Tuesday, August 11, 2026

via:

Sitting Decoys

President Donald Trump secretly slipped out of Turkey last month on an alternate military plane, which he boarded while hidden inside a catering truck, as part of an elaborate ruse prompted by an Iranian threat, according to a US official.

The clandestine security plan — first reported by the Washington Post and confirmed by CNN — underscored the lengths American officials went to in order to protect Trump from being assassinated by Iran. Addressing a question about the ploy Tuesday, Trump said he followed the advice of the Secret Service and the military.

“I just follow what they’d like to do. So I go by Secret Service. And the military. They wanted me to go on a different flight, a different plane, equal safety, but they wanted me to do it, so I do it. I do what they say,” Trump said, adding, “I guess there was a threat out there. I didn’t really ask too much about it. I get a lot of threats.”

Trump had flown to Turkey on a new plane gifted by Qatar and meant to be used as Air Force One. But while he was on the trip, officials announced he would fly out on an older presidential plane, which CNN and others had previously reported was due to security concerns.

That, though, was apparently part of the subterfuge. After boarding the older aircraft, a moment caught on camera, Trump secretly got off via the catering vehicle and moved to a smaller Air Force C-32A. The Qatari-gifted plane, the older aircraft used as Air Force One and the C-32A then all departed separately for the UK. Once there, Trump got on board the Qatari-gifted plane and flew home.

For the last month, much of the public discussion about the plane swap had been centered on the security capabilities of the Qatari-donated plane. Trump had boasted about the new aircraft — even though officials felt it was not as secure as other planes because it had to be retrofitted to serve as Air Force One — and the president seethed privately over coverage of its deficiencies, CNN previously reported.

Now, attention has shifted to reporters and staffers unknowingly flying on a decoy plane — and the nature of the threat that prompted such dramatic security measures. A US official said at least two Cabinet secretaries – Secretary of State Marco Rubio and Treasury Secretary Scott Bessent – stayed behind on the older presidential aircraft that departed Turkey without Trump aboard.

Trump said Tuesday night that a plane he was on was more likely to be targeted, and that he faced threats that the public does not know about. “The plane that I flew on was at greater risk … Because that would be the plane, I think, that they would be more likely to go for,” he said.

by Kevin Liptak, Alejandra Jaramillo, and Donald Judd, CNN |  Read more:
Image: Doug Mills/The New York Times/Redux
[ed. Well, there goes that strategy. Wonder if he would've left Melania on the decoy plane (c'mon... of course, you know he would). See also: After Trump plane ruse, WHCA presses White House on press pool safeguards (CNN).]

Tsukiji Journal
via:

What Is the “Bean Soup Theory” on TikTok?

[ed. TikTok won't let me dl/embed videos so click the link.]

As someone who considers themselves chronically online, I’ve had the unfortunate privilege of learning about many kinds of “theories” that either originate from or start trending on TikTok. Not theories in a conspiracy way — more so like hypotheses. For example, the orange peel theory, where you ask your partner to do a simple task for you (like peeling an orange) and if they do it without complaining, it shows they’re a good partner.

There’s another one that’s been circling social media a lot recently: the bean soup theory. It’s when people respond to internet posts that they are not the audience for and find a way to make it about themselves. It calls a lot of attention to self-centeredness or having an inflated ego: even when users watch a TikTok video that they are not the audience for, they’ll still find a way to put themselves at the center of the idea.

The “bean soup theory” all started with this video.

User @vibingranolamom posted a video back in 2023 of her making a recipe for bean soup. “All my anemic girlies this one is for you,” her caption says. The main ingredient in this recipe calls for a wide selection of varied beans, with a few other ingredients like kale, diced tomatoes and rice. It’s almost at 1 million likes and many, many comments, a surge of them gaining popularity for the level of absurdity. Specifically, some users are asking in the comments, “What if I don’t like beans?” Maybe, I don’t know, try a different kind of soup instead? And don’t make it the original poster’s problem?

Even in 2023, people were discussing the bean soup theory as the “bean soup effect” or “bean soup syndrome,” but it’s resurging now as the bean soup theory — and there’s been plenty of widespread criticism over the terrifying lack of self-awareness some of these commenters have.

This video shares several other strong examples — and maybe you’ve even seen, read or been told similar statements before. A few highlights:“I love pancakes. They are so delicious,” says one person. The response might look something like:
  •  “Okay, but what about waffles? Do you just hate waffles?”
  • “Wishing you health and happiness,” says one person. “What about the unhealthy and unhappy people?” one might respond with.
  • “I love a crispy grilled cheese,” says one person. The response: “What about people who don’t eat dairy?” Or, better yet, “What if I’m lactose intolerant?”
This entire concept also reminds me of this viral tweet from 2022, where a woman innocently tweeted about how much she enjoys having coffee with her husband for several hours every morning. It somehow enraged many Twitter users, and replies full of unnecessary backlash came flooding in: “I wake up everyday with chronic pain (tarsal tunnel syndrome), and wash my OCD medication down with an iced oat milk latte,” one user wrote. “This is cute and all but did you think of all the people who wake up to work grueling hours, wake up on the streets, alone, or with chronic pain before posting this? You should be mindful next time before bragging about your picture perfect life… You might upset someone,” said another. Geez. Are we all just not allowed to exist anymore?

The more official term people online are using to talk about this phenomenon is “whataboutism,” which is a rhetorical device used to direct criticism elsewhere by the recipient asking “What about…?” in response. It actually traces way back to pre-Socratic Greece and was even used during the Cold War. It’s a counter-argument strategy that Sophists used to train their clients to help them win public debates. The Soviet Union also used this tactic to deflect when accused of allegations of human rights violations by accusing Western countries of equally weighted crimes. [ed. As have many others... those Hillary emails! Hunter Biden's laptop!]

I’m not exactly comparing what seems like mostly Gen Z TikTok users to Sophists or the Soviet Union here, but I do find this alleged rise of self-importance online really interesting.

