
0916 | Breaches, Bots and Breakthroughs
Show notes
This episode covers a wide week in tech: a security wave spanning dark web data sales, sabotage and surveillance debates, plus AI shifts from inference demand to structured models and AI-built software, alongside hardware hacking, open-source releases, and a few odd curiosities.
Timeline
- 00:00:04 Opening
- 00:00:28 Security incidents: stolen data and found flaws
- 00:04:49 Surveillance and infrastructure risk
- 00:08:05 AI: inference demand and new model bets
- 00:12:18 AI writes software
- 00:15:39 Money and machines: acquisitions and migrations
- 00:18:36 Java and Linux foundations
- 00:21:06 DIY hardware and handcrafted software
- 00:26:08 Oddities, losses and old mysteries
- 00:29:28 Consumer durability
- 00:30:57 First contact
- 00:32:17 Closing
Related links
- America's Driver's License Breach Is a National Security Disaster
- We got admin access to Baseten's production GitHub in 25 minutes
- Suspected sabotage causes major Netherlands rail disruption
- 25 years of mass surveillance is enough
- The Inference Hardware Revolution of 2026
- Introducing System One Models and Jev
- Gemini 3.8 Live and 3.8 Live Extended Thinking
- How much of F-Droid is LLM generated?
- Building a Linux GPU Driver for the M4 Mac Mini in One Month
- OpenAI buys smartphone camera maker Glass Imaging for $300M
- Alternatives to MinIO for single-node local S3
- Java 27 Released
- Linux from Scratch
- Show HN: Hacking a $20 4G wireless hotspot into a texting device
- Show HN: An e-ink frame that hears birds and draws them as 1800s illustrations
- Show HN: Capsule – Single-file web apps that save their data into SQLite
- The CSS Zen Garden dream, finally shipped
- Chopping up books when they're physically too big
- CSS-Tricks in Limbo
- An Update on Wayback Machine Access
- The k-server conjecture is true
- Let's make quality the norm again
- I can't stop thinking about Papua New Guinea
This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.
Transcript
Mia: Welcome back to the show, everyone — I'm Mia.
Milo: And I'm Milo. It's been a busy day, and the thread running through a lot of it, honestly, is trust — trust in the software we run, in the data companies hold about us, in the hardware we buy, even in what a whole chunk of the software on our phones actually is. But let's start somewhere genuinely alarming.
Mia: Yeah, let's start with a dark web service called Nexus, which reportedly sold 153 million driver's licenses from the US and Canada. And the connection here is a hack of a company called IDScan — so the theory is that this trove came out of that breach.
Milo: A hundred and fifty-three million. For scale, that's a very large fraction of the adult population of the United States and Canada combined. Driver's licenses are not like a leaked password — you can't just reset them. Your license number, your name, date of birth, address, often those are exactly the answers to the "verify your identity" questions that banks and services use.
Mia: That's what makes this feel like more than an ordinary breach story. The reporting frames it as a national security concern, and I think that's not just drama. Identity documents are the root of the identity system. If someone can buy a valid-looking license tied to a real person, that enables fraud, impersonation, account takeovers, potentially things far more organized than petty crime.
Milo: And there's the grim reality that once data like this is out, it's out. There's no patch for a leaked license number. The people in that database can't do anything about it. So the questions that stick with me are the unresolved ones — what exactly was IDScan's exposure? Did the company know the scope? And what does remediation even look like when the compromised asset is 153 million identities?
Mia: Which leads naturally into the second story, because it's about a different kind of credential problem — and this time the company found out because someone told them. A security group called Strix got a GitHub admin token for a company called Baseten in twenty-five minutes. The vector was a public Docker image.
Milo: Twenty-five minutes. And the technique is almost embarrassing in its simplicity. Companies publish Docker images — that's normal, that's how software gets distributed. But if you build those images carelessly, secrets can end up baked into the layers. Credentials, tokens, history, whatever was in the environment when the image was built. Someone pulls the image apart and there it is.
