10 interesting stories served every morning and every evening.

How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache

blog.cloudflare.com

Big Pineapple, the plat­form be­hind 1.1.1.1, Gateway DNS, DNS Firewall, AS112, and sev­eral other Cloudflare DNS ser­vices, stores over 250 bil­lion DNS cache en­tries at any given time. At that scale, wast­ing a sin­gle byte per en­try costs more than 250 gi­ga­bytes of mem­ory across our fleet.

Five suc­ces­sive changes to how cache en­tries are stored in mem­ory cut the per-en­try foot­print by over 50%. Across our fleet, these changes freed up roughly 100 ter­abytes of mem­ory, equiv­a­lent to the amount of RAM in 130 of our Gen 13 servers. The cache also got faster. Insert through­put rose 43% and lookup la­tency dropped 19%, as fewer al­lo­ca­tions and bet­ter mem­ory lo­cal­ity meant we did not trade speed for space.

What we cache

On cold start, Big Pineapple starts out with an empty cache. As DNS queries ar­rive, the cache fills un­til it hits its max­i­mum en­try count, at which point we evict older or less pop­u­lar items to make room.

The ex­act cache size varies by data cen­ter. When EDNS Client Subnet (ECS) is in use, au­thor­i­ta­tive servers re­turn dif­fer­ent an­swers de­pend­ing on the clien­t’s net­work, so we cache mul­ti­ple ver­sions of the same query. This in­creases both the num­ber of en­tries and the mem­ory each one con­sumes, mak­ing the op­ti­miza­tions in this post es­pe­cially im­pact­ful for ECS-heavy lo­ca­tions.

Each item in the cache is a key-value pair. The key iden­ti­fies what was queried:

pub struct CacheKey { qname: Name, qtype: Rtype, au­then­ti­cated: bool, tag: Vec<u8>, }

The value stores the DNS re­sponse it­self: the an­swer, au­thor­ity, and ad­di­tional record sec­tions, along with meta­data like the cre­ation time, a hit counter, and the Time-to-Live (TTL).

pub struct CacheEntry { time­stamp: UnixTimeStamp, pub in­cep­tion: Instant, pub ttl: Ttl, pub hits: u32, pub an­swers: Vec<Record>, pub au­thor­ity: Vec<Record>, pub ad­di­tional: Vec<Record>, pub er­rors: Vec<ExtendedError>, … }

Both structs have room for im­prove­ment. Several fields use types that carry over­head we don’t need once the en­try is stored.

Benchmarking mem­ory us­age

To mea­sure the im­pact of each change, we bench­mark by fill­ing the cache with ran­domly gen­er­ated en­tries that roughly match the traf­fic dis­tri­b­u­tion we see in pro­duc­tion: 56% A records, 25% AAAA, and 19% TXT. Each en­try con­tains be­tween one and four records.

TXT records serve as a stand-in for all non-A/​AAAA record types in the bench­mark. Their size is ran­dom­ized be­tween 64 and 224 bytes, close to the av­er­age re­sponse size we see for vari­able-length record types.

We track mem­ory us­age us­ing a cus­tom al­lo­ca­tor that wraps Rust’s System al­lo­ca­tor and records the num­ber and size of al­lo­ca­tions per cache en­try. Alongside mem­ory, we mea­sure in­sert through­put and lookup la­tency across the full cache flow to make sure mem­ory sav­ings don’t come at the cost of per­for­mance.

These in­puts ap­prox­i­mate pro­duc­tion rather than re­pro­duce it ex­actly. Process mem­ory also de­pends on traf­fic mix, cache oc­cu­pancy, al­lo­ca­tor state, and mem­ory used out­side the cache. We there­fore mea­sured res­i­dent mem­ory across pro­duc­tion in­stances dur­ing the roll­out.

The cost of ca­pac­ity

Vec<T> stores three fields: a pointer to heap-al­lo­cated data, the cur­rent length, and the to­tal ca­pac­ity. When you push an item, Vec checks whether the length ex­ceeds the ca­pac­ity and re­al­lo­cates if needed. If there’s room, it just ap­pends the item and in­cre­ments the length.

Once we store a DNS re­sponse in the cache, how­ever, we never mod­ify it again. The ca­pac­ity field serves no pur­pose, but still costs 8 bytes per Vec. The over-al­lo­cated heap space is wasted as well, as a Vec with ca­pac­ity for eight items but only five stored leaves three slots un­used on the heap.

Using Box<[T]> solves both prob­lems. It can’t grow af­ter cre­ation, so it does­n’t need a ca­pac­ity field or re­serve space for fu­ture el­e­ments. The same ap­plies to String, which also car­ries a ca­pac­ity field. Box<str> drops it.

Each cache en­try stores 8 Vec and String fields. Replacing them with Box<[T]> and Box<str> saves 8 bytes per field, 64 bytes per en­try. It also elim­i­nates the ex­cess heap mem­ory that Vec re­serves for fu­ture growth. The com­bined sav­ings add up to over 15 ter­abytes with over 250 bil­lion cache en­tries.

