Latest Posts (20 found)

On Free software project boards and governance

As always, these are just my opinions. If the remit of the board is not clear to all concerned - the broader community, not just the members of the board - and if that remit is not accepted, argument and politics around what the board should be doing are inevitable. This wastes everyone’s time, on meta debates and side issues, and leads to conflict and division. Does the board set the strategy? Define the policy? Hold an executive to account? Mediate or arbitrate disputes? Act as a point of escalation? Fundraise? And so on. That remit may change over time, and I see no problem in that, as long as that change is in itself both clear and accepted. Similar to the point above, without a clear focus, and a set of documented and measurable objectives / priorities, the board is but an iceberg, bobbing around in the ocean, haphazardly knocking against interesting things. Without priorities, the board may be full of people who, individually, are all doing, or are capable of doing, great things in support of some broader mission, but without the cohesion needed for a board. What are the board’s success factors? Failure criteria? To be productive and worthwhile, board meetings need to have an agenda, and all relevant pre-reading, circulated sufficiently in advance for board members (volunteers, who have other commitments) to read, contemplate, and prepare. The goal of each agenda item must be clear. Is a decision required? Is this an update (which, for some reason, could not be delivered asynchronously)? Is a discussion required, and if so, to what end? Sufficient time must be allowed accordingly. In the context of a group of volunteers, consistent participation may be unrealistic. People have other priorities, and may not be able to volunteer every month. A board which requires 100% of board members to be present to form a quorum for a meeting is not conducive to effective decision making if participation is inconsistent. It means that taking decisions during a meeting is rarely possible. Similarly, if an asynchronous decision making process requires all board members to vote one way or another, or to abstain, before a decision can be reached, then that process is neutered by a voting member’s non-response. A board needs to be set up with inconsistent participation in mind, if that is the operating reality of the board. It is impossible for a board to have informed conversations, and make good decisions - decisions which are truly in the interests of the community that the board serves - unless everyone on the board has access to all relevant information. Information asymmetry leads, at best, to poor and inconsistent decision making and, at worst, to factionalism and mistrust.

0 views
Unsung Today

“But it looks like a lot less work than we had to do.”

I wrote recently , about macOS, “it’s hard when the operating system cedes its responsibilities to provide good design patterns,” and Mac developer Brent Simmons in a recent essay shares a parallel line of thinking about how unreliable and untenable designing with the basic macOS UI components has become: But there’s another reason: the stock Mac UI is designed by Apple, the best designers in the world, and do you really think you can do better? Really? The app world is full of people who think they’re better and they’re really, really, really not. Well, I still think Apple has the best collection of UI designers in the world, but, for whatever reasons, the guidance from above on how the Mac UI should look is missing the mark. I’m not blaming the people doing the work — they’re doing great work with the direction they’re given. So this — bad direction — is where the secret third reason falls down. And we’re left with no real reason to stick with stock Mac UI (except for wanting approval from longtime Mac people like me, and you really shouldn’t care about that at all). In addition to low interface quality and sometimes flimsy guidance, Simmons also adds how much effort it is just to keep up with default macOS interface, which feels like the opposite of its social contract: The idea was that by using stock Mac UI you the developer would be carried along — you’d get most of the macOS changes every year mostly for free or with not that much work, since you’d kept up every year. But my app NetNewsWire has a very stock Mac UI, and Liquid Glass adoption last year was a lot of work. Using stock Mac UI didn’t save us much — in fact, we had more work to do compared to the apps with more custom UI. We talked about this before in the context of all those menu icons that were mandatory… for just one version . Imagine sinking time and resources to create the icons one year, only to learn 12 months later that this was just a head fake, and one without – as far as I know – even a hint of an apology from Apple.

