A Borges story about a guy who gets AI to summarize all the world’s information for him, and then summarize the summary, until the AI has the whole world summarized into a single word. He sits alone at his desk, staring at the word, repeating it endlessly, certain he is experiencing everything

Don’t publish your podcast only on Spotify

I’ve been coming across small or personal podcasts that can only be heard on Spotify. Intrigued by this phenomenon, I created a new podcast on Spotify Creator platform to find out what’s happening.

Spotify, among other services, offers podcast hosting. It’s a similar arrangement to what Substack has for newsletters: generous resources at no cost to create and maintain the newsletter (or, in Spotify’s case, the podcast).

There’s a fundamental difference, though. A newsletter created on Substack can be followed by any email client — Gmail, Outlook, Fastmail, your own domain. Spotify podcasts, however, are limited to Spotify and, worse, have their RSS feed disabled by default.

(more…)

Cool links of the week

I collect cool, interesting links spread all over the web and share them here in weekly posts. Hope you enjoy!

Petrichor. New offline music player for macOS. Reminds me of iTunes from the good old days. And it’s open source.

Blanket. A Linux app (Gnome/GTK) that creates sounds and noise. On macOS? Try Blankie.

Abdisa Dev. I have a soft spot for websites that simulate terminals.

Export YouTube subscriptions into RSS. Much easier than adding channels one by one to a feed aggregator.

A history of Mac settings, 1984–2004. Try accessing it on a computer to see (and interact with!) the preference screens from various system versions.

URL to Any. Various tools for manipulating web page content. Free.

Reachy Mini. Hugging Face, an LLM (AI) repository, has put this cute (and open source) robot on pre-order, designed for teaching robotics with artificial intelligence. For USD 449 (wireless) or USD 299 (“lite” version, works tethered to a computer).

CPU-X. Linux alternative to Windows’ CPU-Z, an app that displays information about your computer’s processor, motherboard, and graphics card.

Notepin. An “extremely simple” blogging platform.

Weather Watching. An “AI” camera analyzes clothing and the presence of umbrellas among pedestrians on a New York street to give a weather forecast. Perhaps the world’s most inefficient weather forecasting.

Packet. Linux app compatible with Android’s Quick Share protocol (the “Android AirDrop”).

FolderDrive. An external drive (128 GB) shaped like the macOS folder icon.

Hued. Try to guess the color of the day. You get three chances.

Adding a feature because ChatGPT incorrectly thinks it exists. When life gives you lemons, make lemonade.

Primesweeper. A minesweeper game but with prime numbers instead of bombs.

Katamari Node-Modules. The Katamari game, but with node.js modules as objects.

⚠️ This Slack error page “weighs” over 50 MB. Here (Safari, cache disabled) it hit 110 MB.

Open RSS. A service that turns any page into an RSS feed.

Revisiting my digital security model

Digital security is what results from balancing defenses with convenience. There’s no point in completely shielding yourself if accessing your private spaces is difficult; on the other hand, an easy-to-remember password (123456, for example) is almost the same as having no password at all.

This Manual has always leaned toward the shielding side, sometimes making situations unnecessarily difficult when a bad outcome (breach, data loss/theft) is unlikely. In 2024, I made a course correction that I promised to share1. Here’s that update.

The “eureka moment” came when I realized there was a third element in that security × convenience equation: the human being protected.

Someone politically exposed or dealing with sensitive third-party data, for example, needs a more robust security apparatus. Someone like me? Not so much.

In this reflection, I changed two things I consider most relevant.

The first was abandoning the YubiKey, a physical cryptographic key used as a second authentication factor. Instead of typing that random six-digit code (TOTP, time-based one-time password) generated by apps like Google Authenticator, I would plug in the YubiKey or tap it with the back of my phone to activate it via NFC. I wrote about YubiKey in June 2021.

Abandoning the YubiKey was motivated more by convenience, or rather the inconvenience of using it, from frustrating scenarios (being out and needing to access a site or app dependent on the key left at home) to more routine ones that add up in frustration (the key being in another room of the house).

TOTPs already provide an extra layer of security that’s good enough for someone who isn’t a target of sophisticated actors — me and probably you. And it’s always with me, on my phone and computer.

The second change was regarding TOTPs. Instead of creating and managing them in a specific app, I migrated them to the password manager.

This change goes against best recommendations, because if the password manager is compromised, the barrier provided by TOTP falls with it. It’s somewhat like having two locks on the door and carrying both keys on the same keychain.

The “accepted risk” here is greater than that of dispensing with the YubiKey. I’m aware and agree to continue.

The lock and key metaphor doesn’t account for a more likely scenario than password manager breach: password leaks by the services themselves. That’s what worries me most. Even in this “all eggs in one basket” arrangement, TOTP would remain useful. With the password but without the random code, my account that had its password leaked would remain secure.

In parallel, passkeys are a new proposal to complement or completely replace passwords and second-factor authentication. I’ve already delved into the subject (April 2024) and revised my opinion a month later. I keep following the technology’s development with genuine interest.

