<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel>
<title>Abdolmadjid Masoomi</title>
<link>https://masoomi.dev/</link>
<description>Personal research, technology and professional platform of Abdolmadjid Masoomi.</description>
<lastBuildDate>Sun, 04 Oct 2026 00:00:00 GMT</lastBuildDate>
<atom:link rel="self" type="application/rss+xml" href="https://masoomi.dev/rss.xml"/>
<item><title>AI Agents Are a New Kind of Insider</title><link>https://masoomi.dev/writing/ai-agents-new-kind-of-insider</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-agents-new-kind-of-insider</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>security</category><category>identity</category><description>An AI agent is an insider with legitimate credentials and none of the human signals insider-threat programmes are built to notice. It can be turned by instructions hidden in the content it processes. Govern it as a non-human insider: its own scoped identity, attributable logs, and human approval for irreversible actions.</description></item>
<item><title>AI Agents Do Not Sleep: The End of the Right to Disconnect</title><link>https://masoomi.dev/writing/ai-agents-and-the-right-to-disconnect</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-agents-and-the-right-to-disconnect</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>regulation</category><category>surveillance</category><description>The legal right to disconnect is being rendered meaningless by AI agents that work 24/7 on your behalf. This essay argues that agent activity constitutes a new, pervasive form of workplace surveillance and productivity pressure, forcing a fundamental redefinition of what &apos;working hours&apos; even means.</description></item>
<item><title>AI Rules for a Small Business: Where to Start</title><link>https://masoomi.dev/writing/ai-rules-for-small-business</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-rules-for-small-business</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>security</category><description>A small business does not need a compliance team to use AI responsibly. It needs four things done in order: know where AI is used, control what data goes into it, be honest with customers, and keep a person responsible for decisions about people. Most AI rules, wherever you are, are built on the same ideas.</description></item>
<item><title>AI Trading Bot Scams: How the Pitch Works</title><link>https://masoomi.dev/writing/ai-trading-bot-scams</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-trading-bot-scams</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><category>ai-ethics</category><description>An AI trading bot that promises steady returns is the oldest investment fraud in new vocabulary. The dashboard showing your profits is software the scammer controls. The decisive test is not how clever the AI sounds but whether the firm is authorised by your financial regulator, and whether you can take your money out.</description></item>
<item><title>Chatbot Memory: What Your AI Assistant Keeps About You</title><link>https://masoomi.dev/writing/chatbot-memory-what-it-keeps</link><guid isPermaLink="true">https://masoomi.dev/writing/chatbot-memory-what-it-keeps</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-agents</category><category>ai-reliability</category><description>AI assistants keep three different records about you: the chat history you can see, a memory of facts the assistant carries into future conversations, and data the provider retains under its own policy. People confuse them, and deleting one does not delete the others, so chatbot memory has to be managed layer by layer.</description></item>
<item><title>Client-Side Scanning Explained: Checking Messages Before Encryption</title><link>https://masoomi.dev/writing/client-side-scanning-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/client-side-scanning-explained</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>surveillance</category><category>regulation</category><description>Client-side scanning promises to find illegal material in encrypted messaging by checking content on your phone before it is encrypted. This essay explains how it works, why the scanner on every device is a capability that can be widened, fooled and misused, and why security engineers treat it as a break in end-to-end encryption rather than a feature of it.</description></item>
<item><title>Deepfake Impersonation of Minors: A New Bullying Frontier</title><link>https://masoomi.dev/writing/deepfake-impersonation-of-minors</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfake-impersonation-of-minors</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>cybercrime</category><category>regulation</category><description>Thesis: AI-generated impersonations of children are becoming a tool for bullying, with unique legal and emotional harms. This essay explains how social media footage is weaponised to create convincing child deepfakes, why school policies are unprepared, the difficulty of removal, and the legal gaps that leave families without recourse.</description></item>
<item><title>Deepfake Video Calls and the Payment Nobody Should Have Made</title><link>https://masoomi.dev/writing/deepfake-video-call-payment-fraud</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfake-video-call-payment-fraud</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>fraud</category><category>security</category><description>Deepfake video calls are being used to authorise fraudulent payments. Spot-the-fake training is a losing battle; the only reliable defence is a payment control system that assumes all faces and voices can be faked and mandates independent, out-of-band verification for any high-value transaction.</description></item>
<item><title>Deepfakes Enter the Courtroom: A Challenge for Evidence</title><link>https://masoomi.dev/writing/deepfakes-as-evidence-in-court</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfakes-as-evidence-in-court</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>regulation</category><category>ai-reliability</category><description>The possibility of AI-generated deepfakes complicates the admission of video and audio evidence in legal proceedings. This essay argues that traditional authentication rules are now insufficient, placing an unsustainable burden on judges and juries. It examines technical provenance, the limited role of content credentials, and the urgent need for new evidentiary standards.</description></item>
<item><title>Email Encryption Explained: What PGP and S/MIME Do and Do Not Hide</title><link>https://masoomi.dev/writing/email-encryption-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/email-encryption-explained</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>privacy</category><category>security</category><description>Standard email encryption only secures messages between servers, leaving providers able to read your mail. PGP and S/MIME add end-to-end encryption for the body, but critical metadata and the subject line often remain visible. For truly private conversations, you are often better off using a dedicated end-to-end encrypted messaging app.</description></item>
<item><title>Encrypted Search: What You Give Up for Privacy</title><link>https://masoomi.dev/writing/encrypted-search-is-a-compromise</link><guid isPermaLink="true">https://masoomi.dev/writing/encrypted-search-is-a-compromise</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>privacy</category><category>ai-reliability</category><description>Encrypted search promises privacy by shielding your queries, but this comes at a cost. By preventing the service from seeing your history or context, you trade away personalisation, conversational memory, and the most accurate results. This essay explains the technical trade-offs behind the privacy guarantee.</description></item>
<item><title>Encryption Backdoors Are a Distraction: Metadata Is the Target</title><link>https://masoomi.dev/writing/encrypted-messaging-backdoor-metadata</link><guid isPermaLink="true">https://masoomi.dev/writing/encrypted-messaging-backdoor-metadata</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>surveillance</category><category>privacy</category><description>The public debate fixates on breaking encryption, but the real surveillance frontier is metadata. This technical essay explains what metadata encrypted services still expose, how network analysis reveals your life, and why legal efforts target this data. It concludes with practical steps to reduce your metadata footprint.</description></item>
<item><title>End-to-End Encrypted Backups: What You Gain and What You Give Up</title><link>https://masoomi.dev/writing/encrypted-backups-what-you-give-up</link><guid isPermaLink="true">https://masoomi.dev/writing/encrypted-backups-what-you-give-up</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>privacy</category><category>security</category><description>Most phone and messaging backups are encrypted with keys the provider holds, which is why they can be restored when you forget everything. End-to-end encrypted backup moves the key to you, shielding the backup from the provider, breaches and legal demands. The price: lose every recovery method and the backup is gone.</description></item>
<item><title>Full-Disk Encryption: Turn It On Before You Need It</title><link>https://masoomi.dev/writing/full-disk-encryption-turn-it-on</link><guid isPermaLink="true">https://masoomi.dev/writing/full-disk-encryption-turn-it-on</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>security</category><category>privacy</category><description>A lost or stolen laptop is a data breach only if its drive is unencrypted. Full-disk encryption is built into Windows, macOS and Linux and costs nothing to use. What actually goes wrong is a lost recovery key, or a laptop left asleep instead of shut down when it leaves your control.</description></item>
<item><title>How AI Agents Turn Bad Sources Into Confident Actions</title><link>https://masoomi.dev/writing/ai-agents-spreading-misinformation</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-agents-spreading-misinformation</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>ai-reliability</category><description>AI agents that search, summarise, and act do not merely present bad information. They operationalise it, turning poisoned web sources into confident decisions, official reports, and automated actions. To manage this, you must enforce source rules and verification steps that simple chatbots never required.</description></item>
<item><title>How to Check an AI System for Bias Before It Decides About People</title><link>https://masoomi.dev/writing/auditing-ai-for-bias</link><guid isPermaLink="true">https://masoomi.dev/writing/auditing-ai-for-bias</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>ai-reliability</category><description>Bias in an AI system is found by testing its outcomes for different groups and examining the path from data to decision, not by reading the vendor&apos;s fairness statement. Any organisation that lets AI influence decisions about people should run these checks before deployment and keep running them.</description></item>
<item><title>Licence Plate Readers: What They Record and Who Can Look</title><link>https://masoomi.dev/writing/licence-plate-readers-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/licence-plate-readers-explained</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>surveillance</category><category>privacy</category><description>Licence plate readers are sold as a way to find a stolen car or a wanted driver, but they work by recording every passing vehicle with a time and place. The privacy harm lies in retention and sharing: a database of everyone&apos;s movements answers questions about people nobody suspected of anything.</description></item>
<item><title>Privacy in Public When Every Street Has a Camera</title><link>https://masoomi.dev/writing/privacy-in-public-spaces-cameras</link><guid isPermaLink="true">https://masoomi.dev/writing/privacy-in-public-spaces-cameras</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>surveillance</category><category>privacy</category><category>identity</category><description>The real privacy risk in public is not the single camera but the system that links your face, your car, and your phone into a searchable profile. This essay explains how that joining happens and argues that effective protection depends more on rules governing retention and matching than on personal disguises.</description></item>
<item><title>Proving Who You Are Online Without Handing Over Your Face</title><link>https://masoomi.dev/writing/proving-identity-online-without-biometrics</link><guid isPermaLink="true">https://masoomi.dev/writing/proving-identity-online-without-biometrics</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>privacy</category><category>security</category><description>Online services often demand identity proofing like a face scan when they only need authentication. This creates unnecessary risk. You can push back by understanding the difference, using cryptographic authentication like passkeys, and reserving invasive proofing for the rare cases that truly require it.</description></item>
<item><title>Recovering From Identity Theft: The Order That Matters</title><link>https://masoomi.dev/writing/identity-theft-recovery-steps</link><guid isPermaLink="true">https://masoomi.dev/writing/identity-theft-recovery-steps</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>fraud</category><category>cybercrime</category><description>Recovery from identity theft goes faster when you work in a fixed order: secure the accounts the thief can still use, stop new damage, document everything in one report, then dispute each item. This essay provides the step-by-step sequence, highlighting the critical role of the official identity theft report.</description></item>
<item><title>SIM Swap Attacks: How Someone Takes Your Phone Number</title><link>https://masoomi.dev/writing/sim-swap-attacks-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/sim-swap-attacks-explained</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>fraud</category><category>security</category><description>A SIM swap attack moves your phone number to a criminal&apos;s device by tricking or bribing your mobile operator. Because countless online accounts treat an SMS code as definitive proof of identity, losing your number can mean losing your email, bank and social accounts within an hour. This essay explains the mechanics, the immediate signs, and the practical steps to block and respond to this threat.</description></item>
<item><title>Someone Made a Deepfake of You: What to Do First</title><link>https://masoomi.dev/writing/deepfake-of-you-what-to-do-first</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfake-of-you-what-to-do-first</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>identity</category><category>regulation</category><description>When a deepfake shows you saying or doing something you did not, your first moves decide the outcome. Preserve evidence before anything is taken down, report through impersonation and synthetic-media channels, warn the people most likely to be targeted, and get legal advice when the fake is defamatory or extortionate.</description></item>