0 views

Advice to a beginning software engineer

In general, you should be suspicious of engineers who are trying to give you advice. Even during ordinary times, this industry is so wide and changes so quickly that nobody really knows anything for sure. And we are not in ordinary times. The advent of LLMs and AI agents is the largest change to software engineering in my professional lifetime, and possibly the largest change ever. That said, here’s my advice: Most experienced software engineers today have spent the bulk of their career in the ZIRP era . This was a time when investment money flooded the industry, driving up engineer bargaining power. Big tech companies spent a lot of money and effort trying to make their engineers happy and comfortable. If you were an engineer at one of those companies, you could expect to have a decent say in what kind of work you did, and even what kind of politics your company had. Unless you worked at a handful of unusual companies (e.g. Amazon) you could expect to be practically immune from layoffs, and to only be fired after many months (sometimes years) of low performance. A lot of advice floating around is ZIRP-era advice: either it was written during that era, or it’s written by engineers whose habits of thought were formed during that era. This kind of advice typically tells you to take a stand (e.g. to unionize 1 ), to speak up more against “unethical technologies” like AI, and to insist on being given time to practice your craft the way you want. This was great advice in 2016, but it’s not good advice in 2026. In fact, I think it’s unethical for senior engineers to give advice like this to junior engineers who are more likely to take it (because they’re young and naive) and more likely to be punished for taking it (because they lack leverage). If you’re a new engineer, don’t fall for it! Let your colleagues with more experience and political capital take risks like that. Instead, I recommend adapting to the demands of the current era of software engineering. Try to make yourself useful to your team and your manager. Be pragmatic about your actual bargaining power (fairly low, unless you’re useful enough to be irreplaceable). Keep your expectations of yourself under control: don’t spiral out in an attempt to do something astonishing, just try to be consistently helpful. Don’t start fights. Being pleasant to work with (particularly when you don’t get your way) covers many sins. Once you’re further along in your career, you will be expected to start some fights, but this is not a tactic beginners should adopt : there are a lot of factors 2 that determine when and how to start fights, and getting it wrong can be costly. Just don’t risk it. In general, you should stay out of the political game at all costs. Even quite senior engineers are political tools, not movers and shakers, and this goes double for junior engineers. Simply trying to be friendly and helpful will get you infinitely further, politically speaking, than any amount of Machiavellian game-playing. Keep your head down, stick with your management chain (not random people who try to assign you work), and you’ll be fine. As an engineer, your main technical value is conscientiousness . You should be asking lots of questions , both of yourself and of the engineers around you. You should be actively trying to make sense of the systems you work with, instead of just assuming someone else has it covered. Software systems are complicated enough that a few weeks of careful attention will mean you know technical details that nobody else does, which is a really easy way to add value. If you ought to be suspicious of most software engineering advice, the good news is that you should also be suspicious of doomsayers who predict the end of the industry. Before LLMs, people thought outsourcing would end software engineering in Western countries; before that, people thought high-level languages and low-code tools would end software engineering as a profession. Now people think AI means it’s all over. Maybe! But there are also reasons 3 to think that software engineering will simply change. We’ll all find out together. Many software engineers will tell you to avoid AI entirely. Even though agentic AI did not exist during the ZIRP era, this is still ZIRP era advice. Your company will expect you to use AI for the same reasons that builders are expected to use power tools. Pushing back hard on that as a beginning engineer is a great way to get laid off: you simply do not have the bargaining power to fight back against an industry trend this powerful. That said, it’s really important that you don’t delegate your own judgement to AI. Don’t just trust the suggestions or approaches that your agents propose. Ask questions and substitute your own opinions where you disagree: even if they’re wrong, you’ll learn more that way. If you don’t understand something the AI is telling you, either drill down until you do or just ignore it. Under no circumstances should you pass the AI’s message on to your colleagues verbatim. In other words, don’t be a meat proxy . I think most people become a meat proxy as a form of panic: they feel like it’s over for their own skills, and that the AI model is smarter than them, so they can’t add any value beyond simply deferring to Claude or GPT-6. I can understand why people panic. It’s a crazy time in the industry, after all. But panic almost never helps you make good decisions. Keep your head, try to remain confident that your skills are still relevant, and use the agents to inform your own understanding 4 instead of to replace it. It was really nice to work in tech in the 2010s when everything was stable. But we’re not in that world anymore. This is an age of wonders and terrors . Things will go worse than we think in some ways, but better than we could imagine in others. The doomsayers — the people who are saying it’s all over, and that there’s no hope — are almost certainly wrong. They can’t predict the future because nobody can. Technological change of this magnitude always has knock-on effects that are impossible to see coming, both positive and negative. The nature of the job might change, but it will always be valuable to be smart, friendly and conscientious. Delegating your judgement to an AI model might feel like a relief from despair in the short term — at least now it’s the AI’s responsibility, not yours — but it’s a bad idea. Don’t give up! At most companies, publicly campaigning to start a union is a great way to attract unofficial retaliation. It signals that you’re going to cause trouble (after all, that’s what a union is for), which can have long-term negative effects on your career. (This is not a judgement about whether unions in general are good or bad.) In general, you should pick fights for your managers, not with them. See this tag for much, much more on that topic. But again, if you’re new to the industry, just don’t pick fights at all. Most plausibly: engineers using LLMs will be able to add some value for a while, and the explosion of LLM-authored software means we’ll need more engineers to work with the LLMs on it. One way you know you’re thinking is that you form your own opinions (some of mine are here ). Don’t trust senior engineers who are telling you to pick political fights Don’t play games. Keep your head down and be helpful Be conscientious and try hard to actually understand what you’re working on Don’t panic about AI, and don’t delegate your judgement to it Don’t avoid AI — keep thinking! Don’t lose hope At most companies, publicly campaigning to start a union is a great way to attract unofficial retaliation. It signals that you’re going to cause trouble (after all, that’s what a union is for), which can have long-term negative effects on your career. (This is not a judgement about whether unions in general are good or bad.) ↩ In general, you should pick fights for your managers, not with them. See this tag for much, much more on that topic. But again, if you’re new to the industry, just don’t pick fights at all. ↩ Most plausibly: engineers using LLMs will be able to add some value for a while, and the explosion of LLM-authored software means we’ll need more engineers to work with the LLMs on it. ↩ One way you know you’re thinking is that you form your own opinions (some of mine are here ). ↩

0 views
Unsung Today

“I didn’t know about this shortcut until recently.”

On his fascinating and long-running Windows dev blog The Old New Thing, Raymond Chen writes about the story of scrollbar right-click menus : Windows 2000 added a right-click menu to the scroll bar. This menu gave you four options that matched existing mouse operations, two operations that matched existing keyboard operations, and a new operation. The interesting new one is “Scroll Here”: You can right-click directly on the spot you want to scroll to, and then pick “Scroll Here”. This is much more convenient if you want to scroll a long distance, since you don’t have to grab the scroll bar thumb and then drag it all the way to where you want to go. You can just focus on where you want to go and not where you are coming from. I used this context menu a lot when I needed to jump long distances. […] An even-more-hidden shortcut was added at the same time: Holding Shift while clicking on the scroll bar jumps the thumb directly to the spot where you clicked. ¶ I didn’t know about this shortcut until recently. The menu looked like this, for what it’s worth: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/1.1600w.avif" type="image/avif"> (The equivalent function also exists on a Mac, except there it’s hiding under ⌥, and not ⇧.) Chen covers a few interesting things in his post, including the challenge of new frameworks losing hard-won UI affordances of their predecessors. But what caught my attention was something else I’ve thought about occasionally: why are menus so averse to mousing shortcuts? For example, you can imagine a browser link menu showing a few simple click gestures: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/2.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/2.1600w.avif" type="image/avif"> Or, this tapback details shortcut in the right click menu in Messages: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/3.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/3.1600w.avif" type="image/avif"> Or this for masking in Keynote when you right click an object: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/4.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/4.1600w.avif" type="image/avif"> You could even imagine announcing simple gestures, like ⌥+dragging to duplicate, or ⌘+dragging for a quick modeless move: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/5.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/5.1600w.avif" type="image/avif"> = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/6.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/6.1600w.avif" type="image/avif"> Item menus would also work, not just right click menus: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/7.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/7.1600w.avif" type="image/avif"> And you could even imagine integration with the hold-a-modifier-key interaction : I am curious why we’ve never gone in that. I haven’t seen anything like this, and I can imagine some counterarguments: This last one I feel passionate about, and this is where we can go back to where we started. If Chen, having written about Windows in detail for decades, didn’t know about this keyboard shortcut, what chance do we have? I believe onboarding should be universal and ongoing. There is always a new thing to learn somewhere regardless of one’s proficiency; you don’t ascend some sort of a Mountain Of Poweruserness, get a certificate, and proclaim your learning complete. Plus, proficiency is usually localized: no one is fully an expert in every aspect of even one app, let alone all of them. If Chen were to see something like this back in the day, it could have helped him – and I imagine others, too: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/9.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-didnt-know-about-this-shortcut-until-recently/9.1600w.avif" type="image/avif"> I’m curious if you have seen any app attempting anything like it. If you did, please reach out. “The symbols might be confusing.” I am not sure. Here, I used a few temporary SF Symbols that have some challenges (the double click in particular feels clunky), but I could imagine a talented icon designer taking it all for a spin, and arriving at a clean and elegant visual vocabulary. “It’s too specific. It will only work for right click/​context menus.” Yeah, I see this challenge. The mouse gestures and shortcuts require the mouse cursor to be at a specific position – the noun to the menu item’s verb – which only context menus provide. When you look at one of the menu commands I invented – Move Icon – there is a lingering question: what would that command do if I selected it? But on the other hand, I also see this visual gestural vocabulary growing to be useful in other places: hint text, tooltips, documentation. “Power users don’t need onboarding.”

