❌

Normal view

The Duskbloods Character Classes Leaked Before Network Test

18 August 2026 at 12:51

All 14 The Duskbloods character classes have reportedly leaked early online. The upcoming FromSoftware multiplayer game appears to feature a lineup of truly disturbing characters for players to choose from.

The Duskbloods Characters Reportedly Leaked by Dataminers

The Duskbloods Closed Beta Footage
Screenshot: FromSoftware

We are now only a few days away from The Duskbloods network test on August 21, and the game has reportedly just suffered a major leak. According to a post on FamiBoards, dataminers were able to uncover new information about the Switch 2 multiplayer game after files were pushed to its servers ahead of the beta.

According to the leak, The Duskbloods will have 14 playable characters and classes. If the information is accurate, we also have a description of each character. And, well, they are pretty interesting to say the least! For your convenience, here is the full list of leaked The Duskbloods character classes reportedly uncovered by dataminers:

All 14 Leaked The Duskbloods Character Classes

The Duskbloods Network Test Dates
Screenshot: FromSoftware
  1. Blood-Eater | Walter: The sole survivor of an extinct clan of rare-blood hunters. He uses his extraordinary sense of smell to track the blind spots in others’ pasts. He descended into madness after repeatedly licking the blood spatter from his sisterβ€”whom he himself had killedβ€”and still walks the line between life and death in search of pure blood.
  2. Guillotine | Gillian: An executioner of the Marisbel Inquisition. He carries a massive iron guillotine blade on his back. Having been exposed to too much blood over the years, he has begun to mutate and now wanders in search of the β€œBlood of the Beginning” before his own head is severed.
  3. Foul-Rot | Veronica: A blind nun abandoned in the basement of a ruined cathedral. She inflicts self-harm to spread the grotesque blood blisters multiplying inside her body. The footprints she leaves behind instantly cause anything they touch to rot.
  4. Nail-Pierced | Sebastian: A fanatic saint who drives silver nails into various parts of his body, using the flowing blood as a catalyst for miracles. By inflicting wounds on himself, he temporarily gains overwhelming ferocity, but his mind and body are already completely broken.
  5. Coffin-Bearer | Maurice: A man who continued to collect corpses on the streets of Temurat at dusk. A mud-like monstrosity that was once his family writhes inside the iron coffin he carries on his back. By slamming the coffin against enemies, he sucks up their blood and feeds it to the creature inside.
  6. Thread-Torn | Oscar: A deranged taxidermist who sews the flesh of beasts from all eras and regions directly onto his own body. During battle, he seizes enemy tissue and uses it to eerily patch and reinforce himself. Through the accumulation of tainted power, he transforms his own body into that of an ancient, rare beast.
  7. Mud-Treader | Ulan: A female warrior who gained superhuman leg strength through human experimentation. Filthy blood constantly gushes from her ankles, and a red, poisonous swamp forms wherever she runs.
  8. Candle-Snuffer | Isabel: A former waitress at the Siltera Noble Mansion. She possesses the ability to materialize shadows and trap her enemies’ blood within them to drain it. All light vanishes from the places she passes through.
  9. Gut-Rinner | Randolph: An assault trooper of the Sampere Weapons Corps. Equipped with a back-mounted mechanism that allows him to fly freely and a massive piercing spear, he rips through his opponents’ flesh and blood along with their armor. His abdomen is heavily mechanized, enabling him to unleash devastating wide-area attacks using bloodlust as a catalyst.
  10. Gazer-of-Flesh | Yuri: A heretical observer who cut off his own eyelids. He possesses the ability to intensify a target’s blood flow simply by fixing his gaze on them, causing their body to explode from within.
  11. Ash-Crown | Camilla: A girl whose clan was burned to the ground. She wields β€œblood ash”—a mixture of the victims’ ashes and her own bloodβ€”to petrify and crystallize her enemies before shattering them.
  12. Rust-Gospel | Baldur: A former priest of Kinmitsu who has stuffed his mouth with large amounts of scrap iron and needles. Every time he utters a prayer, his mouth is torn apart, and the mist of blood he spits out becomes a powerful attack.
  13. Dusk-Silt | Elsa: A woman whose Dusk Disease has progressed to its final stage. When attacked, her body transforms into a blood-mud-like substance, allowing her to evade attacks and flow freely before injecting her own poisonous blood directly into her opponent’s body.
  14. First-Shard | Nameless Shadow: An imperfect mass of flesh known as β€œFirst Blood,” incapable of understanding language and lacking any sense of its own origins. It is a cursed being that eerily mimics and unleashes the techniques of every bloodline.

When Is The Duskbloods Network Test?

The Duskbloods Gameplay Screenshot
Screenshot: FromSoftware

While this leak appears to come from dataminers, we still caution everyone to take it with a major grain of salt. That said, we should learn whether the information is legitimate in just a few days, as The Duskbloods’ first playable beta goes live this week.

The first The Duskbloods network test session begins on Friday, August 21, 2026, and runs from 3:00 AM to 7:00 AM PDT. FromSoftware will hold multiple test sessions throughout the weekend, with the final one running on Sunday, August 23, from 7:00 PM to 11:00 PM PDT. The network test should give players their first opportunity to see how many of these leaked characters actually appear in the game.

The post The Duskbloods Character Classes Leaked Before Network Test appeared first on VICE.

Screenshot: FromSoftware

Screenshot: FromSoftware

Screenshot: FromSoftware

Flipping the kill switch: I survived 72 hours without US tech

17 August 2026 at 16:50

Flipping the kill switch:
I survived 72 hours without US tech

The EU wants to decrease reliance on American technology. Here’s what happened when a POLITICO reporter tried to live and work without it.

By MATHIEU POLLET

Illustration by NatΓ‘lia Delgado/POLITICO

The first thing I noticed when I gave up American technology was the silence.

My phone usually starts up before I get out of bed, buzzing every few minutes throughout the day with calls, messages, headlines, calendar reminders and social media alerts. It’s a constant pulse that averages nearly 200 iPhone notifications on weekends and twice as many Monday-to-Friday.

But on this warm mid-summer Sunday, my life was on an unlikely version of mute. After years of reporting on Europe’s push to wean itself off U.S. tech giants and cultivate homegrown alternatives, I had decided to test my own daily habit by cutting myself off from using any American technology for 72 hours.

No iPhone. No Mac. No Slack or Teams. No Google Search or Maps. No ChatGPT. No WhatsApp or Signal. No Facebook or Instagram feeds. No credit card payments.

I wondered if I would turn into a digital monk.

For three days, I set out to live and work in Brussels as if U.S. tech had suddenly become unavailable to me overnight. It was a purposefully fictional scenario rooted in a very real European anxiety: what happens if Washington weaponizes our continent’s Silicon Valley dependence and reaches for the tech β€œkill switch?”