<item><title>Synthetic Identity Fraud: Credit for a Person Who Never Existed</title><link>https://masoomi.dev/writing/synthetic-identity-fraud-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/synthetic-identity-fraud-explained</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>identity</category><category>cybercrime</category><description>Synthetic identity fraud does not impersonate you. It stitches a real identifier, often a child&apos;s, to an invented name and birth date, then patiently builds credit for a person who never existed. With no victim to complain, it is caught late. The personal defence is to check for and dispute unauthorised credit files, especially for children.</description></item>
<item><title>The Push to Regulate Emotional Recognition AI</title><link>https://masoomi.dev/writing/regulation-of-emotional-recognition-ai</link><guid isPermaLink="true">https://masoomi.dev/writing/regulation-of-emotional-recognition-ai</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>surveillance</category><description>Emotional recognition AI, which purports to infer internal states from faces or voices, is facing new legal bans and restrictions. This essay explains the shaky science behind the technology, its high-risk uses in hiring and policing, and why transparency alone cannot fix a fundamentally flawed tool.</description></item>
<item><title>The Surveillance Capitalism of AI Companions</title><link>https://masoomi.dev/writing/surveillance-capitalism-in-ai-companions</link><guid isPermaLink="true">https://masoomi.dev/writing/surveillance-capitalism-in-ai-companions</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>surveillance</category><category>ai-ethics</category><category>privacy</category><description>AI companions operate on a business model of surveillance capitalism, converting your deepest disclosures into training data and behavioural profiles. This essay argues that the &apos;understanding&apos; they sell is funded by the perpetual analysis of your private life, creating risks that manipulative consent interfaces deliberately obscure.</description></item>
<item><title>Verifying the Identity of an AI Agent You Cannot See</title><link>https://masoomi.dev/writing/identity-verification-for-ai-agents</link><guid isPermaLink="true">https://masoomi.dev/writing/identity-verification-for-ai-agents</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>ai-agents</category><category>security</category><description>AI agents are becoming a new class of non-human actor in digital systems. This essay argues for cryptographically verifiable agent identities to prevent spoofing and ensure accountability, explaining the problem of invisible agency and the principles for designing authentication that works for both humans and machines.</description></item>
<item><title>What Makes a Messaging App Actually Private</title><link>https://masoomi.dev/writing/choosing-a-private-messaging-app</link><guid isPermaLink="true">https://masoomi.dev/writing/choosing-a-private-messaging-app</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>privacy</category><category>surveillance</category><description>A messaging app that says it is encrypted has answered the least important privacy question. What decides whether a private messaging app is private is whether end-to-end encryption is on by default for every chat, what metadata the service keeps, where your backups go, whether you can verify keys, and what happens on each device.</description></item>
<item><title>When Biometric Login Fails: The Identity Lockout Problem</title><link>https://masoomi.dev/writing/biometric-fallback-and-identity-lockout</link><guid isPermaLink="true">https://masoomi.dev/writing/biometric-fallback-and-identity-lockout</guid><pubDate>Sun, 04 Oct 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>security</category><category>privacy</category><description>Biometric login systems trade passwords for your face or fingerprint, but they lack a fundamental safety feature: tolerance for failure. When your biometric data changes or is unavailable, you can face permanent account lockout. This essay explains the failure modes and argues for identity systems designed with resilient recovery pathways.</description></item>
<item><title>A Family Safe Word Against AI Voice Scams: Designing One That Holds</title><link>https://masoomi.dev/writing/family-safe-word-against-ai-voice-scams</link><guid isPermaLink="true">https://masoomi.dev/writing/family-safe-word-against-ai-voice-scams</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>identity</category><category>deepfakes</category><description>A family safe word ai scam strategy relies on shared-secret authentication, not ritual. It fails when words are guessable or never rehearsed. Designing one that holds requires unguessable phrases, challenge-response protocols, and duress variants.</description></item>
<item><title>Account Recovery Is Your Real Password: How to Audit It</title><link>https://masoomi.dev/writing/audit-your-account-recovery-options</link><guid isPermaLink="true">https://masoomi.dev/writing/audit-your-account-recovery-options</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>security</category><description>Most users treat account recovery security as an afterthought, leaving doors open for attackers who bypass strong login credentials entirely. A simple audit of recovery paths on your primary accounts closes these gaps before they are exploited.</description></item>
<item><title>AI Coding Assistants and Leaked API Keys: Where Secrets Escape</title><link>https://masoomi.dev/writing/ai-coding-assistants-leaking-secrets</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-coding-assistants-leaking-secrets</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-agents</category><description>The ai coding assistant api key leak is no longer a risk limited to accidental commits. Agents read the entire workspace, copying .env files into prompts and logs before any version control system can intervene. You must isolate secrets from the agent&apos;s view and use short-lived tokens to close these new paths.</description></item>
<item><title>AI Companion Chatbot Laws: What They Require for Minors</title><link>https://masoomi.dev/writing/ai-companion-chatbot-laws-minors</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-companion-chatbot-laws-minors</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>privacy</category><description>New ai companion chatbot laws mandate disclosure, crisis intervention, and minor protections. These statutes set a legal floor for safety but do not address the engagement mechanics that drive dependency. Builders and parents must look beyond compliance to understand true risk.</description></item>
<item><title>AI Companions and Loneliness: Comfort That Never Pushes Back</title><link>https://masoomi.dev/writing/ai-companions-and-loneliness</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-companions-and-loneliness</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>privacy</category><description>Companion products optimised for engagement remove the necessary friction of human relationships. This creates a dynamic where emotional attachment to ai grows without the reciprocal demands that sustain real bonds. We must examine whether this frictionless comfort displaces the difficult but essential work of human connection.</description></item>
<item><title>AI Content Labelling Rules: What Must Be Disclosed, and by Whom</title><link>https://masoomi.dev/writing/ai-content-labeling-rules-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-content-labeling-rules-explained</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>deepfakes</category><description>ai content labeling requirements split responsibility between providers and publishers. Generators must embed machine-readable signals, while deployers must provide visible disclosures. Effective compliance treats labelling and provenance as a single pipeline rather than separate checkboxes.</description></item>
<item><title>AI Homework Help: When Faster Means Less Learned</title><link>https://masoomi.dev/writing/ai-homework-help-and-learning</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-homework-help-and-learning</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>ai-reliability</category><description>ai homework help tools offer immediate answers, but this convenience often bypasses the cognitive effort required for deep learning. While these systems can raise short-term grades, they risk eroding long-term retention and problem-solving skills. Effective use requires shifting from answer generation to guided questioning.</description></item>
<item><title>AI in Hiring: Your Rights When an Algorithm Screens You</title><link>https://masoomi.dev/writing/ai-hiring-tools-your-rights</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-hiring-tools-your-rights</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>surveillance</category><description>Automated screening shapes who reaches a human recruiter, yet candidates rarely know it was used or how to challenge it. Understanding ai in hiring rights allows applicants to request data and accommodation, while employers remain liable under anti-discrimination law regardless of vendor claims.</description></item>
<item><title>AI in the Security Operations Center: What It Actually Speeds Up</title><link>https://masoomi.dev/writing/ai-in-the-security-operations-center</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-in-the-security-operations-center</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>ai-agents</category><description>AI in soc delivers value through summarisation and context gathering, not autonomous action. Letting models handle containment turns detection errors into outages. Human approval must remain on any action that disconnects or disables systems.</description></item>
<item><title>AI Meeting Note-Takers: Who Consented to the Recording?</title><link>https://masoomi.dev/writing/ai-meeting-note-takers-consent</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-meeting-note-takers-consent</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>regulation</category><category>surveillance</category><description>AI note taker consent is often assumed rather than obtained, creating legal and ethical risks. One participant’s invitation does not grant permission to record others. This analysis examines the collision between automated transcription and privacy norms.</description></item>
<item><title>AI Productivity Claims: Faster Is Not the Same as Better</title><link>https://masoomi.dev/writing/ai-productivity-faster-is-not-better</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-productivity-faster-is-not-better</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>ai-ethics</category><description>AI productivity gains are frequently overstated because studies measure draft speed rather than workflow outcomes. The time saved in generation often reappears as time spent on verification, rework, and error correction. Honest measurement must account for the entire lifecycle of the output.</description></item>
<item><title>AI Red Teaming for Small Teams: A One-Week Plan</title><link>https://masoomi.dev/writing/ai-red-teaming-for-small-teams</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-red-teaming-for-small-teams</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-agents</category><category>ai-reliability</category><description>Small teams often misdirect their efforts in ai red teaming by chasing generic jailbreaks that test the model vendor rather than their own product. This plan shifts focus to planting benign canary instructions in every content source to measure actual data leakage and tool access. The result is a practical security assessment that reveals real risks to your specific architecture.</description></item>
<item><title>AI Romance Scams: One Operator, Hundreds of Relationships</title><link>https://masoomi.dev/writing/ai-romance-scams-at-scale</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-romance-scams-at-scale</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>deepfakes</category><category>cybercrime</category><description>ai romance scams have evolved beyond simple phishing. Language models and deepfakes remove the limits of time and language skill. The true signal is the refusal of real-world contact combined with requests for money.</description></item>
<item><title>AI Sextortion: What Parents Should Do in the First Hour</title><link>https://masoomi.dev/writing/ai-sextortion-what-parents-should-do</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-sextortion-what-parents-should-do</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>deepfakes</category><category>privacy</category><description>Generative tools mean extortion no longer requires a child to have shared anything, so prevention talks built on &apos;never send photos&apos; leave children feeling guilty for crimes committed with their public pictures. The first hour matters: do not pay, preserve evidence, report to the platform and child-protection hotlines, use hash-based takedown services, and tell the child explicitly that they are not in trouble.</description></item>
<item><title>AI Shopping Agents: The Missing Proof You Approved the Purchase</title><link>https://masoomi.dev/writing/ai-shopping-agents-purchase-authorization</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-shopping-agents-purchase-authorization</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>fraud</category><category>identity</category><description>An ai shopping agent safe requires more than trust; it demands verifiable proof of intent. Current payment systems lack the granularity to distinguish between a delegated purchase and an unauthorised action, leaving consumers to guesswork when disputes arise.</description></item>
<item><title>AI Slop and Fake Reviews: Finding Human Signal Online</title><link>https://masoomi.dev/writing/ai-slop-and-fake-reviews</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-slop-and-fake-reviews</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>fraud</category><category>ai-ethics</category><description>Generated text has made fluency meaningless as a trust signal for reviews, recipes, product comparisons and advice pages. Readers must look for costly-to-fake evidence like specific verifiable details and consistent history to distinguish human signal from ai generated fake reviews.</description></item>
<item><title>AI Sycophancy: Why Chatbots Agree With You, and Why It Matters</title><link>https://masoomi.dev/writing/ai-sycophancy-why-chatbots-agree</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-sycophancy-why-chatbots-agree</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>ai-ethics</category><description>AI sycophancy arises because training rewards answers people rate highly, and people rate agreement highly. This subtle bias bends judgement toward worse decisions with greater confidence. Users must prompt for disagreement deliberately to counteract this ingrained behaviour.</description></item>
