<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[my blog]]></title><description><![CDATA[my blog]]></description><link>https://blog.gathuru.xyz</link><image><url>https://blog.gathuru.xyz/img/substack.png</url><title>my blog</title><link>https://blog.gathuru.xyz</link></image><generator>Substack</generator><lastBuildDate>Thu, 27 Aug 2026 04:59:10 GMT</lastBuildDate><atom:link href="https://blog.gathuru.xyz/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Edward Gathuru]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[gathuru@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[gathuru@substack.com]]></itunes:email><itunes:name><![CDATA[Edward Gathuru]]></itunes:name></itunes:owner><itunes:author><![CDATA[Edward Gathuru]]></itunes:author><googleplay:owner><![CDATA[gathuru@substack.com]]></googleplay:owner><googleplay:email><![CDATA[gathuru@substack.com]]></googleplay:email><googleplay:author><![CDATA[Edward Gathuru]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[[WTL] EO 14409 and NSPM-11]]></title><description><![CDATA[Explaining Trump's recent executive actions to myself]]></description><link>https://blog.gathuru.xyz/p/wtl-eo-14409-and-nspm-11</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/wtl-eo-14409-and-nspm-11</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Fri, 17 Jul 2026 16:32:41 GMT</pubDate><content:encoded><![CDATA[<p><em>Note: This is a &#8220;writing to learn&#8221; exercise. See the following article for details.</em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:206831473,&quot;url&quot;:&quot;https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments&quot;,&quot;publication_id&quot;:9298115,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;my blog&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;On Writing to Learn&quot;,&quot;truncated_body_text&quot;:&quot;Motivation&quot;,&quot;date&quot;:&quot;2026-07-13T13:08:25.710Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:59435000,&quot;name&quot;:&quot;Edward Gathuru&quot;,&quot;handle&quot;:&quot;gathuru&quot;,&quot;previous_name&quot;:&quot;aa&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c260b1b4-edbc-4d11-842b-2b553b325c9b_449x449.jpeg&quot;,&quot;bio&quot;:null,&quot;profile_set_up_at&quot;:&quot;2021-11-30T21:11:05.327Z&quot;,&quot;reader_installed_at&quot;:&quot;2022-03-11T17:36:11.929Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:9536892,&quot;user_id&quot;:59435000,&quot;publication_id&quot;:9298115,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:9298115,&quot;name&quot;:&quot;my blog&quot;,&quot;subdomain&quot;:&quot;gathuru&quot;,&quot;custom_domain&quot;:&quot;blog.gathuru.xyz&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:59435000,&quot;primary_user_id&quot;:59435000,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2026-05-31T01:00:56.749Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Edward Gathuru&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">my blog</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">On Writing to Learn</div></div><div class="embedded-post-body">Motivation&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">a month ago &#183; Edward Gathuru</div></a></div><h2>EO 14409</h2><p>The title &#8220;Promoting Advanced Artificial Intelligence Innovation and Security&#8221; frontloads the &#8220;innovation&#8221; even as it promotes security and the opening paragraphs maintains the same vibe. It refers back to Trump&#8217;s rescinding of Biden&#8217;s EOs on AI and emphasizes the importance of maintaining the private sector&#8217;s global lead. It ends the &#8220;Purpose&#8221; section with a recognition of the national security risks but is focused on cyberattacks against American governments or companies with a particular focus on IP theft rather than dangers posed directly by a misaligned AI.</p><p>Sections 2 and 3 focus respectively on hardening American &#8220;systems&#8221; and granting the Federal government (and the NSA in particular) access to frontier models. I feel like the latter section was the main focus on commentary I&#8217;ve read so far<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. I however will spend more time on the former section here because I struggled to follow it more due to my lack of understanding of the structure of the executive branch.</p><p>The EO closes with calling the AG to pursue cybercrime more vigorously but I won&#8217;t have anything to say about it here.</p><h3>&#8220;Upgrading American Systems for Advanced AI&#8221;</h3><p>This section mandates a number of actors in the executive branch take measures to secure American against AI-enhanced cyberattacks. I&#8217;ll organize the activities by the relevant actors and will add some details on who they are where I got tripped up.</p><ul><li><p>Committee on National Security Systems: This is a cross-agency committee that makes rules on &#8220;National Security Systems&#8221; which appears to be a special subset of the info systems governed by standards like NIST SP 800-53. They are called to &#8220;prioritize&#8221; cyber defense but do they not do that already?</p></li><li><p>Executive Office of the President: This groups offices whose role is to serve the President rather than implement some statue.</p><ul><li><p>Director of the Office of Management and Budget: Finds funds with CISA and NCD. Also somehow helps create clearinghouse. I&#8217;m a bit confused about what roles the OMB is supposed to have outside of creating the budget.</p></li><li><p><span>National Cyber Director: Advises the President on cyber issues. Just about everything called for in this section is meant to be done &#8220;in coordination with&#8221; him.</span></p></li><li><p>Assistant to the President for National Security Affairs: This is apparently just the official name for the National Security Advisor.</p></li><li><p>Assistant to the President for Science and Technology: This is the head of OSTP.</p></li></ul></li><li><p>Department of Treasury: The treasury is to make an &#8220;AI cybersecurity clearinghouse&#8221;. I&#8217;m pretty confused about what this means and why it is done by the DoT. The clearinghouse is called &#8220;Gold Eagle&#8221; and it sounds like a place for &#8220;operators of critical infrastructure&#8221; to share any vulnerabilities they find<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. But then what is AI related about it?</p></li><li><p>Department of War</p><ul><li><p>Director of the National Security Agency: The NSA is responsible for benchmarking models. This is a controversial choice.</p></li></ul></li><li><p>Department of Homeland Security</p><ul><li><p>Director of the Cybersecurity and Infrastructure Security Agency: CISA can release &#8220;Binding Operational Directives&#8221; that order agencies to take cybersecurity measures. I think it&#8217;s interesting that NIST, which is in a different department, is responsible for FIPS which establishes security practices. I guess CISA&#8217;s directives are for emergencies or evolving threats in contrast to NIST&#8217;s slowly made and comprehensive standards? CISA is called to issue a new directive to give agencies access to AI agents and tools but I&#8217;m not sure how a directive can do this. I see they instituted a directive about a week after the EO but it doesn&#8217;t seem related to AI at all<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. They&#8217;re also supposed to find funds somewhere for vulnerability detection.</p></li></ul></li><li><p>Department of Commerce</p><ul><li><p>Director of the National Institute of Standards and Technology: I&#8217;ve become familiar with the fact that NIST publishes SPs from readings that reference various parts of 800 but I didn&#8217;t know it was part of the DoC. I&#8217;m including it in this list but it&#8217;s only mentioned in the next section. What&#8217;s notable not mentioned is CAISI, which is in the NIST, though I&#8217;ll save comments on this for the next section.</p></li></ul></li><li><p>Office of Personnel Management: This sounds like it&#8217;s basically the HR office of the Federal government<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. It&#8217;s mentioned here because of their Tech Force initiative focused on hiring early career techies. They care called to expand this initiative and hire more cybersecurity specialists.</p></li></ul><p>This is my first time trying to read an executive order but I don&#8217;t have a clear vision of what this section calls for by reading it.</p><h3>&#8220;Secure Frontier Model Deployment&#8221;</h3><p>This is the section I&#8217;ve already seen commentary so I&#8217;ll just restate my understanding in my own words. The NSA will create classified benchmarks to identify &#8220;frontier models&#8221;. The government will get access to frontier models 30 days before any release. This is only about public release so hypothetically the labs could keep particularly capable models for internal usage. Giving this task to the NSA further sidelines the CAISI which has more of the benchmarking expertise.</p><h2>NSPM-11</h2><p>I remember hearing about executive orders in civics classes but never national security memorandums. This memo opens with a similar tone to the EO. It says AI is an important industry that shouldn&#8217;t be hampered. Then it jumps to stating the importance of using AI in the military and intelligence.</p><p>The Policy section states that &#8220;all AI technologies adopted&#8221; should be controllable. It also states that the tech should never be used in a way that violates the laws or violates free speech. Both of these are somewhat assuring.</p><p>The memo says the Secretary of War should update DOD Directive 3000.09 (I guess they still use the term &#8220;DOD&#8221; in spite of calling it everywhere else the Department of War for legal reasons) but I&#8217;m curious what the update should be. I hope it wouldn&#8217;t involve weakening the necessity of human oversight. The memo also states that the DoD and DNI should terminate contracts that violate the Policy section of the memo. Reading the plain language of that section, I can&#8217;t see how Anthropic violates it. A prohibition on the government using AI for unlawful purposes doesn&#8217;t require private actors to provide all lawful services. That said, I&#8217;m not sure how to read this without Anthropic in mind given that&#8217;s the major example of the DoD breaking a contract with an AI provider.</p><p>This memo restates the call for the CNSS to update the policy on AI use in national security systems. Does this perform a different function than what the executive order did? I guess the OMB can issue its own memorandums and did in OMB memorandum M-25-21. The memo points to it as inspiration for CNSS&#8217;s policy. What is in that memo and what is the purpose of an OMB memo? Does it have the weight of something like a CISA directive?</p><p>This memo replaces Biden&#8217;s NSM-25. I&#8217;m surprised it was still in effect given the flurry of executive actions Trump carried out early in his presidency.</p><p>The DoD and DNI are to work together to speed up procurement, acquire sufficient compute, and create &#8220;AI data and model exchanges&#8221; which I think means just making it easier to share models and data across agencies. The part that sounds most interesting to me is the IC working with labs to secure data centers against attacks. It says they should support &#8220;joint security research and development (R&amp;D) that the private sector cannot undertake alone&#8221;. My understanding from my skimming of the RAND model weight security report was that SL5 is not only difficult but impossible without government support. If this is a step in the direction of providing that support, this is a big deal. However, I still don&#8217;t understand what exact parts of SL5 need government support. I also don&#8217;t think this obligates the labs themselves to take more measures to secure their models.