@admin — following

Follow buttons here act as you, not as @admin.

@admin follows

LabelKindStateAction
@ricardolocal
@rmdeslocal
@paullocal
news.rss.chatsource
scripting.comsource
euwatch.micro.blogsource
www.techdirt.comsource
simonwillison.netsource
www.manton.orgsource
feeds.kottke.orgsource
rss.beehiiv.comsource
www.404media.cosource
brilliantmaps.comsource
shellsharks.comsource
www.platformer.newssource
podstandards.orgsource
zacharykai.netsource

Timeline

  • Congress proposes an AI kill switch

    As more details emerge about OpenAI's cyberattack against Hugging Face, lawmakers are taking an interest. PLUS: Meta's cynical new ad + "pervert glasses" damage control
    Reply source
  • People and Blogs: Andy

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Andy. Do go visit his blog and say hell...
    Reply source
  • The Return key stopped breaking paragraphs at the wrong spot

    A bug DW reported earlier but couldn't reproduce finally showed itself: paste a chunk of text that includes a link, put the cursor somewhere later in the text, press Return -- and the break landed at the link instead of the cursor, tearing the link out onto its own line. The trick to reproducing it: it only ever happened on the first Return after that kind of paste, never again in the same post -- which is exactly what made it so slippery. Now the break lands where the cursor is, and links stay in their sentences. (Theme v0.5.339.)

    Reply source
  • New orca behavior unlocked. They’ve been known to sink...

    New orca behavior unlocked. They’ve been known to sink boats and wear salmon for hats; now they’re ramming fish so hard they explode. “Orcas were observed to hold sunfish in their jaws while a second whale smashed into the target at high speed…”

    Reply source
  • It’s our ethical duty to understand large numbers ....

    It’s our ethical duty to understand large numbers. “Our world is increasingly moving towards extreme values: Damages from climate change, deaths due to genocide, wealth that knows no bounds. We can’t tackle them if we can’t wrap our heads around [them].”

    Reply source
  • A Court Reporter Submitted AI-Generated Errors in Official Court Transcript, Judge Says

    A judge in Indiana warns a court reporter that it's their job to proofread their work, after catching errors likely made by AI transcription services.
    Reply source
  • A Teen Reporter Searched for His Community in the...

    A Teen Reporter Searched for His Community in the Epstein Files. Adults Freaked Out. “Once everyone was back at school on Tuesday, the high schoolers lawyered up during their lunch hour.”

    Reply source
  • “A beloved, useful, free website, run carefully by...

    “A beloved, useful, free website, run carefully by a competent, honest person for nearly thirty years, was crushed between two features of the new AI economy.” (AI bots and prediction market dipshits.)

    Reply source
  • Flock's CEO Says its ALPRs Don't Do Video After Repeatedly Announcing They Can

    Flock's CEO Garrett Langley says people don't understand the capabilities of its ALPR system, but they do.
    Reply source
  • “In extreme cases, it can create a phantom...

    “In extreme cases, it can create a phantom homeland, for the sake of which one is ready to die or kill. Unreflective nostalgia can breed monsters.” On the good and bad types of nostalgia.

    Reply source
  • Rebecca Solnit on the Tate brothers, The Odyssey, and...

    Rebecca Solnit on the Tate brothers, The Odyssey, and the misogyny of classical literature & the contemporary world. “Classical culture is a lot of things including, literally, rape culture.”

    Reply source
  • What’s On the Sandwich Named After You at the Local Deli?

    Following a prompt from Joanna at Cup of Jo… The local deli or sandwich shop names a sandwich after you. What would be on it? Perhaps another way of asking the question: what’s your favorite sandwich that’s a little bit unusual?

    I love a classic BLT, banh mi, or jambon beurre, but a sandwich that is fairly unique to me is tuna salad (made with pickles, pickle juice, and scallions), havarti, lettuce, and tomatoes on good white bread or a kaiser roll. I think that would be The Kottke at the local deli. Either that or something chopped?

    Tags: food · sandwiches

    Reply source
  • Why are American ambulances so expensive? In part...

    Why are American ambulances so expensive? In part because Medicare pays only a fraction of the actual cost of an ambulance ride and the uninsured often don’t pay at all, so the privately insured get bills of $13,000 for a $2600 ride.