  1. All links to blogposts written in Portuguese. Sorry, I didn’t have an English blog at the time.

Anonymous and mild sensibilities have currency because today’s music — whether created and curated by humans or machines — is so often used to make people feel nothing instead of something. […] This music is not meant to be listened to directly; it’s used to drown out everything else.

White man, with prescription glasses, black beard and long hair, black and straight. Black and white photo.Ian Bogost
The Atlantic

Ian reflects on the small success of Velvet Sundown, a band made by artificial intelligence that was already approaching 1 million streams on Spotify. “This is second-order music listening, in which you experience the idea of listening to music. What better band to provide that service than one that doesn’t even exist?”

The Washington Post reports on the discomfort that white-collar professionals are experiencing with the increasing presence of AI note-taking bots in video calls. There are cases where there are more bots than human beings in meetings.

This might be a positive result of the chaotic adoption of artificial intelligence in companies. When everyone is sending bots to online meetings and reading text summaries of them, maybe these people will finally realize that all those meetings could have, in fact, been emails.

How technologies of connection tear us apart

The subtitle of Superbloom, the latest book by American writer Nicholas Carr, might surprise those who have never stopped to question or even observe the media: “How technologies of connection tear us apart.”

Sounds contradictory, doesn’t it? Yes, but it makes sense. With the delicious prose that’s characteristic of him — and which, from time to time, is offered to us in his newsletter —, Carr reviews the history of communication technologies from a new perspective, one in which, because of development focused on eliminating friction and accelerating the speed of information, the social fabric deteriorates.

(more…)

Alerts fatigue, or would that be journalism fatigue?

The Guardian picked up an interesting finding (among many interesting ones) from the 2025 edition of the Digital News Report, perhaps the world’s largest press survey, produced annually by the Reuters Institute:

Analysis by the Reuters Institute for the Study of Journalism found that 79% of people surveyed on the subject around the world said they did not currently receive any news alerts during an average week. Crucially, 43% of those who did not receive alerts said they had actively disabled them. They complained of receiving too many or not finding them useful, according to the research, which covered 28 countries.

There was a time, around 2014, when phone notifications were seen as a phone’s “premium real state,” a battleground for people’s attention, who were already saturated by the volume of digital information.

Unsurprisingly, the notification area also ended up saturated and discarded as yet another digital dumping ground. I suspect many people don’t even care what’s there, accumulating dozens, hundreds of unread, ignored notifications.

The obvious focus of the Reuters Institute research, journalism, reminded me of an excellent short piece by Ricardo Fiegenbaum, a researcher at objETHOS, a research group from Federal University of Santa Catarina. A decidedly non-academic text [pt_BR] (in the best sense), in which he thinks aloud about journalism’s place today:

It’s in this mined, paradoxical, complex and uncertain terrain that I enter when I think about journalism. And every question that presents itself in this scenario — logical, ideological, pragmatic, technological, discursive, etc. — always leads me to the fundamental question: what are we talking about when we talk about journalism?

It’s a good question.

I suspect the fatigue transcends notifications and that much of what’s currently understood as “journalism” escapes one of the profession’s noblest definitions, one that Ricardo mentions: serving societies’ information needs.

From the archives: in 2022, in light of that year’s Digital News Report edition, I was asking myself — echoing Brazilian singer Caetano Veloso — who reads so much news anyway [pt_BR].

You’re going to use Gemini on Android whether you like it or not

Google sent an email to Android phone owners warning that Gemini “will soon be able to help you use Phone, Messages, WhatsApp, and Utilities on your phone, whether your Gemini Apps Activity is on or off.” The change is scheduled for July 7th.

The notice generated confusion even in Android-focused publications. — 9to5Google, Android Police, Android Authority. Even after clarifications, including a statement from Google itself, the whole thing remains… confusing.

From what I understand, if Gemini Apps Activity is disabled, Gemini will continue to be available and have access to the mentioned apps, including WhatsApp and Phone. The difference is that interactions with the AI won’t be recorded in the history and will be stored by Google for up to 72 hours, with the guarantee that they won’t be used to train AIs or reviewed by humans.

(In other words, leaving history enabled subjects interactions to AI training and reviews by other humans.)

Those who *really* don’t want Gemini meddling with calls, messages, WhatsApp, and system settings need to disable integrations with each app within the Gemini app itself. Which seems to be another thing, different from Gemini Apps Activity. I presume it’s this app.

The aforementioned specialized publications, after updating their stories to “clear up the confusion,” concluded that the net result of the change is positive for people’s privacy. I’m not so sure about that. Confusions of this type, which sound intentional and try to hide the “nuclear” toggles (that disable the offered feature), tend to be defeats for privacy. And I won’t even get into the merits of whether Gemini snooping through my messages is good or bad.

Or maybe I still don’t understand it properly.

Related link (I think?): the extensive Gemini Apps privacy center.