Latest Posts (20 found)

A sustainable web career, for when all this blows over

For better or worse the web industry is going through a bit of a phase. The reasons are largely irrational. People still need the web, nothing has changed there. Regardless, the financials of this business are a struggle. Longterm career prospects are looking dicey. Because I openly reject the driving force intent on destroying my profession, and ruffle a few feathers doing so, I often get asked privately for advice from like-minded peers. I can only offer an uninspired but sensible reply: don’t quit a paying job without a fallback. Go to the Winchester, have a nice cold pint, and wait for all of this to blow over. I’m confident the situation will improve. Before it does, what can we focus on to accelerate past the intellectual slump, and better position ourselves once things calm down? For a sustainable web career, where better to look than critical skills in desperately short supply? My focus is on front-end development, but these areas of knowledge are relevant to anyone in the business of making websites. Accessibility has always been a foundation of web development but it’s never been more critical for everyone to champion it. Understand why accessibility is for everyone. Learn how to talk about accessibility in respect to real needs and practical implementation. Accessibility has unfortunately become a virtue signal for certain tech groups. (I’m told LinkedIn is rife with misinformation.) Accessibility is not a feature that can be tacked on to a website like garnish. Accessibility issues can’t be fixed with an automated process at the end. Web professionals must be able to counter this mindset by respecting accessibility in all decisions from day one. Learn and adopt the guidelines as your baseline. Speak to and test with real people. Defer to specialists who are eager for you to understand the realities. CSS is the most vibrant and evolving of the front-end standards. To architecture a good stylesheet takes deep understanding of the language features. Newer features like cascade layers and selectors that reduce specificity make this much easier. CSS has always been equipped to handle well organised styles, but developers who refuse to learn and respect the language have sought to push complexity elsewhere, using simplified abstractions or “CSS-in-JS” solutions. These are inherently limiting, lead to poor performance, and don’t actually solve the problems they claim. CSS should be hard and learning it will give you the ability to express creativity beyond cookie cutter web design. CSS skills will be highly desirable as more websites wish to stand out against the convergence of a generated aesthetic. Communication is a “soft skill” in short supply (for obvious reasons). It’s a great skill if you wish to stand out as an expert, or simply be heard amongst the noise. Learn brevity and focus on important points. Don’t be afraid to ask questions. Address concerns tactfully and early before they escalate. Don’t point fingers, but “cover your ass” — everyone on a project should be working towards the same goal, but some may be misguided in their approach. Remain positive and don’t meet negativity head-on. If you can communicate well you’ll be highly respected in your role. You probably weren’t expecting this one, but here we are. The luxury of not “getting political” has abated. Far-right political ideology is on the rise and dormant hatred is waking up in tech. The epicentre of fash-tech is Musk’s “X” with people like David Heinemeier Hansson spewing racism and abusing authority in communities to push an agenda, and Guillermo Rauch taking a selfie with a war criminal . Large tech giants like Digital Ocean are funding this power grab . Be wary of those denying this threat. If you want to avoid being pushed away from this industry, recognise and reject fascism before it comes for you. Don’t stay silent. I’ve covered topics that’ll see us well for the future, but what should we forget? Facebook’s experiment turned cargo cult is a legacy framework that still lingers, but there’s no reason to learn it today. React has entrenched itself as a lingua franca of code extruders. React code is generated faster than any human can possibly read it. Suffice it to say that despite stale job vacancies still demanding experience, React is not worth investing time. The days of high-paying React development are numbered. GitHub is now a liability. For private repositories use self-hosted git forges. I’d recommend Forgejo . One of the many Tailscale-like services is an easy way to gate remote access. Don’t make stuff public for the dead internet to attack! For CI/CD go local too, or use independent services not tied to tech giants. Take the time to learn basic commands. A little technical and infrastructure knowledge goes a long way. These people are handsome, charismatic, highly personable. I’m talking about: developer relations, youtubers, start-up founders, etc. When the tech industry met us halfway, influencers were entertaining and a good chinwag at after parties. Now the game has changed and we should not allow false narratives to dominate and dictate a closed-web future. Normal people still use the web. Incredibly few can afford to pay for the novelties that influencers peddle. Their attention economy is no longer our concern. So that’s my focus for a sustainable web career, when all this blows over. Remember that above all else: the web is a human creation for human needs. Those needs are not going anywhere. Drop the dead weight accumulated in times of prosperity. Go back to basics and position yourself well for when professional demand returns. Thanks for reading! Follow me on Mastodon and Bluesky . Subscribe to my Blog and Notes or Combined feeds.

0 views

Apple’s App Icon HOA

Louie Mantia has a great post about how app icons are converging towards the squircle on iOS and macOS. His post reads like a history. If you’re wondering, “How did we get to a place where all app icons are becoming squircles?” Mantia’s post answers that question by starting at the beginning. It’s hard to walk away from Mantia’s article without a sense of empathy for Apple’s position, like “Oh ok, I get why they’re doing what they’re doing. It makes sense.” Apple’s direction is kind of a tacit acknowledgement to how most people are shipping app icons. Apple is “paving the cowpaths” as it were, because most app icons are just brand logos. Nowadays, it’s these bland, big-business logo icons that make up a good chunk of iOS Home Screens and macOS Docks, instead of the beautiful, illustrative app icons that used to dominate our devices. So many app icons are just logos in a squircle, so Apple made tools like the Icon Composer and glass effects to help make that approach look good by default. Apple is helping most people most of the time make app icons that don’t suck. [Apple is making] it easier for all apps to fit in on the platform, especially apps built by designers and developers who aren’t familiar with how to make an icon that looks great next to first-party icons. The net effect is: some of the platform’s best icons look worse, while some of the platform’s worst icons look better. In other words, this new approach raises the floor but it also lowers the ceiling. The thought that came to mind as I read Mantia’s post was, “This reminds me of HOAs.” I grew up in a neighborhood where anyone could do anything with their homes and yards, so you had this eclectic mix throughout the neighborhood — everything from “Wow, that house is so unique!” to “That thing is a dump.” Somewhere along the way HOAs became more prevalent (in my neck of the woods), where all the houses in a neighborhood have to meet a certain standard — and so they all start to look the same. It keeps the dumpy things out, yet nobody stands out . That’s kinda what macOS feels like right now with regard to app icons. For better or worse, squircle app icons are Apple’s HOA and we’re all just living in it. Reply via: Email · Mastodon · Bluesky

0 views

Kelsey

My sister is in a currently-running-on-TV political ad. It’s against the republican chucklefuck Tom Tiffany who was one of those anti-American dingleberries that claimed Biden “stole the election” and thinks Trumps tariff plans are super neato. Kelsey’s journey with healthcare insurance has been pretty rough. She gets denied for medications and treatments all the time, which to me is pure criminal behavior akin to attempted murder. Any politician doing anything other than forcing healthcare insurance companies to actually help the people they cover (ya know: Americans) can piss up a rope. She’s sharing her cancer journey herself in a multi-part series on social media sites. Like: View this post on Instagram

