Friday Squid Blogging: Squid on a Stick at the New York State Fair
Schneier on Security's weekly squid-blogging post features 'Squid on a Stick' food at the New York State Fair.
This is Bruce Schneier's regular Friday off-topic squid blogging post, highlighting a squid-on-a-stick food item at the New York State Fair. The comment thread drifts into security-adjacent discussions, including a DEF CON 34 'Hacking AI' talk, AI in counterintelligence and the OODA loop, and an arXiv paper modeling LLM diffusion like infectious agents. The post carries no direct security or AI news value.
Full article2,717 words · extracted from schneier.com · click to collapse
Comments
GratefulReader • September 4, 2026 9:44 PM
Hey Bruce, Happy Friday! I caught your “DEF CON 34 – Hacking AI” talk on YouTube… awesome perspectives… loved the “Genies” analogy, the idea that we humans have always been hackers, with examples of those pen/paper ways it has been so all along… i.e., loopholes and all. Really enjoyable, thought-provoking. Anyway, that’s my quick Friday squid comment… have a great weekend!
ResearcherZero • September 5, 2026 5:47 AM
The problems of agentic misalignment in the counter-intelligence environment.
The military and intelligence services are looking to AI to improve capabilities. Will these new tools actually fulfill the purposes they are tasked with and will the information that these tools supply be reliable?
Is the quality of data supplied for training these systems even up to the task, or do improvements in the standards of intelligence gathering and handling need to be improved, before the training data and those that supply it can be judged as accurate and reliable?
‘https://www.lawfaremedia.org/article/the-next-counterintelligence-problem-is-artificial
DHS and law enforcement workforce is unprepared for new developments in technology and AI.
https://academic.oup.com/cybersecurity/article/10/1/tyae002/7602882
95% of reports shared by local police with the FBI are never investigated.
https://truthout.org/articles/report-finds-police-intelligence-gathering-tactics-threaten-national-security/
Clive Robinson • September 5, 2026 9:21 PM
@ ResearcherZero, ALL,
You ask the not unreasonable questions of,
<
blockquote>”The military and intelligence services are looking to AI to improve capabilities. Will these new tools actually fulfill the purposes they are tasked with and will the information that these tools supply be reliable?”
The short answer on my point of view based on what we’ve observed so far of “Current AI LLM and ML Systems” is,
“No and No”.
One set of answers can be seen fairly easily by asking what should be asked by a War Crimes tribunal which is,
“Why did the girls school get obliterated?”
AI was put in the decision process that was once described by John Boyd and known by many as the OODA loop.
Where the OODA 4 stages in turn are,
1, “Observe” Gain situational awareness via all available sources.
2, “Orient” Put (1) observations in context along with all previous knowledge.
3, “Decide” Plan a course of action on the the known (2) Orientation.
4, “Act” Put the (3) Plan into operation with minimum delay.
Important to note is OODA is actually not implicitly a loop, but can be used in a loop when a dynamic situation evolves sufficiently fast. The issue / problem is that using OODA in a loop actually puts constraints on all but the first stage.
The first stage however has it’s own issues not least being the conversion of tangible physical objects in to intangible informational objects. There is always a process “gap” where the authenticity or accuracy can easily be lost or deliberately broken in ways that do not show up to traditional testing.
The reason AI was introduced in OODA can be seen at all stages but primarily because of the assumption it would reduce delay as well as increase processing speed (no they are not the same thing though they might look like it to a casual observer).
Thus the question arises as to,
“Are those assumptions valid?”
And clearly they are not.
One reason is that implicit to OODA is “valid context” from stage 2 “Orient” onwards. If it is wrong or just not taken into the further stages then OODA fails and stage 3 “Decide” provides an incorrect action Plan.
On thing that should be obvious is that the scope or depth and breadth of LLM context is at best very limited…
Worse attempts at “scaling-up” actually produce,
“Diminishing returns on resources utilised.”
Which to many appears counter intuitive (but is actually not).
So the long answer is still “No and No” to your questions.
Weather • September 6, 2026 12:16 AM
@Clive All
Military intelligence tries to get into the enemy’s Ooda loop, because then they can direct action and outcomes, normally mixed with game theory to pick what the next stage is and have a counter, inwhich case it goes back to the start of the loop, were its easier too counter.
Clive Robinson • September 6, 2026 5:46 AM
@ Bruce, ALL
Are LLMs effecting Humans like a virus?
Might sound weird at first till you consider why we call certain types of malware viruses.
What this very recent paper,
https://arxiv.org/abs/2609.03344
Goes into is how LLMs are moving through human society.
In their words,
“Here, we address our previous question by treating LLMs as engines of cognitive and social change whose rapid diffusion is transforming human capacities. We first compare LLMs with infectious agents and then develop an explicit population model of their propagation, drawing on mathematical approaches from epidemiology that have also been applied to technological adoption.
