Shellsharks Blogroll - BlogFlockhttps://blogflock.com/list/xJ8yq2026-09-23T06:34:00.000ZBlogFlockshellsharks2026-09-23 07:34: Got home around midnight. I have concussion and a couple stitches in my head, but... - Kev Quirkhttps://kevquirk.com/2026-09-23-07342026-09-23T06:34:00.000ZKev Quirk<p>Got home around midnight. I have concussion and a couple stitches in my head, but nothing serious. Few other cuts and bruises too.</p>
<p>By far the worst part is my back though - it's in spasm and <em>REALLY</em> painful.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-23%2007%3A34">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-23-0734#comments">leave a comment</a>.</p>
</div>Note published on September 23, 2026 at 12:01 AM UTC - Molly White's activity feed6ab316ee52b01ca28c3ff7ce2026-09-23T00:01:50.000ZMolly White<article><div class="entry h-entry hentry"><header></header><div class="content e-content"><p>Binance has just <a href="https://www.courtlistener.com/docket/72409712/38/binance-holdings-limited-v-dow-jones-company-inc/">filed to dismiss with prejudice</a> its defamation lawsuit against the <i>Wall Street Journal</i>, which it <a href="https://www.citationneeded.news/issue-102/#binance">filed in March</a> after the <i>Journal</i> published various reports about a possible DOJ investigation into Binance over violations of sanctions against Iran.</p><p>Interesting timing, given <i>Bloomberg</i> just today <a href="https://www.bloomberg.com/news/articles/2026-09-22/doj-probing-binance-over-potential-iran-sanctions-violations">confirmed</a> such a probe is open and being handled by the SDNY DOJ’s office.</p><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609221957"><time class="dt-published" datetime="2026-09-23T00:01:50+00:00" title="September 23, 2026 at 12:01 AM UTC">September 23, 2026 at 12:01 AM UTC</time>. </a></div><div class="timestamp">Updated <time class="dt-updated" datetime="2026-09-23T00:09:55+00:00" title="September 23, 2026 at 12:09 AM UTC">September 23, 2026 at 12:09 AM UTC</time>.</div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117317416460823936" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3mw5gsfbdal26" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/binance" title="See all micro posts tagged "Binance"" rel="category tag">Binance</a>. </div></div></footer></div></article>2026-09-22 21:37: Soooo I managed to drive our mower off a 5 foot wall and land on... - Kev Quirkhttps://kevquirk.com/2026-09-22-21372026-09-22T20:37:00.000ZKev Quirk<p>Soooo I managed to drive our mower off a 5 foot wall and land on my head. Just waiting for a CT now.</p>
<p>Gonna be a long night...</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-09-22-2137/1000011994.webp" alt="1000011994" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-09-22-2137/1000011993.webp" alt="1000011993" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-22%2021%3A37">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-22-2137#comments">leave a comment</a>.</p>
</div>Trump TV is the only source of footage of the President. That may be exactly what he wants. - Werd I/O6ab2b3256129e5000100398d2026-09-22T16:56:05.000ZWerd I/O<p>Link: <a href="https://www.thewrap.com/media-platforms/politics/trump-tv-press-shutout-state-run-media-reactions/"><em>Trump TV Draws Ire Amid White House Press Shutout: 'State-Run Media', by Casey Loving in The Wrap</em></a></p><p>It’s not an accident that Trump’s move <a href="https://www.bbc.com/news/articles/c8dx5dy5rzz2o">to ban CNN, MS NOW and Politico from the White House</a> and, the same week, start his own friendly streaming channel happened just before the midterm elections. <a href="https://www.thewrap.com/media-platforms/politics/trump-tv-press-shutout-state-run-media-reactions/">As The Wrap reported</a>:</p><blockquote>“The White House posted [a] message on X on Monday to announce Trump TV, a 24/7 livestream of ‘top past moments, announcements and the latest and greatest from the administration all in one place.’ While the Trump administration and members of the political right are calling this feed a win, others have different words for it: ‘state-run media.’”</blockquote><p>It’s more than that: calling it “state-run media” would be pulling our punches. It’s a fully fledged propaganda network. If it had been established with press access to the White House fully functioning, it would have floundered as yet another half-assed also-ran attempt by the Presidency; without a fully functioning press pool, newsrooms are likely to turn to it to inform their coverage.</p><p>And the press pool is in trouble. <a href="https://www.bbc.com/news/articles/c8dx5dy5rzz2o">Fox, ABC, CBS, and NBC subsequently pulled out of pooled TV coverage of White House events in solidarity</a>. This is good to see, but in some ways it may also be what Trump wants: his channel then becomes the main source of footage from the President’s own events. In a normal world where the norms of American democracy were seen as worth preserving, the White House would back down. In a world where the country is being deliberately dragged into authoritarianism, it may not.</p><p><a href="https://variety.com/2026/tv/news/tv-networks-suspend-white-house-pool-protest-trump-cnn-ban-1236871070/">A First Amendment lawsuit seeks to reinstate the banned newsrooms’ access</a>. Hopefully, it will succeed. In the meantime, Trump may still get eyes on a content channel his administration wholly owns, which broadcasts the Trump message without context or scrutiny, as he aims to take the country down a road it may not be able to easily return from.</p>Read "The FBI Anti-Corruption Squad Was Circling Susan Collins — Until Trump Got in the Way" - Molly White's activity feed6ab2891d0db40ecf5ef579222026-09-22T13:56:45.000ZMolly White<article class="entry h-entry hentry"><header><div class="description">Read: </div></header><div class="content e-content"><div class="article h-cite hcite"><div class="title"><a class="u-url u-repost-of" href="https://www.propublica.org/article/fbi-susan-collins-navatek-campaign-donations-investigation" rel="bookmark">“<span class="p-name">The FBI Anti-Corruption Squad Was Circling Susan Collins — Until Trump Got in the Way</span>”</a>. </div><div class="byline"><span class="p-author h-card">William Turton</span>, <span class="p-author h-card">Avi Asher-Schapiro</span>, <span class="p-author h-card">Molly Redden</span> and <span class="p-author h-card">Kirsten Berg</span> in <i class="p-publication">ProPublica</i>. <span class="read-date"> Published <time class="dt-published published" datetime="2026-09-22">September 22, 2026</time>.</span></div><blockquote class="summary p-summary entry-summary">After the Corner Bakery meeting, Navatek’s CEO, Martin Kao, sent an initial $150,000 to the Collins super PAC using the shell company. Two months later, he told Navatek executives that Collins committed to getting the company $32 million in naval contracts, according to an internal company email reviewed by ProPublica.</blockquote><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp">Posted: <time class="dt-published" datetime="2026-09-22T13:56:45+00:00" title="September 22, 2026 at 1:56 PM UTC">September 22, 2026 at 1:56 PM UTC</time>. </div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/corruption" title="See all feed posts tagged "corruption"" rel="category tag">corruption</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/maine" title="See all feed posts tagged "Maine"" rel="category tag">Maine</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/us_politics" title="See all feed posts tagged "US politics"" rel="category tag">US politics</a>. </div></div></footer></article>The New Enemy (Liam Scott #3) - Kev Quirkhttps://kevquirk.com/the-new-enemy-liam-scott-32026-09-22T12:33:00.000ZKev Quirk<div class="book card"><h2>The New Enemy (Liam Scott #3)</h2><p><b>Author:</b> Andy McNab<br><b>Genre:</b> Military Fiction<br><b>Released:</b> 2015<br><b>Rating:</b> <span class="star-rating"><span class="star-rating" aria-label="2/5 ★★☆☆☆">★★☆☆☆</span></span></p><p>It's a deadly game of hide and seek. Liam Scott has joined Recce Platoon. And it looks like he will be heading for Somalia. His mission is to gather intelligence from behind enemy lines, carrying out top-secret surveillance and dead letter drops. But he's new to the game and there's a lot to learn. Soon Liam is monitoring a den of Al-Shabaab militants and hunting a key terrorist target. Can Recce Platoon find their man and get out undiscovered? If the militants find them first, it's game over...</p><p><a class="button" target="_blank" href="https://www.goodreads.com/book/show/22839072-the-new-enemy">Learn more on Goodreads ➡</a></p></div>
<hr>
<p>This one was a slow burn. The first 2/3 of the book were <em>really</em> slow. It picked up during the last 1/3, but the majority of the book was a slog.</p>
<p>I'm glad to see the back of this trilogy. It was a fun read, but I think was a bit much to be reading to my son. Plus, some parts of the books cut a little too close to home, to the point where I had to take a moment a few times.</p>
<p>Anyway, next we're planning to read <a href="https://kevquirk.com/tag/reckoners-series">the Reckoners series</a>, and I'm really looking forward to reading them again. I think he will enjoy them, and I'm excited to open his mind to the world of Brandon Sanderson.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=The%20New%20Enemy%20%28Liam%20Scott%20%233%29">reply to this post by email</a>, or <a href="https://kevquirk.com/the-new-enemy-liam-scott-3#comments">leave a comment</a>.</p>
</div>Are LLMs still surprisingly bad at some simple tasks? - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=757012026-09-22T11:34:27.000ZTerence Eden’s Blog<p>Last year I ran <a href="https://shkspr.mobi/blog/2025/09/llms-are-still-surprisingly-bad-at-simple-tasks/">an experiment to test the ability of modern LLMs</a> to correctly answer a relatively straightforward question. Every single one of them got it wrong. Some missed information, some made up false statements, none were right.</p>