0 views

Credit Crunch

If you liked this piece, you should subscribe to my premium newsletter, and you can subscribe on the following links: $70 a year , $18 a quarter , or $7 a month . In return you get a weekly premium newsletter including vast, detailed analyses of NVIDIA , Anthropic and OpenAI’s finances , and the AI bubble writ large . It's a great way to support my free work, and you'll get full access to my massive archive of premium analyses of the tech and finance industry. I just did a two part Hater's Guide To AI Debt that's essential reading given the current climate around AI data center loans. On Friday, I’ll dive into the world of junk debt – or, what happens when a hyperscaler's credit rating slips into the abyss, or what might happen as a certain money-losing AI lab moves into the world of junk, building on the story I'll tell today. If you want to get in touch — and especially if you have any juicy information about Anthropic, OpenAI, or any other companies in the AI bubble — hit me up on Signal at ezitron.76. I’m also on IB on your Bloomberg Terminal.  Every day somebody asks me when or how the AI bubble will burst, what might cause it, what potential avenues I’m missing, begging, pleading for some sort of hole in the argument outside of “but what if all the bad things don’t happen and the good things are even better than we imagined?”  These questions come from everyone ranging from random internet people to hedge fund managers on my Terminal trying to squeeze me for free research, and every one carries with it some thin vein of wrongheaded hope — that there’s some subtle failure in my arguments and, in turn, some way in which this all turns out okay. Even those actively agreeing with me hesitate to follow my arguments through to their logical endpoint, mostly because doing so can make you feel a little queasy. If you actually sit and think about the consequences of what’s happening rather than just a collection of different events organized in a row that you have to remember to speak about on a podcast, it’s easy to say stuff like “ Anthropic has $413 billion in non-cancellable compute contracts ” or “ $18 billion in Oracle data center debt is trading at 84 cents on the dollar ” without ever really thinking about what any of that means.   Everyone acts as if everything in the AI boom is going to go fine, all without much consideration of the real world and its consequences for the greater tech industry. They assume that OpenAI and Anthropic will go public, grow forever, raise whatever debt they need, and that every single data center investment will work out fine. And make no mistake, these companies will need at least $50 billion or more in debt every single year, all with what will likely be low-grade junk credit ratings. It’s time to talk about why that’s very, very unlikely.  Alright kids, let’s talk about debt . Some of you are big, strong, and smart and already know this, but some of you don’t, so we’re going to all learn or re-learn together. I apologize in advance for having to go through all of this, but trust me, you want to know. Every month, the US Treasury (the part of the US government that manages the country’s money) has an auction for ten-year-dated Treasury Notes, typically referred to as “Ten Year Treasuries.” These auctions then receive bids. Regular people offer something called “non-competitive bids,” meaning they’ll say how much money they want to lend the government, and then there are competitive bids where financial institutions say “we’ll buy in at this specific interest rate.” The US government borrows over other time periods too, but that’s not important for today. US government bonds are, in general, considered “risk free,” as they’re backed by the full faith and credit of the American government. This status makes them the base for all lending, because anyone borrowing money has to compete with what the US government (or another government) offers to pay.  You’re paid your interest, in the case of the ten-year bill, every six months, with the principal repaid when the bond matures. Ten-year treasuries are considered the “ benchmark ” rate, because it’s the most actively-traded and liquid security in the world, and while mortgages in the US tend to be structured as thirty-year-long loans, most people tend to either sell or refinance their houses in the first ten years of the loan. It also represents, to paraphrase a friend in fixed-income, a period of time that’s both a long way away but not so long as to be impossible to comprehend. You’ll also notice that the “pricing” of treasuries (and bonds in general) is usually expressed in percentages rather than prices. That’s because the price of a bond doesn’t tell you how much it’ll pay you, how many payments there are left to go, or what its value is relative to other bonds. As a result, the pricing page for ten-year-dated US Treasury notes shows an interest rate — 5.33%, for example — that represents “how much money would I get on an annual basis if I invested in ten-year Treasuries today ?” based on the soup of different notes in the market based on their various maturities and interest rates.  The ten-year is considered the barometer of investor sentiment — how much the market feels comfortable lending to the US government, based on everything they do and do not know, which is why it shifts so often with economic data and the price of oil. And, importantly, when a bond “gets cheaper,” its effective interest rate goes up, because you’re paying less money for a debt instrument that pays a consistent amount.  Right now, ten-years are “selling off,” meaning that the effective interest rate on them is going up, based on a few different factors: So, while we can’t point at one reason, there are plenty of reasons that ten-years are selling off, which is in turn raising the cost of borrowing for literally everybody — consumers, hyperscalers and AI data center developers alike — in a way that’s distinctly difficult to calm down. That last part is very, very important. While stocks can recover based on good news ( even if said good news is entirely fictional ), the price of ten-year-dated treasuries is reacting to so many different economic indicators that even the things that should calm it down — like lower-than-expected jobs numbers — aren’t stopping them from dumping. And so when the ten-years dump, the base interest rate of almost everything increases, and some of the things that are becoming more expensive as a result are actively contributing to the problem. The US Government cannot afford to stop issuing debt, the wars in Iran and Ukraine aren’t going anywhere, and hyperscalers expect to issue $400 billion in bonds in 2027 alone . As a result, everything gets more expensive for everyone, and the worse your credit is, the worse this gets. So, now that we know all that, we can speak to the larger problem. When somebody borrows money, they do so priced at a “spread” above the equivalent-dated US Treasuries — usually judged based on the underlying economic health of the company, the general vibe about the kind of thing they’re borrowing for, and the current ‘price’ (read: effective yield) of their debt, usually measured based on its “spread” from today’s US Treasury prices. This means your borrowing prices can go up based on a few factors: So if your company — say, Oracle — has a bunch of bad press about its debt being distressed , the market will “price” more risk in, selling off the current debt and pricing it as if the effective yield was higher, setting a floor for how expensive your debt will be. This floor will also increase because the price of US treasuries is likely higher today than it was when you raised. I’ll give you an example. As I discussed last week , Oracle’s $18 billion September bond sale would have (yes, the number has gone up) over $7 billion in added interest over the course of the bonds due to both the sell-off of Oracle’s debt and the overall Treasuries market.  At the time, ten-year-dated US Treasury notes were at a mere 4.13% — as mentioned above, a 0.06% increase is significant, so a 120 basis point difference is gigantic — but Oracle’s overall risk has also exploded along with them.  At the time, spreads were between 105bps and 165bps (so 1.05% to 1.65%) above US Treasuries. Today, those spreads range from 171bps to 282bps, a double dose of pain at a time when  the market sentiment is that it doesn’t trust Oracle as much as it did in September — as in how much more it’s demanding over the benchmark rate offered by the government — has increased along with the cost of the benchmark itself.   And so, while I’m not going to repeat everything I went over last week , the point I’m making is that anyone raising any AI-related debt is going to get shafted by both overall Treasury prices , sentiment around AI in general, and their own specific financial situation. Yet Oracle is, at least for now, “investment grade,” which means that even though its debt “trades like junk” (IE: investors are asking for effective yields of anything around the high-yield index’s average of 8.2% ) , it’s in a much better position to borrow than the vast majority of AI data center SPVs or neoclouds like CoreWeave, which has Goatse-level spreads of 672bps to 882bps, with the effective yield on its shortest-dated debt (four years) sitting at 11.53% and its longest-dated (a mere six years) sitting at 13.49%. There are, of course, ways around borrowing on your credit profile. For example, when CoreWeave opened an $8.5 billion delayed draw term loan facility in March 2026 , it was able to get it rated as investment-grade and at SOFR (the percentage on overnight borrowing from the Fed for banks) plus 2.25%, all because the counterparty was Meta, and thus the underlying payments would be considered “safe.” This may seem like the cheat code to get around all these horrifying rates, except CoreWeave, per analysts at UBS, needs to raise $102 billion in debt through 2030, which means it will have to keep raising on its own two feet. Well, there’s a problem there. Per The Information , “cracks are beginning to form” in the AI data center debt boom: Long-term Zitronistas will remember when I brought up some of these names in my end-of-year-2025 piece The Enshittifinancial Crisis , with SMBC present in seven and MUFJ present in seventeen of the data center deals I analyzed, with one or both of them in effectively every Stargate and CoreWeave debt sale, and both involved in SoftBank’s $15 billion 2025 bridge loan . “More selective” doesn’t necessarily mean “done investing,” but is more akin to the lights going on in a particularly-rowdy party and seeing who may or may not have pissed themselves. Data center debt is now pricing based on increasingly-sour sentiment driven by power delays, local pushback and a general anxiety that maybe these debts won’t actually get paid. They also might realize that their due diligence was lacking when it came to building some of the most-ambitious infrastructure projects in history . Here’s an example of how deep the due diligence was for Blue Owl’s $10 billion investment in AI data center projects, per The Information :  In any case, AI data center debt is way more expensive now by virtue of the current state of treasuries, with costs compounded by the anxiety around them in general.  This means that any “virgin” projects — those that aren’t directly backstopped or co-signed by hyperscalers — are guaranteed to hit egregiously-high, 9% to 14% rates, which makes ( as I discussed a few weeks ago in my two-part debt series ) it near-impossible to make the already-questionable economics of running a data center work.  This means that any AI data center debt being raised right now is doing so under stricter credit conditions and doing so at unrealistic, unsustainable prices, if they’re going to be able to raise at all. This makes the $174 billion in debt that SB Energy needs to raise to fund its theoretical data center project with OpenAI — even when backstopped by NVIDIA — either horrendously expensive or impossible to complete, as does it mean that any future large, multi-gigawatt projects will add billions of dollars in interest payments to already-expensive debt. This all makes pontifications that data center spending will increase to $32 trillion by 2050 equal parts stupid and wasteful, on top of the overall problem that there isn’t even enough demand right now for hyperscalers to break even on their 2026 and 2027 capex plans .  Yet data centers are buildings with stuff in them that, in theory, could be repossessed and leased to another party — or at least sold off — in the event of a default. Investors would theoretically get some sort of return (based on the seniority of their debt, but that’s not important right now) if CoreWeave died, or if Oracle’s Project Jupiter (the one connected to its “Force Majeure” notice ) failed to secure power. We’ve got another problem on the horizon, and nobody seems to be talking about it. Back in June , Anthropic President Daniela Amodei said the following at a conference: Quick question, Daniela: are they?   Nobody seems to want to talk about what Anthropic’s plan is once it goes public as far as continuing to raise egregious amounts of capital. Once a public company, Anthropic will no longer be able to raise venture capital at its current scale (over $95 billion in 2026) alone, and if it intends to raise even half that much on a yearly basis , it will become one of the largest issuers of junk-grade debt in history. In both AI labs’ cases, they are most-decidedly going to be priced like junk , even if the malignant scumbags are able to con ratings agencies into giving them investment-grade ratings , because while the bond markets listen to credit ratings, they price based on what the actual company looks like , guaranteeing Oracle-esque 8% minimum yields on whatever they issue. The problem is that OpenAI and Anthropic don’t really have assets . They don’t own any of their data center infrastructure, the chips inside, or even their office buildings, and that’s before mentioning their negative cashflows and products under constant threat from cheaper open source alternatives.  This means there’s very little for the company to offer as collateral, and would be raising debt based on a theoretical break-even point somewhere in the future, one that they would both have to actually explain with a level of depth that neither of them have had to deal with.  The big difference between Anthropic/OpenAI and SpaceX is that the debt in question would be raised to fund company operations rather than capital expenditures , as training costs are not capex and at least based on OpenAI’s audited financials are considered operating expenses. While CoreWeave loses a bunch of money , those losses mostly come from the expensive debt it has to take on to fuel its capex ambitions and the depreciation of its GPUs, meaning that it has (if you remove its largest costs!) a positive EBITDA. This difference also likely precludes either company from raising capital via an SPV or other off-balance sheet funding, because those are collateralized using the underlying asset, such as Anthropic’s $161.2 billion in non-cancelable contracts to lease back Broadcom’s TPUs . Convertible bonds — low-interest bonds that can convert if a stock price is hit or, at maturity, allow investors to take stock or cash — are an option, but run the real risk that the stock is lower than when the bonds were issued, meaning that Anthropic or OpenAI would have to pony up a ton of cash. The only exception would be an SPV tied to customer payments which I’ll get to in a bit. Yet things get a little messier when you factor in non-cancelable contracts, which total $413 billion in Anthropic’s case across the next seven to ten years, guaranteeing financial strain at a time when future cashflows are far from guaranteed. Take-or-pay agreements — the subprime mortgages of the AI bubble — are considered debt equivalents in the eyes of creditors, which would in turn drag on cashflows.  You see, you can jingle the keys of "annualized run rates” and “ adjusted operating income ” in the faces of venture capitalists and journalists as much as you want, but investors require actual cashflows, even within a frothy market. Anthropic’s vulgar “ Earnings Before Training, Interest and Taxes ” measurement does not matter when the entire calculation is made on cashflows , and any attempts to act otherwise are either ignorant or deceptive. EBITDA, of course, refers to Earnings Before Interest, Depreciation and Amortization, which means that all “above the line” costs — such as inference costs, training costs, SG&A and leases — are counted, but the cost of depreciating assets like GPUs (of which Anthropic and OpenAI have none) and interest is left off. Let me give you a very straightforward example from my own story on OpenAI’s audited 2025 financials , when it had $34 billion of expenses and $13.07 billion in losses, for an EBITDA of $20.92 billion, or an EBITDA margin of negative 160%. At that EBITDA, it would immediately slam the door shut on an investment-grade rating for OpenAI or Anthropic, and likely get rated between a B (highly speculative) and a CCC+ (substantial credit risk). If ratings agencies push through at that grade, it means they are completely and utterly corrupt, and going against their own guidance about how credit ratings are provided. Every single metric underlying an investment grade rating comes from EBITDA, and SpaceX was only able to qualify through the success of Starlink as a profitable business. S&P Global also penalizes revenue concentration — specifically referring to customers or products making up a large slice of revenue. In Anthropic and OpenAI’s case, they effectively have two products — the API and subscriptions — and nearly a quarter of Anthropic’s 2025 revenue came from two customers . While SpaceX is a shitty company, it’s a diversified one. OpenAI and Anthropic are not. In any case, if either gets an investment-grade rating, it’s likely that a hyperscaler has stepped up and guaranteed some or all of the debt, but in doing so, they’d likely sacrifice part of their own credit rating in the process. The same might happen — as hinted at above above — through a rotten kind of SPV, where the hyperscaler guarantees a certain amount of contracted revenue to OpenAI, allowing a connected SPV to raise at an investment-grade interest rate.  If we assume that OpenAI or Anthropic gets a junk rating, it becomes entirely-unable to raise from the investment grade market, leaving it with dwindling options based on how junky that rating is. The problem they face there is that even the highest-rated level of junk (BB+) requires sustained cashflows, and even lower rungs like B+, B and B- need some sort of path to EBITDA positivity.  Each level of junk grade carries its own limits in both how much money they could raise based on their particular financial profile and the hard-and-fast rules of various funds investing in high yield debt.  When I say “CLO-eligible term loans,” I’m referring to collateralized loan obligation funds that scoop up large buckets of loans and resell them as one investment vehicle, buying somewhere between 60% and 75% of corporate loans . These CLOs also have their own rules about exposure to debt based on various factors, including industries and credit rating, and depending on where OpenAI or Anthropic fell, the demand for their loans — and secondary sales of their loans (because investors LOVE to resell debt!) deteriorate dramatically based on their rating. The following assumes a $2 trillion valuation, which is far from a foregone conclusion. If we assume $50 billion is what they need on a yearly basis, this becomes increasingly difficult based on the credit rating. As you can see, debt alone isn’t getting these companies $50 billion a year outside of a rating that’s near-impossible outside of ratings agencies defaulting on their jobs. In theory, at a $2 trillion valuation, both Anthropic and OpenAI could sell directly onto the market, but using this as a serious ongoing funding mechanism naturally depresses the price, though the scale of the float — as in how many shares were sold at the IPO.  