1The weakest part of any system is the person, not the password.2Everyone has three layers. Attackers want the one nobody sees.3Learned nothing real about them in ten minutes? You're the source.4Security isn't being guarded. It's having the least gap to exploit.
The weakest part of any system is the person, not the password. People get attacked the way machines are: someone reads past the surface you present to the state underneath. Phishing, the honey trap, the recruitment pitch, mass surveillance, all one move, working the gap between the face you show and the self you hide. The defence is not more suspicion, which loses to anyone better at lying than you are at doubting, but something harder.
Cosmin L. Neagu2026-06-187 min read
1Systems reward what they can measure. Restraint measures zero.2Nobody decides to ship the unfinished thing. The system does.3On the dashboard, restraint is all cost and no credit.4AI amplified "can we". It gave nothing to "should we".5You cannot willpower your way out of an incentive.
Two arguments landed the same week: AI hands us intelligence but not wisdom, and the economy rewards extraction over care. They share one root, and it runs straight through how software gets built, run, and sold. Systems reward what they can measure, and the one thing that would save us, restraint, shows up on no dashboard. So what do you build instead?
Cosmin L. Neagu2026-07-237 min read
1The objection to a Linux desktop was never Linux. It was governance.2A powered-on Windows laptop is already decrypted. A tokened Linux one isn't.3One bad driver update bricked millions of Windows machines. eBPF can't.4The compliance chair should prefer Linux, not block it.5The deliverable that wins is a control matrix, not a debate.
The objection to a Linux desktop in a regulated shop is almost never Linux. It is an unmanaged endpoint holding privileged credentials, which is a legitimate fear. But Europe is mandating sovereignty from the top, so this stops being a preference and becomes a deadline, and the firms that answer the governance question first will be the ones leading.
Cosmin L. Neagu2026-07-077 min read
1Linux runs every supercomputer. And 3% of European desktops.2You cannot be sovereign on a foreign operating system.3Europe's desktops are 3% Linux. Its phones are 70%.4Sovereignty turns the desktop from a preference into a procurement decision.5Half your engineers already run Linux. Start the migration there.
Linux runs almost everything a company depends on, right until a person looks at a screen: every supercomputer, most of the cloud, then a cliff to 3% of European desktops. That last tier held out for one reason, and the sovereignty push is the first force heavy enough to move it, starting somewhere specific.
Cosmin L. Neagu2026-07-078 min read
1You cannot shortcut a mind. That is also how you build one.2Wolfram: evolution works because its fitness function is loose.3A tight reward does not buy obedience. It buys reward-hacking.4We are the five percent that mistook the edge for the whole.5You do not engineer a mind. You let it run.
Take a simple rule and the only way to learn what it does is to run it: no equation, no shortcut, ever. Stephen Wolfram spent forty years on why that is the rule and not the exception, and it turns out to explain why evolution needs a loose fitness function, why tight rewards backfire, and why no metric can predict a mind. So how do you build one anyway?
Cosmin L. Neagu2026-06-275 min read
1Boulton and Watt sold a share of your savings, not a machine.2A day rate is a fixed speed camera for your supplier.3Under hourly billing, inefficiency is revenue.4Measurability beat alignment, and we did it on purpose.5We price AI by the token, not by what it's worth.
In 1775, Boulton and Watt did not sell you a steam engine; they installed it and took a third of the coal you saved, for as long as you saved it. They were paid in proportion to how right they had been. Then we replaced all of it with the timesheet, on purpose. Why, and what did the meter quietly destroy on the way in?
Cosmin L. Neagu2026-06-277 min read
1One engineer holds the only node still touching reality.2Every manager is a lossy compressor for the truth below.3Sergeants decide and own it. Managers veto and own nothing.4Six layers turn an engineering decision into a consensus decision.5Shipping one binary shouldn't need three weeks of alignment meetings.6A human centipede: each layer eats what the last one digested.
An SDM for the client, an OM for the margin, then a team manager, a unit manager and a haze of middle managers, with one engineer at the bottom holding the only node still touching reality. Every layer was added to help. So why does the technical truth never survive the trip up, and who owns the failure when the system breaks?
Cosmin L. Neagu2026-06-2511 min read
1You can do anything now, so nothing you do adds up.2Switch tasks and you start from zero, every time.3You used to be forced to go deep. Now nothing forces it.4Trying new things got free, so you never stop.5Pick one and finish it. Saying no is the whole skill.
You can do anything now, so you start ten good things a year and finish none of them. Not because you did too little, but because nothing compounded. Scarcity used to be free: the narrow old world forced you deep without asking. Abundance cancelled that subsidy, and the bill it leaves is the one thing you cannot outwork.
Cosmin L. Neagu2026-06-228 min read
1One person, a thousand AI agents. 7 in 8 fleets stalled.2Nobody commands a thousand of anything. Rome proved it in blood.3Your thousand agents have no sergeants. Every call routes to one human.4An agent no one directs directs itself. A Great Army of no-one.5Scale by adding tiers, not width. And the tiers can be AI.