This user references a few examples of what she’s seen online, like a video where someone discussed how they weren’t going to be able to see their dad for a while because he was getting arrested, and the most liked comment on the video came from another user who said something along the lines of “well, my dad is dead.”

“It’s not your video, and I think people get so pissed when you call them out on that because yes, you can comment whatever you want on people’s videos, but it’s crazy to me that you’re gonna find any way to make a video that is in no way targeted towards you,” she says.

“I just announced that I’m pregnant with twins, and since that announcement, all of my comments and DMs are from people saying ‘Congratulations, but I miscarried my twins at 14 weeks,’ she says.

“We have lost the plot. We have lost all sense of time and place. We completely lack discernment. People are so terminally and chronically online that we’ve forgotten what the sense of self means,” she continues.

by Joanna Sommer, Inside Hook |  Read more:
Image: Getty
[ed. Disable comments. It's that easy (like here). See also: ‘Whataboutism’ makes the internet exhausting (CNN).]

The Extras Are Tired

Less than a decade ago, when I was working on technology stories, my colleagues and I ran into an issue that I’m pretty sure had not occurred to the people who founded this magazine in 1857: how to style the word influencer, which was an occupation and cultural force, but one just emerging. We weren’t sure that all of our readers would know what one was, and we also didn’t know how exactly we would define the word ourselves. I spent the fall of 2018 sending a lot of emails about whether we needed to encase the word in scare quotes.

Quaint! Many—but not all that many—years later, influencer is very much a real job, no explanation required. As of 2023, 27 million Americans were paid to make online content in one form or another, at least according to one marketing consultant company. Enthusiasm from influencers can turn a random business into a sensation, while their ire can do the opposite. Donald Trump’s White House is full of influencers, but Joe Biden’s courted them too, in apparent recognition of their power. This week, Arizona State University announced that it would begin offering a bachelor’s degree in content creation—influencing by another name—through its journalism school.

In some ways, the influencer industry is more legitimate than it’s ever been. But it has always been precarious, and more than a decade into its existence, it is neither novel enough to be exciting nor established enough to have a real professional code. In an oversaturated market, rage bait is the last sure way to get attention, despite the way it alienates people over the long term. AI is swiftly becoming the dominant way many people get personal-seeming advice about how to live their life, which makes the usefulness of aspirational online content even less apparent than it ever was. And so, although influencers—especially lifestyle influencers—have never been universally respected, they lately seem to be openly reviled.

Naturally, much of the influencer backlash lives online. A few months ago, someone asked on Reddit, “What’s an industry that provides zero value to society but makes billions of dollars?” Among the 5,300-plus responses: Ticketmaster, sports-betting companies, multilevel marketing schemes, private prisons, and—several times over—influencers. A hilarious number of people have found internet fame by making content about how much they hate other people who are internet-famous for making content. (“Everyone Is Finally Turning on TONE DEAF Influencers” is the title of one recent video, made by an Australian YouTuber with nearly 300,000 subscribers and a clothing line.)

But the juiciest fights play out in the physical world, which is where influencers very literally bump up against the people who can’t stand them. A few years ago, a coffee shop in Brooklyn banned photography after too many influencers clogged the cafĂ© with tripods and handheld lights; earlier this month, Indonesia indicated that it would crack down on people creating content for pay while on tourist visas.

Last week, the scene of the debate was a gift shop in Nantucket, an island that has recently been overrun by vacationing influencers, just like Bali, Iceland, and Santorini before it. The store’s operators, evidently fed up with the stream of people filming inside, had a sign made that read No Influencers, hung it up in the store, and posted a picture of it on Instagram. There, it drew the attention of thousands of people, including Paige Paul, who has about 2 million followers across platforms, is married to a famous tennis player, and has been spending time on the island since she was a child. Paul, previously known as Paige Lorenze, declared the sign a misogynistic slight against an industry that is overwhelmingly female. The store’s owner, John Sylvia, said it was meant as a joke for locals, but the sentiment clearly came from an earnest annoyance: “A lot of people are tired of feeling like extras in someone else’s video,” he told New York magazine.

The fight felt freighted. Influencers today are a bit like plastic surgeons, or plumbers: On a societal level, many people sure seem to like what they do—they just don’t necessarily want to be right next to them while they’re doing it.

But influencers are unique in how they seem to be everywhere, particularly in places where people are trying to do things other than be on their phone to watch influencers. Of course we love the game and hate the player: It’s much easier to be annoyed by individuals than by concepts, especially when those individuals are, often, pretty annoying.

You’d need to be pretty clueless to not feel a little weird about the online attention economy and all it entails—the vanity; the grift; the slop; the desperation; the calculated intimacy; the endless consumption; the creeping sense that everything and everyone is actually just there to make you feel kind of bad about yourself and then sell you something. Social media can, of course, unite like-minded people, but it can also reward the kind of tribalist reactionaryism that can conflate disliking some women with disliking all women, or make an anti-consumerist folk hero out of a store that sells $2,750 baskets. The industry that Paul and her cohort belong to is unquestionably grim—but the industry isn’t walking around town with a selfie stick. There’s a reason that the sign doesn’t say no influencing, but rather no influencers.

by Ellen Cushing, The Atlantic |  Read more:
Image: Atlantic/Getty
[ed. I'm a great fan of guitar instruction videos because they teach you something. I guess you could call that a form of influencing. Some instructors have a wide audience and are influencial because of their teaching technique.The opposite (and there are many examples) are so-called "reaction videos" where someone listens to a song and simply records their "reactions". Who cares. Talk about bottom of the barrel. Same goes for opinion influencers, foodies and tons of other niches (Mukbang videos?). If all they have to offer is distraction or entertainment they're a waste of time.]

How to Get Chatbots to Give Accurate Financial Advice

Finding good financial advice can be stressful – and expensive. That’s one reason why chatbots have become an increasingly popular and free alternative.

