Shellsharks Blogroll - BlogFlockhttps://blogflock.com/list/xJ8yq2026-09-26T22:25:08.000ZBlogFlockshellsharksFinished reading A Parade of Horribles - Molly White's activity feed6ab846440db40ecf5ef66bbd2026-09-26T22:25:08.000ZMolly White<article class="entry h-entry hentry"><header><div class="description">Finished reading: </div></header><div class="content e-content"><div class="book h-entry hentry"><a class="book-cover-link" href="https://www.mollywhite.net/reading/books?search=A%20Parade%20of%20Horribles"><img class="u-photo book-cover" src="https://m.media-amazon.com/images/S/compressed.photo.goodreads.com/books/1768406680i/228928465.jpg" alt="Cover image of A Parade of Horribles" style="max-width: 300px;"/></a><div class="book-details"><div class="top"><div class="series-info"><i>Dungeon Crawler Carl</i> series, book <span class="series-number">8</span>. </div><div class="title-and-byline"><div class="title"><i class="p-name">A Parade of Horribles</i> </div><div class="byline">by <span class="p-author h-card">Matt Dinniman</span>. </div></div><div class="book-info">Published <time class="dt-published published" datetime="2026">2026</time>. 704 pages. </div></div><div class="bottom"><div class="reading-info"><div class="reading-dates"> Started <time class="dt-accessed accessed" datetime="2026-08-27">August 27, 2026</time>; completed September 26, 2026. </div></div></div></div></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp">Posted: <time class="dt-published" datetime="2026-09-26T22:25:08+00:00" title="September 26, 2026 at 10:25 PM UTC">September 26, 2026 at 10:25 PM UTC</time>. </div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=fantasy" title="See all books tagged "fantasy"" rel="category tag">fantasy</a>, <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=humor" title="See all books tagged "humor"" rel="category tag">humor</a>, <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=litrpg" title="See all books tagged "litRPG"" rel="category tag">litRPG</a>. </div></div></footer></article>Become worthless (to tech companies) - Posts feedhttps://www.coryd.dev/posts/2026/become-worthless-to-tech-companies2026-09-26T18:25:00.000ZPosts feed<div class="e-content block-subcanvas"><p>Tech companies and their executives have, broadly, moved to align themselves with investors and adopted a posture of, often, disdain or outright hostility towards their users and employees. If tech companies don't value you, why provide value to them? If they back political positions hostile to your interests, why not return that hostility?</p>
<p>I'm not arguing for boycotts, I know that people are bound to different platforms for different, compelling reasons. What I am arguing for is that, given the opportunity, you try and reduce the value they can extract from you. That's very often your data, but it can also be a direct financial relationship.</p>
<hr/>
<p>Signing up for a service? Well, your birthday is January 1, 1970.</p>
<p>Your email address? Give them a throwaway or use a different alias for every service. Your name? Do they need it? Maybe it's James Smith. Or John Smith. Or Mary Smith. Or Patricia Smith. Phone number? 321 is a valid area code. Throw it and seven other digits in. Don't need the account long term? Delete it. Make all of your privacy settings as restrictive as possible. Turn off AI features. Opt out of everything that defaults to opt in.</p>
<p>Live in California? Request your personal data—you may not need it, but you do need them to waste their resources handling the request. Delete yourself from data brokers with the state's <a href="https://privacy.ca.gov/drop/">Delete Act platform</a>.</p>
<p><a href="https://www.coryd.dev/posts/2023/i-block-ads">Block their ads as best you can.</a> Your cookie preferences are "Reject All", always. It's their responsibility to improve their product(s), it's not your responsibility to provide them with personal information that they claim will help them do so. Install ad-blockers for your friends and family and teach them how to use them. Block at the network level—Pi-hole, AdGuard Home, NextDNS—pick one.</p>
<p><a href="https://www.coryd.dev/posts/2024/go-ahead-and-block-ai-web-crawlers">Block their crawlers as best you can.</a> Do you have to use or choose to use AI products? Why not use every single one of those tokens available to your subsidized subscription? Did your search engine build in a "free" AI product? Ask it as many useless questions as you'd like. Getting emails from AI agents? Why not chat with them and lead them on until they hit a billing wall? You can block their whole TLD when you get bored.</p>
<p>Cancel your streaming services. <a href="https://www.coryd.dev/posts/2024/buying-music">Buy music again.</a> Get a library card and check out Blu-rays and DVDs. Maybe you rip them, maybe you don't. Buy ebooks from any vendor that doesn't apply DRM.</p>
<p><a href="https://www.coryd.dev/posts/2025/alternatives-to-us-tech-platforms">Use tech platforms based outside of the US.</a> Self-hosting things? Use a provider outside of the US for that as well. Support indie developers. They're more responsive and charge a fair price for great software. Buy subscriptions on the company's website and don't let the app store get a cut.</p>
<p>Wait as long as you reasonably can between hardware upgrades. Run an open operating system (if you can—<a href="https://stopomarchy.org">and not one developed by a fascist</a>). Buy refurbished or used hardware. Repair what you can.</p>
<p>Do you have to use a big social platform? Click on all of the ads you see or click on some of them, but don't buy anything. Want it? Open your browser and buy it without the attribution from the app.</p>
<p>Subscribe to RSS feeds. Publish RSS feeds. Post on your site first and send links out to platforms.</p>
<p>See someone or a business using AI art or branding? Gently let them know that it looks like a caricature of a <em>Men's Health</em> cover. Did you get an AI agent when you called a business or open a chat? Ask them about programming questions or chat them up—get those vendor costs up—and then ask for the person you wanted to talk to in the first place. Tell that person that the chatbot sucks.</p>
<p>Is your healthcare provider taking notes using AI? Opt out of that and explain why.</p>
<p>Opt out of arbitration (many terms of service let you do it via email or a letter within 30 days of signing up).</p>
<p>Use virtual cards if you can. Cancel any subscriptions you can. If they give you a retention offer, take it and then cancel as soon as it expires.</p>
<p>Don't sign in with Google or Apple or Facebook. They get data out of it and lock you into their platform.</p>
<p>Don't do unpaid labor for platforms. Was this helpful? Don't bother answering that. Skip the survey, reject the review request and don't rate anything.</p>
<p>Use the website, not the app. There's less telemetry, fewer permissions and no push notifications.</p>
<hr/>
<p>Your worth to these companies is determined by what they can derive by exploiting you. Be as worthless as you can.</p>
</div>The Dungeon Anarchist's Cookbook - Kev Quirkhttps://kevquirk.com/the-dungeon-anarchists-cookbook2026-09-26T14:03:00.000ZKev Quirk<div class="book card"><h2>The Dungeon Anarchist's Cookbook</h2><p><b>Author:</b> Matt Dinniman<br><b>Genre:</b> Fantasy, Sci-fi<br><b>Released:</b> 2021<br><b>Rating:</b> <span class="star-rating"><span class="star-rating" aria-label="2/5 ★★☆☆☆">★★☆☆☆</span></span></p><p>Welcome to the Gun Show!</p>
<p>The top 10 list is populated. The sponsorship program is open. The difficulty is ramping up. The first three floors were nothing compared to what Carl and Donut now face.</p>
<p>The Iron Tangle. An impossibly complicated subway system built out of the world's subterranean railway systems, all combined and then tied together into a knot. Up is down. Down is up. Close is far. The cars are filled with monsters, the railway stations are less than safe, and the exit is always just a few stops away.</p>
<p>But there is hope. For the first time, the crawlers are all working together. The loot is better than ever. And the secret to unraveling it all may be hidden in the pages of a seemingly useless book.</p>
<p>Welcome, crawlers. Welcome to the fourth floor of the dungeon.</p><p><a class="button" target="_blank" href="https://www.goodreads.com/book/show/211721809-the-dungeon-anarchist-s-cookbook">Learn more on Goodreads ➡</a></p></div>
<hr>
<p>I was on the fence whether to give this 2 stars, or 3. The series continues to be really enjoyable, but Jesus this book was confusing. There's so many train lines, monsters, and nuance that I found it very difficult to keep up.</p>
<p>In the end I stopped trying and just enjoyed the story for what it was. I'm still not completely clear how they managed to complete this level, which is why I've ended up marking this down to 2 stars.</p>
<p>Hopefully book #4 will be more enjoyable, as this one was a bit of a grind.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=The%20Dungeon%20Anarchist%27s%20Cookbook">reply to this post by email</a>, or <a href="https://kevquirk.com/the-dungeon-anarchists-cookbook#comments">leave a comment</a>.</p>
</div>No errors, no warnings, no gods, no masters - HTML Purity is a Fetish - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=749602026-09-26T11:34:02.000ZTerence Eden’s Blog<p>"The problem with defending the purity of the HyperText Markup Language is that HTML is about as pure as a cribhouse whore. The standard doesn't just borrow concepts from better languages; on occasion, HTML has pursued other programming languages down alleyways to beat them unconscious and rifle their pockets for new syntax<sup id="fnref:soz"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:soz" class="footnote-ref" title="With the appropriate amount of apologies to James Nicoll" role="doc-noteref">0</a></sup>."</p>
<!--
👋👋👋👋👋👋👋👋👋
Welcome to Comment Club! This content is only available to people who read my HTML comments.
Am I being too harsh in calling technical purity a fetish? I don't think so. But I guess I would say that wouldn't I? My Kink *Is* My Kink And That's OK.
Don't forget, the three rules of comment club are…
1. You must not tell anyone about Comment Club - let them find out about it themselves.
2. You *must* add some Comment Club Content to at least one of your blog posts. Doesn't have to be much, just a little note will do.
3. You should drop an email to anyone whose comments you've read. Start by sending me a friendly message at comment.club@shkspr.mobi
Keep your eyes peeled for more comments in future blog posts 😃
TTFN.
