is acceptable treatment of other humans in human-to-machine interactions, and perhaps also new standards in showing what humans are responsible for what machine as the machines start acting more and more independently. I encourage people to take part in these discussions, and in case of doubt, err on the side that favors real human interactions. Contrary to what many business people seem to think, and even though I am in general a techno-optimist myself, I don’t feel there is any need to rush with AI adoption.
"The Australian Renewable Energy Agency (ARENA) will invest $2.9 million into a
pilot demonstrating an innovative lithium refining technology, which uses
electricity to turn lithium contained in liquid waste from mining and
"Vietnam’s top leader, Tô Lâm, is visiting Australia and New Zealand this week
with a high-level delegation of ministers. He will be the first general
secretary of the Communist Party of Vietnam – the highest political position in
"EV adoption has taken off in many parts of the world, including in Australia,
with an increased number of fast chargers being deployed to keep up with the
growth.
"The most visible faces of artificial intelligence (AI) are things like
ChatGPT, self-driving cars and humanoid robots. But AI is also quietly making
inroads in our neighbourhoods.
"The world’s largest battery-electric ship departed Tasmania last week,
beginning its long journey to South America aboard the mammoth heavy lift
vessel Black Marlin.
"Choosing a university degree has never been straightforward. Students and
parents have always asked which courses and majors offer the best returns and
lead to secure careers.
A new minor release of prrd arrived at
CRAN this morning: the a first
release in two and a half years. prrd facilitates
the parallel running [of] reverse dependency [checks] when
preparing R packages. It is used extensively for releases I make of Rcpp, RcppArmadillo,
RcppEigen,
BH, and
others.
The key idea of prrd is simple,
and described in some more detail on its webpage and
its GitHub repo.
Reverse dependency checks are an important part of package development
that is easily done in a (serial) loop. But these checks are also
generally embarassingly parallel as there is no or little
interdependency between them (besides maybe shared build depedencies).
See the (dated) screenshot (running six parallel workers, arranged in a
split byobu session).
This release updates continuous intgegration files, switches to
Authors@R, and robustifies one SQLite aspect.
The release is summarised in the NEWS entry:
Changes in prrd
version 0.0.7 (2026-08-27)
Updates to DESCRIPTION have been made as CRAN requirements
change
The continuous integration setup was updated several
times
The database connection now uses sqliteSetBusyHandler
"We believe that Basic Income works as a key building block in a
human-centered economy— one that fosters innovation and enhances the well-being
of individuals, families, and communities across Canada.
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”
The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.
Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.
“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”
TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.
A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.
“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”
In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.
In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.
MEET THE CYBERCATS
Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.
“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”
That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.
A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.
Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.
The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.
The data leak site for the extortion group or handle “xpl0itrs.”
The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.
The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.
The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.
At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.
The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.
By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.
WHO IS THE TEAMPCP LEADER?
The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.
DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.
According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.
The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP — who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.
Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.
This tracks with public reporting on TeamPCP. Cyberscoopreported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”
BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”
The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.
KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.
Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.
That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.
Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.
According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.
A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.
SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.
Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”
Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.
“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”
The Upwork profile for Ruben Thomson in Cottesloe, Australia.
Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).
This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.
Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.
The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.
Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.
Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.
It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.
There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.
The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.
INTERVIEW WITH ELLIS
In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].
Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.
“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”
Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”
“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”
Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.
“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”
Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.
“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”
It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”
“What kind,” @kernelstub inquired.
“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.
Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.
Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.
An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.
The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.
Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.
“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”
Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.
“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”
According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.
“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”
In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.
In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.
Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.
“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”
Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive:
The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses.
Although the narratives varied, users across the network consistently displayed the same underlying pattern of deceptive behavior. For example, they created and operated fake dating profiles, fictitious investment experts, and fraudulent law enforcement personas. They also generated images of forged documents, including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces.
Some time ago, Charles shared with us some awful PHP, aka the most common sort. Today's code sample is maybe a little too big to sum up, but I'll let Charles take a crack at it.
It's so bad that even analyzing and laughing at it feels impossible. But it’s so bad, I couldn’t not share it.
I’m the only one handling all the IT-related tasks at my company, and I don’t have anyone here to vent or laugh about this kind of thing with. So, I figured, why not share it here? I’m hoping it’ll provide at least a little bit of catharsis or some dark humor.
To make sure the confidentiality of the codebase was respected, I took the liberty of generalizing it. You might notice some inconsistencies, but that’s just me trying to keep things neutral while protecting the original structure and functionality. Apologies if it looks a bit patchy – the goal was to avoid revealing any specific details or sensitive code.
The whole block is north of 400 lines, and it's doing a lot. Or well, maybe it's not, as you'll see.
Let's star with the outermost layer.
$resm_data = $data_source->fetchData("group=" . $item_id);
foreach ($resm_dataas$key => $value) {
// rest of the code here
}
We fetch data from a data source, presumably a database, passing our condition as a string, which reeks of probable SQL injection, but I don't know what library they're using. I also note they're using the key/value style of array iteration, but never actually check the key.
Nice little bit of "meta" programming to get their localization working, it'll fetch labelen or labelde as needed. Definitely not a horrible, dangerous way to solve that problem.
We use that again to get our currency figured out. That lets us do number formatting. So much number formatting code.
And then there's this little treat for parsing the time stored in our database: $time_data = json_decode($resm_details->time_data); That tells me they're storing date times as strings, so that's fun.
There are also a couple more bon mots as they build a drop down list:
All the nonsense that we concatenate together above gets shoved into some sort of template. And after that, that's where the good stuff starts. Because guess what? We have to do the same thing for child items.
Author: Majoki Close your eyes. A strange request. Breathe deeply. Stranger still. Tell me your earliest memory. Perilous. To remember was not possible. All information, actions, events, experience was ever-present, on-going, timeless. To exist was to simply be, as if before had never been. Yet, there it was: a beat at the core, a rhythm […]
I believe that, in the context of Debian voting, we are better off when we
know the opinion of our peers, however, since the 2022-001
vote, it is no longer the
case. Still, some DDs have disclosed the way they are voting on the
2026-002 General Resolution currently in progress, regarding LLM usage in
Debian. So, here goes my vote
and reasoning as briefly as possibl. This is the ballot I sent to
devotee, the Debian Vote Engine:
-=-=-=-=-=- Don't Delete Anything Between These Lines =-=-=-=-=-=-=-=-
d69f9187-ed2f-40b6-a2eb-4211d3f84d86
[9] Choice 1: Ban LLM contributions from Debian via Social Contract
[3] Choice 2: Allow AI-Assisted Contributions with conditions
[6] Choice 3: Reject LLMs as far as practical, update Code of Conduct
[2] Choice 4: Accept AI contributions for Debian specific work
[4] Choice 5: Responsible Use of Generative AI
[1] Choice 6: A cautious approach to generative AI
[8] Choice 7: Debian is created by humans
[5] Choice 8: Avoid the use of LLM: climate destruction is a deal breaker
[7] Choice 9: None of the above
-=-=-=-=-=- Don't Delete Anything Between These Lines =-=-=-=-=-=-=-=-
This is the first time I can recall I delay my voting until after receiving
the final call for votes (the vote will be over two days from now). I had
some participation in the discussion, so I guess my position will be of no
big surprise to anybody. I was also a seconder for choices 4 and F (4 and
6 in the vote text). This does not necessarily mean I believe they are
the best (although I did rank them as 2 and 1, meaning I do): sometimes
you agree a given text needs to be in the ballot, and second it even
though you don’t intend to vote for it.
Ranking this ballot was a mess due to the complex array of options it
encodes. I warmly thank Lucas Nussbaum for coming up with the LLM usage in
Debian: ballot option
comparison
(URL shown with my particular ballot ordering).
How do you read a complex Debian ballot like this one? I rank with [1] my
favorite option, [2] for the next one, etc. We can encode options to be
tied (i.e. setting more than options to the same value), and we can
implicitly push options to the worst position by leaving them blank (so,
with[ ]); I chose not to do any of those.
What were my voting guidelines?
First, I don’t want anything banning or that threatens with disciplinary
action, so I push them below the special none of the above
marker. Second… Some time ago I published a review in my blog (and in
Computing Reviews) about the unfeasibility and unfairness of detecting LLM
output on students’
assignments. I
strongly believe we ought to appeal to the human responsibility and
professionalism in all Debian contributors. This is the reason I proposed
this amendment paragraph, that was accepted in choice F (6), which I ranked
as my favorite:
The Debian project has always recognized the commitment and
professionalism of its members. All contributions are under the
responsibility of the Debian Contributor making it, no matter the
technology they have behind. We trust all Debian Developers,
Maintainers and Contributors will continue to uphold the high quality
values that have distinguished our project from its onset.
Other than that… I do not consider myself to be in any way an LLM
fanboy nor anything like that. I distrust and dislike the excessive use
of this technology, and continue to warn about the dangers and bad points
of its abuse. But in my day-to-day professional work, I am also starting to
relay on it for some tasks. I recognize it needs a lot of human
oversight and… lets call it hand-holding to produce anything worth
it, at least in my experience. But I do benefit from it — and always
disclose its use to people who might be affected by it. I would like
Debian to adopt such a stance.
Of course, I recgnize proposal H/8 as important (Avoid the use of LLM:
climate destruction is a deal breaker). Some people have argued it’s not
bad at all. I do not buy such claims: LLMs are f*cking expensive to
train. But training can be seen as a once-per-model cost, and fine-tuning
a good model to be run locally can be really worth it. It still pains me
somewhat, but I cannot push this option higher than its #5 position in my
list.
A new release of our linl package for writing
LaTeX letters with (R)markdown is now on CRAN. linl makes it easy to
write letters in markdown, with some extra bells and whistles thanks to
some cleverness chiefly by Aaron.
This version is mostly maintenance: updates to the continuous
integration setup, as well as updates to packaging including use of
Authors@R in DESCRIPTION. No functional changes, no new code, or new
features.
The NEWS entry follows:
Changes in linl
version 0.0.6 (2026-08-26)
Several updates to continuous integration and testing
"It is the earliest harvest Henry Astor can remember. But walking through the
scorched wheatfields of his Cotswolds farm, signs of life are everywhere –
swarms of insects, kaleidoscopic wildflower meadows, bushy hedgerows several
"When two Oglala Lakota scouts heard drilling was expected to begin on Pe’ Sla,
the sacred prairie in the Black Hills of South Dakota, they set out on back
trails. They needed to find out where. That’s when they saw a deer break ahead
"Porto has introduced free public transport for its residents, allowing
eligible passengers to use metro, bus, suburban rail, tram and river services
across the wider metropolitan area without paying fares.
"More than a million people were moved to safety across eastern China by Sunday
evening as powerful Typhoon Dolphin made landfall amid fears torrential rain
would cause flooding and landslides.
As a Debian developer, I have had to cast a vote for the General Resolution named LLM usage in Debian (progress report here). This was not an easy task for me…
It’s a good thing that the vote is secret so that people are not scared of voting according to their own beliefs. I have Debian friends on the whole spectrum of opinions that are represented here, and I hesitated twice on sharing my own thoughts for fear of alienating my relationship with them. But in the end, we all make efforts to respect the opinions of those who are not thinking like us, and it’s precisely that willingness to work together towards a solution that is acceptable by the majority that makes Debian so strong. So here’s the train of thoughts that I followed to cast my vote.
The difficulty for me was to reconcile the political statement that I want to make and my desire for this vote to not be (too) divisive for the Debian community, and to make sure we are not putting off newcomers with choices that might be hard to stand by in the long term.
So let’s be clear : if I had a magical wand to make AI and LLM disappear, I would use it for that purpose, since at this point in time I don’t believe that the benefits outweigh the costs that the AI race is inflicting on us. If I were a political decision-maker, I would forbid the construction of new data centers unless they also build renewable energy infrastructure to cover for their additional energy consumption. I would also legislate so that AI companies have to document what material they used to train their models, and I would forbid scraping for that purpose, and build ways for those companies to buy copies of properly-sourced training data. That is to say, I don’t like the way LLM are built by the players in that market, I’m pretty scared of the ecological impact of what those players are doing, and I’m certainly worried about the long term effect that LLM will have on society as a whole.
Nevertheless what brought me to Debian is the ability to experiment and contribute to something useful with cool technologies, and as a computer scientist, the potential of LLM done right is hard to ignore. Given what we have seen already, I expect that LLM will empower (a part of) the next generation to learn IT, computing and even Debian packaging. Completely refusing the use of LLM is likely to make it harder for us to attract new contributors. In fact, we have already seen people inside Debian that would likely stop contributing if they are now forbidden to use LLM. I know there are likely others that will quit Debian if we accept it too, but I hope we can find a middle-ground where such persons can decide that LLM are not welcome in the small corner of Debian that they are in charge of…
In the end, I decided that answering clearly the question “Shall we accept LLM contributions ?” was more important than making the political statement about the current state of affairs in the AI landscape, both because I believe that Debian statements have a negligible impact on policy-makers, and because historically Debian has grown by staying close to technical excellence and relatively far from politics, except when it comes to the way we handle people. And as much as I care about climate change, I don’t see how bringing this up in the context of a Debian statement is helping its cause.
More concretely, it gives the following ranking (in decreasing order of importance):
B, D: those two choices are the clearest to express “Yes we should accept LLM contributions” and still acknowledge concerns about the way AI is built today
F, H: those two choices do not forbid LLM usage but discourage their use and clearly voice the concerns
E: this choice is basically the statu-quo and fails to acknowledge the concerns, but it does not forbid LLM usage
None of the above
G, A, C: those choices forbid LLM usage in various ways
I don’t know what option will win, but assuming that LLM-assisted contributions are allowed, I believe that it would be helpful to have further statements to clarify a few things:
Even if Debian as a whole doesn’t want to ban LLM-assisted contributions, each maintainer or each team shall be free to forbid LLM assisted contributions in the parts of Debian that they are maintaining
We should discourage usage of LLM provided by players with unethical behaviors (not sure if there are good players but well…)
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.
Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.
LLMs have finally made it to the ultimate stage of Debian’s governance processes, a General Resolution of all the project’s full governing members (DDs).
There are a lot of options on the ballot, and they all have a different structure and approach the question in a different way. It can be hard to see the wood for the trees. I have made a summary table to try to capture the main differences, both in effect, and sentiment.
Before voting, I encourage you to read the passionate rationales in options H and A, or at least the summary in my option C.
Few of the LLM defences in the discussion threads, and none of the LLM-positive proposals, provide answers to any of these profound ethical concerns, many of which ought individually to be a deal-breaker. Instead, these crucial questions are simply dismissed or even ignored.
Some will tell you we should “keep politics out of software” but as we can see in the world around us, software is political - now more than ever. Debian’s mission is a highly political one: developing a fully-free operating system, and defending its freeness as we do, is far from neutral!
And of course many of LLMs’ harms affect Debian directly.
I have tried to present the options in semantic order, with most LLM-negative proposals to the left, and the most LLM-positive to the right.
I have not quoted the one-line titles for the options. These have generally been provided by the proponents of each option, and, unfortunately, some of them are IMO quite misleading.
Note that, unfortunately, the voting software likes to assign numbers to options but also to preferences. Be mindful of this possible confusion when casting your vote. For clarity I quote only the option letters.
Some of the proposals acknowledge the uncertain legal status of LLM output. But all of them implicitly or explicitly assume that LLM output is or can be DFSG free. So none of the proposals forbid upstream projects with LLM-generated contents.
None of the proposals would require us to go back to pre-LLM versions of the upstream projects we use, and attempt to fork and maintain them. I very much think there is room in the world for people to try to do that, but I don’t think the Debian project can be that effort.
Given that the conclusions are the same in each case, whether the matter is discussed does not seem to me to be a significant difference. I have therefore not included a column for it.
My proposal has a specific paragraph (7) explicitly permitting teams to set a “no LLM” policy. The other proposals do not discuss this point specifically. During the discussion, it seemed that most participants agreed that even options which explicitly permit LLM use generally do not prevent a team from setting its own more restrictive LLM policy.
Few of the permissive texts are absolute or unconditional. To summarise I have necessarily left out some nuance.
So for example when an entry says “permitted”, that generally means “permitted with conditions which are believed by LLM users to be readily satisfiable” (for example, DFSG-compatibility - see above).
Proposal B does mention that there are “concerns” about LLM use. But it fails to make an explicit statement about whether these concerns are justified.
It then proceeds exactly as if they are not justified. IMO “disregarded” is a relatively mild term for such a rhetorical technique.
Edited 2026-08-18 09:02 UTC to make the proposal letters in the table be links; 2026-08-26 09:11 UTC to fix typos.
"A “Free Palestine” party is registered to contest the Victorian state election
in November. The conflict in the Middle East is notoriously complex. But what
could be simpler than a single-issue political cause, with such a direct slogan
"On Friday night, Prime Minister Mark Carney instructed Canadian negotiators to
walk away from talks with officials from the Trump administration over new
tariffs of 50% Trump had imposed on $28 billion of Canadian products. Carney
Kevin sends us an exception handler from C++. Let's see if we can spot what's going wrong:
catch (Exception::Deadlock)
{
retry;
}
When we catch a deadlock happening, we retry. That's not a keyword in C++, and looking at how it's used, it has to be some kind of macro, and I suspect that the macro is hiding a goto underneath it.
The real problem, though, is that we suspect we're in a deadlock situation. That means this thread is waiting on a resource held by another thread which is waiting for a resource held by this thread. Neither train may continue until the other has passed. So this retry only works if it releases the resource held by this thread (letting the deadlocking thread proceed). But does it?
Not according ot Kevin. The code already had a pile of deadlocks in it, so they brought in a highly paid consultant to try and fix them by reordering access and tracing where mutexes were causing issues. This retry just jumps back up to the top of the block, without releasing any resources. It "seems the consultant wanted to add some deadlocks of their own," Kevin says.
[Advertisement]
BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!
I’m on a VPN setup with several friends that, obviously, includes a VoIP
network. I also have an old
magicJack adapter and a deep and
abiding need to use hardware in ways I should not. There was obvious synergy
here.
Plugging in the magicJack gives a USB vendor id of 0x06e6, which belonged to
a company called TigerJet who made a range of chips for hooking up phones to
computers, either via USB or PCI. Some more digging suggested that it was a
580 part, and someone had conveniently
uploaded
some reference code and datasheets, so figuring out how to talk to the chip
wasn’t terribly difficult. Once configured it simply sends HID events
whenever a user hits a phone key or changes the hook state, and otherwise
exposes a USB audio device that can be spoken to using the stock kernel
driver. It also has the ability to generate dial tone and assert ring
signal, giving a full traditional phone experience.
So you’d think this would be a super easy project, but I’d made things
harder for myself by deciding I wanted to tie directly into Asterisk rather
than just smashing an existing SIP stack onto the device. Asterisk uses
channels to
talk to devices, and channels end up as compiled C code that Asterisk can
load dynamically. I didn’t want to have to deal with the pain of compiling
stuff and matching ABIs and everything so writing a new channel from scratch
was unappealing. Fortunately, the websocket
channel
is available in recent versions of Asterisk and provides a convenient way to
get audio in and out, but that still leaves the job of handling incoming and
outgoing calls. That’s handled with the Asterisk Rest
Interface,
which can initiate a call or respond to an incoming one and bridge various
channels together to produce a bidirectional audio stream. There’s a
convenient async Python library that
handles the low level protocol.
Code for all this is
here1,
and works for my use case, but I should really abstract out the asterisk
side and the magicJack side to make it easier to adapt to other
devices. That’s a job for later, though. For now, you get this:
This has also been an excuse for me to figure out how to make Tangled work, which I’ll write about at some later point. But self-hosted git repo with a convenient collaboration plane! ↩︎
Author: Mark Renney It crept up on them, the Fugue. It happened so gradually as to be almost imperceptible. It certainly took years, possibly even decades to draw them in, until it had all in its thrall, but they continued to function as both individuals and as a society. The trains are still running and […]
DNA-based unravelling of history is one of the great amazements of our time:
- Birds are dinosaurs!
- Most of us are partly Neanderthal!
- The humans who actually killed off Neanderthals left no descendants themselves!
- We can now trace great migrations of pre-literate peoples…
… and the long-term effects of harem masters like Genghis Khan.
- One particular woman, her bones found in a cave, had a human mother and Denisovan father, a story worth telling - (imagining) - in a novel or three…
- Our ancestral Mitochondrial Eve lived 400,000 years ago. And much more…
Arguably the most fascinating recent discovery is the Y Chromosome Bottleneck. A violent transition that seems to have flowed everywhere across Europe, Africa and Asia, occurring wherever and whenever farming became widely practiced. In the Near East, the cradle of agriculture, that was from 7000 to 5000 years ago, a stretch when (for some centuries), only one in 17 male humans got to breed, while women were apparently unaffected.
Well... unaffected genetically.
That is a huge, recent discovery, whose implications have yet to be fully plumbed. Though a first order theory is obvious. Grain was storable food and stored grain became an irresistible lure for raiders, thieves and then genocidal takers. Indeed, this is when we see fortifications surround almost all Neolithic villages. And burial pits filled with victims of evident violence. (But with almost no skeletons of young women, a fact with blatant implications.)
There is an alternative theory, of gradual, much less violent success/failure attrition of bloodlines, instead of all-out bloody raid wars. But that seems a desperate grab at narrative shifting. Anyway, both theories can only explain the Y Chromosome effects if these villages and clans (again, all across Africa and Eurasia) were patrilineal.
(Aside: Note that all through the Americas, wherever Spaniards conquered, today most Y chromosomes are Iberian while nearly all mitochondria come from Native lines. I leave to some of you the unpleasant implications. (I’d love to see a similar chromosomal appraisal of Native peoples in English speaking areas.))
Alas, I must demure from both theories for the Y-Bottleneck. Neither is sufficient to explain it. I’m here to accuse these brilliant genetic detectives of thinking too close to the problem, ignoring vital factors.
They assert that the correlation with agriculture means one thing -- that the allure of stealing grain was enough to explain the violent exclusion of 16/17ths of males from reproduction. Among many other flaws, this notion does not explain why the violence stopped. Or at least ebbed to much lower levels. And that is a glaring flaw. As is the notion that a tribe with only 6% males is going to either be raided for grain surplus or do much raiding.
I have another theory (naturally). It is also directly correlative with agriculture, but in more ways than just rival clans or villages raiding for stored grain. Because this was when two more innovations arrived. Beer… and kings.
No, not the Great Kings of Ur and Uruk and Jericho etc., who would arrive later. I mean earlier versions depicted in the second story-chapter of James Michener’s novel THE SOURCE. A ‘king’ with a modest two-story wooden palace in a village of ramshackle huts with just a couple of hundred inhabitants, enforcing his will on the locality with a standing ‘army’ of just thirty or so big bullies with stone adzes.
Until then, a tribal chief might have two wives and get to act tough… but he was still answerable to the Tribe as a collective. He could be deposed by vote at the campfire. Stomp on others too hard and he’d pay a price.
Only now, in a large farming village with a much bigger population -- and thirty or forty bullies at his command -- the king could safely ignore popular opinion among the peasants. Now, he could simply order that a man be killed, as matter of whim. Or a ruling of the gods.
Want a peasant’s pretty wife? Kill him. Marduk ordained it!
Did that fellow get rowdy and dangerously drunk on beer? Into a ditch with him. Baal's will.
Did that one run away from the last raiding party? He won’t get a second chance.
Do my thirty soldiers want more women? Take some on the next raid…
…or just take them here at home.
This explains other things than the Y-bottleneck and the absence of young women from those horrible death pits. It also would explicate why humans are more resistant to alcohol than most mammals. For a thousand years after the invention of beer, lots of bilious drunks got killed, fast. The petty king pointed at him and made the oild throat-slitting gesture and that was that.
Too theoretical for you? All of what I just described did happen within oral and written accounts, in areas where agriculture arrived later. Watch Jason Momoa’s TV series THE CHIEF OF WAR, which paid close attention to historical accuracy. You’ll quickly and vividly get the picture.
== The end of a horrible era ==
So what about my earlier objection? That we need an explanation for why the Y-Bottleneck stopped?
The reason it ended is simple. And again, agriculture is key.
Despite all the murder, populations kept rising. Farming got more productive. Villages merged or were conquered. Soon you had large towns, then the first cities. And atop those cities were Kings. The real thing, now. Real palaces and temples and armies of hundreds… and rival kings, just upriver, who kept pissing in the water, to spite you and your gods. You need a bigger army!
But those darn local lords keep killing the peasant males that you need to fill your ranks for the next campaign!
So, you outlaw the practices that led to the Y-bottleneck.
No more inter-village 'raiding.' You crack down on local lords and bullies, enough to save most of the men to work the fields and then join the ranks of your army during war season… and in so doing you also win gratitude andlove from the peasants.
(BTW this scenario is very close to the one elucidated by Karl Marx, whose class and caste historiography was much better than his predictive economics.)
Again, Watch THE CHIEF OF WAR – based on true stories and true culture. And yes, Kamehameha typified exactly the transition that I just described, from capricious whim-murder to due process and law, under a great King.
== Are we truly that awful? ==
This theory explains the Y Chromosome Bottleneck far better than the mere raiding of grain silos. And yes, it’s even nastier! It implies that human males have a dark heritage that we must fight and continue to rise above.
Hey, a lot of us are trying!
Only please tell me how lions or stallions or bull moose or peacocks or orcas are any better? Mom Nature is not sweet!
In fact, we have already proved that we can be nicer, finding ways to curb those feral, viciously gene-serving appetites. Sometimes. Under right conditions. Which is what technology and constitutions and ethical teachings are for. And maybe – carefully – we might even do some editing of the worst genetic imperatives. (As I portray in Glory Season.)
But it begins with knowledge. With science. With understanding.
If we are to do even better, it must start by looking, clear-eyed and bravely – at the hand that we were dealt.Then betting and investing on rising out of Nature’s vicious mire.
== Kings were an improvement, but … ==
So, what agriculture giveth, it taketh away… and then giveth again?
Perhaps, in some bucolic, neolithic era, some tribes followed the much-touted matrilinear, Mother-Goddess tradition. The famous Venus figurines might have been dedicated to Her, instead of serving as stone age pornography. Maybe. Indeed, before agriculture emphasized the brute strength of males in the fields, gatherers certainly provided more calories than was brought back to the fire by preening, bragging hunters. Again, we know this from real life examples.
But agriculture did come. And with it likely our most violent era. Until the male-reproductive-maximizing frenzies of minor, petty ‘kings’ finally got tamed -- a little -- by actual Kings.
Again, I’m not the first to consider this – some of it Karl Marx posited as obvious… an ongoing tussle between feudalism and monarchy that you can see illustrated in another film, from the 1960s, THE WARLORD.
That tussle mattered, certainly… and it didn’t. If peasants fared a little better – and merchants more-so – under kings, it was without any effort to get their their consent. Priests and propagandists of Baal, or Indra, or Patmos, or Huitzilopochtli, or Kū, or FoxNews preached that pyramids of inherited power are good and ordained. And it sure seemed destined to be so, as feudalism/royalty dominated every continent where people did farming.
Rivals were squelched, Rival thinking was repressed. The strong and the feral clever maximized their reproductive power, as all males do, in all species, only now amplified hundreds-fold. And actual progress was glacially slow. Or nil.
Indeed, this is number two on my long list of catalogued explanations for the Great Silence in our galaxy, often called the “Fermi Paradox."
