Latest Posts (20 found)

An Interview with Katie Harbath About Disrupting Politics at Facebook

An interview with former Facebook Head of Global Elections Katie Harbath about her new book Disrupting Politics, and how things change for the company in the 2010s.

0 views
Unsung Today

Playdate’s update interface takes charge

Here’s what happens when you try to update your Android phone if it’s low on battery (even if it’s connected to a charger): = 3x)" srcset="https://unsung.aresluna.org/_media/playdates-update-interface-takes-charge/1-framed.1600w.avif" type="image/avif"> It’s a pretty cheap error UI, a misaligned string thrown carelessly in between existing interface pieces. It doesn’t even bother explaining what “too low” means. Compare this to what the Playdate does in the same situation: = 3x)" srcset="https://unsung.aresluna.org/_media/playdates-update-interface-takes-charge/2-framed.1600w.avif" type="image/avif"> If the device battery is depleted, the software simply charges if first to the necessary minimum (spelled out on screen), before automatically proceeding to the actual update – all without any user intervention. We previously talked about fire-and-forget states, or interfaces which give you confidence that once the process starts , it will finish on its own . (If you don’t like military references , we could call these tap-and-walk-away.) This is a really good example. There is even a nice corresponding version for when your Playdate needs to be plugged in first: = 3x)" srcset="https://unsung.aresluna.org/_media/playdates-update-interface-takes-charge/3-framed.1600w.avif" type="image/avif"> Once you do, the process again continues by itself right until the end.

0 views

Swemak: Colemak for Swedish

I have written before about my Swedish Colemak hack, but I never explained what makes it so good. This is a better image what it looks like: If you’re struggling to find the difference against normal Colemak, look at the cluster of five keys next to the return key. This layout makes room for the three Swedish letters , , and , by only changing five keys in total, and they have changed very thoughtfully: (Continue reading the full article on the web.)

0 views
Unsung Yesterday

“Konami looked at its restrictions and designed an entire level based around it.”

A fun little video by Bofner talking about how two Castlevania games on the original Nintendo Game Boy achieved a certain visual effect that wasn’t technically possible: = 2x) and (width >= 700px)" srcset="https://unsung.aresluna.org/_media/konami-looked-at-its-restrictions-and-designed-an-entire-level-based-around-it/yt1-play.2096w.avif" type="image/avif"> = 3x) or (width >= 700px)" srcset="https://unsung.aresluna.org/_media/konami-looked-at-its-restrictions-and-designed-an-entire-level-based-around-it/yt1-play.1600w.avif" type="image/avif"> What I really liked was this sequence of events: Game Boy introduces a special immovable layer to accommodate HUD /GUI elements within games (such as score displays or life meters), Castlevania programmers come up with a creative hack to use the HUD layer draw a movable spike wall instead, then, they use another hack to draw the HUD anyway, outside of the HUD layer.

0 views
David Bushell Yesterday

A sustainable web career, for when all this blows over

For better or worse the web industry is going through a bit of a phase. The reasons are largely irrational. People still need the web, nothing has changed there. Regardless, the financials of this business are a struggle. Longterm career prospects are looking dicey. Because I openly reject the driving force intent on destroying my profession, and ruffle a few feathers doing so, I often get asked privately for advice from like-minded peers. I can only offer an uninspired but sensible reply: don’t quit a paying job without a fallback. Go to the Winchester, have a nice cold pint, and wait for all of this to blow over. I’m confident the situation will improve. Before it does, what can we focus on to accelerate past the intellectual slump, and better position ourselves once things calm down? For a sustainable web career, where better to look than critical skills in desperately short supply? My focus is on front-end development, but these areas of knowledge are relevant to anyone in the business of making websites. Accessibility has always been a foundation of web development but it’s never been more critical for everyone to champion it. Understand why accessibility is for everyone. Learn how to talk about accessibility in respect to real needs and practical implementation. Accessibility has unfortunately become a virtue signal for certain tech groups. (I’m told LinkedIn is rife with misinformation.) Accessibility is not a feature that can be tacked on to a website like garnish. Accessibility issues can’t be fixed with an automated process at the end. Web professionals must be able to counter this mindset by respecting accessibility in all decisions from day one. Learn and adopt the guidelines as your baseline. Speak to and test with real people. Defer to specialists who are eager for you to understand the realities. CSS is the most vibrant and evolving of the front-end standards. To architecture a good stylesheet takes deep understanding of the language features. Newer features like cascade layers and selectors that reduce specificity make this much easier. CSS has always been equipped to handle well organised styles, but developers who refuse to learn and respect the language have sought to push complexity elsewhere, using simplified abstractions or “CSS-in-JS” solutions. These are inherently limiting, lead to poor performance, and don’t actually solve the problems they claim. CSS should be hard and learning it will give you the ability to express creativity beyond cookie cutter web design. CSS skills will be highly desirable as more websites wish to stand out against the convergence of a generated aesthetic. Communication is a “soft skill” in short supply (for obvious reasons). It’s a great skill if you wish to stand out as an expert, or simply be heard amongst the noise. Learn brevity and focus on important points. Don’t be afraid to ask questions. Address concerns tactfully and early before they escalate. Don’t point fingers, but “cover your ass” — everyone on a project should be working towards the same goal, but some may be misguided in their approach. Remain positive and don’t meet negativity head-on. If you can communicate well you’ll be highly respected in your role. You probably weren’t expecting this one, but here we are. The luxury of not “getting political” has abated. Far-right political ideology is on the rise and dormant hatred is waking up in tech. The epicentre of fash-tech is Musk’s “X” with people like David Heinemeier Hansson spewing racism and abusing authority in communities to push an agenda, and Guillermo Rauch taking a selfie with a war criminal . Large tech giants like Digital Ocean are funding this power grab . Be wary of those denying this threat. If you want to avoid being pushed away from this industry, recognise and reject fascism before it comes for you. Don’t stay silent. I’ve covered topics that’ll see us well for the future, but what should we forget? Facebook’s experiment turned cargo cult is a legacy framework that still lingers, but there’s no reason to learn it today. React has entrenched itself as a lingua franca of code extruders. React code is generated faster than any human can possibly read it. Suffice it to say that despite stale job vacancies still demanding experience, React is not worth investing time. The days of high-paying React development are numbered. GitHub is now a liability. For private repositories use self-hosted git forges. I’d recommend Forgejo . One of the many Tailscale-like services is an easy way to gate remote access. Don’t make stuff public for the dead internet to attack! For CI/CD go local too, or use independent services not tied to tech giants. Take the time to learn basic commands. A little technical and infrastructure knowledge goes a long way. These people are handsome, charismatic, highly personable. I’m talking about: developer relations, youtubers, start-up founders, etc. When the tech industry met us halfway, influencers were entertaining and a good chinwag at after parties. Now the game has changed and we should not allow false narratives to dominate and dictate a closed-web future. Normal people still use the web. Incredibly few can afford to pay for the novelties that influencers peddle. Their attention economy is no longer our concern. So that’s my focus for a sustainable web career, when all this blows over. Remember that above all else: the web is a human creation for human needs. Those needs are not going anywhere. Drop the dead weight accumulated in times of prosperity. Go back to basics and position yourself well for when professional demand returns. Thanks for reading! Follow me on Mastodon and Bluesky . Subscribe to my Blog and Notes or Combined feeds.

0 views
Chris Coyier Yesterday

Glasses

How it started: you ever get to your mid fourties and have your eyesight drop off a friggin cliff How it’s going: This is my prescription: I think it means nearsightedness. I’m mostly fine with close-up objects (like my phone/computer), but things 10+ feet away are blurry. The glasses help! Nice for driving and being inside large buildings. As my vision got worse, I honestly thought I just had watery eyes a lot, and that caused the blur. I got prescription sunglasses, too. I got a buy-two discount from Warby Parker, where I went in person to pick out glasses, plus my insurance covered part of it. It was a fairly nice experience, and the glasses arrived relatively quickly. I already want to buy an alternate pair just for styling options. I’m trying to ride the big change to my face with an attitude change too, leaning into the “personality-free dad in the school drop-off line” I was born to be. OK, I’m off to make banal comments about newspaper headlines over white toast.

