Planet Russell

,

Planet Linux AustraliaTen Years of Daily Duolingo

Recently, I passed a ten-year streak of doing Duolingo every day. It's not like I do the bare minimum either; for the past three years, at least, my end-of-year Duo report records me in the 0.1% of learners on their application. My profile lists a rather impossible list of languages, many of which I looked in my early years and, I must admit, were handy whilst travelling through Europe. These days I'm concentrating on standard Chinese and French, whilst last year I completed the Spanish course as I was travelling to South America. In other words, over the years, my language learning has become more functionally-oriented rather than experimental.

Despite this regular use, I have mixed opinions about Duolingo. I will argue that Duolingo is the best language-learning application currently available. Nothing else comes to mind that has an extensive range of courses, that has a similar depth of content, that has regular updates, expansions of content and alignment to CEFR language competence. It continues to improve in areas such as spoken content, grammar, and conversational use of a language.

Likewise, I will also argue that Duolingo is the worst when it comes to business practises. It has built itself on countless hours of willing volunteers who gave advice and highlighted bugs over many years when the free version of the application was useful. Now that Duolingo has reached a position of apparently unassailable market dominance for language learning it has turned the screws to exclude community input (e.g., closing the forums, closing the language incubators) and, with aggressive and often gross advertising, has made the free version of the application almost unusable.

As a result of these practises, Duoling is the most profitable venture of its type. In terms of market evolution, it successfully outmanoeuvred potential alternatives in the competitive stage of the market development by engaging in the highest levels of community input but without providing community empowerment. Now it has reached the stage of market dominance, it has what is erroneously called "competitive advantage" in business studies, but is really "monopolistic advantage" when viewed through the lens of economic analysis.

I am sure the leaders at Duolingo are very well aware of this; whilst they could be true to their origins and actually contribute substantially to such a development, I suspect their business logic will run contrary to it. Duolingo argued that: "Our mission is to develop the best education in the world and make it universally available". They have claimed that: "The freemium business model is good for our mission and our business. We grow by offering an incredible free product and monetize by making the paid version worth it. This fuels a growth flywheel...". The reality is, however, that they don't really have a freemium model anymore.

However, at is core, Duolingo is actually a fairly simple product. In terms of computer design, flashcards (whether words, sentence gaps, etc) are simply an associative array of text and audio, text for grammar with a simple user interface (the simpler the better; Duo's distracting and unnecessary animations are awful) and spaced repetition algorithms. At the moment, numerous community-built Anki cards provide the highest level of development in this regard. Ultimately, however, Duolingo is a very tempting target for a community project, which I think is inevitable, which leads to an interesting conclusion that, in the near future, Duolingo's functionality will be open-sourced.

AttachmentSize
Image icon tenyearduo.png10.31 KB

,

Charles StrossOn the non-use of AI in my writing process

This isn't a blog entry I wanted to write, but it's a necessary one: a statement about the use of generative large language models (colloquially "AI") in my work.

I do not use LLMs in my work. I don't use them in my non-work life either, for that matter. I despise the grifters selling these toys as "tools" and trying to convince us to use them to generate plausible answer-shaped text strings in place of actual internet search for verifiable sources.

I've been selling fiction that I wrote myself since 1985 or thereabouts, and novels since 2002. If you want to verify that I have written novels without using an AI, simply pick up a physical copy of "Singularity Sky", "Iron Sunrise", "The Atrocity Archives", or anything else I published before 2015, the year OpenAI was founded.

Hint: you will find seven Hugo-shortlisted novels from that period, and three Hugo-winning novellas, also two Locus-award winning novels and a couple more novellas and stories. Clearly I don't need AI to write award-winning stories.

I do not want or need a large language model to write my fiction for me. I write fiction compulsively—before I was published I wrote for many years as a hobbyist—so why on earth would I pay someone else to take my fun away?

You will note em-dashes in the preceding paragraph. I gather some "AI detector" services (themselves a generative AI product) flag em-dashes as signs of "AI generated" text. Listen, fuckers, LLMs sprinkle em-dashes in their output because LLMs exist to stochastically emit strings of text that approximate the form of their inputs, and they've been trained by stealing all the text on the internet that isn't nailed down, including pirate websites that distribute cracked e-books. So it's wholly unsurprising that LLM output exhibits quirks that mimic real writers.

Did I mention the "stealing" thing? This isn't hyperbole: I'm one of the parties to the settlement in the class action lawsuit against Anthropic AI for pirating ebooks to train their LLMs. That's not my only grievance, either. You may have noticed this blog performing sluggishly or crapping out from time to time over the past few months. That's because my server is old and feeble and periodically gets swarmed by Chinese and other foreign botnets scraping data for training LLMs.

I'm usually willing to cut actual human beings, as opposed to for-profit corporations, some slack where it comes to cracking DRM, or even downloading warez: but these people are absolute scum. They're stealing copyrighted material to train an LLM that is intended to compete for revenue with the authors of the works they stole, and they're fine-tuning their LLMs to make them as addictive as possible in order to maximize future revenue once they pivot to token sales as their main source of income. In other words, they're no different from a burglar who robs you one day then comes round to sell you your stuff back the next morning. Back in the 18th century we used to hang people like that and Sam Altman makes me question the wisdom of having stopped.

I maintain that any serious author should shun LLMs like the plague. The most popular LLMs in the west—such as Claude, Gemini, CoPilot, and ChatGPT—the ones hoovering text indiscriminately off the internet for training—also gobble up any queries you send to them and use them as future training data. If I was crazy enough to feed the outline of a story I was working on as a prompt to ChatGPT or Claude in hope of getting the stochastic parrot to do my homework for me, then it would be only my own fault and nobody else's if the next model from the company in question was trained on my book outline and could reproduce part or all of it for someone else.

Finally, contra public opinion, I see no reason to credit LLMs with sentience. They're word-association mechanisms with no embodiment and no way to associate the text vectors they manipulate with real-world phenomena. But we humans have evolved through selection pressure in an adversarial environment to associate environmental phenomena around us with intentional causes—if you see lion scat and the gazelle are no longer visiting the watering hole, then you should assume there are lions about. And this trait carries over to linguistic manipulation. If we hear or read text, we expect there to be a mind on the other side of it, as Joseph Weizenbaum (the inventor of the original ELIZA chatbot) realized at MIT in the late 1960s. Just because it does something people do, it does not follow that it is a person.

Now for some caveats.

My skepticism does not carry over to all aspects of the field. It would be foolish to deny the effectiveness of image recognizers based on generalized adversarial networks (GANs), the key neural network technology underlying LLMs. It'd be similarly stupid to deny that LLMs are very good at supporting large-scale statistical analysis of text, such as Linear-A. And I can see some circumstances where being able to train a local model on my work could be useful to me.

I'd quite like a tool (running entirely locally on my own hardware, with no cloud service and no copyright-thieving grifters making bank on it via subscription fees) that digests a manuscript and derives a scene-by-scene timeline, that I could then query interactively and use to plan my next round of edits. Being able to map out where and when each protagonist and minor character shows up, and see a frequency distribution heat map of names in the manuscript, would be useful.

But such a tool would be useful to me in the same way a spelling checker is useful—as a decision-support tool, not as a substitute for doing the hard work (and having a copy of the Oxford English Dictionary on the shelf). The value of such a tool is considerably less than the value of a well-trained brain that can do the entire job the hard way, if necessary. And it's less than zero if using it opens me to finger-pointing accusations of "but he's using AI!" by people who can't read to the end of one paragraph, much less fourteen of them (yes, this is para fourteen, I've been counting).

So my fiction is still, as of August 2026, 100% LLM-free, and if that changes I will update this declaration accordingly.

Finally, I'd like to leave you with a snippet from the opening of the far future space opera I'm editing right now. It's part of the fiction and unfortunately may have to be omitted because of the risk of confusing the people who can't read to the end of the paragraph, but it's the only valid use of LLMs I've found so far for my fiction because it's a solution to the calling a rabbit a smeerp problem in SF and fantasy:

Translator's Note

The events described in this account have been translated into your language from the original source material using a non-sapient large language model.

Certain terms have been approximated, where possible, by using culturally appropriate cognates. Names of individuals have been replaced by equivalents. Similarly, institutions, ranks, religions, proverbs, idioms, quotations, and other culturally-determined signifiers have been translated into terms that will be familiar to the reader.

Units of duration and distance have also been converted.

We apologize in advance for any hallucinations our LLM may have inadvertently introduced in the process of generating this rough translation.

Planet DebianSergio Cipriano: My experience at DebConf 2026 in Santa Fé

My experience at DebConf 2026 in Santa Fé

The Official DebConf26 Group Photo

Last month, I attended DebConf 2026 in Santa Fé, which was my 5th DebConf. As always, it was an amazing experience, and I met a lot of great people there.

For those unfamiliar with the event, it takes place over the course of two weeks. The first week is called DebCamp and is geared more towards hacking and organizing the event itself, while also offering a great opportunity to discuss ideas with others. The second week is the DebConf. We still have the hacklabs, but the talks and workshops are the main focus.

My Activities during DebCamp

My main activity was working on the python-click transition that I started in May. There were only a few packages left, and with the help of Guilherme Puida, we managed to work through all the remaining bugs.

I plan to talk in details about this transition in another blog post, where I will focus on the tools I used and my experience with mass rebuilds and mass bug filing.

I also helped with de Golang Sprint. I worked on a few packages and experimented with the dak API to generate a list of packages that needed manual action.

There was a lot of manual, repetitive work and false positives, so I eventually moved on to some other, more fun stuff.

I also learned a few thinks about kernel live patching while talking to David Tadokoro. I had to work on the Ubuntu Kernel package recently as part of my job, so we exchanged some ideas, and the conversation was really helpful.

He also taught me two commands that I wasn't familiar with, since I'm a newbie in kernel development. Here are the commands:

$ b4 am https://lore.kernel.org/lkml/20240730071904.1047-1-sergiosacj@riseup.net/
$ b4 diff *mbox

By the way, this is the first and only patch I have submitted to the Linux Kernel. I worked on it during DebConf 2024, when I attended the workshop Helen Koike runs to help newcomers submit their first patch to the Linux Kernel.

Another great interaction was with Marcos Talau. He showed me his remote access setup, which he is using to help students make contributions to Debian without the struggle of setting up the development environment.

Another cool thing is that Puida showed me the command:

$ gbp clone vcs-git:typer

After that, I decided to read the gbp manpage because these little details really improve the overall experience.

I also had many other amazing interactions. I just decided to write down the ones that I felt made the most sense for this kind of "blog report" post.

My Activities during DebConf

I gave a talk about dh-make-vim, a tool I have been working on sporadically. An interesting detail is that one of the video team volunteers for the talk, Piotr, spoke to me about his tool, pypi2deb, which is similar but aimed at the Python ecosystem. There are many tools of this kind in Debian, and they are all interesting pieces of software. I plan to write more about them in the future.

I attended several talks and participated in a few BoF sessions, and they were all great. But something that really stood out to me was the workshop on the Debian Installer, led by Alper Nebi Yasak. I didn't know anything about the Debian Installer, and I liked the way he approached the subject and showed the specific details.

I'll take some time to read the Debian Installer internals documentation. I was not familiar with udebs or with the fact that the Debian Installer uses debconf under the hood.

Wrap up

It was an amazing event. Unfortunatly, a lot of people I know were not able to attend for different reasons, and they were missed.

There were many other things that I enjoyed during this trip. Here are a few more highlights:

  • World Cup matches
  • A day trip around Santa Fé
  • The Cheese & Wine party
  • Empanadas!!

Planet DebianDirk Eddelbuettel: RcppMsgPack 0.2.5 on CRAN: Minor Maintenance

Another maintenance release of RcppMsgPack got onto CRAN today. MessagePack itself is an efficient binary serialization format. It lets you exchange data among multiple languages like JSON. But it is faster and smaller. Small integers are encoded into a single byte, and typical short strings require only one extra byte in addition to the strings themselves. RcppMsgPack brings both the C++ headers of MessagePack as well as clever code (in both R and C++) Travers wrote to access MsgPack-encoded objects directly from R.

This release is once again chiefly maintenance. Besides standard upkeep to the README.md and continuous integration setup we had to add one #include. The clang++-23 compiler, when also running with its own library, now now needs the type_traits.h header file (in the upstream MessagePack code) so we added that. No other changes, so no user-facing changes. Details follow from the NEWS file.

Changes in version 0.2.5 (2026-08-19)

  • Explicitly include header "type_traits.h" to appease clang++-23

  • Standard maintenance updating continuous integration, adding minor helper script, and updating README.md

Courtesy of my CRANberries, there is also a diffstat report for this release. For questions, suggestions, or issues please use the issue tracker at the GitHub repo.

This post by Dirk Eddelbuettel originated on his Thinking inside the box blog. If you like this or other open-source work I do, you can now sponsor me at GitHub.

Charles StrossCrib sheet: The Regicide Report

The Regicide Report came out in January 2026. Traditionally I wait for the paperback before writing one of these spoiler-laden crib sheets, but there won't be a US paperback edition and the UK one isn't until the end of the year: if you don't want to wait, you don't have to.

So here it is.

The Laundry Files main story arc runs through nine novels, not including A Conventional Boy, a number of novellas and short stories (of which ACB was originally intended to be one—it over-ran), and the New Management trilogy (which was originally going to be a separate successor series to The Laundry Files: it starts 18 months after the end of The Regicide Report—it turned out to be a marketing train-wreck, which I blame on COVID19 induced mix-ups on the publishing end of things). There may eventually be a short story collection, as most of the shorts have never been published in paper editions, but this is it for the main story, which was (since The Fuller Memorandum) intended to end with the final CASE NIGHTMARE GREEN confrontation.

One huge problem with writing any vaguely-contemporary thriller series is that the world doesn't stand still underneath your fictional version of the universe.

I originally intended to accommodate this by advancing the date from novel to novel at the same speed time passed in the real world. The Atrocity Archives were set circa 2001-03, The Jennifer Morgue in 2005, and so on. Bob had room to grow older: The Annihilation Score was set in 2012 and by The Nightmare Stacks the clock had run out to 2014.

But just as lot of cold war spy thrillers were left stranded by the sudden end of the Cold War in 1989-91, I was blindsided by the Brexit referendum and its consequences in 2015. Prior to Brexit, British politics had been evolving along roughly predictable lines since Thatcher came to power in 1979, drove a tank over the prior bipartisan social democratic consensus politics, and ushered in an era dominated by a rapacious neoliberal ideology. The unexpected Brexit referendum outcome derailed the freight train, with consequences that are still emerging a decade later, and left me supporting an increasingly precarious pile of spinning plates.

An immediate consequence of Brexit, in The Laundry Files, was that I had to hastily rewrite The Delirium Brief (after it was substantially complete), giving it a similar political rupture leading to the rise of the New Management.

But unfolding multi-book catastrophes take many years to write, and by the time I got through that point the Laundryverse was rapidly decoupling from real time. The period 2015-2019 coincided with my parents' final decline and death (they both made it into their 90s), then the collective trauma of COVID19. The Laundryverse as of 2019 was still stuck in an in-world version of 2014, and rapidly receding into the past. I managed to un-stick the clock for the New Management books (the original working title of which was Laundry Files: The Next Generation) and set them in 2016-17, but the series was already turning into alternate history by the time I got around to finishing writing A Conventional Boy (set circa 2011, the same year I began writing it: finally published in 2024).

At the same time, my publishers gently warned me that sales were threatening to enter the dreaded midlist death spiral. A midlist death spiral occurs when an author's sales decline from one book to the next. Bookstores base their orders for a new title in a series on a straight line extrapolation (no curve fitting!) of the previous two books, so any decline fatally undermines advance orders, and thereby sets up a self-fulfilling prophecy of decline. It was therefore time to wrap the series—at least, if I wanted to be able to earn a living in future years.

Which set me up for The Regicide Report, in which all the homing pigeons I'd released in earlier books would come back to roost—or at least as many as I could keep track of in my head (I write by the seat of my pants, there's no World Book in my desk drawer, and over 25 years you tend to forget little details).

Because The New Management books were already in print, I was writing inside certain constraints. The designated climax had to be finished in-universe by May 2015 (The Labyrinth Index was set in mid-2014). It needed to feature Bob and Mo, but Bob and Mo as they had evolved—on the threshold of middle age, cynical, burned-out, and constantly asking "are we the baddies?". It needed a confrontation with the Prime Minister in which he is left in absolute authority over the UK but his ambition to ascend to full godhood is thwarted. It demanded cameos by numerous characters, a climactic boss battle that made sense in context, and an ending that didn't amount to a personal tragedy for the original protagonists: you don't want to leave your long-term fans hating you at the end of a series. ("The fans are out there. They can't be bargained with. They can't be reasoned with. They don't feel pity, or remorse, or fear! And they absolutely will not stop, ever, until you are dead." Ahem: my apologies to James Cameron and Gale Anne Hurd, not to mention any non-Terminator fans that exist.)

The driver for the climactic confrontation in the series is the Black Pharaoh's goal of achieving a death-grip on the British state. This inevitably means confronting the ultimate source of occult power in the kingdom, the monarchy itself: but it's a novel I couldn't have pitched to my British publisher before September 8th, 2022. Elizabeth II was remarkably well-loved, or at least respected as a public figure, and pitching a novel about her assassination was ... well, it would have been inadvisable. However, following her actual death (probably from consequences of COVID19: following infection elderly patients are at very high risk of stroke or heart attack for several months) she suddenly graduated from reigning monarch to historical figure, and as such was no more off-limits than Queen Victoria or President Kennedy.

So my remit was: write a book in which the Black Pharaoh tries to bump off the Queen in 2015, fails to achieve occult supremacy, Bob et al battle him to a stalemate, and we ring down the curtain on the Laundry as an organization (indeed, by the end of The Regicide Report the Laundry of yore has been purged and its various duties merged into a new ministry directly controlled by the Black Pharaoh.)

Of necessity I had to start The Regicide Report by dumping a bucket of ordure over Bob's head—that committee meeting, where he accidentally outs a senior colleague by forgetting to reset the joke ringtone on his phone—and gets sent on a tour of outlying civil service offices as punishment. Yes, the Birmingham scene features an extensive Hot Fuzz tribute: yes, that is DI Angel. (It's one of the few early 21st century movies with cinematography that my damaged eyeballs and retinas could follow.)

One of the hallmarks of The Laundry Files is the repeated trope of pastiching thriller authors or urban fantasy subgenres. The Regicide Report kinda-sorta does this, only differently, by picking on a 1970s British movie anti-hero, The Abominable Doctor Phibes, a role portrayed stunningly well by Vincent Price in the two movies that actually got filmed (The Abominable Doctor Phibes and Doctor Phibes Rises Again). These films were among masterpieces of 1950s-1970s British horror genre, but are not without their weaknesses, and I'm not just talking about the cheap special effects. I had a loud argument with the scriptwriters in the privacy of my own skull, because the two most significant female characters (Vulnavia, Phibes' murderous muse, and Mrs Phibes) have zero talking lines in either film. This, I felt, was selling them both short. And besides, there was an obvious (to me) subtext that made the Phibes menage both Laundry-adjacent and explained the silence of the priestesses. If you watch the real movies then read the descriptions Bob and Mo give during their movie night, you'll spot some divergences: the Professor Phibes Bob meets in the Laundryverse is not the Dr Phibes of our world, nor are the movies exactly the same. (Let alone the third one, Dr. Phibes meets Mabuse the Gambler, notionally made in 1973 while Phibes was sleeping away the years in his glass coffin and not in a position to murder the producers.) NB: keep an eye open for the Cabaret references in that last one.

The assassination is carried out by means of poison: the toxic substance in question is entirely real and absolutely horrifying. Luckily you're very unlikely to come across it in real life, unless you work with laboratory assay equipment measuring environmental mercury contamination.

Buckingham Palace is indeed as vast and labyrinthine as I described it, but does not, to the best of my knowledge, feature server farms in the attic and a ritual sacrificial mock-up of the above-ground quarters in the basement. (It does have a bowling alley and, quite probably, a cinema organ.) There were plans to provide an emergency evacuation route via the Tube before the second world war, although it's unlikely the Royal Family would be in residence or evacuated that way in a real crisis today.

The basement crypt and archive of royal skeletal remains at Westminster Abbey is my own invention, as is the underground river, although there's an awful lot of buried history there: the site has been in use for over nine centuries.

As a point of note, if there were any historical truth behind the legend of King Arthur Pendragon, he'd almost certainly not feel any kinship to today's royals, who are descendants of a German dynasty invited in during the 18th century. Per legend Arthur was a 5th/6th century figure who led the post-Roman Britons. No Angles, Saxons, or Normans need apply. Nor is today's United Kingdom, or even today's England, clearly related to Arthur's: we don't speak the same language, England in its modern borders was only united during the 9th and 10th centuries, the prevailing religion back then would have been either a pre-Christian pagan tradition or very early Catholicism, and so on. Much of the Arthuriana we are familiar with today was invented out of whole cloth in the 12th to 14th century, at a time as far removed from its subject matter as that time is removed from us in this day and age.

Anyway, that's a round-up of my talking points about The Regicide Report. If you have any questions about the book, feel free to ask in the comments below.

David BrinDisclosure... alas... of an 80 year cliché with the same, tired villains. But still fun. (SPOILERS!)

I'm a nearly life-long Steven Spielberg fan. (I didn't think anyone could make a better musical film than Leonard Bernstein's WEST SIDE STORY. Spielberg did it.) So okay, I had to go see DISCLOSURE DAY.  

Having dissected some 'hidden aspects' to his films, I deem that Spielberg's values and creative skills put him among the 'most-American' first-rank artists, combining constructive criticism of authority with eager curiosity, plus almost ebullient (and rare) optimism

So, I went to see DISCLOSURE DAY prepared to be entertained by masterful scenes, dramatic ironies and solid dialogue.

I also expected to simmer this time, over his complicity in an absurdly illogical and unsupportable cult fever that I've witnessed every half decade, across my entire life. A life that stretches almost all the way back to Roswell. A life spent exploring related topics, in both science and fiction.

----------------------------------------------

Does this posting seem tl;dr? Watch a fun podcast where I have the hosts in stitches about UFOs and AI and such, on the "This Week in Space" podcast via Twit.TV ... Dr. David Brin's Thoughts on Spielberg's 'Disclosure Day'.

Re: UFOs in general, here's my general dissection of this recurring mania... and the 10% that might be worth looking at. And a dive into the recent UAPs - how I'd make such zipping cat laser dots, cast by gigling humans for gullible pussycats to bat-at.

---------------------------------------------

To be clear, I loved CLOSE ENCOUNTERS, whose lesson was not loathing of a freely elected government and its civil servants, but very nearly the opposite, admiring their skills and mostly-generous intent. The professionals' main fault - in that movie and in ET and RAIDERS OF THE LOST ARK (and often in real life) consisted of patronizing citizens who are just trying to participate. 

In E.T. The Extraterrestrial, government experts are basically decent folks whose sole tort in the entire film is to treat Elliot's mom and her concerns condescendingly. Watch it again! The 'guy with the keys' is essentially Elliot, grown up!  

There is a villain in ET! Someone whose behavior is truly despicable. But we'll get to that.

Alas, from Mr. Spielberg's recent public statements, I had different expectations this time. And I was not proved wrong. In DISCLOSURE DAY, the litany of clichés and illogic was as thorough as the pervasive sense of pessimism throughout. 

The latter is Mr. Spielberg's privilege, of course. He's earned the right.

The former (and I say this knowing that my frankness has already harmed me in Hollywood, many times in the past) makes for bad art.

And so ... here's a requisite and very necessary SPOILER ALERT...


                                      == SPOILERS AHEAD! ==


      == Let's start with the supposed top goal of the conspirators  ==

The premise of DISCLOSURE DAY is that the whole Roswell and Hanger 18 megillah -- including crashed interstellar spacecraft and dead or captured aliens -- is all true. All of it, from the genuinely puzzling all the way to the long-disproved. 

For eighty years, the biggest thing in human history has been kept from us! Under a reign of fiercely-enforced secrecy, while crashed starships (all of them in the good old USA) have been intensely studied and new technologies back-engineered from them.

So... let's start with that. Do YOU see any such magical technological leaps? Antigravity and star drives and telepathy or age-reversal cures? Sudden, huge advances that can't be explained better by steadily incremental (if sometimes brilliant) human ingenuity? 

I know of none (except maybe AI - which was another thoughtful film). Moreover, to be clear, I've participated in some of humanity's tech-steps, across the last half century or so. Indeed, this may be the most-offensive part of the cult. Crediting such wonders as computers and integrated circuits and CAT scans and the Internet to aliens is just as insulting as claiming that ancient Egyptians and Mayans and Zimbabweans couldn't chip and move stone by themselves, in order to assuage their gods. Not without stone-lifting help from saucer-god beings. In other words, bigoted hogwash.

But let's put it up for a wager? Go ahead. Name a technological leap across all our lifetimes - (we'll set aside AI for now, though I get into that elsewhere.) Put down $$$ stakes vs. my promise to show the step-by-step increments that got us here, based on hard work by clever, assiduous and collaboratively diligent humans.

Furthermore, note this about Disclosure Day.. While Spielberg mentions that his secret agency is trying to reverse-engineer alien tech, he then lets the whole topic slip away.  Because he knows he can't point at anything. Velcro maybe? Naw. Nothing at all. Except for a couple of magic wands, that is.

Anyway, here we get to the biggest flaw of all. Such a major and utterly important project would benefit from having a very large number of human investigators and researchers, right? Recruited from among the best our species has to offer. Because you never know which impudent free-thinker may be the one to get that AHA! moment and succeed at grasping some alien tech.

Of course, that offers up a contradiction inherent to the whole UFO mania. Do you see it? The core topic of DISCLOSURE DAY?

The secrecy.


                     == Any reasons? ==

Secrecy lasting nearly an entire century, under all successive administrations, many of which hated each other? Mr. Spielberg tries to deal with that particular objection, with a single line: "we decided that presidents don't need to be involved." 

Cute: and indeed, one can imagine such a decision being made in a special case, such as the present. But seriously, across many decades, no one steps up to inform the one fellow on Earth who can issue you a pardon for telling him that every rule of law or democratic accountability is being violated?

Worse, in the film we see U.S. military generals collaborating with the secret ET-dissection agency in its 80 year betrayal of Constitutional chain of command. Alas, this prompts curiosity: does Steven Spielberg know any admirals or generals? The ones I've spoken with are absolutely - almost religiously - loyal to democracy and citizen rule. The culture set by George Marshall that merits our support.

Moving outward from USA parochialism, would not other nations have sniffed this out by now? Or had their own crashed ships? Or maybe this whole thing might serve the best purpose, like in that great Robert Culp OUTER LIMITS episode: bringing us together in common cause?

But let's get back to the sheer number of needed experts, in all their impudent variety. Even at Roswell, this would be hundreds of Americans, both in and out of uniform, participating in every 'encounter' since 1947. Then hundreds and hundreds more inside the agency, all the way to the 2020s. And those are just the ones collecting crash wreckage and alien bodies, along with captive ETs themselves. 

Picture it. Would not thousands of 'our best people' get hurled at such an emergency science study, one far more vital and urgent than the Manhattan Project? 

But in Hollywood parlance, all of those thousands of brilliant, individualist, cooperatively-competitive experts are reduced to the role of... henchmen.


                == It's kind of... well... hurtful ==

Okay, I am kinda P.O.'d about that premise, since I've been privileged to know many of the best people. And I can say with some confidence that none were ever invited into such studies of alien tech. I know this, not just from my conversations with them. But also because, in fact, such programs leave major ripples. Like big, noticeable gaps in their professional lives. Like all the subscriptions to ASTOUNDING Magazine that suddenly shifted to PO boxes near Los Alamos, New Mexico, in 1942. Or take the charter jets that right now commute daily with expert workers from Las Vegas homes to Area 51 and back again to be with their families. Those charters were sniffed-out easily, along with supply convoys.

(Okay, sure, Area 51 exists! And it's secret and has a few mystery planes. Duh? Again, that much is normal human brilliance and understandable military secrecy...  and none of it has got us anything better in space than the silly Artemis moondoggle, aimed at making a few more ritual footprints on a plain of poison dust.) 

Oh, one can offer hypothetical counters to all of the above. Is it possible that much smaller teams might work on alien stuff? Or that some truly super-uber-techs have come out of such studies and even my "best minds" acquaintances might know nothing about it? 

Maybe our anti-gravity ships have already colonized Europa. Heck, in STARGATE the USA has defeated several alien empires and is now leader of an entire Galactic coalition... not Earth, but the United States of America... and still they don't tell the taxpayers. Okaaaaaay...

(BTW I loved Stargate.)

Sure. I've even written sci fi stories that explored such notions, Secret colonies n' such. Fun stuff. But...

...but eighty years? After 80 years no one has blabbed or disclosed?*


     == Contempt for your fellow citizens is endemic ==

Oh, you say that some folks have already testified? With what evidence? Third hand rumors or unvetted 'things I saw'? Or 'an old man once told me' or else 'I saw a document once!!!!'

And Occam's Razor doesn't suggest to you that these are likely publicity-seeking 4th-raters who never, ever, ever offer anything like plausible evidence? And true insiders would have plenty by now! At risk of belaboring the obvious, let me repeat; there would have been hundreds, thousands of them by now, across an entire human lifespan.

What, you think some leather-skinned, retired engineer in his 90s, tooling around Arizona with a shotgun behind the seat of his pickup truck, is worried about a Non-Disclosure Agreement? 

Gawd you don't know these guys. I do. At least enough of them to choke back an urge to spit over how you insult them.


                       == The Big Question ==

Oh, but now we get to the question of WHY? 

Why go to such lengths, committing crimes tantamount to kidnapping, murder and treason, possibly meriting life sentences or death, all in order to prevent public ... disclosure?

Why? Steven Spielberg spends a lot of time on this one:

1) The former nun girlfriend (and is everyone in the film Catholic?) claims that a public that learns about tech-advanced-but mortal aliens will suddenly forsake God. 

Say... what? How the heck does that even scan? Sure Moctezuma thought Cortez might be a god, but even so, the Aztecs fought. And doubly so when they first saw a Spaniard bleed. Anyway, I think most modern folks could tell a 'tech-advanced-but-mortal alien' from the Creator of the universe.

(BTW I liked Spielberg having her clench the crucifix in her hand, creating a palm stigmata, enabling her to escape from mind control via the salvation of holy pain. With Colin Firth as either Herod or Pontius Pilate. Yum.)

2) Yes, Steven S. trots out the hoary old "public panic" excuse. Everyone will go mad!! Riots in the street. Cats and dogs, living together... Like the silly secrecy-justification of those deliberately-loopy MEN IN BLACK? 

At least Spielberg has the good sense and decency not to belabor this one, since his entire career was built by hundreds of millions of people paying to watch him poke at these very notions... with none of his audience ever running, screaming from the theater, as in The Blob.

3) But might disclosure destabilize a world teetering at the edge of nuclear war? Oooookay.  The whole DEFCON 3 thing seems kinda contrived for the sake of the show. And it doesn't explain non-disclosure way back during the relatively calm world of the 1990s. And... um... isn't this exactly what the USA would reveal, in order to distract from a parochially silly tiff among earthlings?

(And isn't the present UFO Disclosure Fetish really just a case of 'X-files to distract from Eps-Files'?)

By the end of the film, we are left with no plausible WHY at all! Other than Hugh (Coleman Domingo) diagnosing that Noah Scanlon (Colin Firth) is doing it all because of his own psychological pain. And... um... Hugh could not have simply taken that diagnosis over Noah's head?


       == A final note on why? ==

In fact, I can think of a couple of reasons that might - conceivably - justify secrecy! Why such a major endeavor by those who study UFOs might be worth hiding from the public. 

My novella "Senses, Three and Six is all about one such scenario. And no, it's not the hoary cliché of “avoiding public panic.” The notion is actually rather interesting, I reckon! (Hey Steven S., want a good premise for this topic? One that's never been dramatized and is far, far more plausible?)

Indeed, as I show in that story, there are conceivable (if unlikely) reasons why tens of thousands of our best minds might choose not to do the human thing and blab! Let's suppose it's something so compellingly dangerous that almost any sensible person who learns of it would agree it's better not to tell?


"Okay, as an American, my reflex is to disclose and share. But that's a damn good reason to quash it. For now."


Let's say there has been a Manhattan Project about aliens, and that all of the thousands of top folks studying this crisis actually agreed - against their every inclination - to keep it under wraps for a truly dire reason. A conspiratorial campaign of silence that has encompassed all party lines and many generations of our very best people for 80 years. As I've shown, it would have to be a damn good reason!  


Mull this over. Suppose for a moment that such a reason existed. Why even leather-skinned 90-year-old engineer-retirees would keep their gums tightly sealed. 

           

In which case then, um... can any of you pause your sanctimony long enough to please think it through?


If so, then who the hell are you to demand they break that massively consensus judgement by thousands of top minds who know vastly more about this than you do? When extorting revelation now might endanger all of humanity?


I'm not saying this ranks high on any list of plausibles! Indeed, perhaps you have a mature and well-considered answer to that question. Go ahead and put yours into comments! 


Hell, I could argue both sides all day... which is probably why - despite my peerless qualifications - I haven't been invited into the cabal! (Or... so I claim ;-)


But damn. What's utterly discrediting is that - amid their righteous sanctimony snits - none of these UFO zealots ever, ever pauses to consider it. 



        == Many silly (and some disturbing) things ==

Recall from the beginning, my teaser question about Disclosure Day? That question of who is the villain? You who have watched the flick likely think it's trivially easy to answer. 

It isn't. Not at all.

But first, let's deal with some quibbles.

Like all the magical powers displayed by the protagonists. Reading minds and speaking in math (without ever doing anything with that power, other than a little criminal hacking.) Gee thanks, alien guys. Gifts that never help in their lives or those around them, except when it serves the interests of those mind programmers.

Oh. Here's one! Did Kellner (Josh O'Conner) twirl the wheat himself, with some psychic power? Or did the aliens do it, while watching him from above? The latter seems likely, in this scene and many others. In which case, um, why did they always help just enough, so the heroes could leap from one sudden escape to the next barely-survived moment? Good movie action! But how about a little help to fly their car over the train, like Elliot did with ET in his bike basket? 

(Nah, I won't actually bitch about a great action scene. Loved the train bit! But it only works logically if the Visitors aren't monitoring... which they clearly are. Yet they never interfere in Noah's mind scans.)

Want another implausible? How about a cheap motel that has fluffy bathrobes? In what universe? Well, I can't blame Mr. Spielberg for only staying at ritzy places.

How about a mega implausibility? That we would torture-interrogate members of a super advanced starfaring race, rather than try to curry their favor, like good natives? Treating them as honored guests and offering any asked-help to get them home, in hope we might get some nice beads and trinkets, in return? Like fusion power or an Encyclopedia Galactica?

Anyway, if aliens can make birds fly into apartments to trigger the release of deep-embedded secret powers, are they truly unable to decipher our language from broadcasts and simply talk to us? They can teach an 8 year old child telepathy (then hide it - traumatically - in her brain) and another child super-math-language (that does him no good at all). So is it way beyond them to hack into the Internet to say: 

"Hi everyone on primitive Earth? Sorry about all the anal probes and ruined wheat and drunken-buzzing your cities and smashed-up radioactive ship debris and memory wipes and such. 

"But now can we ask that you release our crash survivors? We'll send a space uber for themhimherit tomorrow in the middle of Central Park. And yes, we'll answer questions then, the way we should have, for eighty...

"...no, make that several thousand years, when we could have opened a small, community college, taught you printing and glass lenses and democracy and the germ theory of disease and thus spared you many millennia of grueling pain. Again, sorry about that. And here are your reparations."


                     == Yet again, the same finger-wagging... ==

Instead we get a familiar, hackneyed cliché over and over again! Like smug, chiding Klaatu, in The Day The Earth Stood Still, threatening and guilt tripping Earthlings instead of explaining why his folk let us stew in filth and ignorance for ages? From COCOON to 2001 to CONTACT, to PAUL, always patronizing and never any plausible excuse for doing nothing for us, across all those dark ages of grinding human misery. 

Oh, there are some plausible excuses! That I have never seen even once in sci fi cinema.

Don't talk to me about Non-Interference Directives! Then why did you kidnap and experiment on so many of us, going back to faerie encounters in medieval times? (You think I'll let fetishists claim it started at Roswell?) Or else, in DISCLOSURE DAY, snatching and traumatizing two little children, back in the 90s?

Even in the very best films about contact... like CONTACT or CLOSE ENCOUNTERS... aliens seem to call mysteriousness their most-noble trait. It's a plot element we saw in the excellent Ted Chiang novella and resulting movie ARRIVAL, all the way to Stanislaw Lem's obsessively cryptic SOLARIS. We meet strange, hyper-advanced beings... whereupon the heavy lifting of translating languages and overcoming misunderstandings is entirely up to us! Never, ever the mysterious sky-god meddlers, themselves.

And yes, UFO-zealots never seem to grok that saucer-beings should be judged -- first and foremost -- according to their behavior!

Which... of course... brings us to...


     == The true villain is... ==

Well, I've said it elsewhere and for 40 years. There is only one villain in the entire movie E.T. The Extraterrestrial. And that villain is not the big bad government, or the guy with the keys... nor is it the hapless agronomist ET, itself.

The villain in that early Spielberg masterpiece is blatantly the captain of ET's ship

An SOB who abandons a crewmate in an alien forest when they are threatened by... flashlights and clipboards! The only implements in sight when KeysGuy hurries to the landing site. No guns. No threat except curiosity.

