Category Archives: Security

DHH Nazism Funded by 1Password VP Who Wrote “Honest Security”

Jason Meller wrote a security rulebook. I read it. He is in direct violation of it.

As CEO of Kolide, Meller published honest.security and reduced it to five tenets on December 8, 2020.

The first: “The values your organization stands behind should be well-represented in your security program.” That’s politics at work. The third holds that trust is demonstrated through informed consent and transparency. The fifth holds that people make rational decisions about risk when they are educated and honestly motivated. Then 1Password, whose 2021 round was joined personally by Shopify’s Tobi Lütke and Harley Finkelstein, the executives who platformed Nazi merchandise and seated David Heinemeier Hansson (DHH) on their board, bought Kolide in February 2024, made Meller VP of Product, and still publishes the document as the guiding principles of its Device Trust product.

Houston, we have a problem.

DHH published his infamous Nazi screed called “As I remember London” on September 15, 2025. The post mourns a London no longer full of “native” British and approves a right-wing Tommy Robinson march promoting white supremacy. That was his launch, and then came his landing the following July.

Meller answered the criticism of DHH on September 26 with a photo of a child in a dance costume, back turned to the camera, at the edge of a lifeless/closed private pool. With that he boasted he became a multi-millionaire thanks to Rails, DHH, and the company DHH keeps: “Let’s ignore the noise and keep building.”

Source: Twitter

He posted that as a director of the Rails Foundation, which DHH chairs. 1Password had taken a board seat in 2024 and Meller filled it with his “values”.

On July 12, 2026, DHH published The will to power will return.” He tries to gin up a “loss” narrative to evoke FUD, claiming the West has lost its will, weak men have made hard times, a hero generation will end the managed decline, and the last such Crisis ended in total war, so do not bet against another. That title is Nietzsche’s phrase fraudulently repackaged by his antisemitic sister Elisabeth Förster-Nietzsche: she made a posthumous compilation cut from his notebooks into a racist doctrine of strength over weakness, which was adopted by the Nazis. It has been treated by scholars as hers rather than the philosopher’s since the Colli-Montinari edition. This isn’t obscure history. Hitler ran PR at her Weimar archive in 1934, photographed at the door taking her hands, and photographed inside contemplating the bust of her brother.

Elisabeth Förster-Nietzsche happily welcomes Hitler at the door of the Nietzsche-Archiv, Weimar, 1934, offering him a warm smile and both hands. Source: Germanisches Nationalmuseum, Deutsches Kunstarchiv, http://www.gnm.de/museum/abteilungen-anlaufstellen/deutsches-kunstarchiv/

Days later DHH published the word remigration, Martin Sellner’s Potsdam term for forced deportation of settled populations, documented here at the time.

On July 21, 2026, DHH doubled-down on the Nazism with “Wolves, sheep, and gypsies.” He describes Romani people in Copenhagen parks beside a wolf population and states the remedy for one is shooting and the remedy for the other is deportation. Make no mistake. DHH pushes the dehumanization of an ethnic group in preparation for its removal on force of death. It is the rhetoric that preceded the Porajmos. DHH then complained publicly when Claude refused to translate his Nazi propaganda into Italian.

On August 31, 2026, DHH named 1Password a Distinguished Corporate Patron of his Omacom Foundation, $100,000 a year for three years, in a quid pro quo he described the same afternoon as proof open source need not be a “commune.”

This dog-whistle invokes Nazi anti-communism, an antisemitic project from the start: the NSDAP fused Jews and the labor movement into one enemy, “Jewish Bolshevism,” and Rosenberg’s 1936 Nuremberg speech made the equation explicit. Seven weeks after the will-to-power essay, DHH reached for the commune as his enemy image on the day he took 1Password’s money.

Source: Twitter

1Password is the first corporate patron he does not own, and the independence ends there. Lütke, on 1Password’s cap table since 2021, pledged $1 million on August 21. His portfolio company followed in ten days. The quid was the default install slot 1Password had held since Omakub. DHH thanked Meller by name for leading it.

