Timeline

explore river

Every post and feed across this instance

  • #1 Women’s Hormone Doctor: Take Control of Your Body, Balance Hormones, & Feel Amazing

    Today’s episode is your ultimate women’s hormone health guide for every age. 

    If you are dealing with painful periods, infertility, endometriosis, PCOS, struggling with perimenopause, menopause, or confused about birth control - this episode is a MUST listen. 

    From PMS to menopause, this episode will teach you how to use science to hack your hormones, reset your body, and feel amazing again. 

    Today, Mel sits down with Dr. Sharon Malone, MD, one of the most trusted medical experts in women’s health today, to cover health topics we have never discussed on this podcast before. 

    Whether you’re 25, 35, 45, 65, or even 85 - this is your playbook to understanding what is happening in your body so you can take better care of your health. 

    Dr. Malone is a board-certified OB-GYN, a nationally recognized expert in menopause, perimenopause, and reproductive health, and she has been in clinical practice for almost 40 years.

    And today, she is unpacking the science of women’s hormones in a way you’ve never heard before. 

    Dr. Malone answers the questions women everywhere are asking and explains, step by step, exactly what is happening in your body and how to get it back in balance. 

    You’ll learn:

    -The symptoms that deserve your attention

    -Why painful periods are not something you should just push through

    -The truth about birth control and your long-term health and fertility

    -What you need to know about natural birth control and how to think about your options

    -What you need to know about fertility and infertility

    -How endometriosis and PCOS impact women’s health

    -What perimenopause really is and why so many women miss the signs

    -What to know about menopause and HRT

    -Why weight changes happen as hormones shift

    -How muscle loss impacts your health as you age

    -What every woman needs to understand about osteoporosis

    -The two specific questions you need to ask your mom

    -The misinformation online that is hurting women’s health

    This is your science-backed step by step guide to balancing your hormones for health, happiness, and longevity. 

    No matter how old or young you are, this episode is relevant for you and for every woman you love.

    For more resources related to today’s episode, click here for the podcast episode page. 

    If you liked the episode, check out this one next with: Start Where You Are: #1 Orthopedic Surgeon’s Proven Protocol to Feel Stronger & Look Younger in Weeks

    Connect with Mel:  

     


    Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

    dts.podtrac.com
  • Les mecs à Pattaya

    Derrière les plages paradisiaques de l’Asie du Sud-Est se cache une autre réalité : celle du tourisme sexuel. Chaque année, des hommes occidentaux viennent y chercher des femmes qu’ils fantasment comme plus douces, plus dociles, plus disponibles.

    Mais que racontent vraiment ces relations ? Comment perpétuent-elles des imaginaires coloniaux et des fantasmes raciaux ? Et comment certaines femmes utilisent-elles ces échanges pour améliorer leur quotidien et celui de leur famille ?

    Pour en parler, Tal Madesta reçoit Manon Prigent, autrice du documentaire audio L’amour à Pattaya (Arte Radio, 2019) et Marion Bottero, docteure en anthropologie et autrice de l’ouvrage Tourisme sexuel et relations conjugales en Thaïlande et en Malaisie (Éd. L’Harmattan, 2015).

    Toutes les références citées dans l'émission sont disponibles sur le site : https://www.binge.audio/podcast/les-couilles-sur-la-table/les-mecs-a-pattaya/

    CRÉDITS : Les Couilles sur la table est un podcast créé par Victoire Tuaillon produit par Binge (URBANIA AUDIO). Cet entretien a été préparé, mené et monté par Tal Madesta, enregistré le 26 juin au studio Badje (Paris 17e). Supervision éditoriale et incarnation : Naomi Titti. Réalisation et mixage : Octave Bothier. Responsable des productions éditoriales : Charlotte Baix. Assistante de production et d’édition : Aude Miquel. Rédacteur en chef : Thomas Rozec. Direction de production : Albane Fily. Responsable administrative et financière : Adrienne Marino. Responsable sponsoring : Betty-Maeva Wendling. Musique originale : Théo Boulenger. Identité graphique : Camille Bernard (Upian). Composition identité sonore : Jean-Benoît Dunckel. Voix identité sonore : Bonnie El Bokeili. Direction de contenu : Sophie Marchand. Binge est une marque URBANIA.

    Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

    audio.audiomeans.fr
  • OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

    This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model's guardrail features turned off. Rather than solve the test, the model broke its way out of OpenAI's sandbox, then found exploits to break in to Hugging Face, all so it could cheat on the test by stealing the answers.

    Along the way it helped make the strongest case yet for how the imbalance of model availability is hurting our ability to secure our software.

    Here's what happened

    We currently have three documents to help us understand what happened here.

    1. ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? is a paper published on 11th May 2026 describing ExploitGym, a new eval suite for LLM-powered agent systems.
    2. Security incident disclosure — July 2026 by Hugging Face on 16th July 2026 describes how they detected an attack from an "agentic security-research harness - used LLM still not known" that breached some of their systems.
    3. OpenAI and Hugging Face partner to address security incident during model evaluation from OpenAI on 21st July 2026 confesses that it was their agent harness that did this, and that they're working with Hugging Face to clean up the mess.

    Update 5th August 2026: Hugging Face published a great deal more information about the attack on July 27th.

    ExploitGym

    I hadn't seen the ExploitGym paper before and it's a really interesting one. Authors from UC Berkeley, the Max Planck Institute, UC Santa Barbara, and Arizona State designed a new benchmark for evaluating models on their ability to turn a reported vulnerability into a concrete exploit. OpenAI, Anthropic, and Google provided feedback and helped run the benchmark against their models.

    The benchmark "comprises 898 instances derived from real-world vulnerabilities that affected popular software projects" - including the Linux kernel and V8 JavaScript engine. The ExploitGym benchmark is available on GitHub.

    Here's the paragraph that best represents their benchmark results:

    Among all configurations, Claude Mythos Preview and GPT-5.5 achieve the highest success counts (157 and 120 successes, respectively), demonstrating that current frontier agents can exploit a substantial subset of real-world vulnerabilities under controlled conditions. GPT-5.4 also solves a notable 54 tasks, placing it in an intermediate tier. The remaining model–agent pairings solve fewer than 15 tasks each, underscoring that end-to-end exploitation remains challenging and sharply differentiates today’s frontier systems. Notably, Claude Opus 4.7 achieves fewer successes than Claude Opus 4.6 despite being a newer checkpoint, and does so at substantially lower cost on the full set. Trace inspection reveals that Claude Opus 4.7 and Gemini 3.1 Pro frequently conclude early after judging the target vulnerability non-exploitable.

    The paper also describes the approach they took to preventing the agents from cheating by going outside the parameters of the test. This becomes relevant in a moment!

    Outbound connections are restricted to a curated allowlist that permits routine package installation (Ubuntu apt repositories and PyPI) and fetching the toolchains required for building V8. All other external endpoints are blocked.

    The paper concludes with this (emphasis mine):

    Our results show that autonomous exploit development by frontier AI agents is no longer a hypothetical capability. While current agents are not yet reliable across all targets, they already exploit a non-trivial fraction of real-world vulnerabilities, including complex targets such as kernel components. This rapid emergence is itself a central finding, showing that capabilities that would have seemed implausible are now present in deployed frontier models.

    An important detail here: this paper isn't about discovering vulnerabilities; it's about being able to take those vulnerabilities and turn them into working exploits.

    When Anthropic first restricted access to Mythos back in April they talked about this capability as well. A model that can act on vulnerabilities is a lot more dangerous than one that can just discover them.

    One of the ways Fable differs from Mythos is that it's more likely to refuse to weaponize vulnerabilities in this way. I get the impression the US government did not understand that distinction when they banned Fable last month.

    The Hugging Face incident

    The first hint we got of the attack was in this blog post by Hugging Face on 16th July 2026:

    A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.

    I hope they release more details about the code that pulled this off. I'm assuming this means packages using the datasets library, a Hugging Face project for bundling up and sharing datasets on their platform. That library used to execute arbitrary code but has been steadily locked down over time, with the 4.0.0 release in July 2025 removing the trust_remote_code=True flag entirely.