0 views

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “ Rey ,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing , which manufactures the fleet of planes used by the employer of Rey’s father — Royal Jordanian Airlines . The logo for Jeppesen ForeFlight, a business unit divested last year by the aerospace firm Boeing. On October 3, Reuters cited three unnamed sources saying a suspected ShinyHunters member in Amman named Saif Al-din Khader was detained by Jordanian authorities and was cooperating with the FBI. KrebsOnSecurity identified Rey as Khader in a November 2025 profile , in which the young man admitted working with multiple ransomware groups. Rey was featured again in a September 28 exclusive about the Dutch police arresting 24-year-old convicted cybercriminal Pepijn van der Stap on suspicion of aiding in data thefts and extortions by ShinyHunters. The story noted that immediately following the Dutchman’s arrest on the evening of September 15, Rey assumed control over the ShinyHunters brand and boasted publicly about stealing highly sensitive data from the FBI and extorting the ransomware group Cl0p . Rey taunted both the FBI and Cl0p with memes posted to his longtime account on Twitter/X, while simultaneously including images of the avatar used by Van Der Stap’s former hacker alias “ Umbreon ” in an apparent attempt to frame the Dutchman for both hacks. A taunting meme uploaded to Twitter/X by Rey on Sept. 22. A giant sized version of the Pokemon character Umbreon can be seen in the bottom left. As noted in our September 28 report, ShinyHunters gained access to the FBI site and other victims by exploiting a vulnerability (CVE-2026-35273) in PeopleSoft , a software-as-a-service platform from the tech giant Oracle that is broadly used by companies to manage hiring and human resources, benefits and payroll. Oracle quickly issued a fix for CVE-2026-35273, which ShinyHunters first began exploiting as a zero-day in June, and at the time Mandiant released web application firewall rules intended for organizations that couldn’t apply the security update quickly enough. ShinyHunters told BleepingComputer in June that the original goal behind exploiting the PeopleSoft vulnerability was to breach the FBI’s own PeopleSoft database, but the hackers said those attacks were unsuccessful for some reason. In recent weeks, however, ShinyHunters turned to a well-known URL-encoding trick to bypass Mandiant’s suggested web application firewall rules. In a report released Sept. 25, security experts at Mandiant and the Google Threat Intelligence Group (GTIG) confirmed that ShinyHunters had mass-exploited the PeopleSoft vulnerability to steal data from dozens of systems across a range of industries, including higher education, technology, healthcare, agriculture, transportation and government. Reuters reported October 5 that the FBI has removed a contractor at Accenture over their failure to patch the FBI recruitment website hacked by ShinyHunters, which exposed sensitive data on more than 5,000 FBI personnel, including each’s person’s unit and specialization, as well as medical and psychiatric records. According to two sources familiar with the ShinyHunters investigation, a navigation and digital aviation unit recently divested by the global aerospace company Boeing was among the victims that ShinyHunters was in the process of extorting when Rey was apprehended by Jordanian authorities. Those sources said the FBI’s investigation into ShinyHunters gained renewed urgency with the group’s attempted extortion of the former Boeing unit, which allegedly included the theft of sensitive information that sources said could pose operational safety and security risks. In a brief statement shared with KrebsOnSecurity, Boeing acknowledged the extortion attempts by ShinyHunters, and said the incident concerned data stolen from Jeppesen ForeFlight , a subsidiary that Boeing sold in November 2025 to the private equity firm Thoma Bravo for $10.55 billion. “We are aware of claims by a threat actor regarding data allegedly associated with Boeing and our former subsidiary Jeppesen ForeFlight,” a Boeing spokesperson shared. “We are actively reviewing the matter with the Jeppesen ForeFlight team.” A spokesperson for Jeppesen ForeFlight shared a written statement in response to questions, saying the company has seen no impact on their end. “Based on our investigation to date into this claim and proactive security posture, there was no impact to our operations or products.” Rey’s alleged involvement in attempting to extort the former Boeing unit is noteworthy because there is strong evidence that his father works for Royal Jordanian Airlines , which is mostly controlled by the Jordanian government and operates its long-haul fleet on passenger planes built by Boeing. Rey claimed on Telegram in early 2025 that his father was an airline pilot, although that could not be independently confirmed. However, as noted in our November 2025 profile of Rey , his family’s shared computer was at one point compromised by password-stealing malware, and the data collected by that malware clearly shows Rey’s father used the same credentials to log in at multiple online portals for Royal Jordanian Airlines employees. Royal Jordanian Airlines has not yet responded to a request for comment. In advance of our September 28 story, KrebsOnSecurity once again emailed Rey’s father to seek comment and update him on his son’s alleged activities. Neither of the Khaders have responded. But just hours after that request was sent, Rey began deleting his various social media accounts, including the Twitter/X account he previously used to taunt the FBI, Cl0p, and other ShinyHunters victims. Rey may have nixed many of his social media profiles, but his cybersecurity blog on GitHub somehow escaped the purge, and it shows that Rey was fixated on the leaders of the Cl0p ransomware group. In March 2026, Rey’s blog featured a lengthy post that identified two Russian men as the core developers and hackers behind Cl0p. Rey’s blog on GitHub. This post doxes two Russian men as the core operators behind Cl0p, one of the oldest and most established ransomware groups still in operation today. Meanwhile, news outlets in the Netherlands reported explosive new allegations leveled at Van der Stap, whose supposed personal transformation from convicted to reformed hacker has been widely covered in the tech news media. The Dutch daily RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate at least two murders. According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks. Van der Stap was released from prison after serving the better part of a four year sentence for data theft and extortion activity that prosecutors said netted between €1.5 million and €2.7 million. In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company Neo Security , saying the job involved probing client networks for security vulnerabilities. Neo Security’s owner Benjamin Korper told Reuters he has hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but that so far investigators have found no evidence he acted against his employer or clients. Korper said Dutch forensic investigators visited his office on September 15, the night Van der ⁠Stap was arrested in a dramatic police raid that reportedly involved flash bang grenades . A screenshot of a Sept 16 story by the Dutch news outlet at5.nl, describing a police raid on Van Der Stap’s residence that reportedly used flash-bang grenades. Prior to his first arrest in 2023, Van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD) — even as he was hacking into and extorting a number of large organizations. When asked in a recent interview why anyone should believe the word of a self-described “reformed” cybercriminal who had so casually deceived countless friends, co-workers and journalists for years, Van der Stap replied that his work spoke for itself and there was nothing he could say that would convince his worst critics. “You can throw a bunch of nice words at someone, but you can’t convince them if they don’t want to be convinced,” Van der Stap told KrebsOnSecurity on Sept. 9. “I’m doing what I can to repay victims, and that’s all I can do. If someone doesn’t want to believe me, then that’s on them.” Cybercriminals aligned with ShinyHunters have been responsible for dozens of data breaches involving billions of stolen records, and breaches claimed by the group stretch back to at least 2019. But experts say the people recently operating behind the ShinyHunters name are not the same core members that populated the group in its early days, most of whom are French citizens who have been arrested (if not also imprisoned) on at least one prior occasion for alleged cybercrime activity. More to the point, ShinyHunters has become something of a franchise. Think the Dread Pirate Roberts character in the 1980s cult movie classic “The Princess Bride,” only succession by death is replaced with succession by arrest, and there can be multiple simultaneous Dread Pirate Robertses. Sources close to the investigation say the FBI is focusing on a remaining handful of cybercriminal freelancers or affiliates who have been feeding the group stolen credentials to various software-as-a-service (SaaS) platforms used by major companies in exchange for a cut of any data ransoms later paid by victims. In the days after the news broke of Van der Stap’s arrest, a cybercrime-focused chat server on Telegram that was allegedly operated by Rey erupted with hot takes, with most participants heaping ridicule on the teenage hacker after he publicly backed down from threats against the FBI and Cl0p, and again when the ShinyHunters’s darknet website suddenly went offline . Several commentators accused Rey of resurrecting the ShinyHunters brand after its core members were rounded up in France, and making a mockery of the group’s name and reputation ever since. “He bought the old forum PGP key and used it to make new Breachforum websites and Telegram channels larping as ShinyHunters to ransom companies and then sell the used data or resell his forum when he goes broke,” one member recounted. A relatively new Telegram channel called “The Battle” has been doxing and needling Rey and other alleged ShinyHunters members for several weeks, and it has gained a considerable readership among the cybercrime communities operating on Telegram. One of the coordinators of that harassment campaign repeatedly portrayed Rey as clueless greenhorn who sought to ride the coattails of a cybercriminal brand that has long enjoyed a reputation for ruthlessly selling or publishing data stolen from victim companies who refuse to give in to extortion demands. “Rey (Saif Al-Din Khader) made a serious mistake when he started pretending to be a member of ShinyHunters,” wrote the administrators of The Battle server on Telegram. “That group had already been dismantled, with many of its members either arrested or imprisoned, yet Rey still chose to use its name while carrying out his crimes. We’re aware of claims that [Rey] caused over $200 million in damages and helped around 5–6 friend groups in the community make money by using Shiny Hunters group aliases to negotiate deals for a 25–30% cut over the past few months.” In an interview with The Register , ShinyHunters claimed they hacked the FBI to counter the agency’s narrative in a May 2026 alert that advised victims against paying a ransom to the group, which came off looking unprofessional and capricious in the FBI’s advisory. A flash notice on ShinyHunters released by the FBI on May 15, 2026. The public notice warned the group has been known to pursue a number of different victim harassment strategies , from sending threatening text messages and phone calls to victims and their family members to in some cases swatting victims. The FBI warned ShinyHunters members “may also falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” The hackers told The Register their attack on the FBI “demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.” At the same time, the group’s leaders seemed to acknowledge that the FBI’s warning materially harmed their prospects for convincing victims to pay, saying “this was fundamentally a public relations and marketing initiative for our business.”

