Latest Posts (20 found)
Unsung Today

“I just chose words carefully.”

I don’t think anyone particularly enjoys typesetting in monospace. Regular text is okay – at least as okay as it can be: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/1.1600w.avif" type="image/avif"> Right aligning is also fine, as long as you don’t mind counting spaces, but centering already gets tricky, as you don’t have a half space to make things truly even: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/2.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/2.1600w.avif" type="image/avif"> And full justification is where things get particularly weird. The spaces are just too large, and cannot be distributed evenly, creating a really unpleasant feeling: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/3.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/3.1600w.avif" type="image/avif"> The solution used in typesetting elsewhere is hyphenation, but in monospace hyphenation also feels unpleasant, with the hyphens drawing too much attention to themselves (and subsequently messing up copy and paste): = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/4.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/4.1600w.avif" type="image/avif"> This is why you don’t see full justification in text files very often. But there is one more option. You can rewrite the text to choose only words that precisely add up to the line length to avoid any double spaces. This is exactly what rs1n did in the late 1990s for his guide to Super Metroid : = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/5.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/i-just-chose-words-carefully/5.1600w.avif" type="image/avif"> It’s astonishing, as it goes like this on for 17,000 more words , each right margin perfectly ending on a letter, no twin spaces in sight. The author lightly covers in the FAQ at the bottom: What program did you use to justify the text? None. I just chose words carefully so that everything lined up on the right hand side. Everything was done with an ASCII editor. I’m sharing this mostly as a curiosity; some rewrites for physical books are par the course to avoid widows and orphans, but you don’t see them as much in onscreen writing. At the same time, who among us didn’t nod in recognition at least, having once spent hours massaging a button UI string or a tooltip just to get it to fit under the certain width in a densely packed interface? #text editing #typography #writing

3 views

Forgejo Hack #2: Integration with Read The Docs

In this second Forgejo Hack installment I'll tell you how to connect a git repository that lives in your self-hosted Forgejo instance to Read the Docs , so that commits to the repository automatically trigger documentation builds, exactly like it works with GitHub.

0 views

rose ▪ bud ▪ thorn - august 2026

Published 30 Aug, 2026 I met Suliman ! I'm having a good time playing FFXIV; made it to Heavensward now, excited to play more. My wife gifted me the new Hello Kitty Island Adventure DLC (Tea Garden) and it's been very sweet and calming :) We had a great date day on which we tried out a vegan kebab we had never eaten before, went to a few manga shops, Build-a-Bear, a cinnamonroll shop, and more. My matcha order surprisingly arrived without notice, just in time, when I had used up my last bit of the old an hour or so prior. We went to Gamescom and I found merch of a Sanrio character I like that barely gets any or is never included anywhere; a Mocha plush, and I even pulled Mocha (or rather, Cinnamoroll dressed as Mocha) out of a blindbox too! Plus I paid less than the price tag said for something. The way my wife looked at me when I pulled the small plushie out of the blindbox brings tears to my eyes. It was just so overtly, shockingly full of genuine love and joy for me. I can't even describe how it feels to see someone look at you like that when finally something good happens to you. I think remembering that look will sustain me for the rest of my life. Saw a full rainbow in a pink sky while looking out the window. I got back into journaling for joy, and using up some of the stickers I had accumulated in the months of not doing so. I felt really grateful for a friend reaching out that I hadn't talked to in months and how supportive he was when I told him about my struggles. He independently remembered specific upcoming days I was worried about, and then checked in with me on them to see how I was doing. I am still so surprised that anyone would do that for me, unasked. Generally received kind messages and emails of support, which I am thankful for. Started feeling more like myself again towards the very end of the month. Getting back into my gym routine that I had to pause for health reasons. Regaining my sense of purpose, re-establishing parts of my life that give me a sense of security, a plan to follow, something to work towards. Studying for my degree. I've really fallen off this semester. Finishing up my blog post drafts. There's so much I wanna put out there, but time just keeps running through my hands like fine sand. This has been the worst month of the year for me... yet. What happened this month cannot ever happen to me again. I've had 20+ high heart rate notifications via my smartwatch this month because of anxiety, stress, panic attacks and rumination, mentally spiraling while sitting there doing nothing. I don't usually mention it when I talk about my illnesses because for the past few years, it genuinely did not affect me at all after treatment with EMDR, but I was diagnosed with (C-)PTSD years ago. Something in my life recently triggered it again pretty badly, so this is the fallout. I've spent most of this month trying to exit this hypervigilant state, this feeling of always being in danger or hunted, even when I know I am safe, and trying to implement the coping mechanisms I had learned. It has also made some some other mental health issues reemerge that were never officially diagnosed, and I might need to get on that. Unfortunately, Germany is currently completely gutting psychotherapy... All of that is the reason it's been quiet and I have been very behind on answering emails. I've endured some really weird and off-putting behavior from multiple different people this month; some friends, some acquaintances, but also strangers.

0 views

Front page

I have not had a huge success with my writing in this blog so far. I don’t collect any analytics 1 , so I am not sure exactly how each post fares, but based on the amount of comments I have received in the various platforms I have shared my posts, the traffic must not be very high. This has not discouraged me from writing. My goal is to share projects that I am developing and to express some of my thoughts when I feel like it. I am glad if someone finds the content interesting and I am even happier to engage anyone who sends a comment my way. In any case, I think that the mere act of sitting down and writing your thoughts is beneficial by itself and it is worth doing, even if the audience is not there. It is true, though, that it feels nice when people accept what you are offering. And two days ago, I finally got my first breakthrough. I shared my last post on Hacker News and it reached the front page . I admit it was satisfying to see that a lot of people approved of the message and wanted to share their own opinions. I spent the next day or so participating in the discussion and digesting all the new information that was available. One of the main themes of the discussion was user interface accessibility. It is a part of software development that is of great interest and importance and I hope to more systematically approach it in my programming and my writing in the near future. The whole experience was positive. I do not claim to be a great writer, nor that my post proclaimed some profound truth, but it was gratifying to see that an extended discussion was started because of something I wrote. As a result, I now am a little braver to share my thoughts with the world. I think they can create bad incentives for content creation.  ↩ I think they can create bad incentives for content creation.  ↩