At that valuation and a planned raise of $60 billion to $100 billion , Anthropic will have a very small float — around 5% — which would mean it was naturally capped on how many shares it could dump in a particular year. It’s hard to gauge this based on the unknowns of its trading volume, but if I had to guess, there’s maybe $20 billion in annual share sales it could do. Ahhhhh HHHH FINE YOU WANT TO TALK ABOUT UBER SO BADLY WE’RE GONNA TALK ABOUT UBER AND AMAZON AND TESLA! I’ll add that both Anthropic and OpenAI want to raise $50 billion at IPO.  In other words, stop making these comparisons, they are not accurate. I realize I’ve gone through a lot of technical stuff so far, but the reality is pretty simple: Anthropic and OpenAI do not resemble the financial condition of any company I could find in the history of the stock market outside of WeWork. They are unprofitable, unsustainable, and the only conditions under which they could raise significant debt would involve catastrophic failures of regulatory and ratings bodies.  I’ll add that the only thing worse than allowing them to go public will be to allow them to raise debt at anything other than the junkiest levels that the market has to offer. These are not stable businesses, nor are they run with much regard for their underlying capital or employees. Both of them have massive amounts of concentration risk , unstable customers , brittle economics, own virtually no assets, and have demonstrated little to no ability to reduce their costs outside of questionable accounting that doesn’t change the fact that they cannot afford their bills. As a result of their $1.3 trillion in compute commitments, neither company can become “capital efficient” by cutting their training costs, because said training costs are the only means of further growth outside of massive price increases that are unlikely to grow their businesses. To make matters worse, both are cutting prices to compete with each other, and per Ramp , said price cuts aren’t increasing usage: Neither company can afford to exist without near-infinite resources, and neither company can afford to slow down due to their massive compute commitments, which have become materially linked to the future growth trajectories of effectively every hyperscaler, as well as Broadcom, which — in pursuit of becoming NVIDIA — has added ruinous amounts of debt at the worst time in history to do so. And that’s really the biggest problem here. While Anthropic and OpenAI are yet to pillory the debt markets, their counterparties — and those inspired by them — have been doing so for years with little or no return on investment. As I discussed a few weeks ago , there are currently over $200 billion of NVIDIA GPUs sitting uninstalled in warehouses, with Morgan Stanley ( as found by Bryce Elder of the FT ) estimating that more than half of GPUs sold in 2026 through 2028 won’t have anywhere to plug in. Hundreds of billions of dollars have been spent on data center capex for effectively no reason, outside of the belief that there’s “insatiable demand for AI compute” when the reality is that more than 70% of all AI revenues — and I estimate more than 80% of all compute sales — are from Anthropic and OpenAI taking up whatever capacity comes online, leaving very little left for the rest of the world and creating the illusion of massive demand. Both of these companies want to dump themselves onto the public markets, raise tens of billions of dollars of debt a year, and dump further shares onto unsuspecting investors based on unrealistic revenue projections of hundreds of billions of dollars a year by 2028 . Both OpenAI and Anthropic are astonishingly bad businesses, losing $20.92 billion and $8 billion respectively in 2025. The best response that anyone has got to these shocking figures is to vaguely point to adjusted profitability numbers provided by companies that have constantly shared deceptive annualized run rate figures as a means of obfuscating their financial condition. And these companies account for, per their own obligations, $1.3 trillion of future earnings across Microsoft, Google, SpaceX, Oracle, and Amazon, with $413 billion of Anthropic’s commitments being non-cancellable , and OpenAI projecting to spend at least $750 billion on compute through the end of 2030 , with no answer as to how these companies afford to do so.  Analyst expectations have OpenAI and Anthropic contributing at least $444 billion in revenue across hyperscalers in the next three years , and if this revenue fails to arrive — either through insolvency or renegotiation of terms — every connected hyperscaler will see massive revenue misses. These are not hyperbolic, mean-hearted or “skeptical” claims, but the hard mathematics underlying an industry that so often convinces those supposedly analyzing it to ignore good sense and assume that nothing bad will ever happen. Meanwhile, nobody seems to be taking the shocking financial condition of Oracle very seriously, despite effectively every warning light blinking at once. It is beyond abnormal for a company backing an $18 billion data center project to give a “ force majeure ” notice no matter what it says on Twitter , and suggests that the $340 billion in data centers it’s building for OpenAI are materially behind schedule, on top of the fact that Oracle is making sounds like it doesn’t intend to pay its debts, which is extremely alarming!  And make no mistake,  if Oracle builds these data centers and OpenAI doesn’t pay for them, it will face an existential financial risk unseen in the history of the tech industry. Oracle’s revenue has been flat for fifteen years when adjusted for inflation , with its only growth coming from its wrongheaded acquisition of Cerner in 2021 and selling AI compute that destroy its gross margins , with its largest company being a technically-insolvent startup with volatile economics and a CEO who wants us to accept “bad things will happen” in exchange for whatever ChatGPT is supposed to be . The problem Oracle also faces is that things don’t have to collapse for a collapse to occur. Chairman and founder Larry Ellison just added another $9.2 billion in stock-backed personal loans to his already-large pile , bringing it (by my count) to around $30 billion, and the margin calls will start somewhere around $60 a share for a stock that pumps and dumps based on any OpenAI news, meaning that anything along the lines of “OpenAI can’t pay Oracle” is guaranteed to start a spiral.  The only reason this hasn’t happened yet is that the media and the markets are unwilling to accept the sheer impossibility of Oracle’s $300 billion, five-year-long deal with OpenAI that neither company can afford and Oracle doesn’t have the capacity to serve . Every one of the “Stargate” data centers is heavily behind schedule, and Stargate Abilene — which Oracle claims is “75% delivered” — has no more than half of its capacity installed, not that anyone bothers to check these things or investigate the claims of anyone connected to the AI bubble. I roll my eyes at the feint and whiny concerns from Bloomberg about “risk related to Larry Ellison” as a result of Paramount’s huge debt raise . Anyone with a fucking calculator and an interest in the truth could’ve seen last year that none of the underlying economics of Oracle’s situation made much sense, it just required not immediately assuming that every AI data center was a perfect angel that would be birthed without fail onto a world flush with cash. Then there’s the shocking deterioration of semiconductor firm Broadcom, which is tied to Anthropic for at least $161 billion in non-cancelable chip leases, which has in turn forced Broadcom to raise $60 billion in debt to build them . Broadcom is, as covered in my Premium Hater’s Guide , a company already bathed in debt thanks to its 2023 acquisition of VMware, one that appears to be taking on tens of billions more as a means of selling TPUs to a company that may or may not exist by the time there’s a data center to put them in. How, exactly, is Anthropic meant to pay for all of those compute leases (or all of that compute) based on its current financial position? Taking away however I may feel about AI in general, for it to reach a size where it can handle even a hundred billion dollars a year in annual operating expenses — Microsoft, by comparison, is at around $176 billion — Anthropic would have to become one of the single-largest cash generators in the history of capitalism, or such a large participant in the world’s debt markets that it starts sucking up cash from the already-distressed and desperate customers of the CCC (lowest tier of junk) bond market . While a few people have danced with the edges of the potential insolvency of OpenAI and Anthropic, nobody seems to want to talk about the actual consequences, choosing always to take one shot of hopium before getting into the grisly details, with the assumption being that something will go alright — so I’m going to rain on everyone’s parade and go through each point one by one. The reason that so many of these misunderstandings exist is that people do not, on the whole, are surprisingly optimistic about basically any consensus opinion. Everybody has been saying that AI data centers are the next industrial revolution, NVIDIA’s stock has gone parabolic, every media outlet has constantly discussed Anthropic and OpenAI, and every hyperscaler has sunk hundreds of billions of dollars over the last few years into AI, which in turn makes you believe that everyone must be right and that everything will be alright by extension. This immediately makes people turn off the parts of their brain that feature critical thinking, because the alternatives are so utterly opposed to what’s been promised by this industry and the media. The assumption is always that this much money can’t be wrong , or that these are the smartest people in the world , or that these are the largest and most-successful companies in the world , even though none of these statements actually answers a single question about “ how the fuck does all of this actually work?”   Even if you think AI is the most wonderful, beautiful software tool ever imagined, there is no rational basis under which you can look at the current economic picture and say that everything will be fine.   The future I am talking about — one where most data center debt goes unpaid, where OpenAI and Anthropic fail to meet their obligations, and when AI GPU sales grind to a halt — involves Google, Microsoft and Amazon having catastrophic misses on their earnings expectations, and their future revenue growth stories collapsing, along with NVIDIA’s revenues dropping as much as 90% once the debt-backed AI capex boom ends. It involves CoreWeave, IREN, Nebius, and every other neocloud running out of money, fucking over investors in both their stock and debt some time in the next few years, with the underlying collateral made up of otherwise-useless data center construction and GPUs that will, at that point, be in a supply glut rivaling the Atari video game burial . I must be clear that I only have to be half right for things to be extremely bad. NVIDIA’s revenue growth cannot be sustained without endless debt issuance at a time when issuing debt is incredibly expensive, all in pursuit of data center construction that takes years to complete for customers that may or may not exist when it does so.  Hyperscalers have no other hypergrowth ideas left — no new Google Search, Microsoft 365, or Facebook — to sell investors, and in pursuit of AI have become the most asset-burdened companies on the Fortune 500, rivaling ExxonMobil, Berkshire Hathaway and Chevron, except instead of oil and diverse stocks they have GPUs that only retain value during a hype cycle. And there really is no hope for the $800 billion or so invested in AI startups in the last four years , as AI acquisitions are thin thanks to their high costs, miserable revenues and utter lack of intellectual property. I’m not sure venture capital — or anyone covering venture capital — has actually conceptualized how significant the losses may be, because I can see a world where virtually every AI investment goes to zero at a time when venture capital is facing an historic losing streak. In fact, I’m not sure anyone is trying to conceptualize what actually happens once the bubble bursts, because doing so requires you to think not just in terms of wasted capital, but about hundreds of billions of dollars of unpaid loans, dead AI investments, half-finished data center projects, and a stock market where 24% of the S&P 500’s value comes from five companies with stock prices boosted by theoretical returns on AI investments that are mostly from OpenAI and Anthropic. The fact we’re living in this bizarre juxtaposition of reality where we can run headlines about OpenAI-connected data centers never getting completed and its massive losses aside headlines about $50 trillion in data center construction by 2050 is a sign that nobody is taking the threat seriously enough.  I would love to say that I think I’m overreacting somehow, but I spend every single week running the numbers and actively looking for evidence that I’m wrong, mostly because the world, despite discussing the fragility of the AI bubble, doesn’t seem to want to think about it actually bursting.  I encourage you to do so, even if you’re pro-AI, even if you truly disagree with me, because this is extremely serious, and you can’t pay $1.3 trillion in commitments with hope. You can truly, madly love LLMs, you can name your dog Dario and your guinea pig Sam, I don’t care, but please, I’m begging you, stop making assumptions based on the best-case scenario, and start taking this seriously, because the consequences of me being right have global stakes.  Anyway, I’ll leave you with a chart from Torsten Slok, Chief Economist at Apollo , and a very reasonable question: if all of these tech companies are expecting record earnings over the next few years, where exactly will the cash come from? The fact we can’t cleanly answer this question as hundreds of billions of dollars get sunk into AI data centers may be the most glaring miss in the history of finance.  If you liked this piece, you should subscribe to my premium newsletter. It’s $70 a year , $18 a quarter , or $7 a month , and in return you get a weekly newsletter that’s usually anywhere from 10,000 to 18,000 words and provides vast, detailed analyses of the biggest events and companies in the AI bubble. If you want to get in touch — and especially if you have any juicy information about Anthropic, OpenAI, or any other companies in the AI bubble — hit me up on Signal at ezitron.76. I’m also on IB on The Terminal. The US government has over $40 trillion in debt, and to pay off that debt, the US government issues more debt, with interest payments making up 14% of all federal spending , and the federal deficit (IE: how much more the government spends than it pulls in in revenue) sitting around $2 trillion a year, meaning that, at minimum, it’ll need to borrow an additional $2 trillion in 2027 beyond what it borrowed in 2026 just to pay what Congress has authorized in spending, and the same amount again in 2028 if the deficit stays the same next year. This means that anyone pricing US Treasuries is doing so under the virtual guarantee that the US government will have to issue more debt . The alternative is that the US government cuts social security, medicaid or military spending, which would be very unpopular, and thus very unlikely to happen. The wars in Iran and Ukraine are putting increasing pressure on the world’s oil supplies, because higher fuel costs push up inflation because they increase the cost of effectively everything — both driving and flying to places, which is how most people and goods move around the world, as well as the cost of electricity (particularly where natural gas is concerned).  As I wrote a couple of weeks back, the war in Iran has also cut the supply of other raw materials, including sulfur (which is used in fertilizers), helium, and aluminium, further exacerbating the inflation crisis.  With the price of everything (at least in theory) inflating, investors demand that their bonds pay them at a rate that matches the rate of inflation.  There’s an ongoing debate — discussed here by the Financial Times — about whether US data center debt issuance has reached a point when it’s creating meaningful competition for US government debt, specifically that issued by Google, Meta, and Amazon, because these “stable” companies are offering attractive rates that are, in the eyes of some investors, as stable as lending to the US government. While it’s had some effect, it isn’t the big reason that the ten-year is selling off. The price of equivalent US treasuries at the time you are issuing the debt. The current price of the company’s debt. Amazon went public in May 1997, raised $54 million ($112 million adjusted for inflation), didn’t get a credit rating at the time (it didn’t issue corporate debt at the time), and had a negative 19% EBITDA margin. It was profitable four years later.  Uber went public in May 2019, got a B+ Credit Rating, had an EBITDA of -$2.7 billion, and an EBITDA margin of negative 21%, taking its first EBITDA profitability in Q2 2023 . It raised $8.1 billion at IPO ($10.6 billion in today’s money). By comparison, OpenAI’s EBITDA margin for 2025 was negative 160%. NVIDIA Will Still Have Customers After The AI Bubble! Sure it will — for its gaming segment that is now so small that it’s blended into “Edge computing” on its earnings. As I’ve discussed previously, 50% to 60% of NVIDIA’s revenues are coming from hyperscalers that are actively participating in the AI boom, and without that boom (and the debt necessary to keep buying chips), nobody else is buying them at anything close to today’s scale. If Anthropic and OpenAI die, all that data center compute will be used by someone else one day! OpenAI and Anthropic represent 80%+ of all compute demand, and their customers — unprofitable venture-backed AI startups — make up 80% of their enterprise revenues , which means they’re likely to die before OpenAI and Anthropic. Someone else will pay for the capacity if they don’t! Who? Who is actually spending money on AI compute? I’ve looked everywhere and I’ve found at the very , very best $22 billion of non-OpenAI/Anthropic compute purchases ! All of this capacity will be useful after the bubble bursts! No it won’t! Any AI data center that’s yet to be completed will cost just as much (if not more so) to finish in a few years as it will today, much like the electricity costs are going to be. In addition, the vast majority of customers for AI compute are unprofitable AI startups that want to compete with OpenAI and Anthropic, meaning that once the venture spigot turns off, nobody will want it. AI services are like airlines — you stand up inference based on the amount of customers you might have, and need to guess correctly about your demand, because if you’re off in either direction, you lose a ton of money. With most of the demand for AI driven by endless media and peer pressure, once the AI bubble bursts, the “demand” for AI services will be entirely driven by utility…and considering most services lose money even during the hype cycle , it’s hard to see what post-bubble economy even exists. This means that it’s unlikely that we’ll have a “booming open source AI market” in the end , and at best we’ll have some sort of handicapped Google monstrosity, though even that seems less likely based on the fallout I fear. Anthropic and OpenAI can just cut their costs! With hundreds of billions of dollars in non-cancellable commitments, neither of these companies can “cut their costs.” OpenAI and Anthropic are the fastest growing companies of all time! Based on annualized run rates that are pegged to non-specific periods of time, all as their costs explode and they sign non-cancelable agreements. If Anthropic and OpenAI die, there will be other winners! Who? There are no other AI companies that are growing anywhere near as fast or have customer bases that come close to Anthropic and OpenAI, and those customers are mostly other AI startups. If Anthropic and OpenAI die, it’s because their customers died, which means their customers won’t be the “winners.”

