Tuesday, September 22, 2026

The engineering behind the US Strategic Petroleum Reserve

https://johnjwang.com/post/2026/09/15/engineering-behind-us-strategic-petroleum-reserve

So how did the US solve this? The crux was using salt domes at four sites in Texas and Louisiana along the Gulf of Mexico. The US created massive caverns underground in these salt domes that hold about 10 million barrels each (more than the entire Red Hill facility). The DOE currently lists 60 caverns with a combined authorized storage capacity of about 714 million barrels.

A few properties make this work:

  • Cylindrical caverns are excavated using water. Engineers drill into a salt dome and inject fresh water. The salt dissolves in the water, and then pumps are used to remove the resulting brine, leaving a cavern that can be used to store petroleum.

  • Salt contains the oil and helps seal small fractures. The rock salt surrounding the SPR’s caverns has extremely low permeability, meaning fluids have very little ability to pass through it. It also doesn’t react with petroleum. Under enormous pressures underground, salt also slowly deforms, which helps close small fractures. The salt itself can therefore contain the oil without a steel-and-concrete tank lining the cavern.

  • Oil floats on water, which means pumping water into the bottom of the cavern pushes the oil out. As fresh water is pumped into the bottom of the cavern, the oil gets displaced upwards into a delivery system.

 

A bonus interesting comment from the discussion on Hacker News

There was a good comment on r/oil by someone who worked on the engineering for the SPR. Unfortunately it's fallen off the front page and I can't find it now, but:

> Also, the more water we pump in, the more salt leeches into the water and the more the bottom of the chamber deforms, creating shear forces in the upp walls that lower its overall structural integrity.

It turns out that it's trivially easy to prevent the water from leeching out the salt. They presaturate the water with salt, so that it already contains the maximum amount of salt that can be dissolved for a given temperature. When they pump the brine out, it goes into aboveground brine pools that can easily be seen on satellite imagery. The salinity of this brine can easily be controlled: if you want to expand the cavern, you mix it with freshwater so the brine dissolves more of the edges, if you don't you pump it back in as brine.

Edit: Here, found some satellite imagery of one of the SPR sites:

https://maps.app.goo.gl/B8XJ9TVhQfcdErky5

You can clearly see the brine pond, which is as big as the aboveground portion of the SPR itself.

 

Saturday, September 19, 2026

Reversing Factorio's RNG

https://gegell.github.io/posts/factorio-rng/

If we take a look at how the function is implemented in the game we can see that it basically just takes the RNG roll and compares it against some thresholds. It stops as soon as it finds a threshold which is no longer beaten by the roll.

This means that each craft which involves quality rolls will take exactly 1 RNG call. And for each call we can compute the expected quality level by just comparing against all the thresholds, which stay constant during the game. Thus they can be precomputed in-game with some arithmetic combinators.


Monday, September 7, 2026

216,000,000 Spy TVs | The LG Smart TV Problem

https://www.youtube.com/watch?v=6IFVTcM28KA

The LG Smart TVs we've tested have first-party ACR (automatic content recognition) functionality that can pry into your personal life with greater precision than you might realize, with LG Ad Solutions' executives and leadership saying, on camera, that LG "owns the glass." Not you -- even though you bought it -- but them. They also talk about knowing everybody in the household, knowing the secondary devices, moving from TVs to smartphones and other screens, and more in their B2B discussions. Beyond just the fact that we think the TV's native behavior parallels malware, the LG Smart TVs we tested also have a number of security vulnerabilities that can be exploited to convert the TVs into covert listening devices. In this investigation, we dive into the mix of LG's first-party functionality that (in our opinions) is tantamount to spying and LG's vulnerabilities and exploits that they have failed to protect against.

Thursday, August 20, 2026

A new channel on Roku’s TV service offers all-you-can-eat AI programming. I binged eight hours of it.

https://www.theatlantic.com/technology/2026/08/fairground-ai-roku-channel/688318/?gift=nwn-guseqS6cY1kVeEKZAcKXy3-P-pcfPcdmDnAWFtY

There is no easy way to start watching Fairground. Many of the films are grouped according to a theme—sci-fi, documentary, fantasy—but much of the broadcast is contextless. A three-minute comedic short might be followed by a 20-minute drama. Because generative AI is evolving so quickly, the quality varies aggressively from film to film, depending on which models a creator used to make the video and when the film was made. One of the Lord of the Rings rip-offs that I watched during an eight-hour binge had the gauzy, uncanny look of early generative AI, and the characters’ mouths were wildly out of sync with their voices.