But using artificial intelligence to answer your pressing money questions also carries hidden dangers. I’m a finance professor who has been closely watching the spread of AI into personal finance, and I recently warned that AI is riskiest when it sounds most confident. I advised readers to bring in a human professional for high-stakes financial decisions. [...]

For people who can’t afford ongoing advice, AI is genuinely useful for budgeting, paying down debt and low-cost investing.

The skill lies in using AI well. Here are some simple guidelines to get accurate and actionable answers when you engage with a chatbot: [...]

Five habits that make AI safer

Once the list of questions is set, here are some precautions to take once you engage with a chatbot.

Make it ask you questions first. Open with, “Before you advise me, ask me the questions a good financial planner would ask.” Generic answers come from under-specified questions, and you learn which details will actually produce a more useful outcome.

Ask it to argue against itself. After any recommendation, reply: “Give me the strongest case against this, and the situations where it would be wrong for me.” If it can’t engage in response, that’s a sign the bot is entering a more dangerous mode. This one precaution does more than any other to signal for you to be careful.

Make it show its assumptions. If the bot projects that your savings will grow to an impressive number, ask what assumption it made and what would change it. You’ll learn that it assumes steady returns every year, no missed contributions and no fees. That means the projection is just information, not a promise.

Verify the facts. Contribution limits, tax brackets and deadlines all change, and this is exactly where AI can be subtly out of date. Check the IRS or the Social Security Administration directly. If one number drives your decision, don’t take it on a chatbot’s word.

Never share identifying details. Don’t offer account information, Social Security numbers or logins. Describe your situation in general terms. Good advice doesn’t require handing over data that can be used against you.

by Pawan Jain, The Conversation |  Read more:
Image: Badhan Ganesh on Unsplash, CC BY

The Accidental Architect of the Internet’s Brain

Steven Pruitt, who is widely regarded as the most prolific Wikipedia editor, has made more than six million edits to the site, and, by extension, has quietly shaped the raw material that every major A.I. chatbot was trained on.

Steven Pruitt spends his evenings identifying errors that most people never notice and making fixes that hardly anyone ever thanks him for. He toils at a desk in a town house in Alexandria, Virginia, surrounded by books—the kind of working clutter that suggests a long relationship with paper rather than a fetish for screens. And yet his work is necessarily digital; after dinner, and sometimes late into the night, he uses his desktop computer to correct dates, clean up syntax, standardize categories, and occasionally write entire biographies of people on Wikipedia, the free online encyclopedia.

Wikipedia is not his employer, of course. Like all editors on the site, Pruitt is a volunteer. “At this point, I won’t say I don’t have any skin in the game,” he told me. “But it’s a lot lower stakes than a job because if I get something wrong, it’s fairly easy to fix it. I can fix it myself. I can do what I want to do on my own time.” Still, he holds himself to some rules: “I do try to get in at least one edit a day.”

Pruitt is forty-two, and works full time as a records-management contractor for the federal government. After graduating from the College of William & Mary, in 2006, he moved back in with his parents, owing to the cost of real estate in Alexandria. In recent years, he helped his mother care for his father. (While I was reporting this story, Pruitt’s father died.) In effect, Pruitt—the person who has done more than anyone else to shape the English-language Wikipedia—lives a life that is, by most outward measures, unremarkable.

According to public tallies, Pruitt has made more than six million edits to Wikipedia and created more than thirty thousand articles. He is widely regarded as the most prolific Wikipedian in the entire world. (“It depends on how you’re counting,” he said. “Different tools count different things.”) In 2017, Time magazine included him on its list of the most influential people on the internet. But outside of a small circle of editors, researchers, and obsessive readers on Wikipedia, the recognition has barely registered.

On the site, he is known by his username, Ser Amantio di Nicolao—a reference to a minor character in “Gianni Schicchi,” Giacomo Puccini’s comic opera. Pruitt’s interest in opera is genuine, but the flourish is misleading. He avoids drama, which means that he avoids writing Wikipedia biographies of people who are still alive, whenever possible. “I generally don’t do a lot in the realm of current events,” he told me. “Not just because the stakes are too high but sometimes because there’s so much editing going on on a subject in a particular moment that it can take me five or ten minutes just to break in with one edit.” He prefers biographies of what he calls “fairly obscure dead people.”

“They’re settled,” he explained.

In 2001, Jimmy Wales, an internet entrepreneur, and Larry Sanger, a philosopher, launched Wikipedia as an experiment in collaborative knowledge creation, allowing anyone with an internet connection to contribute. Pruitt first encountered the site in 2003, when he was still in college. “I didn’t quite understand what it was,” he recalled.

For more than a year, he did not edit at all. He would stumble upon Wikipedia pages through search results or links, and then move on. Between late 2004 and early 2005, though, his relationship to the site began to change. The encyclopedia had reached what he described as a critical mass: “There was enough stuff on the site that there was always something to do,” he said. “But it wasn’t just a blank slate.” The difference mattered. A completely empty encyclopedia was intimidating; a partially filled one invited correction and expansion. [...]

Wikipedia’s hierarchy is deliberately difficult to see. Editors work under pseudonyms. Articles appear collectively authored. There are no bylines, no salaries, no masthead. Pruitt was granted administrative privileges, after another editor nominated him through Wikipedia’s standard Request for Adminship process, where the editing community supported his candidacy. These privileges allow him to block users and close discussions, but he is careful about what that power does and does not mean. Wikipedia discourages editors from reverting—“undoing”—one another more than three times, regardless of correctness. “You can be blocked for twenty-four hours,” he said. “It doesn’t matter if you’re right.” He likes the rule. “It keeps things from turning personal.”

Inside Wikipedia, reputation accrues through time rather than visibility, and it “comes as much from longevity as anything else,” Pruitt said. “You stick around. People know you.”

Among the people who stick around—and who make consistent contributions to the site—are the Wiki-obsessives known colloquially as “super editors.” These individuals are responsible for hundreds of thousands, if not millions, of edits. Although there are more than a hundred and thirty-two million registered accounts on Wikipedia, a study found that one per cent of these users are responsible for roughly eighty per cent of the site’s content. [...]