0 views

AI as the new search engines?

I have never done much in the way of advertising for decoded.legal. When someone new gets in touch to ask about legal work, if it something which we might be well placed to support, I typically offer an initial chat. As part of that, I ask how they heard about us. It is mostly “[x] recommended you to me”, or else “I follow you in the fediverse / I read your blog”. This has been pretty consistent, and word of mouth recommendations, or repeat business from happy clients, accounts for the vast majority of our work. Occasionally, someone says “Your site came up in a search engine”. Recently, there has been an increase in people saying “AI recommended you”. It seems that they were using their genAI tool of choice, and asking that for recommendations for tech solicitors, although I have not asked specifically what prompts they used (and I am not sure what I would do with that information anyway). I have done nothing to the decoded.legal website or blog in terms of “search engine optimisation”. The sites are mostly text, with some basic formatting applied. They load fast over pretty much any connection, because they are tiny. I don’t have a clever plan for cross-linking posts, or a particular structure to what I write, or anything like that. Perhaps I should. But I do not. Most of the time, for blogposts, I don’t even include a “and if you need help with this kind of issue, please contact us” ending because, well, that just seems unnecessary. But anyway, apparently, the sites have good “agentic / AI search optimisation”. I don’t know enough about the topic, but I am surprised that genAI can “recommend” anything. I am surprised that anyone would ask a tool like that for a “recommendation”, which implies some kind of analysis and consideration. For me, this is just search engine territory, and so perhaps some people are using genAI in the same way that they might have used DuckDuckGo, or Startpage, or Google. But people are doing it, and decoded.legal’s name and details are coming up.