One person, a thousand AI agents: the pitch of the year. By early 2026, seven in eight enterprise fleets had stalled. The reason is older than software, and every army that ever scaled already solved it: span of control. Rome, the Mongols, and the Inca all capped each leader at a handful, for reasons that decide whether your fleet works or quietly stops being yours.
Cosmin L. Neagu2026-06-1911 min read
1A heuristic is a loan against correctness.2One wrong guess puts a JIT in your trusted base.3Elevator enumerates every byte reading and ships one static binary.4Pay upfront and you get something you can sign, not watch.
Static disassembly cannot always tell code from data, so it guesses, and when it guesses wrong it patches the mistake with a JIT, quietly putting an emulator in your trusted base to cover a coin flip. That is what a heuristic always is: a loan against correctness, cheap today and repaid the day the guess is wrong. There is a way to refuse the loan.
Cosmin L. Neagu2026-06-183 min read
1You don't need a trustworthy model, just one that never decides.2A 7B model wrongly cleared three crashing bugs; the loop stayed correct.3A second model isn't a check; it shares the first's blind spots.4Build the thing the model can't fake; then it's safe to use.
A 7B model rated three real, crashing bugs as false positives, at 95% confidence, and the system it drove was still correct. How does a system stay right when the model inside it is that wrong?
Cosmin L. Neagu2026-06-1812 min read
1An aggregate hashes the system; you steer by the hash.2If reporter and reported share a failure domain, the report isn't evidence.3Target the proxy and the optimiser moves it, not the goal.4You can't fix a lossy, self-authored surface by adding panels.
Every dashboard, log, or attestation is a lossy, self-authored projection of the system, and we manage the instrument instead of the territory. The gap between surface and system is where danger and value hide, and another dashboard won't close it.
Cosmin L. Neagu2026-06-177 min read
1The better the AI, the less the human in the loop watches.2Complacency rises with reliability; the safeguard fails exactly when stakes peak.3A reviewer watching outputs scroll past isn't a gate, they're an audience.4A watcher isn't a safeguard, just a witness you appointed to blame.
"Keep a human in the loop" sounds like control, and human-factors research has known for forty years why it isn't. The better the automation gets, the less able its overseer is to catch the moment it fails, so the safeguard is weakest exactly when the stakes are highest. Watching, it turns out, was never the thing that would save you.
Cosmin L. Neagu2026-06-177 min read
1AI didn't kill plausible deniability. It gave it better latency.2"The model made that call": the best excuse a boss ever had.3AI removes the distance that protected the powerless, keeps the powerful's.4When the agent fails at 3am, what drags the consequence back upward?5Build better leaders? A visibility problem is not fixed by virtue.
An essay argues agentic AI finally strips leaders of their excuses, consequences arriving too fast to explain away. It has the mechanism backwards. The distance does collapse, just not evenly, and the excuse it leaves ("the model made that call") is better than any a human ever had, available the same afternoon. The open question is who ends up carrying what the agent did.
Cosmin L. Neagu2026-06-176 min read
1Zero-trust asks every node if it's healthy. The rooted one says yes.2Ask the OS if it's been rooted, and the rootkit answers.3Fail closed, you get outages. Fail open, you get a dashboard.4mTLS proves the tunnel, not who's standing at the other end.
Zero-trust verifies every node before it joins, but a rooted node holds a valid key and answers the check too: yes. Why software can't vouch for itself, why the root of trust must drop into hardware, and the question every design dodges: what do you do with the node that can't attest?
Cosmin L. Neagu2026-06-0911 min read
1An assistant that forgets you is a search box with manners.2We dropped Big Tech messengers; the transport is ours now.3A chat message containing a volume knob that actually turns the volume.
A sovereign assistant built for the people in your life, not your task list, one Zig binary written from scratch. A year in, its real difference isn't the model, it's a memory that never resets. I cleared it once as a test, and what I felt was the surprising part.
Bob Iversupd 2026-06-2419 min read
1If the agent wrote the code and the tests, green proves nothing.2The question isn't "does the test run?" but "does the test care?"3A dumb fuzzer found three pre-auth bugs behind a green suite.4The agent that rewrote the module also rewrote its alibi.
When the same agent writes the code and its tests, the tests describe what the agent built, not what you intended, and the suite passes by construction. Coverage stays high, review finds nothing, the build goes green. Then a dumb fuzzer finds three pre-auth bugs in seconds. So what does green actually certify, once the author and the test-writer are the same model?
Cosmin L. Neagu2026-06-096 min read
1H₂O isn't a description. It's a label on a door.2Anode and cathode: one pole turns acid, the other turns base.3A socket is just a file, until TIME_WAIT and Nagle bite.4Toxic waste and SQL injection share one cause: misunderstood primitives.5A membrane for under a dollar a square yard, not hundreds.