Fewer lists, fewer point­ers

Rather than stor­ing the an­swer, au­thor­ity, and ad­di­tional sec­tions in sep­a­rate lists, we can store a sin­gle list with off­sets to the start of each sec­tion. Since DNS record counts per sec­tion fit in a u16, we can use a u16 (2 bytes) for each off­set, com­pared to the 8-byte pointer and 8-byte length that each sep­a­rate Box<[T]> re­quires.

This re­moves two lists, each with an 8-byte pointer and 8-byte length, and re­places them with two 2-byte off­sets, sav­ing 28 bytes per en­try.

These sav­ings do not al­ways map di­rectly to the num­ber of bytes re­moved from in­di­vid­ual fields. Rust in­serts padding to sat­isfy align­ment re­quire­ments and rounds a struc­t’s size up to a mul­ti­ple of its align­ment. Removing a small field can there­fore elim­i­nate ad­di­tional padding. For ex­am­ple, we also packed sev­eral boolean fields into a sin­gle bit­flag. This re­duced the sur­round­ing padding, caus­ing the struct to shrink by more than the size of the in­di­vid­ual booleans.

Dropping the owner

Each DNS record has an owner, the do­main the record be­longs to. In many cases, this owner is iden­ti­cal to the do­main be­ing queried. For ex­am­ple, a query for ex­am­ple.com A re­turns two records with the same owner:

$ dig ex­am­ple.com A

;; ANSWER SECTION: ex­am­ple.com. 300 IN A 198.51.100.1 ex­am­ple.com. 300 IN A 198.51.100.2

But when a CNAME is in­volved, for ex­am­ple, the record owner can dif­fer from the queried do­main:

$ dig ex­am­ple.com A

;; ANSWER SECTION: ex­am­ple.com. 300 IN CNAME cdn.ex­am­ple.com. cdn.ex­am­ple.com. 300 IN A 198.51.100.1 cdn.ex­am­ple.com. 300 IN A 198.51.100.2

The DNS wire for­mat han­dles re­peated own­ers us­ing name com­pres­sion, as de­fined in RFC 1035. Rather than en­cod­ing the same do­main twice, sub­se­quent oc­cur­rences store a 2-byte pointer to the first oc­cur­rence. A do­main like www.ex­am­ple.com can en­code just www fol­lowed by a pointer to where ex­am­ple.com al­ready ap­peared in the mes­sage.

This works well on the wire, but in our cache we store the full owner name along­side each record. Following com­pres­sion point­ers dur­ing cache lookups is ex­pen­sive on the hot path, so we trade mem­ory for speed.

Most records, how­ever, have an owner iden­ti­cal to the queried do­main. For those, we can drop the owner en­tirely and in­fer it at read time. When the owner dif­fers, such as the A records be­hind a CNAME, we store the full name.

pub struct Record { owner: Option<Box<Name>>, class: Class, ttl: Ttl, rtype: Rtype, data: RecordData, }

When owner is None, re­sponse con­struc­tion re­stores the queried do­main from the cache key, avoid­ing a heap al­lo­ca­tion. This means the record is no longer self-con­tained, but the cache key is al­ready avail­able dur­ing every lookup. When the owner dif­fers, Some stores a pointer to the full name on the heap.

In prac­tice, most cached records have an owner iden­ti­cal to the queried do­main, so the ma­jor­ity re­quire no heap al­lo­ca­tion for the owner field.

Enum siz­ing

Rust enums are sum types: each vari­ant can carry dif­fer­ent data, but the enum is al­ways the size of its largest vari­ant.

pub enum Option<T> { Some(T), None, }

Option is ei­ther Some and holds a value, or None and holds noth­ing. Both vari­ants take the same amount of mem­ory. The enum stores a tag in­di­cat­ing the ac­tive vari­ant, fol­lowed by space large enough for the largest vari­ant’s data. When the vari­ant is None, that space is un­used.

For record data, it seems nat­ural to store each DNS record type as an enum vari­ant:

pub enum RecordData { A(Ipv4Addr), Aaaa(Ipv6Addr), Txt(Txt), Naptr(Naptr), Svcb(Svcb), // … }

But the enum is al­ways as large as its largest vari­ant. In our case, that’s NAPTR at 136 bytes. It stores three vari­able-length text fields, a do­main name, and two in­te­gers. As a re­sult, the full enum, in­clud­ing the vari­ant tag and padding, be­comes 144 bytes.

An A record only needs 4 bytes, and an AAAA record needs 16 bytes. A and AAAA make up over 80% of our traf­fic, so most records waste over 120 bytes on padding. Since a sin­gle cache en­try can store many records this quickly adds up.