0 views
Kev Quirk Yesterday

My Hobby Is Learning

I've had lots of hobbies over the years. To name a few off the top of my head, there's been fish keeping , guitar, harmonica, fountain pens, watches, motorbikes, this blog, web development, 3D printing, tattoos, digital minimalism, table tennis, and many more. Some of my hobbies have stuck, but I've never gotten so enthralled into a hobby that I become obsessed. Instead, there's generally 4 steps in the process: I don't always get to step 4. For some hobbies, like watch collecting and motorbikes, I continue to invest some time and money into them, and they continue to bring me joy. But I'm not obsessed. I see someone wearing an interesting watch; it piques my interest and we can have a conversation about it. But I'm not the type of person who can tell a watch brand from across a room (unless it's a Casio). Similarly, I love riding and working on my motorbikes - both bring me genuine joy. But I'm not the kind of biker who has to get out on their bike as much as possible, where driving the car is some kind of punishment. I enjoy driving too. While walking the dogs this morning I was idly thinking about all the random possessions I have scattered around the house that are the culmination of many abandoned hobbies. I started to think about why that is, and it dawned on me… It's not guitars, or harmonicas, or fish, or motorbikes, or watches, or anything else. It's learning about those thing that I find so enjoyable. It's the nitrogen cycle of an aquarium . It's learning to place your fingers at the right part of the fretboard on a guitar. It's learning to ride a motorbike safely and smoothly through some technical twisty roads, or learning how a clutch works and how to strip it down. It's learning. Learning is my hobby. And once I've decided I've learned enough about a topic, I'm good. I don't want to be the next Eric Clapton , Valentino Rossi , King of DIY , or Teddy Baldassarre . I want to be good enough at those hobbies, then move on to the next thing I can learn about. I think that's why computers have always interested me, because there's always something new to learn with them. So in future, instead of going neck deep and spending money on the next frivolous hobby, maybe I'll just spend some time learning about the thing to see if that satisfies my learning hobby. It probably won't though, as I'm something of a magpie when it comes to shiny things. But hey, at least I'm having fun and I'm not hurting anyone, right? Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️ You can reply to this post by email , or leave a comment . I decide I want to take up a hobby. I read, watch videos, and obsessively learn about the topic. Invest lots of time and/or money into the hobby. Decide I've learned enough and move on.

0 views
Stratechery Yesterday

Apple and LG, The House For Everyone Else, Agent Standards and Amazon

Apple is taking a smarter approach to the home than I expected, leaning into integration (with partners); then, what Amazon should do about agents.

0 views
DHH Yesterday

Redundancy is the engine of progress

In the 18th century, 90% of Americans worked in agriculture to feed themselves and the nation. Today, it's around 1%. In the 1950s, there were hundreds of thousands of telephone switchboard operators. Today, they're all gone. There used to be well over a million professional typists too, but word processing largely killed those jobs as well. This is what progress usually looks like: redundancy. Technological advancement has always rendered some jobs unnecessary. That is literally the progress! Freeing humans from a class of work that used to consume their time and talent so they can pursue new problems. Individually, this isn't a picnic. I'm sure lots of the farm laborers displaced by the combine harvester didn't much care for "progress". They cared about having a job. Same too for the switchboard operators and typists. This isn't just a history lesson either. The Minneapolis City Council just voted to require self-driving cars to have a human "safety monitor". Lots of jobs are on the line if cabbies are no longer necessary! Thankfully, the mayor vetoed it. But note that New Jersey still requires a trained attendant to pump your gas. This kind of job-protection thinking is widespread. So it's not hard to see why some programmers are on edge about agents, given the historical precedent of technological progress creating redundancy. But I don't actually think the majority of them ought to worry. With the price of software creation cratering, we're likely to see an unprecedented bloom in apps and services. There's still so much paperwork and other white-collar toil we could automate, and we'll still need agent wranglers to do the work. What is entirely possible, however, is that some companies won't need as many programmers as they did before, while others will hire their first programmers or staff up dramatically. It's very unlikely that the labor market for programming will remain static given the magnitude of this paradigm shift. But, again, that's the progress! That isn't a license to be glib about it. We all need to live. We all need to eat. What's good for humanity at large in the long run may well be temporarily tragic for the individual in the short run. Sympathy and compassion are in order for anyone affected by the changes. Just don't end up like the Minneapolis City Council and think you can legislate progress to a halt. That has never worked.

0 views
Daniel Mangum Yesterday

What's on that Access Port?

In my last post, I wrote about debugging the Nordic Semiconductor nRF54LM20 when a peripheral, specifically the Key Management Unit (KMU), writes directly to memory while the CPU is halted. Or I should really say that I wrote about debugging the application core (Cortex-M33), as the nRF54LM20 also has a RISC-V coprocessor (VPR) referred to as the Fast Lightweight Peripheral Processor (FLPR). Around the time that Nordic announced the VPR core, I wrote two posts; one about its architecture and the other about how communication works between it and an application core.

0 views

Twenty-two pending curl vulnerabilities

On October 14 2026 we will ship curl 8.23.0. The next iteration in the never-ending series of version bumps from the curl project . We always think of the next release as the best version we ever did – and this time is no exception. Decades of collected experiences and meticulous polishing has lead us to this. We decided to shorten the release cycle this time, so that we can release 8.23.0 a few weeks earlier than what we originally planned. We took this decision after we received one particular vulnerability report that highlighted a rather significant flaw. We will ship a new version with this problem removed, together with twenty-one other albeit less serious security vulnerabilities addressed. In the curl project we only assign one of the four different severity levels on all CVEs we report (LOW, MEDIUM, HIGH or CRITICAL), as we basically don’t believe in CVSS scoring . We have only published two CVEs with severity HIGH since 2021, the most recent one being CVE-2023-38545 ; that could lead to a heap buffer overflow. Now we are about to release another one: CVE-2026-92392. All details about CVE-2026-92392 will become public in the European morning of October 14, 2026 in synchronization of the release of curl 8.23.0 which of course will have this problem fixed. We will ship updated Rock-solid curl versions in sync with this. For the safety and security of curl users everywhere (and frankly, all the infrastructure that uses curl), no details of this flaw will be made public before this date. We will alert the distros@openwall mailing list and paying curl support customers about this problem (and the associated fix) ahead of time. I will follow-up with a separate blog post after October 14 to describe this flaw in detail. How it can be triggered, why it isn’t quite the end of the world and what we do in curl to fix this and similar classes of problems.