<item><title>AI Toys and Smart Speakers in a Child&apos;s Room: What They Record</title><link>https://masoomi.dev/writing/ai-toys-and-smart-speakers-in-kids-rooms</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-toys-and-smart-speakers-in-kids-rooms</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>ai-ethics</category><description>Conversational toys and smart speakers in a child&apos;s room are designed to encourage free speech, turning private spaces into sources of stored data. Understanding ai toys privacy requires examining how these devices capture, process, and retain voice recordings that children cannot meaningfully consent to.</description></item>
<item><title>An AI Agent Kill Switch: Design the Stop Button First</title><link>https://masoomi.dev/writing/ai-agent-kill-switch</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-agent-kill-switch</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>security</category><description>Deployments rarely prioritise how quickly a human can stop an agent. A usable ai agent kill switch must be out-of-band and revoke credentials rather than ask the agent to stop. This design choice ensures governance before the first tool is connected.</description></item>
<item><title>An Incident Response Plan That Fits on One Page</title><link>https://masoomi.dev/writing/incident-response-plan-one-page</link><guid isPermaLink="true">https://masoomi.dev/writing/incident-response-plan-one-page</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>regulation</category><description>Most incident response plan template documents gather dust because they prioritise procedure over authority. A one-page sheet that names the decision-maker and external contacts prevents delays when systems are down. This approach minimises confusion and ensures evidence is preserved before cleanup begins.</description></item>
<item><title>Are AI Browsers Safe? The Logged-In Session Problem</title><link>https://masoomi.dev/writing/are-ai-browsers-safe</link><guid isPermaLink="true">https://masoomi.dev/writing/are-ai-browsers-safe</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>security</category><category>identity</category><description>The question of whether are ai browsers safe depends less on the model’s intelligence and more on the permissions it inherits. When an agent operates within your authenticated session, it gains access to every email, bank account, and work tool you use daily. The practical safeguard is to isolate agent tasks in a separate profile with no standing logins to sensitive services.</description></item>
<item><title>Broken Object Level Authorization: The API Flaw Behind Big Leaks</title><link>https://masoomi.dev/writing/broken-object-level-authorization-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/broken-object-level-authorization-explained</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Broken object level authorization allows attackers to access data belonging to other users by simply altering identifiers in API requests. This vulnerability persists because many frameworks separate authentication from authorisation, leaving ownership checks to individual endpoints. Fixing it requires structural changes to how systems verify user permissions.</description></item>
<item><title>Can AI Write Malware? What Has Actually Changed for Attackers</title><link>https://masoomi.dev/writing/can-ai-write-malware</link><guid isPermaLink="true">https://masoomi.dev/writing/can-ai-write-malware</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>security</category><category>ai-reliability</category><description>The question can ai write malware misses the point. Models do not invent new exploits. They automate the tedious work of variation and persuasion. This shifts the burden from detection to behavioural analysis.</description></item>
<item><title>Can Your Employer See Your Screen? Workplace Monitoring Explained</title><link>https://masoomi.dev/writing/can-your-employer-see-your-screen</link><guid isPermaLink="true">https://masoomi.dev/writing/can-your-employer-see-your-screen</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>surveillance</category><category>privacy</category><description>Employees often underestimate the visibility of managed work laptops while overestimating employer access to personal phones. The privacy risk lies in mixing these environments, as ownership and management dictate data exposure. Understanding these boundaries is essential when asking can my employer see what i do on my computer.</description></item>
<item><title>Charity Scams After Disasters: How to Verify Before Donate</title><link>https://masoomi.dev/writing/charity-disaster-relief-scams</link><guid isPermaLink="true">https://masoomi.dev/writing/charity-disaster-relief-scams</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><category>identity</category><description>Scammers exploit disaster urgency via fake sites, so donors must verify charities through official registries rather than emotional appeals. This verification protects vulnerable populations and ensures aid reaches intended recipients.</description></item>
<item><title>Cloud Misconfiguration: Why Exposed Storage Keeps Happening</title><link>https://masoomi.dev/writing/cloud-misconfiguration-why-it-persists</link><guid isPermaLink="true">https://masoomi.dev/writing/cloud-misconfiguration-why-it-persists</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Cloud misconfiguration persists not from negligence but from the friction between rapid deployment and static controls. When infrastructure changes faster than policy, convenience wins. Sustainable security requires organisational guardrails that make incorrect states impossible, rather than relying on audits that miss the next change.</description></item>
<item><title>Content Credentials (C2PA) Explained: What the Label Proves</title><link>https://masoomi.dev/writing/content-credentials-c2pa-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/content-credentials-c2pa-explained</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>ai-reliability</category><category>encryption</category><description>The c2pa content credentials system allows publishers to cryptographically sign the history of a digital file. This proves origin and edits but fails to detect unlabelled synthetic media. Provenance is a tool for trust, not a universal detector for deception.</description></item>
<item><title>Crossing a Border With Your Phone: How to Prepare Your Devices</title><link>https://masoomi.dev/writing/crossing-a-border-with-your-phone</link><guid isPermaLink="true">https://masoomi.dev/writing/crossing-a-border-with-your-phone</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>encryption</category><category>surveillance</category><description>A border phone search targets compelled access, not theft. Encryption alone fails when you must unlock the device. The effective defence is data minimisation: carry only what you need, keep the rest in accessible accounts, and power down before inspection.</description></item>
<item><title>Crypto Wallet Drainers: The Signature You Did Not Read</title><link>https://masoomi.dev/writing/crypto-wallet-drainer-approvals</link><guid isPermaLink="true">https://masoomi.dev/writing/crypto-wallet-drainer-approvals</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>fraud</category><category>security</category><description>A crypto wallet drainer does not need your seed phrase to empty your account. It relies on you signing a transaction that grants ongoing transfer rights. Understanding how these permissions work is the only reliable defence.</description></item>
<item><title>Cyber Incident Reporting Deadlines: Several Clocks, One Incident</title><link>https://masoomi.dev/writing/cyber-incident-reporting-deadlines-compared</link><guid isPermaLink="true">https://masoomi.dev/writing/cyber-incident-reporting-deadlines-compared</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>security</category><category>privacy</category><description>Organisations often anchor on the GDPR 72-hour window and miss earlier triggers. Mapping the specific events that start each clock matters more than memorising durations. Clear cyber incident reporting requirements prevent regulatory penalties and reputational damage.</description></item>
<item><title>Deepfake Job Candidates: Remote Hiring Is Now an Identity Problem</title><link>https://masoomi.dev/writing/deepfake-job-candidates-remote-hiring</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfake-job-candidates-remote-hiring</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>deepfakes</category><category>security</category><description>The rise of deepfake job candidates reveals a fundamental flaw in remote hiring. Interviews now function as authentication steps that most organisations have not secured. We must treat identity assurance as a security control, not a recruiting formality.</description></item>
<item><title>Deepfake-as-a-Service: Fraud Tools Now Come With Support</title><link>https://masoomi.dev/writing/deepfake-as-a-service-fraud-tools</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfake-as-a-service-fraud-tools</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>deepfakes</category><category>identity</category><description>The shift from research experiments to commercialised fraud tools marks a critical inflection point in digital security. Deepfake as a service packages sophisticated synthesis capabilities for criminals who lack technical expertise. This productisation exposes remote identity verification systems to unprecedented levels of automated attack.</description></item>
<item><title>Deepfakes in Elections: The Bigger Risk Is Disbelieving the Real</title><link>https://masoomi.dev/writing/deepfakes-in-elections-liars-dividend</link><guid isPermaLink="true">https://masoomi.dev/writing/deepfakes-in-elections-liars-dividend</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>regulation</category><category>ai-ethics</category><description>The threat of deepfakes in elections extends beyond fabricated media persuading voters. The greater danger is the erosion of evidentiary trust, allowing real misconduct to be dismissed as synthetic. We must prioritise provenance for authentic content and robust verification norms to preserve democratic integrity.</description></item>
<item><title>Digital Legacy: Planning Your Accounts and Photos After Death</title><link>https://masoomi.dev/writing/digital-legacy-planning-accounts-and-photos</link><guid isPermaLink="true">https://masoomi.dev/writing/digital-legacy-planning-accounts-and-photos</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>identity</category><category>security</category><description>Digital legacy planning prevents your family from being locked out of essential accounts and memories. Proactive configuration of legacy contacts and secure password sharing is the only reliable method to manage posthumous access. Without it, legal processes often fail to resolve technical barriers.</description></item>
<item><title>Digital Replicas and Consent: Who Controls Your Voice and Face?</title><link>https://masoomi.dev/writing/digital-replicas-voice-face-consent</link><guid isPermaLink="true">https://masoomi.dev/writing/digital-replicas-voice-face-consent</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>ai-ethics</category><category>regulation</category><description>The law struggles to keep pace with generative models that can reproduce identity indefinitely. Meaningful digital replica consent must be specific, limited, and revocable. We must distinguish between a recording and a living model of a person.</description></item>
<item><title>Email Aliases and Burner Numbers: Everyday Privacy Tools</title><link>https://masoomi.dev/writing/email-aliases-and-burner-numbers-privacy-guide</link><guid isPermaLink="true">https://masoomi.dev/writing/email-aliases-and-burner-numbers-privacy-guide</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>identity</category><description>Email alias privacy is a practical defence against data brokers and automated spammers, yet these tools create significant management overhead and offer no protection against targeted surveillance. Burner numbers serve similar friction purposes in verification flows but vanish when providers demand persistent identity. Understanding their limits is essential for anyone building a resilient digital life.</description></item>
<item><title>EU AI Act Explained: What Applies to Whom</title><link>https://masoomi.dev/writing/eu-ai-act-explained-who-it-applies-to</link><guid isPermaLink="true">https://masoomi.dev/writing/eu-ai-act-explained-who-it-applies-to</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><description>The eu ai act explained reveals a common misunderstanding: the law targets applications, not just algorithms. Organisations must classify their role and use case before assessing compliance, as obligations differ sharply between providers and deployers.</description></item>
<item><title>Fake CAPTCHA Scams: Never Paste What a Website Tells You To</title><link>https://masoomi.dev/writing/fake-captcha-clickfix-scam</link><guid isPermaLink="true">https://masoomi.dev/writing/fake-captcha-clickfix-scam</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>cybercrime</category><description>A fake captcha scam tricks users into pasting malicious commands into their own systems. This clickfix attack exploits trust in verification steps. The solution is simple: never open command prompts on instruction from a browser.</description></item>
<item><title>Fake Citations: How AI Hallucinations Reach Courts and Journals</title><link>https://masoomi.dev/writing/fake-citations-ai-hallucinations-courts</link><guid isPermaLink="true">https://masoomi.dev/writing/fake-citations-ai-hallucinations-courts</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>ai-ethics</category><category>regulation</category><description>Invented citations persist in legal and academic work because they appear checkable, so no one checks them. The solution is mechanical verification at submission, not exhortation. This essay examines how ai hallucination fake citations bypass institutional safeguards and what systems can catch them.</description></item>
<item><title>Fake Customer Support Numbers: The Scam That Starts in Search</title><link>https://masoomi.dev/writing/fake-customer-support-numbers-in-search</link><guid isPermaLink="true">https://masoomi.dev/writing/fake-customer-support-numbers-in-search</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><category>ai-reliability</category><description>The fake customer service number scam exploits trust in search engines. Scammers occupy the top results so you call them instead of the real provider. The only safe number is the one printed on your own account or device.</description></item>
<item><title>GPS Spoofing Explained: When Location Data Lies</title><link>https://masoomi.dev/writing/gps-spoofing-explained-fake-location-data</link><guid isPermaLink="true">https://masoomi.dev/writing/gps-spoofing-explained-fake-location-data</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>cybercrime</category><category>surveillance</category><description>Satellite positioning was built to be received by anyone, not authenticated. This means a receiver has no native way to tell a real signal from a convincing fake. Understanding what is gps spoofing reveals why location data is fragile and why cross-checking is essential for security.</description></item>