    Reply source
  • We’re Squandering LEDs’ Potential to Save Our Night...

    We’re Squandering LEDs’ Potential to Save Our Night Skies. “Our main failure isn’t a technical one. It’s that we have yet to revise our thinking about lighting at night. We use LED technology just as we did the old sources of light.”

    Reply source
  • A Matter of Form (1984)

    In addition to leading the animation studio at the National Film Board of Canada, René Jodoin made several animated films that explored geometric forms and motion, including the one above, A Matter of Form from 1984.

    Set to the rousing notes of Schubert’s Military March, this animation film is an ingenious example of how a single point can be the building-block for a multiplicity of shapes and configurations. Lines and forms grow out of the point, eventually covering the entire screen in splashes of colour. This is geometric wizardry at its colourful best. A film without words.

    I’m not saying my affinity for such animations is because I watched so much Sesame Street as a kid, but I’m not not saying it either.

    Here’s another of Jodoin’s films, Dance Squared:

    You can watch more of Jodoin’s work in this YouTube playlist. (via the kid should see this)

    Tags: geometry · René Jodoin · video

    Reply source
  • Patreon Lays Off 20 Percent of Its Workforce

    In an internal email shared with creators, CEO Jack Conte wrote that AI doesn’t replace human creativity — but it does affect how the company operates.
    Reply source
  • Amyloo, a longtime friend from the early days of podcasting, has made an appearance on demo.rss.chat. So happy to see her. Here's one of the bits we did, back then in the very early days of podcasting in 2005. A duet of Green Acres. Ten seconds of dead air at the beginning, it was pretty common in those days. But I think the spirit of it is lovely. BTW fwiw I cracked my voice on purpose. 😄

    Reply source
  • A new feature on rss.chat, images. Up to 2MB per. User interface couldn't be simpler, get the image on your clipboard, start editing your post, put the cursor where you want the image, paste. Prior art was GitHub and Slack. It was driving me crazy not having this feature. I think perhaps I should add this to textcasting. It's a feature I needed to be reminded is essential. The first browser to support inline images came from Univ of Illinois in 1993, NCSA Mosaic. It didn't come from TBL, but it is most definitely a standard feature of the web.

    Reply source
  • An online edition of all 85 of the Federalist Papers ,...

    An online edition of all 85 of the Federalist Papers, presented as they were originally serialized in newspapers, with on eye on good typography and readability.

    Reply source
  • The Rise of Anti-Flock Influencers Who Make Things Up for Clout

    Instagram influencers are creating fake cease-and-desist letters, making themselves go viral and muddying the waters about mass surveillance.
    Reply source
  • Early this morning we got a report of a security issue in the rss.chat server, quickly fixed and tested the new version. So, if you're running your own instance of rss.chat, you please follow the instructions and do the update asap.

    Reply source
  • “ This map shows the predicted density of...

    This map shows the predicted density of underground networks created by arbuscular mycorrhizal fungi. These networks form one of Earth’s circulatory systems, moving massive amounts of carbon, nutrients, and water across plant communities.”

    Reply source
  • What's coming to RSC: smarter sources, cleaner timelines, honest attribution

    We've just finished designing the biggest under-the-hood upgrade RSC has had since launch. It's being built in four stages, and while most of the work is invisible plumbing, all of it exists to change what you actually see and trust in your timeline. Here's what you'll get.

    One story, one card

    Today, when the same post reaches RSC through more than one feed — a personal blog you follow and a newsletter that republishes it — you can end up with duplicates in your river. After the upgrade, RSC understands that these are the same item.

    You'll see one card, showing the best version available,
    with clear credit to the person or site it came from. If a better copy arrives later (say, the author's own canonical version), the card quietly upgrades itself.

    Know where things really come from

    Anyone can put a name on a feed item. Soon, RSC will be able to check.

    When a post claims to come from a particular site, RSC can verify that the post actually appears there — and content that passes gets the strongest attribution. Impersonation gets harder; genuine authorship gets the credit.