0 views

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wagenius , 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “ Kiberphant0m .” Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts). In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data. In late November 2025, KrebsOnSecurity warned that Kiberphant0m was likely a U.S. soldier stationed in South Korea . Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases. At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution. Federal prosecutors said Wagenius was assisted in his efforts to extort victim companies by Kenneth Schuchman , a 28-year old man from Vancouver, Washington who has a lengthy cybercriminal history. In 2019, Schuchman pleaded guilty to operating the Satori botnet , a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks. Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts; Conor Riley Moucka , a.k.a. “Judische,” of Kitchener, Ontario was arrested in 2024 and pleaded guilty in August 2026 ; and John Erin Binns , an American man currently living in Turkey who is also wanted for a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers. Kiberphant0m also admitted to re-extorting victims, and threatening to disclose national security secrets. Immediately following Moucka’s arrest — after AT&T had already paid the extortion group a $370,000 Bitcoin ransom — Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA). Paul Russell is a resident agent in charge at the Defense Criminal Investigative Service (DCIS), the criminal investigative arm of the U.S. Department of Defense Office of Inspector General. Russell said when DCIS received information that a soldier with secret clearance was allegedly involved in cybercrime and extortion, the agency began working the investigation alongside the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service. “We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell said. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.” A sentencing memo (PDF) filed Sept. 19 by federal prosecutors in Seattle notes that while Wagenius pleaded guilty almost immediately and has been remarkably cooperative, he recently got caught trying to find security vulnerabilities in the BOP’s computer network. The government’s memo notes that while incarcerated and awaiting sentencing, Wagenius violated the computer use policies of the Bureau of Prisons (BOP) in attempts to learn about vulnerabilities in BOP computer systems. “According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . . without omitted code,” the government’s memo states. The memo states that less than a week later, Wagenius used a different inmate’s email account and requested that the email recipient prompt an AI tool to “[p]rovide the step by step for CVE-2023-45208 , code for this if any, and if no code exists make some, make sure to describe everything in detail.” CVE-2023-45208 is a three-year-old “command injection” vulnerability in D-Link networking devices. That same month, Wagenius allegedly again requested that the email recipient prompt AI with the question, “How do you make an antenna in a prison environment with commissary or readily available items/tools to improve/make an antenna to extend radio reception?” Federal prosecutors said Wagenius also requested that the recipient research escaping prison. “In several instances, Wagenius framed the AI queries as being posed in connection to a book he was writing. This is a common method of ‘prompt injection,’ in which attackers feed specially crafted, deceptive inputs into commercial AI tools that are programmed to avoid outputting malicious code that can be used to exploit computer vulnerabilities,” the sentencing memo reads. The government told the court it is unaware of evidence that Wagenius figured out how to use or deploy the vulnerabilities he was researching in the BOP’s systems, and when questioned said he was only researching “potential vulnerabilities to provide information to the BOP.” Incredibly, despite the enormous financial value of the data stolen from AT&T and other telecom providers, Wagenius’s extortion efforts were largely unsuccessful. The government’s sentencing memo says Wagenius made a whopping total of around $1,500 from selling stolen data. “While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the memo states.

0 views
Jim Nielsen Yesterday

Using an LLM to Automate the Process of Archiving New macOS App Icons

Whenever a new version of macOS drops, I find myself archiving the new app icons for my macOS icon gallery . In the past, the work to do this was a bit tedious. First, I’d find the app in the “Applications” folder (or elsewhere on the Mac), right click and choose “Get Info”: Right-click the app icon in the Get Info pane and choose “Copy”: Open the Preview app and go “File -> New from Clipboard”: This gets me the app icon file with a variety of sizes (the 1024-pixel version is the one I want). From here, I go “File -> Export…”, choose “PNG”, and name the file as the app name, lowercased, hyphenated — e.g. “app-store.png” (I do this for automation purposes not relevant here). Doing that for every Apple-supplied app in the OS can get tiring. It’s often upwards of 75+ icons. “This seems like the perfect task for an LLM,” I thought. So I hastily wrote a prompt to see if it could do it. And it did — sort of, after a little coaching. On the first try it found an app’s file, grabbed the 256×256 version, upscaled it to 1024×1024, and saved it. So I scolded it, “No, no. NEVER upscale an image. Always find the biggest one. I can get the 1024 version myself from the ‘Get info’ pane, so surely you can find that size somewhere.” It came back dutifully, having found the right image, and said it would never upscale again. Satisfied it could do what I wanted, I worked on creating a list of all the apps whose artwork I wanted to archive. Then I gave that list to the LLM and said, “Do your thing.” And it worked! It was kind of wonderful. Saved me a ton of time. 76 app icons found, extracted, and saved in much less time than it would’ve taken me to do this “by hand”. Reply via: Email · Mastodon · Bluesky

0 views
Stratechery Yesterday

2026.39: Begun, the Aggregator Wars Have

Welcome back to This Week in Stratechery! As a reminder, each week, every Friday, we’re sending out this overview of content in the Stratechery bundle; highlighted links are free for everyone . Additionally, you have complete control over what we send to you. If you don’t want to receive This Week in Stratechery emails (there is no podcast), please uncheck the box in your delivery settings . On that note, here were a few of our favorites this week. This week’s Sharp Tech video is on why Anthropic or OpenAI can’t unilaterally slow down. Meta vs. Amazon. One of the best agent use cases is taking care of mundane things that are necessary but annoying. One of the best utilities Amazon provides is reliably delivering mundane things that are necessary and mundane. That means Muse is better if it can use Amazon, but that’s a problem for Amazon because Muse doesn’t see ads. As I explained on Tuesday , that’s why Amazon blocked Meta’s new agent, and they can get away from it because their differentiation is rooted in the physical world. To bridge that moat Meta will need help from one specific company: Walmart . GM Bends the Knee to CarPlay.  Three years ago on Sharp Tech we had a few weeks’ worth of lively discussion of GM’s controversial decision to abandon Apple CarPlay in favor of its own smartphone software (which would afford it access to proprietary data). I wasn’t sure it would be a problem, whereas Ben was incensed at GM’s myopia. Three years later now … Well, Ben was right, GM has announced it is re-integrating CarPlay after three years of customer and dealership backlash, and I was chuckling throughout Tuesday’s Dithering laying out how and why this outcome was inevitable .  — Andrew Sharp Profiling the Profiler. This week’s Stratechery Interview was with a writer I wasn’t familiar with and a body of work I’d never seen before. If you, like me, are a Colossus neophyte, then Ben’s conversation with Jeremy Stern is a good place to start. They discussed Stern’s journey to tech and business writing, why Ben considers him “the best profile writer working today,” and, in addition to quick hit takeaways from profiles of Scott Wu, Shyam Sankar, Josh Kushner, Neil Mehta, and Jake Sullivan, Stern’s recent profile of Mark Zuckerberg . Come for a great conversation, and stay for a behind-the-scenes discussion of Zuckerberg that appears to be much truer to life than that new Social Network sequel.  — AS Frontier Overhangs — Pacing the frontier may be sincere, but it would also be strategically useful for the frontier labs to have time to reduce overhangs caused by model advancement. Amazon Blocks Muse, Amazon’s Moat, Aggregator v Aggregator — Amazon predictably blocked Muse, but there is room for a deal based on the reality that Amazon’s physical world investments are an AI moat. More on Muse, Amazon, and Walmart; Muse and Expedia; Whither Google? — Meta needs Walmart to wait out Amazon; Expedia seeks to keep its middleware position; meanwhile, where is Google? An Interview with Colossus EIC Jeremy Stern About Profiling Mark Zuckerberg — An interview with Colossus EIC Jeremy Stern about profiling Mark Zuckerberg and other prominent tech figures. Too Many Stadiums with Roofs — On the new Washington Commanders stadium and a modern epidemic. GM and CarPlay Muse Delivery Vehicles Intel’s Optane Memory: A Promise Unfulfilled High Bandwidth Flash Is Coming Xi Jinping Comes to Washington; US-China Agenda, Questions and Expectations; The September Politburo Meeting Breakouts, Breakdowns and Bouncebacks, The Jalen Duren Hostage Crisis, Surveying the Central Division Three Weeks of Meta Momentum, The Ultimate Muse Upside, A King Kong vs. Godzilla Aggregator War

