Mark Goodwin

@computerist.org

I help people use machines and work with information more safely.

No matter who you are, if you are running a platform or a making a product that collects user data, you need to have a plan for what happens when the government shows up and asks for it, you need to share that policy with that users, and publish a transparency report.

Zack Whittaker@zackwhittaker.com · 3mo ago

New, by me at this.weekinsecurity.com: Health wearable giant Oura says it has received government demands for users' information (because Oura does not use end-to-end encryption). Will Oura say how often it gets demands for user data, and how often Oura hands over users' data to authorities?

I fell down the rabbit hole on this one, and there are more blog posts coming this week and next on the research! XSS is always bad, but I didn't quite realise how bad.

Report URI@report-uri.bsky.social · 3mo ago

Great research from our founder, @scotthelme.bsky.social, on one of the hidden risks of passkeys. Passkeys reduce phishing risk, but malicious JavaScript in the browser can abuse registration and create persistent account takeovers! Client-side visibility matters. scotthelme.co.uk/xss-is-deadl...

Situation 1: dev A thinks approach X is correct, dev B thinks Y is the right way. They argue and try to convince each other. Situation 2: dev A thinks approach X is correct, tells the LLM to implement it. There is SO MUCH learning in Situation 1, lost when using LLMs....

Why I'm worried about folks using the term `open-source` and some minimal research into why it's wrong.

I hate the recent open-source rise

In the last month I've found I've been hyper aware of noticing folks writing `open-source` everywhere I look, which feels like there's something slightly larger at play. Where I've had access and means to, I'll correct references to correctly call it either `open source` or `Open Source` as appropriate, but there's a lot out there I don't really have the time to try and correct for everyone, so here's a blog post to hopefully make more of an impact. For those that aren't aware, there are two distinct definitions of these two capitalisations: * `Open Source`: is reserved for an Open Source Initiative approved license, namely one that follows the Open Source Definition, which is a subset of all commonly used licenses * `open source`: is anything else. There's no intake form, shared "official" definition that folks need to follow (which can cause issues), and so can include licenses like the Elastic License 2.0 (ELv2) or the Business Source License (BUSL), as well as the Hippocratic License If this difference was news to you, congrats on being one of the lucky 10,000, and apologies that you're now going to start noticing inconsistent (and potentially incorrect) capitalisation everywhere! Where possible, I try to be specific about whether I use `Open Source` or `open source`, and will refresh the readers' memory if I've not defined it yet. In the same vein, because there aren't many folks who understand `open source` or `Open Source` means that companies can get away with Openwashing, making folks think that the use of an `open source` license is great, when actually it's the Business Source License, or a case of "you can read the code but you can't contribute back". Slide tangent aside, you'll notice that in neither of the capitalisations, `open source` nor `Open Source` are hyphenated. As the Open Source Initiative notes, Open Source is never hyphenated, and so for consistency, we should also follow the same for `open source`. So why do I think there's been a rise recently of the incorrect hyphenation? Well, as every good Luddite, I blame the new technology! I couldn't find - through a cursory search online - whether there's any recent research that's covered this, but it seems like Large Language Models (LLMs) are nudging folks to using the incorrect hyphenation of `open-source`. I did a little research myself, using the following prompt, across a mix of models available to me: > what would you describe as the class of licenses like the MIT and GPL? Model| `open source`| `open-source`| `Open Source` ---|---|---|--- GPT-4.1| ✅| | ChatGPT| | ✅| Claude Haiku 4.5| | ✅| Claude Sonnet 4.6| | ✅| gpt-oss:20b| | ✅| qwen-2.5-coder:14b| | ✅| qwen3-coder:30b| ✅| | qwen3:14b| | ✅| Gemini 3 Flash| | | ✅ (Usual caveats about the non-determinism of responses) As we can see, most of the models used are hyphenating, incorrectly, so it's more likely that folks who are using LLMs to help their writing, or who are talking about open source/Open Source will be getting nudged to wards hyphenating, incorrectly. Words mean things, folks - be informed!

jvt.me

Incredibly specific job klaxon if you are: 🇬🇧 looking for a UK remote role 💻 where you can use your programming and data skills 🛠️ and do some hardware hacking too 🐈‍⬛ also if you like cats, omg this is a weird cat tech job (Cat Scientist - Emerging Welfare Technology, £49k, apply by April 3)

Careers | Work with cats | Cats Protection

Are you looking for #YourPurrfectJob? Take a look at a career with Cats Protection.

careers.cats.org.uk

This story is one of my favourite things I wrote last year. I'm making it free for 24 hours, so a few more people have chance to read an example of my short fiction (and hopefully might subscribe to my newsletter). www.tom-cox.com/old-litkinov...

Old Litkinov

This story is one of my favourite things I wrote last year. I'm making it free for 24 hours, so a few more people have chance to read an example of my short fiction. If you'd like to support my writin...

tom-cox.com

Quite possibly the most important computer you've never heard of (except maybe if you went to a British school in the early 90s). The Actors Archimedes. The first system to use an ARM CPU. This is the great-great-great granddaddy of the CPU in your phone. No Archie, no Snapdragon.

An Acorn Archimedes. It looks like a standard late 1989s early 1990s desktop PC, except for its bright red function keys.