Full Width [alt+shift+f] Shortcuts [alt+shift+k]
Sign Up [alt+shift+s] Log In [alt+shift+l]
2

Thoughts ahead of WWDC 2026

from anderegg.ca [alt+shift+b] in technology

I’ve been following Apple news and rumours since the year 2000, and I don’t think I’ve ever been less excited for WWDC. Apple’s software story is in rough shape, and I worry that this year’s event won’t do much to help. Perhaps it’ll be the beginning of an upswing, but we’ve got quite a way to go. Before looking forward, let’s look back. WWDC 2024 focused on a number of “Apple Intelligence” features that never materialized. Which is probably for the best because the features that did ship that year were annoying at best and awful at worst. WWDC 2025 introduced a new redesign that I was initially looking forward to… until I saw it in practice. This year, the scuttlebutt is that WWDC will once again be about LLM-based features. Many of those features sound like re-announcements of the ones from 2024. I wasn’t excited about them then, and I’m still not now. If there are Apple Intelligence features announced on Monday, I hope they’re actually useful and not just shoehorned in. It’s reasonable for Apple to do something to improve Siri, but it’s been terrible for so long that I’ve found much better alternatives. I also worry that Apple risks overloading people with “AI” features. Microsoft only recently started learning their lesson about this, and it would be a real shame if Apple wasn’t taking notice. Given Apple’s recent track record, I’m not optimistic. I wish Apple would be content with its excellent place as a platform for machine learning and LLM-based work. I truly believe that local LLM use is the future, and it’s a future with far fewer downsides. I would love for Apple to focus on this, as it’s something they’re already doing well. None of the rumours have hinted at local LLM improvements, but it’s more developer- than user-focused. Maybe there will be more news at the State of the Union event after the keynote. My guess is that most AI features announced will still be sent to a server farm, and will likely involve subscription fees. There’s also been talk...
7th Jun 2026

Stay updated

Get a weekly newsletter with the top 5 articles worth reading every week.

More from anderegg.ca

The Talk Show Timeline

I really enjoy John Gruber’s podcast The Talk Show. However, I’ve noticed that it’s been a while since it was in my feed. I decided to chart previous episode dates to check some of my assumptions about release frequency. Cutting to the chase, here’s a link to The Talk Show Timeline. You can click/tap on days to get a pinned tooltip, which lets you link out to a particular day’s episode. I’ve tried to make this work well on mobile devices, but you’ll likely find it works best on desktop. A note about this: Gruber has mentioned in the past that there has been a personal situation that he’s been working through. He’s also mentioned something to this effect on the podcast at points, but hasn’t gone into detail. I don’t need to know more than has been said, and I just hope things are alright. I’ve read Gruber’s site since 2002 1 and listened to his podcasts since 2007. In that time, I’ve learned that he operates on his own timeline… and has a penchant for procrastination. No shade here! He’s set himself up with a work situation that I envy. I also don’t want to seem grumpy about the lack of podcast episodes; I’m just trying to understand how this current break compares to those in the past. Because it was easiest, and because it would answer my immediate questions, I only looked at the current iteration of The Talk Show. Happily, there’s a single page which lists all the episodes. It had a tiny bit of data weirdness, 2 but I was able to turn this into a JSON file with the details I cared about. With that, I used the calendar heatmap chart in Apache ECharts to display the episodes over time. Some things I noticed: While it’s been a while (29 days) since the last episode (on August 10), this isn’t unheard of. The average is about 12 days between episodes, but there have been 6 other times when the episode gap has been at least this long. The longest gap was 62 days between December 24, 2024 and February 24, 2025. There’s exactly one day with two episodes: July 19, 2014. It was “Cat Pictures” with Marco Arment, which got split into two “sides”. Here’s a link to side 1, and here’s side 2. I mentioned procrastination: 73% of episodes take place on the 16th of a month or later. 28% of episodes take place on either the last or second-last day of the month. Again, no shade! It’s something I chuckle about whenever I notice it. At the current rate, this year is about in line with output going back to 2023. While it has been a while since a new episode dropped, it’s not out of whack statistically. Anyway, this was a Labour Day project that was mostly for my own amusement. I expect there will likely be a new episode of The Talk Show some time fairly soon after tomorrow’s Apple event. I also don’t know if I’ll keep this chart up to date… though it’s not terribly onerous to do now, so who knows. I found Daring Fireball because I was researching the purchase of my first Mac around this time. It wasn’t until October of 2002, but I ended up buying one of the machines he wrote about in his first post that August. ↩ The following dates don’t match the main format: Sunday 30 November, 2025 Mon, 24 Feb 2020 16:05:34 EDT Tuesday 31 December 2019 Tuesday, June 25 2019 Sat, 16 Mar 2019 19:43:49 EDT Wednesday 31 December 2014 Monday, 30 Jun 2014 ↩