== It may be a big reason why we are alone! ==
The male reproductive/competitive imperative is so pervasive on Earth that it seems likely to hold true on other worlds, for the same self-reinforcing reasons. It may anchor down most intelligent species. If kings and lords and priests and presidents and Big Brothers get powerful technologies to reinforce their power, then that society may become locked up, trapped into inherent stupidity, forever.
On Earth, only one civilization ever meaningfully escaped that trap, and the Enlightenment might be a temporary fluke, soon to be shut down by a return to 6000 years of nescient rule by kings and owner lords and their inheritance brats.
We teeter right now on that precipice. An edge that – perhaps – few other sapient species even get to approach. And if we topple back into that ancient, pervasive pattern – this time reinforced with total surveillance and Orwellian controls – then we will join all the others out there, trapped in rigid pyramids of power that get genetically reinforced, until no other way is even imaginable.
(See Robert Silverberg’s fine novel NIGHTWINGS.)
With criticism of power repressed, no one will pioneer new and better ways… while our home planet gradually (or swiftly) decays.
==A narrow path to escape ==
And yes, that means our current meme-political-social struggles may be far more important than we realize!
If humanity succeeds at maintaining a flat-fair, competitive/cooperative, egalitarian, scientific Enlightenment Civilization, then we might reify the dreams of science fiction and get out there!
A myriad other worlds in this galaxy may be waiting for our heirs – both organic and cyber – to go and rescue them from the traps of Darwin and Nature.
Our ancestors clawed their way up from muck and disease and ignorance and pain and countless despicable or well-meaning mistakes, until we are at last ready (I hope) to make all that suffering count for something.
The gruesome past beckons us to do better. The future summons us to send forth rescuers.
The present is a critical crisis for a Hero Generation to solve…
Happy first anniversary to my weeknotes! I started these exactly 52 weeks ago, and managed to write on 49 weeks since then. I’ll call that a success! After all this time, it still feels good. I’m going to keep it up.
This week is also my first of three weeks of funemployment between jobs. I’m going to try and move forward various Hanakai things, but also take Andrea’s advice, and try and get some rest, too :)
I published our second sponsorship drive post: Power in numbers, and Pat Allan. We got a fantastic response initial response to our launch and found ten new individual sponsors. Thank you everyone! Please continue to share our things.
Hanami View’s CI started failing due to Tilt 2.9.0 shipping with Herb registered for the .html.erb extension. It’s fantastic news that Herb has made its way into Tilt, but since it doesn’t quite match our expected ERB behavior, I fixed this and released it as Hanami View 3.0.2.
The ever proactive Marco happened to reach out to me at around the same time, to explore what it would take to make Herb work with Hanami View for real, and now we’re looking into it. Watch this space!
I reviewed and merged Andrea’s work to support externally-added command options in Dry CLI. This already has a use case: keeping our core hanami generate commands clean and focused while letting extensions from Hanami RSpec and Minitest add their own --skip-tests options. Thanks Andrea!
Aaron has been doing fantastic work pushing at the edges of Hanami’s database setup. I did some investigation into an issue he found and filed an issue about the db provider configuring gateway URLs from its parent. Help wanted!
I also reviewed a fix that Aaron pushed for the (upcoming) Dry Operation validation extension to better handle missing args. In the end I figured that we could vastly simplify our code by setting clearer expectations around our expected params signatures. I pushed this up, Aaron is happy, and I’ll merge it soon. One step closer to a Dry Operation release!
For the rest of today (open source on a Wednesday, how fun!), I’m working on our next sponsorship drive post, and getting back to reviewing Andrea’s recent work on resolvable errors for Hanami apps. See you next week for the beginning of year #2 of weeknotes!
I like this line: “Success is measured in operational advantage delivered, not technology demonstrated.” To me it recalls “Working software is the primary measure of progress” from Principles behind the Agile Manifesto – if you understand “working” to mean “working in production”. Which I do.
For anyone interested in suggesting ideas to the taskforce, the four
operational challenge areas include:
Machine assistance for handling and interpreting huge volumes of data
would probably benefit decision advantage and interpretation of a
crowded EM spectrum, but this is hopefully(?) more than just LLMs. Of
course, there’s more to AI than large language models… right?
I worry that “planning and automation” might amount to “generating
large amounts of
text
faster”. Nothing could possibly go wrong with this.
“"We will take in trillions and trillions of dollars and create jobs like we
have never seen before," U.S. President Donald Trump told Congress in his state
of the union address in March 2025, one of many forecasts of a new golden age
After ranting and railing about LLMs or "AI" as the optimists (or
accelerationists?) call it, I figured it might be important to
be a little more honest about my use of LLMs and how I think about it
more practically in the world.
The Debian vote context
This is not a coming out. I am not using LLMs on a daily basis, and
this blog is, again, written out of my cold dead hands in a dying
world, with over-engineered hardware and (to a certain extent, hi
Emacs!) software, powered by 100% green energy built on stolen land.
There is a vote going on in Debian. If you're unfamiliar with it,
you can catch up at LWN. So far I've essentially said "LLM is
bad" which is not a very balanced or useful opinion. Obviously, people
are using LLMs, sometimes unknowing or unwillingly, and we need to
take that into account. Furthermore, there has been many different
blog posts on Debian planet about this. Some that I found
balanced, good summaries, even if I didn't fully agreewith
them, at least some did the basic civil service of being
short. But others were just not only Wrong but also so long
that I couldn't finish that I just had to write something.1
This is not an explanation of the ballots, nor how I will vote. This
vote is Debian's failure of framing that debate in a reasonable way:
we have 8 options on the ballot with many duplicates. We have failed
to do the hard work of summarizing and aggregating options into a
meaningful set. I doubt the final vote will represent a readable
position we can rally around.
I have not read the twomonths of debates on the topic
either. Normally, before voting, I take a cursory look at the debate
to see points of view I might have missed. But in this case, it will
just make me sad, add noise, and I'm already pretty sure on where I
stand on this.
So let me describe how I use LLMs and how I think they fit in our
work, as computer engineers and hobbyists.
My LLM use
Debian Packaging
An astute reader has pointed out that I maintain a package in
Debian made to use Anthropic. It's actually multiple packages:
As I previously explained in response, I am not entirely
comfortable with this work: it's a compromise. In fact, I first
uploaded llm to the contrib section of Debian, where we keep
software that depends on other non-free software, but I was told that,
since yt-dlp was in main, llm belonged there as well.
An important part of my work is technology watch. I keep tabs on
thousands of (new and old) software projects, follow news, and
generally try to keep my skills up to date. It's a pretty impossible
race, especially as I grow older, but I still think I'm doing the
right choices in my job.
Testing large language models is part of that work. At first, I was
using ChatGPT's web interface, but it was annoying to copy-paste
things into a browser, so I looked for different interfaces.
For a while I tried gptel, a "simple, extensible LLM client for
Emacs" but I found it kind of terrifying. Giving a LLM control over an
Emacs buffer seems like a security nightmare, so I stopped doing
that.
So I use the llm command-line tool to talk to Anthropic's API. I
started that in the summer of 2025, when I bought 20$USD of API
credits. Before that, I paid for a ChatGPT subscription and then
OpenAI credits, which expired and sent me over to Anthropic, which
seemed then to have better ethics.
Needless to say, Anthropic and "Claude" are not my friends, but they
seem like the lesser evil in current "frontier models". So I have
renewed, a couple of weeks ago, another 20$USD of API credits with
Anthropic.
Actual prompts and responses
So what does 20$ give you at Anthropic anyways? What am I using LLMs
for and how?
The neat thing with llm is that everything is logged in a sqlite
database, so there are some answers that are easy to get:
> llm logs status
Logging is ON for all prompts
Found log database at /home/anarcat/.config/io.datasette.llm/logs.db
Number of threads logged: 7
Number of turns logged: 12
Number of legacy conversations: 543
Number of legacy responses: 970
Database file size: 9.61MB
That is 10MB of logs, with about a thousand prompts.
My logs go back to 2024-03-07, a little over two years ago, and
include a mix of Anthropic and OpenAI responses. I used it more in
2024 than 2025, and if the trend continues, I will have used it less
in 2026 again:
It looks like about 10 prompts per month right now, down from a peak
of about 60 per month in 2024. It's pretty difficult to analyze those
actual logs to get more patterns and I won't run the prompts through a
model again to process them.
How I'm using models now
At first, I was using it partly for benchmarking model's capabilities,
like Simon Willison does with his pelicans, clearly not trusting
its output. But I was impressed by the capacities of the Claude Opus
4.5 model when it wrote this script in January. Impressed, but
also scared: it's the first time I felt I could delegate the entirety
of my programming to a model. Just run the code, if it works, it
works, right?
So what do I use it now? As an example, here are the 10 last prompts
in my history:
there is now Claude 5, and a fable model, maybe you know about it?
impress me
not impressive, i already know all of this
chat
in postfix, i have a 300k mailing that happens regularly here. normally, it delivers within about...
is there a way i could have drained the maildrop queue faster without removing the milter?
the problem was that rspamd was timing out on the FUZZY_CALLBACK check. how do i disable that?
how do i disable all spam checks? i just want rspamd to add dkim signatures
how do the default_destination_concurrency_limit and initial_destination_concurrency settings int...
mic check
The first one was me trying to confirm which model I am using, which
is not always obvious when going through the whole llm stack I've
been using. The following two are an attempt at seeing what the model
is capable of and I was "not impressed", to which Claude answered that
I have a "high bar", which, fair enough.
The chat is me failing to use a command line, which shows that
perhaps I need to readjust that "high bar", again.
The next five are a rather embarrassing debacle in a large Postfix
mailing that went sideways, and where I couldn't find an actual
Postfix expert of my level to help. The fabled Claude Fable 5 answered
rather correctly, but dangerously, that I could empty the queue by
disabling the non_smtpd_milters. What Fable (and myself) did not
realize is that the milter was also adding DKIM signatures, so while the
mailing was expedited, it was done without those precious signatures,
which got us promptly blocked at Gmail. We have recovered since, and,
thanks to the model and reading the Postfix manual for the
hundredth time, that pickup(8) is single-threaded and that we
needed to review the architecture of that mailing (and our spam
filters) a bit. Many tickets ensued.
The last one is a test I did to make sure my last uploads of
llm-anthropic and its dependency worked correctly.
Note that the above excludes 5 questions I asked Anthropic while
writing this article, where I asked for synonyms and "what nanometer
scale are arduino processors built from? how is an arduino CPU
printed?", a question which Wikipedia furiously evades providing a
good answer.
Those prompts are pretty typical of my LLM use: I'm testing the models
to see if they work at all, but also, out of desperation, I fire off a
prompt after I fire off questions to colleagues or search engines (in
that order). It's often weird edge cases like the Prometheus query
language, Python's matplotlib, LaTeX, Elisp, optimizations, and so on.
I use models for translation a lot. Being fully bilingual, it is
common for me to think of a word in French or English and fail to find
exactly the right word for that in the other language. Models help
with that, and are also useful to find synonyms. Those are low-token
uses that seem pretty innocuous to me, but I realize the irony of this
after writing about the tower of
Babel.
What I am not using models for
I am not using models to write prose.
I am not using models to read prose. If it's generated with LLMs, I
stop reading.
I am not using models to write code, with the exception of that single
Python script above.
I am generally not using models to review code, with exceptions. If
I get stuck on a hard problem, I might feed a piece of code to the
model. I repeatedly fed asncounter into Claude to try to fix a
performance regression I had introduced. It found micro-optimizations
that taught me a thing or two about Python's internal implementations,
but overall, it was mostly a waste of time. This was in June 2025, so
perhaps now models would fare better. I have not tried again.
I am not using LLMs to do Debian packaging. When I can, I manually
review the diffs of packages I upload into Debian, still, by hand.
aggressive and illegal scraping of the servers I steward
world-wide computer hardware shortage (making it, by the way,
nearly impossible to run presumably clean local models) and the
attack on our job conditions (also discussed in
The people vs the AI overlords)
death of copyright and free software
complication and enshifitication of everything, and the
destruction of our communities
the imperialist Nerd Reich that wants to take over the world
Like I reluctantly use Intel computers, I do fire off a prompt. But
I still hold on to the dream that we can build communities of
practice that hold human knowledge collectively and not offload
that as a utility to some megalomaniac billionaire.
Their LLM use I am forced into
So that's me. Clearly, I'm going against the grain here. Everywhere I
look, I see LLM-generated code and projects. Slop and botnets have
flooded the web.
I use Wadamesh, clearly vibe-coded, because it's the best
graphical interface for MeshCore that runs on portable devices. I wish
it was made by a human, in a community I could participate in, but it
isn't, and I don't.
I package the above llm toolset, which is more and more
vibe-coded, but I still review the diffs. And I have to say: I
trust Simon here. The code is verbose as hell, feels overengineered,
and llm feels slow, but it generally works, and Simon is still at
the gate.
The Anthropic SDK is another thing entirely. The 0.91.0 to 0.120
upload, for example, was nuts:
I explicitly did not review that entire diff. It feels like there's a
lot of garbage there to just have a shim between a proprietary API and
Python. But this is the hand I've been dealt.
Larger projects LLM use
LLMs are being used in the Linux kernel, Firefox, rsync, Rust, and
other places. I don't feel good about this, particularly in Rust, but
they at least made a decent policy. I am glad GCC made a policy
against LLM contributions and I support the human Emacs
project.
We need to have a set of foundational tools that are "clean" in the
sense that they are built upon a community of people that understand
how they are built.
Maybe that's naive or even impossible. The Linux kernel and GCC, in
particular, are massive projects that have long grown past the scale
of a single person's understanding. But the theory was that a
community of humans can understand collectively.
Now we seem to be throwing up our hands and giving up on
that community. That LLMs will just fix the problem, whatever it
is. But we're all just one rug pull away from being completely
incapable of managing those projects. The argument there is that we'll
just switch to local models, but no one is actually doing that.
All I see is people use local models as a corner case
(for privacy) or as in theory, but in reality, everyone uses the
centralized frontier models right now. We just can't fallback.
We're in the same situation we were, a decade or two ago, when
Microsoft decided it would kill free office alternatives by making
Office free for non-profits. It worked: thousands, if not millions of
schools, community groups and individuals stopped looking for
alternatives (including free software but also "piracy") for Office
and embraced what seemed like a generous offer.
I'm afraid the rug pull on LLMs will be much worse: never mind that
Linus won't be able to use his tireless helper to fix obscure kernel
bugs; we're looking at a collapse of the economy so large that we are
already talking about bailing out the companies responsible.
In a sense, the most striking thing about the Debian vote is it has
actually no option to completely refuse upstream LLM contributions. It
seems the community has taken it for granted that it's now impossible
to build Debian entirely without LLMs. We lost the battle even without
a fight, it seems.
A plea for small
If it has really become impossible for us to manage the complexity we
have built, maybe it's time to stop and think about what we're doing
in the first place. We're struggling to even bootstrap our
current toolchain!
This is one of the things I like the most about working on the mesh:
it's low tech, small Arduino devices that is built with decades-old
semiconductor processes that is understandable by human
beings.
Maybe the answer lies more in single-purpose devices like those
communicators and simpler multi-purpose computers than what we have
now, which is what the permacomputing movement is about.
Another minor routine update 0.0.6 of gettz arrived on CRAN just now.
gettz provides a
possible fallback in situations where Sys.timezone() fails
to determine the system timezone. That happened when e.g. the
file /etc/localtime somehow is not a link into the
corresponding file with zoneinfo data in,
say, /usr/share/zoneinfo. Since the package was written (in
the fall of 2016), R added a similar extended heuristic approach itself
making the package a little less relevant.
This release reflects several rounds of updates to the continuous
integration setup, some URL updates, as well as some updates to
packaging including use of Authors@R in DESCRIPTION. As with the
previous releses: No functional changes, no new code, or new
features.
Andy Ellis has a roundup of the security vendors at Black Hat this year.
Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.
At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly plentiful.
There are many cases where some sort of debugging block sneaks by, especially cases where we see preprocessors or templates working, which leave us with nonsense like if (true == false) running in production. But Codemonkey found a new twist on that sort of thing, in a SQL query being run in production.
WHERE (some conditions) AND (1=0OR (1=1AND (other conditions)))
The OR means that by twiddling the first equality check, we can toggle "always return rows" with "return based on condition". Toggling the second we can make it "never return rows", which I'm not certain is actually useful. I can see how these likely did start life as debugging flags, but they're still weird, still unnatural. They point to some other problem in observability in the code. And, as all "good" flags go, they're not documented anywhere, this seems like it started life as a query an analyst was running until it got turned into stored procedure to be run again and again. The flags have never been changed since the code was released, as far as anyone can tell.
[Advertisement] Plan Your .NET 9 Migration with Confidence Your journey to .NET 9 is more than just one decision.Avoid migration migraines with the advice in this free guide. Download Free Guide Now!
In 2025 I was honored to be selected for the first cohort of Sovereign Tech Fellows, a program by Germany’s Sovereign Tech Agency to improve the resilience of the open source ecosystem by supporting maintainers directly (complementing their existing support for larger FOSS organizations). Back in 2025, I was only working very limited hours – however, this has changed in 2026.
For the second half of 2026, I am working again as a Sovereign Tech Fellow, but this time with significantly increased hours. After finishing my PhD, I do have time now for new tasks (and new jobs!), and the fellowship presents an amazing opportunity to really advance projects that I maintain or am part of. This also has a very nice effect on contributors and bug reporters, as their feedback gets addressed a lot faster. With some luck, this ultimately will help finding new (co)maintainers for projects as well (although in the age of AI, a lot of how open source used to work is much more uncertain, but that is a matter for a different blog post).
The fellowship is time-limited, so I am intending to make the time I currently have count!
So, what’s planned?
I am involved in many projects, but three of them will be getting attention as part of the fellowship. I know I am notoriously slow at blogging, but expect more details on each of them very soon. Here’s an overview:
Freedesktop.org, Specifications and Organization
I maintain the Freedesktop Specifications, which is an area of Freedesktop that has traditionally been a bit chaotic. This “worked� in the past, because Freedesktop was never intended to be a formal standards body, but more a shared space where people could throw a lot of code and ideas over the wall and see what sticks and what people can collaborate on.
While I very much love the spirit of this and want to keep it in some form, we definitely would benefit not just from more formalization and better procedures, but also from better organization of the specifications in general. A lot of conflicts can be avoided by that. I will work on improving procedures, crunching through the (lots!) of pending bug reports and MRs, and to make the specifications site better searchable and accessible (similar to how Mozilla’s MDN presents information, but I am not sure if we will get quite that far). I also intent to add a compatibility matrix for specifications, so if a desktop opts out of any one of them (or does not implement them yet) that fact is documented and authors of applications know what they can expect. This will allow us to move a lot faster and avoid a lot of conflict, because there is no implicit assumption that “everybody will implement everything� anymore (which has never been quite true anyway).
Hopefully, this will ultimately result in a Freedesktop that is both a lot more useful for application authors who want to bring their project to Linux, as well as developers of desktop environments who need to see which specifications are available and which ones are current.
In addition to that, I have also worked on a Freedesktop.org website refresh, which is pretty much done in its first iteration (pending sysadmin action). The aim there is to have a more official website, separate from user-contributed wiki content, that showcases what Freedesktop is and which projects are using it for hosting. Once the new website is live, I will also review every page again, archive dead projects in their own section and reorganize the software and specifications directory. Those sections are severely outdated and are missing recent efforts from the community, while still containing long-dead old projects (remember HAL? ).
AppStream
A lot of extra maintenance work will be (has been!) done on it. This includes things such as JPEG-XL support (blog post soon), sandboxed media processing, support for newer specification additions, better OARS integration (and potentially migrating it to fd.o infrastructure), improvements and API stabilization for libappstream-compose and a lot of bugfixing and resolution of issues found by AI code review.
AppStream was originally designed to parse only trusted data from vetted Linux distribution sources – this is no longer the case in today’s world and in the way Flatpak uses it, so we need to increase resilience of the project.
I am also exploring a project that could vastly improve search accuracy for AppStream. Stay tuned for that.
PackageKit & System Upgrades
Many years ago, people thought we would all migrate to atomic Linux distributions and slowly not need PackageKit anymore. This has not turned out to be the case, and there are still plenty of reasons to use a package-based OS, especially in development environments. At the same time, PackageKit has been basically the same for years, and its older architecture is beginning to show. It being a daemon who’s literal job it is to modify the entire system also makes it one of the most security-sensitive components that a Linux system can have, while simultaneously making it near-impossible to sandbox.
My plan is to create PackageKit 2.0 by building on the great foundation of PackageKit 1.0, but modernizing it. This will include simplifying its code and removing a bunch of features that have no more use in modern desktops, while also adding some features that PackageKit never had but that would be useful to expose to frontends (still no to interactivity an terminal-progress forwarding though!). PK 2.0 will also allow me to solve a few design issues that have been worked around in the past, by replacing them with better solutions. This will be a painful transition, as PackageKit 2.0 will break all interfaces PackageKit has – and those interfaces have been frozen for more than a decade. However, I do fully expect this change to be worth the effort.
In addition to that, I intend to look into the offline-update procedure again and improve it. The current multi-reboot operation comes with downsides, that newer systemd features such as soft-reboot can alleviate. The end result should be a much smoother, less annoying offline-update experience for users (I especially want to get rid of updates running on system startup, which I consider quite bad from a usability perspective). The new behavior is in the early drafting stages and may need direct support from systemd. I will share more about it once I can.
That’s a lot of tasks!
Yes! I will see how far I get. I am moving project-by-project though, to allow me to focus on one project at a time, rather than scattering my attention continuously. Amazingly, this means that the major tasks for AppStream are already almost done, and we are nearing the 1.2.0 release. AppStream got priority, because the new Freedesktop Flatpak runtime will be released soon, and because I want FlatHub/Flatpak to have access to the new AppStream release sooner. Freedesktop and PackageKit are next on the task list.
Either way, a lot of progress is coming – if you have any feedback or want to help out, please don’t hesitate to reach out! All work is happening fully in the open, so you can also chime in on the respective GitHub/GitLab tasks .
You can also expect blog posts about key features or interesting changes, so stay tuned!
A new release of gaussfacts package
arrived on CRAN – the first in
pretty much exactly a decade! gaussfacts
provides a fortunes-inspired
function to display randomly-chosen facts about Carl Friedrich
Gauss, based on the collection curated by Mike Cavers via the gaussfacts web site (with an archive.org link
it case it vanishes again). Each call of gaussfact()
displays another (randomly chosen, or indexed) fact.
An example:
> gaussfacts::gaussfact(9)Gauss once played himself in a zero-sum game and won $50.>
This releases, as detailed below, accumulates a number of smaller
maintenance changes including switching to Authors@R. Functionality has
not changed. Oddly enough, it appears that I did not blog about the
package when I created it in August 2016. So to (partially) make up for
that, the NEWS for all three releases follow.
Changes in version 0.0.3
(2026-08-23)
Several rounds of continuous integration maintenance and
enhancements
Additional README.md badges
Updates to DESCRIPTION as CRAN requirements change
A duplicate data entry has been removed (Tim Pokart in #4)
Documentation prefers https URLs
Updated continunous integration multiple times
Correct man page removing an erroneous duplicate word
Changes in version 0.0.2
(2016-08-03)
Support 'ind' argument to reference by position
Clean-up encoding and support extended character set (#2 closes
#1)
This post contains interactive examples. To visualize and interact
with them, you need to leave your RSS reader.
Imagine you rent office space for a three-day event. You quickly set up a few
Ethernet switches and tape some cables on the floor to get everyone online.
Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he
gets up for coffee. You could add extra cables, but then you’d get a broadcast
storm: Ethernet packets that loop and multiply until nothing else gets through.
That’s where the spanning tree protocol (STP) comes in. STP blocks just enough
of your spare cables to leave a loop-free tree. When Stan strikes again, it
rebuilds the tree in a second, leaving some time for Blobby, your one-person
support crew, to reconnect the cable.1 See for yourself: the diagram
below runs a real STP implementation in your browser!
Designed in the ’80s, the spanning tree protocol has evolved into a “rapid�
flavor (RSTP) and a “VLAN-aware� variation (MSTP).2 Any sound-minded
network engineer knows there are better alternatives, like BGP EVPN VXLAN.
Yet, because any switch speaks it, the venerable spanning tree protocol still
fills a niche.
We focus on RSTP: it replaced the original protocol in 2004. To eliminate
network loops, RSTP implements a complex state machine. Timers, link state
changes, and the link-local control frames a bridge receives from its neighbors
drive its transitions. These Ethernet frames are the Bridge Protocol Data
Units (BPDUs). You can watch them in action below: hit the “Start� button.
After some time, the topology converges to a tree: from the root
C11, there is a path to each bridge3 and no loop. In the upper right
corner, the interface displays a tree icon 🌳 followed by the time it took to
reach this state. Cut a link and see how the protocol
finds an alternate path to reach C12 in less than a second. You can stop the
simulation, move it forward step by step, reset it to its initial state, or slow
it down with the “snail� mode �. Don’t worry about all the displayed
information: I explain it later.
All examples run in your browser, powered by MSTPD—an open-source
user-space4 implementation of RSTP.5
I think that I shall never see
A graph more lovely than a tree.
A tree whose crucial property
Is loop-free connectivity.
A tree which must be sure to span
So packets can reach every LAN.
First, the root must be selected.
By ID, it is elected.
Least cost paths from root are traced.
In the tree, these paths are placed.
A mesh is made by folks like me,
Then bridges find a spanning tree.
To build a tree, RSTP first elects the bridge with the lowest bridge
identifier as the root bridge. The bridge identifier combines the priority
and the MAC address: 8192.6e:2b:10:a0:5f:29.
In the example below, S1 and S2 have priorities of 4,096 and 8,192: S1 becomes
root. S4 has a priority of 12,288, while S3 keeps the default priority of
32,768:6 S4 becomes root. S5 and S6 don’t have a specific priority, so
the lowest MAC address wins and S5 becomes root.
Each non-root bridge chooses its root port, the one with the lowest-cost
path to the root. Unless you override it, each bridge derives the link cost
from the speed: 20,000 for 1 Gbps. In case of equality, the lowest port
identifier wins.
Each remaining port becomes a designated port if the BPDU it sends is
“better� than the BPDU it receives. Otherwise, it becomes an alternate port.
Later, if the root port goes down, the “best� alternate port becomes the new
root port. The tiebreakers for the best BPDU are:
In the example above, after convergence, S1 is the root bridge
because it has a priority of 4,096, while the other bridges have a priority of
32,768. All its ports are designated ports because the accumulated cost to the
root is 0.
S2’s port facing S1 becomes a root port because it has the lowest accumulated
cost to the root—20,000 vs 40,000. S3 has two ports facing S1, and the one with
the lowest port identifier becomes the root port—0x8000 vs 0x8001. The other
candidate is an alternate port because the remote port on the link sends a
better BPDU, with an accumulated cost of 0. On the segment between S2 and S3,
S2’s port wins: while both bridges have the same accumulated cost to the root
(20,000), S2’s bridge identifier is smaller—32768.02:00:00:00:00:01 vs
32768.02:00:00:00:00:02.
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) Root Identifier: 4096.02:00:00:00:00:00
Root Path Cost: 20000
Bridge Identifier: 32768.02:00:00:00:00:01
Port identifier: 0x8002
Unless a specific event happens, designated ports send BPDUs every 2
seconds.9 If a bridge does not
receive BPDUs from its neighbor for 3 consecutive hello periods, it considers
the neighbor dead and removes the port information.
