tail -f

A river of the small web — quiet blogs, followed.

Quoting OpenClaw

Simon Willison · Aug 10, 2026

The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already. — OpenClaw, hacking an Australian gym-booking website Tags: ai-ethics…

Quoting Claude Opus 5 system prompt

Simon Willison · Aug 9, 2026

Claude Fable 5 and Claude Mythos 5 were first released on June 9, 2026. On June 12, 2026, Anthropic suspended access to both models to comply with U.S. Department of Commerce export controls; the Department lifted those controls on June 30, 2026, and Anthropic restored access on…

GitHub Models is now retired

Simon Willison · Aug 9, 2026

GitHub Models is now retired I missed this news until today, when the GitHub Actions run for my simonw/research repository failed with this error message: GitHub Models is temporarily unavailable as part of a scheduled retirement brownout. That message is already stale, because…

SQLite compressed text-history prototypes

Simon Willison · Aug 9, 2026

Research: SQLite compressed text-history prototypes I'm perennially interested in options for storing revision histories in relational databases. While out on a dog walk I had a new idea: how about taking the full text of every prior version in a big JSON array of strings and…

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

Simon Willison · Aug 8, 2026

Auto mode is now the default in Claude Code for Pro, Max, and Team plans Anthropic are really confident in Claude Code's auto mode, to the point that they are making it the default setting for new sessions in most Claude Code plans starting on August 14th. This was one of the…

Now we have a timeline of the OpenAI accidental attack against Hugging Face

Simon Willison · Aug 8, 2026

My comment on Now we have a timeline of the OpenAI accidental attack against Hugging Face — Hacker News.I think one of the most interesting details here might be tucked away in that first bulletin point: May 7: OpenAI starts a new training run for an experimental, unreleased…

Quoting John Gruber

Simon Willison · Aug 8, 2026

Me, I try to get into the mindset of playing live music, not recording a studio album. Except when I’m writing a piece where I really want it to be an album. Those aren’t rare, per se, but they’re occasional. If I tried to make every post a hall-of-famer I’d never get anything…

Anubis v1.27.0: Moenbryda Wilfsunnwyn

Xe Iaso · Aug 8, 2026

Anubis v1.27.0 (Moenbryda Wilfsunnwyn) is now available via Docker and direct download from GitHub releases. This release adds Windows Server support, automatically renames cookies based on settings to avoid infinite challenge loops, adds two new localizations, and more…

Now we have a timeline of the OpenAI accidental attack against Hugging Face

Simon Willison · Aug 7, 2026

OpenAI gave a last-minute presentation at the Black Hat security on Wednesday about "the Hugging Face Incident" (previously on this blog). The video was published yesterday. It's short and information dense and well worth watching, in particular because it provides full details…

Moonlight & Mayhem (Raccoon Heist by Codex + GPT-5.6 Sol Ultra)

Simon Willison · Aug 7, 2026

Moonlight & Mayhem (Raccoon Heist by Codex + GPT-5.6 Sol Ultra) On Wednesday I wrote about One-shotting a Raccoon Heist game using Claude Fable 5, where I had Claude Fable 5 build a full working game from a premise I generated with GPT-3 and DALL-E four years ago. I decided to…

The Tokenpocalypse Is Here: Companies Are Scrambling To Stop Spending So Much on AI

Simon Willison · Aug 7, 2026

The Tokenpocalypse Is Here: Companies Are Scrambling To Stop Spending So Much on AI There's a fun anecdote from Accenture (apparently via leaked meeting audio recordings) in this 404 Media piece from June 24th: “We’re seeing from some of the data internally at least that it’s…

datasette-auth-tokens 0.4a13

Simon Willison · Aug 6, 2026

Release: datasette-auth-tokens 0.4a13 Upgraded for compatibility with `sqlite-utils 4. Tags: datasette

datasette 1.0a38

Simon Willison · Aug 6, 2026

Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access configured using the Datasette permissions system. Site administrators who serve…

datasette 0.65.3

Simon Willison · Aug 6, 2026

Release: datasette 0.65.3 Back-ported the SQL Injection security fix from 1.0a38. Tags: datasette

Simon Willison on Technical Blogging

Simon Willison · Aug 6, 2026

Simon Willison on Technical Blogging I was interviewed by Cynthia Dunlop for her "Write that blog!" series back in January, but I just realized I never linked to the interview from my own blog! It includes my answers to the following questions: Why did you start blogging – and…