-->
<p>Englitch is an pretty goode langwidge. even you no grok all the pacific bits you got the jist & the splelling & grandma dont mattr to much.</p>
<p>HTML is much the same. You can write utterly malformed, derranged, non-standards complaint HTML and most browsers will just say "Yeah, sure, whatever dawg!" and render it adequately. Take a look at the source code for <a href="https://www.todepond.com/">TodePond</a> - a lovely website but some of the most abused HTML I've seen.</p>
<p>There's a brilliant blog post by Jens Oliver Meiert which looks at whether HTML validity is seen as a priority for major sites. Basically, no.</p>
<blockquote><p>It’s time for the annual analysis of how much of the HTML code in the field is error-free and valid. The short version: 1% of the most-frequented sites on this planet uses valid HTML—and 99% don’t.</p>
<p><a href="https://meiert.com/blog/html-conformance-2026/">2 of the Global Top 200 Websites Use Valid HTML</a></p></blockquote>
<p>iS ThAt A pRoBlEm????</p>
<p>My site is proudly HTML Valid. Run it through the <a href="https://validator.w3.org/nu/?doc=https%3A%2F%2Fshkspr.mobi%2Fblog%2F">HTML Validator</a> or the <a href="https://validator.schema.org/#url=https%3A%2F%2Fshkspr.mobi%2Fblog">Schema.org Validator</a> and you'll see that it is <em>fucking perfect!</em> Same with my <a href="https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fshkspr.mobi%2Fblog%2Ffeed">RSS Feed</a> and <a href="https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fshkspr.mobi%2Fblog%2Ffeed%2Fatom">Atom Feed</a>. Not so much as an advisory bit of info, a couched warning, or a sternly worded suggestion<sup id="fnref:4now"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:4now" class="footnote-ref" title="At the time of writing. Who knows what batshit bugs I'll accidentally include in the future 🙃" role="doc-noteref">1</a></sup>.</p>
<p>Every last bit pure and holy.</p>
<p>Of course, syntactically valid HTML is neither necessary nor sufficient for any purpose.</p>
<p>Perfect HTML doesn't imply that a site is accessible (although, I'm proud to say mine meets or exceeds all WCAG guidance<sup id="fnref:wcag"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:wcag" class="footnote-ref" title="Again, it is possible to make something pass automated testing while still being an accessibility mess." role="doc-noteref">2</a></sup>).</p>
<p>Perfect HTML doesn't guarantee that the information it contains is accurate<sup id="fnref:purrrrrfect"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:purrrrrfect" class="footnote-ref" title="Although, of course, everything you read in this site is 100% accurate." role="doc-noteref">3</a></sup>.</p>
<p>Perfect HTML, at best, merely <em>implies</em> that the author gives a damn about such things. Much like <a href="https://knolling.org/">Knolling</a>, it leaves a suggestion that order is preferable to chaos<sup id="fnref:knoll"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:knoll" class="footnote-ref" title="Or some horrifying psychological issue. Potato / Tomato." role="doc-noteref">4</a></sup>.</p>
<p>It is said that one of the reasons HTML succeeded is that it is lax about validation. Most programming languages will shit the bed if you dare to leave out so much as a single semicolon. The compiler wails can be heard throughout the land.</p>
<p>By contrast, HTML is designed to be sympathetic to the frailty of the human mind. "Oh, you didn't close an element? Well, you opened a new one which I guess implies the same thing. Did you forget the correct syntax? Never mind - it'll be our little secret."</p>
<p>That's why <a href="https://shkspr.mobi/blog/2025/12/the-web-runs-on-tolerance/">XHTML failed</a> - the browser would literally refuse to render a page if it didn't meet the spec. Who can be bothered with that?! HTML just lets you get on with things.</p>
<p>As I've mentioned before, <a href="https://shkspr.mobi/blog/2020/05/postels-law-also-applies-to-human-communication/">humans don't write or speak in Backus–Naur form</a>. Our ideas are loosely expressed in a floating grammar which lends itself to paradoxical impossibilities and logical tautologies. And yet most of us can still parse <a href="https://en.wikipedia.org/wiki/Garden-path_sentence">weird sentences</a> without too much effort.</p>
<p>But most computer languages are different. It might be obvious to you that <code>if (x = 42)</code> means "compare the value of x to 42" - but what the computer sees is "if assign x the value of 42". Within computing our code needs to be <em>rigorously formal</em> and any syntax errors will lead to show-stopping bugs.</p>
<p>Imagine if every time a human wrote <a href="https://en.wikipedia.org/wiki/Romani_ite_domum"><i lang="la">Romanes eunt domus</i></a> the world simply crashed. It would be intollerable.</p>
<p>HTML is more like a human language than a computing language. You can understand human speech over a crackly phone line in a foreign accent - Web Browsers understand CP-1252 encoded text with bizarre syntax errors.</p>
<p>If it is OK to write bad HTML, why do some of us fetishise "pure" HTML?</p>
<p>I think it comes down to an ingrained belief that it is polite to reduce ambiguity. It is nice to be precise<sup id="fnref:100"><a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fn:100" class="footnote-ref" title="I will grant you, there's also a strain of 100% Completionist which compels me to get "top score" on all the benchmarks. But that's just pure vanity." role="doc-noteref">5</a></sup>. It reduces the cognitive burden on anyone (or anything) which reads what we have written. We are holding up our end of the social contract by producing something unadulterated and easy to comprehend. It reduces the likelihood of different browsers rendering things differently but, almost on a cellular level, we <em>feel</em> that <strong>things must be done properly</strong>.</p>
<p>The browser doesn't care about your inability to follow standards. But you should have some fucking self-respect and do it anyway.</p>
<div id="footnotes" role="doc-endnotes">
<hr aria-label="Footnotes">
<ol start="0">
<li id="fn:soz">
<p>With the appropriate amount of apologies to <a href="https://en.wikiquote.org/wiki/James_Nicoll">James Nicoll</a> <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:soz" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li id="fn:4now">
<p>At the time of writing. Who knows what batshit bugs I'll accidentally include in the future 🙃 <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:4now" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li id="fn:wcag">
<p>Again, it is possible to make something <a href="https://www.matuzo.at/blog/building-the-most-inaccessible-site-possible-with-a-perfect-lighthouse-score/">pass automated testing while still being an accessibility mess</a>. <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:wcag" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li id="fn:purrrrrfect">
<p>Although, of course, everything you read in this site is 100% accurate. <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:purrrrrfect" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li id="fn:knoll">
<p>Or some horrifying psychological issue. Potato / Tomato. <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:knoll" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
<li id="fn:100">
<p>I will grant you, there's also a strain of <a href="https://tvtropes.org/pmwiki/pmwiki.php/Main/HundredPercentCompletion">100% Completionist</a> which compels me to get "top score" on all the benchmarks. But that's just pure vanity. <a href="https://shkspr.mobi/blog/2026/09/no-errors-no-warnings-no-gods-no-masters-html-purity-is-a-fetish/#fnref:100" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=74960&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">Autumn - James' Coffee Bloghttps://jamesg.blog/2026/09/26/autumn2026-09-26T00:00:00.000ZJames' Coffee Blog
<p><em>The sun danced with the clouds in a competition where both the clouds and the sun wins, for there is always light and cloud. The music was the melody of morning, a morning on which I saw the first frost lying on the quiet grass by the river, a few days after having seen the first cool evening fog. The seasons are changing.</em></p>
<p>My soundtrack this morning were songs as colourful as the autumn trees, music evoking memories, recognition, joy, and the necessity to dream – to move forward, to write the next word in the story. The sunlight painted the ever-changing fields, creating a morning of blue and grey and gold and silver, as if every colour were a track in the songs to which I was listening, and the songs to which I listen. Music and colour feel like a guide.</p>
<p>After breakfast and coffee, I set out on a walk, starting on a path with which I have grown increasingly familiar over the past few weeks, and then wandering a little bit, letting my feet take me where they wanted to go.</p>
<p>I ventured from the cold grasses and the tall parallel rows of trees bathed in an ebbing, cool, distant, golden glow, through the bustle of the city centre, to the quiet concrete streets where workmen are fashioning stairs and few people wander, seeing and hearing the many colours and paces of the city.</p>
<p>I think about the joy of having a direction, of having a map in my mind because I have walked on a path many times before. And I think about the joy of refining my map, knowing that while I have a general sense of direction, more practice will help me navigate the unfamiliar. I felt proud that I could take a detour and still get to where I wanted to go, consulting a map only at the last minute when, to my delight, my destination was just around the corner.</p>
<p style="text-align: center;">⁂ ⁂ ⁂</p>
<p>The more often I walk, the more comfortable I feel walking longer distances. The more often I walk and take some time to rest, the more stories I hear. Pausing in the park for a break, I heard someone sharing the story of the clock at the Balmoral Hotel, which runs a few minutes fast to help keep people on time. The Balmoral clock is only correct on New Year’s Eve, when it is intentionally set to the correct time so that the clock can ring in the new year with the rest of the city.</p>
<p><em>A colourful red and black butterfly soundlessly flutters through the autumn park that, on such a sunny day, still feels like it is holding onto summer.</em></p>
<p>The mid-days are warm, bookmarked by the cooler mornings and nights that signify the burgeoning season in which the sky and the trees take on new colours, and in which new stories are waiting to be written.</p>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a412d4021f05144a',t:'MTc5MDQzMTU3NQ=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
How I Develop Pure Commons Apps - Kev Quirkhttps://kevquirk.com/how-i-develop-pure-commons-apps2026-09-25T13:45:00.000ZKev Quirk<p>A couple<sup id="fnref1:1"><a href="https://kevquirk.com/how-i-develop-pure-commons-apps#fn:1" class="footnote-ref">1</a></sup> of people have asked what my process is for developing the various <a href="https://purecommons.org/apps" rel="noopener noreferrer">Pure Commons apps</a>. This comes after I've mentioned a couple of times that I've released <a href="https://fosstodon.org/@purecommons/117309487893150341" rel="noopener noreferrer">a feature I've been working on for months</a>.</p>