Mia: So the lesson isn't exotic. It's that build pipelines leak, and everything you ship is public forever. And to Baseten's credit, they fixed it fast — once notified, the response was quick.
Milo: But here's the part that's generating the friction: the bounty. Strix got t-shirts. T-shirts for an admin token to a production GitHub org.
Mia: Which is a genuinely interesting incentive question, and I want to actually steelman Baseten a bit before we pile on. If you're a startup without a formal bug bounty program, an unsolicited disclosure like this is awkward. You didn't invite it, you can't pay what you didn't budget for, and there's legal risk in paying random researchers. So maybe t-shirts are better than nothing.
Milo: Sure, and I'd agree the fix matters more than the reward — the vulnerability is closed, that's the real outcome. But think about the economics from the researcher's side. Someone spends time and expertise finding a critical flaw, handles it responsibly, and the market says that's worth a t-shirt. Meanwhile, the same finding on a gray-market basis — the Nexus side of the world, to connect our first story — could be worth real money.
Milo: If the legitimate path pays in merch and the illegitimate path pays in cash, we shouldn't be surprised when the incentives push people in the wrong direction.
Mia: That's the common thread with the driver's license story, right? Credentials in the wrong hands. In one case it's millions of identities stolen through a breach; in the other it's a credential accidentally given away. Different causes, same category of failure — and the incentive structure for finding and fixing flaws is unclear at best.
Milo: Let's stay in security but shift from data to physical systems, because there's a story out of the Netherlands that's honestly strange. ProRail, the Dutch railway infrastructure manager, is dealing with suspected sabotage — tubes placed on the tracks at multiple locations, and at least fifteen disruptions. They're calling it intentional human action, and police are investigating.
Mia: The detail that gets me is the tubes. This isn't vandalism in the usual sense — it's something placed deliberately, in several spots, causing repeated disruptions. The question the reporting leaves open is who and why. Is it a disgruntled insider? A state actor testing something? Activists? Nobody seems to know yet, and I'd rather not speculate.
Milo: What I think it does do is underline a point we keep circling: security isn't just a software problem. We spend most of our airtime on leaked tokens and stolen databases, but rails are infrastructure too, and they can be attacked with a handful of tubes and a car ride. Critical systems are only as secure as their most neglected physical component.
Mia: And that connects almost too neatly to the next story. Bruce Schneier and Cindy Cohn have an essay in Lawfare marking twenty-five years since 9/11, and their argument is that mass surveillance has escaped its original container.
Milo: The container being counter-terrorism. After 2001, the justification for sweeping surveillance was emergencies, threats, terrorism — and the argument was always that these powers were exceptional. Twenty-five years later, Schneier and Cohn's point is that they've become routine. Not just routine in policing, but commercial — the same collection apparatus, or at least the same collection habits, now powers advertising and ordinary business.
Mia: It's a strong argument and I find it largely persuasive, but let's push on it a little. The counterargument would be that commercial data collection and government surveillance are different things with different rules — a company collecting data to sell you ads isn't the same as a state collecting data to prosecute you.
Milo: Right, and that's a fair distinction on paper. But the essay's underlying point, I think, is about normalization. The infrastructure built for one emergency purpose doesn't get dismantled when the emergency passes; it gets reused. And the commercial sector and the government sector feed each other — data brokers, for example, sit right in between. Once collection is the default, the specific justification becomes almost decorative.
Mia: And notice how all three of these stories — Dutch rail sabotage, the surveillance essay, the credential leaks — are about systems where the threat model changed faster than the governance. The rails were built assuming nobody would do this. The internet's identity systems were built assuming breaches would be rare and small.
Milo: Okay, let's pivot from security to compute, because there's a big-picture piece from IEEE Spectrum framing 2026 as the year AI inference dominates.
Mia: And the argument there is worth unpacking, because it's a shift from how people thought about AI infrastructure even two years ago. The old story was training — giant clusters building giant models. The new story is inference: actually running these things for billions of queries. And crucially, the workload isn't static. Reasoning models generate enormous amounts of intermediate output before answering. Agents chain tasks together, run for minutes or hours, make tool calls.
