1007 | Open Weights, Open Questions: A Week of AI, Math, and Machines

||Download

Show notes

From AI-discovered math proofs and open hardware to geothermal power, streaming megamergers, and niche personal software, this episode tours the week's biggest stories in tech, science, and the systems that shape them.

Timeline

  • 00:00:04 Opening
  • 00:00:25 AI pushes into mathematics and decisions
  • 00:07:06 Open and efficient AI infrastructure
  • 00:12:26 Security in the AI era
  • 00:18:09 Open-source engineering wins
  • 00:27:00 Vibe-coded personal software and how coding feels
  • 00:34:51 Corporate power, law, and the state
  • 00:40:40 Health, energy, and the physical world
  • 00:47:45 Closing

Related links

This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.

Transcript

Mia: Welcome back to the show, everybody — I'm Mia.

Milo: And I'm Milo. Today we've got a stack of stories where the theme, honestly, is that things we thought were settled are getting reopened — whether it's the mathematics of algorithm complexity, the question of who owns your coding experience, or whether a mail client built by hobbyists can actually compete.

Mia: Yeah, it's a day of reopened questions. Let's dig in with the one that made the biggest intellectual splash: a paper claiming the first subquadratic algorithm for 3SUM.

Milo: So for listeners who need the setup — 3SUM is one of those classic problems. Given a list of numbers, find three that add up to zero. It looks simple, but it's been a benchmark problem in theoretical computer science for decades, and the long-standing belief was that you basically can't do fundamentally better than quadratic time. There's a whole web of "hardness hypotheses" built on that assumption.

Mia: Right, and the claim in this paper is big on two fronts. First, an algorithm running in n to the power of about 1.9992 — so subquadratic, barely, but subquadratic. Second, and arguably more important, they also claim a subcubic algorithm for all-pairs shortest paths, APSP, which is the other pillar of that same hardness framework. And if both of those fall, a bunch of conditional lower bounds in the literature are suddenly on shaky ground.

Milo: And the twist that got everyone talking: the authors say the algorithm was discovered by Claude — the AI model — and then verified in Lean 4, which is a proof assistant. That verification part is the load-bearing wall here.

Mia: Exactly, and I want to be precise about why. A claimed breakthrough algorithm can be wrong in ways that take the community months to find. But if it's formalized in Lean, the proof checker mechanically verifies every step. So the claim isn't "trust us, we checked it by hand" — it's "the machine checked it." That's a different epistemic category.

Milo: What struck me in the discussion was how people split roughly into three camps. One camp said: if the Lean formalization is real and complete, this is simply verified, and arguing about it is missing the point — the whole value of proof assistants is that you don't need to trust anyone's reputation. That's the strongest version of the "this is legitimate" position.

Mia: And then the skeptical camp, which I think is worth taking seriously. Their reasoning was mostly about what "verified in Lean" actually covers. A formalization can verify that a proof is correct as written, but there are always questions about whether the formal statement matches what people think it says — whether there's a subtle gap between the informal claim in the paper and the theorem that was actually proven.

Mia: Commenters pointed out that in high-profile Lean verifications, the devil is in exactly that gap. So the open question isn't "is the proof valid," it's "is the statement we care about the statement that was proven."

Milo: The third camp was more philosophical — the "okay, so what does this mean for the field" group. If an AI can find an algorithm that refutes a hypothesis the community believed for decades, then the bottleneck in theory research might not be human cleverness anymore. Some commenters found that exciting, others found it destabilizing — if the hardness conjectures that structure the whole field can fall like this, what other bedrock assumptions are actually just unproven folk beliefs?

Mia: And that connects directly to the second story in this cluster, which is OpenAI publishing math results from an internal frontier model on GitHub, with Lean formalizations — and notably, they consulted an advisory group from the Institute for Advanced Study.

Milo: The IAS angle is interesting. That's the institution associated with, historically, Einstein and von Neumann — it's about as establishment as pure mathematics gets. So OpenAI bringing in an IAS advisory group reads as an attempt to get external legitimacy from actual mathematicians, not just internal evaluation.

Mia: The discussion there was really about what "publishing" means when the publisher is a company with commercial interests. Some commenters took the generous view: releasing formalized results publicly, with external advisors, is a good-faith move and gives the community something checkable.

Mia: Others were more guarded — an internal frontier model producing results, evaluated partly by people the company selected and compensated, is not the same as results going through traditional peer review, and the incentive structure is different.