0 views
Sean Goedecke Yesterday

You have to beat the models at something

In 2025, I wrote that software engineers ought to be assessed by “value over replacement” : not how much money they made for their company, but how much they would have made compared to the average engineer in their position. I’ve always found it vaguely silly when engineers put “built a product that made $X” on their resumes, when they just did the JIRA tickets that came across their desk. Today, value over replacement is even more important. A replacement-level engineer in the 2010s was fine : maybe not worth promoting, but still worth paying , because writing code had a high fixed cost. Now writing code costs a hundred bucks a month . What are you doing that GPT-5.6-Sol or Claude Opus 5 wouldn’t do in your position? Why is it worth paying an extra two or three orders of magnitude for? This is a scary thought. But you’re not doing yourself any favors by pretending that LLMs can’t actually write code and it’s all just a scam, or that LLM-written code is inherently so bad as to cause companies using it to collapse next year. We are not going to wake up in 2027 to find that the AI craze is over and everyone is writing code by hand again. You ought to put some serious thought into what you can do better than the models in the medium and long term. Staying ahead of the models is a moving target. At the start of 2026, “make working changes to large codebases” was in this category , but now it’s not. For this reason, I doubt that you can retreat to some “hard engineering” area that requires deeper expertise. That might work in the short term, but not forever. If LLMs can find a better lower bound on the Riemann hypothesis, they will soon 1 be able to write solid high-performance kernel drivers or GPU shaders or whatever. I think it’s more useful to look at the tasks models haven’t gotten better at over time, and the tasks that are hard for them get better at in principle. The two best examples of these are: What do frontier LLMs get wrong? What kind of coding mistakes do they make? It’s been a long time since I’ve seen a straight-up hallucination from a coding agent, or a simple logic error like an off-by-one. The mistakes they make tend to be errors of ignorance : Other times they’re errors of paranoia : What do these errors have in common? They’re the kind of errors a smart engineer might make if they had no context on the system: they’re competent enough to be able to solve the problem, but they haven’t been around long enough to confidently say “yes, we can take this risk to avoid an extra three thousand lines of code”. Until someone cracks continuous learning or truly massive context windows, this is just an inherent feature of how AI agents operate. If you can catch these errors, you’ll be providing real value. The only way to catch these errors is to be familiar with the codebase and familiar with the system in general. For much more on this, see my post You can’t design software you don’t work on . But there’s also a psychological component to it. You have to be willing to confidently disagree with the agent. AI agents can be very convincing. Often they can get “stuck” on some error above where they’re not willing to take a particular risk, so they keep going back and sneaking in code to cover that case (or writing persuasive arguments about why that case is important). To add value, you need to be willing to say “this sucks, I don’t think we need X and Y at all, why can’t we do Z in a much simpler way?” It takes courage . You can’t rely on other AI agents to review each other’s work. If you use the same model, it’ll reliably make the exact same assumptions and mistakes. But even if you use different models, they’ll also tend towards the same kinds of mistakes — ignorance and paranoia — for the same structural reasons. AI-driven review loops are in fact more likely to get these things wrong, because modern AIs have been RL-ed to try to find a few nitpicks no matter what. Having a critic AI and a worker AI bounce off each other is a really good way to end up with ten thousand lines of paranoid slop. Another area where you can add value on top of AI is communication . Newer models are better at coding, but are paradoxically getting worse at writing. GPT-3.5 and GPT-4 had a human-like writing style at times. GPT-4o introduced the modern slop idiolect, and the newer Anthropic models speak “Claudish” : a bizarre semi-baroque semi-truncated way of communicating that nobody enjoys. There have been a few bright spots — GPT-4.5 was okay, and I quite liked o3 2 — but in general LLMs are not good at this. Here’s two reasons why. First, good writing is not a verifiable domain . If you want a model to get good at mathematics or coding, you can generate problems for it and automatically grade them. You can’t grade good writing. If you try to get humans to grade it — for instance, via the early OpenAI RLHF attempts — you get the kind of writing that sounds impressive to the average person when consumed in single-paragraph form. This is the origin of the “stick three hundred writing devices into every sentence” style. I think it’d be possible in principle to hand-pick some people with good taste and have them do it, but there are some obvious problems 3 that prevent this from happening. Second, the labs have been monomaniacally focused on capability instead of communication . When you’re trying to train a model that can break new scientific ground or replace a software engineer, you might trade off some communication ability. In fact, I think we can identify exactly how this has been happening. If you look at internal model reasoning tokens , they tend to have strange word choices and oddly truncated grammar: RESOLUTION: charge the current-leg’s OWN saved-prefix occupancy EAGERLY: when leg i saves e 1..e t: ALSO commit their occupancy AT LEG i If you were to translate this into proper English, you would probably end up with something that reads like Claudish: Charge the current-leg’s saved-prefix occupancy on a clean, eager path: when leg i saves e 1..e t, commit the occupancy at leg i. I suspect that the weirdly alien writing style of some LLMs is because you’re reading a semi-literal translation of that model’s internal chain-of-thought, which has become nearly incomprehensible in pursuit of better problem-solving abilities. It is surprisingly hard to translate Claudish to good English: not only do you need to follow the convoluted, compressed language of the original, but you need the technical ability to understand the problem the model is solving. Because of all this, technical communication may be a surprisingly durable skill. In Peter Watts’ novel Blindsight , the world is full of cognitively augmented humans. The main character is a “synthesist”: someone whose job is to be a translation layer between these geniuses (who speak in abbreviations and gestures) and everyone else. Watts’ idea is that communication ability may be largely independent from — or even negatively correlated with — intelligence. A “country of geniuses” may still need a bunch of ordinary smart people to translate their insights for everyone else. If you’re trying to communicate to humans, there are also huge advantages to having a human write the content. Many of us are becoming AI-blind : developing an instinctive reflex that stops us reading when we encounter AI-generated content. It’s like the reflex that allows people to ignore flashing billboards or sidebar advertisements on websites. If you circulate some planned technical strategy as an AI-written document, most of your colleagues will have to physically force themselves to read it word-by-word. Whatever you do, don’t be a meat proxy : someone who simply copies requests into an AI agent and submits their output as your own work product. Doing that is just begging to be fired, since you’re definitionally not adding any value yourself. Even if you have a cunning system of multiple agents — the so-called “software factory” — you’re still on dangerous ground. When the features of your system work their way into enterprise AI tooling (and they will), you’ll be disposable. You need to find some way to leverage your expertise to do what the models can’t. Simply not using AI at all is better than being a meat proxy, since you’ll probably do some things better than the model would have, but it’s far better to figure out what AI can do and position yourself to fill those gaps. Right now, there are two main gaps: familiarity with the technical details of the system, and the ability to clearly and persuasively write about those details. If you’re thinking “but LLMs can do these things now!”, substitute your preferred example of high-difficulty software engineering. Although this was probably a “thank God it doesn’t speak like 4o” reaction. Defining good taste is hard, there’s no guarantee that AI lab researchers have good taste to start with, nobody will agree on examples, the bulk of users might not even like it, you won’t be able to get enough people to produce the volume of data you need, and so on. Deep familiarity with the codebase Technical communication Not knowing that there’s a module in the codebase they could use instead of reimplementing some logic Making the change in the wrong system because they didn’t know System X was the standard place for this functionality Adopting a coding style that’s inconsistent with the company’s standard practice Implementing triply-redundant checks for a value that technically could be wrong but practically is set once from config and never updated Assuming that ten milliseconds of stale data is unacceptable and designing a complex, unnecessary system to keep it always up to date Building in fallbacks and “graceful” degradation into some code that ought to simply crash on error (e.g. a CLI tool, or a restartable k8s service) If you’re thinking “but LLMs can do these things now!”, substitute your preferred example of high-difficulty software engineering. ↩ Although this was probably a “thank God it doesn’t speak like 4o” reaction. ↩ Defining good taste is hard, there’s no guarantee that AI lab researchers have good taste to start with, nobody will agree on examples, the bulk of users might not even like it, you won’t be able to get enough people to produce the volume of data you need, and so on. ↩