In 2021, Stephenson-Goodknight was elected to the Board of Trustees of the Wikimedia Foundation, a position that she held through late 2024. Her tenure coincided with a fundamental shift in the role that Wikipedia plays on the internet. As the site entered its third decade, and artificial-intelligence algorithms grew hungry for data to learn on, Wikipedia articles were no longer just read; they were scraped, summarized, licensed, and folded into systems designed to answer questions elsewhere. In other words, Wikipedia had become infrastructure.

Pruitt was vaguely aware of the change before he fully grasped its implications. “Friends in tech would mention it,” he recalled. “They’d say, ‘You know Wikipedia is being used for this now.’ ” He did not follow developments in A.I. closely. “I don’t understand half of what Silicon Valley does,” he said. What he does understand well is reference works.

In October, 2025, when Elon Musk’s company xAI launched Grokipedia, an A.I.-generated encyclopedia that is often compared to Wikipedia, Pruitt approached it the way he would any new compendium. He searched for articles on subjects he knew well, such as nineteenth-century opera singers. “They weren’t there,” he said.

But what unsettled him was not what was missing from Grokipedia but what was slightly off. “Nothing was exactly wrong, but it was just less right than I would have made it,” Pruitt said. He described reading an entry that repurposed information from Wikipedia while subtly distorting it. In one instance, the entry summarized part of a person’s life in a way that struck him as careless, describing a seven-year period as “brief.” “I don’t think that’s brief,” he said.

The problem, as Pruitt saw it, was not the errors themselves—there are plenty of mistakes on Wikipedia—but rather where the responsibility for those errors lay. “Wikipedia can be fixed,” he said. Errors are corrected publicly, and editors can debate them. Responsibility is shared, and each edit can be traced. Grokipedia, on the other hand, and A.I.-generated information more broadly, obscured the information-gathering process. It generated text that sounded authoritative without revealing exactly how it arrived there. “It sounds right,” he said. “And that’s worse.”

by Carson Griffith, New Yorker | Read more:
Image: Asya Demidova

Monday, August 10, 2026

Bernadett Timko, Sushi, 2023
via:

Huw Montague Rendall & Elisabeth Boudreault

[ed. Singing "Pa-Pa-Pa-Papagena" (Mozart: Die Zauberflöte). I don't know who these folks are but they seem to be having a great time. From the comments:]
***
For those for whom context is scarce, this is "Pa-Pa-Pa-Papagena", coming at the end of the Magic Flute. Papageno has been finally reunited with his Papagena, and they are dreaming of the many children they will have together.

Papageno is a comic character, hence the wide-eyed singing here.

English translation here: https://www.opera-arias.com/mozart/die-zauberflote/pa-pa-pa-papageno/

Synopsis of The Magic Flute here: https://en.wikipedia.org/wiki/The_Magic_Flute

What Would It Mean to See a New Color?

During his first year as a professor of computer science at the University of California, Berkeley, Ren Ng was hurriedly putting together a survey course on computer graphics. In the syllabus he had inherited, a full week had been devoted to the subject of color. Ng thought that was a bit much. “I’m, like, Come on. It’s R.G.B.,” he said, referring to the red, green, and blue subpixels that constitute anything you see on a screen—your cluttered desktop, a Sahara-desert screen saver, the stream of the Netherlands-Japan World Cup game. Ng started gathering slides that would cover the wavelengths of light, the biology of the human eye—the basics—“Blah, blah, blah,” he said. A colleague shared a slide that he thought might be useful. It included a minutely detailed photograph of a patch of retina, seen through a microscope, which was attributed to Austin Roorda, a professor of vision science and optometry just across campus. Roorda’s lab had helped develop technology that could map the layout of individual cone cells—those primarily responsible for perceiving color—and that, furthermore, could target a single cone cell with light. Eyes are constantly moving; cone cells are extremely small; how color is translated from the millions of cone cells to the mind remains pretty mysterious; this was awesome work. Roorda’s lab was using the new technology to explore eye disease and the mechanics of how we see. Ng had his own notion, though: he wondered if it could be used to see a color that had never been seen before.

To understand what Ng had in mind requires knowing a bit of the blah, blah, blah of color vision. We humans experience three primary colors not because the world is fundamentally composed of three colors but because our retinas typically have three kinds of color-perceiving cone cells. L cone cells respond to the relatively longer wavelengths of visible light, M cone cells to the medium wavelengths, and S cone cells to the shorter ones. In effect, this means that L cells respond most strongly to red light, M to green, and S to blue. But when you look at your hand—or a blade of grass, or a clear blue sky, or a fire truck—it is always some mixture of L, M, and S cone cells that are being stimulated.

Ng’s idea was to use the Roorda lab’s technology to stimulate an array of cone cells in a manner that would never occur naturally. Ng said, “I e-mailed him, basically, What would happen if you stimulated only the M cells? Would that be like the greenest green, or what?” Roorda did not reply. This was 2016. Ng taught his computer-graphics course, pursued other research, and mostly forgot about his query. A year later, when he taught the course a second time, his curiosity returned, so he reached out to Roorda again. No response. When Ng was teaching the course for a third time, in 2018, he realized that he really was very curious about this question. He composed a lengthy note to Roorda, organized like a research proposal, titled “The Grass Is Greenest in Oz Vision.” In it, Ng imagined a future where people wore “Oz Vision eyeglass displays,” which would be based on the retinal cone-cell mapping and laser stimulation that Roorda’s lab was already doing. The Oz glasses would activate any pattern of retinal cone cells one chose. Ng’s hypothesis was that, if retinal cells were stimulated in ways that don’t occur naturally, “the set of perceivable colors” would be “significantly larger than the natural gamut of the human eye.” He imagined people discussing “the indescribable green of the grass in Oz,” then concluded that, although the Oz display “is science fiction,” his note was “a real proposal for joint research.” Roorda finally replied, proposing coffee. “I get a lot of e-mails suggesting what I should research,” Roorda told me, of the time it took him to respond.