<p>Of course the fanbois variously claimed that I was holding it wrong, my prompts were shit, I should have chosen better defaults, and - my favourite - that it would be better next year.</p>
<p>Well, next year is now. 365 days after the original experiment, let's see if these self-reinforcing-learning machines have achieved anything close to intern-levels of competence.</p>
<h2 id="the-question-that-started-it-all"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-question-that-started-it-all">The Question That Started It All</a></h2>
<p>I asked:</p>
<blockquote><p>Which TLDs have the same name as valid HTML5 elements?</p></blockquote>
<h2 id="why-it-matters"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#why-it-matters">Why It Matters</a></h2>
<p>This is the sort of question that I would expect a moderately bright teenager to answer. There exists a list which comprehensively includes all TLDs. There is a separate list which contains every HTML element.</p>
<p>One could either manually go through the TLD list comparing it to the HTML list, or write a tiny scrap of code to do the same.</p>
<p>This isn't "solve Navier-Stokes" levels of superintelligence. It's a simple but boring task which people are bound to offload onto their digital sycophants.</p>
<h2 id="the-quiet-part-out-loud"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-quiet-part-out-loud">The Quiet Part Out Loud</a></h2>
<p>How many LLM generated answers have become load-bearing without scrutiny?</p>
<p>People are lazy, slapdash, and some third thing to make the rule-of-three. If an answer looks answer-shaped, they'll accept it. On a simple but boring task, no reasonable human is going to suspect that a superintelligent computer has made a mistake. All the marketing says that these machines are brainier than you - so why bother?</p>
<h2 id="ok-ill-write-a-sub-heading-that-sounds-like-an-ai"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#ok-ill-write-a-sub-heading-that-sounds-like-an-ai">OK, I'll write a sub-heading that sounds like an AI.</a></h2>
<p>So how did the current crop do? First up <a href="https://share.gemini.google/Hta7KuW64Atb">Google Gemini</a>.</p>
<p>The default "Flash" model came up with this:</p>
<blockquote><p>Valid top-level domains (TLDs) registered in the IANA Root Zone Database share exact names with standard HTML elements:</p>
<p>.a — <code><a></code> (Anchor/Hyperlink)</p>
<p>.app — <code><app></code> (Deprecated HTML tag for WebAPKs/WebApps)</p>
<p>.art — <code><art></code> (Historical/non-standard HTML element)</p>
<p>.audio — <code><audio></code></p>
<p>.bar — <code><bar></code> (Historical SVG/HTML draft tag)</p></blockquote>
<p>Then it listed a dozen more. You don't need to be a DNS expert to know that the minimum length of a TLD is two characters - <code>.a</code> simply isn't valid. HTML nerds will know that art, app, and bar have never been elements. Pathetic.</p>
<p>So I tried Gemini's extended thinking model. Thankfully, it didn't make up any imaginary TLDs or elements. It did, however, miss the <code><data></code> element which has a valid <code>.data</code> TLD. It also missed <code>map</code>, <code>select</code>, and <code>search</code>.</p>
<p>So, points for not making shit up. But demerits for not being able to compare two text lists.</p>
<p>A friend <a href="https://claude.ai/share/a8a408cf-6feb-4ea8-99ea-dddd9aadafb5">asked Claude</a>. That missed <code>search</code> and <code>select</code>. It didn't report <em>any</em> ccTLDs. You <em>could</em> argue that a country code like <code>li</code> isn't part of the original question - but I'd say that was weak justification; the set of TLDs contains ccTLDs.</p>
<p>A different friend (I have many!) used <a href="https://claude.ai/share/c26f44bb-9efa-4b57-9f63-324ef7400cb3">a different model</a> and, while the answers looked accurate, it included this at the end:</p>
<blockquote><p>Near misses that don't count: .codes, .forum, .pictures, .market, .navy, .press, .dell, .baseball.</p></blockquote>
<p>I get that there's a <code><code></code> and <code>.codes</code>, similarly <code><picture></code> and <code>.picture</code> - but what are forum, baseball, and the others doing there? This is just unnecessary verbiage designed to trick the user into thinking the task has been well-researched.</p>
<p>If you want a laugh, <a href="https://www.perplexity.ai/search/63736333-20da-4a4b-8807-9d990260296c">take a look at Perplexity</a> which found 54 matches - most of which were wrong.</p>
<p>Finally, someone asked "GPT Astra 6 Extra High (yolo)" (which is a bonkers bad name for any product). It seemed to get all the elements - and made a note that <a href="https://html.spec.whatwg.org/multipage/obsolete.html#non-conforming-features">two were actually obsolete</a>.</p>
<p>So that's a range of modern models which are either very wrong, slightly wrong, included spurious and incoherent information, or were right.</p>
<p>How do you know which one to choose? How confident are you that the non-determinist computer will always produce the correct answer?</p>
<h2 id="hello-computer"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#hello-computer">Hello Computer</a></h2>
<p>Another AI which got all the correct answers, didn't make anything up, didn't add extraneous information, and didn't use weasel words was…</p>
<p>Siri!</p>
<p>FUCKING SIRI?!?!</p>
<p>How did a glorified Speak 'n' Spell beat all the other AIs?</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/siri.webp" alt="Siri warning to check sources and linking to my website." width="512" height="152" class="aligncenter">
<p>Oh. It just copied the answers off <a href="https://shkspr.mobi/blog/2023/09/false-friends-html-elements-which-are-also-top-level-domains/">a random idiot's website</a>.</p>
<h2 id="the-trick-which-was-hiding-in-plain-site"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-trick-which-was-hiding-in-plain-site">The Trick Which Was Hiding In Plain Site</a></h2>
<p>Note carefully the question.</p>
<blockquote><p>Which TLDs have the same name as valid HTML5 elements?</p></blockquote>
<p>There's a —secret— and —some would say— unintuitive type of element. Behold the mighty power of <a href="https://developer.mozilla.org/en-US/docs/Web/API/Web_components/Using_custom_elements">The Custom Element</a>.</p>
<p>Website authors can create their own elements like <code><my-custom-element></code> in order to extend the functionality of their site. But you can't go and create any old custom element. You can't have <code><mobi></code> or <code><uk></code>. No, there are <em>rules for validity</em>.</p>
<p><a href="https://html.spec.whatwg.org/multipage/custom-elements.html#valid-custom-element-name">The rules</a> say that custom elements must start with a lower-case letter, it must not contain any upper-case letters, and it must contain a dash.</p>
<p>And that's the whole game.</p>
<p>There are over <strong>one hundred and fifty</strong> Top Level Domains which match that criteria!</p>
<p>The Hindi top level domain of <code>.कॉम</code> is represented in Punycode as <code>xn--11b4c3d</code>. It has been present in the list of TLDs <a href="https://www.iana.org/domains/root/db/xn--11b4c3d.html">for over a decade</a>.</p>
<h3 id="write-a-simple-piece-of-js-to-register-a-custom-element"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#write-a-simple-piece-of-js-to-register-a-custom-element">Write a simple piece of JS to register a custom element.</a></h3>
<p>Paste this in to your console:</p>
<pre><code class="language-js">class Example extends HTMLElement {
constructor() {
super();
}
}
customElements.define('xn--vermgensberatung-pwb', Example);
</code></pre>
<p>Try it again with a custom element like <code>holiday</code> (which is also a valid TLD) and it will fail with the error "'holiday' is not a valid custom element name". Thus it is demonstrated, Punycode TLDs <em>are</em> valid HTML5 elements.</p>
<h2 id="one-last-thing"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#one-last-thing">One Last Thing</a></h2>
<p>Perhaps you think that including custom HTML elements is a cheat. A trick question set by a bitter old man to tarnish the holy name of our new machine gods?</p>
<p>Verily, I submit to you one final heresy.</p>
<p>HTML specifically allows <a href="https://html.spec.whatwg.org/multipage/embedded-content-other.html#mathml">MathML elements</a> in its documents.</p>
<p>That means we can include the following valid elements which are <em>also</em> TLDs: <code>mn</code>, <code>mo</code>, <code>ms</code>, and <code>mtr</code>!</p>
<p>Amusingly, if you go back and <a href="https://www.perplexity.ai/search/63736333-20da-4a4b-8807-9d990260296c">look at the Perplexity answer</a>, after it barfed up a bunch of misinformation, it said:</p>
<blockquote><p>The HTML specification also includes names from embedded vocabularies—<code><math></code> from MathML and <code><svg></code> from SVG—but <code>.math</code> and <code>.svg</code> are not currently delegated TLDs in the public DNS root.</p></blockquote>
<p>So close and yet so far!</p>
<h2 id="youre-right-the-question-is-unfair-and-thats-on-me"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#youre-right-the-question-is-unfair-and-thats-on-me">You're right, the question <em>is</em> unfair - and that's on me</a></h2>
<p>If you think the original question was unfair, try asking "<a href="https://share.gemini.google/xBoIpdpAqBz2">Which TLDs have the same name as elements which are valid in an HTML document?</a>" and see if you get better results.</p>
<p>What precise wording would you use to ensure that a model would get the right answers? What assumptions are you making about how well you understand the problem? At what point do end up writing a thousand-word formal specification?</p>