0 views
Sean Goedecke Yesterday

How to read code

Everyone knows how to read a book. Beginning at the first page, you read each word in order 1 , stopping periodically to think, until you arrive at the last word on the last page. That’s how you read a newspaper article, or a poem, or an email. Why would reading code be any different? English text is designed to be read in order. In fact, there are almost no constraints on the order of a text aside from how you want the reader to consume it. In writing this post, I could put the ideas I want to convey in any order I like. Code, on the other hand, is designed to be run by a computer. The order is thus primarily determined by non-human factors. I cannot simply move 2 a line of code to the beginning of a file or function because I think it provides a better introduction to the program for human readers. The other big difference is that English text is always read as a final product, while code is usually read as a diff . We software engineers spend most of our time reading subtle changes to existing code, not brand-new programs. Imagine if reading this post was like that. You would read each successive draft in the order I wrote them, consuming the post as a changed sentence here and a new sentence there. It would be easy to lose track of the overall flow. The third reason — and I say this as a lover of literature and poetry — is that code is much more structurally complex than English texts. Even famously difficult books are syntactically simpler than most computer programs (for instance, grammatical dependencies are largely bounded by a single paragraph, while code dependencies can stretch across the entire codebase). Their primary difficulty lies in understanding the nuances of human nature being discussed, not in understanding what each word’s grammatical function is 3 . Large codebases are also just longer: War and Peace contains around 600,000 words, while most large modern codebases have that many lines . As I’ve said many times , large computer programs are simply too complex for a single person to fully understand. Reading code in a large program is thus a process of compromise : of deciding which parts to thoroughly grasp and which parts to gloss over; or of portioning out your finite mental capacity across the codebase. Because of all this, most people read code very badly . They struggle through it front-to-back, like a book, and lose track of the execution flow. Or they just read through the diff and miss the significance of un-edited parts of the code 4 . Or they simply are defeated by the complexity, give up and just guess what it means. How can you do better? The best article I’ve read about reading code is this piece about reading mathematics papers, which have a similar structure. The author describes a technique called “dyadic scanning”. Instead of reading slowly and sequentially, you make several passes: first to figure out the overall structure, then the sub-structure, and then finally the details. For code 5 , this means reading out-of-order. I like to pick an important path (say, the happy path for the feature introduced in the diff) and trace through which functions are calling which other functions, just to get a sense of the flow. Only once I’ve got a good sense of that do I pay close attention to what those functions are actually doing. Usually I do multiple passes, each following a different thread. I’ll take a function or a piece of data and try to figure out how it’s used, fanning out to multiple call-sites (including ones outside the diff) as I go. For small diffs, I just ctrl+f for the function name to jump around; for large diffs, I open it in-editor and ctrl+click for easier navigation. I try to be ruthlessly focused on just the thing I’m looking at right now: everything else gets treated as a black box. Once I’m confident I understand the diff, only then will I sit down and carefully read it end-to-end. The purpose of that read is less to learn about the structure — which I should already know by this point — than to catch any weird bits of code I hadn’t noticed in previous out-of-order passes. If I do see anything unusual, I then go back to doing passes. This might sound slow. But in fact each pass is very fast, since I’m not painstakingly puzzling through each line of code. Many people are now saying that you don’t have to read code anymore: either because LLMs now produce reliably high-quality code without oversight, or because you can simply ask a reviewer LLM to read the code for you. I think both of these ideas are false. Obviously the quality of LLM code is context-dependent. As I wrote in Pure and impure software engineering , some software fields (game development, libraries, tools like databases) have wildly different engineering standards, practices and values to other software fields (say, distributed systems at big tech companies). If you’re just making a tool for yourself, you probably don’t have to read the code if you don’t want to. But having read a bunch of AI-generated code this year, I can say that you definitely still have to read it. I routinely find massive errors in AI-generated code. These are not bugs — the code typically does what the AI wanted it to do — so much as they’re problems of alignment . As a recent example, a small change to thread an extra value through some existing code ballooned out into a complex three-thousand-line diff, because the agent noticed a race condition and built a complex machinery to “fix” it. In fact, this race condition was harmless by design: two pieces of unrelated data could become briefly out of sync, with no customer impact. Can LLMs just read the code for you? No, for the same reason: even if they make no mistakes, their technical values will not match yours or those of your company. You can still use LLMs to help you read code, but you have to carefully read and review that LLM output, and you should also be carefully reading the code itself. This is in fact not how many people read in practice. It’s common to skip words or even whole paragraphs due to inattention, or to read an entire book without taking the time to think about it. But at least in theory everyone agrees this is how you should read. Of course, you can do some of this some of the time (more so in some programming languages than others). But the primary constraint is the computer. It is more important that code compiles (or runs without syntax error) than it is for that code to be readable. I don’t wish to understate the importance of syntactically parsing great literature, which I think is both difficult and an underrated skill. For example, I read through the first scene of Hamlet until I saw: “Sit down awhile / And let us once again assail your ears / That are so fortified against our story / What we have two nights seen.” Even a single sentence like this takes work to determine that “That” refers to “ears” and “What” refers to “story” (or, equivalently, has an implied “with” preceding it). And just as one function can have many scattered callers, one sentence in a text can alter the significance of many others. In a previous post, I labeled this the main mistake that most engineers make in code review. Here I’m talking about a meaningful diff: something that touches a few hundred lines or more. Trivial diffs can be read end-to-end. This is in fact not how many people read in practice. It’s common to skip words or even whole paragraphs due to inattention, or to read an entire book without taking the time to think about it. But at least in theory everyone agrees this is how you should read. ↩ Of course, you can do some of this some of the time (more so in some programming languages than others). But the primary constraint is the computer. It is more important that code compiles (or runs without syntax error) than it is for that code to be readable. ↩ I don’t wish to understate the importance of syntactically parsing great literature, which I think is both difficult and an underrated skill. For example, I read through the first scene of Hamlet until I saw: “Sit down awhile / And let us once again assail your ears / That are so fortified against our story / What we have two nights seen.” Even a single sentence like this takes work to determine that “That” refers to “ears” and “What” refers to “story” (or, equivalently, has an implied “with” preceding it). And just as one function can have many scattered callers, one sentence in a text can alter the significance of many others. ↩ In a previous post, I labeled this the main mistake that most engineers make in code review. ↩ Here I’m talking about a meaningful diff: something that touches a few hundred lines or more. Trivial diffs can be read end-to-end. ↩

0 views
Evan Schwartz 2 days ago

Scour - September Update

Hi friends, In September, Scour scoured 1.2 million articles (up from ~880,000 in August) from 28,568 feeds . Also, welcome to the 116 new users who signed up since my last product update email! Here's what's new in the product: You can now find all of your saved, loved, and liked posts, as well as your full reading history, in the Library section. Also, if you click Read on Scour for any article, that page now has tabs for the article's content, other posts that it cites and that cite it, and the feeds it was found in. Here's an example for a widely cited post. Scour now tries to determine the level of expertise each post assumes and infers the level of expertise you have per topic (based on the wording of your interest is and the types of articles you click on or like). At least for me, this means I'm seeing far fewer beginner Rust questions from Reddit showing up in my feed. (For those in tech, this is powered by Jev.) Scour's Search will now show you results for feeds and authors, in addition to posts that match your query. Relatedly, you can now follow individual authors as sources and Scour will try to show you their posts from any website they publish on. Scour now detects and hides more junk, ranging from sales pages and SEO garbage to uninformative link roundups and low-value discussion threads. You should see more high-quality content in your feeds. By my current count, about 1 in 10 posts being shown before was some kind of junk that Scour now hides. I continue to obsess over making Scour feel super fast and snappy. In September the slowest feed loads got about 7x faster (p99 went from 2.1 seconds to 282 milliseconds) and the median feed load time got 2x faster (p50 went from 90 ms to 40 ms). This is also while ranking about 1.4x as much content as the month before. Unfortunately Reddit announced their plan to turn off RSS feeds on November 13th . This is how Scour checks which discussions are happening on Reddit and finds articles posted on different subreddits. After November 13th you'll no longer see links to the Reddit discussions from Scour 😢. Here are some of my favorite articles I found on Scour in September: Happy Scouring! - Evan The biggest news in the tech / AI world was the release of TypeSafe's Jev model . These were some of the related articles that I found interesting: The Latent Space interview with TypeSafe's CEO, Jev: System One models for Prod, not God — with Diogo Almeida, CEO, TypeSafe AI . Fingerprints of Jev and Jev's Architecture Unmasked were interesting black box investigations into Jev's base model using the tokenizer and other externally visible properties. Sixteen Models Walk Into a Storefront gives a very nice breakdown of techniques that can be used to manipulate LLMs' assessments of which products to buy and how much to pay for products. Logo Design Trends in 2027 Favor Marks Someone Can Prove They Made . In the age of AI-generated glossy slop, this is no surprise, but it's a nice write-up. The engineering behind the US Strategic Petroleum Reserve . Quite random but an interesting read. I Judged My Mum for Overusing AI, Until I Caught Myself Doing Worse . I continue to appreciate Sid's commentary on the age of AI. This is very relatable.

0 views
Brain Baking 2 days ago

Homo Irrealis

André Aciman’s Homo Irrealis leaves a strange feeling lingering long after I put down the book. The irrealis aspect of his essays comes across as an aggressive and rather depressing form of nostalgia, where the temporal context is heavily skewed towards the past. André describes it as follows: imagine a heartfelt moment with your lover, perhaps on a special occasion. Instead of savouring the moment, you imagine yourself well into the future, looking back at this moment with nostalgic feelings. That alone took a while for me to understand: you’re creating future moments of nostalgia with every significant moment, yes, but why would you be deliberately thinking about a future where you’re looking back at his moment instead of just being in the now? Exaggerating this further, a constant yearning for the past to the point that you attempt to retread your (or someone’s) exact steps will always result in disappointment. Aciman often tried to visit the New York he experienced when watching a seventies movie. But that version of the city was an imaginary one where imperfect parts of the place have been expertly brushed up to deliver a great picture. When Aciman tries to locate an apartment where a scene from a movie took place, he realises that the building has been torn down a long time ago—heck, even the entire neighbourhood is gone and replaced by a more modern version of tall concrete. It gets worse: some buildings never even existed in that city. For the purposes of a movie, streets and facades can be rebuild and completely altered—in Hollywood, not in New York city. Miles away from the city you live in and you think evokes pure nostalgia because of those magical moments in the theatre. That yearning is dangerous, and yet, thousands of tourists travel all over the world to retread the steps of their favourite author/actor/whatever: visiting their grave, their birthplace, the studio they worked in, the school they spent time in. Homo Irrealis is full of these brain twisters where Aciman identifies with an actor in a movie that in itself is already filled with irrealis moods , where the things that are being discussed have not happened and might never happen—yet they’re discussing it as if it already happened and looking back on it. My brain hurts. To my big surprise, I often catch myself in an irrealis mood. If I’m unsure to take up that job offer, I imagine myself doing it and try to reflect “back” to evoke a feeling: will I like this? Do I see myself doing this for a long(er) time? Suppose I take this, will this make thing a and b less painful? If I say yes to this offer to give a talk, how would I look back to having given the talk? I gave a sourdough bread baking workshop last weekend and always regret saying yes at first because an event like this in the weekend causes logistical problems for parents with young kids. Yet I’ve been doing this for more than ten years and I just know the participants will be enthusiastic and I just know I’ll bike home with a big smile on my face. Thinking about that makes the initial reluctance disappear. Technically speaking, that’s an irrealis mood, since I’m reflecting on the workshop being done before it took place and how I feel having given it. But since I’ve gone through these many times before, I guess it’s less problematic? What I take away from André Aciman is that indeed, irrealis moods can be problematic as we can get stuck in the future of the past (huh?) without just enjoying the ride. I guess the main perpetrator here is again restorative nostalgia. I stumbled upon Aciman’s book by sheer luck: it was set on display in a second hand book store and somehow attracted my attention. Hoping to extract some philosophical guideline on how to contain and constrain nostalgic feelings, I walk away confused. Not here nor there, what should you make of this? That the human mind is an extraordinary thing that can look into a future that hasn’t happened yet and there reflect back on this moment now as if it happened a long time ago. But to what purpose? All of us seek a life that exists elsewhere in time, or elsewhere on-screen, and that, not being able to find it, we have all learned to make do with what life throws our way. I don’t know about you, but I don’t seek a life that exists elsewhere in time. Making do with what life throws my way sounds great: making amends with making do might be my most important mission ever. So perhaps I misunderstand the entire concept. Yet an irrealis mood might help putting a currently challenging time in perspective. My kids might be giving me trouble, but I can see myself in the future looking back at this moment and thinking ah, weren’t those the days? . That might possibly even involve a bit of yearning because in that future trouble will still find us—that’s simply what life throws our way. It’ll be a different kind of trouble. But it will be trouble. Looking back at the things I have experienced, done, or not done, does not immediately invoke yearning. I’m glad many of those aspects are gone: I was happy to finally live by myself; learn how to stand on my own two feet. I was happy to let go of commuting to Brussels every day and slowly killing myself, even though working with that team was such a privilege. All things considered, I am happy to have kids now. Every part of life comes with its own upsides and downsides. Suppose that wasn’t the case, then living turns into a boring drag. Nothing to look back at in order to pat yourself on the back and say hey, I survived this. Is that part of being a Homo Irrealis ? Perhaps not. Less irrealis , more realis . Related topics: / nostalgia / By Wouter Groeneveld on 6 October 2026.  Reply via email .

