Sunlight as a quantum sensor; kimchi as a microplastic vacuum
Two May 2026 results worth remembering: ghost imaging from ordinary sunlight, and a probiotic from fermented cabbage that flushes nanoplastics.
Simplicity over complexity, quantity over quality.
Security Engineer · Notes from building at speed
Currently — 13 essays shipped
Notes from a security engineer building at speed — on shipping, design, and the systems that hold the web together.
Two May 2026 results worth remembering: ghost imaging from ordinary sunlight, and a probiotic from fermented cabbage that flushes nanoplastics.
The streak doesn't break. The conversation about whether we cross 1.5°C is over — the conversation about how often we are above it has begun.
Look at the bill, not the demo. Interconnect queues at utilities have become the new GPU shortage — the next bottleneck isn't compute, it's substations.
A year ago, "AI coding" meant autocomplete with vibes. Today it means a process that reads your GitHub issue and opens a PR.
"Restructuring around AI" is the new "right-sizing." It is partly a real productivity shift and partly a defensible 2026 narrative for the 2021–22 over-hire.
HTTP/2 stream cleanup is hard, and Apache just paid for that. Protocol-state machines that hand-roll their own multiplexing keep producing this exact bug.
A CVSS 10.0 is rare. An exploited-in-the-wild CVSS 10.0 with admin impact, on a controller that sits between branches and the corporate WAN, is rarer.
One threat actor, multiple Fortune 500s, in two weeks. The unifying pattern is depressingly familiar — identity-provider compromise leading to SaaS data theft. No zero-day required.
The frontier is no longer a single line. Five or six independent labs can now ship a near-state-of-the-art coding model, and the marginal cost of doing so is dropping faster than the gains.
I used to read every release post. As of this month, I have given up. The frontier no longer rewards the people who read every release — it rewards the ones with a tight eval loop and the patience to swap.
The European Union's AI Act has been, until now, a law without a working enforcement mechanism. The General-Purpose AI (GPAI) obligations took effect on August 2, 2025, but the European Commission's …
On April 23, 2026, OpenAI released GPT-5.5 — the first model since GPT-4.5 to be described internally as a rebuild rather than an iteration. New architecture. New pretraining corpus. New training obj…
The fight over whether OpenAI is allowed to be a company began deliberations this morning. After six weeks of testimony in the Northern District of California, a nine-person jury — six women, three m…