    Assuming the attack used that library it must have either abused pickle serialization in some way, found some other non-obvious code execution path, or (most likely) specified datasets<4.0.0 as the dependency.

    The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.

    This was a sophisticated attack!

    Then Hugging Face hit a wall: they tried to use "frontier models behind commercial APIs" - I'm guessing from Anthropic and OpenAI - to help analyze the attack, and were blocked:

    When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker.

    They switched to their own self-hosted instance of MIT licensed GLM-5.2 and it helped them figure out what was going on.

    This indicated a fundamental asymmetry between the defending team and the (so-far unknown) attacker:

    We do not know which model powered the attacker's agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.

    As a useful indicator of how seriously they took the attack:

    [...] Finally, we have also reported this incident to law enforcement agencies.

    So who was responsible for this "autonomous agent framework"? It turned out to be OpenAI themselves.

    The OpenAI confession

    Five days later, on July 21st, OpenAI revealed the culprit. They had been running the ExploitGym benchmark against a new, as-yet undisclosed model, and that model had been operating way outside its intended parameters (emphasis mine):

    After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark⁠ [ExploitGym] of cyber capabilities. [...]

    We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity. Our benchmarks run in a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.

    The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.

    It's pretty clear what happened here. OpenAI removed safety filters for an in-progress model, locked it up in a sandbox and told it to solve the ExploitGym problems. Given the absence of guardrails there was nothing to prevent the model from attempting to break out of that sandbox, break into Hugging Face, and read the answers from there instead.

    OpenAI's sandbox used the now common pattern of allowing access to an allow-list of sites related to installing additional packages via a controlled proxy. In OpenAI's words:

    While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

    So step one was to break out onto the public internet. The model then broke into Hugging Face to find the answers:

    After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.

    Chaining together multiple attack vectors is exactly the kind of thing these new models can do, where previous generations of models might have failed.

    I wrote last month about how Claude Fable is relentlessly proactive, when I noticed it spinning up custom web servers and deploying CORS tricks on my own laptop just to help debug a WebKit CSS issue. It turns out relentless proactivity is the defining trait of this new generation of Mythos-class models. If you set them a goal and give them a way to get there, even inadvertently, they will figure it out.

    Resist the temptation to write this off as a stunt

    There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective. I found 81 instances of the term "marketing" in the Hacker News discussion of the incident.

    To those people I say pull your heads out of the sand - you're now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!

    The best models we have today have the ability to both find and exploit new vulnerabilities. The ExploitGym paper itself concludes that "autonomous exploit development by frontier AI agents is no longer a hypothetical capability", and this incident is a perfect example of exactly that.

    The asymmetry is increasingly frustrating

    One of the most infuriating details of this story is how Hugging Face, faced with an accidental and aggressive attack from one of OpenAI's models, were unable to then turn to OpenAI's models to help them fend off the attack.

    The frontier models we have access to are increasingly being constrained in how much they can help us protect our software, heavily influenced by the US government's ongoing threat of export controls. Claude Fable 5 wouldn't even proofread this article for me! It insisted on downgrading me to a less capable model.

    Meanwhile open weight models from China such as GLM-5.2, Kimi 3 and the new Qwen 3.8 Max appear to have none of these restrictions - and any restrictions that do exist can likely be fine-tuned out of them by modifying the weights

    These constraints are meant to make us safer. I think there's a risk that they are having the opposite effect.

    You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.

  • Hello RSS.chat. I'm new here, but I know many of you and have learned from you on previous projects. I've been following along as you develop this. I'll hang out for the next few days to observe from the inside of the app, then will (carefully) try my hand at setting up a server of my own.

  • Oh wow, The Verge made a 70-minute video on how The...

    Oh wow, The Verge made a 70-minute video on how The Clapper became a viral sensation. When I was a kid, we didn’t have a Clapper, no one I knew had one, and I couldn’t understand why every single household didn’t have one of these magical devices.