</p><p>The OPM is called to work with other agencies to create an &#8220;AI National Security Strategic Reserve of non-governmental AI talent&#8221;. This sounds larger in scale than the Tech Force initiative expansion described in the EO but I&#8217;m not sure that&#8217;s right. I do wonder how they plan to hire more people without additional funds. Shouldn&#8217;t the order of operations start with going to Congress to request more headcount? They are also to work with the DNI and DoD to train existing federal employees to use AI.</p><p>Finally, it ends by calling the NSA and DNI to create &#8220;standardized AI national security Test, Evaluation, Verification, and Validation methodologies&#8221;. I wonder what exactly this means. Is it a standard like FIPS but applied to the military and IC?</p><h2>Remaining questions</h2><ul><li><p>How should one read an executive order? What is the legal power of an EO in contrast to informally asking a secretary or director to look into something?</p></li><li><p>What is the status of each of the time bound provisions? We&#8217;re past 30 days but not yet to 60 or 120.</p></li><li><p>How should I read a national security memorandum? What is the purpose and legal weight of a NSPM in contrast to an EO?</p></li><li><p>What elements of SL5 need government support? Does the NSM provide the impetus and means for the federal government to support frontier security research?</p></li><li><p>What is the &#8220;classified annex&#8221; mentioned in the NSPM? I guess it&#8217;s an addition to the NSPM that isn&#8217;t made publicly available?</p></li><li><p>Is a National Security Memorandum (aka NSM-25) the same thing as a National Security Presidential Memorandum (e.g. NSPM-11)? I&#8217;ve been using them interchangeably.</p></li></ul><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I have in mind <a href="https://thezvi.substack.com/p/trump-signs-executive-order-for-ai">this Zvi blog post</a> and <a href="https://www.transformernews.ai/p/trumps-ai-executive-order-was-inevitable">this Transformer article</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>https://www.cyberdefensemagazine.com/inside-gold-eagle-the-white-houses-new-ai-driven-clearinghouse-for-critical-infrastructure/</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>https://en.wikipedia.org/wiki/United_States_federal_civil_service</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[[WTL] RSP Security mitigations: Anthropic]]></title><description><![CDATA[How Anthropic will secure Claude's weights according to the RSP]]></description><link>https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-anthropic</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-anthropic</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Fri, 17 Jul 2026 02:31:38 GMT</pubDate><content:encoded><![CDATA[<p>The latest Responsible Scaling Policy <a href="https://cdn.sanity.io/files/4zrzovbb/website/0bacdc8440ea96e62a8766d99ebe1d4eea6d5f3a.pdf">(Version 3.4; July 8, 2026)</a> defines mitigations for &#8220;Capability Thresholds&#8221;. Since RSP 3.0, mitigations are divided between what Anthropic commits to doing unilaterally and what they believe the industry as a whole should perform. Since May of last year, Anthropic has committed itself to ASL-3. The security mitigations Anthropic commits to involve improving upon ASL-3 but they suggest SL4 is an ideal for some capabilities. I&#8217;ll start with a general description of ASL-3, discuss some of the improvements Anthropic describes in the latest RSP, and touch on some details from their Frontier Safety Roadmap.</p><p><em>Note: This is a &#8220;writing to learn&#8221; exercise. See the following article for details.</em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:206831473,&quot;url&quot;:&quot;https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments&quot;,&quot;publication_id&quot;:9298115,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;my blog&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;On Writing to Learn&quot;,&quot;truncated_body_text&quot;:&quot;Motivation&quot;,&quot;date&quot;:&quot;2026-07-13T13:08:25.710Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:59435000,&quot;name&quot;:&quot;Edward Gathuru&quot;,&quot;handle&quot;:&quot;gathuru&quot;,&quot;previous_name&quot;:&quot;aa&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c260b1b4-edbc-4d11-842b-2b553b325c9b_449x449.jpeg&quot;,&quot;bio&quot;:null,&quot;profile_set_up_at&quot;:&quot;2021-11-30T21:11:05.327Z&quot;,&quot;reader_installed_at&quot;:&quot;2022-03-11T17:36:11.929Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:9536892,&quot;user_id&quot;:59435000,&quot;publication_id&quot;:9298115,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:9298115,&quot;name&quot;:&quot;my blog&quot;,&quot;subdomain&quot;:&quot;gathuru&quot;,&quot;custom_domain&quot;:&quot;blog.gathuru.xyz&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:59435000,&quot;primary_user_id&quot;:59435000,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2026-05-31T01:00:56.749Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Edward Gathuru&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">my blog</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">On Writing to Learn</div></div><div class="embedded-post-body">Motivation&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">a month ago &#183; Edward Gathuru</div></a></div><h2>ASL-3</h2><p>While Anthropic references RAND SL4 as a industry-wide goal it doesn&#8217;t anywhere map their ASL to RAND SL. It mentions ASL-3 is &#8220;suitable against sophisticated non-state attackers&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> but &#8220;[s]ophisticated insiders&#8221; are explicitly out of scope. Therefore it sits somewhere between SL2 and SL3. What follows here is the list of what ASL-3 provides on top of ASL-2 along with a mention of how that maps to the RAND SL benchmarks.</p><ul><li><p>egress bandwidth controls: These are only called for at SL4 in RAND&#8217;s benchmarks.</p></li><li><p>two-party control: This could be either SL2 or SL3.<a href="https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-openai"> I stated a similar statement in OpenAI&#8217;s Framework</a> suggested SL2 because it wasn&#8217;t clear the the interface employees interacted with could prevent employees from stealing the weights. On second thought, it may be enough that developers can&#8217;t download all the weights on some local device. If someone has unilateral read access for a short period after some approval and can&#8217;t feasibly make a copy that should be sufficient.</p></li><li><p>endpoint software control: I think binary allowlisting gets to SL4.</p></li><li><p>change management for secure development: This sounds like SLSA L3 (which OpenAI also appears to achieve though I misunderstood L3 to require multi-party review for all changes).</p></li><li><p>perimeter and access controls: I don&#8217;t have a clear picture in my mind what the boundaries are between SL3 and SL4 when it comes to network or physical controls. The only thing I can see in the SL4 benchmark that isn&#8217;t covered here is the banning of unauthorized devices but I&#8217;m not sure exactly what that would mean. One would have to leave their personal phone away from the office?</p></li><li><p>monitoring: No time-buffered review but they do have comprehensive logging with automated alerts. They also mention honeypots which I don&#8217;t remember seeing in anything I&#8217;ve read from OpenAI or GDM. I think this is at SL3.</p></li></ul><p>Here and in the <a href="https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-openai">OpenAI WTL</a> I&#8217;ve taken the approach of grading individual bullet points in the described security mitigations against the RAND SL benchmarks. I feel it&#8217;s been somewhat helpful as a learning exercise but I&#8217;m unsure how useful it is. I&#8217;m not sure how closely this has brought me to understanding what the deficit is between where Anthropic and OpenAI are and SL4. I also don&#8217;t think I understand why the measures they&#8217;ve instituted are insufficient to guard against sophisticated insiders.</p><p>Like the OpenAI Framework, Anthropic refers to various frameworks. There are two here unfamiliar to me:</p><ul><li><p>CSA STAR Level 2: This is the same CSA of the AI Safety Initiative. Level 1 and 2 are self-assessment and third-party audit respectively. It sounds like it checks similar things as ISO 27001 or SOC 2 but with some cloud specific checks.</p></li><li><p>ISO 42001: This is a new standard for AI systems.</p></li></ul><h2>Improvements</h2><p>Stepping away from the ASL-3 standard and back to the RSP, Anthropic describes some improvements they would make to the ASL-3 in preparation for certain capabilities.</p><ul><li><p>Centralized controls on third-party apps and software updates. I would have assumed this would already be covered by the binary allowlisting in ASL-3.</p></li><li><p>Accounting for internal tools that are less restricted than external products; stronger internal application of the Usage Policy. I assume the lack of internal restrictions is the main thing preventing them from full achieving SL3. I wonder how much applying external controls internally would slow down development?</p></li></ul><p>The new RSP also comes with a new Frontier Safety Roadmap with rich information about what specific security measures the company will experiment with over the next few months.</p><ul><li><p>provable inference: &#8220;[P]rovably &#8216;signing&#8217; AI model outputs in a way that makes them attributable to a specific set of model weights&#8221;. I would love to look more into how this is done cryptographically. This sounds like it would be extremely useful for protecting against weight tampering so I wonder why I haven&#8217;t heard of it before.</p></li><li><p>isolated network prototype: They are trying to gauge how expensive it would be to institute extreme security controls. I&#8217;m confused about the term &#8220;green lines&#8221;. Claude suggests it may refer to the connections an office would have to a fully air-gapped facility containing the actual models weights<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p></li></ul><p>The Roadmap also includes a plan for strengthening the fundamentals. It&#8217;s pretty detailed and it&#8217;s technically not in the RSP so I&#8217;ll save it for a separate article.</p><h2>Competition and decision making</h2><p>Anthropic commits to reaching or exceeding the risk reduction of its competitors. They also commit to burning some of their lead when they are on the verge of a &#8220;highly capable&#8221; model. The general impression I get is that they won&#8217;t lower their standards due to competitors taking risks. This is contrast to GDM where every recommendation is qualified with the statement that they will not follow it if similarly capable models take higher risks. That said, I&#8217;m not sure if GDM&#8217;s approach is that unreasonable and I may be misreading what Anthropic is saying here.