0 views

2026-10-06 09:47: Been trying a new email client, Hylki, after reading about it on OMG! Ubuntu! Really...

Been trying a new email client, Hylki, after reading about it on OMG! Ubuntu! Really enjoying it. It's modern and has a tonne of features. https://hylki.app/ Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️ You can reply to this post by email , or leave a comment .

0 views
DHH Today

Over my dead pencil

Two weeks ago at Rails World, I told my fellow programmers that it's time to put down the pencils. We're not going to write the vast majority of code by hand any longer. Coding agents have gotten so good that it's simply not an economically viable enterprise going forward to have humans typing out lines of Ruby, Rust, or C++. When I polled the room for how many people were still writing a material amount of code by hand on a weekly basis, only a handful put up their hands. So they all knew this, but it still came as a shock to many to actually hear it. And I get that shock. Programming has barely been a professional career for a generation, and now it's being completely transformed. That's unsettling, even for a group of people who've seen technologies come and go on a regular basis. But this isn't just another technology, because AI isn't just another tool. It's far more like gaining some new coworkers who are exceptionally good and fast at a wide range of tasks, but still need a bit of help with some, and whose choices you might occasionally disagree with. From a certain angle, that looks like competition. Especially when it was barely five minutes ago that programmers were being treated like precious priests whose incantations were necessary to yield even the most low-hanging fruit of the computer. This perceived threat of disintermediation is clearly hitting some programmers hard. But I don't think anyone who's willing to lean into the future, make the most of this intelligence explosion, and apply their skills to what comes next needs to worry much. We're about to see an absolute bloom in software development as the price of development plummets and everyone realizes how much automation we still have left to do in this world. I think the only programmers who have to worry about this change are those who refuse to embrace, or drag their feet on, the progress brought by the age of agents. It's fine to be skeptical about the areas where our new clanker colleagues still occasionally get it wrong, but refusing collaboration is not a viable career path for almost anyone. Don't go down with the pencils. There's so much to build. We need you.

0 views
Unsung Today

GUIdebook and other GUI stories

I started GUIdebook in 2003, and last updated it exactly twenty years ago. It’s an interesting time capsule itself now, incompatible with mobile reading and sporting an aged design. I have kept it up because it’s apparently used as a reference in various user interface courses, and if you haven’t seen it, it could be a fun browse. = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/guidebook-and-other-gui-stories/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/guidebook-and-other-gui-stories/1.1600w.avif" type="image/avif"> I walked away from it by accident, distracted by a new job, but I always wanted to evolve it into something better as my storytelling skills and my interactive skills grew. Unsung is GUIdebook’s cousin, of course, especially in pieces like Lisa’s copy (and cut, and paste) , Were Touch Bar’s problems software rather than hardware? , and even little things like Anachronisms . But the direct preview of what I dreamt GUIdebook of becoming was in my last year’s interactive piece Frame of preference . It’s a history of the first twenty years of Mac interfaces told through its settings, it has a proper narrative (I never got to it with GUIdebook), and instead of screenshots, it uses Infinite Mac’s technology to tell the stories via emulation. I’m pretty proud of how it turned out, and you might enjoy it if you haven’t seen it yet. = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/guidebook-and-other-gui-stories/2.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/guidebook-and-other-gui-stories/2.1600w.avif" type="image/avif"> I would love to try a few more things like it. But, back to GUIdebook. Keeping it alive for 20 years required multiple updates as PHP evolved, and a more recent rewrite that ditched easily-hackable PHP altogether. (Don’t ask me how I know it’s easily hackable.) None of these were particularly noticeable on the surface, but I recently added one tiny user-visible change – the screenshots are now properly pixellated: It was fun – and slightly eerie – to update the site’s history page two decades after I touched it last.

0 views
Blargh Today

UniBalun dipole setup

Until now, my HF antennas have mostly been off the shelf. I’ve gone out with an AlexLoop (hmm, alexloop.com seems to be down. I don’t know if that’s permanent), and the Elecraft AX1 . They’ve both been fine, but have some drawbacks. The AX1 is a bit finicky about getting its radial(s) good enough, and the AlexLoop is a bit tricky to set up in a temporary but stable way. I have not have good experience with the half wave G5RV, yet, for some reason. So since all HF antennas are compromises, why not try an inverted V dipole? I had the UniBalun recommended to me, so I went with that. There are some minor things to think about, which is what this blog post is about. To become an antenna, I also needed antenna wire , and a way to put the middle of the dipole high up, with the antenna wire extending straight diagonally down. For a 20m (14MHz) antenna, I cut two 5.2m pieces, expecting to need to either cut or fold them back a bit, for the right resonance. On the UniBalun side I could just crimp an M4 ring to attach the antenna wire, but on the other end of the wire I needed to be more creative. It needed to be able to attach to paracord, and also be fairly easily adjustable in how much should fold back. Even if I were to cut it, I’d probably still want it folded back a bit, to adjust for anything from exact band location to moisture in the ground. I ended up using a butt splice crimp, without crimping it, as a kind of zipper to create the attachment loop. I then used a ziptie to make sure the fold is along the main wire as much as possible. I think an improvement here would be to use a second butt splice crimp instead of the ziptie, and glue the folded tip to it. That way it can move and be adjustable, and also straight. If wind starts moving it, there’s always gaffa tape. I had an extendable window washing pole, so that sorted height. I added a guying collar to secure it with paracord, though a hitch knot appeared to be stable enough too, and is more flexible about how high up you want the guying wire. The guying collar is the same diameter as the pole. Which means while I got it on, it ain’t never coming off. I probably should have bought a slightly bigger guying collar, and secured it with a shelf of tape below it. But it works. My bike’s wheel held the base in place. My antenna analyzer has bluetooth. I thought I’d check that out, to prevent me going back and forth too much. But the Android app is not compatible with the current Android release. And the Linux app didn’t seem to work either. So I told AI to build one: After a few more minor user improvement prompts, I ended up with something pretty usable . Here’s two example sweeps from my testing today: It saves everything from the session, so I can inspect the return loss and other graphs after the fact, too. I’m treating this tool as any official tool I find online; I didn’t look at the code at all. I would not have spent the time to actually build this manually. I would have given up and only used the rigexpert directly. Well, I did use it directly, too. It went well. The UniBalun is rated for 5W in data modes, so that’s what I ran. Not bad at all. Unreasonably effective , in fact. I also dialled in to my BBS over the mercury HF modem . This is my checklist for going out and playing radio. I don’t bring everything, only what I’ll need on the day. But I do go through the list every time because it’s easy to forget something. UniBalun — £9 100m lightweight antenna wire (just over 10m used) — £14 Guying collar — £3 Paracord — less than £1 worth used 2x M4 crimps 2x (or 4x) AWG 16-40 butt splice crimp Tent stakes — £13 USB hub (my Elecraft requires two USB ports to get audio and CAT), and one of my two USB-A ports has a yubikey nano in it. HF radio CAT cable External battery Baofeng + AIOC (convenient modem) Coffee thermos Picnic blanket Set home station frequency & power (if dialing in back home) Headphone cable Arrow antenna AX1 antenna Antenna stand (for AX1 or AlexLoop) Dipole pole Camping stakes Paper towels Lighter (for sealing paracord after cutting)

0 views
Chris Coyier Yesterday

WordPress MCP

I’ve still got all my WordPress sites on Pressable and happily so; I think they do a good job! They do everything you’d expect a WordPress host to do. The things I specifically like are: On that last point, I appreciated this little one-clicker: With that on (and presumably because I also use Jetpack and thus WordPress.com?), I can auth an agent like Claude Code that supports MCPs and get it connected. Now I can, for instance, tell my agent to go make a draft blog post quick about something I’m thinking about, so I won’t forget about it. Just to be meta, I’ll have it look at this blog post and make sure I don’t say anything weird about elephants. And it easily caught me! I think I’m more likely to use this for very rote tasks like making sure my headers are Title Case, and things are formatted like I want them to be, matching a style guide. I think it pairs nicely with having a “SKILL.md” file for it, which can be home-base for a style guide like that. The skill could have stuff in it like “only ever touch draft blog posts”, “make sure blocks of code are labelled for what type of code they are”, “make sure images are self-hosted”, “make sure anything I’m linking to looks correct and the link is valid”. I friggin’ hate AI slop writing, so please know I have no interest in automating anything around that. But as someone who has authored and edited one billion blog posts, some intelligent automation of certain rote tasks is appealing. Customer support is good/fast, including free movement of sites Deploying from a GitHub repo is a first-class citizen Perfectly good DNS management No need for extra security, performance, or update plugins Things are generally with-the-grain of the WordPress ecosystem

0 views
DHH Yesterday

What on earth are you dooming about?

Paradise is not lost, the world is not ending, and most material metrics of humanity have never been better. Yet the endless, incessant dooming about the climate, the inequality, and AI is everywhere. We may have killed God, but we clearly didn't bury the devil's anxieties with him. Yes, we're born with a negativity bias to keep us safe from starvation, saber-toothed tigers, and rival tribes. Good! But you don't have to let your caveman instincts run your whole life. The gift of fear — when the threat is credible and immediate! — is a key survival mechanism. This vague, fuzzy dooming about everything outside your control is not. In fact, nothing will make you more miserable than ruminating over climate tigers, other people's wealth, or thinking machines. Because rumination will break your brain and render it unfit for the purpose of living. If it turns out that The Terminator really is coming to get you, you'll have gained nothing from the upfront neurotic fretting. And if The Terminator fails to appear, you will have squandered your precious time missing the intelligence boom and the creativity abundance that AI has and will unleash. Likewise, if the climate really is doomed, you're not going to stop that spiral by planting another windmill or choking on a paper straw. Game theory has already seen to it that rival superpowers will accelerate their quest for power. None of the climate doomer nonsense Europe has wrung it hands about in the last thirty years has managed to curb the growth in global emissions (but it did wreck the continent's economy!). Finally, envy sits among the seven of deadly sins for a reason. Because freeloader thinking is also a primordial survival tactic, and it sneaks into your psyche when your disappointment with the outcome of your efforts overcomes your rational mind.  There have always been "winners" and "losers", and most of history had the majority of humanity live in abject poverty. The mystery is not "why are some people poor" but "why are some people not". And you won't find the answer to the latter in grievance soups of sorrow and self-pity. This is not the time to doom, baby. This is the time to bloom. Intellectually, spiritually, and productively. Put down your anxieties, arrest your neurotic impulses, and decide to be happy about the present, the future, and your own ability to make something of yourself and this world.