Meller had already explained the bond the evening before: DHH pitched him one-on-one for two hours, and he switched to Mac for Rails and DHH seventeen years ago and is switching platforms again for him now.

Source: Twitter

Then he called DHH’s past year a masterclass in force of will. Nine days before the deportation post, DHH’s own headline had announced the return of the will to power. The phrase is his patron’s, seven weeks on.

Jason Meller, VP of Product at 1Password, August 30, 2026. “Force of will” repeats the title DHH gave his July 12 essay, nine days before the Romani post. The 1935 film title was Triumph of the Will.

On August 31 Meller produced the metric that became the company’s defense: Omarchy is the third largest Linux distribution among active 1Password users and first on weekends. DHH called it crazy. A fan called it his cocaine energy. You know, weekend stuff.

Source: Twitter

When employees and customers objected, this data point was cited. CEO David Faugno told staff the money goes to a foundation and not a person (e.g. to a NSDAP not to Hitler himself), that 1Password rejects DHH’s exclusionary views, and that Omarchy is a top Linux platform for its users. Cofounder Roustem Karimov, in a Slack message obtained by The Verge, accused objecting staff of trying to setup a moral monopoly and ostracizing colleagues by rejecting Nazism.

Now back to those tenets.

Tenet one. Values the organization stands behind, represented in the security program. The CEO says the company rejects DHH’s views. The VP of Product funds them, celebrates them, and sits on a board DHH chairs. One of those is the value the organization stands behind. The money identifies which.

Tenet three. Trust through informed consent and transparency. The pledge was announced by DHH, on DHH’s platform, with the objections handled afterward in private Slack. Employees learned of the affiliation the way everyone else did. Consent was never sought. Transparency arrived through a leak.

Tenet five. People make rational decisions when educated and honestly motivated. The employees and customers who objected read the two posts and decided. Meller’s word for that decision in 2025 was noise. Karimov’s word in 2026 was moral monopoly. The doctrine says respect the informed decision. The practice says discredit it.

Meller’s method is the same on both dates. He never engages the text. He recodes the objection as noise or as shots taken, then answers with a number: his net worth in 2025, weekend install counts in 2026. Honest Security was written against exactly that move. Its whole argument is that a security team which answers human objections with telemetry has already lost.

Every director of the Rails Foundation, every patron of Omacom, and every executive at 1Password now owns Nazi propaganda.

But Meller is different from everyone, because that guy owns them twice. He brokered the money and he wrote a standard that says Meller can’t be trusted.

Introducing RAIV: Redundant Array of Inexpensive Videocards

Since Wirken.AI supports open weights, the question comes up often how big can it go. Well, I lived and worked through the early 1990s of DEC Storageworks RAID, as pioneered in the early 1980s as disk shadowing on the HSC50/HSC70, and my mind immediately went to repeating the past.

Source: Internet search

Cheap datacenter GPUs are being sold used in volume. Pooling them for local inference is well documented, so we just need to think about the redundancy. This is a build with a mirror and a spare, the way we built disk shelves in the old days.

Introducing the Redundant Array of Inexpensive Videocards (RAIV).

AI dance all day
AI dance all night, all weights
local, all is right

Parts

Who knows where prices will go, but here we are in September 2026. The MI50 figure is Pillitteri’s August survey; the board and CPU combo is the going rate from online markets.

Qty Item Unit Line Note
7 AMD Instinct MI50 32GB, used €220 €1,540 6 in two mirrored groups of 3, plus 1 spare. Verify 32GB on each.
1 Supermicro H12SSL-i + EPYC 7302, used €900 €900 5 x16 + 2 x8 PCIe 4.0 slots. Any 7002-series EPYC is fine.
4 16GB DDR4-3200 ECC RDIMM, used €30 €120 64GB. More only if you offload to CPU.
1 2TB NVMe €120 €120 Model storage.
2 1,200W ATX PSU, 80+ Gold €180 €360 Each card needs two 8-pin. Split cards across supplies. Add2PSU adapter to sync.
7 PCIe 4.0 x16 riser cable, 30cm €35 €245 Double-width cards will not sit in adjacent slots. Risers space them out.
7 MI50 fan shroud + 40mm server fan €15 €105 3D-printed shrouds are on Printables; Delta or Sunon fans.
1 Open GPU frame, 8 slot €60 €60 Mining frame. A 4U case works if you have the rack depth.
1 Fan controller, PWM, 8 channel €25 €25 Server fans at full speed are unpleasant.
1 CPU cooler, SP3 €50 €50
Total ca. €3,530 96GB usable per mirror, 192GB across both, 32GB spare.

