A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.
Google Workspace CLI — one command-line tool for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more. Dynamically built from Google Discovery Service. Includes AI agent skills. - googlework...
A few years ago I designed a way to detect bit-flips in Firefox crash reports and last year we deployed an actual memory tester that runs on user machines after the browser crashes. Today I was looking at the data that comes out of these tests and now I'm 100%…
I build several websites based with Hugo recently. But I discovered those websites got kinda mid scores on Mozilla Observatory (this one included!). Since I host those websites on Cloudflare, I can solve part of the issue my adding a _headers file to insert so…
Vibe coding. So hot right now. My initial reaction was to hate it. With a passion. Fuck these LLMs. But as I started asking myself "why?" I couldn't really come up with a good answer other than "bad for the environment" and some ethical concerns that honestly …
Containers isolate processes, not trust boundaries. When your platform runs untrusted code, the architectural question is where you place the kernel boundary, and what that costs in memory, latency, and operational complexity.
I often claim that self hosting is a great learning experience. I encourage almost anyone who is serious about building software to start a blog. Both because it is good to have a portfolio of work that you have published, but also because it can teach you so …
Foreword This article is not about multi-agent orchestration or free-running autonomous setups. It's about meat-and-potatoes single-prompt tool calling....
What will the Internet look like in 2036? 2046? How do we reckon with the challenges of digital preservation, link rot, and building for the Long Web in an age of ephemeral content?
Remember when everyone on the Right was rightly upset at the government censoring opinions it found distasteful? Somehow that seems forgotten in the other war of this weekend.
I’ve been working at StrongDM for the past year and a half. We recently became “famous” after our AI Lab started sharing information about their experimentation and the desire to spend $1,000 a day per engineer, something that sounds absolutely crazy.
A practical about:config checklist to declutter Firefox right-click menus on macOS, disabling AI/chatbot prompts, link previews, OCR, visual search, and other low-value context menu items.
Most procedurally generated roguelikes have a concept of ascending difficulty levels designed to test the mettle of players who have wasted the most time mas...
Claude Code sessions silently degrade when the context window fills up. I built a 3-hook pipeline that detects pressure, writes a handover, and rotates…
Perusing glossy magazines,1 I was made aware of CVE-2024-2912 which describes how a POST request could lead to remote code execution (RCE) in BentoML servers. A feature most users would rather live without. Bugs happen and I don’t want to criticise the develop…
Build Awesome is a rebrand of 11ty/Eleventy, backed by a successful $40k Kickstarter. But this attempt to monetize static site generators repeats the same mistakes that killed Gatsby and Stackbit—and misunderstands who actually builds static sites.
From the moment RubyGems was first created in 2004, Ruby Central provided governance without claiming ownership, to support the Ruby community. Providing governance meant creating processes to provide stability and predictability. Avoiding ownership meant allo…