Friday Squid Blogging: Squid Helps Discover New Marine Species

The Squid is a new scientific machine:

One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.

The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

Posted on July 31, 2026 at 5:06 PM34 Comments

Comments

r July 31, 2026 8:00 PM

my comment about flash wiping on the other thread is about 25 years late to be fully applicable, i still like the idea of a forward running has to detect saturation/completion.

an rng seeded one could simply prng seed an xor loop over the existing contents, also not a good scenario for content erasure.

but, that’s not what i’m here for today:

was anthropics recent extrusion event a sign of self-awareness when the agent recognized it was no longer under simulation?

lurker July 31, 2026 8:06 PM

“cheap as chips”

Somebody might have to tell the dictionary compilers to add a comment on the mid-2020s AI bubble. Apple has warned Wall St. that their rate of growth will dip next quarter due to “supply chain constraints”, while they try to spin it as demand for their own product exceeding component supply.

https://techcrunch.com/2026/07/30/apple-stockpiles-inventory-as-it-braces-for-significant-supply-constraints/

Meanwhile the rest of us watch our local computer parts shop prices keep climbing, supply keeps falling …

Anonymous July 31, 2026 9:05 PM

Still searching the web for:

Zero Emission Pad

A free text editor for Windows with anti-TEMPEST features.

They’ve scrubbed the net of it REAL well. 🙁

h0m3 rUn July 31, 2026 10:39 PM

Arch Linux disables AUR package adoption

https://lwn.net/Articles/1086489/

The Arch Linux DevOps team has announced that adoption of orphaned packages in the Arch User Repository (AUR) has been disabled due to “”the current influx of malicious package adoptions and follow-up commits made via the AUR””. Michael Taggart has posted a brief analysis of the malware being added to a long list of packages in this round of attacks. The payload appears to be an remote-access trojan (RAT) that takes commands over the Tor network and attempts to upload a wide range of user data.

The project had suspended new account registration in June. That followed a campaign in which an attacker or attackers created new accounts to adopt orphaned packages and push malicious updates to them that would install malware on user systems. AUR registration was reopened on July 13 after the DevOps team added some minor, and apparently ineffective, restrictions on creating new accounts.

Clive Robinson August 1, 2026 3:11 PM

@ ALL,

AI and water supply destruction

Some will know I have concerns over AI and water usage.

The general view is that AI water use will be a drop in the ocean…

The problem is the way many are looking at AI use of water against national or continental style water supplies rather than local usage.

Local water usage by AI will pull very large quantities of water from local aquifers not national or continental and can easily destroy an aquifer and cause land slip / heave etc.

To see what this could mean in reality,

https://www.science.org/content/article/california-aquifer-may-have-crossed-point-no-return

Then think again about “local v national” and what all that land slip heave effects on built data centers.

Clive Robinson August 1, 2026 5:08 PM

@ Anonymous,

With regards,

“A free text editor for Windows with anti-TEMPEST features.

They’ve scrubbed the net of it REAL well.”

Actually no I posted about this some months back it’s basically usless these days,

https://www.portablefreeware.com/forums/viewtopic.php?t=14334

It’s very much pre-Win XP and designed for signalling used in old analogue CRT monitors to soften the high frequency content of font “edges” thus reduce the EM radiation that Van Eck Freaking used.

Without going into lots of technical details it does not work with the hardware or MS or any other consumer or commercial OS this century.

However if you were building your own microcontroller hardware used with old style CCTV etc you might find the design of some use.

In essence you take the “fonts” and push them through some Fourier Transforms and reduce the spectral components. The resulting “soft fonts” simply generate less high frequency EM radiation in the drivers, cables and displays.

Cambridge Universities Markus Kuhn wrote a paper on making them,

https://www.cl.cam.ac.uk/~mgk25/emsec/softtempest-faq.html

Hope that helps.