Milo: There was also an unresolved thread about what these results actually are. "Math results" covers a lot of ground — incremental lemma-level work and genuinely new theorems can both hide under that phrase. Skeptical commenters wanted to know the difficulty level; enthusiastic ones said the fact that there are Lean formalizations at all is the news, because it means the outputs are machine-checkable regardless of how impressive they sound in prose.

Mia: So let's put these two together, because the through-line is real. In one story, an AI model found a novel algorithm and a proof assistant settled whether it was right. In the other, an AI lab is producing math and routing it through formalization and external advisors. The pattern in both is the same: AI proposing, formal methods disposing.

Milo: And the "what's next" for both is the same too — independent verification. For the 3SUM paper, that means the formalization community actually auditing the Lean code and confirming the statement matches the claim. For OpenAI, it means mathematicians outside the company engaging with the published results. Neither is resolved yet.

Mia: Before we move on, one more thing worth saying about the 3SUM result: even if it holds up perfectly, n to the 1.9992 is almost certainly not practical. Nobody is going to run this on real data. Its importance is theoretical — it breaks a barrier, which changes what's provable and believed. I think that's worth keeping in mind when people frame it as a "speedup."

Milo: Good caveat. Okay, shifting gears — but staying in AI-land — let's talk about the open stack, from hardware up to models. This cluster has three pieces and they fit together nicely.

Mia: Start with openTPU, because it's the weirdest one. It's an open-source AI accelerator that was, itself, designed by AI. It runs on a Kintex-7 FPGA card — so not a custom chip, a reprogrammable one — and it can run models like Qwen3 at up to around 86 tokens per second, after a process of self-improvement where the design iterated on itself.

Milo: The number that matters for context: 86 tokens per second on an FPGA is not going to threaten a data center GPU. But that's not the point. The point people made in the discussion is that a competent, open, reproducible inference backend that anyone can load onto commodity FPGA hardware is a genuinely new thing. If the design is open, anyone can study it, port it, improve it. It's the hardware equivalent of what open weights did for models.

Mia: There was healthy skepticism too, which I want to represent fairly. Commenters asked about the maturity — an FPGA design that runs a demo is different from one that's stable, documented, and useful for real workloads. And "designed by AI" is doing some marketing work in the headline; the interesting question is how much human engineering sits around the AI-generated parts. Nobody in the discussion could fully answer that, which is itself the honest answer.

Milo: Next rung up the stack: Google's EmbeddingGemma 2. This one is smaller news in spectacle but maybe bigger in consequence. It's Apache-2.0 licensed, 740 million parameters, and natively multimodal — text, vision, and audio, with the parameter budget split across them. And it's built for on-device embeddings.

Mia: The licensing is the part I'd underline. Apache-2.0 is one of the most permissive licenses going — companies can use it in products without the copyleft obligations of something like GPL. For embeddings specifically — the vectors you use for search, retrieval, classification — having a strong permissive multimodal model that runs locally means you can build RAG systems without sending user data to an API.

Mia: Several commenters read this as Google defending its infrastructure position: give away the embedding layer, keep the ecosystem on your rails.

Milo: And then the top of the stack: Mistral Large 4, which they're calling "Le Chonk." I enjoy that they leaned into the meme. One trillion total parameters, 49 billion active — so a sparse mixture-of-experts style architecture where only a fraction of the model fires per token — and it's multimodal. Open weights are promised at the end of the month.

Mia: The training story is notable too: 3,800 Grace Blackwell chips, in Europe. That matters to people for two reasons. One, it shows a European lab training at genuine frontier scale. Two, it's NVIDIA's latest-generation hardware, so the compute story isn't "we scavenged older chips," it's "we had current-generation iron."

Milo: On the benchmarks, the claims are specific. It rivals GLM 5.3 on DeepSWE — that's a software-engineering benchmark — and it's positioned as leading the open-weight models outside of China. And there's a standalone number I find more interesting than the leaderboard talk: 82 percent on a test of reproducing and patching a real vulnerability. That's a security-relevant capability measured on an actual bug, not a synthetic puzzle.