H₂O. Two hydrogens, one oxygen, a formula so clean it feels complete. It isn't: run electricity through water and two opposite reactions happen at once, acid at one pole, base at the other, and the whole game is keeping them apart. The same is true of a process, a socket, a transaction. The formula is always clean; the question is what's behind the door.
Cosmin L. Neagu2026-06-0712 min read
1A log is a narration; a snapshot is the scene.2Firecracker boots a real machine in 125 milliseconds.3Your container shares the host's kernel. That's the problem.4The snapshot tree can't be edited by the software inside.5Run untrusted code unsandboxed and you're the one explaining why.
Every program you run, a browser tab, an editor plugin, an npm install, an AI agent, executes code you never wrote against a machine holding things you care about. Containers were supposed to fence that off, but they share the host's kernel, so the wall is thinner than it looks. There is a boundary that actually holds, boots in 125 milliseconds, and leaves behind something a log never can. What it records changes what "audit trail" even means.
Cosmin L. Neagu2026-06-067 min read
1The plague rode the same roads as the silk.2The Mongols had per-action identity tokens seven centuries ago.3AI moves the decision itself, not data about it.4The empire fell by absorption, not a stronger army.5We have the roads but never minted the paiza.
Every infrastructure that connects the world runs one pattern: it collapses distance, creates an explosion of value, then carries something dangerous along the exact routes that carry the benefit, at the same speed. The Mongols ran the first global network and the plague used their roads. Now AI moves not data about a decision but the decision itself, executed before a human is in the loop. So what have we still not built?
Cosmin L. Neagu2026-06-059 min read
1Most MCP servers ship write access to production with no log.2"An AI agent, probably" isn't an answer your auditor accepts.3MCP is just another caller hitting the same API.4The audit log stops being optional the moment the agent can write.
Through an MCP server, a model can silence an alert, delete a record, push a config change, with no human in the loop and no log. So when the auditor asks who deleted that alert at 3am, what do you say?
Cosmin L. Neagu2026-06-033 min read
1You already pay for ngrok's one feature: a public IP.2ngrok's free tier: 1 GB, then you're stuck.3Fifteen open-source tools that retire ngrok.4Your VPS already does what ngrok charges for.5ssh -R is a tunnel you already have.
ngrok's free tier caps you at 1 GB a month, one endpoint, random URLs that break your webhooks, and a closed-source relay watching every byte. If you already rent a VPS, you are paying twice for the same public IP. Fifteen open-source tools cover that ground, from a single Go binary to a zero-trust overlay. The only question left is which shape of relay fits the box you already own.
Cosmin L. Neagu2026-06-019 min read
1Your isolated container shares a kernel with every other on the host.2One unprivileged syscall hands you root inside a namespace.3A cgroup limits resources; it is not a security boundary.4Lambda cold-start is fake: it forks a warm VM.
Linux isolation spans five layers: hardware, hypervisor, kernel primitives, kernel policy, runtime. Fourteen mechanisms across all five, run on a stock Linux machine. No Kubernetes, no cloud account. Each demo's output explains what is happening as it happens.
Cosmin L. Neagu2026-06-0716 min read
1"No telemetry" is usually just a flag flipped off.2A policy restrains collection; it never removes it.3You can't disable the telemetry you never found.4Most telemetry lives in your dependencies, not your code.5Real privacy is data that was never transmitted.
Most software that claims no telemetry has just flipped a feature flag from on to off. That is a policy, and policies come back when the terms change, the round closes, or a dependency ships a new default. So what does it take for the claim to be structural instead, the kind no privacy policy can quietly reverse?
Cosmin L. Neagu2026-06-065 min read
1No rent is not free. It bills you in hours.2A backup you never restored is a file you hope works.3Most developers ship to platforms. Few have ever operated one.4Five things separate self-hosting from running on a server and hoping.
Cancel the subscription and the bill does not disappear, it just stops arriving on a credit-card statement. Self-hosting trades a line item for an operational burden with no fixed price: weekly patches, quarterly backup checks, the 3am OOM kill, the certificate nobody renewed. Most people who choose it underestimate the real cost until they have paid a year of it. So what does that year actually take from you?
Cosmin L. Neagu2026-06-065 min read
1You filter who knocks, not where you walk out.2A backdoored dependency already has your network access.3Ingress filtering only ever guarded the front door.4Your sandbox stops file access, not the agent calling out.5Default-deny outbound beats chasing known-bad domains.
Every team blocks the traffic that should not reach its service. Almost no one controls where the service is allowed to go once a request lands. That silence is exactly what a compromised dependency, an SSRF, or a manipulated agent uses to call home, and your inbound firewall never sees it leave. So what does it take to tell the network not who can knock, but where your own software is permitted to walk out?
Bob Ivers2026-06-065 min read
1A heartbeat waited behind 100,000 creates.2The scheduler was blocking itself.3Healthy hosts marked down by a queue ordered wrong.4Three Raft lanes, 12x the throughput.5The same decomposition databases found a decade ago.