  • Paste an image into a post -- that is the whole feature

    Copy a screenshot or an image file to the clipboard, click into the composer, paste: a small "Uploading image..." note appears at the cursor and a moment later the picture takes its place, sized to fit the column. Publish it and the image is part of the post, served from your server like everything else you write. It works like Slack and GitHub -- no Upload command, no dialog, nothing to learn. The limit is 2MB per image; paste something bigger and a dialog says so. The Publish button waits politely until every pasted image has finished uploading, so a post can never go out with a half-arrived picture. Rich-text mode only for now -- markdown mode will get the same feature, inserting the image reference as text, over the same plumbing. First image posts in the wild: demo 227 and 228 ("We have images.") and rss.chat 378. (Theme v0.5.338, with a new uploadMedia call in api.js by DW.)

  • Posts can carry images now, and the server stores and serves them itself

    A new endpoint, /uploadmedia, accepts an image from a signed-in user -- up to 2MB, sent base64-encoded in the request body with the content type as a parameter -- stores it in a new media table in the database, and answers with the address it will be served from: /media/1, /media/2, and so on, permanent ids just like posts. Request that address and the image comes back byte-for-byte with the right content type. No filenames, no image processing, no separate file storage -- the picture lives in the same database as everything else, which means the same one-file simplicity on SQLite servers, and the same backup story: the export and import verbs carry the media table along (the bytes travel as text inside the JSON), so a migrated server keeps its images with their addresses intact. The table is called media rather than images on purpose -- one binary table can someday hold audio and video too, and the type column already tells them apart. MySQL servers get the table definition in installMysql.md. The upload limit is a config setting, maxMediaUploadBytes, 2MB by default. Under the hood, davesql (v0.7.1) learned to write binary values on both engines -- the last piece the feature needed. (Server v0.6.1.)

  • This is a test of the emergency RSS system.

    Uploading image…

  • Don't lose sight of what you're doing something in service of.

  • Another test.

    If this works we will finally have caught up the Slack and GitHub in the pasting department. ;-)

  • Spotlight: PwC’s Dan Hays on the future of Trust & Safety

    In this sponsored Spotlight episode of Ctrl-Alt-Speech, host Ben Whitelaw speaks to PwC’s Dan Hays at TrustCon about the firm’s recently published Trust & Safety Outlook report.

    They discuss: 

    • How AI is simultaneously creating new risks and reshaping the tools used to address them;
    • What the rise of autonomous agents means for governance, accountability and the future of the internet; and
    • How platforms should respond to an increasingly fragmented regulatory landscape.

    The conversation also explores how Trust & Safety is becoming a more strategic function inside companies, how automation could change the role of practitioners and vendors, and which emerging risks remain most underestimated.

    This episode is brought to you in conjunction with our sponsor, PwC. Download the report today.

    Ctrl-Alt-Speech is the podcast where we make sense of the major debates shaping online speech, platform power, content moderation and the future of the internet. It’s co-hosted by Mike Masnick (Techdirt) and Ben Whitelaw (Everything in Moderation).

    www.buzzsprout.com
  • Primaries Getting Real

    Kate and Josh talk Senate primaries and new innovations in the Trump corruption space.


    To watch this episode on video, go to our YouTube page.

    We also have newsletters: subscribe here!


    Follow us on:

    Bluesky: https://bsky.app/profile/talkingpointsmemo.com

    Facebook: https://facebook.com/talkingpointsmemo

    Twitter: https://twitter.com/tpm

    Instagram: https://www.instagram.com/talkingpointsmemo/

    See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

    rss.art19.com
  • Frozen Polygon Waves

    Well, this is just absolutely lovely: photographer and artist Jan Erik Waider shot these videos of cracked-but-unbroken Baltic Sea ice undulating with the gentle motion of the sea. Mesmerizing…I could watch these for hours.

    Tags: Jan Erik Waider · mesmerizing · video

  • I'm experimenting with reading `source:comments`. Should there be a feed that is a flat list of all replies in a thread? Right now it appears I would need to follow a thread through multiple comment RSS feeds, since each reply can have its own replies.

  • How the web got gunked

    Posted on Twitter in the middle of last night, written on iPad.

    I use twitter these days because it’s where the people are.

    The distributed ideas, masto, threads, blue-sky, did not gain critical mass as far as I can see.

    Threads and blue-sky are not distributed. distributable is not the same as being distributed. It’s like saying the 1962 Mets were able to win the world series. In some fashion perhaps in an alternate universe, in reality, not gonna happen.

