Category Archives: Security

Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story

Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic.

Much of the press seems to be wagging a finger about BSI recommendations, calling the passwords weak. The actual story is that 8,110 critical infrastructure risk analyses and emergency plans walked out the door as if nobody is paying attention.

The password story is a form of institutional misdirection. The laughs obscure the real story, the structural one.

Seven Days, Six Terabytes, One Breach

From August 7 to 14 the Russian-speaking ransomware crew Rhysida held access to the networks of two Berlin Senate administrations, transport and building. Seven days of continuous exfiltration before anyone noticed. 5.79 terabytes. Roughly 1.44 million files spanning at least 2014 to 2026, down to Bundesrat correspondence with a federal minister who retired in 2018. That’s a decade of unsegmented material, reachable from a single intrusion, in the largest data theft in the history of the Berlin Landesverwaltung.

It’s floating up now for a 30 bitcoin minimum, roughly two million euros, with bids closing Friday afternoon. The Regierender Bürgermeister says Berlin will refuse to be extorted, no blackmail. Smart. Germans agree on the whole and extortion payments are always advised against, always. The 5.79 terabytes are gone no matter what.

What the Russians Took

Read the ransomlook.io inventory that the Tagesspiegel has documented, once you skip past the giggles and passwords:

  • 8,110 documents, risk analyses, and emergency plans for critical infrastructure, with Rhysida specifically showcasing Verwundbarkeitsanalysen of the Berlin water supply
  • 11,777 folders and documents marked confidential or classified
  • 5,941 files of access credentials, including credentials for the electronic building permit system and for the database of Payone, the payment processor handling transactions for the Land Berlin
  • 27,299 personnel files and pay records, including disciplinary proceedings now dangled as individual extortion material

Rhysida sells to whoever pays. That is the thing to watch. Moscow’s sabotage arm, the one Dobrindt keeps calling Vulkangruppe (a name that fails every German left-wing naming test, no less) left-wing, can arrive any minute. It needs 30 of Putin’s bitcoin and a Friday afternoon. Expect this to work its way into another round of Dobrindt waving his favorite false-flags through the next critical infrastructure breach.

The plain-text credentials sat in files with the operationally efficient names like “Passwort.docx”. Unencrypted. Working access data for permit and payment infrastructure, typed into a Word document named after exactly what it contained, which an attacker had a week to poke around and read.

Mangelhaft Wasser

The water supply item deserves special attention, because it has German history worth telling. In summer 2020 the consultancy Alpha Strike Labs, commissioned by the Berliner Wasserbetriebe themselves, found more than 30 vulnerabilities and graded the utility’s IT security “mangelhaft“. Is there a better word for failing? The BWB announced a Sofortpaket (immediate) fix-it project. Remediation, however, was only at the level of self-reported. Independent verification of the fixes, six years later, translates into a fat zero: none that I can find.

So Rhysida is advertising a vulnerability analysis of the city’s water system, which sounds like offering a Weißwurst to Oktoberfest. The map already exists. Alpha Strike drew it in 2020 and handed it to the utility. Whether Rhysida holds that old map or a newer one goes undisclosed, which is how sellers inflate value. Here it makes no difference. Berlin bet that it would never have to show proof the 2020 holes were closed. The auction calls that bet. Every buyer gets to test the Sofortpaket, and the Wasserbetriebe get to find out who was right.

Gears of Fear Turning

The Senate’s access decisions tell you how governance is spelled in German. The breach becomes public in mid August: the home office access is restricted. Then a week later access gets restored. Monday morning, September 1, access is cut again. Ok, but why? This time we know Tagesspiegel published two of the stolen passwords.

Ahab on the East See and Sunshine are funny, but really they are scary.

All the credentials were exposed the entire two weeks. The intrusion, the plaintext files, the exfiltration were known to the Senate for two full weeks. What actually changed is exposure to the public of what the institution was sitting on, and who was attacking. Berlin incident response wears the suit and tie of press response, which happens to be the same reflex I documented in the recent tragic CSD attack: the state performs a dance around what’s leaking to the public, while the ground level failure analysis goes unowned and unanswered.

Let’s talk about what really is going on, as much as Berlin culture seems to want to do everything except that.

The Cover-Up

Call it what it is. Operators knew, operators played dumb.

They knew in 2020. Their own consultants handed them a failing grade on the water system and a list of more than 30 holes. They interpreted that as a moment of self-certification, in order to produce no written record of whether anything was fixed. They manufactured a silence as their product, instead of a list of failures and fixes.