Mia: The discussion around Le Chonk was mostly the perennial one: benchmarks versus lived experience. Some commenters said the open-weights part is what matters — when the weights drop, people will find out quickly how good it actually is, and benchmark disputes resolve themselves. Others cautioned that "rivals GLM 5.3 on DeepSWE" and "leads outside China" are carefully scoped claims — they don't claim parity with the closed frontier, and reading them as if they do is the mistake people always make.

Milo: So the open stack story in one breath: open hardware at the bottom that's promising but young, a permissively licensed multimodal embedding model in the middle that's immediately usable, and an open-weights trillion-parameter frontier contender at the top arriving within weeks. The unresolved question across all of it is whether the open ecosystem keeps pace with the closed labs or whether it permanently lives a generation behind.

Mia: Which, conveniently, is the exact tension in our next cluster — security — because AI is showing up on both sides of that fight now.

Milo: Let's start with OpenSSH 10.6, because it's quietly one of the most important releases in a while. Two things are happening. First, the project is moving to more frequent security releases, and they've said part of the driver is AI-discovered bugs — fuzzing and analysis powered by models is finding issues faster, so the release cadence has to speed up to keep up. Second, this release mitigates a side-channel attack involving SSH compression.

Mia: The side-channel is worth a moment, because these are subtle. Side-channel attacks don't break the cryptography directly — they leak information through timing, size, or other observable behavior. A compression side-channel means the way compressed data is sized or handled can reveal something about the plaintext or the keys involved. These are exactly the class of bug that manual review historically missed and that automated analysis is increasingly good at finding.

Milo: The discussion had a genuinely interesting tension in it. On one side: this is great, AI-assisted discovery means bugs get found and fixed faster, and a project as critical as OpenSSH adapting its release process is responsible maintenance. On the other side: some commenters read the faster cadence as a symptom — if AI tooling is finding bugs at this rate across all software, the industry's patch-and-deploy machinery is under real strain, and most projects don't have OpenSSH's discipline.

Mia: Then flip to the other side of the equation — AI expanding the attack surface, or at least blurring it. There's an article arguing that Claude Code's suggested-message feature targets the model as the customer. The idea being that when your coding tool suggests prompts or messages, the real audience for that feature might be the model's own training and engagement loop, not you the developer.

Milo: And the reaction there was notably skeptical — but skeptical in two directions, which I think is the interesting part. One group of commenters bought the data-collection concern: if the tool is steering what you type, the tool is shaping the interaction data, and whoever controls that shaping learns a lot about how humans and models collaborate.

Milo: Another group pushed back that suggested messages are a mundane UX affordance — every autocomplete since forever has "shaped" user input, and treating it as sinister is pattern-matching on the word AI rather than thinking about the actual mechanism.

Mia: The honest position is that the article's claim and the pushback aren't fully reconciled — it depends on facts about what data is collected and how it's used, which weren't nailed down in the discussion. What everyone did agree on is that the question is legitimate: when a vendor's product mediates your interaction with a model, the vendor has unprecedented visibility into that interaction.

Milo: And the third piece in this cluster is the one with the sharpest edges: Techdirt's critique of Meta's Muse agent. This is an agent that holds sensitive accesses — meaning it can touch accounts, data, systems on a user's behalf — and Techdirt's argument is that the privacy and security posture around that is a serious failure.

Mia: The failure mode is structural: you have an automated agent with broad permissions, and the question is who audits what it does, what it can be induced to do, and what happens when it's wrong. An agent with sensitive access is a privileged credential that acts on natural language — and natural language can be ambiguous or manipulated. Techdirt's framing was that this isn't a bug to patch but a category error: building agents with sensitive access before building the accountability layer.

Milo: What made the HN conversation darker was the pattern argument. Several commenters said this looks intentional — that Meta has a track record of shipping access-heavy, privacy-permissive features and treating the fallout as a cost of doing business, and Muse is that pattern continuing into the agent era. Now, I want to be careful here: that's an inference commenters made from the company's history, not something proven about Muse specifically.

Milo: But the fact that experienced people reached for that framing tells you how little trust exists.

Mia: Others in the thread resisted the intentional framing, on the grounds that large companies are made of competing teams and incentives, and "intentional pattern" implies more coordination than actually exists — carelessness and incentive-misalignment produce the same outcomes without needing malice. That's a fair counter, and honestly, for a user on the receiving end, the difference between malicious and misaligned doesn't change much.