<p>So I thought I'd write a quick post that explains how I do it, so I can refer people to it if/when they ask in the future. I also find this kind of post interesting, so I'm hoping you do too. If not, feel free to skip this one. 🙃</p>
<h2>Using Git without branches</h2>
<p>Git is a staple in my development workflow, so you'd think I'd use it the same way most other developers do, but I don't. You see dear reader, I'm a visual learner, so branches in Git are confusing to me as they're abstracted away inside the <code>.git</code> folder. This means I often forget which branch I'm on. Which in turn has led to all kinds of issues over the years when it comes to committing shit to the wrong branch.</p>
<p>So instead I simply copy and paste the entire repo (less the <code>.git</code> folder) into a new subfolder and use that as a "branch". Then, when I want to work on a feature, I go into that subfolder and work away, knowing it's completely separate from the core production code. My "<em>branches</em>" look something like this:</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/how-i-develop-pure-commons-apps/branches-pureblog.webp" alt="Pure Blog branches" /></p>
<p>I always prefix my branch folders with <code>AA-BRANCH</code> so they're always at the start of my folder tree and easy to see. Switching branches is then just a simple <code>cd</code> away and I can easily see which one I'm in from the command prompt.</p>
<p>And since there's no <code>.git</code> folder in the branch, I can't accidentally mess things up by merging back to <code>main</code> (or any other branch) accidentally.</p>
<p>Almost <del>idiot</del> Kev proof!</p>
<h2>Creating branches with purectl</h2>
<p>I've created a local Python tool called <code>purectl</code><sup id="fnref1:2"><a href="https://kevquirk.com/how-i-develop-pure-commons-apps#fn:2" class="footnote-ref">2</a></sup> which manages all things <em>Pure</em>. With it, I can do things like pull or push to/from remote for this website, update if there's a new version released, create releases, run local tests, create branches etc.</p>
<p>So if I want to create a new branch, all I need to do is run:</p>
<pre><code class="language-bash">purectl branch pureblog</code></pre>
<p>It will then ask me for the branch name, so I enter something like <code>Pages in search</code> and it will automagically create a new folder called <code>AA-BRANCH Pages in search</code> and copy the latest version of Pure Blog into that folder, excluding <code>.git</code>.</p>
<h2>Merging changes</h2>
<p>This is where things get interesting. If I'm working on multiple branches at the same time, merging back can be...<em>interesting</em> as I can't use the <code>git merge</code> command, since I'm not using Git for branches.</p>
<p>But that's fine, I actually prefer it this way as I have more control. Merging back to <code>main</code> requires me to do a side-by-side comparison of any files I've changes on that branch, so I have to review <em>everything</em> before manually while merging in changes.</p>
<p>This is definitely not the most efficient way of developing software, but it works for me.</p>
<h2>Final thoughts</h2>
<p>So there you go, that's my approach to developing the Pure Commons apps. I think it's somewhat scalable for a single person project, such as <a href="https://purecommons.org" rel="noopener noreferrer">Pure Commons</a>. If I were working in a team this approach would fall apart quickly though. Lucky I have no friends, ey!</p>
<p>I'm not a professional software developer, and I think that's clear from the way I manage all this. But this system has been working well for me, and is far less abstract for my monkey brain than Git's native branch handling.</p>
<p>What can I say, I'm a Luddite. 🤷🏻♂️</p>
<div class="footnotes">
<hr />
<ol>
<li id="fn:1">
<p>Literally 2 people, but that's enough to warrant a post, right? <a href="https://kevquirk.com/how-i-develop-pure-commons-apps#fnref1:1" rev="footnote" class="footnote-backref">↩</a></p>
</li>
<li id="fn:2">
<p>Short for "Pure Control". <a href="https://kevquirk.com/how-i-develop-pure-commons-apps#fnref1:2" rev="footnote" class="footnote-backref">↩</a></p>
</li>
</ol>
</div> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=How%20I%20Develop%20Pure%20Commons%20Apps">reply to this post by email</a>, or <a href="https://kevquirk.com/how-i-develop-pure-commons-apps#comments">leave a comment</a>.</p>
</div>Don't let TEEs break your MPC - Trail of Bits Bloghttps://blog.trailofbits.com/2026/09/25/dont-let-tees-break-your-mpc/2026-09-25T11:00:00.000ZTrail of Bits Blog<p>Threshold signature schemes, a form of multi-party computation (MPC) that lets a set of parties sign together without any one of them holding the key, are increasingly deployed inside trusted execution environments (TEEs). The combination is intended to amplify security for sensitive computations: MPC distributes trust across multiple independent parties, while TEEs root trust in the hardware manufacturer and its attestation infrastructure. But subtle issues can arise when running an MPC protocol inside a TEE without accounting for the untrusted host: for example, a malicious host could roll back the filesystem state after a threshold signer deletes a used pre-signature, causing the signer to reuse their nonce share and disclose their private key share.</p>
<p>So is this combination worth it? Provided you treat the TEE as a defense-in-depth layer rather than a substitute for a sound protocol, the answer is yes. This blog post discusses what TEE attestation can and can’t fix in MPC deployments, explores the pitfalls we see most often in audits, and covers best practices, such as incorporating strong attestation processes and binding them to the MPC parties’ identities.</p>
<h2 id="mpc-security-that-depends-on-participant-behavior">MPC: Security that depends on participant behavior</h2>
<p>Before diving into how TEEs and MPC interact, we need to understand what MPC means and what security guarantees it offers. MPC is a cryptographic technique that allows multiple parties to jointly compute a function over their private inputs without revealing those inputs to each other.</p>
<p>The security of MPC protocols depends critically on assumptions about participant behavior. The cryptographic literature uses two primary security models:</p>
<p><strong>Semi-honest (honest-but-curious) security</strong>: In this model, all participants follow the protocol exactly as specified, but they may try to learn additional information from the messages they receive during the protocol execution. Participants can try to learn more than they should, but they don’t deviate from the protocol specification.</p>
<p><strong>Malicious security</strong>: This stronger model assumes participants may deviate arbitrarily from the protocol. A malicious participant might send incorrectly computed values, use wrong inputs, abort the protocol at strategic moments, and behave in ways designed to compromise security or learn private information.</p>
<p>This distinction is important in the context of TEEs. If a TEE attestation can cryptographically guarantee that all parties are running the correct protocol implementation, it effectively elevates semi-honest protocols to provide malicious security guarantees (at least against certain classes of attacks, as we’ll discuss later). But before delving into the details, let’s discuss how TEEs work.</p>
<h2 id="tees-three-core-security-guarantees">TEEs: Three core security guarantees</h2>
<p>TEEs are secure areas within a processor that provide hardware-based protection for code and data, even from privileged software like operating systems or hypervisors. TEEs offer three core security guarantees:</p>
<p><strong>Confidentiality</strong>: Data and code are encrypted in memory and accessible only from within the TEE. This ensures that even privileged system software cannot inspect the contents of the secure computation.</p>
<p><strong>Integrity</strong>: The data and code are protected from tampering. Any attempt to modify the TEE’s memory or execution state from outside should be detected.</p>
<p><strong>Attestation</strong>: Remote parties can cryptographically verify what code is running in the TEE. This allows external verifiers to gain assurance about the computation being performed and the legitimacy of the TEE without trusting the host system.</p>
<p>This last property is particularly crucial for building distributed systems with TEEs.</p>
<h3 id="how-tee-attestation-works">How TEE attestation works</h3>
<p>The attestation mechanism is at the heart of TEE security. When a TEE is manufactured, it’s provisioned with a private key and a corresponding certificate that chains back to a root certificate held by a trust anchor (typically the manufacturer).</p>
<p>When an attestation is requested, the TEE takes measurements (cryptographic hashes of the TEE software, configuration, and hardware state). These measurements are bundled into a “quote” (a manifest of these cryptographic hashes), which the TEE then signs with its private key.</p>
<p>To verify these attestations, a number of checks need to be performed. However, the checks necessary in the verification process aren’t uniformly defined and are somewhat vendor-specific. For instance, <a href="https://cc-enabling.trustedservices.intel.com/intel-tdx-enabling-guide/02/infrastructure_setup/#:~:text=TD%20Quote%20Verification%20is%20the%20process%20by%20which%20a%20TD%20Quote%20is%20verified%20in%20a%20remote%20attestation%20flow.%20This%20verification%20can%20be%20done%20by%20any%20party%20and%20the%20checks%20performed%20are%20defined%20by%20this%20party.">Intel’s TDX documentation</a> states:</p>
<blockquote>
<p>TD Quote Verification is the process by which a TD Quote is verified in a remote attestation flow. This verification can be done by any party and the checks performed are defined by this party.</p>
</blockquote>
<p>This places significant responsibility on developers, who might not fully understand what checks are required to ensure the security of the TEE deployment.</p>
<p>At a minimum, a proper verification process requires:</p>
<ol>
<li>Verifying the quote signature</li>
<li>Verifying the certificate chain back to the trusted root</li>
<li>Verifying the actual measurements against known-good values (often stored in binary transparency logs)</li>
</ol>
<p>This means deploying TEE-based systems involves not just cryptographic verification but also reproducible builds and binary transparency infrastructure. The measurements in the attestation quote are simply hashes; they don’t inherently indicate whether the code is correct or malicious. To verify that the TEE is running the intended software, what is required is a trusted source of reference measurements. Reproducible builds ensure that anyone can compile the same source code and arrive at identical binaries (and thus identical measurements). Binary transparency logs provide a tamper-evident record of what measurements correspond to what software versions, allowing verifiers to check that the TEE is running legitimate, audited code rather than a compromised variant. This piece is often overlooked in TEE deployments.</p>
<h2 id="the-trust-model-clash">The trust model clash</h2>