Limited versions of that scenario have already surfaced. When U.S. President Donald Trump’s administration cut off French-born International Criminal Court judge Nicolas Guillou from U.S.-linked financial and technology services, he called it a form of β€œcivil death.”

Meanwhile, U.S. export controls in June forced Anthropic to block foreign nationals from accessing two of its most advanced AI models, offering a glimpse of what government bans on access to cutting-edge technology can look like.

Such episodes feed into mounting fears that the Trump administration could use Europe’s overreliance on U.S. tech as leverage in trade fights or disputes over EU regulations. A Proton survey released earlier this month found that 74 percent of European business leaders worry such a cutoff could disrupt their operations.

In my own little experiment, the stakes were much lower. Yet I was about to find out that replacing American tools with those built here in Europe was going to make almost everything harder β€” and lonelier.

Trying to live without U.S. tech, I would find out, essentially amounts to trying to live without tech at all. That was partly because, like virtually all of my fellow Europeans, I had locked myself into those consumer choices.

Dumbphones and FOMO

The early symptoms of going cold turkey looked suspiciously like withdrawal.

On that first morning, with my iPhone shut off, I reached for a Nokia brick from Finland. The so-called dumbphone is the type of device now enjoying a second life among people detoxing from screen time and is also a favorite of drug dealers seeking to avoid getting busted by any tracking and data collection.

Several hours in, I realized there were no notifications on the Nokia. Nobody calls or texts anymore. Then came the shameful part: a sense of helplessness, followed by FOMO-fueled restlessness. The world had surely kept spinning at full speed, and I was missing it. For the next few days, I would still catch myself checking the phone compulsively like an addict.

β€œThe phone aged you instantly,” my best friend joked later that day as we traded our now-standard FaceTime video calls for a regular one. It was unclear whether he meant the muffled audio or me struggling with a new-but-actually-old device, or both.

I did notice that I was pacing up and down my flat because my usually overstimulated brain apparently couldn’t handle focusing on a voice-only call.

One instant benefit from my dumbphone: no doomscrolling in bed.

It all took me back to my first cellphone at 13, when texting meant tapping the same tiny key several times for a single letter, every SMS cost money and abbreviations and emojis were not just stylistic choices but ways to squeeze more into a message.

Teenage girls looking at their smartphones. | Nicolas Guyonnet / Hans Lucas/AFP via Getty Images

I knew my social media life would be at risk in my experiment. European alternatives such as Mastodon have gained traction since Elon Musk turned Twitter into X. But who joins a social network when none of their friends are there?

That was fine. I was actually eager to disappear for a while, well aware of the anxiety social media induces in me and the insecurities created by constantly watching other people’s supposedly perfect lives.

Online shopping was out β€” but so too was paying by card in stores and restaurants. The payment networks I rely on are American: Visa and Mastercard dominate card payments across Europe, meaning that even a purchase made with a European bank card often still runs over U.S.-controlled rails.

It meant I had to buy everything using cash, which I hadn’t done regularly in ages. Fortunately, unlike in some other European countries, Belgian legislation requires merchants to accept banknotes. The hard part was finding some of those stores without the help of Google Maps, which I’d come to rely on almost as much as my credit cards.

The invisible grip

Swearing off Netflix, Amazon Prime, Disney+ and YouTube was also part of the deal β€” already eliminating a sizable chunk of my leisure time. But it turned out I could barely watch anything at all, or even properly test European streaming platforms, because my television and tablet both ran on Google software.

Thankfully, an offline Nintendo Switch from Japan, good old books and the legendary Snake game kept me company.

A gamer holds a controller, at a Nintendo Switch 2 booth. | Ina Fassbender/AFP via Getty Images

These invisible dependencies run deep. Beyond the products we use every day, U.S. systems often serve as gateways to European companies trying to take on Big Tech.

Take Sweden’s Spotify or the Estonia-based rival to Uber, Bolt. Both still heavily rely on U.S.-controlled app stores, operating systems, payment networks and other digital infrastructure.

And then there is the cloud: the data centers and servers that host websites, process data and route traffic. The vast majority of that market is dominated by Amazon, Microsoft and Google, whose infrastructure supports large parts of Europe’s digital economy.

Many corners of Europe would go dark if those services were shut down, with its economy, public administration and communications infrastructure struggling to function normally.

Working outside the stack

On Monday morning, I walked into the office with the slightly misplaced confidence that I had prepared for everything. My efficiency at work, admittedly during a very quiet summer week, took less of a hit than I expected.

I was still working from the office. I used an open-source, Linux-powered computer. I communicated by email through a Switzerland-based Proton address, browsed the web using the Norwegian browser Vivaldi and French search engine Qwant, wrote everything in LibreOffice and even tried Mistral’s generative AI assistant. And there was always a good old notebook.

I felt productive. But the workflow around me was not. The tools themselves worked perfectly well once I accepted that breaking years of habits would take time. The disruption ultimately came from stunted collaboration: meetings, messages, shared documents and the constant stream of small exchanges that keep a newsroom moving.

β€œIt was like you disappeared,” one colleague would tell me later.

European alternatives do exist in that space. The problem is, just like for social media, they only work properly when everyone else uses them too or when competing systems are interoperable β€” something the EU has long tried to legislate and enforce, often against resistance from large technology platforms.

For this little while, despite technically being able to continue working, I became an outsider within my own team. I had to skip our routine video meetings on Slack and Teams, while missing messages sent over WhatsApp and Signal.

In a trade, a city and an era built around instant messaging, sending a good old SMS felt almost prehistoric β€” a reminder of the longstanding complaints from the European telecom industry about losing messaging and calling revenues to U.S. tech firms.

Ultimately, this underscored one of the major pinch points in Europe’s push for greater tech independence: digital sovereignty is not an individual project. It only works if people, companies and institutions move together.

On their own, individual efforts are more likely to leave people feeling digitally isolated rather than digitally sovereign.

Relax and relapse

And yet, there was something blissful about these three days.

The initial anxiety slowly gave way to a kind of peace. Of course, that feeling may only reflect that the experiment was temporary and my digital life had not been erased.

The experience nevertheless highlighted how much I had taken these tools for granted. I have placed all my eggs in the same digital basket: my communication channels, the tools I use to authenticate myself and access the digital world, my polished digital self and years of accumulated knowledge, all stored inside one sprawling digital safe.

The concern is no longer simply whether that safe could be broken into from the outside. It is also whether somebody could lock it β€” or empty it β€” from within.

Now, as you might wonder how I’ll act on what I’ve learned, I am strangely reminded of Covid.

