Sign in

nigel kersten

@etwoy.net
999 followers 979 following 209 posts

🇦🇺🇺🇸🇬🇧 immigrant in tech electronic music dilettante, lover of bass music, devotee of the justified ancients of mu mu

PostsRepliesMedia
nigel kersten @etwoy.net · 21/07/2026
Look, as an Australian I understand water is a precious commodity. What I do resent is Thames Water imposing a hosepipe ban on households trying to grow vegetation to improve shade while failing to invest to fix pipe leakages and paying out millions in bonuses. Absolutely criminal behaviour.
210
nigel kersten @etwoy.net · 27/06/2026
We’re all thermodynamics experts now.
020
nigel kersten @etwoy.net · 21/06/2026
Thanks BA!
Mail from British airways. 

Important information about your
flight to Nice
Booking Reference:
Dear Customer,
Please replace with content
030
nigel kersten @etwoy.net · 21/06/2026
Dying at this snippet of the dutch coach celebrating while the crowd squeals.
010
Reposted by nigel kersten
Matt Webb 🌸🌼🌸 @genmon.fyi · 17/06/2026
I can’t stop thinking about this ad, absolutely wild aesthetic
3111
nigel kersten @etwoy.net · 19/06/2026
C’mon Aussie C’mon! (Arsenal shirt there for luck)
110
Reposted by nigel kersten
Tom Cox @dj-acid-reflux.bsky.social · 11/06/2026
THREAD. A few years ago, my dad was surprised to find a small toad had wandered into his porch and took up residence in one of the old shoes he liked to wear for gardening tasks. This led to more drama than might've been anticipated... www.tom-cox.com/my-dad-and-t...
A toad, sitting what appears to be calmly in an old loafer in my parents' porch, while in fact planning how to gradually move up the hierarchy of the local community and into an influential position in local government.
1333188
nigel kersten @etwoy.net · 11/06/2026
It turns out that after 7 years of being fully work-from-home, 90% of your work clothing is just from the waist up.
220
nigel kersten @etwoy.net · 06/06/2026
Why does Vinted make me pick one of two genders for a backpack? You can pick unisex afterwards but it just always feels dumb as hell.
020
nigel kersten @etwoy.net · 04/06/2026
TIL that white eggs come from hens with white feathers and brown eggs come from hens with red feathers.
static.klipy.com
Two Chickens
ALT: Two Chickens
000
Reposted by nigel kersten
Dustin Moskovitz @moskov.goodventures.org · 03/06/2026
these new multimodal system prompts are really strong
071
nigel kersten @etwoy.net · 03/06/2026
open.substack.com/pub/charityd... Love this piece from @charity.wtf - let’s work on the feedback loops!
open.substack.com
AI enthusiasts are in a race against time, AI skeptics are in a race against entropy
Both sides are grappling with a real existential threat, and both sides feel like they are screaming into the void. Here's how to close the gap and get everyone pulling in the same direction.
120
nigel kersten @etwoy.net · 30/05/2026
The way coding agents can flail around trying to fix CSS layout issues is the most humanising thing about them.
static.klipy.com
Chainsaw Man: He Just Like Me FR!
ALT: Chainsaw Man: He Just Like Me FR!
050
nigel kersten @etwoy.net · 29/05/2026
www.aboutamazon.com/stories/aws-... Even through the PR sheen, this is a fascinating story.
aboutamazon.com
The radical network redesign that led AWS to forge a more resilient cloud
How a Slack shout-out, a dusted-off academic theory, and a spaghetti monster led an AWS team to crack an elusive code—and deliver greater reliability and performance for customers.
030
Reposted by nigel kersten
Torsten Bell @torstenbell.bsky.social · 27/05/2026
Blair putting on full display what is in many ways his special ability - to lay out a political argument grounded in his own view of global trends (globalisation in the 2000s, tech in the 2020s). But… institute.global/insights/pol...
institute.global
The Labour Party Is Playing With Fire Over Its Future and the Future of the Country
In this essay, Tony Blair sets out the need for a new agenda for Britain.
34497175
Reposted by nigel kersten
Tom Cox @dj-acid-reflux.bsky.social · 22/05/2026
When I used to write for The Guardian, every time I wrote the word “meow” the editors would change it to “miaow”. It used to really get on my wick. Don’t try to make my cats sound like your upper middle class London cats, you fuckers. My cats did not go to your posh cat schools. They say “meow”.
974673659
nigel kersten @etwoy.net · 22/05/2026
The rampant fearmongering that folks like Lenny and Elena are doing around product management right now is getting in the way of people working out how to actually evolve their roles. Distasteful.
I Lenny's Newsletter
You'll lose your job in 2027.
Assume that your current role is close to its expiration date.
031
nigel kersten @etwoy.net · 21/05/2026
Meme of cat driving car with text: Me listening to Ministry and Skinny Puppy while driving to Trader Joe's to get oat milk and cauliflower gnocchi...
060
Reposted by nigel kersten
Tits McGee @scientits.bsky.social · 21/05/2026
Less than a decade ago
Guardian article from 2017