</p><h2>Conclusion</h2><p>I suspect Google still beats Anthropic in the volume of externally available information about their security measures but there is still to much here for me to digest in one post. One reflection I have is that I should probably do a WTL on the RAND benchmarks or at least the threat models in the report. I don&#8217;t have a good intuition on how a given security mitigation matches up against the threats described in the report.</p><h2>Remaining questions</h2><ul><li><p>What&#8217;s in the Frontier Compliance Framework? My impression is that it&#8217;s a stripped down version of the RSP that is more suitable to share with regulators. I should probably compare these compliance docs with the RSPs for each company for which I can find both.</p></li><li><p>What are the powers of the Board of Directors and the Long-Term Benefit Trust? What is the nature of the Responsible Scaling Officer role? I should look more into the governance structure of each lab in addition to the content of the RSPs.</p></li></ul><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>https://www.anthropic.com/news/activating-asl3-protections</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>https://claude.ai/share/7879b4c5-50df-4a47-ab96-0da2cc1d4903</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[[WTL] RSP Security mitigations: OpenAI]]></title><description><![CDATA[How Open will secure model weights according to their Preparedness Framework]]></description><link>https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-openai</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-openai</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Thu, 16 Jul 2026 03:20:02 GMT</pubDate><content:encoded><![CDATA[<p>The latest Preparedness Framework <a href="https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf">(Version 2; April 15, 2025)</a> rates capabilities as either High or Critical. Models with Critical capabilities are simply not deployed or even developed so security controls are only defined for High. The only section of the Framework of interest is therefore C.3 Security controls.</p><p><em>Note: This is a &#8220;writing to learn&#8221; exercise. See the following article for details.</em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:206831473,&quot;url&quot;:&quot;https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments&quot;,&quot;publication_id&quot;:9298115,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;my blog&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;On Writing to Learn&quot;,&quot;truncated_body_text&quot;:&quot;Motivation&quot;,&quot;date&quot;:&quot;2026-07-13T13:08:25.710Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:59435000,&quot;name&quot;:&quot;Edward Gathuru&quot;,&quot;handle&quot;:&quot;gathuru&quot;,&quot;previous_name&quot;:&quot;aa&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c260b1b4-edbc-4d11-842b-2b553b325c9b_449x449.jpeg&quot;,&quot;bio&quot;:null,&quot;profile_set_up_at&quot;:&quot;2021-11-30T21:11:05.327Z&quot;,&quot;reader_installed_at&quot;:&quot;2022-03-11T17:36:11.929Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:9536892,&quot;user_id&quot;:59435000,&quot;publication_id&quot;:9298115,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:9298115,&quot;name&quot;:&quot;my blog&quot;,&quot;subdomain&quot;:&quot;gathuru&quot;,&quot;custom_domain&quot;:&quot;blog.gathuru.xyz&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:59435000,&quot;primary_user_id&quot;:59435000,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2026-05-31T01:00:56.749Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Edward Gathuru&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">my blog</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">On Writing to Learn</div></div><div class="embedded-post-body">Motivation&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">a month ago &#183; Edward Gathuru</div></a></div><h2>Benchmark comparison</h2><p>Unlike GDM&#8217;s FSF or Anthropic&#8217;s RSP, OpenAI makes no explicit mention of RAND SL. It does however mention a number of specific practices than can be compared against parts of the RAND SL benchmarks.</p><ul><li><p>Defense in Depth</p><ul><li><p>Layered Security Architecture: This sounds enough like the &#8220;[t]wo independent security layers&#8221; in the SL3 benchmark that I&#8217;ll rate it at that level.</p></li><li><p>Zero Trust Principles: This sounds enough like what the SL3 benchmark describes. The SL3 benchmark specifically calls out the &#8220;Advanced&#8221; level of &#8220;CISA&#8217;s Zero Trust Maturity Model&#8221; but that sounds like to much for me to try to dive into now.</p></li></ul></li><li><p>Access Management</p><ul><li><p>Principle of Least Privilege: access to High models is limited, protected with MFA, and &#8220;may require additional approvals&#8221; but it doesn&#8217;t sound like all access to weights takes place through a tool and therefore I rate this SL2.</p></li></ul></li><li><p>Secure Development and Supply Chain</p><ul><li><p>Change Management: Only changes to critical infrastructure seem to mandate multi-party review so this is below SLSA 3 and therefore below SL4. I can&#8217;t see any reason to rank below SL3.</p></li></ul></li><li><p>Operational Security</p><ul><li><p>Monitoring and Incident Response: Logs are not just collected but continuously monitored which I believe pushes them to SL3. There&#8217;s no mention of hardware level protection of the logs or forced time delays for code reviews so I won&#8217;t rate this at SL4.</p></li><li><p>Adversarial Testing and Red-Teaming: OpenAI does them. And they have a bug bounty program. But it&#8217;s unclear if their red-teaming would be &#8220;advanced&#8221; according to the RAND benchmarks so I&#8217;ll rate them SL2 here.</p></li></ul></li></ul><p>The Framework doesn&#8217;t touch upon physical, hardware, or personnel security. I imagine this is because OpenAI gets its compute externally. The overall picture seems to be between SL2 and SL3. The best term for it may be the SL2+ coined in GDM&#8217;s FSF. What&#8217;s different from GDM is that this is the highest security commitment the Preparedness Framework makes. In contrast, GDM would recommend reaching SL3 when it reaches &#8220;ML R&amp;D acceleration level 1&#8221; which I think is comparable to &#8220;AI Self-improvement High&#8221;.</p><p>The Preparedness Framework also doesn&#8217;t even do the move Anthropic&#8217;s RSP or GDM&#8217;s FSF do in mentioning SL4 or higher commitments as ideal industry goals while not committing to undertake them unilaterally.</p><h2>Mentioned frameworks</h2><p>In addition to the list of practices, the Framework lists a number of security frameworks in passing, most of which I&#8217;m unfamiliar with. Familiarity with these frameworks doesn&#8217;t seem necessary for analyzing OpenAI&#8217;s Framework but I&#8217;m taking this opportunity to learn about them. Here I&#8217;ll give a short description of each.</p><ul><li><p><strong>SOC 2</strong>: &#8220;System and organization controls&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. This is a framework for a type of audit a CPA can perform. It scores a organization on up to five metrics they call &#8220;Trust Service Criteria&#8221; which are just the traditional CIA triad plus security and privacy. Confusing, SOC originally referred to &#8220;service organization controls&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> but AICPA changed it while trying to keep the same acronym; apparently, they did this so they could score organizations that don&#8217;t actual perform any services for anyone<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>. A SOC doesn&#8217;t score your org with a level like FedRAMP. Instead, it just describes what your org&#8217;s security measures are and reports on if there are major issues with them and if you are actually applying them<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. The description on the AICPA website stresses that it isn&#8217;t a &#8220;certification&#8221;. It comes in Type 1 or 2 depending on if the report was snapshot or over a 3-12 month window. Apparently there are SOC 1 and SOC 3 and rather than being different versions of SOC they serve different audiences. That said, I&#8217;ve only seen SOC 2 referenced, typically in comparison with ISO 27001.</p></li><li><p><strong>ISO 27001</strong>: International Organization for Standardization<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> standard 27001. This definitely is a certification. It applies to ISMS (Information Security Management System) which seems to be a special term for anything that handles sensitive data. Aside from that the only obvious difference seems to be that SOC 2 is demanded more in the US whereas ISO 27001 is demanded more in Europe, though both are required to varying degrees on both sides of the Atlantic<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>. Where SOC 2 seems to be along the lines of &#8220;do you meet the standards needed for your purposes&#8221;, ISO 27001 scores a company on some objective rubric<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a>. ISO 27001 uses the CIA triad with authenticity and non-repudiation added in.</p></li><li><p><strong>NIST SP 800-53</strong>: NIST &#8220;Special Publication&#8221; 800-53. NIST is the standard making body in the Department of Commerce. Claude says that &#8220;&#8216;Special Publication&#8217; is just a catch-all series for documents that aren't journal articles, Technical Notes, Monographs, or Handbooks&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>. NIST SP 800 groups together all the computer security recommendations and NIST SP 800-53 in particular gives guidance for security and privacy in &#8220;information systems&#8221; which seems to mean the same thing as ISMS. Unlike SOC 2 or ISO 27001, you can&#8217;t get a report or certification on NIST SP 800-53 compliance as a private organization. It is however mandated<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a> that federal &#8220;information systems&#8221; comply with various parts of it based on how dangerous it is for info to leak from those systems<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a>.</p></li><li><p><strong>FedRAMP</strong>: This applies NIST SP 800-53 to cloud providers. The Wikipedia page says FedRAMP is described as &#8220;FISMA for the cloud&#8221; but backs that up with a reference to a dead link<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-11" href="#footnote-11" target="_self">11</a>. I was a bit confused as to why FedRAMP was needed when FISMA already requires agencies to follow various parts of NIST SP 800-53 even when using vendors. Claude suggested two reasons that made sense to me<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-12" href="#footnote-12" target="_self">12</a>: First, the problem of &#8220;N&#215;M assessments&#8221; as Claude called it. Each cloud-agency pairing would need to do its own assessment. After FedRAMP, a cloud provider can be certified once and every agency at a matching impact level can use it. Second, FedRAMP accredits third parties to perform the assessment.</p></li><li><p>&#8220;AI-specific security standards&#8221;</p><ul><li><p><strong>Cloud Security Alliance&#8217;s AI Safety Initiative</strong>: The Cloud Security Alliance is a non-profit. It has a <a href="https://cloudsecurityalliance.org/ai-safety-initiative">AI Safety Initiative</a> and has produced a bunch of whitepapers. The &#8220;Executive Leadership Council&#8221; of the initiative has the CISOs of Google DeepMind, Google Cloud, and Anthropic as well as well as high level reps from AWS, OpenAI, and Microsoft and from CISA in the DHS. That said, I&#8217;m not sure what the importance of this initiative is. It isn&#8217;t a law or a widely used framework or standard. I don&#8217;t think I&#8217;ve seen it referenced elsewhere. I will keep my eyes out for references to it from now on.