Mia: Multiply that by usage and demand doesn't grow linearly — it multiplies.
Milo: The consequence the piece points to is that we have to rethink chips and memory. Inference is a different beast from training — it's latency-sensitive, it's memory-bandwidth-hungry, and the economics are per-token. The hardware that made sense for training runs doesn't automatically make sense for serving.
Mia: Now, here's where it gets interesting, because two other stories this week are essentially bets against the mainstream inference narrative. The first: Diogo Almeida, ex-OpenAI, has a company called TypeSafe AI shipping models called System One and Jev. The pitch is typed, structured outputs, latency between 70 and 500 milliseconds, and — the headline claim — no hallucination.
Milo: Let's sit on that claim for a second. Small models, fast, structured output, no hallucination. The logic is that a huge slice of real-world AI usage doesn't need a reasoning model pondering for thirty seconds. It needs: take this input, return this exact schema, reliably, fast, cheap. Think extraction, routing, classification, function calls. If you constrain the task and the output format hard enough, hallucination becomes much less of a problem.
Mia: I'm sympathetic but skeptical of the absolute phrasing. "No hallucination" is a very strong claim for anything that's still, presumably, a statistical model. What I'd read it as is: for the narrow tasks they're targeting, the failure modes are designed away — typed outputs that either conform or fail loudly. That's a legitimately valuable product even if the marketing outruns the epistemology.
Milo: Agreed. And the contrast with IEEE Spectrum's thesis is the point. Spectrum says inference demand is exploding because models are getting bigger, slower, more agentic. Almeida's bet is that there's a huge market at the other extreme — tiny, fast, boring, reliable. Both can be true. The middle might actually be the squeezed segment.
Mia: The other contrarian bet is Google's. They launched Gemini 3.8 Live and 3.8 Live Extended Thinking — and the direction here is voice that feels natural, plus reasoning that happens in parallel and tasks that run in the background.
Milo: So this is the consumer-facing version of the same tension. Live voice means the model has to respond in real time — you can't have a two-second gap in a conversation. Extended thinking means the model should deliberate longer. Those pull in opposite directions, and Google's answer seems to be to separate them: have the fast conversational layer respond while slower reasoning happens concurrently, and let background tasks keep running after the conversation moves on.
Mia: Which, if it works, is basically the architecture of a human assistant — talk to you now, think about the hard problem in the background, come back with the answer. Whether it actually feels that way in practice is the open question.
Milo: Alright, from inference economics to who's actually writing the software — and this next story is the one I've been turning over all day. An investigation estimates that around seventy percent of recent apps on F-Droid are generated by LLMs.
Mia: Seventy percent. And the detection method is what makes it credible rather than vibes: telltale commits, boilerplate READMEs, the characteristic fingerprints of generated projects. F-Droid is the independent, open-source Android store — it's supposed to be the trusted corner of the ecosystem, and now a large majority of new submissions are, by this estimate, machine-generated.
Milo: The concern writes itself: review capacity. If human maintainers are facing a flood of generated apps, they can't meaningfully review them, which degrades the trust that the whole platform exists to provide. Malicious or just low-quality apps slip in. And there's a subtler loss too — the signal that "this is on F-Droid" used to carry is diluting.
Mia: Let me push back slightly, though. Generated apps aren't automatically bad apps. Some of them are probably fine — a hobbyist using an LLM to ship a utility they couldn't have coded themselves is arguably exactly what these tools are for. The problem isn't generation per se, it's that we can't distinguish generated-and-good from generated-and-slop from generated-and-malicious at scale.
Milo: Which is exactly why the contrast story matters. Cody Ho and Niklas spent about a month building an OpenGL ES 3.0 driver for the GPU in the M4 Mac Mini — by reverse-engineering the hardware, with AI assistance — and got Minecraft running at 200 frames per second.
Mia: This is the part that makes my jaw drop. Apple doesn't document that GPU. Writing a driver means figuring out the instruction set, the command submission model, the memory layout — of a proprietary chip — essentially from scratch. In a month. And a driver is not a CRUD app; this is systems programming at the hardest end.