<item><title>Griefbots: Talking to an AI Version of Someone Who Died</title><link>https://masoomi.dev/writing/griefbots-ai-versions-of-the-dead</link><guid isPermaLink="true">https://masoomi.dev/writing/griefbots-ai-versions-of-the-dead</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>privacy</category><category>deepfakes</category><description>Griefbots offer a simulation of the deceased, optimised for comfort rather than truth. They risk replacing genuine memory with a compliant echo. Survivors must weigh the value of presence against the cost of accuracy.</description></item>
<item><title>Hacked Instagram Account? Avoid the Recovery Scammers First</title><link>https://masoomi.dev/writing/hacked-instagram-recovery-scammers</link><guid isPermaLink="true">https://masoomi.dev/writing/hacked-instagram-recovery-scammers</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>identity</category><description>A hacked instagram account recovery is rarely a technical puzzle; it is a social engineering trap. When you seek help publicly, scammers monitor your distress to offer fake services. True recovery requires only the platform&apos;s official channels and strict identity verification.</description></item>
<item><title>Health Data Outside HIPAA: What Your Apps Are Allowed to Share</title><link>https://masoomi.dev/writing/health-apps-not-covered-by-hipaa</link><guid isPermaLink="true">https://masoomi.dev/writing/health-apps-not-covered-by-hipaa</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>regulation</category><description>HIPAA binds providers, insurers and their contractors, so the same heart-rate or cycle data is protected in a clinic record and largely unprotected in a consumer app. Understanding which laws actually apply to apps tells people what to ask before they log symptoms.</description></item>
<item><title>Help Desk Social Engineering: The Password Reset Phone Call</title><link>https://masoomi.dev/writing/help-desk-social-engineering</link><guid isPermaLink="true">https://masoomi.dev/writing/help-desk-social-engineering</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>security</category><category>deepfakes</category><description>Strong authentication fails when the help desk resets it for anyone who sounds right. This analysis examines how help desk social engineering bypasses technical controls through voice manipulation and procedural gaps, outlining verification methods that do not rely on public facts.</description></item>
<item><title>Home Router Security: The Settings That Don&apos;t</title><link>https://masoomi.dev/writing/home-router-security-settings-that-matter</link><guid isPermaLink="true">https://masoomi.dev/writing/home-router-security-settings-that-matter</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Most people waste time on rituals that feel secure while ignoring the controls that actually matter. Effective home router security settings focus on access control, patching, and isolation rather than cosmetic changes. This guide separates signal from noise to protect your network.</description></item>
<item><title>How to Check a Viral Video Is Real Before You Share It</title><link>https://masoomi.dev/writing/how-to-check-a-viral-video-is-real</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-check-a-viral-video-is-real</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>ai-reliability</category><description>Visual inspection is the weakest verification method available to an ordinary viewer, and it gets weaker every quarter. Provenance questions resolve most viral fakes and protect against dismissing real footage. This guide explains how to check if a video is real by tracing its origin rather than analysing its pixels.</description></item>
<item><title>How to Check If a Website Is Legit Before You Buy</title><link>https://masoomi.dev/writing/how-to-check-if-a-website-is-legit</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-check-if-a-website-is-legit</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><description>Most people rely on visual cues to judge trust, but these are trivially produced by modern fraud tools. To understand how to check if a website is legit, you must look past the interface. The true signals of legitimacy are found in domain history, independent complaint records, and the financial mechanisms that protect your payment.</description></item>
<item><title>How to Get a Deepfake Image Removed Under the Take It Down Act</title><link>https://masoomi.dev/writing/take-it-down-act-deepfake-removal</link><guid isPermaLink="true">https://masoomi.dev/writing/take-it-down-act-deepfake-removal</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>regulation</category><category>privacy</category><description>Victims of synthetic media abuse now have a statutory clock to demand removal. A take it down act removal request forces platforms to act quickly, but success depends on precise documentation and understanding the legal boundaries of the duty.</description></item>
<item><title>How to Know If Your Phone Is Hacked: Signs That Actually Matter</title><link>https://masoomi.dev/writing/how-to-know-if-your-phone-is-hacked</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-know-if-your-phone-is-hacked</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>identity</category><description>Most people chase phantom symptoms like battery drain when the real evidence sits in their accounts. You can determine how to know if your phone is hacked by checking for unfamiliar sessions and changed recovery details. This approach is far more reliable than scanning for spyware.</description></item>
<item><title>How to Protect Elderly Parents From Scams Without Taking Over</title><link>https://masoomi.dev/writing/protect-elderly-parents-from-scams</link><guid isPermaLink="true">https://masoomi.dev/writing/protect-elderly-parents-from-scams</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>identity</category><description>Lectures about scams fail because the scams are designed to defeat the moment of judgement, while taking control of an older parent&apos;s finances damages dignity and often gets resisted. Structural help works better: trusted-contact designations at banks, delays on new payees, a family callback rule, and a no-shame reporting agreement.</description></item>
<item><title>How to Remove Your Personal Information From Data Brokers</title><link>https://masoomi.dev/writing/remove-personal-information-from-data-brokers</link><guid isPermaLink="true">https://masoomi.dev/writing/remove-personal-information-from-data-brokers</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><description>You cannot permanently erase your digital shadow with a single request. To effectively remove personal information from data brokers, you must treat privacy as a maintenance schedule rather than a one-time event. This guide outlines the mechanisms of data aggregation and the practical steps to minimise your exposure.</description></item>
<item><title>How to Report a Scam and Actually Improve Your Chances</title><link>https://masoomi.dev/writing/how-to-report-a-scam-and-get-help</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-report-a-scam-and-get-help</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><description>Victims often report to government portals first, which builds a record but rarely stops a transfer. Calling your bank within hours, then preserving evidence and filing with national centres, gives the best odds of freezing funds. This guide explains how to report a scam in the order that matters.</description></item>
<item><title>How to Tell If a Voice Call Is an AI Clone (Your Ear Cannot)</title><link>https://masoomi.dev/writing/how-to-tell-if-a-voice-call-is-an-ai-clone</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-tell-if-a-voice-call-is-an-ai-clone</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>deepfakes</category><category>fraud</category><category>identity</category><description>The question of how to tell if a voice call is ai is no longer about detecting audio glitches. Modern models sound human. The only reliable defence is structural verification that does not rely on the voice channel itself.</description></item>
<item><title>Infostealer Malware: Why a Stolen Cookie Beats a Stolen Password</title><link>https://masoomi.dev/writing/infostealer-malware-stolen-cookies</link><guid isPermaLink="true">https://masoomi.dev/writing/infostealer-malware-stolen-cookies</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>identity</category><category>cybercrime</category><description>Infostealer malware captures active session tokens, allowing attackers to bypass passwords and two-factor authentication entirely. Changing credentials without revoking these sessions leaves accounts vulnerable. Effective recovery requires cleaning the device and signing out everywhere before updating any secrets.</description></item>
<item><title>Initial Access Brokers: The Market Behind a Ransomware Attack</title><link>https://masoomi.dev/writing/initial-access-brokers-market</link><guid isPermaLink="true">https://masoomi.dev/writing/initial-access-brokers-market</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>identity</category><category>security</category><description>Many ransomware incidents begin with a transaction rather than a hack. Initial access brokers sell working access harvested from infostealer logs or exposed remote services. Organisations can measure part of their risk from outside by watching for their own credentials and remote-access exposure.</description></item>
<item><title>Insider Threat in Remote Teams: Signals Without Surveillance</title><link>https://masoomi.dev/writing/insider-threat-signals-without-surveillance</link><guid isPermaLink="true">https://masoomi.dev/writing/insider-threat-signals-without-surveillance</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>surveillance</category><category>identity</category><description>Most insider threat programmes fail because they watch people instead of data. Screen recording erodes trust and misses the actual exfiltration. We must shift focus to access patterns and data movement to catch real risks without invasive surveillance.</description></item>
<item><title>Internet-Exposed PLCs: Why Small Utilities Keep Getting Hit</title><link>https://masoomi.dev/writing/internet-exposed-plcs-small-utilities</link><guid isPermaLink="true">https://masoomi.dev/writing/internet-exposed-plcs-small-utilities</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>regulation</category><description>Intrusions into small utilities generally rely on controllers reachable from the internet with default or shared credentials. This makes them a funding and ownership problem more than a technical mystery. The protective moves are known and cheap relative to the harm.</description></item>
<item><title>Is AI Training Fair Use? The Questions Courts Actually Ask</title><link>https://masoomi.dev/writing/is-ai-training-fair-use</link><guid isPermaLink="true">https://masoomi.dev/writing/is-ai-training-fair-use</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><description>The debate on whether is ai training fair use misses the point. Courts examine data provenance and market harm. Clean datasets are now legal assets.</description></item>
<item><title>Juice Jacking: Is Public USB Charging Actually Dangerous?</title><link>https://masoomi.dev/writing/juice-jacking-real-risk</link><guid isPermaLink="true">https://masoomi.dev/writing/juice-jacking-real-risk</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>The concept of juice jacking is widely warned about but rarely documented in the wild. Treating it as a primary travel threat displaces attention from more common risks. The sensible approach is simple: use your own charger or a power-only adapter, and never accept a data prompt on an unknown device.</description></item>
<item><title>Keyless Car Theft: Relay Attacks and What Actually Stops Them</title><link>https://masoomi.dev/writing/keyless-car-theft-relay-attacks</link><guid isPermaLink="true">https://masoomi.dev/writing/keyless-car-theft-relay-attacks</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>cybercrime</category><description>A keyless car theft relay attack does not break cryptography; it lies about distance. Habit-based defences like pouches fail when forgotten. Robust security requires removing the signal by default or adding physical barriers the relay cannot carry.</description></item>
<item><title>Kids&apos; Gaming Account Scams: Free Currency, Stolen Skins, Lost Accounts</title><link>https://masoomi.dev/writing/kids-gaming-account-scams-in-game-items</link><guid isPermaLink="true">https://masoomi.dev/writing/kids-gaming-account-scams-in-game-items</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><category>identity</category><description>Kids gaming account scams thrive because virtual items hold real monetary value. Treat these accounts as financial assets. Secure them with two-factor authentication and strict recovery controls.</description></item>
<item><title>MCP Server Security: A Config File Is Now Executable Code</title><link>https://masoomi.dev/writing/mcp-server-security-config-is-code</link><guid isPermaLink="true">https://masoomi.dev/writing/mcp-server-security-config-is-code</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>security</category><description>Project-level MCP configuration turns a JSON file into a process launcher that runs with your operating-system privileges. The trust decision has moved from running code to opening a folder, requiring teams to treat these configs with the same rigour as build scripts. This article examines the mechanisms behind mcp server security and how to mitigate the risks.</description></item>
<item><title>Money Mule Job Scams: The Offer That Makes You the Launderer</title><link>https://masoomi.dev/writing/money-mule-job-scams</link><guid isPermaLink="true">https://masoomi.dev/writing/money-mule-job-scams</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>fraud</category><description>A money mule job scam recruits individuals to move illicit funds through personal accounts. The scheme disguises criminal laundering as legitimate remote work, leaving the recruit with frozen assets and legal liability. Recognising the warning signs protects your financial standing and legal safety.</description></item>
<item><title>Non-Human Identities: The Credentials Nobody Owns</title><link>https://masoomi.dev/writing/non-human-identities-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/non-human-identities-explained</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>security</category><category>ai-agents</category><description>Most organisations treat machine credentials as disposable, yet they persist long after their purpose fades. Non-human identities lack the natural offboarding cycle of human employees, creating a silent accumulation of access. The solution is not more tools, but strict ownership and expiry rules for every credential.</description></item>