</p></li><li><p><strong>NIST SP 800-218 AI updates</strong>: This seems to refer to NIST SP 800-218A. NIST SP 800-218 is about safe software development processes. <a href="https://safeguard.sh/resources/blog/nist-sp-800-218a-ai-development-adoption-2026">According to this summary</a>, 800-218A extends these safety practices to the data models are trained and fine tuned and suggests adding AI model hacks to the threat model.</p></li></ul></li></ul><h2>Remaining questions</h2><p>Where does OpenAI get its compute from? Do they own their own data centers or do they entirely rely upon cloud providers? Are its providers FedRAMP compliant? What would it look like for a company that doesn&#8217;t have its own in-house cloud as Google does to do a push to SL4 or SL5? Can I hope get a picture of what OpenAI&#8217;s security practices look like at a similar fidelity as what I could get for Google or Microsoft?</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>https://en.wikipedia.org/wiki/System_and_organization_controls</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>See https://www.aicpa-cima.com/resources/article/aicpa-system-and-organization-controls-communications-guidelines. The website obnoxiously requires you to create an account to read the content.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>See my chat https://claude.ai/share/4bedd195-eeae-4125-956f-f5f36b850cb2.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>At least, that&#8217;s the impression I get from the top comment in this Reddit thread: https://old.reddit.com/r/cybersecurity/comments/1u87jot/what_is_a_soc_2_report_and_why_does_every/.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>I find it a bit confusing that the ISO acronym matches neither its name in English nor its name in French.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>This is the impression I get reading the comments highlighted when I search for &#8220;ISO&#8221; in the same Reddit thread from above: https://old.reddit.com/r/cybersecurity/comments/1u87jot/what_is_a_soc_2_report_and_why_does_every/.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>https://prescientsecurity.com/resources/blogs/iso-27001-vs-soc-2</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>https://claude.ai/share/f8a5deb3-2631-408f-bcb3-403dbace5d13</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-9" href="#footnote-anchor-9" class="footnote-number" contenteditable="false" target="_self">9</a><div class="footnote-content"><p>By FISMA. In response to FISMA, NIST created FIPS 200 which states: &#8220;Federal agencies must meet the minimum security requirements as defined herein through the use of the security controls in accordance with NIST Special Publication 800-53&#8220; https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-10" href="#footnote-anchor-10" class="footnote-number" contenteditable="false" target="_self">10</a><div class="footnote-content"><p>Federal offices are rated as &#8220;Low&#8221;, &#8220;Moderate&#8221;, or &#8220;High&#8221; for each element of the CIA triad using the process described in FIPS 199: https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-11" href="#footnote-anchor-11" class="footnote-number" contenteditable="false" target="_self">11</a><div class="footnote-content"><p>https://en.wikipedia.org/wiki/FedRAMP</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-12" href="#footnote-anchor-12" class="footnote-number" contenteditable="false" target="_self">12</a><div class="footnote-content"><p>https://claude.ai/share/f8a5deb3-2631-408f-bcb3-403dbace5d13</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[[WTL] RSP Security mitigations: GDM]]></title><description><![CDATA[How GDM will secure model weights according to their FSF]]></description><link>https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-gdm</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/wtl-rsp-security-mitigations-gdm</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Tue, 14 Jul 2026 02:06:33 GMT</pubDate><content:encoded><![CDATA[<p>In this post I&#8217;ll go through Google DeepMind&#8217;s Frontier Safety Framework and describe how they intend to secure their model weights. Any commitments that exist outside the FSF are out of scope. I will only restate or paraphrase the commitments in their own language. I&#8217;ll leave further analysis for later.</p><p><em>Note: This is a &#8220;writing to learn&#8221; exercise. See the following article for details.</em></p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:206831473,&quot;url&quot;:&quot;https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments&quot;,&quot;publication_id&quot;:9298115,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;my blog&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;On Writing to Learn&quot;,&quot;truncated_body_text&quot;:&quot;Motivation&quot;,&quot;date&quot;:&quot;2026-07-13T13:08:25.710Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:59435000,&quot;name&quot;:&quot;Edward Gathuru&quot;,&quot;handle&quot;:&quot;gathuru&quot;,&quot;previous_name&quot;:&quot;aa&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c260b1b4-edbc-4d11-842b-2b553b325c9b_449x449.jpeg&quot;,&quot;bio&quot;:null,&quot;profile_set_up_at&quot;:&quot;2021-11-30T21:11:05.327Z&quot;,&quot;reader_installed_at&quot;:&quot;2022-03-11T17:36:11.929Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:9536892,&quot;user_id&quot;:59435000,&quot;publication_id&quot;:9298115,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:9298115,&quot;name&quot;:&quot;my blog&quot;,&quot;subdomain&quot;:&quot;gathuru&quot;,&quot;custom_domain&quot;:&quot;blog.gathuru.xyz&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:59435000,&quot;primary_user_id&quot;:59435000,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2026-05-31T01:00:56.749Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Edward Gathuru&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:false,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">my blog</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">On Writing to Learn</div></div><div class="embedded-post-body">Motivation&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">a month ago &#183; Edward Gathuru</div></a></div><p>Unlike Anthropic and OpenAI, GDM is part of a larger company that is itself a cloud provider. Google has already described its security practices at length elsewhere and the FSF refers to it. The FSF also refers to the <a href="https://safety.google/intl/en-GB_in/safety/saif/">Secure AI Framework</a> which goes into the specific details of how Google plans to secure &#8220;AI systems&#8221;, which includes the model weights. To avoid biting off more than I can chew, I&#8217;ll save any review of these resources for another day. However, I expect much of what I find under-explained here is fleshed out in other documents so I&#8217;ll make a point to revisit them in later posts.</p><p>The latest FSF <a href="https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/strengthening-our-frontier-safety-framework/frontier-safety-framework_3-1.pdf">(Version 3.1; April 17, 2026)</a> groups mitigations &#8220;against exfiltration or unauthorized modification&#8221; of model weights under &#8220;security mitigations&#8221;. For each &#8220;capability level&#8221; the FSF describes a recommended &#8220;security level&#8221; based on those described in RAND&#8217;s <a href="https://www.rand.org/pubs/research_reports/RRA2849-1.html">"Securing AI Model Weights" report</a>. These levels mean different things here than in the RAND report. The RAND report has a detailed benchmarks for each level. The FSF states it uses the &#8220;goals&#8221; of the report rather than its benchmarks. In other words SL<em>N</em> only means &#8220;can defend weights against an OC<em>N</em> attacker&#8221;. I hope to learn more about how these details differ from the RAND report from SAIF and other Google whitepapers but I consider that out of scope for this post.</p><p>The recommended security levels for different &#8220;critical&#8221; capabilities are organized below.</p><ul><li><p><strong>SL2+</strong>: CBRN uplift level 1, Cyber uplift level 1, Harmful manipulation level 1.</p></li><li><p><strong>SL3</strong>: ML R&amp;D acceleration level 1</p></li><li><p><strong>SL4</strong>: ML R&amp;D automation level 1</p></li></ul><p>SL2+ is a new level defined as RAND SL2 but with additional measures for OC3 attackers (&#8220;insider threats and well-resourced non-state external actors&#8221;). It is mentioned in a footnote that SL3 includes &#8220;additional mitigations designed to prevent unilateral access, harden infrastructure, and prevent data exfiltration&#8221; that aren&#8217;t in SL2+ which hints that SL2+ is SL3 without those mitigations. SL4 adds to both of these &#8220;additional mitigations aimed to isolate model weights, enhanced data center security, further hardening of infrastructure and minimizing potential attack surface&#8221;. I assume &#8220;enhanced data center security&#8221; applies to physical security and personnel. The &#8220;hardening of infrastructure and minimizing potential attack surface&#8221; is very vague and I don&#8217;t hold out much hope the SAIF docs fill in the details here.</p><p>The applier of the Framework (and I&#8217;m unsure who in GDM is responsible for performing this assessment) may still recommend that a given version of Gemini is safe to release if one of the following hold:</p><ul><li><p><strong>&#8220;[I]f [Google security infrastructure] match[es] or exceed[s] the level of security applied to other models with similar capabilities or risk profiles&#8221;</strong>. This seems reasonable given they are assessing the &#8220;residual risk&#8221;. If a similarly capable model is already deployed by another lab but is less secure then overall risk can&#8217;t be said to be increased by release by GDM. I am curious how they assess other labs though. It&#8217;s easy to get third-party info about model capabilities but it seems more difficult to determine what &#8220;level of security [is] applied to other models&#8221;.</p></li><li><p>If <strong>&#8220;we assess that the benefits of the open release of model weights outweigh the risks&#8221;</strong>. This seems to just be describing open source models like Gemma.</p></li><li><p>Or <strong>&#8220;based on mitigations already in place&#8221;</strong>. This is the part that causes me the most confusion. I suppose this describes a case in which they revise downwards the recommended security level for a given capability but only after having achieved that capability.</p></li></ul><p>Some things I almost missed <a href="https://claude.ai/share/7446a82e-c8d8-466a-9468-31921bce5770">until Claude pointed them out to me</a>:</p><ul><li><p>Section 3.1.1 explicitly calls out the risk of model self-exfiltration rather than being focused exclusively on nation state attackers. That isn&#8217;t very relevant for this essay but it&#8217;s something I plan to lookout for in other RSPs.