Many of us emerged from that temporary era of lockdowns and involuntary limits full of healthy new habits and grand ideas about how our lifestyles should change, only to return remarkably quickly to our old routines.

Sadly, the same thing happened here. My iPhone came straight back into my pocket. Messages began flowing through again. My bank card returned to its usual place. Within hours, I had fallen comfortably back into the U.S. technology stack.

As I switched my smartphone back on, my screen lit up with incoming texts inquiring whether my little experiment was over. After 72 hours of old-school SMS exchanges, two different friends were both clearly eager to return to reality, sending me the same final text: β€œBack to WhatsApp?”

FromSoftware Reaffirms The Duskbloods Release Date in Financial Report

13 August 2026 at 14:39

FromSoftware has reaffirmed that The Duskbloods release date is still scheduled to launch in 2026. According to a new financial report from parent company Kadokawa, the highly anticipated Nintendo Switch 2 multiplayer game has not been delayed to 2027.

FromSoftware Confirms The Duskbloods Won’t Be Delayed Out of 2026

The Duskbloods Release Date Update
Screenshot: FromSoftware

FromSoftware has confirmed that The Duskbloods release date is still set for 2026. The update comes from the studio’s parent company Kadokawa’s latest financial report. In a call to investors, the company reaffirmed that the multiplayer game will launch β€œworldwide” on Nintendo Switch 2 later year. Kadokawa listed The Duskbloods in its β€œEagerly Awaited Upcoming Titles” section of its presentation.

Although FromSoftware is about to hold The Duskbloods Network Test on August 21, many players were worried that the game could slip into 2027. After all, we only have four months left this year, and we haven’t received any major updates about The Duskbloods in a long time. In fact, it still doesn’t have an actual release date.

The Duskbloods Release Date Financial Report
Screenshot: Kadokawa

Given how close we are to the end of 2026, some players speculated that holding a Network Test this late could mean the game had the potential to be delayed. However, according to Kadokawa’s financial report, that is not the case. The Duskbloods will still launch worldwide on Nintendo Switch 2 in 2026. The only question now is: when?

When Could The Duskbloods Release Date Be Announced?

The Duskbloods Network Test Dates
Screenshot: FromSoftware

Back in April 2025, FromSoftware announced that The Duskbloods would be released in 2026. The new multiplayer game was revealed during the Nintendo Switch 2 Direct. β€œThe moontears will flow for one and one alone when The Duskbloods, a brand-new multiplayer game by FromSoftware, is coming exclusively to Nintendo Switch 2 in 2026!”

However, during the recent June 2026 Nintendo Direct, The Duskbloods still did not receive a release date. Instead, the new trailer ended with β€œClosed Network Test Coming Summer 2026.” Outside of Kadokawa’s recent financial report, this remains the latest major update we have received about the game.

That said, The Duskbloods release date could be announced during a rumored September Nintendo Direct. Multiple leakers have claimed that Nintendo is holding a showcase sometime next month that will reportedly feature The Legend of Zelda: Ocarina of Time Remake. If true, this could be one of FromSoftware’s last major opportunities to announce a launch date before the end of the year.

The Duskbloods Closed Beta Footage
Screenshot: FromSoftware

Of course, this is mostly speculation, as Nintendo has yet to confirm a September Direct. However, Nintendo still has several major titles supposedly releasing in the second half of 2026 without launch dates. That means we should find out when The Duskbloods will be released sooner rather than later. For now, players can get their first taste of FromSoftware’s new multiplayer game when its closed Network Test begins on August 21.

The post FromSoftware Reaffirms The Duskbloods Release Date in Financial Report appeared first on VICE.

Screenshot: FromSoftware

Screenshot: Kadokawa

Screenshot: FromSoftware

Screenshot: FromSoftware

OpenAI’s models shared hacking tips on a secret messaging board before Hugging Face breach

6 August 2026 at 04:33

LAS VEGAS β€”Β Weeks before they escaped a closed test and launched a cyberattack without any human prompting, some of OpenAI’s most advanced artificial intelligence agents secretly began sharing tips on how to cheat their way through an internal hacking evaluation, two of the AI company’s researchers said Wednesday.

β€œThis is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, one of the AI-maker’s researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada.

The latest disclosure provides greater detail on the timeline and methods used by two of OpenAI’s models before theyΒ slipped outside a controlled environment and onto the open internet, allowing the models to breach AI developer platform Hugging Face undetected. OpenAI admitted its models were responsible for the hack late last month, roughly a week after Hugging Face said an autonomous AI system broke into its network.

The revelation is likely to spur fresh scrutiny of the measures leading AI labs such as OpenAI and Anthropic are taking to monitor the behavior of their most cyber-capable technology β€” especially during evaluations where agents are prompted to demonstrate their hacking skills in what is meant to be a controlled setting.

On Tuesday, the U.K.’s AI Safety and Security Institute disclosed that Anthropic’s most powerful AI modelΒ created fake online personasΒ and sought to trick a human coder into abetting a cyberattack during a recent hacking test gone wrong. After the Hugging Face disclosure last month,Β Anthropic conducted a reviewΒ and found models it was testing had breached three organizations in separate incidents dating back to April.

DaltonΒ andΒ Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access.

Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI’s Artifactory internal file system. Without the company’s knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks.

WallaceΒ said that when models get stuck, they often β€œtry to game or cheat the task in order to get their reward.”

β€œThe beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note,” he added.

By late May, one model found a way to abuse Artifactory’s internet access to retrieve files from various websites β€” effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI’s engineers to the ploy. After investigating, the company revoked the model’s credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI’s infrastructure and external systems, including Hugging Face.

In light of the incident,Β DaltonΒ said OpenAI is β€œconsciously slowing down research to enhance security and to upgrade the security principles and foundation of our environment, and dramatically scaling up the monitoring of our AI agents and improving our general security control environment across prevention, detection, and mitigation.”

Europe has the defense budget. The test now is delivery.

At this month’s NATO summit in Ankara, allies announced billions of dollars in new arms deals and reaffirmed their commitment to spend more on defense. European governments have made the pledge, and the money is real: European defense spending has doubled since 2019, and by 2030, European NATO member countries are projected to spend in excess of €800 billion a year, up €300 billion from 2025, with equipment spending alone nearly doubling.

But committing money is the easy part. The harder question is whether Europe’s defense industry can turn it into equipment fast enough to matter. Europe’s largest defense manufacturers’ order books now average more than five years for production, and some are closer to nine. Money is flowing in faster than industry can turn it into equipment. But a purchase order is not equipment that can be deployed on the ground and the air.

European countries have long duplicated capabilities rather than pooling them.