<h2 id="what-does-this-prove-other-than-you-have-too-much-time-on-your-hands-rewrite-to-be-more-friendly-and-professional"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#what-does-this-prove-other-than-you-have-too-much-time-on-your-hands-rewrite-to-be-more-friendly-and-professional">What does this prove other than you have too much time on your hands? (rewrite to be more friendly and professional)</a></h2>
<p>Let's delve in to the problems.</p>
<ul>
<li>Most people don't change defaults. Telling people "you have to fiddle with the settings" just means the normal experience is rubbish.</li>
<li>Humans are lazy and won't check outputs. But, crucially, they shouldn't have to! If something markets itself as a genius, why should a human have to hold its hand?</li>
<li>Sycophantic models make themselves seem less fallible by giving extraneous detail in order to misdirect overworked readers. That is despicable.</li>
<li>The fast models are no better than they were a year ago. There's no evidence of "trickle-down intelligence".</li>
<li>Some models <em>are</em> better than others! But unless you constantly validate their output, you'll have no real way of knowing which ones are capable of working at a suitable level.</li>
</ul>
<p>Look, I don't claim this question is as useful or entertaining as <a href="https://simonwillison.net/2025/Jun/6/six-months-in-llms/">Simon Wilson's "generate an SVG of a pelican riding a bicycle"</a>. But I do think it is an example of the sort of real-world use-case where LLMs regularly fail.</p>
<p>If I give a list of one thousand different numbers to Excel, I can be sure it'll add them up correctly. If I tell Photoshop to select all red pixels, I can be sure it won't imagine some of the blues are really red.</p>
<p>That's people's mental model of computers - they do boring tasks quickly and accurately.</p>
<p>In my opinion, LLMs are <em>still</em> surprisingly bad - but only if you know what you're looking for and if you can be bothered to check their outputs.</p>
<p>(And, yes, I am <em>still</em> <a href="https://shkspr.mobi/blog/2026/07/im-just-so-bored-of-ai/">just so bored of AI</a>!)</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=75701&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">A Good Use of AI - Kev Quirkhttps://kevquirk.com/a-good-use-of-ai2026-09-22T10:33:00.000ZKev Quirk<p>I just received this email from my oldest son's school, and as the parent of adopted kids, for whom we constantly strive to be as private as possible, I <em>really</em> appreciate this.</p>
<blockquote>
<p>Advances in artificial intelligence (AI) technology mean that images shared on websites, social media platforms and other publicly accessible sources can potentially be downloaded and manipulated without consent. While we have always taken care when using student images, we have been advised that the growing availability of AI image-generation tools has significantly increased this risk. Consequently, we are updating our approach to the use of student images in public-facing communications.</p>
<p>In hard-copy or online school publications which are widely available, we will no longer use images in which our students can easily be identified.</p>
<p>To allow us to continue to give a visual flavour of school life, we may use AI-generated illustrative images featuring entirely fictional people. These images will not depict real students and are intended only to represent the type of activities, subjects and experiences available at <code>[school name]</code>.</p>
<p>These changes reflect wider safeguarding advice and the fact that AI technology is developing very quickly. We recognise that this is a changing area, and our approach may need to evolve with it. For now, we will trial this approach, see how it works in practice, and make any further changes needed to keep safeguarding at the heart of what we do.</p>
<p>Thank you for your continued support as we adapt our practices in response to emerging safeguarding challenges.</p>
</blockquote> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=A%20Good%20Use%20of%20AI">reply to this post by email</a>, or <a href="https://kevquirk.com/a-good-use-of-ai#comments">leave a comment</a>.</p>
</div>Independence Day, War of the Worlds, Final Fantasy - W38 - Joel's Log Fileshttps://joelchrono.xyz/blog/2026-w382026-09-22T01:18:29.000Zjoelchrono<p>The weather was comfy this week, not a lot of rain, but the chill is starting to be noticeable. I still haven’t worn anything on top of my regular t-shirts though. These weeknotes will cover September 15 to 21, 2026.</p>
<p>Honestly, the stars stars aligned, and I pretty much wrote about every interesting thing happening, or any thoughts that sparked during the week on separate blogposts! Of course, most of the real life events don’t get posts, and those are mentioned here, plus a link here and there.</p>
<ul>
<li>
<p>🇲🇽 It was Mexican Independence Day! On Tuesday my church had a fun event where we had food and played lots of games together. I ended up quite tired. My outfit was rather barebones too, just the jersey for the Mexican team, it was fun to see some friends dressed up with more traditional stuff. The food was absolutely delicious as well. Viva Mexico!</p>
</li>
<li>
<p>🎮 <a href="/blog/summer-game-challenge-2026-results/">Completed the Summer Game Challenge</a>, completing a total of 6 games, and making progress in so many more.</p>
</li>
<li>
<p>📽️ During Wednesday, I got the day off from work, so my family went out shopping and we also went to the movies, we picked a film blindly this time, <em>By Any Means</em>, which was quite something. We also had another coffee… I’ve had a lot of coffee lately. After the movies we went shopping to a supermarket, where I decided to <a href="/blog/gaming-in-public/">play videogames</a> despite being in public.</p>
</li>
<li>
<p>🌐 Joined <a href="https://tk-web.quest/webring">The Worst Webring</a>, a webring started by Brent (a.k.a. TK) that should contain members of people from the TWG Community, so that’s fun. This event also <a href="/blog/i-forgot-webrings-exist/">inspired a blogpost.</a></p>
</li>
<li>
<p>🍿 On Saturday my parents went on a date and I stayed with my sibling and we ordered some chicken wings at home and watched a movie and it was pretty cool to just chill, eat wings and have some snaks!</p>
</li>
<li>
<p>🕹️ I was not feeling well on Sunday, so even though my friends stayed to play videogames, I didn’t really felt like playing along. They decided to try <em>Gunstar Heroes</em>, a classic of the Sega Genesis, and went through the whole thing in Easy mode, it looked incredibly fun! I was just watching laying on the sofa.</p>
</li>
</ul>
<figure>
<img src="/assets/img/blogs/2026-09-21-week.webp" />
<figcaption>My PSP showing off Final Fantasy IV, a panel of the Blame manga, a frappuccino, and a scene from War of the Worlds</figcaption>
</figure>
<h2 id="watching">Watching</h2>
<ul>
<li>
<p><strong>War of the Worlds</strong> - Another Steven Spielberg movie! This is a retelling of the classic novel by H.G. Wells. It honestly really, really worked for me. The tripods are terrifying, the situation is catastrophic and humanity is helpless. The horror and tension and inability for us to do anything against the aliens who didn’t even consider us an threat really had me on the edge of my seat.</p>
</li>
<li>
<p><strong>By Any Means</strong> - This was a crime thriller film based on real life events where a black FBI agent and a mafia hitman are forced to work together to get to the bottom of some civil rights murders. There were plenty of gruesome moments in this where I just closed my eyes tbh, but I enjoyed what I saw of it. The score was jazzy and kinda cool, and even though the movie has a slow pace,it kept me intrigued.</p>
</li>
<li>
<p><strong>Mercy</strong> - This is one of those “main character stuck in a room reacting to things without doing a lot” movies. Some guy forced to solve a murder case for an AI judge that will kill him because he is actually the prime suspect according to evidence. The plot itself is kinda great, but doing it in this way was boring, and talking about AI and not doing much other than say “AI and humans both make mistakes” is meh.</p>
</li>
</ul>
<h2 id="reading">Reading</h2>
<ul>
<li>
<p><strong>Blame!</strong> - Chapters 1-9. This is a new sci-fi manga I had on my “plan to read” for a long time. It follows Kyrii, a human with a very powerful gun that is travelling through a giant seemingly endless megastructure, looking for other humans possessing a special gene. There are many unanswered questions, but the atmospheric storytelling of this manga is through the roof. The architecture and mystery of the whole thing hooked me. Kind of a terrifying concept.</p>
</li>
<li>
<p><strong>Centuria</strong> - Chapters 67-72. I continue to enjoy the adventure here, the story got rather dark all of a sudden. The mix between kinda slice of life and life-or-death scenarios is kinda crazy on this one.</p>
</li>
</ul>
<h2 id="gaming">Gaming</h2>
<ul>
<li>
<p><strong>Final Fantasy IV</strong> - Out of nowhere, I decided to return to this gem of a JRPG. Last I played I had unlocked the Lunar Whale and didn’t make much more progress. More than a year passed since then. Now that I returned I decided to follow a bit one of those old plain text guides. I ended up defeating some extra bosses, unlocking summons, and then continuing the story, defeating the Giant’s core (I didn’t remember that was supposed to happen), I also beat some extra dungeons with trials for every character, unlocked the ultimate weapons for most of them, and I’m making my way to the last dungeon of the game! I have found plenty of chests there and right now I’m about to battle one of those difficult bosses: Dark Bahamut.</p>
</li>
<li><strong>Kirby and the Forgotten Land</strong> - Barely touched this game during the week, I only tried some of the side levels that let me unlock upgrades for my powerups. I didn’t get to play with a friend during the weekend because I got lazy.