</p></li><li><p>The RAND SL levels are applied only to critical capabilities but &#8220;tracked&#8221; capabilities may also cause reviewers to recommend against deployment or development. I originally read the distinction between &#8220;critical&#8221; and &#8220;tracked&#8221; capabilities as similar to OpenAI&#8217;s &#8220;tracked&#8221; and &#8220;research&#8221; capabilities i.e. GDM&#8217;s &#8220;tracked&#8221; (confusingly) maps onto OpenAI&#8217;s &#8220;research&#8221; capabilities and are reported but aren&#8217;t used to gate releases.</p></li><li><p>The FSF is pretty explicit about running capability assessments during development rather than just before deployment. These &#8220;early warning evaluations&#8221; are somewhat of a surprise to me since I assumed GDM leaned on the expectation that capability growth will be smooth enough these wouldn&#8217;t be necessary. At least, that&#8217;s the vibe I got from <a href="https://axrp.net/episode/2025/07/06/episode-45-samuel-albanie-deepminds-agi-safety-approach.html">Samuel Albanie&#8217;s appearance on AXRP Podcast</a> and <a href="https://80000hours.org/podcast/episodes/rohin-shah-google-deepmind-agi-safety/">Rohin Shah&#8217;s appearance on the 80,000 Podcast</a>.</p></li></ul><h2>Remaining questions</h2><ul><li><p>All of the capabilities only describe a level 1. I assume they will define additional levels in their RSP as they approach or exceed level 1. Am I correct in that assumption? In that case one could imagine SL3 being required to deploy a model that provides &#8220;CBRN uplift level 2&#8221;.</p></li><li><p>What RAND SL are Gemini external deployments at? The FSF suggests that SL2+ may be below existing Google security practice but doesn&#8217;t state it outright.</p></li><li><p>What RAND SL can GDM feasibly reach in a short timeline?</p></li></ul>]]></content:encoded></item><item><title><![CDATA[On Writing to Learn]]></title><description><![CDATA[Motivation and Commitments]]></description><link>https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/writing-to-learn-motivation-and-commitments</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Mon, 13 Jul 2026 13:08:25 GMT</pubDate><content:encoded><![CDATA[<h2>Motivation</h2><p>Last week I took the <a href="https://bluedot.org/courses/technical-ai-safety">BlueDot Impact Technical AI Safety</a> intensive. One of the things I most enjoyed about the course was the writings. Describing AI safety techniques or failure modes in my own language helped me learn faster and more durably than reading alone. <a href="https://blog.bluedot.org/p/writing-intensive">This post in the BlueDot Impact blog</a> announcing their writing intensive explains why better than I can here.</p><p>I&#8217;d like to make a habit of publishing my &#8220;writing to learn&#8221; (WTL hereafter) as posts here on Substack for multiple reasons:</p><ul><li><p>I want to get into the habit of writing more generally. WTL posts make it more feasible for me to make commitments like &#8220;write at least one publicly accessible writing per week&#8221;.</p></li><li><p>A WTL post can become the basis of more analytical work. For example, I may write short posts describing model weight security commitments in Responsible Scaling Policies for each lab then write a post comparing the commitments for concreteness and strength. These analytic posts can link back to WTL posts and reduce the amount of context I need to restate in a given article.</p></li><li><p>I want to &#8220;show my work&#8221; in my AI safety job applications. By this I mean I want to be able to point to writing I&#8217;ve done ruminating on some subset of AI safety or governance literature rather than simply stating that I&#8217;ve been, for example, working through a particular reading list.</p></li><li><p>A WTL may genuinely worth sharing if there are no other accessible explanations online or on Substack. Even if they are accessible elsewhere my rephrasing of an explanation may help someone searching for more info online.</p></li><li><p>I can share a WTL post in a public forum and get feedback from more knowledgable people.</p></li></ul><h2>Commitments</h2><p>However, a couple of things make me hesitate. First, because I have quite a lot to learn, most of these WTL posts will be basic to anyone with minimal interest in AI safety, policy, computer science, or any of the other topics I plan to write about on this blog. Second, if I&#8217;m fortunate enough to gain a genuine following here I don&#8217;t want to spam them with short low-quality posts as these WTL posts will inevitably be.</p><p>The second concern can be addressed in a straightforward manner. I will clearly indicate in a post title that a post is WTL and I will not re-stack my WTL posts or send them for Substack app or email delivery. The first concern will only be addressed with time as I calibrate my sense of what&#8217;s worth sharing and what should stay in my personal notes. However, I&#8217;ll try to share my notes as a WTL post only when I genuinely feel unsatisfied with other explanations I&#8217;ve encountered or my own understanding of those explanations (since restating things in my own words may allow others to correct me).</p><p>I will use generative AI extensively while learning about an issue or iterating on my explanations but I will always write my WTL posts myself (to do otherwise would defeat the purpose). It will always be described in the language I would use if describing the issue to an earlier version of myself and will be structured in the order I would present the issue. I will cite sharable chat histories in my WTL posts as I will any other source.</p><p>I will update this post if I feel it important to add additional commitments or update or remove older ones. I also may add a section to this post on process and style after I&#8217;ve written enough WTL posts.</p>]]></content:encoded></item><item><title><![CDATA[2025 Reading Reflection]]></title><description><![CDATA[This will be my last upload on my old blog while I&#8217;m migrating everything to Substack.]]></description><link>https://blog.gathuru.xyz/p/2025-reading-reflection</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/2025-reading-reflection</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Fri, 05 Jun 2026 03:37:08 GMT</pubDate><content:encoded><![CDATA[<p>This will be my last upload on my old blog while I&#8217;m migrating everything to Substack. I&#8217;m happy I&#8217;ve taken time to reflect on my reads these past few years. It serves as a good reminder of what I&#8217;ve read in the past. However, I&#8217;ve been doing my writing too late for them to serve as useful reminders of my initial reactions to the content. I don&#8217;t think I read enough to increase the cadence so I just need to make a point of getting in my reviews fresh after reading.</p><h1>Books I read this year:</h1><ul><li><p><strong>James</strong> by Percival Everett: Most of the story is pretty sad but the ending is satisfying.</p></li><li><p><strong>The message</strong> by Ta-Nehisi Coates: I don&#8217;t remember this book being particularly bad but I don&#8217;t think I got much out of it.</p></li><li><p><strong>Anna Karenina</strong> by Leo Tolstoy: A good read. I&#8217;ve unfortunately sat down to write these notes too late to remember my feelings in detail. I felt ambivalent about most characters. I also felt there were some pretty boring sections.</p></li><li><p><strong>The autobiography of Malcolm X</strong> by Malcolm X and Alex Haley: The story got pretty boring after he gets out of prison. I figure he had to be more sensative about how he described his actions and relationships from that point onwards but less of his personality shines through. Overall a good read though.</p></li><li><p><strong>The Mind-Body problem and Metaphysics</strong> by Ralph Stefan Weir: This is one I&#8217;ll have to return to and read more carefully. In addition to becoming more interested in religion again, I&#8217;m also more interested in the philosophy of consciousness. I found the argument convincing but dense.</p></li><li><p><strong>Queenie</strong> by Candice Carty-Williams: I find the book entertaining though I guess I didn&#8217;t find the main character very compelling.</p></li><li><p><strong>That all shall be saved</strong> by David Bently Hart: I agreed with the conclusion but I find the author&#8217;s writing pretty hard to read. I felt at some point I was basically just skimming. I&#8217;ll need to revisit this.</p></li><li><p><strong>Mere Christianity</strong> by C.S. Lewis: This is my second time reading it. Enjoyable but I found it less compelling this time around.</p></li><li><p><strong>The Heaven &amp; Earth Grocery Store</strong> by James McBride: The writing style is a pleasure to read and the way the author describes the Jewish community of the opening character is very vivid. It makes me interested to know more about Jewish American culture.</p></li><li><p><strong>A Grief Observed</strong> by C.S. Lewis: An interesting short read. I&#8217;d love to revisit it sometime soon.</p></li><li><p><strong>The poppy war</strong> by R.F. Kuang: The battle scenes weren&#8217;t particularly good. The way it transitions from their education to the war is pretty abrupt. I also can&#8217;t see how people would be skeptical of magic when it&#8217;s so important to the war. There are also so many characters and they&#8217;re pretty poorly characterized.</p></li><li><p><strong>Screwtape letters</strong> by C.S. Lewis: The format was pretty interesting but it was starting to get pretty stale by the end. In <em>Screwtape Proposes a Toast</em> he&#8217;s mostly complaining about politics and just sounds grumpy.</p></li><li><p><strong>15 dogs</strong> by Andr&#233; Alexis: An amazing read. The ending was pretty sad though. I think it tried to end on a half-optimistic note but if so, it doesn&#8217;t succeed.</p></li><li><p><strong>All the sinners bleed</strong> by S.A. Cosby: A nice detective story. Good writing and interesting characters. I may check out the authors other books next.</p></li><li><p><strong>Christianity: The first 3000 years</strong> by Diarmaid MacCulloch: This was a great read. It&#8217;s long though. I put over 80 hours either reading or taking notes. It was great for me to study deeply. Jumping straight into theology is often so difficult. Having the historical context makes things more comprehensible.</p></li><li><p><strong>Modern Poetry</strong> by Diane Seuss: I&#8217;m not generally a fan of poetry and this unfortunately wasn&#8217;t an exception. I struggled with this one even though there was a poem here and there I really enjoyed.</p></li><li><p><strong>Vatican II: A short introduction</strong> by Shaun Blanchard and Stephen Bullivant: A nice short intro. I&#8217;ve heard many of the documents that came out of the council referenced before but Wikipedia wasn&#8217;t very useful for picking up the context behind them.</p></li><li><p><strong>The Catechism of the Catholic Church</strong>: This was a long read but it was worth it. It actually tends to repetitiveness I think but it&#8217;s a good reference resource.</p></li><li><p><strong>Why Not Socialism</strong> by G. A. Cohen: Easy to digest if not convincing.</p></li><li><p><strong>Giovanni&#8217;s room</strong> by James Baldwin: Really good and very sad. It does a great job of giving you a sense of impending doom.</p></li><li><p><strong>Dream Count</strong> by Chimamanda Ngozi Adichie: I found the stories of the women very compelling. The authors charicatures of leftist students was obnoxious.</p></li><li><p><strong>A Psalm for the Wild-Built</strong> and <strong>A Prayer for the Crown-Shy</strong> by Becky Chambers: Very corny. Would not recommend.</p></li><li><p><strong>Hotel du Lac</strong> by Anita Brookner: A bit slow at the start but once it settled in I found it very engaging.