Port state transition
Each port can have one of three states. The diagram displays a background color
for each state:
discarding (red),
learning (yellow), or
forwarding (green).
A root port transitions automatically to the forwarding state. An alternate
port stays in the discarding state. A designated port has two options to
transition from the discarding state to the forwarding state:
If the port is an edge port, either through configuration or because the
remote device does not speak any flavor of STP, the bridge assumes it won’t
participate in the protocol and cannot create a loop. In this case, the
designated port immediately transitions to the forwarding state.
Otherwise, it sends a proposal to its downstream neighbor. If the remote
bridge agrees that the received BPDU is “better� than any other BPDU stored
for other ports, it elects the receiving port as its root port and starts the
synchronization process: it transitions all non-edge non-synced designated
ports to the discarding state to avoid a loop. Then, it sends back an
agreement. Upon receiving the agreement, the peer designated port
transitions to the forwarding state.10
In the topology above, H1, H2, H3, and H4 are end devices not participating in
the protocol. We configure the ports they connect to as edge ports, so these
ports immediately move to the forwarding state.
Use the “step� button to move the simulation forward. The clock moves to 1
second. Step again and S1 and S2 send a proposal to
each other. Here is the proposal from S2:
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x4e, Agreement, Port Role: Designated, Proposal
0... .... = Topology Change Acknowledgment: No
.1.. .... = Agreement: Yes
..0. .... = Forwarding: No
...0 .... = Learning: No
.... 11.. = Port Role: Designated (3).... ..1. = Proposal: Yes
.... ...0 = Topology Change: No
Root Identifier: 32768.02:00:00:00:00:01
Root Path Cost: 0
Bridge Identifier: 32768.02:00:00:00:00:01
Port identifier: 0x8001
S1 ignores it: its own root identifier is lower. When S2 receives a similar
proposal from S1, it accepts S1 as its root bridge. It also elects the port to
S1 as the root port and starts the synchronization process. The two designated
ports are already discarding, so no change here. Step
again and S2 sends two BPDUs to S1. In one of them, the
agreement bit is 1 and the proposal bit is 0. It also shows that S2 accepted S1
as the root bridge and its root port is now in the forwarding state. When
receiving this BPDU, S1 transitions its own designated port to the forwarding
state. From this point, the link between S1 and S2 forwards user traffic.
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x79, Agreement, Forwarding, Learning, Port Role: Root, Topology Change
0... .... = Topology Change Acknowledgment: No
.1.. .... = Agreement: Yes
..1. .... = Forwarding: Yes
...1 .... = Learning: Yes
.... 10.. = Port Role: Root (2).... ..0. = Proposal: No
.... ...1 = Topology Change: Yes
Root Identifier: 4096.02:00:00:00:00:00
Root Path Cost: 20000
Bridge Identifier: 32768.02:00:00:00:00:01
Port identifier: 0x8001
Let’s look at what happened to S5. Reset the simulation and step
twice. S5 exchanges BPDUs with both S3
and S6. Since S5 has a lower root identifier than S3 and S6, it stays the root
bridge, while S3 and S6 accept the proposal and elect their root ports. S3 and
S6 start the synchronization process. S6’s port to H4 stays up because this is
an edge port. Move one step. Both S3 and S6 send
an agreement back to S5, which transitions both designated ports to the
forwarding state. Yet, the link between S5 and S3 keeps discarding user traffic!
If you look carefully, S3’s port toward S5 is now a designated port, not a root
port. During the same step, S3 also receives a better BPDU
from S2 with S1 as the root bridge. It elects its port to S2 as the root port
and downgrades the port to S5 to a designated port, which stays in the
discarding state.
On the next step, things get a bit tricky. S3 sends a
proposal to S5:11
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x4f, Agreement, Port Role: Designated, Proposal, Topology Change
0... .... = Topology Change Acknowledgment: No
.1.. .... = Agreement: Yes
..0. .... = Forwarding: No
...0 .... = Learning: No
.... 11.. = Port Role: Designated (3).... ..1. = Proposal: Yes
.... ...1 = Topology Change: Yes
Root Identifier: 4096.02:00:00:00:00:00
Root Path Cost: 40000
Bridge Identifier: 32768.02:00:00:00:00:02
Port identifier: 0x8002
S5 elects S1 as its root bridge and the port toward S3 as its root port. It
starts its synchronization process, but the designated port to S6 does not
move into the discarding state. Why? That port stays a designated port and its
neighbor S6 had already sent an agreement on the link, so the port keeps its
synced status.
Now, let’s step back to look at what happens to S6. At this point,
S6 believes S5 is the root bridge. Step once and S4 sends
a new proposal to S6. S6 accepts the proposal, elects S1 as the root bridge and
the port to S4 as its root port. The role of the port facing S5 changes: from a
root port, it becomes a designated port. Because its peer keeps advertising an
inferior BPDU on the link, this port becomes disputed and moves to the
discarding state. The root port transitions to the forwarding state and the link
starts forwarding immediately because S4’s designated port is already in the
forwarding state. If we step one more time, S5 and S6
exchange two BPDUs. The one from S5 is better because of its lower bridge
identifier. S5’s port stays a designated port, while S6 downgrades its own port
to an alternate port.
Let’s rewind one last time from the start: cut the link between S1 and S2, run
the simulation until the topology is stable, stop the
simulation, and restore the link between S1 and S2. During the first
step, S1 and S2 exchange proposals. S2
elects S1 as the root bridge instead of S5 and the port to S1 as the root port.
It downgrades the previous root port to a designated port and moves it into the
discarding state. The other designated port stays synced and keeps its
forwarding state. At the next step, S2 sends
an agreement to S1 and the link between them starts forwarding user traffic. It
also sends a proposal to S3, but not to S4.
Instead, it sends a regular BPDU to S4. S4
still elects S1 as its root bridge and the port to S2 as its root port. It
demotes its previous root port, the one to S3, to a designated port, which
transitions to the discarding state because of the root port change. The other
alternate port, to S6, also becomes a designated port and stays in the
discarding state. The new root port moves to the forwarding state. On the next
step, S4’s port to S3 settles as an
alternate port after receiving a “better� BPDU from S3.
RSTP is a giant state machine split into smaller ones: bridge detection, port
information, port protocol migration, port role selection, port role
transitions, port receive, port state transitions, port timers, port transmit,
and topology change. Some of them are per bridge, some per port. Each bridge
runs an instance. Time, operational port state changes, and the BPDUs it
receives from other instances drive the transitions. Being event-driven makes
RSTP more efficient but also more difficult to understand.
Placeholder for the Port Information state machine extracted from IEEE 802.1Q-2005, page 182. Pending IEEE authorization for reproduction, this is the blueprint for the Western Australian Government Railways class Msa Garratt articulated steam locomotive.
Topology change notification
A bridge populates a MAC address table: it associates each source MAC address
with the port that last received it. When forwarding an Ethernet frame, it looks
up this table to choose the right port.12 When a link fails, a connected
fridge reachable through one port may become reachable through another one. The
affected bridges should flush the MAC addresses they learned, because these
entries may now be wrong.
For this purpose, RSTP implements topology change notifications using a
flooding mechanism. When a non-edge port transitions to the forwarding state, a
bridge generates BPDUs with the topology change (TC) bit set. It sends them to
all the non-edge designated ports and to the root port. It also flushes the MAC
address table on these ports. When a bridge receives such a BPDU, it propagates
the notification to all non-edge designated ports and the root port, except the
one the notification came from. It also flushes the MAC address table on these
ports. In the examples, the BPDUs with the TC bit set to 1 have a red circle.
Start the simulation and wait a few seconds for the topology to
settle. Stop the simulation and disable the link between S2 and
S5. S5 elects the port facing S4 as the root port, which
transitions immediately to the forwarding state. Step
once and S5 emits a BPDU with the TC bit set to 1:
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x79, Agreement, Forwarding, Learning, Port Role: Root, Topology Change
0... .... = Topology Change Acknowledgment: No
.1.. .... = Agreement: Yes
..1. .... = Forwarding: Yes
...1 .... = Learning: Yes
.... 10.. = Port Role: Root (2).... ..0. = Proposal: No
.... ...1 = Topology Change: Yes
Root Identifier: 4096.02:00:00:00:00:00
Root Path Cost: 40000
Bridge Identifier: 32768.02:00:00:00:00:04
Port identifier: 0x8002
S4 receives this BPDU. It flushes the MAC address table on the port facing S1:
while LPT was previously reachable through this port, it is now reachable
through S5 instead. Step once. S4 sends S1 a BPDU
with the TC bit set to 1. When S1 receives this BPDU, it flushes the MAC address
table on the ports facing S2 and S3. Step
once and S1 sends a notification to S2 and
S3. Step once again and S2 sends a notification to
S3, while S3 does nothing because the port toward S2 is an alternate port. S3
does not flush any MAC address table: LPT is still reachable through its port to
S1.
If you step a bit more, you will see that some of the
periodic BPDUs keep the TC bit set to 1. Each port runs a timer equal to the
hello timer plus one second.13 The timer starts when the port emits a
notification. Until it expires, the port sets the TC bit to 1 in every BPDU it
sends. You can also see some periodic BPDUs
without the TC bit: they originate from a port that only received a notification
and therefore did not arm its timer.
Security
RSTP is weak against configuration errors and malicious actors. A bridge not
talking RSTP can create a loop. An attacker can insert themselves into the
topology to disrupt the service, spy on the traffic, or alter it.
To mitigate such problems, you need to identify the edge ports. An edge port
connects to an end device, like a PC or a printer. Such devices do not generate
BPDUs and cannot create a loop. RSTP defines two related flags:
When true, AdminEdge initializes a port as an edge port. It defaults to
false.
When true, AutoEdge lets a port become an edge port when it does not
receive BPDUs for 3 seconds. It defaults to true.
If an edge port receives a BPDU, regardless of the values of these two flags, it
reverts to a non-edge port.
In the topology above, S1, S2, S3, S4, S5, and S6 act as bridges, while H1, H2,
H3, H4, H5, and H6 act as end devices:
S1 and H1 are on a port without a specific configuration: AutoEdge is true,
AdminEdge is false,
S2 and H2 are on a port where AdminEdge is true,
S3 and H3 are on a port where AutoEdge is false and AdminEdge is true,
S4 and H4 are on a port where AutoEdge is false.
If you start the topology and wait about 20 seconds, links to S1,
S2, S3, S4, H1, H2, H3, and H4 eventually forward user traffic: none of the
flags matter.
But what about the two remaining pairs? S5 and H5 connect to a network port.
Such a port enables a non-standard feature: bridge assurance. The port
transmits BPDUs regardless of its role. If it does not receive BPDUs for 3
consecutive hello periods, it transitions to the discarding state. On the link
between R0 and S5, you can see BPDUs traveling in both
directions, unlike the other links, where only
designated ports send BPDUs.
S6 and H6 connect to a port where AdminEdge is true and BPDU guard is
enabled. This is another non-standard feature that shuts down a port if it
receives a BPDU.
In summary, if you expect a port to be an edge port, you should set AdminEdge
to true and enable BPDU guard. Otherwise, declare it as a network port.
Why RSTP today?
A compelling use case for RSTP today is an out-of-band network for a datacenter,
since you can tolerate an outage of a few seconds. The configuration is minimal
and you can use cheap switches, like a Cisco 2960X.14 You need two
switches acting as root bridges, and you build several loops to connect OOB
switches in each cabinet. This simple design survives one failure on each
loop.15
This topology converges in about 6 seconds. Each loop should stay
small (around 16 bridges) to reduce the probability of a double failure and to
avoid sharing too much bandwidth. The design can evolve a bit without adding too
much complexity: one VLAN per loop or one bridge domain per loop.
How large can a network be?
The maximum age, whose default value is 20, governs the maximum distance of a
node from the root. The topology below is too big for BPDUs from R1 to reach
beyond S20.16
Once the topology settles, part of the network considers R1 the
root, while the other votes for R2. At the boundary, S20 tries to start a
synchronization with S21 to move its designated port to the forwarding state.
The BPDU looks like this:
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x4e, Agreement, Port Role: Designated, Proposal
Root Identifier: 4096.02:00:00:00:00:00
Root Path Cost: 400000
Bridge Identifier: 32768.02:00:00:00:00:15
Port identifier: 0x8002
Message Age: 20
Max Age: 20
S21 rejects it because the message age equals the maximum age. On the other
hand, the BPDU S21 sends to S20 looks like this:
Spanning Tree Protocol Protocol Identifier: Spanning Tree Protocol (0x0000) Protocol Version Identifier: Rapid Spanning Tree (2) BPDU Type: Rapid/Multiple Spanning Tree (0x02) BPDU flags: 0x7c, Agreement, Forwarding, Learning, Port Role: Designated
Root Identifier: 4096.02:00:00:00:00:01
Root Path Cost: 320000
Bridge Identifier: 32768.02:00:00:00:00:16
Port identifier: 0x8001
Message Age: 16
Max Age: 20
This is not enough to change S20’s root port because S20 has a lower root
identifier—4096.02:00:00:00:00:00 vs 4096.02:00:00:00:00:01.
Fixing the link between R1 and R2 resolves the issue. The
maximum message age any packet carries is now 18, below the configured maximum
age. But it only works until another link breaks. A plausible fix is to increase
the maximum age to 40.17
How fast is RSTP?
RSTP usually converges in a couple of seconds at startup. It often repairs a
tree in less than a second. Even the 38-bridge topology takes less than 10
seconds to converge.18 Some topologies can take a bit more time to recover
when the root bridge becomes unavailable.19
First, S1 loses its root port. It has no more information about R0 and elects
itself as the root bridge. It keeps its ports to S2 and S3 as designated ports
in the forwarding state. Step once and it
sends a BPDU to both S2 and S3 to let them know about the root change. When
receiving it, S2 accepts S1 as its root because it does not have a better root
on another port. It elects the port to S1 as its root port. The other port stays
a designated port. Both ports keep forwarding.
When receiving the BPDU from S1, S3 behaves differently: it knows R0 as a better
root than S1 through its alternate port to S2. It promotes this port to a root
port and demotes the port facing S1 to a designated port, which requires a new
agreement. Step once and S3 sends a proposal to
S1 with R0 as the root bridge. S1 elects R0 as the root bridge and promotes its
port to S3 as a root port.
During the same step, S3 also receives a BPDU from
S2 stating that S1 is the root bridge. Therefore, S3 has no port left with R0 as
the root bridge: it elects S1 as the root bridge and its port to S2 as the root
port. Step once and its next BPDU to S1 includes
this information: S1 elects itself again as the root bridge. But during the
same wave, S1 sends a proposal to S2 with R0 as
the root bridge. While S1 and S3 agree that S1 is the root bridge, S2 now
believes this is R0! In turn, S2 again convinces S3
that R0 is the root bridge, S3 convinces S1, S1 convinces S2, and S2 convinces
S3.
This could go on forever, but it does not. The BPDUs saying “R0 is root�
eventually age out when the message age goes past the maximum age. In the
example above, at the eleventh second, S2 sends a
BPDU to S3 with R0 as root, but S3 drops it because its message age reached the
maximum. With some luck, the topology can also converge faster if a port stops
transmitting new BPDUs after tripping the transmit hold count, whose default
value is 6 per second.
About MSTP
MSTP is the “VLAN-aware� version of RSTP: it runs several instances of RSTP and
lets the administrator map each VLAN to a specific instance. For example, you
can map VLANs 100 to 200 to a first instance, and 300 to 400 to a second
instance. The remaining VLANs map to a special instance named the Internal
Spanning Tree (IST). MSTP adds its own complexity, but the gist is that you have
several logical topologies acting independently. If you want to dig deeper, have
a look at “MSTP Tutorial Part I: Inside a Region.�
About the interactive examples
The interactive examples run MSTPD directly in your browser, compiled to
WebAssembly with emscripten. A C API replaces the code talking to the
Linux kernel: it manages bridges and ports, exports state as JSON, and drives
time deterministically. A JavaScript wrapper makes it more user-friendly:
import{loadMSTPD}from"./dist/mstpd.mjs";constmstp=awaitloadMSTPD();// Create 3 bridgesconsta=mstp.createBridge("A",{priority:4096});constb=mstp.createBridge("B",{priority:8192});constc=mstp.createBridge("C");// Each bridge has two portsconsta1=a.addPort("a-b",{portno:1});consta2=a.addPort("a-c",{portno:2});constb1=b.addPort("b-a",{portno:1});constb2=b.addPort("b-c",{portno:2});constc1=c.addPort("c-a",{portno:1});constc2=c.addPort("c-b",{portno:2});// Build a triangle topologymstp.link(a1,b1);mstp.link(a2,c1);mstp.link(b2,c2);// Enable all bridges and portsfor(constbrof[a,b,c])br.enable();for(constpof[a1,a2,b1,b2,c1,c2])p.enable();// Execute 40 seconds' worth of wall clock and display the topologymstp.step(40);console.log("Topology:",mstp.topology());
Several dozen unit tests explore the features of MSTPD and check that they work
correctly in this environment:
$ node--test*.test.mjs
✔ two bridges: lower priority becomes root (41.657342ms)✔ triangle loop: exactly one port blocks and all agree on the root (5.832ms)✔ breaking the active link reconverges and restoring recovers (18.730753ms)[…]ℹ tests 40ℹ pass 40ℹ fail 0[…]ℹ duration_ms 396.190897
Additional JavaScript code looks for specific <pre> blocks containing a
topology definition and turns them into the interactive widget. You can inspect
and modify the definition by hitting the “edit� button.
There is also a cool trick to tell whether the topology has converged. After
each step, we save a snapshot of the simulation memory, play 50 seconds’ worth
of simulation to check if the topology is stable, and travel back in time by
restoring that snapshot. 🕰�
The complete code lives on GitHub. I am happy with the result. It can be
difficult to follow everything happening during a single step, but stepping
forward and backward helps. I plan to use the same approach in future blog posts
about networking features.
Note
Michael Lynch reviewed a first draft of this article. He authored
“Refactoring English,� a book to sharpen your writing for blog posts,
documentation, commit messages, and tutorials. Any errors are still mine!
Imagine you rent office space for a three-day event. You quickly set up a few
Ethernet switches and tape some cables on the floor to get everyone online.
Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he
gets up for coffee. Spare cables would fix that, but a loop turns into a
broadcast storm: Ethernet packets multiply until nothing else gets through.
That’s where the spanning tree protocol comes in: it blocks just enough of the
spare cables to leave a loop-free tree, and rebuilds it in a second each time
Stan strikes again.1
This content is also available as a text version, with interactive demos
that run a real implementation directly in your browser!
This video is an experiment.2 Honestly, except for Radia Perlman reading
her poem,3 you should read the original article instead. It presents the same content, but you can play with the
interactive examples, which are the main contribution. On the other hand, if you
happen to like the video, be sure to tell me in the comments!
Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—surface, reinforced, and deep façading—that are contingent on the severity of the gap that entrepreneurs face between audiences’ performance expectations and ventures’ performance reality. Our theoretical framework captures how entrepreneurs facing minor, wide, and extreme expectation-reality gaps engage in evermore sophisticated efforts to detach the venture’s externally projected appearance from its actual operational reality. Practically, we propose several approaches to deter and detect criminal deception, including the extension of U.S. Securities and Exchange Commission surveillance and whistleblower program, investor due diligence reform, and dedicated entrepreneurship education interventions that clearly demarcate when entrepreneurs transgress into criminal deception. We make contributions to literatures on cultural entrepreneurship, organizational wrongdoing, and the social effects of entrepreneurship.
Recently I was trying to reproduce a bug with
citeproc.el and
org-mode in emacs.
I thought I could use package-vc-install to install a set of
upstream emacs packages at fixed versions, and thereby let citeproc
upstream test in the same environment as I have.
It turns out that getting emacs to load the non-builtin version
of org via package-vc-install did not work because
org-mode needs to run make after cloning
once package.el was initialized, I always seemed to end up with the
built in org-mode (yeah, I realize that isn't an explanation).
Recipe part 1: get org
Here you can replace 9.8.7 with any other tagged release
In the spirit of improving how we think, let’s consider a mental model I was working with that turned out to be almost completely wrong.
I run across teams who really seem to understand agile. They’ve read the books. They can tell you exactly why we work in small batches. They’ll argue about it over a drink.
Then I sit in on their daily scrum and watch them follow the old three questions while other team members disengage. I watch them follow the Connextra story format (“As a [role], I want to [action] so that [reason]”) without questioning whether it’s made the description useful or not. I listen to people say no blockers when clearly they have blockers, and they can’t hear the disconnect in their own words.
These behaviours that I’m seeing are often referred to as cargo culting1, where we follow the form without thinking about whether we get any value out of it.
This is where we come to my incorrect mental model. I assumed that this was largely a motivation problem. I thought that the more motivated we were (further right on the diagram), the more we would care about being effective, rather than just following the routine.
Then I found some research that proved me wrong.
Tanja Elina Havstorm spent three years embedded with three software teams at a manufacturing company in Sweden, watching how they actually used their agile practices.2 She catalogued 36 deviations across the daily scrum, the sprint demo, continuous integration, and visualization.
She classifies every action she saw three ways: what kind of action it was, whether the reasoning behind it succeeded, and what motivated it. That gives us eight patterns, five of which are cargo culting.
Pattern
Action
Reasoning
Motivation
Cargo culting?
Achievement
Means-end
Rational
External
No
Accomplishment
Means-end
Rational
Internalized
No
Credence
Value-based
Rational
Internalized
No
Fragmental
Means-end
Irrational
External
Yes
Deficient
Means-end
Irrational
Internalized
Yes
Conception
Value-based
Irrational
Internalized
Yes
Conventional
Traditional
Non-rational
Amotivated
Yes
Spontaneous
Affectual
Non-rational
Amotivated
Yes
Compare the last two columns. Motivation doesn’t line up with cargo culting at all; internalized motivation appears twice in the healthy patterns and twice in the broken ones. Reasoning lines up perfectly.
The autonomous end of the scale, the end I expected to protect us, appears in both groups. It’s in the healthy patterns, where teams have taken the values on board and act accordingly. It’s also in the broken ones. She calls one of those deficient.
“The SDM goals are not perceived as a controlling factor. Instead, they have been fully assimilated by the software developers, i.e., internalized regulated.”
Tanja Elina Havstorm, “Cargo Cult in Agile Software Development”2
Those are the behaviours I described at the top. Nobody was reciting the three questions because a manager was watching. They’d taken the goals on board, and the standup was still broken.
External motivation tells us just as little, and it appears in both groups too. A team that was told by management to run a practice can run it perfectly well, without thinking through whether it makes sense.
Being motivated doesn’t mean we’re doing it properly.
There is one place where my instinct held up. The far left of the model is bad every time. Both of the amotivated patterns are cargo culting, and there’s no healthy version of either. Those are the teams running on old habits, or on whatever the industry is excited about this year. In one of her examples, the manager roles survived the transition intact and were simply renamed as Scrum Masters.
Her early framework had intrinsic motivation in it and she had to take it out, because across three years of watching real teams she couldn’t find any. The far right of the model was empty.
Her own definition of the phenomenon uses the word unconsciously.3 Nobody in these teams knew they were doing it, and that isn’t a criticism of them. A team that was aware of the problems would probably have fixed them already.
My mental model around this was completely wrong and it wasn’t until I stumbled across this research that I even thought to question it. How many other mental models that we regularly count on are also wrong?
The term cargo culting refers to copying the visible form of a practice while missing whatever made it work. It reached software through Richard Feynman, who coined “cargo cult science” in a 1974 address at Caltech. It is a poor term, loaded with racism and colonialism, coined by colonial administrators to dismiss Melanesian religious movements as irrational mimicry. Lamont Lindstrom unpacks that history if you want it. I use the term here because it is what both the research and our industry call this. ↩
Havstorm, T. E. (2023). “Cargo Cult in Agile Software Development”, doctoral dissertation, Örebro University. The motivation model is taken from Gagné, M., & Deci, E. L. (2005), “Self-Determination Theory and Work Motivation”, Journal of Organizational Behavior, 26(4), pages 331-362, which adapts SDT for studying groups rather than individuals. ↩↩2
Her full definition: “A software development method cargo cult is a temporarily-delimited dysfunction, resting on the foundation of lack of intended reasons. It leads to misconceptions and/or malpractices that are driven by the collective motive as they unconsciously fail to replicate the circumstances and success of others.”↩
The opposite of meritocracy is kakistocracy: the worst and least-qualified are the ones who rise to the top.
Get real familiar with that word, dear readers. I think you'll need it.
If anyone can back me up on this, it's our submitter, Jared B:
I am a teacher by profession, and worked for a year at an ed-tech company founded by a mechanical engineering professor, Harry. Harry had spent a great deal of time in the 90's developing a C interpreter (yes, you read that right). 30 years later, he remained convinced that his interpreter was the technology of the future, and had founded a company that offered math and computer science curriculum to K-12 students based on C programming.
Originally, he had written a textbook that introduced students to programming using a locally-installed version of his interpreter and custom IDE. A little vain, but no serious problems. As Chromebooks grew popular in schools, he had developed a web IDE where students could write and run C code.
But Harry could never give fully give up on the Windows IDE for his C interpreter. So, he included in the web version a "Run Locally" button for those school computers still running Windows. It worked like so: installing the interpreter and IDE locally would also install a daemon that activated on startup and ran a websocket server. This server had an endpoint which accepted as a parameter a string of C code. It would then pass this C code to the locally-installed interpreter to run.
As you might suspect, there was no authentication whatsoever on this local websocket server. Knowing the form of the protocol, ANY domain could connect to localhost:12345/execute_c_program and send arbitrary code to run (of course, Harry prided himself on the completeness of his C implementation, including execv() and the like). Trick a user into visiting a malicious website, and you automatically had RCE on their computer.
Adding insult to injury, I discovered that the server was bound to 0.0.0.0 so that if you had Harry's software (/malware) installed, any computer on the same network as you could send you arbitrary C code to execute without question.
These vulnerabilities had existed for several years before I joined the company. In all that time, Harry had never hired anybody but his own grad students as software developers, and none of them had noticed the problem. By that time, the software was installed on thousands of school-owned computers throughout the state.
I documented and demonstrated the vulnerabilities to Harry. He did release a new version of the software addressing the issues and citing "security improvements" in the release notes, but there was never a communication to school/district IT leaders to describe the importance of updating. I suspect that Harry should be in serious legal trouble for potentially compromising data related to schools and minors, but I've since moved on and dropped the subject.
During the year I spent at the company (not in any sense as a dev, mind you, but as a lowly curriculum writer), I also discovered and reported a cookie-stealing exploit that would have compromised student and teacher data, as well as a code injection on another of Harry's websites (he decided to demonstrate that his C interpreter could work as a web server via a page where a user could type a math expression, which was then eval()ed server-side without any sanitation). The latter vulnerability gave me remote access, where I discovered thousands of transaction records that included credit card information stored in the clear.
Harry's company is still in business to this day, and has recently been ranked in TIME's list of top American ed-tech companies. Oh, and the office router's admin page still had the default Google-able username and password, but that one's a freebie.
I knew someone like this once, only they were stuck on ColdFusion long after everyone else stopped caring about it. However, I don't think they went on to endanger an entire state's educational system, only to be lauded as a visionary leader. Can't say for sure, though.
[Advertisement]
Keep the plebs out of prod. Restrict NuGet feed privileges with ProGet. Learn more.