0 views

An audience of one

Every so often I hit some small, specific annoyance, and instead of living with it I spend an afternoon vibe coding my way to a fix. The results are niche beyond belief, held together with optimism, and exactly what I wanted. They work for me. They’re all on one page now at apps.dmcc.io . I’m not selling anything. I’ve put them up for the fun of it, on the off chance one of these itches is one you’ve got too. Every one of them started as my own problem. I build the thing, live with it for a bit, and open it up once I trust it not to embarrass me. Mostly. AudioLock is the one I actually use every day. Android decides where your audio goes and it decides wrong constantly. Media drifts back to the phone speaker mid-ride while my helmet headset sits there connected and silent. AudioLock overrules it. Pick a Bluetooth device, a Cardo or a pair of hearing aids, and it stays the output for media, calls and notifications until that device is genuinely gone. It watches where the audio is actually playing rather than where Android claims, and drags it back when it wanders off. No account, no store listing, a debug-signed APK you sideload. Deeply unglamorous. Fixes the exact thing that was driving me up the wall. whoop-tasker is more of the same, smaller. A screen you have to look at is useless when you’re riding, in a meeting, or asleep, so this gives Tasker a new trick: buzz my WHOOP strap. Front door opens, calendar fires, washing machine finishes, and my wrist knows. The one rule I gave myself was that it must not cost me a single day of the stats WHOOP has been nagging me to keep for months. (Remind me why I paid to be nagged?) So it doesn’t fight the official app for the connection or re-pair anything — it just leans on the same link for the two seconds a buzz takes, then clears off. It physically can’t do anything except buzz. Not a byte of recovery data goes missing. CityWall is completely pointless and I love it. It draws the streets and rivers around you and makes them your phone wallpaper, then quietly redraws it as you travel. Wake up somewhere new and so has your phone. It only ever knows your rough city, never the exact spot, because a wallpaper has no business tracking anyone. Does it need to exist? No. Do I like it? Enormously. May is the oldest itch: where does my money actually go on these vehicles. A self-hosted dashboard for fuel, expenses, maintenance and reminders across every car and bike, with DVLA lookups for MOT and tax so I don’t have to remember either. It’s named after James May, purely so the Top Gear set is complete now that Clarkson and Hammond already exist. Somehow it’s the one strangers have taken to most. Didn’t expect that at all. feedstand is my answer to feeds that decide what you see. An RSS reader that sets articles like a book instead of dumping them in a web view — proper typography, offline caching, full-text search over everything you’ve read, all of it staying on the phone. Paste any URL and it finds the feed, including the ones lurking behind a YouTube channel or a Mastodon profile. No server, so nothing to sign into. It’s the most finished-feeling of the lot, which tells you how long the feed thing has been bothering me. Two of these exist to make a point rather than fix a chore. Bluehood was a weekend thing that got a bit out of hand. It passively watches the Bluetooth devices around you — phones, cars, headphones, delivery vans — and tracks the patterns. With enough data you can tell what time someone walks the dog purely from the metadata their gadgets leak. That was the whole point of building it. It’s firmly alpha, so treat anything it tells you as a rough draft. It’s also, bafflingly, the thing I’ve made that most people have actually looked at. Loyalty Roulette is the same gripe, lighter. I’ve moaned before about privacy poverty — discounts quietly becoming a tax on your data — so this goes after the loyalty-card version. It pools shared card numbers so anyone can take the member price to the till: the savings without handing over your weekly shop, and no single number left tied to a person. mydronefeed is the odd one out because it’s genuinely quite polished, which wasn’t the plan. Point a DJI controller at it and you get a private, sub-second live view of every flight on the web, plus a link you can hand to anyone. Type it into a car screen and there’s your drone, full-screen, no sign-in. There’s a proper free tier for search and rescue teams, too, which is the bit I’m actually pleased with. And GRID/OS , which isn’t solving anything at all. It’s a browser game — Uplink by way of Spooks (MI5: 9 to 5, for my American friends), where you run cyber ops for the Service from a classified terminal at Thames House. Real Cisco, Ubiquiti and MikroTik consoles you work by hand, a trace clock narrowing on you the whole time, and a campaign that ends by asking you to name the mole. No install, nothing to sign in to. I built it because I wanted to, and that’s the entire justification. Not all of them last. I built one called Casey , used it every morning for a while, then quietly stopped. Building this way is cheap and fast, which is the appeal, but it’s also how you end up with a pile of half-used tools and a nagging sense that the time and the energy weren’t free. Worth keeping in mind before the next one. None of these are trying to be a product. They’re specific, slightly janky, and built for an audience of one who happens to be me. If any of them happen to scratch the same itch for you, brilliant, they’re all up there. If not, no harm done — I was going to build them anyway.

0 views
ava's blog Yesterday

link dump - catching up on my online reading

While I am slowly getting back up on my feet after a tough time, I am catching up on emails (will still take a bit!), my RSS feed reader, and several newsletters that have accumulated in my inbox. Here's what I picked out to read and share: This Is Capitalism: Apple's Hidden Data Workers at the Shadows of the AI Boom - 19 page paper detailing what data workers actually do and what problems they deal with, written anonymously by a data worker interviewing their colleagues. Parts of the work descriptions remind me of the work in Severance . Is this really a good reason to triple datacentre capacity in Europe? - online blog post tracing where the idea to triple the EU's data centers comes from that is mentioned in several EU AI strategies. Turns out it's from be a blog post from Savills, a commercial real estate firm who profit off of data centers being built. Fake US thinktank set up and funded by Israel sought to game AI for propaganda - AI slop meant to absolutely flood the web to be included in AI training funded by the Israel government to spread disinformation in AI answers. A new force is increasing inequality in America - WaPo article about how AI is not leveling the playing field or bridging the gap between poor and rich, but instead worsening the gap. People making the most use of AI are concentrated in richer urban areas and are already often rather wealthy, while the AI data centers are in poorer neighborhoods and the data workers are often migrants or in the Global South. Rich people can invest into AI and its stock, therefore profiting off of the hype and concentrating even more wealth. An operational framework for AI literacy in the workplace - 15 page paper from Interface EU addressing the vagueness of "sufficient AI literacy" that is often mentioned in EU AI legislation. It proposes a cumulative three-tier framework based on the nature and consequences of a worker's interaction with AI which then dictates the level of literacy required and how to attain/ensure it and measure it. The Quiet Erosion of Collective Action Under Digital Surveillance - article on chilling effects of permanent surveillance and the feeling of constant suspicion which continues to erode activism. Flipping the kill switch: I survived 72 hours without US tech - online article about an experiment to live without reliance on US tech. The US has such a strong monopoly that almost all online services and tech are unusable with this rule. Gone in one click - assessing the socio-economic impact of browser-level consent in Europe - small informative flyer style PDF by the Implement Group showing figures about cookie consent rates and ad industry revenues depending on the mode of consent. Inside the growing vigilante movement to knock out Flock surveillance cameras - online article by The Guardian. I admire these people, and we need more civil disobedience now, everywhere. Not just against Flock; against Meta glasses wearers, against Ring camera owners (Yes, you too! None of you are the "good ones" with "valid" reasons!) and more. There's many ways to affect these devices that you can find online or just get creative with it. Keep yourself safe, don't write about it, don't record yourself doing it, don't discuss it via digital means, leave your devices at home, and leave no fingerprints. Did someone wearing Meta Glasses film you today? Are you sure? - another Guardian online article, this time about the spy glasses and the people who enable hiding the recording light on them. The man behind GhostMeta is actually so vile and disgusting; anything else I could say would violate the Code of Conduct this blog is hosted on. German links: HeißeLuft.org - German website with interactive map showing where AI data centers are planned, in development, and paused, together with information on protests. Made me discover that they are planning on building one not too far away from me... Deutsche Post trainiert ihre KI mit Ausweisfotos - article about how Deutsche Post is training their AI with ID pictures they get via digital identification procedures. It's not voluntary as they claim, as you need to give permission before being allowed to proceed. Verhaltensscanner in Berlin: Harte Kritik an der KI-Überwachung - online article about the new camera installed in Berlin that will analyze all people in that area via AI surveillance software by Adesso, with more cameras to follow. They want to put them up in high crime rate areas , but keep secret what the standards for this are, which enables a mass roll-out of them if they wanted to without any oversight or control. There has already been one mix-up leading to higher crime reported in an area than actually happened. These cameras already also exist in Hamburg and Mannheim. Möglicher AfD-Sieg in Sachsen-Anhalt - online article detailing the fear of queer people and people of color of an upcoming potential win of the AfD in their state. Afd-Gutachten.de - website containing some stats and a PDF report of a legal assessment on the chances of a successful AfD ban. „Gipfel gegen Linksextremismus“: Mit Trump gegen die Antifa - online article about the cooperation of Germany with the US on its fight against antifascism. Unfortunately it has continued, with the German government realigning to focus more on supposed "leftist extremism" and even re-distributing money away from leftist projects, which mostly hits projects aimed at helping queer people and migrants. Wie weit ist Deutschland beim digitalen Gewaltschutz? - an online article about the really embarrassingly low standards of protection against digital violence, especially image-based ones like deepfake nudes and revenge porn, in Germany. Lots needs to be done in general, but especially to even meet the new EU standards. Wer ist für Straftaten der KI verantwortlich? - legal article about the criminal liability of autonomous AI in Germany, and how crimes done by AI agents are pushing the legal system to its limit as we only legislate for humans. Published 29 Aug, 2026 This Is Capitalism: Apple's Hidden Data Workers at the Shadows of the AI Boom - 19 page paper detailing what data workers actually do and what problems they deal with, written anonymously by a data worker interviewing their colleagues. Parts of the work descriptions remind me of the work in Severance . Is this really a good reason to triple datacentre capacity in Europe? - online blog post tracing where the idea to triple the EU's data centers comes from that is mentioned in several EU AI strategies. Turns out it's from be a blog post from Savills, a commercial real estate firm who profit off of data centers being built. Fake US thinktank set up and funded by Israel sought to game AI for propaganda - AI slop meant to absolutely flood the web to be included in AI training funded by the Israel government to spread disinformation in AI answers. A new force is increasing inequality in America - WaPo article about how AI is not leveling the playing field or bridging the gap between poor and rich, but instead worsening the gap. People making the most use of AI are concentrated in richer urban areas and are already often rather wealthy, while the AI data centers are in poorer neighborhoods and the data workers are often migrants or in the Global South. Rich people can invest into AI and its stock, therefore profiting off of the hype and concentrating even more wealth. An operational framework for AI literacy in the workplace - 15 page paper from Interface EU addressing the vagueness of "sufficient AI literacy" that is often mentioned in EU AI legislation. It proposes a cumulative three-tier framework based on the nature and consequences of a worker's interaction with AI which then dictates the level of literacy required and how to attain/ensure it and measure it. Great quote from it: "No evidence yet shows that these trainings work, and three gaps might explain the reason. The first is motive. Corporate training aims at productivity and teaches people to use the tools well, whereas the law cares whether operators understand how systems fail and cause harm. A workforce fluent in prompting can still be illiterate in the sense a regulator means: trained to produce good output, but not to recognise when a model misleads or to know its duties under data-protection and risk rules." The Quiet Erosion of Collective Action Under Digital Surveillance - article on chilling effects of permanent surveillance and the feeling of constant suspicion which continues to erode activism. Flipping the kill switch: I survived 72 hours without US tech - online article about an experiment to live without reliance on US tech. The US has such a strong monopoly that almost all online services and tech are unusable with this rule. Gone in one click - assessing the socio-economic impact of browser-level consent in Europe - small informative flyer style PDF by the Implement Group showing figures about cookie consent rates and ad industry revenues depending on the mode of consent. Inside the growing vigilante movement to knock out Flock surveillance cameras - online article by The Guardian. I admire these people, and we need more civil disobedience now, everywhere. Not just against Flock; against Meta glasses wearers, against Ring camera owners (Yes, you too! None of you are the "good ones" with "valid" reasons!) and more. There's many ways to affect these devices that you can find online or just get creative with it. Keep yourself safe, don't write about it, don't record yourself doing it, don't discuss it via digital means, leave your devices at home, and leave no fingerprints. Did someone wearing Meta Glasses film you today? Are you sure? - another Guardian online article, this time about the spy glasses and the people who enable hiding the recording light on them. The man behind GhostMeta is actually so vile and disgusting; anything else I could say would violate the Code of Conduct this blog is hosted on. HeißeLuft.org - German website with interactive map showing where AI data centers are planned, in development, and paused, together with information on protests. Made me discover that they are planning on building one not too far away from me... Deutsche Post trainiert ihre KI mit Ausweisfotos - article about how Deutsche Post is training their AI with ID pictures they get via digital identification procedures. It's not voluntary as they claim, as you need to give permission before being allowed to proceed. Verhaltensscanner in Berlin: Harte Kritik an der KI-Überwachung - online article about the new camera installed in Berlin that will analyze all people in that area via AI surveillance software by Adesso, with more cameras to follow. They want to put them up in high crime rate areas , but keep secret what the standards for this are, which enables a mass roll-out of them if they wanted to without any oversight or control. There has already been one mix-up leading to higher crime reported in an area than actually happened. These cameras already also exist in Hamburg and Mannheim. Möglicher AfD-Sieg in Sachsen-Anhalt - online article detailing the fear of queer people and people of color of an upcoming potential win of the AfD in their state. Afd-Gutachten.de - website containing some stats and a PDF report of a legal assessment on the chances of a successful AfD ban. „Gipfel gegen Linksextremismus“: Mit Trump gegen die Antifa - online article about the cooperation of Germany with the US on its fight against antifascism. Unfortunately it has continued, with the German government realigning to focus more on supposed "leftist extremism" and even re-distributing money away from leftist projects, which mostly hits projects aimed at helping queer people and migrants. Wie weit ist Deutschland beim digitalen Gewaltschutz? - an online article about the really embarrassingly low standards of protection against digital violence, especially image-based ones like deepfake nudes and revenge porn, in Germany. Lots needs to be done in general, but especially to even meet the new EU standards. Wer ist für Straftaten der KI verantwortlich? - legal article about the criminal liability of autonomous AI in Germany, and how crimes done by AI agents are pushing the legal system to its limit as we only legislate for humans.