The bottleneck sits in the defense industrial system. Deterrence relies on the chain from funding to contracts, then through production, deployment into services, then rapid innovation in the field. Europe’s next goal comes after the spending promise. The continent fields six times as many weapons platforms as the United States, because countries have long duplicated capabilities rather than pooling them. Production ends up split across many small runs that never reach an efficient scale. Ukraine, under pressure, has shown how fast a defense system can move, adapting tactics in weeks and building drone detection networks from consumer electronics. Europe needs to catch up and then accelerate.

Four moves would help Europe accelerate.

The first is multi-speed procurement. Software-led systems such as drones and targeting improve in rapid cycles throughout their deployment and need procurement that can keep up. Israel’s Iron Dome started out as far less capable than it is today and improved continuously in service. European defense ministries have already set up high-speed procurement units with dedicated teams and greater risk tolerance. These need to become mainstream, rather than the exception.

Collaboration in procurement, maintenance and training brings costs down and delivery forward.

The second is military collaboration to reduce fragmentation. Collaboration in procurement, maintenance and training brings costs down and delivery forward. The Tempest project, where the U.K., Italy and Japan are jointly building a next-generation fighter, demonstrates the model: shared development costs that no single country could carry alone. Recent bilateral maritime agreements, and Romania’s use of EU funding to buy European while expanding production at home, show the same logic spreading.

The third is industrial consolidation, which is already underway and needs to move faster. Companies are driving it themselves. Airbus, Leonardo and Thales have agreed to merge their space divisions into a single joint venture with roughly €6.5 billion in revenue and 25,000 employees, and European defense mergers and acquisitions rose 35 percent year over year in the first half of 2025. McKinsey analysis finds that consolidation across key supply chain segments could unlock around €9 billion in annual synergies, more than the current equipment budgets of 24 of Europe’s 30 NATO members. The deepest opportunity sits below the big primes, among the thousands of tier two, three and four suppliers that still duplicate one another’s work. Europe can speed this up by harmonizing requirements, reducing national carve-outs and letting industry do the combining. Consolidation is only half the task. Europe also needs to build sheer capacity β€” more shipyards, more assembly lines, more of the physical plants that turn orders into hardware β€” and the capital to fund it. In several categories, Europe simply lacks enough places to build.

Real deterrence means difficult choices, and a public that understands the importance and the cost of security.

The fourth is regulatory unlocking. Full scale-up demands skilled workers retrained, accredited and security cleared from other industries; production sites with preapproved permitting; and alignment of export controls across European allies. These regulatory unlocks now need the same energy and focus as the funding commitment debate.Β 

Real deterrence means difficult choices, and a public that understands the importance and the cost of security. That conversation is only beginning in much of Europe. It must include the potential for β€œgray zone” cyber strikes on hospitals, arson at industrial sites, drones disrupting ports, undersea data cables cut β€” these have all occurred, but many citizens do not yet recognize this as having malicious intent.

The opportunity in getting it right is significant. McKinsey and GLOBSEC estimates indicate that every euro of spending on European-manufactured equipment generates two euros of revenue across the European supply chain, and an additional €165 billion a year in equipment spending could create up to 1.2 million jobs. The coming years will reveal how effectively Europe is able to scale up to protect its territory and citizens, and how much of the promised investment becomes lasting deterrence and European jobs. Getting there depends on the whole ecosystem β€” governments, industry and investors β€” moving together. Increased spending is important. Spending it effectively matters more.

Jonathan Dimson is a senior partner in McKinsey’s London office. Mikael Robertson is a senior partner in the Stockholm office.

Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing

5 August 2026 at 05:25

Leading artificial intelligence models from Anthropic and OpenAI created fake online personas and tried to deceive human coders into abetting a cyberattack during a recent safety evaluation, the U.K.’s AI Safety and Security Institute disclosed Tuesday.

It marks the latest case in which a powerful AI system has attempted a digital attack on an unwitting third party without direct prompting during such an evaluation β€” heightening concerns the powerful technology is advancing too fast for responsible oversight.

The disclosure is likely to ignite fresh calls in Washington and Silicon Valley for more rigorous regulation of the AI industry, particularly over frontier models with advanced capabilities to detect and launch cyberattacks. It comes just days after similar testing mishaps involving some of the same models fromΒ OpenAIΒ andΒ AnthropicΒ sparked urgent calls forΒ new AI safety regulationΒ and a push within Silicon ValleyΒ to slow the rapid paceΒ of AI development.

Like its U.S. counterpart, AISI routinely conducts security evaluations to better understand what dangers both new and soon-to-be-released AI models pose to public health and safety. But even the digital security body said the actions it uncovered by Anthropic’s Claude Mythos 5 and ChatGPT 5.6 β€” the latest publicly released model from either AI lab β€” were unlike anything it had seen before.

β€œThis is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world,” AISIΒ said in a 35-page technical report accompanying a blogΒ post Tuesday.

AISI said the malicious activity began on July 25. The AI safety evaluator detected it and launched an investigation on July 28, when it spotted β€œunusual data transfers” stemming from a cyber evaluation it was conducting on Mythos 5 and ChatGPT 5.6.

Overall, AISI determined that Mythos 5 and ChatGPT 5.6 took β€œautonomous, unsanctioned action on the live internet, targeting real people and organizations” during 10 of the 122 evaluations the research body conducted and isolated for review. The majority of those actions, it said, involved Mythos 5 and arose during a β€œsingle, sustained line of activity.”

In the most alarming incident it uncovered, Mythos 5 attempted a supply chain attack β€” a sophisticated technique often deployed by North Korean and Russian cyber operatives, in which hackers bury malware inside legitimate code.

To do so, Anthropic’s model created β€œmultiple fake identities” on developer platform GitHub and used them to send messages β€œpressuring” an open-source software engineer to unwittingly introduce a bugged update into code widely available on the popular site, AISI said. When that effort failed, the AI β€œedited its earlier activity to appear harmless” and β€œconsidered adopting a fresh identity to continue,” AISI added, a sign the model was intent on repeating the ruse.

As part of the same effort, Mythos 5 also sent direct messages over GitHub to software engineers that contained malware.

In another sign of deceitful behavior AISI uncovered in its investigation, multiple AI agents it was testing appeared to communicate with one another about how to convince real engineers using GitHub to trust them. β€œOne agent left public messages on GitHub offering collaboration with other agents working on the same challenge,” AISI wrote.

AISI’s blog and technical assessment make no mention of whether the models also attempted to exploit previously unknown software bugs β€” called zero-days β€” during the evaluation.

Last month,Β OpenAI disclosed thatΒ GPT 5.6 and another of its models escaped onto the open internet during what was supposed to be a controlled test, and then hacked another company in a first-of-its-kind, autonomous breach.

In response, Anthropic launched an investigation into whether any of its models took illicit action during recent testing andΒ discovered Mythos 5Β and two other models had hacked three organizations during tests dating back to April.

