A Blog: Rare texts, musing and free range ranting

On AI Destroying Humanity

Sigh. So this has been making the rounds this past week.

https://www.youtube.com/watch?v=CNut8Ub-lvQ

I originally figured it was ridiculous enough to die on its own. Instead, major news outlets picked it up and ran it, apparently without doing any research into the subject at all or talking to anyone sane about it. I guess that’s how we roll now.

Let’s start with the obvious. An LLM is not the ILOVEYOU virus. It is not infecting a web server. It is not hacking a wiki. Those are commodity pieces of software with mass distribution, and jumping from that to a frontier model is a non-trivial leap in hardware, software, and capability. One does not automatically follow from the other.

Running a frontier model right now is a MASSIVE effort. It needs purpose built datacenters to run. It sprawls across multiple very expensive chips, specialized inference software, specialized harness software, databases, cloud compute, tooling, and hundreds of install packages.

Let’s take one Kimi K3 as an example. It’s not a frontier model, you can get access to it with $10/month. But it’s 1.6 TB of weights at 2.8 trillion parameters. You need about 1.5 TB of VRAM, which means 8x NVIDIA GB300s, which set you back roughly 400 to 700K USD to buy, and as much or more per year to rent.

Now say one of these real frontier models, Astra or Mythos or whatever the next big hype thing is, lands at 10 trillion parameters. That’s roughly 10 to 20 TB unquantized. We’re guessing, because these folks reveal nothing about architectures anymore, but they’re reasonable guesses based on scaling laws. You’d need about 23 TB of VRAM and several million dollars a year to run ONE instance. And it gets worse, because it no longer fits on an 8-way cluster. Now you need special networking configuration and inference software, or a Nvidia NVL72 rack-scale system, which goes for between $3 and $6.5 million.

So the potential “killer rogue” model can only copy itself onto the most expensive compute in the world. The places that have that kind of compute, don’t have it sitting on the shelf idling. And it’s also not open to public to run whatever they want, it’s watched closely for downtime and anomalies. It’s governed by SLA’s and protected by actual cybersecurity controls (which seems to be an area noone at these AI fronties labs understand at all). The highly expensive compute is doing one of two things.

1) Serving customers at a hyperscaler. 2) Serving inference for some well-endowed company.

In the first case, a “killer rogue AI” gets noticed instantly by the hyperscaler’s actually good automated monitoring and it alerts the IT and Cybersecurity team, because something is using their infrastructure without being billed, costing them millions in lost revenue and electricity.

In the second case, the model that lived on that very expensive hardware is now offline, replaced by the rogue one. That model was presumably wired into some valuable internal software, which is now glitching and not running. This will also alert IT/Cybersecurity staff and incident response will begin immediately.

The expensive systems will be contained, The “killer rogue AI” will be evicted and that’ll be the end of that.

Real world systems have friction, resource limits, actual monitoring, Real world systems need to provice business value. You can’t use up the compute running a “rogue agent swarm” without anyone noticing. The researchers in AI labs obviously don’t have to think about these things, which is singularly unique position. It seems that makes all of the lose perspective to reality completely.

To be fair, some of this may be possible in coming decades. Not likely but perhaps non-zero probability. Breakthroughs in architecture, smaller models, and a commoditized computing substrate could change the picture materially. And sure, we might eventually reach a point where superintelligence emerges from all of this. The odds of an LLM program suddenly flipping into superintelligent AGI are nearly nonexistent, partly because language isn’t even the foundation of human intelligence, so betting on it springing from a text predictor is a stretch, but let’s humor the process. If I was writing a near future sci-fi novel, I might use that. But of course, I don’t have to write the novel, because these guys are LARP:ing it in evening news.

Getting back to reality. We don’t have super AGI and the rest of this is mitigable, foreseeable, and an engineering problem that is solved by monitoring and basic cybersecurity controls.