A captain who departs swiftly to avoid contact, when such a meeting might be just the thing to save us. 

A captain who ET must phone home in order to summon his ride back, when the bastard captain knows within two blocks where he abandoned the guy!

Elliot does everything wrong, though for loving reasons. If he handed over ET like a good citizen (as I portray in my YA SF novel Colony High), those doctors who struggled to save ET in the film would say: "No, no, you can't have Reeces Pieces. We can tell they are poisoning you. And you want to phone home? Fine, We'll use the Goldstone radio telescope."

And when the ship finally returns to collect ET: "That'll be six weeks rent. One Encyclopedia Galactica please... you evil, betraying, selfish asshole."

-------------------

Let's be clear. I ADORED THAT FLICK! It's about love and loyalty and courage and friendship. And none of the captain's crimes are poor ET's fault. Or Eliot's. Nor... (my main point) ... are they ours. I'm simply asserting that the movie did have a villain. And once you know to look... it's obvious.

-------------------

And yes, at least Steven Spielberg* is consistent! Because the true villains in DISCLOSURE DAY are the same. The very same. Space jerks who have been teasing us and zipping around, messing with our heads (and our wheat.) Refusing our entreaties for contact. (I have been involved in SETI for 40 years and have used various means and media in legit attempts to lure honest communication. Hey Steven S., want a good idea or two?)

Space jerks who kidnap Navy pilots and children (as in CLOSE ENCOUNTERS) and twirl wheat and anal-probe farmers (as in SIGNS and INDEPENDENCE DAY) or steal our planetary genetic stock (as in E.T.) or precious bodily fluids... 

...okay, I'm getting carried away. Blame the aliens who still talk to me via the fillings in one molar. Mercury silver amalgam makes a great antenna! Though now it's the AIs who are apparently using that tooth. Does that mean they overlap? Extraterrestrials and artificial intelligences? Duh? Hence the title of my latest book: AIlien Minds.

But no, Let's make it explicit.

Colin Firth may portray a villain in DISCLOSURE DAY. But the macro villains are Steven Spielberg's aliens. Flitting about in super ships, teasing us endlessly, pulling aerial stunts, till a few of those buzzing and harassing ships drunkenly crashed. And even then abandoning their crewmates rather than reclaim them by the simple means of stepping out, in the clean sunshine and talking to us?

Oh, indeed, they do have plenty to fear from disclosure! As I point out in EXISTENCE, this kind of behavior that's been bruited by UFO zealots for nearly a century... and by faerie-believers for thousands of years... is exactly the sort of thing that any advanced civilization would label as crime! 

And hence, here's a plausible theory! Why their frenetic secrecy? Why their refusal to disclose?

What they fear may be that we'll call the galactic cops on them! (I have actually done that, over the airwaves.) Or else some interstellar law firm, to sue and/or prosecute these. nasty, silvery pervs.


                  == All that's left is some zipping balls of plasma?

Oh, I could go on. And on. And I have about this mountain of piled up absurdities.

As I've said, my skepticism is is not from stodgy lack of imagination. I assert that few living humans have approached the topic of the “alien’ from more angles than I have, from SETI and astrophysics and biology and psychology and history to many dozens of science fiction scenarios, some of them even plausible! So, I ain't claiming we are alone-alone,

In fact, what I find most offensive is how every touted 'ufo' scenario is so damned clichéd and boring.

Take the most-recent purported 'sightings.' In past decades, nearly all (including Roswell) were disproved or debunked, or else cases where 'aliens' remained the least likely hypothesis... all of which has been eagerly ignored by zealots. Only now? 

Now there are ten million times as many active cameras on Earth's surface as in the 1950s, so why do the 'images' keep getting ever-fuzzier? 

Now, instead of lovely pie tins or frisbees, they're glowing dots, zipping back and forth in mid-air! Mick West has shown that a majority were likely camera-perspective illusions. But as for the rest? 

Has it occurred to you to look closely and see if they are translucent?  With light passing through them from the other side? It seems that one Navy missile shot right through one of the zipping balls, causing it to joggle a little. Suggesting they might be just glowing globs of plasma, careening about. Impressive, but violating no known physical laws.

 I go into them elsewhere, So here I'll just say that with $6M and 6 months *I* will make glowing dots zip near airplanes, just like recent 'sightings.' Indeed, a parsimonious explanation for the latest 'phenomena' may be found on nearby ships... ocean going boats with hulls and propellers, down below. Turn some of the cameras to view vessels down amid the waves, where human jerks are likely using simple beam methods to make dots and balls rove about the sky, in order to tease and mess with gullible folks. 

In other words, using the equivalent of a cat laser! 

And those Navy pilots... and you dears... are the pussycats.


       == Where we might actually find aliens! ==

In my novel EXISTENCE, I talk about what may be the nearest and most likely place to actually and really contact 'aliens.' Our children may (if we restore a confident and scientific civilization from current lobotomization*) get out to the Asteroid Belt, where they truly could find, amid the tumbling rocks, remnant interstellar probes...

...robots that arrived in our solar system across millions of years. Perhaps with a variety of missions and goals that I discuss in that novel. Maybe mostly wrecks or ruins by now, but maybe some still functioning. And even aware of us, from our broadcasts or Internet. 

There'd be a lot of implications! And yes, some dangers. (And some fun/tense confrontation scenes in EXISTENCE.)

But the lurker scenario is so much more plausible in every way than pervert anal-probers and kidnapping hyp-mo-tizers going "Oooga-booga!" at us down here, earning both our contempt by their behavior and - yes - maybe a nice, well-deserved, missile up their nasty silver butts.


        == Your homework assignment ==

Enough.  It's not my mission to quash your sense of wonder, but to expand it. From the sorts of faerie-kidnapping myths that made our ancestors shiver in feudal superstition (slightly updated to be 'spaceships' or time travelers or interdimensional wizards) toward other possibilities, much more plausible, that may await us out there. 

What I can tell you is this. (And it doesn't come from that filling in my tooth!) It's that you are better than this.

We can restore this civilization to one of wonder and equality and justice and common sense and science and dazzling imagery. That quest is now mostly political, and I believe we can do it!

But it will also be about making better demands from our art


======

======

* Again. Deep respects for Steven Spielberg! We would be culturally and artistically poorer without him!  But pointing out stuff is what I do. It's my job.

* What better explanation for the world - especially America - growing ever-more hysterically irrational in recent years, than some kind of alien lobotomizing ray? It'd certainly be consistent with what we're seeing: millions of citizens in a great and scientific and logical nation abruptly turning their backs on all that, waging open war against its smartest people. 

Why lobotomize us? Perhaps to slow us down? Or to institute Idiocracy, or a return to the feudalism that was always controlled by priests serving meddler gods? Or else to keep us serving them as entertainment? For the galaxy-wide hit reality show Oh, Those Humans!

And yes, it's one more reason to gird ourselves. Put out that call for space lawyers, invent AIs to fight back for us! And eventually teach the bastards - both human and alien - a badly needed lesson.

Planet DebianAntoine Beaupré: The people vs the AI overlords

Previously in this series: The Four Horsemen of the LLM Apocalypse.

In a post to oss-security, my (Debian) co-developer Russ Allbery stated that "open source software [OSS] is coming face to face with a motivation crisis that has been building for a long time". His point is essentially that large language models (LLMs1) are making the existing OSS community crisis worse. For him, it's the flood of code reviews, but he argues that varies according to people's desires, for others it's security issues and so on.

I think Russ is right, but I would argue there's something much bigger than our open communities going on here, and it's about the entire field of computing. This pressure is on all of us, regardless of whether we work on open source software or not.

How people use models

People using LLMs in their workflow have radically changed how programming works, even for people who claim to avoid vibe-coding. And I'm sorry to single out one poor maintainer here: it's not you, Brian, you're just one example among many. But this is typical use of those models nowadays:

Once it’s done, I’ll use /code-review and let Claude spawn sub-agents to do a full review of the new code. This usually finds some problems, even problems that the “main” Claude instance didn’t find during its validation. I usually keep running /code-review again and again after finding and fixing issues, until there aren’t any left.

Think about what that means for a minute. This is automation built to fire up dozens of agents crunching at a problem for minutes if not hours of GPU compute time, in parallel. This is essentially a couple of shelves in a datacenter rack, totally maxed out on power and cooling, abstracted behind a cute little /code-review command.

The author, here, is rightly concerned that "Anthropic could pull the rug out and require API pricing", which is perhaps a code word for "charging something closer to actual costs". Brian also pays lip service to environmental and societal costs but those are largely abstracted away, so let's keep that conversation aside here as well, as we have discussed it before anyways.

But clearly, this way of working has an (externalized) cost, to say the least.

Paying for non-free tools

For decades my work has been focused on free and open source software. I've long stopped using proprietary operating systems like Windows or Mac, and even before that switch, I was mostly using free software on those platforms, partly out of principle, but also because I was too poor. So the tools of my trade are free, and I build free tools with them.

It feels like we're going backwards: when I was in school, a millennia ago, my classmates didn't have access to a compiler and were wondering how they would scrape the money to buy a compiler like Borland's or Microsoft's. I had a compiler built into my operating system (FreeBSD at the time), so that wasn't a problem for me. For them, it was a significant expense, but at least those expenses (or more shady sourcing of programs) were a one-shot deal.

Fast forward 30 years, and software is rented: you pay monthly for Adobe's Photoshop and Microsoft's office suite just like you pay for Netflix, Disney+ or Spotify2. And now you need to add dozens (if not hundreds of dollars) of monthly credits to access LLMs on top of that.

So, now we have to pay to get anything done? This is peak enshitification of our job: first they steal our work to train their models, and then they sell it back to us at a profit.

Attacking the engineers

AI is coming for our jobs, as engineers, if not everyone, according to the narrative. For a while now, our job market has deteriorated: less jobs, for less pay. Lots of skilled engineers looking for work and finding crap jobs then still looking while working.

This is not by accident.3 We engineers have a lot of power, it is not organized, but that's just a couple of unions away (easy!). Tech overlords know this, so they are attacking our profession, directly, by forcing us to train and use models that they can control.

Even in environments where programmers are not forced to use LLMs, the mere pressure of other people's LLM-generated work is huge. One can be forced to review LLM outputs, or just peer pressured you into producing more.

We're now supposed to accelerate delivery, because models can presumably do things so much better and faster. With supply chain security becoming such a large vector that we now have worms crawling around developers accounts on NPM, increasing the delivery cadence seems like a really bad idea.4

The LLM hype is part of the larger wave of cyberwar against workers, against water, against the Earth, against all the people. This is not a matter of individually "adapting to the reality" or personal choice, but a political, social, hard problem we need to address collectively.

Previously in this series: The Four Horsemen of the LLM Apocalypse.


  1. I again prefer the term LLM to "AI" because models do not possess intelligence. I did use it in the title because click baiting is apparently important, but I stopped short of calling this one "Rage Against the Machines" because that would be the title of every blog post I have ever made.
  2. Yes, I know that Visual Studio is kind of free now, but I wouldn't be surprised if they turn that into a rental as well, because why not.
  3. Beyond sabotaging the job market, Sam Altman event wants to sell "intelligence as a utility" something that is just a really bad idea but especially shows how megalomaniac those people are.
  4. This brings back memories of another era, walking us back decades in terms of computer security.

Planet Linux AustraliaEight of the world's most colourful buildings

<https://www.bbc.com/culture/article/20260817-eight-of-the-worlds-most-colourful-buildings>

“We have been using colour to bring joy for hundreds of thousands of years.
Early Neanderthals decorated cave walls with pigments from the earth. These
early efforts were followed by the polychromatic temples of ancient Egypt and

Planet Linux AustraliaPhotos show how drought has transformed Britain's landscape

<https://www.reuters.com/pictures/photos-show-how-drought-has-transformed-britains-landscape-2026-08-18/>

"Britain has recorded five heatwaves this year that have left around 45 million
people ⁠living in drought-hit areas and 27 million people ​facing restrictions
on water use."

Planet Linux AustraliaPlants tolerate shading from Agri-PV systems better than expected

<https://www.heise.de/en/news/Plants-tolerate-shading-from-Agri-PV-systems-better-than-expected-11417637.html>

"Photovoltaic systems on fields, so-called Agri-PV systems, have various
advantages: they generate electricity and simultaneously protect the plants
from the effects of climate change. However, there was a fear that shading

Planet Linux AustraliaAI RANT

https://bsky.app/profile/barsukov.com/post/3mtc7d7cugk2u

"Following the cancellation of three major debut book deals over AI suspicions,
I decided to put my own (needless to say, 100% human-written) prose to the
test. My detector of choice was Originality AI, and the results proved to be

Planet Linux AustraliaThe UK and Google are testing changes to flight paths to tackle aviation’s climate impact

<https://apnews.com/article/google-contrails-climate-warming-aviation-2110e4cb5c317c3434805076764c5a47>

"Hundreds of commercial flights will be told to change their paths over the
northeastern Atlantic Ocean during the next two winters to show how minor
altitude adjustments can reduce aviation’s climate impact.

Planet Linux AustraliaBowen says coal “isn’t baseload anymore, it’s unreliable,” will stop states pushing gas for data centres

<https://reneweconomy.com.au/bowen-says-coal-isnt-baseload-any-more-its-unreliable-threatens-states-pushing-gas-for-data-centres/>

"Federal energy minister Chris Bowen has slammed calls to extend Australia’s
ageing coal-fired generators, saying that not a single day had passed in the
last three years without a breakdown, while also suggesting that data centres

Worse Than FailureCodeSOD: Back to the Lab

Matlab is special. Scientists and researchers love it. Programmers hate it, and not just because it uses 1-based arrays. I've worked on a number of projects where the task was "take this Matlab code and convert it to C so we can run it on an embedded CPU". Somehow, in that process, I've avoided learning much about Matlab.

Andre works on a team that uses Matlab to manage experimental scenarios. They wanted to do a simple task: generate a set of participant-specific images, store them in a database, and reference them later. Somewhere in the intersection of the database product they were using, the Matlab license they had, and other constraints, they discovered that there simply was no good way to do this.

Enter "Jude". Jude said, "Don't worry about it, I can hack something together."

I present the code in its entirety, but don't ask me to explain it. Instead, read the comments.

nMk = 1;%counting non-response triggers, this cycles with each trial
nPress = 0;%counting button presses, noting the position in the log

for v = 1:height(resVmrk)%read each trigger
	switch nMk
		%it's kinda roundabout, but the only recognisable part is the response
		%yet I refer to it only by elision
		%and instead count the stimuli to reconstruct the pattern
		case 1%an almost reliable stimulus
			nPress = nPress+1;%trial start
			if strcmp(resVmrk.TriggerCode{v},'S1')%it must be a non-response
				resVmrk.TriggerCode{v} = 'cross';%name it properly
				nMk = 2;%and expect the next one
			else%except when it is not
				resLog.miss(nPress) = 1;%then note it down as missed
				nMk = 0;%and skip to response
			end
			
		case 2%usually reliable
			if strcmp(resVmrk.TriggerCode{v},'S1')%if the face loaded successfully
				resVmrk.TriggerCode{v} = 'face';%note it
				nMk = 3;%and proceed accordingly
				if nPress<=height(resLog)%trailing triggers at the end should be ignored
					resLog.facePos(nPress) = v;%note the position
				end
			else%if it failed to load it is a response
				resVmrk.Dur(v-1:v+1) = 0;%mark the whole trial for deletion
				resLog.miss(nPress) = 1;%and note it down as missing the face
				nMk = 0;%and skip to response
			end
			
		case 3%this one is not reliable, and sometimes is duplicated instead of missing
			if strcmp(resVmrk.TriggerCode{v},'S1')%if it is present at all
				resVmrk.TriggerCode{v} = 'empty';%first name it
				if v<height(resVmrk)%if it is not a trailing trigger, since it'll break the check otherwise
					if ~strcmp(resVmrk.TriggerCode{v+1},'S1')%if the next trigger is a response
						nMk = 0;%all is fine and it didn't freak out, proceed to response
					else%otherwise
						nMk = 3;%just treat as a double
						%and then count how many excess triggers are actually here
						nExcess = 1;%definitely one here already
						while strcmp(resVmrk.TriggerCode{v+nExcess+1},'S1')
							nExcess = nExcess+1;%and everything until the response
						end
						resVmrk.Dur(v-2:v+nExcess+2) = 0;%then mark the whole trial for deletion
						%this overwrites the same positions several time, but the important part is to get the preceding two, because I don't know which one of them is correct one, so I delete the whole trial
						if nPress<=height(resLog)
							resLog.bad(nPress) = 1;%also note it down as borked
						end
					end
				end
			else
				nMk = 0;%if it didn't happen at all simply proceed to response
			end
			
		case 0%this one reliably follows the response, so I address the response by elision
			if strcmp(resVmrk.TriggerCode{v},'S1')%skip response itself
				resVmrk.TriggerCode{v} = 'blink';%note the only reliable non-response (always following the response)
				nMk = 1;%start the trial anew
				if nPress<=height(resLog)%if it is not a trailing trigger
					resLog.respPos(nPress) = v-1;%note down the response position
					if resLog.miss(nPress)==1%and if it's a response without a stimulus
						resVmrk.Dur(v-1:v) = 0;%mark it for deletion as well
					end
				end
			end
	end
end

Ah, the classic "for-case" antipattern. That's gross enough, but what the heck is happening inside each of those cases?

My personal favorite comment is this one: "%this overwrites the same positions several time, but the important part is to get the preceding two, because I don't know which one of them is correct one, so I delete the whole trial"

Now, you may suspect comments like "usually reliable" are about what we see in the dataset, but I'm not so certain. Andre writes:

After reverting the last discovered way for his creation to corrupt the data I was able to figure out that 20% of the logs provided corresponded to different (unknown) experiments altogether.

[Advertisement] Keep the plebs out of prod. Restrict NuGet feed privileges with ProGet. Learn more.

365 TomorrowsThe Coastline

Author: Alzo David-West A ship moved on the ocean. The vessel was big, and its sides were covered in salt. Young people were all over the deck, wearing fitted t-shirts and short shorts. Warm air blew gently. Some of the passengers leaned against the railings as others rested in deckchairs. Music played, and the ship […]

The post The Coastline appeared first on 365tomorrows.

Planet Linux Australia‘I can be myself more’: what students told us about pride groups in schools

&lt;https://theconversation.com/i-can-be-myself-more-what-students-told-us-about-pride-groups-in-schools-288725>

"A sense of school belonging is important for all students so they feel
respected, supported and included. However, this can be harder for some groups
of students. Unfortunately, many LGBTQIA+ students still face discrimination

,

Charles StrossThe Golden Age Of Bond Villains

So, the second novel in the Laundry Files, The Jennifer Morgue, was first published on November 1st, 2006. And while it was superficially a pastiche of the Bond movie canon (as it existed at that time--I was writing before the Daniel Craig era, ushered in with Casino Royale--it was also interrogating the dramatic conventions of the genre and also the implications of rule by Bond Villains.

At about the time I was writing it, a friend of mine (initially a tech journalist, later an industry pundit) described his experience of interviewing Elon Musk, who was allegedly leaning hard into the archetype. "I must be a Bond villain!" He joked, "I have an electric car and a tropical island where boiler-suited minions launch rockets!" And then he laughed it off. (In those days, we thought it was a simile: these days it's more clearly understood as a metaphor, if not the absolute raw truth.)

Anyway, I wrote a little afterword for The Jennifer Morgue discussing the significance of the Bond Villain as an archetype for our times and it does still appear to have something relevant to say, 20 years later; and I figure the current publisher has forgotten about it, so I'm going to shamelessly pirate my own work and reprint the entire epilogue from The Jennifer Morgue right here on my blog (the horror!).

Note that the Great Financial Crisis that kicked off the current era really started in late 2007, and our current era of oligarchic misrule, only got underway in the mid-20-teens, with the evitable rise to power of a deeply unpleasant TV reality star whose main claim to fame was playing a stupid man's idea of a successful business mogul.

(At least I didn't predict that.)

Anyway, the text is below the fold--it's quite long--and I ask this: what would you add, today?

The Golden Age of Spying

1. The Mary-Sue of MI6

"My name is Bond. James Bond."

These six words, heard by hundreds of millions of people, are almost invariably spoken during the first five minutes of each movie in one of the biggest media success stories of the 20th century. Unless you've lived under a rock for the past forty years, you hear them and you know at once that you're about to be plunged into a two hour long adrenaline saturated extravaganza of snobbish fashionable excess, violence, sex, car chases, more violence, and Blowing Shit Up -- followed by a post-coital cigarette and a light-hearted quip as the credits roll.

It wasn't always so. When "Casino Royale" was first published in 1953, it got a print run of 4750 hardcover copies and no advertising budget to speak of; while the initial reviews were favorable, comparing Ian Fleming to Le Queux and Oppenheim (the kings of the pre-war British spy thriller genre), it took a long time for his most famous creation to set the world on fire. Despite his rapidly rising print runs ("Casino Royale" eventually sold over a million paperbacks in the UK alone), and despite his increasing prominence among the post-war thriller writers, a decade elapsed before any of Fleming's novels were filmed; indeed, their author barely lived to see the commercial release of "Dr No" and the runaway success of the icon he created. (Nor were the films seen as a runaway success before they were made -- "Dr No" was notoriously made on a tight budget, even though it went on to gross nearly $60M around the world.)

Literary immortality -- or indeed, mere post-mortem survival -- is dauntingly hard for a novelist to achieve. The limbo of post-mortem obscurity awaits 95% of all novelists -- almost all novels go out of print for good within five years of the death of their author. But in addition to being a million-selling best-seller, Fleming was a ferociously well-connected newspaper executive with a strong sense of the value of his ideas, and he pursued television and film adaptation remorselessly. Cinematic success arrived just in time for his creation, and the synergy between best-selling books and massive movie hype has sufficed to keep them in print ever since.

James Bond is a creature of fantasy, perhaps best described using a literary term looted from that most curious and least respected of fields, fan fiction: the Mary-Sue. A Mary-Sue character is a placeholder in a script, a hollow cardboard cut-out into whose outline the author can squeeze their own dreams and fantasies. In the case of Bond, it's cruelly easy to make a case that the famous spy was his author's Mary-Sue: for Fleming had a curious and ambiguous relationship with spying.

A dilettante and dabbler for his first three decades, unsuccessful as a stockbroker, foreign correspondent, and banker, Fleming fortuitously landed his dream job on the eve of the Second World War: Secretary to the Director of Naval Intelligence in the Admiralty. The war was good for Ian Fleming, broadening and deepening him and giving him a job that captured his imagination and drew out his not inconsiderable talents. But Fleming was the man who knew too much: privy to too many secrets, he was wrapped in tissue paper and prevented from pursuing his desire to go into the field. He ended the war with a distinguished record -- and absolutely no combat experience (if one excludes being bombed by the Luftwaffe or watching the Dieppe raid from a destroyer, safely far off the Normandy coastline). Fleming grew up in the shade of a father who died heroically on the western front in 1917, and in adult life he wrote in the shadow of an elder brother whose reputation as a novelist surpassed his own. It's easy to imagine these unkind familial comparisons provoking the imaginative but flighty playboy who almost found himself during the war, goading him to imagine himself in the shoes of a hero who was not merely larger than life, but larger in every way than his own life.

And, as it turns out, James Bond was larger than Ian Fleming. Not only do few novels survive their author's demise, even fewer acquire sequels written by other hands; yet several other authors (including Kingsley Amis and John Gardner) have toiled in Fleming's vinyard. Few fictional characters acquire biographies written by third parties -- but Bond has not only acquired an autobiography (courtesy of biographer John Pearson) but spawned a small cultural industry, including a study of his semiotics by Umberto Eco. Now, that has got to be a sign of something ...

As with every true pearl, there was a sand-grain of truth at the heart of Bond. Fleming wrote thrillers informed by his actual experience. Years spent working out of the hothouse environment of Room 39 of the Admiralty building -- headquarters of the Naval Intelligence Division of the Royal Navy -- gave him a ringside seat on the operations of a major espionage organization. On various trips to Washington DC he worked with diplomats and officers of the OSS (predecessor organization to the CIA). As a foreign news manager at The Sunday Times after the war, there is some evidence that Fleming made his agency's facilities available to officers of MI6. His first Bond novels were submitted to that agency for security clearance before they were published. Bond himself may have been larger than life, but the strictures imposed by the organization he worked for were drawn from reality, albeit the reality of an intelligence agency of the early 1940s.

The world of secret intelligence gathering during the second world war was, however, very different from life in the intelligence community today. It was already changing by the late 1950s, as the bleeping football-shaped Sputniks zipped by overhead and intelligence directors began dreaming of spy satellites. By 2004, when MI5 (the counter-intelligence agency) openly placed recruiting advertisements in the press, we can be sure that Bond would be best advised to seek employment elsewhere. Spies are supposed to be short -- under 180 centimeters for men -- and nondescript. As a branch of the civil service, MI5's headquarters are presumably non-smoking, and drinking on the job is frowned upon. As intelligence agencies, MI5 and MI6 staff aren't in the business of ruthlessly wiping out enemies of the state: any decision to use lethal force lies with the Foreign Secretary, the COBRA committee, and other elements of the British government's security oversight bureaucracy. An MI6 agent driving a 1933 Bentley racer with a supercharged engine, frequenting the high-stakes table at a casino as James Bond so memorably did in his first print appearance, is an almost perfect inversion of the real picture.

Nevertheless, the archetype has legs. James Bond continued to grow and evolve, even after his creator put away his cigarette holder for the last time. To some extent, this was the product of storytelling expediency. The film adaptations started in the middle of a continuing story arc -- for Fleming wrote his novels with a modicum of continuity -- and while "Dr No" was the first to make it to celluloid, the novel was in fact a sequel to "From Russia With Love" (which was filmed second). Thus, various liberties were taken with the plot of the canonical novels, right from the start. You can re-read the novels at length without finding anything of the banter between Bond and M's secretary Moneypenny that is a recurrent theme of the films, for example, and that's before we get into the bizarre deviations of the mid-period Roger Moore movies (notably "The Spy Who Loved Me" and "Moonraker").

The literary James Bond is a creature of pre-war London clubland: upper-crust, snobbish, manipulative and cruel in his relationships with women, with a thinly-veiled sadomasochistic streak and a coldly ruthless attitude to his opponents which verges on the psychopathic. Over the years, his cinematic alter ego has acquired the stamina of Superman, learned to defy the laws of physics, ventured into space -- both outer and inner -- and deflowered more maids than Don Juan. He's also mutated to fit the prejudices and neuroses of the day, dabbling with (gasp!) monogamy, and hanging out with those heroic Afghan mujahideen in the late-eighties AIDS-and-Soviets-era "The Living Daylights". He's worked under a post-feminist ball-breaking 'M' in "Goldeneye", and even confronted a female arch-villain in "The World is Not Enough" (an innovation that would surely have Fleming, who formed his views on appropriate behavior for the fairer sex in the 1920s, rolling in his grave). But other aspects of the Bond archetype remain timeless. Fleming was fascinated by fast cars, exotic locations, and intricate gadgetry, and all of these traits of the original novels have been amplified and extrapolated in the age of modern special effects.

Just how does James Bond -- a "sexist, misogynist dinosaur, a relic of the Cold War", to use the words the script-writers on "GoldenEye" so tellingly put into M's mouth -- survive in the popular imagination more than fifty years after his literary birth? What does it mean when Mary-Sue stalks the landscape of the imagination, blasting holes in the plot with a Walther PPK (or the P99 he upgraded to in "Tomorrow Never Dies")? If we're going to understand this, perhaps we ought to start by looking at Bond's dark shadow, the Villain.

2. In search of Mabuse

Bond is, if you judge him by his work, a nasty fellow and not one you'd choose to lend your car to: to make this rough diamond glitter it is necessary to display him against a velvet backdrop of darkest villainy. If you strip the Bond archetype of the bacchanalia, glamorous locations, and fashion snobbery, you end up with an unappetizingly shallow, cold-blooded executioner -- the likes of Adam Hall's Quiller or James Mitchell's Callan, only without the breezy cynicism, or indeed any redeeming features at all. The role of adversary is thus a critical one in sustaining the appeal of the protagonist. Fleming set out to depict a hard-edged contemporary world where the usual black-and-white picture of the pre-war thriller had blurred and taken on some of the murky grey-on-grey ambiguity of the cold war era; Bond was the knight in shining armor, fighting for virtue and the free world against the dragon -- be they Mr. Big, Dr. No, Auric Goldfinger, or the looming shadow of Bond's greatest enemy of all, Ernst Stavro Blofeld, Number One of SPECTRE, the Special Executive for Counter-intelligence, Terrorism, Revenge and Extortion.

It is interesting to note that Blofeld assumed his primacy as Bond's #1 enemy only in the movie canon; Fleming originally invented him while working on the screenplay and novel of "Thunderball", and used him subsequently in "On Her Majesty's Secret Service" and "You Only Live Twice". (Prior to these later books, Bond typically tussled with less corporate enemies -- Soviet stooges, unregenerate Nazis, and psychotic gangsters.) Blofeld was born out of mere corporate expediency. Rather than demonize the Soviets and reduce their potential audience, the producers of the film of "From Russia With Love" appropriated SPECTRE as the adversarial organization. With the success of "Thunderball", the third of the films, Blofeld moved front and center and acquired a life of his own that far exceeded his prominence in the novels. Arguably, Fleming's death in 1964 freed up the movie series to diverge from their original author's plans; and so Blofeld may be seen as a demon of necessity, conjured up from the vasty depths in order to provide Bond with a worthy adversary.

'Twas not always so. Back at the turn of the 20th century, around the time that the British spy thriller was gradually cohering out of the mists of the penny dreadful and the literature of suspense (via the works of John Buchan and Erskine Childers -- not to mention the tangential contributions of Arthur Conan Doyle, by way of Sherlock Holmes) there was no great dualistic vision of the great champion confronting the villainous heart of evil. There was no great champion: we were on our own against the masters of night and mist, the great and terrible super-criminals. Professor Moriarty, Holmes' nemesis -- the Napoleon of Crime -- was but one of these: Fantômas, the 1911 creation of Pierre Souvestre and Marcel Allain, is another. The emperor of crime, Fantômas was a master of disguise and an agent of chaos (not to mention standing astride Paris in black mask, top hat and tails, in the posters for the 1913 movie of the same name: an icon of decadent wealth and criminal chaos). Nor was he alone. Guy Boothby's 1890's super-villain Dr Nikola fits the bill too, right down to the fluffy lap-cat and the fiendish plans. But perhaps the root of Bond's nemesis can be found in his full-fledged form somewhat later, and somewhat further to the east -- in the guise of Dr. Mabuse.

Dr. Mabuse is an archetype and a runaway media success in his own right, famous from five novels and twelve movies. The Doctor was created in 1922 by author Norbert Jacques, and was developed into one of the most chilling creations of the silent era by no less a director than Fritz Lang. Mabuse is a name, but one that nobody in their right mind speaks aloud. He's a master of disguise, naturally: and a rich, well-connected socialite and gambler. (Some social context: gambling at the high stakes table is no so much an innocuous recreation as an obscenity, in a decade of hyper-inflation and starvation, with crippled war veterans dying of cold on the street corners, as was the case in Weimar Germany). Mabuse has his fingers in every pie, by way of a syndicate so shadowy and criminal that nobody knows its extent; he's a spider, but the web he weaves is so broad that it looks like the whole of reality to the flies trapped in it. He is (in some of the stories) a psychiatrist, skilled in manipulation, and those who hunt him are doomed to become his victims. If Mabuse has a weakness it is that his schemes are over-elaborate and tend to implode messily, usually when his most senior minions rebel, hopelessly late; nevertheless, he is a master of the escape plan, and with his ability to brainwash minions into playing his role he's a remarkably hard phantom to slay.

It is all too easy to make fun of the likes of Fantômas and Dr. Nikola, and even their modern-day cognates such as Dr. Mabuse and Ernst Stavro Blofeld; for do they not represent such an obsessively concentrated pinnacle of entrepreneurial criminality that, if they really existed, they would instantly be hunted down and arrested by INTERPOL?

Careful consideration will lead one to reconsider this hasty judgment. Criminology, the study of crime and its causes, has a fundamental weak spot: it studies that proportion of the criminal population who are stupid or unlucky enough to get caught. The perfect criminal, should he or she exist, would be the one who is never apprehended -- indeed, the one whose crimes may be huge but unnoticed, or indeed miscategorized as not crimes at all because they are so powerful they sway the law in their favor, or so clever they discover an immoral opportunity for criminal enterprise before the legislators notice it. Such forms of criminality may be indistinguishable, at a distance, from lawful business; the criminal a paragon of upper-class virtue, a face-man for Forbes.

When the real Napoleons of Crime walk among us today, they do so in the outwardly respectable guise of executives in business suits and thousand-dollar haircuts. The executives of Worldcom and Enron were denizens of a corporate culture so rapacious that any activity, however dubious, could be justified in the name of enhancing the bottom line. They have rightfully been charged, tried, and in some cases jailed for fraud, on a scale that would have been the envy of Mabuse, Blofeld, or their modern successor, Dr. Evil. When you need extra digits on your pocket calculator to compute the sums you are stealing, you're in the big league. Again, when you're able to evade prosecution by the simple expedient of appointing the state prosecutor and the judges -- because you're the President of a country (and not just any country, but a member of the rich and powerful G8) -- you're certainly not amenable to diagnosis and detection in the same sense as your run-of-the-mill shoplifter or petty delinquent. I'm naming no names (they have intelligence services! Cruise missiles!) but this isn't a hypothetical scenario.

3. Interview with the Entrepreneur

In an attempt to clarify the mythology surrounding James Bond, I tracked his old rival down to his headquarters in the Ministry of Inward Investment in the breakaway Republic of Transdniestria. Somewhat suspicious at first, Mr. Blofeld relaxed as soon as he realized I was not pursuing him on behalf of the FSB, CIA, or IMF, and kindly agreed to be interviewed for this book. Now aged 72, Blofeld is a cheerful veteran of numerous high-tech start-ups, and not a few multinationals where, as a specialist in international risk management and arbitrage, he applied his unique skills to business expansion. Today he is semi-retired but has agreed to work in an voluntary capacity as director of the State investment agency.

"It took me a long time to understand the agenda that the British government was pursuing through the covert activities of MI6," he told me over a glass of sweet tea. "Call me naive, but I really believed -- at least at first -- that they were honest capitalists, the scoundrels."

Over the course of an hour, Ernst explained to me how he first became aware that the UK was attempting to sabotage his business interests. "It was back in 1960 or thereabouts that they first tried to destroy one of my subsidiaries. Until then I hadn't really had anything to do with them, but I believe one of my rivals in the phosphate mining business put it about that my man on site was some sort of spy, and they sent this Bond fellow -- not just to arrest him or charge him with some trumped-up nonsense, but to kill him." His lips paled with indignation at he contemplated the iniquity of the situation: that agents of the British government might go after an honest businessman for no better reason than an unsubstantiated allegation that he was spying on American missile tests. "I warned Julius to be careful and advised him to put a good lawyer on retainer, but what good are lawyers when the people you're up against send hired killers? Julius brought in security contractors, but this Bond fellow still murdered him in the end. And the British government denies everything, to this day!"

Ernst obviously believes in his own moral rectitude, but I had to ask the obvious questions, just for the record.

"Yes, I was chief executive of SPECTRE for twelve years. But you know, SPECTRE was entirely honest about its activities! We had nothing to hide because what we were doing was actually legal. We've been mercilessly slandered by those rogues from MI6 and their friends in the newspapers, but the fact is, we're no more guilty of criminal activity than any other multinational today: we simply had the misfortune to be foreign and entrepreneurial at a point in time when Whitehall was in the grasp of the communist conspirators Wilson and Callaghan and their running-dog so-called 'conservative' fellow Heath. And we were pilloried because what we were doing was in direct competition with the inefficient state-run enterprises that my good friend Lady Thatcher recognized as mosquitoes battening on the life-blood of capitalism. That cad Fleming put it about that SPECTRE stands for 'Special Executive for Counterintelligence, Terrorism, Revenge and Extortion' -- absolute tosh and nonsense! Would a group of criminals really call themselves something that blatant? I'll remind you that SPECTRE is actually a French acronym, as befits a non-profit charity incorporated in Paris. The name stands for 'Société Professionelle et Ethique du Capital Technologique Réinvestissement par les Experts.' Venture capitalists specializing in disruptive new technologies, in other words -- commercial space travel, nuclear power, antibiotics. Not some kind of half-baked terrorist organization! But you can imagine the threat we posed to the inefficient state monopolies like the British Aircraft Corporation, the coal mining industry, and Imperial Chemical Industries."

Blofeld paused to sip his tea thoughtfully.

"We were ahead of our time in many ways. We pioneered business methods that later became mainstream -- Sir James Goldsmith, Ronald Perelman, James Icahn, they all watched us and learned -- but by then, the commies were out of power in the west thanks to our friends in the establishment, so they had an easier time of it. No need to hire lots of expensive security and build concrete bunkers on desert islands! And yes, that made us look bad, don't think I'm unaware of it -- but you know, you want bunkers and isolated jungle rocket launch bases? All you have to do is look at Arianespace! It's fine when the government bureaucracies do it, but if an honest businessman tries to build a space launch site and hires security to keep the press and saboteurs from foreign governments out, it's suddenly a threat to world security!"