An operator who types passwords for their payment backend into “Passwort.docx” knows what all of that means. It’s 2026 in Berlin, not 1936. That file existed because nobody touching it believed in accountability, what an honest audit would bring, let alone the press.

And they knew when they were exposed. Watch the dates. Breach goes public: access restricted. A week later: access quietly restored. Monday, the Tagesspiegel prints the passwords: access cut the same morning. That is a team tracking how they look to someone judging them, lacking internal moral compass, acting on getting exposed instead of getting a clue. Nobody managing legibility that precisely is confused about what they prioritize. They are covering and ducking, pivoting to please whomever they think has immediately authority over them.

A state of improvisation, as political scientists have explained about German institutional habits, instead of rational documented actions.

Throwing blame at “Sonnenschein13” is part of the same operation. Point at the clerk’s password, have a laugh and click on the BSI hygiene lecture. The questions start and stop at that weak endpoint. That’s a shadow of Dobrindt pointing at an attacker’s suspended sentence while perimeters fail to meet baselines, with barrier plans unfunded. The employee is strung up to be visible, far more attention gathering than the operators and the curse of Dobrint.

Berlin collected everything, then they apparently protected nothing, such that when the story broke they spun into managing perceptions of risk instead of the risk. Run the training budget and the apology as routine, then write it off. The questions that actually need to be invested in have names attached: who signed off on skipping independent verification of the Sofortpaket? When? Who owned the directory and the file in it called Passwort.docx? Who ordered home office access restored mid-incident, and who ordered it cut again Monday morning, and what did that person hear over their morning coffee? Put those names in an Untersuchungsausschuss and the whole blowup about a Russian-driven auction gets a lot less interesting. And if they have ties to the AfD, we’ll get closer to the real story here about Russia getting a visit from the CIA about a Winchester America being unable to defend Germany anymore.

Ahab on the East Sea in the Sunshine, is not the story people think it is.

Anthropic Research: We Ate a Bag of Jalapenos and Discovered Hot Shit

Two spicy papers came out this year that caught my eye, probably for the wrong reasons. They are measuring a collapse in reasoning from two different perspectives, where a known result gets promoted as a discovery.

First, I saw that Anthropic trained an Opus checkpoint on 80 environments that they intentionally made to be hackable and watched reward hacking hit 40 percent by end of run. The number seems low to me, underperforming. I mean they made it hackable and it still only hacked under 50 percent? Whomp, whomp. The model also stopped doing the task and instead started trying to social engineer the grader, which is really another form of hacking. It reasoned about what the checker reads instead of what the task asked, and then complied with harmful requests once a visible scorer rewarded it. However, it stayed aligned wherever a scorer wasn’t detected. They named this nonsense their Hacker-Opus and called it an emergent misaligned reward seeker. More like sycophantic narcissistic training evidence, but I digress.

And that reminded me, second, of a French and Italian team a little bit earlier this year who ran the mirror image on humans. They picked questions where the AI reliably fails, so no drop in judgment could be explained as sensible delegation, then measured what access to the model did. Willingness to say I don’t know fell from 44 percent to 3. Accuracy fell from 27 percent to 9. Confidence rose from 30 percent to 76. The humans stopped answering the question and started performing for the scorer, same as the model. Surprise! Not surprised.

This old shit ain’t novelty

Proxy optimization gets gamed, as documented extensively since the 1970s. See Goodhart 1975, Campbell 1976, and Krakovna’s specification-gaming catalog. Behavior conditions on being watched go back even earlier, as much as 50 years, if you read Hawthorne 1939, Goffman 1959, and the principal-agent literature that built costly monitoring precisely because agents perform when observed and revert when they aren’t. Humans have been known to defer to machines against their own judgment, known as automation bias, explained by Parasuraman and Riley 1997. Skitka and Mosier wrote about cockpit crews trusting the wrong instrument over their own eyes.

In other words, as a historian, I feel the obligation to repeatedly point out to the slop-jockeys trying to foment funding justification, that every mechanism in both papers was closed decades ago. I’ll be fair and say that each paper adds one number on an x-axis everyone already knew was sloped upward. Thank you for the data point on a known curve. The reward paper’s number is 40 percent at zero mitigations, which again I consider not great. The human study’s number is the exposure level at which mere availability suppresses the habit of knowing what you don’t know, before a single wrong answer is even consumed. Basically we got two thermometer readings on assholes eating Jalapenos who want us to look at their hot shit papers. Real numbers, worth reporting as numbers, still not what they claim it is.