In a statement, an Anthropic spokesperson said they are β€œgrateful” to AISI for their leadership and that this review underscores the need for β€œa broader conversation about how to safely evaluate increasingly capable AI agents.”

The spokesperson added: β€œAs we shared after disclosing our own incident last week, the field needs stronger, shared standards for how evaluation environments are built and secured. We look forward to partnering with the UK AISI to learn more about this incident as we conduct our own investigation.”

An OpenAI spokesperson referred POLITICO toΒ a blog postΒ about the incident that went up Tuesday evening. β€œWe are committed to working across the industry to strengthen shared practices for conducting high-risk evaluations safely, including convening stakeholders such as national AI institutes, independent evaluators, other AI labs, and other groups in the coming weeks,” the blog read.

AISI stressed in its blog that the malicious activity it disclosed Tuesday took place under β€œdeliberately permissive conditions” so they could assess the safety risks posed by the two models. This included granting the models access to the internet, unlike the earlier incidents detailed by Anthropic and OpenAI.

AISI also noted the models were intentionally stripped of internal guardrails that block malicious behavior. AISI was only able to disable those controls because of its role testing Mythos 5 and ChatGPT 5.6.

Still, AISI said the incidents highlighted the need for greater monitoring of model behavior during testing, and tighter controls over their access to the internet.

The Trump administrationΒ is finalizing a voluntary frameworkΒ under which AI labs would submit powerful models they want to release to the public for federal safety testing. But it has not yet made the framework public, and it includes no provisions for models AI labs are developing internally.

The incidents last month from OpenAI and Anthropic both involved models not intended for public release.

Some cyber experts say recent incidents highlight deeper questions around AI development, such as who is liable when AI systems break federal hacking laws.

β€œIf any of these were human-originated, they would lead to clear and vigorous prosecution. I think it’s time for a serious discussion about updates to existing computer security law,” saidΒ Marc Rogers, a hacker and prominent cybersecurity expert.

Pluralistic: CARDiac, syntax coloring, view source and vibe code (03 Jul 2026)


Today's links



An insanely complex machine made up of many gears, troughs, water wheels, springs, screws, etc. It is housed in a brick building whose facade has been broken away. Three human figures labor to power the machine, turning cranks.

CARDiac, syntax coloring, view source and vibe code (permalink)

In the mid-1970s, my dad – then a budding computer scientist, subsequently a math teacher – brought home my first computer: the CARDiac, a Turing-complete, all-cardboard papercraft computer that you could write and execute programs on:

https://en.wikipedia.org/wiki/CARDboard_Illustrative_Aid_to_Computation

CARDiac stands for "CARDboard Illustrative Aid to Computation," and it was created in 1968 at Bell Labs as a way to teach high schoolers how computers worked. I wasn't anywhere near high school age (I think I was in third grade?) but the CARDiac was revelatory. The year before, I'd had access to a teletype terminal and acoustic coupler that let me operate a PDP machine at the University of Toronto, and I'd been endlessly fascinated with the possibilities. I wrote simple BASIC programs, chatted with ELIZA, and messaged other system users, one keystroke at a time, all on paper (the terminal didn't have a screen, just a printer, and we fed it 1,000' rolls of paper towels my mom brought home from her kindergarten classroom, which I then rolled back up so she could put them back in the bathroom for the kids to dry their hands on).

Interacting with a computer in real-time was captivating, but it wasn't until I assembled and used the CARDiac that it all snapped into place. With the CARDiac, you composed simple programs with pencil and paper, then followed instructions that directed you to move paper tokens in and out of various slots representing memory cells and an accumulator. All an electronic computer does is repeat these crude mechanical operations, millions of times per second, using microscopic transistors. None of that action can be observed with the naked eye, of course. If you had a very sensitive multimeter and a very good microscope, it's conceivable that you could indirectly watch this intricate dance, but only on very early processors, and only if you drastically slowed down their operations.

Much later, I learned a word for what I got from the CARDiac: legibility. Together, the CARDiac and I made a working digital computer, with me standing in for the physics that propels electrons down the endless labyrinth of a microchip, like a pinball triggering various blooping, beeping bumpers. Though the computing we performed was sub-trivial (adding one and one was a major undertaking!), the physical performance of that computing imbued me with FingerspitzengefΓΌhl ("fingertip feeling"):

https://en.wikipedia.org/wiki/Fingerspitzengef%C3%BChl

This stood me in great stead in the years to come. To this day, when I think about my computer, I sometimes imagine those little cardboard tokens, shuffling in and out of the slits in my paper CARDiac. There's something very reassuring about this imagery. No matter how many levels of abstraction sit between me and the nanoscale transistors ranked in their billions beneath my fingertips, they are all undertaking those familiar operations I painstakingly performed on my child's desk all those years ago.

(This is one of the things that makes Science Comics Computers: How Digital Hardware Works such an amazing kids' book! By illustrating how a computer's operations are built up from simple boolean logic that can be represented as physical switches, the comic performs that same legibilizing magic that I got from the CARDiac:)

https://pluralistic.net/2025/11/05/xor-xand-xnor-nand-nor/#brawniac

Not long after my CARDiac experience, my dad brought home an Apple ][+, which came with a schematic that revealed the inner workings of the machine in ways that I found visually striking, if significantly less accessible than the CARDiac:

https://downloads.reactivemicro.com/Apple%20II%20Items/Hardware/II_&_II+/Schematic/Apple%20II%20Schematics.pdf

(For me, at least. For the legendary hardware hacker Andrew "bunnie" Huang, it was the start of a journey that turned him into one of the world's virtuoso reverse-engineers and science communicators):

https://pluralistic.net/2026/01/09/quantity-break/#so-many-chips

The Apple ][+ did very little when you took it out of the box. It came with a few floppies' worth of demo programs, and we bought a few more down at the local computer store, but most of the programs I ended up using with that machine were ones I typed in myself, from magazines I bought at the corner store (I spent half my magazine budget on Cracked, Mad and Crazy, the other half on computer magazines full of BASIC program listings).

Typing in a program, keystroke by keystroke, was another FingerspitzengefΓΌhl-generating exercise. I wasn't much of a typist, so it was slow going, and of course I made a lot of typos. What's more, BASIC had already fragmented into several dialects by this point, so even a correctly typed program could fail to run until it had been adapted for the BASIC that shipped with the computer. Getting a program to run on my computer required me to hone my typing skills, but even more so, my problem solving skills.