0 views
ava's blog Yesterday

nice things i’ve done for myself lately

I’m focusing on more care, compassion and kindness toward myself lately. It’s small things like just stopping and taking deep breaths and genuine breaks, letting go of arbitrary deadlines for myself that are not needed and stepping away from certain topics or blog posts for a while until I can handle them again. Muting some things, checking when I have the mood and time. I’m putting in effort to spend almost each morning on my balcony for a bit; a habit I had initially started quite a while ago but then unintentionally dropped. Drinking tea, eating breakfast, reading, soaking up some sun when it’s not cloudy. It really helps me feel more present and content. I’m writing this blog post there right now. The sun is out, but I am covered up a bit and my parasol is open. Some birds are singing, and I hear neighbors of mine eat on their balconies as well. The trees are still surprisingly green, and the sky doesn’t have a single cloud. When I am not on the balcony, and I am instead just lounging on the sofa or working, I put some calm morning music on, usually classical music or adjacent. I especially love these three: x x x , or Sabine’s Lothcat . I seemingly don’t grow tired of listening to any of them, and it feels so clarifying and grounding to me, without feeling overbearing or repetitive. I feel safe and focused, content with little, and in my own little flow zone. I’m also showering more often now, after low energy times and depression had made it harder. Even when I don’t feel particularly grimy, it’s a nice end-of-day ritual every other day. I know I always feel better when I’m clean, everything’s fresh and tidy, and my hair isn’t feeling greasy. I also started moisturizing again after the shower and got a moisturizer that smells like strawberry yoghurt, which makes me super happy. I’ve gotten back into taking care of my face again, being more diligent with my skincare, restarted my supplements and reordered the ones that ran out. Something I like to do before bed is going through the apartment and tidying up a bit so the next day starts without clutter. Putting away dishes and cups, clothes, controllers, hobby stuff and more. Preparing my desk, refilling my water bottle for the next day. Setting aside clothes for tomorrow. Sometimes I still clean the kitchen late at night so I get to walk into a spotless kitchen the next morning when I make tea. Having a grimy and messy kitchen from the dinner the night before right in the morning sours my mood and makes everything feel chaotic. As far as purchases go, I have admittedly been generous with myself. I got this new pink faux fur rug recently which I put next to my bed, so each time I get up, my toes touch something really soft. I also like to put soft socks or my Cinnamoroll slippers there so I can immediately put those on. Soft, soft, soft, in pink, white or pastel colors. I bought two Stardew Valley plushies (a Starfruit and Krobus!), restocked on new matcha and ordered CBD buds to make tea with (something I used to rely on a lot more years ago, but has slowly fizzled out). Due to an on-going pain and fatigue episode, I’m not well enough to go to the gym, or even make use of my home equipment, but I have been doing yoga again to the best of my abilities. I’m looking forward to my CBD arriving and making those sessions extra relaxed. I’ve also tackled my academic anxiety. Last semester didn’t go well for me as I was unable to study enough to have a good shot at passing the exams, so I postponed them. I felt great pressure for this semester to be better and to get back to studying as soon as possible, which resulted in a huge mental hurdle to even start and lots of doubt whether I am good enough or should just give up. I went slowly about it, telling myself I can just go do the administrative and organizing aspects of the new semester first and then see. I love using study software/games, so I encouraged myself with a new one so I’d look forward to using it. I set it up, then logged into my university account, prepared everything there, downloaded all needed materials, signed up for the live sessions, put all dates in my calendar, ordered all books I need, and then… actually started studying. It felt great, I had no issues understanding the material at all, and through the previous setup process, everything felt organized and like I truly have a grasp on this semester. I really needed this experience of feeling competent and capable in my studies again. Aside from that, I’m happy about what a perfect game FFXIV turned out to be for someone like me. When I am fatigued and in pain and with quite a bit of brain fog, it helps to have a game that doesn’t dictate what you do, and all gameplay can just be done via mouse, permitting me to move my body as little as possible. If I don’t feel up to it, there is always something easy and mindless to do; no “ugh, I would love to play that game right now, but I am at that difficult part!”. It’s also simply nice to get to run and fly around when in real life, you’re unable to walk or stand much at the moment. I’m very grateful for how much Kami has been helping me with the game as well. On a different note, I’ve had lots of struggles with executive functioning lately, basically feeling locked in and frozen as I cannot start doing the things I want to do, even easy things. Making appointments, refilling prescriptions and restocking anything felt like herculean tasks. All of the above helped me a lot with that. I even made an appointment to get my nails done later today; medication makes it a lot easier to move again, too. Maybe I will also make a different appointment to get a massage another day :) Now that this is done, I’m going to tape some scraps into my journal and then study. Later on, I will write another matcha review . Have a good day. Published 05 Oct, 2026

0 views

How fast is Python 3.15?

It's October once again, and that means it is time to take the new release of Python for a spin (technically, it is the 3.15.0rc3 release that I'm using, the official 3.15 release is still a few days out). As I did with my Python 3.14 performance article of a year ago, today I'm sharing a new run of my informal Python benchmark, comparing Python 3.15 against previous interpreters all the way back to 3.10. If you are not interested in the charts and the tables and just want to read my analysis, feel free to jump to the conclusions section at the end.