0 views
Kev Quirk Yesterday

The New Patrol (Liam Scott #2)

Author: Andy McNab Genre: Military Fiction Released: 2014 Rating: ★★★☆☆ KNOW YOUR ENEMY. Liam Scott is back in Afghanistan, this time with 4 Rifles. No longer the new guy, it's his chance to prove himself and take the lead. But the warzone has changed dramatically, and so have the rules. Working alongside the Afghan National Army, Liam and his new patrol face daily attacks from Taliban insurgents. But the real threat seems to be coming from within his unit. It looks like there's a traitor in their midst. Learn more on Goodreads ➡ This is the second book in the trilogy, after reading the first book to my oldest son, he wanted to continue and read this one. As a veteran myself, parts of this book were close the the bone. I found myself having to take a moment to compose myself a few times, but it's a good read. In hindsight, it's probably too mature and graphic for him, but we're commited now, so we will continue. We're planning to start the 3rd and final book soon. Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️ You can reply to this post by email , or leave a comment .

0 views

Mounts Krn and Batognica

I lost count of how many times I looked—and photographed—Mount Krn over the past decade. It’s impossible to miss, standing right there in the background of almost all my walks around the valleys, with its 2245 meters and its characteristic gently sloping side. And yet, I never hiked it. The reason why I never hiked it was that it’s a long hike and past me wasn’t a fan of long hikes. But past me is, well, in the past. Current me, on the other hand, loves long hikes. And to be fair, “long” is a relative term. How long does a hike need to be to be considered long anyway? The route for this hike has been sitting on my watch ready to go for weeks, waiting for the summer heat to come down a little bit. I’m a stupid hiker, but going up a mountain in 35°C is too stupid, even for me. And down it finally went. Randevouz with a friend was set for 7 am. The plan was straightforward: drive together about an hour, crossing the border with Slovenia, going through Kobarid, to then reach a parking spot inside the Triglav National Park . The whole area around mount Krn is a lovely plateau, gently sloping uphill, with cows and sheep free to roam around. The scenery is wonderfully relaxing. There are many ways to go up these mountains, our plan is to summit Krn first, and once there, do a long loop touching Mount Batognica on our way back to the start. Climbing up is surprisingly easy. It’s a long, easy walk that takes us from roughly 1000 meters above sea level to the 2254 of the summit in just a bit less than 3 hours. I can’t remember the last time I gained this much elevation this easily. And getting to the top is rewarding. The view is stunning. On one side, facing south, a mix of mountains, hills, and the sea far in the distance. On the other side, facing north, a gorgeous assembly of peaks and valleys, trees and rocks. Also from up here, an unusual angle of Mount Matajur. Funny how a place can look almost unrecognisable when seen from a different perspective. Going from the Krn to the Batognica doesn’t take much. The two peaks are near each other. What I didn’t know is how much history is still up there, laying on a ground that carries the scars of the First World War. Rusted barbed wire is everywhere. So are chunks of metals, and rusted shovels and other tools. A few artillery shells are also there, now a memorial. Also bunkers. So many bunkers dug into these mountains. Walking through these places never fails to remind you of the insanity that those wars were. So many lost lives and for what? The clouds decide to pay a visit, the scenery turns grayscale in the blink of an eye. I’m glad the sun is not hammering us on the way down. It’s less hot than it was a few weeks ago, but it’s still summer, and it’s definitely not cold, even up here. The descent to the starting point is long, and mostly enjoyable. A couple of rough kilometres towards the end, the humidity comes back, and the trail is all of a sudden slippery and a bit overgrown. We lose almost 700 meters of elevation in just a couple of kilometres. The view from the other end of the loop is still magnificent. And the cows are still here, still minding their own business. What else are they supposed to do after all? A bit less than 7 hours have passed , and we’re back at the car. Krn didn’t disappoint. Batognica is worth hiking. The whole Triglav National Park is worth exploring. Slovenia is a beautiful country, and if you’re an outdoorsy person, it won’t disappoint you. You love the outdoors and RSS. You're one of the special ones.