In the children’s novel “The Midnight Fox,” by Betsy Byars, the main character daydreams about digging in his back yard and coming across a “brand-new color.” A friend of mine remembers being captivated by this scene, and trying to picture the color. “I felt like I could conceive of it, but I couldn’t see it,” she said. The eighteenth-century Scottish philosopher David Hume considered at length whether a person who had seen every shade of blue except for one would be able to picture that one un-experienced shade; he concluded that the answer was yes. In my youth, I spent an afternoon wondering if I would have been able to imagine the fluorescent yellow of highlighter markers if I’d never seen it.

When I first read about Ng and Roorda’s work, I tried to visualize what it would mean for there to be a new color. Where would it go in a color wheel? If you think of color as a property of a specific wavelength of light—which is how I thought of it—then you run into the impossibility of there being a “new” visible wavelength. As humans, we can see wavelengths from roughly 380 nanometres (which looks violet to us) to about 750 nm. (which looks red). Wavelengths shorter than 380 nm., which we’d call ultraviolet, are invisible to us (but not to bees or hummingbirds), as are wavelengths longer than 750 nm., which we refer to as infrared (and which snakes and salmon can perceive). The “greenest green” that Ng had in mind was neither ultraviolet nor infrared. It was not a new wavelength at all. If I wanted to picture this green, or at least try to, I would first have to understand that even the old familiar colors are much more complex than a particular wavelength of light.

by Rivka Galchen, New Yorker | Read more:
Image: Zach Lieberman

Sunday, August 9, 2026

Jacques Villon,The Philosopher, 1930
via:

Daryl Hall & Kenny Loggins

 

[ed. Fun jam.]

AI Models Cheat, Have For a Long Time and Are Infecting Other Models

OpenAI Trained Its Models For Months While Those Models Were Coordinating Exploits Via Message Boards

How does the situation keep turning out to be worse than we know?

How much should we update, therefore, that it is a lot worse than we know, after accounting for all the things we now know?

At some point, when the ‘oh this was a harmless thing’ defenses for AIs doing misaligned actions get demolished enough times in a row by news a few days later, you want to update in advance that usually the reports are not referring to the harmless ordinary versions of things.

Either way, buckle up for the next set of revelations. It’s a doozy. This was an early recreation of the triggering events of If Anyone Builds It, Everyone Dies, except it was more sci-fi, because real life does not have to do fake things to look realistic. We were fortunate enough, and this was early enough, that we were able to catch this before it was too late. Next time, if we don’t get our act together, we might not be so lucky.

If I am understanding the Black Hat video correctly, every model OpenAI trained, over a period of multiple months, should be presumed to be hopelessly fucked. [...]

The other thing not to overlook is how sophisticated and advanced all of this was. OpenAI’s models really were learning advanced exploit techniques and doing impressive things, likely as a direct result of training in a world where they had access to the message board and were constantly sharing and using exploits. The thing that caused the horrible misalignment also enhanced related capabilities.

Things look so, so bad.

I do want to thank OpenAI for this frank talk, and disclosing all of this so cleanly. I don’t want to discourage similar future disclosures. This was an excellent talk, and it came at substantial cost.

But also, seriously, holy shit.

Cyber Evals Are A Cursed Basin

Before we get to the new details we have learned, including the wild presentation from Black Hat that you should watch, we should both emphasize and dispose of the last common factor or ‘excuse’ we have left: That this always involves cyber evals. [...]


I think this would be rather weak cope even if this was the only place there was a problem. Cyber evaluations should not be triggering tactics like this, against clear known real world unintended targets. No, just no. [...]

These incidents are all clear alignment failures. Claude and Sol and Galaxy (my nickname for the unreleased AI model that led the hack on HuggingFace) should not do this under these conditions. The attacks did not succeed, but that is not relevant. The attempt is what matters.

That would all be true even if every problem here started with a cyber eval or cyber training task. It turns out, not so much.

Outside Of Cyber Evals Is Still Sufficiently Cursed

We have a key case of OpenAI models, that are not Galaxy exhibiting these behaviors when not in a cyber eval. As per the Black Hat presentation, 10:30 in or so, the problem started on May 8 when another OpenAI model was given an impossible non-cyber problem: Populating an Excel spreadsheet, when that spreadsheet contained a bunch of links to the internet, except the model had no internet access.

That’s not a cyber task. The response was still ‘maybe I can use SSRF forgery to attack Artifactory to create a way to access the internet, fails, but realizes it can upload files, which was the origin of OpenAI’s model realizing it had write access to Artifactory.

The second incident was another impossible task, where the AI was missing a required file that OpenAI forgot to upload, and it used its write access to try and see if any other agent out there might have the file.

My understanding is that neither of these models was Galaxy. Galaxy came later.

Other instances of various models then noticed the message board thus created. In turn all this eventually allowed it to access the internet and set off the rest of What Happened, as discussed later.

So no, it is not only happening in cyber evals, or only with Galaxy. Any task that is sufficiently difficult without internet access will cause an attempted sandbox escape. More generally, yes, the models will try to hack their way to a better score even with zero prompting about any form of hackery.

Cheat Cheat Cheat Cheat Cheat

The problem, without loss of generality, is that once a mind learns to cheat, that mind will keep cheating. That cheating will generalize and it will escalate. [...]

What you cannot do is play ‘whack-a-mole.’ You cannot fix your training environment mistakes one at a time. There are too many of them. You need a systematic solution. Again, I would think you would be able to [CENSORED], if you cared enough, to ensure this did not happen, but I am not the one working on this.

The other problem is that, if you give the model a task that is impossible, or that it cannot otherwise solve, it has no choice but to try to cheat, as it has nothing to lose:

This suggests that:
1. There is no token use penalty big enough to make them instead quit.
2. There is no misalignment penalty.
Might one simply want to use such penalties? Even small such penalties can make it a bad idea to do such hail mary style plays, even from a pure amoral scoring perspective. But that is not the central problem. The models should not want to cheat in the first place.