Boxing the vari­ants

To solve this prob­lem, we can box the larger vari­ants of the enum, mov­ing them to a sep­a­rate heap al­lo­ca­tion. The enum then stores an 8-byte pointer to the heap, where the data takes up only the size it ac­tu­ally re­quires.

pub enum RecordData { // Small and com­mon vari­ants are stored in­line A(Ipv4Addr), Aaaa(Ipv6Addr), // Large vari­ants are stored on the heap Txt(Box<Txt>), Naptr(Box<Naptr>), Svcb(Box<Svcb>), // … }

For A and AAAA records, this saves 120 bytes per record. Smaller vari­ant types like TXT and CNAME also ben­e­fit. They still oc­cupy the 24-byte enum, but their heap al­lo­ca­tion is sized to their ac­tual data rather than padded to 144 bytes. NAPTR, the largest vari­ant, ac­tu­ally pays slightly more. It now adds the cost of a heap pointer and al­lo­ca­tion over­head. But NAPTR records are rare in prac­tice, so the trade­off is worth it.

But box­ing the larger record vari­ants in­tro­duces costs of its own.

The costs of box­ing

Boxing has two costs. The first is al­lo­ca­tor over­head. Each boxed vari­ant be­comes a sep­a­rate heap al­lo­ca­tion, and al­lo­ca­tors round up to the near­est size class. Big Pineapple uses je­mal­loc, an al­lo­ca­tor de­signed for mul­ti­threaded, al­lo­ca­tion-heavy work­loads. je­mal­loc groups al­lo­ca­tions of sim­i­lar sizes into fixed-size bins. A TXT record re­quests 32 bytes and fits ex­actly into a 32-byte bin, wast­ing noth­ing, but an MX record re­quests 40 bytes and rounds up to 48, wast­ing 8 bytes.

The sec­ond cost is poor mem­ory lo­cal­ity. Without box­ing, the record enum val­ues for a cache en­try sit in a sin­gle con­tigu­ous al­lo­ca­tion. With box­ing, data for each boxed vari­ant lives in a sep­a­rate heap re­gion. Reading it re­quires fol­low­ing a pointer, and when that pointer lands far from the rest of the en­try, the CPU has to fetch a new cache line. With mil­lions of cache en­tries, boxed data ends up scat­tered across the heap rather than packed to­gether.

Neither cost is cat­a­strophic on its own, but elim­i­nat­ing both, as the next sec­tion shows, yields a mea­sur­able im­prove­ment in both mem­ory us­age and lookup la­tency.

Storing records in wire for­mat

An ob­vi­ous next step would be to store the full DNS re­sponse in wire for­mat, patch­ing only per-client fields like the mes­sage ID on each lookup. But this has draw­backs. DNSSEC records are only in­cluded when the client sets the DO (DNSSEC OK) flag. Storing a com­plete wire for­mat mes­sage means ei­ther caching two vari­ants, one with DNSSEC and one with­out, or fil­ter­ing them out of an al­ready-built mes­sage. There is also a cost to pars­ing the full mes­sage on every lookup, which the enum ap­proach we just de­scribed avoids by stor­ing al­ready-parsed records.

As a mid­dle ground, we store just the record data as raw bytes, while keep­ing the rest of the cache en­try as struc­tured fields. Instead of a list of parsed enum vari­ants, we store the records as a sin­gle Box<[u8]> con­tain­ing each record en­coded as a 2-byte length pre­fix fol­lowed by its raw bytes.

This elim­i­nates the per-vari­ant enum over­head and the boxed heap al­lo­ca­tions from the pre­vi­ous op­ti­miza­tion. The data also be­comes packed con­tigu­ously, which im­proves CPU cache lo­cal­ity. The trade­off is that records can no longer be ran­domly in­dexed. We have to it­er­ate through the buffer se­quen­tially. This adds some com­plex­ity for fea­tures like round-robin ro­ta­tion of A/AAAA records, but since record counts per en­try are small, the cost is neg­li­gi­ble.

When build­ing a DNS re­sponse from cached records, most record types can be copied di­rectly from the buffer into the out­go­ing mes­sage. Previously, each parsed record had to be se­ri­al­ized field by field back into DNS wire for­mat. The new lay­out skips that work for A, AAAA, TXT, and all DNSSEC record types by copy­ing their en­coded bytes di­rectly. Only records con­tain­ing do­main names, such as CNAME, NS, MX, and SOA, still re­quire pars­ing so we can ap­ply DNS name com­pres­sion. Since records that sup­port di­rect copy­ing make up the vast ma­jor­ity of our traf­fic, this change re­duces work on the lookup path. Combined with im­proved mem­ory lo­cal­ity, this re­duced cache lookup la­tency by 5% in our bench­marks.