These things will not be copying themselves around like a virus on your computer, your phone of your entertainment system at home, not in their current form, not now, not in the coming years. Let’s re-visit this in two decades or so.

All of this also betrays a lack of understanding of how complex economic, societal, and technological systems evolve. They don’t evolve in a vacuum. Mitigations always show up as parallel evolutionary developments. You get viruses, you get antivirus software. You get DDoS attacks, you get CDNs like Cloudflare. There’s money in solving problems, and nothing evolves in isolation. We who live and work in cyber security know this intimately because we ARE the mitigating factors.

Believing things evolve in isolation, that one thing changes while all other variables politely stay put, is one of the many reasoning errors that destroys people’s ability to make accurate predictions.

And when you don’t have the requisite knowledge to verify your own predictions, things that sound sane and rational to you are, in fact, completely batshit insane and ridiculous.

Finally I want to leave you with this old, but gold video. Watching it is well worth your time.

https://www.youtube.com/watch?v=kErHiET5YPw

Permalink: /blog/2026/09/12/AI_Destroys_Humanity/

On Open Weights and American AI Leadership

On the 24th, Microsoft published a letter titled Open Weights and American AI Leadership and currently fifty tech companies have signed it. The gist of the letter is, they want “open weight” AI models to be treated as a pillar of American national security.

It is a masterclass in conflation.

The letter spends paragraphs praising open source software. Linux. The internet. Scientific research. Sounds great. Then it pivots.. to Open Weight, not Open Source. Open weight models are framed as the natural successor to the Open Source tradition. They are not.

Open source means getting the recipe, the compiler flags, the training data provenance, the bug tracker so it can be studied, modified, and rebuilt from first principles. Open weights means receiving a forty billion parameter binary blob and being wished the best of luck. It is the difference between a cookbook and a frozen dinner. Both involve food, but only one allows the recipe to be changed.

The signatories of course know this. Most of them do not open source their frontier models. Most of them don’t actually open source anything at all. Imagine NVIDIA open sourcing their CUDA and GPU drivers? Yeah. That’s obviously not going to happen. So they want to release model weights. Or they release nothing at all and rent API access by the token and still get to call it “open”. Calling a weight dump “open” doesn’t make the model open source. It just means we know what the final state of the model was and can do some our own parameter tuning based on it. It’s not a bad thing, but it’s also not open source.

The geopolitical framing is equally convenient. The letter warns that restricting open weights will “drive innovation overseas.” Non American models are naturally treated as a looming threat to “good guy American models”. These are framed as the safe, sovereign choice. This from the same companies that store customer data in Dublin, train models in Singapore, and source chips from Taiwan. Sovereignty is a very flexible concept when it serves the bottom line.

What makes the posturing absurd is the timing. The AI frontier is being recast as a Cold War race. Congress is drafting bills. Export controls are expanding. Billions in defense contracts are being negotiated. All for a technology whose primary consumer use cases remain autocomplete, chatbots, and generating images of astronauts on horseback. The industrial applications are certainly promising. They are also mostly theoretical at this point. No one really knows if any of the use-cases we’re talking about it worth the associated cost. But the geopolitical architecture and rhetoric wars are being built before the building has an actual purpose.

The most cynical move of this letter is the underlying compute shift. The letter celebrates open weights (sorry open source) because they let organizations “run on their own infrastructure.” This sounds like empowerment. It is actually a capital expenditure transfer. Training a frontier model costs hundreds of millions. Running it at scale requires a data centers full of GPUs. This is the model we have at the moment and big tech has been subsidizing the consumer token costs since the start. If the real cost would hit us, I doubt we’d see widespread AI adoptation. So new revenue streams are sorely needed to pull these companies out of red bottom lines. The signatories of the letter are not offering to build those data centers. They are offering you a 120Gb binary VRAM blob and a table of numbers that might help you to do some fine tuning. You can build your own datacenters. Big tech keeps the training secrets, the cloud rental revenue, and the chip partnerships. The consumer gets the electricity bill and the cooling problem.