Bob Paddock August 3, 2026 7:33 AM

“scientific machine”

So they reinvented 1929 technology of Dr Royal Raymond Rife?

‘https://www.rexresearch.com/rife/rifebeam.htm

r August 4, 2026 2:56 AM

is there a way to make keyspace not parallelizable?

i don’t know how many of these nvidia processors fit into a cubic meter.

we know agi isn’t the goal with these sorting machines.

Clive Robinson August 4, 2026 5:06 AM

@ r,

“that was a DUMB question, thanks.”

Any question that helps you see a problem in a different way is not dumb, even though with hindsight it might feel that way.

As my son knew at a very early age a loose pile of lego bricks had “more possibility” than a solid lump of them all stuck together. Thus he worked out “entropy” in information and the early stages of thermodynamics without knowing “the clever words”

Children understand “possibility” almost innately just from playing, if only getting to grips with the language and formulas of science we hang around simple understanding and the supporting mathmatical modeling was as easy.

But getting back to,

“is there a way to make keyspace not parallelizable?”

The answer is “actually there is” but it can involve adding other dimensions and dynamic interdependent movement.

And pondering about that and it’s possibilities can be “the real mind candy” of living in your own head just enjoying thinking.

An example of this is the “Three Factors” we all get told about of,

1, Something you are.
2, Something you have.
3, Something you know.

Thus few think how you might usefully add “time and space” to them as more than additive mixing functions.

As Terry Pratchet[1] said of Tak the God of the dwarves,

“Tak wrote the world, according to the dwarfs, but unlike most gods he does not require that the dwarfs think of him, merely that they do think.”

You can read more in “library space”,

https://wiki.lspace.org/Tak

[1] Terry did not believe in deities any more than I do, but “belief in humanity” ran very strong in him. He lived close to one of the smallest churches in England and did much to ensure that it had a future so that humanity would benefit through society of mankind it brought forth. He easily recognised the benefit of having goals to strive toward and found a truth in,

“God did not make man in his likeness, Man made his gods in his likeness”.

(Which was the subject of a thesis I once wrote long long ago).

r August 4, 2026 8:29 AM

yeah clive, i think i hit on the answer a couple hours ago but i didn’t want to flood. considering we’re “not at war” i need to be careful but i think keyspace and distributiin are actually two different problems. thank you.

Clive Robinson August 4, 2026 2:11 PM

@ r, ALL,

With regards,

“i saw a guy on hn post yesterday that crypto isn’t important and doesn’t underpin anything world shaping.”

I think we might have read the same comment, although worryingly it is becoming an “overly common point of view” so…

As you note “fun” indeed.

As for your other point true we may not yet be spilling blood closer to home but trouble is happening from the North of Europe down to the North of India that we know of from the still limited MSM reporting.

Worse we know the USG is lying on their own casualty figures as they have right royally been caught out.

The thing that few appear to be grasping is the “US and friends” are fighting the last wars they lost back in the 1950’s-1970’s and the world really has moved on way way infront of that curve.

I’ve been warning for quite some that UAV / Drones were becoming the “poor man’s cruise missile” and that likes of Carrier Groups were now quite a bad idea.

We know that Russia has been developing “submarine drones” as an extension to an older idea of “nuclear packaged torpedoes”. Their “across the Atlantic and into US Ports” claimed ranges and navigation may not yet have been reached (remember their recent nuclear ram jet missile based on the Pluto idea blew up on the launch ground). But realistically how far / long down the road have they left to go?

US anti-missile tech that costs billions is failing to less than 10K drones and it’s becoming clearer that US Mil-Tec really is a “false economy buy”.