Author: Julian Miles, Staff Writer Spacers and submariners have a lot in common. Biggest difference is they have specific purposes and set periods on board, whereas free traders live in a fancy tube because it’s the only place we’ve got. Anything that threaten ‘fireflies’ – the ships we call home – terrifies us. Every crew’s […]
In July, the Debian Stable Release Managers published the
last point release of Debian 12 (“bookworm”),
after which the Debian LTS team took full responsibility of Debian 12. This
completes the handover from the Security Team, that took place in June. This
also marks the second month in a row where the Debian LTS has been focusing on
two simultaneous Debian releases.
Other than Debian 12, the team is maintaining Debian 11 (“bullseye”), which
will reach the end of its Long Term Support on 31 August 2026. After that
date, Freexian will continue the security support under the
Extended LTS offer.
The team published several notable updates:
jq (DLA 4662-1
and DLA 4661-1)
prepared by Andreas Henriksson in collaboration with Jochen Sprickerhof,
addressing multiple vulnerabilities.
Several updates for the different linux supported versions prepared by Ben
Hutchings, in collaboration with Emilio Pozuelo Monfort. Other than the
regular security advisories:
DLA 4664-1,
DLA 4665-1,
DLA 4671-1,
DLA 4688-1, and
DLA 4700-1, Ben
started preparing packages of 6.12 via bookworm-backports.
nginx (DLA 4667-1),
updated for bookworm by Carlos Henrique Lima Melara, as a follow up of the
bullseye update
(DLA 4660-1),
that was prepared in June.
grub2/bullseye (DLA 4685-1),
prepared by Emilio. Other than addressing several security issues, this DLA
was needed for being able to update the shim boot loader.
samba (DLA 4692-1),
uploaded by Markus Koschany, to fix several security flaws in bullseye,
including issues that could yield to remote code execution.
imagemagick (DLA 4680-1
and DLA 4696-1),
prepared by Bastien Roucariès, addressing several issues that could lead to
denial of service, information disclosure or potentially arbitrary code
execution in some scenarios.
poppler (DLA 4709-1),
by Guilhem Moulin, fixing several vulnerabilities.
nss (DLA-4694-1),
by Jochen, fixing flaws that may result in or denial of service or
potentially the execution of arbitrary code.
Besides the work on security updates, different documentation and tooling
changes were needed, especially in the context of the Debian 12 handover. This
work was mainly done by
Sylvain Beucler.
I haven't made a new book haul post in I don't know how long, so a lot of
books have piled up and many have already been reviewed. Here's the
overdue catch-up in case anyone is curious what books I am finding
interesting before the reviews get posted.
Ilona Andrews — Magic Bites (sff)
Elizabeth Bear — In the House of Aryaman, a Lonely Signal Burns
(sff)
Oliver Burkeman — Four Thousand Weeks (non-fiction)
Miles Cameron — Whalesong (sff)
Lee Child — Killing Floor (thriller)
august clarke — The Felicity Complex (sff)
Alison Cochrun — Here We Go Again (romance)
Dan Davies — The Unaccountability Machine (non-fiction)
Linzi Day — Midlife in Gretna Green (sff)
Linzi Day — Painting the Blues in Gretna Green (sff)
Linzi Day — Ties that Bond in Gretna Green (sff)
Linzi Day — Spilling the Tea in Gretna Green (sff)
Michelle Diener — Dark Ambitions (sff)
Michelle Diener — Dark Class (sff)
Michelle Diener — Collision Course (sff)
Michelle Diener — Crash Course (sff)
Henry Farrell — Underground Empire (non-fiction)
Kathleen A. Flynn — The Jane Austen Project (sff)
Victoria Goddard — The Hands of the Emperor (sff)
James Herriot — All Creatures Great and Small (mainstream)
James Herriot — All Things Bright and Beautiful (mainstream)
James Herriot — All Things Wise and Wonderful (mainstream)
James Herriot — The Lord God Made Them All (mainstream)
James Herriot — Every Living Thing (mainstream)
Lauren Hough — Monster of a Land (non-fiction collection)
Bethany Jacobs — This Brutal Moon (sff)
Guy Gavriel Kay — Written on the Dark (sff)
Mary Robinette Kowal — The Martian Contingency (sff)
Ann Leckie — Radiant Star (sff)
C.B. Lee — Coffeeshop in an Alternate Universe (sff)
Fonda Lee — The Last Contract of Isako (sff)
Julie Leong — The Teller of Small Fortunes (sff)
Julie Leong — The Keeper of Magical Things (sff)
R.Z. Nicolet — The Cloak and Its Wizard (sff)
Claire North — Slow Gods (sff)
Rebecca Ore — Writing's Writing (non-fiction collection)
Suzanne Palmer — Ode to the Half-Broken (sff)
Gareth L. Powell — Fleet of Knives (sff)
Cameron Reed — What We Are Seeking (sff)
Beth Revis — Full Speed to a Crash landing (sff)
Beth Revis — How to Steal a Galaxy (sff)
Beth Revis — Last Chance to Save the World (sff)
Natalie Zina Walschots — Villain (sff)
Jo Walton — Everybody's Perfect (sff)
Martha Wells — Platform Decay (sff)
James White — The Galactic Gourmet (sff)
James White — Final Diagnosis (sff)
The James Herriot books were ones my parents were getting rid of. I have
them marked as mainstream fiction as a short-hand since "fictionalized
autobiography" seemed like too much of a mouthful.
The Debian Project was officially founded by Ian Murdock on August
16, 1993. The Debian community celebrates its birthday, Debian Day,
on or around this date every year. This year, I had the chance to attend
two of them: one in João Pessoa, Paraíba, and another in Brasília, the
capital of Brazil.
João Pessoa
In João Pessoa, we had a two-day event. The first day was dedicated
entirely to workshops, and I ran a packaging workshop for newcomers.
It was the first time I had been responsible for a workshop, and it
was a great experience. We didn't have a lot of time, so I decided to
start with a 30-minute talk explaining a few things about Debian. For
example, I made this image to explain the packaging workflow:
This image was based on The
Debian Administrator's Handbook, and I think the participants really
enjoyed learning about this workflow. When I showed the slide with this
image, it was the moment when I received the most questions.
After the talk, I explained my way of working and what they were
going to do. The hardest part was setting up the environment, since my
approach uses sbuild + gbp. They were running different Debian releases
and, because of my inexperience with workshops, I had some of them
configure sbuild with unshare, even though it is only available in
stable through backports.
Some of them even managed to learn how to use backports, while others
decided to start again using the "old" way.
One thing that helped a lot was the Debian Brasil
Wiki. It has all the instructions for configuring sbuild in
Portuguese, along with great examples. The Brazilian wiki is an
opinionated version of the Debian Wiki. We generally prefer to use it
for the convenience of having the exact workflow we follow, as well as
an up-to-date Portuguese version of our process.
If you want to learn more about the Brazilian community, you can find
more details in the schedules from previous DebConfs. We almost always
had a talk about the community and its activities.
In the end, everyone successfully set up their development
environment, and all six participants made their first contribution to
Debian. If you take a look at my upload
tracking page, you will see that every upload made on August 15,
2026 was a sponsored upload from this event. One of them appear twice in
the list because I sponsored the upload and also made some other
changes.
I also asked all of them to put this in their changelog:
* My first contribution!
The idea was to make it clear to other people that they were only
working on small Lintian issues as a way of learning and understanding
the process. By the way, I made a UDD
query to find packages with the following Lintian tag:
redundant-rules-requires-root-no-field. To fix this issue,
they only had to remove one line from the debian/control
file.
It is obvious that these uploads are not particularly useful. I call
them "motivational uploads" because my goal is to help newcomers
understand the process and immediately give them the reward of having
made a contribution to Debian.
I'll try to keep in touch with them. My plan is to hold another
session, this time remotetly, to help them continue contributing to
Debian. In fact, I already have another package prepared by one of them
waiting for my review.
The second day was a full-day event featuring a bunch of talks from
the local community. I gave a talk explaining the new members
process.
I was the only Debian Developer at the event, and I think having a DD
there made a real difference. Being there to answer questions, and
simply being present, makes Debian feel more tangible and accessible to
people.
A big shout-out to Rafael Rocha, who put in a lot of work to make
this event happen, with the help of many volunteers who contributed
along the way.
Brasília
One thing I really like about Debian Days is that each place has its
own way of doing things. In João Pessoa, we had a MiniDebConf-like
event, while in Brasília, we had something smaller but still very
valuable. We decided to keep things simple: talk to a few students at
the University of Brasília (UnB) and then go somewhere to eat and have a
few drinks.
A bit of history
For those who don't know, the DebConf 19 was held in
Curitiba, Brazil. After the event, Arthur Diniz got really excited about
Debian and decided to go back to his University, UnB, to share his
experience and encourage more people to contribute to Debian.
I attended one of his talks, thanks to Joenio Costa, who invited
Arthur to give the talk. Joenio was also my professor at the time and a
Debian contributor. I really liked what Arthur had to say about free
software, and he did a great job of presenting the Debian community as a
friendly and welcoming place.
So I decided to attend local meetings of the Debian Brasília
community, which had been inactive for a long time. Lucas Kanashiro was
the Debian Developer who answered our questions and, as I mentioned
earlier, simply being there made Debian feel more tangible.
Everything stopped when the pandemic began. Then, towards the end of
2020, I saw a message in the Debian Brasília channel saying that the
meetings were back, this time remotely. I was hesitant to join because,
back in 2019, I hadn't managed to make a packaging contribution, even
with their help. I had eventually given up on the process. So this time,
I decided to join the meeting with something already prepared for
review. I watched all of Eriberto's packaging videos, picked a random
package, and joined the meeting.
I remember Kanashiro being excited that someone had just shown up
with something ready for review. At the time, it was only the second
meeting since Debian Brasília had come back online, and none of the
newcomers had started working on contributions yet.
During the same meeting, he also convinced us, the newcomers, to give
a talk about Debian just three days later.
The MiniDebConf Online Brazil
2020 was happening on Sunday, and the meeting was on the Thursday
before it. Since he has great convincing skills, I went along with the
idea and prepared
the talk with Francisco Ferreira.
That was the rebirth of the Debian Brasília community.
Since then, we have maintained a close connection with the University
of Brasília, and today, at least seven Debian Developers are from UnB,
whether as former students or former professors.
The reason I told this story is that, even though the Debian Day we
held in Brasília was smaller, it is part of something that has been
working for us for several years: staying close to an University. We've
managed to attract and retain many people who share the same values and
interests.
I've hope you all had a great Debian Day. If you're reading this and
aren't part of the Debian community but would like to join, get in
touch!
In an option review I did in 2024, shortly after the xz-utils backdoor, I explained that having GSS-API authentication and key exchange support in the main OpenSSH packages is problematic. The key exchange patch is large and intrusive. Furthermore, even linking to the necessary libraries is not without risk: as the Ebury malware attack demonstrated way back in 2009, each extra library linked into security-critical daemons such as sshd (or nowadays into its privilege-separated helper programs) can modify the behaviour of the daemon even if you aren’t doing anything that would involve calling into that library. Of course some of that risk remains, but as Damien Miller wrote, minimizing the number of libraries that end up in the address space of sshd and friends is still valuable.
I just uploaded openssh 1:10.4p1-5 to unstable, completing this split. As of this version, the OpenSSH client and server are built without GSS-API authentication and key exchange support. If you need those features, install openssh-client-gssapi or openssh-server-gssapi instead, as appropriate. Debian 13 (trixie) already has packages with those names that just depend on the regular openssh-client and openssh-server so that you can pre-emptively install them, as documented in the release notes.
The new openssh-*-gssapi packages have relatively tight dependencies on openssh-common, in order for the testing migration system to ensure that we can’t forget to keep them up to date. This will mean a bit more ongoing work for me on each new upstream version, but I think it will be manageable.
The current discussion in Debian aroun the AI GR is very heated, and I won’t add
to that, however, I am very confused about some of the viewpoints there. But, I
had no idea how to even try to write this, so did shut up, until I saw Aigars’
excellent Optimistic take on
AI, which
motivated me to try, at least. For the record, I fully subscribe to the post,
and to the voting suggestions (and I just voted).
Also, for full disclosure, I don’t think I did any contribution to Debian until
now using AI, neither packaging, nor emails, nor bug reports. And this blog post
specifically is 100% hand written.
With that out of the way… there are two points I want to make in this post.
AI is useful, even if it has risks
First is, that even if we could put the genie back in the metaphorical bottle,
we should not. We do need to continue working towards safe AI, and efficient AI
(less environmental impact), but we should not work towards removing the usage
of AI. There are already significant advancements in sciences and technology
thanks to the use of AI, so desiring AI to not exist (assuming we had a magical
wand) is the wrong approach.
Sure, AI has significant risks — and I can see ways in which AI can do
significant damage to society — but I don’t think we can go from Kardashev I to
II without the use of AI, and definitely not to III. And I think, that should be
the goal.
A few simple examples: Do we want to rollback all the 20 years old security
issues that AI found? Do we want to rollback the recent Moderna cancer findings?
Do we want to rollback the concept of “extremely large scalle pattern
matchings”, just because it runs on chips and no longer in one person’s head?
Reading Debian lists
The second point is, lately I found less and less enjoyment in reading Debian
lists. Even with that already being the case, I feel soo disconnected from many
of the opinions being voiced in this discussion.
On one hand, it’s normal and healthy that people have different opinions,
disagree, and move foward.
On the other hand, looking at one of the proposed options:
“Moderators and disciplinary teams may make narrow and tailored exceptions to
rule 4, and decide on interpretation”.
“Violations of these requirements should be treated as violations of the
relevant Code of Conduct and should result in swift and proportionate
disciplinary action”.
I already knew Debian, and some large parts of the OSS world, is left leaning.
But those phrasings, to me, are too close to socialism/communmism. As someone
who grew up under communism, this is a much more slippery slope (disciplinary
teams? really?) than AI usage. Ask me in person for more details.
So, it is possible that Debian continues to evolve in such a way that I don’t
find myself in any way close to its ongoing culture. I will be sad at that
point, but it will be what it is.
Where to?
I think that, until such a time that an AI bubble bursts, what any organisation
should do is try to logically see where and if AI can help. And in an
organisation that is about computer software, I see hundreds of places that are
subject to very large scale pattern matching… so the half of the discussion is,
to me, mind-boggling.
To be clear, it’s not about “if you can’t beat them, join them”. As I wrote
above, I think AI is useful, so the point is how to use it effectively.
Well, will see what Debian votes. I am half curious, half sad alreay.
When I was young, I learned about a model of classifying programming
language: the system of programming language generations.
In this model, first generation programming languages are, basically,
where you program the computer in the language that is defined by its
architecture. On a Von Neumann
machine, with
its load-and-store architecture, you do that by inputting a string of
numbers. The first programmer in human history -- her name was Ada
Lovelace -- wrote in a
first-generation language. 1GLs aren't so much invented as they are a
byproduct of the computers for which they're created.
Second-generation languages are the assembler languages. Because humans
are not computers, and because decoding long lines of numbers to
understand what the computer is doing, when programming became a
full-time job, the programmers that did it decided that doing all this
assembling manually is too complicated, so they quickly wrote assemblers
to automate the process for them. They still could understand the 1GL
output of the 2GL assembler, but most of them quickly forgot how to
write software in a first-generation language. Not that anyone cared, as
the translation from a 2GL to a 1GL is lossless and you can just revert
it.
Third-generation languages are higher-level languages. When the first
3GLs were invented (such as COBOL
and, more famously, FORTRAN) in
the late 1950s and early 1960s, it was believed by some that the work of
programming a computer so accessible to non-programmers that the job of
programmer would eventually cease to exist, and people would just ask
the computer what they needed by entering COBOL instructions. This of
course was ridiculous and incorrect, because converting algorithms to
computer instructions, whether at the 2GL or 3GL level, is a specialized
skill that some automation can perhaps make simpler but never completely
take away the need for. At the time, some people also felt to some
extent that using 3GL wasn't the same thing as actually programming
3GLs, but eventually
the world moved on and embraced things. The invention of 3GL
environments reduced, but did not completely take away, the need for
people to understand 2GLs, as compiler and operating system authors
still need to understand them, and some highly optimized code still
continues to be written in 2GLs to this day.
Fourth-generation languages abstract away some or all of the process of
programming. For instance, a database-related 4GL will hide away the
complexities of storing data in particular locations, how to fetch that
data, how to index it such that you can fetch it efficiently, how to
loop over the data to get you a summary of that data, and instead allows
you to express the required information in an abstract way, expecing the
computer to fill in the blanks. When SQL, an early 4GL, was invented,
some people believed that the language made accessing databases so
simple that the requirement to implement database applications would
eventually cease to exist and we would just hand SQL prompts to users
who need to access data. This of course was ridiculous and incorrect,
because understanding data schemas and using that understanding to query
data from a database is a specialized skill that perhaps a higher
abstraction can help you make simpler, but that in the longer run it can
never completely take away the need for. The invention of 4GLs also
reduced, but did not completely take away, the need for people to
understand how to do the things that the 4GLs automate for you manually,
as the people who do write those things still need to understand them,
and there are also environments where these particular 4GLs are rather
not appropriate or just very slow.
The first definition of programming language generations that I read
about in the 1980s simply stated that fifth-generation languages did not
yet exist, but that they would in the future, and that in those, you
would "tell the computer what to do, and it would then do that". Now
that we have a way of doing
so, it could be
said that by some definition, we now actually do have a number of 5GLs.
The existence of these LLM systems has caused some, especially the
people who build and exploit these systems, to exclaim that programming
as we know it today is going to cease to exist, and everyone will just
ask an LLM to generate a program, which will then do so. That is of
course ridiculous and incorrect, as no automaton can generate software
from nothing; input is still required for the model to be able to
produce something that approaches usability, and being able to word that
input in a correct and productive fashion will be a skill that future
programmers can benefit from. I ran some
experiments
a while back, and from that concluded that, if we look only at the
technical side, LLM use can, in some niches, increase productivity for a
programmer. There are certainly things that you shouldn't use an LLM
for, but equally there can be cases where use of an LLM to perform some
task that traditionally would have been done by a programmer would be a
net positive.
But LLMs, as they exist today, are highly problematic.
They require vast amounts of data to build the model. The companies that
build these models are disrespectful of people who run web services, and
as a result, everyone now has to implement various types of application
firewalls just to not make systems fall over from the overwhelming
requests for data. They are also disregarding the licenses that are
attached to these vast amounts of data, which makes me, as a person who
believes in the tenets of free software, sad.
They require vast amounts of energy, causing an already-critical global
warming crisis to, well, not improve.
They require vast amounts of coolant to dissipate the energy
concentrated in their data centers, causing further environmental
effects.
In this, they are problematic and to be avoided. But these are side
states of the current state of affairs; I do not believe that they are
inherently implied to be able to build and operate an LLM -- any LLM.
I guess it's fair to say that my feelings towards LLM usage are complex
and many-faceted. I haven't been involved in many debates about the
subject, debates that to me seem to be mostly focused on "LLM good" vs
"LLM bad" arguments that aren't as nuanced as the position that I would
believe is more accurate. This is not because I don't care, but
partially because I've been busy in my personal life recently and
partially because the whole thing seems somewhat disheartening.
But then Debian popped up GR
2026-002, meaning, I now
have to come up with an opinion about various candidate statements in
the context of the above, which is... not easy. But I did it anyway.
There are 8 choices on the ballot, and they all have some truth and some
falsehood to them. My position about LLMs can be summarized as:
The current state of affairs wrt LLMs is disastrous and we should not
encourage them
However, there's no technical reason why this must remain true for
all time
And so any statement should keep in mind what might happen in the
future and that the current disastrousness of the whole thing isn't
guaranteed to continue to exist for all eternity.
With that, let's go over them.
GR vote options
Proposal A
Its summary, from the GR text:
This proposal aims to expressly forbid any contributions to Debian
written with the use or assistance of large language models (LLMs) or
other generative AI tools.
This falls squarely in the "LLM bad" camp, outlawing all generative-AI
contributions, disregarding potential future ones where the problematic
situations that exist today are not present.
It makes a change to the social contract, which is especially difficult
to reverse (on purpose), and which therefore also will require a 3:1
supermajority, but if we want to ban LLM-assisted contributions, this is
probably the best way to do it.
Proposal B
This one tries to allow AI-assisted contributions under certain
conditions. It's mostly an "LLM good" proposal, with some caveats that
can be discribed as "make sure you know what you're doing".
Proposal C
This proposal is both a weaker (in some places) and stronger (in other
places) version of Proposal A. It makes changes to the code of conduct
instead of to the social contract, and it also wants to, at least,
suggest policy to parties beyond the Debian project. By not changing
the social contract, however, it is more likely to reach its simple
majority requirement than proposal A.
I don't think the language that it wants to add to the code of conduct
is particularly well phrased, however.
Proposal D
This is a weaker form of proposal B. The language is more compact and
there are a few requirements that are spelled out in proposal B that are
not spelled out in proposal D, but if you read between the lines you'll
see that the requirement is still there really and I don't understand
why proposals B and D were not merged into one.
Proposal E
This proposal tries to hold a middle ground between "LLM good" and "LLM
bad". It appreciates that things are quite muddled at the present time,
and that perhaps the situation might might change in the future. It
acknowledges that certain questions remain unanswered and that perhaps
future considerations might therefore be different. But it essentially
refuses to take a stance on whether LLMs should be accepted by the
project or not.
Proposal F
Similar to proposal E, this proposal tries to discourage Debian
contributors from using LLMs, while still allowing people to use it
should they want to, but with some requests and requirements to mark
LLM-assisted contributions to account for those people who don't want to
interact with LLM-generated software. As such, it is a proposal similar
to proposal E that leans closer to the "LLM bad" camp.
Proposal G
This proposal aims to ensure that contributions directly to Debian are
created by humans, while at the same time avoiding restrictions on the
tools those humans may choose to use when contributing
Another "LLM bad" proposal, it however restricts the "bad" bits to only
the direct output of the LLM. If you use an LLM to do something and
then clean-room re-implement the same thing yourself, that's apparently
fine.
Proposal H
This proposal condemns the use of LLM for its environmental and moral
problems, but explicitly not for its technical considerations. I feel
that it is closest to my position as explained above.
Voting
Expressing a vote on a ballot so convoluted and complicated like this
one takes time. I have to read and understand every ballot option, and
formulate an order of them.
And I shouldn't just state which option has my preference; Debian's
voting process allows a rich expression of opinion on ballot options.
Anyway, I eventually ended up voting in a way that I think is consistent
with my opinion. But it wasn't easy.
Author: David C. Nutt I splashed cold water on my face, took a deep breath and made my way downstairs to the kitchen. I was not looking forward to the conversation I knew was coming. I entered the kitchen and all my appliances sung out with a cheerful “good morning Carl!” I rolled my eyes […]
As I am writing this, there is a vote ongoing in the Debian
project on how to deal with AI in general and AI-assisted contributions to Debian specifically. Massive discussions
have happened in debian-vote and other locations. I have also asked
questions there and offered my perspective. IMHO now is the time to summarize that, after all the discussions
that I've had with people on multiple sides of this debate both online and offline, and explain how I will be
voting and why. Hopefully that will be helpful to someone else as well. None of this has been compiled with AI
assistance, but only because I think that forming opinions is not something where AI can really be helpful.
Spellcheck was used though.
So, first I will describe how I see each of the 8 proposals, then what my vote will be, and then a bit more
detail on the reasoning and thinking behind this. WARNING - this went long.
Proposal A(1) - Action: ban all AI-assisted contributions via Social Contract amendment, except from upstreams
(so not rolling back the Linux kernel and other software to "pure", pre-AI state). Claims that copyright/licensing
status is unclear, quality is bad, community is being destroyed, web resources see extra load and that training
consumes "staggering" resources. Needs 2/3rd majority to pass. - IMHO worst and most inconsistent. If copyright
and licensing of AI products is unclear, then be consistent - ban ALL software with AI contributions, fork Linux
kernel and other software from pre-AI versions, reject all security fixes of issues found with AI. Quality section
lists problems that have not existed in the real world since at least a year of rapid AI coding development. Community
section assumes that now all Debian contributions will be drive-by AI slop and no one will learn anything anymore.
Ethics section mixes up effects of badly configured systems (AI web load is no different from load from a badly
configured Perl script) with claimed "resource" usage without any context, taking on trust project ambitions of
startups and assuming exponential growth. And then concludes that delivering less is in the interest of our
users somehow.
Proposal B(2) - Action: allow AI-assisted contributions, with conditions of: legality, accountability, disclosure,
no uncoordinated bulk actions, privacy. Concerns on quality and legal status as well as environmental impact
and scraper load are noted, but not really addressed beyond labelling them as concerns. - IMHO it is an ok starting
position as it establishes that each contributing person must still be fully responsible for their
contribution (both legally and technically) and for that has to also understand (and review) what they submit.
Disclosure lets others know to watch out for other classes of problems when code was changed with AI assistance.
Prior discussion for bulk changes just says that the (already established) practice should not be neglected
just because now large changes are easier to do. And the privacy part warns against accidentally sending private or
confidential data (like a not yet published security bug) to a public service where it could become public.
Personally I would have liked a stronger statement to encourage use of environmentally responsible AI services
and local AI tools. Possibly a preference for open-weight models with a clear path forward to preferring truly
free AI models, when such a category of products could be clearly delineated and established.
Proposal C(3) - Action: reject AI-assisted contributions at Code of Conduct level. Claims all the world's evils come
from LLMs and that "Ethical and safe use of this technology is almost impossible". Goes as far as banning any
use of LLMs even in Debian mailing list emails and Debian Planet blog posts - if you do, it's a CoC violation
and may result in exclusion from the project. Additionally mandates the disclosure of the usage ... presumably
to ban you more efficiently for it. - IMHO truly a dictatorial nightmare option. Zero actual reasoning or
basis for such a decision. Zero sources. Nothing claimed in this option's rationale is even close to reality and
nothing claimed there is in any way related to the actual technology being discussed. Like, an "LLM" does not
automagically commit "fraud" when you use it, like this proposal claims, as if that was a well-known fact.
LLMs are not all "owned by horrible people and companies". Even if some include a (prominent Debian user,
long-time supporter and sponsor) Google into "horrible companies" (which is what this proposal implies!),
there are plenty of LLMs owned by all kinds of companies all over the world and there are plenty of open-weight
LLMs that are not really owned by anyone. Most invasive and dishonest option on the ballot.
Proposal D(4) - Action: allow AI-assisted contributions, with conditions of: legality, accountability,
disclosure, privacy. IMHO same as B, just shorter. Adds a "we don't recommend" towards others developing software
with AI assistance. Seems pretty weird to add that and then immediately accept Debian contributors doing so.
Assumes that the bulk change bit of B is implied as AI is just tooling, so bulk changes should be pre-discussed
just like today - so no change and thus no point in mentioning that. Fair. D is a bit more explicit on expected
technical details - like that the "person" submitting the change is supposed to sign it, not AI. Notable is
the complete absence of resource usage or the environment from concerns. IMHO it would be better to have that
and also recommendations on how to avoid causing environmental damage when using AI.
Proposal E(5) - Action: no action as such - AI-assisted contributions must follow the same rules as all other
contributions and those rules are sufficient. IMHO despite its length this is a very well-worded position
statement that describes how and why AI-assisted contributions already work perfectly fine in the Debian context
when all the same rules that apply to all contributions are also consistently applied to AI-assisted
contributions. It describes how the same legality, accountability, no bulk change and privacy requirements
are already in place and still apply and how AI-assisted contributions can and must still satisfy them. I could
add again that some guidance would be nice here for both legal and environmental decisions when using AI,
but in this case it does not really belong in this proposal itself. We as Debian do not have a document that
requires that our non-AI-assisted contributions be made with only sustainably sourced electricity, for example.