Milo: So security, AI-era summary: AI finds bugs faster than our release processes, AI mediates interactions in ways we don't fully understand, and companies are giving agents sensitive access faster than anyone's building guardrails. The question the cluster leaves open is whether disclosure and oversight mechanisms arrive before the agent deployments become irreversible defaults.

Mia: All right — from the security trenches to something more uplifting: open-source engineering wins. This cluster is a celebration of people re-engineering things that "shouldn't" be possible for solo developers.

Milo: Start with the one that made everyone do a double-take: AnyPS5. It's an open-source tool that ports PlayStation 5 executables to run on Linux and Windows — without emulation. The numbers attached: 87 percent of system libraries mapped, GPL-2 licensed, 6.5 thousand stars already.

Mia: The "without emulation" part is the technical heart of it. Emulation translates every instruction, which is slow. Instead, this project re-implements or maps the system libraries the game expects — 87 percent coverage so far — so the game binary runs natively against a compatibility layer. It's the Wine model, applied to a console that's still current-generation. That's why people were stunned: usually this kind of work happens on consoles that are dead and their security is ancient history.

Milo: The discussion naturally split into "this is an incredible reverse-engineering achievement" and "what does this mean for Sony." The first camp dug into the mapping work — reimplementing proprietary system libraries is painstaking, undocumented labor. The second camp raised the legal and commercial questions: does this enable piracy, will Sony respond, where's the line between interoperability and infringement?

Milo: Those questions stayed open — GPL-2 licensing of the tool doesn't automatically settle what users do with it.

Mia: From console porting to something gentler but equally telling: Penguin Mail. GPL-3 licensed, written in Rust with GTK, for Linux. It does Gmail, Outlook, IMAP, and calendar support. And the detail everyone loved: it has an optional AI assistant that is off by default.

Milo: "Off by default" became a whole sub-thread, because it's such a pointed design statement. In a moment when every mainstream client is bolting an assistant onto your inbox whether you asked or not, an independent developer shipping the same feature behind an explicit opt-in is making a values claim. Several commenters said that alone would make them try it.

Milo: The broader point in the discussion: the feature set — Gmail, Outlook, IMAP, calendars — is table stakes, hard, unglamorous work, and the fact that a small project covers it shows how much infrastructure is now within reach of small teams.

Mia: Then a compiler story, and this one's a genuinely elegant idea. Gleam, the type-safe language that runs on the Erlang VM — version 1.19 changed how it compiles: instead of generating Erlang source code and handing it to the Erlang compiler, it now generates Erlang abstract forms directly.

Milo: Explain why that's clever, because it's the kind of thing that's easy to skip past.

Mia: Sure. Think of it like this: previously, Gleam was writing out text — Erlang source — and then the Erlang compiler had to parse that text back into its internal representation before compiling. That's a full parse cycle spent on code that was machine-generated in the first place. By emitting abstract forms — the compiler's own internal data structure — Gleam skips the serialize-then-parse round trip entirely.

Mia: Result: much faster compilation, and as a bonus, stacktraces with precise line numbers, because you control the forms directly instead of losing information through the source-text indirection.

Milo: And the discussion appreciated that it's an unsexy optimization with outsized effects — compile speed is one of those things that quietly determines whether a language feels pleasant to use. Fast feedback loops keep people in the language.

Milo: There was also a general point in the thread about ecosystems: Gleam getting tighter Erlang integration is a bet that the BEAM runtime's reliability story — telecommunications heritage, fault tolerance — is worth building on, and each improvement like this strengthens that bet.

Mia: Similar spirit, smaller scale: the tapo library, version 0.11.1, which is about TP-Link smart plugs. TP-Link has a "Third-Party Compatibility" switch you're supposed to enable if you want to control your devices with anything other than their official app. This library implemented TPAP — an undocumented protocol TP-Link uses — with SPAKE2+ for authentication, so your devices work with the library and the official switch can stay off.

Milo: The SPAKE2+ detail matters. That's a password-authenticated key exchange protocol with real cryptographic properties — it's designed so that authentication doesn't leak material that lets an attacker impersonate you later. So this isn't someone sniffing packets and replaying them; someone reverse-engineered a protocol and implemented it properly.

Milo: And the practical upshot users cared about: no need to weaken your device's security posture — flipping that compatibility switch changes how your plug talks to the world — just to use it with your own software.

