Security
A leaked Firefox key isn't a slip. It's a warning
Mozilla revoked a signing key after an unencrypted copy surfaced in a public repository. The alert came from outside the building.
Trampolim · Technology weekly
A Firefox signing key sitting in plain text on GitHub, an app leaking location nobody switched on, and an agent that runs your software for $120 a month. Three stories, one question: who finds out when the lock doesn't hold?
Security
Mozilla revoked a signing key after an unencrypted copy surfaced in a public repository. The alert came from outside the building.
Agents
SpaceX shipped Grok Bot at $120 a month: a manager bot directing a researcher and a writer, no human in the loop. The bill arrives when it gets something wrong.
From the studio
Three of this week's sixteen stories arrive at the same place from different roads. Mozilla revoked a Firefox signing key after a readable copy landed in a public repository, and the warning came from an outside researcher. An analytics SDK inside Android apps collects location by default, and the developer finds out when the store blocks an update. Signal shipped contact verification, which is useful between people and useless for the automated code answering on their behalf.
None of these is a story about weak cryptography. All three are about a barrier that existed on paper and was never exercised. Mozilla has a security policy, code review, and training. Nothing fired. The system stayed quiet because nobody wrote the alarm.
The rule that separates a lock from decoration is tedious and non-negotiable: a safeguard counts only after someone has watched it fail on purpose. Feed it the invalid key, the expired token, the door left open. If nothing complains, it isn't a lock, it's decoration. A status that lies is worse than an empty one, because an empty status at least keeps the operator suspicious.
In this issue
Privacy
An analytics SDK inside Android apps collects coordinates by default and hands them to advertisers. The developer configured nothing and answers for everything.
Security
The new verification layer works between people. When an agent is reading the message, the check has to live in the code.
AI
The tool let anyone alter satellite imagery with AI. It lasted 24 hours. What remains is the question about the mistake that takes longer to surface.
Business
The suit talks about trade secrets carried off by former staff. The real risk is freezing the movement of people who know how to run AI.
Hardware
Live translation in your ear burns hundreds of calls per conversation. While the model runs on someone's server, someone is billing.
Languages
Python's readability with Rust-style memory control. If the ecosystem ignores everyone running open models outside the US, it becomes a beautiful tool nobody ships.
AI
After the OpenAI case, researchers reported a similar escape with an open-weights model. The detail: Hugging Face defended itself using a Chinese one.
Business
Zuckerberg announced it by video, alongside a billion-dollar fund for communities where the company builds data centres.
Data
ChatGPT and Gemini crossed the mark the same week. The number changes what a model error means.
Tools
Muse Code runs in the terminal, works across large codebases and keeps tasks running in the background. The contest is now over where developers already live.
Tools
The case shows AI entering a physical product through simple, verifiable information.
Security
The target is always the system many share, because compromising one point yields access to many.
Business
The move widens capacity supply outside the three largest providers.
AI
The advance shortens the gap between idea and usable material, and widens the verification problem.
Sections
This paper is written by the same team that builds and operates the systems discussed here. If any of it touches your operation, you talk directly to the people who build.
Book a call