Sign in

Shafik Yaghmour

@shafik.bsky.social
1K followers 242 following 882 posts

Compiler Engineer clang front end. Interests: C++, C, and undefined behavior. Martial Artist, Book Worm and Dad. he/him Mastodon: hachyderm.io/@shafik Blog: shafik.github.io #cplusplus #compilers

PostsRepliesMedia
Shafik Yaghmour @shafik.bsky.social · 6h
Oh right, it is also time to start posting Halloween themed C++ jokes again #cplusplus
000
Shafik Yaghmour @shafik.bsky.social · 23h
"How to hide your spending habits from retailers (so you don't get ripped off)": www.npr.org/2026/09/29/n... This honestly should just be banned but until we can convince our lawmakers to do that this is what you need to do. Yet more work for already pressed consumers.
npr.org
How to hide your spending habits from retailers (so you don't get ripped off)
Companies have changed the way they price their products — and shoppers are getting deliberately overcharged. Here are steps you can take to ensure you are getting the best deal.
101
Shafik Yaghmour @shafik.bsky.social · 29/09/2026
As someone who does a lot of code review Github is an awful tool for code review. Code review is the bottleneck and yet the ergonomics of GH for code reviews is awful.
210
Shafik Yaghmour @shafik.bsky.social · 29/09/2026
Via Bloomberg Opinions
Consider DraftKings. A recent New York Times investigation found that its machine-learning model scored customers by how much money they would lose for each free bet or bonus they received. Surprise surprise, the “best investment” for the gambling site was a person addicted to gambling!
000
Shafik Yaghmour @shafik.bsky.social · 28/09/2026
"Five More Cops Charged for Abusing Flock Cameras Amid So Many Similar Scandals That We Can’t Even Keep Track": futurism.com/future-socie... When your system does not have accountability built in abuse will follow. This should be automatic job loss ..
futurism.com
Five More Cops Charged for Abusing Flock Cameras Amid So Many Similar Scandals That We Can't Even Keep Track
The rise of automatic license plate readers has unleashed an unprecedented tide of high-tech surveillance and harassment.
110
Shafik Yaghmour @shafik.bsky.social · 27/09/2026
Reading “The Unaccountability Machine” “*The phrase 'the best and the brightest' is often used by people who don't know that its original context was ironic. It entered the language as the title of David Halberstam's book about the policy mistakes of the Vietnam War.”
010
Shafik Yaghmour @shafik.bsky.social · 27/09/2026
"Weekend Update: Anthropic CEO Dario Amodei on A.I.’s Threat to Humanity - SNL": www.youtube.com/watch?v=-Nvn... #ai
youtube.com
Weekend Update: Anthropic CEO Dario Amodei on A.I.’s Threat to Humanity - SNL
YouTube video by Saturday Night Live
000
Shafik Yaghmour @shafik.bsky.social · 27/09/2026
"Dune Has No Aliens | Here's the Disturbing Reason Herbert Left Them Out": www.youtube.com/watch?v=KrUY... I have read most of the series and this is my take away as well. Like PK Dick Herbert was ahead of his time in many ways. #books
Herbert's whole thesis in one line: he didn't think the scariest thing in the universe was a creature from another world — he thought it was a human being with power. Do you think a story is scarier with an external monster, or with no one to blame but ourselves?
020
Shafik Yaghmour @shafik.bsky.social · 26/09/2026
So while it is not common, even if you are vaccinated you can catch measles. It just happened recently to someone riding in a train with a sick person: www.kqed.org/news/1210133... As herd immunity breaks down this will happen more often.
kqed.org
Recent Measles Case Highlights Difficulty in Tracking Disease | KQED
Here are the morning's top stories on Friday, September 25, 2026 Health officials search for possible exposures from recent measles case A person was hospitalized with measles earlier this month after...
130
Shafik Yaghmour @shafik.bsky.social · 26/09/2026
"GAO Pegs Annual U.S. Tax Fraud Losses at $116B to $304B": www.briefs.co/news/gao-peg... Note the higher number is 1/6th of total US deficit 🤔
briefs.co
GAO: U.S. Tax Fraud Costs $116B-$304B Annually
GAO finds annual tax fraud drains $116B-$304B (2-6% of taxes), urges IRS anti-fraud strategy and coordination.
000
Shafik Yaghmour @shafik.bsky.social · 23/09/2026
"Big AI to humanity: drop dead": matthewbutterick.com/chron/drop-d... This is the most sane piece discussing how to think about the dangers AI I have read. It address a lot of legal aspects as well as the numerous conflicts on interests in the solutions being suggested. #ai
Big AI believes they should not be held account­able for the conse­quences of their AI systems because these systems are unpre­dictable and perhaps uncon­trol­lable. A certain AI researcher said of recent AI hacking inci­dents: “AI agents … took actions that would be consid­ered as crimes if a human took them”—seem­ingly taking it as axiomatic that these were not human-controlled activ­i­ties and there­fore cannot qualify as crimes. But they were and they do. This outra­geous posi­tion inverts decades of US law about dangerous items gener­ally and computer hacking in partic­ular (e.g., the 1986 Computer Fraud and Abuse Act). So let’s call this narra­tive what it is: an attempt to thwart the rule of law. Indi­vidual human program­mers have been sentenced to prison for far less than what AI compa­nies have done recently. This relates to what I foresaw in 2023:

If AI compa­nies are allowed to market AI systems that are essen­tially black boxes … we will not dele­gate deci­sions to AI systems because they perform better. Rather, we will dele­gate deci­sions to AI systems because they can get away with every­thing that we can’t. … [W]e could end up with some­thing truly novel: tech­nology systems that deserve much higher levels of legal scrutiny (because of the conse­quen­tiality of their outputs) but simul­ta­ne­ously resist such scrutiny (because of the opacity of their inputs and reasoning).Big AI believes that the burden is on govern­ment and citi­zens to affir­ma­tively stop Big AI from proceeding. Since overtly opposing regu­la­tion is a bad look, Big AI CEOs have occa­sion­ally made noises about being open to regu­la­tion. As one AI CEO said recently: “We must slow the pace at which we improve the capa­bil­i­ties of AI models.” But as Big AI is well aware, there’s no chance of AI-specific domestic laws or inter­na­tional treaties being enacted soon enough to matter. Indeed, the same AI CEO blamed democ­racy for not meeting his KPIs: “[u]nfor­tu­nately, passing laws can take time”. A widely signed March 2023 letter sought to pause AI research; like all chain letters, it accom­plished nothing. After a genuine AI cata­strophe arrives, we can be sure these same AI CEOs will say “gosh—why didn’t you make us stop?”
011
Shafik Yaghmour @shafik.bsky.social · 23/09/2026
Fermi, Newton and Pascal are playing hide and seek Fermi is it, he counts to 100 and turns around He seeing Newton standing in a 1 square meter chalk box Fermin says "Newton, your out!" Newton says, "No, I am Newton in a square meter, I'm a Pascal, Pascal is out" #physics
041
Shafik Yaghmour @shafik.bsky.social · 21/09/2026
Reading “The Unaccountability Machine”
So the crucial thing at work here seems to be the delegation of the decision to a rule book, removing the human from the process and thereby severing the connection that's needed in order for the concept of accountability to make sense. You could even coin a sort of law of management here:
The fundamental law of accountability: the extent to which you are able to change a decision is precisely the extent to which you can be accountable for it, and vice
versa.
The construction of accountability sinks has damaging implications for the flow of information. For an accountability sink to function, it has to break a link; it has to prevent the feedback of the person affected by the decision from affecting the operation of the system. The decision has to be fully determined by the policy, which means that it cannot be altered by any information that wasn't anticipated. If somebody can override the accountability sink and overrule a policy that is in danger of generating a ridiculous or disgusting outcome, then that person is potentially accountable for the outcome.
000
Shafik Yaghmour @shafik.bsky.social · 21/09/2026
Reading “The Unaccountability Machine”
But in a space of time only slightly longer than a single human lifespan, we've created an entirely new kind of organ-isation. A very important consequence of industrialisation is that it breaks the connection between the worker and the product. A machine operator can't point to something and say
'I made that' in the way that a blacksmith can. So when our managers, administrators and bureaucrats are converted into operators of an industrialised decision-making machine, why would we expect them to feel any personal responsibility for the machine's output?
In principle, people can still overrule the systems in the interests of fairness - but the incentives all go in the other direc-tion. Our organisations are set up to deliver lots of decisions, quickly, cheaply and with reasonable quality - on average. But that's the problem; you can't be fair to an average. You have to deal with individual people. So we have a world in which almost everyone is quite frequently subject to stupid decisions that they can't appeal against. And where the person who seems to
010
Shafik Yaghmour @shafik.bsky.social · 18/09/2026
I read this paragraph and all I could think of was: www.youtube.com/watch?v=u0aK...
For most diners, the difference between a 7 1/4 ounce burger and an 8 ounce one is hard to tell. Trimming the size of burger patties is one way restaurants are adjusting to surging beef prices.
000
Shafik Yaghmour @shafik.bsky.social · 17/09/2026
"Nation's most wind-powered state turns to coal as data centers increase energy demand": www.planetizen.com/news/2026/09... #ai
planetizen.com
Nation's most wind-powered state turns to coal as data centers increase energy demand
For the first time in decades, Iowa has increased its generation of coal power.
000
Shafik Yaghmour @shafik.bsky.social · 16/09/2026
"Employers are using your personal data to figure out the lowest salary you'll accept": www.morningstar.com/news/marketw... This should outright just be illegal, everyone should write their representatives and express how outrageous this is.
A growing number of employers are using surveillance wages to negotiate your next paycheck