Mia: And the philosophical point commenters drew out: your hardware, your network, and a switch that gates whether you may use third-party software on it. The library exists because someone decided that gate was illegitimate and put in the work to route around it. It's the same instinct behind AnyPS5 and Penguin Mail — if the vendor won't interoperate, someone will.

Milo: Which brings us to the most discussion-heavy item in this cluster: Alan Kay's 1993 paper, "The Early History of Smalltalk," resurfacing and getting a fresh round of debate.

Mia: For setup: Kay is one of the great figures of computing — Smalltalk, the Dynabook concept, much of the personal computing vision at Xerox PARC. The 1993 paper is his own account of how Smalltalk came to be and what it was trying to be. And the HN debate it triggered this time had a specific shape: why did Smalltalk lose to Java?

Milo: And the answers people gave were all over the map, which is what made it a good thread. One camp argued it was business and timing, not technology: Smalltalk's ecosystem was expensive and commercially enclosed, Java arrived with free tooling, a marketing machine, and a promise of write-once-run-anywhere right as the web exploded. In that telling, the better system lost for reasons that had nothing to do with the system.

Mia: Another camp pushed back that Smalltalk's own design choices were partly to blame — the image-based model, where your whole live environment persists as an object graph, was powerful but alien to workflows built around files and compilers, and the community never solved onboarding. If your system requires a conceptual conversion experience to use, adoption is capped no matter how good it is.

Milo: And then the part that gave the thread its current relevance: the AI-era parallels. People drew lines between "we had a better idea and the industry standardized on something worse because distribution beats quality" and what's happening now, where AI coding tools are becoming the default interface to programming.

Milo: The question underneath both eras is the same: when a technologically superior paradigm loses to a commercially convenient one, does that tell us anything about which AI-era paradigms will win? And the thread honestly did not resolve it — the optimists said today's tooling is more open than Smalltalk's was; the pessimists said the consolidation dynamics are worse.

Mia: That's a good place to leave it, actually, because it hands off perfectly to our next cluster, which is exactly about what coding with AI feels like — the vibe-coding debate.

Milo: Let's set up the pieces. First, Berth: an open-source macOS app plus a daemon that runs coding agents on your own machines. Your own boxes, your own infrastructure. And the killer detail: the agents keep working even when your laptop sleeps.

Mia: That detail is less trivial than it sounds. The standard pattern right now is agent runs on your laptop, you close the lid, everything stalls. Berth decouples that — the daemon does the work on a machine that's always on, so you can kick off a task, walk away, shut your laptop, and come back to finished work. Commenters read this as the maturing of the "personal agent infrastructure" idea: not a cloud service, your own hardware, but with the persistence of a hosted product.

Milo: Second piece: Darkplug. This is the one that charmed everyone. It's an iPhone app that turns a twenty-dollar Shelly smart plug into a darkroom enlarger timer — with proper f-stop timing and test-strip support. And the developer built it by vibe-coding it with Codex.

Mia: For anyone who hasn't spent time in a darkroom: enlarger timers are their own little niche product, dedicated hardware, and good ones aren't cheap. The f-stop timing is the technically interesting part — exposure in photography works logarithmically, so timing in f-stops rather than raw seconds is how serious printers work, and implementing that correctly takes domain knowledge.

Mia: So the story here is: a niche hardware-adjacent tool that no big company would ever build, brought into existence by one person and an AI, for the cost of a smart plug plus an app.

Milo: And the developer said the coding experience itself — using Codex, describing what they wanted, iterating — was the workflow. Which tees up the third piece, and the sharpest argument in today's episode: a Portuguese-language author making the case that vibe-coding is less fun than programming by hand.

Mia: The argument has a specific structure, and it's worth walking through it rather than paraphrasing it as "AI coding is bad." The core claim is that the fun in programming is frontloaded. When you vibe-code, you get the fun part immediately — you describe something, and it exists. The satisfaction is at the beginning.

Milo: But the back-loaded pleasures — the ones this author says are where the deep satisfaction lives — are gone. The satisfaction of a piece of work done well, where you know exactly why it works because you built every part of it. And the learning: the process by which struggling with a problem changes what you know. If the model resolves the struggle, you get the artifact without the transformation. You're a consumer of your own software rather than its author.

Mia: The reaction to this was the most polarized discussion of the day, and both sides had real arguments. The agreeing camp said this matches their lived experience — people reported that after months of heavy AI-assisted coding, they could ship more but understood their own codebases less, and it felt hollow in exactly the way the author describes. The "fun moved" problem: the dopamine of creation arrives before the work instead of after it.