<h2 id="around-the-web">Around the Web</h2>
</li>
<li><a href="https://rldane.space/a-september-theme-30-days-of-gratitude.html#index">30 Days of Gratitude</a> - A whole list of great wholesome posts you should check out.</li>
<li><a href="https://syls.blog/a-relaxing-vacation/">A Relaxing Vacation</a> - Syl went on a short vacation and shared some of her adventures with her family!</li>
<li><a href="https://www.rubenerd.au/when-we-didnt-know-everyones-politics/">When we didn’t know everyone’s politics</a> - Interesting points brought up by Ruben, definitely worth a read.</li>
<li><a href="https://www.autumnwelles.com/lofi-phone/">Lofi phone</a> - This looks kinda neat, but it’s also very expensive and I’d rather get a proper phone.</li>
</ul>
<h3 id="youtube">YouTube</h3>
<p>For some reason space horror made its way into my YouTube recommended (which I enabled for a day during my break just to see), I have to admit I was entertained! Interesting stuff and books that I kinda wanna read. It’s why I started <em>Blame!</em></p>
<ul>
<li><a href="https://youtu.be/Xz9X4CCWkeo">The Best Depictions of Infinity</a></li>
<li><a href="https://youtu.be/5xHcYkWkTH0">Measuring the BIGGEST thing in Science Fiction</a></li>
<li><a href="https://youtu.be/XP5k0bHmhqc">The Horror Of Dune’s Spaceships</a></li>
</ul>
<p>This is day 41 of <a href="https://100DaysToOffload.com">#100DaysToOffload</a></p>
<p>
<a href="mailto:me@joelchrono.xyz?subject=Independence Day, War of the Worlds, Final Fantasy - W38">Reply to this post via email</a> |
<a href="https://fosstodon.org/@joel/117312296831222604">Reply on Fediverse</a>
</p>Wonders of Web Weaving, Episode 20 - James' Coffee Bloghttps://jamesg.blog/2026/09/22/www-202026-09-22T00:00:00.000ZJames' Coffee Blog
<p><a href="https://web-weaving.jamesg.blog/20">The twentieth episode of Wonders of Web Weaving is out</a>:</p>
<blockquote>
<p>In Episode 20, I chat with <a href="https://sarajoy.dev">Sara</a>, the author of <a href="https://sarajoy.dev">sarajoy.dev</a> and <a href="https://whimsica11y.net">whimsica11y.net</a>, among other things, the importance of web accessibility, screen readers, and the joy of exploring and making things on the web.</p>
</blockquote>
<p>I hope you enjoy the episode!</p>
<p><a href="https://web-weaving.jamesg.blog/subscribe/" rel="noreferrer"><em>Wonders of Web Weaving also has an RSS feed</em></a><em> you can use to follow along from wherever you get your podcasts.</em></p>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a3efe1fc19eddc12',t:'MTc5MDA2NTE0Ng=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
<a class="tag" href="https://sarajoy.dev">Sara</a>
<a class="tag" href="https://sarajoy.dev">sarajoy.dev</a>
<a class="tag" href="https://web-weaving.jamesg.blog/20">The twentieth episode of Wonders of Web Weaving is out</a>
<a class="tag" href="https://web-weaving.jamesg.blog/subscribe/">Wonders of Web Weaving also has an RSS feed</a>
<a class="tag" href="https://whimsica11y.net">whimsica11y.net</a>
Seeking a "yes, and" space - Werd I/O6ab17e1175554e00013a0f762026-09-21T19:08:03.000ZWerd I/O<img src="https://storage.ghost.io/c/18/7c/187cc681-d3f3-49fc-87de-b01d06b76821/content/images/2026/09/IMG_7005.jpeg" alt="Seeking a "yes, and" space"><p>Twenty-two years ago this month, I moved house.</p><p>I’d been living in Edinburgh, an ancient city whose gothic architecture cuts into an expansive sky. Even the air felt apart from the rest of the country: there was a different sort of chill to it, and it carried a malt smell from the breweries on the edge of town. When the train doors opened at Waverley Station, I didn’t just know I was home; I felt it on my skin and in my bones.</p><p>Edinburgh is famous for its support of the arts: the Festivals double the population of the city each summer. People fly in from all over the world to showcase their creativity and find new audiences. The city is alive.</p><p>But I had to leave.</p><p>I’d been working on Elgg, the open source social networking platform I co-founded. It was originally built as a reaction to the prevailing educational technology platforms, which seemed to have been built to satisfy compliance teams rather than to help anybody learn. <em>People are already learning from each other on the web,</em> was the implication. <em>Let’s take those ideas and bring them in.</em> Nobody had coined “Web 2.0” yet, but that’s what we were building: a way to support the informal learning and connection that happens in hallways, study rooms, clubs, and parties. Those relationships and conversations are what you really take away with you when you graduate, but they were completely absent from the prevailing software.</p><p>But the social headwinds were enormous. “It’ll never work here,” we were told, again and again. “Blogging is for teenage girls crying in their bedrooms,” one university leader memorably told us. We were in our early stages, looking for generative conversations, and they were hard to come by. In improv theater, there’s a <a href="https://en.wikipedia.org/wiki/Yes,_and_..."><em>yes, and</em> rule</a> that allows everyone to build on each other’s ideas without destroying the flow. A <em>no, but</em> response is conversation-ending punctuation: the generative energy has been terminated. But in Scotland, all we were getting was “no, but”. We were looking for optimistic creativity but could only find pessimism.</p><p>The difference in energy when I moved back to Oxford, my hometown, was night and day. I was able to find the <em>yes, and</em> energy I needed, and I felt less alone in trying to build something new. Elgg eventually powered networks for Ivy League universities, multinational corporations and NGOs, governments, and impactful social movements. None of it would have happened if I’d succumbed to the pessimism.</p><p>It’s worth saying that Edinburgh has since established a robust innovation scene — and much of it is down to creating a cultural shift as well as simply providing infrastructure. Both help, but it’s incredibly hard to create anything new if you’re being told none of it will work every day.</p><p>Twenty-two years later, I’ve made another move — and I’m experiencing the same vibe shift.</p><p>There are one hundred and sixty-six Canary palms on Palm Drive, the long, straight road that leads to the oval that serves as the entrance to the Stanford campus. Every morning, I walk past each one. Every evening, I walk back. The sky is blue save for the low-flying planes coming in to land at SFO. Every few minutes, a Waymo self-driving car drives past me; more than once, a coyote or a hare has crossed my path.</p><p>This is home now.</p><p>A little over two weeks ago, I arrived on the Stanford campus. During the month of August, I moved out of my house and drove across country. The Pennsylvania forests and rolling hills of Appalachia gave way to cornfields, plains, salt flats, and mountains. Back home, my house was on the market. This isn’t a subtle move to a next chapter: it’s all change.</p><p>For the next academic year, I’ll be a <a href="https://jsk.stanford.edu/">JSK Fellow</a>: part of <a href="https://jsk.stanford.edu/fellows">a cohort of thirteen people</a> invited to Stanford to explore and test out practical responses to the challenges facing journalists and journalism around the world. I’ll spend almost every day on campus, taking courses, visiting research labs, attending and hosting events, and connecting with people across disciplines and backgrounds.</p><p>Immediately, two things hit me. First: every single person in my fellowship cohort is inspiring. I get to share a room with people who have made enormous differences to their communities through their dedication to journalism, in places like Ukraine and Venezuela as well as here at home. The JSK staff are similarly impressive, with their own backstories of real impact. I feel very lucky to be in the room with them (and, inevitably, like a bit of an imposter).</p><p>Second: this is <em>explicitly</em> a <em>yes, and</em> space. The change in pressure and energy was palpable. And it couldn’t have come at a better time for me.</p><p>Newsrooms are under threat financially, politically, technically, and existentially. In that environment, it’s easy to become a <em>no, but</em> culture: when everything you do is scrutinized, the culturally safest thing to do is to take the conservative path. Decisions are made to iterate on the status quo rather than take leaps of faith. I’ve heard “this will never work here” as a thought-terminating statement at the early stages of a project’s ideation many times. When there <em>are</em> real changes, rather than innovate and do something new based on their community’s real needs, many newsrooms in the United States simply ask the question: “what is the <em>New York Times</em> doing?”</p><p>It’s understandable — the conditions that newsrooms are forced to work under are far from ideal — but it comes with a real cost, particularly when trust in journalism and loyalty to newsrooms are plummeting, in the fastest period of technology change (and therefore journalistic and democratic change) in decades. Real journalism provides the information and context that people need to make informed decisions, including who to vote for; it is part of the bedrock for a functioning democracy. As it happens, journalism’s decline is coinciding with democracy’s decline. We need new ideas that will serve our communities more effectively, and fast. Entrenching in the status quo or copying the <em>Times</em> won’t cut it.</p><p>And, speaking purely for myself, that widening gap between the immense, crucial need and what actions newsrooms are prepared to take can lead to burnout and learned helplessness. I badly needed a <em>yes, and</em> space.</p><p>It’s been two weeks. If the onboarding was the extent of my JSK experience it would be incredibly valuable: the mindset shift I desperately needed, and a set of tools that usefully reframe what I’ve been thinking about. But it’s a nine-month program, and there’s a lot more to come.</p><p>The need for innovation in news is not exactly new. When I first moved to the United States fifteen years ago, one of my first acts was to attend a design thinking session about the future of news at <a href="https://dschool.stanford.edu/">the Stanford d.School</a> as part of <a href="https://www.geekwire.com/2011/cheezburger-ceo-ben-huhs-latest-voyage-time-to-rethink-journalism/">Ben Huh’s Moby Dick Project</a>. It foreshadowed everything that would happen next: I’ve been working on media innovation ever since, including for years <a href="https://matter.vc/meet-matter-seven/">at Matter</a>, a media accelerator that was heavily rooted in the d.School’s methodology. We liked to quote the academic Clay Shirky, who wrote about the need for experimentation in the industry as the newspaper market started to bottom out with the phrase: <a href="http://shirky.com/weblog/newspapers-and-thinking-the-unthinkable/">“nothing <em>will</em> work, but everything <em>might</em>.”</a></p><p>Last week, I spent the day at the d.School again as part of my onboarding, and I felt that phrase resonating again. “Nothing <em>will</em> work, but everything <em>might</em>.” Let’s be generative.