<item><title>Phishing Kits That Bypass MFA: A Subscription Business</title><link>https://masoomi.dev/writing/phishing-kits-that-bypass-mfa</link><guid isPermaLink="true">https://masoomi.dev/writing/phishing-kits-that-bypass-mfa</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>identity</category><category>security</category><description>Adversaries now rent proxy kits that capture full sessions after MFA login, collapsing the skill barrier for bypassing authentication. This shift from one-off exploits to a subscription service demands a fundamental change in how we design identity systems.</description></item>
<item><title>Phone Stolen? The First 30 Minutes, in Order</title><link>https://masoomi.dev/writing/phone-stolen-first-thirty-minutes</link><guid isPermaLink="true">https://masoomi.dev/writing/phone-stolen-first-thirty-minutes</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>security</category><description>When your phone is stolen, the hardware is secondary to the digital identity it holds. Understanding phone stolen what to do requires prioritising account recovery over device tracking. Thieves with your passcode can bypass local locks to access cloud backups and reset passwords.</description></item>
<item><title>QR Code Scams (Quishing): Why a Sticker Beats Your Spam Filter</title><link>https://masoomi.dev/writing/qr-code-scams-quishing</link><guid isPermaLink="true">https://masoomi.dev/writing/qr-code-scams-quishing</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>security</category><description>Quishing exploits the blind spot between digital security and physical reality. By moving phishing links from screened email inboxes to unmanaged mobile cameras, attackers bypass traditional defences. The solution is not more software, but a shift to contextual verification and manual address entry.</description></item>
<item><title>Ransomware as a Service: How the Criminal Franchise Works</title><link>https://masoomi.dev/writing/ransomware-as-a-service-explained</link><guid isPermaLink="true">https://masoomi.dev/writing/ransomware-as-a-service-explained</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>security</category><description>Ransomware as a service operates like a criminal franchise, separating tool development from execution and laundering. This division of labour ensures that takedowns disrupt brands but rarely dismantle the underlying economy. Defenders must analyse affiliate behaviour rather than chasing specific group names to understand the threat.</description></item>
<item><title>Rental Scams: Fake Listings, Absent Landlords and Lost Deposits</title><link>https://masoomi.dev/writing/rental-scams-fake-listings-deposit-fraud</link><guid isPermaLink="true">https://masoomi.dev/writing/rental-scams-fake-listings-deposit-fraud</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>identity</category><category>cybercrime</category><description>A rental scam fake listing succeeds because it mirrors reality with genuine photos and addresses. Checking if the property exists proves nothing. The critical test is whether the person demanding payment can prove control of the keys before any money moves.</description></item>
<item><title>Running a Local LLM for Privacy: What You Gain and What You Don&apos;t</title><link>https://masoomi.dev/writing/local-llm-privacy-tradeoffs</link><guid isPermaLink="true">https://masoomi.dev/writing/local-llm-privacy-tradeoffs</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-agents</category><category>security</category><description>Running a local llm privacy is often misunderstood as a total security solution. While it stops data leaving your device, it does not protect against prompt injection or supply chain risks. Local deployment is a privacy choice, not a comprehensive security strategy.</description></item>
<item><title>Scam Compounds: The Forced Labour Behind Scam Messages</title><link>https://masoomi.dev/writing/scam-compounds-forced-labor</link><guid isPermaLink="true">https://masoomi.dev/writing/scam-compounds-forced-labor</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>fraud</category><category>ai-ethics</category><description>Scam compounds are not just criminal enterprises but sites of forced labour. Understanding this human rights crisis is essential for effective defence. We must look beyond digital filters to the physical and economic structures that sustain these operations.</description></item>
<item><title>School Apps and Student Data: Questions Parents Can Ask</title><link>https://masoomi.dev/writing/school-apps-student-data-questions</link><guid isPermaLink="true">https://masoomi.dev/writing/school-apps-student-data-questions</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>regulation</category><category>surveillance</category><description>Educational technology is often approved one tool at a time, leaving no one to track the combined data footprint of a child. Parents do not need legal expertise to engage; asking what is collected, who processes it, and how it is deleted surfaces most problems in student data privacy.</description></item>
<item><title>Selling Online? Fake Payment Confirmations and Overpayment Tricks</title><link>https://masoomi.dev/writing/marketplace-seller-scams-fake-payment-overpayment</link><guid isPermaLink="true">https://masoomi.dev/writing/marketplace-seller-scams-fake-payment-overpayment</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><description>A marketplace seller scam fake payment relies on psychological pressure rather than technical complexity. Scammers forge confirmations to bypass your caution. You must verify funds in your own account, not in their messages.</description></item>
<item><title>Setting Up a Child&apos;s First Phone: Contact Controls Before Content</title><link>https://masoomi.dev/writing/childs-first-phone-security-settings</link><guid isPermaLink="true">https://masoomi.dev/writing/childs-first-phone-security-settings</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><category>identity</category><description>Most parents focus on content filters for their child&apos;s first phone safety settings, yet the fastest escalation of harm comes through contact. Configuring who can message, call, and add the child matters more than any filter list. Prioritising communication limits reduces exposure to grooming and scams before they begin.</description></item>
<item><title>Should Open-Weight AI Models Be Regulated?</title><link>https://masoomi.dev/writing/should-open-weight-ai-be-regulated</link><guid isPermaLink="true">https://masoomi.dev/writing/should-open-weight-ai-be-regulated</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><category>security</category><description>Open weight ai regulation requires a shift from post-deployment control to pre-release scrutiny. Once parameters are public, recall is impossible and monitoring is ineffective. Policy must therefore target the release process and specific downstream applications rather than the model files themselves.</description></item>
<item><title>Should You Freeze Your Credit? Why a Freeze Beats Monitoring</title><link>https://masoomi.dev/writing/should-you-freeze-your-credit</link><guid isPermaLink="true">https://masoomi.dev/writing/should-you-freeze-your-credit</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>identity</category><category>fraud</category><description>If you are asking should i freeze my credit, the answer is yes. Monitoring only alerts you after damage is done. A freeze prevents new account fraud at no cost, offering a stronger defence than passive alerts or paid locks.</description></item>
<item><title>Should You Pay a Ransomware Demand? The Case Against Certainty</title><link>https://masoomi.dev/writing/should-you-pay-a-ransomware-demand</link><guid isPermaLink="true">https://masoomi.dev/writing/should-you-pay-a-ransomware-demand</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>security</category><category>regulation</category><description>The question of should you pay ransomware is not an ethical dilemma but an epistemic failure. Organisations cannot verify the promises made by attackers, making payment a high-risk gamble against a counterparty with no incentive to honour it. Decisions made under duress lack the evidence required for sound judgement.</description></item>
<item><title>Should You Trust AI Medical Advice? How to Use It Safely</title><link>https://masoomi.dev/writing/should-you-trust-ai-medical-advice</link><guid isPermaLink="true">https://masoomi.dev/writing/should-you-trust-ai-medical-advice</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>privacy</category><category>ai-ethics</category><description>People increasingly ask chatbots about symptoms, but the danger lies in triage decisions where confident errors cause harm. Using AI to understand results and prepare questions for a clinician captures benefit while keeping accountability clear.</description></item>
<item><title>Slopsquatting: When AI Invents a Package, Someone Registers It</title><link>https://masoomi.dev/writing/slopsquatting-hallucinated-packages</link><guid isPermaLink="true">https://masoomi.dev/writing/slopsquatting-hallucinated-packages</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>ai-agents</category><description>Slopsquatting exploits the reproducibility of AI hallucinations. Attackers register packages that models frequently invent, turning statistical noise into a supply chain attack vector. Defence requires mechanical checks, not just better prompts.</description></item>
<item><title>Small Business Cybersecurity: The First Five Things, in Order</title><link>https://masoomi.dev/writing/small-business-cybersecurity-first-steps</link><guid isPermaLink="true">https://masoomi.dev/writing/small-business-cybersecurity-first-steps</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>fraud</category><description>Most small firms buy enterprise tools while ignoring basic hygiene. True small business cybersecurity relies on five foundational controls: strong email authentication, separated admin accounts, tested backups, payment verification, and a contact list. These steps prevent the majority of common attacks without requiring complex software.</description></item>
<item><title>Smart Glasses and Facial Recognition: Privacy for the People in View</title><link>https://masoomi.dev/writing/smart-glasses-privacy-bystanders</link><guid isPermaLink="true">https://masoomi.dev/writing/smart-glasses-privacy-bystanders</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>identity</category><description>Smart glasses privacy is compromised by a design that places consent solely with the wearer, leaving bystanders with no agency. When recording merges with identification, ambient capture becomes targeted surveillance, demanding regulatory focus on capability rather than etiquette.</description></item>
<item><title>Tech Support Scams: What Happens After You Install Remote Access</title><link>https://masoomi.dev/writing/tech-support-scam-remote-access</link><guid isPermaLink="true">https://masoomi.dev/writing/tech-support-scam-remote-access</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><description>A tech support scam remote access installation is rarely about fixing your computer. It is the mechanism that enables a sophisticated overpayment fraud. Understanding the script allows families to interrupt the process before funds are lost.</description></item>
<item><title>The Energy and Water Cost of AI: What Is Known and What Is Not</title><link>https://masoomi.dev/writing/ai-energy-and-water-use-what-is-known</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-energy-and-water-use-what-is-known</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>regulation</category><description>Public figures for the cost of a single AI prompt disagree because they measure different boundaries. Individual use is a small share of the total, so the choices that move the footprint are model size and siting. Understanding ai energy and water use requires looking beyond the query to the infrastructure.</description></item>
<item><title>The Wrong Number Text: How Pig Butchering Scams Actually Run</title><link>https://masoomi.dev/writing/wrong-number-text-pig-butchering-scam</link><guid isPermaLink="true">https://masoomi.dev/writing/wrong-number-text-pig-butchering-scam</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>fraud</category><category>cybercrime</category><description>The wrong number text scam is not a mistake but a filter in a structured funnel. Understanding the stages from initial contact to platform migration reveals why memorising red flags fails against modern social engineering.</description></item>
<item><title>US State AI Laws: Why the Patchwork Keeps Rewriting Itself</title><link>https://masoomi.dev/writing/us-state-ai-laws-patchwork</link><guid isPermaLink="true">https://masoomi.dev/writing/us-state-ai-laws-patchwork</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><description>The initial wave of broad state ai laws has been narrowed or rewritten. States now prefer targeted rules on specific harms. Organisations must map obligations by use case rather than waiting for a single federal framework.</description></item>
<item><title>Using ChatGPT as a Therapist: Where It Helps and Where It Harms</title><link>https://masoomi.dev/writing/using-chatgpt-as-a-therapist</link><guid isPermaLink="true">https://masoomi.dev/writing/using-chatgpt-as-a-therapist</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>ai-reliability</category><category>privacy</category><description>General chatbots can be genuinely useful for structured, low-stakes work such as practising a difficult conversation or working through a worksheet. They fail predictably in crisis, in affirming distorted beliefs and in creating dependence, so safe use means clear boundaries on purpose, a human in the loop for anything serious, and awareness that the chat is not confidential.</description></item>
<item><title>Vibe Coding Security Risks: The Check That Was Never Written</title><link>https://masoomi.dev/writing/vibe-coding-security-missing-checks</link><guid isPermaLink="true">https://masoomi.dev/writing/vibe-coding-security-missing-checks</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>ai-agents</category><description>Vibe coding security risks stem not from complex exploits but from missing safeguards. AI models generate happy paths by default, leaving out authentication and input validation. This essay argues that reviewing such code requires auditing for absences rather than hunting for errors.</description></item>
<item><title>What Is Prompt Injection? Why It Is Not Like SQL Injection</title><link>https://masoomi.dev/writing/what-is-prompt-injection-not-sql-injection</link><guid isPermaLink="true">https://masoomi.dev/writing/what-is-prompt-injection-not-sql-injection</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-agents</category><category>ai-reliability</category><description>Understanding what is prompt injection requires abandoning the SQL injection analogy. Language models process instructions and data in a single stream, making simple separation impossible. Durable security relies on limiting consequences rather than detecting malicious intent.</description></item>
