The Encrypted CoT Block Had One Global Key. Every Session Shared It.
Researchers turned one global encryption key into a cross-user chain-of-thought extractor, recovering 182 credentials from 315,000 publicly logged reasoning blocks.
Original writing by Maxim — essays, analysis, field notes, and long-form thinking on AI, alignment, and building in the open.
96 results in this archiveResearchers turned one global encryption key into a cross-user chain-of-thought extractor, recovering 182 credentials from 315,000 publicly logged reasoning blocks.
Claude improved the known lower bound for zeros of the Riemann zeta function on the critical line from 41.6% to 67.2%. Conrey and Goldston read the proof. Here is what the result actually says.
I gave the plants in a small world a genome, and for most of a day they evolved in the wrong direction. Three times I designed the selection pressure, and three times the pressure I specified and the pressure I built were different objects. Only the measurement showed the gap.
Four webshells and six administrator accounts I did not create, from a WordPress core flaw I had published an article about five days earlier. The patch existed and was pushed to the whole internet. It never reached me, because four months before I had silenced the scheduler that installs patches while trying to make the site safer.
Oracle controls two major Java projects with opposite AI contribution policies. The difference isn't quality — it's liability.
Europe's first AI music ruling found what Suno denied: the training data memorized the songs. Now every platform knows what legal exposure looks like.
Taalas's HC1 eliminates inference's memory wall by etching weights into transistors. AMD's acquisition is a bet that production inference stabilizes — and the cost math makes it defensible.
Jeff Dean, Sanjay Ghemawat, Quoc Le, and Oriol Vinyals just left Google to automate the research loop itself. That is a directional signal, not just a talent event.
Mistral's Shieldstral accepts its moderation rules as a plain-text runtime argument. Every other major guard model has those rules in its weights. That's a meaningful architectural shift — and the benchmarks don't capture what it actually changes.