Google Exposes a Paw and a Vulnerability

May 20, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Google is a BAIT outfit. “BAIT” means in my lingo “big AI technology.” The companies upon which I bestow the moniker are different from the run-of-the-mill Silicon Valley outfit for several reasons:

  1. The stakes are very high. One company will eventually become the sun in the AI universe; other BAIT outfits will orbit it.
  2. Innovation is becoming increasingly competitive. The reason is that very few BAIT outfits have done much more than wrapped software around Google’s “Attention Is All You Need” essay and the fact that most of the people in the world use Google products and services. That’s gravitational pull.
  3. Traditional management methods for a BAIT outfit just don’t work very well. Whether it is the bonkers trial between the luminaries of Grok and OpenAI or the somewhat wonky effort to build data centers when zoning, power, and water are not cooperating, BAIT outfits are stirring up chaotic storms.
  4. The total win mentality throws out the rule book for everything that a traditional business once cherished.

image

Two entrepreneurs get a cloud invoice. These innovators can’t pay for food. A giant bill for cloud services means their dream has done up in smoke. Thanks, Venice.ai. Good enough.

I don’t want to write about Google’s human resource challenges. Personally I don’t think the AI protest roiling Google’s UK unit is going to end with the Prince falling in love with Snow White. I am not sure that Google’s injection of more and more advertising is going to keep customers happy or eagerly paying money to watch cable TV Google style. I am also skeptical that Google’s method of shoving AI into its nooks and crannies will deliver user happiness. I had to terminate a simple test of Gemini on May 11, 2026, because Gemini kept crashing and losing data. Yep, nice work, Gemini.

Instead I want to point to an article in Cybernews titled “Google Cloud Developers Going Bankrupt Over Gemini API Key Abuse: Hard Spending Caps Now Available.” The article asserts:

The Google Cloud’s subreddit has turned into a bottomless pit of people wailing over massive cost overruns and spending caps that don’t cap spending. And the cited sums are devastating. Here are just a few of the headlines posted over the past months:

  • Went to bed with a $10 budget alert. Woke up to $25,672.86 in debt to Google Cloud.
  • 80,000 NOK ($7,500) drained from my Google Cloud account in 5 minutes – full forensic breakdown of how the attack worked.
  • Charged $10,138 in March 2026 due to Google’s documented Gemini API key vulnerability – support closed my case twice, saying “no fraud found.”
  • WARNING: Google Cloud/Gemini API ”Spend Caps” do NOT work in real-time ($1,800 charged on a $100 cap).
  • Google Cloud detected $975 of API key fraud on my account, sent one email at 11 p.m., then let the bill grow to $18,596 – 5 support agents have refused to help.
  • $10 budget alert – hijacked Gemini API Key billed $1,300 in a few minutes.

I recall similar tales of woe from the early days of the Internet. People set up sites and then opened their monthly invoice to discover the fascinating pricing mechanisms based on tiers. As traffic went up, so did the online fees. I also recall tales of woe related to Amazon’s cloud services. Due to the brilliant interface and outstanding documentation, an AWS customer would receive a “surprise”; for example, a low cost service explodes to a high cost service without warning. The trick is that some AWS users had no idea what happened. Well, welcome to the exciting world of unilateral billing policy changes.

After doing a couple of projects for what was the old AT&T and Bell Labs outfits, I learned that these billing mechanisms were neither new or out-of-bounds. What happened is that more people than ever jumped into online and learned about pricing thresholds, special services, and tiering really meant: Money for good old Ma Bell. Yes, there was a reason the old AT&T morphed into the wonderful oligopolies we enjoy today in the US of A.

Now back to the write up in Cybernews. I noted this passage:

It appears Google Cloud has no hard spending caps, and its fraud detection tools, while capable of flagging suspicious activity, do not take automated actions to stop the abuse.

Cybernews continued:

In February [2026], Truffle Security discovered that old Google API keys, previously used in other projects as harmless identifiers, overnight became ticking time bombs once they were granted access to the Gemini API. Thousands of multipurpose Google API keys can be found exposed on websites, code repositories, apps, and elsewhere, and Google itself previously encouraged users to “safely embed them in client code.” Truffle Security even demonstrated the attack by using Google’s own exposed API keys to hit the Gemini API, and found thousands of API keys belonging to major financial institutions and other companies. “If the vendor’s own engineering teams can’t avoid this trap, expecting every developer to navigate it correctly is unrealistic.”