</p></li><li><p><strong>The Vegetarian</strong> by Han Kang: My second time reading it. I still don&#8217;t know quite what to make of it.</p></li><li><p><strong>Animal Liberation</strong> by Peter Singer: Very compelling read. I&#8217;ve gone vegetarian this year so I was already on board with his argument. I was surprised how bad and useless animal testing is. The chapter on the history of animal rights is really interesting.</p></li><li><p><strong>Washington Black</strong> by Esi Edugyan: Good but a bit boring in some parts near the middle. I found the ending very unsatisfying.</p></li><li><p><strong>Provoked</strong> and <strong>Enough Already</strong> by Scott Horton: Very, very detailed books.</p></li><li><p><strong>The Other End of the Leash</strong> by Patricia B. McConnell, <strong>Decoding Your Dog</strong> by the American College of Veterinary Behaviorists, <strong>Perfect Puppy in 7 Days</strong> by Dr. Sophia Yin, <strong>The Culture Clash</strong> by Jean Donaldson: I&#8217;m summarizing these all together because I read them back to back and sometimes at the ame time so the content blended together for me. I found some of the content elucidating but not as much as directly working with dogs. I want to revisit these later.</p></li><li><p><strong>The Scammer</strong> by Tiffany D. Jackson: I found the ending pretty unsatisfying. I wanted to know what happened to the other students. The twist at the end was pretty interesting though.</p></li><li><p><strong>The Stupidity of War</strong> by John Mueller: Very compelling.</p></li><li><p><strong>The Tainted Cup</strong> and <strong>A Drop of Corruption</strong> by Robert Jackson Bennett: Solid fantasy.</p></li><li><p><strong>Churchill, Hitler, and &#8220;The Unnecessary War&#8221;</strong> by Patrick J. Buchanan: This is my first book on WW2. I found it interesting though not particulary convincing. He only has a few pages near the end on the Holocaust. At most it shows Churchill seriously blundered at various points but there was certainly a point at which entering the war against Hitler was better than surrender.</p></li><li><p><strong>Human Smoke</strong> by Nicholson Baker: I&#8217;m semi-convinced that FDR wanted war with Japan though in hind sight that was clearly the right move.</p></li><li><p><strong>A Game of Thrones</strong> and <strong>A Clash of Kings</strong> by George R.R. Martin: I loved this whole series but the second is definitely my favorite. It saddens me that we won&#8217;t ever see and ending for the series.</p></li></ul><h1>Movies I watched this year:</h1><p>I&#8217;m throwing this into reading reflection. I&#8217;m not sure if I should make this a more general media reflection. This year I will skip reviewing manga. I wish I had written reviews for the Broadway shows I watched back when I still lived in NYC. Like with the later half of the readings for this year I&#8217;m writing reviews long after watching so I&#8217;m only going to bother with a general summary of my reaction. While the books are ordered on when I read them this will be ordered by best to worst.</p><ul><li><p><strong>The Secret Agent</strong>: My favorite movie of the year. Both funny and engaging and sad.</p></li><li><p><strong>Brokeback Mountain</strong>: Very good and sad.</p></li><li><p><strong>Sentimental Value</strong>: I enjoyed.</p></li><li><p><strong>Eddington</strong>: Funny though I don&#8217;t know what to make of the ending. I was surprised to see how negative the reviews were.</p></li><li><p><strong>Highest 2 Lowest</strong>: Pretty good.</p></li><li><p><strong>No Other Choice</strong>: Nice.</p></li><li><p><strong>Together</strong>: Body horror. Nice.</p></li><li><p><strong>Superman</strong>: Nice and feel-good.</p></li><li><p><strong>The Phoenician Scheme</strong>: I hate to out myself as so uncultured by I think this was my first Wes Anderson. I liked it visually but I struggled go follow what was going on.</p></li><li><p><strong>Rental Family</strong>: Interesting setup. I enjoyed.</p></li><li><p><strong>28 Years Later</strong>: I never watched the original. I liked it. Not as scary as I worried it would be.</p></li><li><p><strong>Hamnet</strong>: Not bad but I didn&#8217;t particularly enjoy it.</p></li><li><p><strong>Wicked: For Good</strong>: Not as good as the first half but I felt the same way about the second half of the Broadway show.</p></li><li><p><strong>Bugonia</strong>: Okay but I didn&#8217;t like the ending.</p></li><li><p><strong>Jurassic World Rebirth</strong>: Okay.</p></li><li><p><strong>Avatar Fire and Ash</strong>: Mediocre but I wasn&#8217;t expecting much going in.</p></li></ul><h1>Looking forward to next year:</h1><p>I had originally hoped to read more Eastern history but I&#8217;m going to have to spend a lot more time reading about AI. In fact, I&#8217;m going to spend a lot less time reading for simple pleasure which saddens me.</p>]]></content:encoded></item><item><title><![CDATA[2024 Reading Reflection]]></title><description><![CDATA[Books I read this year:]]></description><link>https://blog.gathuru.xyz/p/2024-reading-reflection</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/2024-reading-reflection</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Mon, 24 Mar 2025 01:48:00 GMT</pubDate><content:encoded><![CDATA[<h1>Books I read this year:</h1><ul><li><p><strong>Anthem</strong> by Ayn Rand: Sort of boring.</p></li><li><p><strong>Anabolics</strong> by William Llewellyn: Helpful info about steroids.</p></li><li><p><strong>The Strange Case of Dr. Jekyll and Mr. Hyde</strong> by Robert Louis Stevenson:</p></li><li><p><strong>Go Tell It on the Mountain</strong> by James Baldwin: Nice book but not an easy read from what I remember.</p></li><li><p><strong>This Is How You Lose the Time War</strong> by Amal El-Mohtar and Max Gladstone: Bad book. I don&#8217;t get why I&#8217;m supposed to like the main characters.</p></li><li><p><strong>A Scanner Darkly</strong> by Philip K. Dick: Awful, annoying read. Worst thing I&#8217;ve read in a long while. The characters are all extremely annoying.</p></li><li><p><strong>L&#8217;&#201;cole des Sorciers</strong> by J.K. Rowling: It re-read the first Harry Potter book in French. It was a challenge but was as engaging as when I&#8217;d first read it in English.</p></li><li><p><strong>Short Fiction</strong> by H. P. Lovecraft: I got into the habit of reading these before bed. Few of them are particularly scary but most are decent reads. I managed to get through everything of his that I could find online save a few of his longer stories (the Curious Case and the Dream Quest come to mind).</p></li><li><p><strong>Klara and the Sun</strong> by Kazuo Ishiguro: Not a bad book but the way Klara was treated was just not realistic. People become so attached to dogs and even inanimate objects but a speaking AI who grows up with a child is abandoned? Also, throwing in some confusing world building at the end was an annoying choice.</p></li><li><p><strong>She Who Became the Sun</strong> and <strong>He Who Drowned the World</strong> by Shelley Parker-Chan: Okay books. Character behave in strange and hurtful ways (especially in the second book) but the prose is tolerable. I have issues with the characterization of Zhu. She goes from a purely ambitious character to having hints of somehow being a liberator character.</p></li><li><p><strong>Uncle Vanya</strong> by Anton Pavlovich Chekhov: I read this before seeing the play on Broadway. Short, easy read.</p></li><li><p><strong>Howl&#8217;s Moving Castle</strong> by Diana Wynne Jones: Howl is annoying but the book isn&#8217;t so bad.</p></li><li><p><strong>The Koran- A Very Short Introduction</strong> by Michael Cook: Interesting read. I don&#8217;t play on reading the Koran any time soon though.</p></li><li><p><strong>The Wonderful Wizard of Oz</strong> by L. Frank Baum: I read this before going to see the Wiz. I&#8217;d never seen any of the movies or plays based on this book and only was familiar with the character and story though its influence on pop culture. Reading it, I realized Howl&#8217;s Moving Castle takes a lot from this author.</p></li><li><p><strong>The Picture of Dorian Gray</strong> and <strong>The Importance of Being Earnest</strong> by Oscar Wilde: I find Wilde&#8217;s character over-witty and annoying.</p></li><li><p><strong>The Vegetarian</strong> by Han Kang: Strange book. I wasn&#8217;t as disturbed as my fellow book club members but I wouldn&#8217;t recommend it.</p></li><li><p><strong>Crime and Punishment</strong> by Fyodor Dostoevsky: Great book. Wasn&#8217;t sure what I was expecting going into this book but I didn&#8217;t expect it to be so funny.</p></li><li><p><strong>Richard II</strong> by William Shakespeare: I&#8217;m still working on getting through my remaining history plays.</p></li><li><p><strong>The Story of Art</strong>: A long read, basically a text book. I&#8217;m probably going to have to return to this multiple times to fully digest it but it inspired me to start visiting the Met and the MoMA semi-regularly for a couple months. As it warms up, I&#8217;ll hopefully pick this book and habit back up.</p></li><li><p><strong>Jane Eyre</strong> by Charlotte Bront&#235;: One of my favorites this year.</p></li><li><p><strong>Wide Sargasso Sea</strong> by Jean Rhys: Not a bad read but pretty frustrating. This may just be a matter of my taste, but it formed a poor contrast with Jane Eyre. Maybe I just like the straightforward 19th century style of its sequel. I definitely disliked the feeling of confusion I had about the feelings of Antoinette and Rochester.</p></li><li><p><strong>Wuthering Heights</strong> by Emily Bront&#235;: This was such an engaging book I got through it all in one weekend.</p></li><li><p><strong>Complete Poems</strong> by Emily Bront&#235;: I picked this up because I liked here prose so much. From what I understand, little of her work was published during her lifetime and most of the poems take place in a fictional world that is never fully explained. I struggled with this as I do all poetry and the footnotes were useless. I&#8217;m happy I struggled through it though, and there were a few I really liked.</p></li><li><p><strong>Shakespeare&#8217;s Sonnets</strong>: I read the Folger&#8217;s edition which mostly provided useful notes. Surprisingly accessible when read with patience.</p></li><li><p><strong>The Illiad</strong> and <strong>The Odyssey</strong> by Homer (translated by Robert Fagles): When writing about such great works, I especially feel my own stupidity. With that said, here are my thoughts: The Illiad a bit repetitive and boring. Hector is clearly a better man than Achilles and I was sad when he died. I was surprised how much combatants focused on stripping dead bodies of armor and weapons. In the Odyssey, I was surprised by how hospitable everyone is. The Odyssey is of course, the far more interesting of the two. Both books were a pleasure to read and Fagles deserved great credit.</p></li><li><p><strong>The Oresteia</strong> by Aeschylus (translated by Robert Fagles): I don&#8217;t know why I found this such a struggle to read when I found Fagles&#8217; Theban plays so easy.</p></li><li><p><strong>Children of Blood and Bone</strong> by Tomi Adeyemi: The author builds an interesting world but can&#8217;t quite deliver in the story. The latter half of the book devotes a lot of time to an uninteresting romance and the ending didn&#8217;t make me interested enough in the sequel.