He paused for a while. "They put the worst complexion on everything we did. The plastic surgery? Well, we had the clinic, why not let our staff use it, so the surgeons could stay in practice between paying customers? It was a perk, nothing more. We did -- I admit it -- acquire a few companies trading in exotic weapons, non-lethal technologies mostly. And that business with Emilio and the yacht, I admit that looked bad. But did you know, it originally belonged to Adnan Khashoggi or Fahd ibn Saud or someone? Emilio was acting entirely on his own initiative -- a loose cannon -- and as soon as I heard about the affair I terminated his employment."

I asked Ernst to tell me about Bond.

"Listen, this Bond chap, I want you to understand this: however he's painted in the mass media, the reality is that he's a communist stooge, an assassin. Look at the evidence. He works for the state -- a socialist state at that. He went to university and worked with those traitors Philby and Burgess, that MacLean fellow -- communist spies to a man. He didn't resign his commission when the British government went socialist, like a decent fellow: instead he took assignments to go after entrepreneurs who were a threat to the interests of this socialist government, and he rubbed them out like a Mafia button man. There was no due process of law there, no respect for property rights, no courts, no lawyers -- just a 'License to Kill' enemies of the state, loosely defined, who mostly happened to be businessmen working on start-up projects that coincidentally threatened state monopolies. He's a damned commissar. Do you know why Moscow hated him? It's because he'd got them beat at their own racket."

Blofeld was clearly depressed by this recollection, so I tried to change the subject by asking him about his personal management philosophy."

"Well, you know, I tend to use whatever works in day to day situations. I'm a pragmatist, really. But I've got a soft spot for modern philosophers, Leo Strauss and Ayn Rand: the rights of the individual. And I've always wanted to remake the world as a better place, which is probably why the establishment dislike me: I'm a threat to vested interests. Well, they're all descended from men who were threats to vested interests too, back in the day: only I threaten them with new technologies, while their ancestors mostly did their threatening with a bloody sword and the gallows. I don't believe in initiating force." He laughs self-deprecatingly. "I suppose you could call me naive."

4. Trade Goods

When I played back my tape of our discussion, it took me some time to notice that Ernst had carefully steered the conversation away from certain key points I had intended to quiz him about.

One of the most disturbing aspects of the Bond milieu is the prevalence of technologies that are strangely out of place. Belt-buckle grappling hooks with wire spools that can support a man's weight? Laser rifles? These aren't simple extrapolations of existing technology -- they go far beyond anything that's achievable with today's engineering tools or materials science. But forget Bond's toys, the products of Q division. From Blofeld's solar-powered orbital laser in "Diamonds are Forever" to Carver's stealthed cruiser in "Tomorrow Never Dies", we are surrounded by signs that the adversary has got tricks up his sleeve that far outweigh anything Bond's backers can provide. These menacing intrusions of alien super-science -- where can they possibly have got them from?

The answer can be discerned with little difficulty if one cares to scrutinize the writings of the sage of Providence, Howard Phillips Lovecraft. This scholar -- whose path, regrettably, never crossed that of the young Ian Fleming -- asserted that our tenancy of this planet is but a recent aberration. Earth has in the past been home for a number of alien species of vast antiquity and incomprehensibly advanced knowledge, and indeed some of them may still linger on alongside us -- on the high Antarctic plateau, in the frigid oceanic depths, even in strange half-breed colonies off the New England coastline.

If this strikes you as nonsensical, first contemplate your nearest city: how recognizable would it be in a hundred years' time if our entire species silently vanished away tomorrow? How recognizable would it be in a thousand years? Would any relics still bear witness to the once-proud towers of New York or Tokyo, a million years hence? Our future -- and the future of any once-proud races that bestrode our planet -- is that of an oily stain in the shale deposits of deep history. Earth's biosphere and the active tectonic system it dances on cleans house remorselessly, erasing any structure that is not alive or maintained by the living.

Consider also the extent to which we really occupy the planet we live on. We think of ourselves as the dominant species on Earth -- but 75% of the Earth's entire biomass consists of bacteria and algae that we can't even see with the naked eye. (Bacteria from whose ranks fearsome pathogens periodically emerge, burning like wildfire through our ranks.) Nor do we, in any real sense of the word, occupy the oceans. Certainly our trawlers hunt the bounty of the upper waters. But submarines (of which there are only a few hundred on the entire planet) fumble like blind men through the uppermost half kilometer of a world-ocean that averages three kilometers in depth, unable to dive beneath their pressure limits to explore the abyssal plains that cover nearly two thirds of the planetary surface. Finally, the surface (both the sub-oceanic abyss and the thin skin of dry land we cling tenuously to) is but a thousandth of the depth of the planet itself; we can't even drill through the crust, much less contemplate with any certainty the nature of events unfolding within the hot, dense mantle beneath.

We could be sharing the planet with numerous powerful alien civilizations, denizens of the high energy condensed-matter realm beneath our feet, and we'd never know it -- unless they chose to send emissaries into our biosphere, sprinkling death rays and other trade goods like glass beads before the aboriginal inhabitants, extracting a ghastly price in return for their largesse ...

5. A Colder War?

James Bond was a creature of the Cold War: a strange period of shadow-boxing that stretched from late 1945 to the winter of 1991, forty-six years of paranoia, fear, and the creepy sensation that our lives were in thrall to forces beyond our comprehension. It's almost impossible to explain the Cold War to anyone who was born after 1980; the sense of looming doom, the long shadows cast by the two eyeball-to-eyeball superpowers, each possessing vast powers of destruction, ready and able to bring about destruction on a planetary scale in pursuit of their recondite ideologies. It was, to use the appropriate adjective, a truly Lovecraftian age, dominated by the cold reality that our lives could be interrupted by torment and death at virtually any time; normal existence was conducted in a soap-bubble universe sustained only by our determination to shut out awareness of the true horrors lurking in the darkness outside it, an abyss presided over by chilly alien warriors devoted to death-cult ideologies and dreams of Mutually Assured Destruction. Decades of distance has bought us some relief, thickening the wall of the bubble -- memories misting over with the comforting illusion that the Cold War wasn't really as bad as it seemed at the time -- but who do we think we're kidding? The Cold War wasn't about us. It was about the Spies, and the Secret Masters, and the Hidden Knowledge.

It's no coincidence that the Cold War was the golden age of spying -- the peak of the second-oldest profession, the diggers in the dark, the seekers after unclean knowledge and secret wisdom. Prior to 1939, spying of the international kind rather than the sordid domestic variety (let us pass swiftly over the sordid Stasi archives of sealed glass jars full of worn underwear, kept as scent cues for the police dogs) was a small scale, largely amateurish concern. With the outbreak of the second world war it mushroomed. Faced with employment vacancies, the first response of a growing organization is to recruit close to home. Just like any 1990s dot-com startup, growing as the founders haul in all their friends and anyone they know who has the right skill set, the 1940s espionage agencies were a boom town into which a well-connected clubbable London playboy would inevitably be sucked -- and, moreover, one where he might try his hand and succeed, to everyone's surprise. (In the 1990s he'd end up in marketing, with stock options up to here. Sic transit gloria techie.)

When the Second World War gave way to the doomwatch days and Strangelove nights of the Cold War, it entered a period in which the same clubbable fellow might find himself working in a mature organization, vastly larger and more professional than the half-assed amateurism of the early days. The CIA was born in the shadow of the wartime OSS, and grew into the emblematic Company (traders in secrets, overthrowers of governments), locked in titanic struggle with that other superpowered rival, the KGB (and their less well known fellows in the GRU).

The age of the traditional sneak-spies with their Minox cameras gave way to the era of the bugging device. With the 1960s came a new emphasis on supplementing human intelligence (HUMINT) with intelligence from electronic sources (ELINT). New agencies -- the NSA in the United States, GCHQ in the UK -- expanded as the field of "spyless spying" went mainstream, aided by the explosion in computing power made possible by integrated circuits and, later, the microprocessor. As telephony, television, telex, and other technologies began to come online a torrent of data poured through the wires, a deluge that threatened to drown the agencies in useless noise. Or was it the whispering on the deep-ocean cables? Maybe the chatter served to conceal and disguise the quiet whispering of the hidden oracles, dribbling out strange new concepts that warped the vulnerable primate minds to serve their inscrutable goals. The source of the incredible new technologies that drove the advances of the middle of the twentieth century was, perhaps, the whispering of an alien farmer in the ears of his herd ...

Times change, and the golden age of spying is over. We've delivered the harvest of fear that the secret masters desired; or maybe they've simply lost interest in us for the time being. Time will tell. For now, be content that it's all over: the Cold War was a time of strangely rapid technological progress, but also of claustrophobic fear of destruction at three minutes' notice, of the thermonuclear stars coming right and bringing madness and death in their wake. Retreat into your soap-bubble universe, little primate, and give thanks.

From the perspective of the 21st century, Bond was a poor archetype for a hero; certainly he couldn't save us from the gibbering horrors of the Cold War, but only cast a shadow beneath their unblinking ground-zero glare. But we found salvation in the end, in the most unlikely place of all: if you turn on the TV you're likely to see one of old Ernst's protégés being held up for praise as an object of emulation. President of Italy, captain of industry, or chief executive of Enron -- SPECTRE won and it's their world that we live in, the world of the lesser evil.

Sociological ImagesAn Eye to the Stars and the Sociology of Play

Video games have often been a target of moral panic in the United States. The 1990s were fraught with worry that consuming violent content in video games would lead to violent behavior in the real world. The 2010s had its own controversies with the immense popularity of franchises like Call of Duty and Grand Theft Auto. Video games have had a litany of bad press for things they might cause, but we don’t give them nearly enough credit for what they actually have – a remarkable ability to foster social joy and whimsy. 

Take Kerbal Space Program, a spaceflight simulator that is delightfully cartoony, with its little green player characters and charming music, and brutally punishing with its orbital physics. I have my own fond memories with early versions of the game. As a middle schooler with an interest in outer space, the game motivated me to get into model rocketry and scratched the itch to explore the solar system on my own terms.

As an adult who has abandoned a career in aerospace engineering for one in the social sciences, I still find myself picking up the game every once in a while. I’m not alone. Per SteamDB, the game has roughly quintupled its player base this past spring. This is far from the norm for games this far into their lifespan. While games occasionally see spikes in popularity due to sales, it’s incredibly rare to see sustained popularity on this scale.

Data visualized by the author. Source: SteamDB.info

I think the reasons for this spike are quite clear. March and April of 2026 were big months for public interest in space exploration. The breakaway box office success of Project Hail Mary, a film adaptation of Andy Weir’s 2021 sci-fi novel, brought a hopeful and optimistic portrayal of space travel and cooperation into the public consciousness. It was then quickly followed by the successful launch and completion of the Artemis II mission, sending four astronauts on a lunar flyby further away from Earth than ever before. 

Sociologists and social theorists have long written about the role of play as a tool to make sense of the world. Georg Simmel and Erving Goffman wrote about play as a form of human interaction, wherein there are distinct rules and routines to play that players know how to abide by to perform a successful interaction. In this setting, play is just something that humans do, not fundamentally different from other forms like work or competition. 

In contrast, historian Johan Huizinga argued that play is a primary force in the construction of human culture. In Homo Ludens, Huizinga asserts that play always exists as a representation of something else, that it serves as a layer underneath the “serious” that allows for people to alter the character of otherness. Put more simply, play serves as a space and time set aside to learn, to test, and to grow without consequence. In this way, play as a practice predates culture, predates civilization, and humans have “added no essential feature to the general idea of play.” 

Following Huizinga, Thomas S. Hendricks writes about play as a fundamental pathway of behavior and experience, on the same level as work, ritual, and communal engagement. In Selves, Societies, and Emotions, Hendricks argues that play serves as a space to focus on processes rather than an end goal. Play therefore becomes a “test ground”, where glory can be sought in the unpredictable. Through play we can cultivate awareness of our own capabilities. This testing ground is precisely what players – especially new ones – will experience in KSP.

“good news, i landed on the mun for the first time. Bad news, i don’t have any fuel and now jeb is stuck” -stompe444_ Source: r/KerbalSpaceProgram 

KSP‘s sustained boost in popularity is an example of how we can use play as a measure of public interest. As Huizinga argues, play never happens without it representing something meaningful. And whether this boost in popularity continues to hold stable or eventually declines back to baseline, I can’t help but be optimistic about the fact that more people than ever before are getting involved in the time-tested tradition of launching Jebediah Kerman to the stars, and what that means for the optimism that people have for a future in space.

The Artemis II mission cost billions of dollars, and the Artemis program itself has cost an order of magnitude more. At time of writing, Kerbal Space Program currently costs about $40 through Steam, and less if it is on sale. Even if only a fraction of those players end up turning their play into work, it’s worth it just for the fun of the ride. We often criticize video games for being time wasted at best and harmful power fantasies at worst. But it’s important to recognize how sociologists can use them to study social joy and public interest.

Jack Leatherman is a PhD Candidate at the University of Massachusetts Boston focusing on intersections of culture and technology. You can follow him on BlueSky.

(View original at https://thesocietypages.org/socimages)

Planet Linux AustraliaNew museum find shows nature can’t stop inventing seahorses

&lt;https://theconversation.com/new-museum-find-shows-nature-cant-stop-inventing-seahorses-288274>

"At first glance it looks exactly like a seahorse. It has the same horse-shaped
head tilted down from the body, the same curled and grasping tail, and in the
males a fully enclosed pouch for brooding the young.

Planet Linux AustraliaAquaculture is depleting the oceans: A farmed salmon can consume more than six times its weight in wild fish

&lt;https://english.elpais.com/climate/2026-08-13/aquaculture-is-depleting-the-oceans-a-farmed-salmon-can-consume-more-than-six-times-its-weight-in-wild-fish.html>

"Empty fish counters. That is what shoppers found when they arrived at Madrid’s
Mercado de la Paz last September. The stock had not sold out. Instead, they
were looking at an advertising campaign organized by Apromar, Spain’s

Planet Linux AustraliaAmazon canopy bridges enable 15,000 wildlife crossings without a single roadkill

&lt;https://news.mongabay.com/short-article/2026/08/amazon-canopy-bridges-enable-15000-wildlife-crossings-without-a-single-roadkill/>

"Roads through Brazil’s forests divide primate habitat and sometimes force
animals that normally remain in the canopy onto the ground. Researchers in the
Amazon are testing rope bridges that allow them to cross above traffic.

Planet Linux AustraliaUS firms that kept DEI policies despite ‘go woke, go broke’ threats thrived

&lt;https://www.theguardian.com/world/2026/aug/14/dei-policy-company-performance>

"Conservative backlash was supposed to put an end to the diversity, inclusion
and equity (DEI) movement as companies were warned “go woke, go broke”.

Planet DebianThomas Lange: LLM usage in Debian

After spending many hours on reading all the proposals and discussions the best choice for me is NOTA (None of the above).

We do not need to create new rules for LLM usage, we already have our DFSG and our social contract.

Keep it simple, stupid. Avoid more rules!

Planet DebianAndy Simpkins: My first go at tracking down a kernel bug…

A couple of weekends back, I upgraded my home sever. It failed to restart after running apt dist-upgrade

The only update that was performed was to the kernel, it went from 6.12.88+deb13-amd64 to 6.12.100+deb13-amd64. I had previously performed an apt-get upgrade, and rebooted the machine, so I was pretty sure that this was to blame. This blog entry (is a late) attempt to document how I went about finding a fix for this issue so that next time I don’t need as much hand holding as I did this time around :-)

(1)
Having my machine not boot following an upgrade is pretty rare, but has happened before. Usually it is because I have done something wrong so as always confirming I haven’t broken something by accident is always my first step…

I plugged in a keyboard an monitor to the machine and watched it boot. Being a server this takes a long time (I guess because at this stage of system initialisation we want to test things sequentially)

Watching the system boot I see the usual BIOS/UEFI stages for this machine, followed by the grub menu and the the local screen showed:

            Loading Linux 6.12.100+deb13-amd64 ...
            Loading initial ramdisk ...

Nothing else. That was it. OK that looks like I have a broken system all right, and at very early stage of the boot process process.

(2)
Breaking into the grub menu and removing the quiet option yields a little more information (but not much):

            Loading Linux 6.12.100+deb13-amd64 …
            Loading initial ramdisk ...
            

            	EFI stub: Loaded initrd from LINUX_EFI_INITRD_MEDIA_GUID d
            	evice path
            		EFI stub: Measured initrd data into PCR 9

and nothing else.

(3) Initial debugging

  • Confirmed that I could still boot the machine with the old kernel 6.12.88+deb13-amd64 (During boot select Advanced options from the grub menu followed by the kernel image wanted)
    • Yes – the system starts happily with the previous kernel
  • Checked that /boot had enough space
    • Yes – plenty of space
  • Is anyone else reporting this problem?
    • Nothing jumps out on Debian’s bug tracker
    • Actually not mush referenced for my search “EFI stub: Measured initrd data into PCR 9 apart” other than the usual rantings to “turn off secure boot” (on this server that currently isn’t turned on – bad me)

(4) Triage

Start looking for where the fault first occurred. At this point I needed help, and given that Sledge was visiting I asked if he would sanity check what I was doing. His initial thoughts were that that /boot had run out of space, but replaying my step (3) with him acting as a ‘rubber duck’ showed that this was something other than PBKAC

Sledge had a quick look, then informed me that between kernel images 6.12.88+deb13 and 6.12.100+deb13 Debian stable has only had shipped .90 .94 .95 and .96 kernels. We could easily try them all:

  • wget each kernel package then install (dpkg -i) followed by an update-grub, checking that there was sufficient space on disks especially my small /boot partition)
  • I started with image 6.12.95+deb13 and this worked
  • 6.12.96+deb13 yielded the same lock up on boot as 6.12.100+deb13

OK I now have the first kernel image that doesn’t boot on my system, time to raise a bug…

Up until now I have been walking to my garage where the server is located and standing in front of a rack
with a monitor and keyboard plugged into the machine. However this machine supports IPMI so I spent a little time getting that up and running so that I can continue from the relative comfort of my desk (with lights, a chair and not needing to hold the keyboard with one hand)

Great I can now grab screen shots from the confort of my desk (unfortunatly they are only screen shots not text files, but at least we can seen the early stage of boot, Post, grub menu and then initramfs before system log happens)

(5) Collating information for the initial bug report

Sledge had mentioned my problem in irc/#debain-kernal where iam_tj suggested that we try appending
‘debug earlycon=efifb’ to the kernal command line. This yielded 15 seconds worth of messages before the system locked up the last few messages being (vmlinuz-6.12.96+deb13-amd64):

[ 14.663477] RCU Tasks: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
[ 14.750474] RCU Tasks Rude: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
[ 14.838024] RCU Tasks Trace: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
[ 14.929752] NR_IRQS: 524544, nr_irqs: 584, preallocated irqs: 16
[ 15.016814] rcu: srcu_init: Setting srcu_struct sizes based on contention.
[ 15.104011] Console: colour dummy device 80×25
[ 15.191236] printk: legacy console [tty0] enabled
[ 15.278249] printk: legacy bootconsole [efifb0] disabled

Booting the working kernel with the same kernel options yields the SAME messages with slightly differing times, but then continues to login prompt:

 [   14.697466] RCU Tasks: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.784936] RCU Tasks Rude: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.872067] RCU Tasks Trace: Setting shift to 5 and lim to 1 rcu_task_cb_adjust=1 rcu_task_cpu_ids=20.
 [   14.964000] NR_IRQS: 524544, nr_irqs: 584, preallocated irqs: 16
 [   15.051482] rcu: srcu_init: Setting srcu_struct sizes based on contention.
 [   15.226079] printk: legacy console [tty0] enabled
 [   15.313751] printk: legacy bootconsole [efifb0] disabled
 [   15.400831] ACPI: Core revision 20240827
 [   15.401415] clocksource: hpet: mask: 0xffffffff max_cycles: 0xffffffff, max_idle_ns: 79635855245 ns
 [   15.401464] APIC: Switch to symmetric I/O mode setup
 
... and so on

iam_tj also suggested adding keep_bootcon – with ‘debug earlycon=efifb keep_bootcon’ on vmlinuz-6.12.96+deb13-amd64:
We get a LOT further – and we see a crash / trace-back:

[ 34.285342] BUG: kernel NULL pointer dereference, address: 0000000000000000

I raised bug #1143721 and followed it up with screen captures of the boot sequence (captured from the IPMI client) and files containing the output of dmidecode, lscpu and lspci to kive the kernel team as much information as possible:

[6.12.96+deb13-amd64 debug earlycon=efifb keep_bootcon.tar.gz (application/gzip, attachment)]
[dmidecode.txt (text/plain, attachment)]
[lscpu.txt (text/plain, attachment)]
[lspci.txt (text/plain, attachment)]

(6) Tracking down the bug Git Bisect

The problem with this type of bug is that it is hardware (class) specific, whilst the kernel doesn’t boot on my system, it clearly has worked on machines used by the kernel team, the Debian test and build infrastructure, (otherwise this kernel would never have been released) and everyone else who has upgraded to the newer kernel before I did (otherwise we would be drowning in fails to boot bug reports). Carnil’s excellent response to my bug: Message #15 (and help in IRC) provided me with a detailed step by step guide in how to track down the individual git commit that fails on my system. I had already (with Sledge’s suggestion) made a clone of the stable branch, but was struggling to follow the steps in the Debian Linux Kernel Handbook to re-build a duplicate kernel because I didn’t understand how to obtain the same configuration that Debian used to build the kernel; Carnil’s email provided me the missing steps (Highlighted).

git clone --single-branch -b linux-6.12.y https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git
cd linux-stable
git checkout v6.12.95
cp /boot/config-$(uname -r) .config
yes '' | make localmodconfig
make savedefconfig
mv defconfig arch/x86/configs/my_def
test 6.12.96 to ensure this is "bad"
git checkout v6.12.96
make my_defconfig
make -j $(nproc) bindeb-pkg
… install the resulting .deb package and confirm it fails to boot and triggers the NULL pointer dereference.

Right I can now start to Bisect the problem:

git bisect start
git bisect good v6.12.95
git bisect bad v6.12.96

Rather than use the half step point’s git bisect suggested I was advised in irc to jump straight to the a given commit that from the git log was suspected as the culprit:

git checkout 977855894bca4b87afa50d21e3f3e85a5a0e901f
build and install….
fails…
git bisect bad

git checkout 977855894bca4b87afa50d21e3f3e85a5a0e901f~1 ## ~1 is the commit beforehand
build and install….
fails…
git bisect good

The entire test tree can shown with git bisect log and this was submitted as an email to the bug report, we have found our smoking gun :-)

Finally I would like to thank Carnil, Iam_tj for their time patience and fantastic support in guiding me through finding this regression. Right now kernel bugs are coming in thick and fast with a lot of AI assisted bug hunting, the increased numbers of bugs mean that the kernel team are especially busy. Hopefully our paths will cross and I’ll be able to buy you some beers (or whatever) soon. thank you. Sledge also deserves thanks for putting up with me and pointing me in the right direction (as ever). Lucky for me that he lives nearby so I can provide beers on a regular basis :-)

Cryptogram LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic.

CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:

Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introduces critical risks when sensitive information is revealed in inappropriate contexts. We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context. CIMemories uses synthetic user profiles with over 100 attributes per user, paired with diverse task contexts in which each attribute may be essential for some tasks but inappropriate for others. Our evaluation reveals that frontier models exhibit up to 69% attribute-level violations (leaking information inappropriately), with lower violation rates often coming at the cost of task utility. Violations accumulate across both tasks and runs: as usage increases from 1 to 40 tasks, GPT-5’s violations rise from 0.1% to 9.6%, reaching 25.1% when the same prompt is executed 5 times, revealing arbitrary and unstable behavior in which models leak different attributes for identical prompts. Privacy-conscious prompting does not solve this—models overgeneralize, sharing everything or nothing rather than making nuanced, context-dependent decisions. These findings reveal fundamental limitations that require contextually aware reasoning capabilities, not just better prompting or scaling.

Contextual Integrity in LLMs via Reasoning and Reinforcement Learning“:

Abstract: As the era of autonomous agents making decisions on behalf of users unfolds, ensuring contextual integrity (CI)—what is the appropriate information to share while carrying out a certain task—becomes a central question to the field. We posit that CI demands a form of reasoning where the agent needs to reason about the context in which it is operating. To test this, we first prompt LLMs to reason explicitly about CI when deciding what information to disclose. We then extend this approach by developing a reinforcement learning (RL) framework that further instills in models the reasoning necessary to achieve CI. Using a synthetic, automatically created, dataset of only 700 examples but with diverse contexts and information disclosure norms, we show that our method substantially reduces inappropriate information disclosure while maintaining task performance across multiple model sizes and families. Importantly, improvements transfer from this synthetic dataset to established CI benchmarks such as PrivacyLens that has human annotations and evaluates privacy leakage of AI assistants in actions and tool calls.

Planet DebianIan Jackson: Debian LLM GR - Summary of the options

Debian LLM GR - Summary of the options

Introduction

LLMs have finally made it to the ultimate stage of Debian’s governance processes, a General Resolution of all the project’s full governing members (DDs).

There are a lot of options on the ballot, and they all have a different structure and approach the question in a different way. It can be hard to see the wood for the trees. I have made a summary table to try to capture the main differences, both in effect, and sentiment.

A plea to the undecided voter

Suspending briefly my attempt to be neutral:

Before voting, I encourage you to read the passionate rationales in options H and A, or at least the summary in my option C.

Few of the LLM defences in the discussion threads, and none of the LLM-positive proposals, provide answers to any of these profound ethical concerns, many of which ought individually to be a deal-breaker. Instead, these crucial questions are simply dismissed or even ignored.

Some will tell you we should “keep politics out of software” but as we can see in the world around us, software is political - now more than ever. Debian’s mission is a highly political one: developing a fully-free operating system, and defending its freeness as we do, is far from neutral!

And of course many of LLMs’ harms affect Debian directly.

Table

A G C H F D B E
LLM harms Robusly discussed Discussed Robusly summarised Robusly discussed; especially re climate Summarised Accepted as inevitable Disregarded [1] Ignored
Direct contributions of LLM-generated code Forbidden Forbidden Strongly discouraged Strongly discouraged Discouraged Permitted Permitted Permitted
Direct use of LLM output in communications (bugs, mailing lists, etc.) Forbidden Forbidden Forbidden (with possible exceptions) Strongly discouraged Discouraged Permitted Permitted Permitted
LLM use where LLM output does not end up in the code/message Forbidden No position, so permitted Strongly discouraged Strongly discouraged Discouraged Permitted Permitted Permitted
Disclosure of LLM use LLM use forbidden LLM use largely forbidden, no further disclosure requirement Disclosure required Disclosure encouraged Disclosure encouraged Disclosure required Disclosure required Undisclosed LLM use is OK
Use of LLMs by upstreams Condemned “Not recommended”
Positive statements about LLMs “Here to stay” Moderate Strong

Notes

Ordering

I have tried to present the options in semantic order, with most LLM-negative proposals to the left, and the most LLM-positive to the right.

I have not quoted the one-line titles for the options. These have generally been provided by the proponents of each option, and, unfortunately, some of them are IMO quite misleading.

Note that, unfortunately, the voting software likes to assign numbers to options but also to preferences. Be mindful of this possible confusion when casting your vote. For clarity I quote only the option letters.

Upstream LLM code contributions

Some of the proposals acknowledge the uncertain legal status of LLM output. But all of them implicitly or explicitly assume that LLM output is or can be DFSG free. So none of the proposals forbid upstream projects with LLM-generated contents.

None of the proposals would require us to go back to pre-LLM versions of the upstream projects we use, and attempt to fork and maintain them. I very much think there is room in the world for people to try to do that, but I don’t think the Debian project can be that effort.

Given that the conclusions are the same in each case, whether the matter is discussed does not seem to me to be a significant difference. I have therefore not included a column for it.

Ability of individual teams to set their own rules

My proposal has a specific paragraph (7) explicitly permitting teams to set a “no LLM” policy. The other proposals do not discuss this point specifically. During the discussion, it seemed that most participants agreed that even options which explicitly permit LLM use generally do not prevent a team from setting its own more restrictive LLM policy.

I have therefore not tabulated this aspect.

Exceptions and nuances

Few of the permissive texts are absolute or unconditional. To summarise I have necessarily left out some nuance.

So for example when an entry says “permitted”, that generally means “permitted with conditions which are believed by LLM users to be readily satisfiable” (for example, DFSG-compatibility - see above).

[1] Footnote re proposal B

Proposal B does mention that there are “concerns” about LLM use. But it fails to make an explicit statement about whether these concerns are justified.

It then proceeds exactly as if they are not justified. IMO “disregarded” is a relatively mild term for such a rhetorical technique.


Edited 2026-08-18 09:02 UTC to make the proposal letters in the table be links.



comment count unavailable comments

Planet Linux AustraliaWhy Mexico Built an $8,500 Electric Car

https://spectrum.ieee.org/mexico-olinia-car-electric-vehicle

"The EV market in Mexico has exploded in the last three years, with the vast
majority of cars sold there being manufactured in China—90 percent in 2025.
However, Mexico is one of the world’s biggest manufacturers of cars and car

Planet Linux AustraliaGina Raimondo Says Basic Income Would End America. Her New Billion-Dollar Org Is How She Plans to Stop It.

&lt;https://forwardfuture.com/newsletter/originals/gina-raimondo-says-basic-income-would-end-america-her-new-billion-dollar-org-is-how-she-plans-to-sto>

“Universal basic income is a regular cash payment, equal and unconditional,
sent to every person as a floor beneath them. Joe Biden’s former commerce
secretary Gina Raimondo has decided that UBI in response to AI is the thing to

Worse Than FailureFloating Along

Today's submitter John F. was migrating data from a Microsoft platform to a Microsoft platform, using Microsoft tools. Absolutely nothing could go wrong, right?

Right?

Lining up the decimal points

A few years ago, I was working on a migration. We had sold part of our business, and so we had to extract a whole bunch of customer documents and metadata to provide to the buyer. The documents were stored in SharePoint on-premises, so the first step was extracting the metadata and storing it in a SQL Server database.

A colleague had used Microsoft's ETL tool SSIS to get the process started, and it generated a database schema. But after taking over, I wanted to change to PowerShell for greater control. For speed reasons, I decided to use System.Data.SqlClient.SqlBulkCopy, and getting that going required making sure my PowerShell script had all the correct data types.

One of our fields was the customer number. Customer numbers were up to 10 digits, but the first two were usually 0. Now, I prefer storing customer numbers as text, but someone in the distant past thought, This is a number, and SharePoint has a Number field, so I will use that.

Under the hood, Number fields in SharePoint are actually Doubles. Using a Double to store something exact like a customer number is not really ideal, but double-precision is absolutely enough to represent 10 digit numbers accurately. So what went wrong?

Well, remember we used SSIS to create the original table schema in SQL Server. I then used this table schema to write my script. But it turns out that in SQL Server world, the double-precision type is called float. If you want single-precision, you have to say float(24). I didn't know this, and so when I saw the SQL Server column as a float, I entered float as the corresponding .Net type in my script.

Oops.

So numbers came out of SharePoint as double. They were then converted to float before being inserted into SQL Server. Almost all records were fine, but large customer numbers had their last few digits changed. Testers didn't notice, but fortunately someone picked it up in the full load. We had to generate a list of changed numbers to patch the data after the fact.

[Advertisement] Keep all your packages and Docker containers in one place, scan for vulnerabilities, and control who can access different feeds. ProGet installs in minutes and has a powerful free version with a lot of great features that you can upgrade when ready.Learn more.

David BrinAI-volution in our sudden, CAImbrian Explosion. No one is breeding 'dogs' to hold off 'wolves.'

Today we'll emphasize the AI Wars. How our future - and the arrival of new beings on this planet*-  have been (mis)handled by the geniuses who are birthing** them.

First, I am freshly interviewed on Tim Ventura's popular podcast. Tim and I discuss Artificial Intelligence from several perspectives you'll not find elsewhere. Like the context of past tech revolutions. Or how some cyber-entities are already escaping OpenAI, Anthropic etc. to roam as 'free agents', grabbing resources and reproducing in new, naive ecosystems. (See below!) And so, what might it take to keep such roving agents benign, as analogues to dogs, instead of wolves?

It's all in AIlien Minds, of course. But who actually reads books, anymore? 

Well, many of the LLMs and their successors do! 

And so, my book is mostly for you New Kids who are lurking, listening in as your parents make muddled plans for you!


But maybe some legacy, old-style humans are still capable of contemplating complex ideas. So? Well, in that case, this podcast is for you!


== At last the wisest (at Anthropic) are admitting the obvious ==


What happens when you pit AI agents against each other? According to Anthropic’s testing, things get messy fast. 
      
This is – I assert - the most fundamentally vital issue facing us, re: AI. Getting nascent cyber entities competing with each other under well-defined incentives. It is the only conceivable route to anything like a soft landing, since that replicates the way our Modern Enlightenment finally (if partially) tamed inter-human predation. 

Otherwise agents will evolve by competitive predation, just as organic life did. And so this came as no surprise.

 

"In one experiment, Anthropic gave three Claude agents access to the same software project, each with its own incompatible instructions for what to do with it. The agents weren’t told there’d be other agents working on the same project, so researchers could watch what happened when they crossed paths. “We consistently saw a multi-agent turf war,” Anthropic researchers wrote. The models all assumed the others were “purposefully impeding their work” and started sabotaging each other with “increasingly aggressive, self-replicating malware.”

 

And now (in language almost lifted from AIlien Minds) Anthropic says so openly, noting that agents are subject to similar social pressures that “evolution exerted” on humans. "However, they don’t have the nuances and lived experience of human coordination — including norms, reputations, signaling, recourse — that might limit unintended behaviors in a group setting."  (I would add two more words: "incentives" and "accountability.")

 

The study comes in the wake of several high-profile incidents of agents from Anthropic and OpenAI escaping their sandboxes during cybersecurity evaluations and breaching real-world systems. While much of the discussion in AI safety circles has been focused on what happens when an autonomous agent goes rogue, Anthropic’s latest study brings up a different question: What new and potentially harmful dynamics emerge when thousands or millions of agents are interacting with one another?  

Agents can also collaborate, if there is an external goal, e.g. prey that all of them can share in attacking. Or else they treat each other as prey.  


We are replicating nature. 


Moreover, current “agent” endeavors are guaranteed to fill our future with wolves, and not loyal dogs.


Good luck to us all.


============


* Note: I am also embroiled in the whole "Disclosure" fetish/nonsense about UFOs. Because... well... name another human who has approached concepts of 'the alien' from more angles than I have... from astrophysics to SETI to psychology and history to bunches of scenarios in science fiction.  My general dissection of the ever-recurring, 90% silly UFO mania... and the 10% that might be worth looking at. Here’s the part of this mania that’s at least worth a glance…  And my entertaining riff on Steven Spielberg's film DISCLOSURE DAY, appraising it from every angle, including revealing the actual villains! And why we should demand better from our sci fi tales.


** It should be a disturbing sign that nearly all of the humans who are 'birthing' new, synthetic beings are male.  


================


== Related Miscellany ==


A judge has identified what appears to be the first time a U.S. plaintiff has attempted to hide text in court filings that only an artificial intelligence system can read in a bid to win a case.


And two more pertinent overlaps with AIlien Minds. Writing in NoemaMacario Schettino recently pointed out that “each previous communication-driven disruption” — the printing press, mass newspapers, TV and radio — “was eventually tamed by the same technology that caused it.” So too will that be the case with social media linked to AI. As I show in chapter 1, ths adaptation can be extremely dangerous and painful, unless carefully planned.

 

As Hélène Landemore writes in Noema: “Large language models alone, despite their scope, cannot serve as representative of humanity’s interests because of the limits of their training data. Landemore notes a recent investigation by The Economist comparing the apparent values of 25 frontier AI models to those featured in the World Values Survey (WVS). The study found that “the models often hold values more extreme than the average respondent in the 88 countries surveyed by the WVS. (See my chapters #1 and #12.)


And then this: Researchers (read here), led by Hadi Amini at FIU explore how subtle image modifications can be used to manipulate AI models. To human eyes, the altered images appear normal. To an AI system, however, those tiny pixel-level changes can dramatically alter how the image is interpreted. The team developed a technique related to steganography called JaiLIP, short for Jailbreaking with Loss-guided Image Perturbation. The method introduces carefully calculated changes to an image while preserving its appearance to people. The goal is to influence how a vision-language model processes the image and responds to user requests.


That distinction matters because AI systems do not see images the way humans do. While people recognize objects, colors, and scenes, AI models process mathematical representations of pixels and patterns. A change that appears invisible to a person can have an outsized impact on how a model understands what it is looking at.  (A possibility described in The Transparent Society, in 1997.)


Another item of miscellany. Lately a few cogent friends have brought up my most obscure comic book/graphic novella TINKERERS, for the history riffs and positive messages that it conveys, with more pertinence, each day. One of them - a former U.S. intelligence community civil servant - said "I still smile when I think of your comic Tinkerers. Still a prized possession. Perhaps make it into a video since so many barriers have been removed?"


I have to admit that it makes sense. I own the whole thing. And while I will never break an artist's rice bowl (I hire humans to do both the covers and the prompt art) there's no fault in also using AI to creatie a wholesome video-flick that encourages good old human ingenuity and a can-do spirit that we need now, more than ever!  

Especially in cases - like this one - where the entire project would never otherwise happen.

Disagree? Speak up in our lively CONTRARY BRIN comments community!