Google pushes actions down. People move to other teams. The result is, “Yo, no kidding.” Without a functional customer support system and spotty or non-existent documentation, using Google can be an interesting problem for a customer. When a surprise invoice arrives, the institutional memory of who, what, why, when, and how seems diaphanous or a chimera.

What’s the fix? My interpretation of the write up, is, “The customer is responsible.” Yep, global penetration to most countries on earth with billions of users. “Hey, user, it is your job.” The approach is convenient, and it explains in part the thrills and chills of relying on Google.

As I said, Gemini did not work on May 11, 2026. It is my fault. Pay your bill. Oh, and the AT&T pricing model. Former Bell and AT&T employees once worked at the Google. Their contributions are numerous just like the digits on some of those surprise invoices.

Stephen E Arnold, May 20, 2026

France Lines Up to Gore Some US Tech Bros

April 13, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

France has élan. My interest in the reactions of people who visit the country for the first time is keen. We live in rural Kentucky, and at get togethers which often involve cooking a freshly killed pig or wearing Derby pins and drinking local beverages, tales of travelers’ experiences are exchanged. Some people love the food, but report the waiters ignored them. Other say, “I entered a bakery and said, ‘Hello,’ and no one waited on me.” The tales of getting a hefty fine on the metro, visiting a small town and finding the shops closed for lunch, and the bafflement when a Kentuckians’ passport and wallet are stolen a few minutes after landing at the Marseille France Airport are far too common.

image

Venice.ai, you don’t know a French gendarme from a guardrail. Good enough.

Imagine how Americans working at Microslop, sorry, I meant to type Microsoft are reacting to this French decision: “France Says “Au Revoir” to Windows, “Bonjour” to Linux.” To be fair, I don’t know if French people who use Microsoft products will switch. The government agencies will adapt over time. Nevertheless, the decision is delightfully French.

The cited article reports:

France is planning a major shift in its government technology infrastructure, announcing its intention to move away from Microsoft Windows in favor of Linux. The decision marks a significant step in the country’s broader effort to reduce reliance on U.S.-based technology companies and regain control over its digital systems. The transition will begin with government workstations, particularly within key digital agencies, as part of a wider strategy to adopt open-source and locally controlled technologies.

From my point of view, this is just one example of the steps France and other countries will be taking to wean themselves from the tech bros’ approach to computers, online information, and software. Pressure is likely to be exerted on French government contractors to ensure that “digital sovereignty” is part of the work process.

What’s this mean for French technology firms? I would assume that big outfits like Dassault Systèmes-type organizations will comply, probably on a negotiated timeline. Private startups will use whatever is cheaper and does the job. If that means, Microsoft PowerPoint, those firms will do what they can until France ratchets up the pressure. Who can forget the arrest of Pavel Durov in August 2024. That action appears to have put a hitch in the Telegram git-along.

The write up points out:

Government leaders have emphasized the need to regain control over national data, infrastructure, and decision-making systems, rather than depending on foreign technology providers.

The write up adds:

France’s move highlights a growing shift in how nations view technology – not just as a tool for productivity, but as a strategic asset tied to sovereignty, security, and long-term independence.

My take: More bad news for US technology companies is coming. Next up will be actions directed at US firms’ business practices. In fact, at some point, I can see an American tech bro landing his private jet at a French airport. He will be detained and charges will be filed. He will be able to leave France, but the French wheels of justice will grind forward. Many things can result from this type of French direct action.

Today Linux Tomorrow maybe a Silicon Valley luminary. Just a thought.

Stephen E Arnold, April 13, 2026

A Pragmatic Look at Data Center Power: Just Turn Everything on at Once. No Problemo.

March 12, 2026

green-dino_thumb_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

A happy honk to the UK online information service the Register. “Your Datacenter’s Power Architecture Called. It’s Not Happy” presents some useful information about how AI compute data centers operate when the “on” button is pressed. The article explores in reasonably a non-EE geeky way some of the different facets of taking a corn field in Louisiana or a tobacco farm in Tennessee and building a five soccer field size data center. Heck, make it bigger. Land is cheaper than in Manhattan. Go for 20 soccer fields of AI compute hardware.

image

Yep, AI is close enough for horseshoed. Thanks, MidJourney. Nice fire.