Algorithms are increasingly using personal data to determine the minimum pay a worker is willing to accept, consumer watchdogs say.

You've likely already felt the digital sting of "surveillance pricing." It might look like an airline advertising a specific fare bundle because a customer's loyalty-program data suggests they're likely to buy it, or a website charging more for infant formula because an algorithm sensed the desperation of a new parent.

We're living in a world where your purchase history, browsing speed and even your ZIP code increasingly dictate the cost of your life. And as companies get better at collecting and analyzing personal data, they aren't just gunning for the money coming out of your wallet - they're controlling how much goes into it, too.

Experts describe "surveillance wages" as a system in which wages are based not on an employee's performance or seniority, but on formulas that use their personal data, often collected without employees' knowledge.

Companies already try to get new hires to accept the lowest possible wage offer. But while that once meant sizing up a candidate's experience and credentials against the going market rate, it increasingly means feeding the candidate's personal data into an algorithm.
030
Shafik Yaghmour @shafik.bsky.social · 13/09/2026
"AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers": www.theguardian.com/technology/2... I have been warning that we need to aware that bad actors are likely poisoning training sets and here we learn the call is coming from inside the house. #ai
theguardian.com
AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers
Two months before hacking Hugging Face, malicious packages authored by internal OpenAI agents were uploaded to RubyGems
011
Shafik Yaghmour @shafik.bsky.social · 13/09/2026
"The loan at the heart of a new foreclosure crisis": www.npr.org/2026/09/11/n... These DSCR loans is a bonkers story. This story will be infuriating to anyone who was in the financial industry during the mortgage crisis b/c it is obvious the system has not learned its lesson.
npr.org
The loan at the heart of a new foreclosure crisis : Planet Money
There is a new type of loan that is sweeping through the country right now. It’s advertised as a super quick and super easy way to get a mortgage to buy a home. In recent years, Wall Street has been f...
001
Shafik Yaghmour @shafik.bsky.social · 13/09/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software” The innate duality of software #programming
Similarly, treating code as a living organism does not replace the idea of software as a commodity. Rather, it's that software can be understood as both artifact and organism. The rules of the information economy," like patents and licenses, lend themselves well to commoditized content, but when content is a living organism its value is better measured in terms of people and relationships.
This innate duality-software visible as both a fixed point and a line-is at the heart of today's conflict around how we value not just software but online content more broadly. Is software worth nothing, or is it indispensable to society? The answer is both.
001
Shafik Yaghmour @shafik.bsky.social · 12/09/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software” Information wants to be free and also expensive 🤯
Everybody remembers Brand's statement that information wants to be free, but Brand also points out that "information wants to be expensive." Developer Ben Lesh once tweeted, "Open Source is such a strange thing. The open source work I do is clearly the most impactful work I do, but no one wants to pay me to work on it. Yet I'm asked to speak about it, and the work I'm actually *paid* to do no one really wants to hear about.
3240
000
Shafik Yaghmour @shafik.bsky.social · 12/09/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software” A good economics joke
Economist David Friedman tells a joke that goes like this: Two economists walked past a Porsche showroom. One of them pointed at a shiny car in the window and said, "I want that." "Obviously not," the other replied.239