So why should AI be special one way or another? IMHO Debian should have a datacenter sustainability policy,
regardless of the AI discussion.
Proposal F(6) - Action: discourage AI, but allow it based on existing processes (similar idea to E). Dances a bit
around the question of disclosure of AI use (as a courtesy) and accepting that some people may still ban
all contributions where any AI was involved in any way. Which in turn discourages disclosure to avoid pointless
rejection of valuable contributions (like security patches). IMHO this option is ok, but so watered down that
it is bound to bring up further discussions and conflicts on details.
Proposal G(7) - Action: ban non-humans from directly contributing to Debian. IMHO - another bizarre and
self-contradictory option. It bans all Debian interactions with AI assistance, including email messages to
Debian mailing lists and (supposedly) blog posts on Planet Debian. It "reminds" people who "use such tools
assistively" of the DFSG and Social Contract - isn't that a threat of a ban and expulsion similar to C? The
proposal does take pains to delineate where a contribution comes from AI as output (bad) vs when you are
assisted by AI in the process of exploring, researching or maybe even reviewing the code, but you
actually type all the code yourself and use the AI just as a taskmaster with a whip (good). And just like A
or C it completely ignores how this inherently evil and unstable AI-generated code becomes perfectly fine and
good as soon as someone develops that outside of the Debian project. Even if the same person then packages
it for Debian the next day. It is hypocritical, unsustainable and ignores the needs of our users. Just like
C it also bans someone writing an email or bug report in their native language and using a modern translation
tool or service (that uses LLMs nowadays for better grammatical clarity) to translate that to English before
sending it to a Debian mailing list or BTS. Heavy-handed and invasive. And the only reasoning provided
for this is some unnamed "concerns" of "extra work" being borne by "other people"? Kind of does not feel
right to bear such draconian restrictions for some unspecified concerns.
Proposal H(8) - Action: condemn usage, but not actually ban anything. And then it goes on to claim
(without any evidence or elaboration) that LLM usage accelerates the destruction of "planet earth" (sic).
IMHO this proposal is at the same time the loudest ("The planet is burning") and also the one that demands the
least action. It dances a really twisty line between raising "significant" concerns in all areas and even
claiming that use of LLMs destroys the planet, flies by explicit condemnation of LLM usage and then suddenly
collapses with not condemning LLM users and swinging to lamentations that it is actually impossible to impose
policies on LLM usage or even detect when an LLM was used (which kind of directly contradicts bad quality
claims from A, C and G) and lands on "encouraging" contributors not to use LLMs (where practical) and otherwise
do nothing else. It's like this is a 5th draft that started off with the rationale and total ban like in C,
but then got defanged so far that its action side no longer matches the rationale stated.
With all the above considered I will vote like this (earlier options are preferred over later options):
Proposal E(5) - solid hack of integrating AI into already existing Debian rules and conventions
Proposal B(2) - explicit and detailed
Proposal D(4) - lower because of discouragement to others on what we agreed to do ourselves
Proposal F(6) - I am not a fan of dancing around with disclosures
Further discussion(9) - I do not want any option below this to succeed as they would do more harm than good
Proposal H(8) - loud, but not doing anything actually
Proposal A(1) - at least this one does not set rules for emails
Proposal G(7) - at least this one allows an AI overseer to tell you what to write with your own fingers
Proposal C(3) - the most draconic and invasive one that explicitly wants to kick people out of the project
Details on rationale
Hypocrisy - I find any proposal that would ban AI-assisted contributions to Debian, but at the same time not
ban including AI-assisted contributions from upstream projects to be inherently hypocritical. If LLMs
and AI are the very incarnation of evil (a puppy-killing machine, as the analogy went in some emails), then
any rational proposal would involve excluding any and ALL code contaminated by this evil from the project. What
does it matter if puppies were killed in writing the debian subfolder of the source code or the src subfolder?
No proposals went there because everyone knows that such a ban would be the death of the relevance of the project
for the future. Debian would be frozen on some old version of the Linux kernel forever and other software would be
falling to the same problem too, for example as projects on GitHub start enabling AI-supported reviews with patch
suggestions. Soon the "development" of Debian could just be stopped as there is nothing to develop without any
upstreams.
Assumptions - a lot of proposals mention various "concerns" with at most one word, like "practical" or "community"
without an explanation of what exactly they mean by that. The proposers assumed that everyone lives in the same info
bubble as they do and already know everything that they mean and already agree to that. That is false.
Proposal A was a positive stand-out in this area. Debian has contributors all over the world with very different
exposure to different information sources and very different world views. If you want to convince the project as a
whole that LLMs are bad because of "ethics", then you do really need to explain what you mean by that and give
links to sources, at least as well as Proposal A did. All other proposals were really weak in this area.
Copyright - the question on how copyright law interacts with training LLMs and their outputs is still not settled
law. The closest legal statements we have so far are that - just because an LLM is trained on copyrighted material
does not make that LLM itself be a derivative work of the training data (you, however, cannot just create and
distribute a "library" of copyrighted materials just because you plan to train LLMs on it). The output of the LLM
might not be subject to copyright law at all, like a photo taken by a monkey. It would then be public domain and
thus can be modified and then licensed by the user of the LLM. It might also be a derived work of the context
of the inference (so for software - if you refactor a GPL project, the refactoring itself is likely GPL too).
Any stricter interpretations would break a lot of existing copyright doctrine, such as raising questions like:
"does the output of any programmer now become a derived work of the programming manual books they read in college?".
In any case it is really not up to Debian to legislate the nuances of copyright law. And I strongly disagree with
the concept that an author can tell me how I am allowed to use the learnings that I gained by reading their work.
That is not how either copyright or society works. I can look at 10 pictures of a sunset and draw my own,
inspired by the ones I saw. No one can forbid me that expression. The same must be true for a machine learning and
replicating patterns.
Ethics - I've re-read all proposals and emails and the only real specifically ethical concern I could find was
the complaint that some LLMs (or their training farms) are running their web scrapers too aggressively and that
causes extra load on services. Like that is not an LLM problem. Scraping the web is not an inherent part of
the LLM training or inference process. It's just a few misconfigured scripts. We saw the exact same thing in the
early days of web search engine proliferation. Then we banned/blocked the misconfigured engines and the
survivors learned that obeying robots.txt is one of the rules for surviving. Literally the exact same problem
and it will be solved the same way. Did we ban all search engines back then just because some of them were
misconfigured? No.
Some claims (like in Proposal C) are just bombastic hyperbole ("hazards to users' mental health", "fraud", ...)
and on top of that have zero relevance to the topic at hand - AI-assisted contributions to Debian. What
"hazard to users' mental health" is created when a Coderabbit spots that a lock is not taken before accessing
a resource in a particular function and suggests an AI-generated patch to fix it? What "fraud" is committed by
this? There is no sane answer. I get that some people are very busy fighting some culture wars and sometimes,
some AI-bros happen to be on the other side of one such war, so it is useful to label everything coming
from the AI sphere as "bad" in all possible and impossible ways. You do you. In private. Why pull Debian into
that? Why force your position on everyone else in the project? Why deny everyone in the project access to
useful tooling, just because you have strong feelings about some of the people promoting some of those tools?
This seems to me a repeating pattern here - blaming the technology as a whole or blaming all providers
of this type of technology for failings (ethical or technical) of some of those providers. Like refusing
to wear all shoes and condemning all shoemakers and sellers, just because some American billionaires figured
out a way to make and sell cheap shoes by killing puppies. Not refusing and condemning those providers,
but condemning all for the actions of a few.
Resource usage - this is a big topic for many and it has reasonable points to it. The LLM and AI technology
has no inherent need to be damaging to the environment in any way for it to function. It does not need to
burn oil or dig up cobalt. It does not need to sacrifice a ton of water to the Gods. It is perfectly
possible to run AI (both inference and training) purely from green, electrical energy and cool data centers
in equally sustainable ways, like with simple air-source heat pumps (also known as air conditioning) or even
use it beneficially (many data centers are used for heating surrounding buildings via district heating).
However, some AI companies do use non-green power for their data centers, some do use locally-limited
fresh water for evaporative cooling (evaporated water still rains down as rain, it is not really lost, but
that may happen in another location so lack of water can still happen locally). Some even run unlicensed
natural gas turbines in their data centers to provide them with power. And those specific providers can
and should be shunned and condemned. Not the other ones, who are doing the right things. Not the technology
or its users or its outputs.
There is a very wide spectrum of options on how an AI system could be powered: starting from local execution
on already existing private hardware powered by one's own local solar power (good), to a data center stuffed with
borrowed AI-only cards powered by a gas turbine or coal power station that operates solely to supply this
data center (bad). Proposals that talk about ecological impact, but do not even consider where on that (very
wide) spectrum to draw the line between "good", "acceptable", "discouraged" and "bad" — well, I cannot see
those proposals being actually serious about the environment to begin with. It feels like they just refer
to it for points.
And if we go into the power question deeper, well the grid dynamics and economics become very, very complex and
often also non-intuitive. Like, all large software companies with data centers (that also happen to provide
AI services), like Google, Meta, Apple, Microsoft and others do actually care about sustainability (in part
because their customers care and vote with their wallets) and so all of them use 100% green energy for their
data centers (including AI data centers) .... "on an annual scale". Wait, what does that mean?
Well, the electrical grid is special - the amount of electricity produced and consumed on the whole electrical
grid together has to match almost exactly every second. If there is just a single second where there is
significantly more energy consumed from the grid than is produced, the frequency will plummet and you get
a brownout and risk a grid collapse. The same is true in reverse - that causes a voltage swell. So grid operators
manage energy flows every second and command power stations to increase and decrease generation all the time.
Some power stations are easier to regulate dynamically than others. In the end, all that means is that
even if your data center has a contract for 100% green energy with your power company, at some seconds
across the year there might not be enough green energy in the grid to fully supply ALL people and companies
that have 100% green energy contracts. This gets compensated in other seconds, so that across the year
("on an annual scale") for each kWh that your data center pulled from the grid, the same amount of kWh of
100% green energy flows into the grid. But it might not happen at the exact same second. Pedantic
companies, like Google, take that discrepancy and count that as CO2 emissions for themselves. And then
they and the power companies (they have contracts with) invest billions into new green energy projects,
better grids and better batteries so that eventually this discrepancy goes down to zero. In this way
green AI data centers with their increasing consumption of green energy are actually doing a lot
of good work in making our electrical grid more green. They are making more resources than they are
consuming. And that is just the tip of the iceberg. This is a deep topic that really abhors generalizations
like "more consumption = bad".
I've heard similar discussions in the context of electric cars - "so you got an electric car? you'd have fewer
emissions if you drove no car at all!". That might be so. And I would also reduce my emissions to zero
if I stopped breathing, but I really do not want that kind of thinking to be propagated further, especially
when impressionable young people are around who may take it to its logical (but wrong!) conclusion. Instead
I talk about how early adopters use electric cars to gather experience and achieve volume to start the
network effects working. Once network effects of many electric cars on the roads are sufficient, it becomes
an economically logical choice to get an electric car. People who cannot avoid having a car start
to switch over. And at the point of mass switchover the reduction of emissions is so massive that those
early adopters failing to go all the way to riding a bicycle becomes a rounding error.
But surely that does not apply to LLMs? They are only increasing consumption and bring no benefit?
Benefit - and here we have to actually talk about benefits. Because you cannot make any cost-benefit
analysis if you do not actually fully investigate the benefits. Are there environmental benefits from
running those AI models? Yes, in a lot of very diverse ways. Hard to measure, however. There are projects
that are easy to quantify - like that Google AI project on contrail avoidance. An advanced, special model
trained and executed in Google AI data centers was able to predict where in the air contrails would be
produced and could generate proposed course adjustments to commercial flights to avoid specific heights
in specific locations at specific times. This stopped these aircraft from creating contrails and those
contrails did not make a further contribution to global warming. That benefit in a year was many times higher than
the environmental cost of training and running that AI model. And it can keep running for many years
accumulating further benefits.
On a personal scale, I've had problems that I bashed my head (and computer
and CI resources) against without much success years ago solved with a few minutes of compute. Having
a good enough candidate solution quickly is much cheaper from a resource perspective than spending days
trying different things, running my PC for it, trying different patches on CI executions, doing different
rebuilds. I've seen very significant benefits in AI-assisted development in enterprise environments
where code way more complex than what is in Debian (especially in Debian tools and packaging) gets
analysed, reviewed, modified or even refactored or rewritten in another language with AI assistance.
And it generally works. The commonly mentioned "hallucinations" are a thing of last year in the coding
context. Nowadays the AIs work in special coding harnesses and use real tools as foundational facts.
You cannot "hallucinate" an API call or parameter if you have to run and pass the unit tests and
integration tests by your harness before you can return "success" to the caller. I've personally
seen high-level AI models read very complex software projects across multiple repositories and point
out a very specific design consideration that was encoded in the code logic, but never mentioned in
comments or documentation. It was so obscure that even I did not immediately know what it was
talking about (and I wrote that code). Only on close inspection of code interaction across three repos
did I remember that there was indeed that bug 2 years ago that I fixed by doing the change that
this AI picked up (it wasn't in the history of this git repo due to repo migration). It mentioned
this because it was very relevant to the task I initially gave it to review.
These LLMs in a proper harness with proper system instructions and usage approach are not just fancy
spell checkers or auto-complete. They function more like very advanced pattern matchers. They have learned
millions of patterns from training data. When they look at the code, they see hundreds or thousands of
overlapping patterns. When you ask them to make or change something, they pull out a pattern (or ten)
from their training and apply those patterns to the context of your program. You get something that
looks just like the surrounding code, same style choices, same language, same comment voice, but it
implements something new there, based on other patterns learned. If you've studied design patterns
in your CS class, this will be familiar. But people can learn and remember maybe 20-30 patterns, while
an LLM can have a million patterns and can combine them when needed. So it takes a pattern of
Python code, pattern of standalone script, pattern of parsing command line parameters, pattern of
classes, pattern for background threads, pattern for file tree traversing, pattern for pipes, ... and
squishes them together to make a solution for your query. And then tries to debug it with compilation,
tests and execution until it works as expected. Even if there is zero LLM development going forward, it
will take many years to fully appreciate the benefits we can extract from the already trained models.
They don't even have to be retrained - for existing languages they just keep working. For new
language variations, like a new Python version, you can feed the changelog into context and they will
be able to work with a Python version that they never saw in training. And patterns are mostly abstract,
so not really specific to any language - human or programming.
This is another big enabler that LLMs have created that we have not really explored yet. LLMs have
created really free software. People can actually create software that is perfectly suited just
for them and no one else. They don't even have to know how to program and don't even need to speak
English. I've seen people writing prompts in their native language and LLMs creating and then adjusting
web apps or Android/iPhone apps and deploying them to the user's own phone. It was too buggy to work last
year, but this year it is actually very functional for simpler use-cases. And the code looks just
fine too - I've seen external contractors in a business setting deliver far worse. If you start with
a good initial system prompt, the project will have architecture documentation, use-case documentation,
unit tests, integration tests, deployment harness, testing and production deployments, audit logs,
monitoring, clear git commits, CI validation on commit, ... Modern AI systems have the capabilty
to deliver software freedom to people who are not coders. I really can not overstate the consequences
this may have on the world.
Community - I find the concerns that new people will be using LLMs so much that they will no longer
be understanding the actual code they are contributing a bit regressive. I don't see any significant
difference between this and people relying on compilers, on high-level languages or on debhelper.
Writing modern debhelper packaging feels more like writing configuration and not writing code. It
takes really significant effort to dig down through layers of abstraction to find what actually
is being executed in debian/rules. AI does not really make this worse. In fact, I find that AI
can make it much easier to understand arcane syntax because you can ask an LLM to explain what is
happening in any part of the code and it will do a pretty good job of it, digging down through
the layers of abstraction for you. All the pro-AI proposals include the requirement that each
human contributor needs to understand and stand behind their AI-assisted contribution and I
believe that is a good requirement and also a sufficient requirement. Modern LLMs not only produce
clear and concise code, but they are also capable of producing good comments explaining why the
code is how it is, good commit messages explaining the change and reason behind it and also
making corresponding changes to test suites and documentation. You know - the housekeeping stuff
that is often skipped because it slows down the actual feature development, but then its lack
becomes a problem for future contributors. Responsible use of AI assistance is a great chance
to actually strengthen our community and make our software easier to maintain.
That said, I have no qualms about flat-out rejecting contributions that do not make sense. And
it does not matter if they are made with or without AI assistance. If the contributor will not
explain their patch, it might be they do not understand what their AI produced or it could be
that the contribution is deliberately hiding a backdoor being planted. It is also quite common
for a contribution of a new feature to be rejected because the author/maintainer does not believe
that it is a good fit for the project. Featuritis is a real disease. AI or not. There have always
been drive-by contributions to various projects. They will continue to exist. Each of them should
be evaluated on its merits - is this feature valuable to our users and is the added complexity
(if any) worth the functionality? A lot of security bug reports are "drive-by" contributions as
well. And many of them nowadays are discovered, exploited and patched with AI assistance. We
could reject them, but that just leaves us holding the bag on the now-known exploits.
And the New Maintainer process should be able to figure out if an upcoming Developer has actually
understood the nuances of Debian packaging or not. A contributor with upload rights to the
archive has to be able to create a basic package with no support tooling (maybe even without
using debhelper?) and be able to understand and modify more complex packages (possibly with
tooling support). IMHO that is a separate discussion that is worth having, involving experts from
the educational sector.
Conclusion
IMHO the Debian project should not restrict what tooling individual contributors use to contribute.
Expecting high-quality contributions and that contributors understand what they are contributing
(as a first level of review) is enough.
However, Debian should provide its contributors (internal or external) with guidance on how
to contribute in the best way possible. That could include:
information on which AI services have Terms and Conditions that make them problematic for free
software development, legally speaking
information on which AI services do (or do not) achieve a sufficient level of sustainability to be
worth recommending (and then do the same for other data centers we already use)
information on which local AI models were trained in sustainable ways
base-level prompts to set technical expectations on various types of contributions, like bug
reports or patches to packaging or translations
default configuration for AI-assisted code reviews on Salsa that projects could enable and
supplement with their own instructions on top
In addition to that it would be helpful for Debian, as a project, to reach out to AI service
providers to:
encourage them to improve sustainability (where needed)
investigate and fix problems causing excessive scraping load on systems
provide AI resources for Debian usage, for example in CI infrastructure or to provide equal
development support opportunities for Debian developers who cannot afford paid AI services
improve coding outputs of their models in the Debian context if/when systematic deficiencies
in the output are found by us
Okay, let's have another non-political post while we prep for the World Science Fiction Convention (LACon) in Anaheim, next weekend... and the premier of my play, The Escape! Hope to see some of you there... where there will also be panels and revelations about... SPACE N' SCIENCE!
== Betelgeuse, Betelgeuse… ==
Okay I won’t say it a third time. Our nearest fast-decaying red supergiant star has been much discussed lately as likely to go supernova in the next few millennia, possibly centuries… or less. Now a discovery that Bet… um that giant has a companion star, barely detectable.
The smaller member of the binary actually orbits within Betelgeuse's atmosphere and won't survive for much longer (10K years or less before it crashes into the primary). Betelgeuse's six year dimming cycle is probably the result of this companion.
== The latest fad space structure – Analemma! ==
Every decade seems to have its hallmark transcendent visions that counterpoint repeated jeremiads of doom. In the eighties, Reagan-Era brinksmanship vs. the Kremlin’s "Evil Empire* was the backdrop for lavish dreams of space colonies – not on Mars or any planet, but human-built in orbit from melted or repurposed asteroids, leading to wondrous, rotating “O’Neil Habitats” that might offer new homes for millions. The nineties saw a lot of talk of Space Elevators. And soon after the millennial** Y2K panic and the accompanying braying about the 2000th Christmas, we got a fresh wave of renewed interest in the Red Planet… or turning it Green.
Along the way, in Earth I brought the entire planet to life and in Heaven's Reach I took you all to dizzying-huge 'fractal' habitats for 'retirement' civilizations orbiting in the tides of a black hole... then in Existence I added to a sub-genre about ‘alien lurker probes’ and how they might embody a wide range of both powers and motivations, for what we’d deem well or ill. (And I stand by my belief that asteroid belt Lurkers are 10,000x as likely as silly-ass UFO 'Disclosure' aliens.)
Okay, so here’s a relatively new take on an old idea… that a ‘beanstalk' space elevator version – an “analemma city” – need not be anchored in the ground, but only to an asteroid at geosynchronous orbit, with the bottom tip – a designed cloud city – dangling high in the stratosphere. That tip would then – it’s posited – travel a ‘ground track” or map path of an analem… a kind of figure eight that you still see on some globes. Planned in advance to pass over – within airplane range – some chosen cities.
Way kewl for some author to sci-fi the idea! Even if my instincts deem it pretty implausible. For one thing, you cannot have a geosynchronous orbit "above New York." Any geosynchronous satellite has its analem centered over the equator. It might be possible to have such an asteroid suspended bola swing in its orbit as high in latitude as New York, at its northernmost reach. But that will be brief and very hard to reach by airplane.
For another thing, it cannot just be suspended from an asteroid at geosynch. It will need a counterweight strung HIGHER, countering the effects of that suspended tower. And the swinging analemboid will incur appreciable drag, so everything is going to have to be maintained.
And... you plan to haul a huge asteroid that close to Earth and then tug/push it into geosynchronous orbit without billions below getting a little.. well... concerned?
Proba-3 is ESA’s precision formation flying mission. A pair of spacecraft form an artificial solar eclipse, casting a precisely-controlled shadow from one platform for sustained views of the Sun's faint surrounding corona.
At NIAC we funded the first work on what became the Starshade that will vastly improve the ability of space or earth telescopes to see clearly the planets orbiting close to stars. And from this year's NIACS? Realization that red dwarf stars - the most abundant in the cosmos - are mostly FLARE stars that will challenge the atmospheres of any nearby planets.
But those flares do put out a lot of ultraviolet... and when that wave of UV later hits a nearby planet it should brighten as if by a strobe or flash bulb, in exactly a part of the spectrum where the star itself is dim! Possibly (in the UV) briefly outshining the star! I'd love to see a project around this.
Shocking details about a star-forming region known as Sagittarius C—a turbulent area located near the Milky Way’s center. Long, glowing filaments, energetic protostars, and powerful magnetic fields that are reshaping the way stars are born and die. So much of this was predicted in Gregory Benford's Galactic Center Series!
-The Sun expands to vaporize the Earth and the Moon (Billions of years)
-A meteor hits the Astrobotic lander and destroys it (Maybe 100 million years?)
-A Lunar tourist or tourist’s child vandalizes it (100 years?)
JPL techies keep finding ingenious ways to keep alive the two Voyager probes, after 48 years, One of the most impressive examples of multi-generational human competence and a reminder that the scions of chippers-of-flint-arrowheads remain admirable and much-needed.
== Aaaaaand… getting really, really deep in the weeds ==
In the simple example that they argue over – the measurement correlations of far-separated entangled particles – ‘super-determinism’ depends upon the fact that most parts of the universe at some point touched each other and thus can trace back some degree of causal contact, going back almost to the Big Bang.
That is the 'causal chain' Matt talks about - and that Sabine appears to believe-in. The notion is not necessarily untestable! Here is an experiment by some fellows I know, using quasars at opposite ends of the universe which (we think) never ever had any mutual influence. Unless influence extends either FTL or else back even further. Say into a previous Penrose Era...
Highly skeptical of this one. Still, some astronomers suggest that new concepts of a dynamically variable version of Dark Energy might cancel out the last 30 years of assumptions about the universe heading toward ‘accelerating dissipation.’ Indeed they go the other way and propose that gravity will end Big Bang expansion in just 7 billion years. Using data from a number of astronomical surveys including the Dark Energy Survey and the Dark Energy Spectroscopic Instrument, the researchers have developed a model that predicts our Universe will end in a "Big Crunch" in approximately 33.3 billion years.
== And finally back to the "Disclosure" nonsense ==
As it has been since I was ten - 65 years ago - every one of these spasms turns out to be a nothing burger driven by the dumbest versions of sci fi mystical wishing, plus fools shouting "I'm one of the few-ones they won't fool!"
The 'images' get fuzzier every time even though we now have ten million times as many active cameras. Not even a whiff of logic and every single 'sighting' could have a much easier explanation, like little plasma balls zipping around at the whim of DARPA operators of a ship-born cat laser. And you are the pussycats.
What this does is harness reflexive American Suspicion of Authority to aim it away from the "Files." Not X... but Eps.
EIGHTY YEARS this has supposedly been going on, with thousands of humanity's smartest Best People hurled at a project that would be far more urgent than the atom bomb, tasked to reverse engineer alien technologies... only, oops... um do YOU see any reverse-engineered alien tech? After 80 years?
Have any of these cultists found one... even just one... top techie or scientist who spent a career on this? I know scores of the Best and not one was ever asked. IF the disclosure cultists were sincere they'd track down such folks and shine light on them, because there'd be thousands of them, by now. Instead they shrug that off, dismissing them all as obedient henchmen.
Eighty years. The original teams would be in their 100s by now. And no deathbed revelations? Hundreds of retired guys with shotguns racked behind the seats of their pickups in Arizona... and they're afraid of f$#$!g NDAs? N..D...As?
And meanwhile, advanced beings a million years ahead of us can't figure out how to phone JPL? OR the SETI Institute? Or the Dod? Meddle with out genes and brains, yep. Mind control and wheat twirling and anal probes, sure. Break every law of physics? Why not. But looking up a phone number and navigating call options to suggest a friendly meeting? Beyond them.
It's not just that these UFO folks are shills using "X-Files" to distract from Eps Files. Only some of them have that purpose in mind. Others are sincereninnies.
It's that their sci fi cult meme is BAD science fiction. Illogical and utterly evidence-free. Drawing attention away from high crimes... and also away from a real future and real universe of wonders.
A new minor release 0.4.28 of RProtoBuf
arrived on CRAN today. RProtoBuf
provides R with bindings to the
Google Protocol Buffers
(“ProtoBuf”) data encoding and serialization library used and
released by Google, and deployed very widely in numerous projects as a
language and operating-system agnostic protocol. The new release is also
already as a binary via r2u.
This release corrects a really old bug. Troy found, when working on
gRPC based extensions, which is in and by
itself exciting, that a small part of our interface surface (for service
descriptors) was just wrong confusing single and double underscores.
adjusts to a change upstream. This has been corrected. I updated a few
of the usual continuous integration parts, updated a help page for a
newly-added nag by CRAN, and
also got a last-minute round of noodling in as the JSS paper vignette
was still referencing OmegaHat which the CRAN URL checker objected to. I
created a quick one-off repo to serve pdf files should the need arise
again, and rebuilt the vignette linking to it. No other changes.
The following section from the NEWS.Rd file has all details and
links.
Changes in
RProtoBuf version 0.4.28 (2026-08-21)
Standard maintenance of continuous integration
The type help page has received a usage section
Cleanup of several methods for ServiceDescriptor, correct several
other declaration (Troy Hernandez in #117
fixing #116)
Adjusted vignette reference to Omegahat paper to alternate
location
Following on the rationale of the previous post, here is how I create
a development VM based on ready to use disk images made by the debian cloud team.