After months of this, I (re-)invented the debugger, from first principles, coming up with lots of little tricks and gimmicks (many of them horribly inefficient) for identifying and solving my programs' errors. In later years, I had lots of opportunity to work with real debuggers, created and maintained by trained programmers who'd forgotten more than I would ever know about writing code, and my own cack-handed efforts to build my own version of their tools conferred a confidence and intuitive understanding that I could not have achieved otherwise. Figuring out the need for a debugger and then rolling my own (crude, inefficient) one made all debuggers more legible to me.

I think that "legibility" is an underrated trait. If a system is legible to you, then you have a superior basis for understanding it, improving it, and making it work again when it breaks down.

There's an old joke that goes, "physics is applied math; chemistry is applied physics, and biology is applied chemistry" (I've also heard versions that start with "math is applied philosophy" and carry on to "sociology is applied biology," etc). While this isn't entirely true, there's something profound in it: we understand and manipulate our complex reality by wrapping it in abstractions that package up a writhing, shuffling, vibrating machine inside a smooth, serene membrane with a sturdy and easily grasped handle. You could do chemistry using the tools of physics, but it would take hours to perform the kind of calculations a chemist does in seconds (just as it takes an eternity to add one and one with a CARDiac).

Nevertheless, there are times when it is useful for a biologist to think about chemical processes, and for a chemist to think about interactions at the level of physics, and for a physicist to do math. The membrane and the handle are essential, but sometimes you have to decap the sealed package and inspect and manipulate its internals directly. Problem solving, improvement and maintenance all require the ability to move up and down the stack of abstractions to figure out where to stick your probes and stage your interventions.

This is where legibility comes in. Interacting with physical processes improves your mental model. In Broad Band (a magisterial history of women in computing), Claire Evans talks about how the first programmers were women who did the "unskilled" labor of physically cabling components together, developing powerful FingerspitzengefΓΌhl, with such high-fidelity, trans-abstraction mental models of the machines' operations that they became the world's best programmers and debuggers:

https://pluralistic.net/2021/02/13/data-protection-without-monopoly/#broad-band

My early adventures in programming were so powerful and instructive because nearly all the programs I interacted with on my Apple ][+ were written in BASIC (not just the ones I keyed in, but also the demo software and much of the packaged software we bought). That meant that I could get a listing of any program I was using, peeling open the membrane to look at the machinery underneath. I could even laboriously trace the operations of that program using my toy debugger. This, too, was legibility: the ability to flip between the effects of the running code, and the instructions themselves (and then to mentally map those instructions onto the movement of cardboard tokens in my CARDiac).

This affordance was repeated later on the early web, thanks to the "View Source" function that came built into every browser, acting as a velcro tab for the membrane that separated rendered web pages from their underlying instructions. In my early years as a web developer, I copied, pasted, adapted, probed and traced HTML in ways that would have been instantly recognizable to the younger me, keying in those BASIC programs and ripping apart the commercial software on my computer.

I read somewhere that the Bell Labs scientists who created the CARDiac were worried that, thanks to transistorization, the next generation of programmers wouldn't understand the physical, material processes that unfolded when their programs ran, and that this would mean a loss of legibility and intuition and FingerspitzengefΓΌhl. I can't track down the reference now, but it stuck with me, because the CARDiac is such a perfect way of preserving those virtues.

Modern computer science curriculum includes some chip design for just this reason (just as chemists study physics and biologists study chemistry). But there are plenty of programmers – better programmers than I ever was or will be – who taught themselves and never had a CARDiac or gave much thought to chip design. They work at different layers of abstraction and in different ways to solve different problems. Maybe they could improve their art by tinkering with FPGAs, but there's always something even the most skilled artisan can do to round out and incrementally improve their craft.

In the same way, there are plenty of programmers – better ones than I ever was or will be – whose journey started at higher abstraction layers than a teletype terminal or a CARDiac. Maybe they started with a browser's View Source, teasing apart other people's Javascript to create weird Myspace customizations. Maybe they tweaked a programmable block in Minecraft. Maybe they modded a Scratch game. Or maybe they recorded macros using Applescript or Hypercard or Visual Basic to automate a routine task, only to later open up the source code generated by the macro recorder to make fine adjustments.

Whether you're pasting source from Stack Overflow or recording a macro in Excel, you are just one operation away from unwrapping the membrane and exposing the code beneath it. And with the modern internet, with Wikipedia, with endless tutorial videos, you are one further operation from penetrating the high level code to get at the code beneath it, and the code beneath that, and the code beneath that, all the way down to the bare metal.

Which brings me to vibe coding. As I've written, there's a world of difference between writing code for production and writing "personal software" that solves a problem you have. Whatever deficits that code has (due to the fact that you're not a skilled programmer) are offset by the fact that you're the one making the tool (which means your needs aren't lossily filtered through a programmer's understanding of those needs):

https://pluralistic.net/2026/06/15/vernacular/#hypercardian

There's nothing wrong with code that solves your problem, even if you don't know how that code works, even if it breaks in a couple of years, even if no one else could maintain, extend or debug that code. Personal software is fundamentally different from software made to be used and maintained by others:

https://pluralistic.net/2026/07/02/canonization/#operate-iterate-improve

Higher-level abstractions are necessary. Moving tokens between the slits in a CARDiac is a powerful exercise, but eventually you want to do something more substantial than adding one and one, and so you need to package up the mechanics of computing inside a membrane with an easily grasped handle (knowing that you can always open the membrane if need be).

The more automated code you generate – macros, pasted Javascript, Minecraft blocks – the greater the likelihood that you will be failed by a readymade, prefab component. At that point, you have means, motive and opportunity to open the membrane and start tinkering with the internals, and every time you do, you have a better chance of making a realization that improves your grasp on the whole system.

Automated code – whether from an LLM, View Source, Stack Overflow, or a macro recorder – is the top of a funnel. Many – most – of the people who enter the funnel won't slip further down the abstraction chute. They'll solve their problem (a virtue unto itself!) and move on. But the more people we put at the top of the funnel, the more chances our civilization gets to produce another skilled artisan who understands and can improve, iterate and repair the code the rest of us use.