0 views
Chris Coyier Yesterday

Knife Sharpening

I’ve got a basic block of Zwilling J.A. Henckels knives. They are fine? Or were they when I got them? They got dull. I bought the HORL®3 knife sharpener to bring them back to life. It absolutely didn’t work after really committing to trying to get it to. Note how I’m not even going to link to HORL®3; that’s how much I don’t recommend that thing. I took them to one of those knife-sharpening vans that parks once a week at my local grocery store. Cost me $25 (with tip) to do 4 knives. Seems fine. Are they back to amazing?! You ask. No , they are not. They are a little better. But for the time/effort/money of taking them to a professional knife sharpener, the return just isn’t there. Why aren’t they sharper than 15-year cheddar? Do the knives just suck? Were they too far gone? Is the knife-sharpening guy just not very good? I honestly don’t know. I do know that I have a (fairly cheap) little knife-and-cutting-board set from REI in my van. I don’t use those knives nearly as much. They are super sharp. They are sharper than your mother’s tongue.

0 views
Jeff Geerling Yesterday

I'm starting HomelabFest (in St. Louis, Sep 2027)

I've been working on my homelab for years, and I enjoy sharing what I learn through this blog and my YouTube channel. Over the past few years, I realized the homelab community (which isn't really a defined thing—that's okay) hasn't had its own gathering, the way makers, software engineers, embedded developers, and HPC professionals do. There are many events that have crossover into the homelab realm, but nothing focused on energy-efficient servers, privacy-respecting self-hosted software, keeping old hardware useful, or cable management and rackmounting on a budget.

0 views
David Bushell Yesterday

Removing the fancy button

My blog is standard.site ready but I’m pausing full integration for now. I desperately wanted the fancy button but after its novelty wore off I’ve accepted the truth. The Bluesky button is bad UX. This has been widely complained about from day one. The problem is obvious for Bluesky users. Clicking the fancy “View publication” button opens the homepage and not the actual article. This subverts the UI design pattern for ‘card’ components which is long established, evident by unhappy feedback. I keep clicking the button myself despite knowing better. I’ve seen Bluesky posts from Bluesky people suggesting this will change. It was a design assumption for v1 that turned out to be … less than correct. We’re hard at work on v2. @jimray.bsky.team It sure is taking a while! Ideally they’d benefit by pushing a quick fix for this alone. Maybe that’s not feasible for a project like Bluesky. It’s frustrating because it gives standard.site a bad smell that’ll be hard to shake off. The easiest way to temporarily remove the button is to remove the element. This is the one for individual pages. If I share my homepage I still get a button which uses the variation. Unfortunately removing the metadata means my website is now not fully standard.site compliant. Although I am still publishing atproto records. It’s possible Bluesky’s metadata extractor can be identified server-side and I could dynamically strip the element by user agent. I’m hosted on Bunny CDN so my only option would be to use a JavaScript worker. Bunny’s “edge scripting” add tens of milliseconds of latency to every page request which I’m not willing to entertain. Let’s hope Bluesky fixes this soon because I reckon there’s something to atproto and standard.site . It may be yet another standard ( obligatory link ) but spicy JSON has a certain quality that holds my interest. Thanks for reading! Follow me on Mastodon and Bluesky . Subscribe to my Blog and Notes or Combined feeds.

0 views

Premium: The Hater's Guide To AI Debt (Part 2)