The write up says:

GPU clusters and AI accelerators don’t operate on the old rules. They don’t ask for 15 kW. They demand hundreds of kilowatts per rack, an order-of-magnitude leap that legacy electrical and thermal architectures were never designed to survive. The comfortable assumptions baked into decades of datacenter design are now liabilities, and the industry is facing a reckoning it can no longer defer.

What? Are big time AI outfits kicking the can down the road or simply ignoring the fact that “power” is just there. It’s like water. In their accelerated lives, power has not been top of mind. Now the whiz kids at big tech AI companies have an opportunity to learn about the challenges their acres of computers and assorted gizmos will require.

The write up identifies a number of issues; for example:

Let’s talk about the current-squared problem and resistive losses. Because power loss scales with the square of the current, even small reductions in current lead to significant increases in efficiency. The power distribution efficiency is governed by Joule resistive loss (Ploss</loss> = I2R).

If you are not into this power lingo, the author seems to be saying that the new AI compute data centers require some extra engineering. Why? The pricey CPUs and GPUs can run hot. These devices plus RAM and solid state storage are voltage?sensitive. Even idle or under utilized racks can run at higher temperatures than old-fashioned data center racks. When demand hits to create a video for grandma, the AI compute system has to deal with heat. AI centric systems can throttle themselves. Pushing harder means that electrical noise can become a factor. Furthermore, failover is harder because the stacks are non?identical and latency?sensitive.

How do you deal with infrastructure challenges, power, and cooling? Answer: Novel engineering and money. The problem is that these big AI compute data centers are now the equivalent of the room-sized mainframes in the late 1950s. The solutions make 20 somethings laugh when the Smithsonian in DC puts some of its historical hardware on display.

The real equations are not the EE marvels. Nope, the basic equations pivot on the cost of time required to engineer, design, test, and manufacture the components necessary to keep power draw lower and temperatures even lower. At the same time, the solutions have to allow the CPUs and GPUs to go fast.

Accelerationists think about software. Accountants and people with common sense think about plumbing. Experienced professionals think about time and how much it costs to crunch quite challenging engineering into tiny intervals. Speed can kill data centers, the financial dreams of high tech whiz kids, and some businesses.

What happens when one tries to scale these nifty data centers? No big deal. We are big tech doing AI. We have the answers.

Stephen E Arnold, March 12, 2026

Google Finally Has a Winning Play in the eGame Sector

February 5, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

Google has had interest in online games, gaming, eGames, and related pastimes for a couple of decades. But control of online games like the online ad agency’s control of Web search has eluded the friendly outfit. I recall Google’s interest in an online gaming tie up in the early 2000s. I don’t think I heard much about that other than it was a non-starter.

You may or may not recall such Google efforts as Android gets the default Google Play store as a way to “get” games. Google did a service within YouTube focused on eGames. Google fiddled around with a social media play in eGames which was part of the Google+ service. There was, I believe, there was a me-too of Apple’s Game Center for Android. About a decade ago, the Google tried to buy Twitch, showing that gamer eyeballs seemed important in 2014. In 2019, Google rolled out the barrels of money and created Stadia. The store and other parts of the service were just killed. Someone at Google rounded up “leadership” support for a Google Play Pass, and I still don’t know what that provides. There is something called “Game Snacks.” Plus the Stadia “technology” is floating around in the Google Cloud or was the last time I checked. I think what I remember is that Google was doing its Don Quixote approach: Keep going until one kills a windmill… in an eGame or a Google wizard’s mind.

image

A large creature named Googzilla is really excited about its stumbling into a greenfield with bundles of cash to pick up and use. There’s no competition in sight. Now all the creature has to do is wait for the developers, eGame companies, and players to come to this field and have fun. The creature will just gather up the money, of course. Thanks, Venice.ai. Good enough.

Google may have made its mark on gaming.