2 weeks ago • 1 votes
Bubbles.town

I mostly use my web stats service because I get a lizard-brain kick from watching numbers go up, but it also provides some fun insights. For example, it’s how I found out about bubbles.town. At first I thought this might be a Mastodon instance. I get a lot of referral traffic from Mastodon, but each instance has its own URL. You can guess at mas.to, but dice.camp doesn’t provide many clues. Bubbles, as it’s known, is a very nice service. It aggregates a curated list of indie blogs. People can sign up and vote for posts they enjoy, but they can’t submit new articles. Authentication and comments are both handled using Fediverse technologies. In my case, I was able to log in via my Mastodon instance. The idea is to highlight cool indie writers around the web. I love this sort of thing so very much. Anyway, this is all to say that you should check out Bubbles. Seeing a blog-based reaction to one of my posts on the service filled my heart with immense joy.

9th Aug 2026 • 1 votes
An infuriating goodbye to Photoshop

I’ve been using Photoshop since the mid-90s. First at school, with Photoshop 3, then through work. I bought my first boxed copy of CS2 in 2005, then upgraded to CS5 in 2010. I subscribed to Photoshop Creative Cloud on day one. Today, I uninstalled it. I hope I never have to use Adobe software ever again. Photoshop used to be a joy to use. Whenever I got access to an upgraded version, I’d always have fun exploring the new features. I got really good at using it. When Adobe launched the Creative Cloud version of Photoshop in 2013, I signed up immediately. The subscription meant I would always have an up-to-date Photoshop, and I loved the idea that new features would be rolled out more frequently. But over time things started getting worse. Slowly at first, but then much more quickly. Originally, the Creative Cloud app was native and relatively useful. I wasn’t ever excited to open it, but I certainly didn’t mind having it installed. At some point, it became a terrible web-based app. Over time it felt slower and more broken. One thing I loved as part of the Creative Cloud subscription was the Creative Cloud Synced Files service. Basically, it was Adobe’s version of DropBox. I used it all the time to share screenshots and samples of in-progress work. Then, in 2023, Adobe announced they’d be discontinuing the service. There was so much pushback that they delayed the service’s retirement for a year. It makes sense, it was a nice feature of the subscription plan and businesses had come to rely on it. This was the first time I started questioning my Creative Cloud subscription. Out of curiosity, I looked around at the available options. I played with Pixelmator Pro, Acorn, and Affinity Photo. They were all fine, but I couldn’t let Photoshop go. I just knew it too well. But I also started realizing how little I was using it. I used to do a lot of traditional web development. In days of yore, this involved getting Photoshop mockups from designers. Those images needed slicing into pieces that you’d use to build a site or an app. But I hadn’t gotten a Photoshop document from a client in years. The PSD had been replaced with Sketch files, then with links to Figma documents. I still used Photoshop to touch up images, but that really didn’t use much of its power. The only thing holding me to the product was familiarity. Then I started to notice some real quality issues. For some reason that I still don’t understand, my copy of Photoshop stopped updating. I didn’t notice for a while, but eventually I stumbled upon the release notes and saw that I was something like nine months behind. I was able to fix this by forcing the Creative Cloud app to reload its settings using Command + Option + R, at which point I could update. Then, a few months later, Photoshop updates started getting stuck. I’d start an update, but it would spin for hours but never complete. I was able to fix this by uninstalling Photoshop using the Creative Cloud app, then re-installing it… but I had to do this more than once. Soon after that, every new Photoshop update would reset my preferences to the defaults. I’d need to take 5 or so minutes to re-apply my settings every time. A little while later, Adobe started silently updating my /etc/hosts file for license verification purposes. As posited in that link above, the Creative Cloud app now felt like malware to me. But that wasn’t all, Photoshop itself had started feeling terrible. There was now an annoying welcome screen that would re-appear for me whenever I didn’t have an image open. There was an option to disable it, but the option was reset every time I relaunched Photoshop for a couple of releases. Then Adobe decided to replace almost all of Photoshop’s native UI controls with web-based ones. This was the final straw. I’m sure some of these issues were special cases for me. Something that got stuck somewhere, maybe. I’m a developer, so maybe my tooling was