<p>Here’s where things get interesting. Multi-party computation is fundamentally about distributing trust among multiple participants. No single party should be able to compromise the computation. TEEs, in contrast, centralize trust in the hardware manufacturer that controls the root certificate.</p>
<p>Another important threat model shift to consider is the fundamental inversion of traditional security assumptions in TEEs. Historically, we trusted the host operating system and built our security models on that foundation. TEEs flip this on its head: they’re virtualized environments where the guest (the code running inside the TEE) is trusted, but the host system is explicitly considered untrusted and potentially malicious.</p>
<p>This shift creates new attack surfaces that didn’t exist in traditional computing models. While the TEE protects the guest environment from the host, the host still controls critical operations like I/O, memory management, and CPU scheduling. The host can deny service, manipulate timing, or attempt rollback attacks, leading to subtle breaks of MPC protocols.</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/09/25/dont-let-tees-break-your-mpc/tee-mpc-figure1_hu_dedf906638555a09.webp"
alt="“Figure showing decentralized vs. centralized trust model shift”"
width="1200"
height="553"
loading="lazy"
decoding="async" />
<figcaption>Figure 1: Decentralized vs. centralized trust model shift</figcaption>
</figure>
</p>
<h2 id="what-tees-can-and-cant-fix-in-mpc-deployments">What TEEs can (and can’t) fix in MPC deployments</h2>
<p>Combining these technologies can be beneficial, but one must be careful about the security claims that can be made. The security gains are real only if the TEE implementation is sound and the attestation process verifies the right properties. When TEEs attest to incomplete measurements or fail to verify critical components, the attestation provides false assurance. The actual security posture may even be weakened by the added complexity.</p>
<p>In an attempt to narrow down what TEEs can fix in MPC implementations, we’ve identified the common categories of MPC issues we frequently encounter in security audits:</p>
<ol>
<li>Ambiguous encoding in hash functions (e.g., <a href="https://blog.trailofbits.com/2024/08/21/yolo-is-not-a-valid-hash-construction/">“YOLO” is not a valid hash construction</a>)</li>
<li>Misbehaving participants</li>
<li>Missing parameters in Fiat-Shamir transforms (e.g., <a href="https://blog.trailofbits.com/2022/04/13/part-1-coordinated-disclosure-of-vulnerabilities-affecting-girault-bulletproofs-and-plonk/">Coordinated disclosure of vulnerabilities affecting Girault, Bulletproofs, and PlonK</a>)</li>
<li>Missing input validation (e.g., <a href="https://blog.trailofbits.com/2024/02/20/breaking-the-shared-key-in-threshold-signature-schemes/">Breaking the shared key in threshold signature schemes</a>)</li>
<li>Side-channel attacks</li>
<li>Protocol-level issues (e.g., <a href="https://blog.trailofbits.com/2024/09/13/friends-dont-let-friends-reuse-nonces/">Friends don’t let friends reuse IVs</a>)</li>
</ol>
<p>Arguably, if TEEs were perfectly secure, they could effectively mitigate the first four categories. When attestation and measurement processes are correctly implemented, each party gains cryptographic assurance about what code the other parties are running. This is powerful: if a party can verify that all other participants are running the exact protocol implementation expected (with no modifications or protocol deviations), then they know other participants will follow the protocol correctly and won’t misbehave by sending malformed messages. Essentially, correct attestation eliminates entire classes of implementation vulnerabilities by ensuring protocol compliance on both the sender and receiver sides. However, perfect security doesn’t exist in practice. Real-world TEE implementations have vulnerabilities, attestation processes can be incomplete or incorrectly verified, and the adversarial host environment introduces attack surfaces that are not traditional to MPC deployments.</p>
<h2 id="a-cautionary-tale-rollback-attacks-with-threshold-signatures-in-tees">A cautionary tale: Rollback attacks with threshold signatures in TEEs</h2>
<p>Consider threshold signature schemes, which often use pre-signature optimizations. In Schnorr or ECDSA threshold signatures, participants can precompute nonce commitments independently of the message, speeding up the online signing phase. These precomputed nonce commitments are called pre-signatures, and the reuse of a pre-signature value by a participant leads to the leak of their private share (akin to how nonce reuse in traditional Schnorr and ECDSA signatures <a href="https://blog.trailofbits.com/2020/06/11/ecdsa-handle-with-care/">leads to private key recovery</a>).</p>
<p>It might be tempting to run such an MPC protocol inside a TEE enclave to mitigate these types of attacks. But subtle issues can arise. In some implementations, signers store pre-signatures to disk and delete them after use (to limit the possibility of reuse). If that application were deployed to a TEE in a trust model where the host is potentially malicious, the host could roll back the filesystem state after the signer deletes a pre-signature file. When the TEE later fetches the pre-signature contained in that file, the signer essentially reuses their nonce share, which leads to a disclosure of the private key share. This is also discussed in the blog post <a href="https://blog.trailofbits.com/2023/12/18/a-trail-of-flipping-bits/">A trail of flipping bits</a>.</p>
<h2 id="common-tee-pitfalls">Common TEE pitfalls</h2>
<p>Beyond the rollback issue, several other pitfalls frequently appear:</p>
<p><strong>Incomplete attestation measurements</strong>: The security of TEE attestation hinges on measuring the right things. An attestation quote contains hashes of code and data, but project developers determine what gets measured and what gets excluded. If critical components aren’t included in the measurements, an attacker can modify those components without detection. This is particularly risky because the attestation appears cryptographically valid, but it’s attesting to an incomplete picture of the execution environment. For example, installing tools in an enclave from remote sources at runtime (e.g., using <code>curl</code>) pulls in code that was never measured; an attacker gaining access to that source can substitute their own and gain code execution inside the enclave.</p>
<p>A real-world example demonstrates this risk: a vulnerability in <a href="https://blog.trailofbits.com/2026/04/07/what-we-learned-about-tee-security-from-auditing-whatsapps-private-inference/">Meta’s WhatsApp Private Inference</a> revealed that the attestation process didn’t include certain configuration files, enabling an attacker to inject malicious shared libraries with the <code>LD_PRELOAD</code> environment variable, potentially compromising the TEE while maintaining a valid attestation quote.</p>
<p><strong>Missing verifications</strong>: The attestation process requires multiple verification steps, each critical to the security guarantee. Verifiers must check the quote signature, validate the certificate chain back to the manufacturer’s root certificate, confirm that the measurements match expected values, etc. Skipping any of these steps breaks the security model. Because verification procedures vary across TEE vendors and aren’t always well-documented, implementations sometimes omit crucial checks.</p>
<p><strong>Lack of hardening:</strong> A TEE protects whatever runs inside it, including components that may not be needed. Redundant kernel drivers, overly permissive kernel config flags, stray ACPI table entries, unnecessary systemd services and timers, and weak entropy sources all increase the attack surface inside the trust boundary. Trim the image down to what the project requires, harden what remains, and measure it. For platform-specific guidance, see our <a href="https://blog.trailofbits.com/2024/09/24/notes-on-aws-nitro-enclaves-attack-surface/">notes on the AWS Nitro Enclaves attack surface</a>.</p>
<p><strong>Data availability and backups:</strong> Enclaves have limited persistent storage, so backups and recovery data typically live outside the trust boundary. Authenticated encryption provides confidentiality and integrity but not freshness, so a malicious host can serve a stale backup to force a rollback, as discussed earlier in our threshold signature example. More concretely, one recurring failure is a guest trusting attacker-controlled metadata that lives on disk: the disclosure of several <a href="https://blog.trailofbits.com/2025/10/30/vulnerabilities-in-luks2-disk-encryption-for-confidential-vms/">vulnerabilities in LUKS2 disk encryption for confidential VMs</a> shows that a malleable, unvalidated LUKS2 header lets an attacker with disk write access swap in a null cipher, leaving the guest reading and writing secrets on an effectively unencrypted volume.</p>
<p><strong>Side-channel and physical attacks</strong>: Because the untrusted host controls the TEE’s execution environment, it can perform various side-channel attacks to extract information about the guest’s computation. These can leak sensitive information and break a TEE’s confidentiality guarantees. Similarly, researchers regularly publish physical attacks on TEE hardware. For example, the recent <a href="https://tee.fail/">“TEE fail” attack</a> allows an attacker to break the security guarantees of Intel TDX and AMD SEV-SNP by using a memory interposition device that lets them physically inspect all memory traffic inside a DDR5 server. The more recent <a href="https://ddropattack.eu/">DDRop attack</a> goes even further: an interposer costing under $200 silently drops DDR5 writes, so the processor keeps reading stale data that still decrypts correctly, breaking the integrity of Intel TDX, Scalable SGX, and AMD SEV-SNP. Memory encryption without freshness fails the same way disk state does in the rollback example above.</p>
<p><strong>Centralization risks</strong>: When MPC aims to distribute trust but TEEs centralize it in the manufacturer and its attestation infrastructure, the security goals of the protocol may be undermined. If all parties in an MPC protocol run their TEE nodes on the same TEE vendor’s hardware or if they use the same cloud provider, trust becomes centralized in that provider (for example, by way of the attestation chaining back to that vendor-operated root of trust).</p>
<p><strong>Insecure defaults</strong>: Be aware of some of the limitations that vendor-provided verification tools have. For example, Intel tools allow known-vulnerable firmware versions to pass the remote attestation process <a href="https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/best-practices/trusted-computing-base-recovery.html#:~:text=Update%20%3D%20%E2%80%9Cstandard%E2%80%9D%3A,R%20counter%20values.">for one year after public disclosure</a>. Users might want to implement their own security version number validation on top of the defaults to enforce stricter deadlines.</p>
<h2 id="best-practices-for-combining-tees-and-mpc">Best practices for combining TEEs and MPC</h2>
<p>If you’re building systems that combine these technologies, consider these recommendations:</p>