I read “Videogame Stocks Slide on Google’s AI Model That Turns Prompts into Playable Worlds.” The trusted news source’s story says:

The AI model, dubbed “Project Genie”, allows users to simulate a real-world environment through prompts with text or uploaded images, potentially disrupting how video games have been made for over a decade and forcing developers to adapt to the fast-moving technology…. Project Genie also has the potential to shorten lengthy development cycles and reduce costs, as some premium titles take around five to seven years and hundreds of millions of dollars to create. Videogame developers have been increasingly adopting artificial intelligence as a way to stand out in a highly competitive industry dominated by large players. A Google study last year showed that nearly 90% of game developers use AI agents.

I interpret this to mean:

  1. Google has taken a step toward becoming the go-to source for some of the most expensive and tedious part of game development
  2. Google has made it clear that as its AI improves, the smart game outfits will use Google services
  3. Consumers of eGames will look for game experiences enhanced, built upon, and generated by Google. (Why not just do everything related to the eGame in Google?)

Adding up these points, Google may have found a way to begin to expand its eGame capabilities attracting independent developers, forcing eGame giants to realize the value of their firms and products can be affected by the long-time eGame fumbler, and disrupting the how of eGames.

Net net: This is a big deal. My hunch is that Google finally rolled out something that would allow the firm to increase its eGame revenue. In my opinion, Googzilla stumbled into a green field of money. How long will it take regulators and consumer advocates to understand the impact of this new eGame success? A long, long time.

Stephen E Arnold, February 5, 2026

Microsoft: Parallel Wagering and Risk

January 30, 2026

green-dino_thumbAnother dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.

I had a French teacher who loved French proverbs. Her name was Madame Matthews, and she was a German teaching French in a one-horse town in central Illinois. I vaguely recall that one of her lessons was a knock off of what I thought was a British proverb. Here it is in la langue de Molière:

Le jeu est le fils de l’avarice et le père du désespoir.

However, I just read “Microsoft Lost $357 Billion in Mark Cap As Stock Plunged Most Since 2020.” That’s a big bet Satya Nadella made, and it has been working. Until now. Then I read “Microsoft Shares Dive as Data Center Spending Overshadows Earnings Surge.” Yep:

Le jeu est le fils de l’avarice et le père du désespoir.

Big bets. Big risk.

image

A wealthy professional is gambling at multiple games of chance at the same time. A crowd is watching, amazed that this person would play blackjack, run the slots, and hope that the roulette ball in on his wave length. Thanks, Venice. Good enough.

Now let’s put this swing for the fences strategy in the context of a run of the mill user. “Microsoft Is Working to Rebuild Trust in Windows” provides some consulting type lingo to the “experience” of using the world’s most popular operating system. That article offers:

Windows is at breaking point, and Microsoft knows it. Sources familiar with the company’s plans tell me Windows engineers are now focusing on fixing the core issues of Windows 11 over the coming months, in a process known as “swarming.” Microsoft is redirecting engineers to urgently fix Windows 11’s performance and reliability issues, aiming to halt the operating system’s death by a thousand cuts.

Let’s think about Microsoft and the interesting idea of “fixing the core issues.”

Microsoft is the juicy target for many bad actors. Some of the vulnerabilities have been known and exploited for years. In Tallinn, Estonia, I spoke with an advanced computer science class. One of the students said, “Yeah, Windows is pretty easy to exploit.” When was I in Estonia? How about 2006? The class was learning what flaws Windows had because it was a big, fat, floppy target.

Next let’s consider that Microsoft is using AI to code its different services. The only problem is that some of that code output by smart software has flaws. Humans may not be available to grind through the outputs searching for snipes. My recollection is that snipes were quite difficult to locate.

Also, consider that Microsoft has allowed interns, contract workers, real live on site programmers to add features and functions to Windows that demonstrate progress, commits, or innovations for the sole purpose of getting a raise, bonus, or  promotion. I gave a lecture at Microsoft after which there was a reception. I spoke with a senior lead something in the Word unit. I asked if the word processor would ever include the type of numbering system used by the law firms with which I interacted. He said, “No. No need.” Right! No need. There were specialists like the little outfit in Charlottesville, Virginia, which figured out how to make Word number the way lawyers and courts want documents numbered. That little outfit made a lot of money selling its widget to law firms. Microsoft was right, “No need.”