0 views
Stratechery Yesterday

Apple and a Hacker’s Future

Listen to this post : My computer got hacked, which is always embarrassing to admit, because it was my fault; the vulnerability that was exploited is detailed in this Ars Technica story : Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.” The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here . Details of CVE-2026-65400 became public at last week’s Black Hat security conference. Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities. Apple credited security firm Bynario for reporting the vulnerability. The computer in question was my always-on Mac Mini that runs nothing but Claude and Codex; the first thing that makes this story interesting is that that was my saving grace. I have discussed, in both Writing Things Down and in several episodes of Sharp Tech , Gecko, the agent that I have built for the people that work with me. It’s awesome, but purposely constrained in capability and in what it can access. My real agent is a dedicated Claude Code thread that writes down all of my ideas and tracks the status of the myriad of projects I’ve spun up over the last few months. There are a few reasons why I use Claude for this functionality, even though I’m not a big fan of Claude-speak: Claude in its Code harness seems to handle wide-ranging discussions better than Codex, and it follows my instructions about writing things down in the way I want to more gracefully. Code also has a persistent monitoring tool that I utilize as an inbox to capture interactions with a status board I built to visually track everything I have written down, as well as interactions with a Telegram bot (OpenAI’s new Dots achieve some of this functionality , which has been sorely needed in ChatGPT/Codex). Said monitoring tool stands down every 30 minutes, so my agent restarts it on a schedule; that is what triggered an URGENT notification from Claude: Claude had more diagnostic information, unilaterally stopped executing all commands, and noted that my account could now run admin commands without a password, which it assumed was how the files were written; it then had a number of suggested next steps to address the problem. The one I ignored was its recommendation that I not invoke Claude anymore; in fact, I used Claude to root out the malware — we eventually found the exact four second period where it gained access — create a tool to watch for it in the future, and then wiped the Mac Mini. All of this happened before I found the Ars Technica article detailing the vulnerability, and it was pretty remarkable. I understand that people are nervous about giving these agents access to one’s computer — as I noted, the Mac Mini in question has nothing on it except for Codex and Claude — but in this case you could make the case that I would have been in much more trouble had I not had an agent running persistently. Apple doesn’t seem too happy about agents; last week the company’s developer site released a note entitled Updates to Full Disk Access in macOS ; I’m going to quote it in full: We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with. Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. To say that I’m nervous about what Apple’s solution will entail is a massive understatement. There is one aspect in which the Mac is the perfect agent host: Apple has, for decades, invested in a combination of scriptability, automation, and accessibility APIs (these are very often the same thing) that makes it remarkably well-suited to computer use. Then there is the fact that macOS is a certified Unix system; this means that agents — which are perfectly suited to the command line — have access to the entire universe of tooling built for Unix systems. And, of course, Mac hardware is amazing. The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile. The biggest issue is GUI-only permission prompts that are invisible to software running on said computer, including agents. These permission prompts are a part of a macOS subsystem called Transparency, Consent, and Control (TCC), although Apple doesn’t seem to use this name anymore. There are a whole host of things on your Mac that are covered by TCC — the list only gets longer with every OS release — and you have to explicitly approve access to the covered items for every app that wants to access them. If you’ve been prompted for permission to use the Camera, or, much more annoyingly, access the Desktop or Downloads, you’ve encountered TCC. This system is annoying but manageable on your primary Mac; it’s a disaster on a headless Mac running agents, for two reasons. First, agents write new programs all of the time, and in my case, those programs need access to devices on my network (SMB shares, for example, trigger a TCC warning). What I need is a permission layer for agents, not the programs they create; TCC is operating at the wrong level of abstraction. Second, the TCC subsystem exposes its prompt in a protected space that no program can see; that means that programs silently fail and the agents don’t know why; what I have to do is remember that there is probably a permissions prompt on screen, log into the Mac Mini with screen-sharing software, and click OK. There are in fact good reasons for this. The goal of the TCC subsystem is to protect you from malware accessing your computer nefariously; if the prompts were accessible by software running in userland then malware could work around it. Again, though, I am running a computer that is purpose-deployed for agents: for my use case TCC is nothing but a headache — one that indirectly led to my being hacked. Again from Ars Technica: As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren’t within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week’s security update is also a must. Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale ); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously; the reason I didn’t depend solely on Tailscale from the get go is that I wanted a secondary way to reach the Mac Mini (which should have been SSH tunneling; again, this is somewhat embarrassing and my fault). What really irks me about this episode, however, is how Apple released the fix. Obviously I know that you should always keep your computer up-to-date for security purposes; that’s why I have all of my computers set to automatically install security updates. What I didn’t understand is that this setting does not in fact apply to most security updates. CVE fixes almost always arrive in point releases; in fact, the most recent point release was about fixing this bug. In fact, I suddenly realized that I had been leaving myself more exposed than I should have been for years, under the mistaken assumption that checking “Install…security updates automatically” would in fact install security updates automatically. I am admittedly being pedantic here; at the end of the day I hadn’t installed the point release promptly enough. Still, it does bug me that a company that is so concerned about access to my Desktop wasn’t very concerned about how a pretty important setting reads to a fairly sophisticated user. Again, this is my mistake, but the mistake was an honest one downstream of trusting Apple to call a security update a security update, particularly if they give the option to automatically install them. That’s trust they have by-and-large earned; what is increasingly frustrating is that that is trust they increasingly demand, and the scope of those demands is continually increasing. It may seem silly to complain about the labeling of an update, but if you’re going to demand permission for accessing a network share can you at least patch my computer when I explicitly gave you permission to? This, by extension, is why the note about full disk access is unnerving. I can understand that users may not understand that granting an agent full disk access means that that agent can read your iMessages (for now — I bet that the iMessage store will be encrypted in the near future, a la iTunes in the 2000s ); other users, however, may want exactly that. Or, like me, they might want to actually use a Mac as their own personal computer, not as an Apple-managed device increasingly akin to an iPhone. Maybe this episode shows I’m too dumb to risk that; maybe it just means Apple and I are, after many years together, speaking past each other. Last week Mark Gurman wrote an article on Bloomberg entitled Apple Is Finally Ready to Enter Its Next Big Category: the Smart Home : Apple Inc. plans to make its long-delayed push into the smart-home market on Oct. 13, marking a critical product expansion for the company under new Chief Executive Officer John Ternus. At the center of the strategy is a smart-home hub code-named J490, according to people familiar with the matter. Apple also plans to announce the first update to the HomePod mini since that device’s 2020 debut and its first new TV set-top box since 2022… The products also serve as a showcase for Apple’s new Siri AI assistant, technology that the company spent years developing. The revamped Siri suffered numerous delays, and the smart-home devices should help spotlight Apple’s efforts to finally catch up in artificial intelligence. The home hub will take the form of a roughly 6-inch square display, with versions that can be mounted on a wall or placed on a countertop, according to the people, who asked not to be identified because the products haven’t been announced… Apple envisions customers placing several of the displays throughout their homes. They could be used to control thermostats, door locks and other connected products, as well as for video calls, intercom-style communication, music playback and viewing slideshows of photos stored in Apple’s iCloud service. That wasn’t the only home automation related announcement last week; Muse creator Nat Friedman posted on X : I get, very acutely, that I am not representative of the general population. I actually use agents, for one. More than that, I’m not a target customer for Muse: I’m more interested in building my own agent than in using Meta’s; one of my current projects is the construction of a small home electronics lab to make some of my own agent-controlled gizmos. With that noted, what struck me about Gurman’s article is just how unenthused I am by an Apple smarthome product. Some of this is fatigue from a decade of Siri disappointment and skepticism about the company’s ability to deliver on a voice-centric product. More than that, however, I bristle at the idea of introducing Apple’s constraints to more parts of my life. Those constraints aren’t just about things like full disk access. To the extent that Apple delivers on integration with things like thermostats and door locks is the extent to which they work with 3rd-party device makers; the problem is that third party device makers mostly suck, particularly from a software perspective. Even if Siri were perfect, Apple will have the challenge of delivering an experience that isn’t defined by the lowest common denominator. What I’m much more interested in is controlling the software layer myself. The fact of the matter is that with AI you can decompile almost all existing software — there is a revolution happening in gaming over the past few weeks, as game after game is decompiled to source and ported to any platform you wish — and you can write your own. That means my software that interacts with my agent in the way I want it to for everything; that’s way more exciting than praying Apple delivers the right API and that 3rd-party developers don’t suck. This, by the way, is a problem facing Siri; I wrote after the recent iPhone event and Ternus’ vision of the “Intelligent Personal Hub”: What is most interesting, however, is how the biggest advantage Apple has traditionally had may be a hindrance…it’s extremely impressive that Apple claims 300,000 apps work with Siri. Note, however, that the implication of it being “easy for developers to adopt new capabilities” is that developers have to actually put in the work — that’s work in addition to updating their UI for Duo. In a world where everyone has to convince developers to build integrations, this wouldn’t be an issue. However, this is where browser use looms large: to the extent that agents can just use the web is the extent to which they get an integration with basically everything for free, and it’s Apple, with its dependency on developers plugging into APIs, who is at a disadvantage… In Apple’s vision, the utility of Intelligence is defined by its ability to augment your existing workflow. Thus the reference to updating your calendar and reminders. It’s very possible, however, that the better workflow is to outsource a lot of work that used to happen in apps to the agent directly. What’s better, using a structured reminders app that you have to check, or simply being reminded directly by an agent? In truth the answer will likely vary by person, but it’s worth pointing out that Apple is so married to the app paradigm that they probably never even considered the alternative. Apps were amazing, and a better experience than what came before; that doesn’t mean they are the best experience, and anyone who has seriously used an agent knows exactly what I mean. Apps get in the way, which is to say that integrating with them is to make your agent worse; I don’t want a different UI per app, when I have at my disposal true UI — the Universal Interface for everything digital. This is where the Muse Gadgets program is a stroke of genius. Meta is seeding an entire ecosystem of devices, some of which might become real products, and it’s completely open source. The payoff isn’t in selling devices; it’s in Muse being the interface for everything. 21 years ago Paul Graham wrote Return of the Mac : All the best hackers I know are gradually switching to Macs. The reason, of course, is OS X. Powerbooks are beautifully designed and run FreeBSD. What more do you need to know?… With OS X, the hackers are back. When I walked into the Apple store in Cambridge, it was like coming home. Much was changed, but there was still that Apple coolness in the air, that feeling that the show was being run by someone who really cared, instead of random corporate deal-makers. So what, the business world may say. Who cares if hackers like Apple again? How big is the hacker market, after all? Quite small, but important out of proportion to its size. When it comes to computers, what hackers are doing now, everyone will be doing in ten years. Almost all technology, from Unix to bitmapped displays to the Web, became popular first within CS departments and research labs, and gradually spread to the rest of the world. As someone who switched to the Mac in 2004, a year before Graham wrote his article, this was edifying: “I just switched to the Mac, I guess I’m a cool hacker”. In truth, the Unix part didn’t matter much to me; I preferred the design and the UI, and really wanted to try GarageBand. And, over the ensuing years, I appreciated the extent to which the Mac just worked — slower than the alternatives at first, then at parity, and then, with Apple Silicon , better than anything else. The thing about AI, however, particularly agents, is that they make anyone a hacker. You really can do anything now, if only you have the volition and the ideas, and once you embrace that, a walled garden feels less like protection and more like a prison. I’m not, to be clear, predicting Apple’s downfall; I’m not even changing my computer or phone. What is surprising to me, however, is that not only am I uninterested in the company’s home device, I can, for the first time, envision a future where I don’t buy Apple by default. Indeed, this already happened: even before this incident I had already purchased a new server, which will run Linux; I will never put a Mac in a rack again. That’s fine for Apple, of course; that’s not what their computers were designed for. The question, however, is whether what they are designed for is the future I am barreling towards, one where agentic abstraction both renders traditional interfaces relics even as it makes computing everywhere more accessible than it has ever been, where the limit is not a developer building for scale but my own imagination building for myself.

0 views
Unsung Yesterday

“I don’t know why this is so hard.”

Speaking of string interpolation , I loved this recurring gag in BoJack Horseman :