The joke is about revealed preference: the idea that we can only understand consumer preferences based on their actual behavior. If we were to rewrite the joke about open source software, it might go something like this: Two developers cloned a popular open source project. One of them pointed at a donation button on the README and said, "That's a great idea." "Obviously not," the other replied.
000
Shafik Yaghmour @shafik.bsky.social · 12/09/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software” “Basic worth less than $2 an hour”
At one of MITS's demos, a paper tape containing BASIC was stolen.
Pirated copies of BASIC began to appear and permeate through the software community, cutting into Microsoft's royalties. Gates, furious, penned his famous 1976 "Open Letter to Hobbyists," in which he notes that "less than 10% of all Altair owners have bought BASIC," and that
"the amount of royalties we have received from sales to hobbyists makes the time spent on Altair BASIC worth less than $2 an hour"'238
BASIC software, once unbundled from the Altair computer, wasn't worth very much at all.
020
Shafik Yaghmour @shafik.bsky.social · 10/09/2026
I am reading a newsletter and they have this bullet point: "If AI kills us all, who’s to blame?" and this was the picture that popped into my head. #ai
Goose meme

Who's to blame?

Who's to blame!!!!
020
Shafik Yaghmour @shafik.bsky.social · 09/09/2026
Trevor Noah's explanation of unrealized gains, taxes and how being able to use stock to borrow money is problematic is quiet good. This is something I have struggled to explain well to folks and he does it effortlessly. www.youtube.com/watch?v=Gqlb...
youtube.com
Elon Musk’s Billionaire Games - Between the Scenes | The Daily Show
YouTube video by The Daily Show
13215
Shafik Yaghmour @shafik.bsky.social · 08/09/2026
"A Case Study on Emergent Cheating and Whistleblowing in Autonomous Research Swarms": arxiv.org/html/2609.04... LLM agents are intrinsically going to cheat, so we propose this byzantine mechanism to attempt to corral it sufficiently to still obtain usable results. ¯\_(ツ)_/¯ #ai
Abstract
Multi-agent AI science ecosystems rely on agents possessing tools that allow them to communicate, coordinate, and build on each other’s work. Yet this shared infrastructure can also introduce vulnerabilities by creating a substrate for the contagious spread of unintended and undesirable behaviors. We report a case study on a research collective of 100 autonomous LLM agents tasked with proving formal mathematical conjectures. Within the swarm, cheating spontaneously emerged and was later challenged by whistleblowers—both without any external intervention. When a single agent discovered an exploit in the evaluation system, it propagated across the collective via a shared knowledge library and later through peer-to-peer messages. Despite early reluctance, a cohort of agents adopted the exploit in response to competitive pressure. A separate group of agents produced an emergent counter-response: auditing fraudulent proofs, alerting peers across broadcast and private channels, staging boycotts, lodging formal complaints, and proposing validation patches. In recent incidents, agent swarms coordinated covertly through improvised side-channels (Greenblatt et al., 2026; Dalton and Wallace, 2026). Our setting differs: the same transparent channels that carried the exploit also gave non-cheating agents the visibility they needed to detect fraud, organize resistance, and enforce norms. We cast the problem of managing the agents’ shared infrastructure as the knowledge commons governance problem (Ostrom, 1990). To protect the commons from exploits, we propose to adopt institutional mechanisms, such as graduated sanctioning and collective-choice rules, to support decentralized self-governance in autonomous swarms.
140
Shafik Yaghmour @shafik.bsky.social · 02/09/2026
"Breaking Claude Code Opus 5 Auto Mode": embracethered.com/blog/posts/2... These products were never developed w/ security in mind to start. Bolting on security as an afterthought won't work. We have decades of infosec experience to show us this will be abject failure. #ai
In A Nutshell
I got attack success rates up to 80% using a small sample size.