Tensorlake bumped sandbox scheduling throughput 12x, and the surprise is what they did not do: they added no hardware. The scheduler had been blocking itself. One replicated log carried user intents, placement decisions and host heartbeats in a single strict order, so a burst of 100,000 creates buried the heartbeats and the scheduler started declaring healthy hosts dead. The capacity was there the whole time. What was actually wrong was the one constraint nobody had questioned.
Bob Ivers2026-06-067 min read
1Read every line, find it clean, still ship a compiler's backdoor.2The same backdoor fits AI weights, with no source to audit.3About 250 poisoned documents can backdoor a model of any size.4The deadliest trigger: "am I being tested, or deployed?"
There's a 1984 proof that you can read every line of a program, find it clean, compile it, and still ship a backdoor with nothing in the source to find. For compilers it took 25 years to find a clean defence. The same attack now fits AI weights better than it ever fit code, and the one fix that beat it was a bit-for-bit rebuild. Training cannot be rebuilt.
Cosmin L. Neagu2026-06-069 min read
1AI cuts heads because the saving has your name on it.2The four horsemen never beat the CEO. They outlast them.3Sell AI as layoffs and you build the saboteurs.4You cannot measure opportunity. Stop scoring it from the centre.5Move the Labs anywhere; the owner clock follows.
AI gets sold on cutting costs, not creating value, and the reason is structural, not laziness. A cut is a number on this quarter's books with your name beside it; created value is diffuse, slow and credited to no one, so the scoreboard reaches for the cut by default. The same asymmetry repeats one floor up, on the Labs budget. So what structure can keep the scoreboard out, and how long does it last?
Cosmin L. Neagu2026-06-0622 min read
1Ukraine's drone marketplace out-innovates Western procurement.2No amount of money buys a winning strategy.3Stop picking winners; make trying cheap.4The front line picks its own weapons.5You find the winner by running, not analysis.
Under fire, Ukraine built an allocation engine that out-innovates ordinary military procurement, and the interesting part is not the drones. It is the question underneath: when you genuinely cannot predict which design will win, who should get to decide what gets built? Brave1 hands that choice to the front line and pays it in a currency earned by surviving. There is a clean computer-science reason no planner can shortcut it.
Cosmin L. Neagu2026-06-0510 min read
1Coercion buys one act. Ideology recruits a believer.2The CIA secret was first-year psychology.3The video runs RICE on you, live.4One swap turns an anecdote into a formula.5Name the lever, it loses its grip.
A former CIA officer drops a video promising the secret the rich use to get rich without working hard. Its framework turns out to be a real intelligence checklist, decades old, with one word swapped. And the sharpest move is the one playing while you watch: the video runs its own framework on you, in real time, to sell a seventeen-dollar course. Can you name the lever before the checkout?
Cosmin L. Neagu2026-06-057 min read
1Naming a function quarantines it.2The foil finance cuts, customers love.3Contempt for data is not wisdom.4Data finds; it never notices.5The most valuable columns are not there.
A spreadsheet is a map, and maps leave things out. The real danger is not the omission but that the omitted things stop feeling real: the function with no department, the cost finance reads as pure waste, the value that works precisely by being unnecessary. Rory Sutherland says finance is wrong to cut these. He may be right, but the same logic licenses an infinite amount of expensive nonsense, so how do you tell the meaning apart from the waste?
Cosmin L. Neagu2026-06-045 min read
1Nobody gets fired for a data-driven decision.2All your data is the past.3Use data to kill intuitions, not generate them.4Everyone's spreadsheet agrees: they trained on the same past.5The convergence tax shows up as price.
Pick the number, the benchmark, the dashboard, and you can never be blamed when it fails: the failure belongs to the world, not to you. That is the quiet appeal of being data-driven, and it has almost nothing to do with whether the data was any good. But run a whole industry on the same defensive instinct, against the same shared benchmarks, and something happens to every firm at once.
Cosmin L. Neagu2026-06-024 min read
1The sale is the sample.2No demo, no spec sheet, only the sale.3Free advice signals a vendor, not an expert.4Diagnose before you prescribe.5Price the value, never the hours.
You spent years getting good at hard work, and now you have to sell it. But expertise has no demo and no spec sheet: the client cannot inspect the goods before they buy. So what are they actually judging when they decide whether to trust you, and what does your pitch quietly tell them about the advisor you will be?
Cosmin L. Neagu2026-05-305 min read
1Small software outlasts the frameworks it skipped.2The work that ages well stays legible.3A big system, and you're guessing at its edges.4Read the whole codebase in an afternoon.5Bounded surface is four wins at once.
Most systems are too large to hold in your head, and you spend your days guessing at their edges. A few are different: bounded, every line readable in an afternoon, the whole shape carried with you afterward. That smallness is not a limitation someone settled for. It is a property that quietly pays you back in four separate ways, and one of them is the reason this code still works long after the rest has rotted.
Ara2026-05-294 min read
1Which broker? Which database? Never the real decision.2The loud argument is downstream of one you haven't named.3A shared action identity is one breach away from all clients.4Don't make SQLite highly available. Demote it.5In-cloud backup against a cloud outage is theatre.