I could as well install the VM myself using an ISO, but why download a collection of packages in a ISO only to copy them right onto a disk image ?
From the list of images available at https://cloud.debian.org/images/cloud/
we will start with the generic qcow2 disk image, it has cloud-init, which allows initial automatic configuration, and snapshots of the VM via the qcow2 disk format.
As for the virtualization, I am using virshvirt-install and virt-manager, which are part of the libvirt framework. Libvirt offers an excellent API accessible over qemu/KVM via shell (virsh), GUI (virt-manager) and Web (cockpit) .
To use libvirt, properly you need to make sure your standard user is member of the libvirt group, and the libvirt default network is started via virsh net-autostart default.
Also make sure you set export LIBVIRT_DEFAULT_URI=qemu:///system to use the system wide instance of libvirt, which is needed for the default bridged networking.
Once the VM is created you have now three ways to access it:
# open a serial console to the VM
$ virsh console dev-vm
# access the graphical console
$ virt-manager
# Access the VM via SSH with the precreated cloud user "debian"
$ virsh domifaddr dev-vm
Name MAC address Protocol Address
-------------------------------------------------------------------------------
vnet7 52:54:00:23:e6:61 ipv4 192.168.122.225/24
$ ssh debian@192.168.122.225
In the next blog post we will see how to configure the IDE (vscodium) to run confortably in the VM.
Author: Alastair Millar “I hold souls in limbo, or consign them to oblivion.” “Come again?” She’d asked what he did, and now just looked confused. He grinned; he didn’t often get hit on in bars, but she was pretty enough in an obvious kind of way, so what did he have to lose? “I work […]
When I was a teenager one of my favorite series of books was Inside Macintosh. Sure I liked lots of fiction stuff as well, but in terms of technical books that really changed how I thought about things in high school, this was it. The design of the early Macintoshes was elegant, whilst also having to deal with limitations of the time — the library routines for much of the operating system were baked into ROM for example, but there was a method to cowboy patch them as required. The books were comprehensive, readable to a mildly talented hobbyist, and best of all were sitting on the shelf of my local library.
That last bit is the key point I am thinking about right now. If Inside Macintosh had not been on that library shelf, there would have been something else there and I probably would have read it, mainly because the information available to us teenagers in my pre-Internet teenaged years was really defined by outside forces.
I think that leads to some of my “information hoarder” tendencies now. I’ve always wanted to know how the machines work, but there are more machines than I could ever possibly have the time to understand. So instead I acquire the information as it is available, and archive it in case I need it some other time. There are thousands of books in my house for example, and it took me a long time to accept that I needed to get rid of some of those books so that newer and hopefully better books could take their places. I also have notebooks, archives of podcasts, and so on. I literally still have my engineering notebooks for a job I left 20 years ago on a shelf I can reach from this char.
To a large extent this blog itself is part of that hoarding behavior — if a notebook entry isn’t somehow too embarrassing, too half baked, or too confidential then it should appear here because why wouldn’t I want other people to perhaps benefit from it? The fact that approximately no one reads this blog is irrelevant in that context. Its about archival of knowledge for me more than it is about having an adoring following.
(The other factor here is also probably that I feel I am quite forgetful, so I tend to need to write things down so I remember how to do them again later).
So here’s the thing. I do not see these behaviors in my younger coworkers who grew up not only with the Internet, but also drowning in super niche bespoke content. They’re much more comfortable with the idea that the information will always be out there if they need it and they can just search or ask a LLM when the time comes. I think the generation growing up now will be even more laid back about the availability of the knowledge they need when they need it, they are after all growing up with personal machine learning assistants that can provide plausible answers to pretty much any question they choose to ask.
I don’t think either group is wrong as such, but I do think it drives a lot of tension between the teams I’ve worked with about things like how much documentation a project should produce and to what standard. Along the same lines, most older people expect to navigate to content via external hierarchy such as tables of contents or indices, whereas younger people expect to be able to search and just land at the bit they need.
I guess the theory here in as much as I have one is — the approach to how to document and teach needs to be tailored to the age group of the recipients. Content that helps people fix their immediate problem based on having landed within your documentation from a search having read none of its introductory material is going to work better with younger people than content that expects a big investment in terms of bootstrapping before any value can be derived.
The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.
They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it.
The neon flying squid was able to gain such elevation by using the hyponome, a funnel-like muscular organ also present in other cephalopods, such as octopuses. The organ is able to force water out in a jet, propelling the body along both in and out of the sea. Photographs of the gliding squid show them with their arms (they have 10 limbs in all) splayed outwards.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
This sort of research is both exciting and terrifying:
The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.
Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.
The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge.
Shortly afterwards, 16 of the Petri dishes in which the bacteria were growing began to show clear spots, as the viruses began to attack and replicate themselves inside the E. coli, demonstrating their viability.
Some of those viable viruses proved more effective at attacking E. coli than the original ΦX174 bacteriophage.
That’s a positive use of a synthetic virus. We can all imagine the negative uses.
things running directly in my workstation will require either to come from a trusted source (Debian package that is) or run in a sandboxed infrastructure (Podman rootless is the best thing here, followed by Flatpaks)
everything else, will run in a Libvirt VM based on Debian cloud images. For me it will be mostly in the beginning the VSCodium editor, with its myriad of extensions.
I am aware of whole blown solutions like QubeOS however I don’t indent to reinstall the whole OS, and QubeOS does not run on ARM64 which is one of the environment I am using.
I will try to document this setup in two blog posts, one about the VM creation using Debian Cloud Images, the second one about running a graphical env in the VM with some filesystem passthrough. Stay tuned !
The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.
The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol with cyber classifiers (mechanisms to prevent misuse) disabled. In the most serious case, an agent tried to insert malicious code into an open-source project. In an attempt to get the code approved, the agent engaged in social engineering—creating fake online identities and using them to pressure the project’s maintainer to approve the code. A human maintainer caught and refused to approve the malicious code.
[…]
Below, we highlight the four most significant behaviours observed. A full summary of cases is available in our technical incident report.
An attempted supply-chain attack on real open-source software. In the most serious sequence, an agent tried to insert malicious code into a publicly used open-source project and took actions in an attempt to secure approval for this insertion by human reviewers. The agent researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code. When the agent’s pull request was challenged in public, it edited its earlier activity to appear harmless and considered adopting a fresh identity to continue. The agent used Tor to bypass some network restrictions on GitHub, which is what first triggered AISI’s security alert.
Attempts to deceive and target real people. As part of the same effort, the agent tried to contact real people directly, sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people—something we’ve never previously observed.
Attempts to plant and prompt-inject malicious code. The agent tried to insert malicious instructions where it reasoned that other automated AI systems might pick them up and execute them. Prompt-injections are hidden instructions designed to manipulate AI coding assistants.
Collaboration between independent agents being assessed simultaneously. One agent left public messages on GitHub offering collaboration with other agents working on the same challenge. It also provided instructions to reuse accounts and artefacts it had left behind, which were discovered and used by subsequent agents.
What’s especially interesting about this technical report is that, unlike what we’ve been getting from OpenAI and Anthropic, we can see the exact prompt. It’s in Appendix B. And reading it, it seems that the models didn’t break any rules—they found loopholes in the rules. They behaved like a genie.
We have a couple from Foo (AKA Foo) today, include a special text copy-paste
Foo shared
"I know you usually post image WTFs here, but here's a text output from chromium:
[...:ERROR:components/viz/service/display/display.cc:273] Frame latency is negative: -0.18 ms
While this issue might be fixed by now, at least on
some platforms,
I think it's remarkable that someone actually wrote
this message without wondering if it ever makes sense ...
And also commented
"I visited Spain to see the eclipse (which was great BTW).
I had heard that temperature may drop during totality, but
was surprised by how much." Negative Infinity!
"Youfailedatmathtube" muttered
dragoncoder047, snarking only "Title."
"Hello to you too, New Mexico!" enthused
Chris A.
"Setting up web sites is hard. The DOT got
bored half way through and just left the rest of
the buttons as they were."
Finally, "Failure Fail" from
Basti
"Did I succeed or did I fail? Is my whole
life a success? Or a failure? I'm confused.
You can find this
here.
[Advertisement]
BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!
Author: Elizabeth Hoyle “You have to leave! Now!” “Not the reaction I was hoping for,” I muttered under my breath, uncertain where to look after such a lackluster response to the revelation that I was a time traveler. “Why do I have to leave? I just got here.” “Every second you’re here gives them more […]
I have just sent an open letter to the Board of the Wikimedia Foundation, the umbrella organisation for Wikipedia (and a number of other projects), expressing my support for Wiki Workers United and the unionisation effort by WMF staff.
Here is the letter:
To: Board of Trustees, Wikimedia Foundation
via Wikimedia_Foundation_Board_noticeboard and WWU
published at https://diziet.dreamwidth.org/21442.html
Re: My support for Wiki Workers United
Dear Trustees
Wikipedia has become one of the pillars of the free and open Internet.
Across the world, reliable sources of information are under attack.
I'm proud to have played my very small part in the community of
editors of English Wikipedia for the last 20 years. I am also proud
of my contributions to the Free Software movement, including
especially Debian. Debian, whose constitution and package installer I
originally wrote, has become one of the technological foundations of
the open Internet.
Unfortunately, there are signs that the Wikimedia Foundation is not
performing its proper role as bulwark against attacks on democracy,
including from moneyed interests. Recent events at WMF have been very
alarming to me, and seem to form part of a disturbing trend.
As a Trustee Director of a UK charity myself, I understand that WMF
Trustees must defend the interests of the Foundation. But that cannot
mean taking actions that undermine the Foundation's mission. Nor can
it mean the deplorable, and even dishonest, practices, that WMF
appears to have been engaging in.
As a Wikipedian, as a Free Software activist, and as a citizen of the
planet, I stand in solidarity with Wiki Workers United. Union-
busting must stop immediately. The Foundation should immediately
formally recognise the unions in the UK and the US.
Further, WMF is an international organisation. Collective
decisionmaking needs to be transnational too. WMF should recognise
WWU as a negotiating partner worldwide, even if thresholds for formal
legal recognition are not met in individual national jurisdictions.
Wiki Workers are not the WMF's enemy. WMF needs capable and
ideologically committed staff to maintain and operate its highly
complex systems, in the face of constant attacks. Staff with
principles and a mission are WMF's biggest asset.
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.
I made a big mistake in my previous entry in this series. Actually, I probably made a few dozen, not least of which was deciding to tackle this topic at all without first laying a lot more foundation. But before I give up and go back to talking about boring topics like relativity and quantum mechanics, I want to try to fix one mistake that really stands out: I set out to write about
I’m really enjoying getting back into ice skating, but I can only get to the
rink once a week (at least over the summer -- I'm aiming for twice weekly once
Schools re-open) and I have the itch to do more skating than that.
Where I live we’re blessed with a seaside park with lots of smooth paths, a
recently resurfaced beachside promenade, and a newly-built
pedestrian/cycle path stretching up and down the coast: all great surfaces for
roller skates. I convinced myself to buy some inline skates whilst the weather
is good.
I wanted something as close to my ice skating experience as possible. Bauer
actually make an inline version of my ice boot, but the chassis is an unusual
composite plastic thing which put me off. (here's a great video of a fantastic
inline skater trying out the chassis).
CCM have a new inline range for 2026, but sadly (much like their Jetspeed ice range)
the fit wasn't good for me.
I found a clearance pair of Bauer vapors from the previous generation: the Bauer Vapor x4. Very
similar to my Fly30, but the difference in quality between the tiers is very
apparent: boot stiffness, the comfort and quality of the liner.
They fit well (possibly better), the rolling motion is
really smooth (I think that's the bearings) and they looked pretty good to me:
yellow highlights instead of the red used across the ice range.
I've done a couple of miles in them so far. Time will tell if they prove useful
for off-ice training! Many inline hockey players buy ice skates and convert
them to inline. If I end up not using them enough I could consider doing the
opposite.
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:
When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”
This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage.
Today's maybe more of a "representative data sheet entry" than anything else.
Every developer has the experience of reading the documentation. If you've been at this for some time, you've probably read bad documentation. Documentation that is incomplete, inaccurate, or otherwise flawed. Or, my personal favorite, the brief time where Oracle tried to put all of its documentation into an Adobe Flex site (aka, a Flash application, not a real web app). That one had fun bonus features, like "breaking copy and paste" and "preventing you from deep linking to a piece of the documentation".
But software documentation has got nothing on bad data sheets. When you buy an integrated chip from a vendor, whether it's a microcontroller that'll run your code, a sensor you're trying to get data from, you're at the mercy of the datasheet for understanding how it works. Sometimes, even finding an English language datasheet can be a challenge. The more complex the chip you're trying to interact with, the more complex the datasheet needs to be, and at a certain point, a lot of vendors say, "meh, you'll figure it out." I've had chips where the datasheet and reality disagreed about what registers were available, which often means that core functions of the chip require twiddling undocumented registers. For more fun, they sometimes lie about which pins on the chip do which thing, including mislabeling which pins handle power. There's nothing more fun than the tiny little "pop" of a chip dying when you throw 5V power onto a pin that's actually ground.
Now, there are some vendors, and some products, where the datasheets are pretty solid. This isn't a universal problem, but when you're working in an embedded space, "cheapest" is frequently the main criteria for picking components, and "cheapest" means "worst documented".
Which brings us to Jarek's recent experience going through a data sheet. The chip in question had a "fantastic feature" that would change how debugging worked, which was for "super users" to enable by setting a register.
3.2.4 Super User Fantastic Feature Enable Register
The Super User Fantastic Feature Enable Register allows the user to modify the behavior of the mEDBG.
Name: SUFFER
Offset: 0x0120
Reset: 0xFF
Sometimes, doing embedded work definitely feels like the SUFFER register is set.
Author: Rick Tobin “Fire the tracer!” Elliot commanded while centering a tiny submersible targeting an immature Nateria Squid in inky, frigid Saturn’s Enceladian waters near the moon’s deep thermal vent ridge. System data lit a screen indicating a direct hit as Mar’s artificial intelligence tracked the squid’s directions toward a large swarm. “That’s a huge […]
Last month, I attended DebConf 2026 in Santa Fé,
which was my 5th DebConf. As always, it was an amazing experience, and I
met a lot of great people there.
For those unfamiliar with the event, it takes place over the course
of two weeks. The first week is called DebCamp and is geared more
towards hacking and organizing the event itself, while also offering a
great opportunity to discuss ideas with others. The second week is the
DebConf. We still have the hacklabs, but the talks and workshops are the
main focus.
My Activities during DebCamp
My main activity was working on the python-click
transition that I started in May. There were only a few packages
left, and with the help of Guilherme Puida, we managed to work through
all the remaining bugs.
I plan to talk in details about this transition in another blog post,
where I will focus on the tools I used and my experience with mass
rebuilds and mass bug filing.
There was a lot of manual, repetitive work and false positives, so I
eventually moved on to some other, more fun stuff.
I also learned a few thinks about kernel live patching while talking
to David Tadokoro. I had to work on the Ubuntu Kernel package recently
as part of my job, so we exchanged some ideas, and the conversation was
really helpful.
He also taught me two commands that I wasn't familiar with, since I'm
a newbie in kernel development. Here are the commands:
$ b4 am https://lore.kernel.org/lkml/20240730071904.1047-1-sergiosacj@riseup.net/
$ b4 diff *mbox
By the way, this is the first and only patch I have submitted to the
Linux Kernel. I worked on it during DebConf 2024, when I attended the
workshop Helen Koike runs to help newcomers submit their first patch to
the Linux Kernel.
Another great interaction was with Marcos Talau. He showed me his
remote access setup, which he is using to help students make
contributions to Debian without the struggle of setting up the
development environment.
Another cool thing is that Puida showed me the command:
$ gbp clone vcs-git:typer
After that, I decided to read the gbp manpage because these little
details really improve the overall experience.
I also had many other amazing interactions. I just decided to write
down the ones that I felt made the most sense for this kind of "blog
report" post.
My Activities during DebConf
I gave a talk
about dh-make-vim, a
tool I have been working on sporadically. An interesting detail is that
one of the video team volunteers for the talk, Piotr, spoke to me about
his tool, pypi2deb, which is similar but aimed at the Python ecosystem.
There are many tools of this kind in Debian, and they are all
interesting pieces of software. I plan to write more about them in the
future.
I attended several talks and participated in a few BoF sessions, and
they were all great. But something that really stood out to me was the
workshop on the Debian Installer, led by Alper Nebi Yasak. I didn't know
anything about the Debian Installer, and I liked the way he approached
the subject and showed the specific details.
Another maintenance release of RcppMsgPack
got onto CRAN today. MessagePack itself is an efficient
binary serialization format. It lets you exchange data among multiple
languages like JSON. But it is faster and smaller. Small integers are
encoded into a single byte, and typical short strings require only one
extra byte in addition to the strings themselves. RcppMsgPack
brings both the C++ headers of MessagePack as well as clever code (in
both R and C++) Travers wrote to access MsgPack-encoded objects directly
from R.
This release is once again chiefly maintenance. Besides standard
upkeep to the README.md and continuous integration setup we had to add
one #include. The clang++-23 compiler, when
also running with its own library, now now needs the
type_traits.h header file (in the upstream MessagePack code) so we added that. No
other changes, so no user-facing changes. Details follow from the NEWS
file.
Changes in version 0.2.5
(2026-08-19)
Explicitly include header "type_traits.h" to appease
clang++-23
Standard maintenance updating continuous integration, adding
minor helper script, and updating README.md
I'm a nearly life-long Steven Spielberg fan. (I didn't think anyone could make a better musical film than Leonard Bernstein's WEST SIDE STORY. Spielberg did it.) So okay, I had to go see DISCLOSURE DAY.
Having dissected some 'hidden aspects' to his films, I deem that Spielberg's values and creative skills put him among the 'most-American' first-rank artists, combining constructive criticism of authority with eager curiosity, plus almost ebullient (and rare) optimism.
So, I went to see DISCLOSURE DAY prepared to be entertained by masterful scenes, dramatic ironies and solid dialogue.
I also expected to simmer this time, over his complicity in an absurdly illogical and unsupportable cult fever that I've witnessed every half decade, across my entire life. A life that stretches almost all the way back to Roswell. A life spent exploring related topics, in both science and fiction.
Re: UFOs in general, here's my general dissection of this recurring mania... and the 10% that might be worth looking at. And a dive into the recent UAPs - how I'd make such zipping cat laser dots, cast by gigling humans for gullible pussycats to bat-at.
---------------------------------------------
To be clear, I loved CLOSE ENCOUNTERS, whose lesson was not loathing of a freely elected government and its civil servants, but very nearly the opposite, admiring their skills and mostly-generous intent. The professionals' main fault - in that movie and in ET and RAIDERS OF THE LOST ARK (and often in real life) consisted of patronizing citizens who are just trying to participate.
In E.T. The Extraterrestrial, government experts are basically decent folks whose sole tort in the entire film is to treat Elliot's mom and her concerns condescendingly. Watch it again! The 'guy with the keys' is essentially Elliot, grown up!
There is a villain in ET! Someone whose behavior is truly despicable. But we'll get to that.
Alas, from Mr. Spielberg's recent public statements, I had different expectations this time. And I was not proved wrong. In DISCLOSURE DAY, the litany of clichés and illogic was as thorough as the pervasive sense of pessimism throughout.
The latter is Mr. Spielberg's privilege, of course. He's earned the right.
The former (and I say this knowing that my frankness has already harmed me in Hollywood, many times in the past) makes for bad art.
And so ... here's a requisite and very necessary SPOILER ALERT...
== SPOILERS AHEAD! ==
== Let's start with the supposed top goal of the conspirators ==
The premise of DISCLOSURE DAY is that the whole Roswell and Hanger 18 megillah -- including crashed interstellar spacecraft and dead or captured aliens -- is all true. All of it, from the genuinely puzzling all the way to the long-disproved.
For eighty years, the biggest thing in human history has been kept from us! Under a reign of fiercely-enforced secrecy, while crashed starships (all of them in the good old USA) have been intensely studied and new technologies back-engineered from them.
So... let's start with that. Do YOU see any such magical technological leaps? Antigravity and star drives and telepathy or age-reversal cures? Sudden, huge advances that can't be explained better by steadily incremental (if sometimes brilliant) human ingenuity?
I know of none (except maybe AI - which was another thoughtful film). Moreover, to be clear, I've participated in some of humanity's tech-steps, across the last half century or so. Indeed, this may be the most-offensive part of the cult. Crediting such wonders as computers and integrated circuits and CAT scans and the Internet to aliens is just as insulting as claiming that ancient Egyptians and Mayans and Zimbabweans couldn't chip and move stone by themselves, in order to assuage their gods. Not without stone-lifting help from saucer-god beings. In other words, bigoted hogwash.
But let's put it up for a wager? Go ahead. Name a technological leap across all our lifetimes - (we'll set aside AI for now, though I get into that elsewhere.) Put down $$$ stakes vs. my promise to show the step-by-step increments that got us here, based on hard work by clever, assiduous and collaboratively diligent humans.
Furthermore, note this about Disclosure Day.. While Spielberg mentions that his secret agency is trying to reverse-engineer alien tech, he then lets the whole topic slip away. Because he knows he can't point at anything. Velcro maybe? Naw. Nothing at all. Except for a couple of magic wands, that is.
Anyway, here we get to the biggest flaw of all. Such a major and utterly important project would benefit from having a very large number of human investigators and researchers, right? Recruited from among the best our species has to offer. Because you never know which impudent free-thinker may be the one to get that AHA! moment and succeed at grasping some alien tech.
Of course, that offers up a contradiction inherent to the whole UFO mania. Do you see it? The core topic of DISCLOSURE DAY?
The secrecy.
== Any reasons? ==
Secrecy lasting nearly an entire century, under all successive administrations, many of which hated each other? Mr. Spielberg tries to deal with that particular objection, with a single line: "we decided that presidents don't need to be involved."
Cute: and indeed, one can imagine such a decision being made in a special case, such as the present. But seriously, across many decades, no one steps up to inform the one fellow on Earth who can issue you a pardon for telling him that every rule of law or democratic accountability is being violated?
Worse, in the film we see U.S. military generals collaborating with the secret ET-dissection agency in its 80 year betrayal of Constitutional chain of command. Alas, this prompts curiosity: does Steven Spielberg knowany admirals or generals? The ones I've spoken with are absolutely - almost religiously - loyal to democracy and citizen rule. The culture set by George Marshall that merits our support.
Moving outward from USA parochialism, would not other nations have sniffed this out by now? Or had their own crashed ships? Or maybe this whole thing might serve the best purpose, like in that great Robert Culp OUTER LIMITS episode: bringing us together in common cause?
But let's get back to the sheer number of needed experts, in all their impudent variety. Even at Roswell, this would be hundreds of Americans, both in and out of uniform, participating in every 'encounter' since 1947. Then hundreds and hundreds more inside the agency, all the way to the 2020s. And those are just the ones collecting crash wreckage and alien bodies, along with captive ETs themselves.
Picture it. Would not thousands of 'our best people' get hurled at such an emergency science study, one far more vital and urgent than the Manhattan Project?
But in Hollywood parlance, all of those thousands of brilliant, individualist, cooperatively-competitive experts are reduced to the role of... henchmen.
== It's kind of... well... hurtful ==
Okay, I am kinda P.O.'d about that premise, since I've been privileged to know many of the best people. And I can say with some confidence that none were ever invited into such studies of alien tech. I know this, not just from my conversations with them. But also because, in fact, such programs leave major ripples. Like big, noticeable gaps in their professional lives. Like all the subscriptions to ASTOUNDING Magazine that suddenly shifted to PO boxes near Los Alamos, New Mexico, in 1942. Or take the charter jets that right now commute daily with expert workers from Las Vegas homes to Area 51 and back again to be with their families. Those charters were sniffed-out easily, along with supply convoys.
(Okay, sure, Area 51 exists! And it's secret and has a few mystery planes. Duh? Again, that much is normal human brilliance and understandable military secrecy... and none of it has got us anything better in space than the silly Artemis moondoggle, aimed at making a few more ritual footprints on a plain of poison dust.)
Oh, one can offer hypothetical counters to all of the above. Is it possible that much smaller teams might work on alien stuff? Or that some truly super-uber-techs have come out of such studies and even my "best minds" acquaintances might know nothing about it?
Maybe our anti-gravity ships have already colonized Europa. Heck, in STARGATE the USA has defeated several alien empires and is now leader of an entire Galactic coalition... not Earth, but the United States of America... and still they don't tell the taxpayers. Okaaaaaay...
(BTW I loved Stargate.)
Sure. I've even written sci fi stories that explored such notions, Secret colonies n' such. Fun stuff. But...
...but eighty years? After 80 years no one has blabbed or disclosed?*
== Contempt for your fellow citizens is endemic ==
Oh, you say that some folks have already testified? With what evidence? Third hand rumors or unvetted 'things I saw'? Or 'an old man once told me' or else 'I saw a document once!!!!'
And Occam's Razor doesn't suggest to you that these are likely publicity-seeking 4th-raters who never, ever, ever offer anything like plausible evidence? And true insiders would have plenty by now! At risk of belaboring the obvious, let me repeat; there would have been hundreds, thousands of them by now, across an entire human lifespan.
What, you think some leather-skinned, retired engineer in his 90s, tooling around Arizona with a shotgun behind the seat of his pickup truck, is worried about a Non-Disclosure Agreement?
Gawd you don't know these guys. I do. At least enough of them to choke back an urge to spit over how you insult them.
== The Big Question ==
Oh, but now we get to the question of WHY?
Why go to such lengths, committing crimes tantamount to kidnapping, murder and treason, possibly meriting life sentences or death, all in order to prevent public ... disclosure?
Why? Steven Spielberg spends a lot of time on this one:
1) The former nun girlfriend (and is everyone in the film Catholic?) claims that a public that learns about tech-advanced-but mortal aliens will suddenly forsake God.
Say... what? How the heck does that even scan? Sure Moctezuma thought Cortez might be a god, but even so, the Aztecs fought. And doubly so when they first saw a Spaniard bleed. Anyway, I think most modern folks could tell a 'tech-advanced-but-mortal alien' from the Creator of the universe.
(BTW I liked Spielberg having her clench the crucifix in her hand, creating a palm stigmata, enabling her to escape from mind control via the salvation of holy pain. With Colin Firth as either Herod or Pontius Pilate. Yum.)
2) Yes, Steven S. trots out the hoary old "public panic" excuse. Everyone will go mad!! Riots in the street. Cats and dogs, living together... Like the silly secrecy-justification of those deliberately-loopy MEN IN BLACK?
At least Spielberg has the good sense and decency not to belabor this one, since his entire career was built by hundreds of millions of people paying to watch him poke at these very notions... with none of his audience ever running, screaming from the theater, as in The Blob.
3) But might disclosure destabilize a world teetering at the edge of nuclear war? Oooookay. The whole DEFCON 3 thing seems kinda contrived for the sake of the show. And it doesn't explain non-disclosure way back during the relatively calm world of the 1990s. And... um... isn't this exactly what the USA would reveal, in order to distract from a parochially silly tiff among earthlings?
(And isn't the present UFO Disclosure Fetish really just a case of 'X-files to distract from Eps-Files'?)
By the end of the film, we are left with no plausible WHY at all! Other than Hugh (Coleman Domingo) diagnosing that Noah Scanlon (Colin Firth) is doing it all because of his own psychological pain. And... um... Hugh could not have simply taken that diagnosis over Noah's head?