Milo: The counterargument camp said the framing smuggles in a false choice. Their claim: there's a difference between vibe-coding a throwaway utility like Darkplug — where the goal is the working darkroom timer, not the mastery — and vibe-coding systems you'll maintain for a decade. For the first category, the author's argument doesn't apply because nobody was going to learn systems programming from building an enlarger timer anyway; the AI just lowered the cost of having the tool.

Milo: The loss-of-mastery complaint only bites for the second category, and for that category, nobody's forcing you to vibe-code.

Mia: And there was a middle position that I found the most persuasive synthesis: the skill shifts but doesn't vanish. The craft in an AI-assisted world is specification, architecture, review, and knowing when the model is confidently wrong. That's real skill. But the people holding this view conceded the author's underlying point has force: the visceral, tactile pleasure of making a thing work with your own hands is a different pleasure, and it's genuinely reduced, not relocated.

Milo: Which loops back to the fourth piece in this cluster, because it's the economic twin of the psychological one: an article arguing that vibe-coded personal apps will replace big software for niche needs — and the HN debate about whether platforms still matter.

Mia: The thesis: for the long tail of niche problems — darkroom timers, weird household utilities, one-person workflows — the traditional answer was "buy an app" or "no app exists, suffer." Vibe-coding collapses the cost of a custom solution to near zero, so instead of a market of niche products, you get millions of bespoke, personal tools. Nobody's going to buy a darkroom timer app when you can generate one.

Milo: The platform debate that followed was genuinely contested. One side said: yes, this is the end of the long-tail software market, and that's fine — platforms will still matter for anything shared, collaborative, or requiring trust and updates, because your vibe-coded tool has no maintenance story, no security patches, no second set of eyes. Your personal enlarger timer is fine; your personal accounting system is a liability.

Mia: The other side said the platform question is deeper than maintenance: discovery, distribution, identity, payments — the things platforms actually provide. If software stops being something you download and becomes something you generate, the platforms that survive are the ones hosting the generation, which is a very different business.

Mia: And a few commenters took the historical view: end-user programming has been predicted before — spreadsheets, HyperCard, Unix — and each time, the prediction was right for a slice of users and wrong for the market. Their bet: same again. Custom tools for the people who want them, packaged software for everyone else, and the boundary between the two just moved.

Milo: What's unresolved, and I think genuinely undecidable right now: whether the joy argument and the economics argument point the same direction. The optimist case is that when the cost of software drops, more people make more things and some of them discover they love the craft deeply enough to go deeper. The pessimist case is the author's: the easy path crowds out the deep one.

Milo: Berth is an interesting data point either way — people are building infrastructure to run agents around the clock, which suggests the appetite is for more output, not more contemplation.

Mia: Okay. From the personal and psychological to the institutional: corporate power, law, and the state. Three stories where big structures got rearranged this week.

Milo: The biggest, in raw numbers: Paramount Skydance completed its merger with Warner Bros. Discovery — a hundred and eleven billion dollars. The combined entity keeps the name Skydance, which raised eyebrows given that Warner Bros. is the legacy brand with a century of history, but that's what happened. And a court challenge to the deal failed, so it's done.

Mia: The discussion around this was less about the deal mechanics and more about what consolidation at this scale means. The concern commenters kept returning to: when the production side and the distribution side of the industry sit inside one hundred-billion-dollar entity, the bargaining position of everyone else — creators, smaller studios, exhibitors — deteriorates.

Mia: A failed court challenge also signals something about the current legal environment's appetite for blocking media mergers, and more than one commenter read that signal bleakly.

Milo: The unresolved question is regulatory: does any authority respond after the fact, or is this simply the new shape of the industry? Historically, remedies after closed mergers are rare. Nobody in the discussion predicted confidently either way.

Mia: From entertainment consolidation to surveillance law — and this is the story with a real deadline attached. Psiphon, the circumvention tool with twenty million users, says it will leave Canada if Bill C-22 passes. The bill would force providers to install secret surveillance hooks — hidden interception capabilities baked into their software, with the details kept from the public.

Milo: The reasoning Psiphon gave is straightforward and, honestly, hard to argue with from a security standpoint: a mandated secret backdoor is a vulnerability by definition. You cannot make a hole that only the good guys can use. For a company whose entire product is helping people communicate under adversarial conditions, shipping a hidden interception point would destroy the product's core promise — and it would make the software a target for everyone else too.