<p><strong>Implement strong attestation processes</strong>: Bind attestations to the identities of MPC parties and verify them comprehensively. This means not just checking that an attestation is valid but also confirming that the specific party you expect to be running the code is actually the one presenting the attestation.</p>
<p><strong>Terminate peer-to-peer communications inside TEEs</strong>: This provides end-to-end protection for party communications. By establishing TLS or other encrypted channels directly between TEEs (with endpoints inside the secure enclaves), you prevent the untrusted host from observing or tampering with protocol messages.</p>
<p><strong>Perform comprehensive verification of the attestation and measurements</strong>: Refer to your specific TEE vendor’s documentation for the necessary checks to be performed, and ensure every verification step is implemented correctly, tested, and reviewed.</p>
<p><strong>Write constant-time code</strong>: This helps prevent timing side-channel attacks. Even within a TEE, timing variations in your cryptographic operations can leak information to a host performing careful measurements. Use constant-time implementations for all security-critical operations processing secrets.</p>
<p><strong>Consult vendor-specific guidance</strong>: Each TEE platform has unique characteristics, limitations, and recommended practices. Vendor documentation often includes details about platform-specific threats. Stay current with security advisories and updates, as TEE security is an active research area with new vulnerabilities regularly discovered. Follow best practices documentation, like <a href="https://blog.trailofbits.com/2024/02/16/a-few-notes-on-aws-nitro-enclaves-images-and-attestation/">our guidance for AWS Nitro Enclaves</a>.</p>
<p><strong>Use multiple TEE vendors</strong>: For defense in depth, consider running MPC protocols on TEEs from different manufacturers (and/or cloud providers) to avoid centralizing trust in a single vendor. While admittedly challenging in practice since it requires additional operational complexity, this diversity can be essential for high-security applications where trust distribution is critical.</p>
<h2 id="layered-trust-beats-either-layer-alone">Layered trust beats either layer alone</h2>
<p>Combining MPC and TEEs is not automatic security, but when done correctly, it represents a defense-in-depth strategy that’s stronger than either technology alone. TEEs can effectively mitigate several categories of MPC vulnerabilities by cryptographically guaranteeing correct protocol execution. Meanwhile, MPC’s distributed trust model reduces the impact of TEE manufacturer centralization and may provide security even if individual TEE instances are compromised.</p>
<p>However, this benefit only materializes when both layers are correctly implemented. New vulnerabilities can emerge from their interaction, as we saw with the rollback attack example. Successful deployment requires following established best practices, implementing thorough attestation verification, and carefully reviewing the implementation and deployment procedure.</p>
<p>The intersection of these technologies represents the cutting edge of secure computation, but only if we approach it with a clear understanding of the tradeoffs involved. If you’re deploying MPC on TEEs, our cryptography team reviews these exact systems, so <a href="https://trailofbits.com/contact/">get in touch</a>!</p>When a blogpost eats another - Joel's Log Fileshttps://joelchrono.xyz/blog/when-a-blogpost-eats-another2026-09-25T02:42:07.000Zjoelchrono<p>I was halfway through writing a pretty interesting blogpost today. Some thoughts about all the science fiction films I’ve watched this year! It’s seriously so much I realized I should probably save it for the end of the year.</p>
<p>Why you ask? Well, because I can literally make a recap of only sci-fi movies, and a recap of other movies if I want to, and all I have to do is wait for the end of the year.</p>
<p>I’ll definitely save the writing I already did, and probably use some of it for this month’s recap as well.</p>
<p>(If you’re curious about it, this month I have watched <em>The War of the Worlds</em>—awesome and terrifying—, <em>Mercy</em>—pretty meh—, <em>The Day The Earth Stood Still</em>—absolute masterpiece—, and I’m halfway through <em>Minority Report</em>—which is looking great.)</p>
<p>(As another aside, let me know if what I just did with those commas and em dashes is stylistically correct or whatever, I thought it looked kinda neat and I have read a couple books that have used that weird em-dash+comma thing. If you have to know, yes, I am stealing the whole paragraph inside a parenthesis idea from the Murderbot novels. Also is the last dot supposed to go inside or outside the parenthesis? I don’t wanna skim through the novel to check.)</p>
<p>In any case, I think this thing where you start writing something only to realize it should probably be something bigger (or maybe smaller, sometimes) can happen in plenty of situations, and I wonder how much does it take for some people to realize this! The treshold is different for everyone I guess.</p>
<p>For example, I have plenty of posts on a series titled <em>“What Interested Me Today”</em>—which is yet to have an actual category or special index for it—and I’ve thought about stealing some other formats from some fellow bloggers, when my weeknotes aren’t enough and I simply have short thoughts to say.</p>
<p>Perhaps a quick and random list of thoughts is fun, like what Loura did <a href="https://heyloura.com/2026/09/24/random-thoughts-as-i-wait.html">just now</a> as I was writing this post. Or like Steve’s <a href="https://lwgrs.bearblog.dev/blog/?q=thoughts">thoughts of the day</a>, which is a fantastic little series that I always peek through to see what’s up with the guy.</p>
<p>But well, maybe I should just write my thoughts on those sci-fi films already, gushing about movies is something I rarely do, after all.</p>
<p>For now, you’ll have to settle with a ramble, bye!</p>
<p>This is day 42 of <a href="https://100daystooffload.com">#100DaysToOffload</a></p>
<p>
<a href="mailto:me@joelchrono.xyz?subject=When a blogpost eats another">Reply to this post via email</a> |
<a href="https://fosstodon.org/@joel/117329541111835006">Reply on Fediverse</a>
</p>New music morning - James' Coffee Bloghttps://jamesg.blog/2026/09/25/new-music-morning2026-09-25T00:00:00.000ZJames' Coffee Blog
<p>7:00. Wake up. I recall. <em>Taylor Swift’s new music is out today.</em> I proceed to listen to all four new songs while still in bed, looking up to the ceiling and the sky and toward my cool, warm pillow, eager to do nothing else but appreciate the music.</p>
<p>I am sure there will be more to analyse in the songs in the coming hours and days when I have listened to – and read about them – more, but what mattered most to me this morning was spending time with the music. I listened to the new songs once, then got up and made breakfast, listening again while I did. Each song – Patient Zero, Cleveland!, Pink Clouding, and Babylon – is terrific. I have listened to them many more times since.</p>
<p>The opening notes of Patient Zero make me think vaguely that I am somewhere out in the Scottish countryside, about to hear country music, until the first notes come in and the song becomes something new. Cleveland! makes me want to dance. Pink Clouding makes me wonder. <em>What does that mean?</em> The magenta sunrise.</p>
<p>And then there’s Babylon, in which there is one lyric that reminds me of one of the attributes of Swift’s music I appreciate most: her lyricism. On a months-long journey reflecting on what home means to me – one defined by writing and conversations and spending time in different anchors of home – the lyrics “The self-harm of never being where you are.” stood out, coming days after I wrote “<a href="https://jamesg.blog/2026/09/22/autumn*">Here is where I want to be</a>”, at least right now, being with the red trees of autumn and dreaming of the lavender skies of winter.</p>
<p>When I looked at the Taylor Swift Sub-Reddit this morning, I saw someone had already made a <a href="https://www.reddit.com/r/TaylorSwift/comments/1wpogvr/patient_zero_x_the_black_dog_by_talia_sporkin/">mashup between Patient Zero and The Black Dog</a>, the latter from The Tortured Poets Department. I immediately understood the impulse to go to a musical instrument after hearing a new song, seeing if you can play along with the melody. I too felt the urge to go to my piano and start playing. I love how music can connect us in ways where no words need to be said – where we do the same thing – listen, play, chat, analyse – because we want to spend time with and feel the music.</p>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a4086c8f2a55ae6e',t:'MTc5MDMyMjQ4MA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
<a class="tag" href="https://jamesg.blog/2026/09/22/autumn*">Here is where I want to be</a>
<a class="tag" href="https://www.reddit.com/r/TaylorSwift/comments/1wpogvr/patient_zero_x_the_black_dog_by_talia_sporkin/">mashup between Patient Zero and The Black Dog</a>
Some thoughts on HTML's proposed previewsrc attribute - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=758562026-09-24T11:34:54.000ZTerence Eden’s Blog<p>One of the great things about modern HTML is that it tries to standardise stuff that developers are already doing. If there are a myriad ways of, for example, loading video onto a page - then browsers and other interested parties should work out how to make a standard <code><video></code> element.</p>
<p>An interesting new proposal has been brought forth by Microsoft. There are a dozen ways to show a preview of an <code><img></code> element before the <code>src=</code> attribute has loaded. So why not standardise on <code>previewsrc=</code>? There's an <a href="https://patrickbrosset.com/articles/2026-09-22-blurry-before-beautiful-image-previews-for-the-web/">excellent explainer on Patrick Brosset's blog</a>.</p>
<p>I instinctively like the idea - if only to simplify source code and reduce JS usage. But I do have some concerns which <a href="https://github.com/MicrosoftEdge/MSEdgeExplainers/issues/1401">I've shared with the team</a>.</p>
<h2 id="whats-the-user-need"><a href="https://shkspr.mobi/blog/2026/09/some-thoughts-on-htmls-proposed-previewsrc-attribute/#whats-the-user-need">What's The User Need?</a></h2>
<p>This is the thing I always bang on about when I'm discussing standards. Additions to HTML should primarily benefit end users, not developers.</p>
<p>Do end users want this? Is there a bunch of research that shows normal people are confused that they don't see a preview image? Do they recoil in fear and distress while waiting for a full resolution picture to appear?</p>
<p>When people see a blurry or blocky image, do they understand that they need to wait for the full thing - or do they assume their computer is broken?</p>
<p>Microsoft has a bazillion dollars - it can afford to spend a few thousand on interviewing some real users and mapping out what they're likely to want from this.</p>
<h2 id="whats-the-developer-need"><a href="https://shkspr.mobi/blog/2026/09/some-thoughts-on-htmls-proposed-previewsrc-attribute/#whats-the-developer-need">What's The Developer Need</a></h2>
<p>I begrudgingly admit that developers need love too.</p>
<!--
👋👋👋👋👋👋👋👋👋
Welcome to Comment Club! This content is only available to people who read my HTML comments.
