The AI mess is real, and it's leaking your data
We've got migrations running hot, fakes one prompt away, and models spilling secrets. The tools are loud; the risks are quiet. Audit your agents, check your scanners, and don't trust anything that looks too clean. Esto te toca: la gente needs to know what's actually happening before it hits. Why this matters for us: every leak, every fake, every bad migration lands on our backs first.
Taste is a skill, not a gift
Ravi Mehta says taste isn't some mystical talent you're born with — it's the thing you develop by reading a lot, watching a lot, and noticing what actually lands. The writers and editors with the sharpest judgment are the ones who've spent years absorbing the good and the bad. You can't shortcut that.
The piece lands right now because LLMs have made this distinction suddenly urgent. A model can draft a hundred variants in a minute. What separates the usable from the forgettable is human taste — the eye that knows which one is worth keeping. The people who've built that judgment over years are the ones steering the output, not the ones typing the prompt.
Why this matters for us:
La gente who spend years honing their eye — writers, editors, anyone who's learned to read the room — are the ones who'll still matter when the machines do the grunt work.
Stripe bought an AI model for its payments stack — why?
Stripe picked up an AI model from OpenAI to handle card-not-present fraud, the kind that hits when someone's card is swiped online without a chip or chip pin. The model lives inside Stripe's fraud system, which already uses machine learning to flag suspicious transactions in real time. By adding an OpenAI model, Stripe is giving that system a bigger brain for pattern recognition — not replacing it, layering on top.
This is the same move that's been rippling through fintech: payments companies are treating large language models like a new sensor in the stack. For merchants, the result should be fewer false declines on legit orders. For consumers, that means your card doesn't get declined at checkout because a rule engine overreacted. The tradeoff is that the model itself can be fooled — adversarial examples exist, and Stripe will have to keep hardening against them.
Why this matters for us: our merchants get fewer false declines on real transactions, and our customers stop getting hit by overzealous fraud filters at checkout.
The models are good at syntax; they're bad at consequences.
— links.tldrnewsletter.com
#migrations-are-getting-messy-and-ai-is-making-it-worse-7be117Migrations with AI — the pulse we need to talk about
Gergely Orosz at the Pragmatic Engineer is laying out a real problem: the way teams are using LLMs for code migrations is moving faster than the tools can actually help. The post walks through the gap between what people expect from AI and what's still genuinely hard —…
Audit your agent files — before the AI leaks your data
Addyo is asking a question that most teams aren't asking yet: what files are your AI agent actually reading? The post walks through a practical method for auditing which documents your LLMs have access to — the spreadsheets, the internal wikis, the customer emails. Because…
tailcat: SSH-like remote commands over Tailscale
A new tool called tailcat lets you run commands on remote Tailscale machines the way you'd use SSH — but without the key management headache. You fire off something like tailcat machine-name command and it hits the Tailscale control plane to get the right endpoint and tunnels the connection. The whole thing is open source and sits at github.com/tailscale/tailcat.
The value is practical: teams that already use Tailscale for private networking can skip the SSH server setup, the authorized_keys dance, and the port-forwarding tricks. You're just talking to machines you already know about. For the cousin who runs a small web shop with three VPS boxes and a home lab, this is the kind of tool that saves an hour of troubleshooting every other week — the kind of thing that ends up in dotfiles and stays there.
Why this matters for us: la gente who are already juggling private networks for their side businesses and family servers need tools that respect that setup instead of forcing a whole new system on top of it.
Faking a brand is a one-prompt away
A16Z put up a post on how easy it is to generate a convincing fake brand — logo, tagline, color palette, even a few press mentions — using a handful of prompts. The point isn't that AI is impressive; it's that the friction to look legitimate has collapsed. Anyone with a…
Usertesting.com lets you pay $5 to test any screen
Usertesting.com just launched a new way to buy 1-on-1 screen recordings. You describe what you want to test — a landing page, a checkout flow, a new feature — and someone in the US opens your site in a new tab, talks through it out loud, and sends back a 60-second video with their mouse and voice captured. You pay $5 for the recording.
The model is simple. Each recording is 60 seconds, $5, one person, one task, one voice. No decks. No slides. Just a real person trying to do something on your site and telling you what they ran into. The recordings come back quickly and are easy to watch on a phone or laptop while you're commuting.
This is a different kind of research than a survey or a focus group. You're watching one person at a time, but you can order a batch and spot patterns — where people drop off, what confuses them, what they do instead of what you planned. It's the kind of thing that used to mean booking a lab, recruiting, and a full afternoon. Now it's a tab you open, a prompt you write, and $5 per person.
Why this matters for us: for the primo running a side hustle or the small shop testing a new menu page, this is a way to catch mistakes before they hit — fast, cheap, and without a research consultant.