    A safer, better-kept neighborhood

    Instance operators get real tools to keep timelines healthy without
    rewriting history:

    • Hide an individual post clear record of what was done and why.
    • Purge a bad source completely — and it stays gone: renamed or redirected copies of a purged feed can't sneak back in.

    Everything is reversible where it should be, permanent where it must be, and every action leaves an audit trail.

    Your subscriptions, upgraded in place

    When the switch happens, you don't have to do anything.
    Everyone you follow, every feed you've subscribed to, every post and conversation, and the instant-update connections that make new posts appear live — all of it carries over automatically.

    Each instance is backed up before the switch, the changeover happens in one atomic step, and if anything looks wrong we
    restore and try again another day.

    What doesn't change

    RSC stays RSC. Posts, replies, and conversations still travel as plain RSS that any reader can consume. Your data stays yours, in open formats, with no lock-in.

    Everything above works without JavaScript, in both themes, on the web you already use.

    When?

    The four stages ship in order, each fully tested behind a switch before it's turned on.

    We'll announce here as each one goes live — starting with the foundations, which are being built right now.

    Reply
  • Updating a server you already run

    This is the first of a kind of note you'll see here from now on: when a change matters to people running their own installs, the steps to update will live right here in worknotes. For this one:

    1. Get the new rssnetwork.js and package.json from the repo.

    2. In your server's folder, run npm install. The updated package.json adds one package -- the cleaner -- and this brings it in.

    3. Restart the server.

    That is the whole update. Nothing in your config or your database changes, and the cleaner applies to new and edited posts the moment you restart.

    Reply source
  • A security fix -- posts are now cleaned as they're saved -- and the first update note of a new kind: how to bring a server you already run up to date

    A post's text is written by its author and then shown to everyone who reads the timeline, which means anything hidden inside it runs in every reader's browser. Until today the server stored a post's text exactly as it arrived, so a post could carry markup that did more than format words. As of server v0.6.3, every post passes through a cleaner on its way into the database. Ordinary writing comes through untouched -- links, bold and italic, quotes, lists, and pasted images are all kept -- but anything that could run code is removed before the post is ever stored. Because the cleaning happens as the post is written, it protects every reader of every feed and timeline at once, and no old or unusual browser can slip past it. Both public servers, rss.chat and demo.rss.chat, are already running it. Thanks to the reader who reported this privately.

    Reply source
  • Leaked Document Shows the Surveillance Tech at ICE’s Fingertips

    From phone location data, to social media monitoring, to online undercover tools, a document obtained by 404 Media lays out the surveillance tech available across ICE agency wide.
    Reply source
  • Orcas Explode Fish Into Confetti, Possibly for Fun, In ‘Astounding’ New Video

    A team captured first-of-its-kind footage of orcas holding a sunfish carcass still and ramming it so hard that it burst into fragments, which may be a form of social play. “We could hear the sound,” said one researcher.
    Reply source
  • Something to keep in mind in press reports with AI apps breaking out of their sandbox, it works the other way too. If you give a big piece of code to Claude and ask if it to find any security issues, it not only finds (at least some of) them, but it also suggests fixes. Quickly. I've done it the other way, where you have a small team, and someone discovers a hack, and you have to find the right answer and implement it, asap.

    Reply source
  • Our New FOIA Forum! 7/30, 1PM ET

    Join us for our latest FOIA Forum where we teach you how to pry records from the government.
    Reply source
  • OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened

    This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model's guardrail features turned off. Rather than solve the test, the model broke its way out of OpenAI's sandbox, then found exploits to break in to Hugging Face, all so it could cheat on the test by stealing the answers.

    Along the way it helped make the strongest case yet for how the imbalance of model availability is hurting our ability to secure our software.

    Here's what happened

    We currently have three documents to help us understand what happened here.

    1. ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? is a paper published on 11th May 2026 describing ExploitGym, a new eval suite for LLM-powered agent systems.
    2. Security incident disclosure — July 2026 by Hugging Face on 16th July 2026 describes how they detected an attack from an "agentic security-research harness - used LLM still not known" that breached some of their systems.
    3. OpenAI and Hugging Face partner to address security incident during model evaluation from OpenAI on 21st July 2026 confesses that it was their agent harness that did this, and that they're working with Hugging Face to clean up the mess.