To build the record data buffer, we write into a reusable scratch­space buffer that per­sists across cache in­ser­tions. Since pre­vi­ous writes have al­ready grown it, the buffer rarely needs to be re­al­lo­cated. Records vary in size, so we do not know the ex­act buffer size un­til they have been se­ri­al­ized. Once the records are in the scratch­space buffer, we al­lo­cate a Box<[u8]> and mem­cpy the data into it. This re­places the sep­a­rate al­lo­ca­tion for each boxed record with one al­lo­ca­tion for all record data. It also avoids the waste from shrink­ing a Vec<u8>, where the al­lo­ca­tor may not be able to re­claim the un­used tail of the orig­i­nal al­lo­ca­tion. In our bench­mark, this change alone in­creased cache in­sert through­put by 13%.

The re­sults

The pro­duc­tion mea­sure­ments show how the bench­marked per-en­try sav­ings trans­lated to whole-process res­i­dent mem­ory. The graph be­low shows p90, p98, and p99 mem­ory us­age across Big Pineapple in­stances. The first dashed line marks the start of the roll­out on May 18, 2026, and the sec­ond marks its com­ple­tion across all ser­vices on July 6, 2026. Each re­lease in­tro­duced one or more of the op­ti­miza­tions de­scribed above, so mem­ory us­age dropped in steps rather than all at once.

As each re­lease rolled out, restarted in­stances be­gan with empty caches and con­sumed more mem­ory as those caches filled. The sta­ble plateaus there­fore rep­re­sent steady-state mem­ory us­age bet­ter than the ini­tial dips.

Per-instance mem­ory us­age dropped across all per­centiles. At p99, mem­ory dropped from 9.3 GB to 5.3 GB, a 43% re­duc­tion in res­i­dent mem­ory. At p90, mem­ory dropped from 6.5 GB to 3.8 GB, a 42% re­duc­tion. Instances with fuller caches saw the largest ab­solute sav­ings.

In our bench­marks, these five op­ti­miza­tions re­duced the per-en­try mem­ory foot­print from 953 bytes to 420 bytes, a 56% re­duc­tion. Per-entry al­lo­ca­tions dropped from 1.1 KB to 461 bytes. The re­duc­tions mea­sured in pro­duc­tion are smaller be­cause res­i­dent mem­ory in­cludes the cache along­side all other process data. After the roll­outs set­tled, ag­gre­gate work­ing-set mem­ory across the fleet was roughly 100 ter­abytes lower.

Performance also im­proved. Cache in­sert through­put in­creased by 43%, while lookup la­tency dropped by 19%.

Metric

Before

After

Change

Per-entry net foot­print

953 bytes

420 bytes

-56%

Per-entry al­lo­ca­tions

1.1 KB

461 bytes

-58%

Cache in­sert through­put

625,000 en­tries/​s

893,000 en­tries/​s

+43%

Cache lookup la­tency

828 ns

670 ns

-19%

We plan to rein­vest the freed mem­ory into in­creas­ing cache ca­pac­ity with­out in­creas­ing our mem­ory us­age, which im­proves cache hit rates and re­duces up­stream query vol­ume. We’re also ex­plor­ing fur­ther op­ti­miza­tions to the cache it­self.

To learn more about Big Pineapple, see How Rust and Wasm power Cloudflare’s 1.1.1.1. If you work on DNS or other large sys­tems, share the op­ti­miza­tions that have worked for you in the Cloudflare Community or on the Cloudflare Developers Discord.

Microduck - A tiny biped robot you can teach new tricks | Pollen Robotics

pollen-robotics.com

MicroduckMade to move · Ready to learn

A 25 cm open-source biped you train your­self with re­in­force­ment learn­ing. Playable out of the box.

Pre-order for $399

The launch film · sound on

Roll thetape

Waking up the duck…

Meet the twin

sim2re­althat works

Trained in sim, de­ployed on the real ro­bot. This is the sim­u­lated twin the ducks were trained on.

Fun out of the box. Yours to re­train.

Teach it newtricks

Every be­hav­iour is a pol­icy you can re­train on your own ma­chine.

01

Train in sim­u­la­tion

Behaviours are learned in physics sim, on your ma­chine or on Hugging Face Jobs.

02

Deploy on the ro­bot

One step from sim­u­la­tion to the real thing.

03

Refine the sim­u­la­tion

Tune, re-train, re-de­ploy.

04

Publish the pol­icy

Share your new be­hav­ior with the com­mu­nity!

Walk

Velocity-tracking gait.

Sit & stand

Sits down, holds the pose, stands back up on its own.

Kick

A one-shot boot, then straight back to walk­ing.

Grab

Dips the beak to the ground, scoops, and pops back up­right.

Roller skat­ing

Roller skat­ing lo­co­mo­tion when the skates are equipped.

Get back up

Flat on its back to stand­ing, all by it­self, ready for the next com­mand.

One ro­bot, four colour­ways

Choose your­colour

Every Microduck ships in one of four colour­ways. Same ro­bot, same brains un­der­neath - pick the shell that best fits you.

Waking up the duck…

Out in the world

In the wild

The real ro­bot in real places - on desks, on the pitch, out at golden hour.