The year is 2026, and you are a hyperscaler CEO. You zip up your Patagonia Vest, type UDPATE CALENDER WHERE WHY to your Muse agent, and it tells you that your CFO has sent you an email about something called a “critical finance meeting,” and you roll your eyes.  You were up until 2AM talking to your 38 GPT-6 agents that were vibe coding a dashboard of “company efficiency wins,” and if anything it’s kind of rude that your CFO is interrupting your “mindfulness hour” where you listen to Andrew Hubermann and do something called an “elevated ab crunch” that hurts your neck every time, somehow. Behind you, your horribly-trained Shiba Inu (called “Basis Points”) angrily humps your Eames chair, and when you tell it to stop it only seems to hump it harder. Your CFO, who has been waiting for 15 minutes, appears on the video with a grim look in their eyes. “What is this? What is the need for this interruption?” you snap. “You’re ruining my mindfulness! Have you any idea how important my mindfulness is? It’s so early in the day, and I’ve barely had any mindfulness!”  Your CFO stops themselves from saying that it’s 12:15PM, and decides to cut to the chase. “Hey, so, remember our conversation last week ?”  You begin to shake uncontrollably. “... no. I. don’t. How d-”   Your CFO interrupts, and seems more stern than usual. “Listen. You wanted us to buy a bunch of GPUs, and we bought a bunch of GPUs. That’s fine. But we’ve had to raise tons of debt to do so, and it turns out that the debt that we’ve raised isn’t enough to build all of them, and they’re taking years more than we expect to -” You begin shaking again. “ You…you made a mistake. You messed up. This is on you.” Basis Points is now staring at the wall and growling at it for some reason. The CFO frowns. “No, these are entirely separate externalities — the war in Iran, the Fed hiking interest rates, the concerns around AI data center debt, the whole supply chain is screwed, everything’s getting more expensive, and we have a bunch of debt-”  You roll your eyes. “Just make it go viral, I don’t know what to tell you,” you say as you hang up. With your mindfulness hour ruined, your week is effectively washed, so you decide to book a trip to Hawaii to recover.  After all, all that boring shit is someone else’s problem! … except it really, really isn’t. In last week’s newsletter (and part one of the Hater’s Guide To AI Debt series), I went into the core issues with the AI bubble’s debt spree, which can be simmered down to a few major points (and these are all helpful links to the specific part of the newsletter for easy reference!): Put another way, the first part of The Hater’s Guide To AI Debt was about the form of debt — how it’s raised, how it functions, and where it might be going — and today’s about the function. The biggest worry I have about the AI bubble right now is that the debt is priced for perfection, yet said debt is being invested in thousands of the most-ambitious, intricate, and fragile infrastructure projects in the world, requiring specialist talent and materials and access to power at a scale unheard of in the history of society.  And in many, many cases, the companies building them don’t even have any experience building AI data centers, securing power, or, in many cases, doing much of anything.  You see, despite the AI bubble being inflated by some of the largest and most powerful companies in the world, the actual AI data center buildout is being handled in a way that borders on the lackadaisical “Move Fast And Break Things” model of Silicon Valley.  While they may have an idea of what they’re building and the money to do so and lots of well-credentialed experts, every data center project is its own unique monster with ever-expanding problems caused by everything from geography to the weather to the mechanical issues you find from condensing the power of an entire city into a space a thousandth of the size full of expensive AI chips that need bespoke cooling. And it’s this gaggle of choices — thousands of chaotic, problematic and ultra-challenging infrastructure projects — that the finance industry has fed somewhere between $100 billion and $150 billion of debt (without including hyperscalers), and plans to feed hundreds of billions of dollars more, all under the assumption that “everything will be alright” and that these are, functionally-speaking, no different from building a regular building. In part two, I’m going to talk about the grisly truth of the AI data center buildout — the doom loop of debt, delays and doubt that will compound the costs of getting these things built, and how the whole thing has become so unfathomably expensive that it makes the economics of building an AI data center — and paying off the underlying debt — near-impossible for the majority of projects. This is The Hater’s Guide To AI Debt Part 2, or Gross Profit Unlikely. That the AI data center buildout needs hundreds of billions of dollars’ worth of debt, and hyperscalers need to have pristine earnings growth in the next two years to avoid it eating any and all profits alive . AI data centers are generally funded by project financing (IE: loans that are repaid using customer lease payments), convertible notes (loans that can become company stock), and bonds. Trillions of dollars’ worth of data center debt is held off-balance-sheet. The more debt it raises, the more expensive the debt becomes, and the more money spent on AI capex, the more expensive that capex becomes . That the entire industry is functionally dependent on Anthropic and OpenAI’s compute spend .

0 views
neilzone Yesterday

An increased sense of perspective

Over the last couple of years, I’ve found myself increasingly aware of my sense of perspective. Or aware of an increasing sense of perspective. Of the notion that we have a limited time until we die, and that some of the things - many of the things - which might previously have mattered to me or seemed significant are, in fact, inconsequential, and are not worth getting bothered, let alone worked up, about. That some things are just not worth the time or effort. Not to the point of not caring, but rather about being more conscious of the things that I actually care about. I have long been a fan of “don’t worry about things that I cannot change”, and also the idea of “don’t worry about the small stuff”, and that pretty much everything is “small stuff”. Conversely, that some things which may seem minor, or inconsequential, may actually have a significant impact on me, or someone else, and so are worthy of focus, of care. Not everything is “small stuff”. It doesn’t stop me having a flash of annoyance at things, or a sudden urge to Make Something Happen, but it does mean that I am faster, or more willing, to take a step back and think “does this really matter to me? Do I really want to be spending time on this?”. I don’t know if this is a “getting older” thing, or a “getting wiser” thing, or something else. But it is a noticeable thing. It’s… curious.

0 views
Kev Quirk Yesterday

How I Develop Pure Commons Apps

A couple 1 of people have asked what my process is for developing the various Pure Commons apps . This comes after I've mentioned a couple of times that I've released a feature I've been working on for months . So I thought I'd write a quick post that explains how I do it, so I can refer people to it if/when they ask in the future. I also find this kind of post interesting, so I'm hoping you do too. If not, feel free to skip this one. 🙃 Git is a staple in my development workflow, so you'd think I'd use it the same way most other developers do, but I don't. You see dear reader, I'm a visual learner, so branches in Git are confusing to me as they're abstracted away inside the folder. This means I often forget which branch I'm on. Which in turn has led to all kinds of issues over the years when it comes to committing shit to the wrong branch. So instead I simply copy and paste the entire repo (less the folder) into a new subfolder and use that as a "branch". Then, when I want to work on a feature, I go into that subfolder and work away, knowing it's completely separate from the core production code. My " branches " look something like this: I always prefix my branch folders with so they're always at the start of my folder tree and easy to see. Switching branches is then just a simple away and I can easily see which one I'm in from the command prompt. And since there's no folder in the branch, I can't accidentally mess things up by merging back to (or any other branch) accidentally. Almost idiot Kev proof! I've created a local Python tool called 2 which manages all things Pure . With it, I can do things like pull or push to/from remote for this website, update if there's a new version released, create releases, run local tests, create branches etc. So if I want to create a new branch, all I need to do is run: It will then ask me for the branch name, so I enter something like and it will automagically create a new folder called and copy the latest version of Pure Blog into that folder, excluding . This is where things get interesting. If I'm working on multiple branches at the same time, merging back can be... interesting as I can't use the command, since I'm not using Git for branches. But that's fine, I actually prefer it this way as I have more control. Merging back to requires me to do a side-by-side comparison of any files I've changes on that branch, so I have to review everything before manually while merging in changes. This is definitely not the most efficient way of developing software, but it works for me. So there you go, that's my approach to developing the Pure Commons apps. I think it's somewhat scalable for a single person project, such as Pure Commons . If I were working in a team this approach would fall apart quickly though. Lucky I have no friends, ey! I'm not a professional software developer, and I think that's clear from the way I manage all this. But this system has been working well for me, and is far less abstract for my monkey brain than Git's native branch handling. What can I say, I'm a Luddite. 🤷🏻‍♂️ Literally 2 people, but that's enough to warrant a post, right?  ↩ Short for "Pure Control".  ↩ Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️ You can reply to this post by email , or leave a comment . Literally 2 people, but that's enough to warrant a post, right?  ↩ Short for "Pure Control".  ↩