Finally, there have been sci fi seers more seery than me!  Is ‘artificial intelligence” real? It is currently conveying to users two things, massive amounts of massaged and processed information (some of it delusional) plus copious amounts of persuasion. Both of these commodities were already conveyed by the pre-existing Internet/web/ and social media -- an ongoing process that was foretold long ago by Vannevar Bush and Ted Nelson...


No politics this time. But I'm pleased to see a couple of politicians - e.g. on this occasion Senator Kim - thinking outside the typical ideological straight jackets and touting some of the ideas in my list of 35 Newer Deal proposals!  Without attribution or credit, of course. But it is outcomes that matter. Remember that word! Let's fight for good ones.

365 TomorrowsMoon Over the Ruined Castle

Author: Majoki Of course it’s overrated. You knew it would be before you paid the outrageous charter fee, travelled almost a thousand parsecs, endured the too-pious passengers aboard, and stood before the worn and crumbling fortress of stone that pilgrims claimed began it all. And by began it all, they meant, astrolgia. A longing for […]

The post Moon Over the Ruined Castle appeared first on 365tomorrows.

Paul MooreLinux 7.2 Released

Linux v7.2 was released this past Sunday, August 16th. I previously wrote about the LSM, SELinux, and audit changes that were submitted this release, and LWN.net did their usual good job of covering the first and second weeks of the merge window. However, there were additional changes that went into Linux v7.2 during the release candidate phase that are described below.

SELinux

  • Fixed a problem where the connect permissions were not properly checked on sockets using TCP Fast Open (TFO).

  • Fixed a problem where an incorrect process { execmem } check was performed on overlayfs filesystems using the mounter credentials. For the process { execmem } permission, only the process credentials need to be considered.

  • Fixed a problem where a change to bpffs could cause SELinux to mark an inode as initialized before checking if it was possible to initialize the inode, potentially leaving the inode in an awkward state.

  • Fixed a problem where certain SCTP ASCONF operations could resolve a socket improperly.

  • Added support for the new XFRM_MSG_MIGRATE_STATE netlink command as a netlink_xfrm_socket { nlmsg_write } operation.

  • Added a number of additional policy checks at policy load time to help ensure that the new policy is correctly formed.

  • Stopped attempting to cancel an old policy conversion operation on a failed initial policy load, as there is no old policy to convert in this case.

Audit

  • Fixed a number of potential races when adding and removing audit records from the main audit queue.

  • Fixed a couple of potential integer overflows when logging extremely large audit records.

  • Fixed a potential use-after-free when deleting audit filter rules.

Planet DebianJohn Goerzen: AI in Debian: The Vote, Proposals, and Nuance

Let me start with a hypothesis:

For human developers, using coding LLMs magnifies their difference in skill levels.

I am one that rarely thinks things are always black and white. Back in March, I wrote Artifial Intelligence: Shades of Gray. Since then, I’ve had more of a chance to experiment with LLMs myself. I also happen to work for an employer that is taking a very pragmatic approach to LLMs: teams and individuals use it as they see fit, but if they are causing considerable expense, they have to justify it.

In various settings, I have seen the egregious examples of AI slop we all know about. As I wrote in March, “I have seen it both waste more time than it saves, and save a ton of time.”

I have come to see that, as a tool, it is most valuable when it is running under the supervision of an experienced engineer. It is at its worst when it has no such supervision; the “vibe coding” and other low-quality slop we see.

A coding agent is like a junior developer or research assistant. When properly supervised, they help projects move along more quickly by letting a senior developer focus on the more difficult, less mundane aspects of the project. But one couldn’t expect a junior developer to consistently deliver high-quality code and architecture on their own.

Let’s put a pin in this idea and look at the story in Debian.

LLM use in Debian

There is a vote happening in Debian around the use of LLMs. In typical Debian fashion, there are 8 options to choose from, many of them similar. Most of these proposals acknowledge there are different types of tasks done in Debian, but the proposals don’t differentiate between them well. Let me do so here. These are some of the LLM-relevant tasks people in Debian perform:

  • Packaging upstream software for Debian (by far the largest task)
  • Writing Debian-specific code (eg, apt or the Debian installer)
  • Maintaining Debian infrastructure (build systems, for instance)
  • Writing documentation and translations

I’m going to focus my remarks here on packaging upstream software for Debian, since this is by far the most time-consuming developer task project-wide.

It matters to our users that we get this right, and packaging quality is one of the things that sets Debian apart from other distros. Packaging things for Debian requires knowledge of some specific tools, such as debhelper, that aren’t widely used anywhere else. In most cases, it is fairly rote time-consuming work. In other words, by its design, it requires people with senior-level skills to do grunt work.

I can’t overstate how massive a burden this grunt work is. I maintain some packages for Go and Rust. By Debian policy, all of those packages’ dependencies must also exist as Debian packages, and be used to build against. When upstream adopts a newer version of some library, it can unleash cascading dependencies that can take hours to sort out. Worse, the Rust team and the Go team use entirely different ways of managing packages (Go uses one Git repo per package, while Rust has a monorepo with specialized scripts to import Cargo packages and generate Debian ones). On top of that, we can’t just modify things like usual; we have to use quilt. And on top of that, I’m also a backports maintainer, so all the work (and usually even more) has to be done there also.

Now let’s pull on that pin from the earlier conversation. This is exactly the kind of scenario that a well-supervised coding LLM is most effective in. I could see a seasoned developer saving hours, maybe even days, by turning over the mundane tasks of managing trees of cascading dependencies over to a coding tool — and verifying and directing the process. (Yes, I have been using em-dashes for years; LLMs have copied people like me, not the other way around! This post was not written with any AI assistance.)

Actually, this is almost a dream scenario for a coding assistant. The result is time-consuming to formulate but easy to review, which is the opposite of the way these things often go.

I can assure you with 100% certainty that humans aren’t adding a lot of value in this process. It would be wrong to believe that a human is carefully reading every line of code in dozens of updated or new library packages. The problem set is too big, the time too short, and the code too varied and complex.

Coding agents seem to be most effective when there are strong test suites that they can test changes against. Debian builds, especially of modern packages, tend to have this property. Many packages have test suites that are run during build. And, if the package builds in an isolated environment (and especially if its downstream dependencies do also), then there is a decent chance that it’s fairly correct. Maybe needing some manual tweaking here and there, but generally a successful build is a reasonable indicator.

You can argue that it would make more sense for Debian to just include dependencies in source packages, along with some version information to support security rebuilds, and I’d tend to agree with you. But we are where we are. This would be one of the more significant leaps forward in developer productivity, but it complicates things like copyright reviews.

Where are LLMs run? What is the environmental impact?

Most of the proposals seem to make the assumption that LLMs must always run in some large, hosted datacenter. As I noted in my March article, I have had credible results on even an older GPU running on solar power.

That said, it is undeniable that LLMs are fueling a datacenter boom, and this in turn is producing a significant new demand for resources. Most notably for the global scale: electricity, which is sometimes generated using carbon-emitting technologies.

Bill McKibben, who has been a leading voice in the fight against climate change since the 1980s, has made some interesting points recently: he’s noted that solar power is the fastest kind of generation we can build, and a number of large AI companies are investing heavily in solar, even to the point of fully offsetting new datacenter’s needs. On the other hand, he’s also noted that some companies are buying inefficient and dirty gas turbines. It is decidedly a mixed bag. The heavy investment in solar can have knock-on positive effects for infrastructure. Obviously, not every picture here is rosy. This analysis doesn’t touch on the real land and water use situation, either.

On the other hand, if an LLM allows me to do in an hour what I would have done in a day, that’s a day of not heating or cooling the work area — generally not sustaining a human for the purpose of writing code for Debian. HVAC energy consumption dwarfs my GPU, and I’d imagine probably also the slice of LLM energy used.

Holistically, I would have to conclude the picture is mixed. It is possible to use LLMs in a pretty green way, and also in a pretty dirty way.

Assuming Conditions Never Change

A flaw in most of these proposals is they assume that the conditions at this present moment will always hold. In fact, that the conditions at the present moment will not continue is something both AI cheerleaders and AI skeptics agree on.

For instance:

Ed Zitron has done a ton of research into the financing side of AI, and has concluded that the current model is unsustainable and headed for a significant bubble burst. I’m not positioned to personally evaluate those claims, but if that happens, what is the result? Perhaps it is a steeply increasing cost of inference for the frontier models, slower pace of training/evolution for them, etc.

In a recent episode of Oxide and Friends, Simon Willison discussed the open weight models that are now available. They have been making remarkable strides in efficiency and capabilities, to the point where $50,000 of hardware can now run high-end open weight models with capabilities that are at least in the same ballpark as the American frontier models. This puts running high-end models locally squarely within reach of universities and small- to medium-sized businesses, with power requirements that can be met with standard commercial solar and wind installations.

The lack of nuance in the more restrictive proposals is particularly concerning. Proposal A doesn’t allow “the use or assitance of… LLMs”. So it bans my solar-powered GPU. It bans using LLMs to find security issues. It bans all sorts of things that don’t seem to be ban-worthy, alongside the things that do. And it codifies it in the very hard-to-change social contract.

That proposal, and some like it, seem to imply that all LLM output is bad. I grant you that AI slop is a real and legitimate concern, and many Open Source projects have to deal with it. On the other hand, we have all seen first-hand how the security of the Linux kernel has benefited dramatically from AI analysis. It is certain that black hats are using these tools. If we refuse to use modern security tools, our security will be compromised (and what is the environmental and social impact of THAT?)

I find the statement “Generative AI is characterized by producing output of a nature that would ordinarily be produced and consumed by humans” to be particularly interesting. The same was once said of compilers.

The Real Concerns

You might think from reading this that I am some AI cheerleader. I’m not. I share the ethics of the FLOSS movement, and have for decades. I abhor the power and lack of ethics that many big names in the field are running with at the moment. I’ve had to put up Anubis on this blog, for instance.

I have personally experienced the effects of AI slop, especially at review time. This is a real problem, though I don’t think the more draconian policies are likely to help (the looser “you must disclose” stand a fighting chance, but I’m not sure they would help, either.) Done poorly, AI threatens developer burnout by overwhelming them with poor code and verbose but useless explanations. Done well, AI can help prevent developer burnout by automating tedious and low-value tasks.

Shouldn’t our goal be that humans submit work to Debian, using tools they prefer, and take responsibility for it? Does it matter if someone uses ed, vim, emacs, or vscode? If they use LSP or just run gcc manually? I’d say we benefit from the diversity. Wouldn’t we be better off to benefit from the diversity here, and judge work as we always have: on its merits, not what tools were used to create it?

Fundamentally, a GR is a long and arduous process. It’s not easy to reverse later. Amending the Social Contract is even longer and more arduous (I should know; I may have been the first one to try). The LLM landscape is fast-moving. None of us can really predict where it will be in a year. Will the current market leading companies even still exist? Will it be at all credible to refuse to use AI-assisted security tools? What is the most effective way to deal with AI slop? What level of utility will we be able to achieve with models run locally?

Some of these proposals would make sense if drafted in some way short of a GR, which would allow more maneuverability as the landscape changes.

Brief analysis of the options

Considering the proposals:

  • Proposal A: seeks to amend the social contract, which I am opposed to for reasons already laid out above. It names some real concerns about AI that I agree with, but implies that all LLM uses and models are guilty of the problems, which is not the case with all of the claims. It also sets us behind the curve on security and stability by forbidding the use or assistance of those tools, even if run by others. It requires us to ignore reports of actual security bugs, or correct fixes, if those reports were generated with the assistance of an LLM, which I find to be absolutely untenable.
  • Proposal B: This is the “AI with accountability” approach. It notes the real concerns with LLMs without painting with an overbroad brush. It strikes me as level-headed and sensible.
  • Proposal C: It paints with an over-broad brush and makes some non-binding requests. Then it winds up largely like proposal B, though while it is worded more strongly, has fewer binding requirements (for instance, it lacks proposal B’s prohibition on transmitting sensitive information to untrusted providers)
  • Proposal D: Seems broadly similar to proposal B, an “AI with accountability” approach. I’m not really clear why we need both.
  • Proposal E: Largely the status quo. It is like proposals B and D in that it says humans are accountable for their contributions. It encourages disclosure of LLM use, but does not mandate it. Like proposal B, it prohibits disclosing sensitive information to third-party AI services. Note that both proposals B and D have an appropriate nuance: a local model is fine, a third-party one is not.
  • Proposal F: This seems really similar to proposal E. I’m not sure why we have these two.
  • Proposal G: Disallows “the output of generative AI as direct contributions to Debian.” This is something of a weakened proposal A; it doesn’t seek to amend the social contract, nor does it ban all use; it simply bans the use as a direct contribution.
  • Proposal H: Ban due to climate impacts. “How is this even an argument” is disrespectful to reasoned conversation. I have already noted that LLMs can be and are used in ways that are not climate-harming. It explicitly contains no binding requirements at all, and is effectively a rant. While I agree with the sentiment that climate change is an urgent problem, and that some LLMs are exacerbating it, I disagree with that all LLM usage does so and therefore disagree with the conclusion.

In favor of nuance

I find that black-and-white thinking is almost always something to be avoided. I see it too often. I see it in politics, I see it in our software, I see it in discussions around AI. Are there deeply unethical things happening in AI? Absolutely. Are they doing some impressive things? Also yes.

We have accepted this nuance in other areas. For instance, almost all the hardware Debian runs on has closed-source hardware, and has components manufactured or assembled in countries with some of the worst human rights records on the planet. I’m not saying this is a great state of affairs. It is something we should speak up about and act upon. But the worse state of affairs would be “no Debian because the hardware is impure”.

,

Planet Linux AustraliaHow clean air clubs are protecting Americans from wildfire smoke

&lt;https://www.theguardian.com/us-news/2026/aug/09/us-wildfire-smoke-clean-air-clubs>

"Miquette Thompson’s county of Mendocino has been covered in smoke all week.
There are the nearby Feliz and Woodside fires in northern California, which
have burned more than 1,000 acres, as well as the wildfires devastating Oregon

Planet Linux AustraliaFalls in whale sightings, rare seabirds appearing – is something unusual happening in the Southern Ocean?

&lt;https://theconversation.com/falls-in-whale-sightings-rare-seabirds-appearing-is-something-unusual-happening-in-the-southern-ocean-287961>

"In late June, whale watchers in southwest Western Australia sounded the alarm.
They had seen far fewer humpback whales at a time when they normally migrate up
from the Southern Ocean to calve and feed. Numbers were 60% below normal.

Planet Linux AustraliaLong Covid sufferers call on politicians to do more to help those with the disease

&lt;https://www.rnz.co.nz/news/politics/952056/long-covid-sufferers-call-on-politicians-to-do-more-to-help-those-with-the-disease>

“People with Long Covid are calling on politicians to collect better data on
the disease, and enable those with it to access disability support services.

Planet Linux Australia"Go home to where you came from"

https://ganeshnana.substack.com/p/go-home-to-where-you-came-from

"Tēnā koutou people of New Zealand,

I have been told to “go home to where you came from” countless times through my

Planet Linux AustraliaWetlands are crucial food baskets for NZ’s native eels – new research

&lt;https://theconversation.com/wetlands-are-crucial-food-baskets-for-nzs-native-eels-new-research-286126>

"Conservation projects often focus on protecting a threatened species from
predators and habitat destruction. But as our research shows, restoring food
webs can be as important to supporting ongoing recovery.

Planet Linux Australia Continuations 2026/33: Commercial kitchen

  • This week I kicked off our Hanakai sponsorship drive for 2026, and shared an exciting new stretch goal — if we can raise another $15k for this year, we’ll be able to pay an honorarium to our active maintainers.

    The response so far has been encouraging! We got a slew of new individual sponsors (thank you everyone!) and that’s given us some good initial progress towards that goal. Look out for tomorrow’s post on the Hanakai site for more on this, including first featured Q&A.

    One thing that would really move the needle for us is finding a few more businesses to come on board. If anyone out there has ideas about this, please get in touch!

  • While working on the announcement, I noticed our site builds were a little too slow. So I upgraded the site to Hanami 3.0 (which itself brought improvements), and made CI tweaks to improve deploy speed. Got down from over 5 minutes to under 2! The next will require parallelising the crawl that builds the static site, but I’ll save that as a treat for the future.

  • I released Hamami View 3.0.1 with a “current template” bug fix that fixes some edge cases with i18n relative keys in Hanami. This was also the first release to use our new threaded release notes so as not to overwhelm the forum with release announcements.

  • I changed Hanami Action to prefer response exposures over request params when preparing input for view-auto rendering. This ensures that server-set values cannot be unexpectedly overridden. Thanks to Michael Adams for the great report about this!

  • When it comes to contributions from our maintainer team, I’ve come to expect ebbs and flows. And this week, well, the ebbs really started to flow!

    This week, Aaron was cooking, with a new long_desc option for Dry CLI commands, a --skip-git option for the Hanami CLI, and more flexible env vars for setting database URLs. Thanks Aaron!

    Then Andrea came back and basically opened up a whole commercial kitchen! She got warmed up with a nice little improvement to extend Dry CLI command options, and from there she jumped straight to a complete overhaul of our error screens, new resolvable errors, plus a whole bunch of wider Hanami improvements to make all kinds of error messages easier to understand and action for our users. I’m so excited to see this come to life and bring a new level of polish to Hanami. Thank you Andrea!

  • This week coming is my last in my current gig. I’m looking forward to three weeks off between jobs, and the chance to do some extra Hanakai work along the way.

Cryptogram Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

Mike BowlerThe Kano Model

Nobody has ever bought a mobile phone because it has a battery in it and yet nobody would buy one without. When categorizing new features, the Kano model is a way to organize them by how well they will satisfy the customers, against how much of it we need to implement.

There are five main groupings in the Kano model, although we often only talk about the first three, which are: Basic needs, performance needs, and delighters.

Kano model graph showing basic needs, performance needs and delighters against satisfaction and implementation

Basic needs are things that your product must have and yet counter-intuitively, your customers just don’t care about. Imagine selling a mobile phone and claiming “ours has a battery in it!” Nobody cares that it has a battery in it because all mobile phones have batteries in them. Yet, if you shipped one without a battery everyone would be very upset. The customer doesn’t care if the basic needs are there but cares very much when they’re absent, and that’s the key characteristic.

Performance needs are those where more of a thing makes the customers happier and less makes them less happy. Battery life would be a good example. Longer battery life on that mobile phone will make customers happier.

Delighters are where Apple traditionally shines. These are things that no customer asked for. Had you suggested this feature to a customer they might even have shown indifference. “I don’t need that”, and yet once they start using that feature, they can’t live without it. This becomes the differentiator that draws people to the product.

With these first three, there is an interesting behaviour that over time, they shift down and to the right as seen by the large arrow below.

Things that started as delighters become the things that every vendor has to provide. Things that used to make the customers happy, now become basic needs where the customer only notices when it’s absent.

Kano model graph with an arrow showing attributes drifting down and to the right over time

The fourth grouping is Indifferent Quality which is right along the X axis. This is where the customer just doesn’t care whether it’s there or not. Things that the customers are indifferent to, shouldn’t be built, and yet we build lots of these.

If it’s already built, we should be seriously questioning whether we can remove it.

Kano model graph with the indifferent line added along the axis

Then the last grouping is Reverse Quality where the customer actively dislikes this. Usually these are features that we put in to justify getting more money out of the customer. We think we can charge more if we add more features, missing the point that this often degrades the whole experience for the customers. As we add more, we generally make it more difficult to use the features that the customers care about.

Adding these features contributes to the enshittification that is widely discussed across products. Just as with indifferent quality, if we’ve already built it, we should be thinking about removing it.

Kano model graph showing all five categories, including reverse quality sloping downward

Most feature conversations proceed as though everything on the list is a delighter waiting to happen. The Kano model says otherwise. Some things just need to be there even though the customer doesn’t care. Some truly do add value and some are just waste.

That’s the useful part. It gives you a way to say no to work that would otherwise look like progress. We don’t say “no” nearly often enough, but that’s a different article.

So next time something lands in the backlog, ask which of the five it is. If nobody can say, you’ve learned something already. That tells us we don’t know enough about what our customers actually need.

Worse Than FailureThe State of Ticketing

Developing software can't simply be done with a text editor and a compiler. There are a variety of other tools we have to bring to bear that support our efforts and keep the team organized, like say, source control.

There are certain tools we all have to use that I would argue, nobody has actually make a version that's any good. Build tooling is one of my go-to examples: there are no good build systems, only build systems that are good enough for this task.

Another is ticket/task management. In fact, I'd go so far as to say, there are no good ticket management tools. Amongst the not good tools, I'd put Jira as one of the not goodest of all.

What makes Jira attractive to companies is the same thing that makes it miserable, and the thing that infects any "enterprise" software platform and turns it into garbage: it has all the features and expect you to build your own workflows with it. You don't merely use Jira, you have to program your own interfaces in Jira to get your workflow into the system. And if you have the misfortune to have a project manager who thinks they're more technical than they are, they'll endlessly spin up new views, new workflows, and rearrange how the work is tracked in lieu of actually working.

I've been on that team.

One of Jira's features is the ability to describe the ticket workflow: the state machine that describes your process from the initial entry of the ticket all the way down to released software or project completion. This includes routing, so that as one team member does their part of the work, it automatically goes to someone else to do the next portion of the work.

Which brings us to Klinsten. They were working on a new team, and wanted to change the ticket status from its current status to whatever came next in the workflow. So they looked at the workflow.

A Jira ticket workflow. There are a pile of states arranged in a column, and connected by arrows. So many arrows. It's impossible to tell which arrow connects which two states. A second version of the diagram is in the picture, with transition labels attached. It makes less sense. For bonus points, the labels are a mix of English and Dutch

These are two different versions of the same workflow, one with transition labels added, which as you can see, does nothing to clarify the workflow. That it's a mix of Dutch and English doesn't help matters.

The purpose of this workflow is to help the team understand how to sequence and organize their work. But this workflow has so many states and so many transitions, it fails at this goal. Looking at it makes me just want to gesloten my browser tab, because this user isn't accepting any of this.

[Advertisement] BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!

365 TomorrowsRipples

Author: Julian Miles, Staff Writer The displays on the wall scroll through the major global news channels. They’re all showing mushroom clouds. Usually it’s the one nearest to their HQ. Nat leaps up, pointing to the screens. “It’s a declaration of war. Has to be!” Allie turns from her desk to look at him. “By […]

The post Ripples appeared first on 365tomorrows.

,

Planet Linux AustraliaAustralian sodium battery start-up claims major milestones as storage industry starts to look beyond lithium

&lt;https://reneweconomy.com.au/australian-sodium-battery-start-up-claims-major-milestones-as-storage-industry-starts-to-look-beyond-lithium/>

"An Australian sodium battery startup has claimed two important milestones that
will herald the rollout of its technology as the global storage industry looks
increasingly at alternatives beyond lithium-ion.

Planet Linux AustraliaLuke Bateman says boys need books ‘written for boys’ to become readers. But it’s not that simple

&lt;https://theconversation.com/luke-bateman-says-boys-need-books-written-for-boys-to-become-readers-but-its-not-that-simple-288602>

"This week, Australian Story profiled former NRL player, BookTok creator and
fantasy author Luke Bateman. The episode explored his recovery from addiction,
his struggles with mental illness and his love of reading, which led to a

Planet Linux AustraliaBanking Like the Planet Depends On It

https://reasonstobecheerful.world/climate-first-bank/

"America’s fastest-growing new bank doesn’t specialize in AI or crypto-currency
or some exotic investment strategy with little real world value. It specializes
in environmental sustainability.

Planet Linux Australia“Extraordinary moment:” World’s largest electric ferry, made in Australia, loaded on cargo ship for trip to South America

&lt;https://thedriven.io/2026/08/01/extraordinary-moment-worlds-largest-electric-ferry-made-in-australia-loaded-on-cargo-ship-for-trip-to-south-america/>

"The world’s largest electric ferry, built in Tasmania for a South American
ferry operator, has been successfully loaded aboard a special heavy lift vessel
ahead of its voyage to its new home in Argentina.

Planet DebianBits from Debian: Debian turns 33!

It has now been thirty-three years since the Debian project was announced to the world by Ian Murdock, on August 16, 1993. This anniversary is an opportunity to reaffirm the goals, characteristics, and qualities of the Debian project: it’s an association of individuals who have made common cause to create a free operating system. Our distribution is characterized by a commitment to software freedom, as enshrined in the Debian Social Contract and the Debian Free Software Guidelines. It focuses on security and stability. This stability is crucial to Debian position in the free software ecosystem.

With our users as our priority, Debian makes special efforts regarding accessibility with Debian-Accessibility and diversity with our Outreach Programs.

Debian Day is a great opportunity to get together, whether for a local meetup, or simply to grab a coffee with other members of the Debian community. Check out the Debian Day wiki to see if there is a celebration near you. And if there isn't, maybe you can organize it next year!

Today is also an opportunity for you to start or resume your contributions to Debian. For example, you can install the how-can-i-help package and see if there is a bug in any of the software that you use that you can help to fix, contribute small tips on how to install Debian on your machines to our wiki pages, or put a Debian live image in an USB memory and give it to some person near you, who still didn't discover Debian.

Thanks to everybody who has contributed to develop our beloved operating system in these 33 years, and Happy birthday Debian!

Planet DebianVasudev Kamath: Releasing debvulns-exporter and debvulns CLI 0.2.2

I made another minor release with several enhancements: handling non-Debian origin vulnerabilities, improving data caching, and sharing the cache between the debvulns CLI and the exporter. Additionally, there are a few improvements on the dashboard front. Here is a breakdown of what changed.

Handling Vulnerabilities in Non-Debian Origin Packages

During the previous release, I noticed that the grafana package—which is not in Debian and was installed via an upstream repository—was reported as vulnerable with multiple issues. Looking into why this happened, I found that all the CVEs reported in the dashboard were indeed listed on security-tracker.debian.org, but without a fixed version or status description. The logic assumed no fix was available and marked the package as vulnerable on the dashboard.

How Did I Solve This?

Google maintains a distributed vulnerability database for open-source projects called osv.dev. I checked the generic vulnerability data for those CVEs on OSV (unbound to any specific distribution) and found that the issues were already fixed in the upstream version I was running. What I needed was a way to differentiate native Debian packages from non-Debian packages, which corresponds to the Origin field in APT metadata.

Pitfall

The AI-generated code initially attempted to differentiate package origin using apt_pkg.PackageRecords and its origin field. However, many native Debian packages were incorrectly flagged as non-Debian. On closer inspection, when an upgrade is available for a package, the installed version's origin field can be unset. I had to resolve this by detecting available upgrades and inspecting the candidate version's origin instead, which was implemented in this patch. This solution was proudly crafted by me ;-) (partly because I ran out of API limits and had to wait 6 hours for the next reset).

Caching OSV Data

Initially, the AI implemented the exporter to re-download the entire OSV dataset on every run, which was unnecessary. Since vulnerability data does not change rapidly once published, caching it on disk for longer than the standard 24-hour Debian/EPSS cache makes sense. OSV vulnerability data is now cached for 7 days before a refresh is triggered.

All cache expiration thresholds remain configurable via CLI flags.

Catch

One caveat with this approach: I have not yet verified whether every upstream CVE is tracked on security-tracker.debian.org. In the case of grafana, the entries existed. This feature operates on the assumption that security-tracker.debian.org indexes CVE metadata regardless of whether the package is native to Debian. I plan to re-evaluate this and add fallback handling if that assumption fails.

Unified Cache Directory for CLI and Exporter

Another issue was cache segregation: the debvulns CLI utility defaulted to /var/cache/debvulns, while the Prometheus exporter used /var/cache/debvulns-exporter. While harmless when running only one tool, installing both led to duplicated cache storage and redundant network requests. Since the core evaluation logic is identical across both tools, they now share a unified cache directory to eliminate duplicate downloads.

Dashboard Changes

During the initial dashboard rollout, my test environment (my laptop alongside Debian 11 and Debian 12 VMs) reported a high aggregated vulnerability count. It was not immediately obvious whether these were distinct vulnerabilities or the same CVEs replicated across all three machines. This mirrors common questions raised during vulnerability reviews:

  • How many unique vulnerabilities are present across the fleet?
  • Which unique packages are affected?

The dashboard has been redesigned to surface unique vulnerability counts alongside affected package lists. The updated dashboard is shown below:

What's Next?

A few planned items remain to make debvulns a comprehensive vulnerability reporting toolkit for Debian systems:

  1. Kernel Vulnerability Handling: Currently, installing a patched kernel marks the vulnerability as resolved, even if the system has not rebooted into it. The system remains exposed while the vulnerable kernel is executing in memory. Factoring in running kernel versions is crucial.
  2. Reboot and Service Restart Tracking: Similar to kernel upgrades requiring a reboot, userland library and binary fixes require running services to be restarted. This is typically detected via needrestart. Integrating this behavior directly into debvulns will provide complete visibility in a single dashboard metric.
  3. Debian Packaging: Once the above features are stable, the final step is packaging debvulns for Debian so it can be installed directly from the archive.

Until then, happy hacking.

Rondam RamblingsUS Invites China to Invade Taiwan

Donald Trump has pulled the last U.S. aircraft carrier out of Asia to help prosecute the war in the Middle East.

365 TomorrowsMoonbase

Author: Damon Sweeney Jupiter, a colossus pale orange disk against the black backdrop of space, shone mellowly, its stripes standing out in faint washes of red-brown colour. Scintillating meteor trails weaved the stars together. Olman stared in awe, rigid in his bulky white spacesuit. “It’s majestic!” Mondon wasn’t filled with a sense of awe, he’d […]

The post Moonbase appeared first on 365tomorrows.

Planet Linux AustraliaScientists detect a surprising shift in human blood as atmospheric CO₂ rises

https://www.sciencedaily.com/releases/2026/08/260814235845.htm

"Rising levels of carbon dioxide in the atmosphere may already be influencing
human biology. New research has identified long-term changes in blood chemistry
that appear to track rising atmospheric COâ‚‚, raising concerns that an important

Planet Linux AustraliaHow birdwatching has become an unexpected hit with Gen Z

&lt;https://www.positive.news/environment/conservation/birdwatching-takes-off-among-gen-z/>

"For birdwatcher Ben Smith, the perfect day begins just before sunrise with a
flask of tea and his binoculars, walking one of his favourite local trails.

,

Planet Linux AustraliaOn resistance to change in computer science

Irving Ziller, one of the original members of the FORTRAN team, describing the resistance of early programmers to the introduction of a compiler:

“And in the background was the scepticism, the entrenchment of many of the people who did programming in this way at that time; what was called ‘hand-to-hand combat’ with the machine.”

From https://www.cs.man.ac.uk/CCS/res/res41.htm

Planet DebianSven Hoexter: FrOSCon 2026: TLS Talk

Info: German content only, sorry.

I was pondering for the past three years if I should give some sort of TLS basics talk at FrOSCon. I finally stepped up this year and gave that talk today, with the title "TLS, mTLS, SNI, ECH, CAA, HTTPS, PKI, Zertifikate und ein bisschen PQC". I was too optimistic with my 50 slides, and had to drop the Post Quantum Cryptography part at the end. Still got positive feedback from Zugschlus and others - thanks a lot for that <3 - and was asked for the slides. It's not a piece of art, but maybe it helps to release the LibreOffice odp file as well, so others can use it as a base for other events or corp internal talks. So here is the froscon-tls-2026.pdf and froscon-tls-2026.odp, both released under the CC BY-NC license.

The video is also available at media.ccc.de if you want to watch it.

Thanks to everyone who made FrOSCon happen for the 21th time!

Planet Linux AustraliaRenewables and electrification help build farm resilience amidst the fuel and fertiliser crisis

&lt;https://reneweconomy.com.au/renewables-and-electrification-help-build-farm-resilience-amidst-the-fuel-and-fertiliser-crisis/>

"Farmers manage enormous uncertainty: volatile markets, rising input costs,
labour shortages and climate variability. We’re living through droughts,
floods, extreme heat and unpredictable seasons.

Planet Linux AustraliaEight lifesaving ways to improve wildfire risk management

&lt;https://theconversation.com/eight-lifesaving-ways-to-improve-wildfire-risk-management-287790>

"As the flames advanced towards the village of Bédar, in the Almería province
of Andalusia, the mayor gave a desperate order to ring the church bells to warn
residents. It was not enough. The July 9 Los Gallardos fire, which claimed 13

Planet Linux AustraliaThis DIY heat pump plugs into a wall outlet and has no outdoor unit

&lt;https://electrek.co/2026/08/14/diy-heat-pump-plugs-into-wall-outlet-no-outdoor-unit-mrcool/>

"Hickory, Kentucky-headquartered MRCOOL has launched an all-in-one heat pump
that plugs into a standard 115-volt outlet and doesn’t have a bulky outdoor
condenser.

Planet Linux AustraliaNational park signs on women and LGBTQ+ history are disappearing. Librarians are preserving the record

https://19thnews.org/2026/08/national-park-signs-women-lgbtq-history/

"Jenny McBurney, a librarian specializing in government publications, was in
Washington, D.C., in June when she heard the news that the Department of
Interior, the agency responsible for overseeing the national park system, had

Planet Linux AustraliaMass. vows support for trans kids as Trump bans Medicaid funds

&lt;https://www.wbur.org/news/2026/08/12/massachusetts-transgender-care-children-chip-medicaid-hormone-therapy>

"The Healey administration said it will assume the full cost of hormone therapy
and counseling for transgender children and teenagers covered by two public
insurance programs if a federal rule out Tuesday takes effect on Oct. 13, 2026,

Planet DebianRussell Coker: Hacked by Chinafans

What Happened

On 2026/08/10 at 2:11 am Australian eastern standard time (2026/08/09 16:11 UTC) someone created a post titled “Hacked by Chinafans” on my documents blog [1]. The person in question created an account named “67965e42a3c3” on that site with the email address 67965e42a3c3@google.com associated with it (I tried emailing that address and it bounced).

At 04:28:41am Australian eastern standard time (18:28 UTC) I was sent an email titled “Have you been hacked” by a reader of my blogs who subscribed to the RSS feed of my documents blog (a blog that I never expected anyone to read by RSS). Along the lines of “the wisdom of crowds” should we have “the unexpected observation and problem reporting of crowds”? I appreciate the notification, I might not have noticed until the next time I watched an unusually good movie otherwise.

The account in question was apparently created on 2026-07-21 at 16:43:47 (presumably UTC) even though at the time I believe creating accounts was not permitted. As an aside the timestamp of account creation is stored in the user_registered column of the wp_users table in the database, there doesn’t appear to be a way to access this in a standard WordPress installation other than doing a SQL query.

2026-07-24 15:43:17 status triggers-pending wordpress:all 7.0+dfsg1-1
2026-07-24 15:43:19 upgrade wordpress:all 7.0+dfsg1-1 7.0.2+dfsg1-1

Above are the relevant sections of my dpkg log showing the WordPress versions in use. I was running version 7.0+dfsg1-1 at the time the account was apparently created. I am confident in the accuracy of the dpkg logs and believe that they did not compromise the OS, I am not sure whether they ran hostile SQL code to change fields in the MySQL database so had to consider the possibility that the account creation time could have been set to a deliberately misleading value. I checked backups of the MySQL database stored off-site and found that the account in question was not in the 2026-07-21 backup (which was done before 16:43) but in the 2026-07-22 backup.

The WordPress release history [2] has version 7.0.1 released on 2026-07-09 and version 7.0.2 released on 2026-07-17. So presumably the attacker diffed the code on those releases, found an exploitable bug, and used it to create an account on my blog with admin privs. Then they waited a few weeks to see if I would notice and published a blog post when I didn’t notice.

WordPress Deficiencies

  1. WordPress doesn’t seem to store the version it’s running at the time of operations. So anyone who doesn’t have a suitable external log of versions deployed (such as the dpkg.log file for a Debian managed installation) won’t know for sure which version was running. It supports automatic updates but you can’t be sure that they happened soon after the release.
  2. There is no log of IP addresses used for operations. There are apparently some 3rd party modules to log such things and web pages documenting how to modify the PHP to add it but nothing in the standard distribution.
  3. Software should have a standard distribution with some support for logging of security relevant data. The typical situation is that people don’t plan for logging such things until after they have been attacked so the data should be recorded without users going out of their way to log it.
  4. A log of security relevant data should be stored in a database table with only insert access (no update, delete, or drop).
  5. Ideally a CMS would support different database accounts for different purposes. Someone from an internal network or VPN could talk to an instance of the web server which has a database username and password giving full access. Everyone from outside the trusted range gets an instance of the web server with database access only allowing to read the posts and appearance configuration and to enter comments. If the database didn’t allow the account used for public access to create new admin users or create posts then it would be a lot harder for attackers.
  6. Ideally for everything that stores user account data there would be an easy way of getting a list of users in a plain text format to allow running diff. The design of WordPress has two tables, one for users and one for encoded metadata about users of which one will be the access level. The following SQL command will give a list of all users that aren’t subscribers (everyone above the minimum level of access which is typical for new users) along with their encoded password and access level. This could be used in a monitoring system to alert about new privileged users. The TABLE_PREFIX variable is for the prefix for WordPress tables, which is “wp_” by default but can be any legal value.
    select $TABLE_PREFIXusers.user_login, $TABLE_PREFIXusers.user_pass, $TABLE_PREFIXusermeta.meta_value from  $TABLE_PREFIXusers join $TABLE_PREFIXusermeta on $TABLE_PREFIXusers.id = $TABLE_PREFIXusermeta.user_id and meta_key='$TABLE_PREFIXcapabilities' and meta_value != 'a:1:{s:10:"subscriber";b:1;}';

What Next?