The ro­bot, and what to add to it

Pick your­pack

The ro­bot is every­thing you need on day one. The packs add play gear and spare parts.

$399

The ro­bot

Microduck

In the box

Robot, bat­tery, USB-C ca­ble, game con­troller.

$39

Dual charger, 2x bat­ter­ies.

$119

3x spare mo­tors, 5x mo­tor ca­bles, 2x bat­ter­ies, dual charger, 10x NFC tags, Hugging Face credit, screw­driver, screw pack.

$39

Laser pointer, NFC po­laroid, 2x rollers, ball, 10x NFC tags.

Built in the open

Open source

The SDK, the sim­u­la­tion and the full RL train­ing stack are on GitHub. What the ro­bot runs is what you can read, fork and re­train.

pollen-ro­bot­ics/​mi­cro­duck

ssh mi­cro­duck

$ ro­botctl mon­i­tor # sta­tus of the ro­bot$ ro­botctl con­fig­ure # con­fig­ure the ro­bot$ ro­botctl up­date # up­date the ro­bot

Apache-2.0

The whole soft­ware stack, per­mis­sively li­censed

MuJoCo

The physics sim every pol­icy is trained in

7 poli­cies

Every shipped move, pub­lished and re­train­able

Join the flock

Builds on show, poli­cies to swap, help when a leg does some­thing strange. The com­mu­nity lives on Discord.

End of tape · be kind, rewind

Pre-orders are­open now

Pre-order for $399

In four colour­ways. Ships be­fore Christmas 2026.Introductory price, be­fore taxes and ship­ping.

Small Models Have Arrived

calv.info

For the past few weeks, I’ve been play­ing with gpt-5.6-luna. It is shock­ingly ca­pa­ble, fast, and smart. I reg­u­larly see it do ~100 tps, and rip around my code­base, email, and knowl­edge base.

Of course, the biggest thing with luna is the cost. I’ve tried run­ning some fairly com­pli­cated re­search threads, and it’s pretty tough to run up a large bill. Even hav­ing it search across thou­sands of emails, I end up with an API cost in the tens of cents.

With GLM 5.3, we even have a new op­tion at the Pareto fron­tier.

When do­ing cod­ing work, I al­most al­ways reach for the most ex­pen­sive and ca­pa­ble mod­els (Fable 5, 5.6 Sol). So it’s been easy to miss the progress the small fast mod­els have made.

One thing a few in­vestors I’ve talked with have men­tioned: It’s weird we’re not see­ing more con­sumer AI com­pa­nies. Why is that?”

There’s a straight­for­ward an­swer: to­ken costs.

In the times be­fore AI, the play­book for big con­sumer apps looked like this…

cre­ate some sort of com­pelling web­site which is fairly cheap to run

at­tract a bunch of users (typically with some vi­ral­ity)

raise money, scale to more users

cre­ate an ads mar­ket­place

This roughly de­scribes most of the big con­sumer com­pa­nies (Google, Facebook, Snapchat, etc.).1

But what if you want to add AI to your prod­uct? Well, now you have some real in­fer­ence costs on every re­quest! Suddenly the amount of cap­i­tal re­quired in­creases dra­mat­i­cally.

A pet eval of mine is to build a daily news site, per­son­al­ized to me:

re­search @calvinfo on the in­ter­net. fig­ure out what news they might like. build a mi­cro-site with to­day’s top sto­ries, per­son­al­ized for them. search hn, red­dit, twit­ter, etc.

re­search @calvinfo on the in­ter­net. fig­ure out what news they might like. build a mi­cro-site with to­day’s top sto­ries, per­son­al­ized for them. search hn, red­dit, twit­ter, etc.

With the pre­vi­ous gen­er­a­tion of mod­els (Sonnet class), you’d spend ~$1 to get any­where. Charging $30/mo is un­ten­able for a con­sumer app. There’s ob­vi­ously a lot we can op­ti­mize here, but if you’re charg­ing what the WSJ or The Economist charges, you’d bet­ter be de­liv­er­ing sim­i­lar value.

But look­ing at luna, the re­sults are pretty de­cent, and the av­er­age cost is ~$0.10. Now we’re talk­ing!

Where I think this gets even more in­ter­est­ing is in the world of busi­ness.

My Segment co-founder Peter and I were re­cently com­par­ing notes on a hike. Across his var­i­ous star­tups, Peter has seen two kinds of work:

the IQ 180” work. some mad sci­en­tist ge­nius type comes up with some crazy so­lu­tion you’ve never thought of.

the token spewer” work. be­ing ul­tra re­spon­sive, push­ing the ball for­ward across dozens of dif­fer­ent fronts.

Peter runs mul­ti­ple com­pa­nies. Beyond Segment, he’s raised $100m+ for Charm Industrial, and just re­cently closed a Series A for Revoy. He’s in­cred­i­bly or­ga­nized and ef­fi­cient with his time.