For comparison, one DGX Spark is 128GB for about $4,000. Two RTX PRO 6000 cards are 192GB for around $17,000.

Quality Test Purchase

Before you get a pack, try getting one card and testing it. Run rocm-smi –showmeminfo vram and confirm 32GB. Load a model that fills it and run for an hour. It’s a problem in the market that 16GB cards are listed as 32GB with modified firmware. When one passes, then you can feel better about getting six more from the same seller.

Board Setup

BIOS: enable Above 4G Decoding and Resizable BAR. Without them the cards do not enumerate; one builder replaced a motherboard over this. Give each card an x16 or x8 slot. A card on a one-lane riser holds weights but cannot process a prompt at usable speed.

Given this isn’t fancy cooling, limit each card to about 150W with rocm-smi –setpoweroverdrive. Generation speed is limited by memory bandwidth, not compute, so this limit will affect little.

Software

Ubuntu 24.04. Do not install the ROCm SDK, since AMD in their vendor wisdom doesn’t support it; the ROCm 7.0 changelog reads painfully “Removed support for AMD Instinct MI50 and MI60.” Use one of the gfx906 llama.cpp containers that bundle the ROCm 7.2 runtime with kernels built for the card. The host needs the amdgpu driver and your user in the video group. The Vulkan build of llama.cpp is the fallback. Recent Ollama releases omit the gfx906 files; skip it.

Mirror and Spare

One model across all seven cards is a stripe. If a card fails, the process exits, and the model no longer fits. Ruh roh.

Split into two groups of three. Run two llama-server processes, one per group, each with its own copy of the model, on two ports. A 100B-class model at four-bit fits in 96GB with room for context. Put nginx or Caddy in front with a health check on /health and failover between backends.

The seventh card stays installed, powered, and idle. When a card in group A fails, the proxy serves from B. Move the spare into A’s group, restart A. One in-flight conversation is lost. Dance, dance, dance.

Test

Load both groups. Start a long generation on A. Pull the power lead on one of A’s cards. Time until the proxy serves from B. Restart A with the spare and time the reload. Record both.

Run all seven cards at full load for an hour and monitor the host: CPU temperature, VRM temperature, PCIe errors in dmesg.

Fun fact, in 1997 I built a fat Sun workstation to run a hospital’s massive StorageWorks shelf (fronting a huge robot arm that fed tapes from a room full of them) and the whole thing shut down under load from the Sparc (CPU) overheating, not from the disks. Ah, the good old days.

I found no published failover timings for a build like this, in any language. Let’s do this and publish some. Share and share alike.

Berliner Senat, Passwort.docx: Ahab Ostsee als Vertuschungsgeschichte

English | Deutsch

Die Russen lachen über Ahab Ostsee 1-2-3. Und dann noch Sonnenschein 13. Das waren Passwörter, die beim Einbruch in die Berliner Senatsverwaltung offengelegt wurden. “Ahabostsee123” ist tatsächlich eine Yacht für Urlaub auf der Ostsee.

Ein Großteil der Presse hebt den Zeigefinger, zitiert BSI-Empfehlungen und nennt die Passwörter schwach. Die eigentliche Geschichte: 8.110 Risikoanalysen und Notfallpläne für kritische Infrastruktur sind zur Tür hinausspaziert, als würde niemand hinsehen.

Die Passwort-Geschichte ist institutionelle Ablenkung. Das Gelächter verdeckt die wirkliche Geschichte, die strukturelle.

