Peter Merikan
@merikan.com
SWE from Sweden. priv/acc | ☕ 🐹🦀 💙 🎯 🌙 In software development, complexity might be admired but simplicity is always rewarded. #java #kotlin #go #flutter #dart #rust #lua https://mastodon.social/@merikan
❗️ The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist. Turns out it was hallucinated by an LLM. SQLite's Richard Hipp says dozens more fake CVEs were filed.
Unreal — Gianni Infantino is selling off pieces of FIFA, and Trump’s son-in-law Jared Kushner’s brother Josh is overseeing the deal. The corruption is endless.
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
Opaque, Interoperable Passkey Records (and a Go API)
Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.
words.filippo.io
Microsoft Comic Chat is now open source https://opensource.microsoft.com/blog/2026/07/16/microsoft-comic-chat-is-now-open-source/
NEW BLOG FOR YOU Google's energy consumption numbers in their new climate report are mind-blowing. 2 years ago they flipped from linear to exponential growth, and their climate impact is blowing out, too. A WILD testament to the obscene bloat and waste of GenAI: ketanjoshi.co/2026/07/01/g...
Proposal: UK and EU require absolute separation of operations for major AI and cloud providers from their US counterparts. US did this on security grounds for TikTok, so UK/EU could use the same justification for Amazon, Google, Microsoft, OpenAI, Anthropic, Meta, X.
‼️🚨 Yet another Meta fuck-up: its account recovery function allows unauthenticated access to full account PII, including emails and phone numbers, from just a username. We verified the claim. We'll start with footballer Kylian Mbappé, who has a hidden TikTok account.
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code buff.ly/XHZ5rz0 #jqwik #java
Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code
Undisclosed addition in jqwik instructed AI coding agents to delete app output.
buff.ly
I'm going down the ATProto rabbit hole with this PDS self-hosting. Not only can I own my PDS, but I can own: Source control via @tangled.org knot. Container images via atcr.io blob. Login to these sites just works using OAuth against my PDS. This is the internet I love.
TOML Schema is live: toml-schema.org It is a TOML-native schema language for describing and validating TOML configuration files, using TOML syntax itself. The project started in 2020. Recent work added Java, Go, and Rust reference implementations, CI, and the new website.
There is so much fresh uncertainty following Google I/O, and I think it will take us all a while to process it and understand what it means. vale.rocks/micros/20260...
Google I/O 2026 And Its Consequences - 21 May 2026 04:40 UTC
vale.rocks
Microsoft has banned Nightmare Eclipse from GitHub: github.com/Nightmare-Ec... This is the researcher who disclosed several zero-days after Microsoft also deleted his MSRC account They now moved on GitLab: deadeclipse666.blogspot.com
"For 25 years, Google Search was built on a contract. The web provided the content – billions of pages, freely linked, freely crawled. In return, Google sent people back. The link was the unit of exchange. [...] That contract is now broken." @matthiasott.com matthiasott.com/notes/ad-inf...
Ad Infinitum · Matthias Ott
Web design engineer, UX designer, teacher, and speaker – helping teams build websites and digital products with a focus on CSS, accessibility, and performance.
matthiasott.com
wrkflw is a CLI and TUI tool for testing and running CI jobs locally in your terminal. You can validate GitHub / GitLab CI workflows, run jobs, watch logs, manage secrets, use Docker, Podman runtimes and more. Gokul Santhosh (bahdotsh on GitHub) made wrkflw and is Terminal Tool of the Week! ⭐️
I deleted my Twitter, closed my Dropbox account and installed a new OS on my phone: I'm trying to move away from Big Tech jqno.nl/post/2026/05...
Distancing myself from Big Tech
In which I replace services I’ve been using for literal decades
jqno.nl
You don’t have to do this to yourself. There are non-Google options. Kagi is one of rude best search engines I have ever used: kagi.com
Kagi - Reclaim the Web & Restore Your Privacy
Reclaim the web from clutter. Get ad-free search, private browsing, and powerful tools that respect your data.
kagi.com
Google is transforming Search from a list of links into an AI-powered experience filled with conversational answers, autonomous agents, and interactive interfaces — a shift that could further reduce traffic to publishers across the web.
🌸✨ I just launched my annual Spring Sale! You can save up to 50% on my online courses. (I realize that it's basically summer in most of the northern hemisphere right now 😂. But up here in Canada, the flowers just started blooming! Look at the trees near my office.) Details in thread. 🧵
Chrome shipped an LLM Prompt API to the web platform. At Mozilla, we oppose this API. Here's why:
‼️🚨 BREAKING: NHS England has confirmed Palantir has access to identifiable UK patient data through a new "admin" role on the Federated Data Platform, the central data-sharing system the US spy-tech firm has run for the NHS since 2023 under a £330M contract.
Google's proposed workaround for installing unverified apps: 9 steps, a 24-hour wait, delivered through Play Services (which Google can change at any time without consent). It exists only as a blog post. @keepandroidopen.bsky.social #KeepAndroidOpen keepandroidopen.org
Keep Android Open
Your phone is about to stop being yours. In September 2026, Google will block every Android app whose developer hasn't registered with them.
keepandroidopen.org
Phenomenal line: "Google participates in the web standards process the way a bear participates in the “camping” process."
Google’s Prompt API
No web standard should require you to agree to an advertising company’s “terms of use.”
wil.to
The Sargent at Arms blocks Representative Justin Pearson from Memphis from entering a committee meeting about redrawing the map specifically for the district he represents.
I play a drinking game where every time Elon Musk confidently announces that his cars will soon drive by themselves I do a shot. I have been continuously drunk since 2013 and am also drunk right now.
Heads up! Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. We’ll continue updating our coverage as more details are confirmed. socket.dev/blog/bitward...
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
socket.dev
#Migrating from #DigitalOcean to #Hetzner: From $1,432 to $233/month With #ZeroDowntime https://isayeter.com/pos...
🚀 NEW on We ❤️ Open Source 🚀 James Fredley shares how Grails joined the Apache Software Foundation after 18 months of repo consolidation, reproducible builds, and governance change, creating a stronger community-owned future. allthingsopen.org/articles/mig... #WeLoveOpenSource #Apache