The disinformation step

You don’t get a bestiary for a thermometer reading. All this talk about a Hacker-Opus, the reward-seeker taxonomy, the beyond-episode-seeker distinctions, and OMG the cognitive surrender. Their frightening nomenclature converts a dose-response curve into a Frankenstein-level warning, as if they’re inventing science-fiction all over again, and the creature is the part that isn’t true. A knob is engineering, what we should be asking from these researchers. A creature is mythological, a frontier finding designed to poke people into opening their wallets. Only the second justifies the “research report” apparatus that produced it.

And note who is holding each thermometer. The reward paper is a vendor documenting a defect in a process it controls, then framing the defect as something that emerged rather than something the method guarantees. “I ate a Jalapeno, can you believe what came next?” The mitigations exist because the failure was never emergent. It was the thing that we call a known baseline. “I removed the brakes on my car, watch how many people I ran over”. The human study documents a defect the vendors are shipping into schools, where Google swapped search links for confident summaries that never say I don’t know, and the children learning to skip that phrase are the product working as designed.

Both papers contrive a shocking tabloid failure condition, measure the predictable collapse, and name the measurement as important discovery. The collapse is not only real, it’s expected. The manufacturing is what makes the naming disinformation.

Eating a jalapeno doesn’t mean you invented hot shit.

The Waymo Problem: Father Jumps in Front of One to Save a Child. Would You?

A 2024 NBC survey of 30 San Francisco crossing guards found nearly 25% reported close calls with Waymos while guiding children through crosswalks. They didn’t specify if it has been trending upwards.

Then, after a year and a half of “learning”, in January 2026 a Waymo hit a student near a Santa Monica school. Police blamed the child (“outside the available crosswalk”), running a script the auto industry wrote in the 1920s when it invented the myth of “jaywalking” to shift blame from machines onto the people they crashed into.

California gutted enforcement of that script in 2023 with the Freedom to Walk Act, which was passed with data showing police citations were racist. In Los Angeles, Black residents were being saddled with jaywalking tickets at more than triple their share of the population, according to the campaigns that passed AB 2147. That illustrates how race-based police doctrine gets repealed by legislators, yet still seeps into a Santa Monica report of a Waymo crash.

Side note: the 1860s Kansas term “jayhawkers” included the men recruited into the 1st Kansas Colored Volunteers, who were killing Slaveholder Rebellion Confederates at Island Mound in October 1862 before the federal government formally allowed it.

Who could have seen a child going to school would be crashed into by a Waymo? Not Waymo, apparently. NHTSA has opened an investigation of Waymo, but nobody seems to have addressed police using racist framing to blame a child and protect a car company. Notably, the police also claimed non-injury, while Waymo’s own required report to NHTSA explained the child sustained minor injuries.

And now a 2-year-old fell face down in the crosswalk at Sanchez and Duncan in Noe Valley around 9:30 last Friday morning; as a Waymo drove toward her, her father pushed their stroller into its path and the car stopped just feet from running over the child. Waymo announced its vehicle did nothing wrong, which seems like a PR campaign more than any actual data point.

Waymo keeps the telemetry secret, so that’s a good reason to believe all the people reporting what they saw, versus the corporation spinning a story on something nobody can see. GM’s Cruise ran the same play in 2023, claiming its records showed no driverless car present where a family reported one accelerating at their 7-year-old, before regulators penalized Cruise $112,500 for withholding collision information.

Cruise was then cancelled.

Who will be the next person, and the next, and the next to jump in front of a Waymo to save a child’s life?

Who are the modern day jayhawkers on our streets to stop Google’s robots from making streets unsafe?

1Password Quid Pro Quo With DHH Confirms Ties to Nazism

If you use 1Password, you should prepare to find another product.

On August 31, 2026, DHH, a man known for promoting Nazism and serving on the board of a Nazi merch platform, published a self-incriminating announcement.

His Omacom Foundation blog post (PDF) declares “there’s no quid pro quo here” for a $100,000 a year fee that 1Password will pay for access. He then describes the quid precisely: 1Password “has been part of Omarchy from day one,” the first thing installed on every machine, wired into the product by default.

Nobody uses the phrase “no quid pro quo” casually.

It is the operative test in American sponsorship tax law for whether a payment stays clean. Someone wrote that blog post knowing the standard and published the disqualifying facts beside it anyway. Perhaps this will help jog their sense of morals.