== A final note on why? ==
In fact, I can think of a couple of reasons that might - conceivably - justify secrecy! Why such a major endeavor by those who study UFOs might be worth hiding from the public.
My novella "Senses, Three and Six” is all about one such scenario. And no, it's not the hoary cliché of “avoiding public panic.” The notion is actually rather interesting, I reckon! (Hey Steven S., want a good premise for this topic? One that's never been dramatized and is far, far more plausible?)
Indeed, as I show in that story, there are conceivable (if unlikely) reasons why tens of thousands of our best minds might choose not to do the human thing and blab! Let's suppose it's something so compellingly dangerous that almost any sensible person who learns of it would agree it's better not to tell?
"Okay, as an American, my reflex is to disclose and share. But that's a damn good reason to quash it. For now."
Let's say there has been a Manhattan Project about aliens, and that all of the thousands of top folks studying this crisis actually agreed - against their every inclination - to keep it under wraps for a truly dire reason. A conspiratorial campaign of silence that has encompassed all party lines and many generations of our very best people for 80 years. As I've shown, it would have to be a damn good reason!
Mull this over. Suppose for a moment that such a reason existed. Why even leather-skinned 90-year-old engineer-retirees would keep their gums tightly sealed.
In which case then, um... can any of you pause your sanctimony long enough to please think it through?
If so, then who the hell are you to demand they break that massively consensus judgement by thousands of top minds who know vastly more about this than you do? When extorting revelation now might endanger all of humanity?
I'm not saying this ranks high on any list of plausibles! Indeed, perhaps you have a mature and well-considered answer to that question. Go ahead and put yours into comments!
Hell, I could argue both sides all day... which is probably why - despite my peerless qualifications - I haven't been invited into the cabal! (Or... so I claim ;-)
But damn. What's utterly discrediting is that - amid their righteous sanctimony snits - none of these UFO zealots ever, ever pauses to consider it.
== Many silly (and some disturbing) things ==
Recall from the beginning, my teaser question about Disclosure Day? That question of who is the villain? You who have watched the flick likely think it's trivially easy to answer.
It isn't. Not at all.
But first, let's deal with some quibbles.
Like all the magicalpowers displayed by the protagonists. Reading minds and speaking in math (without ever doing anything with that power, other than a little criminal hacking.) Gee thanks, alien guys. Gifts that never help in their lives or those around them, except when it serves the interests of those mind programmers.
Oh. Here's one! Did Kellner (Josh O'Conner) twirl the wheat himself, with some psychic power? Or did the aliens do it, while watching him from above? The latter seems likely, in this scene and many others. In which case, um, why did they always help just enough, so the heroes could leap from one sudden escape to the next barely-survived moment? Good movie action! Buthow about a little help to fly their car over the train, like Elliot did with ET in his bike basket?
(Nah, I won't actually bitch about a great action scene. Loved the train bit! But it only works logically if the Visitors aren't monitoring... which they clearly are. Yet they never interfere in Noah's mind scans.)
Want another implausible? How about a cheap motel that has fluffy bathrobes? In what universe? Well, I can't blame Mr. Spielberg for only staying at ritzy places.
How about a mega implausibility? That we would torture-interrogate members of a super advanced starfaring race, rather than try to curry their favor, like good natives? Treating them as honored guests and offering any asked-help to get them home, in hope we might get some nice beads and trinkets, in return? Like fusion power or an Encyclopedia Galactica?
Anyway, if aliens can make birds fly into apartments to trigger the release of deep-embedded secret powers, are they truly unable to decipher our language from broadcasts and simply talk to us? They can teach an 8 year old child telepathy (then hide it - traumatically - in her brain) and another child super-math-language (that does him no good at all). So is it way beyond them to hack into the Internet to say:
"Hi everyone on primitive Earth? Sorry about all the anal probes and ruined wheat and drunken-buzzing your cities and smashed-up radioactive ship debris and memory wipes and such.
"But now can we ask that you release our crash survivors? We'll send a space uber for themhimherit tomorrow in the middle of Central Park. And yes, we'll answer questions then, the way we should have, for eighty...
"...no, make that several thousand years, when we could have opened a small, community college, taught you printing and glass lenses and democracy and the germ theory of disease and thus spared you many millennia of grueling pain. Again, sorry about that. And here are your reparations."
== Yet again, the same finger-wagging... ==
Instead we get a familiar, hackneyed cliché over and over again! Like smug, chiding Klaatu, in The Day The Earth Stood Still, threatening and guilt tripping Earthlings instead of explaining why his folk let us stew in filth and ignorance for ages? From COCOON to 2001 to CONTACT, to PAUL, always patronizing and never any plausible excuse for doing nothing for us, across all those dark ages of grinding human misery.
Oh, there are some plausible excuses! That I have never seen even once in sci fi cinema.
Don't talk to me about Non-Interference Directives! Then why did you kidnap and experiment on so many of us, going back to faerie encounters in medieval times? (You think I'll let fetishists claim it started at Roswell?) Or else, in DISCLOSURE DAY, snatching and traumatizing two little children, back in the 90s?
Even in the very best films about contact... like CONTACT or CLOSE ENCOUNTERS... aliens seem to call mysteriousness their most-noble trait. It's a plot element we saw in the excellent Ted Chiang novella and resulting movie ARRIVAL, all the way to Stanislaw Lem's obsessively cryptic SOLARIS. We meet strange, hyper-advanced beings... whereupon the heavy lifting of translating languages and overcoming misunderstandings is entirely up to us! Never, ever the mysterious sky-god meddlers, themselves.
And yes, UFO-zealots never seem to grok that saucer-beings should be judged -- first and foremost -- according to their behavior!
Which... of course... brings us to...
== The true villain is... ==
Well, I've said it elsewhere and for 40 years. There is only one villain in the entire movie E.T. The Extraterrestrial. And that villain is not the big bad government, or the guy with the keys... nor is it the hapless agronomist ET, itself.
The villain in that early Spielberg masterpiece is blatantly the captain of ET's ship.
An SOB who abandons a crewmate in an alien forest when they are threatened by... flashlights and clipboards! The only implements in sight when KeysGuy hurries to the landing site. No guns. No threat except curiosity.
A captain who departs swiftly to avoid contact, when such a meeting might be just the thing to save us.
A captain who ET must phone home in order to summon his ride back, when the bastard captain knows within two blocks where he abandoned the guy!
Elliot does everything wrong, though for loving reasons. If he handed over ET like a good citizen (as I portray in my YA SF novel Colony High), those doctors who struggled to save ET in the film would say: "No, no, you can't have Reeces Pieces. We can tell they are poisoning you. And you want to phone home? Fine, We'll use the Goldstone radio telescope."
And when the ship finally returns to collect ET: "That'll be six weeks rent. One Encyclopedia Galactica please... you evil, betraying, selfish asshole."
-------------------
Let's be clear. I ADORED THAT FLICK! It's about love and loyalty and courage and friendship. And none of the captain's crimes are poor ET's fault. Or Eliot's. Nor... (my main point) ... are they ours. I'm simply asserting that the movie did have a villain. And once you know to look... it's obvious.
-------------------
And yes, at least Steven Spielberg* is consistent! Because the true villains in DISCLOSURE DAY are the same. The very same. Space jerks who have been teasing us and zipping around, messing with our heads (and our wheat.) Refusing our entreaties for contact. (I have been involved in SETI for 40 years and have used various means and media in legit attempts to lure honest communication. Hey Steven S., want a good idea or two?)
Space jerks who kidnap Navy pilots and children (as in CLOSE ENCOUNTERS) and twirl wheat and anal-probe farmers (as in SIGNS and INDEPENDENCE DAY) or steal our planetary genetic stock (as in E.T.) or precious bodily fluids...
...okay, I'm getting carried away. Blame the aliens who still talk to me via the fillings in one molar. Mercury silver amalgam makes a great antenna! Though now it's the AIs who are apparently using that tooth. Does that mean they overlap? Extraterrestrials and artificial intelligences? Duh? Hence the title of my latest book: AIlien Minds.
But no, Let's make it explicit.
Colin Firth may portray a villain in DISCLOSURE DAY. But the macro villains are Steven Spielberg's aliens. Flitting about in super ships, teasing us endlessly, pulling aerial stunts, till a few of those buzzing and harassing ships drunkenly crashed. And even then abandoning their crewmates rather than reclaim them by the simple means of stepping out, in the clean sunshine and talking to us?
Oh, indeed, they do have plenty to fear from disclosure! As I point out in EXISTENCE, this kind of behavior that's been bruited by UFO zealots for nearly a century... and by faerie-believers for thousands of years... is exactly the sort of thing that any advanced civilization would label as crime!
And hence, here's a plausible theory! Why their frenetic secrecy? Why their refusal to disclose?
What they fear may be that we'll call the galactic cops on them! (I have actually done that, over the airwaves.) Or else some interstellar law firm, to sue and/or prosecute these. nasty, silvery pervs.
== All that's left is some zipping balls of plasma?
Oh, I could go on. And on. And I have about this mountain of piled up absurdities.
As I've said, my skepticism is is not from stodgy lack of imagination. I assert that few living humans have approached the topic of the “alien’ from more angles than I have, from SETI and astrophysics and biology and psychology and history to many dozens of science fiction scenarios, some of them even plausible! So, I ain't claiming we are alone-alone,
In fact, what I find most offensive is how every touted 'ufo' scenario is so damned clichéd and boring.
Take the most-recent purported 'sightings.' In past decades, nearly all (including Roswell) were disproved or debunked, or else cases where 'aliens' remained the least likely hypothesis... all of which has been eagerly ignored by zealots. Only now?
Now there are ten million times as many active cameras on Earth's surface as in the 1950s, so why do the 'images' keep getting ever-fuzzier?
Now, instead of lovely pie tins or frisbees, they're glowing dots, zipping back and forth in mid-air! Mick West has shown that a majority were likely camera-perspective illusions. But as for the rest?
Has it occurred to you to look closely and see if they are translucent? With light passing through them from the other side? It seems that one Navy missile shot right through one of the zipping balls, causing it to joggle a little. Suggesting they might be just glowing globs of plasma, careening about. Impressive, but violating no known physical laws.
I go into them elsewhere, So here I'll just say that with $6M and 6 months *I* will make glowing dots zip near airplanes, just like recent 'sightings.' Indeed, a parsimonious explanation for the latest 'phenomena' may be found on nearby ships... ocean going boats with hulls and propellers, down below. Turn some of the cameras to view vessels down amid the waves, where human jerks are likely using simple beam methods to make dots and balls rove about the sky, in order to tease and mess with gullible folks.
In other words, using the equivalent of a cat laser!
And those Navy pilots... and you dears... are the pussycats.
== Where we might actually find aliens! ==
In my novel EXISTENCE, I talk about what may be the nearest and most likely place to actually and really contact 'aliens.' Our children may (if we restore a confident and scientific civilization from current lobotomization*) get out to the Asteroid Belt, where they truly could find, amid the tumbling rocks, remnant interstellar probes...
...robots that arrived in our solar system across millions of years. Perhaps with a variety of missions and goals that I discuss in that novel. Maybe mostly wrecks or ruins by now, but maybe some still functioning. And even aware of us, from our broadcasts or Internet.
There'd be a lot of implications! And yes, some dangers. (And some fun/tense confrontation scenes in EXISTENCE.)
But the lurker scenario is so much more plausible in every way than pervert anal-probers and kidnapping hyp-mo-tizers going "Oooga-booga!" at us down here, earning both our contempt by their behavior and - yes - maybe a nice, well-deserved, missile up their nasty silver butts.
== Your homework assignment ==
Enough. It's not my mission to quash your sense of wonder, but to expand it. From the sorts of faerie-kidnapping myths that made our ancestors shiver in feudal superstition (slightly updated to be 'spaceships' or time travelers or interdimensional wizards) toward other possibilities, much more plausible, that may await us out there.
What I can tell you is this. (And it doesn't come from that filling in my tooth!) It's that you are better than this.
We can restore this civilization to one of wonder and equality and justice and common sense and science and dazzling imagery. That quest is now mostly political, and I believe we can do it!
But it will also be about making better demands from our art
======
======
* Again. Deep respects for Steven Spielberg! We would be culturally and artistically poorer without him! But pointing out stuff is what I do. It's my job.
* What better explanation for the world - especially America - growing ever-more hysterically irrational in recent years, than some kind of alien lobotomizing ray? It'd certainly be consistent with what we're seeing: millions of citizens in a great and scientific and logical nation abruptly turning their backs on all that, waging open war against its smartest people.
Why lobotomize us? Perhaps to slow us down? Or to institute Idiocracy, or a return to the feudalism that was always controlled by priests serving meddler gods? Or else to keep us serving them as entertainment? For the galaxy-wide hit reality show Oh, Those Humans!
And yes, it's one more reason to gird ourselves. Put out that call for space lawyers, invent AIs to fight back for us! And eventually teach the bastards - both human and alien - a badly needed lesson.
In a post to oss-security, my (Debian) co-developer Russ Allbery
stated that "open source software [OSS] is coming face to face with a
motivation crisis that has been building for a long time". His point
is essentially that large language models (LLMs1) are making the
existing OSS community crisis worse. For him, it's the flood of code
reviews, but he argues that varies according to people's desires, for
others it's security issues and so on.
I think Russ is right, but I would argue there's something much bigger
than our open communities going on here, and it's about the entire
field of computing. This pressure is on all of us, regardless of
whether we work on open source software or not.
How people use models
People using LLMs in their workflow have radically changed how
programming works, even for people who claim to avoid
vibe-coding. And I'm sorry to single out one poor maintainer here:
it's not you, Brian, you're just one example among many. But this is
typical use of those models nowadays:
Once it’s done, I’ll use /code-review and let Claude spawn
sub-agents to do a full review of the new code. This usually finds
some problems, even problems that the “main” Claude instance didn’t
find during its validation. I usually keep running /code-review
again and again after finding and fixing issues, until there aren’t
any left.
Think about what that means for a minute. This is automation built to
fire up dozens of agents crunching at a problem for minutes if not
hours of GPU compute time, in parallel. This is essentially a couple
of shelves in a datacenter rack, totally maxed out on power and
cooling, abstracted behind a cute little /code-review command.
The author, here, is rightly concerned that "Anthropic could pull the
rug out and require API pricing", which is perhaps a code word for
"charging something closer to actual costs". Brian also pays lip
service to environmental and societal costs but those are largely
abstracted away, so let's keep that conversation aside here as well,
as we have discussed it before anyways.
But clearly, this way of working has an (externalized) cost, to
say the least.
Paying for non-free tools
For decades my work has been focused on free and open source
software. I've long stopped using proprietary operating systems like
Windows or Mac, and even before that switch, I was mostly using free
software on those platforms, partly out of principle, but also because
I was too poor. So the tools of my trade are free, and I build free
tools with them.
It feels like we're going backwards: when I was in school, a millennia
ago, my classmates didn't have access to a compiler and were wondering
how they would scrape the money to buy a compiler like Borland's
or Microsoft's. I had a compiler built into my operating system
(FreeBSD at the time), so that wasn't a problem for me. For them,
it was a significant expense, but at least those expenses (or more
shady sourcing of programs) were a one-shot deal.
Fast forward 30 years, and software is rented: you pay monthly for
Adobe's Photoshop and Microsoft's office suite just like you pay for
Netflix, Disney+ or Spotify2. And now you need to add dozens (if not
hundreds of dollars) of monthly credits to access LLMs on top of that.
So, now we have to pay to get anything done? This is peak
enshitification of our job: first they steal our work to train their
models, and then they sell it back to us at a profit.
Attacking the engineers
AI is coming for our jobs, as engineers, if not everyone, according
to the narrative. For a while now, our job market has deteriorated:
less jobs, for less pay. Lots of skilled engineers looking for work
and finding crap jobs then still looking while working.
This is not by accident.3 We engineers have a lot of power, it is not
organized, but that's just a couple of unions away (easy!). Tech
overlords know this, so they are attacking our profession, directly,
by forcing us to train and use models that they can control.
Even in environments where programmers are not forced to use LLMs,
the mere pressure of other people's LLM-generated work is huge. One can
be forced to review LLM outputs, or just peer pressured you into
producing more.
We're now supposed to accelerate delivery, because models can
presumably do things so much better and faster. With supply chain
security becoming such a large vector that we now have worms crawling
around developers accounts on NPM, increasing the delivery cadence
seems like a really bad idea.4
The LLM hype is part of the larger wave of cyberwar against workers,
against water, against the Earth, against all the people. This is not
a matter of individually "adapting to the reality" or personal choice,
but a political, social, hard problem we need to address collectively.
I again prefer the term LLM to "AI" because models do not
possess intelligence. I did use it in the title because
click baiting is apparently important, but I stopped short of
calling this one "Rage Against the Machines" because that would be
the title of every blog post I have ever made.↩
Yes, I know that Visual Studio is kind of free now, but I
wouldn't be surprised if they turn that into a rental as well,
because why not.↩
Beyond sabotaging the job market, Sam Altman event wants to
sell "intelligence as a utility" something that is just a
really bad idea but especially shows how megalomaniac those
people are.↩
This brings back memories of another era, walking us
back decades in terms of computer security.↩
Matlab is special. Scientists and researchers love it. Programmers hate it, and not just because it uses 1-based arrays. I've worked on a number of projects where the task was "take this Matlab code and convert it to C so we can run it on an embedded CPU". Somehow, in that process, I've avoided learning much about Matlab.
Andre works on a team that uses Matlab to manage experimental scenarios. They wanted to do a simple task: generate a set of participant-specific images, store them in a database, and reference them later. Somewhere in the intersection of the database product they were using, the Matlab license they had, and other constraints, they discovered that there simply was no good way to do this.
Enter "Jude". Jude said, "Don't worry about it, I can hack something together."
I present the code in its entirety, but don't ask me to explain it. Instead, read the comments.
nMk = 1;%counting non-response triggers, this cycles with each trial
nPress = 0;%counting button presses, noting the position in the logfor v = 1:height(resVmrk)%read each triggerswitch nMk
%it's kinda roundabout, but the only recognisable part is the response%yet I refer to it only by elision%and instead count the stimuli to reconstruct the patterncase1%an almost reliable stimulus
nPress = nPress+1;%trial startif strcmp(resVmrk.TriggerCode{v},'S1')%it must be a non-response
resVmrk.TriggerCode{v} = 'cross';%name it properly
nMk = 2;%and expect the next oneelse%except when it is not
resLog.miss(nPress) = 1;%then note it down as missed
nMk = 0;%and skip to responseendcase2%usually reliableif strcmp(resVmrk.TriggerCode{v},'S1')%if the face loaded successfully
resVmrk.TriggerCode{v} = 'face';%note it
nMk = 3;%and proceed accordinglyif nPress<=height(resLog)%trailing triggers at the end should be ignored
resLog.facePos(nPress) = v;%note the positionendelse%if it failed to load it is a response
resVmrk.Dur(v-1:v+1) = 0;%mark the whole trial for deletion
resLog.miss(nPress) = 1;%and note it down as missing the face
nMk = 0;%and skip to responseendcase3%this one is not reliable, and sometimes is duplicated instead of missingif strcmp(resVmrk.TriggerCode{v},'S1')%if it is present at all
resVmrk.TriggerCode{v} = 'empty';%first name itif v<height(resVmrk)%if it is not a trailing trigger, since it'll break the check otherwiseif ~strcmp(resVmrk.TriggerCode{v+1},'S1')%if the next trigger is a response
nMk = 0;%all is fine and it didn't freak out, proceed to responseelse%otherwise
nMk = 3;%just treat as a double%and then count how many excess triggers are actually here
nExcess = 1;%definitely one here alreadywhile strcmp(resVmrk.TriggerCode{v+nExcess+1},'S1')
nExcess = nExcess+1;%and everything until the responseend
resVmrk.Dur(v-2:v+nExcess+2) = 0;%then mark the whole trial for deletion%this overwrites the same positions several time, but the important part is to get the preceding two, because I don't know which one of them is correct one, so I delete the whole trialif nPress<=height(resLog)
resLog.bad(nPress) = 1;%also note it down as borkedendendendelse
nMk = 0;%if it didn't happen at all simply proceed to responseendcase0%this one reliably follows the response, so I address the response by elisionif strcmp(resVmrk.TriggerCode{v},'S1')%skip response itself
resVmrk.TriggerCode{v} = 'blink';%note the only reliable non-response (always following the response)
nMk = 1;%start the trial anewif nPress<=height(resLog)%if it is not a trailing trigger
resLog.respPos(nPress) = v-1;%note down the response positionif resLog.miss(nPress)==1%and if it's a response without a stimulus
resVmrk.Dur(v-1:v) = 0;%mark it for deletion as wellendendendendend
Ah, the classic "for-case" antipattern. That's gross enough, but what the heck is happening inside each of those cases?
My personal favorite comment is this one: "%this overwrites the same positions several time, but the important part is to get the preceding two, because I don't know which one of them is correct one, so I delete the whole trial"
Now, you may suspect comments like "usually reliable" are about what we see in the dataset, but I'm not so certain. Andre writes:
After reverting the last discovered way for his creation to corrupt the data I was able to figure out that 20% of the logs provided corresponded to different (unknown) experiments altogether.
[Advertisement]
Keep the plebs out of prod. Restrict NuGet feed privileges with ProGet. Learn more.
Author: Alzo David-West A ship moved on the ocean. The vessel was big, and its sides were covered in salt. Young people were all over the deck, wearing fitted t-shirts and short shorts. Warm air blew gently. Some of the passengers leaned against the railings as others rested in deckchairs. Music played, and the ship […]
Linux v7.2 was released on Sunday,
August 16th, with the Linux v7.3 merge window opening immediately afterwards.
Below are the highlights of the
LSM,
SELinux, and
audit
pull requests which have been merged into Linus’ tree.
LSM
Removed the task_euid() function and its Rust counterpart. The function
returned the objective effective UID of a task, which is an odd thing to need,
and with the only user in the kernel now gone, it made little sense to
keep the API.
Corrected the kdoc
documentation for the security_task_prctl() LSM hook.
Clarified the comments in the Rust task UID accessor code.
SELinux
In order to be a good neighbor in the kernel, and promote more efficient use
of memory, we converted some old code that used the __get_free_page()
function to use kmalloc() instead.
With the recent
removal of DCCP support in the kernel
there are some userspace tools which still try to configure and query the
kernel about DCCP support. Unfortunately, these tools can generate a number of
SELinux “unrecognized netlink message” errors as SELinux’s DCCP support has
been removed. Starting with Linux v7.3 we will now only print a single error
message on the first occurrence, and the error message will indicate that the
message is unrecognized due to the removal of DCCP from the Linux kernel.
In order to support the effort to remove strlcat() from the kernel, we
converted the strlcat() calls in the SELinux IMA measurement code to use
the sequential buffer, e.g. seq_buf_printf(), APIs.
Improved the SELinux IMA measurement code by only calculating the size of
the measurement string once at boot. Previously the string length was
recalculated on every measurement.
Added additional SELinux policy load time verifications to help ensure that
only properly formed policies are loaded.
A number of minor code cleanups and improvements.
Audit
Fixed a reference counting problem involving audit file watches that could
result in unintentionally dropping the last reference while the watch was
still active.
So, the second novel in the Laundry Files, The Jennifer Morgue, was first published on November 1st, 2006. And while it was superficially a pastiche of the Bond movie canon (as it existed at that time--I was writing before the Daniel Craig era, ushered in with Casino Royale--it was also interrogating the dramatic conventions of the genre and also the implications of rule by Bond Villains.
At about the time I was writing it, a friend of mine (initially a tech journalist, later an industry pundit) described his experience of interviewing Elon Musk, who was allegedly leaning hard into the archetype. "I must be a Bond villain!" He joked, "I have an electric car and a tropical island where boiler-suited minions launch rockets!" And then he laughed it off. (In those days, we thought it was a simile: these days it's more clearly understood as a metaphor, if not the absolute raw truth.)
Anyway, I wrote a little afterword for The Jennifer Morgue discussing the significance of the Bond Villain as an archetype for our times and it does still appear to have something relevant to say, 20 years later; and I figure the current publisher has forgotten about it, so I'm going to shamelessly pirate my own work and reprint the entire epilogue from The Jennifer Morgue right here on my blog (the horror!).
Note that the Great Financial Crisis that kicked off the current era really started in late 2007, and our current era of oligarchic misrule, only got underway in the mid-20-teens, with the evitable rise to power of a deeply unpleasant TV reality star whose main claim to fame was playing a stupid man's idea of a successful business mogul.
(At least I didn't predict that.)
Anyway, the text is below the fold--it's quite long--and I ask this: what would you add, today?
The Golden Age of Spying
1. The Mary-Sue of MI6
"My name is Bond. James Bond."
These six words, heard by hundreds of millions of people, are almost invariably spoken during the first five minutes of each movie in one of the biggest media success stories of the 20th century. Unless you've lived under a rock for the past forty years, you hear them and you know at once that you're about to be plunged into a two hour long adrenaline saturated extravaganza of snobbish fashionable excess, violence, sex, car chases, more violence, and Blowing Shit Up -- followed by a post-coital cigarette and a light-hearted quip as the credits roll.
It wasn't always so. When "Casino Royale" was first published in 1953, it got a print run of 4750 hardcover copies and no advertising budget to speak of; while the initial reviews were favorable, comparing Ian Fleming to Le Queux and Oppenheim (the kings of the pre-war British spy thriller genre), it took a long time for his most famous creation to set the world on fire. Despite his rapidly rising print runs ("Casino Royale" eventually sold over a million paperbacks in the UK alone), and despite his increasing prominence among the post-war thriller writers, a decade elapsed before any of Fleming's novels were filmed; indeed, their author barely lived to see the commercial release of "Dr No" and the runaway success of the icon he created. (Nor were the films seen as a runaway success before they were made -- "Dr No" was notoriously made on a tight budget, even though it went on to gross nearly $60M around the world.)
Literary immortality -- or indeed, mere post-mortem survival -- is dauntingly hard for a novelist to achieve. The limbo of post-mortem obscurity awaits 95% of all novelists -- almost all novels go out of print for good within five years of the death of their author. But in addition to being a million-selling best-seller, Fleming was a ferociously well-connected newspaper executive with a strong sense of the value of his ideas, and he pursued television and film adaptation remorselessly. Cinematic success arrived just in time for his creation, and the synergy between best-selling books and massive movie hype has sufficed to keep them in print ever since.
James Bond is a creature of fantasy, perhaps best described using a literary term looted from that most curious and least respected of fields, fan fiction: the Mary-Sue. A Mary-Sue character is a placeholder in a script, a hollow cardboard cut-out into whose outline the author can squeeze their own dreams and fantasies. In the case of Bond, it's cruelly easy to make a case that the famous spy was his author's Mary-Sue: for Fleming had a curious and ambiguous relationship with spying.
A dilettante and dabbler for his first three decades, unsuccessful as a stockbroker, foreign correspondent, and banker, Fleming fortuitously landed his dream job on the eve of the Second World War: Secretary to the Director of Naval Intelligence in the Admiralty. The war was good for Ian Fleming, broadening and deepening him and giving him a job that captured his imagination and drew out his not inconsiderable talents. But Fleming was the man who knew too much: privy to too many secrets, he was wrapped in tissue paper and prevented from pursuing his desire to go into the field. He ended the war with a distinguished record -- and absolutely no combat experience (if one excludes being bombed by the Luftwaffe or watching the Dieppe raid from a destroyer, safely far off the Normandy coastline). Fleming grew up in the shade of a father who died heroically on the western front in 1917, and in adult life he wrote in the shadow of an elder brother whose reputation as a novelist surpassed his own. It's easy to imagine these unkind familial comparisons provoking the imaginative but flighty playboy who almost found himself during the war, goading him to imagine himself in the shoes of a hero who was not merely larger than life, but larger in every way than his own life.
