The latest note Someone built a C compiler with an LLM for $100 and it boots Linux
A solo dev used an LLM as a pair programmer to write a C compiler from scratch. It compiles itself and boots the Linux kernel. Total AI budget: $100.
Ideas, observations & work in progress
A closer look at the systems
shaping how we live and work.
The notebook
142 notes & counting
The latest note A solo dev used an LLM as a pair programmer to write a C compiler from scratch. It compiles itself and boots the Linux kernel. Total AI budget: $100.
Tigris Data swapped their database-backed queue for Kafka, then swapped Kafka for FoundationDB. The reasons why tell you more about queue design than any tutorial.
Someone built a 22KiB transformer that trains in 13 seconds. The trick is not the model size, it is how they squeezed PyTorch out of the picture.
Someone built a lab where you can test tiny language models that run entirely client-side. No API calls, no backend, just WebGPU and a lot of patience.
A new paper shows the system prompt is not what makes models say 'as a language model'. It is the chat template wrapper that turns raw output into self-aware hedging.
Someone built a tool that generates fonts where every tokenizer chunk takes the same visual width. Suddenly prompt length is readable.
Project Suncatcher is Google's proposal to deploy GPU clusters in low Earth orbit. The pitch is simple: space is cold, solar power is free, and latency to ground stations is acceptable for batch jobs.
A live benchmark that ranks models by performance per dollar spent, not just raw scores. Turns out the best model depends on your budget.
A new language model is generating text faster than most tools can render it. The bottleneck just moved from the API to the browser.
The language added so many tools in the last decade that the community stopped caring about new syntax. That is a good sign.
A Reddit user discovered that giving a model explicit instructions to behave like JEV (a fictional expert persona) produces cleaner outputs, even when the model has no training data about JEV.
Pirate Face archives open-weight language models that companies try to delete. Turns out model takedowns happen more often than I thought.
Someone built a tool to make AMD GPUs run local LLMs without the usual driver nightmares. The benchmarks show Vulkan beating HIP by 20 percent.
Researchers found that visually identical characters from different scripts let prompts bypass safety filters. The models see different tokens, humans see the same word.
The Matasano founder uses Claude to draft, then rewrites everything by hand. No copy-paste. The LLM is a research assistant that never ships.
A reverse engineering enthusiast spent four years breaking open the PlayStation 2's Mechacon chip, the hardware guardian that controlled everything from disc authentication to region locking.
Driver's license numbers are not passwords. They are permanent identifiers tied to voting rolls, benefits systems, and background checks. The National Public Data breach exposed 272 million of them.
A graphics engineer got neural texture maps working with ES optimisation. No gradients, no autodiff, just mutation and survival.
The Python library you call from a Jupyter notebook might be Rust underneath. PyO3 makes that translation invisible.
A fintech with 50 million users fell for spoofed government data requests. The weak link was not the encryption.
A new transformer variant ditches the attention loop entirely. Faster inference, cleaner scaling, same performance.
A new paper shows agents that evolve their control flow at runtime, not just prompt chains.
Yayster is an LLM that runs locally in Emacs buffers. No API calls, no cloud, just a model sitting in your editor watching you code.
A solo developer just open-sourced their macOS music player. The interesting bit is not the player, it is the local jukebox mode that turns your Mac into a shared library for other devices.
A government Rails site was compromised hours after the CVE-2024-28103 patch dropped. The attackers were watching the release notes.
A DNS resolver that filters out known malicious domains at query time. No logs, no tracking, just threat intel applied at the network layer.
A developer used an LLM to translate 1993 Amiga assembly into modern game engine code. The surprising bit is how much of it actually worked.
A live playground for experimenting with domain-specific ML languages, no install required.
Someone repurposed their home security setup to log every bird species that flies past. The microphone was already there.
ProtectEU strategy revives the old argument that law enforcement needs a key to everything. The technical problems have not changed.
The Pixel 11 drops hardware memory tagging that was standard on the Pixel 8 and 9. GrapheneOS called it out on Twitter.
Someone fed an LLM a codebase to remember, then asked questions. The model started catching bugs the author missed. Not by design, by accident.
The GPU monopoly now owns the model zoo. This changes who controls open-weight AI.
A new graph database stores everything in a single file and ships as a 200KB binary. No server, no JVM, just embed it.