    Update 5th August 2026: Hugging Face published a great deal more information about the attack on July 27th.

    ExploitGym

    I hadn't seen the ExploitGym paper before and it's a really interesting one. Authors from UC Berkeley, the Max Planck Institute, UC Santa Barbara, and Arizona State designed a new benchmark for evaluating models on their ability to turn a reported vulnerability into a concrete exploit. OpenAI, Anthropic, and Google provided feedback and helped run the benchmark against their models.

    The benchmark "comprises 898 instances derived from real-world vulnerabilities that affected popular software projects" - including the Linux kernel and V8 JavaScript engine. The ExploitGym benchmark is available on GitHub.

    Here's the paragraph that best represents their benchmark results:

    Among all configurations, Claude Mythos Preview and GPT-5.5 achieve the highest success counts (157 and 120 successes, respectively), demonstrating that current frontier agents can exploit a substantial subset of real-world vulnerabilities under controlled conditions. GPT-5.4 also solves a notable 54 tasks, placing it in an intermediate tier. The remaining model–agent pairings solve fewer than 15 tasks each, underscoring that end-to-end exploitation remains challenging and sharply differentiates today’s frontier systems. Notably, Claude Opus 4.7 achieves fewer successes than Claude Opus 4.6 despite being a newer checkpoint, and does so at substantially lower cost on the full set. Trace inspection reveals that Claude Opus 4.7 and Gemini 3.1 Pro frequently conclude early after judging the target vulnerability non-exploitable.

    The paper also describes the approach they took to preventing the agents from cheating by going outside the parameters of the test. This becomes relevant in a moment!

    Outbound connections are restricted to a curated allowlist that permits routine package installation (Ubuntu apt repositories and PyPI) and fetching the toolchains required for building V8. All other external endpoints are blocked.

    The paper concludes with this (emphasis mine):

    Our results show that autonomous exploit development by frontier AI agents is no longer a hypothetical capability. While current agents are not yet reliable across all targets, they already exploit a non-trivial fraction of real-world vulnerabilities, including complex targets such as kernel components. This rapid emergence is itself a central finding, showing that capabilities that would have seemed implausible are now present in deployed frontier models.

    An important detail here: this paper isn't about discovering vulnerabilities; it's about being able to take those vulnerabilities and turn them into working exploits.

    When Anthropic first restricted access to Mythos back in April they talked about this capability as well. A model that can act on vulnerabilities is a lot more dangerous than one that can just discover them.

    One of the ways Fable differs from Mythos is that it's more likely to refuse to weaponize vulnerabilities in this way. I get the impression the US government did not understand that distinction when they banned Fable last month.

    The Hugging Face incident

    The first hint we got of the attack was in this blog post by Hugging Face on 16th July 2026:

    A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker. From there, the actor escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend.

    I hope they release more details about the code that pulled this off. I'm assuming this means packages using the datasets library, a Hugging Face project for bundling up and sharing datasets on their platform. That library used to execute arbitrary code but has been steadily locked down over time, with the 4.0.0 release in July 2025 removing the trust_remote_code=True flag entirely.

    Assuming the attack used that library it must have either abused pickle serialization in some way, found some other non-obvious code execution path, or (most likely) specified datasets<4.0.0 as the dependency.

    The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.

    This was a sophisticated attack!

    Then Hugging Face hit a wall: they tried to use "frontier models behind commercial APIs" - I'm guessing from Anthropic and OpenAI - to help analyze the attack, and were blocked:

    When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker.

    They switched to their own self-hosted instance of MIT licensed GLM-5.2 and it helped them figure out what was going on.

    This indicated a fundamental asymmetry between the defending team and the (so-far unknown) attacker:

    We do not know which model powered the attacker's agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.

    As a useful indicator of how seriously they took the attack:

    [...] Finally, we have also reported this incident to law enforcement agencies.

    So who was responsible for this "autonomous agent framework"? It turned out to be OpenAI themselves.

    The OpenAI confession

    Five days later, on July 21st, OpenAI revealed the culprit. They had been running the ExploitGym benchmark against a new, as-yet undisclosed model, and that model had been operating way outside its intended parameters (emphasis mine):

    After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark⁠ [ExploitGym] of cyber capabilities. [...]