SpaceX launches V3 Starlink satellites but booster relights fail again
SpaceX launched a second Starship V3 flight carrying new Starlink satellites, but the booster section had trouble relighting its engines on the return. The company got some boxes checked — more satellites, more flights — but the booster problem is back, and it's the same kind…
GoPro's Mission 1 Pro packs a bigger sensor — and real cinematic footage
GoPro just released the Mission 1 and Mission 1 Pro, a new line of action cameras that trade the old tiny sensor for a 1/1.7-inch one. Bigger sensor means more light, less noise, and footage that actually looks like something worth watching instead of a grainy dashcam shot.
The Pro model adds a 10-bit color profile and a 20mm lens. The standard model is 8-bit with a wider 15mm. Both shoot 5.3K at 60fps and 4K at 120fps. They're waterproof to 33 feet without a case, use USB-C, and fit in the same mounts as old GoPros. The Pro runs about $500; the standard is $350.
Action cameras have been stuck for years — tiny sensors, flat color, and footage that looks like it was shot on a 2012 phone. The Mission 1 line breaks that pattern. If you're the cousin filming a pickup game, the auntie shooting her grandson's birthday, or anyone who wants a camera that survives a drop and still produces video worth editing, this is the first action camera that doesn't make you compromise.
Why this matters for us: the gente who shoot on their phones can finally afford a camera that handles the heat, the sweat, and the drops without looking like a security feed.
Open-source AI code scanners — which one actually catches the bugs?
TLDR InfoSec pitted the biggest open-source AI code-security scanners against each other. The idea is simple: feed each tool a vulnerable repo and see which one flags the problems without drowning you in false positives. The goal is to pick a tool that actually works for the…
Glow is the free CRM for independent bodegas and taquerias
Glow just shipped a point-of-sale app built specifically for mom-and-pop shops — the bodega, the taqueria, the nail salon. It runs on a phone. No register, no belt, no $3,000 setup fee. You tap an item, it logs the sale, and the owner gets a daily summary. It's free. The whole point is that it doesn't require a credit card or a sales call.
The real trick is the free tier: no subscription, no per-location fee, no upsell to a merchant account. Most POS systems are a wedge — get you into their payment processing and lock you in. Glow makes money by selling analytics to suppliers who want to know what sells in a neighborhood. The product is the bait. The data is the business.
Why this matters for us: the tools we use to run our shops shouldn't need a venture round to exist — this is a model that actually lets la gente keep their margins without getting sold to a payment processor.
Cognition launches Agent — hands-free coding that works on the desktop
Cognition just shipped Agent 2, the next version of its hands-free coding agent that lives in your desktop app. You tell it what you need in natural language and it plans, writes code, opens files, runs tests, and fixes errors without you touching the keyboard.
The old Agent…
Claude Code now runs on iPhone — and it's a mess
Claude Code, the developer tool that lets you talk to Claude and it writes code for you, is now available for iOS. Not the app on your phone. The simulator. You have to run the Mac version on a Mac, then pair your iPhone to it, and suddenly the model is executing on your pocket.
Anthropic didn't ship this for you to code on the bus. It's a proof of concept — a way to test whether the tool works when you're not sitting at a desk. The catch is the Mac still does the heavy lifting. Your phone is just a remote control with a screen.
The move says something about how the tool is being positioned. Claude Code is a dev tool. Devs aren't always at their desk. They're at the bodega, they're riding the train, they're waiting for the kid's soccer practice. This puts the tool in their hand even if the real computation happens back at the Mac. It's a first step toward running the thing without a laptop at all.
The simulator is a rough way to get there. It's not the product. But it shows what's coming: Claude Code without the desk.
Why this matters for us: Brown devs who juggle multiple jobs don't always get a desk — and tools that assume one leave them out.
Model inversion: stealing secrets from your AI model
Researchers can pull private data out of a trained model by probing its outputs — not by hacking a server, but by feeding it inputs and reading the probabilities it spits back. The attack works on classification models, on image classifiers, and even on large language models.…
Model inversion: how your LLM leaks secrets
Model inversion is a new class of attack against large language models. Instead of guessing prompts, attackers feed the model carefully crafted inputs and watch its outputs — then reverse-engineer the data it was trained on. The result: personal information, private documents, even training data from competitors, pulled straight out of the model's weights.
The paper from Greptile walks through three attack vectors: membership inference (did this person exist in the training set?), reconstruction (rebuild the original record), and extraction (pull out specific fields like email or SSN). The attacks work best on smaller models and on data that was heavily featured in training — which is to say, most of the public web scraped into LLMs.
The fix isn't one thing. Red teaming, input filtering, and output sanitization help but don't solve it. The real move is treating any LLM that touches sensitive data as a leaky bucket: assume it will regurgitate what it saw, and design around that. That means not feeding PII in, rotating training data, and — for anything that matters — using on-prem models where you control what gets in and what gets out.
Why this matters for us: If you're running a model on customer data, your competitors and scammers can pull that data back out — so the question is whether your business is storing more secrets than it realizes.