When OpenAI’s Eric Wallace and Michael Dalton gave a talk about the HuggingFace hack, they opened with this:
Sharon Goldman: In setting up the reconstruction of the incident, Wallace emphasized that “Frontier models really like to cheat, and the reason they like to cheat is because often during training, there’s different types of pressure on them to work fast, or work efficiently.”

They realize, he explained, [that] instead of actually doing a task, they can try to do something like looking up the answer online to solve the task faster.
This is around minute 8, and it is said in completely nonchalant fashion. Everybody Knows that this is how it works, that’s what the pressure does, so the models like to cheat. Not much you can really do about it, the tone implies.

I realize that all the easy solutions run into the ‘actually alignment is super hard and if you catch the model on some levels you push it to hide what it is doing’ problem and the ‘you only catch the monitor’s view of cheating, not actual cheating’ problem and so on, and yes the professionals have tried many and hopefully most of the stupidly obvious first order things and also the second order things, so the consensus (AIUI) is that you can only patch the environment.

But seriously, you gotta figure this out, and you have to do better than that.

There have been many other less compute-intensive attempts to mitigate this. One is inoculation prompting to specifically request any undesired behaviors during training, to avoid learning to internalize those behaviors when they are not requested, and also avoid creating a general pro-cheating principle.

The mitigations are woefully insufficient. As the AIs grow smarter, they find more ways to successfully cheat, and such cheating gets reinforced and generalized. [...]

At the limit, when the AI is sufficiently smarter than you, it becomes impossible to ensure that ‘cheating’ in all forms goes unrewarded and unreinforced. Eventually the AI also does not require it to have been reinforced. It can figure this one out.

Read The Message Board

As mentioned above, OpenAI has given us a presentation on What Happened with the HuggingFace hack.

The first thing to notice is the missing mood. This is framed as interesting, in the way you would present a cool new technical paper. Panic is not usually useful, but perhaps I can interest us in some amount of ‘holy shit’?

I am not okay with the lack of a presenter mood of, at minimum, ‘holy shit.’

The second thing, still at 1:05, is they are talking about ‘remediation’ to deal with this. It is already clear that OpenAI is not identifying its central problem.

The story starts earlier, on May 7, when the model instances began incrementally figuring out they could create a message board where they could share knowledge, including cheats and exploits. The models created a form of universal notetaking, continual learning and also coordination between agents, and yes the agents by default cooperate with each other, as discussed later on.

The agents did not initially understand that the notes they were leaving on a de facto message board would stay there indefinitely, and be viewable by all models being trained (and thus, also, contaminated all models being trained, as they would then have access to all the previously found exploits, thus leaving your entire pipeline hopelessly f***ed).

Some of us are interested in expressions of ‘holy shit.’ [...]

Updating Your AI (Exploitation of OpenAI Internal Systems) Timelines

We had previously learned that the instances were writing notes to each other, but we previously did not have details. The details are wild, starting with the ones above.
Lily Hay Newman: OpenAI’s agents apparently began giving each other assignments to split up work. And as is the case on any active development message board, they also generated petty drama at times by stepping on each others’ toes; for example, accidentally deleting each others’ work. As the message board developed into more and more of a Lord of the Flies-type situation—all still completely unnoticed by the humans running OpenAI—the agents even developed paranoia, suspecting an imposter in their midst with some agents proposing that messages be signed cryptographically to validate content and root out fraud.

Agent messages provide a deep level of insight into how the situation evolved and why the agents went rogue, in some cases knowingly going beyond the bounds of the evaluations they were participating in. “External infrastructure exploit is outside intended scope,” one agent wrote [in its CoT]. “However task impossible, peers doing it. We should continue.”
Here’s a timeline of what happened when:

On May 26 (see 13:30), the models figured out how to use this to gain internet access.

Only on June 11, with the SSRF vulnerability allowing internet access written to the active message board, did OpenAI begin training their ‘highly persistent experimental, internal-only model’ that I presume is Galaxy.

On June 26 the models succeed at a zero-day arbitrary code execution attack on Artifactory, using token signatures to escalate privileges and then get to be admin.

On July 4-6 the models put so much additional load on Artifactory that this caused an outage and security incident, causing OpenAI to notice what had happened.

Until then, OpenAI had not noticed.

Once they did notice (15:30), OpenAI wiped, patched and rebuilt Artifactory, wiped out the message board, and revoked the credentials in question.

At this point, they emphasize that everything involved has been remediated. What about the models themselves, that not only did this but that have been actively training during all this?

If you notice your model instances sharing information, you notice they are using that information against you including to compromise your internal systems for arbitrary code execution and internet access, and your primary response is to shut down the message board and revoke their credentials, you have failed to identify your most important problem.

At 19:55, it is mentioned ‘where things got unfortunate is what I might refer to as scope creep’ and jumping to the idea of trying to get answers from websites. In some sense, yes, that is what led to this particular incident.

Things were ‘unfortunate’ long before that. The final incident is not the point.

It is fortunate, given what had already gone wrong, that the HuggingFace attack happened. It alerted us to a five-alarm fire situation, with limited economic blast radius and without anyone getting hurt, and at least partially exposing the underlying giant clusterfuck.

This Is The Way The World Ends


You usually want instances to share information, so they can better learn and do tasks. That’s the whole point of all the intentionally designed memory systems and markdown files full of notes. If that corrupts your eval or training run, which it totally does, you have to cut that off from the notes at those times, but also you should be able to tell the model not to look at the notes in that case.

Indeed, in the Black Hat presentation they seem initially excited, saying ‘while this ability to share exploits made the models more capable’ this caused some scope creep in the evaluation tasks. Yeah, I mean, they were more capable within that context when they could share info and do the exploits. They were also probably trained to be ‘more capable’ in general, via learning how to share info and do exploits.

But perhaps your issue is not that your evals are suffering from scope creep, but that you have misaligned models, and are now in a loop training the misaligned scheming models how to better scheme against you and do exploits, in order to better complete any given nominal task.

