Category Archives: Security

2026 National Firearms Survey of AR-15 Hunters Who Don’t Exist

The 2026 National Firearms Survey claims 36 million Americans hunt every year. The federal government counts 14 million. The gap is 21 million mystery people, and that gap now sits unexplained in front of the Supreme Court.

William English of Georgetown posted the second wave of his survey to SSRN on August 24. Eleven days later, on September 4, he filed an amicus brief in his own name, with the Center for Human Liberty, in Viramontes v. Cook County and Grant v. Higgins, telling the Court his unreviewed working paper “warrants reliance” as proof that AR-15 type rifles are in common use for lawful purposes. Page 9 of the brief lists those purposes. Hunting sits third, at 50.2 percent of owners, behind home defense and target shooting.

I’m a bit perplexed at how little data integrity there is in this whole system.

The raw data is on Harvard Dataverse. I downloaded it and ran the numbers. Every headline figure in the paper reproduces exactly: 16,688 validated owners, 30.0 percent owning an AR-15 or similar rifle, 50.2 percent of those citing hunting. The math is simple, and the problem is what it’s being used falsely to imply.

16 million AR-15 hunters, 14 million hunters

The survey asks every validated gun owner whether they go hunting at least once in a typical year. 40.8 percent say yes. The paper puts the adult gun-owning population at 88 million. Multiply those and the survey implies 35.9 million annual hunters in the United States, roughly one adult in seven.

The U.S. Fish and Wildlife Service runs the National Survey of Fishing, Hunting, and Wildlife-Associated Recreation every five years, since 1955. The 2022 wave drew over 100,000 respondents and counted 14.4 million hunters aged 16 and over, six percent of the population. It counts anyone who hunted, licensed or unlicensed, on public land or private, with a rifle or a bow. It is the benchmark every state wildlife agency and every hunting organisation in the country uses.

English’s survey question anticipates there will be a license objection. Its wording very clearly invites respondents to “count hunting on private land, which may not require a hunting license.” The federal survey already does also, however. The 2.5x gap isn’t explained by the caveat.

Then look at the AR-15 subsample. 63.8 percent of AR-15 and similar-rifle owners say they hunt every year. Applied to the paper’s 26.4 million owners, that is 16.9 million AR-15 owners hunting annually. The entire American hunting population, by the federal count, is 14.4 million. The survey’s AR-15 owners alone outnumber it by two and a half million.

Look at this the other way now. Among respondents who say they hunt every year, 47 percent own an AR-15 or similar rifle. Half of America’s hunters owning a pistol-grip semiautomatic is a claim anyone who has stood in a check station line can weigh against what actually comes through it.

Overcount explained

Self-reported hunting has a hard external check, because the federal government has measured it for seventy years. Against that check, the gun owners in this sample overstate by a factor of two and a half. The same respondents, in the same sitting, supplied the defensive gun use figures and the rifle and magazine counts that the brief carries to the Court. Those rest on self-report alone. The one variable that can be measured with an outside benchmark fails it.

The data offers other insights about who was answering. Among the 5,001 AR-15 owners with complete counts, 23.1 percent entered more AR-15 type rifles than total rifles owned. Individual respondents reported owning 5,678, 1,513, 1,332, and 1,000 AR-15s. The paper drops those counts from the stock estimate and keeps the respondents as owners for the 30 percent prevalence figure. Median completion time for the full owner questionnaire, including itemised magazine counts by capacity and narrative defensive incident questions, was five minutes. Nearly half finished in under five.

The ownership question itself opens with “Some have argued that few gun owners actually want or use” these rifles, before asking whether the respondent owns one. That is a leading stem, and the paper prints it as a methodological refinement. The instruction that follows tells owners to include rifles “modified or moved to be compliant with local law.” A California featureless rifle is legal precisely because the statute defines it as something other than an assault weapon. The survey counts it as one, and the note under Table 8 adds rifles kept in other states to the tally, which is how California, New York, New Jersey, Massachusetts and Maryland all land near the 30 percent national figure despite bans. The brief then spends three pages accusing a rival study of a “demonstrable coding error.”