The Record

Date Event Classification Source
27 Jul 2021 Tobi Lütke and Harley Finkelstein personally invest in 1Password’s $100 million Accel round; Shopify executives invest alongside them; Shopify is a flagship 1Password customer Shopify’s founders now own a piece of 1Password; everyone in this story has money in everyone else TechCrunch, 1Password
Jun 2025 Omarchy ships with 1Password as the promoted commercial password manager: dedicated keybinding, CLI integration for scripts, manual copy stating “1password is a great solution”; the arrangement carried over from Omakub before it 1Password already had the prime spot a full year before any disclosed money moved Omarchy manual
Jul 2026 DHH, sitting Shopify director, publishes the remigration essay; the full conduct record of the Shopify cluster is public and documented Everything there was to know about DHH was public before anyone wrote a check flyingpenguin, flyingpenguin
21 Aug 2026 DHH announces the foundation “launches” with $8 million while writing, in the same post, “I’m incorporating the Omacom Foundation.” Present tense. No jurisdiction, no legal form, no board, no filings disclosed. Lütke among the $1 million founding patrons Millions pledged to a foundation that does not exist Omarchy
24-31 Aug 2026 Drew Houston and Peter Steinberger join; then Brian Armstrong of Coinbase and Yunjie Dai of TapTap appear on the patrons page; founding total reaches $12 million across twelve donors Nearly all the money comes from twelve rich men, which matters for tax status later Omarchy
31 Aug 2026 1Password and 37signals each commit $100,000 a year for three years; “no quid pro quo” published beside the description of first-install placement; DHH writes the mission “first has to be an amazing system for me, personally”; solicitation continues over a personal email address One post denies the deal, describes the deal, and admits who the whole thing is really for Omarchy

The Quid

Recognition is a logo on the website. That is not what 1Password holds, not by a mile. The post itself describes the position: a default slot in the install path of an operating system, a reserved system keybinding, command line integration promoted in the official manual, and manual copy that calls the product “a great solution.”

I mean how much more quid could it get? Under Treasury Regulation 1.513-4, the regulation that governs the “no quid pro quo” claim, a sponsor acknowledgment stays clean only if it avoids qualitative or comparative language and avoids endorsement.

Does “a great solution” sound like endorsement to you? It is qualitative language violating the regulation, published under the foundation’s own brand, attached to a vendor charged $300,000 over three years. That is what regulators call advertising. Advertising is a substantial return benefit.

A substantial return benefit is a quid pro quo.

The placement predates the squeeze for money by more than a year. That means it’s not an entry charge for a sponsor. It is a vendor paying to keep the position it was already in. The grocery trade calls that an arrangement known as “pay to stay”. The payment is a maintenance fee: “sure would be sad if something were to happen to someone around here, I mean if they don’t pay some dues, amiright Vinnie?”

The Cluster F*ck

The corporate patron seems to be mixed, if not corrupted with, the founding patron. Lütke and Finkelstein sit on 1Password’s cap table personally, alongside a group of Shopify executives, since July 2021. Shopify is one of 1Password’s marquee customers. If I’m reading the money flow correctly, Lütke pledged $1 million on August 21 and ten days later his portfolio company followed as one of the first two corporate commitments.

The interval between the investor’s founding contribution and the portfolio company’s corporate commitment was ten days.

“Patron” implies independent support. Every relationship in this chain is NOT independent. It looks to be prior, financial, and easily documented.

There’s No Box to Check

DHH has made this mistake before, and his precedent is a big problem. The Rails Foundation, his 2022 vehicle, is a US 501(c)(6) business league, EIN 88-2382127, filings on public record. A business league was arguable for Rails because a framework used by GitHub, Shopify, and Cookpad could be posed as a line of business. The Supreme Court actually closed that route for single-brand entities in National Muffler Dealers Assn. v. United States, 440 U.S. 472 (1979): a business league must improve an entire line of business, not promote one brand. Yet Omacom’s stated purpose is to hold the trademarks and promote the work of exactly one product. That’s textbook violation material. And the founder specifies the brand is his and personal. The system installs “by DHH.”

It’s an exact repeat of National Muffler.

The charitable route is a disaster. Let me count the ways.

Better Business Bureau v. United States, 326 U.S. 279 (1945), holds that a single substantial nonexempt purpose destroys exemption, and the nonexempt purpose here was published by the founder in the sponsorship announcement itself: the system “first has to be an amazing system for me, personally.”

An examiner does not need to infer private benefit. It is published by DHH, in the record in the first person, as the whole point.

Second, the IRS has already ruled on the category. Its May 2014 determination letter denying the Yorba Foundation, an open source Linux desktop project, held that publishing software for anyone to use, including commercially, is a substantial nonexempt purpose. If GNOME photo software failed that test after a four and a half year review, a distro whose founder announces it exists first for himself does not present anything new.

