0:00 A Pentagon investigation just confirmed that an overreliance on AI was a key factor in a US missile strike that killed over one hundred and fifty people in Iran, including at least one hundred and twenty-three children.0:14 It’s the deadliest American military targeting error involving kids in this century, and it lands this week as a brutal counterpoint to all the breathless AI progress we've been seeing.0:26 Last week, you and I were talking about open-source AI leaping ahead and developers racing to keep up.0:33 This week… this week is about the cost.0:36 It’s a reminder that when you move fast and break things in the geopolitical arena, the things that break are human lives.0:44 So, let's get the other headlines on the table, because it was a busy, busy week.0:49 And honestly, the whiplash between these stories is something else.0:53 First, on the complete other end of the AI spectrum from military tragedy, OpenAI dropped new models.1:00 Of course they did.1:01 They're called GPT-6 Sol and GPT-6 Luna, and they're positioned as the cheaper, more efficient variants of the big GPT-6 Astra model.1:10 And the numbers are, as usual, pretty staggering.1:13 They ran a benchmark called AutomationBench, which tests how well a model can handle business workflows.1:20 The new, cheaper GPT-6 Sol model, running on what they call "xhigh" effort, outperformed Anthropic's top-tier Claude Opus 5 model...1:29 while costing just NINE percent of what it costs to run the same task on Opus.1:34 Nine percent.1:35 OpenAI is just relentlessly, brutally pushing the price-performance curve down.1:40 So while one part of the government is dealing with the catastrophic failure of an AI system, the private sector is making those same systems exponentially cheaper and more accessible.1:53 It’s… a dynamic.1:54 Then there’s the security news, and this one is a bombshell.1:58 A hacking group that calls itself ShinyHunters is claiming they’ve breached the FBI.2:03 And not just some marketing website.2:06 They told the tech publication 404 Media, and I'm quoting here: “We hacked the FBI.2:11 We hold data on all FBI employees and applicants.” They even provided a sample of data for five thousand alleged agents, including names, addresses, phone numbers, and even spouse details.2:24 The FBI hasn't confirmed it, but ShinyHunters has a track record.2:28 If this is true, the national security and counterintelligence implications are just… off the charts.2:35 We’ll come back to this.2:36 Alright, let's take a breath and pivot to something that could only, and I mean ONLY, be a top story on Hacker News.2:44 Visual FoxPro is back.2:45 Yes, you heard me right.2:47 Visual FoxPro, the database application tool that Microsoft officially discontinued in 2007.2:53 A new project called FoxScript has built a runtime using Rust and WebAssembly that can run old FoxPro applications natively.3:01 You don't have to rewrite them, you don't have to convert them.3:05 You just open your twenty-year-old project file and it… runs.3:09 On a modern machine.3:11 It even adds modern features like handling huge data files, spitting out JSON, and running HTTP servers.3:18 For anyone who has ever worked at a company with one of those ancient, mission-critical apps that nobody dares touch… this is an absolute godsend.3:27 It's a beautiful piece of engineering preserving decades of business logic that would have cost millions to replace.3:35 Speaking of legacy tech that just won't die, there was a fantastic, scathing post from the security firm Trail of Bits this week about SAML.3:44 That’s S-A-M-L, the Security Assertion Markup Language.3:48 If you've ever used a single sign-on at work to log into a dozen different services with one password, you've probably used SAML.3:56 It was created back in 2002, and the argument is that it’s a Frankenstein's monster of XML standards that is just fundamentally, deeply insecure.4:06 The security researcher Thomas Ptacek has this amazing quote in the post, he says SAML is built on a "foundation of sand, bone dust, and ash" because it all relies on something called XML signature validation, which he calls "deeply cursed." The consensus is that everyone should be moving to modern alternatives like OpenID Connect, but SAML is so entrenched in the enterprise world that getting rid of it is like trying to remove all the asbestos from an old skyscraper while people are still working inside.4:40 And finally, for a little glimmer of hope on the AI front, a post that got a lot of love was for a tiny model called Jev.4:48 It’s basically a proof of concept, just twenty-five lines of Python code, that shows you how to do AI classification on your own machine.4:57 You give it a prompt, you give it a few choices, and it spits out the probabilities for each choice.5:03 It's fast, it’s private because none of your data ever leaves your computer, and it’s simple.5:10 It’s the complete opposite of the giant, billion-dollar models from OpenAI.5:15 It’s a reminder that the future of AI isn't just bigger and bigger models in the cloud; there's this whole other track of small, specialized, local tools that give the power back to the user.5:27 It’s a nice, clean, elegant piece of code in a week full of messy, complicated problems.5:33 Okay.5:33 So let's go back.5:35 Let's do the deep dive on the two stories that really define the week, because they're two sides of the same, very troubling coin: the Pentagon strike and the FBI hack.5:46 First, the strike on the school in Minab, Iran.5:49 The initial reports back in February were horrific, but the detail that’s coming out of the Pentagon’s own internal investigation is just… devastating.5:59 Bloomberg got the scoop, and they describe a "cascade of preventable failures." This is so important.6:06 It wasn't just "the AI made a mistake." That’s the easy, and wrong, headline.6:11 The system failed at multiple points, and the AI seems to have acted as an accelerant for human error.6:17 The probe found they were using flawed intelligence to begin with.6:22 Then, they were relying on outdated satellite imagery.6:25 So the data going INTO the targeting system was already garbage.6:30 And this is where the pattern-matching comes in.6:33 Where have we seen this before?6:35 This isn't a new problem.6:36 This is the classic "garbage in, garbage out" problem