0 views
Jim Nielsen 2 days ago

Apple’s App Icon HOA

Louie Mantia has a great post about how app icons are converging towards the squircle on iOS and macOS. His post reads like a history. If you’re wondering, “How did we get to a place where all app icons are becoming squircles?” Mantia’s post answers that question by starting at the beginning. It’s hard to walk away from Mantia’s article without a sense of empathy for Apple’s position, like “Oh ok, I get why they’re doing what they’re doing. It makes sense.” Apple’s direction is kind of a tacit acknowledgement to how most people are shipping app icons. Apple is “paving the cowpaths” as it were, because most app icons are just brand logos. Nowadays, it’s these bland, big-business logo icons that make up a good chunk of iOS Home Screens and macOS Docks, instead of the beautiful, illustrative app icons that used to dominate our devices. So many app icons are just logos in a squircle, so Apple made tools like the Icon Composer and glass effects to help make that approach look good by default. Apple is helping most people most of the time make app icons that don’t suck. [Apple is making] it easier for all apps to fit in on the platform, especially apps built by designers and developers who aren’t familiar with how to make an icon that looks great next to first-party icons. The net effect is: some of the platform’s best icons look worse, while some of the platform’s worst icons look better. In other words, this new approach raises the floor but it also lowers the ceiling. The thought that came to mind as I read Mantia’s post was, “This reminds me of HOAs.” I grew up in a neighborhood where anyone could do anything with their homes and yards, so you had this eclectic mix throughout the neighborhood — everything from “Wow, that house is so unique!” to “That thing is a dump.” Somewhere along the way HOAs became more prevalent (in my neck of the woods), where all the houses in a neighborhood have to meet a certain standard — and so they all start to look the same. It keeps the dumpy things out, yet nobody stands out . That’s kinda what macOS feels like right now with regard to app icons. For better or worse, squircle app icons are Apple’s HOA and we’re all just living in it. Reply via: Email · Mastodon · Bluesky

0 views
Chris Coyier 2 days ago

Kelsey

My sister is in a currently-running-on-TV political ad. It’s against the republican chucklefuck Tom Tiffany who was one of those anti-American dingleberries that claimed Biden “stole the election” and thinks Trumps tariff plans are super neato. Kelsey’s journey with healthcare insurance has been pretty rough. She gets denied for medications and treatments all the time, which to me is pure criminal behavior akin to attempted murder. Any politician doing anything other than forcing healthcare insurance companies to actually help the people they cover (ya know: Americans) can piss up a rope. She’s sharing her cancer journey herself in a multi-part series on social media sites. Like: View this post on Instagram