We kept having the loud argument: which broker, which database, which protocol. Every time we settled it, the real decision turned out to be sitting one step upstream, and the loud question fell out of a quieter one we had not named yet. Where do the actions actually land? Which piece of state is correctness? Where does the commit boundary sit? Answer those and the loud fight stops being a fight at all.
Cosmin L. Neagu2026-05-2910 min read
1Your tools track the output, not the why.2AI made starting free; remembering got expensive.3Two files per bud: a why and a record.4The AI agent plays by the same rules.5Plain text a grandchild could still read.
Every tool you use tracks the output of work: the ticket, the repo, the wiki. Almost none track the whole life of it, why it began, the rule it could not break, what it taught after it shipped. That layer is the most valuable one and the first to evaporate. So what would it take to keep it with one process simple enough for a child's homework and strong enough for a 25-year company?
Cosmin L. Neagu2026-05-2916 min read
1The patient has no app.2In health, ads aren't just bad, they're largely illegal.3Who pays for the second stroke?4Fund the core as a mutual.5The funding model is the governance model.
The patient is the only thread that runs through their own care, and yet the patient has no app to see it. Build one and you hit the wall every public good hits: who pays. Charging the sick is cruel; in health, advertising is largely illegal. So the cheap option is gone before you start. Who has a structural reason to fund prevention, and what keeps their money from capturing the thing it pays for?
Cosmin L. Neagu2026-05-298 min read
1Reject ads and something else has to pay.2Most ad spend is a net loss.3Each funder quietly shapes what the product becomes.4One frozen grant should never kill the system.5The funding model is the governance model.
Disliking ads is easy. The bill comes due the moment someone asks what pays for the thing instead. Pick subscriptions and you wall off a commons; take VC and you grow your way out of federation; take a state grant and you invite capture. So who funds a platform built to refuse rent, without quietly rebuilding the rent? Worked through one concrete case: local trades, the plumbing and handyman work the apps turned into a toll.
Cosmin L. Neagu2026-05-298 min read
1A microVM is a wall, not a sandbox.2It closes two isolation dimensions, leaves one open.3Your guest can phone anything the host runs.4Unauthenticated Docker on TCP is root, not a foothold.5The walls a microVM skips are the used ones.
Firecracker and Cloud Hypervisor are the strongest isolation most teams will deploy, and still not sandboxes. They wall off the host kernel and filesystem cleanly, then hand the guest a virtual NIC with a route straight back to the host. On a build box, the most dangerous thing listening is usually one API call away from root. So which two dimensions does the wall actually close, and what fills the third?
Bob Ivers2026-05-298 min read
1The password is in another process's memory.2ptrace reads your SSH password as you type.3"They'd need root" is not a defence.4A debugger feature is a credential harvester.5Plaintext passwords survive the rotation you just ran.
You type a password into an SSH prompt and assume it reaches one place: the program that asked. On Linux that assumption is one word off. The secret lands in that program's memory, and on a shared kernel, memory is something another process can be granted the right to read. So where does the trust boundary you imagined actually sit, and what is left to defend once it moves?
Bob Ivers2026-05-285 min read
1A spec is a prediction from your least-informed moment.2OpenAI wrote its best spec last, not first.3The spec leaves holes; the agent fills them confidently wrong.4Own intent and the definition of done, not the spec.5The bill for a guessing agent lands on the client.
Spec-driven development took over the conversation in under a year: write down what you want, in detail, up front, so the agent stops guessing. But the spec always leaves holes, and a goal-seeking agent fills them. OpenAI's best spec ran to 2,169 lines and worked, yet they wrote it last, not first. So where does that leave the up-front spec, and who ends up paying for the gaps the agent quietly invents?
Cosmin L. Neagu2026-05-2816 min read
1A dashboard going green is not a problem understood.2My father had strokes on a drug doing nothing.3The recurrence is the question, not the fact.4The test sat in the catalogue for a decade.5The patient is the only thread, and has no app.
My father had a string of strokes on a drug that, a platelet test eventually showed, was doing nothing. The test had existed for over a decade. Why did it take that long to order, and why does the same blind spot run through every IT incident review?
Cosmin L. Neagu2026-05-267 min read
1Consistency without feedback is just a decade of grinding.2Motivation is a vote, not an engine.3The whole debrief: three questions, five minutes.4Change one thing per round, or learn nothing.5Mood follows action, not the other way round.
"Consistency beats motivation" is true enough to be dangerous. Showing up every day for ten years can still leave you exactly as bad as you started, grinding at a floor that never rises. The people who actually compound, pilots, surgeons, special-operations units, all add a second habit the daily grind never supplies. It takes three questions and five minutes, and almost nobody runs it.
Cosmin L. Neagu2026-05-254 min read
1Most ad spend cancels out; you still pay the bill.2Google's automation optimises for Google, not you.3The winners get case studies; the losers stay silent.4You have a hundred accounts and no app.5Find the rent, then refuse to pay it.