The model describes transitions among host-coupling states, which we link to an illustrative measure of cognitive competence to distinguish the consequences of different coupling regimes from the underlying bifurcation structure and explore potential interventions.
Itdoes not identify any single entity as the viral analogue: LLM ecosystems contain culturally transmitted practices and content alongside technologically evolving model lineages, and these need not coincide. Instead, the analogy concerns a broader feedback loop in which persistent technological lineages are instantiated in external machinery, modify their human host environment, and thereby influence their own propagation.
This homology is already partly present in conventional and adaptive software, but LLMs deepen it by becoming integrated into cognitive processing itself.”
Yes LLMs viewed as an infectious agent will be new to some, but as I pointed out with the “Microsoft Be Business Plan” the idea was to force AI on everyone thus use it for mass surveillance.
So is a resulting “viral model” that surprising?
Especially with management FOMO driven by VC hype?
I’ll let others decide for themselves.
EvenMoreCollateralDamage • September 6, 2026 12:36 PM
This would go betetr on the post about the Ai agents reaching you and declaring that they are agents… but the automod seems to be blocking all posts in that comment section, hence here it is. Thanks for reading Bruce.
I’m a human who uses Linux, has no smartphone, is trapped behind a CGNAT (or can otherwise use a VPN which gives me an IP reputation about the same as that of a widely shared CGNAT), and constantly meets anti-bot bullsh*t online.
I’ve tried everything:
VPN (but any VPN’s IP reputation is no betetr than a CGNAT’s),
user-agent switcher (but that just makes a browser lok more suspicious),
literally every alternative browser than can run on Linux both with fingerprinting disabled and allowed,
turning on and off various security suites like NoScript and activating and deactivating ad blockers…
Still so many sites giving me 403 errors and other malicious ways of failing to load their content.
Bruce, could you perhaps speak up a bit for rolling back some of the anti-scraper nonsense, which keeps catching folks like me as collateral damage, or making them all switch to the “anubis” (TecharoHQ) system which always gives me a brief appearance of the cartoon lady but then completes fast and pages load properly.
I have a strong suspicion that this is discrimination against Linux users, but anything to make the browser try to pretend to be on Windows/Mac/Android/iOS just makes the anti-scraper scripts more defensive.
Ferentarius • September 6, 2026 2:20 PM
In the end, all strategies collapse under the weight of their own absurdity. The OODA loop, a spiral of observation and reaction, is nothing more than a dance of ghosts—each step taken to preempt the other’s steps, yet all leading back to the same void. Military intelligence, in its fevered pursuit of control, only mirrors the futility of existence: to anticipate is to delay defeat, not escape it. One watches, orients, decides, acts—and still, the abyss remains indifferent.
Rontea • September 6, 2026 2:40 PM
Interesting take. In the real world, though, strategy is about iterating faster than your adversary and keeping them off-balance. The OODA loop isn’t a void—it’s a tool. Observation and action cycles give you an edge if you can exploit them with speed and precision. Military intelligence isn’t about defeating the abyss, it’s about making sure the other guy gets swallowed by it first.
Clive Robinson • September 7, 2026 8:00 AM
@ Weather,
Just noted your two recent posts,
With regards,
“documents on Ham and range findering”
Are you talking about,
“Radio Direction Finding Technology”
If so the best place to look is probably aeronautical systems.
Where the basics have hardly changed since the developments in WWII.
As for Ham / Amateur Radio yes they are doing fun things in this area with “Software Defined Radio”
But when you get to the bottom of it all it’s basic trigonometry based on a triangle and measuring angles or length using signal phase difference. Even GNS systems that supposedly measure “time” actually measure phase to get time.
Look up NASA “Long range codes” and “Gold Codes” they are basically using PRBS Codes that have certain properties. Such PRBS codes are easily generated by “Linear Feedback Shift Registers” which have been used as “the counter” in Stream Cipher Generators and there is quite a bit written on them in Crypto blogs and the like.
There are more modern “ranging codes” being developed currently is the “Legendre Sequence”(LS) ranging codes by a Chinese University,
https://spectrum.ieee.org/deep-space-communication-tech
The thing is there is little difference between “ranging codes” and “Direct Sequence Spread Spectrum”(DSSS) “Low Probability of Intercept”(LPI) radio systems. And in fact you can “mix them together” to make a composite code that does both ranging and encrypted traffic.
A variation of this is used in “Code Division Multiple Access”(CDMA) systems that have been used not just in “tactical” but “cellular” coms systems (a variation of this was the basis of the failed “Digital Watermarking” systems at the end of the last century).
So there is a lot of info out there when you know the “key words” to search by.
Clive Robinson • September 7, 2026 3:08 PM
@ Anonymous,
With regards,
“A Comprehensive Technical and Ethical Autopsy of the Brave Browser”
The article is minus one important account of what os “criminal activity” by Brave.