Theresa May plans to let people change gender without medical checks

Speaking at Pink News awards dinner, prime minister reiterates her commitment to improving trans rights

Photo of May, with caption: Theresa May delivers a speech at the Pink News awards held at One Great George Street, London.
132554580
Reposted by nigel kersten
Nathaniel C. Green @nathanielcgreen.bsky.social · 20/05/2026
The key to being a good scholar or teacher, the key to being a good anything, really, is wanting to be with people. There are a lot of people out there who are terrible scholars and teachers because they don't like people and want nothing to do with them.
0316
Reposted by nigel kersten
Chris Short @chrisshort.net · 21/05/2026
Microsoft surprises with its first server Linux distribution: Azure Linux 4.0 #devopsish
zdnet.com
Microsoft surprises with its first server Linux distribution: Azure Linux 4.0
You'll be able to run this Linux distro on both Azure and your desktop using Windows Subsystem for Linux. Here's what we know about it so far.
122
nigel kersten @etwoy.net · 21/05/2026
Boo Michelin, boo! www.theguardian.com/food/2026/ma...
theguardian.com
‘We feel let down’: sustainable chefs in UK mourn end of Michelin green star
Guide retires award for eco-friendly practices – and says restaurants will no longer be able to advertise they have it
010
nigel kersten @etwoy.net · 19/05/2026
*exhales properly for the first time in months*
110
nigel kersten @etwoy.net · 19/05/2026
Ah May, the London month where I pull out my transitional wool clothing to work out which ones have provided tasty meals for clothes moths. If anything drives me to going full gorpcore synthetic fabrics, it's going to be the bloody moths here.
030
nigel kersten @etwoy.net · 19/05/2026
Baudrillard is not entirely unproblematic, but I do love these quotes interspersed amongst my timeline.
131
nigel kersten @etwoy.net · 19/05/2026
2SER is a goddamn cultural institution!
1196
nigel kersten @etwoy.net · 18/05/2026
That famed English directness.
Article screenshot from The Guardian 

Text is: 