0 views

Credit Crunch

If you liked this piece, you should subscribe to my premium newsletter, and you can subscribe on the following links: $70 a year , $18 a quarter , or $7 a month . In return you get a weekly premium newsletter including vast, detailed analyses of NVIDIA , Anthropic and OpenAI’s finances , and the AI bubble writ large . It's a great way to support my free work, and you'll get full access to my massive archive of premium analyses of the tech and finance industry. I just did a two part Hater's Guide To AI Debt that's essential reading given the current climate around AI data center loans. On Friday, I’ll dive into the world of junk debt – or, what happens when a hyperscaler's credit rating slips into the abyss, or what might happen as a certain money-losing AI lab moves into the world of junk, building on the story I'll tell today. If you want to get in touch — and especially if you have any juicy information about Anthropic, OpenAI, or any other companies in the AI bubble — hit me up on Signal at ezitron.76. I’m also on IB on your Bloomberg Terminal.  Every day somebody asks me when or how the AI bubble will burst, what might cause it, what potential avenues I’m missing, begging, pleading for some sort of hole in the argument outside of “but what if all the bad things don’t happen and the good things are even better than we imagined?”  These questions come from everyone ranging from random internet people to hedge fund managers on my Terminal trying to squeeze me for free research, and every one carries with it some thin vein of wrongheaded hope — that there’s some subtle failure in my arguments and, in turn, some way in which this all turns out okay. Even those actively agreeing with me hesitate to follow my arguments through to their logical endpoint, mostly because doing so can make you feel a little queasy. If you actually sit and think about the consequences of what’s happening rather than just a collection of different events organized in a row that you have to remember to speak about on a podcast, it’s easy to say stuff like “ Anthropic has $413 billion in non-cancellable compute contracts ” or “ $18 billion in Oracle data center debt is trading at 84 cents on the dollar ” without ever really thinking about what any of that means.   Everyone acts as if everything in the AI boom is going to go fine, all without much consideration of the real world and its consequences for the greater tech industry. They assume that OpenAI and Anthropic will go public, grow forever, raise whatever debt they need, and that every single data center investment will work out fine. And make no mistake, these companies will need at least $50 billion or more in debt every single year, all with what will likely be low-grade junk credit ratings. It’s time to talk about why that’s very, very unlikely.  Alright kids, let’s talk about debt . Some of you are big, strong, and smart and already know this, but some of you don’t, so we’re going to all learn or re-learn together. I apologize in advance for having to go through all of this, but trust me, you want to know. Every month, the US Treasury (the part of the US government that manages the country’s money) has an auction for ten-year-dated Treasury Notes, typically referred to as “Ten Year Treasuries.” These auctions then receive bids. Regular people offer something called “non-competitive bids,” meaning they’ll say how much money they want to lend the government, and then there are competitive bids where financial institutions say “we’ll buy in at this specific interest rate.” The US government borrows over other time periods too, but that’s not important for today. US government bonds are, in general, considered “risk free,” as they’re backed by the full faith and credit of the American government. This status makes them the base for all lending, because anyone borrowing money has to compete with what the US government (or another government) offers to pay.  You’re paid your interest, in the case of the ten-year bill, every six months, with the principal repaid when the bond matures. Ten-year treasuries are considered the “ benchmark ” rate, because it’s the most actively-traded and liquid security in the world, and while mortgages in the US tend to be structured as thirty-year-long loans, most people tend to either sell or refinance their houses in the first ten years of the loan. It also represents, to paraphrase a friend in fixed-income, a period of time that’s both a long way away but not so long as to be impossible to comprehend. You’ll also notice that the “pricing” of treasuries (and bonds in general) is usually expressed in percentages rather than prices. That’s because the price of a bond doesn’t tell you how much it’ll pay you, how many payments there are left to go, or what its value is relative to other bonds. As a result, the pricing page for ten-year-dated US Treasury notes shows an interest rate — 5.33%, for example — that represents “how much money would I get on an annual basis if I invested in ten-year Treasuries today ?” based on the soup of different notes in the market based on their various maturities and interest rates.  The ten-year is considered the barometer of investor sentiment — how much the market feels comfortable lending to the US government, based on everything they do and do not know, which is why it shifts so often with economic data and the price of oil. And, importantly, when a bond “gets cheaper,” its effective interest rate goes up, because you’re paying less money for a debt instrument that pays a consistent amount.  Right now, ten-years are “selling off,” meaning that the effective interest rate on them is going up, based on a few different factors: So, while we can’t point at one reason, there are plenty of reasons that ten-years are selling off, which is in turn raising the cost of borrowing for literally everybody — consumers, hyperscalers and AI data center developers alike — in a way that’s distinctly difficult to calm down. That last part is very, very important. While stocks can recover based on good news ( even if said good news is entirely fictional ), the price of ten-year-dated treasuries is reacting to so many different economic indicators that even the things that should calm it down — like lower-than-expected jobs numbers — aren’t stopping them from dumping. And so when the ten-years dump, the base interest rate of almost everything increases, and some of the things that are becoming more expensive as a result are actively contributing to the problem. The US Government cannot afford to stop issuing debt, the wars in Iran and Ukraine aren’t going anywhere, and hyperscalers expect to issue $400 billion in bonds in 2027 alone . As a result, everything gets more expensive for everyone, and the worse your credit is, the worse this gets. So, now that we know all that, we can speak to the larger problem. When somebody borrows money, they do so priced at a “spread” above the equivalent-dated US Treasuries — usually judged based on the underlying economic health of the company, the general vibe about the kind of thing they’re borrowing for, and the current ‘price’ (read: effective yield) of their debt, usually measured based on its “spread” from today’s US Treasury prices. This means your borrowing prices can go up based on a few factors: So if your company — say, Oracle — has a bunch of bad press about its debt being distressed , the market will “price” more risk in, selling off the current debt and pricing it as if the effective yield was higher, setting a floor for how expensive your debt will be. This floor will also increase because the price of US treasuries is likely higher today than it was when you raised. I’ll give you an example. As I discussed last week , Oracle’s $18 billion September bond sale would have (yes, the number has gone up) over $7 billion in added interest over the course of the bonds due to both the sell-off of Oracle’s debt and the overall Treasuries market.  At the time, ten-year-dated US Treasury notes were at a mere 4.13% — as mentioned above, a 0.06% increase is significant, so a 120 basis point difference is gigantic — but Oracle’s overall risk has also exploded along with them.  At the time, spreads were between 105bps and 165bps (so 1.05% to 1.65%) above US Treasuries. Today, those spreads range from 171bps to 282bps, a double dose of pain at a time when  the market sentiment is that it doesn’t trust Oracle as much as it did in September — as in how much more it’s demanding over the benchmark rate offered by the government — has increased along with the cost of the benchmark itself.   And so, while I’m not going to repeat everything I went over last week , the point I’m making is that anyone raising any AI-related debt is going to get shafted by both overall Treasury prices , sentiment around AI in general, and their own specific financial situation. Yet Oracle is, at least for now, “investment grade,” which means that even though its debt “trades like junk” (IE: investors are asking for effective yields of anything around the high-yield index’s average of 8.2% ) , it’s in a much better position to borrow than the vast majority of AI data center SPVs or neoclouds like CoreWeave, which has Goatse-level spreads of 672bps to 882bps, with the effective yield on its shortest-dated debt (four years) sitting at 11.53% and its longest-dated (a mere six years) sitting at 13.49%. There are, of course, ways around borrowing on your credit profile. For example, when CoreWeave opened an $8.5 billion delayed draw term loan facility in March 2026 , it was able to get it rated as investment-grade and at SOFR (the percentage on overnight borrowing from the Fed for banks) plus 2.25%, all because the counterparty was Meta, and thus the underlying payments would be considered “safe.” This may seem like the cheat code to get around all these horrifying rates, except CoreWeave, per analysts at UBS, needs to raise $102 billion in debt through 2030, which means it will have to keep raising on its own two feet. Well, there’s a problem there. Per The Information , “cracks are beginning to form” in the AI data center debt boom: Long-term Zitronistas will remember when I brought up some of these names in my end-of-year-2025 piece The Enshittifinancial Crisis , with SMBC present in seven and MUFJ present in seventeen of the data center deals I analyzed, with one or both of them in effectively every Stargate and CoreWeave debt sale, and both involved in SoftBank’s $15 billion 2025 bridge loan . “More selective” doesn’t necessarily mean “done investing,” but is more akin to the lights going on in a particularly-rowdy party and seeing who may or may not have pissed themselves. Data center debt is now pricing based on increasingly-sour sentiment driven by power delays, local pushback and a general anxiety that maybe these debts won’t actually get paid. They also might realize that their due diligence was lacking when it came to building some of the most-ambitious infrastructure projects in history . Here’s an example of how deep the due diligence was for Blue Owl’s $10 billion investment in AI data center projects, per The Information :  In any case, AI data center debt is way more expensive now by virtue of the current state of treasuries, with costs compounded by the anxiety around them in general.  This means that any “virgin” projects — those that aren’t directly backstopped or co-signed by hyperscalers — are guaranteed to hit egregiously-high, 9% to 14% rates, which makes ( as I discussed a few weeks ago in my two-part debt series ) it near-impossible to make the already-questionable economics of running a data center work.  This means that any AI data center debt being raised right now is doing so under stricter credit conditions and doing so at unrealistic, unsustainable prices, if they’re going to be able to raise at all. This makes the $174 billion in debt that SB Energy needs to raise to fund its theoretical data center project with OpenAI — even when backstopped by NVIDIA — either horrendously expensive or impossible to complete, as does it mean that any future large, multi-gigawatt projects will add billions of dollars in interest payments to already-expensive debt. This all makes pontifications that data center spending will increase to $32 trillion by 2050 equal parts stupid and wasteful, on top of the overall problem that there isn’t even enough demand right now for hyperscalers to break even on their 2026 and 2027 capex plans .  Yet data centers are buildings with stuff in them that, in theory, could be repossessed and leased to another party — or at least sold off — in the event of a default. Investors would theoretically get some sort of return (based on the seniority of their debt, but that’s not important right now) if CoreWeave died, or if Oracle’s Project Jupiter (the one connected to its “Force Majeure” notice ) failed to secure power. We’ve got another problem on the horizon, and nobody seems to be talking about it. Back in June , Anthropic President Daniela Amodei said the following at a conference: Quick question, Daniela: are they?   