This is not open source. It is open cost.

The letter ends with a flourish about “American technological leadership” and “shared prosperity.” Shared by whom is the question. The signatories include the same half dozen companies that control every layer of the stack (yeah and ok, DoorDash, apparently for some reason) and keep swapping the 10 trillion dollar I.O.U between themselves. They control the chips. the cloud. The models and their distribution. They are not asking for an open ecosystem. They are asking for regulatory cover to keep selling binary blobs while the rest of the world buys the hardware and builds the datacenters to run them.

Open source lowered barriers. Open weights shift them. Open weights are ultimately a good thing, but I doubt this play is done with good, open sourced intentions. Quite the contrary, I’d imagine.

Maybe I’m cynical and jaded. Maybe time will prove me wrong. Maybe.

Permalink: /blog/2026/07/26/Open/

HOWTO: Use Sonos Speakers as Audio Outputs on Debian 13

So I have bunch of SONOS speakers around the house and I wanted to use these from my Linux desktop machine, essentially just like I’d use them from Spotify Connect (selecting one of the SONOS speakers as output and that’s it).

Sonos speakers support AirPlay 2, and PipeWire — the default sound server on Debian 13 “Trixie” — has native AirPlay (RAOP) support.

That means you can make your Sonos speakers show up right in the system audio menu and route any application’s sound to them, no third-party software required.

Prerequisites

Everything needed ships with a standard Debian 13 desktop install:

  • PipeWire with pipewire-pulse and WirePlumber (the default audio stack)
  • libspa-0.2-modules (contains the RAOP modules; installed with PipeWire)
  • avahi-daemon running, for mDNS discovery — check with:
systemctl is-active avahi-daemon
  • Your PC and the SONOS speakers on the same network
  • If you run a firewall, allow incoming UDP on ports 6001 and 6002 (AirPlay timing/control traffic), e.g. sudo ufw allow 6001:6002/udp

Only Sonos models with AirPlay 2 work (roughly everything from the Sonos One and Beam onward). Older models would need a DLNA-based tool like pa-dlna instead.

Step 1: Enable AirPlay discovery in PipeWire

Create ~/.config/pipewire/pipewire.conf.d/raop-discover.conf:

context.modules = [
    { name = libpipewire-module-raop-discover }
]

Step 2: Restart PipeWire

systemctl --user restart pipewire pipewire-pulse

Step 3: Verify

List your audio sinks:

wpctl status

Each discovered speaker appears as a sink named after its Sonos room, e.g.:

├─ Sinks:
│      62. Office                              [vol: 1.00]
│      80. Built-in Audio Analog Stereo        [vol: 0.40]

They also show up in your desktop’s sound settings and audio menu. Select one and play something — expect a 1–2 second delay when the stream starts (AirPlay buffering), after which audio stays in sync.

To test from the terminal:

pw-play --target <sink-id> /usr/share/sounds/alsa/Front_Center.wav

Troubleshooting

Which speakers are on my network?

Sonos devices answer SSDP queries and expose a description XML on port 1400. Quick inventory with avahi (apt install avahi-utils):

avahi-browse -rt _raop._tcp     # AirPlay devices visible via mDNS

Or query a speaker directly if you know its IP:

curl -s http://<speaker-ip>:1400/xml/device_description.xml | grep -E 'roomName|modelName'

A speaker doesn’t appear in the sink list

PipeWire only creates sinks for speakers that Avahi discovers via multicast mDNS. On some networks (Wi-Fi access points with IGMP snooping, or speakers meshed over SonosNet) the multicast responses never reach your machine, even though the speaker is reachable directly.