And yet, Peter men­tioned that ~95% of the work he does falls into bucket 2. It’s hop­ping on calls. Nudging peo­ple. Blocking and tack­ling.

To be clear, Peter says his com­pa­nies would be dead-in-the-wa­ter to­day with­out an IQ 180 tech­ni­cal mind solv­ing the deep prob­lems. Just that most of his work falls in bucket 2.2

I think de­mand for frontier-level” mod­els is go­ing to keep com­pound­ing. Especially for fields that re­quire novel break­throughs or dis­cov­ery (engineering, hard sci­ence, model train­ing).

But I also think the de­mand for fast/cheap/good-enough” mod­els is just about to take off.

Think of the peo­ple you in­ter­act with on a daily ba­sis: cowork­ers, ven­dors, and cus­tomers. Nine times out of ten, you want some­one who is su­per re­spon­sive, and just han­dles things for you. Most of the human to­kens” at com­pa­nies to­day are spent this way — hir­ing skews heav­ily to­ward the fast/​cheap/​good-enough ar­che­type.

There’s a lot of work that needs to hap­pen to make fast/​cheap/​good-enough mod­els a re­al­ity for busi­ness. New har­nesses, prompt in­jec­tion safety, roles, and per­mis­sions. But I’m con­fi­dent we’ll fig­ure that out.

If you’re also ex­per­i­ment­ing with mak­ing small mod­els use­ful, please drop me a line.

Footnotes

Amazon and Netflix are the no­table ex­cep­tions ↩

Amazon and Netflix are the no­table ex­cep­tions ↩

Peter is also be­ing mod­est here. He’s sharp as a tack. ↩

Peter is also be­ing mod­est here. He’s sharp as a tack. ↩

507 Mechanical Movements

507movements.com

Wait… you said they were an­i­mated!

Ah, yes… well, un­for­tu­nately we do not have all the an­i­ma­tions work­ing yet, but we do have quite a few.

Look for the color thumb­nails. They iden­tify the com­pleted an­i­ma­tions. Use the prev and next links (above right) to browse the thumb­nail pages.

As time goes on, we’ll be adding more un­til all 507 are com­plete. Click the Facebook Subscribe” or Twitter Follow” but­ton be­low to be no­ti­fied of our progress.

Meanwhile, we hope you en­joy the an­i­ma­tions we have com­pleted, along with Henry T. Brown’s orig­i­nal il­lus­tra­tions in this clas­sic tech­ni­cal ref­er­ence.

See the About page for more.

Close

Trade

xkcd.com

Comics I en­joy: Three Word Phrase, SMBC, Dinosaur Comics, Oglaf (nsfw), A Softer World, Buttersafe, Perry Bible Fellowship, Questionable Content, Buttercup Festival, Homestuck, Junior Scientist Power Hour

xkcd.com is best viewed with Netscape Navigator 4.0 or be­low on a Pentium 3±1 em­u­lated in Javascript on an Apple IIGSat a screen res­o­lu­tion of 1024x1. Please en­able your ad block­ers, dis­able high-heat dry­ing, and re­move your de­vice­from Airplane Mode and set it to Boat Mode. For se­cu­rity rea­sons, please leave caps lock on while brows­ing.

The load-bearing vocabulary of Claude

louisabraham.github.io

nytimes.com

www.nytimes.com

Please en­able JS and dis­able any ad blocker

Access Denied

www.gatesnotes.com

Reference #18.b4132817.1787889254.a9b45f4

https://​er­rors.edge­suite.net/​18.b4132817.1787889254.a9b45f4

US Government Designates Host of NoBlogs.org a "Global Terrorist"

crimethinc.com

On August 26, 2026, the United States gov­ern­ment clas­si­fied the Italian col­lec­tive Autistici/Inventati as a Specially Designated Global Terrorist,” cit­ing the col­lec­tive’s far-left” pol­i­tics to jus­tify the des­ig­na­tion. They an­nounced sim­i­lar des­ig­na­tions of the British group Palestine Action and the transna­tional Palestinian move­ment Masar Badil in the same state­ment.

Founded in 2001, Autistici/Inventati is a vol­un­teer-run provider of pri­vacy-ori­ented email, web­sites, mail­ing lists, blogs, and com­mu­ni­ca­tions tools for users who pre­fer not to rely on cor­po­rate plat­forms. According to the US State Department, Autistici/Inventati hosts roughly 16,000 mail­boxes, 1,500 web­sites, 5,500 mail­ing lists, and 10,000 blogs’ on its cus­tom-built plat­form.”

Autistici/Inventati ex­plain their val­ues and goals in their man­i­festo:

We be­lieve that com­mu­ni­ca­tion must be free—and for free—and, there­fore, uni­ver­sally ac­ces­si­ble.