35m ago 11.32 BST
Josh Simons formally resigns from parliament, paving way for Makerfield byelection
Josh Simons has this morning formally resigned as MP for Makerfield.
The Treasury has confirmed the news this morning. In a good example of how British politics can be utterly baffling to outsiders, it has put out a press release saying Simons has been appointed as "steward and bailiff of the Three Hundreds of Chiltern"
This is a job that does not actually exist. But many years ago it did, and anyone who held the post was no longer allowed to serve as an MP. So this is the Treasury signalling Simons is out of parliament - although nowhere in the press release does it actually
020
Reposted by nigel kersten
Camille Fournier @skamille.themanagerswrath.com · 17/05/2026
I enjoyed reading this mikefisher.substack.com/p/there-are-...
mikefisher.substack.com
There Are Always More of Them Before They Are Counted
Why the SaaS apocalypse probably is not one
0212
Reposted by nigel kersten
Bronwen Scott @snailseyeview.bsky.social · 10/03/2025
We’ve looked at snails with one shell and slugs with no shells. Now let’s have a look at a snail with two shells, because Nature laughs at our puny attempts to pigeonhole. In today’s #AtoZ – J is for Julia (Juliidae) (1/9) Pic: © uwkwaj CC BY-NC
Small, perky snail with head poking out between its two shells. The snail has a pair of long, tubular tentacles. The shells are like clam shells, except they are vivid green. The hinge is at the top. 

Julia exquisita: Kwajalein Atoll, Marshall Islands. © uwkwaj CC BY-NC https://www.inaturalist.org/photos/166680082In this photo, the snail is lying on its side with the hinge of the two shells pointing towards the camera. The shell and snail are both very bright green. The snail has white blotches on its back. 