And to end this list of issue, allow me to point out that the interface across the heavy lifting apps like PowerPoint and Visio is not normalized. Exactly how does one add specific tools to custom toolbar without first mastering the art of solving the Riemann Hypothesis? Microsoft tries but seems to lose sight of the duck it is trying to hit with its over engineered incentive system.

Now let’s think about the French proverb. My view is that Satya Nadella has gambled, bet a lot, and is now thinking, “Now what?” Investors appear to be thinking, “Yeah, now what?” With layoffs looming, some Microsofties are thinking, “Okay, now what?”

Talk about energizing Google and the makers of Linux distributions aimed at consumer computer users is amping up. Okay, Mr. Nadella, “Now what?” But more AI? Build more data centers and carry the cost of electricity so consumers are not burdened? Do the Elon thing and power the data centers with turbines or just install one of those July 2026 mini nuclear reactors?

This proverb is one that Madame Matthews might suggest you analyze in 500 words:

Le jeu est le fils de l’avarice et le père du désespoir.

Mr. Nadella is not playing one game. He is parallel betting. Does that reduce risk or increase it? Why not ask OpenAI?

Stephen E Arnold, January 30, 2026

Amazon AWS: Two Pizza Team Engineering Delivers Indigestion to Lots of People

October 20, 2025

green-dino_thumbNo smart software. Just a dumb and quite old dinobaby.

Years ago an investment bank asked me to write a report about Amazon’s technical infrastructure. I had visited Amazon as part of a US government entity. Along with four colleagues from different agencies, I had an opportunity to ask about how Amazon’s infrastructure could be used as an online services platform. I did not get an answer, just marketing talk. One of the phrases stuck with me; to wit, “We use two pizza teams.”

The idea is that no technical project can involve more developers than two pizzas can feed. I was not sure if this was brilliant, smart assery, or an admission that Amazon was a “good enough” engineering organization.

I had a couple of other Amazon projects after that big tech study. One was to analyze Amazon’s patents for blockchain. Let me tell you. Those Amazon engineers were into cross chain methods and a number of dizzying engineering innovations. Where did that blockchain stuff go? To tell the truth, I don’t have many Amazon blockchain items lighting up my radar. Then I did a report for a law enforcement group interested in Amazon’s drone demonstration in Australia. The idea was that Amazon’s drone had image recognition. The demo showed the drone spotting a shark heading toward swimmers. The alert was sounded and the shark had to go find another lunch spot. What happened to that? I have no idea. Then … oh, well, you get the idea.

Amazon does technology which seems to be  okay with leasing Kindle books and allowing third party resellers to push polo shirts. The Ring thing, the Alexa gizmo, and other Amazon initiatives like its mobile phone were not hitting home runs.

I read “Widespread Internet Outage Reported As Amazon Web Services Works on Issue.” [This is a Microsoft link. If it goes dead, don’t call me. Give Copilot a whirl.] Okay, order those pizzas. The write up reports:

The Amazon cloud computing company, which supports wide swaths of the publicly available internet, issued an update Monday just after 3 p.m. ET saying that the company continues to “observe recovery across all AWS services.” “We are in the process of validating a fix,” AWS added, referring to a specific problem set off by the connectivity issue announced shortly after 3 a.m. Eastern Time.

Okay, that’s 12 hours and counting.

I want to point out that the two-pizza approach to engineering is cute. The reality is that AWS is vulnerable. The outage may be a result of engineering flubs. You are familiar with those. The company says, “An intern entered a invalid command.” The outage may be a result of Amazon’s giant and almost unmanageable archipelago of servers, services, software, and systems was hacked by a bad actor. Maybe it was one of those 1,000 bad actors who took out Microsoft a couple of years ago? Maybe it was a customer who grew frustrated with inexplicable fees and charges? Maybe it was a problem caused by an upstream or downstream vendor? One thing is sure: It will take more than a two pizza team to remediate and prevent the failure from happening again.

In that first report for the California money guys, I made one point: The AWS system will fail and no one will know exactly what went wrong.

Two pizza engineering is a Groucho Marx type of quip.  Now we know what one gets: Digital food poisoning.

Stephen E Arnold, October 20, 2025 at 530 pm US Eastern

Blue Chip Consultants: Spin, Sizzle, and Fizzle with AI

October 14, 2025

green-dino_thumbThis essay is the work of a dumb dinobaby. No smart software required.

