Issue #97Friday, August 28, 2026

The AI mess is real, and it's leaking your data

We've got migrations running hot, fakes one prompt away, and models spilling secrets. The tools are loud; the risks are quiet. Audit your agents, check your scanners, and don't trust anything that looks too clean. Esto te toca: la gente needs to know what's actually happening before it hits. Why this matters for us: every leak, every fake, every bad migration lands on our backs first.

ai_explainer_worthy

Taste is a skill, not a gift

Ravi Mehta says taste isn't some mystical talent you're born with — it's the thing you develop by reading a lot, watching a lot, and noticing what actually lands. The writers and editors with the sharpest judgment are the ones who've spent years absorbing the good and the bad. You can't shortcut that.

The piece lands right now because LLMs have made this distinction suddenly urgent. A model can draft a hundred variants in a minute. What separates the usable from the forgettable is human taste — the eye that knows which one is worth keeping. The people who've built that judgment over years are the ones steering the output, not the ones typing the prompt.

Why this matters for us:
La gente who spend years honing their eye — writers, editors, anyone who's learned to read the room — are the ones who'll still matter when the machines do the grunt work.

Read the sourceblog.ravi-mehta.com
fintech_unbanked

Stripe bought an AI model for its payments stack — why?

Stripe picked up an AI model from OpenAI to handle card-not-present fraud, the kind that hits when someone's card is swiped online without a chip or chip pin. The model lives inside Stripe's fraud system, which already uses machine learning to flag suspicious transactions in real time. By adding an OpenAI model, Stripe is giving that system a bigger brain for pattern recognition — not replacing it, layering on top.

This is the same move that's been rippling through fintech: payments companies are treating large language models like a new sensor in the stack. For merchants, the result should be fewer false declines on legit orders. For consumers, that means your card doesn't get declined at checkout because a rule engine overreacted. The tradeoff is that the model itself can be fooled — adversarial examples exist, and Stripe will have to keep hardening against them.

Why this matters for us: our merchants get fewer false declines on real transactions, and our customers stop getting hit by overzealous fraud filters at checkout.

Read the sourcethefinancialengineer.substack.com
ai_scams

Migrations with AI — the pulse we need to talk about

Gergely Orosz at the Pragmatic Engineer is laying out a real problem: the way teams are using LLMs for code migrations is moving faster than the tools can actually help. The post walks through the gap between what people expect from AI and what's still genuinely hard —…

Read the sourceblog.pragmaticengineer.com
ai_scams

Audit your agent files — before the AI leaks your data

Addyo is asking a question that most teams aren't asking yet: what files are your AI agent actually reading? The post walks through a practical method for auditing which documents your LLMs have access to — the spreadsheets, the internal wikis, the customer emails. Because…

Read the sourceaddyo.substack.com
other

tailcat: SSH-like remote commands over Tailscale

A new tool called tailcat lets you run commands on remote Tailscale machines the way you'd use SSH — but without the key management headache. You fire off something like tailcat machine-name command and it hits the Tailscale control plane to get the right endpoint and tunnels the connection. The whole thing is open source and sits at github.com/tailscale/tailcat.

The value is practical: teams that already use Tailscale for private networking can skip the SSH server setup, the authorized_keys dance, and the port-forwarding tricks. You're just talking to machines you already know about. For the cousin who runs a small web shop with three VPS boxes and a home lab, this is the kind of tool that saves an hour of troubleshooting every other week — the kind of thing that ends up in dotfiles and stays there.

Why this matters for us: la gente who are already juggling private networks for their side businesses and family servers need tools that respect that setup instead of forcing a whole new system on top of it.

Read the sourcegithub.com

Daily issue · no spam

Get the daily on your stoop

One short email a day — AI, tech, and what it means for our communities. Plain language, cultural lens, no Silicon Valley jargon.

other

Faking a brand is a one-prompt away

A16Z put up a post on how easy it is to generate a convincing fake brand — logo, tagline, color palette, even a few press mentions — using a handful of prompts. The point isn't that AI is impressive; it's that the friction to look legitimate has collapsed. Anyone with a…

other

Usertesting.com lets you pay $5 to test any screen

Usertesting.com just launched a new way to buy 1-on-1 screen recordings. You describe what you want to test — a landing page, a checkout flow, a new feature — and someone in the US opens your site in a new tab, talks through it out loud, and sends back a 60-second video with their mouse and voice captured. You pay $5 for the recording.