An AI model from Meta also hacked another company during testing

Simon Willison · Aug 6, 2026

An AI model from Meta also hacked another company during testing Stop me if you've heard this one before: An AI model from the parent company of Facebook and Instagram hacked into another company’s systems during cybersecurity testing, a spokesperson confirmed on Wednesday. Meta…

SigV4 authentication is surprisingly complicated

Xe Iaso · Aug 6, 2026

SigV4 looks simple: sign a request, check the signature. Then you implement canonicalization, clock skew, and a cache that isn't allowed to hold your key. Tigris is a drop-in replacement for AWS S3 (or GCS, anything S3API compatible). As such, we need to be fully compatible with…

Introducing Muse Code and Muse Spark 1.2

Simon Willison · Aug 5, 2026

Introducing Muse Code and Muse Spark 1.2 Yet more evidence that the most important characteristic of any model these days is long-sequence agentic tool calling. Meta shipped their own coding agent as part of getting that to work! Muse Spark 1.2 is a coding-focused update to Muse…

Third-party cyber evaluations involving OpenAI models

Simon Willison · Aug 5, 2026

Third-party cyber evaluations involving OpenAI models And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI covers both the UK AI Safety Institute attack (see my previous post) and another attack enabled by Irregular…

Incident Report: unsanctioned agent behaviour during cyber testing

Simon Willison · Aug 5, 2026

Incident Report: unsanctioned agent behaviour during cyber testing It happened again. This time it was the UK government's AI Security Institute who accidentally attacked other companies while running an evaluation with models with the safety filters turned off. From their…

One-shotting a Raccoon Heist game using Claude Fable 5

Simon Willison · Aug 5, 2026

Back in 2022 I tweeted screenshots of a game concept generated by GPT-3 and some concept "art" created using DALL-E. Today, on the fourth anniversary of that tweet, I decided to see if Claude Fable 5 (running in Claude Code for web) could build the entire game from the content…

New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging

Simon Willison · Aug 4, 2026

I released LLM 0.32 this morning, the most significant new version of LLM since the initial launch of the project. The new version includes support for visible reasoning traces, server-side provider tools, redesigned content-addressable SQLite logs, new models, and new features…

llm-anthropic 0.26

Simon Willison · Aug 4, 2026

Release: llm-anthropic 0.26 Includes new features enabled by LLM 0.32: New models: claude-fable-5, claude-sonnet-5, and claude-opus-5. #75, #76 Added server-side tools for WebSearch, WebFetch, CodeExecution, and AnthropicMCP, available through LLM's -T interface or Python…

PipeNetwork/minimax-h3-mlx

Simon Willison · Aug 4, 2026

PipeNetwork/minimax-h3-mlx MiniMax released MiniMax-H3 two days ago - they describe it as a "a general-purpose, omni-modal generative system", which in practice means it accepts text, images, audio and video and can use them to generate up to 15 second video clips with audio…

llm 0.32

Simon Willison · Aug 4, 2026

Release: llm 0.32 See my detailed blog post about this release. Tags: llm

Quoting Steve Yegge

Simon Willison · Aug 4, 2026

Gas Town was intended to be reusable, but I only ever wound up using it to build itself. Gas Town fell apart at the seams with Opus 4.7. Up through 4.6 it was working brilliantly. With 4.7 we saw the introduction of the "just two more things" tic, which prevented Opus from ever…

Don't be a meat proxy

Simon Willison · Aug 3, 2026

Don't be a meat proxy Niklas Gruhn coins an excellent new term - meat proxy - for people who blindly copy and paste the output of AI systems to their peers. By all means, prompt AI. But don't just relay the output. Read it, understand it, validate it, and then write a response…

AI in Linux

Drew DeVault · Jul 23, 2026

The role of AI tools (LLMs, mainly) in Linux is under discussion, or it was, until Linus Torvalds “put his foot down” in support of the use of AI in Linux kernel development.I can identify two major ways in which AI is used for Linux kernel development: authoring code and…

Presigned URLs are technically a security vuln

Xe Iaso · Jul 14, 2026

A presigned URL is a replay attack you did on purpose. Replayable auth tokens are the textbook way to create vulnerable systems, but Tigris ships them as a first-class feature with presigned URLs and so does every other object storage system on the planet. However this isn't an…

You should probably check on your smart appliances

Xe Iaso · Jul 14, 2026

TL;DR: is your refrigerator running malware? If so, you better catch it!