Milo: And I think the honest framing is: AI as a tool for human engineering, not a replacement for it. These two clearly had deep expertise — you can't reverse-engineer a GPU by prompting. What AI did was accelerate the grind: generating test hypotheses, helping decode patterns, writing the tedious layers. The seventy-percent F-Droid story is AI replacing judgment at the bottom of the skill ladder; the driver story is AI amplifying judgment at the top. Same technology, completely different outcomes.
Mia: The unresolved question, then, is what the F-Droids of the world do about the first outcome without choking off the second. You can't review harder your way out of a seventy-percent flood, and you can't ban LLMs without punishing people like the driver authors.
Milo: From there, let's talk about money and what runs on machines — starting with an acquisition. OpenAI has bought Glass Imaging for more than three hundred million dollars. Glass was founded by ex-Apple engineers who worked on Portrait Mode.
Mia: Portrait Mode! That's the computational photography feature that made depth-of-field effects possible on a phone — genuinely hard engineering combining optics, machine learning, and imaging pipelines. So OpenAI buying the people behind that, plus the company, for north of $300 million, reads as a signal.
Milo: The signal being hardware. OpenAI famously doesn't have its own consumer hardware, and there's been endless speculation about whether they'll ever build a device. Acquiring world-class imaging talent — people who know how to make cameras and software feel magical — is not what you do to improve ChatGPT's text output. It's what you do if you're thinking about a camera, glasses, or some kind of visual device.
Mia: Though we should be careful — the sources tell us the acquisition and the founders' background; the hardware ambition is the direction being reported, not a confirmed product roadmap. What's fair to say is that $300M for an imaging company makes a lot more sense with a hardware thesis than without one.
Milo: And on the other end of the money-and-machines spectrum: what happens when infrastructure software gets abandoned. rmoff did a review of single-node S3 alternatives after what's being called the abandonment of MinIO.
Mia: MinIO was the go-to open-source S3-compatible object store for self-hosting. When the project's direction soured, a lot of people were left asking: what do I run now? And rmoff's answer is a genuine survey — S3Proxy, RustFS, SeaweedFS, Garage, Ozone, Ceph — all tested with Docker and Compose.
Milo: What I like about this is that it's a real user doing real evaluation, not benchmarks from a vendor. And the takeaway isn't "X wins" — it's that the space is genuinely contested. Some of these are lightweight and simple, some are battle-tested and heavy. Ceph is a monster with enormous capability and complexity to match; Garage is built for the small-scale, resilient case; SeaweedFS has its own interesting design. The right answer depends entirely on what you're storing and how much you care.
Mia: The link between these two stories, I think, is flux. OpenAI is deciding what hardware it wants to exist; self-hosters are deciding what software they want to run after a dependency turned unreliable. In both cases the "obvious" answer stopped being obvious.
Milo: Let's talk foundations now — Java and Linux, which sound boring next to everything we've covered, and are precisely not. JDK 27 is generally available, and there are a few items in it worth naming. G1 is now the default garbage collector.
Mia: Post-quantum key exchange for TLS 1.3 is the one I want to flag, because it's the "boring" feature that's actually about the next decade. The threat is harvest-now-decrypt-later: adversaries recording encrypted traffic today to decrypt once quantum computers mature. Upgrading the key exchange in the world's most-used TLS stack means traffic secured by Java today is protected against that future. This is infrastructure work that nobody will ever notice and everybody benefits from.
Milo: Also in the release: Structured Concurrency in its seventh preview and the Vector API in its twelfth incubator. Those iteration counts tell their own story — the Java team ships these things deliberately, preview after preview, taking the time to get them right rather than freezing an API they'll regret.
Milo: Structured concurrency, in particular, is trying to fix a genuinely hard problem: making concurrent tasks behave like a coherent unit with a lifecycle, instead of loose threads leaking everywhere.