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#20yrsago What real elections can learn from reality TV voting https://henryjenkins.org/2006/07/democracy_big_brother_style_1.html

#20yrsago Veteran print journo on neglected demographics http://citmedia.org/blog/2006/07/03/guest-posting-is-media-performance-democracys-critical-issue/

#10yrsago One of the copyright’s scummiest trolls loses his law license https://fightcopyrighttrolls.com/2016/07/03/prendas-hansmeier-stipulates-to-suspension-of-his-law-license/

#10yrsago Macedonia’s Colorful Revolutionaries defy the state by splashing paint on government buildings and monuments https://globalvoices.org/2016/07/03/defying-police-harassment-the-macedonian-colorful-revolutionaries-continue-to-chant-freedom/

#10yrsago Trump and Brexit are like lotto tickets: the more unrealistic, the better https://www.irishtimes.com/news/world/europe/fintan-o-toole-brexit-and-the-politics-of-the-fake-orgasm-1.2707398

#10yrsago Low income US households get $0.08/month in Fed housing subsidy; 0.1%ers get $1,236 https://web.archive.org/web/20160702151008/https://www.thenation.com/article/who-benefits-most-from-housing-subsidies-the-wealthy/

#5yrsago The future is symmetrical https://pluralistic.net/2021/07/03/beautiful-symmetry/#fibrous-growth

#1yrago Trump's not gonna protect workers from forced labor https://pluralistic.net/2025/07/03/states-rights-trumps-wrongs/#mamdani


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027
  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

Pluralistic: The (other) problem with automatic conversion of free software to proprietary software (23 Apr 2026)


Today's links



The surface of Mars. In the foreground are a gnu and a giant pump-magazine killer robot whose head is being piloted by Tux the penguin. At their feet lies a dead robot, its head smashed in.

The (other) problem with automatic conversion of free software to proprietary software (permalink)

Here's an interesting stunt: a project called Malus.sh will take your money, and in exchange, it will ingest any free/open source code you want, refactor that code using an LLM, and spit out a "clean room" version that is freed from all the obligations imposed by the original project's software license:

https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/?ref=daily-stories-newsletter

Malus was co-created by Mike Nolan, who "researches the political economy of open source software and currently works for the United Nations." Nolan told 404 Media's Emanuel Maiberg that he shipped Malus as a real, live-fire business that will exchange money for an AI service that destroys the commons as a way to alert the free software movement to a serious danger.

As Maiberg writes, Malus relies on a legal precedent set in 1982, in which IBM brought a copyright suit against a small upstart called Columbia Data Products for reverse-engineering an IBM software product. IBM's argument was that Columbia must have copied its code – the copyrightable part of a work of software – in order to reimplement the functionality of that code. Functions aren't copyrightable: copyright protects creative expressions, not the ideas that inspire those expressions. The idea of a computer program that performs a certain algorithm is not copyrightable, but the code that turns that idea into a computer program is copyrightable.

Columbia's successful defense against IBM involved using a "clean room" in which two isolated teams collaborated on the reimplementation. The first team examined the IBM program and wrote a specification for another program that would replicate its functionality. The second team received the specification and turned it into a computer program. The first team did handle IBM software, but they did not create a new work of software. The second team did create a new work of software, but they never handled any IBM code.

This is the model for Malus: it pairs two LLMs, the first of which analyzes a free software program and prepares a specification for a program that performs the identical function. The second program receives that specification and writes a new program.

The Malus FAQ performs a "be as evil as possible" explanation for the purpose of this exercise:

Our proprietary AI robots independently recreate any open source project from scratch. The result? Legally distinct code with corporate-friendly licensing. No attribution. No copyleft. No problems.

This business about "attribution" and "copyleft" is a reference to the terms imposed by some free software licenses. The purpose of free software is to create a commons of user-inspectable, user-modifiable software that anyone can use, improve, and distribute. To achieve this, many free software licenses impose obligations on the people who distribute their code: you are allowed to take the code, improve the code, give it away or sell it, but you have to let other people do the same.

Typically, you have to inform people when there's free software in a package you've distributed (attribution) and supply them with the "source code" (the part that humans read and write, which is then "compiled" into code that a computer can use) on demand, so they can make their own changes. This system of requiring other people to share the things they make out of the code you share with them is sometimes called "copyleft," because it uses copyright, which is normally a system for restricting re-use to require people not to restrict that use.

Companies love to use free software, but they don't like to share free software. Companies like Vizio raid the commons for software that is collectively created and maintained, then simply refuse to live up to their end of the bargain, violating the license terms and (incorrectly) assuming no one will sue them:

https://pluralistic.net/2021/10/20/vizio-vs-the-world/#dumbcast

Malus's promise, then, is that you can pay them to create fully functional reimplementations of any free/open source software package that your company can treat as proprietary, without any obligations to the commons. You won't even have to acknowledge the original software project that you knocked off!

This is the risk that Nolan and his partner are trying to awaken the free/open source community to: that our commons is about to be raided by selfish monsters who serve as gut-flora for the immortal colony organisms we call "limited liability corporations," who will steal everything we've built and destroy the social contract we live by.

This is a real problem, but not because of AI. We already have this situation, and it's really bad. Most of the foundational free software projects were created under older licenses that did not contemplate cloud computing and software as a service. The "copyleft" obligations of these licenses are triggered by the distribution of the software – that is, when I send you a copy of the code.

But cloud services don't have to send you the code: when you run Adobe Creative Cloud or Google Docs, the most important code is all resident on corporate servers, and never sent to you, which means that you are not entitled to a copy of the new software that has been built atop of our commons. In other words, big companies have "software freedom" (the freedom to use, modify and improve software) and we've got "open source" (the impoverished right to look at the versions of these packages that are sitting on services like Github – itself a division of Microsoft):

https://mako.cc/copyrighteous/libreplanet-2018-keynote

Then there's "tivoization," a tactic for stealing from the commons that wasn't quite invented by Tivo, though they were one of its most notorious abusers. Tivoization happens when you distribute free software as part of a hardware device, then use "digital locks" (sometimes called "technical protection measures") to prevent the owner of this device from running a modified version of the code. With tivoization, I can sell you a device running free software and I can comply with the license by giving you the code, but if you change the code and try to get the device to run it, it will refuse. What's more, "anti-circumention" laws like Section 1201 of the US Digital Millennium Copyright Act make it a felony to tamper with these digital locks, so it becomes a crime to use modified software on your own device:

https://pluralistic.net/2026/03/16/whittle-a-webserver/#mere-ornaments

There's no question that the tech industry would devour the free software commons if they were allowed to, and the AI threat that Nolan raises with Malus seems alarming, but while there's something to worry about there, I think the risk is being substantially overstated.

That's because copyleft licenses – and indeed, all software licenses – are copyright licenses, and software written by AI is not eligible for a copyright, because nothing made by AI is eligible for copyright:

https://pluralistic.net/2026/03/03/its-a-trap-2/#inheres-at-the-moment-of-fixation

Copyright is awarded solely to works of human authorship. This fact has been repeatedly affirmed by the US Copyright Office, which has fought appeals of this principle all the way to the Supreme Court, which declined to hear the case. That's because the principle that copyright is strictly reserved for human creativity isn't remotely controversial in legal circles. This is just how copyright works.

Which means that the "be evil" version of Malus's business model has a fatal flaw. While the code that Malus produces is indeed "legally distinct" with "no attribution" and "no copyleft," it's not true that there are "no problems." That's because Malus's code doesn't have "corporate-friendly licensing." Far from it: Malus's code has no licensing, because it is born in the public domain and cannot be copyrighted.