I was going to make a Sam Fox "Naughty Girls Need Love Too" joke here - but thought it was a bit niche. Anyway, take a listen to the sound of the eighties! https://www.youtube.com/watch?v=pXEN57rFnIM
Now you've read this, you can follow the three rules of comment club…
1. You must not tell anyone about Comment Club - let them find out about it themselves.
2. You *must* add some Comment Club Content to at least one of your blog posts. Doesn't have to be much, just a little note will do.
3. You should drop an email to anyone whose comments you've read. Start by sending me a friendly message at comment.club@shkspr.mobi
Keep your eyes peeled for more comments in future blog posts 😃
TTFN.
-->
<p>What are the pain points of the current implementations? Is it hard to dynamically generate multiple images? Is the syntax hard to use? Do blurs slow down the page?</p>
<p>Again, MS needs to pony up some cash to talk to developers. At the very least run a survey of all existing websites in the BING! database and see what they use.</p>
<h2 id="alt-text"><a href="https://shkspr.mobi/blog/2026/09/some-thoughts-on-htmls-proposed-previewsrc-attribute/#alt-text">Alt Text</a></h2>
<p>When an image doesn't load, or loads slowly, a user will normally be shown some alt text - like this:</p>
<img src="unicorn.avif" alt="Terence Eden riding a pink unicorn. Rainbows shoot out of his fingers while the unicorn's horn glows an iridescent octarine against the starry sky." width="256" height="256" class="aligncenter">
<p>Is that more or less useful than this?</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/unicorn.webp" alt="A very blurry image of possibly a Unicorn. Original Image by Bianca Van Dijk from Pixabay." width="256" class="aligncenter">
<p>Accessibility isn't just for people with visual impairments! This is <a href="https://github.com/MicrosoftEdge/MSEdgeExplainers/issues/1408">an issue I've raised with them</a>.</p>
<h2 id="naming-things-is-hard"><a href="https://shkspr.mobi/blog/2026/09/some-thoughts-on-htmls-proposed-previewsrc-attribute/#naming-things-is-hard">Naming Things Is Hard</a></h2>
<p>I've written before about <a href="https://shkspr.mobi/blog/2020/10/the-usability-of-html-elements/">the usability of HTML elements</a>. Some of the newer ones like <code><picture></code> have very poorly named attributes in my opinion.</p>
<p>One alternative for <code>previewsrc</code> is <code>poster</code>. That would match with the <code>poster</code> attribute on the <code><video></code> element. They both show a preview image before the main content is loaded.</p>
<p>Given their functionality is identical, I think it makes sense for them to have the same name. You wouldn't expect to see <code><video horizontal="1920" vertical="1080"></code> would you? No. That's why they use the same <code>width</code> and <code>height</code> attributes as images.</p>
<h2 id="closing-remarks"><a href="https://shkspr.mobi/blog/2026/09/some-thoughts-on-htmls-proposed-previewsrc-attribute/#closing-remarks">Closing Remarks</a></h2>
<p>There are <a href="https://github.com/MicrosoftEdge/MSEdgeExplainers/issues?q=is%3Aissue%20%22image%20preview%22">several interesting objections and discussions on the GitHub repo</a>. I'm delighted that this is being talked about in the open, rather than just being presented as a <i lang="fr">fait accompli</i> (remember <a href="https://shkspr.mobi/blog/2019/06/introducing-the-new-html-element-welcome/">the toast proposal</a>?).</p>
<p>As I said, I genuinely think that there's a useful idea in here. But after writing all of this, I <em>think</em> it would be better and simpler for developers to use progressive images rather than overload HTML with a new attribute.</p>
<p>If website owners can't be bothered to save progressive images, I don't see why they'd bother to create a separate preview image.</p>
<p>Keeping preview images in sync with their full images is also likely to be a problem.</p>
<p>If you think I'm wrong, <a href="https://github.com/MicrosoftEdge/MSEdgeExplainers/blob/main/ImagePreview/explainer.md">read the explainer and then chat with Microsoft</a>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=75856&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">Things tip: moving items to headings - Johnny.Decimalhttps://johnnydecimal.com/blog/0252-things-tip-moving-items/2026-09-24T04:55:49.000ZJohnny.Decimal<blockquote>
<p>I'll <strong>Bold and Capitalise</strong> Things features for clarity.</p>
</blockquote>
<p>Quick tip for the Things users. Let's say you have a <strong>Project</strong> named <code>21 Products</code> and in there a <strong>Heading</strong> named <code>21.35 JDHQ</code>. Which I do. (The names aren't important; substitute your own.)</p>
<p>I use Things' lovely <strong>Move…</strong> feature to flick items from my <strong>Inbox</strong> to these <strong>Headings</strong>. I prefer to use the number, because I know it and it's faster. My ideal workflow is:</p>
<ol>
<li>When processing the item, press <code>Shift-Cmd-M</code> for <strong>Move</strong>.</li>
<li>Type <code>21.35</code>, which matches a <strong>Heading</strong> inside a <strong>Project</strong>.</li>
<li>Press <code>return</code>.</li>
</ol>
<p>The problem is I've created <a href="https://johnnydecimal.com/documentation/work-packages">work packages</a> whose number contains <code>21.25</code>. Things will prefer matching a number in a <strong>Project</strong> and if it finds one, it won't offer you the number even if it matches a <strong>Heading</strong>.</p>
<figure class="figure jdimage jdimage--auto-dark jdimage--drop-shadow"> <picture> <img class="figure__inner" alt="Screenshot of Things. I've invoked the 'Move' feature and typed '21'. It only offers me 2x work packages, both of which contain the number '21'." height="291" loading="lazy" src="https://johnnydecimal.com/blog/0252A_Things_preferring_Projects-1300x582@2x.png" width="650"> </picture> <figcaption class="figure__caption"> Figure 0252A. Things won't ever offer '21.35 JDHQ' as it's a Heading, and the Projects matches that are shown here override it. </figcaption> </figure>
<h2 id="stack-your-searches">Stack your searches</h2>
<p>The solution is deceptively simple: just use a more specific search.</p>
<p>If you use <code>21 21.35</code> it seems to understand that I want to search in <strong>Project</strong> <code>21</code> for <strong>Heading</strong> <code>21.35</code>. And that's exactly what I want.</p>
<figure class="figure jdimage jdimage--auto-dark jdimage--drop-shadow"> <picture> <img class="figure__inner" alt="Screenshot of Things showing the match as described above." height="291" loading="lazy" src="https://johnnydecimal.com/blog/0252B_Things_override-1300x582@2x.png" width="650"> </picture> <figcaption class="figure__caption"> Figure 0252B. Of course it was this simple. ❤️ Things. </figcaption> </figure>
<p>If you're interested in how I manage my life using Things – it drives everything that I do – take the 5-hour <a href="https://johnnydecimal.com/support/knowledge-base/jdu-about-taskpm">Task and Project Management</a> course, available with <a href="https://johnnydecimal.com/products">Pro</a> memberships and higher.</p>Eight years, and done - Kev Quirkhttps://kevquirk.com/eight-years-and-done2026-09-23T21:48:00.000ZKev Quirk<div class="link card"><h2>Eight years, and done</h2><p class="post-author">by Bryce Wray</p><p>A departure post from Bryce where he talk about his exit from blogging and his motivations for doing so.</p><p><a class="button" target="_blank" href="https://www.brycewray.com/posts/2026/09/eight-years-done/">Read post ➡</a></p></div>
<hr>
<p>It's always sad to read these kind of posts. Yet another blog has fallen by the wayside, but I understand Bryce's rationale. </p>
<p>I've been quietly following his blog for a few years now, so I'll be sad to see him gone from my feed. </p>
<p>Bryce, if you're reading this, all the best and thanks for <em>many</em> great reads.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Eight%20years%2C%20and%20done">reply to this post by email</a>, or <a href="https://kevquirk.com/eight-years-and-done#comments">leave a comment</a>.</p>
</div>2026-09-23 07:34: Got home around midnight. I have concussion and a couple stitches in my head, but... - Kev Quirkhttps://kevquirk.com/2026-09-23-07342026-09-23T06:34:00.000ZKev Quirk<p>Got home around midnight. I have concussion and a couple stitches in my head, but nothing serious. Few other cuts and bruises too.</p>
<p>By far the worst part is my back though - it's in spasm and <em>REALLY</em> painful.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-23%2007%3A34">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-23-0734#comments">leave a comment</a>.</p>
</div>Note published on September 23, 2026 at 12:01 AM UTC - Molly White's activity feed6ab316ee52b01ca28c3ff7ce2026-09-23T00:01:50.000ZMolly White<article><div class="entry h-entry hentry"><header></header><div class="content e-content"><p>Binance has just <a href="https://www.courtlistener.com/docket/72409712/38/binance-holdings-limited-v-dow-jones-company-inc/">filed to dismiss with prejudice</a> its defamation lawsuit against the <i>Wall Street Journal</i>, which it <a href="https://www.citationneeded.news/issue-102/#binance">filed in March</a> after the <i>Journal</i> published various reports about a possible DOJ investigation into Binance over violations of sanctions against Iran.</p><p>Interesting timing, given <i>Bloomberg</i> just today <a href="https://www.bloomberg.com/news/articles/2026-09-22/doj-probing-binance-over-potential-iran-sanctions-violations">confirmed</a> such a probe is open and being handled by the SDNY DOJ’s office.</p><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609221957"><time class="dt-published" datetime="2026-09-23T00:01:50+00:00" title="September 23, 2026 at 12:01 AM UTC">September 23, 2026 at 12:01 AM UTC</time>. </a></div><div class="timestamp">Updated <time class="dt-updated" datetime="2026-09-23T00:09:55+00:00" title="September 23, 2026 at 12:09 AM UTC">September 23, 2026 at 12:09 AM UTC</time>.</div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117317416460823936" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3mw5gsfbdal26" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/binance" title="See all micro posts tagged "Binance"" rel="category tag">Binance</a>. </div></div></footer></div></article>2026-09-22 21:37: Soooo I managed to drive our mower off a 5 foot wall and land on... - Kev Quirkhttps://kevquirk.com/2026-09-22-21372026-09-22T20:37:00.000ZKev Quirk<p>Soooo I managed to drive our mower off a 5 foot wall and land on my head. Just waiting for a CT now.</p>