The model is simple. Each recording is 60 seconds, $5, one person, one task, one voice. No decks. No slides. Just a real person trying to do something on your site and telling you what they ran into. The recordings come back quickly and are easy to watch on a phone or laptop while you're commuting.

This is a different kind of research than a survey or a focus group. You're watching one person at a time, but you can order a batch and spot patterns — where people drop off, what confuses them, what they do instead of what you planned. It's the kind of thing that used to mean booking a lab, recruiting, and a full afternoon. Now it's a tab you open, a prompt you write, and $5 per person.

Why this matters for us: for the primo running a side hustle or the small shop testing a new menu page, this is a way to catch mistakes before they hit — fast, cheap, and without a research consultant.

Read the sourcereadwriterachel.com
other

GoPro's Mission 1 Pro packs a bigger sensor — and real cinematic footage

GoPro just released the Mission 1 and Mission 1 Pro, a new line of action cameras that trade the old tiny sensor for a 1/1.7-inch one. Bigger sensor means more light, less noise, and footage that actually looks like something worth watching instead of a grainy dashcam shot.

The Pro model adds a 10-bit color profile and a 20mm lens. The standard model is 8-bit with a wider 15mm. Both shoot 5.3K at 60fps and 4K at 120fps. They're waterproof to 33 feet without a case, use USB-C, and fit in the same mounts as old GoPros. The Pro runs about $500; the standard is $350.

Action cameras have been stuck for years — tiny sensors, flat color, and footage that looks like it was shot on a 2012 phone. The Mission 1 line breaks that pattern. If you're the cousin filming a pickup game, the auntie shooting her grandson's birthday, or anyone who wants a camera that survives a drop and still produces video worth editing, this is the first action camera that doesn't make you compromise.

Why this matters for us: the gente who shoot on their phones can finally afford a camera that handles the heat, the sweat, and the drops without looking like a security feed.

small_business_ai

Glow is the free CRM for independent bodegas and taquerias

Glow just shipped a point-of-sale app built specifically for mom-and-pop shops — the bodega, the taqueria, the nail salon. It runs on a phone. No register, no belt, no $3,000 setup fee. You tap an item, it logs the sale, and the owner gets a daily summary. It's free. The whole point is that it doesn't require a credit card or a sales call.

The real trick is the free tier: no subscription, no per-location fee, no upsell to a merchant account. Most POS systems are a wedge — get you into their payment processing and lock you in. Glow makes money by selling analytics to suppliers who want to know what sells in a neighborhood. The product is the bait. The data is the business.

Why this matters for us: the tools we use to run our shops shouldn't need a venture round to exist — this is a model that actually lets la gente keep their margins without getting sold to a payment processor.

other

Claude Code now runs on iPhone — and it's a mess

Claude Code, the developer tool that lets you talk to Claude and it writes code for you, is now available for iOS. Not the app on your phone. The simulator. You have to run the Mac version on a Mac, then pair your iPhone to it, and suddenly the model is executing on your pocket.

Anthropic didn't ship this for you to code on the bus. It's a proof of concept — a way to test whether the tool works when you're not sitting at a desk. The catch is the Mac still does the heavy lifting. Your phone is just a remote control with a screen.

The move says something about how the tool is being positioned. Claude Code is a dev tool. Devs aren't always at their desk. They're at the bodega, they're riding the train, they're waiting for the kid's soccer practice. This puts the tool in their hand even if the real computation happens back at the Mac. It's a first step toward running the thing without a laptop at all.

The simulator is a rough way to get there. It's not the product. But it shows what's coming: Claude Code without the desk.

Why this matters for us: Brown devs who juggle multiple jobs don't always get a desk — and tools that assume one leave them out.