The same respondents, on self-defense

The leading stem is a troubling pattern. The AR-15 question opens with “Some have argued that few gun owners actually want or use” them. The magazine question opens with the identical clause. The defensive gun use question opens with “Many policymakers recognize that a large number of people participate in shooting sports but question how often guns are used for self-defense.” The deterrence question hands the respondent an example before asking, a landowner with a rifle on his shoulder turning away a trespasser.

Every contested number in the brief comes from a question that first told the respondent who was arguing against them. That’s not subtle.

The defensive gun use estimate of 2.2 million per year reproduces from the data. It comes from dividing every incident a respondent ever reported by the adult years the respondent has lived, then multiplying by 88 million owners. That method assumes a rate that holds across a lifetime.

The data says that’s wrong.

Gun owners aged 18 to 20 report 0.47 defensive uses per adult year, roughly one every two years. Owners aged 26 to 30 report 0.09. Owners over 80, who lived their prime years through the 1970s, 80s and 90s when the FBI violent crime rate ran well above today’s, report 0.002. The rate falls in every single bracket from 18 to 80, by a factor of 200 end to end. Lifetime incident counts should rise with age, since a longer life offers more chances. Here they peak at 26 to 30 and fall to almost nothing.

The paper calls this “concentrated in early adulthood.” The easier explanation is that the youngest respondents in an online panel say yes the most.

Yes, there are yes clusters.

Respondents who own an AR-15, own a magazine over ten rounds, and hunt every year report a lifetime defensive gun use at 64.6 percent. Respondents with none of the three report it at 20.8 percent. 1,239 validated owners said yes to all five contested items in the survey: the rifle, the magazine, the hunting, the defensive use, and the deterrence. Owning a rifle that also gets used for deer makes a gun no better in a fight. It makes a respondent more likely to say yes. The defensive use rate tracks the person answering, and the survey has no way to tell the two apart.

Then look at the gunfire. 23.7 percent of reported incidents involved firing the gun, with a median of two rounds. At the paper’s own 2.2 million annual figure that is 521,000 defensive shootings a year, over a million rounds fired at people or animals in self-defense. One respondent reported firing a million rounds in a single incident, two more reported 500.

A million rounds.

The FBI’s justifiable homicide data for 2015 through 2024 records 2,776 killings by private citizens across the whole decade, 88.5 percent with a firearm. That is about 246 a year. One attacker killed for every 2,100 defensive shootings. 53.3 percent of the incidents took place outside the home but on the respondent’s property, and 8.4 percent were against animals.

The brief tells the Court that 70.6 percent of defensive uses were so successful there was no crime to report. The FBI figure suggests a far simpler reading of why nothing was reported.

Built for the brief

The Azrael, Blocher, Cook, Hemenway and Miller critique of the 2021 wave took three years to reach print in the SMU Law Review. By then the first paper had been cited in roughly sixty-five briefs and at Supreme Court oral argument. The second wave reached the Court in eleven days, carried by its own author, with the survey firm named as a data-quality credential and The Trace’s funders named in a footnote on the same page where the brief borrows The Trace’s numbers.

The 40.8 percent hunting rate appears nowhere in the body of the paper. It sits in one row of an appendix table on page 69. The body text on page 41 says instead that “half report using them for hunting.” Respondents ticked “Hunting” from a list of reasons for owning the rifle. The paper turned a ticked box into use, and the brief carried the upgraded version to the Court.

Page 5 says the survey “was sponsored and paid for by a grant from the Wealth of Nations Institute.” The Wealth of Nations Institute is a Delaware nonprofit with an IRS ruling year of 2024, a Kennett Pike mail-drop address in Wilmington, and a single public filing reporting under fifty thousand dollars in program spending. A 51,398-respondent Centiment panel costs more than that. Whose money came through that vehicle is unstated. The PDF’s own metadata lists its creator as OpenAI Prism, with a creation date of August 26, two days after the date on the title page.

Harry Frankfurt defined bullshit as speech produced with indifference to whether it is true. The purpose it serves sits downstream of the speaker, and here the downstream is a docket.

The 2026 National Firearms Survey answers a question a court asked. It reports that half of American hunters own an AR-15 and that AR-15 owners alone outnumber every hunter the federal government can find. That is some real bullshit in the Supreme Court’s docket. The test was easy, so I’m guessing it’s not being done for a reason.