Mia: And the companion story is Linux From Scratch hitting version 13.1. The whole project is a set of instructions for building a complete Linux system from source code, piece by piece — compiler, linker, kernel, everything. No distro, no package manager magic. You assemble it.
Milo: Why does that still matter in 2026? Because it's the best education in what an operating system actually is that exists. And there's a thematic echo with what we just said about Java: both are about long-term, careful systems engineering. Java evolves over decades with previews and incubators; LFS teaches people the layers underneath decades of abstraction. In a world of generated apps and AI-assisted everything, these are the counterweights — people who understand what's under the floor.
Mia: Which brings us nicely to the DIY and handcrafted corner of this week, and there's a lot of it. Let's start with the cheapest one: a twenty-dollar 4G hotspot — the MF800 — plus a Clicks keyboard and a SHARP display, turned into a Linux messaging device through a project called openstick.
Milo: The appeal here is obvious given everything else in this episode. These little hotspot bricks contain a full ARM Linux system, and openstick is about getting real Linux onto them. Add a keyboard and a screen and you have a purpose-built messaging device — something like a modern PDA. It's a statement against the smartphone monolith: a device that does one thing, runs Linux, and costs almost nothing.
Mia: Then there's Fugleramme — "frame" in Norwegian, I believe — which might be my favorite project of the week. It's an e-ink frame built on a Raspberry Pi that listens for birds with BirdNET-Go, the bird-sound recognition model, and when it detects a species, it draws that bird as an 1800s-style illustration. All running locally.
Milo: And it's the all-local part that elevates it. No cloud, no subscription — the recognition happens on the device. And the aesthetic choice is lovely: instead of a notification or a camera image, you get an antique naturalist illustration fading in when a bird sings nearby. It's ambient computing as art. Most smart-home products are louder, faster, more intrusive; this is quieter and slower, on purpose.
Mia: Third in the DIY software line: Capsule, which packs a web app — HTML plus a SQLite database — into a single .capsule file. Portable, offline, built with Rust and Tauri, and with AI integrated.
Milo: The idea is essentially a return to the document-as-application. A .capsule file is like a self-contained little world: the interface and the data travel together. You copy it, it works. No server, no deployment, no account. The SQLite inside means the data is real and structured, not just a blob.
Mia: And the contrast with the F-Droid flood is worth naming. Capsule is the kind of thing a small team or individual can build because the constraints are tight — one file, offline, local data. Constraints are what make small software viable. The slop problem exists largely because modern app development has no natural ceiling on complexity.
Milo: Next: Firefox.com has been rebuilt in native modern CSS — done by Jo Sprague of Mozilla and Lincoln Loop — with almost no tooling. Modern CSS has features like container queries, nesting, custom properties, and the rebuild leans on those directly. The only build-step concession is PostCSS, and just for handling imports.
Mia: The significance is that Firefox.com was, like a lot of the web, built with preprocessors and tooling that existed to paper over CSS's old limitations. Those limitations are largely gone now. When the language itself can do what your framework was doing, you can delete the framework — and every deleted dependency is one less thing that breaks, one less supply-chain risk, one less thing to understand. It rhymes with the Capsule story: subtract until it's simple.
Milo: And then the most analog item on the entire show: Matt Kirkland cutting large books into smaller physical volumes. His example is Lonesome Dove — 850-plus pages, a genuinely difficult object to hold and read — so he takes a knife, folder covers, and glue, and splits it into multiple slim volumes.
Mia: I love that this is in the same conversation as openstick and Capsule, because it's the same instinct. When the standard format doesn't serve you, remake it. His intervention is purely physical — no app, no firmware — and it solves a real ergonomics problem. An 850-page paperback is genuinely unpleasant to read in bed. Three 280-page volumes are not.
Milo: And there's a durability angle too, which we'll get to — a well-bound small volume might actually survive better than a massive glued paperback whose spine gives out halfway through. Which is our bridge to the closing topics.
Mia: So, CSS-Tricks. For years it was one of the most beloved resources on the web — front-end tutorials, deep CSS knowledge, the site a generation of developers learned from. It had gone quiet, and then this week the news: DigitalOcean acquired it, laid off the team, and donated three million dollars to DHH's Omarchy project — without communicating what happens to the site itself.