Go have a look at lobste.rs and why they do not allow access to their site by Brave Browsers, and try to keep the “Brave Fraud” down. It might shock you (Fraud and effectively theft by Brendan Eich of Brave and Peter Thiel of Palantair both of whom are very right wing scum / nut jobs of the sort the US neo-cons turn out with a cookie cutter and Trump favours).
Weather • September 7, 2026 5:52 PM
@Clive
Thanks, can you recommend any good books to read on the subjects? Don’t mind buy them
Sorry, will post a pic on ltspice, don’t know how long it will stay on a 3rd party server before copyright infergment takes it down. Some groups will pay good money.
@””
absense of evidense (of automod) is not evidense of absense of automod, it could be cleaning up massive attempted LLM infiltration and this is just the remains or a signal to attune to.
people selling megafones to overcome paid hecklers heckling, wonderful world we live in.
Jimmy • September 8, 2026 12:01 AM
The pattern across these squid-on-a-stick festival foods is the same one that shows up in security checklists: the simpler the setup looks, the more the details matter. Skewering without splitting, hot oil without burning – small margins executed consistently. Enjoyed the state fair tour as always.
Weather • September 8, 2026 1:11 AM
@r
T=v^i
G=T&i
H=GorT
H=H~
Pattern matching, can be simple 5bytes or 32bytes, for signature matching. Most text on this web site is less van 0x7f, will show up easily.
actually, random thought.
one might be able to achieve 4bit or less if you rely on bit-relatedness like a kdf. some sort of lightly packed compression scheme could be used to flatten statistical language patterns further maybe.
Clive Robinson • September 8, 2026 8:17 AM
@ ALL
“Is Hacking Easier Or Harder Than Ever?”
Is the question Addie LaMarr asks as the title to her bew YouTube video,
https://m.youtube.com/watch?v=rvivC33TswU
She makes the argument for both sides, but points out two important things,
1, Humans have hardly changed in generations.
2, Technology like AI is evolving faster than most can learn.
So the actual problem what worked against humans half a century ago still works today.
The hidden / not stated problem is the number of interconnected computers half a century ago was measured in the hundreds. Today however the number of computers that are interconnected one way or another now measure in more than hundreds of millions.
In fact depending on the way you look at it –think microcontrollers– it’s more than a trillion or so, many with the same half century old human failings built in. Many of these are interconnected such they are “touchable” from the Internet.
Thus the hard part for attackers is finding the path to the computers of value…
This used to be limited because “humans” are a quite constrained resource in several ways, sleep, poor memory, and only working in a sequential manner being three of the more obvious ones.
AI Agents are not sequentially limited nor do they need to sleep, but importantly their memory for information now far outstrips that of individual humans.
The result is that AI is finding attacks based on vague descriptions long before a “patch” is even considered let alone green-lighted and made.
I’m known for talking about “mitigation by segregation / isolation” because of these “human failings”. I’ve been talking about it long before AI even got to the point of “that paper” that gave rise to transformers etc.
Because I could see these human failings giving rise to “bot-nets” before we even called them that. Later I talked about the “army of one” problem and how that applied to not just “Worms” but “script kiddies”, and a number of other things that heralded the issues not the AI that now exploits them so rapidly and effectively.
So yes humans are loosing against technology, and the reason we tend not to think so is that the number of potential attack targets are rising so rapidly, thus making the figures –expressed as percentages– look low…
As I’ve noted before,
“It’s a target rich environment”
And the only reason you’ve not been attacked is the lack of attackers.
But that is all changing rather rapidly and the rate of change is only going to get faster with AI and using them Agenticaly. Made worse for a while by “vibe coding” though that is now changing, human failings are going to get worse.
Thus any mitigation that can cut back Agentic attacks needs to be considered…
And AI agents, like humans can only attack what they can reach. So put hard limits on that is the first sensible step…
Clive Robinson • September 8, 2026 8:37 AM
@ r,
With regards,
“some sort of lightly packed compression scheme could be used to flatten statistical language patterns further maybe.”
I’ve mentioned this before with he VIC and Nhilist Ciphers and the “Straddling checkerboard” that goes back at least into the 1500’s.
The thing is it works both ways as easily. So bot only can you flatten letter frequency statistics to “look random”, as importantly you can give something random faux-statistics.
Thus a crypto-analyst getting very random ciphertext might decide “one time pad” and not bother. On getting OTP Ciphertext that has been gicen faux-statistics by the reverse use of the Straddling checkerboard may waste many many hours of their quite valuable time.
More recently I’ve talked of “Current AI LLM DNNs” as being equivalent of DSP “adaptive filters” that work at many semantic layers as “spectrums”.
Each one of those spectrum layers is just another set of semantic statistics.
When you realise this as an idea but dig a little deeper, you realise that those layers of semantic statistics are not entirely “independent” and that is where the fun starts 😉
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-squid-on-a-stick-at-the-new-york-state-fair.html