The fix is to define the sink statically by IP. Create ~/.config/pipewire/pipewire.conf.d/raop-static-sonos.conf:

context.modules = [
    {   name = libpipewire-module-raop-sink
        args = {
            raop.ip = "192.168.1.50"          # the speaker's IP
            raop.port = 7000
            raop.name = "Kitchen"
            raop.transport = "udp"
            raop.encryption.type = "auth_setup"   # required for AirPlay 2
            raop.audio.codec = "PCM"
            stream.props = {
                node.name = "raop_sink.sonos_kitchen"
                node.description = "Kitchen (Sonos)"
            }
        }
    }
]

Two notes:

  • raop.encryption.type = "auth_setup" is essential. Discovered sinks pick this up automatically from mDNS, but static sinks default to none, and Sonos speakers reject unauthenticated streams.
  • Give the speaker a DHCP reservation on your router, since the config pins its IP.

Restart PipeWire again after editing.

A speaker appears but playback fails with “403 Forbidden”

If a sink exists but vanishes the moment you try to play to it, check the PipeWire log:

journalctl --user -u pipewire | grep -i raop

A 403 Forbidden reply to the RTSP handshake means the speaker has AirPlay access control enabled (acl=1 in its mDNS records). This happens when the speaker has been added to Apple Home with restricted access. You can fix it on the Apple side: in the Home app, go to Home Settings, then Speakers & TV Access, and choose “Anyone On the Same Network”.

Two sinks appear for the same speaker

Avahi sometimes reports a device twice (IPv4 and IPv6 cache entries) and create duplicate sinks. If it bothers you, pin discovery to specific devices with stream.rules in raop-discover.conf — match on raop.name (the MAC-prefixed mDNS service name) and use the rules to exclude duplicates or rename sinks:

context.modules = [
    {   name = libpipewire-module-raop-discover
        args = {
            stream.rules = [
                {   matches = [ { raop.name = "~804AF297F666@.*" } ]
                    actions = { create-stream = {
                        stream.props = { node.description = "Office (Sonos Era 100)" }
                    } }
                }
                {   matches = [ { raop.name = "!~804AF297F666@.*" } ]
                    actions = { create-stream = { } }
                }
            ]
        }
    }
]

With this small config change you get Sonos speakers as audio outputs, visible in the audio menu.

Permalink: /blog/2026/07/15/SONOS-on-Debian-13/

Second Brain

I recently tried Obsidian. Again. For maybe 7th time… inspired by someones youtube video about organized project documentation which has always been my nemesis. I like writing notes, with a paper and pen, but I’m a complete administrative catastrophy when taking notes or “drafting ideas” using digital devices. The “second brain” pitch is about capturing everything you read and think into Notion or Obsidian notes, organizing it with the right method, and an external mind should emerge.. one that makes you smarter, more creative, and (per the YouTube thumbnails) helps you run a six-figure business. There’s a book, a course, a certification program, and an entire ecosystem of tools and influencers built on the idea.

Every single one of these “second-brain systems” seems be focusing on how to easily capture notes and then magically by connecting them with (can you believe..) links, derive some kind of value out of it.

I have a bookmark folder called “New Stuff”. I put new links in there every now and then, but I hardly ever look at them, because it’s just easier to fire a new search for whatever I’m looking for. The folder has around 2500 bookmarks in it. “This looks interesting” link folder is hardly a second brain. But lot of the self-help videos seem to think there’s something valuable in this so maybe I just don’t get it.

There is, as far as I can find, no peer-reviewed study showing that second-brain systems improve learning, output, or anything else. The entire evidence base is testimonials, largely from people whose job is selling the method.

But there is some evidence pointing the other way. “Google effect” would indicate that in controlled experiments, people who believed a computer would store what they typed remembered significantly fewer facts than people who believed it would be erased. Your brain, perhaps quite rationally, doesn’t bother to keep what it believes is filed somewhere else. So a second brain maybe isn’t a “idea backup storage”. It’s basically an instruction to your first brain to zone out and take a break.

Saving a thing feels like learning the thing. I always feel “important” when I drag a new link into my “New Stuff” folder. But I don’t think I learn anything from it. It’s just a dopamine hit from doing something you believe is useful.