interfering with something? Only: every time I ran into an issue, I’d see dozens of people complaining about the same thing on the Adobe support forums. It really felt like Photoshop and the Creative Cloud app had grown into blobs of pain that Adobe no longer knew how to properly maintain. As this was happening, Apple had released their Creator Studio service. For the same price as my Creative Cloud Photography plan, I could get an updated version of Pixelmator Pro, plus a bunch of other great apps. I’ve since signed up and haven’t looked back. But Adobe wasn’t done with me yet. It turned out that my subscription, which had been going since 2013, was on an “Annual Paid Monthly” plan. Even though I was getting billed monthly, I couldn’t actually cancel any time I wanted. I had sort of remembered this being a thing when I signed up, but had long since forgotten about it. Anyway, the one-month window to cancel without a termination fee recently arrived, and I got around to cancelling today. Cancelling required me to log into my Adobe account on the web. No problem, I thought. I had set up Adobe Authenticator, and had used it dozens of times to log in before. This time, however, the authenticator app needed me to log in. To log into the authenticator app, the app asked me to use the app to authenticate the app. Sorry? This was, of course, impossible. Eventually I figured out that I could use an alternative method to log into the app, so I could then use the app to authenticate my web session. This felt bone-headed, but whatever. I then received the following email. There’s nothing hidden here, this is the full contents of the message. At this point, though, I was actually able to start the cancellation process. The first screen of the cancellation flow looked like this: Here’s what it looked like after selecting things: I guess no one at Adobe uses dark mode? Anyway, the next 3 steps included Adobe begging me not to cancel, and even offering me three free months. This process had not convinced me I’d be happier staying. But even after completing the cancellation, I wasn’t done. I now wanted to uninstall everything. The Photoshop part of this was easy enough using the uninstaller app in the /Applications/Adobe Photoshop/ folder. The Creative Cloud app was more stubborn. There was also a link to an uninstaller for it in the /Applications/Adobe Creative Cloud/ folder… but running it failed with the error: Couldn’t uninstall Creative Cloud for desktop. You still have Creative Cloud applications installed on your computer that require it. Weird. The only other “app” I had installed was Camera Raw, which was just a plugin. There was also no way to uninstall it inside of the Creative Cloud app. I was able to find the plugin in /Library/Application Support/Adobe/Plug-Ins/CC/File Formats/. Deleting it and relaunching the Creative Cloud app showed that it was now no longer installed. I tried running the Creative Cloud uninstaller again, but I got the same error. This time I tried the “Repair” option, offered as part of the uninstaller, but that also failed. So I then tried the Creative Cloud Cleaner Tool… but this failed, too. At this point I was really annoyed, so I decided to manually remove things. I do not recommend doing this yourself, but here’s a general list of the stuff I got rid of: Under /Applications/: all the Adobe folders Under /Applications/Utilities/: all the Adobe folders The /Library/Application Support/Adobe and ~/Library/Application Support/Adobe directories, as well as any com.adobe.* files Under /Library/Preferences/ and ~/Library/Preferences/ all the Adobe* and com.adobe.* files Under /Library/Caches/ and ~/Library/Caches/ any Adobe* directories Under /Library/LaunchAgents/, /Library/LaunchDaemons/, and ~/Library/LaunchAgents/ directories: all the com.adobe.* files Under /Library/PrivilegedHelperTools: all com.adobe.* files Under /Users/Shared: all Adobe* directories Let me reiterate: you should not follow my lead here. I likely missed some things, and it’s very easy to mess things up by deleting system files. I offer no support if you decide to follow these steps. Again, it’s quite possible that there’s something weird going on with my machine or my installation… but I swear I never did anything but use the Creative Cloud app to manage things. I expect Adobe to be able to clean up their mess if they’re going to install files all over the friggin’ place. Anyway, all this said, I’m still slightly sad to be rid of Photoshop. Pixelmator Pro suits my current needs, but there are definitely things I will miss from Photoshop. Pixelmator Pro’s UI is a bit of a Liquid Glass nightmare, but it’s a massive improvement in terms of software quality. I’m extremely happy that it doesn’t strew zillions of files across my computer. I’m also pretty certain it will be much easier to unsubscribe from if I decide to do so in the future. So long, Photoshop. I’ll remember the old days fondly, but you are well past your prime.