Can one quantify the payoffs from AI? Not easily. So what’s the solution? How about a “free” as in “marketing collateral” report from the blue-chip consulting firm McKinsey & Co. (You know that outfit because it figured out how to put Eastern Kentucky, Indiana, and West Virginia on the map.)

I like company reports like “Upgrading Software Business Models to Thrive in the AI Era.” These combine the weird spirit of Ezra Pound with used car sales professionals and blend in a bit of “we know more” rhetoric. Based on my experience, this is a winning combination for many professionals. This document speaks to those in the business of selling software. Today software does not come in boxes or as part of the deal when one buys a giant mainframe. Nope, software is out there. In the cloud. Companies use cloud solutions because — as consultants explained years ago — an organization can fire most technical staff and shift to pay-as-you go services. That big room that held the mainframe can become a sublease. That’s efficiency.

This particular report is the work of four — count them — four people who can help your business. Just bring money and the right attitude. McKinsey is selective. That’s how it decided to enter the pharmaceutical consulting business. Here’s a statement the happy and cooperative group of like-minded consultants presented:

while global enterprise spending on AI applications has increased eightfold over the last year to close to $5 billion, it still only represents less than 1 percent of total software application spending.

Converting this consultant speak to my style of English, the four blue chippers are trying to say that AI is not living up to the hype. Why? A software company today is having a tough time proving that AI delivers. The lack of fungible proof in the form of profits means that something is not going according to plan. Remember: The plan is to increase the revenue from software infused with AI.

Options include the exciting taxi meter approach. This means that the customers of enterprise software doesn’t know how much something costs upfront. Invoices deliver the cost. Surprise is not popular among some bean counters. Amazon’s AWS is in the surprise business. So is Microsoft Azure. However, surprise is not a good approach for some customers.

Licensees of enterprise software with that AI goodness mixed in could balk at paying fees for computational processes outside the control of the software licensee. This is the excitement a first year calculus student experiences when the values of variables are mysterious or unknown. Once one wrestles the variables to the ground, then one learns that the curve never reaches the x axis. It’s infinite, sport.

Pricing AI is a killer. The China-linked folks at Deepseek and its fellow travelers are into the easy, fast, and cheap approach to smart software. One can argue whether the intellectual property is original. One cannot argue that cheap is a compelling feature of some AI solutions. Cue the song: Where or When with the lines:

It seems we stood and talked like this before
We looked at each other in the same way then
But I can’t remember where or QWEN…

The problem is that enterprise software with AI is tough to price. The enterprise software company’s engineering and development costs go up. Their actual operating costs rise. The enterprise software company has to provide fungible proof that the bundle delivers value to warrant a higher price. That’s hard. AI is everywhere, and quite a few services are free, cheap or, or do it yourself code.

McKinsey itself does not have an answer to the problem the report from four blue chip consultants has identified. The report itself is start evidence that explaining AI pricing, operational, and use case data is a work in progress. My view is that:

  1. AI hype painted a picture of wonderful, easily identifiable benefits. That picture is a bit like a AI generated video. It is momentarily engaging but not real.
  2. AI state of the art today is output with errors. Hey, that sounds special when one is relying on AI for a medical diagnosis for your child or grandchild or managing your retirement account.,
  3. AI is a utility function. Software utilities get bundled into software that does something for which the user or licensee is willing to pay. At this time, AI is a work in progress, a novelty, and a cloud of unknowing. At some point, the fog will clear, but it won’t happen as quickly as the AI furnaces burn cash.
  4. What to sell, to whom, and pricing are problems created by AI. Asking smart software what to do is probably not going to produce a useful answer when the enterprise market is in turmoil, wallowing in uncertainty, and increasingly resistant to “surprise” pricing models.

Net net: McKinsey itself has not figured out AI. The idea is that clients will hire blue chip consultants to figure out AI. Therefore, the more studies and analyses blue chip consultants conduct, the closer these outfits will come to an answer. That’s good for the consulting business. The enterprise software companies may hire the blue chip consultants to answer the money and value questions. The bad news is that the fate of AI in enterprise software developers is in the hands of the licensees. Based on the McKinsey report, these folks are going slow. The mismatch among these players may produce friction. That will be exciting.