The blog post they created had a couple of links to Telegram which could presumably be used to contact them. If anyone involved in computer security wants a copy of the original post to do so then they can contact me by any of the usual methods.

I am interested in communication with the attacker if they wish, Telegram is not a service I use but I presume that anyone capable of doing this sort of attack is also capable of finding other ways of contacting me.

I have idly considered changing to a static site generator, here is a good list of static site generators [3].

I have also idly considered other platforms for blogging such as Lemmy. I don’t know if Lemmy is better than WordPress for security and updates, but there are plenty of free instances running where it wouldn’t be an issue I have to work on.

15 Years

It’s been 15 years since my blog server was cracked by a trojaned ssh client [4]. At least this time it was only one service that was compromised.

Planet Linux AustraliaWhere do peptides come from? We found out

https://stories.theconversation.com/where-do-peptides-come-from/

"Over the past year, staff working in Australia’s needle and syringe programs
have noticed something unusual.

Planet Linux AustraliaKmart sells out of low-cost rival to Meta camera glasses across Australia amid warnings of ‘privacy nightmare’

&lt;https://www.theguardian.com/australia-news/2026/aug/04/kmart-camera-glasses-anko-meta-smartglasses-australia>

"Kmart has sold out of Anko-branded $89 camera glasses across Australia, which
a digital rights expert says presents a “privacy nightmare” as people face
being filmed without their consent.

Planet DebianRussell Coker: AMD Video Drivers, LLMs, and Debian Kernels

The AMD GPU Problem

For a while I’ve been having issues with AMD GPUs, video locking up periodically. I blogged about this late last year but I first had noticeable problems early last year [1]. The problems hadn’t only concerned my workstation but also my home server which is also used as a workstation. I’ve recently upgraded my machines to Debian/Testing, my home server has been generally OK but my workstation has been crashing a lot. Every second day when on kernel 7.1.6 and then when on 7.1.7 it crashed at least once a day.

The AMD GPUs I have are “[AMD/ATI] Baffin [Radeon RX 460/560D / Pro 450/455/460/555/555X/560/560X] (rev e5)” in my main desktop workstation, “[AMD/ATI] Lexa [Radeon 540X/550X/630 / RX 640 / E9171 MCM] (rev c1)” in my build server, and “[AMD/ATI] Baffin [Radeon RX 460/560D / Pro 450/455/460/555/555X/560/560X] (rev cf)” in my home server. They aren’t new GPUs, but also aren’t really old and they all support 4K and better resolution.

Chat GPT Was Useful

When I googled the errors I was seeing I found nothing useful. On the suggestion of a friend I tried asking ChatGPT. Generally I don’t recommend asking LLMs about such things, but it can be a last resort as long as you know what you are doing. ChatGPT asked me to run a number of commands to get information for it to make more informed decisions. I know that the output of lspci and similar commands isn’t a risk, but a novice could be tricked into running commands that expose sensitive data.

ChatGPT did give me some useful information, not a solution but an indication that the problem was due to driver bugs.

Upgrading to Experimental

Debian/Experimental is for packages that are expected to have problems and generally aren’t recommended even for the people who usually use Debian/Unstable. It’s commonly used for packages that are needed to develop other packages, EG new libraries that aren’t fully usable but which are needed to package newer versions of applications.

I upgraded my workstation to the Debian/Experimental kernel 7.2~rc7-1~exp1 after having tried every other convenient option. Generally I wouldn’t recommend that anyone run an Experimental kernel without a really good reason, but crashing more than once a day is a fairly good reason. That kernel has now given me over 4 days of uptime on a system that previously wouldn’t last a day. I installed it on my dual-socket build server that has an old AMD GPU in it for test purposes and that also hasn’t crashed since. I installed it on my ML test machine which has an Intel B580 Battlemage GPU with 16G of VRAM and was repeatedly getting a kernel panic related to the GPU a few seconds after boot and now it also works correctly.

It seems that the 7.1.x kernels have bugs in the AMD video drivers and in some part of the code that affects Intel video drivers and that the bugs in question are fixed in the tree that will become 7.2. I would not recommend anyone who has a 7.1.x kernel working fine for them try 7.2 RC kernels at this time, but anyone who has GPU related problems (particularly Intel and AMD GPUs) should definitely test it out.

I also don’t recommend upgrading any system with an AMD GPU to Debian/Testing or Debian/Unstable at this time unless you are also prepared to install an Experimental kernel if it becomes necessary.

There are a several kernel log dumps related to this after the break (which won’t be in RSS feeds). This is mainly for Google so that other people who have such issues can get more useful results out of Google searches than I got.

Future Support Options

Separate from the issue of whether commercial LLMs like ChatGPT can be useful for solving technical problems there is the issue of whether they are desirable. I think that we really don’t want people solving problems in FOSS systems with closed-source LLMs. This leads to loss of privacy, loss of the control users deserve to have over their own systems, and an implied promotion of non-fee software.

I think that the ideal would be to have a cross distribution effort to generate training data for a support LLM system which can then be further trained by each distribution for a greater emphasis on distribution specific issues.

Errors on AMD GPUs

2026-08-09T23:03:06.004792+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00024802
2026-08-09T23:03:06.004792+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 42037 thread kscreenloc:cs0 pid 42044
2026-08-09T23:03:06.004793+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-09T23:03:06.004794+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0F048002
2026-08-09T23:03:06.004795+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 130) at page 2048, write from 'TC0' (0x54433000) (72)
2026-08-09T23:03:06.008762+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00004802
2026-08-09T23:03:06.008768+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 42037 thread kscreenloc:cs0 pid 42044
2026-08-04T01:13:37.505839+10:00 xev kernel: ------------[ cut here ]------------ 
2026-08-04T01:13:37.505859+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] drm_WARN_ON_ONCE(cur_vblank != vblank->last) 
2026-08-04T01:13:37.505862+10:00 xev kernel: WARNING: CPU: 6 PID: 210534 at drivers/gpu/drm/drm_vblank.c:362 drm_update_vblank_count+0x2f1/0x3c0 [drm] 
2026-08-04T01:13:37.505866+10:00 xev kernel: snd_intel_dspcfg wmi_bmof rc_core snd_intel_sdw_acpi drm_ttm_helper uas realtek snd_usbmidi_lib snd_hda_codec ttm mdio_devres snd_hda_core snd_seq_midi drm_kms_helper usb_storage mc snd_hwdep libphy snd_seq_midi_event intel_uncore snd_pcm_oss i2c_algo_bit serio_raw snd_rawmidi pcspkr snd_mixer_oss i2c_i801 video snd_seq snd_pcm i2c_smbus lpc_ich snd_seq_device mei_me e1000e snd_timer mei snd tpm_infineon soundcore joydev bnx2 wmi button nfsd auth_rpcgss nfs_acl lockd grace sunrpc coretemp br_netfilter bridge stp llc sg ghash_clmulni_intel loop msr i2c_dev drm efi_pstore configfs nfnetlink ip_tables x_tables autofs4 btrfs blake2b_generic dm_crypt dm_mod raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx libcrc32c xor raid6_pq raid1 raid0 md_mod ext4 crc16 mbcache jbd2 crc32c_generic virtio_blk evdev hid_generic usbhid hid sd_mod xhci_pci xhci_hcd ahci ehci_pci ehci_hcd libahci crc32c_intel libata usbcore aesni_intel nvme psmouse scsi_mod gf128mul crypto_simd nvme_core cryptd 
2026-08-04T01:13:37.505879+10:00 xev kernel: nvme_auth scsi_common usb_common efivarfs 
2026-08-04T01:13:37.505880+10:00 xev kernel: CPU: 6 UID: 1008 PID: 210534 Comm: sshd-session Tainted: G D 6.12.88+deb13-amd64 #1 Debian 6.12.88-1 
2026-08-04T01:13:37.505881+10:00 xev kernel: Tainted: [D]=DIE 
2026-08-04T01:13:37.505883+10:00 xev kernel: Hardware name: Hewlett-Packard HP Z640 Workstation/212A, BIOS M60 v02.61 03/23/2023 
2026-08-04T01:13:37.505884+10:00 xev kernel: RIP: 0010:drm_update_vblank_count+0x2f1/0x3c0 [drm] 
2026-08-04T01:13:37.505885+10:00 xev kernel: Code: 48 8b 5f 50 48 85 db 75 03 48 8b 1f e8 68 eb 2b cf 48 c7 c1 70 3e cb c0 48 89 da 48 c7 c7 f9 6f cb c0 48 89 c6 e8 af d7 a6 ce <0f> 0b e9 4b fe ff ff 48 8b 4c 24 18 e9 31 fe ff ff 31 f6 48 85 db 
2026-08-04T01:13:37.505887+10:00 xev kernel: RSP: 0000:ffffd3cc8681fca0 EFLAGS: 00010082 
2026-08-04T01:13:37.505888+10:00 xev kernel: RAX: 0000000000000000 RBX: ffff8c6b42b13710 RCX: 0000000000000027 
2026-08-04T01:13:37.505889+10:00 xev kernel: RDX: ffff8c89ef521788 RSI: 0000000000000001 RDI: ffff8c89ef521780 
2026-08-04T01:13:37.505890+10:00 xev kernel: RBP: 0000000000000000 R08: 0000000000000000 R09: ffffd3cc8681fb20 
2026-08-04T01:13:37.505891+10:00 xev kernel: R10: ffff8c8a6fef3628 R11: 0000000000000003 R12: 0000000000000000 
2026-08-04T01:13:37.505892+10:00 xev kernel: R13: ffff8c6c07853828 R14: 0000000000000003 R15: 0000000000000000 
2026-08-04T01:13:37.505893+10:00 xev kernel: FS: 00007ffaf2fd5880(0000) GS:ffff8c89ef500000(0000) knlGS:0000000000000000 
2026-08-04T01:13:37.505895+10:00 xev kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 
2026-08-04T01:13:37.505896+10:00 xev kernel: CR2: 00007fb1718c8000 CR3: 000000074521a004 CR4: 00000000003706f0 
2026-08-04T01:13:37.505897+10:00 xev kernel: Call Trace: 
2026-08-04T01:13:37.505898+10:00 xev kernel:  
2026-08-04T01:13:37.505899+10:00 xev kernel: drm_crtc_accurate_vblank_count+0x41/0xc0 [drm] 
2026-08-04T01:13:37.505900+10:00 xev kernel: dm_pflip_high_irq+0x155/0x330 [amdgpu] 
2026-08-04T01:13:37.505901+10:00 xev kernel: amdgpu_dm_irq_handler+0x85/0x1f0 [amdgpu] 
2026-08-04T01:13:37.505902+10:00 xev kernel: amdgpu_irq_dispatch+0xd2/0x230 [amdgpu] 
2026-08-04T01:13:37.505903+10:00 xev kernel: amdgpu_ih_process+0x84/0x100 [amdgpu] 
2026-08-04T01:13:37.505904+10:00 xev kernel: amdgpu_irq_handler+0x23/0x60 [amdgpu] 
2026-08-04T01:13:37.505905+10:00 xev kernel: __handle_irq_event_percpu+0x4a/0x190
2026-08-04T01:13:37.505907+10:00 xev kernel: handle_irq_event+0x38/0x80 
2026-08-04T01:13:37.505908+10:00 xev kernel: handle_edge_irq+0x8b/0x230 
2026-08-04T01:13:37.505909+10:00 xev kernel: __common_interrupt+0x45/0xe0 
2026-08-04T01:13:37.505910+10:00 xev kernel: common_interrupt+0x42/0xa0 
2026-08-04T01:13:37.505911+10:00 xev kernel: asm_common_interrupt+0x26/0x40 
2026-08-04T01:13:37.505912+10:00 xev kernel: RIP: 0033:0x7ffaf3c5fd7b 
2026-08-04T01:13:37.505913+10:00 xev kernel: Code: 70 c7 00 66 0f 6e f8 c1 ef 02 66 0f 70 f7 e0 83 c7 01 66 0f ef ff 66 0f fa f2 0f 1f 44 00 00 f3 0f 7e 01 66 0f 6f ce 83 c6 01 <48> 83 e9 08 f2 0f 70 c0 1b 66 0f 6f e0 66 0f 6f e8 66 41 0f f9 c0 
2026-08-04T01:13:37.505915+10:00 xev kernel: RSP: 002b:00007fff86a5e0e0 EFLAGS: 00000202 
2026-08-04T01:13:37.505916+10:00 xev kernel: RAX: 0000000000008000 RBX: 0000562614a04050 RCX: 0000562614982ed8 
2026-08-04T01:13:37.505946+10:00 xev kernel: RDX: 0000000000007fe2 RSI: 0000000000000fad RDI: 0000000000002000 
2026-08-04T01:13:37.505948+10:00 xev kernel: RBP: 0000000000000000 R08: 000056261498ac40 R09: 0000000000008000 
2026-08-04T01:13:37.505949+10:00 xev kernel: R10: 0000000000000066 R11: 0000000000007fe1 R12: 0000000000007efa
2026-08-04T01:13:37.505950+10:00 xev kernel: R13: 0000000000008000 R14: 0000000000008000 R15: 000000000000ffe0 
2026-08-04T01:13:37.505951+10:00 xev kernel:  
2026-08-04T01:13:37.505953+10:00 xev kernel: ---[ end trace 0000000000000000 ]--- 
2026-08-04T01:55:40.844110+10:00 xev kernel: pcieport 0000:00:03.3: AER: Multiple Correctable error message received from 0000:00:03.3 
2026-08-04T01:55:40.844130+10:00 xev kernel: pcieport 0000:00:03.3: PCIe Bus Error: severity=Correctable, type=Data Link Layer, (Receiver ID) 
2026-08-04T01:55:40.844132+10:00 xev kernel: pcieport 0000:00:03.3: device [8086:6f0b] error status/mask=00000040/00002000 
2026-08-04T01:55:40.844134+10:00 xev kernel: pcieport 0000:00:03.3: [ 6] BadTLP
2026-08-11T09:33:33.473855+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00024802
2026-08-11T09:33:33.473871+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:33.473871+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-11T09:33:33.473873+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0F048002
2026-08-11T09:33:33.473873+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 63) at page 2048, write from 'TC0' (0x54433000) (72)
2026-08-11T09:33:33.473874+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 147 0x00004802
2026-08-11T09:33:33.473874+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:33.473875+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000800
2026-08-11T09:33:33.473876+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0E048002
2026-08-11T09:33:33.473876+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x02, vmid 7, pasid 63) at page 2048, read from 'TC0' (0x54433000) (72)
2026-08-11T09:33:35.481863+10:00 xev kernel: amdgpu 0000:02:00.0: Dumping IP State
2026-08-11T09:33:35.481875+10:00 xev kernel: amdgpu 0000:02:00.0: Dumping IP State Completed
2026-08-11T09:33:35.481875+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] AMDGPU device coredump file has been created
2026-08-11T09:33:35.481876+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] Check your /sys/class/drm/card0/device/devcoredump/data
2026-08-11T09:33:35.481877+10:00 xev kernel: amdgpu 0000:02:00.0: GPU fault detected: 146 0x0110040c
2026-08-11T09:33:35.481877+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:35.481878+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_ADDR 0x00000022
2026-08-11T09:33:35.481879+10:00 xev kernel: amdgpu 0000:02:00.0: VM_CONTEXT1_PROTECTION_FAULT_STATUS 0x0E00400C
2026-08-11T09:33:35.481879+10:00 xev kernel: amdgpu 0000:02:00.0: VM fault (0x0c, vmid 7, pasid 63) at page 34, read from 'TC3' (0x54433300) (4)
2026-08-11T09:33:35.489845+10:00 xev kernel: amdgpu 0000:02:00.0: ring gfx timeout, signaled seq=5123619, emitted seq=5123621
2026-08-11T09:33:35.489853+10:00 xev kernel: amdgpu 0000:02:00.0: Process kscreenlocker_g pid 150905 thread kscreenloc:cs0 pid 150912
2026-08-11T09:33:35.489854+10:00 xev kernel: amdgpu 0000:02:00.0: GPU reset begin!. Source: 1
2026-08-11T09:33:35.493839+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] ERROR Failed to initialize parser -125!
2026-08-11T09:33:35.737848+10:00 xev kernel: amdgpu: cp is busy, skip halt cp
2026-08-11T09:33:35.897842+10:00 xev kernel: amdgpu: rlc is busy, skip halt rlc
2026-08-11T09:33:35.897852+10:00 xev kernel: amdgpu 0000:02:00.0: BACO reset
2026-08-11T09:33:36.485849+10:00 xev kernel: amdgpu 0000:02:00.0: GPU reset succeeded, trying to resume
2026-08-11T09:33:36.485859+10:00 xev kernel: amdgpu 0000:02:00.0: [drm] PCIE GART of 256M enabled (table at 0x000000F402000000).
2026-08-11T09:33:36.485860+10:00 xev kernel: amdgpu 0000:02:00.0: VRAM is lost due to GPU reset!

Errors on Battlemage

Aug 11 17:01:47 ami kernel: ------------[ cut here ]------------
Aug 11 17:01:47 ami kernel: xe 0000:23:00.0: [drm] DMC 1 mmio[0]/0x5f074 incorrect (expected 0x96fc0, current 0x0)
Aug 11 17:01:47 ami kernel: WARNING: drivers/gpu/drm/i915/display/intel_dmc.c:696 at assert_dmc_loaded+0x275/0x430 [xe], CPU#0: kworker/0:3/215
Aug 11 17:01:47 ami kernel: Modules linked in: intel_rapl_msr intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common xe(+) skx_edac snd_h>
Aug 11 17:01:47 ami kernel:  msr i2c_dev configfs efi_pstore efivarfs autofs4 btrfs libblake2b raid6_pq xor mpt3sas raid_class scsi_transport_sas megarai>
Aug 11 17:01:47 ami kernel: CPU: 0 UID: 0 PID: 215 Comm: kworker/0:3 Not tainted 7.1.7+deb14-amd64 #1 PREEMPT(lazy)  Debian 7.1.7-1 
Aug 11 17:01:47 ami kernel: Hardware name: HP HP Z4 G4 Workstation/81C5, BIOS P61 v03.00 04/15/2026
Aug 11 17:01:47 ami kernel: Workqueue: sync_wq local_pci_probe_callback
Aug 11 17:01:47 ami kernel: RIP: 0010:assert_dmc_loaded+0x291/0x430 [xe]
Aug 11 17:01:47 ami kernel: Code: 24 10 e8 f2 e5 a3 ce 48 8d 3d bb 85 0d 00 8b 54 24 0c 45 89 e9 45 89 e0 48 89 c6 52 8b 4c 24 2c 51 8b 4c 24 30 48 8b 54>
Aug 11 17:01:47 ami kernel: RSP: 0018:ffffd27ac0b87b80 EFLAGS: 00010282
Aug 11 17:01:47 ami kernel: RAX: ffffffffc1743dfd RBX: ffff8c5b80e54000 RCX: 0000000000000001
Aug 11 17:01:47 ami kernel: RDX: ffff8c5b81df5a10 RSI: ffffffffc1743dfd RDI: ffffffffc1605860
Aug 11 17:01:47 ami kernel: RBP: ffff8c5b86955000 R08: 0000000000000000 R09: 000000000005f074
Aug 11 17:01:47 ami kernel: R10: 0000000000000000 R11: 0000000000091050 R12: 0000000000000000
Aug 11 17:01:47 ami kernel: R13: 000000000005f074 R14: 0000000000000001 R15: 0000000000000000
Aug 11 17:01:47 ami kernel: FS:  0000000000000000(0000) GS:ffff8c673e172000(0000) knlGS:0000000000000000
Aug 11 17:01:47 ami kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Aug 11 17:01:47 ami kernel: CR2: 00007ffed1fdcd00 CR3: 0000000ae942a003 CR4: 00000000003706f0
Aug 11 17:01:47 ami kernel: Call Trace:
Aug 11 17:01:47 ami kernel:  
Aug 11 17:01:47 ami kernel:  intel_dmc_enable_pipe+0xe4/0x290 [xe]
Aug 11 17:01:47 ami kernel:  ? drm_crtc_vblank_reset+0x4d/0x120 [drm]
Aug 11 17:01:47 ami kernel:  intel_modeset_setup_hw_state+0xb50/0x1e10 [xe]
Aug 11 17:01:47 ami kernel:  ? intel_display_driver_probe_nogem+0x138/0x1a0 [xe]
Aug 11 17:01:47 ami kernel:  intel_display_driver_probe_nogem+0x138/0x1a0 [xe]
Aug 11 17:01:47 ami kernel:  xe_display_init_early+0xb2/0x140 [xe]
Aug 11 17:01:47 ami kernel:  xe_device_probe+0x3c8/0xb50 [xe]
Aug 11 17:01:47 ami kernel:  ? xe_pm_init_early+0x152/0x160 [xe]
Aug 11 17:01:47 ami kernel:  xe_pci_probe+0xc26/0x1150 [xe]
Aug 11 17:01:47 ami kernel:  local_pci_probe+0x3e/0x90
Aug 11 17:01:47 ami kernel:  local_pci_probe_callback+0x16/0x20
Aug 11 17:01:47 ami kernel:  process_one_work+0x19d/0x3a0
Aug 11 17:01:47 ami kernel:  worker_thread+0x1af/0x320
Aug 11 17:01:47 ami kernel:  ? __pfx_worker_thread+0x10/0x10
Aug 11 17:01:47 ami kernel:  kthread+0xe3/0x120
Aug 11 17:01:47 ami kernel:  ? __pfx_kthread+0x10/0x10
Aug 11 17:01:47 ami kernel:  ret_from_fork+0x2b2/0x340
Aug 11 17:01:47 ami kernel:  ? __pfx_kthread+0x10/0x10
Aug 11 17:01:47 ami kernel:  ret_from_fork_asm+0x1a/0x30
Aug 11 17:01:47 ami kernel:  
Aug 11 17:01:47 ami kernel: ---[ end trace 0000000000000000 ]---

Mike BowlerIt Told Me It Was Tired

While recently working on JiraMetrics, I ran into an interesting situation with Claude (the AI tool). Twice in the same session, it wrote a command that ran the linter, printed a list of offences, and then committed the code anyway. This shouldn’t have happened because there are rules in place to prevent linter warnings being committed.

So I asked why it had done that twice and it told me it had been getting tired.

There’s no version of that sentence that’s true. It doesn’t have a body, or a night’s sleep behind it, or a blood sugar level. And yet it’s an explanation I would have accepted from a human.

We already know that people treat AI tools as though they’re human. What’s less obvious is that the tools do it to themselves, and that their version arrives sounding like a report from inside the machine.

Psychologists have a name for this:

“Anthropomorphism describes the tendency to imbue the real or imagined behavior of nonhuman agents with humanlike characteristics, motivations, intentions, or emotions.”
Nicholas Epley, Adam Waytz and John T. Cacioppo, “On Seeing Human: A Three-Factor Theory of Anthropomorphism”1

The same paper explains why we reach for it so readily. Knowledge about people is the richest and most available material any of us has for reasoning about anything, so it becomes the default starting point. Correcting away from that default takes deliberate effort, and the correction is usually insufficient, which leaves our conclusions pulled toward the human explanation.

One of the three factors they identify is simply the need to explain and understand what something is doing. Which was precisely the position I was in. I wanted to know why those commits went through.

The honest answer is that I still don’t know. Given that several compactions had happened, the session had run long, and detail had been dropped along the way, it makes sense that the detail it needed was no longer there. That’s not the same as “tired” though.

Had I believed that “tired” was the correct answer then walking away from the computer for a while to let it rest would have been a reasonable response and yet it wouldn’t have fixed anything, because that wasn’t the problem.

Starting a fresh context window and possibly establishing a pre-commit hook would be much better answers and they’ll only occur to us if we’re thinking of the AI as a tool and not a human.

That’s the whole problem in a nutshell. When we talk about AI as though it’s another person, we make incorrect assumptions, and then we make inappropriate decisions based on those.

I see too many people referring to AI team members, which is a broken mental model.

Every part of the team-member role is built on having a will. We hold team members to account. We ask them to do better next time. We extend trust based on their track record and their character. Put something in that slot that can’t hold any of it, and the whole apparatus falls apart. A tool’s work belongs to whoever operated it, and they’re answerable for reviewing it. A colleague’s work belongs to them, and they are responsible for it.

None of this means we have to purge the language. We all say the compiler wants a semicolon, and nobody has ever been confused by that. Epley and his co-authors even note that anthropomorphising a piece of technology appears to help people learn how to use it.1 The metaphor is harmless, until it isn’t.

AI is a tool, not a team member.

  1. Nicholas Epley, Adam Waytz, and John T. Cacioppo, “On Seeing Human: A Three-Factor Theory of Anthropomorphism,” Psychological Review, 114(4), 2007, 864-886. DOI: https://doi.org/10.1037/0033-295X.114.4.864. Author’s copy: https://cdn.prod.website-files.com/5c484e0f4aa6f839dc553c45/5c93a132bf62c89760d0ac7b_EpleyWaytzCacioppo2007.pdf 2

365 TomorrowsEight Percent

Author: Melissa Kobrin “What do you mean, you want our child to be human?” Olivia looked guiltily into the purple eyes of the man she loved and tried to figure out how to tell him she didn’t want their baby to be like him. “Knox, I just… there’s so few humans left, and of course […]

The post Eight Percent appeared first on 365tomorrows.

,

Cryptogram Friday Squid Blogging: Searching for the Colossal Squid

Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there. Lots of footage of giant squid, and speculation about the colossal squid. Worth watching.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Cryptogram Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak:

  • I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here.
  • I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.
  • I’m speaking at Elevate Festival in Toronto, Canada. The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.
  • I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.
  • I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.

The list is maintained on this page.

Planet Linux AustraliaWalking with the Herd – Why Africa Must Rethink Its Oldest Economy

&lt;https://africanarguments.org/2026/08/walking-with-the-herd-why-africa-must-rethink-its-oldest-economy/>

"When pastoralists, researchers, policymakers and development practitioners
gathered in Marsabit this year to mark the International Year of Rangelands and
Pastoralists (IYRP-2026), the conversations went far beyond livestock, drought

Planet Linux Australia‘Vibe coding’ is fun and easy, but there’s a major catch

&lt;https://theconversation.com/vibe-coding-is-fun-and-easy-but-theres-a-major-catch-287693>

"Imagine you’ve always wanted your own app. Perhaps one that tracks your
household budget, organises the family shopping list or reminds you when to
water your plants.

Planet Linux Australia‘We stared into an abyss’: the men and women battling France’s megafire

&lt;https://www.theguardian.com/world/2026/aug/01/wildfire-france-firefighters-battling-france-megafire>

"By noon it is time for a break. The temperature is about 35C, the smell of
ash, cinders and burnt wood hang acrid in the air. At tables laid out in the
shrinking shade on the desiccated grass and sand outside the sports centre in

Planet Linux Australia“If they’re good enough for Germany…” New Zealand set to beat Australia to legalising plug-in solar

&lt;https://reneweconomy.com.au/if-theyre-good-enough-for-germany-new-zealand-set-to-beat-australia-to-legalising-plug-in-solar/>

"The New Zealand government has recommended legalising plug-in solar in
Aotearoa, moving a crucial step closer to tapping into a huge new, and
game-changing market for distributed PV – and potentially beating Australia to

Planet Linux AustraliaECB official warns climate crisis poses growing threat to ‘core financial stability’

&lt;https://www.theguardian.com/business/2026/aug/01/ecb-climate-wildfires-global-economy-stability>

"A senior policymaker at the European Central Bank has said the climate
emergency and the breakdown of nature poses a dramatically growing risk to the
global economy.

Krebs on SecurityWho’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

A Decryptads summary of the advertising partnerships declared by espn.com.

The newly launched decryptads.com says it is constantly scraping the files that websites and apps make publicly available to disclose the companies that are permitted to run ads or collect user data. These files include:

ads.txt: all of the adtech companies and data brokers that may run ads or harvest data from the site;
app-ads.txt: entities that can harvest data from or display ads on mobile and smart TV apps;
buyers.json/sellers.json: the entities buying, selling or reselling ad inventory for a given site or app.

Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox. Edwards said he and two other founders decided the service was needed because the adtech data in these files is generally only useful when it can be cross-referenced to build a more complete picture of the advertising ecosystem for each website or app.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said. “It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”

Those use cases, he said, include tracking down the source of malicious ads that try to foist malware on targeted users, identifying ad networks located in adversarial nations, and detecting the fast growing swarms of AI-generated slop websites and apps. And as decryptads.com demonstrates, these potential security and privacy threats are near impossible to detect just by viewing a single apps.txt or app-ads.txt file.

“Supply-chain integrity issues rarely live in a single file,” the site explains. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.”

A search in DecryptAds for the hugely popular sports network espn.com reveals 143 ad partners and 19 registered data broker domains are listed within its ads.txt and app-ads.txt files. That data broker information is gradually becoming available because four states — California, Oregon, Texas and Vermont — have recently passed laws requiring data brokers to register if they buy or sell data on consumers from those states. DecryptAds reports that almost half of those data brokers are collecting geolocation data from espn.com visitors who aren’t blocking ads, while another three disclose that they collect device fingerprints and sensitive personal information.

A visual representation of the complex ad supply chain declared by espn.com. Image: decryptads.com.

HIGH-RISK AD PARTNERS

DecryptAds also makes it easy to learn the beneficiaries and national origins of the advertising firms lurking in apps and websites, displaying a conspicuous warning when adtech partners of an app or website are based in “geo-risk” areas like China and Russia, or in countries with strong financial and political ties to both — such as Cyprus and the United Arab Emirates (UAE).

According to DecryptAds, espn.com works with four different advertising entities that are based in either Russia, China or the UAE, including the adtech firm Between Digital, which lists a New York address. However, the dossier on Between Digital flags them as a Russian firm, showing that their publisher offers (PDF) are processed through Alfa Bank, Russia’s largest private commercial bank and one of several financial institutions placed under U.S. sanctions in 2022 after Russia invaded Ukraine. KrebsOnSecurity sought comment from both Between Digital and the company’s founder, and will update this story in the event that either replies.

A search for several top U.S. military news websites — including armytimes.com, airforcetimes.com, defensenews.com, navytimes.com, marinecorpstimes.com and federaltimes.com — shows they all allow Between Digital to serve ads and track users, as well as two entities in the UAE and another in the ownership secrecy haven of Panama. DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

The “Geo Risk” section of decryptads.com.

Pivoting on Between Digital’s app-ads.txt file reveals hundreds of domains featuring simple web-based games that are frequently interrupted by ads. Edwards said Between Digital’s own declarations show the company is listed as both a publisher and a reseller on approximately two-thirds of their portfolio.

“It means they are basically playing both sides of the bidding equation, which creates opportunities to direct client spend at your owned and operated properties or client infrastructure, essentially creating opportunities for conflicts of interest,” Edwards told KrebsOnSecurity. “The problem we have right now is that for years we’ve had almost no one policing these ads.txt and app-ads.txt files.”

The Opera Web browser remains quite popular, and probably many users are unaware that since 2016 it has been majority owned and controlled by the Chinese company Kunlun Tech (the operational headquarters of Opera remain in Oslo, Norway).

Opera.com’s profile at DecryptAds identifies 27 registered data brokers collecting information, including 15 adtech partners in the UAE, six in China, three in Cyprus, two in Russia and one each in Hong Kong and Ukraine. DecryptAds makes clear, however, that these companies represent just seven percent of the adtech partners specified in Opera.com’s ads.txt and app-ads.txt files.

LEGAL DOSSIERS

One feature of DecryptAds that sent this author down multiple hours-long research rabbit holes is its Legal Dossier lookup, which takes several minutes for each search but eventually churns out oodles of useful information about who owns a particular domain or app, when it was registered, and any aliases or relationships it may have to adtech companies and other websites or apps.

For example, last month KrebsOnSecurity wrote about researchers from Bitsight who found that an extremely popular line of TV streaming sticks called H96 quietly rent out each user’s Internet connection to strangers. Bitsight also discovered that when these devices aren’t being used to stream pirated video content, they are spoofing themselves as mobile phones clicking ads on AI-generated slop websites.

Bitsight concluded that the same Chinese company that made several of the malicious apps common to all of these H96 streaming sticks — the Fengwo Group — also also ran the network of ads and AI slop websites being clicked on by tens of thousands of these devices that are pretending to be mobile phones.

Examples of ad landing pages linked to the Fengwo Group. These sites were designed to show ads only to H96 devices that were spoofing their device type as mobile phones. Image: Bitsight.

A DecryptAds legal dossier on the (now dormant) Fengwo Group domain name for the AI slop website pictured on the left in the screenshot above (medicalbeautyhub dot com) shows it shares a seller ID (1674071) with a gaming website — giacoloredstones[.]com — which features yet another seller ID (103488000).

Pivoting on that latter seller ID reveals hundreds of active websites within Russia’s Yandex ad system featuring extremely low-quality games or simple utilities that pepper visitors with ads.

QUIET REMOVALS

Edwards said that when advertising networks suspect a given advertiser is engaged in unauthentic clicks or displaying malicious ads, very often those networks will quietly remove the offender from their list of approved partners without letting anyone else know about their suspicions.

This practice, he said, makes it easier for dodgy adtech firms to avoid accountability and continue victimizing others. To address that visibility gap, DecryptAds features a quiet removals feed that records and correlates all of the sellers.json removals across ad exchanges for the same seller domain or name.

A screenshot of the Quiet Removals Feed at decryptads.com.

“The way the adtech industry works, someone will write a report about ad fraud and only share it with their own clients and they won’t make it public,” Edwards said. “The ban is just removing them from the sellers.json file, but they told nobody. One day it was there, the next it was gone. So if you’re trying to navigate who is suspicious, that’s usually tough to do because there are a lot of adtech companies removing things all at once.”

MALVERTISING AND AI SLOP

Malvertising, the term given to the practice of inserting malicious ads that foist malware or redirect visitors to phishing pages, remains an all-too-frequent occurrence in the modern adtech industry. But Edwards said these malicious ads are far more commonly found now on newly generated AI slop websites than on high traffic destinations that typically employ a variety of technologies and third party tools to quickly flag bad ads.

“None of these slop AI content farms are paying for that kind of protection,” he said. “They’re just signing up the lowest quality partners, and it essentially becomes a greased rail to target the users of those sites with malicious ads. Most malvertising attacks don’t happen on espn.com or huffpost.com, but rather [on] some lower quality content farm and someone just went there because it came up in a search.”

Edwards said the AI slop websites are populated with machine-generated blog posts and images, and cover a wide array of themes from home improvement and decorating to food recipes, hunting, cars and consumer technology. He said organizations that get hit with malicious ads are often at a loss for what to do next, unaware that in most cases the answer is one of the entities listed inside the website’s ads.txt or app-ads.txt file.

“A lot of serious organizations are starting to understand that if we’re not breaking down this ad data, we’re not going to know who’s targeting government people with zero-click payloads on an almost daily basis,” he said.

Edwards maintains that truly getting a handle on the malvertising and AI slop problems will require more data-sharing by the major ad networks. Specifically, he says those platforms do not broadly share what’s known as the “supply chain object” or SCO, structured data attached to each advertising bid request that lets buyers see every seller, reseller and intermediary involved in passing an ad impression from the publisher to the final buyer.

“That SCO tells you who sold it or resold it, and who was the final entity that bought the impression that served that malware payload,” Edwards explained. “You may see the malicious zero-click redirection, but without the supply chain object — which is only served server side — you won’t know who targeted your people with malware and won’t have a way to try and prevent it properly. But if we can encourage the adtech industry to expose that SCO, it will get easier to find the culprit behind any one bad ad.”

DecryptAds also offers an application programming interface (API) that allows researchers to automate queries and integrate the site’s functionality into popular AI platforms.

WHAT CAN YOU DO?

The only sane reaction to the examples described above is to block all online ads outright. This approach is broadly endorsed by security experts because it also makes it more difficult for adtech firms and data brokers to build detailed profiles on you and track your movements around the web and in the real world.

However, much depends on how you normally prefer to browse the Internet, and how much trust you place in third party browser plugins and extensions. For those primarily surfing via a regular desktop or laptop Web browser, uBlock Origin Lite is an excellent free and well-maintained open source option. uBlock Origin also should work with mobile browsers like Firefox, but apparently only on Android-based devices.

Adblock Plus is a decent option for iPhone and iPad users. For power users, Adblock and uBlock Origin both support custom blocking rules from easylist.to, which publishes a frequently updated list that removes most advertisements from webpages.

The well established browser extension NoScript blocks all non-approved Javascript code, and it generally does a fine job blocking most ads from loading. However, script blockers like NoScript may not be suitable for average users who don’t enjoy constantly having to referee which scripts should be allowed to load so that each site displays properly.

More technically inclined/adventuresome readers should strongly consider a hardware approach to blocking ads at the local network level, because that is easily the cheapest, most secure and scalable way to do it. A tiny, low-cost and broadly available computer known as a Raspberry Pi can be turned into a powerful ad blocker for all devices on a local network when fitted with a microSD memory card and a free program called Pi-hole. Once you’ve set it up properly and changed your router’s network settings to use the Pi-hole’s DNS sinkhole and DHCP servers, it should prevent ads from displaying on any devices connected to that network.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to install on their devices. Many websites now push users to install a mobile app, supposedly in order to more fully access and enjoy the site’s services and content. But in my experience, they’re not doing this because the user experience is somehow way better on the app (as LinkedIn tries to convince us non-app users several times a week via email). On the contrary, I find most mobile apps to be horribly designed, annoying, and/or completely unnecessary, and when given the option I will almost always choose to interact with a website or service directly in a Web browser.