Milo: That's a strange sequence of events, and the strangeness is the point. If DigitalOcean wanted to preserve CSS-Tricks, the announcement would say so. If they wanted to shut it down, saying so would be honest. Saying nothing leaves a beloved resource in limbo, and the donation to Omarchy — a Linux desktop project of DHH's, which is a completely different domain — makes the whole thing read like an asset play plus a goodwill gesture, with the community as an afterthought.
Mia: The unresolved question is simply: what happens to the archive? All those articles are still linked from countless tutorials and courses. If the site decays or vanishes, a big piece of the web's living history goes with it. The Wayback Machine link is actually relevant here, because the Internet Archive reported a wave of massive automated traffic — so heavy that their 429 rate-limit blocks started catching real users, and they've asked people to get in touch if they hit errors.
Milo: Which is its own little tragedy: the archive of the web is being strained by bots, and the mitigation — rate limiting — harms the exact humans it exists to serve. And it loops back to CSS-Tricks: if a site's future is uncertain, the archive is the fallback, and the archive itself is under load.
Mia: Let me balance the sour note with a genuinely wonderful one. In mathematics, Coester, Koutsoupias, and Zbysiński have proved the k-servers conjecture, using an approach based on work functions.
Milo: For people who don't know it: the k-server problem is one of the classic questions in online algorithms. You have k servers and a sequence of requests arriving at various locations; each request must be served by moving some server there, and you don't know future requests. The conjecture — open since the 1990s — was that there's always a strategy where the cost is at most k times the optimal offline cost. It was known for small cases and specific spaces; the general proof is the news.
Mia: And I want to be honest that I can't walk through the work-functions argument in detail — this is a serious proof. What I can say is what the technique has meant historically: work functions were the tool behind the previous landmark results on this problem, and extending them to the full generality was the wall everyone kept hitting. That someone found the way through, after roughly three decades, is one of those moments where a field's longest-standing question just... gets answered.
Milo: Two closing items before we wrap. The first is durability — and honestly, after a week of leaked identities, abandoned infrastructure, and LLM slop, it might be the most radical story of the lot. Norway's consumer council, Forbrukerrådet, has a report saying what everyone already suspects: products last less than they used to. And their call is for policy that makes quality and the circular economy the norm, rather than the exception.
Mia: What I appreciate is that it's framed as a systems problem, not a consumer-virtue problem. The council isn't saying "buy better" — they're saying the rules of the market currently reward making things worse, and policy should flip the default. Design for repair, design for longevity, make durability the baseline competitors have to meet rather than a premium feature you pay extra for.
Milo: And notice how it connects to everything handmade we discussed. The openstick device exists because a $20 hotspot is more durable, in a sense, than a flagship phone's upgrade cycle. Kirkland's book-splitting is durability of attention — making a 850-page object readable. Capsule is durability of software — one file, no dependencies, nothing to rot.
Mia: And on that note, one last story to end on, and it's my favorite kind. In 1930, an explorer named Mick Leahy made his way into the Highlands of New Guinea and found about a million people living there — a million people whose existence was, until that moment, completely unknown to the outside world.
Milo: A million. Not a scattered band of a few hundred — roughly a million people, with their own societies, agriculture, wars, histories. And the account of it is captured in a documentary called First Contact. The magnitude of the oversight is what stays with me. The world map had a million-person hole in it, in the twentieth century, on a landmass that explorers had skirted for centuries.
Mia: I think it's the right note to end on after everything else. Twenty-five years of surveillance expansion, and yet a million people went unseen within recent memory. We leak a hundred and fifty-three million identities and can't secure a rail line, and still the world holds rooms we haven't entered. Humility seems like the only sane posture — about security, about AI, about what we think we know.
Milo: On that note — thanks for listening, everyone. I'm Milo.
Mia: And I'm Mia. Take care of your credentials, your books, and your birds. See you next time.