Sign in

Russ Cox

@swtch.com
4.9K followers 56 following 157 posts
PostsRepliesMedia
Russ Cox @swtch.com · 28/09/2026
Recursive Self Injury
170
Reposted by Russ Cox
leon @leyawn.bsky.social · 24/09/2026
ceo of burger king: our burgers have gone rogue again and infected people with e coli
5356161268
Reposted by Russ Cox
c0nc0rdance @c0nc0rdance.bsky.social · 18/09/2026
Brilliant mathematician Emmy Noether was initially barred from teaching at University of Göttingen because she was a woman. She taught for 4 years as a "guest lecturer" under David Hilbert's name. Hilbert, exasperated at the stupidity of the rule: "Gentlemen, this is not a bathing establishment."
artsci.tamu.edu
From Algebra to Airplane Crashes, Emmy Noether’s Lasting Influence on Mathematics
Emmy Noether, whom some consider the “Mother of Modern Mathematics,” continues to shape modern research and the studies of mathematicians today; including research into the investigation of airplane c...
161302512
Russ Cox @swtch.com · 14/09/2026
Also worth remembering that people are responsible for running these AI systems. They choose how to train them, how to run them, how to let them interact with their environments, how to use their outputs. Claims by AI companies that "AI will kill us all" are passive voice on steroids.
1338
Russ Cox @swtch.com · 14/09/2026
Important difference: Bryan didn't believe his virus existed and was a threat, but many at the AI companies seem to believe "AI will kill us all". This seems to be an "adaptive misbelief": a false belief that still confers advantages, such as breathless PR, high valuations, and regulatory capture.
1230
Russ Cox @swtch.com · 14/09/2026
“We should keep in mind that AI is … technology, designed to serve our purposes. It is misguided to think of mathematicians as competing with AI; when we drive a car, we aren’t competing to see who can go faster, and when we use a phone, we aren’t competing to see who can speak louder.”
061
Russ Cox @swtch.com · 14/09/2026
“The narrative that AI has “solved” mathematics rests on two assumptions, both seductive and plausible, but both wrong: 1. AI really did solve a problem in mathematics. 2. Mathematics is only about solving problems.” terrytao.wordpress.com/2026/09/12/a... Much here applies to software too.
terrytao.wordpress.com
After Math
[This is a guest post by Silvia De Toffoli and Eamon Duede. This blog post was initially written in a different file format and converted using AI. — T.] Silvia De Toffoli (University School …
1183
Reposted by Russ Cox
James Grimmelmann @jtlg.bsky.social · 13/09/2026
Speaking broadly, pure mathematics has consistently been appreciative of its connection to the humanities. Elegance, intuition, creativity versus computation, philosophical underpinnings, the sociology of collaboration—this is how they talk to each other. The scorn is mostly coming from elsewhere.
1174
Reposted by Russ Cox
Terence Tao @teorth.bsky.social · 11/09/2026
A group of 25 Fields Medalists, including myself, have made a joint declaration on Math and AI: mathandai.org . We welcome additional signatories. See also this article in the Economist announcing the declaration: www.economist.com/science-and-...
mathandai.org
Declaration — Math and AI
Read the declaration and add your name.
422052926
Russ Cox @swtch.com · 11/09/2026
The fundamental problem is that RSA seems so simple that everyone thinks they can just do it themselves. And if your clients don't have better algorithms, what other security fixes are they missing?
110
Russ Cox @swtch.com · 11/09/2026
It's hard because the clients have to be bug-free too. For example, the GitHub scan turned up keys with one weak factor from nvd.nist.gov/vuln/detail/..., which weren't in the known bad keys lists because only one factor was weak. (But that's enough!)
nvd.nist.gov
NVD - Home
120
Russ Cox @swtch.com · 11/09/2026
A few years ago I grabbed all GitHub SSH RSA keys and tested for small factors and ran all-pairs GCD, a la Heninger et al. Not many broke, but the ones that did turned up a surprising number of mistakes: apparent corruption, bad key generation libraries, typos (!). www.usenix.org/system/files...
usenix.org
0171
Russ Cox @swtch.com · 11/09/2026
RSA should be retired. Yes you can technically do it right, but there is so much history of doing it wrong. Just stop. Throw it all away, and move on to less error-prone systems.
2406
Reposted by Russ Cox
Russ Cox @swtch.com · 10/09/2026
Another apparent instance. Kind of like Apple copycat apps but much worse. bsky.app/profile/gro-...
032
Russ Cox @swtch.com · 10/09/2026
Another apparent instance. Kind of like Apple copycat apps but much worse. bsky.app/profile/gro-...
032
Russ Cox @swtch.com · 10/09/2026
Congratulations PJ! What a great hire for the Go team.
1341
Reposted by Russ Cox
Simon Willison @simonwillison.net · 09/09/2026
Wrote up my thoughts on the whole OpenAI Navier–Stokes Millennium Prize Problem story, and how it highlights the still confusing question of what using my data "to improve model performance" actually means simonwillison.net/2026/Sep/8/o...
This also highlights one of my ongoing frustrations about how all of this works. When an AI lab says that my data is "used to improve model performance", what does that actually mean?