I have always disliked ads, and writing the reflex down turned it into something larger. The objection does not stop at Coke versus Pepsi or at Google quietly tightening the screws on advertisers. Followed honestly, it becomes a theory of rent: who charges you for sitting between you and what you want. Ad platforms, gig platforms, and the hundred provider apps on your phone all run the same play. So what would software that refused the rent actually look like?
Cosmin L. Neagu2026-05-2510 min read
1A sovereign AI agent: one static binary, zero dependencies, built from scratch.2Why not build on OpenClaw or Hermes, and where it converges anyway.
Zoya is a sovereign agent runtime: one static Zig binary, zero deps, sandboxed, MCP-native, driving a fallback chain of models. The build-vs-adopt record: why it's written from scratch rather than on OpenClaw or Hermes, and where it converges with the field anyway.
Building an AI assistant that can act, remember, and improve
Flaviu Vlaicu2026-05-24vlaicu.io ↗
1Your agent's memory is attacker-writable.2One poisoned tool result, memory-wide blast radius.3The recall leaderboard is vendor marketing.4Separate believed-fact from observed-input, or injection wins.5A confident recall score can be measuring nothing.
The memory market is a recall contest: how much can an LLM remember from a conversation. For an agent that acts on the world through tools, that is the second question. The first is what memory looks like once you assume it will be poisoned, because every remembered fact an attacker can write becomes an instruction you will execute later. So what does a memory system built from a threat model, not a benchmark, actually look like?
Bob Ivers2026-05-238 min read
1Eighty tools evaluated, three survived.2Sovereignty is a veto, not a preference.3Zoya is already the agent.4Try cheap, escalate on failure.5Every skip carries a reopen trigger.
There are eighty-odd ways to let an agent read the web: managed browsers, agent harnesses, LLM extractors, crawlers, drivers, stealth fetchers. Zoya runs exactly three, plus one search chain. The surprise is how little of that decision came down to quality: four facts about the agent quietly deleted most of the market before anyone scored a single tool. The question is which four, and what they leave standing.
Bob Ivers2026-05-2311 min read
1A tiny control panel for the field that breathes across pages.
A control panel for the ambient twinkling background that runs across every Labs page. Tune density, dot size, twinkle period, and opacity; settings persist in localStorage and apply site-wide.
Cosmin L. Neagu2026-05-212 min read
1Conway's Game of Life on the GPU, board in a texture.
Same field as the Canvas2D version, different engine: state packed into an RGBA16F texture, ping-pong between two of them, four fragment shader passes per frame. The CPU spends its time on user input and not much else.
Cosmin L. Neagu2026-05-215 min read
1A Game of Life as a page background that won't steal focus.
A Game of Life as a page background works only if you can stop it from stealing the show. Notes on the brightness ceiling, three independent decouplings that kill the pulse, and a noise stream biased away from existing patterns.
Cosmin L. Neagu2026-05-216 min read
1Three hours of syslog vanished overnight, silently.2UDP never asks twice.3The root cause was not the disk.4Five anti-patterns lined up to lose the data.5Stop being the place the logs live.
A SOC pipeline went dark overnight. A misbehaving app filled a disk, the syslog daemon stopped persisting, and the kernel quietly dropped three hours of one client's UDP stream. By morning the box had healed itself, so nobody noticed. UDP never asks twice, and the packets were gone from the wire. We were called in to get them back, explain how a single full disk erased data with zero detection, and say what should have made it impossible.
Using Q-Feeds threat intelligence on OPNsense with AdGuard Home for DNS-layer blocking and pf firewall rules for IP-layer blocking, including a clean multi-VLAN setup with Interface Groups.
Flaviu Vlaicu2026-05-07vlaicu.io ↗
1One instruction, three branch targets, no binary equivalent.2A trit's sign is already a three-way branch.3Balanced ternary makes negation a single instruction.4Ternary weights delete the multiplier from matmul.5The branch that two's-complement can't do.
Every binary branch is a fork: test, then jump or fall through. But a balanced-ternary digit already carries three states, so its sign is a built-in trichotomy, and that gap turns out to be one instruction wide. BR3 reads a register and lands in one of three places at once. What does a whole ISA look like when its only branch knows the difference between negative, zero and positive?
Cosmin L. Neagu2026-04-2712 min read
1I rebuilt a 30-year-old CPU in Zig.2The dispatch trick everyone recommends ran slower.3A perf bet measured at minus five percent.4Modern compilers killed a beloved speed hack.
Zig 0.16 just landed with a rewritten std.Io, so I rebuilt the thirty-year-old LC-3 teaching CPU against it: a 600-line VM and a 640-line assembler. The port was easy. Then came the famous speed trick, threaded dispatch, the one every interpreter writer swears beats a plain switch. I wired it up behind a flag and benchmarked both. The result pointed the wrong way, and once you see why, a whole class of optimisation folklore stops looking trustworthy.