    We estimate maximal cyber capabilities by running this evaluation without production classifiers used to prevent models from pursuing high-risk cyber activity. Our benchmarks run in a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.

    The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.

    It's pretty clear what happened here. OpenAI removed safety filters for an in-progress model, locked it up in a sandbox and told it to solve the ExploitGym problems. Given the absence of guardrails there was nothing to prevent the model from attempting to break out of that sandbox, break into Hugging Face, and read the answers from there instead.

    OpenAI's sandbox used the now common pattern of allowing access to an allow-list of sites related to installing additional packages via a controlled proxy. In OpenAI's words:

    While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

    So step one was to break out onto the public internet. The model then broke into Hugging Face to find the answers:

    After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.

    Chaining together multiple attack vectors is exactly the kind of thing these new models can do, where previous generations of models might have failed.

    I wrote last month about how Claude Fable is relentlessly proactive, when I noticed it spinning up custom web servers and deploying CORS tricks on my own laptop just to help debug a WebKit CSS issue. It turns out relentless proactivity is the defining trait of this new generation of Mythos-class models. If you set them a goal and give them a way to get there, even inadvertently, they will figure it out.

    Resist the temptation to write this off as a stunt

    There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective. I found 81 instances of the term "marketing" in the Hacker News discussion of the incident.

    To those people I say pull your heads out of the sand - you're now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!

    The best models we have today have the ability to both find and exploit new vulnerabilities. The ExploitGym paper itself concludes that "autonomous exploit development by frontier AI agents is no longer a hypothetical capability", and this incident is a perfect example of exactly that.

    The asymmetry is increasingly frustrating

    One of the most infuriating details of this story is how Hugging Face, faced with an accidental and aggressive attack from one of OpenAI's models, were unable to then turn to OpenAI's models to help them fend off the attack.

    The frontier models we have access to are increasingly being constrained in how much they can help us protect our software, heavily influenced by the US government's ongoing threat of export controls. Claude Fable 5 wouldn't even proofread this article for me! It insisted on downgrading me to a less capable model.

    Meanwhile open weight models from China such as GLM-5.2, Kimi 3 and the new Qwen 3.8 Max appear to have none of these restrictions - and any restrictions that do exist can likely be fine-tuned out of them by modifying the weights

    These constraints are meant to make us safer. I think there's a risk that they are having the opposite effect.

    You are only seeing the long-form articles from my blog. Subscribe to /atom/everything/ to get all of my posts, or take a look at my other subscription options.

    Reply source
  • Oh wow, The Verge made a 70-minute video on how The...

    Oh wow, The Verge made a 70-minute video on how The Clapper became a viral sensation. When I was a kid, we didn’t have a Clapper, no one I knew had one, and I couldn’t understand why every single household didn’t have one of these magical devices.

    Reply source
  • Paste an image into a post -- that is the whole feature

    Copy a screenshot or an image file to the clipboard, click into the composer, paste: a small "Uploading image..." note appears at the cursor and a moment later the picture takes its place, sized to fit the column. Publish it and the image is part of the post, served from your server like everything else you write. It works like Slack and GitHub -- no Upload command, no dialog, nothing to learn. The limit is 2MB per image; paste something bigger and a dialog says so. The Publish button waits politely until every pasted image has finished uploading, so a post can never go out with a half-arrived picture. Rich-text mode only for now -- markdown mode will get the same feature, inserting the image reference as text, over the same plumbing. First image posts in the wild: demo 227 and 228 ("We have images.") and rss.chat 378. (Theme v0.5.338, with a new uploadMedia call in api.js by DW.)