A French dev got sick of Prometheus configs and wrote a monitoring tool that fits in one binary, one YAML file, and one SQLite database.
Someone embedded a SQLite database directly into a Linux executable. The binary still runs, the database still queries, and the toolchain does not care.
A startup ditched everything GPUs do well and made a chip that runs one architecture 20 times faster.
Running a model on your laptop does not mean it is broken. The context window might be.
DuckDB 2.0 switched from yacc to a hand-written PEG parser. The goal was not speed. It was error messages that do not make you want to quit programming.
A quiz shows that even technical readers cannot spot which GPT-4 response has a cryptographic watermark baked in. The detection gap is real.
One database to rule them all. Raphael Bauer makes the case for ditching Redis, Elasticsearch, and message queues in favour of PostgreSQL extensions.
An LLM reverse-engineered a 2008 HP laser printer's protocol and generated a working macOS driver. No human debugging required.
Three years after first commit, the project that made local LLMs possible ships a stable release.
Researchers built an LLM using exclusively elementary-level text. The results challenge assumptions about what makes a model fluent.
A new interface shows chat threads as directed acyclic graphs where you can rewrite nodes and re-run paths. Fixes the branching problem most chat UIs ignore.
A new tool checks if ChatGPT's GPU kernels are actually correct before you run them in production.
The company that sells license plate readers to 5000 police departments just announced privacy controls. Timing raises questions.
Tailscale traced database corruption back to a WAL-mode edge case that survived billions of deployments since 2010.
Researchers figured out how to steal the internal reasoning steps from proprietary models like GPT-4o and Claude through API timing attacks.
Needle2 runs on phones, smartwatches, and Raspberry Pis. The entire model is smaller than a single photo.
A developer built a tool that lets you rewind SQLite databases to any point in their history, no external dependencies required.
A network engineer pushed Go to saturate a 100 Gbps link using AF_XDP. The surprising bit is not the speed, it is that Go got there at all.
A 2010 study found that estrogen, not testosterone, drives sex-specific brain development in newborn male mice. The testicular hormone converts to estrogen in the brain.
Zapscape is a guest-to-host escape for KVM on x86. It lets a compromised VM run code on the host machine, which is the nightmare scenario for cloud providers.
Why learning communities ban code assistants while enterprises mandate them.
Someone is flooding the National Vulnerability Database with fake SQLite vulnerabilities written by language models, and it is breaking actual security work.
A developer forked the TypeScript compiler to add Go-style defer statements. The implementation works, the maintenance burden is real.
Sixteen parsers, a server that writes what it cannot read, and what a hostile data source teaches you about production data engineering.
Why my intrusion detection capstone needed an Isolation Forest, a Random Forest and an autoencoder to reach 0.95 F1 on real attack traffic.
Someone just released a minimal codebase for supervised fine-tuning, direct preference optimisation, and group relative policy optimisation on consumer hardware.
A security firm ran Claude through GlobaLeaks' codebase and found medium-severity bugs for seventy-six dollars per finding. The question is whether a human would have caught the same issues faster.
Manifest deprecated their LLM router after six months. The reason is not what I expected.
A researcher deployed a fake human verification page that only AI crawlers would fall for. The logs are filling up.
OpenAI open-sourced the internal security guidelines they used when building Codex. Turns out threat modelling an AI code generator is different from threat modelling a database.
iOS 26.6 fixed 75 security issues, macOS got 155. That is not normal patch volume.
OrchidFiles reported a flaw that let anyone read private repo secrets. GitHub marked it duplicate, did not patch it, then banned the researcher.
Research engineer roles at the big labs filter for production ML skills first, paper count second.
A Debian general resolution proposes banning LLM-generated patches. The reasoning is direct: you cannot verify the training data's licensing.
Law enforcement claimed strong encryption would end investigations. A new paper tracks what actually happened: encryption went mainstream, crime still gets solved.
New research shows children anthropomorphise LLMs at much higher rates than adults, which changes how we should think about guardrails.
Antares models are 1B to 8B parameters, fine-tuned on security tasks, and Apache 2.0 licensed. This is not another rebranded Llama wrapper.
A Chinese LLM patched critical security bugs in a codebase where OpenAI's models and Anthropic's Claude refused to engage. The refusal problem is real.