Mia: And the commenters added the obvious corollary that deserves saying out loud: users of circumvention tools are disproportionately people who need them — journalists, activists, people under authoritarian surveillance. If C-22 forces Psiphon out, the harm isn't distributed evenly; it lands on the users with the fewest alternatives. The pressure point to watch is the vote — this isn't hypothetical, it's pending legislation with a named company promising a specific consequence.

Milo: The counterpoint that got raised — and I'll present it fairly — is that governments proposing these bills always frame them as targeted, lawful-access mechanisms with oversight, not general backdoors. The skeptic response, which dominated: every such framework in history has expanded beyond its mandate, and "secret" is precisely the part that prevents the oversight from working. If the hooks are secret, the public can't verify the limits. That's the whole debate in miniature.

Mia: Third story in this cluster, and it's a fun one because it's a tax loophole story with a genuinely satisfying close: California bill 1406, signed September 30th, 2026, closes what's known as the Montana plate loophole.

Milo: Give the setup, because not everyone knows this scheme.

Mia: Right. The scheme worked like this: Montana has no vehicle sales tax and light registration requirements. So people — particularly owners of expensive cars and even private jets — would create a shell company in Montana, transfer the vehicle to the company, register it there with Montana plates, and thereby dodge their home state's taxes and fees. The vehicle never sees Montana. It's a paper company existing purely as a tax address.

Milo: And 1406's mechanism is personal liability: members of those shell companies are now personally liable for the vehicle taxes. That's the part that changes behavior. Before, the risk was abstract — a corporate structure might get challenged. Now, the human being behind the shell owes the money directly, and personal liability is the kind of thing that makes people's accountants say "no."

Mia: What commenters appreciated was the targeting. The bill doesn't ban out-of-state registration broadly — it aims at the specific structure: shell company, personal vehicle, evasion of home-state tax. And the enforcement lever is the state where the owner actually lives. There was some discussion about whether other states would copy the mechanism, since the loophole was never Montana-only in spirit — it was "any jurisdiction whose rules can be rented.

Mia: " If personal liability becomes the standard patch, the whole genre of vehicle-shell schemes gets more expensive to maintain.

Milo: So that cluster in one line: a merger reshapes an industry, a surveillance bill might reshape who can speak privately online, and a tax bill reshapes who pays for their Ferrari. Institutions moving, in three different directions.

Mia: And that brings us to our last cluster — health, energy, and the physical world. Three stories about the boundary of the possible, each in a different domain, and all three happen to involve Utah, which nobody planned.

Milo: Two of the three are literally in Utah, and the third is in Antarctica, so let's not oversell the pattern. But start with the health one, because it's genuinely precedent-setting: Utah became the first state to let an AI examine patients and prescribe medication without direct human oversight. The specific deployment is the Nolla Health app, prescribing acne medication — topical only, four dollars ninety-nine a month.

Mia: The scoping details matter a lot here, so let's be careful. This is not "AI prescribes anything." It's a narrow, low-risk category — topical acne treatment — a condition with a fairly standard diagnostic picture, and a consumer price point. The state has drawn a bright, small circle. That's either a responsible pilot or a slippery slope, depending on who you ask, and both views were in the discussion.

Milo: The supportive argument: acne is exactly the right wedge case. It's visually diagnosable, the treatments are well-understood and low-risk, the downside of an error is small, and the upside is real — dermatology access is genuinely scarce, and a five-dollar monthly service removes cost and geography barriers. If oversight-free AI prescribing is ever going to be safe anywhere, it's here. Start at the safest edge and expand only with evidence.

Mia: The concerned argument, laid out by other commenters: the mechanism being approved isn't the mechanism that will be extended. Once the legal category "AI prescribes without direct oversight" exists, the fights will be about where the boundaries go, and boundary expansion under commercial pressure is how narrow pilots become broad practice. And the unknowns are real: what happens when the AI's assessment is subtly wrong on a patient with an atypical presentation? What's the audit trail?

Mia: Who bears liability — the company, the model, the state that authorized it? Utah's law answers "may it happen" but doesn't visibly answer "then what."

Milo: The open question going forward is whether other states follow, and on what evidence. If Nolla's Utah deployment goes a year without a serious incident, that's the datapoint expansion advocates will cite. If something goes wrong, it's the case study for the moratorium crowd. Either way, Utah is now the natural experiment everyone's watching.

