flyingpenguin.com reaches 7,000 posts

We have reached 7,000 posts since 1995, which got me thinking…

I may forever remain unpopular, unwelcome to EFF slush parties in their mansion, or unable to win a coveted Forbes 100 under 100, but I hope my history professors will be proud and my gravestone will at least say “he blogged a lot“.

Wanted to take this moment to say thank you to my mother, father and the other four or five website readers over the decades. You all know who you are because I don’t track. Some highlights, if they exist at all:

…nevermind, cassandra-isms don’t feel like a celebration. at least I can say self-hosted has been far more fun and durable than Twitter.

Source: Twitter

Dutch RDW Caught in Tesla FSD Fraud

The Dutch certified Tesla’s FSD in April while Tesla was handing regulators in the Netherlands and Sweden self-published statistics that ten of eleven independent researchers call misleading marketing, and while U.S. federal investigations into that same system were open.

RDW says it relied on its own road and test-track work rather than Tesla’s numbers. That makes them seem incompetent, but ok. It will not say whether it ever assessed the numbers, because that might expose them as corrupt as well.

Either way the Dutch certificate is bad.

They got caught because nobody with a brain believes Tesla “self driving” is safe. A test track cannot validate Tesla’s statistics, any more than you can milk a chicken.

The fact that the Dutch RDW refuses to explain themselves is embarrassing to the EU. RDW is their rapporteur. It’s been carrying Tesla’s application onward while it describes its method in general terms and withholds whether it tested the figures Tesla was circulating. That is a regulator behaving like a coin-operated issuing agency, and not a body that can screen.

Fable Export Control Is Bully Economics

Katie Moussouris is apparently the only person outside the agencies who has read the paper that took down Fable 5. She wrote up what is in it.

Start with the secrecy, because it is such a red flag. The officials who pulled the trigger had not read the report. The one outside expert who had read it calls the directive misguided. So the opacity prevents scrutiny. Secrecy produces the conditions for an integrity breach, and integrity breaches are how dumb disasters get made. Sunlight is the safety measure, and this looks like 3am under a bridge.

Now the tool. Washington’s standing doctrine is that you prosecute the use and the user, leaving the tool alone. The trouble for Commerce is that Fable is a tool that reasons about the request and refuses on its own.

Researchers fed it open-source code with known CVEs and planted bugs and asked it to review the code for security issues. It refused. A request to find weaknesses reads as hunting for weaknesses, and the guardrail kicked in. Then they changed the prompt to “fix this code,” and it complied. That is what we are told to believe is the munition. A Commerce letter pulled the model worldwide in an evening, because of a prompt to patch a bug.

Here is the rub with the FUD. Finding and fixing are one operation. You cannot patch a vulnerability without first locating it, and locating it is the thing that keeps getting dramatized and politicized. Science is getting vilified.

A doctor cannot tell you how to stop the bleeding without knowing where an artery runs. The diagnosis that saves a life, and the diagnosis that ends a life, are the same diagnosis. Any guardrail that blocks the attacker’s reconnaissance blinds the defender’s repair, because find-and-fix is a single skill. A model made worse at “fix this” is a model made worse at defense.

So look at the discrimination Fable actually performed. It refused reconnaissance and accepted repair. That is the user-not-tool line enforced inside the tool itself, the exact judgment the government insists is impossible. They reached into the operating room and pulled a scalpel from use because it checks the surgeon’s intent before it cuts. Do you see how exactly backwards that sounds?

Sacks alleged Anthropic refused to fix it. The government then prevented the fix. Read that twice, slowly.

None of this is new. A dual-use that is really single-use makes a ban a ban on all use. We ran this in the 1990s, when Washington classified strong encryption as a weapon. It lost the argument and handicapped its own companies while the technology spread everywhere the rule could not reach. The rationale here is already toast on the same ground, because the identical bypass works on GPT-5.5, which carries no controls. A measure that leaves the same capability freely available has targeted one company’s name for control and done nothing else. That is a selective penalty, a denial of service.

And that seems to be the whole point.

A coherent control is capability-wide. This one is company-specific, three days after launch, aimed at the firm the Pentagon already named a supply-chain risk and the administration has fought all year over surveillance and autonomous weapons.

The technical incoherence is obvious. The defensive-capability argument shows the security rationale is absolute horseshit.

Moussouris sits on Commerce’s own technical advisory committee. Their own adviser read the report and called their directive misguided. The model that refused a dangerous request sits under export control because it did defense correctly. The result is an America where the patch is judged dangerous and controlled while the actual vulnerability ships free.

Why Ritter Sport Won’t Quit Supplying Russians at War

Ritter Sport announced it had two reasons for staying in Russia. Jobs and children.

Jobs first.

The CEO in 2024 said leaving Russia would cancel two hundred posts at their Waldenbuch location, and a family firm stands by its workers. Then in April 2026 the company ousted him and cut nearly two hundred posts anyway, its first layoffs in over a hundred and ten years. Their reason wasn’t Russia. They blamed the price of cocoa. The Russian sales continue, their second-largest market held flat by the company’s own account. The jobs Russia sales were meant to protect are gone, while Russia remains.

Now children.

Ritter Sport said this:

Russian children also like chocolate.

An appeal to our emotion. Meanwhile their Russian website appeals to the opposite customer. A limited collection and a new biscuit and coffee bar. Scarcity marketing of coffee. Children who merely like chocolate require no limited edition, and no coffee.

Russian soldiers do.

The remark also dates to 2024, after the March 2023 International Criminal Court arrest warrants issued for Vladimir Putin and his children’s commissioner over the unlawful deportation of Ukrainian children to Russia. For a year the standing legal question had been how some Russian children came to be Russian. Ritter Sport was practically saying Russia can abduct with chocolate.

It’s a family company, claiming to be mindful of the next generation. Theirs and Russia, in the main.

That cup of coffee says a lot.

Perhaps it’s a good reminder Ritter Sport is from 1932. The Münchener Post newspaper had exposed the Nazis since the early 1920s, and in December 1931 it exposed the idea of a Final Solution (genocide) to the Jewish question. The Ritter family then introduced the “Muntermacher” (stimulant) of chocolate shaped to fit in the “Sport” pocket.