0 views
neilzone Yesterday

Automating local backups of UniFi OS Server on Linux with uos-backup

Earlier today, I migrated my self-hosted UniFi controller from Network Manager to UniFi OS Server . One of the annoyances of the new setup is that it does not allow automated local backups - just automated backups to Ubiquiti’s cloud. Fortunately, one can work around this. In the UniFi interface, I set up a new local user, , to use for this automated backup. I am using . is a simple Python scripts which someone has kindly written and shared. I did the following, on the machine I wanted to use to take and store the backups. Get the code: Change to the directory with the code: Edit the python script, for the correct URL, username for my new backup user, and password. Check that the requirements are met: Copy the script to : Make it executable: Create the directory to store the backups. This is the directory specified in the script; you can create a directory with a different path, and then just update the script according Test that the script works: Even though I had just set up a new user, I had managed to get the username and password wrong in the script, and this step helped me debug it. I checked in /var/lib/uos-server/ to check that I had backup files. Set up the systemd services: I then added the backup directory path to restic, so that it gets picked up with my automated restic backups too.

0 views
neilzone Yesterday

Migrating my self-hosted UniFi controller from Network Manager to UniFi OS Server

One of the jobs that has been on my list for a while is to migrate my UniFi controller installation from the self-hosted network manager tool to the new UniFi OS Server tool. The only reason that it was a job at all is because UniFi has decided to discontinue support for the UniFi network manager. Which is probably for the better, as it contained outdated packages anyway. Frankly, I’m not massively impressed with UniFi any more. If I were starting again, I am not sure that I would pick UniFi kit, but I don’t know what I would go for instead. I simply want to run my own controller, without external access or access by anyone else, to control the network infrastructure at home. I did the migration, and it mostly worked. Here’s what I did: I read the Unifi OS Server installation instructions . I also read the Backups and Migration in UniFi instructions. My UniFi controller is running in a virtual machine, so I took a snapshot of that first. If all else failed, I could roll back the snapshot. I backed up the configuration of my existing UniFi network manager configuration. I downloaded it to my local machine. I also backed up the ssh configuration information for my UniFi devices, in line with the instructions: It is also recommended to copy the SSH username and password from Devices > Device Updates & Settings > Device SSH Settings, in case any devices need help later when connecting to the new instance of UniFi Network. I stopped the UniFi network manager with . I followed the Unifi OS Server installation instructions . It will be interesting to see how updates work. The instructions say: Captive portals will be served on port 8444, changed from port 8843 on Network Server. It did not mention that there was also a change to the port to the controller. However, the final line of the set up information showed that it was port 11443. So I changed my nginx proxy config from 8443 to 11443, and reloaded nginx. I could now access the new UniFi OS Server interface. It went downhill from here. I was intending to restore from backup, so I clicked the option for this. It then prompted me to - forced me to - sign in with a ui.com account. I’ve no idea why. It is a local controller, and I don’t want any remote access facilities. Nevertheless, I could not find a way around it. So I did, but I can’t say that I am impressed by this. It then said: We’ve discovered that you already have a self‑hosted UniFi Network installation. Would you like to import your current network settings into UniFi OS Server? But the options were not “Yes” and “No”, but rather “Continue without importing” and “Next”. This was a surprise anyway, as the instructions say: On macOS and Windows, the installer will automatically detect and offer to migrate your existing Network Server setup (if installed in the default location). On Linux, or if auto-migration doesn’t occur, you can manually migrate by installing UniFi OS Server and using the Site Export tool I am running it on Linux, so I did not expect any migration. I guessed that “Next” means “yes”, so I selected “Next”. It took me to a url ending . This was a blank screen. Nothing at all. I waited a couple of minutes, then refreshed the page. It then showed me a page showing that it was “restoring backup”, but the progress bar remained blank for quite a while. It also said that it was restoring to settings from January 2026, not last night’s backup, which surprised me. After a couple of minutes, the progress bar flashed by, and it was done. The import/migration appears to have correctly imported all my devices, and is set up to talk to them. But other aspects of the migration were underwhelming. It did not restore the settings for my mailserver. It was preset to use the “UI Mail Server”. I set it up to use my own mailserver, and it failed, with a useless error message. When I logged in to my mailserver to see what was going on, I saw . It appears that I am not the only person with this issue , albeit with a slightly different setup. They seem to have resolved it by disabling TLS, which is not an option for me. I have not yet got this to work. Even though I had configured automatic backups on the previous Unifi Network Server, they were not enabled on the new UniFi OS Server. I tried to set it up, but I was prompted for my “Ubiquiti SSO account password”. I tried the password for my ui.com account, but I got an error message of “Something went wrong. Please try again later.” Which was no use at all. Having turned off Remote Access (below), I went back to the Backups dialogue. Now, there was an option to download, or upload & restore, but nothing about automation. The info box says that I can schedule backups here, but there is no user interface for that. I took a manual backup. I cannot see a way to do automated backups to my local file system. If this is correct, this is absurd. I may see if I can do something using the command line. *Edit: yes, I can, with python and systemd. See Automating local backups of UniFi OS Server on Linux with uos-backup . “Remote access” is enabled by default, even though I am confident that I did not have remote access enabled before. When I attempted to untick it, it showed a dialogue box: So I disabled it. https://help.ui.com/hc/en-us/articles/220066768-Updating-and-Installing-Self-Hosted-UniFi-Network-Servers-Linux It did not restore my preferred time format (24 hours). I had to turn off analytics, which was on by default. It worked better than I was expecting, but that’s mainly because my expectations were very low. Why the email server and automated backups do not work, I do not know. I will need to investigate these. But at least I am now running a supported controller again. Once I’ve done a scan of the new system with greenbone, I’ll be interested to see what it reports.

0 views

August 2026 blend of links

As I am near the end of my summer holiday and paternal leave (for a total of five weeks nonetheless), I find it very difficult to take the time to… well… to do anything really. Having a soon-to-be four-month-old in the house feels like a full-time job, with long hours and short nights, pure bliss, laughs, and impromptus naps; nothing really blog-friendly I’m afraid. But still, between two heatwaves and two batches of homemade pizza, I’ve managed to save some interesting links. A digital museum of video game levels – So many memories, and the fact that the levels available in this museum are empty makes the site even more precious; isn’t it strange that we mostly remember some video games as places we’ve visited rather than games we’ve played? The Banjo-Kazooie and Half-Life 2 levels made me travel back in time, while it’s always nice to get a nice, serene view of Anor Lando . (via Kottke ) Another week on Linux – Saving this link for the next time — roughly every two or three months — I’m even considering installing a Linux partition on my computer. Jurassic Park computers in excruciating detail – Attention to spammers, scammers, and other email impersonators: if you want me to click on a fake link you send me, just make it somehow related to Jurassic Park. (via Daniel Benneworth-Gray ) WalletWallet – I will never understand why the Wallet app on iPhone is so little permissive: this website shouldn’t exist as its features should already exist within the app. (via Dense Discovery ) Nomos Club – In August, I have spent far too much time looking at watches (no pun intended), and I’ve grown quite fond of what Nomos is doing: in-house movements, Bauhaus-inspired design, beautiful craft. I like my Seiko SPB251 very much, but I want this watch. Apple Music weirdness – While reading this, I nodded in approval so hard that I almost hurt my neck. BitCam – Delightful. Absolutely delightful. (via John Gruber ) The TEMU-fication of Software, Digital Goods & Services – “ Just like with physical goods, we will probably end up with a two-tier market, in which we have a large and massively profitable lower tier of generated slop, and a smaller, more expensive upper tier of work that is still recognizably human. ” Eylenburg's Tech Website – Nerd paradise. (via 82Mhz )