Julia exquisita: Kwajalein Atoll, Marshall Islands. © uwkwaj CC BY-NC https://www.inaturalist.org/photos/263219540
271150386
Reposted by nigel kersten
Diane Duane @diane.dianeduane.com · 14/05/2026
Spotted on Tumblr…
Screenshotted tweet:”If people are fighting for an orb you are reading fantasy. If people are fighting fir a cube you are reading sci-fi. If it gas more sides than that. I dont know. I dont know man.”
230130483066
nigel kersten @etwoy.net · 15/05/2026
Next step to the UK rejoining the EU is to shamelessly pander to the EU superpowers in our Eurovision entry: www.youtube.com/watch?v=8XR2...
youtube.com
LOOK MUM NO COMPUTER - Eins, Zwei, Drei - Official Music Video
YouTube video by LOOK MUM NO COMPUTER
000
nigel kersten @etwoy.net · 14/05/2026
closing 20 Finder windows I didn't realise were open while a tear rolls down my wrinkled cheek at the memory of the Spatial Finder.
010
Reposted by nigel kersten
Jill Walker Rettberg @jilltxt.bsky.social · 13/05/2026
Genre glitching: a new sign of AI-assisted writing? Thanks to @doremus-schafer.bsky.social and @srettberg.bsky.social who shared the two examples of this that I discuss in today's blog post. Please please please send me any other examples you see of this! jilltxt.net/genre-glitch...
jilltxt.net
Genre glitches and unexpected promotional phrases as a sign of AI writing
A genre glitch is a characteristic of LLM-assisted writing where the text suddenly switches genre, typically inserting a short promotional phrase full of sensory details into an informational text.…
14514186
Reposted by nigel kersten
Jim Pickard @pickardje.bsky.social · 14/05/2026
we only know about the £5m Harborne donation thanks to journalists at the Guardian, but sure trash the MSM for clicks
22816129
nigel kersten @etwoy.net · 13/05/2026
today is a Carter USM day www.youtube.com/watch?v=iQXR...
youtube.com
Carter U.S.M. - Sheriff Fatman
YouTube video by CarterUSMMusicVEVO
010
Reposted by nigel kersten
arseblog @arseblog.com · 12/05/2026
"If you say it enough times, people will believe it whether it's true or not" – from Arsecast Extra 694 with @gunnerblog.bsky.social, out now in all the usual places
1619323
Reposted by nigel kersten
Matt Blair @mjmbca.bsky.social · 13/05/2026
Not for nothing, but I think a lot of people have wrongly settled on “Twitter became a right-wing cesspool because all the cool people left” instead of “All the cool people left because Twitter became a right-wing cesspool.”
56028974
Reposted by nigel kersten
daniel:// stenberg:// @bagder.mastodon.social.ap.brid.gy · 11/05/2026
#Mythos finds a #curl vulnerability yes, as in singular one. daniel.haxx.se/blog/2026/05/11/myth…
daniel.haxx.se
Mythos finds a curl vulnerability
yes, as in singular _one_. Back in April 2026 Anthropic caused a lot of media noise when they concluded that their new AI model _Mythos_ is _dangerously good_ at finding security flaws in source code. Apparently Mythos was so good at this that Anthropic would not release this model to the public yet but instead trickle it out to a selected few companies for a while to allow a few good ones(?) to get a head start and fix the most pressing problems first, before the general populace would get their hands on it. The whole world seemed to lose its marbles. Is this the end of the world as we know it? An amazingly successful marketing stunt for sure. ## My (non-) access Part of the deal with _project Glasswing _was that Anthropic also offered access to their latest AI model to “Open Source projects” via Linux Foundation. Linux Foundation let their project Alpha Omega handle this part, and I was contacted by their representatives. As lead developer of curl I was offered access to the magic model and I graciously accepted the offer. Sure, I’d like to see what it can find in curl. I signed the contract for getting access, but then nothing happened. Weeks went past and I was told there was a hiccup somewhere and access was delayed. Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report. To me, the distinction isn’t that important. It’s not that I would have a lot of time to explore lots of different prompts and doing deep dive adventures anyway. Getting the tool to generate a first proper scan and analysis would be great, whoever did it. I happily accepted this offer. (I am purposely leaving out the identity of the individual(s) involved in getting the curl analysis done as it is not the point of this blog post.) ## AI scans of curl Before this first Mythos report, we had already scanned curl with several different very capable AI powered tools (I mean _in addition to_ running a number of “normal” static code analyzers all the time, using the pickiest compiler options and doing fuzzing on it for years etc). Primarily AISLE, Zeropath and OpenAI’s Codex Security have been used to scrutinize the code with AI. These tools and the analyses they have done have triggered somewhere between _two and three hundred_ bugfixes merged in curl through-out the recent 8-10 months or so. A bunch of the findings these AI tools reported were confirmed vulnerabilities and have been published as CVEs. Probably a dozen or more. Nowadays we also use tools like GitHub’s Copilot and Augment code to review pull requests, and their remarks and complaints help us to land better code and avoid merging new bugs. I mean, we still merge bugs of course but the PR review bots regularly highlight issues that we fix: our merges would be worse without them. The AI reviews are used _in addition_ to the human reviews. They help us, they don’t replace