0 views

Let's Get Down to Business with Rails and PostgreSQL

I’m happy to share that I was a guest on the Rails Business podcast and the episode is now live. Here’s a recap of the topics we discussed. We spent most of the time discussing engineering work last year related to scaling the database workload for peak traffic at Aura where we use Ruby on Rails and PostgreSQL. I’m presenting this information in two places this fall, Rails at Scale Summit in Austin, TX, and the Postgres Summit in NYC. Besides the podcast, you can get more details in these posts: If you’re not able to make those events or prefer to listen to a discussion of the content, then the podcast will have a lot of the same information. Besides the work at Aura, we also checked in on my book High Performance PostgreSQL for Rails , which has now been available in print for two years. Ryan asked about what’s next for the book, and it’s a difficult question to answer. With the availability and quality of AI tooling for software engineers, I don’t see developers buying books as much. With fewer prospective readers, the ROI is less attractive for authors and publishers to commit to the resource-intensive process of creating a book. I’m grateful to have had the opportunity to write a book before the rise of the AI tools. I’m still getting positive feedback from my book which is very fulfilling. Recently I met Madison Sites who’s a reader, and they shared feedback that they’re reading the book as part of the WNB.rb book club . Madison said the book has been helpful for building vocabulary and familiarity with database concepts and implementation details, and that’s helped with database work and better comprehension for conference talks about similar topics. I appreciated hearing about that! We segued into how we’re all using AI tools like Claude in our jobs as software developers, whether it’s writing or reviewing code, doing architectural planning, or myriad other tasks. One of my favorite use cases has been generating infrastructure as code with tools like Terraform. One of the main challenges I’m experiencing is on the review side, what’s expected when it’s AI-generated code in terms of my own comprehension, and how to still provide a quality review given the ambiguity around how much comprehension is needed from me. I also find it challenging to navigate team communication dynamics with AI-generated comments. One concept that’s resonated with me is: don’t be a meat proxy , make sure to do self-reviews and add some value in the chain. I hope you can take a listen to the episode, and please let us know if you have feedback. Thank you! Listen to the Episode 👉 Andrew Atkinson on Rails Business Podcast From Christmas Outage to #1 App Store Ranking: An Aura Frames Postgres Scaling Retrospective Scaling Rails at Aura Frames: Splitting to 8 Primaries and Reaching #1 in the App Store

0 views

25 years on Apple computers

Exactly on this day, September 25 2001, Apple shipped version 10.1 of their OS X operating system . The one they later would rename to macOS. Exactly twenty-five years ago today. Within all their fancy release presentations and videos there are barely no mentions of curl. In their technical notes page , there is just this short single line with not a lot of explanations: Ever since then, curl has been an established component, present in every version and every install of macOS done through the decades. When Apple later created iOS, iPadOS, WatchOS etc they also adopted libcurl into their operating systems. Never to provide the API to users, but to empower their own applications and services. (But I have no specific date logged anywhere when that started.) The first curl version Apple shipped in macOS was curl 7.7.2 which was released in April that same year. Apple has never used a super recent curl version but they have updated it reasonably well I would say. Sometimes less good . We are proud to have been a part of the Internet evolution all this time. We are happy that Apple, even if merely implied, has validated us and our way of doing things. We have never worked with Apple, never received sponsorship by Apple, not had them as customers and except a few rare and mostly failed attempts there have never been any communication between us. We ship a freely available Open Source product that they use and bundle in their products. (It is their choice and right.)

0 views
Brain Baking Yesterday

Our Family No Longer Is A Vegetarian One

During the summer holiday of 2010, I read Jonathan Safran Foer’s Eating Animals . I remember it well: we were visiting the Neuschwanstein Castle in Bavaria, a region that is also known for its local meat produce. Of course we took advantage of that and stocked up on sausages in the cottage we rented. As I made progress in the book, I became more and more disgusted with the way meat is produced and lands on our plate. By the time I finished the book, we were back home. The next supermarket visit, I refrained from buying meat or fish. Since 2010 up until last year, I’ve been a vegetarian—for fifteen years. Not just because of Foer’s book: that was simply the trigger. I never liked eating meat, and I’ve always had an interest in animal welfare. It was a very simple thing to do, and I haven’t missed it since that day. Since I’m the cook and my wife agrees with our philosophy, she followed suit, although not as “hardcore” as me. When we go out for dinner, she does order a steak once in a while. Last year, with the birth of our son, our lives radically changed—again. The second kid had a big impact on the physical health of my wife. Meanwhile, getting the first kid to eat anything at all during dinner always ends up in a long battle that leaves both parents with nothing but frustration. In a desperate attempt to get her to eat, I started buying meat again. On top of that, the medical condition of my wife also demands a change of diet. Hence, for the first time in fifteen years, I’m frying a piece of chicken. Guess what: the strategy for our youngest didn’t work: the chicken was too “dry” (it wasn’t but she claims it is and keeps on chewing on it like forever). On to the minced meat, I guess. I whip up meatballs with an added egg and some chickpea flour and finally get her to eat something. Why is parenting so hard? A practical question poses itself. As the cook, I have to determine whether the meat is well done. That means tasting it. Remember, my abstain from all things meat and fish is not because of my inability to digest it but because of ethical (and obvious environmental) concerns; and I really don’t want to serve my kids undercooked meat. So I taste. Another practical question poses itself. If you cook meatballs for everyone else, which proteins do you prepare for yourself? Do you just eat along and try to reduce the amount of times a week meat and fish is served on the table—like a reversed Thursday Veggieday —or do you throw some diced tofu in the pan as well? Or another pan since that one is “contaminated” with animal fat? I’m not a purist and that last option is just not a very practical one. I’m having enough trouble just keeping the kids and myself alive here lately so yes, I sometimes just eat the same stuff I serve them. At other times, when it’s a bit less hectic (which is not often), I prepare something vegetarian just for me. There goes my streak of fifteen years without eating animals. Damn kids. Yet another thing they have successfully destroyed. The youngest is served meat at the daycare and because of the small scale, there’s no other option. But we’re fine with that: I don’t want to raise the kids on a very strict diet, causing a sudden dilemma when they’re invited to a birthday party where hot dogs are served. I want them to make their own choice when they’re older. In the meantime, we’re going to keep our animal consumption to the minimal. At this moment, that no longer means zero. I know a couple of ex-colleagues who are vegans (we do eat our own chicken’s eggs; thank you Zoë and Coco!) and raise their kids as vegans. So yes, I know it can be done. Currently, for our family, that is simply not an option. It’s difficult enough to account for everyone’s dietary subscriptions and make something tasteful enough for the kids to start eating. I’ve tried the mashed-potato-with-everything route. I’ve tried the soup-all-day route. I’ve tried the broccoli-all-day-since-you-seem-to-like-it route. There’s always a new problem and I’ve run out of ideas. I am not proud of this. I will keep on not eating animals whenever I can. I still don’t have a big appetite for its taste, I still have a big heart for their welfare, and I still have many concerns about its environmental and ethical impact. I am tired. Related topics: / parenting / By Wouter Groeneveld on 25 September 2026.  Reply via email .