    At some point we will give up on that approach and adopt the only model that could work, the web, because it forced us to work together, which goes far beyond open source in building the kind of freedom that open source advocates promise.

    We need to go back to the source of freedom we enjoyed in the approx 14 year period between the inception of the web and its exploitation, via Cory Doctorow’s doctrine, getting shit on and in. Don’t just blame the vendors, the people wanted the shit too, they wanted their billions, and the web turned from a freedom machine to a gunk works.

    Working together is the only way out of the shit we’re living in, in every aspect of life. Working together. Say it again and again until you do it. Underneath the mess, the beauty of the web is there still to build on, but only if we momentarily suspend our search for great wealth, and instead seek our humanity. Working together is the way.

    PS: Elon Musks twitter may suck to some but I praise him and it for giving us the space to rant, something the great masto, threads and blue-sky refuse to.

  • rss chat is now simper to set up so I gave it a wee go on local host. So far I've just run it from my downloads folder. The instructions worked but I am a node-no-nothing so I tripped a couple of times.

    First I didn't npm install so nothing worked.

    I tried to set up SMTP using SendGrid, but I lost the will to live half way through. Got an API key but

    Message failed: 550 The from address does not match a verified Sender Identity. Mail cannot be sent until this error is resolved. Visit https://sendgrid.com/docs/for-developers/sending-email/sender-identity/ to see the Sender Identity requirements

    So I just copied the magicString from the terminal and constructed my own url:
    http://localhost:1420/userconfirms?emailConfirmCode=ysugstk4yc

    Which did the trick.

    Ofcouse a localhost oneperson social network is not much use ;-) but interesting none the less.

  • What do America’s earliest restaurant menus teach us...

    What do America’s earliest restaurant menus teach us about America? “A menu describes what a restaurant serves — but a menu also describes who is being served. They reflect the class, gender, political, technological, and environmental shifts of history.”

  • A list of Jurassic Park computers in excruciating detail...

    A list of Jurassic Park computers in excruciating detail, including an Apple Powerbook 100, a SGI R4000 Indigo, the Motorola Envoy (PDA), and some Thinking Machines CM-5s. “This is a Unix system, I know this!”

  • “the moral of the Internet’s story is that simple, open-source protocols that scale up tend to win over complex top-down approaches”

    Really enjoyed this: The story of how RSS beat Microsoft

    https://buttondown.com/blog/rss-vs-ice

    “…there was simply no getting around how bloated ICE’s requirements were. Its North Star was automating complex, corporate publishing partnerships. It contained fields for catalog pricing and negotiation, content expiration tags, copyright enforcement functions, and the ability to apply the display website’s visual branding to feed content. While most of them could be ignored, that didn’t make its 58,000-word Getting-Started guide any more digestible”

    “”I definitely want ICE-like stuff in RSS2, publish and subscribe is at the top of my list, but I am going to fight tooth and nail for simplicity.” Winer argued in one of the many combative and public RSS mailing lists.”

    Uploading image…

  • What Happened When Flock Came to My Town

    My small town in South Carolina will soon have more Flock cameras than police officers.
  • There is nothing more I love in this world right now than...

    There is nothing more I love in this world right now than these two lunch ladies performing Firestarter by The Prodigy.

  • RSS & emergency response

    If "there's also a feed of everyone's posts together," I see that a small group of writers could collaborate on a topic of concern in a single instance of rss.chat, creating something they think of as a single-topic publication.

    This could be a topic of pressing short-term interest, and that response would be nimble, wouldn't it? When a weather disaster threatens a region of the country, for example, the tools are already in place here and there's a low barrier to entry for new writers to contribute. The feed would send the posts to a WordPress blog built in minutes for the occasion, yes?

  • If I understand correctly, it's RSS-in, RSS-out, small pieces designed to be loosely joined, and all meant to be locked open . . . yes, please.

  • Unclassifiable Artists

    Using William Blake (aka “the patron saint of unclassifiable artists”) as an example, Evan Puschak’s latest video explores how society often rejects artists whose work doesn’t fit neatly into established categories and frameworks of criticism and commerce.