Sieben Tage, sechs Terabyte, ein Einbruch

Vom 7. bis 12. August zog die russischsprachige Ransomware-Gruppe Rhysida Daten aus den Netzen zweier Berliner Senatsverwaltungen ab, Verkehr und Bauen. Bemerkt hat es niemand vor dem 14. August. 5,79 Terabyte. Rund 1,44 Millionen Dateien, mindestens von 2014 bis 2026, bis hinunter zu Bundesratskorrespondenz mit einem Bundesminister, der 2018 in den Ruhestand ging. Ein Jahrzehnt unsegmentiertes Material, erreichbar über einen einzigen Einbruch, der größte Datendiebstahl in der Geschichte der Berliner Landesverwaltung.

Jetzt steht es zum Mindestgebot von 30 Bitcoin im Netz, rund zwei Millionen Euro, Gebotsschluss Freitagnachmittag. Der Regierende Bürgermeister sagt, Berlin lasse sich nicht erpressen. Klug. Die Deutschen sind sich da weitgehend einig, und von Lösegeldzahlungen wird immer abgeraten, immer. Die 5,79 Terabyte sind so oder so weg.

Was die Russen mitgenommen haben

Man lese das Inventar auf ransomlook.io, das der Tagesspiegel dokumentiert hat, sobald man an den Kicherern und Passwörtern vorbei ist:

  • 8.110 Dokumente, Risikoanalysen und Notfallpläne für kritische Infrastruktur, wobei Rhysida ausdrücklich Verwundbarkeitsanalysen der Berliner Wasserversorgung zur Schau stellt
  • 11.777 Ordner und Dokumente, als vertraulich oder als Verschlusssache eingestuft
  • 5.941 Dateien mit Zugangsdaten, darunter Zugänge zum elektronischen Baugenehmigungssystem und zur Datenbank von Payone, dem Zahlungsdienstleister für Transaktionen des Landes Berlin
  • 27.299 Personalakten und Gehaltsunterlagen, darunter Disziplinarverfahren, die jetzt als individuelles Erpressungsmaterial baumeln

Rhysida verkauft an jeden, der zahlt. Darauf ist zu achten. Moskaus Sabotagearm, den Dobrindt beharrlich “linke” Vulkangruppe nennt (ein Name, der jeden deutschen Linken-Namenstest nicht besteht, nebenbei), kann jeden Moment auftauchen. Er braucht nur 30 von Putins Bitcoin und einen Freitagnachmittag. Man darf erwarten, dass die Karte beim nächsten Einbruch in kritische Infrastruktur in eine weitere Runde Dobrindt mündet, der mit seinen liebsten falschen Flaggen wedelt.

Die Klartext-Zugangsdaten lagen in Dateien mit dem betrieblich effizienten Namen “Passwort.docx”. Unverschlüsselt. Funktionierende Zugangsdaten für Genehmigungs- und Zahlungsinfrastruktur, in ein Word-Dokument getippt, das genau nach seinem Inhalt benannt war, und in dem ein Angreifer eine Woche lang stöbern und lesen konnte.

Mangelhaft Wasser

Der Punkt Wasserversorgung verdient besondere Aufmerksamkeit, weil er eine deutsche Vorgeschichte hat, die erzählt gehört. Im Sommer 2020 fand die Beratungsfirma Alpha Strike Labs, beauftragt von den Berliner Wasserbetrieben selbst, mehr als 30 Schwachstellen und bewertete die IT-Sicherheit des Versorgers mit “mangelhaft“. Gibt es ein besseres Wort für durchgefallen? Die BWB kündigten ein Sofortpaket an. Die Behebung blieb jedoch auf dem Niveau der Selbstauskunft. Unabhängige Überprüfung der Fixes, sechs Jahre später: eine dicke fette Null. Ich finde keine.