We try to ac­com­plish all this by of­fer­ing in­ter­net ser­vices (web sites, e-mail, mail­ing lists, chats, blogs, newslet­ters, and more) us­ing our best skills and knowl­edge to de­fend both in­di­vid­u­als or groups shar­ing our same aims or ideals. […]

We be­lieve that me­dia and com­mu­ni­ca­tion should not be the ex­clu­sive do­main of in­for­ma­tion pro­fes­sion­als. We be­lieve in the value of self-man­age­ment: this is why we have no spon­sors or fund­ing of any kind, apart from vol­un­tary do­na­tions from those who be­lieve that our pro­ject is im­por­tant and must sur­vive. None of us earns a cent from this pro­ject (in fact, quite the op­po­site).

We be­lieve that com­mu­ni­ca­tion must be free—and for free—and, there­fore, uni­ver­sally ac­ces­si­ble.

We try to ac­com­plish all this by of­fer­ing in­ter­net ser­vices (web sites, e-mail, mail­ing lists, chats, blogs, newslet­ters, and more) us­ing our best skills and knowl­edge to de­fend both in­di­vid­u­als or groups shar­ing our same aims or ideals. […]

We be­lieve that me­dia and com­mu­ni­ca­tion should not be the ex­clu­sive do­main of in­for­ma­tion pro­fes­sion­als. We be­lieve in the value of self-man­age­ment: this is why we have no spon­sors or fund­ing of any kind, apart from vol­un­tary do­na­tions from those who be­lieve that our pro­ject is im­por­tant and must sur­vive. None of us earns a cent from this pro­ject (in fact, quite the op­po­site).

Many book fairs, ra­dio pro­grams, and other cul­tural pro­jects rely on the Autistici/Inventati plat­form noblogs.org for web­site host­ing. According to one anti-fas­cist re­search group, Some of the most well-known NoBlogs sites be­long to re­searchers who solely re­port on far-right hate and rad­i­cal­iza­tion, never do­ing any­thing aside from show­ing you what ex­ists.” Such re­searchers helped to iden­tify the fas­cists who par­tic­i­panted in the Unite the Right” rally in 2017, dur­ing which one Neo-Nazi mur­dered Heather Heyer in an ac­tual act of ter­ror­ism.

The US State Department is ra­tio­nal­iz­ing this des­ig­na­tion by al­leg­ing that Autistici/Inventati provides en­crypted tools and ser­vices to nu­mer­ous vi­o­lent far-left ex­trem­ist groups,” in­clud­ing Portland-based Rose City Antifa. Their claim about Rose City Antifa seems to be false, how­ever, con­flat­ing Rose City Antifa with an­other pro­ject called Rose City Counterinfo.

On the ba­sis of this er­ror, the State Department rushed to pro­claim an al­leged Portland Antifa con­nec­tion to Hamas” and Iran’s IRGC [Islamic Revolutionary Guard Corps], with the sole jus­ti­fi­ca­tion be­ing the al­le­ga­tion that an un­named extremist me­dia group”—which they do not al­lege had any re­la­tion­ship to Rose City Antifa—had re­pub­lished state­ments from Hamas and the IRGC on a web­site hosted by noblogs.org. This is rep­re­sen­ta­tive of the dis­hon­esty and er­ro­neous­ness of the State Department press re­lease as a whole.

When a mil­i­tary force car­ries out an at­tack on a vil­lage, the first thing they do is at­tempt to cut the com­mu­ni­ca­tion lines that con­nect it to the out­side world. We have to un­der­stand the at­tack on Autistici/Inventati the same way. Now that tech cor­po­ra­tions from Meta to the plat­form for­merly known as Twitter have showed that they are will­ing to ban who­ever the US gov­ern­ment in­structs them to, the US gov­ern­ment is go­ing af­ter groups that pro­vide web ser­vices on a non-com­mer­cial ba­sis.

Because there is no domestic ter­ror­ist or­ga­ni­za­tion” des­ig­na­tion in the United States, the Trump ad­min­is­tra­tion be­gan its crim­i­nal­iza­tion of anti-fas­cists by des­ig­nat­ing European anti-fas­cist groups as terrorists.” They are tar­get­ing an Italian tech pro­ject for the same rea­son: they aim to put the pieces in place to crim­i­nal­ize do­mes­tic pro­test­ers by as­so­ci­at­ing them with des­ig­nated Global Terrorist” groups.

According to the United States Department of the Treasury, start­ing on September 25, 2026, any trans­ac­tions with Autistici/Inventati will be prohibited by the Global Terrorism Sanctions Regulations.”1 The press re­lease from the Treasury stip­u­lates:

Violations of US sanc­tions may re­sult in the im­po­si­tion of civil or crim­i­nal penal­ties on US and for­eign per­sons.

Violations of US sanc­tions may re­sult in the im­po­si­tion of civil or crim­i­nal penal­ties on US and for­eign per­sons.

Autistici/Inventati have re­leased a short state­ment about the des­ig­na­tion:

We deny all al­le­ga­tions in­cluded in the state­ments, while we strongly af­firm our ded­i­ca­tion to pro­vid­ing a plat­form of tools for dig­i­tal self-de­fense, ad­dress­ing the need of free com­mu­ni­ca­tion for ac­tivists and other in­di­vid­u­als, groups and as­so­ci­a­tions.

