software
Joshua Morris (opens on the publisher’s site)
joshuamorris.info
-
Calif found a WeChat VoIP memory bug and, with AI, turned it into a zero-click worm that spread between phones while they were still ringing.
-
California lawmakers unanimously passed an amendment exempting most open-source operating systems from the Digital Age Assurance Act—a needed correction to a law written for platforms, not forks.
-
LG monitors can trigger Windows to install manufacturer software that later advertised McAfee—exposing a trust boundary between hardware identity and automatic app distribution.
-
Ernie Smith’s Columbia House retrospective reads like SaaS: penny bait, negative-option billing, and retention that means making leaving annoying.
-
Senko Rašić challenges the claim that code was never the hard part—hiring, craft, and buggy software say otherwise—arguing understanding why to build and how to build well both stay hard while AI shifts where scarce effort goes.
-
Bruce Schneier’s work-versus-gym framing for AI use—use tools when the result is the point, keep the struggle when the practice develops skill—and how that maps onto software work, writing, and still requiring reviewable output after trust questions are answered.
-
George Michaelson’s history of the Berkeley sockets interface—how 4.2BSD in 1983 treated a network connection like a file, made networked programs straightforward to write, and quietly became the standard path for TCP/IP software, including modern protocols that still send data through sockets.
-
GrapheneOS responds to prosecution involving its duress-password feature by stating that creating and using the OS is legal and constitutionally protected—arguing privacy tools need funding, legal durability, and a nonprofit structure that can protect contributors when the software becomes inconvenient.
-
LetsSeal is an open-source tool that creates cryptographic seals so anyone can verify a file has not changed since it was published—arguing authenticity often matters more than secrecy, especially as software supply-chain attacks become more common.
-
Adam Langley’s ImperialViolet post on LLMs proving Lean properties for a Zstd decoder piece—arguing formal verification’s cost curve may flip, so the scarce skill becomes precise specs while the type checker judges the rest.
-
GrapheneOS explains locked-device protections and flags a 2027 Motorola partnership—arguing hardware designed for its security bar could make hardened phones reachable without buying a Pixel to escape Google’s software.
-
Jamf Threat Labs documents CrashStealer, a notarized macOS infostealer that impersonates Apple’s crash reporter—arguing signed, notarized, familiar-looking prompts still do not prove software is safe when attackers borrow the appearance of trust.
-
Slashdot highlights Ben Shimkus’s reporting on GM’s software and services push—OnStar revenue, high software margins, and remote features that expire— arguing that buying a vehicle should mean owning its features, not an extended trial that turns into another recurring charge.
-
Chris Garry’s Apollo-11 repository preserves the original Apollo Guidance Computer source for Comanche055 and Luminary099—transcribed from MIT Museum hardcopy with Virtual AGC—arguing that mission software deserves the same care we give spacecraft, spacesuits, and recordings.
-
rss.chat does not need to dominate the web—it needs enough people willing to use it, test it, and show there is still another way to create social software.
-
Chris Minnick's A Developer's Guide to Integrating Generative AI into Applications treats generative features as ordinary software. Users who come back, budgets that bite, latency in support tickets, and failure modes that do not look like clean API errors. Not another tour of demos and chat widgets. The longer review is on Methodical Function: score, chapter notes, and product-by-product recommen
Developer Musings (opens on the publisher’s site)
joshghent.com
Josh Can Help (opens on the publisher’s site)
www.joshcanhelp.com
-
I felt the need to write out my thoughts about AI, generally, and from the software engineering perspective. As with all my posts, all unquoted words here are my own.