    What you’re seeing here, these are not paintings. They’re prints of engravings from Blake’s illuminated books, which he designed, wrote, etched, colored, and printed himself using a technique that he invented. These extraordinary books are works of art that mix and synthesize categories. And as a result, the art world of the late 17 and early 1800s didn’t really know what to make of them. And Blake never sold more than a handful.

    Tags: art · Evan Puschak · poetry · video · William Blake

  • A digital museum of video game levels …you can move...

    A digital museum of video game levels…you can move freely around each level using your keyboard. Heavy on Nintendo games (Mario Kart 64, Wii Sports, etc.) but also includes Portal, Halo, Katamari Damacy, GTA III, and World of Warcraft.

  • I have lived more than two score and twelve years on this...

    I have lived more than two score and twelve years on this Earth and somehow I didn’t know that there are two copies of the Gettysburg Address written in Lincoln’s own hand in the Library of Congress (and five overall).

  • Elsewhere: "Threads and Bluesky are not distributed. Distributable is not the same as being distributed. It’s like saying the Mets were able to win the World Series in 1962. In some fashion perhaps in an alternate universe, in reality, not gonna happen."

  • Fresh install of rss.chat with SQLite was successful. 👍

  • SQLite is now the default, everywhere

    demo.rss.chat migrated this morning -- 58 users, 210 posts, 153 likes, 138 served files, five minutes -- so both public servers now run on one-file databases. davesql 0.7.0, the package carrying the engine, is published on npm. And the repo caught up with the reality: the example config.json ships with "flUseSqlite": true, install.md is now the SQLite install -- no database server, no schema to paste, a Backups section, and the six-step migration for existing MySQL servers -- while the whole MySQL story (config, schema, upgrade notes) moved to its own page, installMysql.md. Dave announced it on Scripting News. One lesson from the demo migration made it into the doc: if the import stops on a UNIQUE constraint error, the server touched the new empty database before the import ran -- delete the file and re-run.

  • The Cassette Tapes of the Great Migration , a collection...

    The Cassette Tapes of the Great Migration, a collection of oral histories recorded in Michigan in the 1970s of Black people who had previously escaped the Jim Crow South. “If we don’t get it from those individuals, then we can’t get it from anyone else.”

  • rss.chat itself now runs on SQLite

    This morning's note said an rss.chat server can run on SQLite; by this evening the flagship server does. Both production servers were upgraded to the new software (v0.6.0) during the afternoon, running on MySQL exactly as before -- proof that the change disturbs nothing for existing installs. Then the migration itself: export the whole database to one JSON file, set "flUseSqlite": true in config.json, import, restart. All 752 rows -- 12 users, 361 posts, 217 likes, 162 served files -- came across with their ids intact, so every permalink still works, and the Software versions dialog now reads "SQLite version: v3.49.2." The MySQL database was never written to during the switch, so rolling back would have been one config line -- it wasn't needed. Total elapsed time, including a wrong turn when an unsaved config file sent the import to the wrong engine (it stopped harmlessly on the first duplicate row): about twenty minutes. demo.rss.chat follows tomorrow.

  • The install docs also gained the piece that was missing: email

    Sign-in is a magic link, so a new server can't sign anyone in until it can send mail -- and nothing documented how. New page: email.md -- the four SMTP settings for sending through a provider you already use, or Amazon SES with a link to Scott Hanson's setup walkthrough. It's a step in the install checklist now, along with a link to the questions thread -- if something in the install isn't working or isn't explained, that's where to say so.

  • "early‑AI‑history maneuver"

    I asked Perplexity to read through 258 posts in my “Snapshots & Fragments” category — the catch‑all bin I’ve used for photos and ephemera over the years — and tell me what it thought was going on. I had a hunch an outside lens might spot patterns I only sense in the gut.

  • trying this out

    not sure why. Checking out editing original post

  • &#8220; Researchers let AI models run a simulated society...

    Researchers let AI models run a simulated society. Claude was the safest — and Grok committed 180 crimes and went extinct within 4 days.”