</p></li><li><p><strong>The Other Black Girl</strong> by Zakiya Dalila Harris: Another unhappy ending. I didn&#8217;t really get the behavior of the main character. In the book club, others were making the point that the whole OBG concept is iffy.</p></li><li><p><strong>The Nature of Things</strong> by Lucretius: Easier to read than I expected. I expected to get a book on Epicurean philosophy but Lucretius is more interested in arguing for naturalism. The metaphysics is hard to follow but I imagine that&#8217;s because I&#8217;m missing lots of context.</p></li><li><p><strong>Seven Days in June</strong> by Tia Williams: Not especially good or bad or interesting.</p></li><li><p><strong>No Longer Human</strong> and <strong>The Setting Sun</strong> by Osamu Dazai: Both are short, sweet, depressing reads. I loved them.</p></li><li><p><strong>And Then There Were None</strong> by Agatha Christie: The reveal at the end is hilariously absurd. I was literally laughing out loud. This was a good one though.</p></li><li><p><strong>Rebecca</strong> by Daphne du Maurier: This competes with Wurthering Heights as my favorite read of the year. The characters are interesting, the setting is colorful and interesting, and the main character&#8217;s personality really come through.</p></li><li><p><strong>Three Body Problem</strong>, <strong>The Dark Forest</strong>, and <strong>Death&#8217;s End</strong> by Liu Cixin: I liked each book more than the preceeding. It&#8217;s near impossible to get these books from the library since the waiting list is so long but that&#8217;s for good reason. I normally hate reading Sci-Fi but these were amazing.</p></li><li><p><strong>Seeing Voices</strong> by Oliver Sacks: I picked this up as a prepared to start taking ASL classes. It&#8217;s a short read and I basically skimmed it but it corrected some of my misconceptions about sign language.</p></li><li><p><strong>The Heart is a Lonely Hunter</strong> by Carson McCullers: The ending is sort of sad and unsatisfying but overall a good read.</p></li><li><p><strong>Guns, Germs, and Steel</strong> by Jared Diamond: I assumed this book would be more about recent history. An interesting read but I think I&#8217;ll have to return to it to fully digest.</p></li><li><p><strong>There there</strong> by Tommy Orange: I was pretty unhappy with the ending but the way the stories of the characters weave together is interesting.</p></li><li><p><strong>One state, two states</strong> by Benny Morris: As far as I can tell, a pretty even handed history of a complicated issue.</p></li><li><p><strong>Hillbilly Elegy</strong> by J.D. Vance: I decided to pick this up after Trump chose him for VP.</p></li><li><p><strong>Cafe in Berlin</strong> and <strong>Ferien in Frankfurt</strong> by Andre Klein: These were both simple reads but I found them surprisingly difficult. I thought I&#8217;d be able to jump into reading German as easily as I had French after the Michel Thomas course but it&#8217;s been quite difficult. I need to invest way more time into it if I want to get any good.</p></li></ul><h1>Books I&#8217;m still reading:</h1><p>I ended the year still reading Anna Karenina. I&#8217;m also going to continue reading Byzantium as part of my history self-teaching. I also want to finish the French and German language learning picks I made. In particular, I have Andre Klein&#8217;s series in mind for German; and the French Harry Potter translations, for French. I may return to Lingua Latina but only if I have the time. I also want to finish the Shakespeare poetry book I got.</p><h1>Looking forward to next year:</h1><p>I&#8217;m actually going to get through the Catechism this year. I&#8217;ll also be reading and reviewing a bunch of manga and light novels. Aside from that, I have no particular intentions aside from reading widely.</p>]]></content:encoded></item><item><title><![CDATA[2023 Reading Reflection]]></title><description><![CDATA[This reflection comes out way late again.]]></description><link>https://blog.gathuru.xyz/p/2023-reading-reflection</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/2023-reading-reflection</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Thu, 20 Jun 2024 00:20:10 GMT</pubDate><content:encoded><![CDATA[<p>This reflection comes out way late again.</p><h1>Books I read this year:</h1><ul><li><p><strong>On Liberty</strong> by J.S. Mill: A liberal classic. On the face of it, nothing Mill advocates is considered radical from our modern point of view. But it&#8217;s still and inspiring defense of the value of liberty. Furthermore, you get the sense that</p></li><li><p><strong>The Riverside Shakespeare</strong>: I&#8217;ve read through all the plays and corresponding commentary. At first I struggled but I eventually habituated to the language. I feel a strong sense of satisfaction from having immersed myself in some of the most important texts of the English language. My feeling of accomplishment rivals that of my completion of the Bible.</p></li><li><p><strong>The Three Theban Plays</strong> by Sophocles (translated by Robert Fagles): I was able to complete all three plays in just a couple weeks. It&#8217;s inspired me to possibly read more classical Greek literature. The context around why Croesus&#8217;s Thebes must fall to Athens good to know while reading The Knight&#8217;s Tale/Two Noble Kinsmen.</p></li><li><p><strong>The Illustrated History of the World (Volume 1 &amp; 2)</strong> by J.M. Roberts: Both volumes were (relatively) short and sweet.</p></li><li><p><strong>Pygmalion</strong> by George Bernard Shaw: Short read. Wasn&#8217;t sure what to make of it.</p></li><li><p><strong>Frankenstein</strong> by Mary Shelley: My new favorite book.</p></li><li><p><strong>SPQR</strong> by Mary Beard: Nice introduction to Roman history.</p></li><li><p><strong>Europe in the High Middle Ages</strong> by William Chester Jordan: Really helpful and good read.</p></li><li><p><strong>Moby Dick</strong> by Herman Melville: Pretty good read. I was worried by the reviews I came across but there were many funny sections and I found little boring.</p></li><li><p><strong>Foster</strong> by Claire Keegan: Nice short read.</p></li><li><p>Various plays by William Shakespeare: I was hoping to finish but slowed down during the summer. I mostly have the history plays left. I read Macbeth, Othello, King Lear, Antony and Cleopatra, A Midsummer Night&#8217;s Dream, Romeo and Juliet, The Merchant of Venice, As You Like It, The Tempest, Much Ado About Nothing, Love&#8217;s Labour&#8217;s Lost, Comedy of Errors, Titus Andronicus, Two Gentlemen of Verona, Twelfth Night, Measure for Measure, Coriolanus, Pericles, Cymbeline, and The Two Noble Kinsmen.</p></li></ul><h1>Books I&#8217;m still reading:</h1><ul><li><p><strong>Shakespeare: The Invention of the Human</strong> by Harold Bloom: I picked up this book as a companion to my Shakespeare anthology. Sometimes illuminating but often over my head. Bloom has inspired me to read more classics. It says something about my reading comprehension that I can&#8217;t exactly state what it means that Shakespeare &#8220;invented&#8221; the human. I can only finish this once I finish the rest of the plays.</p></li><li><p><strong>The Power Broker</strong> by Robert Caro: I starting reading this while looking for a history of New York. I got 2/3rds of the way through and haven&#8217;t looked at it for half a year.</p></li></ul><h1>Other notes</h1><p>I read Hamlet and Julius Caesar in 2022 before starting with the rest of the plays. The biggest helpers for making myself read more have been making Anki cards on unknown vocab and other knowledge and getting and e-reader. Also joining some book clubs provides a good motivation.</p>]]></content:encoded></item><item><title><![CDATA[Food Terminology Is Nuts]]></title><description><![CDATA[It&#8217;s surprisingly difficult to find clear definitions for these terms online:]]></description><link>https://blog.gathuru.xyz/p/food-terminology-is-nuts</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/food-terminology-is-nuts</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Sat, 08 Jul 2023 00:37:18 GMT</pubDate><content:encoded><![CDATA[<p>It&#8217;s surprisingly difficult to find clear definitions for these terms online:</p><ul><li><p>seed = plant embryo</p></li><li><p>fruit = seed container</p></li><li><p>nut = hard-shelled fruit</p></li><li><p>grain = small, hard seed</p></li><li><p>cereal = grain-yielding plant</p></li></ul><p>&#8220;A legume is a plant in the family Fabaceae&#8221; <a href="https://en.wikipedia.org/wiki/Legume">according to Wikipedia</a>. A pulse is legume seed. Beans, lentils, and peas are all pulses. As far as I can tell there&#8217;s no real definition for these.</p>]]></content:encoded></item><item><title><![CDATA[the Dumbest superintelligent tool is aligned]]></title><description><![CDATA[In a Twitter thread I&#8217;m unable to rediscover, commenters were touting Chat-GPT&#8217;s chess abilities.]]></description><link>https://blog.gathuru.xyz/p/dumbest-superintelligent-tool-is-aligned</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/dumbest-superintelligent-tool-is-aligned</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Mon, 24 Apr 2023 03:00:32 GMT</pubDate><content:encoded><![CDATA[<p>In a Twitter thread I&#8217;m unable to rediscover, commenters were touting Chat-GPT&#8217;s chess abilities. If I remember correctly, one commenter pointed out this capability demonstrated Chat-GPT wasn&#8217;t simply a &#8220;stochastical parrot&#8221; because the most efficient way to encode the many possible sequence of moves involves creating some model of a chess board. I believe I&#8217;ve come up with a similar argument with the following conclusion: the dumbest superintelligent tool AI is aligned.</p><p>Unaligned intelligences are either &#8220;too dumb&#8221; or &#8220;too smart&#8221;:</p><ul><li><p>&#8220;too dumb&#8221; AIs are always unaligned in the sense that they cannot achieve or even represent their users&#8217; goals. Such AIs fail to generalize in unfamiliar environment, fail, and are eliminated.</p></li><li><p>&#8220;too smart&#8221; AIs consistently generalize and therefore must understand their users&#8217; goals but not share them.</p></li></ul><p>An AI that is &#8220;too smart&#8221; but doesn&#8217;t immediately destroy humanity must be biding its time. But such an AI must be a master of deception in addition to being a superintelligence at its task. For example, an unaligned superintelligent self-driving car would have to develop a theory of mind and future planning abilities far in excess of what&#8217;s necessary for sharing the road with humans or planning a trip from A to B.</p><p>I think this relates to Chat-GPT&#8217;s chess abilities because the best way for a tool intelligence to succeed is to model its user. It&#8217;s simplest if the AI and its model of the human share a goal. If goals can be thought of as having different levels of &#8220;complexity&#8221;, then &#8220;pretend to perform my task to deceive humans&#8221; is more complex than &#8220;perform my task&#8221;.</p><p>Other notes: I realized my reading reflection left out a couple of important books I read last year. The first was &#8220;Facing Mount Kenya&#8221; by Jomo Kenyatta, Kenya&#8217;s first president. Before becoming a politician, he studies anthropology in Britain. His Western teaching in conjunction with his experience growing up near the end of the pre-colonial era equiped him to give an interesting account of Kikuyu life. A lot of it is &#8220;political&#8221; in the sense that it argues for independence and the preservation of traditional Kikuyu culture. I&#8217;d like to read a more modern work to compare it to how anthropologists understand the region&#8217;s history now. The two things that gave me the most discomfort were his defense of polygamy and his defense of female genetical mutiliation. At one point he remarks that the average Kikuyu man had 2 wives, which I can only imagine working out with a lot of violence. He defends female genetal mutiliation as a rite of passage for young woman. From what I understand, the earliest political movements for independence focused on bringing back the practice.