RAIV in Berlin Says the Senate Has Time for Breach Triage

Berlin’s Chief Digital Officer told the Innenausschuss that “AI tools” will rank more than 1.2 million leaked files by risk; the published archive runs to 1.44 million. People have opinions about this nod to AI, of course, including me.

However, he gave us no location and no one asked him the obvious questions, so here we go.

All we are talking about is document classification. A model reads a file and says: personal data, credentials, court record, infrastructure drawing, contract, noise. Open-weight models that anyone can download today do this very well for free. The harness around the model actually does the real work: extract text, regex the obvious identifiers, run a fixed rubric, log everything, hand the top tier to humans.

I’ve written and published on exactly this extensively, not to mention published tools.

Berlin Loves a Good RAIV

Last week I published the RAIV, a Redundant Array of Inexpensive Videocards: seven used AMD MI50 cards at 220 euros each on a secondhand EPYC board, two mirrored groups of three plus a hot spare, 192 GB of VRAM, about 3,500 euros all told. It’s familiar if you built large storage in the 1990s, so a dead card loses one job if that and the run lives. I’m calling this one the Berlin RAIV because I’m terrible at marketing and don’t care. More important is that it runs a 100B-class open model at four-bit per mirror, or a 20B-class classifier on every card in parallel, which is what this job calls for.

Sail Time

A classifier needs the first thousand tokens of a document plus the regex hits, so budget 1.5 billion tokens for the archive. An MI50 pushing a 20B sparse model through llama.cpp prefills on the order of 500 tokens a second, conservatively. We have six cards, 3,000 a second, so six days per rig. Ten of these Berlin RAIVs run the full archive in under a day of model time and cost 35,000 euros, or less depending on used-parts dealers this week (and the inevitable rush of squatters). Extracting and OCRing 5.8 terabytes is CPU work and takes longer. Two weeks should be enough, including human review of the most sensitive files. The Senate has spent three weeks explaining why it has no time, which should have been used instead for real forensics work.

Rhysida asked for two million. I’m saying ten rigs of used AMD cards shows them a middle finger for less than the Senatsverwaltung’s annual caffeine budget.

That’s just the hard reality in tech terms. Now the fluff of politics.

Batten the Hatches

The archive contains civil defence plans, Kasernen documents, and detail drawings of water works, substations and emergency power. Letting any of that flow to a US service lands under the CLOUD Act, which compels the provider to hand data to US authorities on request wherever the server sits. The Senate would be duplicating Berlin’s infrastructure vulnerabilities inside a particular foreign jurisdiction (hiring Nazis) in order to find out how bad the first copy was. Rhysida at least stole it. The Senate would be donating it to the bad guys.

In 1938 Roosevelt had a Nazi spy ring operating out of New York, the Rumrich case. He had the FBI arrest it, try it, and convict it. He did not phone Berlin and ask the Gestapo to send its people to make it easier on Americans. The Bezirk Lichtenberg understood this and refused the Senate’s Clownstrike software due to legit data access concerns. The Senate has yet to catch up with its own Bezirk.

Germany can do this. It needs to pivot to a science-based response, reducing its dependency on mythological methods.

The cards are the real recycling deal. The models are public. The skills are here; the CCC has been describing the response in the open for three weeks, and a RAIV is a weekend build.

Any politician who says “we had no time” and ships this archive across the Atlantic is choosing the one option that makes the German national security damage even larger and more permanent.

My ask for the Thursday group is one sentence: which tool, where does it run, and who gets that ranked list?

Berlin Breach Turns 21: IT Says It Follows Orders and Only Vendors Can Change Admin Passwords

The Berlin Senate was saying the theft amounted to at most 215,000 records until Friday afternoon. After 15:35 the Rhysida countdown ran out and the state began downloading its own files. That is how Berlin learned what it lost.

Florian Hauer, state secretary for digitalisation, told the interior committee on Monday:

“Was tatsächlich abgeflossen ist, wissen wir positiv erst seit Freitag 15.35 Uhr. Bis Freitag waren die Informationen, die wir hatten, der Index, den die Täter ins Darknet gestellt hatten.”

What actually left, we know for certain only since Friday 15:35. Until Friday, the information we had was the index the perpetrators had posted on the darknet.