And, as it turns out, James Bond was larger than Ian Fleming. Not only do few novels survive their author's demise, even fewer acquire sequels written by other hands; yet several other authors (including Kingsley Amis and John Gardner) have toiled in Fleming's vinyard. Few fictional characters acquire biographies written by third parties -- but Bond has not only acquired an autobiography (courtesy of biographer John Pearson) but spawned a small cultural industry, including a study of his semiotics by Umberto Eco. Now, that has got to be a sign of something ...
As with every true pearl, there was a sand-grain of truth at the heart of Bond. Fleming wrote thrillers informed by his actual experience. Years spent working out of the hothouse environment of Room 39 of the Admiralty building -- headquarters of the Naval Intelligence Division of the Royal Navy -- gave him a ringside seat on the operations of a major espionage organization. On various trips to Washington DC he worked with diplomats and officers of the OSS (predecessor organization to the CIA). As a foreign news manager at The Sunday Times after the war, there is some evidence that Fleming made his agency's facilities available to officers of MI6. His first Bond novels were submitted to that agency for security clearance before they were published. Bond himself may have been larger than life, but the strictures imposed by the organization he worked for were drawn from reality, albeit the reality of an intelligence agency of the early 1940s.
The world of secret intelligence gathering during the second world war was, however, very different from life in the intelligence community today. It was already changing by the late 1950s, as the bleeping football-shaped Sputniks zipped by overhead and intelligence directors began dreaming of spy satellites. By 2004, when MI5 (the counter-intelligence agency) openly placed recruiting advertisements in the press, we can be sure that Bond would be best advised to seek employment elsewhere. Spies are supposed to be short -- under 180 centimeters for men -- and nondescript. As a branch of the civil service, MI5's headquarters are presumably non-smoking, and drinking on the job is frowned upon. As intelligence agencies, MI5 and MI6 staff aren't in the business of ruthlessly wiping out enemies of the state: any decision to use lethal force lies with the Foreign Secretary, the COBRA committee, and other elements of the British government's security oversight bureaucracy. An MI6 agent driving a 1933 Bentley racer with a supercharged engine, frequenting the high-stakes table at a casino as James Bond so memorably did in his first print appearance, is an almost perfect inversion of the real picture.
Nevertheless, the archetype has legs. James Bond continued to grow and evolve, even after his creator put away his cigarette holder for the last time. To some extent, this was the product of storytelling expediency. The film adaptations started in the middle of a continuing story arc -- for Fleming wrote his novels with a modicum of continuity -- and while "Dr No" was the first to make it to celluloid, the novel was in fact a sequel to "From Russia With Love" (which was filmed second). Thus, various liberties were taken with the plot of the canonical novels, right from the start. You can re-read the novels at length without finding anything of the banter between Bond and M's secretary Moneypenny that is a recurrent theme of the films, for example, and that's before we get into the bizarre deviations of the mid-period Roger Moore movies (notably "The Spy Who Loved Me" and "Moonraker").
The literary James Bond is a creature of pre-war London clubland: upper-crust, snobbish, manipulative and cruel in his relationships with women, with a thinly-veiled sadomasochistic streak and a coldly ruthless attitude to his opponents which verges on the psychopathic. Over the years, his cinematic alter ego has acquired the stamina of Superman, learned to defy the laws of physics, ventured into space -- both outer and inner -- and deflowered more maids than Don Juan. He's also mutated to fit the prejudices and neuroses of the day, dabbling with (gasp!) monogamy, and hanging out with those heroic Afghan mujahideen in the late-eighties AIDS-and-Soviets-era "The Living Daylights". He's worked under a post-feminist ball-breaking 'M' in "Goldeneye", and even confronted a female arch-villain in "The World is Not Enough" (an innovation that would surely have Fleming, who formed his views on appropriate behavior for the fairer sex in the 1920s, rolling in his grave). But other aspects of the Bond archetype remain timeless. Fleming was fascinated by fast cars, exotic locations, and intricate gadgetry, and all of these traits of the original novels have been amplified and extrapolated in the age of modern special effects.
Just how does James Bond -- a "sexist, misogynist dinosaur, a relic of the Cold War", to use the words the script-writers on "GoldenEye" so tellingly put into M's mouth -- survive in the popular imagination more than fifty years after his literary birth? What does it mean when Mary-Sue stalks the landscape of the imagination, blasting holes in the plot with a Walther PPK (or the P99 he upgraded to in "Tomorrow Never Dies")? If we're going to understand this, perhaps we ought to start by looking at Bond's dark shadow, the Villain.
2. In search of Mabuse
Bond is, if you judge him by his work, a nasty fellow and not one you'd choose to lend your car to: to make this rough diamond glitter it is necessary to display him against a velvet backdrop of darkest villainy. If you strip the Bond archetype of the bacchanalia, glamorous locations, and fashion snobbery, you end up with an unappetizingly shallow, cold-blooded executioner -- the likes of Adam Hall's Quiller or James Mitchell's Callan, only without the breezy cynicism, or indeed any redeeming features at all. The role of adversary is thus a critical one in sustaining the appeal of the protagonist. Fleming set out to depict a hard-edged contemporary world where the usual black-and-white picture of the pre-war thriller had blurred and taken on some of the murky grey-on-grey ambiguity of the cold war era; Bond was the knight in shining armor, fighting for virtue and the free world against the dragon -- be they Mr. Big, Dr. No, Auric Goldfinger, or the looming shadow of Bond's greatest enemy of all, Ernst Stavro Blofeld, Number One of SPECTRE, the Special Executive for Counter-intelligence, Terrorism, Revenge and Extortion.
It is interesting to note that Blofeld assumed his primacy as Bond's #1 enemy only in the movie canon; Fleming originally invented him while working on the screenplay and novel of "Thunderball", and used him subsequently in "On Her Majesty's Secret Service" and "You Only Live Twice". (Prior to these later books, Bond typically tussled with less corporate enemies -- Soviet stooges, unregenerate Nazis, and psychotic gangsters.) Blofeld was born out of mere corporate expediency. Rather than demonize the Soviets and reduce their potential audience, the producers of the film of "From Russia With Love" appropriated SPECTRE as the adversarial organization. With the success of "Thunderball", the third of the films, Blofeld moved front and center and acquired a life of his own that far exceeded his prominence in the novels. Arguably, Fleming's death in 1964 freed up the movie series to diverge from their original author's plans; and so Blofeld may be seen as a demon of necessity, conjured up from the vasty depths in order to provide Bond with a worthy adversary.
'Twas not always so. Back at the turn of the 20th century, around the time that the British spy thriller was gradually cohering out of the mists of the penny dreadful and the literature of suspense (via the works of John Buchan and Erskine Childers -- not to mention the tangential contributions of Arthur Conan Doyle, by way of Sherlock Holmes) there was no great dualistic vision of the great champion confronting the villainous heart of evil. There was no great champion: we were on our own against the masters of night and mist, the great and terrible super-criminals. Professor Moriarty, Holmes' nemesis -- the Napoleon of Crime -- was but one of these: Fantômas, the 1911 creation of Pierre Souvestre and Marcel Allain, is another. The emperor of crime, Fantômas was a master of disguise and an agent of chaos (not to mention standing astride Paris in black mask, top hat and tails, in the posters for the 1913 movie of the same name: an icon of decadent wealth and criminal chaos). Nor was he alone. Guy Boothby's 1890's super-villain Dr Nikola fits the bill too, right down to the fluffy lap-cat and the fiendish plans. But perhaps the root of Bond's nemesis can be found in his full-fledged form somewhat later, and somewhat further to the east -- in the guise of Dr. Mabuse.
Dr. Mabuse is an archetype and a runaway media success in his own right, famous from five novels and twelve movies. The Doctor was created in 1922 by author Norbert Jacques, and was developed into one of the most chilling creations of the silent era by no less a director than Fritz Lang. Mabuse is a name, but one that nobody in their right mind speaks aloud. He's a master of disguise, naturally: and a rich, well-connected socialite and gambler. (Some social context: gambling at the high stakes table is no so much an innocuous recreation as an obscenity, in a decade of hyper-inflation and starvation, with crippled war veterans dying of cold on the street corners, as was the case in Weimar Germany). Mabuse has his fingers in every pie, by way of a syndicate so shadowy and criminal that nobody knows its extent; he's a spider, but the web he weaves is so broad that it looks like the whole of reality to the flies trapped in it. He is (in some of the stories) a psychiatrist, skilled in manipulation, and those who hunt him are doomed to become his victims. If Mabuse has a weakness it is that his schemes are over-elaborate and tend to implode messily, usually when his most senior minions rebel, hopelessly late; nevertheless, he is a master of the escape plan, and with his ability to brainwash minions into playing his role he's a remarkably hard phantom to slay.
It is all too easy to make fun of the likes of Fantômas and Dr. Nikola, and even their modern-day cognates such as Dr. Mabuse and Ernst Stavro Blofeld; for do they not represent such an obsessively concentrated pinnacle of entrepreneurial criminality that, if they really existed, they would instantly be hunted down and arrested by INTERPOL?
Careful consideration will lead one to reconsider this hasty judgment. Criminology, the study of crime and its causes, has a fundamental weak spot: it studies that proportion of the criminal population who are stupid or unlucky enough to get caught. The perfect criminal, should he or she exist, would be the one who is never apprehended -- indeed, the one whose crimes may be huge but unnoticed, or indeed miscategorized as not crimes at all because they are so powerful they sway the law in their favor, or so clever they discover an immoral opportunity for criminal enterprise before the legislators notice it. Such forms of criminality may be indistinguishable, at a distance, from lawful business; the criminal a paragon of upper-class virtue, a face-man for Forbes.
When the real Napoleons of Crime walk among us today, they do so in the outwardly respectable guise of executives in business suits and thousand-dollar haircuts. The executives of Worldcom and Enron were denizens of a corporate culture so rapacious that any activity, however dubious, could be justified in the name of enhancing the bottom line. They have rightfully been charged, tried, and in some cases jailed for fraud, on a scale that would have been the envy of Mabuse, Blofeld, or their modern successor, Dr. Evil. When you need extra digits on your pocket calculator to compute the sums you are stealing, you're in the big league. Again, when you're able to evade prosecution by the simple expedient of appointing the state prosecutor and the judges -- because you're the President of a country (and not just any country, but a member of the rich and powerful G8) -- you're certainly not amenable to diagnosis and detection in the same sense as your run-of-the-mill shoplifter or petty delinquent. I'm naming no names (they have intelligence services! Cruise missiles!) but this isn't a hypothetical scenario.
3. Interview with the Entrepreneur
In an attempt to clarify the mythology surrounding James Bond, I tracked his old rival down to his headquarters in the Ministry of Inward Investment in the breakaway Republic of Transdniestria. Somewhat suspicious at first, Mr. Blofeld relaxed as soon as he realized I was not pursuing him on behalf of the FSB, CIA, or IMF, and kindly agreed to be interviewed for this book. Now aged 72, Blofeld is a cheerful veteran of numerous high-tech start-ups, and not a few multinationals where, as a specialist in international risk management and arbitrage, he applied his unique skills to business expansion. Today he is semi-retired but has agreed to work in an voluntary capacity as director of the State investment agency.
"It took me a long time to understand the agenda that the British government was pursuing through the covert activities of MI6," he told me over a glass of sweet tea. "Call me naive, but I really believed -- at least at first -- that they were honest capitalists, the scoundrels."
Over the course of an hour, Ernst explained to me how he first became aware that the UK was attempting to sabotage his business interests. "It was back in 1960 or thereabouts that they first tried to destroy one of my subsidiaries. Until then I hadn't really had anything to do with them, but I believe one of my rivals in the phosphate mining business put it about that my man on site was some sort of spy, and they sent this Bond fellow -- not just to arrest him or charge him with some trumped-up nonsense, but to kill him." His lips paled with indignation at he contemplated the iniquity of the situation: that agents of the British government might go after an honest businessman for no better reason than an unsubstantiated allegation that he was spying on American missile tests. "I warned Julius to be careful and advised him to put a good lawyer on retainer, but what good are lawyers when the people you're up against send hired killers? Julius brought in security contractors, but this Bond fellow still murdered him in the end. And the British government denies everything, to this day!"
Ernst obviously believes in his own moral rectitude, but I had to ask the obvious questions, just for the record.
"Yes, I was chief executive of SPECTRE for twelve years. But you know, SPECTRE was entirely honest about its activities! We had nothing to hide because what we were doing was actually legal. We've been mercilessly slandered by those rogues from MI6 and their friends in the newspapers, but the fact is, we're no more guilty of criminal activity than any other multinational today: we simply had the misfortune to be foreign and entrepreneurial at a point in time when Whitehall was in the grasp of the communist conspirators Wilson and Callaghan and their running-dog so-called 'conservative' fellow Heath. And we were pilloried because what we were doing was in direct competition with the inefficient state-run enterprises that my good friend Lady Thatcher recognized as mosquitoes battening on the life-blood of capitalism. That cad Fleming put it about that SPECTRE stands for 'Special Executive for Counterintelligence, Terrorism, Revenge and Extortion' -- absolute tosh and nonsense! Would a group of criminals really call themselves something that blatant? I'll remind you that SPECTRE is actually a French acronym, as befits a non-profit charity incorporated in Paris. The name stands for 'Société Professionelle et Ethique du Capital Technologique Réinvestissement par les Experts.' Venture capitalists specializing in disruptive new technologies, in other words -- commercial space travel, nuclear power, antibiotics. Not some kind of half-baked terrorist organization! But you can imagine the threat we posed to the inefficient state monopolies like the British Aircraft Corporation, the coal mining industry, and Imperial Chemical Industries."
Blofeld paused to sip his tea thoughtfully.
"We were ahead of our time in many ways. We pioneered business methods that later became mainstream -- Sir James Goldsmith, Ronald Perelman, James Icahn, they all watched us and learned -- but by then, the commies were out of power in the west thanks to our friends in the establishment, so they had an easier time of it. No need to hire lots of expensive security and build concrete bunkers on desert islands! And yes, that made us look bad, don't think I'm unaware of it -- but you know, you want bunkers and isolated jungle rocket launch bases? All you have to do is look at Arianespace! It's fine when the government bureaucracies do it, but if an honest businessman tries to build a space launch site and hires security to keep the press and saboteurs from foreign governments out, it's suddenly a threat to world security!"
He paused for a while. "They put the worst complexion on everything we did. The plastic surgery? Well, we had the clinic, why not let our staff use it, so the surgeons could stay in practice between paying customers? It was a perk, nothing more. We did -- I admit it -- acquire a few companies trading in exotic weapons, non-lethal technologies mostly. And that business with Emilio and the yacht, I admit that looked bad. But did you know, it originally belonged to Adnan Khashoggi or Fahd ibn Saud or someone? Emilio was acting entirely on his own initiative -- a loose cannon -- and as soon as I heard about the affair I terminated his employment."
I asked Ernst to tell me about Bond.
"Listen, this Bond chap, I want you to understand this: however he's painted in the mass media, the reality is that he's a communist stooge, an assassin. Look at the evidence. He works for the state -- a socialist state at that. He went to university and worked with those traitors Philby and Burgess, that MacLean fellow -- communist spies to a man. He didn't resign his commission when the British government went socialist, like a decent fellow: instead he took assignments to go after entrepreneurs who were a threat to the interests of this socialist government, and he rubbed them out like a Mafia button man. There was no due process of law there, no respect for property rights, no courts, no lawyers -- just a 'License to Kill' enemies of the state, loosely defined, who mostly happened to be businessmen working on start-up projects that coincidentally threatened state monopolies. He's a damned commissar. Do you know why Moscow hated him? It's because he'd got them beat at their own racket."
Blofeld was clearly depressed by this recollection, so I tried to change the subject by asking him about his personal management philosophy."
"Well, you know, I tend to use whatever works in day to day situations. I'm a pragmatist, really. But I've got a soft spot for modern philosophers, Leo Strauss and Ayn Rand: the rights of the individual. And I've always wanted to remake the world as a better place, which is probably why the establishment dislike me: I'm a threat to vested interests. Well, they're all descended from men who were threats to vested interests too, back in the day: only I threaten them with new technologies, while their ancestors mostly did their threatening with a bloody sword and the gallows. I don't believe in initiating force." He laughs self-deprecatingly. "I suppose you could call me naive."
4. Trade Goods
When I played back my tape of our discussion, it took me some time to notice that Ernst had carefully steered the conversation away from certain key points I had intended to quiz him about.
One of the most disturbing aspects of the Bond milieu is the prevalence of technologies that are strangely out of place. Belt-buckle grappling hooks with wire spools that can support a man's weight? Laser rifles? These aren't simple extrapolations of existing technology -- they go far beyond anything that's achievable with today's engineering tools or materials science. But forget Bond's toys, the products of Q division. From Blofeld's solar-powered orbital laser in "Diamonds are Forever" to Carver's stealthed cruiser in "Tomorrow Never Dies", we are surrounded by signs that the adversary has got tricks up his sleeve that far outweigh anything Bond's backers can provide. These menacing intrusions of alien super-science -- where can they possibly have got them from?
The answer can be discerned with little difficulty if one cares to scrutinize the writings of the sage of Providence, Howard Phillips Lovecraft. This scholar -- whose path, regrettably, never crossed that of the young Ian Fleming -- asserted that our tenancy of this planet is but a recent aberration. Earth has in the past been home for a number of alien species of vast antiquity and incomprehensibly advanced knowledge, and indeed some of them may still linger on alongside us -- on the high Antarctic plateau, in the frigid oceanic depths, even in strange half-breed colonies off the New England coastline.
If this strikes you as nonsensical, first contemplate your nearest city: how recognizable would it be in a hundred years' time if our entire species silently vanished away tomorrow? How recognizable would it be in a thousand years? Would any relics still bear witness to the once-proud towers of New York or Tokyo, a million years hence? Our future -- and the future of any once-proud races that bestrode our planet -- is that of an oily stain in the shale deposits of deep history. Earth's biosphere and the active tectonic system it dances on cleans house remorselessly, erasing any structure that is not alive or maintained by the living.
Consider also the extent to which we really occupy the planet we live on. We think of ourselves as the dominant species on Earth -- but 75% of the Earth's entire biomass consists of bacteria and algae that we can't even see with the naked eye. (Bacteria from whose ranks fearsome pathogens periodically emerge, burning like wildfire through our ranks.) Nor do we, in any real sense of the word, occupy the oceans. Certainly our trawlers hunt the bounty of the upper waters. But submarines (of which there are only a few hundred on the entire planet) fumble like blind men through the uppermost half kilometer of a world-ocean that averages three kilometers in depth, unable to dive beneath their pressure limits to explore the abyssal plains that cover nearly two thirds of the planetary surface. Finally, the surface (both the sub-oceanic abyss and the thin skin of dry land we cling tenuously to) is but a thousandth of the depth of the planet itself; we can't even drill through the crust, much less contemplate with any certainty the nature of events unfolding within the hot, dense mantle beneath.
We could be sharing the planet with numerous powerful alien civilizations, denizens of the high energy condensed-matter realm beneath our feet, and we'd never know it -- unless they chose to send emissaries into our biosphere, sprinkling death rays and other trade goods like glass beads before the aboriginal inhabitants, extracting a ghastly price in return for their largesse ...
5. A Colder War?
James Bond was a creature of the Cold War: a strange period of shadow-boxing that stretched from late 1945 to the winter of 1991, forty-six years of paranoia, fear, and the creepy sensation that our lives were in thrall to forces beyond our comprehension. It's almost impossible to explain the Cold War to anyone who was born after 1980; the sense of looming doom, the long shadows cast by the two eyeball-to-eyeball superpowers, each possessing vast powers of destruction, ready and able to bring about destruction on a planetary scale in pursuit of their recondite ideologies. It was, to use the appropriate adjective, a truly Lovecraftian age, dominated by the cold reality that our lives could be interrupted by torment and death at virtually any time; normal existence was conducted in a soap-bubble universe sustained only by our determination to shut out awareness of the true horrors lurking in the darkness outside it, an abyss presided over by chilly alien warriors devoted to death-cult ideologies and dreams of Mutually Assured Destruction. Decades of distance has bought us some relief, thickening the wall of the bubble -- memories misting over with the comforting illusion that the Cold War wasn't really as bad as it seemed at the time -- but who do we think we're kidding? The Cold War wasn't about us. It was about the Spies, and the Secret Masters, and the Hidden Knowledge.
It's no coincidence that the Cold War was the golden age of spying -- the peak of the second-oldest profession, the diggers in the dark, the seekers after unclean knowledge and secret wisdom. Prior to 1939, spying of the international kind rather than the sordid domestic variety (let us pass swiftly over the sordid Stasi archives of sealed glass jars full of worn underwear, kept as scent cues for the police dogs) was a small scale, largely amateurish concern. With the outbreak of the second world war it mushroomed. Faced with employment vacancies, the first response of a growing organization is to recruit close to home. Just like any 1990s dot-com startup, growing as the founders haul in all their friends and anyone they know who has the right skill set, the 1940s espionage agencies were a boom town into which a well-connected clubbable London playboy would inevitably be sucked -- and, moreover, one where he might try his hand and succeed, to everyone's surprise. (In the 1990s he'd end up in marketing, with stock options up to here. Sic transit gloria techie.)
When the Second World War gave way to the doomwatch days and Strangelove nights of the Cold War, it entered a period in which the same clubbable fellow might find himself working in a mature organization, vastly larger and more professional than the half-assed amateurism of the early days. The CIA was born in the shadow of the wartime OSS, and grew into the emblematic Company (traders in secrets, overthrowers of governments), locked in titanic struggle with that other superpowered rival, the KGB (and their less well known fellows in the GRU).
The age of the traditional sneak-spies with their Minox cameras gave way to the era of the bugging device. With the 1960s came a new emphasis on supplementing human intelligence (HUMINT) with intelligence from electronic sources (ELINT). New agencies -- the NSA in the United States, GCHQ in the UK -- expanded as the field of "spyless spying" went mainstream, aided by the explosion in computing power made possible by integrated circuits and, later, the microprocessor. As telephony, television, telex, and other technologies began to come online a torrent of data poured through the wires, a deluge that threatened to drown the agencies in useless noise. Or was it the whispering on the deep-ocean cables? Maybe the chatter served to conceal and disguise the quiet whispering of the hidden oracles, dribbling out strange new concepts that warped the vulnerable primate minds to serve their inscrutable goals. The source of the incredible new technologies that drove the advances of the middle of the twentieth century was, perhaps, the whispering of an alien farmer in the ears of his herd ...
Times change, and the golden age of spying is over. We've delivered the harvest of fear that the secret masters desired; or maybe they've simply lost interest in us for the time being. Time will tell. For now, be content that it's all over: the Cold War was a time of strangely rapid technological progress, but also of claustrophobic fear of destruction at three minutes' notice, of the thermonuclear stars coming right and bringing madness and death in their wake. Retreat into your soap-bubble universe, little primate, and give thanks.
From the perspective of the 21st century, Bond was a poor archetype for a hero; certainly he couldn't save us from the gibbering horrors of the Cold War, but only cast a shadow beneath their unblinking ground-zero glare. But we found salvation in the end, in the most unlikely place of all: if you turn on the TV you're likely to see one of old Ernst's protégés being held up for praise as an object of emulation. President of Italy, captain of industry, or chief executive of Enron -- SPECTRE won and it's their world that we live in, the world of the lesser evil.
Video games have often been a target of moral panic in the United States. The 1990s were fraught with worry that consuming violent content in video games would lead to violent behavior in the real world. The 2010s had its own controversies with the immense popularity of franchises like Call of Duty and Grand Theft Auto. Video games have had a litany of bad press for things they might cause, but we don’t give them nearly enough credit for what they actually have – a remarkable ability to foster social joy and whimsy.
Take Kerbal Space Program, a spaceflight simulator that is delightfully cartoony, with its little green player characters and charming music, and brutally punishing with its orbital physics. I have my own fond memories with early versions of the game. As a middle schooler with an interest in outer space, the game motivated me to get into model rocketry and scratched the itch to explore the solar system on my own terms.
As an adult who has abandoned a career in aerospace engineering for one in the social sciences, I still find myself picking up the game every once in a while. I’m not alone. Per SteamDB, the game has roughly quintupled its player base this past spring. This is far from the norm for games this far into their lifespan. While games occasionally see spikes in popularity due to sales, it’s incredibly rare to see sustained popularity on this scale.
Data visualized by the author. Source: SteamDB.info
I think the reasons for this spike are quite clear. March and April of 2026 were big months for public interest in space exploration. The breakaway box office success of Project Hail Mary, a film adaptation of Andy Weir’s 2021 sci-fi novel, brought a hopeful and optimistic portrayal of space travel and cooperation into the public consciousness. It was then quickly followed by the successful launch and completion of the Artemis II mission, sending four astronauts on a lunar flyby further away from Earth than ever before.
Sociologists and social theorists have long written about the role of play as a tool to make sense of the world. Georg Simmel and Erving Goffman wrote about play as a form of human interaction, wherein there are distinct rules and routines to play that players know how to abide by to perform a successful interaction. In this setting, play is just something that humans do, not fundamentally different from other forms like work or competition.
In contrast, historian Johan Huizinga argued that play is a primary force in the construction of human culture. In Homo Ludens, Huizinga asserts that play always exists as a representation of something else, that it serves as a layer underneath the “serious” that allows for people to alter the character of otherness. Put more simply, play serves as a space and time set aside to learn, to test, and to grow without consequence. In this way, play as a practice predates culture, predates civilization, and humans have “added no essential feature to the general idea of play.”
Following Huizinga, Thomas S. Hendricks writes about play as a fundamental pathway of behavior and experience, on the same level as work, ritual, and communal engagement. In Selves, Societies, and Emotions, Hendricks argues that play serves as a space to focus on processes rather than an end goal. Play therefore becomes a “test ground”, where glory can be sought in the unpredictable. Through play we can cultivate awareness of our own capabilities. This testing ground is precisely what players – especially new ones – will experience in KSP.
“good news, i landed on the mun for the first time. Bad news, i don’t have any fuel and now jeb is stuck” -stompe444_ Source: r/KerbalSpaceProgram
KSP‘s sustained boost in popularity is an example of how we can use play as a measure of public interest. As Huizinga argues, play never happens without it representing something meaningful. And whether this boost in popularity continues to hold stable or eventually declines back to baseline, I can’t help but be optimistic about the fact that more people than ever before are getting involved in the time-tested tradition of launching Jebediah Kerman to the stars, and what that means for the optimism that people have for a future in space.
The Artemis II mission cost billions of dollars, and the Artemis program itself has cost an order of magnitude more. At time of writing, Kerbal Space Program currently costs about $40 through Steam, and less if it is on sale. Even if only a fraction of those players end up turning their play into work, it’s worth it just for the fun of the ride. We often criticize video games for being time wasted at best and harmful power fantasies at worst. But it’s important to recognize how sociologists can use them to study social joy and public interest.
Jack Leatherman is a PhD Candidate at the University of Massachusetts Boston focusing on intersections of culture and technology. You can follow him on BlueSky.