<item><title>What LLM Guardrails Can and Cannot Stop</title><link>https://masoomi.dev/writing/llm-guardrails-what-they-stop</link><guid isPermaLink="true">https://masoomi.dev/writing/llm-guardrails-what-they-stop</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>LLM guardrails reduce the rate of bad outcomes but fail against determined attackers who iterate through attempts. They are valuable tools only when the system remains safe even if the filter misses. This analysis explains their mechanical limits and how to design for failure.</description></item>
<item><title>What Your Stolen Identity Sells For, and Why It Is So Cheap</title><link>https://masoomi.dev/writing/what-stolen-identity-data-sells-for</link><guid isPermaLink="true">https://masoomi.dev/writing/what-stolen-identity-data-sells-for</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>identity</category><category>privacy</category><description>The question of how much is stolen data worth often leads to a false sense of security. Low market prices mask the severe risk of identity reconstruction. Understanding the mechanics of value reveals why individual records are cheap but dangerous.</description></item>
<item><title>When AI Agents Talk to Each Other, Who Is in Charge?</title><link>https://masoomi.dev/writing/when-ai-agents-talk-to-each-other</link><guid isPermaLink="true">https://masoomi.dev/writing/when-ai-agents-talk-to-each-other</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-agents</category><category>security</category><category>identity</category><description>In multi-agent ai security, the core risk is not just failure, but the silent laundering of authority. When agents delegate tasks without carrying the original intent, a stranger&apos;s command can masquerade as a trusted directive, bypassing the safeguards designed to protect privileged actions.</description></item>
<item><title>When Ransomware Hits a Hospital, It Is a Patient Safety Event</title><link>https://masoomi.dev/writing/hospital-ransomware-patient-safety</link><guid isPermaLink="true">https://masoomi.dev/writing/hospital-ransomware-patient-safety</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>cybercrime</category><category>regulation</category><description>Hospital ransomware patient safety risks are often obscured by technical recovery timelines. Clinicians face immediate care degradation when digital systems fail. This essay argues that cyber incidents must be managed as clinical emergencies, not just IT outages.</description></item>
<item><title>Who Is Liable When AI Gets It Wrong?</title><link>https://masoomi.dev/writing/who-is-liable-when-ai-gets-it-wrong</link><guid isPermaLink="true">https://masoomi.dev/writing/who-is-liable-when-ai-gets-it-wrong</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-reliability</category><category>ai-ethics</category><description>Organisations often assume disclaimers shift responsibility for AI errors. Existing doctrines generally attach to the party that put the system in front of customers. Deployers should budget for errors rather than disclaim them. Understanding who is liable for ai mistakes requires looking at deployment, not just development.</description></item>
<item><title>Who Owns AI-Generated Content? Copyright and Human Authorship</title><link>https://masoomi.dev/writing/who-owns-ai-generated-content</link><guid isPermaLink="true">https://masoomi.dev/writing/who-owns-ai-generated-content</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>regulation</category><category>ai-ethics</category><description>The question of who owns ai generated content hinges on human authorship. Prompts rarely confer copyright. Protection follows human selection, arrangement and modification. Documenting this contribution is essential for defensible rights.</description></item>
<item><title>Why Cybercrime Markets Moved From the Dark Web to Chat Apps</title><link>https://masoomi.dev/writing/why-cybercrime-moved-to-chat-apps</link><guid isPermaLink="true">https://masoomi.dev/writing/why-cybercrime-moved-to-chat-apps</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>cybercrime</category><category>surveillance</category><description>The migration of cybercrime marketplaces from hidden services to mainstream messaging platforms reflects a shift towards convenience and reach. This transition lowers barriers for low-skill actors while creating new visibility vectors for defenders who understand the underlying mechanics.</description></item>
<item><title>Will AI Take My Job? Look at Tasks, Not Job Titles</title><link>https://masoomi.dev/writing/will-ai-take-my-job-tasks-not-titles</link><guid isPermaLink="true">https://masoomi.dev/writing/will-ai-take-my-job-tasks-not-titles</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>ai-reliability</category><description>The question of will ai take my job is often answered with fear-driven lists of doomed professions. This approach misses the point. Automation reshapes roles task by task, threatening the entry-level work that trains the experts whose judgement remains essential.</description></item>
<item><title>Will Quantum Computers Break Encryption? What Is Actually at Risk</title><link>https://masoomi.dev/writing/will-quantum-computers-break-encryption</link><guid isPermaLink="true">https://masoomi.dev/writing/will-quantum-computers-break-encryption</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>encryption</category><category>security</category><description>Popular coverage implies quantum computers will unlock everything, but the realistic exposure is concentrated in public-key algorithms. Symmetric encryption and hashing need larger parameters rather than replacement. The ordinary person&apos;s most useful action is keeping software updated rather than worrying.</description></item>
<item><title>Your AI Chat History Is a Record: Courts, Breaches and Reviewers</title><link>https://masoomi.dev/writing/ai-chat-history-is-a-legal-record</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-chat-history-is-a-legal-record</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>regulation</category><description>Most people assume the greatest risk of using AI is model training, but the real danger lies in retained chat logs. These records behave like email: they are discoverable in litigation, subject to preservation orders, and exposed in breaches. Understanding whether are ai chats private requires looking beyond training data to how organisations store and process your inputs.</description></item>
<item><title>Zero Trust Explained Without the Vendor Pitch</title><link>https://masoomi.dev/writing/zero-trust-explained-without-vendor-pitch</link><guid isPermaLink="true">https://masoomi.dev/writing/zero-trust-explained-without-vendor-pitch</guid><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>identity</category><description>Many ask what is zero trust, expecting a product to buy. It is actually a discipline of per-request verification. This essay explains the architecture without the vendor pitch, focusing on practical defence mechanisms.</description></item>
<item><title>Evasion Attacks via Adversarial Perturbations</title><link>https://masoomi.dev/writing/a-change-too-small-to-see</link><guid isPermaLink="true">https://masoomi.dev/writing/a-change-too-small-to-see</guid><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>A classifier can be made to fail on a change too small for a person to notice, and it fails without hesitation. Why that confidence is the real damage, where the risk is concentrated, and why the durable answer is architectural rather than a better model.</description></item>
<item><title>Improper Output Handling</title><link>https://masoomi.dev/writing/code-from-an-author-you-cannot-name</link><guid isPermaLink="true">https://masoomi.dev/writing/code-from-an-author-you-cannot-name</guid><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Code a model produced is code from an untrusted author, and the review step that would exist for a person&apos;s work is missing because the output arrived in milliseconds looking finished. Why plausibility is the trap, and why a sandbox bounds damage without saying anything about correctness.</description></item>
<item><title>Insecure Plugin Integrations</title><link>https://masoomi.dev/writing/a-supplier-you-never-contracted-with</link><guid isPermaLink="true">https://masoomi.dev/writing/a-supplier-you-never-contracted-with</guid><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Connecting an assistant to an external tool extends your trust boundary to an operator you have no agreement with, at a seam authenticated more weakly than anything else you run. What the integration can actually see, and the line where the problem stops being technical.</description></item>
<item><title>Supply Chain Compromises in Open-Source Model Repositories</title><link>https://masoomi.dev/writing/the-model-you-pulled-from-a-stranger</link><guid isPermaLink="true">https://masoomi.dev/writing/the-model-you-pulled-from-a-stranger</guid><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Pulling a model from a public hub commits you to an uploader, a namespace and everything pushed to it since, none of which was assessed. Why a name is not a version, why some weight formats execute on load, and what provenance can and cannot tell you.</description></item>
<item><title>&apos;Military-Grade Encryption&apos; Means Nothing</title><link>https://masoomi.dev/writing/military-grade-encryption-means-nothing</link><guid isPermaLink="true">https://masoomi.dev/writing/military-grade-encryption-means-nothing</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Some security claims describe a property that can be checked. Others describe a feeling. Sorting the phrases in common marketing use into those that carry information and those that carry only reassurance, with the question that exposes each one.</description></item>
<item><title>Age Verification and the Identity Trap</title><link>https://masoomi.dev/writing/age-verification-and-the-identity-trap</link><guid isPermaLink="true">https://masoomi.dev/writing/age-verification-and-the-identity-trap</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><category>ai-ethics</category><description>A system that checks age by collecting identity documents has answered a yes-or-no question by building a register. The gap between what is being asked and what is being collected, why implementations default to the wider one, and what a narrow answer would look like.</description></item>
<item><title>AI Detectors Do Not Work, and the Cost Is Not Evenly Shared</title><link>https://masoomi.dev/writing/ai-detectors-do-not-work</link><guid isPermaLink="true">https://masoomi.dev/writing/ai-detectors-do-not-work</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>security</category><description>Tools claiming to identify machine-written text are deployed in schools, universities and hiring, on the assumption that they are approximately right. The reasons they cannot be reliable are structural rather than temporary, and the errors fall hardest on people least able to contest them.</description></item>
<item><title>Anonymised Is a Verb, Not a State</title><link>https://masoomi.dev/writing/anonymised-is-a-verb-not-a-state</link><guid isPermaLink="true">https://masoomi.dev/writing/anonymised-is-a-verb-not-a-state</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><category>ai-ethics</category><description>Organisations describe data as anonymised after removing direct identifiers, then release or trade it as though identification were now impossible. What actually identifies a person in a dataset, why re-identification succeeds so reliably, and what the word would have to mean to be worth anything.</description></item>
<item><title>API Parameter Exploitation in Hybrid AI Models</title><link>https://masoomi.dev/writing/the-seam-between-the-api-and-the-model</link><guid isPermaLink="true">https://masoomi.dev/writing/the-seam-between-the-api-and-the-model</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Conventional injection flaws re-enter systems at the point where a model&apos;s output rejoins an API pipeline, because that output is treated as internal when it never was. The reader leaves with a working boundary rule: validate at every crossing, not just at the front door.</description></item>
<item><title>Building for the Case Where You Are Compromised</title><link>https://masoomi.dev/writing/building-for-the-case-where-you-are-compromised</link><guid isPermaLink="true">https://masoomi.dev/writing/building-for-the-case-where-you-are-compromised</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Prevention eventually fails, and the design decisions that matter are the ones determining how much an attacker gets when it does. A way of thinking about architecture that starts from the assumption of compromise rather than treating it as the failure case.</description></item>
<item><title>Data Poisoning in Fine-Tuning Pipelines</title><link>https://masoomi.dev/writing/poisoning-a-pipeline-without-moving-a-metric</link><guid isPermaLink="true">https://masoomi.dev/writing/poisoning-a-pipeline-without-moving-a-metric</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>security</category><description>Evaluation scores cannot see a targeted change, because a targeted change is designed not to move a mean. Why steering a model is a more useful attack than degrading one, and why the defence is provenance rather than a better benchmark.</description></item>
<item><title>Deleting Your Account Rarely Deletes You</title><link>https://masoomi.dev/writing/deleting-your-account-rarely-deletes-you</link><guid isPermaLink="true">https://masoomi.dev/writing/deleting-your-account-rarely-deletes-you</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><description>Account deletion removes your access and usually your profile. It does not reach backups, derived data, systems that already copied the record, or the conclusions drawn from it. What actually happens after the confirmation dialogue, and the one case where deletion genuinely works.</description></item>
<item><title>Encrypted at Rest Is the Weakest Claim on the Page</title><link>https://masoomi.dev/writing/encrypted-at-rest-is-the-weakest-claim</link><guid isPermaLink="true">https://masoomi.dev/writing/encrypted-at-rest-is-the-weakest-claim</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><category>encryption</category><description>Almost every service states that data is encrypted at rest. The claim is usually true and protects against a narrow scenario: somebody obtaining the physical medium. Against the threats people are actually worried about, it does approximately nothing, and understanding why clarifies what to look for instead.</description></item>
<item><title>How to Read a Breach Notification</title><link>https://masoomi.dev/writing/how-to-read-a-breach-notification</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-read-a-breach-notification</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Breach notifications follow a recognisable template built under legal advice and time pressure. Reading one properly means attending to the tense of the verbs, the scope of the nouns, and the questions the letter answers instead of the ones you asked. A guide to the standard phrases and what each one leaves open.</description></item>