Last week this blog asked the Senate to publish how much data left the network between 7 and 12 August, or admit it can’t.

Hauer admitted it.

The state isn’t able to assess its own exfiltration without help from the attackers, since its count came first from the attack catalogue and then from the actual attack files. The download alone, he said, would take days. Why? Is that because Copperhead Dobrindt blocked fiber speeds, personally slowing Germany down?

Hauer says the Landeskriminalamt is reading the dump alongside an unspecified AI sorting for classification markings. Reviewing what attackers publish is fine. Having nothing else to review is…not. Berlin claims no record of its own traffic, weighting investigations on whatever Rhysida chose to post. Berlin asks the bank robber for a copy of selfies because their own cameras were off and they never kept a vault ledger.

Twenty-One Systems

Then Maria Borelli, head of the state IT agency ITDZ, took the microphone.

“Wir haben alle Fachverfahren, die bei uns in Betrieb sind, haben wir die administrativen Passwörter bereits geändert, bis auf 21 Verfahren, wo das nicht möglich ist, weil das Passwort fest verdrahtet ist in dem Quellcode. Das heißt, es ist nur mit Unterstützung des Softwareherstellers möglich, das zu tun.”

For all the specialist applications we operate, we have already changed the administrative passwords, except for 21 applications where that is impossible, because the password is hardwired in the source code. That means it can only be done with the support of the software vendor.

Administrative credentials. Hardcoded. No rotation in sight.

Twenty-one systems that ITDZ itself runs, three weeks after discovery, with the vendor as the only path to rotation and no date offered.

Rhysida’s second package on Sunday night carried login credentials.

Joachim Selzer of the Chaos Computer Club said passwords from the first pre-release two weeks ago still opened the published systems the following Wednesday.

The first post in this series argued the laughter over weak passwords was a cover story for 8,110 critical infrastructure documents walking out the door.

I stand by that assessment. These 21 are a very different animal from the joking around with Ahabostsee123. A user picks a weak password and there’s in-built agility to rotate it, usually required by regulations.

The open question is why Germany in this day and age allows a vendor to have an admin password nobody can change, what procurement office signs for that, and which operator ran it for years without formal complaint (e.g. audits).

Any credential Rhysida captured for those hardcoded admin systems depends now on a vendor, if they even exist anymore, shipping code.

Note that we are making an assumption about the number. ITDZ can count 21 among the systems in its own care. The Left’s working-group audit found the Land has no inventory of applications on its network, and Hauer told parliament in August he was “surprised how big” the state IT system is.

It’s only big in a relative sense. If you don’t have a working inventory management system it’s always too big. Twenty-one is the figure from someone who kept track. Now we are wondering about the Land systems uncounted, and their password age that nobody has checked.

Radioactive reaction

Borelli opened her answer with a sentence about how ITDZ fits into the response:

“Aktuell agieren wir reaktiv, das heißt, wir reagieren auf explizite Anweisungen des Landes.”

Currently we are acting reactively, meaning we respond to explicit instructions from the Land.

The operator of the state network, during an active incident, describes itself to parliament like an obedient cog that merely turns as it is told, waiting for orders. That is the failure mode already described in the earlier post: security run as a service line inside an agency expected to turn a profit, the profit taxed, responsibility split between the agency, a chancellery commissioner, a security officer in every ministry and twelve districts.

That’s not a healthy environment for security to improve.

Bavaria gave its state security office a legal mandate over the whole network in 2017. Berlin’s equivalent explains that it has no initiative or ideas, and merely changes passwords when told to by people who don’t even know how many passwords exist.

In November 2024 Borelli told the digital affairs committee that cutting detection spend would produce “the risk of cyberattacks or errors.” That was right.

In September 2026 she tells the committee her agency is in “exchange” with the vendors and the security office on how to proceed with the 21 systems, now that the prediction has landed and it’s too late.

Monday run down

One answer on Monday placed the stolen data, “to my understanding,” on employees’ personal drives.

Bianca Kastl of the CCC, live-tooting the hearing, pointed at the leak’s own directory tree: “Personalangelegenheiten / GI-Vertraulich / 00_alt”. That’s personnel matters, classified confidential, archive folder. That has the hallmarks of a departmental share, which if so would be the third official account of this breach corrected by the dump itself, after “no sensitive data” on 19 August was completely wrong and the 215,000 figure changed on Friday.