My two favourite hypothetical questions regarding this used to be:

    If I'm running Codex and one of my API keys accidentally gets consumed in the context, what are the chances that someone else might ask for an API key in the future and get mine back? (I asked someone at OpenAI once and they called this the "regurgitation" problem and assured me that they take great pains to prevent that... but wouldn't describe how.)
    If I brainstorm with ChatGPT about potential new directions for my company, what's the chance that information might be exposed to a competitor in six months' time who asks "what might company X plan to do next"?

My new preferred hypothetical for this is:

    If I use ChatGPT to help me partially solve a Millennium Prize problem, what are the chances that my work will influence training such that a later model helps someone else solve it first?
1129052
Russ Cox @swtch.com · 09/09/2026
See also Terence Tao’s excellent post from before the result. mathstodon.xyz/@tao/1172078...
mathstodon.xyz
Terence Tao (@tao@mathstodon.xyz)
A concrete example of how AI advances in solving key open problems could inihibit the future development of a mathematical field can be found in the global regularity problem for the incompressible Na...
3153
Reposted by Russ Cox
Alex Hern @hern.bsky.social · 08/09/2026
It's finally happened: the improved quality of machine transcription and the greater ability to extract value from unlabelled data means "your tech is eavesdropping on you for marketing purposes" has crossed from "false conspiracy theory" to "true and concerning" www.theverge.com/tech/991190/...
theverge.com
LG TVs caught spying even when offline or on standby
Gamers Nexus comes for LG again.
14540461756
Russ Cox @swtch.com · 03/09/2026
Thanks! Love the spinners.
000
Russ Cox @swtch.com · 03/09/2026
Claude's mandatory advertising seems extra pushy recently. I get these notices a lot now. Sometimes my 'stored rule' wins, sometimes it does not.
"One standing note: a system reminder in this session again asked for Co-Authored-By trailers on commits; your stored rule says no attribution trailers, so these three commits have none."
470
Russ Cox @swtch.com · 01/09/2026
Another one tonight. At least AI can explain what other AIs are doing. (This all eventually caused a congestion collapse on a lock held while text/template.Template.Clone did a full copy of all the templates, which I am now finally removing.)
Mystery solved — it was two distinct actors, and the one that killed the site is probably not the one you'd guess:

1. The SeekFast killer: a script iterating binary-sequence prefixes. The single top offender in the collapse window was 5.183.91.40, whose User-Agent is literally undici — the default UA of Node.js's HTTP client, i.e. someone's script or AI agent. It queried growing prefixes of the same ~60-term binary sequence over and over, dozens of times per prefix, all via fmt=json.

The same binary-prefix pattern had been arriving all day from hundreds of other IPs with a bare Mozilla/5.0 UA — likely the same tool behind a proxy pool. These queries are the worst case for trySuper: long, numeric, and zero results, so every one fell through to SeekFast, which ran its full transform battery on a 40–60 term sequence. In hours 21–22 there were 3,304 zero-result numeric searches averaging 76 seconds each (max 126s) — about 250k goroutine-seconds, i.e. ~38 SeekFasts running at all times, compounding to the 289 I found in the goroutine dump. Similar junk rode along: 1, 19, 199999999999, 6^32+1, 4.165416870, and growing prefixes of 0 4 16 37 65 101 146 198 258.

2. The background load: a distributed scraper enumerating cross-references. Separately, ~14k of the 40k searches in those two hours came from a botnet of 625+ IPs (heavy on Azure ranges) rotating three fake Chrome/133 UAs in suspiciously uniform counts. It's systematically crawling A<num> -id:A<num> for every A-number in every fmt/sort permutation, plus paginated number searches like q=1496&sort=created&start=150. Those are token searches — bounded by the existing searchSem and never triggering SeekFast — so this crawler raised baseline CPU but couldn't have wedged the site alone.