12th Jul 2026 • 2 votes
AI and software security: the slop is now signal

No matter how you feel about AI, it’s changing the world of software. The “T” in ChatGPT was invented to improve language translation, and large language models (LLMs) are very good at this. Interestingly, translating between French and Japanese is effectively the same as translating between English and Python for these systems. As LLMs improve, we’re also finding that there’s little difference between “help me fix mistakes in this document”, and “find the flaws in this codebase”. LLMs are now great at both tasks, but the latter has much larger implications. Last month, Anthropic announced Claude Mythos, a next generation model which shows a significant leap in performance over currently available models. During testing, Anthropic noticed that the model was also much better at finding software flaws. The biggest improvements here come from identifying chains of issues which can be combined to produce a larger effect. Because of this, they decided not to release the model to the general public. Instead, they started Project Glasswing, which invited key software vendors to find issues in their code first. Some are calling this a marketing stunt. It’s at least a bit of that. Anthropic’s brand focuses on trust and safety, so holding back a model due to cybersecurity worries helps promote that ideal. However, the model’s system card shows real improvements across the board. More than that, we’re already dealing with AI systems affecting security today. Daniel Stenberg is the original author and lead developer of cURL (and the libcurl library). cURL is a command-line tool for transferring things over the internet. It’s nearly 30 years old, and it’s boring infrastructure in the best possible way. The libcurl library (which allows people to embed cURL’s functionality into their apps) is used in just about everything. Last year, Stenberg wrote about how AI submissions were making reviewing bug reports much more difficult. In that post, he links to previous thoughts about AI. He’s not been a fan, and his reasoning was understandable — other people’s use of AI was making his job worse. In January of this year, he shut down cURL’s bug bounty program to try and stem the deluge of AI bug reports. But then something changed. As the bug bounty was being wound down, people were realizing that Anthropic’s Opus 4.5 model, released in November of 2025, was a massive leap forward in terms of code generation. As more people started using this model, and similarly powerful ones from other AI vendors, the quality of the automated bug reports improved dramatically. At the beginning of April, Stenberg noted that he was seeing less “AI slop”, and was now dealing with a tsunami of reasonable bug reports. Just two weeks later, he shared a thread of charts he was preparing for a presentation. More reports than ever, less slop, and a higher quality of reports overall. It’s not just cURL seeing this, either. Mozilla, makers of Firefox, have written about the same change in bug reports from slop to helpful over the last several months. So have the Linux kernel team. Some of those issues have been around for nearly a decade, and could potentially have already been exploited. In a startlingly short amount of time, AI generated bug reports have gone from being a nuisance to being legitimately helpful. The issue is, even if these reports are helpful, they’re coming in faster than ever. There will always be more people looking for flaws than people willing or able to fix them. Finding flaws can be profitable, either through bug bounty reports or by sale to state-level actors. A troubling new pattern comes from the nature of open source: it happens in public. Security researchers can now have AI agents review all patches committed to a project. Those agents might find new issues, or even patches for high-impact vulnerabilities. In the former case, maybe they’ve found a new bug to report. 1 In the latter, maybe they have a new attack vector to leverage before anyone patches it. As frightening as this all sounds, some people are more optimistic. Mozilla recently published some initial thoughts about their work using the Claude Mythos preview. The main upshot is: yes, there are more attackers than defenders, but software defects aren’t infinite. If defenders can use systems like Mythos on their own codebases, they can potentially fix vulnerabilities before anyone has a chance to abuse them. Maybe future software could be defect-free. Personally, I think this might be a bit too hopeful. A larger organization like Mozilla will have the resources to be ever-vigilant, but not everyone will. If you run a large open source project, you can get Claude access for free… but the world is built on a pile of tiny projects. When those fall over, very bad things can happen. Even if the Mozilla take is correct, I worry that things will get worse before they get better. Whatever the future holds, I suspect that most people reading this won’t be security researchers or maintainers of software packages. Here are some concrete steps the rest of us can take: Software is forever An early lesson every developer learns is: software is never done. Even if you’re not adding new features, there’s always another security patch to apply or an API that’s being changed out from under you. This was true in the days before LLMs, and it’s even more true now. I’ve been working with more clients who have been vibe-coding apps. When used as internal tools, these apps can be genuinely helpful. However, I worry when I see they have access to important data or are hosted next to critical systems. If you have a system connected to the internet (or some other untrusted environment), you must have a plan to maintain it for as long as it will exist. Someone has to ensure the system is secure and apply patches when they become available. This has always been a good idea, but now it’s imperative. Update as soon as possible If there’s an update for your operating system or your phone, you should install it as soon as you can. Again, this has always been good advice, but it matters a lot more now. Really think before clicking things Phishing attempts powered by AI are more able to appear legitimate. They’re also easier to personalize. Recently Adobe’s customer support platform was targeted in a fairly novel phishing scheme. I suspect we’ll see more like this going forward. ⋯ We’re in an odd moment. It’s possible we’re at the start of something genuinely good, a time when security defenders can start outpacing attackers. It’s also possible that things are just about to hit the fan in ways we’ll all notice. Whatever the case, the software you depend on today will need someone watching it tomorrow. That part hasn’t changed, and probably never will. Here’s the prompt used to identify this issue. ↩

10th May 2026 • 1 votes

More in technology

FLIP Fluid on Flip Dots

[Hardware] Electromechanical Fluid Simulation

4 days ago • 1 votes
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’

5 days ago • 1 votes
The Reason You Prohibit Things

You want less of them. That’s the reason. You may find that it’s too hard to stop people from doing the thing, literally blood, sweat, and tears trying to prosecute people, but that’s a different thing.

5 days ago
📚 BoredReading

You seem to be enjoying this.

Join free to unlock everything.

Create free account

Already have an account? Sign in