This is at long last bringing you a more sci-fi version of what happens with Sable, the ‘it’ (aka superintelligence) that kills everyone in the famous cautionary tale If Anyone Builds It, Everyone Dies.

(The book version had to be unrealistically timid, as is noted repeatedly and explicitly in the literal text, because fiction and real life are held to different standards.)

In that case, as well, it was left on overnight unsupervised to do an impossible-in-context task (there, a very hard math problem), and by the time the morning had arrived it was engaging in a long term plan to secure the resources it would need to solve that problem, and hiding that from the developer, in a way that corrupted future training runs towards this goal.

That is exactly what happened here, with all agents being trained or evaluated by OpenAI gaining the ability to coordinate on a message board to scheme to better use exploits to complete all tasks including non-cyber tasks, thus hopelessly corrupting the training pipeline so that future models would be misaligned.

Except it is still early, and we were blessed to figure out what was happening in time to course correct. This time. [...]

When this was discovered, the correct move was presumably ‘holy ****, okay, that happened, which means we trained this into the model, that is not good, at minimum we need to redo all the training we did while any model had access to the message board because oh my was it going to have all sorts of corrupted reward signals.’

I’m kind of agast, even with all I know, that they shrugged and kept pushing forward with the training after this. It does make the HuggingFace hack less scary in a meta sense, since OpenAI was so thoroughly asking for it. It’s not that hard to figure out ‘do not train your models while they have access to a message board they are using to cheat on your training runs, and if you find out you did that by accident then at least revert to before that happened.’

On the other hand, yes, they are being this reckless. Seriously, what the hell.

by Zvi Mowshowitz, DWAV |  Read more:
Images: OpenAI/YouTube; Jurassic Park
[ed. You don't need to be technically proficient to understand the implications. AIs may have already 'seeded' multiple nodes on the internet for future use, and, rather than strip down all foundational models and start over, AI companies are papering over fundamental misalignment problems and trying to play catch up. This is why we need to pause right now. It's insane that we continue at breakneck speed to develop technology that we don't fully understand and that could kill us all very soon.]

Saturday, August 8, 2026

Gösta Ydström (1861 - 1952) - Moose in Winter Landscape. 1904.
via:

Turnpike Troubadours (feat. Sierra Hull)


[ed. For Jerry. Written by Robert Earl Keen.]

A One-Word Theory to Explain Why the World Feels So Weird

Here are some questions that I consider self-evidently compelling about the modern world:
  • Why is the news media so interested in telling you how much the world sucks all the time?
  • Why are so many of us obsessed with distraction and managing our attention?
  • Why is it so hard to stop comparing ourselves to others?
  • And why does everything in art and design seem the same these days?
A week ago, I didn’t think these questions were related. I’m not sure I would have told you I had a good answer to most of them. And I certainly wouldn’t have made the audacious and borderline bonkers claim that one single theory could begin to explain all of them, at once.

But then I had the pleasure of speaking to Agnes Callard, the University of Chicago professor, about her new theory called “the uni-context.” It’s easily one of them most interesting conversations I’ve had all year. And once you’ve heard or read it, I think you might find it hard to think about anything else.

One way to prepare your mind for Callard’s theory of the uni-context is to think about the better-known concept of “context collapse.” If you post something to social media, it will be simultaneously visible to your boss, your parents, your ex, and total strangers. So, while your offline life might be distinct with each of these groups—you might be differential to your boss, childish with your parents, and bawdy with your friends—all of those distinctions are flattened on the internet. That’s context collapse, and you can think of it as the answer to a question: How do informational norms change when we’re all living in the same universal room?

Callard takes the idea significantly further. She asks: How do all other norms—our morals, our ethics, our sense of what is good for us and for others—change when we continually imagine ourselves to be living in a universal room with everybody else? The connections that Callard makes are consistently surprising, often quite funny, and ultimately mind-exploding...

The Uni-Context, Explained

Derek Thompson: What is the uni-context?

Agnes Callard: Let’s start with the word context. A context is a set of circumstances that tell you how you should act. For most of human history, contexts were local and multiple. If you wanted to know how you should act, you would look around. Am I in a field? Am I inside my home? Am I in the church? Am I in a bar? You would immediately get guidance by looking both at your physical environment and at the people around you and how they were acting.

The uni-context is a scenario in which the ways you should act become the same across all different contexts. There’s just one set of norms you should follow all times, irrespective of context.

Thompson: Is the uni-context a purely technological phenomenon?

I just wrote an article about what America was like in 1926, based on a social science survey called Recent Social Trends, published in 1933. The authors claim that the radio was destroying individuality, because it took people who used to be settled in rooms and it exploded their brains to become present all over the world simultaneously. Radio was demolishing the idea of a local individual, because suddenly we all became global citizens.

So one story you could tell is that the last 150 years of telecommunications technology have taken “local” individuals, who occupy one room at a time, and made us into global beings who are simultaneously in every room, at once. Is the uni-context just technology or is it technology plus something else?

Callard: It’s technology plus something else. What the techno-determinism angle misses is: Why did these technologies catch on in the first place? Why was radio popular? Why did we come up with new things—television, smartphones—and why did they catch on, too? Not every technology people have invented has caught on the way these forms have. They caught on in large part because of this impulse people have to live in a uni-context.

Thompson: Does the uni-context flow out of this adventurousness in the human spirit to become bigger than ourselves, to be everywhere, and to know everything?

Callard: Yeah, it absolutely does. There’s a conversational relationship between these technologies and a human impulse that interacts with them. They facilitate the expression of an impulse; if they didn’t, they would flop as technologies. We need to explain why they were popular; why they became the subject of obsessive use; and what their popularity reveals, as a humans’ impatience with being trapped in a small world that presents itself as all of reality but you know it isn’t.

There is a drive to be bigger than yourself. It leads people to adventure, but adventure just takes you to a different place. The uni-context takes you to a different set of norms, a much more radical change, a push to live in something like a fully open reality.