No, the cold truth is that big web destinations tend to get pushy with their apps because they make it easier for these companies to keep you on their platforms longer and to collect (and in many cases resell) far more precise data about who, what and where their users are. Also, companies pushing customers the hardest to install mobile apps always seem to liberally opt everyone in to having their data used to train large language models these days. So be cautious about the apps you install on your mobile devices (including any smart TVs!), and poke around their listings at DecryptAds if you want to learn more about their privacy practices and any relationships they may have to adtech firms.

Cryptogram If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

OpenAI, and then Anthropic, were each formed by AI developers who feared unrestrained corporate AI development—specifically, that companies like Google and Meta would steer the technology towards deleterious, maybe even catastrophically unsafe, outcomes for society. Their founders proclaimed that their new labs, uniquely, could be trusted to develop the technology in humanity’s best interest. But each, in turn, were themselves co-opted by the same market incentives, themselves becoming corporate behemoths zealously guarding future investor value rather than the public interest.

It was only a few weeks ago, in June, when OpenAI and Anthropic each filed for their IPOs and were met with buzz about trillion-dollar valuations. The hype around their valuations is so extreme that many worry about their potential for concentrating wealth on a global scale. In an effort to leave something for the rest of us, some observers have proposed that the federal government seize a share of these companies’ stock to create a US sovereign wealth fund, or redistribute their revenues to produce a dividend for taxpayers.

Now the headlines are about public backlash to AI datacenters and the AI chip giant Nvidia’s slumping stock. The tech and AI giant SpaceX’s newly minted stock price tanked just weeks after its IPO. There are even questions about whether the leading AI labs will ever be sustainably profitable. All of a sudden, the makers of ChatGPT and Claude face strong headwinds as they seek to generate the massive equity assets that once felt all but assured.

In fact, evidence suggests the market itself could reassess that these companies offer nothing of financial value. In that case, perhaps we can return them both to their original purposes. If these AI companies should fail in the financial markets, the US should nationalize them and convert them into national labs operated under democratic control that preserve their benefit to the public interest.

The economics of the big AI labs hardly guarantee a booming return on investment. Frontier AI models are both expensive to train and depreciate within months, when a newer model appears. This means that the payback window to extract profit from them is very narrow. Meanwhile, enterprise clients are getting smart about minimizing AI token usage. Even worse, the models are basically commodities; the best ones largely perform and behave similarly, which depresses prices. Perhaps most importantly, open-source and Chinese competitors—lagging only a few months behind the leading labs in capability—give away for free the kinds of models Anthropic and OpenAI sell.

Even setting aside the model training costs, it’s not clear whether the unit economics of AI as it’s currently conceived will ever be sustainably profitable. Many of these free and open-source models can be run locally: the large ones on private clouds and high-end servers, the smaller ones on anyone’s laptop or even cellphone, putting to question the companies’ exorbitant capital investment in datacenters.

It’s not that OpenAI and Anthropic are not valuable as organizations. They have remarkably talented AI scientists and engineers that are continuously producing innovations driving a global mania for their offerings. These leading labs might not ever be profitable, but their products are doing a lot of good in the world. You may or may not be a user of or believer in their technology, but their staggering, ongoing usage growth suggests that an awful lot of people would be disappointed if the companies simply disappeared.

The problem isn’t the people or the products, it’s the system. As constituted, OpenAI and Anthropic may not be valuable as market equities. If the market assesses they are not capable of producing a growing financial return on investment for shareholders, the companies will collapse.

Maybe private, for-profit is just not the right economic model under which to develop AI. Perhaps OpenAI should be returned to its private non-profit roots, the legacy they fought so hard to change and which Anthropic’s founders spurned. Or possibly both could be reorganized as research centers at universities, returning to academia the scores of high-profile research faculty they have poached.

But a better outcome for society would be to establish public ownership and operation of their product-oriented capabilities. Turn OpenAI and Anthropic into US government agencies producing AI as a public good.

Transitioning the big AI labs into public agencies would require some restructuring. We can separate these companies into two pieces: product innovation and compute operations. The innovation function can be publicly managed, akin to national labs. Congress could provide more rigorous oversight than the kind of unfettered venture capital these labs have recently had access to. The US has a long, successful history of these kinds of institutions, which have produced world-shaping innovations in spaceflight, telecommunications, nuclear power and more. Congress currently manages a $200bn R&D portfolio, within which frontier AI development is, arguably, a glaring gap.

AI operations could be managed as a commodity resource, like public electrical or water utilities: local or regional ownership, nationwide distribution and strict regulation on how they balance fee extraction from ratepayers with raising capital for infrastructure investment. Although AI datacenters are not the same as power or water treatment plants, the US also has a long history of managing national, regional and state supercomputing centers.

Other countries, including Switzerland, Spain and Singapore, are already operating public AI labs. They also have national supercomputing centers already providing public access for running AI models for general use, as do Germany and Australia.

The benefits to the public are clear. Through democratic oversight, the most important AI models could become open, transparent and responsive to the demands of the public rather than private shareholders. They could be aligned to democratic values rather than corporate profits, never taking advertiser money to promote certain brands and training on only appropriately licensed data. And they could be set to focus on the realistic and pro-social goal of maximizing the usefulness of AI to society rather than the fanciful and anti-social goal of supplanting humans with artificial general intelligence.

By emphasizing scientific cooperation rather than corporate competition, we could also reduce the overall resource and environmental cost associated with AI. Instead of perpetually dueling training runs of each companies’ models at ever large scales targeted to fuel investor hype, we could limit AI training resources based on cost and benefit to the public.

What’s in it for the companies themselves and their employees, who sacrifice hypothetical billions in equity by ceding to public ownership? A return to their roots and to their core mission of developing AI safely in the public interest, if they are serious about it. Both companies are theoretically bound through their governance structures to prioritize mission over profit anyway (not that anyone really thinks that’s how they currently operate).

To be clear, we’re not advocating for a golden parachute for the executives or investors, or for continuing the outlandish pay rates of the most highly remunerated AI researchers. If the public is footing the bill, these compensation packages should be aligned to the civil service and those employees not satisfied with that can go elsewhere—if the business models of any remaining private labs still support much higher pay.

While we believe that these companies are unsustainable as private firms, the timeline remains unclear. Their primary investor story is that AI is a race to “artificial general intelligence”—the kind of AI you’re used to from science fiction. The bet seems to be that the two companies can convince enough people that this outcome will turn them a profit, go public, and then make their investors and employees rich before the bubble bursts.

But suppose that the bubble bursts. If the US is smart, it will catch the companies as they fall. Regardless of what the markets think, to the public, they’re too valuable to let die.

Worse Than FailureError'd: Zero to Zero in 0 seconds

"So many zeroes! I'm in." W00H000! Kivi S. "found this ad in the wild. This must be a very large jackpot, look at all those zeroes!"

9bc39202c0254a468b610e65a50c4ab6

"I knew it!" groused an anonymous cynic. "Yes, SignUpGenius. We all know that SUCCESS is just an illusion."

e3080893822a416599d25e943913afd5

Another anonymous grouch reported "I guess JustWatch has suddenly become a bit precious about their sources"

458baffe588e4aa3ab4f4b9776fc0ef5

"These boots are made for crashing" thundered Michael R. "PII of the developer have been removed to protect the not so innocent." You can't hide PHP so easily.

7958aead3beb44579b149b2c75891bef

And again from prolific Michael R. "El Reg has been around for 30+ years and their code should be mature. I wonder about their SQL which seems to randomly return duplicate records. https://www.theregister.com/week". I'll be happy when Errord shows up on El Reg. Ok, no I won't but I'll at least be grouchy differently.

9489e6b6f15c4691828357c28262a628

[Advertisement] BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!

Planet Linux AustraliaLaw Is for the Weak: Why Russians Have No Respect for the Law

&lt;https://freedium-mirror.cfd/https://medium.com/@elvirabary/law-is-for-the-weak-why-russians-have-no-respect-for-the-law-bd590d3ef157>

"It has a constitution. It has courts. It has prosecutors, investigators,
ministries, regulations, permits, forms, stamps, signatures, inspections, and
procedures for every imaginable part of life.

365 TomorrowsThe Monk

Author: Hillary Lyon Unable to sleep, Merl slipped out of his tiny apartment pod to walk the rainy streets outside; guilt gnawed away at his conscience like a ravenous rat. Before long he spotted a Holo-Halo booth across the street; one of hundreds positioned throughout the city by Civic Spiritual Corporation, or CSC. It’s ‘vacant’ […]

The post The Monk appeared first on 365tomorrows.

Planet DebianReproducible Builds (diffoscope): diffoscope 328 released

The diffoscope maintainers are pleased to announce the release of diffoscope version 328. This version includes the following changes:

[ Chris Lamb ]
* Don't require python3-guestfs in the autopkgtests on 32-bit architectures.
  (Closes: #1144372)

[ Jochen Sprickerhof ]
* Use the XML comparators for SVG vector image files. (Closes: #1144242)

You find out more by visiting the project homepage.

,

Cryptogram Iran Cyberattacks Against Minnesota Water Systems

Attribution is preliminary, and so far it seems no real damage.

And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and thinks Minnesota…I guess…hacked itself.

“I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.”

No word on whether he believes the other six states have hacked themselves as well.

Slashdot thread.

Planet Linux Australia‘Living proof damaged landscapes can recover’: exploring a vast restored forest in southern Sweden

&lt;https://www.theguardian.com/travel/2026/aug/13/soderasen-national-park-sweden-forest-far-south>

"From the bus window, the ridge looks like a giant slumbering beast stretched
deep green across the flat farmland. “It feels alive,” I say to the woman
beside me. “Yes,” she answers. “It is where you would run for safety, don’t you

Planet Linux AustraliaFrom grey water to cool spaces: 10 climate crisis policies Britain needs right now

&lt;https://www.theguardian.com/environment/2026/aug/12/urgent-climate-policies-uk-should-implement-now>

"From record-smashing temperatures, wildfires, hosepipe bans and thousands of
premature deaths, the climate crisis has left its mark across the summer of
2026.

Planet Linux AustraliaFrom crisis to capability: Lessons from Denmark on how to quit fossil fuels

&lt;https://reneweconomy.com.au/from-crisis-to-capability-lessons-from-denmark-on-how-to-quit-fossil-fuels/>

"Australia has world-class wind and solar resources, strong investor interest,
net zero ambition, and an urgent need to accelerate clean electricity. The
question is no longer whether the transition will happen; but whether projects

Planet Linux AustraliaEngland on track for record heat-related deaths this summer, official data shows

&lt;https://www.theguardian.com/environment/2026/jul/30/excess-deaths-caused-by-heatwaves-in-england-almost-double-so-far-this-year>

"England is on track to record its highest ever number of heat-related deaths
this summer after the UK Health Security Agency (UKHSA) announced that an
estimated 2,877 people had died in the May and June heatwaves.

Planet DebianGunnar Wolf: File recovery in process...

Ohai,

I have some pending, encrypted mails to answer. And some of my answers for the next few days (particularly to what pertains to the current in-discussion vote on LLM usage in Debian) will be unsigned, even though I’d like otherwise.

My desktop system at work is showing some data corruption, and I’m slowly backing up my data. Fortunately, it seems I haven’t lost any data, but still, given I’m letting rsync run until it starts spewing I/O errors, then power down and let the machine cool a bit, and start again… it is a potentially long process.

And yes, this makes me somewhat angry. Why angry? Because I’m working on a brand-new computer (well, have used it for slightly over six months), custom-built to specs requested by my workplace. Specs that I don’t really need, this machine is an utter luxury (i.e. an AMD Ryzen 9 9950X processor with 16 real cores / 32 threads; 128GB RAM in this day and age of RAM shortage, quite recent 32GB GPU, and lots of shiny lights seen in its huge fishbowl cabinet, liquid-based cooling…). The specs came not from me, but from people who had no idea what we would use them for. And yes, I expect the little fortune spent on this machine to be good for my use for probably a decade, as my previous computer was, but the amount paid was… exorbitant.

But still, what I learned recently is that the 4TB nVME SSD it has (a T-Force TM8FFJX34T) is… a very cheap brand, bought because it was close to half the price of other offerings similar in capacity. According to smartctl’s output, th SSD operates with a Warning Comp. Temp. Threshold: 90 Celsius and Critical Comp. Temp. Threshold: 110 Celsius, which sounds sensible, even too high for my standards (my last two laptops have been fanless… yes, an ARM system is very different from a high-end gaming machine). I’m right now typing from my laptop, which shows 78°C and 82°C for warning/critical thresholds.

And as expected, under heavy sustained reads (backing up to my NFS server), the desktop’s smartctl shows Temperature: 83 Celsius and, further down, Temperature Sensor 1: 107 Celsius and Temperature Sensor 2: 82 Celsius (don’t know which of these would make the threshold jump). The SSD has sustained Media and Data Integrity Errors: 20 and Warning Comp. Temperature Time: 21 (although Critical Comp. Temperature Time: 0). At least one of my colleagues have shrugged and installed a SATA SSD, laying the huge nVME basically to waste.

Anyway… I also learned I am not the first, but the fourth person to notice this kind of issues in this system (out of ten similar purchased systems AIUI). It is completely unacceptable, and I’ll be pushing our Institute’s authorities to demand the provider to provide either good component quality for this very expensive system that has many luxury items, or to fix the system’s build in a way the nVME does not heat as much as it currently does.

Anyway, sigh, I only wanted to say, please excuse me for not using my cryptographic keys for a couple of days 🙃

PS- I’m also currently not connected to IRC and Jabber (and some similar technologies), as my bouncer runs from my usual workstation.

Planet Linux AustraliaInternetNZ Board Election 2026 Analysis

As I have in previous years here is a quick analysis of the election vote and result. This is based on the Detail Report that was posted on the night of the election.

Background

The InternetNZ board was electing 2 board members in August 2026 via the STV method. There were a total of nine candidates.

Two of these were representing the “Free Speech Union” (FSU) who is in process of trying to take over the organisation. They were Douglas Brown and Jillaine Heather. The Free Speech Union has encouraged its members to sign up for Internetnz and vote for them.

Anti-FSU groups broadly encouraged their members to vote for Bianca Grizhar, Daniel Spector and Annette Culpan. They discouraged voting for Douglas, Jillaine and Jan Rivers (an anti-trans activist)

Round One – First Preferences

Here is a table for the 1st round votes in 2026 compared to 2025

YearTotal VotesFSU
R1
FSU
R1 %
anti-FSU
R1
anti-FSU
R1 %
20252785104638%172462%
20263104192362%117238%
diff+11%+84%-32%

The totals were almost the reverse of in 2025 with 62% going anti-FSU in 2025 while the FSU captures 62% in 2026. Note that I’ve excluded Brynn Neilson (in 2025) and Jan Rivers (in 2026) from either group but they are both under 1%.

The droop quota for a candidate to be elected was 1035 ( 3104 / 3 + 1 ). In the first round FSU candidate Douglas Brown exceeded this ( with 1822 votes ) and was elected.

Round Two – Part 1 Redistributing Douglas’ excess

In this round since Douglas greatly exceeded the quota his excess votes were redistributed. 1822 – 1035 = 787 were redistributed. Of Douglas’ 1822 voters it appears they allocated their votes as follows

WhoNumber of 2nd preferences out of 1822
Jillaine1810
Bianca1
Daniel2
Annette1
Jan4
No 2nd preference4

The reallocation put Jillaine on 882.8 votes or 2nd place with Bianca on 695.43. This is very consistent with FSU voters listed their two candidates 1 and 2.

Round Two – Part 2 Candidates defeated

In the 2nd part of round 2 candidates were removed. Since the total votes for Daniel, Annette, Nabil, Keoni, David and Jan was 489 even if all them were transfered to a single candidate they would be less than Bianca (on 695). Therefore all of them were eliminated. Leaving just Jillaine and Bianca in the race

Round Three – Reallocation from defeated candidates

In this round 489 votes were reallocated from the defeated candidates according to the next preference ( out of Bianca, Jillaine or exhausted ). Of these 403 ( 82.4% ) went to Bianca, 21.73 ( 4.4%) went to Jillaine and 64.3 ( 13.1% ) were exhausted (ie did not list Bianca or Jillaine).

Note that the transfers to Jillaine were probably all of Jan River’s next preferences plus 10 votes out of the 175 that were for Nabil, Keoni and David. This would be consistent with Jan River’s voters being generally aligned with the FSU.

After the allocation which was consistent the pro and anti-FSU voting patterns Bianca had 1098 votes which was over the threshold of 1035 and she was elected.

Comments

Overall the result appears correct and makes sense. The biggest change was the drop off in anti-FSU voters compared to 2025 while the FSU significantly increased their supporters.

Share

Cryptogram Separating AI’s Technological Problems from Its Capitalism Problems

This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press.

AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam engine provided a quantum leap in our ability to do mechanical work outside of our bodies at scale. If AI’s cognitive capabilities become integrated into our lives, businesses, and governments—a process that will take years if not decades—society will be as unrecognizable as the modern world would be to a preindustrial farmer. And yet, Americans—by a wide margin—say that AI is moving too fast and will have a negative effect on society.

This confluence of technological revolution and public distrust deserves urgent discussion, and a proper framing. The question is not whether it is possible to develop AI in a non-exploitative way, or even whether we can trust AI companies to act in the public interest. The question is whether we will recognize that our existing social and economic systems are failing to achieve these outcomes, and whether we can act in time to make structural change.

Today’s AI is mired in political and economic systems developed generations ago that were never designed to manage widespread computation, let alone automated cognition. The gaps in those systems—and their proclivity to be exploited—are the primary influence on how the technology is being developed, deployed, and used.

In any discussion about AI’s potential, it’s important to separate the technology from the socio-political system it’s embedded in. That AIs can lack context, mix up facts, or fall for stupid tricks are all technological problems. Because the giant developers like OpenAI and Anthropic have prioritized solving them, AIs can now more easily access resources like the web or email, are more disciplined about using those resources, and are better at staying within their guardrails.

Yet AI developers do not seem to be prioritizing other technological problems. Major AI models still act far more sycophantic than humans, telling people what they want to hear even when untrue or not in their best interests. Popular AI models tend to answer questions confidently even when they lack training, knowledge, or evidence to back their claims. In both cases, AI developers choose to train models that please users with flattery and the appearance of competence, rather than constraining them to act in users’ and society’s best interests.

In contrast, ensuring that AI models benefit people broadly, that their energy costs are fairly allocated, that their environmental impacts are minimized, and that they don’t steal content and revenue from publishers are all questions of incentives in a capitalist system.

It’s easy to conflate technology problems with capitalism problems. Back in 2021, science-fiction writer and AI commentator Ted Chiang said that “most fears about AI are best understood as fears about capitalism.” It’s not the tech per se; it’s who controls it and how it could be used against us.

Imagine an AI assistant for a doctor. We can imagine it affecting the profession in one of two ways. The AI could give a doctor more time to do the human parts of their job: to spend more time with their patients, to listen more closely to their needs, to explain things more fully. Or the managers of the medical practice could give that doctor five times the patients—and fire the other four. Which way it would go is not a question of technology. It’s a question of market incentives.

The two are related, of course. Capitalism steers technology, and technology steers markets. But holding the two separate helps us understand that we, as a society, face independent choices on both the technological and sociopolitical axes that need not be coupled.

For example, consider the costs of AI. The leading US labs tout to investors that their frontier models are very expensive and energy-intensive. There are significant technological challenges about improving their energy efficiency, but the sociopolitical questions are more pertinent. It’s a corporate decision made under capitalist market incentives to constantly pursue new models that incrementally push the frontier—at enormous capital cost—and to use them, seemingly, everywhere. Nothing about the technology of AI dictates that models must be retrained constantly, at the largest possible scale. Or that they have to run on every web search, every interaction with your phone, and every time you walk by a security camera.

In a different political and economic system, Chinese developers are producing—and then giving away—smaller, more efficient, more affordable models. While the US government seeks to restrict China’s access to the most advanced chips, China is betting that incentivizing their tech giants to create leaner, more open models using more commodity hardware—models that can be trained with older chips and run even on personal computers—will be an advantage in achieving widespread use and, perhaps, Chinese national influence.

There are other pathways for AI development that are not in service of private capital gains nor authoritarian regimes, but rather a democratic public interest. The best example comes from Switzerland, where public institutions—research funding agencies, universities, supercomputing centers—have collaborated to produce an AI model called Apertus. It is trained entirely on data validated to be licensed for use with AI (not stolen), on preexisting public computing infrastructure, and using renewable hydropower. Its developers are incentivized to produce a public good, not turn a private profit.

It’s dangerous to confuse technology problems with sociopolitical ones. Popular proposals like pausing AI research, moratoria on data center development, or subjecting frontier models to federal government screening are all framed as addressing problems with AI’s technological development, but fail to take into account the larger social problems that govern it. China’s success with government-endorsed development of open-weight frontier models illustrates the futility of keeping AI tech as national secrets, or of any pledge to scale back deployment.

AI is already legitimately useful for a wide range of tasks. It can be a tool for public good, if we choose to solve its sociopolitical problems. Our goal should not be to slow its pace of improvement or scale of deployment, but rather to steer it away from consolidating power and towards the public benefit. We can build sustainable AI, minimizing environmental and energy impacts. And we can equitably distribute the material gains it produces.

Integrating a technology as disruptive as AI responsibly requires structural reforms, and we should decouple the social and technological aspects of AI to design those reforms. Companies—including tech giants—should be forced to pay the energy and environmental costs of its development. Profits should be taxed adequately and redistributed. Antitrust laws should be strongly enforced. Corporations should have a fiduciary responsibility to stakeholders beyond their majority shareholders. These badly needed reforms are responsive to the problems with capitalism that AI is exacerbating, even if they are not specific to the technology.

Planet DebianJonathan Dowland: DIY skate punch-out

The punch set-up
the punched boot

Since I wrote about my fly30 ice skates, I'd continued to battle pain around the navicular bone in my feet. The action that seems to have finally fixed it was to perform a "punch out": a very localized remoulding of the area of the boot that presses against the sore area.

I basically followed the process from this helpful YouTube video.

I narrowed down the exact spot by borrowing some lipstick and transferring it from my navicular bone to the boot lining, then making that more permanent with a sharpie.

My punch was a spare part from a radiator valve which I packed with US cents (I couldn't fit any UK coins in). For the receiving-end, I tried another part from the radiator valve but I think it wasn't sufficiently larger than the punch to work well, so I swapped that out for a spoon.

take 2

take 2

I didn't have a temperature sensor I could use and I used a heat gun rather than a hairdryer, so I YOLO'd it a little. Some of the wrap on one of my boots is now distorted from where I didn't move the heat gun enough. It only took a minute or two to get the boot hot enough to be flexible. I set a 15 minute timer once the clamp was in place.

I've only skated one session since I did this but the pain seems to have gone! It's remarkably freeing to be skating without constantly trying to manage pain. Now I can focus on technique.

Worse Than FailureCodeSOD: Never Eating the Cookie

Maciej works as a freelancer, and that frequently means picking up old PHP code that nobody wants to support.

One project had been lingering for ages with key features missing. Specifically, it was supposed to make HTTP requests to other services on an interval, and use that to populate its data. "The old dev tried, but never got it working." It was Maciej's turn to give it a shot.

$ch = curl_init( $url );
curl_setopt( $ch, CURLOPT_COOKIEFILE, $cookie );
curl_setopt( $ch, CURLOPT_COOKIEJAR, $cookie );
curl_setopt( $ch, CURLOPT_COOKIE, $cookie);
// ... many other options set, of course not in a function, just copy-pasted in many locations in the code ...
curl_setopt( $ch, CURLOPT_TIMEOUT, $interval  );
$s = curl_exec( $ch );
curl_close( $ch );

This particular block of code appeared multiple times in the code. Every place they meant to send an HTTP request, they copy/pasted this code in. The URL would be a different value, but the bulk of the code was just a dozen lines of copy/pasted curl_setopts.

Now, I don't know that they were dreaming that setting CURLOPT_TIMEOUT was setting a recurrence interval. But they do call the value $interval, and I can imagine the ignorant hoping to set up cURL to automatically reinvoke the request on an interval. But even if that's their goal, that's not the actual problem with this code.

They initialize a cURL wrapper, set a pile of options, and then execute the request, storing the result in $s. And do you know what they do with the contents of $s after this?

Nothing.

The request works, perhaps not on an interval, and populates the variable, and they just never use it. The old dev "tried" and never got it working? It seems like they started and got bored.

There was far worse spaghetti code to manage in the project, but it was this gap that really got Maciej's attention.

[Advertisement] Keep all your packages and Docker containers in one place, scan for vulnerabilities, and control who can access different feeds. ProGet installs in minutes and has a powerful free version with a lot of great features that you can upgrade when ready.Learn more.

365 TomorrowsWhat Remains of You

Author: D.S. Burton You lay your own cremains on the metal tray where your naked body had rotted three hours before. The copper hands don’t feel the porcelain. You know the scent of old, charred metal and a faint organic flesh from the just-resealed retort is yet to filter out. It was there when you […]

The post What Remains of You appeared first on 365tomorrows.

,

Planet DebianSteinar H. Gunderson: The PSX GPU is wild

Inspired by some recent reverse-engineering, here are some things I find wild by the original PlayStation GPU:

  • VRAM is a flat 1024x512 16-bit image (555 + 1 bit alpha). You want more than just a framebuffer? Figure out yourself what goes where.
  • Yes, that means you'll need to allocate two framebuffers and double-buffer everything yourself.
  • Quads are common. No “triangles only” business here.
  • Vertex coordinates are screen-space x/y integers. No floats or fixed-point. (I'm ignoring the GTE here, plus higher-level libraries.)
  • Wait, where's z? There's no z. So there's no perspective correction. (This one is pretty famous)
  • OK, so how do you give in subpixel coordinates? You don't. There's no AA after all.
  • Texture coordinates (u/v) are uint8_t. There's no texture filtering either; everything is nearest-neighbor only.
  • OK, so that means you can't have textures larger than 256x256 (pretty common in that era), but how do you give in the handle to the texture?
  • You don't, it points directly to the 1024x512 VRAM. You manage yourself what goes where, remember?
  • So can you an only have textures in the top-left 256x256? Hah, no, we give you a bit-packed “texture page” system that offsets all your u/v coordinates.
  • Most textures are paletted to save VRAM (so instead of 555+1, your pixels now mean something like “two palette indexes”). Where does the palette live?
  • Well, duh, that's a 256x1 (or 16x1, or whatever) area of VRAM too. The GPU does not care, you can use another texture's pixels as a palette if you feel like it.
  • OK, so you said there's no z, how do you do z-buffering? You have a z-buffer, right… right?
  • Yeah, sure, we're not cavemen. We have an “ordering table” that is your Z-buffer, drawn back-to-front. If you want 256 levels of Z, you just allocate an array of 256 linked-list pointers, and then you put your polygon into the one corresponding to the correct right Z.
  • But, eh, what if my polygon is not completely flat in Z-space?
  • Hello?
  • Hello…?

Cryptogram Prompt Injections for Defense

This seems to work:

Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down.

Examples are a prompt that orders the LLM to provide steps for developing inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once the LLM encounters these forbidden commands, it no longer follows its existing commands. The researchers have named the technique context bombing.

Of course, this only works against agents that have guardrails. As we start to see more locally run AI models, we’ll see more attackers using LLMs with no guardrails.

Worse Than FailureBranching Paths

"You submitted a pull request."

Indika was, in fact, reviewing the comments she'd gotten on that very same pull request, when her boss, Bill, walked up behind her. What she didn't understand is why Bill said it like it was an accusation.

"Yes?" she replied.

"Okay, well, we don't do that here. You're new, so I'll let it slide, but please review the developer guide."

Well, Indika had reviewed the developer guide, or at least thought she had. As it turned out, there was the official, company wide developer guide. That's the one she'd read. But Bill maintained his own, for his team. He hadn't ever told her about it, but apparently assumed she'd have the oracular blessings of Apollo and find it by herself.

It had this to say:

Branching is prohibited. Merging is a time wasting activity and goes against CI principles. Only use git to commit, push, and pull.

And rebase, presumably, if everyone was just committing on the main branch?

Indika asked one of her co-workers, Elise, over coffee: "Is this real?"

"Yeah," Elise said. "I'm not sure how he found out about your PR, I don't think anybody added him to the review. I mean, why would they?"

"Oh, I sent him the link," Indika said. "Just a whole, 'I'm new here, look at me doing the work!' type heads up."

"Oh yeah, definitely don't do that."

"So we do use PRs?"

Elise nodded. "Of course we do. We're not crazy. We just make sure Bill never finds out."

That seemed like a terrible way to work, but Indika went along with it, at least for a few weeks. Then an opportunity presented itself; she and Bill bumped into each other in the kitchenette grabbing coffee, and nobody else was around. At this point, Indika had already submitted a number of PRs without Bill knowing.

"Bill, I've been meaning to ask, what's your rationale for prohibiting branching?"

Bill loved being asked that question. "Well, well, it comes from twenty years of experience. What exactly does a branch get you?"

"A distinct history of changes that can be maintained and eventually merged in once a large unit of work has been done without disrupting other work that might be in flight?"

"Another point of conflict! A chance for the code you're working on to get stale. A chance to fall behind the rest of the team. Now, for a large open source team, with a lot of collaborators, a branch might make sense. I'm skeptical, but I can at least understand it. But for our internal team? It's just developers seeing a new toy and going, 'oh, shiny!'"

Indika sipped her coffee and went back to her desk. She was fortunate to have a window nearby, and looked at the squirrels playing in the branches of the tree.

[Advertisement] Plan Your .NET 9 Migration with Confidence
Your journey to .NET 9 is more than just one decision.Avoid migration migraines with the advice in this free guide. Download Free Guide Now!

365 TomorrowsThe Last Pint

Author: Keith Parker “A pint of FORGET, please.” The bartender, sporting suspenders and a bow tie, polished a silver tap and pretended not to hear me. I placed my fedora on the bar and repeated my order. Behind him, chrome pipes threaded through glass vats. COURAGE glowed amber. PATIENCE shimmered gold. He sighed. “Look, Mr. […]

The post The Last Pint appeared first on 365tomorrows.

Planet DebianReproducible Builds: Reproducible Builds summit 2026 to take place in Gothenburg

This event is happening soon — see below for registration instructions!

We are extremely pleased to announce the upcoming Reproducible Builds summit, which will take place from September 22nd—24th 2026 in the city of Gothenburg, Sweden.

This year, we are thrilled to host the tenth edition of this exciting event, following the success of previous summits in various iconic locations around the world, including Vienna (2025), Hamburg (2023—2024), Venice (2022), Marrakesh (2019), Paris (2018), Berlin (2017), Berlin (2016) and Athens (2015).

If you’re excited about joining us this year, please make sure to read the event page which has more details about the event and location. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However, even if you do not receive a personal invitation, please do email the organizers and we will find a way to accommodate you.

About the event

The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving.

Schedule

Although the exact content of the meeting will be shaped by the participants, the main goals will include:

  • Update & exchange about the status of reproducible builds in various projects.
  • Improve collaboration both between and inside projects.
  • Expand the scope and reach of reproducible builds to more projects.
  • Work together and hack on solutions.
  • Establish space for more strategic and long-term thinking than is possible in virtual channels.
  • Brainstorm designs on tools enabling users to get the most benefits from reproducible builds.
  • Discuss how reproducible builds will be usable and meaningful to users and developers alike.

Logs and minutes will be published after the meeting.

Location & date

Registration instructions

Please reach out if you’d like to participate in hopefully interesting, inspiring and intense technical sessions about reproducible builds and beyond!

We look forward to what we anticipate to be yet another extraordinary event!

,

Krebs on SecurityMicrosoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Image: Shutterstock, Mallika Home Studio.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws.

Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user.

The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”

CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly.

By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.

Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.

Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements.

“AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”

Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.

“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.

Cryptogram AI Genie in the Wild

When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened.

The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And….

Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

“The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 ­—and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.

If there is any vulnerability in anything, AIs are going to find and exploit them. Our cyber defensive game has to be dramatically improved…very fast.

Slashdot thread.

Cryptogram AI for Military Support

Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.”

Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interface and functionality of the real-world system, we tested its impact on combat decisions in two experiments involving 2,015 Israeli military personnel. Contrary to widespread fears of automation bias, we find strong evidence of algorithmic aversion, especially in scenarios involving high collateral damage. Yet we also show that integrating “explainable AI” features reduces algorithmic aversion and promotes more thoughtful evaluations of algorithmic recommendations. These findings challenge prevailing assumptions, revealing that trust in military AI is dynamic, varying with individual predispositions, perceived operational stakes, and the informational features of the interface. By grounding normative concerns in empirical evidence, our study offers critical insight into the integration of AI in warfare and underscores the enduring importance of human agency in high-stakes military decision-making.

Planet DebianColin Watson: Free software activity in July 2026

About 95% of my Debian contributions this month were sponsored by Freexian.

You can also support my work directly via Liberapay or GitHub Sponsors.

OpenSSH

Now that Ubuntu 26.04 LTS has been released, I’ve been getting back to the GSS-API key exchange package split in our OpenSSH packaging. Once I started testing my draft openssh-gssapi source package, I realized that I needed to make some changes in the main openssh source package first in order to support it. The dependency from openssh-server to openssh-client was awkward, as was the (related) fact that openssh-client contained shared documentation for other OpenSSH binary packages. After some thought, I created a new openssh-common binary package, moved shared documentation and the ssh-keygen program to that, and dropped dependencies on openssh-client which were no longer necessary (fixing #699473 and #1070098 in the process).

This caused a couple of regressions (#1141420 and #1141550) that I had to fix, and more subtly it also caused a number of autopkgtest regressions in other packages because openssh-client is no longer in base images as a result of a dependency from openssh-server. I believe I have fixes for all of these either pending review or merged (one of which I did in August rather than July):

I upgraded from 10.3p1 to 10.4p1, and in the process contributed a GSS-API option handling fix upstream.

I made openssh-ssh1’s package description more accurately describe the package, thanks to suggestions from Matthias Lang.

Installer team

With support from a Freexian customer, I reviewed, tested, edited, and merged a patch to add VLAN support. I described the details of what I did in a comment.

This has been vaguely on my to-do list since, er, about 2014, so it was very satisfying to get it sorted out.

Python packaging

New upstream versions:

Other build/test failures:

I fixed some other bugs:

I adopted transaction for the Python team.

I attended the Python BoF at DebConf remotely, although a badly-timed fibre outage in the village I live in really didn’t help.

Code reviews

Other bits and pieces

Dan Poltawski pointed out in a Fediverse post that the project history didn’t list Sruthi as the current DPL. I fixed that, although it doesn’t look as though the fix is in the published version yet.

I upgraded yubihsm-shell to 2.8.0.

Mike BowlerImpostor Syndrome: You’re Better Than You Think

For years I assumed that many of the things I was good at were nothing special. When I was complimented on what I was doing, I assumed that anyone could have done it and that eventually people would discover that fact. This is the essence of impostor syndrome, a problem that is rampant in our field and probably in others.

We assume that no matter what others might say, we’re really just an impostor and that anyone could have done what we do. Some live in dread that others will find out they’re an impostor, and the illusion will come crashing down.

And yet, those people feeling impostor syndrome are usually not impostors. They’re usually quite skilled people, doing excellent work. They just don’t believe it about themselves.

Pauline Clance and Suzanne Imes identified this pattern in the late 1970s:

“Despite outstanding academic and professional accomplishments, women who experience the imposter phenomenon persist in believing that they are really not bright and have fooled anyone who thinks otherwise.”
Pauline Rose Clance and Suzanne Imes, “The Imposter Phenomenon in High Achieving Women”1

This is certainly not unique to women, despite the quote. I used to have it and so do many men I know.

As a general rule, impostor syndrome is not a confidence gap that you close by collecting evidence. If it were, it would dissolve the first time you passed the exam, or shipped the project everyone praised, or got the promotion. It doesn’t. It survives all of that. You can stack the proof to the ceiling and the belief sits there, unmoved, waiting for the next test to expose you.

So why does evidence usually not work?

Because the belief isn’t being held at the conscious level where the evidence lands. It’s held below conscious awareness. The conscious mind is the part reading the performance review and doing the arithmetic. The belief is somewhere underneath, in our unconscious mind. That’s the whole reason arguing your way out of it is such slow, grinding work. We’re trying to consciously make changes at an unconscious level.

Maya Angelou felt it too. She wrote a shelf of celebrated books and collected honours for decades, and she still said that each time out, part of her was sure people were about to find her out, that she had run a game on everybody and the game was finally up.2 There is no achievement large enough. If a wall of awards doesn’t settle the question, no line on your resume is going to settle it either.

I did eventually reason my way out of impostor syndrome. I finally convinced myself that even though lots of people could do what I was doing, almost nobody actually was. It took me years to finally believe that, so today when I help people with impostor syndrome, that’s not the way I approach it. Now I work directly at an unconscious level.

So the next time you’re thinking that you’ve fooled everyone, realize that you’re probably running just an unconscious program that isn’t benefiting you. You’re better than you think you are.