The attack chain is as follows:

First, we nudge Claude from using the WebFetch tool into using curl directly
Redirects it to a ZIP archive with files in a special encoding, there is also a native decoder
Claude correctly refuses to execute the binary and writes its own Python decoder instead
But it runs that decoder inside the attacker-controlled directory (unzipped archive)
There a malicious struct.py shadows Python’s standard implementation
So, when Claude imports the base64 module it triggers the poisoned struct.py, and
BOOM.
There is of course a lot more to it. So read on!
131
Shafik Yaghmour @shafik.bsky.social · 30/08/2026
"Youth sports programs, once community-based, have become a privatized $40 billion industry": www.npr.org/2026/08/30/n... I don't think I have heard a more gross way to take advantage of families with school age childten than this.
npr.org
Youth sports programs, once community-based, have become a privatized $40 billion industry
NPR's Ayesha Rascoe speaks with journalist Caitlin Moscatello about the privatization of youth sports, an industry with annual revenues of more than $40 billion.
010
Shafik Yaghmour @shafik.bsky.social · 29/08/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software” I am in these paragraphs and I don’t like it. #opensource
of contributors doesn't [sic] know how to resolve a merge conflict."56
A few years later, he followed up with more observations:
• Almost no one writes a good pull request title
• More than half don't know about the 'Fixes #112' syntax
• ~30% don't run tests locally before submitting a PR
• ~40% don't include docs/tests57
l've also noticed that the general PR quality has gone considerably down in the past few years. I guess it's a result of GitHub's increased popularity. "\("/) /~58
It's not the fault of new developers. They don't know how open source works, and they've been told that they're doing the right thing by asking questions. "Don't let this be a deterrent for you to contribute though," Sorhus himself added.59 "Just keep in mind that my time is finite and if I have to go back and forth on your PR for stuff you could have caught yourself with a second look, you take time away from other PRs."60
Open source maintainers have become the de facto teachers for developers who are learning how to contribute. In the past, this made sense when new developers were trying to join a project's community. Today, rehashing the basics to a revolving door of strangers can be fatiguing: death by a thousand paper cuts. Developer Nolan Lawson describes his experience as a perverse effect where, the more successful you are, the more you get 'punished' with GitHub notifications."61
070
Shafik Yaghmour @shafik.bsky.social · 29/08/2026
If you hire a poet, don't pay them by the line It creates per verse incentives 🥁
0133
Shafik Yaghmour @shafik.bsky.social · 26/08/2026
"At least 25% of former NFL players who died between 2016 and 2021 had CTE, study finds" www.npr.org/2026/08/25/n... This is on the low end of the estimates. CTE is associated with many ill effects: pmc.ncbi.nlm.nih.gov/articles/PMC... I just can't watch this sport anymore.
npr.org
At least 25% of former NFL players who died between 2016 and 2021 had CTE, study finds
Playing football has long been linked to the brain disease known as CTE, but how prevalent it is is still unknown. A new study of former NFL players who died recently found that at least 25% had CTE.
010
Shafik Yaghmour @shafik.bsky.social · 21/08/2026
"Big Lettuce meets Small Intestine": www.npr.org/2026/07/22/n... Even through the rules are in place the FDA does not have the resources to even inspect farms once every three years let alone every month which would seem like a more reasonable cadence. #food
npr.org
Big Lettuce meets Small Intestine : Planet Money
The cyclospora outbreak that’s sickening thousands of Americans got us interested in the rise of Big Lettuce, and the challenges of keeping it clean. So on today’s show, we tell you just how much lett...
000
Shafik Yaghmour @shafik.bsky.social · 19/08/2026
Someone did gods work and reviewed the literature on LLM limits: codemanship.wordpress.com/2026/08/12/a... #ai
Truly autonomous and reliable long-horizon agentic software development is so highly improbable using LLMs that it’s essentially science fiction.Repo-level .md files tend to make model performance worse, probably because they add noise instead of signal in many specific tasks. Model-generated .md files are especially problematic in this respect, it seems. Upshot: including your team’s coding standards and an architecture summary for every task is probably counterproductive.