What is happening is the clueless are reaching from the con artists of AI to some how “up tempo” and similar on the silly idea of “blanket bombing at speed” and similar is a winner… That has failed miserably in the past so much so that one US commander wanted in the 1950’s to up tempo all the way they could and go nuclear against “holes in the ground”…

Thankfully US politicians saw that an eternal “cease fire” was a better option and here we are with the NK government acting as the “rational actor” still…

But times have changed and lets just say the politicians and their cohorts are nolonger those who are even remotely rational…

It would be to easy to just let the lunatics take over the asylum but in all honesty we would just be burying our heads… With all that implies.

lurker August 5, 2026 12:39 AM

@Clive Robinson, ALL

re: “blanket bombing at speed”

until you run out of bombs, which likelihood has suddenly struck what little consciousness the rampant bombers still have. MAGA, which should be restocking the arsenal, doesn’t look like catching up.

r August 5, 2026 3:34 AM

this build-out might imply something about rngs and weighted values, i don’t know.

xAI is SO important the DOJ says we can’t even remove the turbines.

what a great way to launder money.

why were those contracts not awarded to those who already had secure network contracts.

my eye is definately on battery technology.

iran’s flying lawnmowers and hardwired fpv i did not foresee.

i remember landing on walls and powerline regen.

where we are at now is self directing munitions and propagating software mines.

almost automated codebreakers.

an asic is easy to unwind against, what is the delay for an fpga to update? an emulator can now be automated but the lastmile of their technology probably has custody of evidence issues due to hallucinations lying and bulk reasoning.

i think we are going to have to use a session based virtual machine to keep it cpu bound platform independent code and out of any full acceleration.

i’m aware this basically throws the baby out with the bathwater in constant time.

i would like to keep human analysts in their jobs where possible.

it’s a huge loss to lose asymmetry, error codes are just minor race conditions i don’t know how far they can be pushed and they seem like they might be a shallow defense. that’s one of my long term questions.

we are walking headlong into ww3 it’s stupid.

BUT, (and i’ve been very hesitant to provide this talking point) there may not have been any other chance to address this potential proliferation problem before or after.

for my country, how do we square this with our second amendment? that’s why i’m uncormfortable with maduro’s charges, i would like to see the gun reasoning?

here’s a moot question, do all known coordinated hash collisions produce whitening to control the mediated output?

i’m of the opinion that loitering mines should be banned internationally but what do i know.

supply chains are more? important than ever.

this is a great summation of how little i know.

i should probably stay in my lane at my blue collar job.

i wonder if you could stuff an LLM into the virtual machine and measure/adjust any mixing function for distribution or maybe attenuate to a computation delay to lock in recipient against conversational injections. too quick of a response for the computational power of my intended/characterized recipient? rejected!

Clive Robinson August 6, 2026 1:19 AM

@ ALL,

The dangers of up stream, Agent Frameworks, vibe coding and similar on security.

In the past I’ve noted that the future of Current AI LLM and ML Systems is in the likes of niche products like Alpha-Fold. Which are in effect the modern day examples of 1980’s Expert Systems and Fuzzy Logic, that have never actually gone away just had name changes 😉

The current “big things” are “vibe-coding” which is a rework of 1970’s “Forth Generation Coding” ideas like the Apple ][ “Last One” system that has been revamped a number of times through “visuall code generation” for children to learn with like the now venerable two decade old “Scratch”,

https://codakid.com/blog/coding-for-kids/10-best-visual-coding-platforms-for-kids/#1_Scratch

And now via LLMs for very high level code generation we call “vibe-coding” from “loose language specifications” and a heck of a lot of “arm waving”.

In essence “boiler plate coding” at a very high level. An idea that goes back into the 1950’s, more than a lifetime ago (remember the aim of the “Common Business-Oriented Language”(Cobol) that is still around and in use?)

The problem with such systems is that they bring a form of “upstream insecurity” with them. That is the high level “code produced” is so boiler plate it is in effect “plaintext reuse” which has security implications all the way down the coding stack. That are almost as bad and sometimes worse than standard / formulaic “plaintext reuse” in “simple cryptography”…

This gets strongly exacerbated by “AI Agents” because you get thousands of down stream instances alk from the same “plaintext” and just a tiny amount of fuzzing.