David Siegel argued with Richard Stallman for two years in the 1980s. Now he is watching the exact same debate play out with AI models.
Fifteen years of a compartmentalised desktop OS, zero remote code execution bugs. The paper tracking every public Qubes vulnerability is out.
A new paper argues that LLM agent security cannot be solved by better prompts or guardrails alone. The architecture itself leaks privilege.
SQLite will happily store NUL characters in text columns. Your application layer might truncate them silently.
Gwern argues personalised LLM assistants could filter spam, draft replies, and catch your mistakes before you send them. The privacy trade-off is obvious.
A developer trained MNIST digit recognition using only SQL queries. No Python. No frameworks. Just recursive CTEs and window functions.
Anthropic's Model Context Protocol promised to standardise how AI agents talk to tools. A new audit shows most implementations ship with auth disabled by default.
Iroh built a system that splits LLM inference across volunteer nodes. The networking stack handles dropouts mid-inference. Wild.
Google announced Gemini 2.5 Flash will be discontinued in February 2027. Developers who built on it are scrambling.
The moment you realise you are debugging prompt chains instead of writing code.
Dan Luu measured the same coding task twenty times with the same prompt. The variance in output quality was higher than the difference between model versions.
Standard ML has a production compiler that predates Java, runs on ARM64, and ships with a garbage collector tuned for symbolic computation.
Simon Willison's sqlite-utils 4.0 adds schema migration tracking. The library that made it trivial to load data into SQLite now makes it trivial to evolve those tables.
Sidenote lets you comment on a rendered blog post, then an LLM writes the actual markdown diff. No forking, no pull requests.
The National Institute of Standards and Technology maintains atomic clocks in Colorado and Maryland, then serves that time over the internet. The API is simpler than you think.
Physicists found that the standard mean-field approximation for neural networks breaks down when you look at correlations between neurons.
ZKPs let you prove you are over 18 without revealing your birth date. Google just released a library that does it in WebAssembly.
ClickHouse's query language is Turing-complete. Someone proved it by rendering 3D scenes with recursive CTEs and array functions.
vLLM's Micro-Agent proves that three coordinated 8B models can outperform a single frontier model on complex reasoning tasks.
A GitHub repo called Bash4LLM+ does what Python libraries do in thousands of lines, using only shell builtins and curl.
The US Army tested remote breach clearing with swarms of explosive-packed drones. No soldiers crossed the kill zone.
LastPass notified users of another breach. This is the third major incident since 2022. At what point do we stop calling it a password manager and start calling it a credentials museum.
The SQLite team keeps a public list of every way you can break their database. Turns out most corruption comes from ignoring fsync or writing to the file yourself.
Deepset's Haystack framework caught my eye because it treats retrieval-augmented generation as a data pipeline problem, not a chatbot wrapper problem.
Researchers trained particles to form complex shapes without central control. Each particle runs the same neural network, learns local rules, and the swarm organises itself.
A ransomware gang says they got into Tata's systems and grabbed confidential files from Apple and Tesla. The supply chain question nobody wants asked.
The clean energy boom is no longer about emissions targets. It is about not having your grid held hostage by someone else's pipeline.
A firmware update silently killed Transparent Memory Encryption on consumer chips. The engineers stopped replying when users asked why.
Someone found 10,000 GitHub repositories distributing malware disguised as cracked software and game cheats. The scale is wild.
WebGPU makes training tiny neural networks that grow patterns possible in real-time, no server required.
LTAP is Databricks' answer to running transactions and analytics on the same engine. The pitch is clever. The implementation details matter more.
A GitHub repo sketches how Europe could pool scattered compute across universities and research labs to train a GPT-4 class model without buying a new datacenter.
A city government announced a locally trained language model. Turns out it was two existing models stitched together with the weights renamed.
The Arch Linux team spent the weekend cleaning up more than 1,500 malware-laden packages from the AUR. The scale is what surprised me.
The Arch User Repository just had 400 packages backdoored. The attack vector was not clever. It was obvious, predictable, and it worked anyway.
Ivanti Sentry got a pre-auth RCE with the maximum theoretical severity score. Public exploit code is already live.
Researchers found that transformer attention mechanisms lack the executive control functions that let human brains manage working memory. The models can retrieve information, but they cannot suppress irrelevant context.