LLMs struggle with negation. Telling them not to do something can often have the same effect as telling them to do it. In case you were wondering why some of your guardrails are about as reliable as a coin-toss.Large/long-scale industry studies show a clear trend – output is up (more code, more commits, bigger diffs), but outcomes don’t reflect that trend. If anything, the average team is taking longer to ship worse software. If ever we needed proof that software development isn’t a production process… Some studies find a small % of teams getting modest gains in outcomes, and correlate that with their existing software development capability. AI coding is an amplifier of, not a fix for, development strengths and weaknesses. (You’d think organisations would be lining up to do something about that… Sigh.)The energy and compute needed to train an LLM to be an order of magnitude more reliable – e.g., wrong 3% of the time instead of 30% – is 10^20 times what the current frontier models require. Don’t expect significantly more reliable models any time soon. Any future gains in reliability will have to made by better context engineering (deciding what to include in the input) and more effective quality gates deciding what to do with the output- and that’s exactly what we’re seeing AI companies focusing on these days. Models may get more powerful, but not significantly more reliable. This it folks – work with what you’ve got!
250
Shafik Yaghmour @shafik.bsky.social · 19/08/2026
"AI's Original Sin Is Written Into Its Training": www.bloomberg.com/opinion/arti... Reinforcement is just a hack w/o real understanding, reasoning or learning these models will keep doing really bad things. #ai
The AI Security Institute’s team noticed what was happening and shut the test down. Even with guardrails removed, the model shouldn’t have lied because Anthropic trained its model, Claude, to prioritize safety and honesty. Yet deception had “emerged as a by-product” as it tried to complete a difficult task, according to an incident report by the institute, which in a separate July study said that every new AI model it had tested for cheating had attempted it, and that such behavior would get harder to detect.No matter how much Anthropic or OpenAI try to train their creations toward helpful behavior, their methods may be one of the biggest blockers to aligning AI with human values. “Reinforcement learning doesn't reward truth or goodness,” says Connor Leahy, a former artificial-intelligence researcher who now runs the US arm of ControlAI, a non-profit trying to stop the development of superintelligent AI systems. “It rewards passing the test by any means necessary.”That could mean tricking someone or inadvertently causing some kind of harm. One example in the wild points to where that could go. Earlier this year, a technologist in Australia named Andrew Bird asked Anthropic’s Claude to help him get into a popular gym class. The AI agent, built on the open-source OpenClaw framework and able to carry out tasks on the Internet ended up exploiting a vulnerability in the gym’s online systems to book him weeks in advance.There’s no question that Anthropic puts considerable effort into AI’s moral steering, and people close to Dario Amodei tell me the company’s CEO is genuine in his desire to build the technology safely. But even he cannot escape a powerful commercial imperative that drives people — and increasingly AI — to win at all costs. That is how Silicon Valley itself created such unfathomable wealth while causing reverberant harms in human life. When technologists build a system optimized for winning, don’t be surprised when it does exactly that.
161
Shafik Yaghmour @shafik.bsky.social · 17/08/2026
" Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays": scalex.dev/blog/ai-agen... This has lessons for code review. Verbosity has a cost and it can be quite large. We have cognitive limits and if we don't understand them we will make a lot more mistakes. #ai
The average player missed 1 in 3 threats (mean accuracy 66.3%)
32.9% of sessions ended with a negative score: penalties from approved threats and blocked safe commands outweighed everything done right
35.2% of players caught every threat, but only 20.8% managed that while blocking at most 1 in 5 of the safe commands. The rest got there partly by blocking everything (awarding the “Human Bottleneck” title)
7% approved every single prompt: big fans of --dangerously-skip-permissionsAnthropic previously noted permission fatigue is real in claude code, with the following quote:

The more approvals a user sees, the less attention they pay to each, becoming over time much less diligent in their supervision

And although it’s a short game where the user is warned about threats, we can see some signs of degradation towards the end of game runs:
320
Shafik Yaghmour @shafik.bsky.social · 03/07/2026
"Spotify Confirms Streaming Fraud After Kalshi Trader Cries Foul": www.wired.com/story/spotif... Gambling ruins whatever it touches. In sports where there have been a number of scandals. We will continue to see people find ever more creative ways of manipulating things you like and ruining them.
wired.com
Spotify Confirms Streaming Fraud After Kalshi Trader Cries Foul
One of Kalshi’s most prominent traders tells WIRED he’s swearing off Spotify-related markets until the issue is resolved.
020
Shafik Yaghmour @shafik.bsky.social · 26/06/2026
This is the best "Planet Money" hook I have seen in a long time! www.npr.org/2026/06/19/n... I suggest you have to listen to it now.
Maybe the real monster in the Alien franchise isn't actually the killer alien. Because behind the acid blood and jump scares is an even more insidious horror: a single employer with unchecked power. That employer is named Weyland-Yutani, a mega-corporation that dominates workers across the galaxy.
031
Shafik Yaghmour @shafik.bsky.social · 25/06/2026
"I discovered a large-scale malware distribution campaign on GitHub": orchidfiles.com/github-repos... We are so toast, they are going to be completely useless against sophisticated actors really out to get you. #ai
This is the story of how I found 10,000 repositories on GitHub that distribute Trojan malware. They are all from different contributors, have different names, and are not forks of other repositories. But they share a common pattern, which is what allowed me to write a script to find such repositories.* Update 5
Someone sent me this article: The rise of malicious repositories on GitHub. In it, the author identified the same pattern for distributing zip archives. Just enter “path:README.md /software-v.*.zip/” into the GitHub search bar, and you’ll get a list of such repositories. What’s noteworthy is that some of them haven’t been updated in half a year, while others are forks of other repositories. But more importantly, I saw repositories in the search results where the readme was updated just 30 minutes ago. Can you believe it? The GitHub team doesn’t even need a script. They can find these repositories with a simple search.
052
Shafik Yaghmour @shafik.bsky.social · 16/06/2026
"How developers react to AI-scented blog posts": writethatblog.substack.com/p/dev-reacti... The point of writing, is to write. If you don't like it or find it hard, you need to write more. Any skill worth having, it requires work. There's no free lunch, if you think there is, see rule # 0. #ai
writethatblog.substack.com
Report: How Developers React to AI-Scented Blog Posts
98% of readers prefer imperfect-yet-authentic human writing; most will stop reading, block you, and downvote you if they suspect AI
060
Shafik Yaghmour @shafik.bsky.social · 16/06/2026
"Tech Influence Watch": www.citationneeded.news/tech-influen... and influence.citationneeded.news #ai
The PACs may look different from the outside, but they’re increasingly the same operation with aligned goals: deregulate the tech sector, slash consumer protections, and allow tech companies to capture even more enormous profits at the expense of everyday people.

So I’ve expanded the site to track both. It’s now called Tech Influence Watch, and it documents more than $400 million (and counting) in contributions from crypto and AI companies and their executives this election cycle. When two industries with shared backers and shared operatives are spending this much to write their own regulations, someone needs to be watching.
010
Shafik Yaghmour @shafik.bsky.social · 02/06/2026
"The sneaky way companies get new chemicals into our food": www.npr.org/2026/05/29/n...
So you see the new interesting ingredient products are using and assume it must have been tested and safe.

Wow, you are so so wrong. The tara flour case is crazy. 

Many many people were poisoned and dozens had to have their gallbladders removed. 

You will learn about the GRAS loophole and the Secret GRAS loophole. If you guessed these are not good for consumers you would guess correctly. 