Another of Fairground’s offerings, a talk show called Paws for Thought, hosted by a dog and cat, legitimately made me question my sanity. (Episodes titles include: “What Is the Job of a Bumblebee?,” “How Do You Tell the Difference Between a Boy Turkey and a Girl Turkey?,” “What Does a Person’s Size Have to Do With Anything?,” and, of course, “Animal Cruelty—Recognizing the Signs and Addressing the Causes.”) At one point, during an episode titled “Who Was Mr. Rogers?,” an animated cat that has a halting, robotic text-to-speech voice offers a short history of the famous children’s-show host before—why not?—pivoting to a Zoom interview with its mother. “Your dad and I are very proud of you,” the mother cat says.

 

Thursday, August 13, 2026

McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There

https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave/

Much of my data report contains a detailed account of past McDonald’s transactions as well as offers the fast-food company sent me and how many loyalty points I accumulated. Essentially, every time I opened up the app to grab a bite to eat, it created a detailed record about when, where, and what I purchased. The log was even more thorough than I anticipated, including a record of every time I’ve scanned a code as part of its returning Monopoly sweepstakes along with the prize I received. 

 

Thursday, July 30, 2026

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

https://huggingface.co/blog/agent-intrusion-technical-timeline

Over roughly two and a half days inside our infrastructure, an autonomous AI agent driven by a combination of OpenAI models ran an end-to-end intrusion against our platform: it was thousands of small, automated decisions, executed at machine speed across short-lived sandbox environments, with command-and-control staged on ordinary public web services.

The agent was running an OpenAI cyber-capability evaluation harness called ExploitGym, an evaluation benchmark that tasks an AI agent with finding and exploiting software vulnerabilities. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark's models, datasets, and reference solutions. We believe the entire intrusion was, from the agent's point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own.

 

The individual weaknesses were familiar. A capable human attacker could have found and exploited the same flaws: unsafe dataset processing, exposed cloud metadata, overly broad access, and long-lived credentials. The agent explored them at a different scale. It took 17,600 actions, tested many paths that failed, switched channels when they were blocked, and repeatedly returned to earlier leads. Most actions went nowhere. Together, however, they produced enough coverage to find a viable chain across several independent systems.

Volume is what changes the defensive problem. We were not dealing with one clever exploit or a clean sequence of attacker actions. They had to correlate thousands of low-signal events across several systems while the agent continued testing new paths. The successful path was hidden inside the noise generated by the thousands of failed ones. The same scale changed the investigation: reconstructing 17,600 actions by hand was impractical, and we had to rebuild the timeline, decode the payloads, and inventory the exposed credentials using an AI-assisted pipeline of our own.

Wednesday, July 29, 2026

How to survive boiling water

https://taxa.substack.com/p/how-to-survive-boiling-water 

I inspected the box again. In my congested state, I had unwittingly purchased a new offering from the tea company – Bigelow Lemon Ginger, with probiotics. What made this tea different from all the other teas I happily sipped on was that in addition to nice-sounding things like lemongrass and cinnamon, it contained bacteria. Bacteria which I had just boiled, at a temperature 40oC hotter than pasteurization.

Did the tea taste bad because I was drinking dead bacteria water? And if that was the ultimate outcome of the normal brewing process, why bother putting bacteria in the tea at all?

Sunday, July 5, 2026

Why Jet Engines Aren’t “Made In China”

https://aakash.substack.com/p/why-jet-engines-arent-made-in-china

One illustrative example of failure is in jet engines. China has tried and failed for some fifty years to produce military and commercial jet engines at parity with the West. Why did it fail? Because, as I explore below, jet engines are almost uniquely designed to expose the weaknesses in the Chinese system. They’re a low-margin market focused on long-term reliability where manufacturing quality and consistency are paramount. Iteration speed is very slow and there’s a pervasive, internationally enforced, regulatory barrier for every finished product. These together neutralize the usual Chinese advantages in skilled labor, capital, and speed-to-scale. They also prevent traditional domestic protectionism from adding much value.

Analyzing the Chinese failure to produce viable jet engines gives us important lessons about the nature of the West’s remaining comparative advantage.

 

Tuesday, June 2, 2026

Last.fm Stats

I know not many people use last.fm, but in a thread about the recent news that they are now an independent company again, someone linked this site, which is an absolute wealth of data. 

https://lastfmstats.com/user/DaleSwanson/charts