Stephen E Arnold, October 14, 2025

Cloud Storage: Working Really Well Most of the Time

September 10, 2025

If true, cloud services are outstanding. does Microsoft’s Cloud and Azure behave like this?

We at Beyond Search love the cloud. You love the cloud. Everyone loves the cloud. Except when the cloud deletes your entire life’s work. That’s what happened to one unfortunate soul according to a Seuros blog post and shared via Windows Central: “AWS Data Crisis: Engineer Restores 10 Years of Work Thanks To A Compassionate Insider.”

The victim is known as Abdelkader Boudih (aka Seuros) and he saved a lot of developer tools on the AWS cloud so is desktop wouldn’t be crowded. Here a description of the situation:

“When AWS deleted my account, they didn’t just hurt me. They hurt every developer who uses my gems. Every student who could have learned from those tutorials. Every future contribution that won’t happen because my workflow is destroyed.”

Darn.

Boudih stated he had backups of his backups and followed all proper procedures but he didn’t expect AWS to be a problem. The scenario began with AWS asking Boudih for verification, but he didn’t see it until it was past expiation. He then had to send in a bill and a copy of his ID. AWS said the files were unreadable. His account then went bye-bye.

There’s a ninety day grace period before AWS deletes all data. He spoke with customer support and never received straight answers. He did receive emails asking him to rate AWS’s service and give them five stars. Brilliant!

Anyone else recognize the frustration?

Here’s the conspiracy theory:

“This is no doubt in response to Boudih’s claims that an AWS insider had reached out shortly after the Seuros blog post began circulating publicly.

The insider suggested that AWS MENA (the second acronym stands for Middle East and North Africa) was "running some kind of proof of concept on ‘dormant’ and ‘low-activity’ accounts." It wasn’t just Boudih’s account that was affected.

It gets technical from this point on, but it basically boils down to the assumption that an AWS developer typed the wrong command and ended up deleting accounts that were still very much in use, like Boudih’s.

There’s no real proof that any of this happened, but Boudih points to the slow progress and ineffective feedback from support as explanations for a potential cover-up.”

The lesson to be learned here is to never rely on third-party storage vendors. Doesn’t anyone use external hard drives anymore? Of course not, the cloud is just there. What worry?

Whitney Grace, September 10, 2025

Cyber Security: Evidence That Performance Is Different from Marketing

August 20, 2025

Dino 5 18 25This blog post is the work of an authentic dinobaby. Sorry. No smart software can help this reptilian thinker.

In 2022, Google bought a cyber security outfit named Mandiant. The firm had been around since 2004, but when Google floated more than $5 billion for the company, it was time to sell.

If you don’t recall, Google operates a large cloud business and is trying diligently to sell to Microsoft customers in the commercial and government sector. A cyber security outfit would allow Google to argue that it would offer better security for its customers and their users.

Mandiant’s business was threat intelligence. The idea is that Mandiant would monitor forums, the Web, and any other online information about malware and other criminal cyber operations. As an added bonus, Mandiant would blend automated security functions with its technology. Wham, bam! Slam dunk, right?

I read “Google Confirms Major Security Breach After Hackers Linked To ShinyHunters Steal Sensitive Corporate Data, Including Business Contact Information, In Coordinated Cyberattack.” First, a disclaimer. I have no idea if this WCCF Tech story is 100 percent accurate. It could be one of those Microsoft 1,000 Russian programmers are attacking us” plays. On the other hand, it will be fun to assume that some of the information in the cited article is accurate.

With that as background, I noted this passage:

The tech giant has recently confirmed a data breach linked to the ShinyHunters ransomware group, which targeted Google’s corporate Salesforce database systems containing business contact information.

Okay. Google’s security did not work. A cloud customer’s data were compromised. The assertion that Google’s security is better than or equal to Microsoft’s is tough for me to swallow.

Here’s another passage:

As per Google’s Threat Intelligence Group (GTIG), the hackers used a voice phishing technique that involved calling employees while pretending to be members of the internal IT team, in order to have them install an altered version of Salesforce’s Data Loader. By using this technique, the attackers were able to access the database before their intrusion was detected.

A human fooled another human. The automated systems were flummoxed. The breach allegedly took place.