Rhysida bietet also eine Schwachstellenanalyse des städtischen Wassersystems an, was klingt, als würde man dem Oktoberfest eine Weißwurst anbieten. Die Karte existiert bereits. Alpha Strike hat sie 2020 gezeichnet und dem Versorger übergeben. Ob Rhysida die alte Karte oder eine neuere hält, bleibt offen, so treiben Verkäufer den Wert hoch. Hier macht es keinen Unterschied. Berlin hat gewettet, nie beweisen zu müssen, dass die Löcher von 2020 geschlossen wurden. Die Auktion ruft die Wette auf. Jeder Käufer darf das Sofortpaket testen, und die Wasserbetriebe erfahren, wer recht hatte.

Das Getriebe der Angst

Die Zugangsentscheidungen des Senats zeigen, wie Governance auf Deutsch buchstabiert wird. Der Einbruch wird Mitte August öffentlich: Der Homeoffice-Zugang wird eingeschränkt. Eine Woche später wird der Zugang wiederhergestellt. Montagmorgen, 1. September, wird er erneut gekappt. Gut, aber warum? Das ist der Tag, an dem der Tagesspiegel zwei der gestohlenen Passwörter veröffentlichte.

Ahab Ostsee und Sonnenschein sind lustig, aber sie schließen in Wahrheit die größere Geschichte auf.

Sämtliche Zugangsdaten waren die ganzen zwei Wochen über offen. Der Einbruch, die Klartextdateien, der Datenabfluss waren dem Senat bekannt. Was sich tatsächlich änderte, war die öffentliche Sichtbarkeit dessen, worauf die Institution saß, und wer angriff. Berliner Incident Response trägt Anzug und Krawatte der Pressearbeit, derselbe Reflex, den ich beim jüngsten tragischen CSD-Anschlag dokumentiert habe: Der Staat tanzt um das herum, was an die Öffentlichkeit sickert, während die Fehleranalyse auf der Arbeitsebene ohne Eigentümer und ohne Antwort bleibt.

Reden wir darüber, was wirklich vorgeht, so sehr Berlins Vertuschungskultur auch alles andere tun will.

Die Vertuschung

Nennen wir es beim Namen. Die Betreiber wussten Bescheid, die Betreiber stellten sich dumm.

Sie wussten es 2020. Ihre eigenen Berater überreichten ihnen ein Mangelhaft für das Wassersystem und eine Liste mit mehr als 30 Löchern. Sie deuteten das als Moment der Selbstzertifizierung, um keinerlei schriftliche Spur zu hinterlassen, ob irgendetwas behoben wurde. Sie produzierten Schweigen, statt einer Liste von Mängeln und Fixes.

Ein Betreiber, der Passwörter für sein Zahlungs-Backend in “Passwort.docx” tippt, weiß, was das alles bedeutet. Wir schreiben 2026 in Berlin, nicht 1936. Diese Datei existierte, weil niemand, der sie anfasste, an Rechenschaft glaubte, an das, was eine ehrliche Prüfung zutage fördern würde, geschweige denn die Presse.

Und sie wussten, wann sie entlarvt waren. Man achte auf die Daten. Einbruch wird öffentlich: Zugang eingeschränkt. Eine Woche später: Zugang stillschweigend wiederhergestellt. Montag druckt der Tagesspiegel die Passwörter: Zugang am selben Morgen gekappt. Das ist ein Team, das verfolgt, wie es vor jemandem dasteht, der es beurteilt, ohne inneren moralischen Kompass, das auf Entlarvung reagiert statt auf Erkenntnis. Niemand, der Sichtbarkeit so präzise steuert, ist sich unklar über seine Prioritäten. Sie decken und ducken sich, drehen sich zu dem, von dem sie glauben, dass er unmittelbar über ihnen steht.

Ein Zustand der Improvisation, wie Politikwissenschaftler deutsche institutionelle Gewohnheiten beschrieben haben, statt rationaler, dokumentierter Handlungen.