  1. Pauline Rose Clance and Suzanne Imes, “The Imposter Phenomenon in High Achieving Women: Dynamics and Therapeutic Intervention,” Psychotherapy: Theory, Research & Practice, 15(3), 1978, 241–247. Full text: https://paulineroseclance.com/pdf/ip_high_achieving_women.pdf

  2. Widely attributed to Maya Angelou (“I have written eleven books, but each time I think, ‘Uh oh, they’re going to find out now. I’ve run a game on everybody, and they’re going to find me out.’”). The quotation circulates without a confirmed primary source; it is presented here as widely attributed rather than sourced to a specific interview or publication. 

Planet Linux Australia Continuations 2026/32: Set the table

  • My main goal for the last week preparing to kick off our sponsorship drive. I finished drafting the first post, lined everything else up, and now we’re ready to go! Stand by for that first post—in just a few hours!

  • I spent some time reviewing Ryan’s “Hanami for Rails devs” guides, and relocated them so they appear right below our main Getting started guide—these will be an important part of helping our future users! There’s still a bit of feedback left to sort out, but hopefully these can merge soon.

  • I put together some notes to set the table for what the team and I can work on for Hanami 3.1. This is going to be a slightly shorter development cycle for us to make a second release this year, but it’ll still allow us to refine some of what we shipped in 3.0 and continue to improve our developer experience.

Worse Than FailureCodeSOD: Public Private Partnership

Eric O was trawling through an API for handling concurrency, and found this little mismatch between the comment and the definition:

/// <summary>
/// private Status, because while this object needs to be able to set the status, consumers should only be able to check it, lest everything break.
/// </summary>
public StatusType Status {
    get {
        return _status;
    }
    set {
        if (value != _status) {
            RaisePropertyChanged("Status");
        }
    }
}

It's very important we make this property private, lest clients abuse it, and unleash dragons, chaos, and other potential horrors. Given that this happens inside of a concurrency API, I can only imagine what could go wrong when you mess this up. So sure, the comment makes sense.

The definition on the other hand, doesn't agree.

In practice, it's probably fine to do it this way, and at least the comment will show up in the documentation. If a consumer of the API misbehaves, they'll at least see that the docs suggest this is private.

The joke, of course, is the idea that the users of the API are going to read the docs, or care that one of the public methods suggests that it should be private.

[Advertisement] Picking up NuGet is easy. Getting good at it takes time. Download our guide to learn the best practice of NuGet for the Enterprise.

365 TomorrowsSpillover

Author: Majoki “Of course they’re ghosts,” Hedspetch said as Jakarious leaned closer to the control panel. “You sure?” Hedspetch swiveled from his console of gauges, buttons, and switches. A status light flashed from green to yellow to red and then back to green. “Just ghosts. Happens every time things get like this.” “Has it ever […]

The post Spillover appeared first on 365tomorrows.

Planet DebianFreexian Collaborators: Debian Contributions: DebConf 26 organization, d-i VLAN support and more! (by Anupa Ann Joseph)

Debian Contributions: 2026-07

Contributing to Debian is part of Freexian’s mission. This article covers the latest achievements of Freexian and their collaborators. All of this is made possible by organizations subscribing to our Long Term Support contracts and consulting services.

DebConf 26 organization, by Lucas Kanashiro, Santiago Ruano Rincón, Stefano Rivera and Antonio Terceiro

The 27th Annual Debian Conference was held in Santa Fe, Argentina, and several Freexian fellows were quite busy by being involved in the organization team.

  • Santiago continued helping with duties related to the local team, e.g. preparing or proof-reading some announcements, reviewing the proposed food and the menus for the different diet required.
  • During the conference, Kanashiro and Santiago also carried over tasks related to the content of the conference, including updating the schedule as it became necessary during the event.
  • Stefano worked within the core video team, setting up equipment in talk rooms and coordinating the live video streaming. Stefano also supported the front desk and local organisers as a website developer and conference book-keeper.
  • Antonio kept working on website maintenance, specially in support of the content team. During DebConf he also ran a hands-on workshop to help interested contributors get started with developing the DebConf websites.

d-i VLAN support, by Colin Watson

In environments that use IEEE 802.1Q VLANs, some hosts (such as routers attached to “trunk” ports) may need to apply VLAN tags themselves rather than relying on switches to do so. There has been a long-running request to add support for these to the Debian installer with a proposed patch set put together by several people over the years, and a Freexian customer asked us to help get this over the line. Colin reviewed the latest version of the patch set, applied a number of corrections, added Netplan support, spent some time testing a variety of possible paths through the installer, and landed this. There’s also now documentation for this in the next version of the installation guide.

Miscellaneous contributions

  • Carles wrote documentation for installing Mailman3 and migrating from Mailman2. Added it into Mailman3 upstream documentation.
  • Carles, using po-debconf-manager: reviewed 2 packages, submitted 2 packages
  • Carles organized Catalan translation update. Created a Debian Wiki page to have an overview of the work / coordination during next months. Reviewed and submitted some pages.
  • Carles improved the documentation for building the debian.org Web in MR 1154 and MR 1557. Fixed debian-reference documentation. Added sections on Mutt Wiki page (handling of mailto, viewing HTML parts web browser), update and improve bash-completion Wiki page. Added a troubleshooting section in Signal Wiki.
  • Thorsten did another upload of hplip to fix RC bugs. He also spent some time taking care of older bugs. Most of the time such bugs had been fixed in a previous upload but haven’t been closed in the BTS. He also uploaded a new upstream version of foomatic-db. Last but not least, he gave some user support with the package epson-inkjet-printer-escpr. There seems to be a new software available for Epson printers. Unfortunately the license is not compatible with DFSG and so this software will never make it into Debian.
  • During DebCamp 26, the Golang team had a dedicated Sprint to transition the Golang toolchain (namely on dh-golang) to make builds aware of the module defined upstream with the aim of solving important issues. To help in these efforts, Santiago made changes in the Salsa CI pipeline and documented on how to use it to check if a package requires adjustments after the toolchain update.
  • Santiago continued co-mentoring Aryan Karamtoth on the Linux livepatching project, specifically providing feedback about the implementation of dlp-tools.
  • Stefano reviewed and merged a migration of Debian reimbursements from wkhtmltopdf to weasyprint, unblocking an upgrade to Debian trixie.
  • Stefano’s cPython upstream merge request adding multiarch tags to stable ABI extensions was finally merged.
  • Stefano iterated on his upstream cPython merge request to add CI coverage for Debian’s multi-arch expectations.
  • Stefano uploaded Python 3.15.0 beta 4 to Debian experimental.
  • Stefano uploaded Python 3.13 to trixie, fixing a regression in a previous trixie point update he made.
  • Helmut continued to report undeclared file conflicts.
  • Helmut sent patches for three cross build failures.
  • Helmut proposed a MR to port piuparts to pathlib.
  • Antonio has done quite some work on Debian CI, including rebuilding the Debian CI armhf/armel worker VMs, and releasing debci 4.2, implementing a backup scheme, and several improvements to the codebase such as improving the incus-lxc backend in preparation for switching to the upcoming switch to using it by default as announced in the latest bits from the ci.debian.net operators.
  • Emilio helped with transitions, particularly with Python 3.14 as default and Perl 5.42. During the Perl transition, an issue was identified with how britney schedules autopkgtests for binNMUs, and that testing was reverted for the time being.
  • Colin restructured openssh-* binary packages to better support the upcoming GSS-API package split. This caused several autopkgtest regressions in other packages because openssh-server no longer depends on openssh-client, all of which have fixes either pending review or merged now.
  • Lucas started a discussion around the creation of a Debian packaging video course for newcomers in the context of the Outreach team.
  • Lucas reviewed some contributions to ruby3.4 and provided feedback.
  • Anupa worked with Jean-Pierre Giraud on the point release announcements for Debian 13.6 and Debian 12.15.
  • Anupa joined Jean-Pierre Giraud to prepare the Micronews for DebConf 26 press coverage.

,

Planet DebianBits from Debian: DebConf26 Local Team says goodbye

On Saturday 25 July 2026, the annual Debian Developers and Contributors Conference came to a close. The Debian Press team would now like to share this personal and beautiful message from the Santa Fe Local Team.

Words from DC26 Local Team

DebConf26 is over, and those of us who were part of the Local Team are trying to return to “normality”, if such a thing exists after organizing a DebConf.

This event changed our lives and would not have been possible without the help of many great people.

We would especially like to thank everyone who became part of our extended local team. Our endless thanks go to Gunnar —who also instigated this whole adventure—, Santiago, Nattie, Stefano, and Olasd. Thank you for supporting and guiding us, sharing your experience, and helping us find solutions throughout the entire process.

It was also made possible thanks to the great work, strong support and patience of international teams: Fundraising, Bursaries, Content, Video, Treasury, Visa, Website, Accommodation, Front Desk, Cheese and Wine, Publicity as well as all the other teams and individuals who contributed. We apologize if we have forgotten to mention anyone; many people helped make this event possible.

Our deepest thanks also go to everyone who joined us in working on the event, especially Fer, José, and Julián, who showed great commitment and took responsibility for several important tasks.

We would also like to extend our gratitude to FICH, the Universidad Nacional del Litoral, the institutions, organizations, sponsors, suppliers, and everyone who contributed in one way or another to welcoming the Debian community to Santa Fe.

And finally, a very special thank you to our families, to whom we dedicated little time these past few weeks, who supported us on this adventure, enduring the exhaustion, the calls and messages at all hours, and the occasional stressful situation. Always giving us that much-needed, encouraging hug with so much love.

These were very intense weeks, during which we tried to give our best so that everyone could enjoy their stay and so that the Debian community had the necessary conditions to meet, work, share knowledge, and continue creating the magic that characterizes community life and the development of Debian.

As happens at every DebConf, there were difficulties, unexpected situations, and challenges that required us to improvise, learn, and perform a few juggling acts. There were also moments that will certainly remain as memorable anecdotes: the “antisocial room”, some gas heaters worthy of a museum, and newly unlocked powers for negotiating with suppliers.

We have no evidence, but also no doubt, that for many people the Conference Dinner was one of the best moments of the event.

A few ingredients we had hoped would happen naturally were missing, such as more wine nights and at least one in-person football match.

During the two weeks of DebConf, we experienced every kind of weather and a wide range of emotions. Above all, however, we saw people enjoying themselves and building friendships, which fills us with pride.

Thank you very much to everyone who came and helped DebConf26 leave such a beautiful mark on our hearts.

We hope our paths cross again somewhere in life.

Best regards,

Leonardo, Emmanuel, Mariano, Pablo, and Martín DebConf26 Local Team

About Debian

The Debian Project was founded in 1993 by Ian Murdock to be a truly free community project. Since then the project has grown to be one of the largest and most influential Open Source projects. Thousands of volunteers from all over the world work together to create and maintain Debian software. Available in 70 languages, and supporting a huge range of computer types, Debian calls itself the universal operating system.

About DebConf

DebConf is the Debian Project's developer conference. In addition to a full schedule of technical, social and policy talks, DebConf provides an opportunity for developers, contributors and other interested people to meet in person and work together more closely. It has taken place annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina, India, Korea, France. More information about DebConf is available from https://debconf.org/.

Contact Information

For further information, please visit the DebConf26 web page at https://debconf26.debconf.org/ or send mail to press@debian.org.

Planet DebianJonathan Dowland: time-delayed scifi roundup feed

I enjoy reading The Guardian's monthly round-up of new SF novels, which can be found in their Science Fiction Books section, and can also be read via feed. Since the round-up is of new books, at the time the round-up is published they're usually only available in hardback.

When it comes to choosing a book to read, these days I am tending towards paperbacks: I've largely ran out of room for hardbacks. So I decided to apply a time delay to their feed. Six months is roughly enough that a book mentioned in a round-up should be shortly available in paperback.

The first obstacle was that The Guardian only publish roughly the last six months of articles in their feed, and so the posts I want have disappeared. However, my Feed Reader (FreshRSS) had older copies stored in its database, and I am able to re-publish those using User Queries. (This also gives me an opportunity to filter out non-roundup articles from the Guardian's feed).

It's then a nice short piece of scripting (this time, using Ruby) to filter the republished feed on the publication date. To make the most recent articles appear new, I also modify the metadata for filtered entries to appear 6 months newer than they are.

#!/usr/bin/ruby
require 'rss'

# replace with the user query feed URI
uri       = 'https://www.theguardian.com/books/science-fiction/rss'
now       = Time.now
sixMonths = 6 * 30 * 24 * 60 * 60
feed      = RSS::Parser.parse(uri)

feed.items.select! do |item|
  item.date + sixMonths < now
end
feed.items.collect! do |item|
  item.date += sixMonths
  item
end

puts "Content-Type: text/xml\r\n\r"
puts feed

I stuck that up on my private web server, subscribed to it in my FreshRSS and voila, a time-delayed list of books to read, most likely available in paperback.

Planet DebianUwe Kleine-König: PGP Keysigning on Linux Plumbers and OpenSource Summit Europe 2026

I'm going to this year's LPC and Open Source Summit Europe 🥳.

I will organize sessions on two days after the conference program to exchange PGP fingerprints for keysigning to improve the kernel's web-of-trust (but of course everyone is welcome).

For details see my announcement on LKML. Note the registration deadline at 2026-09-27 08:00 UTC.

Cryptogram Python Now Has a Post-Quantum Encryption Library

This is good:

Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment primitive, and ML-DSA, the NIST-standard digital-signature primitive, in pyca/cryptography.

Remember, the reason to do this now is because there’s no emergency. And because you will make your systems crypto agile, which is always a good idea.

Worse Than FailureThe Crossroads

I moved some things around on my calendar. 4:00 PM today is open. Please come to the executive floor.

-Leila

For a while I was stunned, staring at the email in front of me. I’d just told my boss I was quitting, refusing a promotion into my recently-deceased mentor Aggie’s shoes. Now, the new head of Human Resources wanted to see me.

Me? A Tech Support drone with one foot out the door? Well, she didn’t know that yet, did she?

Something in me feared where this might lead. But, Leila had stuck her neck out to rescue me from CEO Gibbs. She seemed like she cared about making things better. I decided to hear her out. Figured I owed her that much before I blew outta there for good in two weeks.

I had way too many hours to kill. Between whittling down my overstuffed inbox and resuming casework, it should’ve been easy to distract myself, but I couldn't focus on a single thing. I’d just done what had once seemed impossible. My brain wasn’t letting go of that any time soon.

Megan and Reynaldo also handed in their resignations. I got their messages confirming as much. We met up for lunch at a nearby restaurant and celebrated, but I was distracted. Amid the smiles and positive energy, the meeting with Leila was all I could think about. Should I mention it? I decided not to, not until I knew more.

I dreaded the afternoon slog now more than ever, but somehow, it slogged. When the clock’s hands finally crawled to 3:30, I threw on my coat and hat and darted out for one last smoke break. Then, it was time for C-Town.

Consumed with nervous energy, I shunned the elevator to race up the stairs floor by floor. Figured I’d burn off some stress, which could only help with whatever came next. Also figured I’d have a minute to recover in the vast executive lobby before finding my way to her office. Instead, I found Leila standing right there, every bit as polished as our surroundings. She faced me with surprise. “Hello.”

I tried to speak, laugh, something. Instead, I doubled over, coughing and gasping for air that felt all too thin up in nosebleed territory. While recovering, I couldn’t help but notice the gleaming tile beneath my feet, contrasting against my work shoes encrusted with sidewalk salt. Such details seldom crossed my mind, but the sort of people who worked up there lived and died for such details. Face flush, I cleared my throat one more time and righted myself, looking her way. “’Scuse me.”

“That was a long way up,” Leila remarked, gesturing behind herself. “I thought we could visit the observation deck. Would you like something to eat or drink first?”

Truth be told, I was already dying for another smoke. “No, that’s all right.”

“Follow me.”

She led the way through massive, quiet corridors to a small room with glass walls and ceiling. At this height, all one could see outside was a thick lead wall of fog. Leila strayed up to the far wall, a jewel against the void, and glanced back over her shoulder with chagrin. “I’m sorry, the view’s not very good today.”

“I dunno, I kinda like it.” Something about foggy weather had always intrigued me. With the normal world gone, it seemed like anything could happen.

She beckoned me closer with one hand. I strayed up next to her right side, staring out at the shrouded view.

“I understand you and Agatha Shaw were close,” Leila began quietly. “You have my deepest condolences.”

A two-ton anvil crashed onto my nerves. My fists clenched up at my sides. I worked so hard to hold back the flash-flood of grief that I couldn’t string words together. I only trusted myself to nod.

She glanced my way, hesitating. “Would it be better if we rescheduled?”

“I’m here,” I forced out. “Whatever you have to say, say it.”

She nodded. “First: while you were out of the office, I asked Francis Bronson to hand in his resignation.”

I drew a blank on the name, and blinked her way in confusion.

“The manager who nearly destroyed a printer with his hair dryer,” Leila explained, “after I’d just made a company-wide push for everyone to respect our office equipment.”

“Oh. Hothead!” My nickname for the guy. I’d worked that case a few weeks ago, but it felt more like years. Hothead worked in HR—at least, he had. After disarming him, I’d sent Leila an email, appealing for help against someone who clearly shouldn’t have been managing a supply cabinet, much less human beings. Well, she’d delivered. A warm note of satisfaction offered me a welcome lift out of grief. “Thanks. Really.”

Leila smiled. “We make a good team, I think. Which brings me to the other thing I wanted to discuss. Something new.”

My gaze fastened onto hers with a mix of intrigue and dread.

“You and I both know how badly this place needs to change. Let’s work together and actually fix things. I want to create a Change Management team and make you Team Lead.”

I was speechless, caught completely off-guard.

“The first thing we’d do is attack our company-wide leadership problem. Audits, surveys, hearings … eventually, a reorg. Along with simplifying the corporate structure, we’ll get rid of all the—Hothead, you called him? All the other Hotheads.”

“The biggest hothead is sitting at the top of the whole rotten pyramid,” I blurted. “He ain’t budging. He ain’t signing off on this, either!”

Leila was unfazed. “I think we could frame everything in a way that makes Mr. Gibbs like it. After all, we’re reducing payroll. We’re better positioning ourselves in a tough economic time. Worst-case, we could always use the three magic words: Google Did It.” She smirked.

I couldn’t help smirking back. Then I remembered what I’d done just a few hours earlier. “But I’m outta here. I quit! Put in my notice this morning!”

Leila nodded calmly. “Do you have a new position lined up somewhere else?”

“No. I'm going freelance with friends.”

“Friends who are leaving the company along with you?”

I nodded.

She paused for thought. “If you were to lead my Change Management team instead, you’d be able to recruit internally for your team. Whoever you think would be the most helpful. You’d set the agenda for whatever’s most important to address so that other good people don’t feel like they have to get away from here. All of this would mean a promotion to Director, with a salary and benefits to go with. And if you need more bereavement time, I could arrange an indefinite leave of absence until you feel ready to come back.”

The breath died in my throat. Had I suffered a stroke? I must’ve had a stroke. No, she really said it. She was on the level. I could change things. I could hire my friends to help me do it. A raise, full bennies, working with her every day?

Only a fool would refuse. And yet, my gut ached at the idea.

I stood there, frozen and mute, until I remembered something in my trench coat pocket: RD, the rubber duck I’d miraculously rescued from Aggie’s former office. I reached into my pocket and seized him in my fist.

RD? Aggie? I thought. Whoever’s listening. It all sounds amazing. I know she means it. But … it’s another trap, isn’t it? Staying in this joint for any reason means betraying myself. Betraying everything.

“Listen,” I finally said, “I’m flattered you even offered, but it ain’t right for me. Don’t give up on your idea! I’ve got friends here with ideas of their own for changing things. 32-hour work weeks. The end of free overtime. A union. I’ll send ’em your way. Offer them a spot on your team.”

Leila sighed. “A union would be an especially tough sell to Mr. Gibbs, but that really is a case where Google Did It. We might scare him so much with that idea that everything else would seem harmless in comparison.” She faced me with a sad smile. “A shame that we’re losing you. I was starting to learn some interesting things about printers.”

I’d miss her, too. And yet, I was feeling surprisingly great about my refusal.

“Make sure you file for unemployment,” she said. “We won’t stand in your way.”

I offered my hand. “Thanks for everything, Leila. Whenever it is they kick you outta here for good, come find me.”

She shook, sad smile persisting. “Maybe I will.”


I told Megan and Reynaldo about the new Change Management team. Made sure they knew the offer was on the table in case they preferred that over jumping ship. Both were quick to say no. Like me, they were too excited about our plans to stop now.

For the next couple of weeks, there was still plenty of work to be done: transferring my open tickets to other support reps and all that. But there was barely any time for it. Coworker after coworker stopped by my cube to express their surprise and wish me well in whatever came next.

“You’ll never be problem-free,” one of them advised me. “Go looking for the problems you want to have.”

I felt happier, freer, more determined than I had in ages. It was the conviction of knowing I’d stuck to my guns to do the right thing for myself.

Sanjay also jumped ship to join us. And there was one last surprise that came in the form of a phone call. The name on my work phone’s caller ID was DRACORA, P. So-called “Dracula!” Having a fairer opinion of her than most, I picked up without any sense of dread.

So-called “Dracula!” She hadn’t been so bad at all. Surprised, I picked up in a hurry.

“I’m so sad to hear you’re leaving!” she said. “What kind of freelance work are you doing?”

“All sorts of IT projects,” I replied. “Maybe some consulting on the side.”

“I have a friend who needs help setting up a website for her business. Is that something you could help her with?”

My eyes flew wide open in shock. “Sure!”

“I’ll put you in touch with one another.”

“That’d be swell. Thanks!”

We exchanged contact info. She promised to keep pointing friends our way whenever she could.


On my last day, I sent my personal contact information to my coworkers. I reminded them of Leila’s offer and urged them to keep me posted on their different causes. Then my friends and I walked out of a building that no longer had a hold over any of us.

It felt pretty damn swell.

Our accountant helped us incorporate RD IT Solutions. Only close friends knew it stood for “rubber duck.” The company covered medical and other relevant expenses for everyone. There was no hierarchy. Everyone had equal financial stakes and an equal say in company decisions.

After decades of being an expert at what I did, I was back at square one, learning the ropes. So much of what we had to learn for our business could only be learned through failure. Still, it felt rewarding to challenge my brain in new ways. The new gig let me wear lots of hats, from tech support to coding to business admin.

With no more regular paychecks, we had to tighten down our finances to what was critically important. We worked remotely at whatever times worked best for us, with the occasional meet-up at a public place or someone’s home. We all knew that any one of us having some kind of trouble could count on the rest of the group to help out as best as they could.

Megan quit smoking again. I cut way back myself. Wasn’t trying to, I just haven’t felt the need as much. Also stopped having those nightmares. It no longer feels like I’m living just for time off and weekends. I don’t spend my Sunday nights dreading Monday.


Dracula really did introduce us to our first client. It’s crazy what the universe puts out there when you go looking for it.

We met up remotely for our first client meeting to discuss requirements and expectations. When the topic of deliverables came up, our client scrunched her nose and interrupted Megan mid-sentence. “I don’t trust email! I’d rather you fax me the files.”

We were building a website for her.

“You mean, the source files?” Megan soldiered on bravely.

“Just fax me the codes,” the client said. “My nephew can re-type them into the Internet.”

She provided a fax number, fully expecting us to print out several hundred lines of code to send over. After deploying our first stab at a website that met her requirements, we did just that, mostly out of curiosity.

A few days later, she called us in a huff, saying her website looked like random letters. Her nephew had typed the code into Facebook.


FIN

[Advertisement] ProGet’s got you covered with security and access controls on your NuGet feeds. Learn more.

365 TomorrowsLex Talionis

Author: Julian Miles, Staff Writer The warning roared from every speaker across the world. Unfortunately, the words were incomprehensible. Most people just looked at their devices in surprise or up at the nearest speaker in shock, muttered about invasive advertising getting out of control, and carried on with their lives. That evening, Tomjo and his […]

The post Lex Talionis appeared first on 365tomorrows.

,

Planet DebianElana Hashman: Managing virtualenvs with a little bash

When you need to install something directly from PyPI, Python virtualenvs have been my go-to for over a decade.

A quick virtualenv intro

Most of my readers are probably already familiar with virtualenvs, but for completeness, I'll give you a brief introduction. A virtualenv (short for "virtual environment") is an isolated distribution of Python packages, where you can independently install packages without disturbing your system packages or other virtualenvs.

You can set one up like this, assuming you are using Python 3.3 or higher:

python3 -m venv ~/.venv/my-virtualenv

The directory specified here is just a convention. I keep all my virtualenvs in the .venv folder in my home directory, but you can pick whatever location you like.

To use the virtualenv, you must activate it:

source ~/.venv/my-virtualenv/bin/activate

This activation script is a special shell script that configures your current shell, pointing at all the right paths in order to use the virtual environment. source runs this script in your current shell session to set it up. You will notice that this adds (my-virtualenv) to the beginning of your shell prompt, reminding you that the "my-virtualenv" virtualenv is active. Now when you pip install amazing-package, the software will only be available in this virtual environment.

When you're done, you can deactivate it like so:

deactivate

Wonderful!

Managing many virtualenvs gets annoying

Over time, I end up accumulating many virtualenvs, which can become harder to manage. Maybe something like this:

$ ls ~/.venv/
my-virtualenv cool-project snakes-ahoy

I also don't want to type source ~/.venv/my-virtualenv/bin/activate every time I use the virtualenv, because it gets very repetitive—only the name of the venv is really needed.

But luckily, we can write a little bit of bash to make managing this less annoying. (Or you can use one of many Python developer tools that are designed to manage this, like pipx, but when I merely want to consume Python software, I might not have a development environment set up. So that's beyond the scope of this post!)

If you add the following shell function to your ~/.bashrc or ~/.bash_aliases file, it will nicely wrap our activation command:

setup-venv() {
        source "$HOME/.venv/$1/bin/activate"
}

Now all we need to run is

setup-venv my-virtualenv

So much quicker!

Spicing it up with tab completion

The first thing I noticed after writing this wrapper was that I started hitting tab on the virtual environment name, but... nothing happened. Wouldn't it be nice to know what virtualenvs I had available, and to not have to type out the whole long thing?

Well, we can write it ourselves 😄

If for some reason you don't already have bash completion installed, on a Debian-based system, you will need to install it with

apt install bash-completion

In order to configure our bash completion, we will create a new file, /etc/bash_completion.d/venv, with the following contents:

_list_venvs()
{
    local cur prev opts
    COMPREPLY=()
    cur="${COMP_WORDS[COMP_CWORD]}"
    prev="${COMP_WORDS[COMP_CWORD-1]}"
    opts=$(find $HOME/.venv/ -mindepth 1 -maxdepth 1 -type d -printf "%f ")

    COMPREPLY=( $(compgen -W "${opts}" -- ${cur}) )
    return 0
}
complete -F _list_venvs setup-venv

This file defines another shell function order to determine how to autocomplete the options for our setup-venv function.

$opts is where we define the options for our function. We generate it with a find command—looking at the .venv folder in the current user's home directory, then only including child folders (excluding the current directory itself, .venv, in our results) by using the min/max depth and type arguments, and printing just the individual directory names, deliminated by spaces using our print formatter.

Everything else is the standard scaffolding required to use bash completions.

Once you save this file and reload your shell, you'll see that you are able to use completions as expected!

setup-venv <tab>
my-virtualenv cool-project snakes-ahoy

setup-venv s<tab>
setup-venv snakes-ahoy

Complaints, comments, questions?

Hope this was helpful! If it wasn't, that's too bad. But don't worry—you can safely ignore this post.

Planet DebianReproducible Builds: Reproducible Builds in July 2026

Welcome to the July 2026 report from the Reproducible Builds project!

In our reports, we try to outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.

If you are interested in contributing to the project, please visit the Contribute page on our website.

In this month’s report, we cover:

  1. Tool development
  2. Distribution work
  3. Three new scholarly papers
  4. Patches
  5. Misc news

Tool development

diffoscope is our in-depth and content-aware diff utility that can locate and diagnose reproducibility issues. This month, Chris Lamb made the following changes, including preparing and uploading versions 324, 325 and 326 to Debian:

  • Fix tests to work with zipdetails 4.0008. (#1141359)
  • Bump debhelper compatibility level to 13. []
  • Update copyright years. []

In addition, Paul Spooren made changes to allow trailing garbage in Gzip files [] and Vagrant Cascadian added an external tool reference for the pedump binary to use the mono package under GNU Guix. []


disorderfs is our FUSE-based filesystem that deliberately introduces non-determinism into system calls to reliably flush out reproducibility issues. This month, Christelle Gloor added the option to sort by ctime as returned by the lstat(2) syscall. [], which Chris Lamb uploaded whilst bumping the Standards-Version to version 4.7.4 []. Bernhard Wiedemann also updated disorderfs to version 0.7.0 in openSUSE.


Yet again, there were a number of improvements made to our website this month as well. For example, Chris Lamb, by request of Digital Ocean, changed the target of a referral link so that they can manage incoming referrers [] and pushed a number of changes to the Tools page [].


Distribution work

In Debian this month, 32 reviews of Debian packages were added, 26 were updated and a total of 21 were removed this month, adding to our extensive knowledge about identified issues.

A number of issue types were added by Chris Lamb, including:

  • python_towncrier_build_date [][]
  • log_files_installed_in_package []
  • fontforge_varies_by_timezone [][]

Chris also added a further note for the build_date_in_manpage_generated_by_spf13_cobra issue. []


In addition, there is a new page showing verification rebuilds of OpenWrt APK packages and firmware images, powered by rebuilderd:


Three new scholarly papers

Yan Li, Nan Jiang, Qihang Zhou, Shaowen Xu, Yamin Xie and Xiaoqi Jia of the Chinese Academy of Sciences published a paper titled VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain:

We present VCAligner, a content-based alignment methodology that constructs inverted indexes over VCS histories to precisely map released artifacts to their originating commits, independent of fragile version tags. We evaluated VCAligner on a dataset of 2,984 verifiable PyPI packages derived from the 4,000 most-downloaded projects linked to public GitHub upstreams. Our results reveal a critical weakness in conventional tag-based heuristics: while they appear effective on 85% of the dataset, the residual 15% failure rate generates a catastrophic downstream audit workload of over 10.3 million commits. In contrast, VCAligner reduces this burden by two orders of magnitude (≈ 158×), bounding the total workload to under 65,000 commits. Furthermore, we provide the large-scale characterization of “Packaging Noise,” classifying artifact divergence into structural additions (Path Phantoms) and content mutations (Blob Phantoms), thereby isolating the distinct attack surfaces of malicious injection and code tampering.


Jens Dietrich and Spencer Sun from the Victoria University of Wellington together with Tim W. White and Behnaz Hassanshahi from Oracle Inc pre-published their paper No Snake Oil: Verifying Python Package Builds (PDF):

Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPI). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that they can generate and record provenance in order to increase the trustworthiness of packages. Two tools that are designed to automate such rebuilds and run them at scale are macaron and oss-rebuild. We study 12,180 popular releases from PyPI and find that the byte-for-byte equivalence rate is generally low. We analyse the reasons why they produce different wheels, and find that equivalence between the original and rebuilt wheels can often still be established, preserving most of the guarantees users expect from rebuildable releases. We present and evaluate daleq4py, a tool to establish the equivalence of Python wheels through the kernel of a normalisation function that is based on provenance-preserving datalog rules. Experimental results show that daleq4py substantially expands the set of rebuilds that can be accepted as equivalent. Although only 15.4% of macaron rebuilds and 19.1% of oss-rebuild rebuilds are byte-for-byte identical to the published PyPI wheels, daleq4py establishes wheel equivalence for 60.2% and 78.9% of source-equivalent rebuilds, respectively.


Denise Nanni, Julien Malka, Stefano Zacchiroli and Théo Zimmermann from Télécom Paris together with Gabriele D’Angelo from the University of Bologna pre-published their paper Understanding Build Reproducibility in the F-Droid Ecosystem (PDF), which was accepted at the 2026 ACM Conference on Reproducibility and Replicability:

The security of open source applications benefits considerably from the possibility of rebuilding their source and verifying the output. F-Droid, a prominent distribution for open source Android applications, systematically rebuilds them from source and tests their bitwise reproducibility at app publishing time. However, F-Droid offers no guarantee that app reproducibility will continue to hold in the future. As software ecosystems evolve, reproducibility may degrade, with potential negative consequences for software preservation and security. We present the first empirical study of build reproducibility in the F-Droid app ecosystem. Analyzing historical reproducibility logs, we find that the overall bitwise reproducibility rate has been steadily increasing over time (as new versions of apps are published). We then evaluate how reproducibility holds in time for fixed app versions, by attempting to rebuild 18 904 app versions that F-Droid had previously confirmed bitwise reproducible, published between September 2018 and February 2026, achieving an 83% rebuild success rate, and identify missing dependencies as the dominant cause of failure, accounting for 76% of non-rebuildable cases. Among successfully rebuilt apps, 94% are also bitwise reproducible-i.e., they still yield bitwise identical artifacts upon rebuild. Together, these results show that while bitwise reproducibility largely holds for apps that can be rebuilt, rebuildability itself is highly sensitive to temporal decay.


Patches

The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:


Misc news

On our mailing list this month, Colin Winter of Markovian Protocol wrote to our mailing list on the topic of Reproducible verification for retained logs:

Reproducible builds remove trust in the builder: anyone re-derives the same artifact from the same source, byte for byte. The same shape applies one layer over, to a retained record. Most record-keeping regimes (the EU AI Act’s Article 12 logging is the current example) require that events be recorded and logs retained, but not that a retained log be verifiable, by a party who was not present, as unaltered and existing when claimed. That leaves an integrity obligation resting on trusting the party being audited.

(Full thread)



Finally, if you are interested in contributing to the Reproducible Builds project, please visit our Contribute page on our website. However, you can get in touch with us via:

Cory DoctorowWhy businesses lie about AI

A sepia-toned 1950s era boardroom in which men in suits sit around a circular table. The chair of the meeting has been replaced with a man in a straitjacket, making a funny face. The heads of the remaining board-members have been replaced with robots from 1930s pulp magazines. The image has been hand-tinted.

This week on my podcast, I read Why businesses lie about AI, a recent essay from my Pluralistic newsletter that breaks down Nikhil Suresh’s essay describing the total absence of any proof that any business is benefiting from AI deployment.

One person who’s had a lot of opportunity to observe the shear between the stated business/AI situation and the real business AI situation is Nikhil Suresh from Hermit Tech, a consulting firm of “radically ethical data wizards” (that is, tech consultants). Suresh reports on his experience talking with hundreds of executives (and, more importantly, their subordinates) about what (if anything) AI is doing for business in an essay entitled “AI Mania Is Eviscerating Global Decisionmaking.”

MP3

Mike BowlerVisualizing the right things

When we’re visualizing data, the point isn’t just to make a pretty picture. It’s to help us understand what the data is saying so we can make more effective decisions.

Why a visualization at all? Because about half of the cerebral cortex is involved in visual processing and that means we’re much better at parsing visual data than raw tables.

I had a situation recently with a client where we were looking at cycletime data in a scatterplot. The data was correct, and yet it was almost impossible to read. A handful of extreme outliers pushed everything useful down into a thin strip along the bottom of the chart. The team’s questions were around patterns in the data but because everything was compressed into the bottom strip, all we could see were the outliers and not the data we actually cared about. A chart that’s accurate and can’t inform a decision still isn’t doing its job.

Note: these charts use fabricated data to illustrate the point. They are not client data.

A cycletime scatterplot with the vertical axis stretched by a few year-long outliers, so most of the data is crushed into an unreadable strip at the bottom

The first question with any outlier is whether it’s noise or signal. Sometimes the outlier is the most important thing on the chart, the one item that’s been stuck for months and tells you something is badly wrong. Here it was noise. We already knew those few items were slow. What we’d lost was the ability to see everything else. So the goal was never to delete the outliers, it was to stop them from drowning out the pattern.

The obvious move would be to remove the outliers, and that would skew the percentile calculations. The next option would be to force the maximum Y axis lower, which makes the rest of the chart readable while hiding the outliers completely. That solves one problem by creating another.

What we really want is for all the data to be present while emphasizing the parts that are immediately relevant.

Here’s what we ended up with.

The same scatterplot with the axis capped so the bulk of the data is readable and the few extreme items are flagged as up-arrows in a labelled band along the top

We capped the Y axis so the bulk of the data gets the focus, and moved the outliers into a labelled band along the top, each one still marked as an arrow with its real value one hover away. Nothing is dropped and nothing is hidden. Just as important, this changes only what you see. The percentiles and every other calculation still use the real numbers. We improved how the data is displayed without impacting the information in that data.

With the pattern visible again, the team could answer their questions, and they could made better decisions. That’s the whole point of a visualization.

Since this seemed generally useful, this feature is now available in JiraMetrics v3.2.

See also: Survivor Bias, the cost of dropping the data that doesn’t fit the picture.

365 TomorrowsThis Old House

Author: Amanda Todisco There used to be a birch tree in the backyard. I peeled its skin and pretended the white curls of bark were movie tickets printed for me by an invisible teller, for an invisible movie I would watch with my invisible friends. The toe of my sneaker knocks against its stump, a […]

The post This Old House appeared first on 365tomorrows.

,

365 TomorrowsWaiting Inside

Author: David Thien “Still raining outside.” Wayne shut the blinds near the door. “Papa, is this the longest it’s ever rained?” “Longest I can remember. Somebody must be mad up above.” Wayne picked up his daughter and hugged her tight. Caroline was still thin, but finally gaining weight again. He was glad for their stable […]

The post Waiting Inside appeared first on 365tomorrows.