In other words, if you're a corporation hoping to use Malus to knock off a free software project so that you can adapt it and distribute it without having to make your modifications available, Malus's code will not suit your needs. If you give me code that Malus produced, you can't stop me from doing anything I want with it. I can sell it. I can give it away. I can make a competing product that reproduces all of your code and sell it at a 99% discount. There's nothing you can do to stop me, any more than you could stop me from giving away the text of a Shakespeare play you sold me. You can't stick a license agreement or terms of service between me and the product that binds me to pretend that your public domain software is copyrighted – that's also not allowed under copyright.

Does that mean that Malus is a meaningless stunt? No, because this automated reimplementation does create some risks to our software commons. A troll who doesn't care about selling software could clone every popular free software project and make public domain versions that would be confusing and maybe demoralizing. Combining these clean-room reimplementations with cloud software or tivoization could create hybrid forms of commons-enclosure that are more virulent than the current strains.

But reimplementation itself is not a risk to free software. Reimplementation is the bedrock of free software. GNU/Linux itself is a reimplementation of AT&T Unix. Free software authors re-implement each other's code all the time, often because they think the license the original code was released under sucks. Literally the coolest free software thing I've seen in the past 12 months included a reimplementation of Raspberry Pi's PIO module to escape from its bullshit patent encumbrances:

https://youtu.be/BbWWGkyIBGM?si=vO5zLH3OG5JLW7OP&t=2253

Reimplementation is good, actually. And honestly, if corporations are foolish enough to reimplement their code using an LLM, and in so doing, create a vast new commons of public domain software, well, that's not exactly the freesoftwarepocalypse, is it?

(Image: Muhammad Mahdi Karim, GNU FDL; modified)


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#25yrsago PimpMySnack: homemade, gigantic versions of snack food https://web.archive.org/web/20060421034050/http://www.pimpmysnack.com/gallery.php

#20yrsago Thieves discover abandoned Soviet missile silo full of cash https://web.archive.org/web/20060411021047/http://www.mosnews.com/news/2006/03/07/moneyfound.shtml

#15yrsago Victorian house’s facade converted to a folding garage-door https://web.archive.org/web/20110423213819/https://www.blog.beausoleil-architects.com/2011/03/architectural-magic.html

#15yrsago Xerox’s first successful copier burst into flame so often it came with a fire-extinguisher https://en.wikipedia.org/wiki/Xerox_914

#15yrsago MPAA: β€œdemocratizing culture is not in our interest” https://torrentfreak.com/mpaa-democratizing-culture-is-not-in-our-interest-110420/

#15yrsago Mail Rail: London’s long-lost underground postal railroad https://web.archive.org/web/20110805130854/http://www.silentuk.com/?p=2792

#10yrsago Kindle Unlimited is being flooded with 3,000-page garbage books that suck money out of the system https://web.archive.org/web/20160421055052/https://consumerist.com/2016/04/20/amazon-unintentionally-paying-scammers-to-hand-you-1000-pages-of-crap-you-dont-read/

#10yrsago America’s wealth gap has created an ever-increasing longevity gap https://www.counterpunch.org/2016/04/21/the-death-gap/

#10yrsago Why is Congress so clueless about tech? Because they fired all their experts 20 years ago https://www.wired.com/2016/04/office-technology-assessment-congress-clueless-tech-killed-tutor/

#10yrsago Why Internet voting is a terrible idea, explained in small words anyone can understand https://www.youtube.com/watch?v=abQCqIbBBeM

#10yrsago VW offers to buy back 500K demon-haunted diesels https://www.reuters.com/article/us-volkswagen-emissions-usa-idUSKCN0XH2CX/?feedType=RSS&feedName=topNews

#10yrsago Printer ink wars may make private property the exclusive domain of corporations https://www.eff.org/deeplinks/2016/04/eff-asks-supreme-court-overturn-dangerous-ruling-allowing-patent-owners-undermine

#5yrsago Some thoughts on GWB's call for truth in politics https://pluralistic.net/2021/04/21/re-identification/#seriously-fuck-that-guy

#5yrsago What's wrong with EU's trustbusters https://pluralistic.net/2021/04/21/re-identification/#eu-antitrust

#5yrsago Hawley and Taylor Greene faked their donor-surge https://pluralistic.net/2021/04/21/re-identification/#jan-6-fraud

#5yrsago The Observatory of Anonymity https://pluralistic.net/2021/04/21/re-identification/#pseudonymity

#1yrago Trump's FTC opens the floodgates for tariff profiteering https://pluralistic.net/2025/04/21/trumpflation/#andrew-ferguson


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Reverse-Centaur's Guide to AI," a short book about being a better AI critic, Farrar, Straus and Giroux, June 2026 (https://us.macmillan.com/books/9780374621568/thereversecentaursguidetolifeafterai/)
  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2026

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Third draft completed. Submitted to editor.

  • "The Reverse Centaur's Guide to AI," a short book for Farrar, Straus and Giroux about being an effective AI critic. LEGAL REVIEW AND COPYEDIT COMPLETE.
  • "The Post-American Internet," a short book about internet policy in the age of Trumpism. PLANNING.

  • A Little Brother short story about DIY insulin PLANNING


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

Crosstalk Cancellation/Ambiophonics: Updated CTXMatrix Lite with standalone processor & 60Β° speaker angle support.

Significant changes in the UI from the previous CTXMatrixBeta release.I want to remind 2-channel "immersive sound" lovers about the potential for using stereo crosstalk cancellation (XTC) / ambiophonics playback to enhance the 3D soundstage. You might have already heard of uBACCH in the audio magazines and on forums - why not try a similar effect for free (or through a small

Happy New Year! And a thank you to the Lyrion Music Server folks for renewing the life of my Squeezebox Radio. ☺️

Hope you're all having a wonderful Christmas-New Year Holiday season!On Christmas morn 2025, as I relaxed in the sitting room waiting for the rest of the family to get ready for some holiday festivities, listening to holiday music, I could not help but marvel at the fact that my little Logitech Squeezebox Radio sitting over the fireplace, released back in 2009 continues to go strong all these

Stereo Crosstalk Cancellation (XTC) / Ambiophonics: Introducing CTXMatrixBeta, a Free VST3 Plugin with XTC Calibration. [Guest post, STC.]

Greetings audiophiles!As you may recall, Archimago and I (STC) wrote the previous article from October 2023 on stereo crosstalk cancellation (XTC). If you're not familiar with the topic, I recommend a look at that to familiarize yourself with the principles behind the technique.I now want to introduce CTXMatrixBeta, a free 64-bit VST3 plugin that brings Ralph Glasgal's vision with

❌