Die Schuld auf “Sonnenschein13” zu schieben, gehört zur selben Operation. Auf das Passwort der Sachbearbeiterin zeigen, lachen, die BSI-Hygienevorlesung anklicken. Die Fragen beginnen und enden an diesem schwachen Endpunkt. Das ist ein Schatten von Dobrindt, der auf die Bewährungsstrafe eines Angreifers zeigt, während Perimeter die Baselines verfehlen und Sperrpläne unfinanziert bleiben. Die Angestellte wird sichtbar aufgehängt, weit aufmerksamkeitsträchtiger als die Betreiber und der Fluch Dobrindts.

Berlin hat alles gesammelt und dann offenbar nichts geschützt, sodass es, als die Geschichte aufflog, ins Management der Risikowahrnehmung kippte statt des Risikos. Schulungsbudget und Entschuldigung als Routine abspulen, dann abschreiben. Die Fragen, in die tatsächlich investiert werden müsste, tragen Namen: Wer hat abgezeichnet, dass die unabhängige Überprüfung des Sofortpakets übersprungen wird? Wann? Wem gehörte das Verzeichnis und die Datei darin namens Passwort.docx? Wer hat angeordnet, den Homeoffice-Zugang mitten im Vorfall wiederherzustellen, wer hat angeordnet, ihn Montagmorgen wieder zu kappen, und was hat diese Person beim Morgenkaffee gehört? Man setze diese Namen in einen Untersuchungsausschuss, und der ganze Aufruhr um eine russisch getriebene Auktion wird deutlich weniger interessant. Und wenn sie Verbindungen zur AfD haben, kommen wir der eigentlichen Geschichte näher: Russland bekommt Besuch von der CIA, weil ein Winchester-Amerika Deutschland nicht mehr verteidigen kann.

Ahab Ostsee im Sonnenschein ist nicht die Geschichte, für die die Leute sie halten.

Waymo Fines Really Just Billionaires Buying City Streets for Waymo Elites

America, as characterized by a card in the Monopoly game
A fine that can’t be contested and doesn’t change behavior isn’t enforcement; it’s a permit with a per-diem, or worse.

SFMTA is now on an $860k/year revenue line that depends on Waymo continuing to break laws such as parking illegally. The public regulator’s incentive is flipped by a wealthy corporation to the opposite of the public interest.

Waymo has been slapped with more than 8,300 parking tickets since January 2025. With fines of nearly $1 million for various violations, the robotaxi company says it’s cooperating with the city…

The 577 tickets reported at 85 North Point alone, over 565 days, is one citation per day at one address a block from Pier 39. That’s not a fleet-wide learning problem; that’s a single PCO walking the same block every morning and finding the same car in the same Waymo employee queue. Waymo knows the address. So does SFMTA.

Reporters give us AV safety experts like Koopman, who says money is nothing to Waymo. Just look at the reclusive elites who work there and how much they find ways to cheat public infrastructure costs. Remember how Google buses poached city bus stops, blocking city buses, and refused to allow non-Google staff to ride? The smarter reporting is that money is something to SFMTA.

Whatever “the Waymo Driver continues to learn from every mile” means, it is not learning how to stop breaking the law. It’s perhaps the exact opposite, learning how to corrupt and destroy the public systems that enforce laws for public benefit.

2026 pace: 4,131 tickets in 200 days = 20.7/day = 145/week, annualizing to 7,500. That’s 2025 (4,178, 80/week) × 1.8, on a fleet that grew 1.5× (800 → 1,200+).

Per-vehicle rate went up: 5.2 tickets/car/year in 2025 to 6.3 in 2026.

$957,008 over 8,309 tickets = $115 per ticket (2024 was $110, so fine escalation is nil). 2026 run rate ≈ $860k/year. Spread across 1,200 cars that is $1.96 per car per day. Cheaper than any garage in the Wharf. Or to put it another way:

…most common infraction for Waymos in the city, with 2,038 tickets, was “parking in stands,” aka taking up a space intended for a specific type of vehicle such as a… bus. The other top infractions were parking in a prohibited space, obstructing traffic, double parking, and blocking bike lanes. …the second-most common address (with 369 citations) was just two blocks away at 150 Beach St., outside a parking garage.

Waymo is literally blocking the bus while cheating the car garage model.