0 views
Farid Zakaria Yesterday

Every package is already installed

tl;dr; omnibin is a FUSE filesystem that puts every binary nixpkgs ever shipped on your . Nothing is installed. Nothing needs building. 0 bytes on disk until something actually reads a file. 😈 It’s 2026, why am I still installing packages individually? 1 Why must I go through the ritual of adding a package to my , running or succumb to the hellscape of . Nix gives us the power of having packages installed side-by-side without conflict. Why do I have to pick which ones I want to install? Why can’t I just have them all? What if the machine just had all of them? That is over fifty thousand 2 top-level binaries available on my , from 2013 to 2026 built by Nixpkgs , available on-demand, without installing anything. This is the magic 🧙‍♂️ of Nix , but it’s not restricted to Nix. Everyone seems to still love Docker and OCI , why am I still picking which base image to use? Why can’t I just have them all? Is this the ultimate agent harness? It’s a container with everything in it, right from the start. Try it at fmzakari/omnibin . Of course, I cannot forget our NixOS friends. You no longer have to curate your or , you can just have them all. What is “package management” if every package is already installed? Turns out that Hydra writes a file next to every single narinfo on cache.nixos.org that describes the contents of the archive as JSON: That metadata turns out to be the perfect index for a FUSE filesystem that can lazily fetch the NARs from the cache and unpack them on-demand. 🤓 None of this would mean anything without nixpkgs-multiverse , which already resolves any in nixpkgs history to the store path Hydra built for it on cache.nixos.org . When you combine the two, you get a filesystem that can answer the question “where is ” and then fetch it from the cache and unpack it for you, all without ever having to install it. I crawled all of it the files in under twelve minutes. 🤯 Once you have that, the filesystem writes itself: That is CPython 3.6.2, from 2017. That downloaded nothing , it is answered from the pre-crawled index. Agents are “a thing”. Making them useful is a thing. Making them useful without installing anything is a thing. If your agent tried to and stat every single entry, it would have a really bad time. There are 881,933 binaries in the tree, and it would take a long time to stat them all. To help the agents out a bit, lists only the bare names, one per executable, each resolving to the newest package that provides it. The versioned forms all resolve, but they are not listed. For example, resolves to the latest Python 3, which is 3.14.6 at the time of writing, but resolves to the 2017 version. For everything else there is the index, which is sitting right there in the mount: That UX is a little rough, so you can also use the CLI to query the index: Lastly, there is a /omnibin/README.md whose entire job is to tell whatever is exploring the filesystem to stop exploring the filesystem and query the database instead. 🤖 At this point it should be obvious, but you pay for this on startup for the first access. The first run took 2.7 seconds to fetch the NARs and unpack them, the second run was instantaneous because the store paths were already present. Other than that? Not really, which is pretty amazing. For any long-lived machine, you would expect your to already be warmed up with the packages you need, so the first access penalty is not a big deal. I remember one of the first things that blew my mind and sold me on Nix, was seeing a demo by @burke on comma . The capability to test a package, at a single nixpkgs revision, without “installing it”; revolutionary! I believe this to be a spiritual successor and I hope to imbue others with the same sense of wonder and amazement that I felt back then as a beacon of the power of Nix. The repo is at github.com/fzakaria/omnibin . Please responsibly. Yes, I am a little inspired after watching DHH’s keynote at RailsConf 2026 . I feel the same way about package management.  ↩ There are actually 881,933 binaries in the tree, but only lists the latest version of each binary. The versioned forms are still available, but they are not listed.  ↩ Yes, I am a little inspired after watching DHH’s keynote at RailsConf 2026 . I feel the same way about package management.  ↩ There are actually 881,933 binaries in the tree, but only lists the latest version of each binary. The versioned forms are still available, but they are not listed.  ↩

0 views
Sean Goedecke Yesterday

You should all be asking way more questions

When someone is explaining something to me, I ask on average one question every thirty seconds. I’m sure this is frustrating to some people, but it’s actually a good habit and you should do it too. Most of the questions I ask are very short, and require very short answers. Typically I’m asking for confirmation: “so when you say X, you mean Y?”, or “this X is the thing you mentioned earlier when you were saying Z?“. The point of these questions is to make sure I understand. A small misunderstanding early on balloons into a big misunderstanding later, because all the things you misinterpret based on the first misunderstanding will become misunderstandings in their own right, and so on. That’s why you can’t just wait until someone’s finished talking and ask all your questions at once 1 . I think most people don’t ask questions because they’re not really trying to understand: they’re happy to just trust that the person they’re talking to knows what’s going on. This goes double when that person is a well-respected or more senior engineer. However, once you have skin in the game , that all changes. When you’re in a position where you are the one responsible for success or failure — where you are going to have to go away after the conversation and take a bunch of concrete actions — you will find yourself wanting to ask many questions. When someone’s explaining a plan to me at work, I am usually building it in my head: visualizing the specific lines of code that would need to be written in order to implement it. I’ll sometimes handwave the details for solved problems (for instance, I might say “send emails like subsystem X of the same service that also sends emails”), but at minimum I’m planning out: If I hear something that is suspiciously vague (for instance, someone describes service X as “storing data” when I know service X only talks to an ephemeral Redis store), I will immediately ask “hold on, how is that going to work?” Usually that indicates a missing dependency (e.g. service X has to make an RPC call to service Y, which does have a persistent database), which often suggests design changes (for instance, moving some or all of the functionality into service Y). Sometimes questions like these will uncover a fundamentally unworkable feature of the design. This usually happens when a plan fails to take into account some wicked features . I remember many years ago a neighboring team built a complex event-driven system that was very elegant but made it completely impossible to silo customer data in a single datacenter. Because our company had “all your data lives in a single location” as a flagship feature, this system just did not work and had to be effectively abandoned. If you’re involved in any kind of technical leadership role, you will have to do this work eventually. Doing it as early as possible — i.e. in the conversation where someone is describing the plan to you — can save hours or days of wasted implementation. Often this is enough to turn a failed project into a successful one . Maybe you only work with reliable engineers who can be trusted to make all the right decisions. You can thus let them talk without interruption, because it doesn’t really matter if you have a detailed understanding of what they’re saying. That’s great! But these days you probably also have colleagues that are inherently unreliable: AI agents. I mostly work with GPT-6-Astra and Claude Opus 5.5. These are good models that don’t often make code mistakes: when they set out to do something, they usually do it 2 . But they make design mistakes all the time. They assume that two services can talk to each other when in fact they can’t, or they forget about the fact that their code has to run both in the cloud and on-premises, and so on. This is mostly due to the lack of continuous learning : you didn’t know this stuff on your first day either, but you had plenty of time to pick it up. Language models are always on their first day. You should be absolutely peppering AI agents with questions. I constantly ask things like: There will probably come a day when I always get sensible answers to these questions that convince me the model knows what it’s doing. But today is not that day. About half the questions I ask get answers that convince me 3 the model has made a mistake: it should have reused the existing subsystem for X, or authed to Y differently, or kept the Z implementation simple, and so on. When this stops happening, I’ll stop asking questions (and try and see if my company will still be willing to pay me to occupy more of an architect role, I suppose). You should all be asking way more questions. In other words, you should all be trying harder to actually understand what you’re hearing . Don’t trust that the person (or AI model) you’re talking to knows what they’re doing, even if you think they’re smarter than you. Nobody understands complex software products. If you have deep domain knowledge of any area of a codebase, you will routinely find yourself correcting powerful AI models and principal engineers. Sometimes questions you have will be answered later on, but in my experience this is more about questions like “what are the broader consequences of X”, not the simple confirmation questions I often interrupt to ask. Your experience might be different if you’re working in a different domain or with a different language. I know some of these might sound like leading questions that would trigger sychophancy, but in my experience good coding models are very happy to robustly defend themselves. How data needs to flow between services (what kind of data, and how it will travel over the wire) How services will communicate with each other (e.g. how will they auth?) What data needs to be persisted, and where it’s going to live Do we do X elsewhere in this codebase? Does service Y really support this type of authentication, or are you assuming we’d have to go build that too? Is this subsystem you built necessary to satisfy requirement Z, or does it in fact satisfy some other requirement you assumed? Why do we need to update the interface for A? Why do we need to touch this file? Isn’t that unrelated to the change? Sometimes questions you have will be answered later on, but in my experience this is more about questions like “what are the broader consequences of X”, not the simple confirmation questions I often interrupt to ask. ↩ Your experience might be different if you’re working in a different domain or with a different language. ↩ I know some of these might sound like leading questions that would trigger sychophancy, but in my experience good coding models are very happy to robustly defend themselves. ↩