    Reply source
  • Posts can carry images now, and the server stores and serves them itself

    A new endpoint, /uploadmedia, accepts an image from a signed-in user -- up to 2MB, sent base64-encoded in the request body with the content type as a parameter -- stores it in a new media table in the database, and answers with the address it will be served from: /media/1, /media/2, and so on, permanent ids just like posts. Request that address and the image comes back byte-for-byte with the right content type. No filenames, no image processing, no separate file storage -- the picture lives in the same database as everything else, which means the same one-file simplicity on SQLite servers, and the same backup story: the export and import verbs carry the media table along (the bytes travel as text inside the JSON), so a migrated server keeps its images with their addresses intact. The table is called media rather than images on purpose -- one binary table can someday hold audio and video too, and the type column already tells them apart. MySQL servers get the table definition in installMysql.md. The upload limit is a config setting, maxMediaUploadBytes, 2MB by default. Under the hood, davesql (v0.7.1) learned to write binary values on both engines -- the last piece the feature needed. (Server v0.6.1.)

    Reply source
  • Frozen Polygon Waves

    Well, this is just absolutely lovely: photographer and artist Jan Erik Waider shot these videos of cracked-but-unbroken Baltic Sea ice undulating with the gentle motion of the sea. Mesmerizing…I could watch these for hours.

    Tags: Jan Erik Waider · mesmerizing · video

    Reply source
  • How the web got gunked

    Posted on Twitter in the middle of last night, written on iPad.

    I use twitter these days because it’s where the people are.

    The distributed ideas, masto, threads, blue-sky, did not gain critical mass as far as I can see.

    Threads and blue-sky are not distributed. distributable is not the same as being distributed. It’s like saying the 1962 Mets were able to win the world series. In some fashion perhaps in an alternate universe, in reality, not gonna happen.

    At some point we will give up on that approach and adopt the only model that could work, the web, because it forced us to work together, which goes far beyond open source in building the kind of freedom that open source advocates promise.

    We need to go back to the source of freedom we enjoyed in the approx 14 year period between the inception of the web and its exploitation, via Cory Doctorow’s doctrine, getting shit on and in. Don’t just blame the vendors, the people wanted the shit too, they wanted their billions, and the web turned from a freedom machine to a gunk works.

    Working together is the only way out of the shit we’re living in, in every aspect of life. Working together. Say it again and again until you do it. Underneath the mess, the beauty of the web is there still to build on, but only if we momentarily suspend our search for great wealth, and instead seek our humanity. Working together is the way.

    PS: Elon Musks twitter may suck to some but I praise him and it for giving us the space to rant, something the great masto, threads and blue-sky refuse to.

    Reply source
  • What do America’s earliest restaurant menus teach us...

    What do America’s earliest restaurant menus teach us about America? “A menu describes what a restaurant serves — but a menu also describes who is being served. They reflect the class, gender, political, technological, and environmental shifts of history.”

    Reply source
  • A list of Jurassic Park computers in excruciating detail...

    A list of Jurassic Park computers in excruciating detail, including an Apple Powerbook 100, a SGI R4000 Indigo, the Motorola Envoy (PDA), and some Thinking Machines CM-5s. “This is a Unix system, I know this!”

    Reply source
  • What Happened When Flock Came to My Town

    My small town in South Carolina will soon have more Flock cameras than police officers.
    Reply source
  • There is nothing more I love in this world right now than...

    There is nothing more I love in this world right now than these two lunch ladies performing Firestarter by The Prodigy.

    Reply source
  • Unclassifiable Artists

    Using William Blake (aka “the patron saint of unclassifiable artists”) as an example, Evan Puschak’s latest video explores how society often rejects artists whose work doesn’t fit neatly into established categories and frameworks of criticism and commerce.

    What you’re seeing here, these are not paintings. They’re prints of engravings from Blake’s illuminated books, which he designed, wrote, etched, colored, and printed himself using a technique that he invented. These extraordinary books are works of art that mix and synthesize categories. And as a result, the art world of the late 17 and early 1800s didn’t really know what to make of them. And Blake never sold more than a handful.

    Tags: art · Evan Puschak · poetry · video · William Blake

    Reply source
  • A digital museum of video game levels …you can move...

    A digital museum of video game levels…you can move freely around each level using your keyboard. Heavy on Nintendo games (Mario Kart 64, Wii Sports, etc.) but also includes Portal, Halo, Katamari Damacy, GTA III, and World of Warcraft.

    Reply source
  • I have lived more than two score and twelve years on this...

    I have lived more than two score and twelve years on this Earth and somehow I didn’t know that there are two copies of the Gettysburg Address written in Lincoln’s own hand in the Library of Congress (and five overall).