Nobody seems to want to talk about what Anthropic’s plan is once it goes public as far as continuing to raise egregious amounts of capital. Once a public company, Anthropic will no longer be able to raise venture capital at its current scale (over $95 billion in 2026) alone, and if it intends to raise even half that much on a yearly basis , it will become one of the largest issuers of junk-grade debt in history. In both AI labs’ cases, they are most-decidedly going to be priced like junk , even if the malignant scumbags are able to con ratings agencies into giving them investment-grade ratings , because while the bond markets listen to credit ratings, they price based on what the actual company looks like , guaranteeing Oracle-esque 8% minimum yields on whatever they issue. The problem is that OpenAI and Anthropic don’t really have assets . They don’t own any of their data center infrastructure, the chips inside, or even their office buildings, and that’s before mentioning their negative cashflows and products under constant threat from cheaper open source alternatives.  This means there’s very little for the company to offer as collateral, and would be raising debt based on a theoretical break-even point somewhere in the future, one that they would both have to actually explain with a level of depth that neither of them have had to deal with.  The big difference between Anthropic/OpenAI and SpaceX is that the debt in question would be raised to fund company operations rather than capital expenditures , as training costs are not capex and at least based on OpenAI’s audited financials are considered operating expenses. While CoreWeave loses a bunch of money , those losses mostly come from the expensive debt it has to take on to fuel its capex ambitions and the depreciation of its GPUs, meaning that it has (if you remove its largest costs!) a positive EBITDA. This difference also likely precludes either company from raising capital via an SPV or other off-balance sheet funding, because those are collateralized using the underlying asset, such as Anthropic’s $161.2 billion in non-cancelable contracts to lease back Broadcom’s TPUs . Convertible bonds — low-interest bonds that can convert if a stock price is hit or, at maturity, allow investors to take stock or cash — are an option, but run the real risk that the stock is lower than when the bonds were issued, meaning that Anthropic or OpenAI would have to pony up a ton of cash. The only exception would be an SPV tied to customer payments which I’ll get to in a bit. Yet things get a little messier when you factor in non-cancelable contracts, which total $413 billion in Anthropic’s case across the next seven to ten years, guaranteeing financial strain at a time when future cashflows are far from guaranteed. Take-or-pay agreements — the subprime mortgages of the AI bubble — are considered debt equivalents in the eyes of creditors, which would in turn drag on cashflows.  You see, you can jingle the keys of "annualized run rates” and “ adjusted operating income ” in the faces of venture capitalists and journalists as much as you want, but investors require actual cashflows, even within a frothy market. Anthropic’s vulgar “ Earnings Before Training, Interest and Taxes ” measurement does not matter when the entire calculation is made on cashflows , and any attempts to act otherwise are either ignorant or deceptive. EBITDA, of course, refers to Earnings Before Interest, Depreciation and Amortization, which means that all “above the line” costs — such as inference costs, training costs, SG&A and leases — are counted, but the cost of depreciating assets like GPUs (of which Anthropic and OpenAI have none) and interest is left off. Let me give you a very straightforward example from my own story on OpenAI’s audited 2025 financials , when it had $34 billion of expenses and $13.07 billion in losses, for an EBITDA of $20.92 billion, or an EBITDA margin of negative 160%. At that EBITDA, it would immediately slam the door shut on an investment-grade rating for OpenAI or Anthropic, and likely get rated between a B (highly speculative) and a CCC+ (substantial credit risk). If ratings agencies push through at that grade, it means they are completely and utterly corrupt, and going against their own guidance about how credit ratings are provided. Every single metric underlying an investment grade rating comes from EBITDA, and SpaceX was only able to qualify through the success of Starlink as a profitable business. S&P Global also penalizes revenue concentration — specifically referring to customers or products making up a large slice of revenue. In Anthropic and OpenAI’s case, they effectively have two products — the API and subscriptions — and nearly a quarter of Anthropic’s 2025 revenue came from two customers . While SpaceX is a shitty company, it’s a diversified one. OpenAI and Anthropic are not. In any case, if either gets an investment-grade rating, it’s likely that a hyperscaler has stepped up and guaranteed some or all of the debt, but in doing so, they’d likely sacrifice part of their own credit rating in the process. The same might happen — as hinted at above above — through a rotten kind of SPV, where the hyperscaler guarantees a certain amount of contracted revenue to OpenAI, allowing a connected SPV to raise at an investment-grade interest rate.  If we assume that OpenAI or Anthropic gets a junk rating, it becomes entirely-unable to raise from the investment grade market, leaving it with dwindling options based on how junky that rating is. The problem they face there is that even the highest-rated level of junk (BB+) requires sustained cashflows, and even lower rungs like B+, B and B- need some sort of path to EBITDA positivity.  Each level of junk grade carries its own limits in both how much money they could raise based on their particular financial profile and the hard-and-fast rules of various funds investing in high yield debt.  When I say “CLO-eligible term loans,” I’m referring to collateralized loan obligation funds that scoop up large buckets of loans and resell them as one investment vehicle, buying somewhere between 60% and 75% of corporate loans . These CLOs also have their own rules about exposure to debt based on various factors, including industries and credit rating, and depending on where OpenAI or Anthropic fell, the demand for their loans — and secondary sales of their loans (because investors LOVE to resell debt!) deteriorate dramatically based on their rating. The following assumes a $2 trillion valuation, which is far from a foregone conclusion. If we assume $50 billion is what they need on a yearly basis, this becomes increasingly difficult based on the credit rating. As you can see, debt alone isn’t getting these companies $50 billion a year outside of a rating that’s near-impossible outside of ratings agencies defaulting on their jobs. In theory, at a $2 trillion valuation, both Anthropic and OpenAI could sell directly onto the market, but using this as a serious ongoing funding mechanism naturally depresses the price, though the scale of the float — as in how many shares were sold at the IPO.  At that valuation and a planned raise of $60 billion to $100 billion , Anthropic will have a very small float — around 5% — which would mean it was naturally capped on how many shares it could dump in a particular year. It’s hard to gauge this based on the unknowns of its trading volume, but if I had to guess, there’s maybe $20 billion in annual share sales it could do. Ahhhhh HHHH FINE YOU WANT TO TALK ABOUT UBER SO BADLY WE’RE GONNA TALK ABOUT UBER AND AMAZON AND TESLA! I’ll add that both Anthropic and OpenAI want to raise $50 billion at IPO.  In other words, stop making these comparisons, they are not accurate. I realize I’ve gone through a lot of technical stuff so far, but the reality is pretty simple: Anthropic and OpenAI do not resemble the financial condition of any company I could find in the history of the stock market outside of WeWork. They are unprofitable, unsustainable, and the only conditions under which they could raise significant debt would involve catastrophic failures of regulatory and ratings bodies.  I’ll add that the only thing worse than allowing them to go public will be to allow them to raise debt at anything other than the junkiest levels that the market has to offer. These are not stable businesses, nor are they run with much regard for their underlying capital or employees. Both of them have massive amounts of concentration risk , unstable customers , brittle economics, own virtually no assets, and have demonstrated little to no ability to reduce their costs outside of questionable accounting that doesn’t change the fact that they cannot afford their bills. As a result of their $1.3 trillion in compute commitments, neither company can become “capital efficient” by cutting their training costs, because said training costs are the only means of further growth outside of massive price increases that are unlikely to grow their businesses. To make matters worse, both are cutting prices to compete with each other, and per Ramp , said price cuts aren’t increasing usage: Neither company can afford to exist without near-infinite resources, and neither company can afford to slow down due to their massive compute commitments, which have become materially linked to the future growth trajectories of effectively every hyperscaler, as well as Broadcom, which — in pursuit of becoming NVIDIA — has added ruinous amounts of debt at the worst time in history to do so. And that’s really the biggest problem here. While Anthropic and OpenAI are yet to pillory the debt markets, their counterparties — and those inspired by them — have been doing so for years with little or no return on investment. As I discussed a few weeks ago , there are currently over $200 billion of NVIDIA GPUs sitting uninstalled in warehouses, with Morgan Stanley ( as found by Bryce Elder of the FT ) estimating that more than half of GPUs sold in 2026 through 2028 won’t have anywhere to plug in. Hundreds of billions of dollars have been spent on data center capex for effectively no reason, outside of the belief that there’s “insatiable demand for AI compute” when the reality is that more than 70% of all AI revenues — and I estimate more than 80% of all compute sales — are from Anthropic and OpenAI taking up whatever capacity comes online, leaving very little left for the rest of the world and creating the illusion of massive demand. Both of these companies want to dump themselves onto the public markets, raise tens of billions of dollars of debt a year, and dump further shares onto unsuspecting investors based on unrealistic revenue projections of hundreds of billions of dollars a year by 2028 . Both OpenAI and Anthropic are astonishingly bad businesses, losing $20.92 billion and $8 billion respectively in 2025. The best response that anyone has got to these shocking figures is to vaguely point to adjusted profitability numbers provided by companies that have constantly shared deceptive annualized run rate figures as a means of obfuscating their financial condition. And these companies account for, per their own obligations, $1.3 trillion of future earnings across Microsoft, Google, SpaceX, Oracle, and Amazon, with $413 billion of Anthropic’s commitments being non-cancellable , and OpenAI projecting to spend at least $750 billion on compute through the end of 2030 , with no answer as to how these companies afford to do so.  Analyst expectations have OpenAI and Anthropic contributing at least $444 billion in revenue across hyperscalers in the next three years , and if this revenue fails to arrive — either through insolvency or renegotiation of terms — every connected hyperscaler will see massive revenue misses. These are not hyperbolic, mean-hearted or “skeptical” claims, but the hard mathematics underlying an industry that so often convinces those supposedly analyzing it to ignore good sense and assume that nothing bad will ever happen. Meanwhile, nobody seems to be taking the shocking financial condition of Oracle very seriously, despite effectively every warning light blinking at once. It is beyond abnormal for a company backing an $18 billion data center project to give a “ force majeure ” notice no matter what it says on Twitter , and suggests that the $340 billion in data centers it’s building for OpenAI are materially behind schedule, on top of the fact that Oracle is making sounds like it doesn’t intend to pay its debts, which is extremely alarming!  And make no mistake,  if Oracle builds these data centers and OpenAI doesn’t pay for them, it will face an existential financial risk unseen in the history of the tech industry. Oracle’s revenue has been flat for fifteen years when adjusted for inflation , with its only growth coming from its wrongheaded acquisition of Cerner in 2021 and selling AI compute that destroy its gross margins , with its largest company being a technically-insolvent startup with volatile economics and a CEO who wants us to accept “bad things will happen” in exchange for whatever ChatGPT is supposed to be . The problem Oracle also faces is that things don’t have to collapse for a collapse to occur. Chairman and founder Larry Ellison just added another $9.2 billion in stock-backed personal loans to his already-large pile , bringing it (by my count) to around $30 billion, and the margin calls will start somewhere around $60 a share for a stock that pumps and dumps based on any OpenAI news, meaning that anything along the lines of “OpenAI can’t pay Oracle” is guaranteed to start a spiral.  