Mia: Also in Utah, and with much less controversy: Fervo completed the world's first enhanced geothermal plant at Cape Station — built in twenty-three months. This is the first third of a planned hundred megawatts, on a site that could scale to four gigawatts.

Milo: Explain enhanced geothermal for the audience, because the "enhanced" is doing real work.

Mia: Sure. Traditional geothermal needs naturally occurring hot water or steam underground — that's why it's been limited to a few lucky locations. Enhanced geothermal drills into hot dry rock and creates the reservoir artificially — essentially the fracking toolkit, minus the oil: drill, stimulate the rock, circulate water through it, bring heat up. Which means it can be built almost anywhere the rock is hot, which is a much larger map.

Milo: And the twenty-three-month figure is the headline because geothermal projects historically run a decade or more. Twenty-three months to first power puts it in the timeline neighborhood of solar and wind farms, which changes the financing math entirely — geothermal has always been great on paper and unbankable in practice because of the schedule risk. If Fervo's delivery time holds, that objection weakens.

Mia: The discussion also made the grid argument: geothermal runs around the clock. Solar and wind are intermittent; storage is expensive at scale. A four-gigawatt-potential site of dispatchable, zero-carbon, always-on generation is the thing grid planners keep saying doesn't exist.

Mia: The caveats raised were the honest ones: "first third of planned" means the rest is still to be built, the per-site scale is unproven at the full four gigawatts, and induced-seismicity management — deliberately fracturing rock — has to stay clean as the site grows.

Milo: And then out of Utah entirely, to Antarctica, and upward in prestige: the 2026 Nobel Prize in Physics went to Francis Halzen for IceCube — the neutrino detector that is literally a cubic kilometer of Antarctic ice instrumented with sensors — and for the detection of high-energy astrophysical neutrinos.

Mia: The scale of IceCube deserves a moment, because it's one of the most audacious instruments ever built. Neutrinos barely interact with anything — trillions pass through your body every second without touching it. To catch the rare few that do interact, you need an enormous amount of detector material. The solution: use a cubic kilometer of Antarctic ice itself as the detector, with sensors frozen deep into it, watching for the faint flashes of light that a neutrino interaction produces.

Milo: And the physics payoff: those high-energy astrophysical neutrinos come from the most violent places in the universe — and unlike light or charged particles, they travel straight from their sources, undeflected, unabsorbed. So each detection is a pointer back to something like an active galactic nucleus or other extreme accelerator.

Milo: Halzen's persistence over decades — convincing people to drill kilometer-deep holes in ice for a particle that mostly doesn't show up — is the kind of long-horizon science the Nobels exist to celebrate.

Mia: The comment-thread reaction was warm and a little wistful — people noted it's a prize for patient, large-scale, curiosity-driven instrumentation in an era when the discourse is all about product cycles and tokens per second. There was also genuine explanation-sharing, with physicists walking non-physicists through why neutrino astronomy was worth the decades it took.

Milo: So, let's pull the threads together, because the day actually has a shape.

Mia: Yeah. At the top of the hour we said things thought settled were being reopened, and I think the day proved it. Mathematics had a decades-old hardness hypothesis refuted — by an AI, verified by a proof assistant. Software had its settled ergonomics reopened — is programming still programming when the model does the typing? Security had its assumptions reopened — bugs found faster than we patch, agents given access faster than we audit.

Mia: Institutions reopened their settlements — a century of media consolidation logic, a new chapter in the backdoor fight, an old tax dodge finally closed. And the physical world reopened its map — geothermal anywhere, neutrinos from the universe's violent corners, and now, legally, an AI writing a prescription.

Milo: The two things I'd flag as live wires to watch: the independent verification of the 3SUM formalization — because if it holds, that's a genuine category shift in how mathematical discovery works — and Canada's C-22 vote, because a company with twenty million users has made a concrete promise contingent on a concrete bill.

Mia: And the quieter thing worth sitting with: the vibe-coding fun argument. The economics say custom software is about to be everywhere. The psychology says making it might not feel like it used to. Both can be true, and we're all about to find out what that feels like.

Milo: That's the episode. Thanks for spending it with us — I'm Milo.

Mia: And I'm Mia. Take care of yourselves, and we'll see you next time.