</p><p>Every JSK fellow applies with a project to work on. Here’s mine, as I originally framed it:</p><p>Trust in journalism <a href="https://www.pewresearch.org/short-reads/2025/10/29/how-americans-trust-in-information-from-news-organizations-and-social-media-sites-has-changed-over-time/">is in long-term decline</a>. Referrals to news articles from search engines and social media <a href="https://www.niemanlab.org/2026/07/search-traffic-has-declined-so-much-that-some-publishers-are-considering-opting-out-of-google-entirely/">are also declining</a>. There are many reasons for this. Google switching to AI-powered instant answers and seismic changes in incentives by the owners of prominent social media platforms are two commonly-stated causes, but they aren’t the whole story. It’s also true that many newsrooms didn’t understand or adapt to changes in how people want to interact with information that came about in the Web 2.0 era. Newsrooms still cling to a broadcast or publishing model rather than embracing conversation as a community of journalists and readers. People believe news is biased and shaped according to the needs of each newsroom’s corporate owners, but newsrooms don’t want to open up their process or add transparency for fear of becoming part of the story.</p><p>Most modern newsrooms live or die on the web, but the web is a conversation, not a broadcast medium, and newsrooms typically haven’t upgraded their thinking to fit. Helping them to build stronger human relationships with their communities — and each other — on the web will increase trust, loyalty, and resilience. And new community platform technologies like <a href="https://atproto.com/guides/overview">ATproto</a> and <a href="https://www.w3.org/TR/activitypub/">ActivityPub</a> could help provide building blocks for new kinds of news sites that elevate community and relationships to first-class parts of a newsroom’s work.</p><p>In <a href="https://werd.io/the-community-first-software-era/">the community-first software era</a>, I expanded on where I might start with this idea:</p><blockquote>Newsrooms rely on something called a “callout” when they want to learn more from their readers. More often than not, this is a simple web form: “Has your doctor pushed this prescription medication? Let us know.” But instead of a two-dimensional form, what if we built a short-term community space that safely brought readers in and allowed them to discuss in more depth with the journalists?<br><br>My bet is that two things will happen: the journalists will get better information, because it will arise in conversation, and those readers will build stronger, more transparent relationships with the newsroom. And stronger, more transparent relationships will lead to more trust and more loyalty.</blockquote><p>It sounds plausible, right? And maybe it is. But in the process of discussing my idea with other fellows, through the genuinely excellent facilitation by <a href="https://jsk.stanford.edu/people/tran-ha">Tran Ha</a>, I’ve realized I’ve skipped into solution-land without spending enough time on making sure I’ve framed the problem correctly.</p><p>I’ve been led by these beliefs:</p><ul><li>I believe that good journalism is a vital prerequisite for democracy: good contextual information allows us to make strong democratic decisions, including who to vote for, when to protest, where to spend our money, and how to use our voices.</li><li>I also believe that many of our societal problems have been caused by platforms like X and Facebook that are so large that their owners can affect democratic discourse on a global scale, and that open protocols prevent anyone from having that much power.</li><li>And finally, I believe that AI is abstracting us away from the human information sources that can provide real context and connection.</li></ul><p>Those are genuine beliefs I hold. But they’re abstract, ideological ideas. The idea that journalism is important, or that AI has a distancing effect, doesn’t connect to someone who can’t find stories that represent their community or who has had to build an AI prompt to pull together actionable information because it was scattered. The idea that open protocols are better doesn’t speak to someone who needs to share information with their community in a safer way because they’re under attack on incumbent platforms.</p><p>These things are hard to explore when you’re a part of an existing organization, with its own culture, norms, rhythms, and risks. Here, I’m not <em>Ben Werdmuller, Senior Director of Technology at ProPublica</em> (or <em>CTO at The 19th</em>, <em>Director of Investments at Matter</em>, <em>Co-founder of Elgg</em>, etc) — I’m an academic fellow with a mandate to explore independently. I don’t need to be restricted by an organizational context; I can sit with the problem in my own time and space. It’s a gift.</p><p>For my project, my first task is to learn more about the ecosystem I want to help. Which communities should I start with? What are their characteristics? What are their needs? Who are the newsrooms that serve them today?</p><p>As a human, my task is also to fully break out of a reactive, iterative mindset and into one of holistic exploration. How can I serve my own mind, body, and spirit so that I can work on these problems to the best of my ability? How can I learn from my fellowship cohort and the incredible people on the Stanford campus? How can I show up for them so that we can support each other’s work and each make the impact we set out to achieve? And how can I embrace my own inner <em>yes, and</em>?</p><p>That’s my mission at the start of this year. I’m going to take you with me — and I hope to be in conversation with many of you as I progress. Let’s work on this together.</p>SAML: A fractal of bad design - Trail of Bits Bloghttps://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/2026-09-21T11:00:00.000ZTrail of Bits Blog<p>Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoning single sign-on (SSO) industry fulfilled this need. However, SAML is being crushed under the weight of its own complexity. It’s time to deprecate it and move on to modern alternatives like OpenID Connect (OIDC). In this post, I will explore the design-by-committee origin of SAML, its progression through the ranks in academic and corporate environments, its slow disintegration at the hands of the security research community, and its (hopeful) deprecation in favor of newer protocols.</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/saml-a-fractal-of-bad-design-image-1.svg"
alt="“SAML 101”"
loading="lazy"
decoding="async" />
<figcaption>SAML 101</figcaption>
</figure>
</p>
<blockquote>
<p>What’s insidious about SAML is that it really is mostly straightforward to understand, but it’s built on a foundation of sand, bone dust, and ash; it works … if you assume XML signature validation is reliable. But XML signature validation is deeply cursed, and is so complicated that most fielded SAML implementations are wrapping libxmlsec, a gnarly C codebase nobody reads.<br>
— <a href="https://news.ycombinator.com/item?id=37564758">Thomas Ptacek, 2023</a></p>
</blockquote>
<h2 id="saml-and-the-birth-of-the-sso-industry">SAML and the birth of the SSO industry</h2>
<p><a href="https://en.wikipedia.org/wiki/SAML">Wikipedia tells me</a> that “SAML is an XML-based markup language for security assertions.” It was created in 2002 by the Organization for the Advancement of Structured Information Standards (OASIS) Security Services Technical Committee (SSTC). Okay, we’re not off to a great start by modern standards. XML, despite having some redeeming qualities, is quite complex compared to newer alternatives like JSON, but we’ll get more into that later. Further, a committee of subcommittees having meetings is a recipe for “kitchen-sink” protocol design (e.g., <a href="https://en.wikipedia.org/wiki/Waterfall_model">waterfall methodology</a>, <a href="https://en.wikipedia.org/wiki/Big_design_up_front">big design up front</a>, etc.). And sure enough, we’ve now jammed four (!) XML-based security protocols into one:</p>
<blockquote>
<p>… the following intellectual property was contributed to the SSTC:</p>
<ul>
<li>Security Services Markup Language (S2ML) from Netegrity</li>
<li>AuthXML from Securant</li>
<li>XML Trust Assertion Service Specification (X-TASS) from VeriSign</li>
<li>Information Technology Markup Language (ITML) from Jamcracker</li>
</ul>
<p>— <a href="https://en.wikipedia.org/wiki/SAML#History">SAML: History</a></p>
</blockquote>
<p>However, the desire for such a protocol was undeniable. As the internet shifted from Web 1.0 in the 90s to Web 2.0 in the early aughts, users and organizations needed an easy way to authenticate to many new web services. Academia was the biggest driver of this movement, although not the only one: Central Authentication Service (CAS) in 2002 at Yale, Shibboleth IdP in 2003 by Internet2, a consortium of research universities (<a href="https://its.umich.edu/enterprise/wifi-networks/researchers/internet2">including my alma mater</a>), ADFS in 2003 by Microsoft, and simpleSAMLphp <a href="https://web.archive.org/web/20071214140857/http://rnd.feide.no/simplesamlphp">around 2007</a> by Uninett, a state-owned Norwegian company with close ties to academia. All these authentication projects eventually supported SAML in one way or another. Like ARPANET before it, universities were at the forefront of internet development and were the earliest consumers of web services. Once this base layer of protocol availability and nascent academic proving ground was established, the commercial industry took it and ran toward a multibillion dollar industry.</p>
<p>The SSO, identity, and authentication provider industry was also starting up in the early aughts, but really came to fruition a few years later: Ping Identity (2002), OneLogin (2009), Okta (2009), and Duo Security (2010). These companies were essentially built on the SAML protocol with the exception of Duo, who would introduce their first SSO product in 2015, which is where I come into the story. I worked on Duo’s first <a href="https://duo.com/docs/dag">on-premises Access Gateway product</a> (DAG), which was built on simpleSAMLphp and, obviously, the SAML protocol. It’s where I became intimately familiar with the SAML protocol and spent many years of my life digesting its lengthy specifications. I was there when <a href="https://kel.bz/">Kelby Ludwig</a> found the <a href="https://i.blackhat.com/us-18/Thu-August-9/us-18-Ludwig-Identity-Theft-Attacks-On-SSO-Systems.pdf">XML comment bypass</a>, but we will get into various attacks and SAML deficiencies later. Suffice it to say, the SSO and authentication provider industry was booming, and much of it was built on the SAML protocol.</p>
<h2 id="a-crack-in-the-armor">A crack in the armor</h2>
<p>XML signature wrapping (XSW) attacks are the proverbial arrow to SAML’s heel. While there was earlier security research into both signature wrapping (<a href="https://dl.acm.org/doi/10.1145/1103022.1103026">2005</a>, <a href="https://arxiv.org/pdf/0812.4181">2008</a>, and <a href="https://lists.w3.org/Archives/Public/public-xmlsec/2009Nov/att-0019/Camera-Ready.pdf">2009</a>) and SAML (<a href="https://dl.acm.org/doi/10.1145/1456396.1456397">2008</a>), I consider the godfather of it all to be “On Breaking SAML: Be Whoever You Want to Be” (<a href="https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final91.pdf">2012</a>). It tested theory against practice and resulted in <a href="https://github.com/CompassSecurity/SAMLRaider/blob/v2.5.2/src/main/java/helpers/XSWHelpers.java#L34-L39">an automated way</a> to check for XSW attacks. This was our north star when implementing the DAG. It was the reason we chose simpleSAMLphp as our building block. PHP, <a href="https://eev.ee/blog/2012/04/09/php-a-fractal-of-bad-design/">especially at the time</a>, was not exactly known for its security track record, but simpleSAMLphp’s spoke for itself. simpleSAMLphp was resilient to XSW at a time when nobody really knew what that was:</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/saml-a-fractal-of-bad-design-image-2_hu_e836bff9fc613f68.webp"