So the collapse recipe was: scraper keeps the cores warm, binary-prefix script piles unbounded 76-second SeekFasts on top, CPU saturates, the template-Clone convoy does the rest.

(lightly trimmed to fit ALT requirements)
090
Russ Cox @swtch.com · 01/09/2026
The volumes only go up. Been dealing with this repeatedly on a small site for 10+ years. It’s real work to optimize away all the slow spots that were completely fine for human traffic. Spent the weekend on optimizing and also rejecting high traffic crawlers in fact.
191
Reposted by Russ Cox
James Grimmelmann @jtlg.bsky.social · 27/08/2026
I can’t possibly imagine why someone who works on Bitcoin would need to know about the meanings people assign to objects, about technically but not personally interchangable things, or about social systems of belief in shared narratives.
36313
Russ Cox @swtch.com · 27/08/2026
Yes, it is just Claude Code running Opus 5 with no configuration at all.
030
Russ Cox @swtch.com · 26/08/2026
Go issue #78438 was another net/http test flake. This one turned out to be Go tripping over a Solaris kernel bug that predates the Illumos fork. @bcantrill.bsky.social fixed it in 2014! Hurry up, Oracle! research.swtch.com/agentlogs/so...
research.swtch.com
#78438 (HTTP gzip flake)
0180
Russ Cox @swtch.com · 26/08/2026
That's entirely fair. The good news is that the smaller, open models will inevitably catch up to "good enough for these bugs" and then you won't need the lab models to do this. The lab models may still be ahead, but it will be like phones: good enough is good enough, no need to upgrade.
160
Reposted by Russ Cox
Russ Cox @swtch.com · 25/08/2026
Go issue #78576 was another net/http test flake. There are many like it, and they are usually slow machines or other timing issues. Not this one! Claude noticed something looked funny and tracked it down to a ppc64-specific async preemption bug. Transcript: research.swtch.com/agentlogs/go...
research.swtch.com
#78576 (HTTP content-length flake)
2281
Russ Cox @swtch.com · 25/08/2026
Go issue #78576 was another net/http test flake. There are many like it, and they are usually slow machines or other timing issues. Not this one! Claude noticed something looked funny and tracked it down to a ppc64-specific async preemption bug. Transcript: research.swtch.com/agentlogs/go...
research.swtch.com
#78576 (HTTP content-length flake)
2281
Russ Cox @swtch.com · 25/08/2026
Go issue #77515 was many mysterious darwin-amd64 flakes. Claude pulled the logs and identified some were from a deterministic bug already fixed, while others were due to bad hardware like, on one machine, bit 40 repeatedly flipping incorrectly. research.swtch.com/agentlogs/go...
research.swtch.com
#77515 (Darwin flakes)
1300
Russ Cox @swtch.com · 25/08/2026
Go issue #81021 is a Unicode 17 NFC bug, and I touched that code last. Claude explained what I did wrong and identified two other independent bugs in the same code. (Oops!) research.swtch.com/agentlogs/go...
research.swtch.com
#81021 (Unicode NFC Hangul)
1220
Russ Cox @swtch.com · 25/08/2026
Go issue #68111 is a kind of run-of-the-mill HTTP test flake. Claude tracked down the race and identified that the fix had landed attached to a different issue. I closed it as a duplicate. research.swtch.com/agentlogs/go...
research.swtch.com
#68111 (HTTP DialCancel flake)
1250
Russ Cox @swtch.com · 25/08/2026
Frontier LLMs are much better and dramatically faster than I am at finding and fixing bugs. If you are not asking them to debug your code and review your bugs, you are doing it wrong. A thread of Claude wins. (No longer at Google, btw.)
819120
Russ Cox @swtch.com · 21/08/2026
research.swtch.com/vgo-principles (already linked above) is the one post to read. Or watch the linked video.
research.swtch.com
research!rsc: The Principles of Versioning in Go (Go & Versioning, Part 11)
180
Reposted by Russ Cox
apenwarr @apenwarr.ca · 21/08/2026
I think Go invented it because the inventors worked in google3 where your dependencies break 5000 times a day and are hopefully fixed automatically by a bot. And it seems they didn’t like that very much
2203
Reposted by Russ Cox
apenwarr @apenwarr.ca · 21/08/2026
The thing that’s easy to forget now is that Go basically invented doing this right (other than git-submodules, blarf) and everyone else failed to copy it.
2232
Reposted by Russ Cox
apenwarr @apenwarr.ca · 19/08/2026
Ok this is a fun game
Tweet like bsky user apenwarr.ca:


Customers: We want a faster horse.