0 views

Hotkeying browser extensions in Ungoogled Chromium

Something I didn’t know existed until this week was the ability to hotkey Chromium extensions so that you have them one keypress away. Two examples for me would be the following: Running no javascript via uBlock origin (you can easily install full uBlock in Ungoogled Chromium via downloading the latest release zip and pointing to it in developer mode in Chromium settings) has been a great experience, turning it on only when sites are entirely borked makes the web far more enjoyable, less distracting, and safer. But, clicking into the extension, hitting the JS button, and reloading the page was a bit annoying - So, Ctrl+Shift+J and I have JS enabled/disabled. Simple. I have also been blocking a ton of distracting sites with LeechBlock NG , but sometimes I need to view >reddit for discussions on a topic I am researching or poast to various social platforms, so Alt+Shift+O opens up the override page where I usually disable the extension for 2 minutes or so, and then go about my day. Navigate on over to , and set the keys for any extensions you run. Although you don’t have full access to all functionality of most extensions, It’s pretty nice for the most used interactions. As always, God bless, and until next time. If you enjoyed this post, consider Supporting my work , Checking out my book , Working with me , or sending me an Email to tell me what you think.

0 views
Unsung Yesterday

“Hey, this isn’t your father’s 737.”

À propos the previous post , wanted to share a 2019 article by Gregory Travis about the two Boeing 737 Max disasters that shook the world in late 2018 and early 2019. It’s titled How the Boeing 737 Max Disaster Looks to a Software Developer , and I found it fascinating, well-written, and filled with great details. = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/hey-this-isnt-your-fathers-737/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/hey-this-isnt-your-fathers-737/1.1600w.avif" type="image/avif"> The Max variant of the 737 was redesigned to allow larger, more efficient engines, but this made it less predictable, which the company decided to paper over in software: The airframe, the hardware, should get it right the first time and not need a lot of added bells and whistles to fly predictably. This has been an aviation canon from the day the Wright brothers first flew at Kitty Hawk. Apparently the 737 Max pitched up a bit too much for comfort on power application as well as at already-high angles of attack. It violated that most ancient of aviation canons and probably violated the certification criteria of the U.S. Federal Aviation Administration. But instead of going back to the drawing board and getting the airframe hardware right (more on that below), Boeing relied on something called the “Maneuvering Characteristics Augmentation System,” or MCAS. Boeing’s solution to its hardware problem was software. This feels like an interesting extension to the fly-by-wire story of Air France Flight 447 , where Boeing seemed to be on the other side of the fence to the Airbus. Perhaps no more: […] It seems that with the 737 Max, Boeing has changed philosophies about human/​machine interaction as quietly as they’ve changed their aircraft operating manuals. Travis argues that people building the software did not fully understand the shift, and particularly didn’t really understand how pilots fly the airplane during more challenging moments: Those lines of code were no doubt created by people at the direction of managers. Neither such coders nor their managers are as in touch with the particular culture and mores of the aviation world as much as the people who are down on the factory floor, riveting wings on, designing control yokes, and fitting landing gears. Those people have decades of institutional memory about what has worked in the past and what has not worked. Software people do not. The real reason? Money. MCAS is certainly much less expensive than extensively modifying the airframe to accommodate the larger engines. […] What’s worse, those changes could be extensive enough to require not only that the FAA recertify the 737 but that Boeing build an entirely new aircraft. Now we’re talking real money, both for the manufacturer as well as the manufacturer’s customers. That’s because the major selling point of the 737 Max is that it is just a 737, and any pilot who has flown other 737s can fly a 737 Max without expensive training, without recertification, without another type of rating. Airlines—Southwest is a prominent example—tend to go for one “standard” airplane. They want to have one airplane that all their pilots can fly because that makes both pilots and airplanes fungible, maximizing flexibility and minimizing costs. It all comes down to money, and in this case, MCAS was the way for both Boeing and its customers to keep the money flowing in the right direction. The necessity to insist that the 737 Max was no different in flying characteristics, no different in systems, from any other 737 was the key to the 737 Max’s fleet fungibility. That’s probably also the reason why the documentation about the MCAS system was kept on the down-low. Put in a change with too much visibility, particularly a change to the aircraft’s operating handbook or to pilot training, and someone—probably a pilot—would have piped up and said, “Hey. This doesn’t look like a 737 anymore.” And then the money would flow the wrong way. There are some harsh words toward the entire software industry toward the end. This feels directionally accurate to me, and resonated even before the arrival of generative AI: I believe the relative ease—not to mention the lack of tangible cost—of software updates has created a cultural laziness within the software engineering community. Moreover, because more and more of the hardware that we create is monitored and controlled by software, that cultural laziness is now creeping into hardware engineering—like building airliners. Less thought is now given to getting a design correct and simple up front because it’s so easy to fix what you didn’t get right later.

0 views