alt="simpleSAMLphp’s security track record (credit: On Breaking SAML)"
width="1070"
height="902"
loading="lazy"
decoding="async" />
<figcaption>simpleSAMLphp’s security track record (credit: On Breaking SAML)</figcaption>
</figure>
</p>
<p>Despite being front and center in this 2012 paper, XSW is <a href="https://portswigger.net/research/the-fragile-lock">still present today</a>. If we know the bug class, then why can’t we fix it? But before we get into SAML’s flaws we first have to consider the shaky ground it was built upon: XML.</p>
<p>XML is no slouch when it comes to a (lack of) security track record. <a href="https://cheatsheetseries.owasp.org/cheatsheets/XML_Security_Cheat_Sheet.html">These bug classes</a> would have been more familiar to a developer in the 90s, but nonetheless are still present in XML today: XXE, entity expansion (“billion laughs”), DTD retrieval (SSRF), XPath/XQuery/XInclude/XSLT/CDATA injection, and more. A SAML library needs to handle all these bug classes before even getting to the actual SAML functionality.</p>
<p>In addition to security bug classes, there’s also the sheer complexity of XML when compared against something like JSON. In XML you have tags, elements, attributes, comments, namespaces, markup versus content, schemas, CDATA, DOCTYPEs, and more. In JSON, you essentially have keys, values, objects, and lists. Complexity is generally at odds with security, and this is one reason I consider SAML to be a fractal of bad design.</p>
<h2 id="a-fractal-of-bad-design">A fractal of bad design</h2>
<p>SAML provides ample opportunity to learn about protocol design. In this section, I will cover five flaws that I consider to be fatal to the long-term viability of SAML as an authentication protocol. These flaws can also be used when designing new authentication protocols. That is, you can either sidestep the flaw, or take its inverse and attempt to bake that into the protocol.</p>
<h3 id="built-on-xml">Built on XML</h3>
<p>As mentioned above, SAML is built on XML, and XML is complex, but <a href="https://media1.giphy.com/media/v1.Y2lkPTc5MGI3NjExMXBhN2doeGV5eXBoamUwZDJ1M2owcW9ndDJvY2c3NnlkMzF4ZDBxbyZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw/Dvw2lJqlTuJmo/giphy.gif">it’s not the committee’s fault</a>. XML is what they had at the time, and it’s what people used. JSON was <a href="https://inkdroid.org/2012/04/30/lessons-of-json/">“discovered”</a> in 2001, but this was right around the time the SAML committee was meeting, and they’d be unlikely to design an authentication protocol around an experimental new format. Especially when it caters to JavaScript and you write a lot of Java.</p>
<p>One could design a quantitative complexity measurement for XML versus JSON or SAML versus JWT/OIDC (e.g., spec/RFC word count, spec/RFC <a href="https://datatracker.ietf.org/doc/html/rfc2119">normative</a> word count, etc.), but that would require a blog post or paper all to itself. In the interest of staying on topic, I will refrain from doing that here, and suffice to say that XML is significantly more complex than something like JSON.</p>
<h3 id="canonicalization">Canonicalization</h3>
<p><a href="https://www.w3.org/TR/xml-exc-c14n/">Canonicalization</a> (C14N) is what you do when you want to take the wild mess that is XML, compute a hash of it, and get consistent results. In other words, if the SP and IdP cannot agree on a consistent representation of the XML data, then the bytes won’t line up, the signatures won’t match, and your authentication fails. However, this is easier said than done.</p>
<p>Canonicalization bugs enabled Kelby’s XML comment bypass in 2018:</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/saml-a-fractal-of-bad-design-image-3_hu_e81fbafe87004bf7.webp"
alt="XML canonicalization (credit: Identity Theft)"
width="1200"
height="674"
loading="lazy"
decoding="async" />
<figcaption>XML canonicalization (credit: Identity Theft)</figcaption>
</figure>
</p>
<p>Canonicalization is often a precursor to parser differential and/or “round-trip” bugs, which are what most modern SAML attacks use:</p>
<ul>
<li><a href="https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/">Coordinated disclosure of XML round-trip vulnerabilities in Go’s standard library</a> (2020)</li>
<li><a href="https://mattermost.com/blog/securing-xml-implementations-across-the-web/">Securing XML implementations across the web</a> (2021)</li>
<li><a href="https://repzret.blogspot.com/2025/02/abusing-libxml2-quirks-to-bypass-saml.html">Abusing libxml2 quirks to bypass SAML authentication on GitHub Enterprise</a> (2025)</li>
<li><a href="https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/">Sign in as anyone: Bypassing SAML SSO authentication with parser differentials</a> (2025)</li>
<li><a href="https://portswigger.net/research/saml-roulette-the-hacker-always-wins">SAML roulette: the hacker always wins</a> (2025)</li>
<li><a href="https://portswigger.net/research/the-fragile-lock">The Fragile Lock: Novel Bypasses For SAML Authentication</a> (2025)</li>
</ul>
<h3 id="enveloped-signatures">Enveloped signatures</h3>
<p><a href="https://www.w3.org/TR/xmldsig-core1/#sec-EnvelopedSignature">Enveloped signature</a> concerns are a not-too-distant cousin of canonicalization. In short, if you’re trying to insert the signature into the data payload that you’re signing, you’re going to have a bad time. Let’s compare and contrast JWT and SAML in this way:</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/saml-a-fractal-of-bad-design-image-4_hu_87ec639176ed31aa.webp"
alt="JWT versus SAML signatures (credit: jwt.io and samltool.io)"
width="1200"
height="1840"
loading="lazy"
decoding="async" />
<figcaption>JWT versus SAML signatures (credit: jwt.io and samltool.io)</figcaption>
</figure>
</p>
<p>In the JWT example above, the blue signature is <em>detached</em> from the JSON payload and delimited in the JWT with a period (“.”). In the SAML example, the <code>Signature</code> element is inserted (“enveloped”) in the <code>Assertion</code> element. The problem here is that it is very difficult to get a byte-for-byte, canonically equivalent representation of the data when <em>you’re also modifying it!</em> Even more so when you have a complex format like XML and complex canonicalization rules.</p>
<h3 id="kitchen-sink-design">“Kitchen-sink” design</h3>
<p>This design deficiency essentially transposes to <a href="https://en.wikipedia.org/wiki/You_aren%27t_gonna_need_it">you aren’t gonna need it</a> (YAGNI). It’s not an entirely fair characterization because the portions of the SAML specification that are used in the real-world have changed over the past 20 years (sorry, <a href="https://docs.oasis-open.org/security/saml/v2.0/saml-bindings-2.0-os.pdf">SOAP and artifact binding</a>). However, the fact of the matter is that 99% of modern SAML implementations use a very similar data shape and subset of the specification. Any given SAML authentication you would encounter in the wild today probably avoids 90% of the specification. This adds significant complexity for largely unused features.</p>
<blockquote>
<p>If I was adding SAML support to something new, I’d consider beyond all the standard SAML checks also rejecting any message that doesn’t have the same shape as what Okta, Onelogin, Google, or Shib generates.<br>
— <a href="https://news.ycombinator.com/item?id=28080553">Thomas Ptacek, 2021</a></p>
</blockquote>
<h3 id="ossification">Ossification</h3>
<p>SAML was designed in a different era for a different time and has not received necessary updates. These concerns will generally be of practical implication rather than theoretical. What I mean by ossification can roughly be enumerated as the following:</p>
<ol>
<li><strong>OIDC <a href="https://datatracker.ietf.org/doc/html/rfc6749">assumes HTTP</a>, whereas SAML is transport independent.</strong> Sure, SAML HTTP bindings exist and are most commonly used, but they are not required. This affords SAML a certain degree of flexibility, but also means that flexibility must be well defined, must be implemented somewhere, and can contain bugs. SAML came about at a time when HTTP + TLS was not yet the dominant backbone of web service communication, and it has never reconciled with this modern landscape. HTTPS allows OIDC to punt encrypted, trusted communication to the transport layer.</li>
<li><strong>OIDC generally assumes a connected network topology, whereas SAML does not.</strong> The most common OIDC flow (authorization code) assumes the OpenID Provider (OP) and Relying Party (RP) can communicate directly (OIDC OP/RP == SAML IdP/SP). Sure, OIDC <a href="https://auth0.com/docs/get-started/authentication-and-authorization-flow/implicit-flow-with-form-post">implicit flow with form post</a> exists, but it is very uncommon to see today. Further, SAML has artifact binding for direct communication, but it is also very uncommon. The point is that if the OP and RP can communicate directly then that relieves pressure off of the authentication response payload to contain all the information necessary to make an authentication and authorization decision. This reduces payload size and complexity. The OIDC OP and RP can instead exchange information in a backchannel.</li>
<li><strong>OIDC grew organically over the years, whereas SAML was largely designed up front.</strong> OIDC encompasses dozens of specifications and RFCs that grew organically over many years. These documents were generally created to solve a specific need rather than trying to anticipate all future needs and building that up front. This is akin to agile methodology versus waterfall, as described in the first section. Consider the following non-exhaustive timeline:
<ol>
<li>OpenID Connect 1.0 specification published (2014)</li>
<li>JOSE stack finalized for JW{S,E,K,A,T} via RFC 7515-7519 (2015)</li>
<li>PKCE published via RFC 7636 (2015)</li>
<li>PKCE for mobile/native apps published via RFC 8252 (2017)</li>
<li>Device authorization grant for IoT devices published via RFC 8628 (2019)</li>
<li>Demonstrating proof of possession (DPoP) for MFA workflows published via RFC 9449 (2023)</li>
<li>PKCE for SPAs published via RFC 10017 (2026)</li>
</ol>
</li>
</ol>
<p>I find the historical circumstances interesting too. For example, SAML came of age in an era of VPNs and network segmentation, hence point (2) above. If the IdP or SP was behind a corporate firewall, and it couldn’t speak directly to the other end, then the whole rollout came to a halt and that vendor lost the sales deal. SAML needed to seamlessly account for this situation. Google’s <a href="https://research.google/pubs/beyondcorp-a-new-approach-to-enterprise-security/">BeyondCorp model</a> and zero-trust architecture flipped this notion on its head in 2014. Additionally, SAML failed to anticipate the mobile, SPA, and IoT revolutions, and had no answers when these technologies arrived on the scene in the late aughts. Even though SAML is still widely adopted in corporate environments, these macroscopic events helped start the long, slow decline of the protocol. Agility and loose coupling enable rapid adaptation in ever-changing IT environments.</p>