us. We also see a high volume of high quality security reports flooding in: security researchers now use AI extensively and effectively. Security is a _top_ _priority_ for us in the curl project. We follow every guideline and we do software engineering properly, to reduce the number of flaws in code. Scanning for flaws is just one of many steps to keep this ship safe. You need to search long and hard to find another software project that makes as much or goes further than curl, for software security. Steps involved in keeping curl secure ## May 6, 2026 It was with great anticipation we received the first source code analysis report generated with Mythos. Another chance for us to find areas to improve and bugs to fix. To make an even better curl. This initial scan was made on curl’s git repository and its master branch of a certain recent commit. It counted 178K lines of code analyzed in the src/ and lib/ subdirectories. The analysis details several different approaches and methods it has performed the search, and how it has focused on trying to find which flaws. A fun note in the top of the report says: > curl is one of the most fuzzed and audited C codebases in existence (OSS-Fuzz, Coverity, CodeQL, multiple paid audits). Finding anything in the hot paths (HTTP/1, TLS, URL parsing core) is unlikely. … and it correctly found no problems in those areas. Completely unscientific poll on Mastodon about people’s expectations for Mythos scanning curl ## The size of curl curl is currently 176,000 lines of C code when we exclude blank lines. The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece. On average, every single production source code line of curl has been written (and then rewritten) 4.14 times. We have polished on this. Right now, the existing production code in git master that still remains, has been authored by 573 separate individuals. Over time, a total of 1,465 individuals have so far had their proposed changes merged into curl’s git repository. We have published 188 CVEs for curl up until now. curl is installed in over _twenty million instances_. It runs on over _110 operating systems_ and _28 CPU architectures_. It runs in every smart phone, tablet, car, TV, game console and server on earth. ## Five findings became one The report concluded it found **five** “Confirmed security vulnerabilities”. I think using the term _confirmed_ is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take. Five issues felt like nothing as we had expected an extensive list. Once my curl security team fellows and I had poked on the this short list for a number of hours and dug into the details, we had trimmed the list down and were left with _one_ confirmed vulnerability. The other four were three false positives (they highlighted shortcomings that are documented in API documentation) and the fourth we deemed “just a bug”. The single confirmed vulnerability is going to end up a _severity low_ CVE planned to get published in sync with our pending next curl release 8.21.0 in late June. The flaw is not going to make anyone grasp for breath. All details of that vulnerability will of course not get public before then, so you need to hold out for details on that. The Mythos report on curl also contained a number of spotted bugs that it concluded were not vulnerabilities, much like any new code analyzer does when you run it on hundreds of thousands of lines of code. All the bugs in the report are being investigated and one bye one we are fixing those that we agree with. All in all about twenty bugs that are described and explained very nicely. Barely any false positives, so I presume they have had a rather high threshold for certainty. curl is certainly getting better thanks to this report, but counted by the volume of issues found, all the previous AI tools we have used have resulted in larger bugfix amounts. This is only natural of course since the first tools we ran had many more and easier bugs to find. As we have fixed issues along the way, finding new ones are slowly becoming harder. Additionally, a bug can be small or big so it’s not always fair to just compare numbers ## Not particularly “dangerous” My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing. This is just _one_ source code repository and maybe it is much better on other things. I can only tell and comment on what it found here. ## Still very good But allow me to highlight and reiterate what I have said before: AI powered code analyzers are _significantly_ better at finding security flaws and mistakes in source code than any traditional code analyzers did in the past. All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real. Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others. Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find. ## How AI analyzers differ * They can spot when the comment says something about the code and then conclude that the code does not work as the comment says. * It can check code for platforms and configurations we otherwise cannot run analyzers for * It “knows” details about 3rd party libraries and their APIs so it can detect abuse or bad assumptions. * It “knows” details about protocols curl implements and can question details in the code that seem to violate or contract protocol specifications * They are typically good at summarizing and explaining the flaw, something which can be rather tedious and difficult with old style analyzers. * They can often generate and offer a patch for its found issue (even if the patch usually is not a 100% fix). ## More details from the report **Zero memory-safety vulnerabilities found.