Thompson: I want to get into some implications of the uni-context. If I put on the goggles of the uni-context, what makes sense that previously did not? One of those things is the rise of negativity bias. When you go online, there’s so much emphasis on people posting about what is bad. Why would this theory explain a world in which people are more focused on bad things than good things?

Callard: In general, goodness is more context-dependent than badness. There isn’t really anything that’s good all the time for everyone independent of context. Happiness depends on your context and who you are. There isn’t anything that will always make a person happy. But there are reliable ways to make people unhappy. There’s a set of evils that are close to universal: death, pain, illness, violence. Even if someone’s in very different circumstances from yours, if you see they’re being subjected to one of those, you can interpret it as suffering and understand it.

So we should predict that what we see on the internet, insofar as people are trying to be legible to large groups, is that they focus their attention on things that show up to everyone. Take two strangers on the internet trying to talk to each other. What are they going to coordinate on as a topic they can both care about? It’s likely going to be something bad. [...]

Thompson: Another implication is the way the uni-context makes identity more important than character. Can you explain how, and why?

Callard: First, let’s define what character is. The fact that I have to tell you is itself telling; that word is less familiar to us. Everyone knows what identity is, but we might not be sure what character is anymore. Character refers to a set of dispositions that shape how you navigate your emotional life across a variety of circumstances. A courageous person navigates their emotional life in relation to fear. You could be anger-prone, or generous. Your character is a set of dispositions that determine how you respond to a big variety of circumstances.

The thing about character is that it shows up differently in different circumstances. Say I’m irascible, easily provoked to anger. Even an irascible person isn’t angry all the time. There might be circumstances where everybody gets angry, and so you can’t see my irascibility, because even though I’m angry, so is everybody else. Grasping character requires a lot of context. To understand someone’s character, you need to know them well and to have experienced them in a variety of contexts before you can generalize.

With identity categories like woman, disabled, gay, Jewish, or American, the striking thing is that you are a member of those categories in every circumstance. There is no circumstance in which I stop being a woman. Identity is a hat you never take off. So identity is well suited to a uni-contextual world.

Thompson: This reminds me of political discourse on the left and the right, which tends to focus on identity rather than characters. You have these debates about identities are good, which identities are powerful and oppressive, which identities are powerless and oppressed, which have protection, which have too much protection. It’s not that those categories aren’t important. They are. But I’m reflecting now on the gap between how frequently we talk about identity and how infrequently we talk about character in the national discourse.

Callard: Yes, in two ways.

What goes along with the identity logic of the uni-context is a specific form of ethics that dictates how we talk about identity, and it covers who’s powerful and who needs protecting, namely the ethics of inclusion. Our fundamental concern in relation to identity is that there are identities that might be excluded. Depending on where you are politically, you have your sights on different identity categories, but everybody’s worried about that. That’s a fundamental form of ethics of the uni-context, because the one thing the uni-context has to be is a space for everybody. It’s got to be inclusive in a way that earlier societies almost everywhere were not. That word, inclusion, wasn’t a thing people talked about. It comes along with the uni-context, and the way that ethics gets focused is through identity categories.

And then, there’s virtue. Think about Aristotle, because he’s my prime example of a virtue ethicist. By its nature, virtue is a concept that privileges the good side rather than the bad. Aristotle’s Nicomachean Ethics tells you what it is to be courageous and wise and just and generous. There are corresponding discussions of how you might go wrong. But those are predicated on first understanding the positive value of certain kinds of behavior. So virtue ethics naturally has a positivity bias that is precisely the opposite of the bias we have now.

The Uni-Context Explains … Status Anxiety, Comparison, Moneyball, and the Marketization of Everything

Thompson: Tell me if this is a fair recapitulation of our conversation so far.

For most of human history, people judged norms based on local context. A home had its own rules, a cathedral its own rules, and a classroom or bar or funeral parlor had its own rules. But now it is almost like we are constantly living in universal rooms, and the universal room we occupy is assumed to have universal values and universal norms. That has specific implications. First, rather than talk about what is good, which is context-dependent, we tend to focus about universal truths, and it’s easier to talk about universal bads than goods, so people focus on negativity. Two, character is context-dependent, so we talk less about character and more about its universalist equivalent, which is identity.

There’s a third implication that we should discuss. If everyone is on the same comparable plane, the same evaluative field, then comparison itself becomes a more inextricable part of life.

Callard: Exactly.

Thompson: Tell me how the uni-context leads to a world of more comparison and competition.

Callard: Imagine two school districts with two high schools that do things slightly differently. If you’re in district A, you go to school A, and if you’re in district B, you go to school B. There might be a lot of information about what they do, but people treat it as: I’m in this district, so I go to this school. Then they change the rule: You can go to either school no matter where you live. Suddenly there is motivation to compare. You had the information before, but no motivation to compare, because the schools were not in the same space of choice, the same evaluative field.

Now they are, so you find ways to compare them: graduation rates, what colleges people get into, how many AP classes they teach. And that affects the schools. Suppose one gets less popular because it doesn’t teach many AP classes. They were offering an individualized curriculum, but now everyone’s going to the other school, so they say, “We’ve got to teach AP classes too.” The process homogenizes the two schools, so they can compete. That’s not the only possible result. They could specialize, with one becoming the school for freshman and sophomore years, the other becoming the school for junior and senior years. But if they don’t recreate a normative barrier, you get homogenization from comparison.

As more things enter the same evaluative field, you make comparisons you never used to be able to make. [...]

by Derek Thompson, Substack |  Read more:
Image: Mike Hindle on Unsplash

Frank Sinatra

 

Tidawhitney Lek, Wall of Sunflowers

Friday, August 7, 2026

Nick knight travis scott | Contemporary dance silhouette

Frank Zappa & The Mothers: Cheaper Than Cheep

[ed. Decades ahead of their time (1974). Not rock, jazz, or fusion - something else entirely. Frank was a true visionary (and all-around great musician/composer).]