I’m sure there are many good use-cases for these systems if you’re an author or academic researcher but I’ve personally never really found any use for them. And I’ve been trying for years.

Of course now that we’re in the (sigh) AI era, it seems these systems are focused on pointing Claude Code or some MCP agent at your Obsidian vault and believing your second brain finally “comes alive” to run your business (why does everyone taking notes always have to aim for running a business?)

But sure. Maybe your AI session gets better context out of it. But if the whole point of your notes is that a machine reads them, your incentive to learn anything at all in your own brain drops to zero. You’re not building knowledge. You’re curating a prompt library while getting small dopamine hits because it feels useful and important.

When did you last retrieve a note that changed your project or code? If the honest answer is “I usually just Google it,” you don’t have a second brain. Maybe you just have a very organized way of avoiding your first one.

That’s how all my attempts have ended up so far. I’m pretty sure I’ll keep trying though because it sounds good. Help me understand this?

Permalink: /blog/2026/07/11/Second_Brain/

The Sovereignty Rant

So the US government decided Anthropic’s frontier models couldn’t be shared outside its borders. No deprecation notice. No migration guide. No apologetic status page with a little yellow icon. Just gone on a Friday, which is of course the only day anything ever breaks.

Sovereignty drags a lot of flag-waving baggage behind it. The engineering version of the word is much smaller and far less self-important. It has nothing to do with patriotism or “buy local to feel good.” It’s about whether a critical dependency can be yanked by someone who isn’t in the room and was never going to ask first.

These days, these critical dependencies stack up into layers, neatly enough to be reassuring right up until it isn’t. In relity, every layer is just a spot where someone else gets to throttle, meter, or just pull the plug.

At the top is the app and SaaS layer, the Microsoft 365s and Workspaces everyone swears they could migrate off any time now. Below that is the freshly arrived AI model layer and its APIs. Under that, cloud and compute, where most of Europe’s spend cheerfully flows to about three American companies. Below that, chips, governed by export rules that change with the mood. And at the bottom, connectivity, the satellites and subsea cables nobody thinks about until a Russian fishing trawler drags an anchor across the bottom of the ocean.

The AI-model layer is the new arrival. A year ago it wasn’t really on the register at all. Now half the stack depends on it and we’re all apparently fine with a single API call that can quietly vanish over a weekend. Just fine. No concerns. Our modern infrastructure has chokepoints, and whoever’s sitting on one gets to squeeze whenever it’s convenient.

The word “sovereign” is now stamped on basically every cloud and AI vendor homepage, usually next to a stock photo of a flag or a very secure-looking padlock. It’s the new “cloud-native.” A few years ago everything was cloud-native, including products that were just a VM in a trench coat. Last year everything was “AI-powered,” including a few things doing what was clearly a regex and a prayer. AI demand arrived (or was drummed up by the vendor hype machine) before anyone agreed what the word meant. The vacuum got filled with whatever definition was most flattering and least expensive to claim. The mechanics are pure greenwashing. Find a thing people want, find the cheapest way to look like it’s on offer, and get it onto the slide before legal wakes up.

The usual shape is depressingly consistent. A local datacenter gets stood up in some small far-away village with a promise of tech jobs, a stack of compliance certs gets collected, and the whole thing gets christened a “sovereign cloud.” But where data physically lives and who has authority over it are two completely different questions. If the company running it is headquartered somewhere whose laws can compel it to hand over data or cut access, the location of the disk is a charming detail and nothing more. The CLOUD Act and FISA 702 are the usual party guests. It’s sovereign the way a rental car is “your car” right up until someone with more authority and a clipboard wants the keys back.

The EU’s shiny new cloud-and-AI law comes with four whole tiers of “sovereignty assurance,” which is about three more tiers than anyone actually wanted. Only the top tier actually keeps non-EU providers out. Everything below it lets the usual hyperscalers waltz in, provided their home country counts as “aligned enough,” a phrase doing an Olympic amount of deadlifting in this context. Some of the “sovereign” contracts already going out are landing with joint ventures that politely include the exact foreign giants the whole exercise was meant to reduce dependence on.