1 views

What GLM-5.3 Flash running on Chinese hardware actually means

Z.AI confirmed that their most recent model release was running all inference on Chinese manufactured hardware. While no doubt an impressive feat, Western companies still have a huge advantage that I can't see changing quickly. To start with, it's worth looking into where Chinese AI hardware is. I'm focusing entirely on the HiSilicon parts - the most competitive parts from Huawei. There are (many, actually) other manufacturers building AI hardware, but it's widely believed that they are no further ahead than HiSilicon, so I think that for brevity it's a fair starting point. One caveat before I go further: Z.AI didn't actually name a chipmaker, and didn't publish throughput or power numbers either. Nobody has independently verified the claim. So I'm assuming HiSilicon here because it's the only plausible candidate at that scale, not because anyone has confirmed it. It's also worth mentioning that the US export restrictions ( CSIS has a good overview ) of high end AI hardware have made this an enormous priority, understandably, for the Chinese. And it's definitely worth mentioning that finding accurate sources for many of the numbers I'll cite are difficult to be confident in, so take the exact numbers with a pinch of salt. The current 'scale-up' series of HiSilicon chip, the 910c series, pairs 96GB of HBM 2e memory with two compute dies, probably achieving something like 1.6PFLOP/s of INT8 compute with ~3TB/sec of memory bandwidth, at around 600W. In essence, this is substantially behind even the H100 from Nvidia, which is now 4 years old. These are around 60% as fast as the H100, and has various other footguns (no native FP8 support for example), which probably restrict efficiency further for many use cases. The next generation 950-series doesn't meaningfully increase compute as far as I can see, but does use domestically produced HiZQ/HiBL HBM memory. Interestingly the cards are configured in two variants - the 950PR and 950DT, with the former focusing on prefill and the latter on decode. In reality, the two products are very similar, but the prefill variant using slower HiBL memory vs the decode HiZQ memory. It does however support more quantisation types, like FP8. I think this shows the limitations of what Chinese hardware can do - at least for the near future. Yes, they can run inference, but so can many sets of hardware now - AMD, Google and Amazon all have competitive solutions, and OpenAI are making significant progress on their Jalapeño inference chip , which in the first published benchmarks did 1.5-1.9x the work per watt of Nvidia's GB300. Inference hardware while no doubt complex, is a pretty solved problem right now with a lot of competition - and that's before you bring in the Cerebras and Groq approach chips. The wall that these Chinese hardware manufacturers are hitting is the lack of viable EUV (extreme ultraviolet) fabrication. This is the next generation silicon manufacturing process from ASML and it is extremely hard . I'd really, really recommend reading Chip War by Chris Miller for the full story, but regardless until there is significant progress on this - and by significant progress, I don't mean the reverse engineered prototype in a Shenzhen lab. I mean reliable, scale production. The industry would be astonished if they got this to scale production before 2030. Bear in mind the Shenzhen prototype hasn't produced a working chip yet, and the more optimistic forecasts have them doing that around 2030 - volume production is a further step beyond it. It took ASML 25 years to figure out this technology - and a good 5+ years of this was scaling it up from the lab to "real" production lines. While China no doubt has incredible engineering talent and the ability to reverse engineer some of ASML's work, it's still a daunting challenge. Without EUV it is not possible to go (much) below the "7nm" fabrication size. Without being able to go below that size, you quickly hit a wall in thermal efficiency, and you reach a point where you simply cannot make the chip(s) any bigger or faster because you cannot expel the heat quickly enough. Added to that, the additional export restrictions on HBM memory to China are clearly causing significant issues, hence the strange use of two different home grown memory technologies in the 950-series - no doubt because they can't produce enough fast (which is still comparatively slow ) memory. These are really the same base constraint - without EUV manufacturing technology you can't produce the latest generations of very fast HBM memory either. Clearly the approach China is taking is instead of really looking for solid incremental leaps in compute and memory from better manufacturing techniques, the idea is to build a lot of them. Even if your fastest chips are at best 5 years behind the latest Nvidia GPUs, you can just build 10 times as many for the same overall inference capacity. And it really is roughly 10x - not against the H100 I was comparing to above, but against what Nvidia actually ships today. A Rubin VR200 is somewhere around 35PFLOP/s of dense FP4 with 22TB/sec of HBM4 bandwidth. The 910c is 60% of a four year old H100; Rubin is another order of magnitude past that. No doubt China is uniquely positioned in being able to do this - with enormous power generation capacity to power this, and huge quantities of skilled engineering and manufacturing labour to build the facilities and cooling required. But really, it's far from ideal. As models get larger, you have to split them over more and more underpowered sets of hardware. Another problem is it makes the models slow - Z.ai's own API is noticeably slower than Western providers serving the same weights. The bit I keep coming back to though is power. And here you have to be careful, because 10x the throughput gap is not 10x the power bill - the 910c pulls about 600W against something like 2000W for a Rubin part. Divide the spec sheets and you get a much less dramatic 2-3x on both compute per watt and bandwidth per watt. But the spec sheets flatter the 910c. 96GB a chip, against the 288GB or more you get on current Western parts, leaves much less room for KV cache, which forces smaller batches, and decode throughput per watt falls away badly at small batch sizes. Add a less mature software stack, and the interconnect and cooling overhead of running 10x the chips, and 5x worse on tokens per watt feels about right to me. If anything that's the charitable end. Which matters because electricity is usually reckoned to be 10-20% of the total cost of running a GPU cluster, with hardware amortisation dominating. Multiply that by five and power goes from a small component of costs to something like half your total bill. That's fine when you have China's generation capacity and you're happy to treat the difference as a strategic subsidy. It's a lot less fine if you ever want to sell inference into a competitive global market on price. Small models getting better doesn't rescue this either. They help, obviously - a 30B model serving a task that used to need a 300B one is a real saving. But it's a saving both sides get - that smaller 30B model still runs 10x as fast on Western hardware, so the ratio between Chinese and Western hardware efficiency stays exactly where it was. And assuming China doesn't have some huge breakthrough in fabrication technology - which as I said before is highly unlikely - it's probable that the gap between Western and Chinese AI hardware will widen if anything. So, to round up - yes it's an impressive feat that they've managed to do this, but there are some hard constraints on efficiency that are unlikely to be solved any time soon. And yes, China could overcome it by sheer quantity, but it's a subpar solution that has real impact on the speed, capacity and economics of their inference.

0 views
alikhil 2 days ago

Protect Kubernetes Services with OAuth2 Proxy, Gateway API, Traefik, and Pocket ID

My previous guide used ingress-nginx annotations to put internal Kubernetes services behind OAuth2 Proxy. It was written for an ingress-nginx setup. That controller is being retired, and Gateway API is the direction Kubernetes recommends for new traffic management work. This post rebuilds the same authentication flow with Gateway API, Traefik, OAuth2 Proxy, and Pocket ID. Why Traefik? Gateway API standardizes and , but it does not standardize browser-based OIDC login or an external-auth filter. This setup uses Traefik’s CRD for those pieces. With Envoy Gateway, Kong, Cilium, or another implementation, the Gateway API resources can stay, but the authentication adapter must change. This setup exposes three HTTPS hostnames below one domain: One parent domain lets OAuth2 Proxy use a narrowly scoped shared session cookie, such as . Do not set the cookie domain to a wider parent domain when unrelated applications use it. only checks a session: it returns when one is valid and otherwise. Traefik’s middleware turns that into the browser redirect to OAuth2 Proxy. That separate redirect step is the most important difference from the old ingress-nginx annotations. I verified the authentication flow on a local K3s cluster. The commands below use standard Kubernetes and Helm commands, so they are not tied to that local environment. Start with a running cluster, , and Helm. You also need DNS for pointing to the endpoint that accepts HTTPS traffic for Traefik. Gateway is only routing configuration; Traefik is the process that accepts the traffic. On a managed cloud cluster, expose Traefik through a of type . On bare metal, use MetalLB or your existing external load balancer. A local cluster normally uses its own port mapping or local load-balancer mechanism. Replace with a domain you control before applying any manifest. The login callback and session cookie need HTTPS. Gateway API is an add-on API, not a resource installed in every Kubernetes cluster. Install its standard CRDs before installing a Gateway implementation. If your platform manages Gateway API already, check its documentation before applying another version. The standard channel is enough here. It contains the stable , , and APIs. This guide uses Traefik’s Gateway API provider plus its Kubernetes CRD provider. The first handles standard and objects. The second is required because the authentication middleware is a Traefik CRD. The setting above is the common managed-cluster case: the cloud controller creates an external address for the Traefik Service. If your cluster uses another traffic-entry mechanism, adapt this one setting and point DNS at that endpoint. The resource below does not create the external listener by itself. Check that Traefik registered a and that its Service has an address before adding DNS: I assume cert-manager and a working named already exist. A DNS-01 issuer is usually the simplest way to obtain a wildcard certificate. If you use HTTP-01, request the individual names instead. Apply it and wait for both the certificate and Gateway: Do not continue until the Certificate is and the Gateway is . I use Pocket ID as the OIDC provider because passkeys make a small personal or team setup simple. You can substitute another OIDC provider; only the OAuth2 Proxy provider settings change. Expose it with a standard rather than an Ingress. The chart’s Service listens on port . Apply it, then open . Complete Pocket ID’s initial setup. Create a user with a passkey and make sure its email address is verified. Create a group and add the user to it. Then create an OIDC client named with this redirect URL: Save its client ID and client secret. OAuth2 Proxy will allow only members of ; Pocket ID must therefore send the claim. Verified email is also required : OAuth2 Proxy rejects Pocket ID’s ID token if its email is not verified. Create a Kubernetes Secret with the OIDC client credentials and a 32-byte cookie secret: Use the official chart’s values to create OAuth2 Proxy’s : Open now. You should reach Pocket ID and return to OAuth2 Proxy. Fix the issuer URL, callback URL, client secret, or TLS before adding an application route. The protected service needs an , a middleware that calls OAuth2 Proxy, and an middleware that changes an unauthenticated into a browser redirect. Keep the middleware order: ForwardAuth returns the , then Errors changes it into a login redirect while preserving the original URL. is the safe default for a direct public entry point. A production setup behind Cloudflare or a cloud load balancer must define its trusted proxy boundary before accepting forwarded headers. Use a private browser window so that an old cookie cannot hide a problem: You should be redirected to Pocket ID. After authentication, loads and displays the headers that OAuth2 Proxy passed through Traefik. If the browser receives a plain , check that both middleware resources are attached to the and that maps to . If the login works but access is denied, check the user’s verified email and membership in . Gateway and route status are useful for routing problems: These steps demonstrate the authentication flow. A production deployment still needs a secret store, network policies, a session store when needed, and explicit trusted proxy configuration. If a local Kubernetes detail is unclear or the steps above do not work as expected, see alikhil/oauth2-proxy-k8s-lab . It contains the k3d configuration I used, including traffic entry, DNS, certificates, and cleanup. The old ingress-nginx guide remains available for existing installations; migrate one hostname at a time after verifying login, logout, deep links, and an expired session. is the Pocket ID UI and OIDC issuer. serves OAuth2 Proxy endpoints. is a protected demo service.