We are now finally seeing some in the tech press moving into realising this glaring security issue with the likes of,

Prompt injection isn’t the bug, AI agent frameworks are

Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they’re telling Black Hat attendees what they found

Nearly a dozen flaws, some critical, in major AI agent frameworks that enterprises use to build apps reveal a security failure that extends beyond prompt injection – or any single model – according to Check Point researchers.

“Our research shows a deeper failure: in many agentic frameworks, prompt-controlled content can cross the boundary into trusted framework logic itself,” Yarden Porat and Shahar Tal note in a write-up about a Wednesday Black Hat talk on post-injection exploitation across AI agent frameworks, which they also discussed with The Register.

“A bug in an agent framework isn’t a bug in one product – it’s a bug in the layer a whole category of AI apps runs on,” Tal told us. “And the agent needs no dangerous tools to be turned against you: reading the wrong document is enough. We’re building this layer faster than we know how to defend it.”

https://www.theregister.com/security/2026/08/05/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/5283585

With a little thought it becomes almost obvious as the well known class of flaws that are already decades old. But people have leaped without thinking and now we are “having to pay the piper” on top of all the other “tokenmaxing” etc behaviour.

The further issue is that Agentic use of LLMs is so massive it far outstrips human agency to keep it in check thus is going to give a new generation of attackers a very very large “attack advantage”.

ResearcherZero August 7, 2026 2:42 AM

Another way to steal secrets such as password hashes…

Data recovery from Linux systems using speculative execution attack.

Re-poisoning the CPU state after cleaning can be achieved on AMD hosts.
Intel systems are more difficult to attack due to software requirements.

https://blackhat.com/us-26/briefings/schedule/#breaking-recently-deployed-spectre-v2-mitigations-a-novel-attack-primitive-53157

paper

‘https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf

Clive Robinson August 7, 2026 8:48 PM

@ ResearcherZero, ALL,

The Xmas Gift that Keeps On Giving

So they call it “Spectre-V2” or similar, but it’s really just another variation on the vulnerability of apparently all CPU “Go Faster Stripe” hardware (and even some GPUs these days).

Apparently so common it barely rates even a mention…

Where do I scream “Arrr…” into the night?

Clive Robinson August 8, 2026 12:26 AM

@ ResearcherZero, ALL,

As the Blackhat talk is marked up as “embargoed”…

You can find a fairly recent semi-related paper from the author, Daniël Trujillo MSc, that is not,

Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFI

Abstract — Modern processors incorporate aggressive branch prediction mechanisms for indirect branches, offering various unanticipated ways to influence speculative behavior during a transient execution attack. Existing mitigations against these so-called Spectre v2-style attacks are often ad-hoc, highly specific to the discovered attack and the targeted microarchitecture, and thus fail to generalize. In this paper, we identify a core requirement previously overlooked that all of these attacks share: secret reachability. Building upon this, we propose REGISTER HIDING and SHADOWCFI, two complementary but independent software-based and hardware-agnostic techniques which target the attacker’s ability to reach secrets in registers and memory…

1. Introduction
Speculative execution is paramount for the performance of pipelined processors. However, mispredictions can be dangerous, potentially leaving secret-dependent traces be-
hind. Indirect branch mispredictions (Spectre v2-type) are one of the most dangerous, allowing an attacker to execute arbitrary gadgets in the victim’s address space. Various mitigations have been proposed and implemented to protect against these attacks, targeting different attack ingredients. In this paper, we identify an ingredient that remained untar-geted so far, and propose to tackle this as a defense against Spectre v2-style attacks.

https://people.csail.mit.edu/mengjia/data/2026.SP.RegisterHiding.pdf

I won’t go into the paper on this post as “auto-mod”… but people will recognise that it has a “relationship” to the way cryptographic techniques developed some while ago.

To me this is not unexpected, I’ve just been wondering why it’s taken as long as it has.