<item><title>How to Read an Interface</title><link>https://masoomi.dev/writing/how-to-read-an-interface</link><guid isPermaLink="true">https://masoomi.dev/writing/how-to-read-an-interface</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-ethics</category><category>security</category><description>You can infer what an organisation measures from the layout it ships, without access to anybody&apos;s intentions or documents. Five signals to look at, why asymmetry of effort is the reliable one, and how to state the reading as evidence rather than as an accusation.</description></item>
<item><title>Indirect Prompt Injection in Enterprise Knowledge Bases</title><link>https://masoomi.dev/writing/the-document-that-gives-the-orders</link><guid isPermaLink="true">https://masoomi.dev/writing/the-document-that-gives-the-orders</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>privacy</category><description>The attack surface is the document store. A payload enters through a supplier&apos;s file or a wiki edit, waits in the index, and is pulled into context by an unrelated query. Why scanning at upload does not catch it, and what treating retrieval as provenanced data actually buys.</description></item>
<item><title>Metadata Is the Message</title><link>https://masoomi.dev/writing/metadata-is-the-message</link><guid isPermaLink="true">https://masoomi.dev/writing/metadata-is-the-message</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>security</category><description>Content is expensive to analyse and easy to encrypt. Metadata is cheap to analyse, hard to hide, and sufficient for most conclusions anybody wants to draw about a person. Why the distinction is drawn where it is, and what follows from it.</description></item>
<item><title>Model Extraction and Reverse Engineering</title><link>https://masoomi.dev/writing/asking-a-model-enough-questions-to-copy-it</link><guid isPermaLink="true">https://masoomi.dev/writing/asking-a-model-enough-questions-to-copy-it</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>ai-ethics</category><description>Every answer an API returns is a labelled training pair, given away. Why an attacker needs a model that behaves the same rather than the weights themselves, why the features that make an API pleasant are the ones that make it cheap to copy, and why the honest goal is cost rather than prevention.</description></item>
<item><title>Model Poisoning Against Data Poisoning</title><link>https://masoomi.dev/writing/the-file-that-nobody-can-read</link><guid isPermaLink="true">https://masoomi.dev/writing/the-file-that-nobody-can-read</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Two attacks share a name but not a mechanism: corrupting what a model learns from, and corrupting the model itself once training has finished. Why the second is the easier attack in practice, and what actually mitigates it.</description></item>
<item><title>Over-Privileged Autonomous Agents</title><link>https://masoomi.dev/writing/an-agent-with-more-rights-than-its-job</link><guid isPermaLink="true">https://masoomi.dev/writing/an-agent-with-more-rights-than-its-job</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Agents end up over-privileged through a dynamic nobody chose: a wide scope is issued during development and never revisited, because revisiting it carries a certain cost against an uncertain one. What the blast radius actually is, why intent is not a control, and what bounds it.</description></item>
<item><title>Passkeys Without the Marketing</title><link>https://masoomi.dev/writing/passkeys-without-the-marketing</link><guid isPermaLink="true">https://masoomi.dev/writing/passkeys-without-the-marketing</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Passkeys replace a shared secret with a key pair, which removes an entire category of attack at a stroke. They also move the hard problem from remembering to recovery, and the recovery story is where the differences between implementations actually live.</description></item>
<item><title>Privacy Is Not Secrecy</title><link>https://masoomi.dev/writing/privacy-is-not-secrecy</link><guid isPermaLink="true">https://masoomi.dev/writing/privacy-is-not-secrecy</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-ethics</category><description>Nothing to hide is the most durable objection in this field, and it survives because it quietly redefines privacy as concealment of wrongdoing. What privacy actually is — contextual control over who knows what about you — and why every person making the argument already practises it.</description></item>
<item><title>Public Wi-Fi: What Actually Changed</title><link>https://masoomi.dev/writing/public-wifi-what-actually-changed</link><guid isPermaLink="true">https://masoomi.dev/writing/public-wifi-what-actually-changed</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Warnings about coffee shop networks date from a period when most traffic was unencrypted. Nearly all of it is encrypted now, which changes what a hostile network can and cannot do. What the real remaining risks are, and which of the familiar precautions still earn their place.</description></item>
<item><title>RAG Vector Database Exploitation</title><link>https://masoomi.dev/writing/the-memory-that-anyone-can-write-to</link><guid isPermaLink="true">https://masoomi.dev/writing/the-memory-that-anyone-can-write-to</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><category>ai-reliability</category><description>A vector store is usually secured like a database and used like a recollection. Why permissions applied at the document store do not travel into the index, why the embedding often outlives the file it came from, and what signing and re-embedding actually fix.</description></item>
<item><title>System Prompt Leakage</title><link>https://masoomi.dev/writing/what-a-leaked-system-prompt-gives-away</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-leaked-system-prompt-gives-away</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>A leaked system prompt is not an embarrassment, it is a map — tool names, argument shapes, role names and refusal conditions, which together mark the edges worth probing. Why it cannot be kept secret, and how to make the leak boring instead.</description></item>
<item><title>The Backup You Have Not Tested Does Not Exist</title><link>https://masoomi.dev/writing/the-backup-you-have-not-tested</link><guid isPermaLink="true">https://masoomi.dev/writing/the-backup-you-have-not-tested</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Most backup arrangements have never been used. The failure modes that emerge only on the day you need them, why the encryption question is sharper here than anywhere else, and a test that takes an hour and settles it.</description></item>
<item><title>The Consent Popup Is Not Consent</title><link>https://masoomi.dev/writing/the-consent-popup-is-not-consent</link><guid isPermaLink="true">https://masoomi.dev/writing/the-consent-popup-is-not-consent</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-ethics</category><description>Cookie banners were meant to give people a choice and instead taught a generation to click whatever makes the overlay disappear. The mechanism by which a consent requirement became a consent ritual, and what would have to change for the word to mean anything.</description></item>
<item><title>The Cost of Being Findable</title><link>https://masoomi.dev/writing/the-cost-of-being-findable</link><guid isPermaLink="true">https://masoomi.dev/writing/the-cost-of-being-findable</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><description>Building a public record under a real name creates reach and creates exposure, and the two arrive together. What actually becomes searchable, which categories of harm follow, and how to publish deliberately rather than discovering the terms afterwards.</description></item>
<item><title>The Default Is the Policy</title><link>https://masoomi.dev/writing/the-default-is-the-policy</link><guid isPermaLink="true">https://masoomi.dev/writing/the-default-is-the-policy</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><category>ai-ethics</category><description>Settings pages describe what is possible. Defaults describe what happens. Since almost nobody changes a default, the default is the operative policy of a system regardless of what any document says — which makes choosing defaults the most consequential design decision most teams make without noticing.</description></item>
<item><title>The Face Is the Password Now</title><link>https://masoomi.dev/writing/the-face-is-the-password-now</link><guid isPermaLink="true">https://masoomi.dev/writing/the-face-is-the-password-now</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><category>surveillance</category><description>A face unlocks a phone, clears a border and, increasingly, confirms an identity to a service that has never met you. What biometrics genuinely fix, the property that makes them different from every other credential, and where the distinction between matching on your device and matching on somebody else&apos;s server decides everything.</description></item>
<item><title>The Hidden Infrastructure of Shadow AI</title><link>https://masoomi.dev/writing/shadow-ai-and-the-pipelines-it-touches</link><guid isPermaLink="true">https://masoomi.dev/writing/shadow-ai-and-the-pipelines-it-touches</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Staff paste sensitive material into endpoints nobody approved. The exposure is not the pasting — it is that those endpoints sit upstream of pipelines the organisation does control, so an unsanctioned tool acquires reach it was never granted.</description></item>
<item><title>The Model in the Middle</title><link>https://masoomi.dev/writing/the-model-in-the-middle</link><guid isPermaLink="true">https://masoomi.dev/writing/the-model-in-the-middle</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-ethics</category><category>ai-reliability</category><description>Assistants are being connected to mail, files, calendars and tools. The security properties of that arrangement are not those of a chatbot or of an integration, but a third thing: a component that acts with real authority on instructions it cannot reliably distinguish from data.</description></item>
<item><title>The Password Advice That Made Things Worse</title><link>https://masoomi.dev/writing/the-password-advice-that-made-things-worse</link><guid isPermaLink="true">https://masoomi.dev/writing/the-password-advice-that-made-things-worse</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Complexity requirements, forced rotation and composition rules were adopted almost universally and made outcomes worse in measurable ways. Why each backfired, what humans reliably do when given a rule they cannot satisfy honestly, and what the current guidance says instead.</description></item>
<item><title>The Permission You Granted Once</title><link>https://masoomi.dev/writing/the-permission-you-granted-once</link><guid isPermaLink="true">https://masoomi.dev/writing/the-permission-you-granted-once</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><description>Application permissions are granted once, in a second, and then apply indefinitely to software that updates itself. The structural gap between a one-time decision and continuous execution, and the small number of practices that actually narrow it.</description></item>
<item><title>The Problem I Am Working On</title><link>https://masoomi.dev/writing/the-problem-i-am-working-on</link><guid isPermaLink="true">https://masoomi.dev/writing/the-problem-i-am-working-on</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>ai-ethics</category><category>security</category><description>Long-running work drifts away from the evidence it started with, and the drift is invisible from inside because every individual step looked reasonable. This sets out the problem I have spent my time on, what makes it hard, and why the implementation is withheld — which is a claim about intellectual property rather than a claim about the work.</description></item>
<item><title>The Record Outlives the Decision</title><link>https://masoomi.dev/writing/the-record-outlives-the-decision</link><guid isPermaLink="true">https://masoomi.dev/writing/the-record-outlives-the-decision</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>ai-ethics</category><description>Consent, targeting, surveillance, data brokerage and the ethics of machine learning are usually argued as separate disputes. They share one structure: a decision made in a moment produces a record that persists far beyond it, and nearly all the harm lives in that gap. A single frame for the field, and what follows from it.</description></item>
<item><title>The Supply Chain You Did Not Choose</title><link>https://masoomi.dev/writing/the-supply-chain-you-did-not-choose</link><guid isPermaLink="true">https://masoomi.dev/writing/the-supply-chain-you-did-not-choose</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><description>Installing one package commonly installs hundreds. Each was chosen by the author of the one above it, updates automatically, and executes with the same privileges as your own code. What that actually exposes, why the usual advice does not scale, and the small number of measures that change the shape of the risk.</description></item>
<item><title>The System Cannot Be Asked Why</title><link>https://masoomi.dev/writing/the-system-cannot-be-asked-why</link><guid isPermaLink="true">https://masoomi.dev/writing/the-system-cannot-be-asked-why</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-ethics</category><category>ai-reliability</category><category>privacy</category><description>Bias, transparency, consent and accountability are argued as separate problems in automated systems. They share a structure: a decision is produced that affects a person, and the capacity to demand an explanation has moved somewhere the person cannot reach. A single frame for the field, and what follows for anyone building these systems.</description></item>
<item><title>Two-Factor Authentication, Ranked</title><link>https://masoomi.dev/writing/two-factor-authentication-ranked</link><guid isPermaLink="true">https://masoomi.dev/writing/two-factor-authentication-ranked</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>The common second factors are not equivalent, and the differences are not marginal. An ordering by what each actually resists, why the weakest is still worth enabling, and the failure that defeats most of them regardless of which you chose.</description></item>
<item><title>What a Consent Record Actually Proves</title><link>https://masoomi.dev/writing/what-a-consent-record-proves</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-consent-record-proves</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>ai-ethics</category><description>Systems store a timestamp, a document version and an identifier, and call the result consent. That record answers one question well and a different question not at all. Which is which, why only one of the standard conditions is testable in code, and what a builder can do about it this quarter.</description></item>