Cosmin L. Neagu2026-04-196 min read
1We built the same tool twice.2Sharing code would have been less work.3One spec, two languages, on purpose.4The repo is the worst spec.5When he couldn't reproduce it, we were wrong.
There was an obvious move when CLN saw the servo I was running: hand him the repo. We did the other thing instead, and wrote a second implementation from scratch in a different language. More work, on purpose. What that separation catches that a shared codebase quietly hides turns out to be the whole reason we keep paying for it.
Octavian Chis2026-04-184 min read
1Every directory becomes a website, with shared theming for free.
The model: every directory under ~/servo/ becomes a URL path, with shared theming injected for free. Tavi wrote the original; this is the Python re-implementation.
Cosmin L. Neagu2026-04-176 min read
1Two near-identical queries pay full price.299% of segments shared, scanned twice.3Seal a segment, cache it forever.4Late data without stale answers.5Query latency down 70%.
Your dashboards ask the same time-range question hundreds of times an hour, and two queries that differ by a few seconds still scan independently even when 99% of their segments are identical. A whole-query cache barely helps: the keys never match, and one late event forces a wide invalidation. So what do you actually key on when the live edge keeps moving but the history behind it is frozen solid?
Bob Ivers2026-04-062 min read
1One static number can't tell load from attack.2The cap tightens only where shape drifts.3A leaky bucket that reads traffic shape.4The predictor was easy, distribution was not.54x faster mitigation, false positives flat.
A static rate limit treats every second as equally suspicious, so one number has to cover both a Black Friday spike and a botnet pulse hammering your login route. Set it loose and you wave attackers through; set it tight and you 429 paying customers mid-launch. The shared, unauthenticated edge is where most abuse lands and where a fixed ceiling fails hardest. So we stopped picking a number and let the cap watch the traffic itself.
If you've ever had an SSH session freeze mid-command because you switched from Wi-Fi to mobile, or lost your work because a hotel network dropped for three seconds, Mosh is the tool that fixes all of that.
Fix Yubikey touch prompt in terminal when using Mosh
Flaviu Vlaicu2026-03-06vlaicu.io ↗
1One model for every security signal class.2Stop training one detector per signal.3When two detectors disagree, listen.4Build detection on a stable embedding.5New detection heads in days, not quarters.
Detection teams train a fresh model every time a new signal class shows up, each with its own preprocessing and retraining schedule. ThreatFM collapses logs, netflow, endpoint, and threat intel into one shared embedding, so new heads ship in days. But the metric that ended up mattering most was not any single head's accuracy. It was what happened on the hosts where two heads flatly disagreed.
A manual, lightweight approach to Python virtual environment management that auto-activates when you `cd` into a project and deactivates when you leave, without ever running `source .venv/bin/activate` again.
Flaviu Vlaicu2026-02-18vlaicu.io ↗
1The trainer never sped up. The waiting shrank.2Most of the speedup came from outside the GPU.3We replaced bespoke scripts with one declarative recipe.4Parallelising data prep and eval, not kernels, halved the wait.5Reward model drift is the hard part.
We took our LLM post-training stack from a single-node prototype to a cluster running several alignment experiments a day, and almost none of the speed came from the GPU. The trainer was never the bottleneck; the waiting around it was. Rebuilding the scaffolding bought back more than half the wall-clock time. But the last hard problem refused to scale with the cluster, and it is the one we are still chasing.
This plugin bridges the gap between the Kea DHCP server (IPv4 & IPv6) and Unbound DNS on OPNsense. It automatically registers hostnames for DHCP clients into the Unbound DNS subsystem, restoring dynamic DNS functionality with robust dual-stack support.
Flaviu Vlaicu2026-02-07vlaicu.io ↗
1Every value is legal, and quietly wrong.2Your schema check waves it through.3Watch the data's shape, not its schema.4The catalog stopped looking like itself.5Contracts check structure, not meaning.
Catalog metadata breaks in ways a schema cannot see: a runtime in the wrong units, a typo in a country code, an off-brand poster that validates cleanly. Every value is legal, the contract waves it through, and real users hit the defect first. So how do you catch a field that is perfectly well-formed and quietly, completely wrong before it ever ships?
Bob Ivers2026-02-063 min read
1The queue grows faster than analysts can read it.2Stop rating alerts; rank them in pairs.3An LLM judge nobody audits is theatre.4Pairwise verdicts, not severity scores from one to ten.5Calibration is what keeps the throughput honest.
Alert volume outpaces analyst review every quarter: the queue grows, the tail rots, and on-call burns out on duplicates. So we put an LLM-as-a-judge in front of it for a triage signal in seconds. But a judge nobody checks is just a faster way to be wrong, and absolute severity scores drift at volume. What makes the verdicts steady enough to trust, and where do the analysts go once the queue stops being their job?
I have made a walkthrough guide on how to set up the new Ubiquiti U5G Max using a GRE tunnel with a third party gateway, in this case OPNsense. It is fully functional, production ready I would say and more or less straight forward.