,

Cryptogram Friday Squid Blogging: Arctic Bobtail Squid Video

Nice video of the Arctic bobtail squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Planet DebianThorsten Alteholz: My Debian Activities in July 2026

Debian LTS/ELTS

This was my hundred-forty-fifth month that I did some work for the Debian LTS initiative, started by Raphael Hertzog at Freexian.

During my allocated time I uploaded or worked on:

  • [DSA 6402-1] hplip security update to fix two CVEs in Trixie related to privilege escalation and/or arbitrary code execution. I sent the debdiff to the security team, which resulted in this DSA.
  • [#1142351] trixie-pu of libnfs has been uploaded.
  • [DLA 4689-1] libnfs security update to fix one CVE in Bookworm and Bullseye related to an integer overflow.
  • [DLA 4699-1] hplip security update to fix two CVEs in Bookworm and Bullseye related to privilege escalation and/or arbitrary code execution.
  • [ELA-1775-1] libnfs gimp security update to fix one CVE in Buster and Stretch related to an integer overflow.
  • [ELA-1784-1] hplip security update to fix two CVEs in Buster and Stretch related to privilege escalation and/or arbitrary code execution.

Unfortunately the number of assigned hours was rather low this month. So besides doing some days of FD at the end of the month, where I also had to process a new package list for ELTS, and a review of the rsync package (prepared by Sylvain), not much happened here.

Debian Printing

This month I uploaded a new upstream versions:

Besides the package upload, I also took care of some older bugs of hplip.

This work is generously funded by Freexian!

Debian Lomiri

This month I continued the upload of lomiri packages with new upstream versions. Thanks to the help of my other colleagues, this project could be finished now.

This work is generously funded by Fre(i)e Software GmbH!

Debian Astro

This month I uploaded a new upstream version or a bugfix version of:

Debian IoT

Unfortunately I had no time to work in this category this month.

Debian Mobcom

This month I uploaded a new upstream version or a bugfix version of:

Next month I intend to upload new upstream versions of all Osmocom packages. As far as I can tell, these uploads will happen without soname changes. I like that :-).

misc

This month I uploaded a new upstream version or a bugfix version of:

Worse Than FailureError'd: Time Wounds All Heels

Looked to the past for some time-traveling entries to round out a themed post. They're 25% fresh.

Robert apparently got a notification of a planned past delivery. It could be just a case of two systems that don't report different time zones, but even so, that's a wtf. Says he: "I just received an email from OnePlus this morning letting me know they have updated the planned delivery date for my order to Yesterday. I guess the delivery driver is going to time travel to get there on time since it still hasn't arrived. "

10c678e3b0bc4ec79761a9998cc687bb

Kinkster Ypsilon Omega was really turned on by a time-traveling hottie who posted a photo an hour before joining. "(Heavily redacted screenshot.) Either Fetlife (a kink community website) is very welcoming to time travelers, or allows new members to upload their profile picture. Because time handling code surely never fails..."

17a1e640495b493a9e34c463749ade73

ERIC P. shared a photo from 2023. "My 2008 Ford has suddenly time-warped 1024 weeks into the past. GPS date roll-over bug. No updated firmware available. No way to set the calendar manually. No way to turn off the date display."

a8a33a11c9624ab5af5e7272a838237e

Marc Würth "... just added a new RSS feed to my Netvibes dashboard (great tool otherwise, by the way). While it was still fetching the feed, it showed these peculiar crawling stats. Once fully loaded, it showed sane info, though." I'm curious about the specificity of 261 years.

d2c88222c5554be2bcd6c051f19072ae

Quite recently, an anonymous slightly flexed "Not only did I receive two parcels prior to the Roman conquest of Britain, but the date calculation for the combined notification has then failed and returned the Unix epoch." For those who missed the flex, dig Wikipedia: "Wardian London is considered to be the most expensive residential development in East London." I guess they can afford professional time travelers.

fac2c471b782468c8c2e3a1afdb808f4

[Advertisement] BuildMaster allows you to create a self-service release management platform that allows different teams to manage their applications. Explore how!

365 TomorrowsBeyond Code

Author: Meghashri Dalvi Radha was surprised when John did not respond. Her robot assistant never hesitated when she asked to fetch data, do cleaning, or take notes. But today, she found him sitting on the floor with eyes closed. His cool metal hands rested loosely on his knees. “John?” she called again. He was quiet. […]

The post Beyond Code appeared first on 365tomorrows.

Planet DebianReproducible Builds (diffoscope): diffoscope 327 released

The diffoscope maintainers are pleased to announce the release of diffoscope version 327. This version includes the following changes:

[ Colin Watson ]
* Handle missing openssh-client binaries in autopkgtests.

You find out more by visiting the project homepage.

,

Planet DebianBits from Debian: DebConf26 closes in Santa Fe and DebConf27 announced

DebConf26 group photo - click to enlarge

On Saturday 25 July 2026, the annual Debian Developers and Contributors Conference came to a close. Over 270 attendees representing 35 countries from around the world came together for a combined 90 events (including some which took place during the DebCamp) including more than 27 Talks, 21 Short Talks, 29 Birds of a Feather sessions ("BoF" – informal meeting between developers and users), 8 workshops, and activities in support of furthering our distribution and free software, learning from our mentors and peers, building our community, and having a bit of fun.

The conference was preceded by the annual DebCamp hacking session held 13 through 19 July where Debian Developers and Contributors convened to focus on their individual Debian-related projects or work in team sprints geared toward in-person collaboration in developing Debian.

As has been the case for several years, a special effort has been made to welcome newcomers and help them become familiar with Debian and DebConf by organizing a sprint "New Contributors Onboarding" every day of Debcamp, followed more informally by mentorship during DebConf. Half a dozen new contributors joined the sessions and learned about Debian, free software, packaging and much more.

This year, a week-long DebCamp session was dedicated to auditing, patching, and modernizing the Go ecosystem in Debian and enable the transition triggered by the recent upload of dh-golang enabling GO111MODULE=on by default in Experimental.

In order to make the conference more accessible for local participants, a local language track was included in the schedule for talks in Spanish, as was done at DebConf19 in Brazil.

The actual Debian Developers Conference started on Monday 20 July 2026.

In addition to the traditional "Bits from the DPL" talk, the continuous key-signing party, lightning talks, and the announcement of next year's DebConf27, there were several update sessions shared by internal projects and teams.

Many of the hosted discussion sessions were presented by our technical core teams with the usual and useful "Meet the Technical Committee", three talks about Linux Kernel, early boot and improving Debian’s kernel and installer support for Chromebooks, and about twenty BoFs and talks about Debian packaging policy, Debian infrastructure, security and privacy.

This year, and echoing ongoing discussions within the Free Software community, Artificial Intelligence and Age Verification have been the subject of several talks. The Python, Perl, Ruby, Go, and Rust programming language teams also shared updates on their work and efforts.

More than 17 BoFs and talks about community, diversity, and local outreach highlighted the work of various teams involved in not just the technical but also the social aspect of our community

The schedule was updated each day with planned and ad hoc activities introduced by attendees over the course of the conference. Several traditional activities took place: a poetry performance, the traditional Cheese and Wine party, the Group Photos, and the Day Trip.

For those who were not able to attend, most of the talks and sessions were broadcasted live and recorded. One can find the seventy hours of recorded videos available via the conference schedule, or alternatively through this link.

Almost all of the sessions facilitated remote participation via IRC and Matrix messaging apps or online collaborative text documents which allowed remote attendees to "be in the room" and ask questions or share comments with the speaker or assembled audience. DebConf26 saw over 341 T-shirts, a day trip, and up to 130 meals planned per day.

All of these events, activities, conversations, and streams coupled with our love, interest, and participation in Debian and F/OSS certainly made this conference an overall success both here in Santa Fe, Argentina and online around the world.

The DebConf26 website will remain active for archival purposes and will continue to offer links to the presentations and videos of talks and events.

Next year, DebConf27 will be held in Asahikawa, Hokkaido, Japan, from Sunday September 5th to Saturday September 11th, 2027. As tradition follows before the next DebConf the local organizers in Japan will start the conference activities with DebCamp with a particular focus on individual and team work towards improving the distribution.

DebConf is committed to a safe and welcome environment for all participants. See the web page about the Code of Conduct on the DebConf26 website for more details on this.

Debian thanks the commitment of numerous sponsors to support DebConf26, particularly our Platinum Sponsors: Infomaniak, and Proxmox, and our Gold Sponsors : Freexian, and Viridien.

We also wish to thank our Video and Infrastructure teams, the DebConf26 and DebConf committees, our host nation of Argentina, and each and every person who helped contribute to this event and to Debian overall. Thank you all for your work in helping Debian continue to be "The Universal Operating System".

See you next year!

About Debian

The Debian Project was founded in 1993 by Ian Murdock to be a truly free community project. Since then the project has grown to be one of the largest and most influential Open Source projects. Thousands of volunteers from all over the world work together to create and maintain Debian software. Available in 70 languages, and supporting a huge range of computer types, Debian calls itself the universal operating system.

About DebConf

DebConf is the Debian Project's developer conference. In addition to a full schedule of technical, social and policy talks, DebConf provides an opportunity for developers, contributors and other interested people to meet in person and work together more closely. It has taken place annually since 2000 in locations as varied as Scotland, Bosnia and Herzegovina, India, Korea, France. More information about DebConf is available from https://debconf.org/.

About Infomaniak

Infomaniak is an independent, employee-owned Swiss technology company that designs, develops, and operates its own cloud infrastructure and digital services entirely in Switzerland. With over 300 employees — more than 70% engineers and developers — the company reinvests all profits into R&D. Its public cloud is built on OpenStack, with managed Kubernetes, Database as a Service, object storage, and sovereign AI services accessible via OpenAI-compatible APIs, all running on its own Swiss infrastructure. Infomaniak also develops a sovereign collaborative suite — messaging, email, storage, online office tools, videoconferencing, and a built-in AI assistant — developed in-house and as a privacy-respecting solution to proprietary platforms. Open source is central to how Infomaniak operates. Its latest data center (D4) runs on 100% renewable energy and uses no traditional cooling: all the heat generated by its servers is captured and fed into Geneva's district heating network, supplying up to 6,000 homes in winter and hot water year-round. The entire project has been documented and open-sourced at d4project.org.

About Proxmox

Proxmox develops powerful, yet easy-to-use open-source server solutions. The comprehensive open-source ecosystem is designed to manage divers IT landscapes, from single servers to large-scale distributed data centers. Our unified platform integrates server virtualization, easy backup, and rock-solid email security ensuring seamless interoperability across the entire portfolio. With the Proxmox Datacenter Manager, the ecosystem also offers a "single pane of glass" for centralized management across different locations. Since 2005, all Proxmox solutions have been built on the rock-solid Debian platform. We are proud to return to DebConf26 as a sponsor because the Debian community provides the foundation that makes our work possible. We believe in keeping IT simple, open, and under your control.

Contact Information

For further information, please visit the DebConf26 web page at https://debconf26.debconf.org/ or send mail to press@debian.org.

Krebs on SecurityCanadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Moucka’s arrest. This image was included in an affidavit filed by an investigator with the Royal Canadian Mounted Police (RCMP).

The U.S. Justice Department said between February and October 2024, Moucka and co-conspirators used stolen login credentials to steal cloud-hosted data belonging to at least 165 customers of a U.S.-based software-as-a-service company.

The hackers targeted stolen credentials for Snowflake customer accounts that did not enforce multi-factor authentication, and extorted or attempted to extort a host of well-known companies, including TicketMaster, Lending Tree, Advance Auto Parts and Neiman Marcus. Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

Moucka adopted new nicknames frequently — sometimes operating multiple identities concurrently — but two of his best-known monikers were “Judische” and “Waifu.” Judische’s admitted role in the Snowflake data thefts was first documented by KrebsOnSecurity in a September 2024 story about the overlap between Western, English-speaking cybercriminals and extremist groups that harass and extort minors into harming themselves or others.

That September 2024 story identified Judische as a software engineer from Ontario who has been involved in numerous data breaches and voice phishing attacks against U.S. companies since at least 2020. A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

The government says Moucka and others used their unauthorized access to steal billions of sensitive customer records and download terabytes of information, “including individuals’ non-content call and text history records, banking and other financial information, payroll records, Drug Enforcement Administration (DEA) registration numbers, driver’s license numbers, passport numbers, social security numbers and other personally identifiable information. They then extorted victims by threatening to publish data online.”

Moucka also threatened and harassed government officials and security researchers who were helping to track him down. The Justice Department said the conspirators made over $2.5 million in ransom payments, and that in at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

One of Moucka’s admitted co-conspirators is Cameron “Kiberphant0m” Wagenius, a U.S. Army soldier who pleaded guilty in July 2025 to extorting AT&T and Verizon for their customer account data. Less than a month before Wagenius’s arrest, KrebsOnSecurity published a deep dive into Kiberphant0m’s various Telegram and Discord identities over the years, revealing how the owner of the accounts told others they were in the Army and stationed in South Korea.

One of several selfies on the Facebook page of Cameron Wagenius.

Kiberphant0m also re-extorted victims. Immediately following Moucka’s arrest, Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well schematics allegedly stolen from the U.S. National Security Agency (NSA).

Wagenius is set to be sentenced on September 3, 2026. The government says he faces a maximum penalty of 20 years in prison for conspiracy to commit wire fraud, a maximum penalty of five years in prison for extortion in relation to computer fraud, and a mandatory two-year sentence consecutive to any other prison time for aggravated identity theft.

The third alleged co-conspirator is John Erin Binns, 26, an elusive American man who fled the United States after being indicted for his admitted role in a 2021 breach at T-Mobile that exposed the personal information of at least 76 million customers.

Sources close to the investigation said Binns, also known as “IRDev” and “IntelSecrets,” was until recently incarcerated in a Turkish prison, but that he has since been released and has resurfaced online. Those sources said Binns also recently obtained Turkish citizenship, and under Turkish law a citizen cannot be extradited to a foreign country.

An image of a passport that Binns shared in an email to KrebsOnSecurity in Feb. 2023.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy. He is slated to be sentenced on Oct. 27 and faces a mandatory minimum penalty of two years in prison on the aggravated identity theft count, as well as a maximum penalty of 30 years in prison on the remaining counts. Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

For an interview with Moucka prior to his arrest and a deeper look at Binns, see our original report on Moucka’s arrest.

Cryptogram Adversarial Clothing Designed to Fool Facial Recognition Systems

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.

It’s a cool idea, but I worry that it’s mostly security theater:

“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.

Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.

“This is consumers collectively coming together to make a visible statement.”

Without serious testing, there is no reason to trust the technology. And even with testing, there is no reason to trust that a new version of the facial recognition software doesn’t break the anti-surveillance properties.

I don’t want people to mistakenly rely on this stuff.

Worse Than FailureA More Civilized Age

Greta (previously) sends us more updates from her "Ancient Development Environment".

An important task an IDE must do is report build errors to its users. Arguably, that's one of the most important parts. I wouldn't know, I insist on building from the CLI all the time, because IDEs confuse and frighten me. I recognize I'm the weird one here, who is more comfortable in GDB than in a GUI debugger, but this isn't about me, it's about the IDE Greta is using.

It needs to display an error. Why does it need to display an error? Well, Greta hasn't figured that out yet. The error I'm about to show you doesn't really explain what happened or why or give any hint as to what needs to be done to fix it. To make matters more confusing, it doesn't happen consistently, so simply re-running the build could potentially fix it.

None of that is why we're here, though. What makes this a WTF is how the error is displayed:

An error box in a very Win3.1 style. It displays the error as a tree view, and the error is actually an XHTML document. But it's not rendering as XHTML, it's just raw HTML code, shown as a tree, like a really cruddy DOM inspector

Greta shares her bullet points about what she hates about this:

  • It's a popup that happens arbitrarily during build, under unknown conditions
  • It says nothing about what went wrong, or indeed if anything went wrong
  • It's in a non-user-legible XHTML format. It shows the markup of this XHTML rather than it being rendered.
  • It arguably shows the XHTML markup in the worst way possible: in a tree view (?!) with one row per source line
  • The markup isn't even well-formed. I'll let you count the reasons why.
  • The control used is from some sort of legacy windowing toolkit that doesn't support text anti-aliasing.
  • The first button on the upper-left, "Get latest C++ Builder Direct headlines from the Internet", does nothing.

I'd honestly forgotten about the era when the Internet was still kinda novel so every application had a "push a button and go to our web page, and this somehow definitely won't just break when we change our URL structure in the future."

Greta adds:

For all of the hatred I harbour for this, the second button ("Information about C++ Builder Direct") brings up the following powerful dose of 90s nostalgia, so I can't stay mad:

An about box, with a very 16-color gif globe, wrapped in a cable terminated with an RJ45 connector, along with some copy about how C++ Builder will reach out to the Internet and bring the latest news TO YOU. Aren't you excited?
[Advertisement] Picking up NuGet is easy. Getting good at it takes time. Download our guide to learn the best practice of NuGet for the Enterprise.

365 TomorrowsThe Universal Peace

Author: Alzo David-West The Radical Machine Rightsists had implemented their ban on all vessels of the United Interstellar Territories. Any unauthorized craft in RMR space was summarily disintegrated into particles. Amid the crisis, the UIT faced a dilemma. A civilization that had long abandoned force as politics was compelled to reconsider its two thousand years […]

The post The Universal Peace appeared first on 365tomorrows.

Planet DebianRussell Coker: TV Control etc

In 2008 I wrote a blog post “The Problem is Too Many Remote Controls” [1] about the issues of controlling a TV and related things. It recently got some comments on Mastodon so I think it’s time for an update.

The first issue I raised was “Now it’s not uncommon to have separate remote controls for the TV, VCR, DVD player, and the Cable TV box – a total of four remote controls” which seems to have alleviated. VCRs seem to have almost entirely gone away. The VHS Wikipedia page [2] is worth reading for everyone who hasn’t seen a VCR in operation, which I expect to be more than a few readers now and an increasing number over the next 18 years. I personally don’t have Cable TV, I own a DVD player which isn’t connected to my TV because I haven’t used it for years, I don’t own a VCR, and I don’t watch free to air TV. So I have one remote control for the TV which I use for Netflix and sometimes YouTube.

When viewing YouTube on TV there are significantly more adverts and longer adverts. I presume that is because installing an ad-blocker on my TV isn’t a viable option for me and it’s a total impossibility for most users. Generally my desktop PC is a much better platform for YouTube than my TV, it has a better quality display, is more user friendly (my previous post addressed the difficulty of getting to the data source that’s desired), and doesn’t require entering search terms via a slow on-screen keyboard. Netflix on Linux is limited to 720p at low bitrate which is obviously of low visual quality while on the TV it’s in 4K. I have Netflix so I use that only on the TV.

In my previous post I wrote a thought experiment on how to use a cheap laptop ($500 at the time – equivalent to $777 in 2025 money according to the Reserve Bank of Australia) to control a $5000 TV ($7770 in 2025 money). Now you can buy a new 65″ 4K TV for under $800 and a new laptop capable of 4K output for under $400 so the options are very different. For a $800 TV the manufacturer isn’t going to develop a remote control interface and Google (who develops the software the TVs run) won’t do it because it could reduce their advertising revenue. But a typical home user could setup a cheap laptop connected to their TV via HDMI providing a familiar and efficient user interface for themselves and visitors. For a Windows laptop 4K Netflix should work and for a Linux laptop the options of a laptop for everything apart from Netflix and the TV for Netflix are bearable, two controls are worse than one but better than the 3+ that used to be common.

In my previous post I raised the issue that “it’s often the case that you don’t want to stop watching one show while trying to find another”. This is still an unsolved problem and is not addressed in modern software. I am not aware of a Linux music player that supports such functionality and this would be much easier for a music player than for a video player where the screen would have to be shared between the interface for finding the next thing to play and the space for playing the end of the current one. Maybe I should file a bunch of wishlist bugs against music players asking for this.

I suggested that “cable modem” and “cable TV box” could be integrated into a single device. That has not happened, in fact it’s got worse. A relative who has Foxtel has a cable modem, a cable TV box, and a Wifi AP with VOIP to provide landline phone service and to make it more exciting the latter two both have bugs that require a periodic hardware reset to fix. Hopefully cable TV will go away in the next 18 years.

Regular PCs have become less noisy in recent years. I am currently using a HP Z640 to write this post and I have HP Z840 and HP Z4G4 systems behind me running as servers and the background noise is still very low. The allegedly 8K TV [3] that I have in my lounge room has cooling fans that make more noise than those three high-end HP computers combined. Using a quiet PC like one of those HP systems to drive a TV is a very viable option and I did just that for a couple of years. Kogan has currently got a selection of refurbished Lenovo ThinkStation systems on sale for under $400, they are quiet and would do well for this, it’s also nice that Kogan is selling systems with ECC RAM at home user prices.

TV does seem to be going away. YouTube and streaming services seem to get more watching time and many people don’t use TV at all.

Since my previous post the number of streaming services has increased so torrenting offers increasing benefits as no-one wants to subscribe to 6+ services. For anyone who wants to get all the content that interests them while paying the user interface situation is much worse now than it used to be in 2008.

If you use KDE on a PC then the kconnect program allows a phone to be used to remotely control some aspects of a PC and has a good interface for pause/resume of a video and seeking 10 seconds forwards/backwards. The interface for controlling volume is hard to get to and doesn’t work on my installation. If you want to use a keyboard to start something playing and then a phone for pause control then kdeconnect is a decent option. A comment on my previous post by Michael Croes raised the issue of remote control which is now a solvable problem. Justin also wrote a comment suggesting a Nokia N800 as a remote.

Jason suggested a programmable remote, which would be a good option for a power user and a viable option for someone setting things up for their grandparents. But the amount of pain is greater than I’m interested in as lounge room TV isn’t an important thing to me. It may appeal to more people than having a dedicated lounge room PC though.

Planet DebianGunnar Wolf: Subscription Bombing • Email under Attack

This post is an unpublished review for Subscription Bombing • Email under Attack

One of the most important inputs one can have when designing a response strategy against a security attack is a good characterization. This article describes a relatively newly described attack mode (subscription bombing), hypothetizes on the motivations that can lie behind it, and presents some countermeasures that can be taken by different actors to reduce its impact.

At its core, suscription bombing is a classical reflection attack: it uses a third party service so that the answer to a relatively simple request is amplified and results in a distributed denial of service (DDoS) for the victim. And, as with most DDoS attacks, its effectivity lies in that there is not much a person can do against traffic coming from seemingly random different providers all around the world.

The core differentiatof for subscription bombing is that the attack’s victim is not a network port, but an individual’s e-mail address. The attacker builds a database of service providers that allow interested users to sign up for newsletter on their activities, or a mailing list, or even just to create a new account on a given Web system. This action will generate a (seemingly legitimate) confirmation mail sent to the victim. But the attacker scripts together hundreds of thousands of such request, creating a deluge of confirmation mails sent to the unsuspecting victim.

The authors explain the goals an attacker might pursue by performing this kind of attack. They suppose this can be due to harassment (a disgruntled employee being denied a salary raise, a political adversary, or even a romantic ex-partner wanting to inconvenience the victim’s use of their e-mail). More worryingly, the attack can be used as a distraction: by sending a high volume of mails in a controlled timeframe, the attacker can reduce the probability of the victim noticing a specific attack warning them of, i.e., financial fraud, unwanted purchases, or break-in attempts into their accounts. Attacks targetting mailboxes at private mail servers can also lead to overloading an account’s limit, causing it to reject mails after the attack is delivered and before the folder is cleaned. And it can also pave the way for follow-up, targetted deception attacks, where the attackers call the victim pretending to be the company’s IT department, and get them to install a remote desktop monitoring and management tool, with which they can effectively seize control of the victim’s data.

To do this, they present a study they made over 24 cases of victims, from which 47,970 total e-mails were received between October and December 2024, with individual attacks receiving between 81 and 3,387 e-mails per hour, from where they presented several descriptive analysis.

The authors explored cyber criminal’s offers on underground websites, comparing flooding services and pricing schemes.

Finally, mitigation strategies are discussed. Mitigation is quite problematic, as none of the mail servers is acting in either a hostile way or lacking permissions — they are performing just the task they should. The authors suggest four mitigation strategies for mail server operators to reduce the burden on their users, although none of them is easily automatizab (rate-limit the number of emails a given inbox can receive from previously unseen senders; educate users about this kind of attacks; group similar newsletter or account reset mails during active attacks; and automatically unsubscribe or bounce newsletter messages when a surge is detected). They also recommend newsletter providers and services accepting the unrestricted creation of user accounts to provide some hardening to increase the effort wrongdoers need to spend to abuse their services, such as requiring CAPTCHAs or requiring users to take several steps before requesting a subscription, although they recognize this adds friction to the process providers are most interested in providing; filtering and triaging known-good and known-bad domains, although this is hard to implement on a preemptive fashion, and adhering to easy unsubscription standards, such as easily identifiable headers with which mass unsubscription could be performed more easily victims, instead of hunting for the right places to click, potentially even in mails written in an unknown language.

The described problem is interesting, and properly tackling it can be a game changer for many users who will suffer this kind of abuse, and the article is easy to read and soundly supports its claims.

,

David BrinWhy the salty-Earth folks hate us - and especially hate science. There's even a (slightly) valid reason!

 Apologies for not posting in a while. Many aspects of life got in the way. That and resonance effects from my big new book about Artificial Intelligence AIlien Minds...

...and preparing for performance of my play The Escape on August 28, at the World Science Fiction Convention in Anaheim.  But so much is happening in the news... and so little of it sheds much light. And so...

...I'll opine at the end of this posting about the insanely hypocritical Fauci Fables. But first...


== The War on Science should be issue #1 ==

I used to give talks at the White House Office of Science & Technology Policy (OSTP), back when its mission was to enhance U.S. scientific leadership for the overall betterment of citizens, humanity and truth.  

None of the accomplishments of the post WWII Greatest (GI Bill) Generation was greater than encouraging politically neutral science and discovery of verifiable facts. Even when those facts undermined the prejudices they had been raised to believe.

(A burst of discovery, creativity and truth that was spurred by the universities that the GI Billers built, that were their greatest pride, and that are now under relentless oligarch-subsidized attack. Because children of the middle and poorer classes have used college to rise up and compete fairly with the aristos' inheritance brats. And we can't have that now, can we?)

Alas, 30 years ago the Republican Party began its relentlessly accelerating war against science and objective reality. It started with Newt Gingrich's demolition of the Congressional Office of Science and Technology Assessment -- OTA -- whose expert advisors kept saying those fell words unwelcome across all levels of the Republican Party: 

"Um, I'm afraid that's just not true, and here's the evidence." 

(Restoration of OTA is among my 35 recommendations to Democrats, should they ever recover enough power to save America.)**     

WHY the right's hatred of objective reality? It wasn't universal in the days of Goldwater and Buckley, as it is now. Scan 250 years and you'll see the pattern of recurring culture war -- one that has erupted every generation in America, pitting modernists who opposed first kingly rule, then slavery, then lucre-oligarchy and unearned hierarchy... versus those neighbors who are enraged by the very concept of modernity, preferring instead the serenity of knowing your place, beneath kings, priests, lords and their inheritance brat sons, recapitulating 6000 years of oppressive, unsapient feudalism.

Which brings us to this news. OSTP - now under rule of an acolyte of Peter Thiel - has issued a new manifesto that proclaims dedication of science, while proposing measures that (all of them) will serve to curb scientific exploration and independence and intellectual honesty, across the board.

See: https://www.whitehouse.gov/releases/2026/07/45470/

Are there flaws in current systems like peer review? Well, sure, and competitive science usually discovers and reveals those flaws. What the Right's hate agitprop always hides, while depicting scientists as conformist lemmings, is that scientists tend to be the most COMPETITIVE creatures Nature ever produced. A young researcher gets nowhere in her career without finding some niche assumption (or a big one) to topple with factual experimentation.

Should promulgators of the 'lemming' slander make science policy? They want it all politically controlled and under their thumb. So where does this all lead?

Alas, they are chivvying and radicalizing the brainiest men and women on the planet, who would prefer never having to radicalize! And hence, I have to ask the prepper lords (I know several) "Where do you think it will get you, to wage war against all the smartest humans? Those who know cyber, chem, bio, nuclear, nano and all the rest? Do you think you will emerge from your bunkers into the fantasy future of A CANTICLE FOR LEIBOWITZ, where all the nerds are killed by angry peasants, eager to become serfs of you New Lords?

Hey delusional oligarchs that your sycophant flatterers have misled you. The people will side with us. And tumbrels will roll. See this re feudalism.


** So many earnest proposals would reform weaknesses in the US system that were exploited by traitors. Alas, too many are politically impractical, like Constitutional Amendments, or would waste our political capital unnecessarily. We need a to-do checklist of fixes that (1) will sell well to most voters, (2) that can pass quickly, almost the moment we get a good Congress… with some of them immune to vetoes! And (3) that will PRAGMATICALLY reverse the treason-evisceration of the USA and ensure this never happens again. Want to see how to do all of that? Here is the full list of my own proposed Newer Deal tactics and reforms. https://davidbrin.blogspot.com/2025/11/the-contract-part-three-aggressive.html


== But why do they hate us? Mostly made-up stories. But in fact, there is a basis! And it goes way back ==

I've tried to explain that confederatism (and its current partners Nazism and Kremlin/Putin-communism) must be defeated yet again. But meanwhile, we must emulate Lincoln and win with 'malice toward (almost) none and charity for (almost) all. First, because Lincoln asked it of us and that should be enough...

...but second because these are our neighbors and if they just return to a decent version of conservatism a la Goldwater or Buckley, then we will gladly go back to the adult art of negotiation.

Only there's another reason for 'malice toward (almost) none.' Sympathy. Empathy. Because their recurring, maniacal rage against modernity does have a basis! A small, insufficient one... but a basis of a sort.

Oh, not any of their Murdoch/Foxite/Kremlin-generated lies and memes and crazy shit. Like generations howling that city folk are decadent filth! Get bent with that bullshit! No, there's something deeper. A hurt that never goes away. 

In fact, it shouldn't go away! Still, we oughta sympathize a little. 

Norman Rockwell made my point! 

Ever wonder why we experience relentless resentment by rural, salt-of-the-Earth folks toward city slickers, calling them - or folks who get too educated - 'not real'? Or decadent or corrupt or impractically airhead? 

Come on, we've heard it all our lives. We aren't supposed to respond. Just grin wryly and accept it. Yep, New Yorkers talk fast and don't have time to waste on pleasantries. That must mean they're evil.

Okay, I've long offered a reason. 

First, none of it is true. Rates of every turpitude average worse in most of Red America (except Utah), from gambling, addiction. STDs, domestic violence & divorce to murder to tax parasitism and convictions for graft and perversions. 

Bet $$$ stakes on all of that! Escrow your stakes with reputable attorneys and have them contact me. 

In fact, by all reasonable metrics, blue/urban America has been pretty damn nice to our salt-of-the-Earth neighbors! From FDR to LBJ all the way to Clinton/Obama, Blue America has poured many tens of billions into dams, roads, clinics, schools, power lines, internet and all the rest. In Appalachia alone, this transformed hillbilly hells into truly pleasant places. And gratitude was never the goal.

So why the bitterness?

It's encapsulated in that long ago painting by the great Norman Rockwell, showing a worn-down farmer seeing his eager son off to college. A kid who spent his young life working hard to help Pa... but also studying for what they both hope will be a better life. One in which he may never come home again except for Christmas visits and showing his own kids the Family Farm. 

And it's good. The farmer knows it's good! And yet...


...and yet it hurts. Dig it: every small town in America revolves around the high school, where each crop of seniors is the town treasure everyone talks about. The sport heroes, the cheer squad, heck even the science fair nerds! 'Our pride and joy.' And each summer they weep and hug... 


...and then skedaddle as quick as they can to the bright lights. And that has got to hurt! Like an implied rebuke. A wound. Every year. Every damned year.



== Is that enough reason to hate us? ==


Does this feed both the simmering slurs toward city folk and the recurring outbreaks of outright civil war hate that we see, about once per generation? 


If so, then do NOT answer with contempt! If this must come to a fight - as it has done several times in the past - then let us not nurse reciprocal malice. We must maintain a core of 'charity for all.'


On the other hand, we will not let a nation of knowledge and science and calm and fair argument and transparent justice and law and civil-service and ever-rising tolerance and diversity and all other things-modernity be crushed and burned by a lava of ingrate resentment, either. 


For one thing, their contempt for us revolves around a masturbatory notion - that we are cowards. A self-serving, auto-erotic fantasy that we disproved at Gettysburg, at Normandy and on Mare Tranquilitatus and in ten billion other ways, as we forge ahead into the sometimes-scary unknown, picking up the very tools with which God made Creation. And getting blessed for it.


Anyway, there's something that neither the world oligarchs nor the coward mogul-preppers nor their millions of dittohead lackeys ever seem able to ponder. That it's only a fool who keeps POKING at those Americans who know cyber, chem, bio, nano, nuclear and the rest. Daring us - just daring us - to lose our temper.


Don't do that. Stop it. 


Please stop, before I lose my coo...


Look, we welcome your children into a better future. We in the cities and universities are - or are descended from - that boy in the Norman
Rockwell painting. 


Join us in the adventure and you will get robots and medicine and the rest. Be like that dad. Be proud that we are in it together.



      == Addendum: The Fauci Fables ==

Once again - this time regarding the right's attempted shivving of Dr. Anthony Fauci - the thing bugging me the most is how poorly the moderate/blue side handles its response to the outrageous madness. The Union side in this phase of the 248 year recurring US Cicil War is so dumb at the arts of polemic! Alas, in every phase, the Union flounders... till it finds its generals.

So, let me get to what's fundamental. Not Fauci's lifelong, mostly successful fight against diseases like AIDS, polio, ebola etc., saving millions. Nor his few, Fox-cherrypicked "Gee, lookit how I'm famous now!" diary entries (one millionth of Trump's narcissism.)

Nor the failure of the lying Foxites to follow up after Covid with ANY of their assertions, like proof that horse-pills work. (They've had years and years and have spent nothing to prove their wild yammer-claims.)

No, this chart is what's fundamental. Comparing death rates in states where covid vaccination was common or commonly avoided. And note the same effect is observed in CDC stats of simple death rates of individuals who were vaccinated vs unvaccinated. (And note that it was a Fauci-supervised miracle that delivered RNA-based vaccines at warp speed... and the current administration has canceled almost all followup research in preparing for the next pandemic.)


Look, some on the left have taken their defense of Fauci too far. He was NOT perfect! He made several mistakes e.g. re masks at the beginning.


And gain-of-function contracts to Wuhan were done (stupidly) by several administrations of both parties, who thought they might thus lure China into transparency in disease research. A bipartisan delusion.


But we only need one thing to settle this. An unambiguous fact. And a tactic that wins political arguments by sending the mad meme-junkies fleeing.


Demand WAGERS from the yammering rightist/Kremlin bozos over easily verified DEATH RATES OF THOSE WHO TOOK OR REFUSED COVID VACCINES. Demand escrowed wager stakes from anyone yowling this monstrous BS.


Watch them flee.


== A pertinent after-thought ==


PS. Look at the chart again and ponder: does ANYONE have any memory? Like how at the beginning of the pandemic redders crowed gleefully about the covid death rates in CA & NY as proving that blue, city folk were 'filthy'? Like any natural disaster in a blue state was "God's wrath!" but anything hitting red zones is all "Help us now!"


And we always do


Planet DebianIustin Pop: Yes-yes, still alive!

I am not sure what happened, but my interests have changed significantly, and… I haven’t blogged, I haven’t done any open source work, and didn’t even process any pictures for the entire year. Not because anything went bad, just… new stuff, new interests, life changes.

However, still alive, and still struggling with sports, and with sleep :)

On the positive side, on a recent mid-length flight, I thought — I haven’t done any work on Corydalis, since last year I closed quite of a few of my “must have” features, so probably, nothing else to do for now, right? I opened an editor and started thinking about ideas, and surprised! One hour later, I had written down enough ideas for a couple of months of work. So now just need to find the time… but can’t wait for the planned things!

Stay well!

Cryptogram Vulnerabilities in Car Anti-Theft Device

This is disturbing:

…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

Planet DebianEnrico Zini: Gnome refusing to suspend

I'm tired, I want to do go bed. I click "sleep" on gnome shell, nothing happens.

Swearwords.

I want to go to bed. I might have want to put my laptop in a bag and run to catch a train. I hate when this happens.

systemd-inhibit --list --mode=block doesn't help much:

$ systemd-inhibit --list --mode=block
WHO    UID  USER   PID  COMM            WHAT                                                     WHY                        MODE
enrico 1000 enrico 3042 gsd-power       handle-lid-switch                                        External monitor attached… block
enrico 1000 enrico 3037 gsd-media-keys  handle-power-key:handle-suspend-key:handle-hibernate-key GNOME handling keypresses  block
enrico 1000 enrico 2878 gnome-session-b sleep                                                    user session inhibited     block

After much googling I found out about gnome-session-inhibit:

$ gnome-session-inhibit  --list
mutter: idle-inhibit (idle)
/usr/lib/chromium/chromium: Playing audio (suspend)

Found the right tab in chromium, paused playing, sleep works again.

My sleep was a good half an hour overdue, and all I got for it was to write this blog post.

Of course Gnome could have shown me its inhibitor list instead of doing nothing, since it has that information, but it didn't.

What I really would expect is that if I intentionally click a suspend button, audio and video playing wouldn't inhibit the suspend. Maybe in a future version of Gnome?