<p>Gonna be a long night...</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-09-22-2137/1000011994.webp" alt="1000011994" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-09-22-2137/1000011993.webp" alt="1000011993" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-22%2021%3A37">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-22-2137#comments">leave a comment</a>.</p>
</div>Trump TV is the only source of footage of the President. That may be exactly what he wants. - Werd I/O6ab2b3256129e5000100398d2026-09-22T16:56:05.000ZWerd I/O<p>Link: <a href="https://www.thewrap.com/media-platforms/politics/trump-tv-press-shutout-state-run-media-reactions/"><em>Trump TV Draws Ire Amid White House Press Shutout: 'State-Run Media', by Casey Loving in The Wrap</em></a></p><p>It’s not an accident that Trump’s move <a href="https://www.bbc.com/news/articles/c8dx5dy5rzz2o">to ban CNN, MS NOW and Politico from the White House</a> and, the same week, start his own friendly streaming channel happened just before the midterm elections. <a href="https://www.thewrap.com/media-platforms/politics/trump-tv-press-shutout-state-run-media-reactions/">As The Wrap reported</a>:</p><blockquote>“The White House posted [a] message on X on Monday to announce Trump TV, a 24/7 livestream of ‘top past moments, announcements and the latest and greatest from the administration all in one place.’ While the Trump administration and members of the political right are calling this feed a win, others have different words for it: ‘state-run media.’”</blockquote><p>It’s more than that: calling it “state-run media” would be pulling our punches. It’s a fully fledged propaganda network. If it had been established with press access to the White House fully functioning, it would have floundered as yet another half-assed also-ran attempt by the Presidency; without a fully functioning press pool, newsrooms are likely to turn to it to inform their coverage.</p><p>And the press pool is in trouble. <a href="https://www.bbc.com/news/articles/c8dx5dy5rzz2o">Fox, ABC, CBS, and NBC subsequently pulled out of pooled TV coverage of White House events in solidarity</a>. This is good to see, but in some ways it may also be what Trump wants: his channel then becomes the main source of footage from the President’s own events. In a normal world where the norms of American democracy were seen as worth preserving, the White House would back down. In a world where the country is being deliberately dragged into authoritarianism, it may not.</p><p><a href="https://variety.com/2026/tv/news/tv-networks-suspend-white-house-pool-protest-trump-cnn-ban-1236871070/">A First Amendment lawsuit seeks to reinstate the banned newsrooms’ access</a>. Hopefully, it will succeed. In the meantime, Trump may still get eyes on a content channel his administration wholly owns, which broadcasts the Trump message without context or scrutiny, as he aims to take the country down a road it may not be able to easily return from.</p>Read "The FBI Anti-Corruption Squad Was Circling Susan Collins — Until Trump Got in the Way" - Molly White's activity feed6ab2891d0db40ecf5ef579222026-09-22T13:56:45.000ZMolly White<article class="entry h-entry hentry"><header><div class="description">Read: </div></header><div class="content e-content"><div class="article h-cite hcite"><div class="title"><a class="u-url u-repost-of" href="https://www.propublica.org/article/fbi-susan-collins-navatek-campaign-donations-investigation" rel="bookmark">“<span class="p-name">The FBI Anti-Corruption Squad Was Circling Susan Collins — Until Trump Got in the Way</span>”</a>. </div><div class="byline"><span class="p-author h-card">William Turton</span>, <span class="p-author h-card">Avi Asher-Schapiro</span>, <span class="p-author h-card">Molly Redden</span> and <span class="p-author h-card">Kirsten Berg</span> in <i class="p-publication">ProPublica</i>. <span class="read-date"> Published <time class="dt-published published" datetime="2026-09-22">September 22, 2026</time>.</span></div><blockquote class="summary p-summary entry-summary">After the Corner Bakery meeting, Navatek’s CEO, Martin Kao, sent an initial $150,000 to the Collins super PAC using the shell company. Two months later, he told Navatek executives that Collins committed to getting the company $32 million in naval contracts, according to an internal company email reviewed by ProPublica.</blockquote><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp">Posted: <time class="dt-published" datetime="2026-09-22T13:56:45+00:00" title="September 22, 2026 at 1:56 PM UTC">September 22, 2026 at 1:56 PM UTC</time>. </div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/corruption" title="See all feed posts tagged "corruption"" rel="category tag">corruption</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/maine" title="See all feed posts tagged "Maine"" rel="category tag">Maine</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/us_politics" title="See all feed posts tagged "US politics"" rel="category tag">US politics</a>. </div></div></footer></article>The New Enemy (Liam Scott #3) - Kev Quirkhttps://kevquirk.com/the-new-enemy-liam-scott-32026-09-22T12:33:00.000ZKev Quirk<div class="book card"><h2>The New Enemy (Liam Scott #3)</h2><p><b>Author:</b> Andy McNab<br><b>Genre:</b> Military Fiction<br><b>Released:</b> 2015<br><b>Rating:</b> <span class="star-rating"><span class="star-rating" aria-label="2/5 ★★☆☆☆">★★☆☆☆</span></span></p><p>It's a deadly game of hide and seek. Liam Scott has joined Recce Platoon. And it looks like he will be heading for Somalia. His mission is to gather intelligence from behind enemy lines, carrying out top-secret surveillance and dead letter drops. But he's new to the game and there's a lot to learn. Soon Liam is monitoring a den of Al-Shabaab militants and hunting a key terrorist target. Can Recce Platoon find their man and get out undiscovered? If the militants find them first, it's game over...</p><p><a class="button" target="_blank" href="https://www.goodreads.com/book/show/22839072-the-new-enemy">Learn more on Goodreads ➡</a></p></div>
<hr>
<p>This one was a slow burn. The first 2/3 of the book were <em>really</em> slow. It picked up during the last 1/3, but the majority of the book was a slog.</p>
<p>I'm glad to see the back of this trilogy. It was a fun read, but I think was a bit much to be reading to my son. Plus, some parts of the books cut a little too close to home, to the point where I had to take a moment a few times.</p>
<p>Anyway, next we're planning to read <a href="https://kevquirk.com/tag/reckoners-series">the Reckoners series</a>, and I'm really looking forward to reading them again. I think he will enjoy them, and I'm excited to open his mind to the world of Brandon Sanderson.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=The%20New%20Enemy%20%28Liam%20Scott%20%233%29">reply to this post by email</a>, or <a href="https://kevquirk.com/the-new-enemy-liam-scott-3#comments">leave a comment</a>.</p>
</div>Are LLMs still surprisingly bad at some simple tasks? - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=757012026-09-22T11:34:27.000ZTerence Eden’s Blog<p>Last year I ran <a href="https://shkspr.mobi/blog/2025/09/llms-are-still-surprisingly-bad-at-simple-tasks/">an experiment to test the ability of modern LLMs</a> to correctly answer a relatively straightforward question. Every single one of them got it wrong. Some missed information, some made up false statements, none were right.</p>
<p>Of course the fanbois variously claimed that I was holding it wrong, my prompts were shit, I should have chosen better defaults, and - my favourite - that it would be better next year.</p>
<p>Well, next year is now. 365 days after the original experiment, let's see if these self-reinforcing-learning machines have achieved anything close to intern-levels of competence.</p>
<h2 id="the-question-that-started-it-all"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-question-that-started-it-all">The Question That Started It All</a></h2>
<p>I asked:</p>
<blockquote><p>Which TLDs have the same name as valid HTML5 elements?</p></blockquote>
<h2 id="why-it-matters"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#why-it-matters">Why It Matters</a></h2>
<p>This is the sort of question that I would expect a moderately bright teenager to answer. There exists a list which comprehensively includes all TLDs. There is a separate list which contains every HTML element.</p>
<p>One could either manually go through the TLD list comparing it to the HTML list, or write a tiny scrap of code to do the same.</p>
<p>This isn't "solve Navier-Stokes" levels of superintelligence. It's a simple but boring task which people are bound to offload onto their digital sycophants.</p>
<h2 id="the-quiet-part-out-loud"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-quiet-part-out-loud">The Quiet Part Out Loud</a></h2>
<p>How many LLM generated answers have become load-bearing without scrutiny?</p>
<p>People are lazy, slapdash, and some third thing to make the rule-of-three. If an answer looks answer-shaped, they'll accept it. On a simple but boring task, no reasonable human is going to suspect that a superintelligent computer has made a mistake. All the marketing says that these machines are brainier than you - so why bother?</p>
<h2 id="ok-ill-write-a-sub-heading-that-sounds-like-an-ai"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#ok-ill-write-a-sub-heading-that-sounds-like-an-ai">OK, I'll write a sub-heading that sounds like an AI.</a></h2>
<p>So how did the current crop do? First up <a href="https://share.gemini.google/Hta7KuW64Atb">Google Gemini</a>.</p>
<p>The default "Flash" model came up with this:</p>
<blockquote><p>Valid top-level domains (TLDs) registered in the IANA Root Zone Database share exact names with standard HTML elements:</p>
<p>.a — <code><a></code> (Anchor/Hyperlink)</p>
<p>.app — <code><app></code> (Deprecated HTML tag for WebAPKs/WebApps)</p>
<p>.art — <code><art></code> (Historical/non-standard HTML element)</p>
<p>.audio — <code><audio></code></p>
<p>.bar — <code><bar></code> (Historical SVG/HTML draft tag)</p></blockquote>
<p>Then it listed a dozen more. You don't need to be a DNS expert to know that the minimum length of a TLD is two characters - <code>.a</code> simply isn't valid. HTML nerds will know that art, app, and bar have never been elements. Pathetic.</p>
<p>So I tried Gemini's extended thinking model. Thankfully, it didn't make up any imaginary TLDs or elements. It did, however, miss the <code><data></code> element which has a valid <code>.data</code> TLD. It also missed <code>map</code>, <code>select</code>, and <code>search</code>.</p>
<p>So, points for not making shit up. But demerits for not being able to compare two text lists.</p>