We will not back down, we will keep do­ing what we have been do­ing all these years and we will do what­ever is in our pos­si­bil­ity to counter the false al­le­ga­tions made by a po­lit­i­cally des­per­ate ad­min­is­tra­tion with the sole in­ten­tion of sway­ing peo­ple and me­dia at­ten­tion away from their own vi­o­lence and war­mon­ger­ing.

Anti-fascism and anti-cap­i­tal­ism are not ter­ror­ism. Protesting is not ter­ror­ism. And every­one has the right to speak out and to strug­gle for hu­man­ity.

We deny all al­le­ga­tions in­cluded in the state­ments, while we strongly af­firm our ded­i­ca­tion to pro­vid­ing a plat­form of tools for dig­i­tal self-de­fense, ad­dress­ing the need of free com­mu­ni­ca­tion for ac­tivists and other in­di­vid­u­als, groups and as­so­ci­a­tions.

We will not back down, we will keep do­ing what we have been do­ing all these years and we will do what­ever is in our pos­si­bil­ity to counter the false al­le­ga­tions made by a po­lit­i­cally des­per­ate ad­min­is­tra­tion with the sole in­ten­tion of sway­ing peo­ple and me­dia at­ten­tion away from their own vi­o­lence and war­mon­ger­ing.

Anti-fascism and anti-cap­i­tal­ism are not ter­ror­ism. Protesting is not ter­ror­ism. And every­one has the right to speak out and to strug­gle for hu­man­ity.

Building on the so­cial me­dia bans of the pre­ced­ing years, the ter­ror­ist des­ig­na­tion of Autistici/Inventati is an ef­fort to sup­press dis­si­dent me­dia and a sig­nif­i­cant step to­wards state re­pres­sion on the ba­sis of ide­ol­ogy alone. This will not stop with an­ar­chist pro­jects, but will even­tu­ally ex­tend across the po­lit­i­cal spec­trum to every­one who does not fall in line with the ad­min­is­tra­tion, un­less the ad­min­is­tra­tion is re­moved from power. The dan­ger to all will in­crease un­til that oc­curs.

Of course, Donald Trump’s suc­ces­sors could keep re­pres­sive poli­cies like this in place, much as Joe Biden did. We must make sure that there is enough po­lit­i­cal pres­sure on any po­lit­i­cal for­ma­tion that could suc­ceed the Trump pres­i­dency to com­pel them to roll back the re­pres­sive mea­sures that Trump‘s ad­min­is­tra­tion in­tro­duced.

Further Reading

For a le­gal analy­sis of this des­ig­na­tion, you could start here.

US Sanctions Three European Activist Networks, Including Italian Privacy Collective

Make Ready: Safeguarding Our Movements against Repression

The spe­cific threat from the Treasury Department reads as fol­lows: As a re­sult of to­day’s ac­tion, all prop­erty and in­ter­ests in prop­erty of the des­ig­nated or blocked per­son de­scribed above that are in the United States or in the pos­ses­sion or con­trol of US per­sons are blocked and must be re­ported to OFAC [the Office of Foreign Assets Control]. In ad­di­tion, any en­ti­ties that are owned, di­rectly or in­di­rectly, in­di­vid­u­ally or in the ag­gre­gate, 50 per­cent or more by one or more blocked per­sons are also blocked. Unless au­tho­rized by OFAC, or ex­empt, OFACs reg­u­la­tions gen­er­ally pro­hibit all trans­ac­tions by US per­sons or within (or tran­sit­ing) the United States that in­volve any prop­erty or in­ter­ests in prop­erty of blocked per­sons.” ↩

The spe­cific threat from the Treasury Department reads as fol­lows: As a re­sult of to­day’s ac­tion, all prop­erty and in­ter­ests in prop­erty of the des­ig­nated or blocked per­son de­scribed above that are in the United States or in the pos­ses­sion or con­trol of US per­sons are blocked and must be re­ported to OFAC [the Office of Foreign Assets Control]. In ad­di­tion, any en­ti­ties that are owned, di­rectly or in­di­rectly, in­di­vid­u­ally or in the ag­gre­gate, 50 per­cent or more by one or more blocked per­sons are also blocked. Unless au­tho­rized by OFAC, or ex­empt, OFACs reg­u­la­tions gen­er­ally pro­hibit all trans­ac­tions by US per­sons or within (or tran­sit­ing) the United States that in­volve any prop­erty or in­ter­ests in prop­erty of blocked per­sons.” ↩

Just a moment...

www.tokyodev.com

To add this web app to your iOS home screen tap the share button and select "Add to the Home Screen".

10HN is also available as an iOS App

If you visit 10HN only rarely, check out the the best articles from the past week.

Visit pancik.com for more.