The only reason this hasn’t happened yet is that the media and the markets are unwilling to accept the sheer impossibility of Oracle’s $300 billion, five-year-long deal with OpenAI that neither company can afford and Oracle doesn’t have the capacity to serve . Every one of the “Stargate” data centers is heavily behind schedule, and Stargate Abilene — which Oracle claims is “75% delivered” — has no more than half of its capacity installed, not that anyone bothers to check these things or investigate the claims of anyone connected to the AI bubble. I roll my eyes at the feint and whiny concerns from Bloomberg about “risk related to Larry Ellison” as a result of Paramount’s huge debt raise . Anyone with a fucking calculator and an interest in the truth could’ve seen last year that none of the underlying economics of Oracle’s situation made much sense, it just required not immediately assuming that every AI data center was a perfect angel that would be birthed without fail onto a world flush with cash. Then there’s the shocking deterioration of semiconductor firm Broadcom, which is tied to Anthropic for at least $161 billion in non-cancelable chip leases, which has in turn forced Broadcom to raise $60 billion in debt to build them . Broadcom is, as covered in my Premium Hater’s Guide , a company already bathed in debt thanks to its 2023 acquisition of VMware, one that appears to be taking on tens of billions more as a means of selling TPUs to a company that may or may not exist by the time there’s a data center to put them in. How, exactly, is Anthropic meant to pay for all of those compute leases (or all of that compute) based on its current financial position? Taking away however I may feel about AI in general, for it to reach a size where it can handle even a hundred billion dollars a year in annual operating expenses — Microsoft, by comparison, is at around $176 billion — Anthropic would have to become one of the single-largest cash generators in the history of capitalism, or such a large participant in the world’s debt markets that it starts sucking up cash from the already-distressed and desperate customers of the CCC (lowest tier of junk) bond market . While a few people have danced with the edges of the potential insolvency of OpenAI and Anthropic, nobody seems to want to talk about the actual consequences, choosing always to take one shot of hopium before getting into the grisly details, with the assumption being that something will go alright — so I’m going to rain on everyone’s parade and go through each point one by one. The reason that so many of these misunderstandings exist is that people do not, on the whole, are surprisingly optimistic about basically any consensus opinion. Everybody has been saying that AI data centers are the next industrial revolution, NVIDIA’s stock has gone parabolic, every media outlet has constantly discussed Anthropic and OpenAI, and every hyperscaler has sunk hundreds of billions of dollars over the last few years into AI, which in turn makes you believe that everyone must be right and that everything will be alright by extension. This immediately makes people turn off the parts of their brain that feature critical thinking, because the alternatives are so utterly opposed to what’s been promised by this industry and the media. The assumption is always that this much money can’t be wrong , or that these are the smartest people in the world , or that these are the largest and most-successful companies in the world , even though none of these statements actually answers a single question about “ how the fuck does all of this actually work?”   Even if you think AI is the most wonderful, beautiful software tool ever imagined, there is no rational basis under which you can look at the current economic picture and say that everything will be fine.   The future I am talking about — one where most data center debt goes unpaid, where OpenAI and Anthropic fail to meet their obligations, and when AI GPU sales grind to a halt — involves Google, Microsoft and Amazon having catastrophic misses on their earnings expectations, and their future revenue growth stories collapsing, along with NVIDIA’s revenues dropping as much as 90% once the debt-backed AI capex boom ends. It involves CoreWeave, IREN, Nebius, and every other neocloud running out of money, fucking over investors in both their stock and debt some time in the next few years, with the underlying collateral made up of otherwise-useless data center construction and GPUs that will, at that point, be in a supply glut rivaling the Atari video game burial . I must be clear that I only have to be half right for things to be extremely bad. NVIDIA’s revenue growth cannot be sustained without endless debt issuance at a time when issuing debt is incredibly expensive, all in pursuit of data center construction that takes years to complete for customers that may or may not exist when it does so.  Hyperscalers have no other hypergrowth ideas left — no new Google Search, Microsoft 365, or Facebook — to sell investors, and in pursuit of AI have become the most asset-burdened companies on the Fortune 500, rivaling ExxonMobil, Berkshire Hathaway and Chevron, except instead of oil and diverse stocks they have GPUs that only retain value during a hype cycle. And there really is no hope for the $800 billion or so invested in AI startups in the last four years , as AI acquisitions are thin thanks to their high costs, miserable revenues and utter lack of intellectual property. I’m not sure venture capital — or anyone covering venture capital — has actually conceptualized how significant the losses may be, because I can see a world where virtually every AI investment goes to zero at a time when venture capital is facing an historic losing streak. In fact, I’m not sure anyone is trying to conceptualize what actually happens once the bubble bursts, because doing so requires you to think not just in terms of wasted capital, but about hundreds of billions of dollars of unpaid loans, dead AI investments, half-finished data center projects, and a stock market where 24% of the S&P 500’s value comes from five companies with stock prices boosted by theoretical returns on AI investments that are mostly from OpenAI and Anthropic. The fact we’re living in this bizarre juxtaposition of reality where we can run headlines about OpenAI-connected data centers never getting completed and its massive losses aside headlines about $50 trillion in data center construction by 2050 is a sign that nobody is taking the threat seriously enough.  I would love to say that I think I’m overreacting somehow, but I spend every single week running the numbers and actively looking for evidence that I’m wrong, mostly because the world, despite discussing the fragility of the AI bubble, doesn’t seem to want to think about it actually bursting.  I encourage you to do so, even if you’re pro-AI, even if you truly disagree with me, because this is extremely serious, and you can’t pay $1.3 trillion in commitments with hope. You can truly, madly love LLMs, you can name your dog Dario and your guinea pig Sam, I don’t care, but please, I’m begging you, stop making assumptions based on the best-case scenario, and start taking this seriously, because the consequences of me being right have global stakes.  Anyway, I’ll leave you with a chart from Torsten Slok, Chief Economist at Apollo , and a very reasonable question: if all of these tech companies are expecting record earnings over the next few years, where exactly will the cash come from? The fact we can’t cleanly answer this question as hundreds of billions of dollars get sunk into AI data centers may be the most glaring miss in the history of finance.  If you liked this piece, you should subscribe to my premium newsletter. It’s $70 a year , $18 a quarter , or $7 a month , and in return you get a weekly newsletter that’s usually anywhere from 10,000 to 18,000 words and provides vast, detailed analyses of the biggest events and companies in the AI bubble. If you want to get in touch — and especially if you have any juicy information about Anthropic, OpenAI, or any other companies in the AI bubble — hit me up on Signal at ezitron.76. I’m also on IB on The Terminal. The US government has over $40 trillion in debt, and to pay off that debt, the US government issues more debt, with interest payments making up 14% of all federal spending , and the federal deficit (IE: how much more the government spends than it pulls in in revenue) sitting around $2 trillion a year, meaning that, at minimum, it’ll need to borrow an additional $2 trillion in 2027 beyond what it borrowed in 2026 just to pay what Congress has authorized in spending, and the same amount again in 2028 if the deficit stays the same next year. This means that anyone pricing US Treasuries is doing so under the virtual guarantee that the US government will have to issue more debt . The alternative is that the US government cuts social security, medicaid or military spending, which would be very unpopular, and thus very unlikely to happen. The wars in Iran and Ukraine are putting increasing pressure on the world’s oil supplies, because higher fuel costs push up inflation because they increase the cost of effectively everything — both driving and flying to places, which is how most people and goods move around the world, as well as the cost of electricity (particularly where natural gas is concerned).  As I wrote a couple of weeks back, the war in Iran has also cut the supply of other raw materials, including sulfur (which is used in fertilizers), helium, and aluminium, further exacerbating the inflation crisis.  With the price of everything (at least in theory) inflating, investors demand that their bonds pay them at a rate that matches the rate of inflation.  There’s an ongoing debate — discussed here by the Financial Times — about whether US data center debt issuance has reached a point when it’s creating meaningful competition for US government debt, specifically that issued by Google, Meta, and Amazon, because these “stable” companies are offering attractive rates that are, in the eyes of some investors, as stable as lending to the US government. While it’s had some effect, it isn’t the big reason that the ten-year is selling off. The price of equivalent US treasuries at the time you are issuing the debt. The current price of the company’s debt. Amazon went public in May 1997, raised $54 million ($112 million adjusted for inflation), didn’t get a credit rating at the time (it didn’t issue corporate debt at the time), and had a negative 19% EBITDA margin. It was profitable four years later.  Uber went public in May 2019, got a B+ Credit Rating, had an EBITDA of -$2.7 billion, and an EBITDA margin of negative 21%, taking its first EBITDA profitability in Q2 2023 . It raised $8.1 billion at IPO ($10.6 billion in today’s money). By comparison, OpenAI’s EBITDA margin for 2025 was negative 160%. NVIDIA Will Still Have Customers After The AI Bubble! Sure it will — for its gaming segment that is now so small that it’s blended into “Edge computing” on its earnings. As I’ve discussed previously, 50% to 60% of NVIDIA’s revenues are coming from hyperscalers that are actively participating in the AI boom, and without that boom (and the debt necessary to keep buying chips), nobody else is buying them at anything close to today’s scale. If Anthropic and OpenAI die, all that data center compute will be used by someone else one day! OpenAI and Anthropic represent 80%+ of all compute demand, and their customers — unprofitable venture-backed AI startups — make up 80% of their enterprise revenues , which means they’re likely to die before OpenAI and Anthropic. Someone else will pay for the capacity if they don’t! Who? Who is actually spending money on AI compute? I’ve looked everywhere and I’ve found at the very , very best $22 billion of non-OpenAI/Anthropic compute purchases ! All of this capacity will be useful after the bubble bursts! No it won’t! Any AI data center that’s yet to be completed will cost just as much (if not more so) to finish in a few years as it will today, much like the electricity costs are going to be. In addition, the vast majority of customers for AI compute are unprofitable AI startups that want to compete with OpenAI and Anthropic, meaning that once the venture spigot turns off, nobody will want it. AI services are like airlines — you stand up inference based on the amount of customers you might have, and need to guess correctly about your demand, because if you’re off in either direction, you lose a ton of money. With most of the demand for AI driven by endless media and peer pressure, once the AI bubble bursts, the “demand” for AI services will be entirely driven by utility…and considering most services lose money even during the hype cycle , it’s hard to see what post-bubble economy even exists. This means that it’s unlikely that we’ll have a “booming open source AI market” in the end , and at best we’ll have some sort of handicapped Google monstrosity, though even that seems less likely based on the fallout I fear. Anthropic and OpenAI can just cut their costs! With hundreds of billions of dollars in non-cancellable commitments, neither of these companies can “cut their costs.” OpenAI and Anthropic are the fastest growing companies of all time! Based on annualized run rates that are pegged to non-specific periods of time, all as their costs explode and they sign non-cancelable agreements. If Anthropic and OpenAI die, there will be other winners! Who? There are no other AI companies that are growing anywhere near as fast or have customer bases that come close to Anthropic and OpenAI, and those customers are mostly other AI startups. If Anthropic and OpenAI die, it’s because their customers died, which means their customers won’t be the “winners.”

0 views
Stratechery 2 days ago

Game Decompilation, Is This Legal?, A Well-Trodden Path

Games are being decompiled, but the real risk to gaming is new games and increased personalization.

0 views