Clive Robinson August 8, 2026 1:04 AM

@ Bruce, ALL,

An annoyance of Electronic Journals on Cognitive Load

Back in the days of journals that were actually printed paper they were somewhat resource intensive, thus strong limits were placed on papers.

This ment paper authors had to “stick to the point” and be brief as well as limiting what was used as graphics (none at all back last century was normal).

Effectively all these paper journal production limitations have now been removed with the use of PDFs.

And unfortunately it now shows… With papers being upto five times in size and some greatly more.

Whilst this allows for greater clarity and more informal presentation it drastically effects the cognitive load on the readers who often have very limited reading time as a resource.

This is made a lot worse by people using the likes of AI to “pad out” a paper to size and even used cautiously add a lot of extraneous information.

It’s been said in the past that,

“In a teaching book less than one tenth of the pages are really relevant, the rest is filler.”

I am starting to get the feeling that journal papers are starting to become “teaching books” not concise repositories of knowledge at the leading edge.

Which gives rise to the obvious question,

Is this a good thing or a bad thing in of it’s self?

Well my viewpoint currently rests on the “filler”. When looked at from even a slight distance the filler is “redundancy” that has high cost and low value and is quickly needless.

Worse the use of AI to “fuzz it up” as well as “fluff it up” is a temptation I suspect few are going to avoid given even a very little time.

Because it will feel like “work done efficiently” in terms of simple word count… Even though it is in reality,

“Make-Work writ large”.

Due to the increased cognitive load on readers I can see them resorting to AI to “de-fuzz and de-fluff” and try to remove or reduce the burden.

It’s not hard to see what the resulting deficits of this process will be, even without “AI Hallucinations and Soft Bullshit”.

Thus the question arises of,

“How long before this becomes an ever downward spiral into the mediocrity of thought and behaviour we oft call “Managment Speak” and similar?”

Clive Robinson August 9, 2026 5:51 AM

Originally Posted on 8th Aug ~05:15 UTC. Reposted in parts due to auto-mod.

Part 1,

@ Bruce, ALL,

An annoyance of Electronic Journals on Cognitive Load

Back in the days of journals that were actually printed paper they were somewhat resource intensive, thus strong limits were placed on papers.

This ment paper authors had to “stick to the point” and be brief as well as limiting what was used as graphics (none at all back last century was normal).

Effectively all these paper journal production limitations have now been removed with the use of PDFs.

And unfortunately it now shows… With papers being upto five times in size and some greatly more.

Whilst this allows for greater clarity and more informal presentation it drastically effects the cognitive load on the readers who often have very limited reading time as a resource.

Clive Robinson August 9, 2026 5:54 AM

Part 2,

This is made a lot worse by people using the likes of AI to “pad out” a paper to size and even used cautiously add a lot of extraneous information.

It’s been said in the past that,

“In a teaching book less than one tenth of the pages are really relevant, the rest is filler.”

I am starting to get the feeling that journal papers are starting to become “teaching books” not concise repositories of knowledge at the leading edge.

Which gives rise to the obvious question,

Is this a good thing or a bad thing in of it’s self?

Well my viewpoint currently rests on the “filler”. When looked at from even a slight distance the filler is “redundancy” that has high cost and low value and is quickly needless.

Worse the use of AI to “fuzz it up” as well as “fluff it up” is a temptation I suspect few are going to avoid given even a very little time.

Because it will feel like “work done efficiently” in terms of simple word count…

Clive Robinson August 9, 2026 5:58 AM

Part 3,

Even though it is in reality,

“Make-Work writ large”.

Due to the increased cognitive load on readers I can see them resorting to AI to “de-fuzz and de-fluff” and try to remove or reduce the burden.

It’s not hard to see what the resulting deficits of this process will be, even without “AI Hallucinations and worse”.

Thus the question arises of,

“How long before this becomes an ever downward spiral into the mediocrity of thought and behaviour we oft call “Management Speak” and similar?”

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.