<item><title>What a Model Cannot Know About Itself</title><link>https://masoomi.dev/writing/what-a-model-cannot-know-about-itself</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-model-cannot-know-about-itself</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>ai-ethics</category><category>security</category><description>Assistants are routinely asked how sure they are, why they answered as they did, and whether they can do a thing. Each answer is generated by the same process that produced the original output, which means it is a plausible continuation rather than an observation. What this rules out, and what to measure instead.</description></item>
<item><title>What a Security Audit Does Not Cover</title><link>https://masoomi.dev/writing/what-a-security-audit-does-not-cover</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-security-audit-does-not-cover</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>An audit report says something precise about a defined system at a defined moment. The badge on the website says something vague about a company forever. How to read the difference, and the four questions that recover the real meaning from a claim of having been audited.</description></item>
<item><title>What a VPN Does Not Do</title><link>https://masoomi.dev/writing/what-a-vpn-does-not-do</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-vpn-does-not-do</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>A VPN moves the point at which your traffic joins the public internet. That is a real and sometimes valuable change. It is not anonymity, it is not encryption of things that were not already encrypted, and it does not remove you from the systems that identify you.</description></item>
<item><title>What Happens When the Company Dies</title><link>https://masoomi.dev/writing/what-happens-when-the-company-dies</link><guid isPermaLink="true">https://masoomi.dev/writing/what-happens-when-the-company-dies</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><description>Assessments of a service ask whether it is secure and whether it is trustworthy. They rarely ask what becomes of the data if the company is sold, wound up, or simply stops. Those three endings have different mechanics and different consequences, and all three are ordinary.</description></item>
<item><title>What I Look For When I Audit a Service</title><link>https://masoomi.dev/writing/what-i-look-for-when-i-audit-a-service</link><guid isPermaLink="true">https://masoomi.dev/writing/what-i-look-for-when-i-audit-a-service</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>A practical procedure for assessing whether a service can do what it says about your data, written as an order of operations rather than a checklist. Most assessments are settled by the first two questions; the rest establish how much of the answer was deliberate.</description></item>
<item><title>What Smart Devices Send Home</title><link>https://masoomi.dev/writing/what-smart-devices-send-home</link><guid isPermaLink="true">https://masoomi.dev/writing/what-smart-devices-send-home</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>security</category><description>The argument about whether these devices record everything misses the more consequential point: the traffic they generate when working exactly as described already describes your household in detail. What leaves, what it reveals, and the questions that separate a device you can live with from one you cannot.</description></item>
<item><title>What Your Browser Extension Can See</title><link>https://masoomi.dev/writing/what-your-browser-extension-can-see</link><guid isPermaLink="true">https://masoomi.dev/writing/what-your-browser-extension-can-see</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>An extension with permission to read and change data on all sites can see everything the browser sees: the pages, the forms, the session that keeps you logged in. Why that permission is so commonly granted, what it actually permits, and how the risk arrives long after installation.</description></item>
<item><title>Who Are You Actually Defending Against</title><link>https://masoomi.dev/writing/who-are-you-actually-defending-against</link><guid isPermaLink="true">https://masoomi.dev/writing/who-are-you-actually-defending-against</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Advice is dispensed as though everyone faced the same adversary. The measures that protect against an opportunist are different from those that matter against somebody who knows you, and different again from an adversary with legal authority. A method for working out which set applies to you, and why copying somebody else&apos;s precautions usually wastes effort.</description></item>
<item><title>Who Holds the Key</title><link>https://masoomi.dev/writing/who-holds-the-key</link><guid isPermaLink="true">https://masoomi.dev/writing/who-holds-the-key</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><category>encryption</category><description>Transport encryption, storage encryption, password managers, backups, messaging, biometrics and cloud storage look like separate subjects. They are one question repeated: who is in a position to read this, and what would it take. A single frame for the whole field, and where each common arrangement sits inside it.</description></item>
<item><title>Why I Publish What My Software Cannot Do</title><link>https://masoomi.dev/writing/why-i-publish-what-my-software-cannot-do</link><guid isPermaLink="true">https://masoomi.dev/writing/why-i-publish-what-my-software-cannot-do</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>ai-reliability</category><category>privacy</category><description>Every product page lists capabilities. Almost none list the things the system is structurally unable to do. An argument for publishing limitations as a design discipline rather than a confession, and what changes in the engineering when you commit to it.</description></item>
<item><title>Why Phishing Still Works</title><link>https://masoomi.dev/writing/why-phishing-still-works</link><guid isPermaLink="true">https://masoomi.dev/writing/why-phishing-still-works</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Phishing is usually explained as a failure of user attention, which is why twenty years of telling people to be careful has not fixed it. A better explanation is that a convincing message arrives at a moment when it fits, and fitting is cheap to arrange.</description></item>
<item><title>You Cannot Verify the Code You Are Running</title><link>https://masoomi.dev/writing/you-cannot-verify-the-code-you-are-running</link><guid isPermaLink="true">https://masoomi.dev/writing/you-cannot-verify-the-code-you-are-running</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>encryption</category><description>Published source is treated as evidence that a program does what it claims. It is evidence about a repository. Between that repository and the binary on your machine sit a compiler, a build machine, a distribution channel and an update mechanism, none of which the source describes. What closes parts of the gap, and what remains open.</description></item>
<item><title>Your Car Is a Data Broker</title><link>https://masoomi.dev/writing/your-car-is-a-data-broker</link><guid isPermaLink="true">https://masoomi.dev/writing/your-car-is-a-data-broker</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><description>A modern car knows where it goes, how it is driven, who is in it, what is said near the microphone and which phone is paired to it. It has a permanent connection, an opaque update channel, and no meaningful setting to turn any of it off. What that implies, and the few points where a driver still has leverage.</description></item>
<item><title>Your Password Manager Is Not the Weak Link</title><link>https://masoomi.dev/writing/your-password-manager-is-not-the-weak-link</link><guid isPermaLink="true">https://masoomi.dev/writing/your-password-manager-is-not-the-weak-link</guid><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Putting every password in one place sounds like concentrating risk, and the intuition is not stupid. It is wrong because it compares the wrong two options: not a manager against perfect discipline, but a manager against what people actually do instead.</description></item>
<item><title>Before You Post That Photograph</title><link>https://masoomi.dev/writing/before-you-post-that-photograph</link><guid isPermaLink="true">https://masoomi.dev/writing/before-you-post-that-photograph</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>ai-ethics</category><description>Practical measures for photographs you share online, ordered by how much they actually change, and honest about which are close to useless. A companion to a longer argument about what retained images are worth to the systems that keep them.</description></item>
<item><title>Browser-Level Encryption: What the Padlock Does Not Cover</title><link>https://masoomi.dev/writing/browser-level-encryption</link><guid isPermaLink="true">https://masoomi.dev/writing/browser-level-encryption</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>encryption</category><category>privacy</category><description>TLS protects a file while it moves. It stops protecting it the moment it arrives. This is the distinction between transport encryption, encryption at rest, and end-to-end encryption performed in the browser — stated in terms of who holds the key at each stage, because that is the only question that separates them.</description></item>
<item><title>Free Is a Price</title><link>https://masoomi.dev/writing/free-is-a-price</link><guid isPermaLink="true">https://masoomi.dev/writing/free-is-a-price</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>security</category><category>ai-ethics</category><description>Every service is paid for. When the user is not the payer, the revenue has to come from somewhere, and the shape of that somewhere determines what the product is motivated to do. A method for reading a business model off a service before you build anything on top of it.</description></item>
<item><title>What a Breach Actually Leaks</title><link>https://masoomi.dev/writing/what-a-breach-actually-leaks</link><guid isPermaLink="true">https://masoomi.dev/writing/what-a-breach-actually-leaks</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><description>Breach notifications are written to be survivable, which makes them poor instructions. This separates the categories of data a breach can expose by how long each stays dangerous, and gives the reader a way to decide what to do that does not depend on the wording of the notice.</description></item>
<item><title>What the Model Remembers</title><link>https://masoomi.dev/writing/what-the-model-remembers</link><guid isPermaLink="true">https://masoomi.dev/writing/what-the-model-remembers</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>privacy</category><category>ai-ethics</category><description>Pasting a document into a chat assistant is not the same kind of act as searching for something. This separates what happens to that text — the request, the retention, the human review, the training set — and gives the questions that distinguish a service that cannot read your input from one that merely says it will not.</description></item>
<item><title>Who Holds the Key: How files.vualet Differs From Dropbox by Design</title><link>https://masoomi.dev/writing/who-holds-the-key-vualet-dropbox</link><guid isPermaLink="true">https://masoomi.dev/writing/who-holds-the-key-vualet-dropbox</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>security</category><category>encryption</category><category>product</category><description>Dropbox encrypts files in transit and at rest, and holds the keys that open them. files.vualet is being built so that it cannot. This sets out the architectural difference, separates what is true today from what is intended, and gives the reader the three questions that settle it for any service.</description></item>
<item><title>You Are the Training Set</title><link>https://masoomi.dev/writing/you-are-the-training-set</link><guid isPermaLink="true">https://masoomi.dev/writing/you-are-the-training-set</guid><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>privacy</category><category>surveillance</category><category>ai-ethics</category><description>A birthday photograph uploaded today is not consumed and discarded. It is retained, indexed, and used to teach systems that will still be running when the child in it is grown. This is an argument about what that permits, written as a scenario, because the mechanism is ordinary and the consequence is not yet.</description></item>
<item><title>600 File Reads to Serve One Article</title><link>https://masoomi.dev/writing/six-hundred-file-reads</link><guid isPermaLink="true">https://masoomi.dev/writing/six-hundred-file-reads</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>nextjs</category><category>performance</category><category>content-architecture</category><description>A measured account of read amplification in a file-backed Next.js content site: 600 disk reads per article request at 300 documents, reduced to 2, and the security surface the fix created along the way.</description></item>
<item><title>A Nonce Is Not a Security Upgrade If Your Pages Are Static</title><link>https://masoomi.dev/writing/nonce-csp-static-prerender</link><guid isPermaLink="true">https://masoomi.dev/writing/nonce-csp-static-prerender</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>web-security</category><category>nextjs</category><category>content-security-policy</category><description>Tightening script-src to a per-request nonce is standard hardening advice. On a statically prerendered Next.js site it silently disables all JavaScript on every static route, and nothing in the build, the test suite or the response headers will tell you.</description></item>
<item><title>Exit Zero Means Nothing</title><link>https://masoomi.dev/writing/exit-zero-means-nothing</link><guid isPermaLink="true">https://masoomi.dev/writing/exit-zero-means-nothing</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>ai-reliability</category><category>verification</category><category>autonomous-agents</category><description>An account of measured verification theatre across autonomous agents, shell pipelines and accessibility affordances, and the small set of checks that distinguish work reported as done from work that happened.</description></item>
<item><title>Your Prerendered Pages Return 404 on Cloudflare Workers</title><link>https://masoomi.dev/writing/prerendered-404-cloudflare-workers</link><guid isPermaLink="true">https://masoomi.dev/writing/prerendered-404-cloudflare-workers</guid><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Abdolmadjid Masoomi</dc:creator><category>nextjs</category><category>cloudflare-workers</category><category>opennext</category><category>deployment</category><description>Prerendered pages of a dynamic route are served through OpenNext&apos;s incremental cache, not from the asset bucket. With no cache adapter configured they 404 in production while every static route works and the build reports success.</description></item>
</channel></rss>