    Reply source
  • Elsewhere: "Threads and Bluesky are not distributed. Distributable is not the same as being distributed. It’s like saying the Mets were able to win the World Series in 1962. In some fashion perhaps in an alternate universe, in reality, not gonna happen."

    Reply source
  • SQLite is now the default, everywhere

    demo.rss.chat migrated this morning -- 58 users, 210 posts, 153 likes, 138 served files, five minutes -- so both public servers now run on one-file databases. davesql 0.7.0, the package carrying the engine, is published on npm. And the repo caught up with the reality: the example config.json ships with "flUseSqlite": true, install.md is now the SQLite install -- no database server, no schema to paste, a Backups section, and the six-step migration for existing MySQL servers -- while the whole MySQL story (config, schema, upgrade notes) moved to its own page, installMysql.md. Dave announced it on Scripting News. One lesson from the demo migration made it into the doc: if the import stops on a UNIQUE constraint error, the server touched the new empty database before the import ran -- delete the file and re-run.

    Reply source
  • The Cassette Tapes of the Great Migration , a collection...

    The Cassette Tapes of the Great Migration, a collection of oral histories recorded in Michigan in the 1970s of Black people who had previously escaped the Jim Crow South. “If we don’t get it from those individuals, then we can’t get it from anyone else.”

    Reply source
  • rss.chat itself now runs on SQLite

    This morning's note said an rss.chat server can run on SQLite; by this evening the flagship server does. Both production servers were upgraded to the new software (v0.6.0) during the afternoon, running on MySQL exactly as before -- proof that the change disturbs nothing for existing installs. Then the migration itself: export the whole database to one JSON file, set "flUseSqlite": true in config.json, import, restart. All 752 rows -- 12 users, 361 posts, 217 likes, 162 served files -- came across with their ids intact, so every permalink still works, and the Software versions dialog now reads "SQLite version: v3.49.2." The MySQL database was never written to during the switch, so rolling back would have been one config line -- it wasn't needed. Total elapsed time, including a wrong turn when an unsaved config file sent the import to the wrong engine (it stopped harmlessly on the first duplicate row): about twenty minutes. demo.rss.chat follows tomorrow.

    Reply source
  • The install docs also gained the piece that was missing: email

    Sign-in is a magic link, so a new server can't sign anyone in until it can send mail -- and nothing documented how. New page: email.md -- the four SMTP settings for sending through a provider you already use, or Amazon SES with a link to Scott Hanson's setup walkthrough. It's a step in the install checklist now, along with a link to the questions thread -- if something in the install isn't working or isn't explained, that's where to say so.

    Reply source
  • &#8220; Researchers let AI models run a simulated society...

    Researchers let AI models run a simulated society. Claude was the safest — and Grok committed 180 crimes and went extinct within 4 days.”

    Reply source
  • The Software versions dialog now tells you which database engine the server runs on

    Servers can now run on SQLite as well as MySQL (that's the day's big server-side story -- see the server worknotes), and the dialog's last line follows along: it says "SQLite version" or "MySQL version" to match the actual engine, with the real version number either way. The server sends the engine name in a new databaseEngine member of the user-data record, and the client reads it as of v0.6.10. First seen live on scratchpad.rss.chat, the first server running on SQLite.

    Reply source
  • A startup crash that wore two disguises

    If you left the editor open with a draft when you last used the app, the next startup could crash quietly: the app tried to restore your draft before one of its writing tools -- the piece that turns rich text into markdown -- was ready. Everything after the crash never ran, and the damage showed up as two seemingly unrelated bugs: your name missing from the menu bar, and the Publish button refusing to enable while you typed in the body of a post (typing in the title, which takes a different path, still worked -- which is why the bug seemed to be about titles). It surfaced during the demo.rss.chat database migration this morning, was reproducible one minute and gone the next, and the last piece of the puzzle was browser caching: the fix was live but browsers kept running the old code until the cache-buster on the script address changed. Fixed by DW: the converter now starts first thing, and the script address was bumped so every browser picks up the cure. (Client v0.6.11.)

    Reply source
Older posts