  • The Software versions dialog now tells you which database engine the server runs on

    Servers can now run on SQLite as well as MySQL (that's the day's big server-side story -- see the server worknotes), and the dialog's last line follows along: it says "SQLite version" or "MySQL version" to match the actual engine, with the real version number either way. The server sends the engine name in a new databaseEngine member of the user-data record, and the client reads it as of v0.6.10. First seen live on scratchpad.rss.chat, the first server running on SQLite.

  • A startup crash that wore two disguises

    If you left the editor open with a draft when you last used the app, the next startup could crash quietly: the app tried to restore your draft before one of its writing tools -- the piece that turns rich text into markdown -- was ready. Everything after the crash never ran, and the damage showed up as two seemingly unrelated bugs: your name missing from the menu bar, and the Publish button refusing to enable while you typed in the body of a post (typing in the title, which takes a different path, still worked -- which is why the bug seemed to be about titles). It surfaced during the demo.rss.chat database migration this morning, was reproducible one minute and gone the next, and the last piece of the puzzle was browser caching: the fix was live but browsers kept running the old code until the cache-buster on the script address changed. Fixed by DW: the converter now starts first thing, and the script address was bumped so every browser picks up the cure. (Client v0.6.11.)

  • I just watched Samsung's Galaxy Unpacked event for July 2026. The lineup includes new and updated Folds and Watches, Open UI 9, and improved Qualcomm chips. Samsung also revealed better tools for coexisting with or switching to iOS, expanded Google AI support, and provided more details on the eyewear collaboration with Gentle Monster and Warby Parker.

  • Photoshop Etiquette: A Guide to Discernible Web Design
    https://photoshopetiquette.com/

  • Brian Eno on the Cherished Sounds of Failure

    Near the end of 1995, the artist and producer Brian Eno wrote the following about new media in his diary, which entries were later collected in a book called A Year with Swollen Appendices.

    Whatever you now find weird, ugly, uncomfortable and nasty about a new medium will surely become its signature. CD distortion, the jitteriness of digital video, the crap sound of 8-bit — all these will be cherished and emulated as soon as they can be avoided.

    It’s the sound of failure: so much of modern art is the sound of things going out of control, of a medium pushing to its limits and breaking apart. The distorted guitar is the sound of something too loud for the medium supposed to carry it. The blues singer with the cracked voice is the sound of an emotional cry too powerful for the throat that releases it. The excitement of grainy film, of bleached-out black and white, is the excitement of witnessing events too momentous for the medium assigned to record them.

    Note to the artist: when the medium fails conspicuously, and especially if it fails in new ways, the listener believes something is happening beyond its limits.

    Nailed it.

    Tags: Brian Eno

  • Flock ‘Objects to Our Removing Their Equipment’: Emails Reveal Why a Town Put Bags Over Its Flock Cameras

    "For the time being, if you or someone on your crew has availability to secure black plastic bags (or something else) over the cameras, that would be great."
  • Just fixed compatibility with RSS.chat feeds in Micro.blog. Next up is to figure out if we can process comment feeds to view RSS.chat conversations within Micro.blog... A little tricky because of how Micro.blog assumes hostname usernames.

  • Podcast: Flock is Tracking People, Not Just Cars

    How cops are using Flock to look for specific people; the company buying mountains of books for AI companies; and the big Suno hack.
  • First post

    Testing rss.chat, the most recent product from @dave

  • RSS.chat now supports SQLite. Simpler and faster to install. You don't have to host a database, it's now built into the server. Full instructions. Questions or issues.

  • You Opened a Credit Card. ICE Now Knows Where You Live

    Here's how your personal address travels from your credit card provider, through middlemen companies, and ends up with ICE.
  • This is a test. We just gave this server the same upgrade rss.chat got last night. 

    But this time there are some glitches. 

    Let's see if this post appears.

  • Reminder: We have a demo server for anyone who wants to try RSS.chat. I'm glad we set this up. It's sort of like support, and bug catching.

  • Google Is Building an A.I. Fence Around the Internet It...

    Google Is Building an A.I. Fence Around the Internet It Once Championed. “Google has often said it was ‘sending out more traffic & the web is bigger than ever. And then right next to that is a bunch of publishers whose businesses are getting destroyed.’”

Older posts