The ServiceNow incident exposed customer data through misconfigured access controls, not a novel exploit. This is the enterprise security story that never makes headlines.
YAML, TOML, and JSON parsers can run arbitrary code during deserialization. Most dependency scanners miss them entirely.
Third-party integrations are the soft underbelly of university IT. Oxford just learned that again.
Meta keeps pushing back the Llama 4 release because the reasoning capability is not matching internal benchmarks. This is the first time open-weight AI has hit a public delay.
Random UUIDs as primary keys in SQLite cause page splits that triple insertion time. Integer keys stay fast because SQLite is built for sequential writes.
Anthropic open-sourced a framework for testing how well AI models find security bugs. It includes 32 real CVEs and a scoring system. Time to feed it some of my old projects.
A self-hosted tool that spins up Docker containers with public URLs. No orchestrator, no cloud bill.
A CLI tool that flattens your data science repo into one massive prompt. Smart filtering meets the 200K token era.
Reuven Lerner argues Python's syntax sugar is making it harder to explain what code actually does. He compares it to Pinyin romanisation: useful for getting started, obscuring the underlying structure.
A popular extension with 3 million users can be tricked into sending your spreadsheet contents to an attacker-controlled server. The fix is not obvious.
An enthusiast loaded a 1T-parameter model into 768GB of Intel Optane DIMMs and got 4 tokens per second on a single GPU. Slow, but it worked.
Someone finally built a home security camera system that encrypts on-device and costs nothing per month.
A developer catalogues the tell-tale signs of AI-generated code. The patterns are obvious once you see them.
PHP's dependency manager is rolling out cryptographic signatures. The timing matters more than the tech.
Feature flags that run on Cloudflare's edge network, not your backend. This might actually change how you roll out features.
The Norwegian University of Science and Technology is running LLM workloads on Chinese storage hardware. The performance numbers are interesting.
Dirty Frag, Copy Fail, Fragnesia. Three distinct kernel exploits in eighteen months, all exploiting how Linux reassembles fragmented network packets.
New research shows agents generating backend code slowly drop requirements like authentication checks. The longer the generation, the worse the decay.
Models.dev is an open-source database that tracks pricing, context windows, and rate limits across every major LLM provider. No more tab-sprawl to compare GPT-4 versus Claude costs.
A bill requiring platforms to moderate content encouraging violence against Jewish communities turns moderation from a platform choice into a legal obligation.
A new platform gamifies phishing detection with streak tracking and leaderboards. Finally, security awareness training that does not feel like compliance homework.
Linus Torvalds says automated vulnerability scanners have turned the kernel security mailing list into noise. The tools work, the signal-to-noise ratio does not.
Turso used a TLA+ variant called Quint to model their libSQL fork and found over ten real bugs in SQLite's transaction logic that billions of existing tests never saw.
The Online Safety Bill could give UK authorities the power to demand VPN providers weaken encryption or log traffic. Mozilla's response is blunt.
Steering vectors let you nudge a model's behaviour without retraining. They fell out of favour when newer models stopped responding to them. DeepSeek-V4-Flash brought them back.
A programmer rewrote PyTorch's transformer architecture using Rust and abstract algebra. The result is dense but fast.
The first public kernel memory corruption exploit for Apple's M5 chip dropped today. No zero-day trading, just research in the open.
A new LLM observability tool runs without PostgreSQL or Redis. That is not a feature list, that is an architecture decision.
Claude's API is now inside AWS Marketplace. That means billing through your AWS account, usage tied to AWS credits, and regional deployment closer to your data.
Mythos discovered a vulnerability that was already documented in the data it was trained on. The industry is calling this autonomous discovery.
Mythos, an autonomous security agent, caught a buffer overflow in curl that human auditors missed. The tooling works.
Google's Gemini API File Search now handles images inside documents. RAG just got less annoying for technical docs.
Multi-agent systems waste tokens on natural language between agents. A structured clipboard beats conversational interfaces.
No notes match that search. Try another topic or keyword.
Behind the notes
Artificial Intelligence Engineer intern at Voxon Photonics in Adelaide. Studying a Master of Information and Communications Technology at UniSC, with a focus on data, machine learning and security.
Meet the person behind the work