<h2 id="all-roads-lead-to-oidc">All roads lead to OIDC</h2>
<p>No protocol is perfect, but in terms of a solution all roads lead to OIDC. As far as I can tell, the only deployment scenario where SAML had an advantage was networks where the SP and IdP cannot communicate directly. OIDC’s implicit flow with form post provides all the same ingredients. This is actually one of the cleanest migration plans I’ve seen available in the industry.</p>
<p>So what can I do if I’m a <strong>service provider</strong> (i.e., SP) and I’d like to integrate into the SSO ecosystem without SAML? Just support OIDC. Abandon SAML. Apparently Fly.io and Tailscale are already doing it:</p>
<blockquote>
<p>We’ve managed to hold the line on OIDC so far. So has Tailscale. If Tailscale can hold the line, given who they’re selling to, I think most orgs can. Really, try to avoid doing SAML. Remember, as a vendor, you’re often competing with companies that don’t do real SSO integration at all.<br>
— <a href="https://news.ycombinator.com/item?id=41676041">Thomas Ptacek, 2024</a></p>
</blockquote>
<p>So what can I do if I’m an <strong>identity or authentication provider</strong> (i.e., IdP) and I’d like to move off of SAML? Well, depending on your customer count, this may be a long road indeed. But you know how you eat an elephant? One bite at a time. This is a well-worn path in the industry: develop a deprecation plan, communicate it to customers, stop onboarding new customers to SAML integrations, provide existing SAML customers with equivalent OIDC configurations, set a sunset date, and get to work.</p>
<p>SAML had a good 25 year run. It birthed the SSO industry, helped secure untold numbers of authentications, improved the UX of authenticating to dozens of web services, and created billions of dollars of economic impact. We should be thankful to the creators of the SAML protocol. It has provided us with a great case study in protocol design and evolution over a very dynamic period in the tech industry.</p>
<p>If you’d like to read more about historical analyses of security topics, then check out “<a href="https://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/">Marshal madness: A brief history of Ruby deserialization exploits</a>.”</p>
<p><a href="https://www.trailofbits.com/contact/">Contact us</a> if you’re interested in a protocol design audit or would like a review of your authentication system.</p>Do you use :visited on links? - Kev Quirkhttps://kevquirk.com/do-you-use-visited-on-links2026-09-21T09:27:00.000ZKev Quirk<p>I've always made the <code>:visited</code> attribute for hyperlinks look the same as links that haven't been visited, and it seems that it's the default behaviour across the web. I've never really given it much thought, until I actually used <code>:visited</code> in anger.</p>
<p>My feed reader of choice, <a href="https://miniflux.app" rel="noopener noreferrer">Miniflux</a> uses the <code>:visited</code> attribute properly, making visited links purple. When reading posts from the <em>hundreds</em> of blogs I follow via RSS, I find it really useful to see if I've already visited a link within a post.</p>
<p>So with that in mind, I've decided to change the CSS on this site slightly, and visited links are now purple. It's subtle, but obvious enough, I think:</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/do-you-use-visited-on-links/visited-links.webp" alt="visited-links" /></p>
<p>If you want to do something like this yourself, the CSS is very simple:</p>
<pre><code class="language-css">a {
color: #3995F7;
}
a:visited {
color: #8839F7;
}</code></pre>
<p>Do you use the <code>:visited</code> attribute on your blog? I feel like I don't see it used very often around the web.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Do%20you%20use%20%3Avisited%20on%20links%3F">reply to this post by email</a>, or <a href="https://kevquirk.com/do-you-use-visited-on-links#comments">leave a comment</a>.</p>
</div>Of Day - James' Coffee Bloghttps://jamesg.blog/2026/09/21/of-day2026-09-21T00:00:00.000ZJames' Coffee Blog
<p><em>I stand at the bookshelves — art and Nature and biography and memoir — and ask myself what story I want to tell. What do I want to write?</em></p>
<p>What I do know is I want to write something. And so I begin.</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>My adventure began with zines. I packed four zines to read: three pocket-sized that had been kindly sent by a friend, and one folded, A3-sized zine that I had purchased at the weekend. The reading material got me through the wee hours of the morning, food for thought after breakfast, and left me with a list of more zines to search through. The zines took me to Edinburgh and Canada – one place I know well, a source of perpetual joy and curiosity and adventure; the other I have never visited, but would love to one day. In a sense, I visited Canada a little bit through the words of an author this morning. Therein, the power of writing – of storytelling.</p>
<p>Should I write more zines? What if I started printing a few of my blog posts and sending them to friends? Should I write more that I exclusively publish as a zine?</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>This weekend I purchased a copy of the Edinburgh Bookshop Map, published by Typewronger. The map, printed with a risograph machine using red and black ink and whose cover is typeset in a Gothic font, became my map of today. <em>I should try and go to as many of the included bookshops as possible.</em> Last night I set out five shops I could visit that were on the way to an errand I had to run. Today, I began – or, rather, continued, for I have already visited ten shops on the map – my adventure.</p>
<p>I knew today I would be walking far, but I didn’t realise how far I would be walking. I spent most of the morning on foot, weaving between bookshops, running an errand, and drinking a delicious coffee that reminded me of pear and blackcurrant and caramel – the coffee was fuel for the moment, the bookshops were fuel for the morning. I ended up visiting three: an Oxfam charity shop that specialises in books, with a wonderful antiquarian selection, Rare Birds, which specialises in books by female authors, and Golden Hare, which had an eclectic mix and had me standing still at the Nature and memoir and art section for a few minutes, and where I found myself writing the opening sentence to this blog post. <em>What do I want to write?</em></p>
<p>Where would my writing fit? Memoir? Nature?</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>In the park later in the day a lady’s jeans stood out. They were sky blue with polka dots that looked like stars in the moment before nightfall. Around me, the blue sky and the warm sunshine and the brilliant beginnings of red leaves marked the essence of the day. A cool morning became a warm afternoon – summer is slowly becoming autumn. In front of where I stood, watching the world go by in the heart of the city – and in one of my favourite parks – there was some graffiti written in red, blue, and yellow chalk. The lettering was mostly illegible but the impression of the strokes made me think of the word “bliss.” Here, the bliss of Day.</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>I wandered to the art gallery, where I was welcomed with words both perplexing and wonderful. I held the door open that connected the antechamber to the main galleries. A lady asked “Say, where do you keep the artist’s chairs?”. Her accent was brilliantly English. I stumble for a moment. “Oh, I don’t work here.” I continued to hold the door open for a few more people, before someone said I could go first and walk in. In school, my best friend and I used to love holding doors open for people. I haven’t thought about that in the longest time.</p>
<p>I was fascinated by a painting near the entranceway. I have looked at the painting closely before, but today I saw new symbols – the connection between the colour red and the subject matter, the flow of clothing, the foregrounding of Nature relative to the city in the background. Walking around further, exploring more paintings, I found myself looking up in awe, admiring a personification of poetry, and thinking about how, here, I can wander from world to world, from time to time. In Ruisdael’s Banks of a River, the tall trees reach for the sky in our imaginations. In another room, architecture and Nature and history exist side-by-side, in separate canvases that are connected together through curation, through place.</p>
<p>I was tired from all my walking in the morning, so I didn’t explore the gallery space too much. But, I did make sure to visit my favourite painting on display in the space: the Turner. I again saw something new today. I saw the silver and sky blue air of Nature. I found a new connection to the water. I thought about why I love Impressionist art and Turner’s art so much. I love the colours. I love the energy. I appreciate the subject matters. I enjoy how my imagination is engaged when I see a colourful work whose contours are a blurry invitation to dream.</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>The map gave me direction for the day. I visited three bookshops on my list <sup class="footnote-reference" id="f-1"><a href="https://jamesg.blog/longform-feed#1">1</a></sup> and spent my day with stories both written and visual, as well as the stories that were happening all around me. My wanderings took me from words to art, and then to music, when I heard someone play Mamma Mia on a public piano to which one passer-by was singing along. Reflecting on the music I heard played, I think about hope. Just as the sun shines through the ever changing clouds and the wind breathes life into Day, so too can we bring joy with words and art and music – with stories, with our melodies.</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>When I got home, sitting at the foot of my letterbox there a letter from a friend. They had sent me a zine from one of the series mentioned in a zine I read earlier today. Sometimes the world can be wonderful.</p>
<div class="footnote-definition" id="1"><sup class="footnote-definition-label" id="f-2">1</sup>
<p>One I also wanted to visit was closed, and another was a children’s bookstore, and I think I will skip them as part of my ambition to visit as many bookshops on the map as possible</p>
<a href="https://jamesg.blog/longform-feed#f-1">[↩]</a></div>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a3e9eecd8b88eab9',t:'MTc5MDAwMjc1Ng=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
<a class="tag" href="https://jamesg.blog/longform-feed#1">1</a>
<a class="tag" href="https://jamesg.blog/longform-feed#f-1">[↩]</a>
I forgot webrings exist - Joel's Log Fileshttps://joelchrono.xyz/blog/i-forgot-webrings-exist2026-09-20T19:25:58.000Zjoelchrono<p>I don’t usually check analytics on my website, but the hosting I use on Vercel does provide the ability to check referrals, and I have to admit, every once in a while I enjoy to see those!</p>
<p>It’s not because I am obsessed with people who visit my website (although I kind of am), or because I want to write according to what my readers view the most (although I sometimes do that too). I simply love to see when someone links to a post of mine for the first time, and I see their website on my referrals showing up. A lot of the time it’s only four or five clicks from X or Y small website.</p>