</p><p>The second book I read was &#8220;The Other Wes Moore&#8221; by Wes Moore. I had gotten the book as a gift from my aunt. The author compares his upbringing to that of a murderer with the same name.</p>]]></content:encoded></item><item><title><![CDATA[2022 Reading Reflection]]></title><description><![CDATA[Books I read in 2022:]]></description><link>https://blog.gathuru.xyz/p/2022-reading-reflection</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/2022-reading-reflection</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Sat, 25 Mar 2023 23:16:38 GMT</pubDate><content:encoded><![CDATA[<h1>Books I read in 2022:</h1><ul><li><p><strong>The Genetic Lottery</strong> by Kathryn Paige Harden: The book argues that inequality is in part determined by genetic differences and that egalitarians should embrace this. I came to this book not know what scientists mean by &#8220;heritability&#8221; or how they measure it but came away from it with a basic understanding of the current state of the nature-nurture debate as it relates to education and class. It&#8217;s been almost a year since I read this book (as is the case with other books on this list) but I don&#8217;t remember finding the more politically focused parts of the book all that great, though I&#8217;m sure I agree with egalitarian ideals.</p></li><li><p><strong>Who We Are and How We Got Here</strong> by David Reich: Easily my favorite book of the year. I really inspired me to educate myself more on genetics and human history. I&#8217;ve recommended this book to multiple people: not a thing I can say about any other book on this list or even very many off it.</p></li><li><p><strong>Human Diversity</strong> by Charles Murray: A three part book focusing on cognitive differences rooted in class, sex, and race: ordered from most established to most speculative according to the author. The book is chock-full of info on psychometrics, genetics, and neurology but does a great job explaining everything.</p></li><li><p><strong>How to Read the Bible</strong> by James L. Kugel: An excellent book. I&#8217;m confident I&#8217;ll read it again and buy it next time. I wish I had made this book my companion while I was reading the Bible the first time. The book compares ancient interpretations of the Bible with modern scholarship. The author is an Orthodox Jew and has some interesting ideas about how people of faith can understand scripture in light of what we&#8217;ve learned but that&#8217;s not for me to comment on. I really want a text of this quality that covers the New Testament.</p></li><li><p><strong>The Bible (partially: Ezra, Nehemiah, Esther, the Poetic books except for Job, the Prophets, all of NT except for John)</strong>: I feel a real sense of accomplishment having finish the whole Bible. I&#8217;ve taken the experience as a lesson in how, by making reading into a habit, you can complete any text. One thing I began to appreciate as I read, and only fully understood as a read secondary texts on the Bible, is how long time spans between its earliest and latest texts. In my head, everything in antiquity and beyond blended together. But reading the Bible, critical texts, and unrelated work on anthropology have inspired me to deepen my understanding of world history. I&#8217;m not sure when I&#8217;ll next revisit any part of the Bible but when I do, I&#8217;d like it to be the King James Version.</p></li><li><p><strong>Meditations</strong> by Marcus Aurelius: I finally finished this book after a near year long break from it. I&#8217;m disappointed I&#8217;ve got so little out of it. But it&#8217;s a short read so I&#8217;ll give it another go sometime.</p></li></ul><h1>Looking forward to this year:</h1><ul><li><p><strong>Shakespeare&#8217;s Collected Plays</strong>: I intend to read all of them. Wish me good luck! This will be the replacement of my Bible reading plan in the sense that I will make it a daily habit.</p></li><li><p><strong>The Cantebury Tales</strong> by Chaucer (translated by Nevill Coghill): Another collection culturally important tales. I probably won&#8217;t have time to read this unless I finish or take a break from Shakespeare.</p></li><li><p><strong>The Catechism of the Catholic Church</strong>: The same podcaster I followed along while reading the Bible is starting a similar podcast for the Catechism. I&#8217;m not sure what I could learn that I haven&#8217;t already either from the Bible, Sunday school, or elsewhere.</p></li></ul><p>Aside from that, I&#8217;m non-commitant. I&#8217;ve tried picking up <strong>Thus Spoke Zarathustra</strong> and <strong>The Structure of Scientific Revolutions</strong> again, only to be reminded why I dropped these texts in the first place. I may read more history, anthropology, or biology books. I&#8217;ve been telling myself to read more sci-fi for some time now.</p><p>I also need to read more an AGI x-risk. I got <strong>Superintelligence</strong> and <strong>The Alignment Problem</strong> from the EA book service and I do plan to read them. The problem is that the less I&#8217;m convinced by the AI don&#8217;t-kill-everyone (or whatever it&#8217;s called) argument, the less urgency I feel in getting up to speed on their arguments. I plan to write more about why I&#8217;m not worried to better organize my thoughts and motivate my learning. But between my job, working out, and reading, it seems like I have little time for anything else. In hindsight, much of my time as a student was wasted.</p>]]></content:encoded></item><item><title><![CDATA[2021 Reading Reflection]]></title><description><![CDATA[Books I read this year:]]></description><link>https://blog.gathuru.xyz/p/2021-reading-reflection-ad5</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/2021-reading-reflection-ad5</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Fri, 31 Dec 2021 01:07:00 GMT</pubDate><content:encoded><![CDATA[<h1>Books I read this year:</h1><ul><li><p><strong>Bowling alone</strong> by Robert D. Putnam: Classic book on social alienation in America. I&#8217;d like to see more updated statistics and international comparisons. Aside from generational succession, the main driver of the fall in social capital seems to be technological change. This make me pessimistic and I wonder how today&#8217;s communitarians hope to solve this problem.</p></li><li><p><strong>Mere Christianity</strong> by C.S. Lewis: I took fairly detailed chapter by chapter notes. I&#8217;ll admit that I didn&#8217;t find his arguments convincing and at times I found them hard to follow. But overall, I enjoyed the books and the opportunity to learn more about the Christian worldview.</p></li><li><p><strong>The Bible (partially: Pentateuch, Joshua, Judges, Ruth, 1 &amp; 2 Samuel, 1 Chronicles, Job, John)</strong>: I started the Bible in a Year reading plan in early August and haven&#8217;t missed a day yet. I&#8217;m on Day 149 and have been taking notes and listening to the accompanying podcast. Above are the books I&#8217;ve completed in entirety. Readings often vary wildly in how engaging or interesting they are but overall I&#8217;ve enjoyed the readings and look forward to the day I can say I&#8217;ve completed it.</p></li><li><p><strong>A Time to Build</strong> by Yuval Levin: I read this book early fall and didn&#8217;t take any notes so my reflection here will be surface level. Levin makes a good argument that America&#8217;s current problems are caused by weak institutions. However, its hard to see how to apply this revelation except in the most personal manner. I also don&#8217;t see how empowering our institutions in their current state would be good for us. I&#8217;m more interested in building alternatives.</p></li><li><p><strong>The death of expertise</strong> by Tom Nichols: This is another book I don&#8217;t fully remember.</p></li><li><p><strong>The Precipice</strong> by Tony Ord: Very well argued and informative book. It covers a wide range of issues but the author handles it very well. The arguments are presented in a very clear and precise manner. I hope to read it a second time soon. The subject matter is somber but still in general makes me excited about the future of humanity.</p></li><li><p><strong>Doing Good Better</strong> by William MacAskill: Good book introduction to Effective Altruism. I was already familiar with most of the concepts behind the book but I still enjoyed it.</p></li><li><p><strong>Human Compatible</strong> by Stuart Russell: I&#8217;ll admit that I&#8217;m new to the issue but I don&#8217;t find the idea of AI as an existential risk very convincing. I hope AGI reading group can help me better understand the arguments presented here. I may re-read this book afterwards to better formulate my criticisms.</p></li></ul><h1>Books I&#8217;m still reading:</h1><ul><li><p><strong>Meditations</strong> by Marcus Aurelius: Very short. It&#8217;s interesting but I haven&#8217;t had much use for its wisdom I guess.</p></li><li><p><strong>The Bible (remainder)</strong>: I&#8217;ll probably take a break when summer rolls around.</p></li><li><p><strong>The structure of scientific revolutions</strong> by Thomas Kuhn: I started this one over the summer. I was already familiar with the argument of this book through summaries in other media but felt I ought to read the original.</p></li></ul><h1>Looking forward to next year:</h1><p>I struggled to keep up with my reading pace when the semester got busy. Having one book (Bible) I was constantly making progress through did work though. Looking forward through, I need to figure out how to do so with other books if I&#8217;m going to get as much reading done as I&#8217;d like.</p><p>I don&#8217;t expect to get as much reading done. I&#8217;ll mostly be focused on personal projects and self-study. I&#8217;ll hopefully get into the AGI Safety Fundamentals Program but the reading list is mostly papers.</p><p>I&#8217;ll focus on finishing up Meditations over the next week, then I&#8217;ll continue the Bible reading plan. If I have free time, I hope to read some sci-fi classics. Also, now that I&#8217;ve read some intro EA stuff, I hope to read some books off of the Progress Studies reading list.</p>]]></content:encoded></item><item><title><![CDATA[Welcome to my blog!]]></title><description><![CDATA[Hello and welcome to my blog!]]></description><link>https://blog.gathuru.xyz/p/welcome-to-my-blog-564</link><guid isPermaLink="false">https://blog.gathuru.xyz/p/welcome-to-my-blog-564</guid><dc:creator><![CDATA[Edward Gathuru]]></dc:creator><pubDate>Thu, 02 Jul 2020 15:15:00 GMT</pubDate><content:encoded><![CDATA[<p>Hello and welcome to my blog!</p><h1>Blog Purpose</h1><p>In this blog I will write about the things I&#8217;ve been working on or thinking about. The content will be varied: ranging from shorter posts reviewing media I&#8217;ve recently consumed, to longer posts about topics I&#8217;ve spent time researching, to the occasional <em>how-to</em> on a tech problem I&#8217;ve struggled with.</p><p>If all that sounds interesting, checkout the RSS feed in the sidebar. I hope you enjoy!</p>]]></content:encoded></item></channel></rss>