0 views
Unsung 2 days ago

“An absolute bare minimum of interactivity”

I mentioned Atari’s Pong recently , a game often considered to be the first videogame ever. It wasn’t, and as a matter of fact, it was a clone of one of the games from the first home console Magnavox Odyssey , released earlier in 1972: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/1.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/1.1600w.avif" type="image/avif"> This is a 34-minute video by FrameRater walking through the console and all of its strange games: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/yt1-play.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/yt1-play.1600w.avif" type="image/avif"> I found it a very interesting case study. The Odyssey had a version of Pong before Pong – but it also had many other games that could be charitably described as “Pongs in disguise.” It all feels very, very convoluted for such a simple concept. You have to insert the right cart, tape an overlay to your TV of a certain size (the roll of tape is included), and understand the complex and poorly written instructions in the manual . Then, during the play time, you’d have to master the very strange controllers (left dial – horizontal movement, right dial – vertical movement), often do a lot of work that the console didn’t do (keeping track of collisions, or even scoring!), and deal will all sorts of accessories in the real world, like included cards, dice, stickers, and so on. You can admire the scope of this all – when life gives you Pong, you make a pongolade – but it all feels so clunky and convoluted, which the video catalogs in detail. But, in hindsight, it doesn’t matter if the included Pong (here, called Table Tennis) is good, right? Reader, Table Tennis wasn’t good at all. It wasn’t just the strange controllers, but also the really weird logic where you could twist the ball already in flight: Only looking at this made me realize, some 50+ years too late, the true power of Pong. = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/3.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/an-absolute-bare-minimum-of-interactivity/3.1600w.avif" type="image/avif"> Pong didn’t bother with many games, with complicated rules, with the breadth of it all. It just did one thing really, really well. For the Odyssey, it seemed like a lot of games were about mastering the controller. For Pong, it was only ever about mastering the game . The interface was simple: you have one dial, so rotate it. The game was fun to play, with its logic both challenging and predictable. The instructions were sparse and barely needed anyway. There was automatic scoring, which Odyssey didn’t have. There were also sounds – turns out, people really liked sounds. The Odyssey was clearly an in-betweener, a complicated hybrid device weighed down by its well-intentioned maximalism. Pong was simple, attractive, optimized to the bone. I feel that it offers universal lessons, feeling eerily similar to iPod’s release in 2001 – focusing on just the few things that mattered, and doing them really, really well. #complexity #craft #games #history #youtube

0 views
Stratechery 2 days ago

2026.35: Internet Hype and Real World Change

Welcome back to This Week in Stratechery! As a reminder, each week, every Friday, we’re sending out this overview of content in the Stratechery bundle; highlighted links are free for everyone . Additionally, you have complete control over what we send to you. If you don’t want to receive This Week in Stratechery emails (there is no podcast), please uncheck the box in your delivery settings . On that note, here were a few of our favorites this week. This week’s Stratechery video is on Nvidia’s Risky Business . The Breaker’s Advantage . One of the most important takeaways of The Hugging Face Incident is that agents are more useful for attacking infrastructure than in defending it. While in theory defenders know the code, their number one job is to not break things; for attackers breaking things is the point. This week’s Article Autonomy and Innovation makes the case that this dichotomy isn’t just relevant to security: it also explains why startups consistently defeat incumbents, and why AI’s takeover of the economy will take longer than people think. The New Battle for HDMI1.  For years Netflix insisted its service stood alone, resisting attempts by companies like Apple to integrate their service. Now Netflix is poised to go in the other direction, potentially selling access to other streaming services. Ben wrote about the company’s shift on Tuesday , and on this week’s Sharp Tech chalked it up to Hollywood staying irrational longer than Netflix could stay patient.  — Andrew Sharp How Data Center Discourse Ends.  The backlash to the continued buildout of AI data centers has continued all summer, and now looks even more widespread than it was when Ben tackled the issue in May and we dedicated an entire episode of Sharp Tech to the controversy . Now that people in tech are legitimately worried, however, it’s time to zag: I think that this will ultimately be a non-issue , just like so many other overwhelming Internet movements. — AS Autonomy and Innovation — Incentives favor offense when it comes to agentic cybersecurity; it’s the same dynamic that will limit incumbents and fuel startups in the long run. Netflix to Sell Streaming Services?, Streamers as Aggregators, Revisiting Roku — Netflix is considering selling other streaming services, and I think it’s a good idea; it’s also a let-down for Netflix’s original goals and potential pivots. Apple Updates Mini and Studio, AI Computers, OpenAI Jalapeño — Apple and OpenAI have two completely different hardware announcements; both represent pressure on Nvidia. Halt and Catch Ire — A survey of data center madness, and why I’d bet the under on the durability of the backlash . Omarchy and Open Macs Has the Solid State Transformer’s Time Finally Come? Five US-China (and Russia) Questions; Cabbage with Formaldehyde; The Continuing Tax Crackdown; Unitree Stock Down 45% Peyton Watson to the Cavs, Building a Top Five for 2031, Top 5 Feats of Loser Behavior Meta’s New Restrictions for Teens, Nvidia’s Open Source Investments, Q&A on Netflix, Druckenmiller, Parameters and Performance

0 views
neilzone 2 days ago

Time to drop .legal?

My wife and I run a small law firm in the UK. Originally, we called it decoded:Legal. It made sense at the time, even though quite a few places struggled with the idea that a company name might have a colon in it. We used , and I registered too (and, it seems, ) although I don’t think I’ve set up DNS for either of them. Then, when a friend pointed out that there is a tld, I thought “that looks nicer”, and we switched to , both as the company name and also our domain name. I wonder if - nice though it still is - I should think about using a different tld. (If I moved, I’d maintain decoded.legal indefinitely anyway, because people are used to sending email to @decoded.legal addresses.) The .legal tld appears to have a poor reputation. For instance, it is on this list of “The Top Most Abused Top Level Domains” . It would be a shame if people could not find our business, or access any of its online properties, because .legal is on that list. (And, yes, I could seek an exception, but that hardly seems the point.) As far as I know, this has not been a problem so far, but this could be survivorship bias: I don’t know about the people who have never seen me. The .legal tld is operated by Binky Moon, LLC , which is based in the USA. I wonder if it would be sensible to use a .tld subject to UK control instead. Obviously, it would be nice if I was not dependent on anyone other than me for my domain name, but that is unrealistic. I use a few .onion domains - for access within Tor - including for decoded.legal properties. For instance, our website and blog are available at http://dlegal66uj5u2dvcbrev7vv6fjtwnd4moqu7j6jnd42rmbypv3coigyd.onion . (And, yes, it is intentional that this no longer has https .) Realistically though, the vast majority of people are not going to visit us in onionspace.