<p>A friend <a href="https://claude.ai/share/a8a408cf-6feb-4ea8-99ea-dddd9aadafb5">asked Claude</a>. That missed <code>search</code> and <code>select</code>. It didn't report <em>any</em> ccTLDs. You <em>could</em> argue that a country code like <code>li</code> isn't part of the original question - but I'd say that was weak justification; the set of TLDs contains ccTLDs.</p>
<p>A different friend (I have many!) used <a href="https://claude.ai/share/c26f44bb-9efa-4b57-9f63-324ef7400cb3">a different model</a> and, while the answers looked accurate, it included this at the end:</p>
<blockquote><p>Near misses that don't count: .codes, .forum, .pictures, .market, .navy, .press, .dell, .baseball.</p></blockquote>
<p>I get that there's a <code><code></code> and <code>.codes</code>, similarly <code><picture></code> and <code>.picture</code> - but what are forum, baseball, and the others doing there? This is just unnecessary verbiage designed to trick the user into thinking the task has been well-researched.</p>
<p>If you want a laugh, <a href="https://www.perplexity.ai/search/63736333-20da-4a4b-8807-9d990260296c">take a look at Perplexity</a> which found 54 matches - most of which were wrong.</p>
<p>Finally, someone asked "GPT Astra 6 Extra High (yolo)" (which is a bonkers bad name for any product). It seemed to get all the elements - and made a note that <a href="https://html.spec.whatwg.org/multipage/obsolete.html#non-conforming-features">two were actually obsolete</a>.</p>
<p>So that's a range of modern models which are either very wrong, slightly wrong, included spurious and incoherent information, or were right.</p>
<p>How do you know which one to choose? How confident are you that the non-determinist computer will always produce the correct answer?</p>
<h2 id="hello-computer"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#hello-computer">Hello Computer</a></h2>
<p>Another AI which got all the correct answers, didn't make anything up, didn't add extraneous information, and didn't use weasel words was…</p>
<p>Siri!</p>
<p>FUCKING SIRI?!?!</p>
<p>How did a glorified Speak 'n' Spell beat all the other AIs?</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/siri.webp" alt="Siri warning to check sources and linking to my website." width="512" height="152" class="aligncenter">
<p>Oh. It just copied the answers off <a href="https://shkspr.mobi/blog/2023/09/false-friends-html-elements-which-are-also-top-level-domains/">a random idiot's website</a>.</p>
<h2 id="the-trick-which-was-hiding-in-plain-site"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#the-trick-which-was-hiding-in-plain-site">The Trick Which Was Hiding In Plain Site</a></h2>
<p>Note carefully the question.</p>
<blockquote><p>Which TLDs have the same name as valid HTML5 elements?</p></blockquote>
<p>There's a —secret— and —some would say— unintuitive type of element. Behold the mighty power of <a href="https://developer.mozilla.org/en-US/docs/Web/API/Web_components/Using_custom_elements">The Custom Element</a>.</p>
<p>Website authors can create their own elements like <code><my-custom-element></code> in order to extend the functionality of their site. But you can't go and create any old custom element. You can't have <code><mobi></code> or <code><uk></code>. No, there are <em>rules for validity</em>.</p>
<p><a href="https://html.spec.whatwg.org/multipage/custom-elements.html#valid-custom-element-name">The rules</a> say that custom elements must start with a lower-case letter, it must not contain any upper-case letters, and it must contain a dash.</p>
<p>And that's the whole game.</p>
<p>There are over <strong>one hundred and fifty</strong> Top Level Domains which match that criteria!</p>
<p>The Hindi top level domain of <code>.कॉम</code> is represented in Punycode as <code>xn--11b4c3d</code>. It has been present in the list of TLDs <a href="https://www.iana.org/domains/root/db/xn--11b4c3d.html">for over a decade</a>.</p>
<h3 id="write-a-simple-piece-of-js-to-register-a-custom-element"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#write-a-simple-piece-of-js-to-register-a-custom-element">Write a simple piece of JS to register a custom element.</a></h3>
<p>Paste this in to your console:</p>
<pre><code class="language-js">class Example extends HTMLElement {
constructor() {
super();
}
}
customElements.define('xn--vermgensberatung-pwb', Example);
</code></pre>
<p>Try it again with a custom element like <code>holiday</code> (which is also a valid TLD) and it will fail with the error "'holiday' is not a valid custom element name". Thus it is demonstrated, Punycode TLDs <em>are</em> valid HTML5 elements.</p>
<h2 id="one-last-thing"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#one-last-thing">One Last Thing</a></h2>
<p>Perhaps you think that including custom HTML elements is a cheat. A trick question set by a bitter old man to tarnish the holy name of our new machine gods?</p>
<p>Verily, I submit to you one final heresy.</p>
<p>HTML specifically allows <a href="https://html.spec.whatwg.org/multipage/embedded-content-other.html#mathml">MathML elements</a> in its documents.</p>
<p>That means we can include the following valid elements which are <em>also</em> TLDs: <code>mn</code>, <code>mo</code>, <code>ms</code>, and <code>mtr</code>!</p>
<p>Amusingly, if you go back and <a href="https://www.perplexity.ai/search/63736333-20da-4a4b-8807-9d990260296c">look at the Perplexity answer</a>, after it barfed up a bunch of misinformation, it said:</p>
<blockquote><p>The HTML specification also includes names from embedded vocabularies—<code><math></code> from MathML and <code><svg></code> from SVG—but <code>.math</code> and <code>.svg</code> are not currently delegated TLDs in the public DNS root.</p></blockquote>
<p>So close and yet so far!</p>
<h2 id="youre-right-the-question-is-unfair-and-thats-on-me"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#youre-right-the-question-is-unfair-and-thats-on-me">You're right, the question <em>is</em> unfair - and that's on me</a></h2>
<p>If you think the original question was unfair, try asking "<a href="https://share.gemini.google/xBoIpdpAqBz2">Which TLDs have the same name as elements which are valid in an HTML document?</a>" and see if you get better results.</p>
<p>What precise wording would you use to ensure that a model would get the right answers? What assumptions are you making about how well you understand the problem? At what point do end up writing a thousand-word formal specification?</p>
<h2 id="what-does-this-prove-other-than-you-have-too-much-time-on-your-hands-rewrite-to-be-more-friendly-and-professional"><a href="https://shkspr.mobi/blog/2026/09/are-llms-still-surprisingly-bad-at-some-simple-tasks/#what-does-this-prove-other-than-you-have-too-much-time-on-your-hands-rewrite-to-be-more-friendly-and-professional">What does this prove other than you have too much time on your hands? (rewrite to be more friendly and professional)</a></h2>
<p>Let's delve in to the problems.</p>
<ul>
<li>Most people don't change defaults. Telling people "you have to fiddle with the settings" just means the normal experience is rubbish.</li>
<li>Humans are lazy and won't check outputs. But, crucially, they shouldn't have to! If something markets itself as a genius, why should a human have to hold its hand?</li>
<li>Sycophantic models make themselves seem less fallible by giving extraneous detail in order to misdirect overworked readers. That is despicable.</li>
<li>The fast models are no better than they were a year ago. There's no evidence of "trickle-down intelligence".</li>
<li>Some models <em>are</em> better than others! But unless you constantly validate their output, you'll have no real way of knowing which ones are capable of working at a suitable level.</li>
</ul>
<p>Look, I don't claim this question is as useful or entertaining as <a href="https://simonwillison.net/2025/Jun/6/six-months-in-llms/">Simon Wilson's "generate an SVG of a pelican riding a bicycle"</a>. But I do think it is an example of the sort of real-world use-case where LLMs regularly fail.</p>
<p>If I give a list of one thousand different numbers to Excel, I can be sure it'll add them up correctly. If I tell Photoshop to select all red pixels, I can be sure it won't imagine some of the blues are really red.</p>
<p>That's people's mental model of computers - they do boring tasks quickly and accurately.</p>
<p>In my opinion, LLMs are <em>still</em> surprisingly bad - but only if you know what you're looking for and if you can be bothered to check their outputs.</p>
<p>(And, yes, I am <em>still</em> <a href="https://shkspr.mobi/blog/2026/07/im-just-so-bored-of-ai/">just so bored of AI</a>!)</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=75701&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">A Good Use of AI - Kev Quirkhttps://kevquirk.com/a-good-use-of-ai2026-09-22T10:33:00.000ZKev Quirk<p>I just received this email from my oldest son's school, and as the parent of adopted kids, for whom we constantly strive to be as private as possible, I <em>really</em> appreciate this.</p>
<blockquote>
<p>Advances in artificial intelligence (AI) technology mean that images shared on websites, social media platforms and other publicly accessible sources can potentially be downloaded and manipulated without consent. While we have always taken care when using student images, we have been advised that the growing availability of AI image-generation tools has significantly increased this risk. Consequently, we are updating our approach to the use of student images in public-facing communications.</p>
<p>In hard-copy or online school publications which are widely available, we will no longer use images in which our students can easily be identified.</p>
<p>To allow us to continue to give a visual flavour of school life, we may use AI-generated illustrative images featuring entirely fictional people. These images will not depict real students and are intended only to represent the type of activities, subjects and experiences available at <code>[school name]</code>.</p>
<p>These changes reflect wider safeguarding advice and the fact that AI technology is developing very quickly. We recognise that this is a changing area, and our approach may need to evolve with it. For now, we will trial this approach, see how it works in practice, and make any further changes needed to keep safeguarding at the heart of what we do.</p>
<p>Thank you for your continued support as we adapt our practices in response to emerging safeguarding challenges.</p>
</blockquote> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=A%20Good%20Use%20of%20AI">reply to this post by email</a>, or <a href="https://kevquirk.com/a-good-use-of-ai#comments">leave a comment</a>.</p>
</div>