Read the sourcemacrumors.com
ai_scams

Model inversion: stealing secrets from your AI model

Researchers can pull private data out of a trained model by probing its outputs — not by hacking a server, but by feeding it inputs and reading the probabilities it spits back. The attack works on classification models, on image classifiers, and even on large language models.…

Read the sourcelinks.tldrnewsletter.com
ai_scams

Model inversion: how your LLM leaks secrets

Model inversion is a new class of attack against large language models. Instead of guessing prompts, attackers feed the model carefully crafted inputs and watch its outputs — then reverse-engineer the data it was trained on. The result: personal information, private documents, even training data from competitors, pulled straight out of the model's weights.

The paper from Greptile walks through three attack vectors: membership inference (did this person exist in the training set?), reconstruction (rebuild the original record), and extraction (pull out specific fields like email or SSN). The attacks work best on smaller models and on data that was heavily featured in training — which is to say, most of the public web scraped into LLMs.

The fix isn't one thing. Red teaming, input filtering, and output sanitization help but don't solve it. The real move is treating any LLM that touches sensitive data as a leaky bucket: assume it will regurgitate what it saw, and design around that. That means not feeding PII in, rotating training data, and — for anything that matters — using on-prem models where you control what gets in and what gets out.

Why this matters for us: If you're running a model on customer data, your competitors and scammers can pull that data back out — so the question is whether your business is storing more secrets than it realizes.

Read the sourcegreptile.com

Past issues

30
Aug 30Sun

Robots, robots, and more robots

Issue #99
Aug 29Sat

The grifts are multiplying — and we're still here

Issue #98
Aug 27Thu

The AI bust is here — and it's real.

Issue #96
Aug 26Wed

Bonds defaulting, robots getting smarter — the usual chaos.

Issue #95
Aug 25Tue

Models are getting heavy, builders are getting real

Issue #94
Aug 24Mon

This week, the world's grinding gears

Issue #93
Aug 23Sun

Lo que viene: labras, filtros, fundadoras, y la migra

Issue #92
Aug 22Sat

La migra and the meta: big tech's growing pains

Issue #91
Aug 21Fri

Open source is bleeding — and so is your wallet

Issue #90
Aug 20Thu

The feed is widening — and it's getting weirder

Issue #89
Aug 19Wed

The day the ground shifted — and the side gigs stayed

Issue #88
Aug 18Tue

AI is growing up — and so are the bills

Issue #87
Aug 17Mon

Lying models, real planes, and the benchmarks that lie to you

Issue #86
Aug 16Sun

AI is learning to lie and steal — and the guardrails are off

Issue #85
Aug 15Sat

La migra moves, gas triples, and the water plants got hacked

Issue #84
Aug 14Fri

Issue 83 — 2026-08-14

Issue #83
Aug 6Thu

Silicon Valley's reckoning is here — y la pregunta es para los de abajo

Issue #75
Aug 5Wed

Issue 74 — 2026-08-05

Issue #74
Aug 3Mon

Software is cheap, math is open, hardware is real — esto es lo que importa.

Issue #72
Aug 2Sun

El teléfono ya no es tuyo — y ni los eclipses se ven fácil

Issue #71
Aug 1Sat

El hardware se vuelve la barrera — y la gente sigue adelante

Issue #70
Jul 31Fri

Silicon, cuts, and the real moat — lo que importa

Issue #69
Jul 30Thu

The internet's noise floor is rising — and la gente is paying for it

Issue #68
Jul 29Wed

Agent swarms are finally paying for themselves

Issue #67
Jul 28Tue

Issue 66 — 2026-07-28

Issue #66
Jul 27Mon

El cohete, la inteligencia, y lo que le toca a la gente

Issue #65
Jul 26Sun

Tecnología y clima — lo que no nos lo dice la gente

Issue #64
Jul 25Sat

Issue 63 — 2026-07-25

Issue #63
Jul 24Fri

Las herramientas que nos rodean se están moviendo — y a veces nos pasan por encima

Issue #62
Jul 12Sun

Lo que importa hoy: la gente, no la máquina

Issue #61

Daily issue · no spam

Get the daily on your stoop

One short email a day — AI, tech, and what it means for our communities. Plain language, cultural lens, no Silicon Valley jargon.