0 views

Premium: The Hater's Guide To Circular Financing (Part One)

[NVIDIA Company Meeting, the present day, YMCA playing] JENSEN HUANG : We love NVIDIA, don’t we folks? We’re the biggest, most-beautiful semiconductor company, we make the biggest, hottest GPUs for Clammy Sammy and Wario Amodei ’s huge, beautiful AI labs, but they can’t afford them because they’re losing so much money! [crowd booing] It’s okay! It’s okay! Big strong men, the biggest muscles, big, beautiful, strong men like Satya Nadella are calling me, begging — they’re begging, can you believe it? — they’re begging me, “Sir, Sir, please ship me Vera Rubin sir! I can’t get enough!” [crowd braying] they can’t get enough of Vera Rubin! They’re begging me to get Vera over there! Vera! Where’s Vera! [scanning crowd] get her up here! No, no, don’t do it, she’s too shy! We love Grace too, [voice turning gravely] Grace Blackwell , what a gal! I told them all we’re going to ship a trillion dollars of Grace Blackwell and Vera Rubin by the end of 2027 , our beautiful girls Grace and Vera , they’re our biggest and most-expensive girls yet, our Gee-Pee-Yous , the media says “we don’t believe you sir!” but I’m gonna make everyone buy ‘em, hell I’m gonna give ‘em the money to do it like I did with CoreWeave and then I’m gonna tell  Clammy Sammy and say “Samuel, give ‘em a few billion like you gave to Michael Intrator ,” and he’ll say “yes sir!”  Now, people are saying to me — “Sir! Sir! Your customers can’t afford your semiconductors! Sir, they’re too expensive!” and I say they’re not expensive enough! We’re gonna charge ‘em 17% more! [crowd braying] Should we up the price? Should we do it? We’re gonna do it!  In my mind, this is how Jensen Huang speaks to his workers, more than 70% of whom are millionaires as a result of NVIDIA’s remarkable stock growth, and from what I’m told by insiders, there’s a near-manic attention paid to stock movements as a result. I imagine working there must feel a little insane. Assuming you arrived before the stock went parabolic in 2024, you’ve seen your RSUs explode 10x in the space of a few years, all based on the back of everybody talking about how big and huge AI is… … all as it becomes blatantly obvious that NVIDIA’s biggest customers are, for the most part, funded by NVIDIA . While NVIDIA still ostensibly sells things other than AI GPUs (like autonomous cars , laptop graphics cards, and simulation technology for robotics ), more than 90% of its revenue comes from data center hardware. As a result, the company has become almost-entirely valued on whether or not it can continually come up with rationalizations for its largest customers to spunk tens of billions of dollars a quarter.  Why else would NVIDIA invest even an iota of effort into making an NVIDIA-branded Openclaw or build a platform for LLMs to do “agentic” things , or give $6 billion to Poolside (while investing another $1 billion) and hire away most of its staff? Why else would it plan to invest billions of dollars in Perplexity at a $30 billion valuation that lands somewhere between “fucking stupid” and “laughable”?  Sorry, I’m being a little vague. Everything NVIDIA has done for the last three years has existed to do two things: NVIDIA has succeeded in doing the first primarily by selling these GPUs to hyperscalers like Amazon, Google, Microsoft, Oracle, and Meta, who make up somewhere between 50% and 60% of its GPU sales depending on which analyst you ask.  The rest comes from a mixture of unnamed “sovereign AI customers” and “neoclouds” — companies that exist to raise debt, buy NVIDIA GPUs, and put them in data centers to rent to theoretical AI customers. Per Vivek Arya of Bank of America (at the BoFA Global Technology Conference in June), sales to “neocloud/sovereign/on-premise” were about the same as those to hyperscalers, and while it’s tempting to dither here and say “there could be large sovereign buildouts!” I can’t find compelling evidence that these actually exist outside of a theoretical 75 billion Euro investment in AI infrastructure in France by SoftBank , which doesn’t have that much money to spend. In any case, NVIDIA’s entire strategy has become a case of either convincing the largest companies in the world to give Jensen Huang $100 billion a year or artificially inflating its revenues through circular financing, which is obviously what I’m talking about today. This is the first part of my Hater’s Guide To Circular Financing, a comprehensive analysis of the current state of NVIDIA’s massive circular financing operation, why it has yet to break, its limitations, and the material concerns that were raised in its latest quarterly earnings. The second part, coming next week, will cover the history of circular financing, where we’ve seen it before, and what we can learn from its horrible past. Create sales for its AI GPUs and associated hardware. Create demand for AI compute for its customers.

0 views
Unsung 2 days ago

“They had no concept of a duty of care to their users.”

A Mastodon post by computer scientist David Chisnall has a very Unsung opener: I have used vim since around 2000. I have written five books, a PhD thesis, a few dozen papers and over 150 articles with it. At this point, my higher brain functions are not engaged at all when I use a bunch of common vim commands, they just happen. Documents I wrote with anything else have random :w in the middle. Chisnall goes on to talk about one specific vim feature: Persistent undo is one of my favourite features of vim. […] I don’t often need the persistent undo. But on the few occasions when I have needed it, it’s been invaluable: ooops, I deleted something from this file, maybe last week and one reboot ago, what was it? Undo until I find it, copy it, paste it into the current version. Or, a bit more commonly: I had this working, then I tidied it up ready to commit, now it isn’t working, what did I do? Vim has kept this working across major version upgrades over a period of about 20 years. I don’t even think about it, it’s just part of Raskin’s First Law: A program may not harm a user’s data or, through inaction, allow a user’s data to come to harm. If vim or the computer crash, or if I close a file and come back to it six months later, my undo history is still there. NeoVim is a fork of vim (in news for other reasons ): So I tried NeoVim when it was quite new. Vim that you are familiar with, but better? Great! The first thing I noticed in NeoVim was that undo didn’t work. I tried opening the file in vim and undo didn’t work there either . Neovim had changed the format of the undo files. It hadn’t upgraded the old one. It hadn’t used a different name for its undo files. It had just noticed the existence of a vim undo file, deleted it (losing all of the data in it) and replaced it with one that vim couldn’t read. I raised an issue about this and was told that the persistent undo format was unstable and users should not rely on data being preserved in a feature explicitly called persistent undo. It had changed once and would probably change again. And that ended my experience with NeoVim. The authors showed immediately that they absolutely could not be trusted with any of my data. Breaking persistent undo is something I could forgive as a bug, but the attitude that just because something is a persistent file on your filesystem that contains data that you might want is no reason for their program not to delete it meant they had no concept of a duty of care to their users. I liked this post (which I quoted almost in its entirety), because it covers a few important things: I also loved it for the appearance of Raskin’s First Law. Jef Raskin, of Macintosh and Canon Cat fame, put together the three laws in his 2000 book The Humane Interface , and they go as follows: It was a very important and formative book for me to encounter as a young designer. I have no idea how these laws haven’t made it to Unsung before today. #principles #text editing #undo I have never heard of the persistent undo like that, and it seems kind of amazing. People do remember when software loses their hard work or disrespects them. I can see how “It had changed once and would probably change again” can be such a powerful feeling. A computer shall not harm your work or, through inaction, allow your work to come to harm. A computer shall not waste your time or require you to do more work than is strictly necessary. An interface is humane if it is responsive to human needs and considerate of human frailties.

1 views
Jeff Geerling 2 days ago

Building a mini Homelab that fits in my carry-on

I'm traveling to Chicago for VCF Midwest next month. I'll be demoing NTP time history on vintage Macs, with my own GPS-derived NTP service hosted on an Xserve G5, synced via NTP or a strange AppleTalk timing extension from the 1990s . So I built a little 'portable homelab' (pictured above) that supports 1-10 Gbps networking, can run off a small battery for at least an hour, switches between multiple WANs (so I can get my own 5G Internet connection, in case I need it), and gives me 12 wired Ethernet connections.

0 views