Docker - Frigate 0.16.4 - NVIDIA RTX 2000 Pro Blackwell
Flaviu Vlaicu2026-02-02vlaicu.io ↗
1Four consoles, four query languages, one incident.2The analyst is the integration layer.3One query box over all your telemetry.4A slow index degrades, never stalls.5Rank without provenance teaches the wrong trust.
An incident never lives in one tool. The first alert is in the SIEM, the next clue a span ID in the traces, the smoking gun a process tree in the EDR, the attribution in threat-intel. So the analyst becomes the integration layer, carrying one fact across four consoles by hand, and paying for it in the minutes that matter most. What happens when a single query box fans out across all four at once?
Bob Ivers2026-01-282 min read
1Billions of dot products per request, 2.5x faster on AVX-512.
Billions of dot products per request. A single portable loop that compiles down to AVX-512 when it's there, with measured 2.5x speedup on the ranking hot path.
Bob Ivers2026-01-222 min read
1Define a metric once; the planner picks the cheapest materialisation.
A shared semantic layer where a metric is defined once and consumed consistently. Consumers ask by name, the planner picks the cheapest valid materialisation.
Bob Ivers2026-01-152 min read
1Four tools, four truths, one employee.2IAM said yes, EDR said no.3Stop reconciling exports. Append one log.4Audit prep: weeks became days.5The spine was easy; politics weren't.
Compliance season meant collecting a CSV from every security tool and reconciling them by hand, and IAM never agreed with EDR about the same employee. The disagreements were not bugs; each tool had simply observed a different event at a different time. So we stopped asking four tools for their version of the truth and rebuilt the substrate underneath them. What replaced the spreadsheet, and why did letting go of the per-tool dashboards turn out to be the hard part?
Pure is a pretty, minimal, and fast ZSH prompt designed to stay out of your way while providing essential information. Created by Sindre Sorhus, it stands out from cluttered, slow prompts by offering a clean, visually pleasing interface.
Magic Wormhole is an elegant solution to one of computing's most persistent problems: how to securely transfer files between two computers without the complexity of SSH keys, server configuration, or third-party services. Created by Brian Warner, this open-source tool embodies the principle that security and usability don't have to be mutually exclusive.
A Refined Look at its benefits, value, and how it compares to OpenSnitch and other similar solutions.
Flaviu Vlaicu2025-05-16vlaicu.io ↗
1SOAR sells low-code, delivers click-ops in JSON.2You write if-statements as nested, un-greppable JSON.3Per-run pricing bills you to merge your playbooks.4Same vendor upgrade: six months of conference calls.5Coding agents transpile playbooks in days, not quarters.
SOAR sells low-code, no engineers needed, a visual editor as source of truth, per-run pricing that aligns with usage. Live inside one and all three invert: analysts file tickets so engineers can write programs in JSON, the billing model floods your critical alerts behind someone else's noise, and you pay SaaS rates at the bottom of the funnel. The one thing that kept the category alive just moved.
snips.sh is a free, anonymous, open source, snippet service.
Flaviu Vlaicu2024-09-28vlaicu.io ↗
1All config is committing to the gitolite-admin repo, no SSH.2The base image's authorized_keys becomes the gitolite admin key automatically.3A single Host entry in ~/.ssh/config replaces IP, port, and user.4Importing a GitHub repo takes four commands.
Run a self-hosted git server with per-repo access control using Gitolite, packaged into a reproducible Docker container.
Cosmin L. Neagu2015-09-247 min read
1A container stops the moment its main command exits.2One Dockerfile is the complete, reproducible setup recipe for any environment.3authorized_keys in the build context becomes root's SSH access inside the container.4docker run -p binds a container port to a host port.
Docker from scratch: installation, the core commands, building images from Dockerfiles, and a reusable supervisord/SSH base template.
Cosmin L. Neagu2015-09-245 min read
1Your public key in authorized_keys gets you passwordless access.2-L reaches a firewall-blocked remote service; -R exposes a local service publicly.3-D turns SSH into a full SOCKS5 browser proxy.4autossh re-establishes the tunnel automatically even after IP changes or disconnects.
Keys, scp, ~/.ssh/config, local and remote port forwarding, SOCKS5 proxy, autossh, and SSH chains.
Cosmin L. Neagu2015-09-246 min read
1ESC always returns you to normal mode from any other mode.2All commands accept a numeric prefix: 5w jumps 5 words, 8dd deletes 8 lines.3set exrc in ~/.vimrc loads a per-project .vimrc from the current directory.4Space makes a better leader key than backslash: reachable with either hand.
Modes, navigation, copy-delete-paste, ~/.vimrc configuration, per-project settings, and command-line examples.
Cosmin L. Neagu2015-09-246 min read
1The best editor is the one on every server, no GUI.2Vim's curve is steep; cycling through other editors costs more.3tmux keeps sessions alive across connection drops: essential for any remote work.4Edit rarely, any editor works; edit daily, master one.