0 views
Martin Fowler Yesterday

Fragments: October 4

In response to my last fragments (probably the bit about us worrying if LLMs have consciousness when we when we should be wondering why they don’t have a conscience) “Metalanguage” replied : we shipped the id and forgot the superego. classic software lifecycle. I don’t know what was on their mind, but their post immediately made me think of the classic 1956 movie Forbidden Planet. Plenty of sci-fi, and other literature, have explored humans creating technology with unintended behavior, going back at least to Mary Shelly. But that movie was particularly influential on sci-fi film-making and in the heart of its story is what happens when we nurture a thinking machine. I use the term “nurture” here deliberately. We talk of building software, but building implies a degree of determinism. When we build a bridge, or a locomotive, we expect it to behave in a controlled and well-understood manner. That’s a difference in degree to how we cultivate plants in our garden, or nurture young children. One of the challenges of working with these systems is understanding what has changed in this shift from building a computational system to nurturing an inferential one, and how our processes need to change in response. We get unintended behavior with deterministic building: some bridges have collapsed, and our computational systems often have bugs. But one difference is that when we find a bug in a computational system we can usually fix it. Even if we can’t, we can usually disable a component so the bug won’t do further harm. With inferential LLMs however, there is no such simple fix or disablement, which may lead us to the fate of the Krell. (If you haven’t seen Forbidden Planet, it’s well worth watching. Yes, it shows it was made in the 1950s - with special effects, music, acting, and attitudes of that decade. But the story is solid, and its key theme is very relevant to the future we build with generative AI. Just don’t read about it in advance, it’s better to be immersed in the story without spoilers - although my memory of that experience is understandably hazy.) ❄                ❄                ❄                ❄                ❄ Many people who follow me also know my friend Ola Bini, who was my colleague at Thoughtworks for many years, and was living in Ecuador working as an independent software security expert. Sadly his time in Ecuador was dogged by a bogus prosecution by the authorities there. But things seemed to have settled down, and although not allowed to leave Ecuador, Ola was able to get on with his life. Sadly that’s no longer the case as he was deported from Ecuador on Friday: According to information released by his lawyer, Bini was intercepted by a car with four people who identified themselves as immigration agents. He was then taken to an immigration office without further information or a formal order from a competent authority. There, officials told Bini that his visa had been revoked but didn’t show any supporting document. Bini’s defense filed a habeas corpus to safeguard his freedom and prevent his deportation. Yet, Ecuadorian authorities affirmed that the developer represents a threat or risk to public security and the state structure, and must leave the country. The ground for deportation is a secret report which allegedly asserts that Bini committed acts against the security of Ecuador. The defense could not access its contents. I was really worried for a while, since it wasn’t clear where he was going to be deported to. But he tweeted from Sweden , so I’m thankful for that. But this is only a partial relief. Ola has spent thirteen years in Ecuador and made it his home. To be thrown out of your home for scant reason is a heavy thing to bear, and the officials who did that have committed a serious offense. ❄                ❄                ❄                ❄                ❄ DDD Europe have released the video of Gien Verschatse interviewing Eric Evans and myself at the conference in June. We start by talking about how we bonded over conceptual modeling in the late 1990s. The conversation quickly moves to AI, we note that it’s impossible to predict how such a big change will work out. We do expect that it will cause us to think about our work in different ways, but the change may well be liberating, it’s reinvigorated Eric’s love of programming. people are probably going to feel very frustrated by [the new way of thinking about software]… but when you get through that, there is a kind of a wonderful feeling of my brain’s been loosened up. Our background in agile planning helps with the uncertainty, as we are used to taking small steps and being attentive to feedback. We mull on the interplay of writing and thinking, in terms of both prose and code, and how its very much an iterative process of exploration and refinement - the same is true when we chat with our LLMs. And don’t miss Eric’s important final tip. ❄                ❄                ❄                ❄                ❄ Paul Graham: There were a lot of things that only worked because there’s a limit to the rate at which humans can operate. We’re about to find out what all of them are, as they break. ❄                ❄                ❄                ❄                ❄ The speculation continues about whether or not reading code will play a part in a software developer’s future. Geoffrey Huntley says . People are still saying, very loudly, that code should be readable so that humans can understand it. I no longer think that’s the goal. Interestingly his example has the LLM explain a haskell function definition… by translating it to Python. Which, to me, suggests there is a role for code - just that LLM need not store code in the same form that it presents it to a reader. This is essentially the same idea as projectional editing , which posits that the editable representation of software need not be the same as its storage representation. Sam Ruby touches on this as he muses on a Rails World keynote . He quotes DHH saying: Rust is a good prompt compilation target for the moment, but so is C++. And soon assembler. Then microcode. Myopic to think we’re going to stop the agentic drill bit until it reaches computing bedrock. He responds with: The post leaves one question unasked, though: what sits at the top of the drill? What do we keep, edit and trust as the source of truth? He carries out exercise of looking at some Rails software. Represented in Ruby/Rails and its about 60,000 tokens. Compiling it into C it turns into 4,000,000 tokens. That increase in token size will hamper the LLM, that still has to fit it into its context window, and even if it were to fit, figure out where to focus its attention. Sam points out reasons why, even absent a human reading it, it makes sense to represent the program in a higher-level language. what Rails becomes when agents write the code: the most compact, precise and conventional specification of a web application, whatever it ends up compiled to. Let the drill go as deep as it can. Just keep the notation at the top. This all reminds me of what Unmesh Joshi argued : that code serves “two distinct but intertwined purposes”: instructions to a machine, and a conceptual model of the problem domain. After exploring how those change with LLMs he concludes: The role of coding is not disappearing. But it is changing. As LLMs make code generation cheaper, the mechanical act of writing instructions becomes less central. What becomes more important is making the conceptual model explicit, discovering the right vocabulary, and refining that vocabulary through iteration, domain expertise, and feedback. This is also why programming languages continue to matter deeply. We are not meant to be passive reviewers of generated code. The act of writing code is itself part of our thinking. Code is still instructions for a machine. But it is also a model of understanding. In the LLM era, that second role becomes even more important. The future of coding is not just writing more code faster. It is building better conceptual models, better vocabularies, and better foundations on top of which both humans and LLMs can work. ❄                ❄                ❄                ❄                ❄ In a later post, Sam pondered on how people are talking about the capabilities of agents in a way that resembles the parable of the blind men and the elephant. We all only have only a partial view of this object and where it’s going. A theme for all of us: The practical question isn’t whether agents are good. It’s this: for the task in front of you this week, where will the information come from, and what will check the result? ❄                ❄                ❄                ❄                ❄ The Economist’s pithy summation of investors concerns about the dangers of AI companies’ products : It’s hard to celebrate an initial public offering that leads to a terminal public offing. ❄                ❄                ❄                ❄                ❄ The news about the latest model from Google is interesting . Gemini 4 Argon has an insanely low hallucination rate on Artificial Analysis. 15%. Grok 4.7 is at 29%. GPT-6 Astra 45%. Opus 5.5 59%. Fable 5.1 69%. The only models below it barely answer anything. None of them get more than 15% right. It gets fewer answers right than Opus 5.5 on max, 50% against 66%. But when it doesnt know, it says so instead of making something up. Being clearer about what it doesn’t know, at a cost of getting less answers right, is definitely a trade-off I prefer.

0 views
Unsung Yesterday

“Yeah… I was very tired that night.”

The (un)installation bug from the previous post was an overeager directory delete, but a more common problem I’ve seen is this one. Here’s an example from iTunes 2.0 : The installer tries to erase a previous version of iTunes using (with root privileges) the command. However it doesn’t take into account that volume names can contain spaces. […] When the diskname (partition name) starts with a space the following happens: So removes (all mount points!) and a nonexistent path , but no errors are displayed because they are /dev/​nulled. And a very similar thing a decade later, from Steam’s Linux installer: I launched Steam. It did not launch, it offered to let me browse, and still could not find it when I pointed to the new location. Steam crashed. I restarted it. It re-installed itself and everything looked great. Until I looked and saw that steam had apparently deleted everything owned by my user recursively from the root directory. Including my 3TB external drive I back everything up to that was mounted under /media. The culprit was identified by another user a few messages down: could be evaluated as is empty These are the sort of classic user-generated content meets string concatenation/​interpolation bugs that haunt engineers’s dreams. The solution: If a user gives you a string, you have to wrap it as safely as possible so that it could never break apart into pieces in transit. So you wrap the path with quotation marks. (I believe you can actually do this everywhere in Linux – will work as well as – except no one ever does so as it’s quite annoying.) But then, a string with quotation marks would escape containment, so you have to escape those by changing to . And then, naturally, you also have to escape any freefloating backslashes to . Of course, there are usually functions that take care of all of the above; you just have to remember to use them, as well as think about the edge cases like a variable being empty to begin with. This all is a distant version of SQL injection – perhaps most well-known from this XKCD comic – and a more modern prompt injection . There’s even a version of it in UI design: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/1.1600w.avif" type="image/avif"> = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/2.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/2.1600w.avif" type="image/avif"> = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/3.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/3.1600w.avif" type="image/avif"> Here, the wrapping isn’t for security reasons, but to help people understand where the command ends and the string begins. But this introduces a new challenge, as any type of visual wrapping – quotation marks, bolding, italicization – can draw undue attention to the string itself. So, sometimes you just leave it be and hope for the best: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/4.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/4.1600w.avif" type="image/avif"> But let’s go back to the installation issues. I bet there are were tons more string interpolation and escaping bugs that we simply never learned about. Yet, as users of a project called Bumblebee learned in 2011, nothing beats the destructive power of a simple typo. The best way to start here is with the summary of the fix to the bug, because that is the best encapsulation of the story: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/5.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/yeah-i-was-very-tired-that-night/5.1600w.avif" type="image/avif"> Yeah, you read it right. Here’s the original bug report : An extra space at line 351: causes the install.sh script to do an on the directory for people installing in ubuntu. Totally uncool dude!!! The script deletes everything under . I just had to reinstall linux on my pc to recover. Removing the space will fix this. Probably should do it quickly!!! Reader, the bug was fixed quickly.

0 views
matklad Yesterday

Benchmark In Milliseconds

How long should a micro benchmark run? My rule of thumb is to tweak the input size until the benchmark takes about 300ms, for the following reasons: The imminently-to-be-stated assumption here is that the purpose of benchmarking isn’t so much a precise measurement of performance, but rather providing the author with enough intuition to make a correct decision. Milliseconds are integers ranging from 1 to 999. Enough precision to notice even a small improvement, and easy to scan visually. No need for different units or floating points (compare with ). Anything faster than, say, risks being skewed by fixed costs (e.g, interpreter startup). Hundreds of milliseconds is an eternity for a computer, usually enough to make one-off overheads irrelevant without using fancier (= less robust) techniques to explicitly account for them. For a human, hundreds of milliseconds is fast, but noticeable. Pushing numbers into human-perceptible range allows me to use my intuitive sense of time and speed, it doesn’t rely exclusively on numeracy. It’s plain fun to see, as a result of optimization work, how a previously lagging CLI command becomes “instant”. But anything longer than a second makes iterating on the benchmark slower than it needs to be. Running a benchmark 10 times in a row to eyeball variance should be fast!

0 views
Unsung Yesterday

“But it would have bothered us the rest of our lives.”

On the morning of December 28, 1998, the day before the game Myth II: Soulblighter was supposed to hit the store shelves, the publisher received a phone call: […] one of Bungie’s overseas publishers called to say that a woman had played the game and then tried to uninstall it. The game software had uninstalled Myth II as it was supposed to--but it had also erased some of the other files on her hard drive. The first reaction was panic […] [Bungie cofounder Jason] Jones and another programmer tried to replicate the problem. They quickly found it and figured out how to correct the faulty lines of code. Fixing the problem would be easy—except for the 200,000 copies that were already packaged or on the road. Seropian, Jones, Zartman, Donohue, and sales and marketing director David Joost met to decide what to do. They had two options. The first was to say nothing. The argument in favor of this alternative was that the problem occurred only when the program was uninstalled and then only when someone had installed the game in an unconventional way to begin with. Since the chances were slim that anyone would install the game in this weird fashion and uninstall it right away, the risk to the company’s reputation was minuscule, particularly since they could post an announcement on their Web site along with a free patch that could be downloaded to correct the problem. The second option was to recall the game. That would force them to trace every copy that had already gone out, scrap every finished copy, and start all over again. The story continues in a Chicago Reader article by Bill Mahin preserved on Internet Archive – there’s a blizzard and other things going wrong – and is a great callback to the days of software being sold as physical media, in physical boxes. I was curious about the cause of the bug, and found this answer from someone who worked on the original Myth I: So I wrote the Myth TFL installer (not this one). The reason this happened is because you could install other maps and whatnot, and to make the uninstall clean, we had to recursively delete your data folder. In the sequel, somehow that code […] was used to delete the applications directory, instead of just the data directory in the applications directory. So if you installed it on C:\, it would delete everything recursively from there. Nowadays, uninstall usually leaves any user installed files (like saves or downloaded content) but at the time, as the article suggests, hard drive space was more precious. Also, I wasn’t there for this issue, so I don’t know the above for sure, but having written the previous installer, I’m pretty confident that’s what happened.

0 views