** Methodology note: this review is hand-driven analysis using LLM subagents for parallel file reads, with every candidate finding re-verified by direct source inspection in the main session before being recorded. The CVE to variant-hunt mapping was built from curl’s own vuln.json. No automated SAST tooling was used. This outcome is consistent with curl’s status as one of the most heavily fuzzed and audited C codebases. The defensive infrastructure (capped dynbufs everywhere, `curlx_str_number` with explicit max on every numeric parse, `curlx_memdup0` overflow guard, CURL_PRINTF format-string enforcement, per-protocol response-size caps, pingpong 64KB line cap) systematically closes the bug classes that would normally be productive in a codebase this size. Coverage now includes: all minor protocols, all file parsers, all TLS backends’ verify paths, http/1/2/3, ftp full depth, mprintf, x509asn1, doh, all auth mechanisms, content encoding, connection reuse, session cache, CLI tool, platform-specific code, and CI/build supply chain. ## AI finds existing kinds of errors It should be noted that the AI tools find the usual and established kind of errors we already know about. It just finds new instances of them. We have not seen any AI so far report a vulnerability that would somehow be of a novel kind or something totally new. They do not reinvent the field in that way, but they do dig up more issues than any other tools did before. ## More to find These were absolutely not the last bugs to find or report. Just while I was writing the drafts for this blog post we have received more reports from security researchers about suspected problems. The AI tools will improve further and the researchers can find new and different ways to prompt the existing AIs to make them find more. We have not reached the end of this yet. I hope we can keep getting more curl scans done with Mythos and other AIs, over and over until they truly stop finding new problems. ## Credits Thanks to Anthropic and Alpha Omega for providing the model, the tools and doing the scan for us. Thanks also to the individual who did the scan for us. Much appreciated! Top image by Jin Kim from Pixabay Thanks for flying curl. It’s never dull.
7247121
Reposted by nigel kersten
Angri Bundel @anibundel.com · 11/05/2026
We lost Douglas Adams 25 years ago today. This has made a lot of people very sad and has been widely regarded as a bad move.
136110442907
nigel kersten @etwoy.net · 12/05/2026
Merlin, the Cornell Uni bird identification app feels like the old internet we were trying to create. merlin.allaboutbirds.org
merlin.allaboutbirds.org
Merlin Bird ID - Home
Identify Bird Songs and Calls Sound ID listens to the birds around you and shows real-time suggestions for who’s singing. Compare your recording to the songs and calls in Merlin to confirm what you...
130
nigel kersten @etwoy.net · 12/05/2026
Graham is doing super interesting stuff here that will be of interest to the more architecturally minded amongst you!
232
Reposted by nigel kersten
Levi Stahl @levistahl.bsky.social · 11/05/2026
Man, two all-timers in the space of a month. Nice job, New Yorker cartoon editors. The idea of this one is brilliant, but the execution is maybe even more so—getting the figure in the coffin to read both ways like it’s supposed to is something.
A cartoon by Paul Noth from the most recent New Yorker. It shows a coffin. On one side is an anthropomorphic rabbit in windows weeds. On the other a duck in same. In the coffin is a duck, or a rabbit, depending on how you look at the head, which is the simple head from the classic “is it a duck or a rabbit?” drawing.
101392425
Reposted by nigel kersten
Peter Orlowicz @peterorlowicz.bsky.social · 11/05/2026
Slightly increase a band. Crosby, Stills, Nash, and Middle-Aged
081
nigel kersten @etwoy.net · 11/05/2026
Started experimenting with Bevel for health insights and needed to add some context after it started quizzing me about an elevated heart rate. #COYG
Bevel AI chat screenshot explaining elevated heart rate due to Arsenal match Bevel AI chat screenshot explaining elevated heart rate due to Arsenal match
020
nigel kersten @etwoy.net · 07/05/2026
Squirrels loving the neighbours bird feeder. Birds loving being able to just forage for scraps on the ground.
Squirrel heads deep in bird feeder while two large pigeons eat feed off the ground
000
nigel kersten @etwoy.net · 06/05/2026
*squints*
Claude status page with lots of red and green Colourblind test image that says fuck the colour blind
173
nigel kersten @etwoy.net · 05/05/2026
Sometimes prompt engineering makes me wonder whether we’re doing retro phrenology as described by the dear Terry Pratchett. “It works like this. Phrenology, as everyone knows, is a way of reading someone's character, aptitude and abilities by examining the bumps and hollows on their head.”
130
nigel kersten @etwoy.net · 03/05/2026
Reddit has always been somewhat of a cesspool until you put effort into curating it, but after 20 years I think I’m done. AI slop has destroyed the vast majority of subreddits I care about.
120
nigel kersten @etwoy.net · 03/05/2026
This would be less terrifying if I hadn’t been watching The Boys.
111
nigel kersten @etwoy.net · 02/05/2026
Tribute DJs. I guess it was inevitable… www.sirmagazine.co.uk/features/fat...
sirmagazine.co.uk
The 4am Idea That Became Fatboy Tim
Hawaiian shirts, barefoot sets, and a selfie Norman Cook asked for. Tim Davies on two decades as the world's first, and maybe only, tribute DJ
000