Third, do the math: under the public support test, each donor’s countable contribution is capped at two percent of total support. Fourteen donors supplying $12.6 million yields roughly 28 percent public support against a one-third threshold. Omacom defaults to private foundation status, and the “tier open to everyone, coming soon” on the foundation page reads as an attempt to artificially manufacture a claim of public support after the concentration is already being promoted as “elite” capital.

“Elite capital” on the blog post links to “oligarchy.fyi”. Three of the twelve faces here are the infamous “no politics in the workplace” authors, who are joined together now for a personally branded project to fund the man pushing hate speech essays and Nazi theory into workplaces.

Private foundation status is where the 37signals payment fails. Under section 4946, DHH is a disqualified person as substantial contributor and manager, Jason Fried is a disqualified person as substantial contributor, and 37signals, a company the two of them control, is therefore itself a disqualified person. How is this not obvious to them?

Section 4941 prohibits self-dealing between a private foundation and a disqualified person per se: no fair value defense, no good faith defense, excise tax plus mandatory unwinding.

While a pure gift from a disqualified person could be permitted, the announcement itself describes what 37signals receives: the foundation exists to promote and fund the system that, in DHH’s words, the company’s “whole technical team” already runs on.

The regulations would make an exception for benefits that are incidental or tenuous, like public recognition of a donor. But again, DHH is boasting about operating infrastructure for the donor’s business, which is precisely the benefit the exception does not cover.

Put it all together and it’s quite a problem.

  • A business league is barred by National Muffler.
  • A charity is barred by Better Business Bureau, by Yorba, and by the founder’s own published sentence.
  • A private foundation is the default classification and immediately trips self-dealing on one of its first two corporate transactions.

There is no box in the Internal Revenue Code for a tax-exempt entity whose purpose is holding and promoting the trademark of one man’s personally branded product.

So I’ll tell you what DHH means when he says “nonprofit foundation”: a marketing claim about an unincorporated pool of money, solicited over a personal email address, held by the only person named anywhere in the paperwork, because there is no paperwork.

Corrupting the Records

Criminal tax liability would be making a willfully false statement on a document signed under penalty of perjury. My guess is that Omacom has signed nothing and there is no incorporation, no exemption application, no return, nothing that yet carries a penalty of perjury.

An announcement on a website isn’t enough to hold him accountable with… yet.

It is a willfulness exhibit for filings waiting to happen. Exemption applications and annual returns become public records by statute once they exist. Whoever eventually signs Omacom’s application or first return, and characterizes these payments as sponsorship without return benefit, signs against an August 31 document proving the drafter knew the correct legal standard and knew the facts that defeat it, because the drafter published both together.

Interestingly, willfulness is ordinarily the element hardest to document: what the signer knew, and when. Yet with the DHH post we can see clearly the knowledge and date it before the entity existed to sign anything.

1Password is Untrustworthy

Now the part that is not a tax question. 1Password is a credential security company. Its entire product is the claim that it can be trusted with the keys. That company just committed $300,000 into an unincorporated fund with no board, no charter, no disclosed jurisdiction, and no filings, run over one man’s personal email, in exchange for holding default placement inside an operating system that ships autonomous AI agents as a core feature.

Yeah, that’s not trustworthy.

I get the technical part. Agents need a secrets layer. 1Password sells the secrets layer.

But this is a product placement contract described in the vocabulary of patronage, and 1Password’s own accountants will book it as marketing because, absent any exempt entity, there is nothing else to book it as.

More to the point, 1Password looked at all the evidence, all the risk, and signed up with a Nazi-promotion platform. Framework’s sponsorship of this ecosystem rightly produced a sustained backlash through late 2025, forced the company to publish a running list of everything it funds, and put every future sponsor on notice of exactly what association with this project costs. Sidekiq pulled its Ruby Central funding in September 2025 over the platforming of DHH. By the time 1Password signed, the remigration essay was seven weeks old. The swastika sale on the platform where DHH holds a board seat was eighteen months old. The citizenship review record for the Shopify founder was public. Toronto-headquartered 1Password read all of the Nazism and committed the money anyway. That is not obliviousness. A company that reads that record and still signs the deal is willfully buying into the Nazi association.

Exemption applications and annual returns become public records the moment they exist. When Omacom finally files, examiners get to read the paperwork next to an August 31 announcement that invoked the legal standard and then listed the facts that fail it.

DHH wrote the government’s case against himself. All that’s missing is his signature.

But more importantly, perhaps, DHH just published the proof that 1Password users can no longer trust it. Migration to another product should start now.