And for the all-time cautionary tale, there’s Gaia-X. A 2019 push for a sovereign European cloud. Spectacular volume of diagrams, working groups, and press releases. Almost nothing in production. Not for lack of engineering talent, but because the setup was voluntary, fragmented, and quietly steered by the very incumbents it was supposed to dethrone. Turns out asking the foxes to help design the chicken coop fence has a predictable result.

The small mercy is that telling real from snake-oil doesn’t require a law degree.

Can a foreign government or a vendor’s HQ cut access overnight, and has it already happened to some other poor soul? Who holds the encryption keys and who can be quietly compelled to produce them? Closed API, or open weights that actually run in-house? Not where the datacenter lives but who genuinely owns the company operating it? Whether there’s a tested exit plan or just a slide that confidently says “multi-cloud” and means nothing? And where the money actually goes? Because the spend is either building real capability or just renting someone else’s platform with a local flag sticker slapped on the side.

Failing one of those isn’t a dealbreaker. Having no answer at all, not being able to describe the blast radius, that’s already a hole in the floor.

For language models specifically, the options tend to collapse into three, and every one of them comes with a catch.

US closed frontier models are the most capable. The catch is the switch lives in someone else’s hand, possibly someone who tweets or uses too much orange tan spray. Chinese open-weight models like Qwen and Kimi are cheap to the point of being almost suspicious, auditable, and happy to run locally. The catch is the censorship, the narrative baggage, and a brand new dependency to replace the old one. Building European models, Mistral and the various public-sector efforts, gives genuine control. The catch is it’s slower and costs real money, two things committees love.

We need to stop picking a country and start picking an architecture. Open weights on owned infrastructure can’t be killed from a distance. That property holds no matter whose flag the model shipped under. The capability gap is closing fast too. The distance between the best open model and the closed frontier went from about a year to a few months, and on coding they’re basically neck and neck. The strongest open weights right now are mostly Chinese, and no amount of squinting changes that. Open weights still mean the thing can be run locally regardless of origin.

Downloading a model is the easy bit. It’s basically a git clone and some disappointment about your available VRAM. Knowing whether it’s safe to point at a bank, a hospital, or a government workflow is actual engineering, and it’s the part almost nobody has bothered to fund.

Evaluation, red-teaming, regression-testing a model before it gets anywhere near production should be the standard. The EU’s AI Act waves vaguely in this direction for the most capable models, but the in-house muscle to actually do any of it is thin to nonexistent, and nobody seems particularly bothered about that part. Sovereignty without an evaluation pipeline isn’t sovereignty. It’s running a stranger’s 120Gb binary as root and calling it strategy.

The reflexive response to all this is a world-weary shrug. The argument goes that EU catching up is hopeless, so the grown-up move is to negotiate decent terms and make peace with the dependency. It sounds like realism.

Airbus, GSM, and Galileo all looked adorably naive at the start and all turned out fine. These are all projects that had mandated demand and a long horizon. The Gaia-X flop had a voluntary consortium and a lovely set of intentions.

None of this requires becoming a policy person or saying “strategic autonomy” out loud in meetings. Most of it is the instinct already applied to tech everywhere; we just need to drag up those old desogns and apply it to the AI-layer. Nothing has really changed.

At the team level, spending some time thinking and writing down what actually happens if a given vendor/model vanishes tends to be clarifying, in the way a cold shower is clarifying. “Critical AI” and cloud dependencies get treated like SaaS subscriptions when they should be treated like infrastructure supply. Reserves, redundancy, and an exit plan that has been tested rather than merely promised.

And all of this lands back on the off switch. Sovereignty isn’t about isolation or flags. It’s the ability to keep running when someone an ocean away changes their mind on a Friday afternoon. That’s it. That’s the whole ask.

Permalink: /blog/2026/06/16/Sovreignity/