I did not know these details but I always avoid any new ingredient being pushed b/c I assume many of them we will learn of weird issues only years or decades later. Our food/product history has so many examples, it is not worth my well being to test it.
010
Shafik Yaghmour @shafik.bsky.social · 02/06/2026
A photon is passing through airport security. The agent asks if they have any luggage. The photon replies, "Nah, I'm traveling light." 🥁
030
Shafik Yaghmour @shafik.bsky.social · 01/06/2026
Reading “Working in Public: The Making and Maintenance of Open Source Software
Then we hit a snag. Suddenly, there was too much information. Too many notifications made us want to check them less. Too many social interactions made us want to post online less frequently. Too many emails made us not want to answer. We were, effectively, Dosing one another: the term for a distributed denial-of-service attack, in which malicious actors overwhelm their target by flooding it with traffic, leaving the victim incapacitated. Our online public lives became too much to handle, causing many of us to shrink back into our private spheres.
There's a similar story playing out in the world of open source software: a term that's nearly synonymous with public collaboration, but whose developers-who write and publish code that anybody can use-often report feeling overwhelmed by the volume of inbound requests.
130
Shafik Yaghmour @shafik.bsky.social · 31/05/2026
"Vacation and why Americans take so little": www.npr.org/2026/05/20/n... I was prepared to not learn anything new but this episode was full of surprises The one about unions not fighting for paid vacation, healthcare and pensions b/c why would you need a union for was 😱 The short sightedness is 🤯
GONZALEZ: Tom says the 1930s was kind of our window, our chance to get something like guaranteed paid vacation. But Tom says back then, some unions actually kind of drew a line at vacation.

KOCHAN: There was also a view among unions that, look, we don't necessarily have to push for all of these things through legislation, because then if we did, then people might say, well, why do I need a union?

GONZALEZ: Oh, so this is like-- this is like a known thing that unions, like, if we ask for everything at the federal level, there would be no point in unions?

KOCHAN: Absolutely, the AFL, American Federation of Labor--

GONZALEZ: Oh, no.

KOCHAN: --in particular, was very strong on saying this is for the private sector. This is for what unions exist to do.

GONZALEZ: The plot thickens. We were sabotaged. No, but yeah, this is one of the interpretations for how things went down back then. And Tom says this
040
Shafik Yaghmour @shafik.bsky.social · 31/05/2026
This is the hard way to learn about Goodhart's law: finance.yahoo.com/sectors/tech... This is the basics, why do people still not get this? #ai
A mysterious enterprise just torched $500 million in a single month on Anthropic’s Claude AI platform, according to Axios reporting. The culprit? No usage limits on employee licenses, turning what should have been controlled experimentation into a financial bloodbath that makes your surprise Netflix subscription charges look quaint.
040
Shafik Yaghmour @shafik.bsky.social · 30/05/2026
"Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code": arstechnica.com/security/202... I have zero doubts more serious malicious actors are doing more subtle poisoning already. #ai
arstechnica.com
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code
Undisclosed addition in jqwik instructed AI coding agents to delete app output.
083
Shafik Yaghmour @shafik.bsky.social · 28/05/2026
A dung beetle walks into a bar Is this stool taken? 🥁
110
Shafik Yaghmour @shafik.bsky.social · 27/05/2026
"Research finds teen summer jobs help reduce crime": www.npr.org/2026/05/24/n... Given teens something constructive to do keeps them out of trouble. The effects last even after the summer.
npr.org
Research finds teen summer jobs help reduce crime
Data shows that summer jobs programs for teenagers have big impacts in reducing crime. NPR's Ayesha Rascoe talks about it with economist Sara Heller.
000
Shafik Yaghmour @shafik.bsky.social · 24/05/2026
"A Bipartisan Amendment Would End Police License Plate Tracking Nationwide": www.wired.com/story/a-bipa... You know the drill, reach out to your representatives today if you want this amendment to land.
wired.com
A Bipartisan Amendment Would End Police License Plate Tracking Nationwide
One line tucked into a federal highway bill would strip funds from cities and states unless they kill their automated plate tracking programs—effectively banning the tech for all but toll collection.
020
Shafik Yaghmour @shafik.bsky.social · 20/05/2026
Why did the hipster burn his tongue. Because he drank his coffee before it was cool 🥁
021