A member asked whether the E-Akte, the electronic file system the Land is rolling out across its administration, is built so that a single admin account is unable to download everything. Kastl reports there is no answer. The E-Akte by design pulls copies out of distributed systems of varying security and joins them at one point. That looks to be where the 8,110 infrastructure files go next.

BSI president Claudia Plattner reached for platitudes and said Germany needs passkeys and real zero-trust architectures, “and that applies to all of Germany.” Marketing buzzwords are buzzwords. Passkeys and Zero-Trust are terms used for selling not for actual securing. Agility is the proper term for the rotation capability, without the downsides to Passkeys. RBAC projects will make all the Zero-Trust products look like bicycles on the Autobahn.

Hauer said further checks will “most probably” surface structural deficits that arose years ago, and that fixing them “will not cost little money.” Well, well they sure will cost a lot less money than NOT doing them. That’s how security usually works when it’s run right. Spend now or spend way more later. The money in November 2024 was yanked out under a coalition that is now asking for it back just thirteen days before the election.

The Left and Greens have an Aktuelle Stunde on Thursday.

The FDP wants an inquiry and two resignations. Let the politics run its course. The engineering here is much smaller and it shouldn’t matter who wins. At least twenty-one admin passwords are vendor dependencies, and if any of them sit in what Rhysida took, they belong to whoever reads the dump. The Land’s own operator has said on video that it is just following orders and can’t know or do what’s right on its own.

Every candidate for the Rotes Rathaus should be asked who is investigating, where the data flows, which systems and by what date will be burned to the ground and replaced.

Every Tesla Musk Declared Would “Appreciate” Lost More Than Half Its Value

April 2019 was when Elon Musk told Tesla buyers the normal rules of car ownership no longer applied to them. Do you remember? Did you buy a Tesla?

Speaking on Lex Fridman’s podcast, he said buying a Tesla was an investment in the future:

I believe you are buying an appreciating asset – not a depreciating asset

His claim was pumping the Full Self-Driving computer and a promised robotaxi network. He put a number on it that July, tweeting about any Tesla with the FSD package that his dream of autonomy (already years past when he promised it would arrive):

should be worth $100k to $200k

He was still repeating the pitch on the Q3 2023 earnings call, saying each car with autonomy hardware “may be worth five times what it is today.”

Five times! The con artist.

His cars built under his promise have now aged five years, and iSeeCars’ analysis of over 950,000 used sales from March 2025 to February 2026 puts the Model Y at 57.8% depreciation, the Model X at 61.2% (roughly $61,000 lost per car) and the Model S at 62.0% — three of the fifteen worst-holding vehicles in the entire market, worse than the Range Rover and the BMW 7 Series.

Source: Visual Capitalist

The WORST depreciation in the market.

Robotaxis never came, of course, FSD is crashing and killing more people than ever, and Tesla itself slashed the FSD price by a third in 2023 shortly after Musk called the price a temporary low, on top of the new-car price cuts that cratered used values.

Tesla’s own reports to NHTSA under the Standing General Order. January through June crashes, 2022 to 2026: 180, 261, 269, 476, 826. A 4.6x rise over five years. The increase from 2025 to 2026 alone (350) is nearly double the 2022 total for the same six months. May 2026 set the single-month record at 207. Source: Electrek

A CEO who repeatedly told customers and investors that a mass-produced car would gain value, that he would solve driverless next year, then took the actions that guaranteed it would not, has delivered only the opposite of what he sold.

He was born with a silver spoon into a Nazi family, fled the rise of democracy in 1988 to illegally immigrate and launder his family apartheid money through American lack of tech regulation (PayPal), and now stands as one of the worst humans in history. His legacy, given global authoritarian platforms funded with ill-gained Tesla money, is predicted worse than Stalin:

14 million dead projected by 2030 (interval 8.5-19.7 million)

Source: Joe Rogan show
Leader of AfD celebrating her election victory in the German state of Saxony-Anhalt. Elon Musk replying to her in German, "Well done!"
Source: Twitter