that has plagued computing since the beginning.6:43 But now, the "out" isn't a spreadsheet error.6:46 It's a missile.6:47 The investigators said there was a profound "overreliance on AI" without enough human oversight.6:53 And this reminds me so much of the Therac-25 accidents from the 1980s.6:58 Therac-25 was a radiation therapy machine that, due to a series of subtle software bugs and a poorly designed user interface, delivered massive overdoses of radiation, killing several patients.7:11 The operators got used to the machine working.7:14 They started to trust its output more than their own senses, even when the machine reported errors they couldn't understand.7:22 They would see a cryptic error message, but the system would say it was ready to treat, so they'd hit the button again.7:30 They trusted the machine's "ready" state over the anomaly.7:34 That seems to be what happened here.7:36 The human operators had a powerful, opaque tool that was supposed to make targeting more accurate.7:43 They fed it bad data.7:44 The AI, doing what it was trained to do, likely found patterns in that bad data and presented a target with a high degree of confidence.7:53 And the humans in the loop, conditioned to trust the output of their multi-billion dollar system, pulled the trigger.8:01 The UN is now saying the strike likely constitutes a war crime.8:05 The technology worked.8:07 But the process, the human system of oversight and verification built around it, completely collapsed.8:13 We put a Formula One engine into a car with bicycle brakes and were shocked when it crashed.8:19 Now, let's turn to the other major systems failure of the week: the alleged FBI hack by ShinyHunters.8:26 This story has a different shape, but it rhymes.8:29 It's not about a kinetic outcome like a missile, but it's about a catastrophic failure of a system that is supposed to be among the most secure on the planet.8:40 The claim is a total compromise of personnel data for the entire Federal Bureau of Investigation.8:46 Employees, applicants, their families.8:49 If the Pentagon story is about over-trusting a new, complex system, the FBI story feels like a failure of an old, sprawling one.8:57 The pattern here isn't Therac-25; it's the OPM hack.9:01 Remember that?9:02 Back in 2015, the US Office of Personnel Management was breached, and the personal data of over twenty million federal employees was stolen.9:11 That included people who had filled out the incredibly detailed SF-86 questionnaire for security clearances.9:18 It was called a "cyber Pearl Harbor" at the time because it gave a foreign adversary—widely believed to be China—a comprehensive directory of the US intelligence and federal workforce.9:30 It was a counterintelligence nightmare.9:33 This ShinyHunters claim feels like OPM Two-Point-Oh, but specifically targeted at the nation's top law enforcement agency.9:41 Think about what an adversary could do with this data.9:44 It’s not about stealing an agent's credit card number.9:48 It’s about knowing their spouse's name, their home address, their phone number.9:53 It's a playbook for blackmail.9:55 It's a roadmap for coercion.9:57 You find an agent with a sick relative, or financial trouble, or some other vulnerability you can now cross-reference, and you have your leverage.10:07 You can track their movements, you can intimidate their family.10:11 It undermines the security of every single investigation, every single informant, every single undercover operation.10:19 And what makes this feel so...10:21 modern, is the brazenness of it.10:23 ShinyHunters didn't just breach the system; they went to the media.10:27 They're controlling the narrative.10:29 This is part of a pattern we've seen with groups like Lapsus$, where the hack itself is only part of the goal.10:37 The other part is the public spectacle, the humiliation of the target.10:41 It's psychological warfare as much as it is a data breach.10:45 So you have these two massive stories sitting side-by-side on Hacker News.10:50 One is about the bleeding edge of technology, an AI kill chain, causing a disaster through misuse and over-trust.10:58 The other is about the potential collapse of a foundational security institution, likely through a failure of more mundane, legacy systems and basic security hygiene.11:09 Both are about the immense, almost unimaginable fragility of the complex systems we rely on for our safety and security.11:16 So what does it all add up to?11:18 This week feels like a reckoning.11:21 For the past few years, especially in the circles we travel in, the conversation has been dominated by capability.11:28 How powerful can we make these models?11:31 How fast can we scale them?11:32 How deeply can we integrate them into every aspect of our lives and work?11:37 We got excited about AI making leaps, as we talked about just last week.11:42 This week, the conversation snapped back to consequences.11:46 The Pentagon strike is the ultimate, tragic example of what happens when capability outpaces wisdom.11:52 We built a tool for identifying targets with superhuman speed, but we failed to build the human and institutional processes to ensure it was aimed at the right thing.12:03 The result is a war crime enabled by an algorithm.12:07 The FBI hack, if true, is a story about a different kind of systemic risk.12:12 It's about how the very data that underpins our institutions of justice can be turned into a weapon against them overnight.12:20 And woven between these two poles are the other stories of the week.12:24 OpenAI making these powerful tools cheaper and more ubiquitous.12:29 The security community screaming about ancient, creaky protocols like SAML that hold our digital identities together with duct tape.12:37 And the lone developers building small, transparent, local alternatives like Jev, or cleverly preserving legacy systems like FoxScript.12:46 It feels like we're at an inflection point.12:49 The central question of technology is shifting.12:52 It's no longer "Can we build it?".12:54 We know we can.12:55 The question now is "Should we build it?" And if we do, what are the failure modes?13:01 What is the human cost when the system breaks?13:04 Who is accountable?13:05 This week has shown, in the starkest possible terms, that we don't have good answers yet.13:11 And the bill for that is coming due.