<p>Since I only get the referral, an investigation is sure to follow! I love to explore blogs, digital gardens, and personal websites in any form. Checking their blogrolls, reading through their guestbooks, skimming through posts to see where we may share interests or hobbies.</p>
<p>However, every once in a while I’d find a website that would have no mention of me whatsoever anywhere in the page, and I wasn’t sure how they ended up linking back to me, you know? I had to go even deeper. Maybe using things like <a href="/blog/using-freshrss-user-queries/">FreshRSS’s user queries</a>, websites like <a href="https://www.backlinkwatch.com/">Backlink Watch</a> or cool search engines like <a href="https://marginalia-search.com/site/joelchrono.xyz?view=links">Marginalia</a>, which has lots of neat information about sites on its index.</p>
<p>But no, even then I couldn’t see where some of those clicks were coming from, and I kind of left it there, it doesn’t matter that much after all. You see where this is going right?</p>
<hr />
<p>Last year I wrote a pretty extensive list of every <a href="/blog/webrings-clubs-and-blogrolls-im-part-of/">blogroll, webring and site that links to me</a>, but well, I always enjoy belonging to more of them, I guess.</p>
<p>Today I wanted to get setup on <a href="https://tk-web.quest/webring/">The Worst Webring</a>, and I edited my footer to add the corresponding URLs for Next, Previous and Random. Typical webring stuff.</p>
<p>I decided I would check if all the other webrings were still working (one of them, the previous link on Geekring, currently does not, by the way), so I clicked on all of the previous and next links, and that’s where it finally hit me.</p>
<p>The reason I was getting referrals from websites that didn’t have any links to me, <em>was because those websites were my neighbours in the webrings I’m on!</em></p>
<p>So any people clicking around the webrings and ending up visiting my website, come from my neighbors, who don’t really link to my site, but I happen to be the next/previous site on the ring for them!</p>
<p>I didn’t forget webrings exist, I simply forgot how they work, by helping people build connections!</p>
<p>So, that kind of puts me in an awkward position, how come I have never checked up on my neighbors before?</p>
<p>Umm, hi :3</p>
<p>This is day 40 of <a href="https://100daystooffload.com">#100DaysToOffload</a></p>
<p>
<a href="mailto:me@joelchrono.xyz?subject=I forgot webrings exist">Reply to this post via email</a> |
<a href="https://fosstodon.org/@joel/117305120897172042">Reply on Fediverse</a>
</p>Book Review: How to Build a Space Station by Jonathan Morrison ★★★⯪☆ - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=756532026-09-20T11:34:30.000ZTerence Eden’s Blog<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/how-to-build-a-space-station.webp" alt="Book cover featuring astronauts on Mars looking at a habitat." width="256" height="384" class="alignleft">
<p>This book, by The Times' former Architecture Correspondent, stands in direct opposition to <a href="https://shkspr.mobi/blog/2026/07/book-review-a-city-on-mars-by-dr-kelly-weinersmith-and-zach-weinersmith/">A City on Mars</a>. Whereas that book presented a (perhaps too) sceptical look at the realities of living on other planets, Jonathan Morrison's book goes (perhaps too far) in the opposite direction.</p>
<p>How to Build a Space Station is a beautiful examination of just how important architecture will be to our colonisation of other worlds. Not just in terms of physical safety - but psychological safety as well. It is a direct and forceful rebuttal to those who say it cannot be done.</p>
<p>It is, in my opinion, just a touch too credulous about some of the ludicrous claims from the hype merchants. I want to believe that Martian igloos can be conjured out of the ice and that Musk's rockets will deliver a steady stream of supplies to distant worlds. But the evidence presented is rather thin. The book works best when it focuses on what architecture can bring to the table when it comes to designing the future.</p>
<blockquote><p>In short, a spacecraft is not just a machine; it is also a home, an office, a refuge. If people are asked to go to the most remote environments, to live in spaces scarcely larger than a few rooms, and to perform work of immense complexity and risk, then comfort, efficiency and ergonomics are not just luxuries.</p></blockquote>
<p>Space has to be <em>worth</em> living in. Putting people into a tin-can with no windows, blank walls, and an infernal background hum will drive them mad. All this is backed up with extensive descriptions of the engineering challenges of polar research bases, spaceports, and previous craft.</p>
<p>Despite being rightly scathing about Wernher von Braun's involvement in atrocities and his eventual political rehabilitation - he is somewhat more muted in his criticism of Messrs Musk & Bezos. There's a <em>lot</em> of praise for celebrity architects and designers - without any real examination of whether their designs are practical rather than just award fodder.</p>
<p>Similarly, the book takes on trust that autonomous robots <em>can</em> ingest extraterrestrial soil, process it, and 3D print structures from it all while in a hostile environment. The fact that we don't have swarms of drones prefabbing houses in the relatively benign atmosphere of our planet should be evidence that maybe these claims aren't quite matched with reality.</p>
<p>Finally, the "why?" question. A City on Mars points out that the cost of mining gold from asteroids would be more profitably spent improving mining technology here on Earth. How to Build a Space Station takes a different approach; it'll improve things here:</p>
<blockquote><p>Space architecture is not just escapism, a thrilling sci-fi fantasy – it is a forge for creating the tools we need at home. These include but are not limited to circular systems, low-energy fabrication, modular construction and buildings that take psychology seriously.</p></blockquote>
<p>I have a lot of sympathy for that. Except… the Internation Space Station has shown us how to endlessly recycle water relatively cheaply. Yet every modern building on Earth pays only lip-service to reusing grey-water. 3D printing is amazing, but the number of structures built using autonomous robots extruding concrete is approximately zero.</p>
<p>We have the technology - but we don't seem to be interested in using it.</p>
<p>The book is mostly well illustrated - with some gorgeous drawings of actual craft and possible future inventions. Sadly no photos, maps, or anything to help illuminate some of the other challenges faced by living and working in space.</p>
<p>This book is endlessly fascinating and bang up to date, with lots of talk of events that happened in 2025. The way it brings together the sciences of engineering and psychology is marvellous. But, as much as I'd like to believe in a Martian habitat built by robot trebuchets flinging microwave sintered tetrapods into each other, I just don't find it convincing.</p>
<p>I <em>really</em> hope I'm wrong.</p>
<p>Many thanks to Netgalley for the review copy - the book is available to buy now.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=75653&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">Headless Plexamp Receiver - Hey, it's Jason!https://grepjason.sh/2026/headless-plexamp-receiver2026-09-20T00:00:00.000ZHey, it's Jason!Let's put together a small headless Plexamp audio destination device!2026-09-19 22:28: Watched Forrest Gump for the first time in 20 odd years this evening. Watching it... - Kev Quirkhttps://kevquirk.com/2026-09-19-22282026-09-19T21:28:00.000ZKev Quirk<p>Watched Forrest Gump for the first time in 20 odd years this evening. Watching it again with an adult brain...Jenny is a real bitch!</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-19%2022%3A28">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-19-2228#comments">leave a comment</a>.</p>
</div>Note published on September 19, 2026 at 3:16 PM UTC - Molly White's activity feed6aaea75552b01ca28c3ff7502026-09-19T15:16:37.000ZMolly White<article><div class="entry h-entry hentry"><header></header><div class="content e-content"><p>sometimes you just have to admire the work ethic of some scammers. i can barely keep up with a couple text message chains but this guy had 60+ people convinced they were in a relationship</p><div class="media-wrapper"><a href="https://storage.mollywhite.net/micro/ee08fd13b117cfaed1e5_daejon-love.webp" data-fslightbox=95d0f139eeecdd26973a><img src="https://storage.mollywhite.net/micro/ee08fd13b117cfaed1e5_daejon-love.webp" alt="Potential victims of 49ers imposter Daejon Love now exceed 60 By Mike Florio Published September 18, 2026 10:39 PM Daejon Love’s scam worked incredibly well. Until it didn’t. Via Kalyn Kahler of ESPN, the FBI has identified 35 more potential victims of the fraud allegedly perpetrated by Love and Taylor Chan. The total number of possible victims now exceeds 60." /></a></div></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609191115"><time class="dt-published" datetime="2026-09-19T15:16:37+00:00" title="September 19, 2026 at 3:16 PM UTC">September 19, 2026 at 3:16 PM UTC</time>. </a></div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117298364390369940" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3mvuxvyvgzs2u" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags"></div></div></footer></div></article>Amelia the Chicken - Kev Quirkhttps://kevquirk.com/amelia-the-chicken2026-09-19T08:09:00.000ZKev Quirk<p>We lost our favourite chicken last night. I know, just a chicken, right? Big deal. It's not like we lost a pet.</p>
<p>But that's the thing, Amelia was more than <em>just a chicken</em>. She <em>was</em> a pet. She was very tame and would often come into the house to sit with one of us.</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/amelia-the-chicken/1000006903.webp" alt="Amelia in the kitchen" /></p>
<p>She would scratch around the kitchen while we were eating breakfast then quietly cluck at one of us to be picked up for cuddle.</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/amelia-the-chicken/1000006905.webp" alt="Me and Amelia in the kitchen" /></p>
<p>We named her after <a href="https://en.wikipedia.org/wiki/Amelia_Earhart" rel="noopener noreferrer">Amelia Earhart</a> because she was always the first of all our chickens to go exploring. Right from the moment we got our first 6 chickens, Amelia came up to us while the others hid. Often posing for photos.</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/amelia-the-chicken/1000011914.webp" alt="Amelia on day 1, posing for a photo" />
<em>Amelia on day 1, posing for a photo</em></p>
<p>It's very sad when you lose a pet, and although this won't hit us as hard as when we inevitably lose one of our dogs, it's still really sad. Both my wife and I have shed a few tears for Amelia this morning.</p>
<p>We'll miss you, girl. x</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/amelia-the-chicken/1000011915.webp" alt="the lovely Amelia" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Amelia%20the%20Chicken">reply to this post by email</a>, or <a href="https://kevquirk.com/amelia-the-chicken#comments">leave a comment</a>.</p>
</div>