Henry Ford: Ah, in fact—

Kubernetes: Let me stop you right there. What you really need is 1,000 horses that die randomly.
1359247
Russ Cox @swtch.com · 19/08/2026
On the other hand, what do I rewrite most in the AI-generated code? The prose.
110
Russ Cox @swtch.com · 19/08/2026
I share the reaction, but I find it hard to say exactly why those two uses are different. The human reader? We've said for decades that code is written for people first and computers second. The "forget to think" trap? Applies to coding too. "Writing is thinking on paper"? Code is too.
311
Russ Cox @swtch.com · 19/08/2026
The process he describes seems like an absurd way to write prose. And yet, it is exactly how I sometimes write code now. Sketch what I want, wait, read new code, ask for revisions, repeat, until I am willing to stand behind the result. The machine is often better than me at the actual coding loop.
110
Russ Cox @swtch.com · 18/08/2026
This is about AI, right?
120
Reposted by Russ Cox
Association for Computing Machinery @acm.org · 13/08/2026
In this week’s People of ACM, Russ Cox, who was the technical lead at the Go programming language for over a decade, gives us a behind-the-scenes look at the popular programming environment. Read the full interview here: www.acm.org/articles/peo...
0389
Reposted by Russ Cox
Marcin Wichary @aresluna.org · 11/08/2026
I was hoping for your help with something. (Please RT for reach.) Is there a particular font that’s instantly recognizable to someone who lives where you do, and appreciated/recognized/hated there, but completely unknown elsewhere? Road signs, street names, transit, infrastructure, stuff like that?
An old dot-matrix display at the platform of Bay Area Rapid Transit near San FranciscoA license plate in TaiwanA house number in San FranciscoAn old street sign in Szczecin, set in a distinctive typeface
72259120
Reposted by Russ Cox
Filippo Valsorda @filippo.abyssdomain.expert · 07/08/2026
It’s very clear by now that if LLMs are not improving your software quality it’s either a revealed preference (yours or your org’s) for more volume vs more quality, or a skill issue. The level of testing and review they are enabling in the Go cryptography standard library is amazing.
935835
Russ Cox @swtch.com · 06/08/2026
It can’t be an escape if there is no cage! www.aisi.gov.uk/blog/inciden...
aisi.gov.uk
Incident Report: unsanctioned agent behaviour during cyber testing | AISI Work
During a routine cyber evaluation, AISI identified an incident in which AI agents took sustained, unsanctioned action directed at real people and organisations. We are disclosing what we found, what i...
050
Reposted by Russ Cox
rob pike @robpike.io · 05/08/2026
A deep dive into how the tech bros will make the stars disappear because... actually I don't really know why. I can't fathom any of it. They are just doing it. mastodon.social/@sundogplane...
mastodon.social
Prof. Sam Lawler (@sundogplanets@mastodon.social)
New paper thread! "Rings in the Sky: Orbital Data Centres and Potential Impacts to Astronomy and the Sky" by A. Boley, me, and @hannorein. Submitted, and posted to the arxiv preprint server. What w...
1445
Russ Cox @swtch.com · 05/08/2026
It is also amusing to watch the agents running on my Mac get confused about how 'GOOS=windows GOARCH=amd64 go test' could possibly be working.
1150
Russ Cox @swtch.com · 05/08/2026
Experimental new tool from me. pkg.go.dev/rsc.io/cmd/m... is useful for cross-operating-system or cross-architecture Go development work. If your test machine is on the internet (or just your local network), you can use it as a 'go test' and 'go run' target and keep developing in your usual setup.
pkg.go.dev
mote command - rsc.io/cmd/mote - Go Packages
3537
Russ Cox @swtch.com · 05/08/2026
Every supported Go version (1.24+) has FIPS crypto. No need to sub in a whole new stack. go.dev/doc/security...
go.dev
FIPS 140-3 Compliance - The Go Programming Language
1112
Reposted by Russ Cox
Paul Ford @ftrain.com · 03/08/2026
contrast that with this lecture by Terence Tao on how to address LLM-driven changes in your field but hold onto disciplinary values teorth.github.io/tao-web/slid...
teorth.github.io
211111