Several observations are warranted:

  1. This is security until a breach occurs. I am not sure that customers expect this type of “footnote” to their cyber security licensing mumbo jumbo. The idea is that Google should deliver a secure service.
  2. Mandiant, like other threat intelligence services, allows the customer to assume that the systems and methods generally work. That’s true until they don’t.
  3. Bad actors have an advantage. Armed with smart software and tools that can emulate my dead grandfather, the humans remain a chink in the otherwise much-hyped armor of an outfit like Google.

What this example, even if only partly accurate, makes it clear than cyber security marketing performs better than the systems some of the firms sell. Consider that the victim was Google. That company has touted its technical superiority for decades. Then Google buys extra security. The combo delivers what? Evidence that believing the cyber security marketing may do little to reduce the vulnerability of an organization. What’s notable is that the missteps were Google’s. Microsoft may enshrine this breach case and mount it on the walls of every cyber security employees’ cubicles.

I can imagine hearing a computer-generated voice emulating Bill Gates’, saying, “It wasn’t us this time.”

Stephen E Arnold, August 20, 2025

Microsoft Investigates Itself and a Customer: Finding? Nothing to See Here

May 26, 2025

dino orangeNo AI, just a dinobaby and his itty bitty computer.

GeekWire, creator of the occasional podcast, published “Microsoft: No Evidence Israeli Military Used Technology to Harm Civilians, Reviews Find.” When an outfit emits occasional podcasts published a story, I know that the information is 100 percent accurate. GeekWire has written about Microsoft and its outstanding software. Like Windows Central, the enthusiasm for what the Softies do is a key feature of the information.

What did I learn included:

  • Israel’s military uses Microsoft technology
  • Israel may have used Microsoft technology to harm non-civilians
  • The study was conducted by the detail-oriented and consistently objective company. Self-study is known to be reliable, a bit like research papers from Harvard which are a bit dicey in the reproducible results department
  • The data available for the self-study was limited; that is, Microsoft relied on an incomplete data set because certain information was presumably classified
  • Microsoft “provided limited emergency support to the Israeli government following the October 7, 2023, Hamas attacks.”

Yeah, that sounds rock solid to me.

Why did the creator of Bob and Clippy sit down and study its navel? The write up reported:

Microsoft said it launched the reviews in response to concerns from employees and the public over media reports alleging that its Azure cloud platform and AI technologies were being used by the Israeli military to harm civilians.

The Microsoft investigation concluded:

its recent reviews found no evidence that the Israeli Ministry of Defense has failed to comply with its terms of service or AI Code of Conduct.

That’s a fact. More than rock solid, the fact is like one of those pre-Inca megaliths. That’s really solid.

GeekWire goes out on a limb in my opinion when it includes in the write up a statement from an individual who does not see eye to eye with the Softies’ investigation. Here’s that passage:

A former Microsoft employee who was fired after protesting the company’s ties to the Israeli military, he said the company’s statement is “filled with both lies and contradictions.”

What’s with the allegation of “lies and contradictions”? Get with the facts. Skip the bogus alternative facts.

I do recall that several years ago I was told by an Israeli intelware company that their service was built on Microsoft technology. Now here’s the key point. I asked if the cloud system worked on Amazon? The response was total confusion. In that English language meeting, I wondered if I had suffered a neural malfunction and posed the question, “Votre système fonctionne-t-il sur le service cloud d’Amazon?” in French, not English.

The idea that this firm’s state-of-the-art intelware would be anything other than Microsoft centric was a total surprise to those in the meeting. It seemed to me that this company’s intelware like others developed in Israel would be non Microsoft was inconceivable.

Obviously these professionals were not aware that intelware systems (some of which failed to detect threats prior to the October 2023 attack) would be modified so that only adversary military personnel would be harmed. That’s what the Microsoft investigation just proved.

Based on my experience, Israel’s military innovations are robust despite that October 2023 misstep. Furthermore, warfighting systems if they do run on Microsoft software and systems have the ability to discriminate between combatants and non-combatants. This is an important technical capability and almost on a par with the Bob interface, Clippy, and AI in Notepad.

I don’t know about you, but the Microsoft investigation put my mind at ease.

Stephen E Arnold, May 26, 2025

Next Page »

  • Archives

  • Recent Posts

  • Meta