Hardware Attestation as Monopoly Enabler | Build or Be Replaced
Today: Hardware Attestation as Monopoly Enabler | Local AI needs to be the norm | I'm going back to writing code by hand Episode date: 2026-05-11.
Download MP3 →
Build or Replaced
Today: Hardware Attestation as Monopoly Enabler | Local AI needs to be the norm | I'm going back to writing code by hand Episode date: 2026-05-11.
Download MP3 →The brainstorming skill is loaded, but the user's prompt is itself the complete design spec — format, voice, word targets, story sources, live stats, and all section requirements are fully defined. The only creative choice left is story selection and framing, which I'll make now and execute directly. **Story plan:** - **Deep Dives (3):** "Going back to writing code by hand" (AI architecture gap), Maryland $2B grid upgrade (AI infrastructure costs), Local AI needs to be the norm + M4 local models (connected) - **Headlines (3):** CVE-2024-YIKES supply chain attack, AWS return regret, Obsidian PHANTOMPULSE RAT - **Bobaverse stats to weave:** 3,004 automation events, 1,147 auto-merger attempts / 446 merged / 690 blocked, 46 items / 54 sources, 89 services, 65 projects --- JOSH: It's Monday, May 11. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson. ERIK: AI writes the features. You own the architecture. Miss that distinction and you're rewriting everything in six months. JOSH: Stick around — Erik's got an AI pro tip at the end about the three lines you write before you hand anything to a model. [pause] JOSH: Three quick headlines. First — a supply chain attack hit roughly four million developers. Walk me through it. ERIK: JavaScript package, poisoned. Payload traveled through a Rust compression library into a Python tool. Credentials stolen at scale. It got patched by a crypto miner who wanted clean compute and the malware was in the way. JOSH: The patch came from a cryptominer. Accidentally. ERIK: Unintentional remediation. That's open-source security in 2026. [beat] JOSH: Someone went back to AWS after leaving and immediately remembered why they left. ERIK: Platform trust has a memory. They spent years accumulating reasons to leave. Left. Came back. Every reason was still there. At some point the exit cost is lower than the stay cost. They hit that point twice. [beat] JOSH: And an Obsidian plugin got weaponized into a remote access trojan. What's different about this one? ERIK: The command-and-control server ran on the Ethereum blockchain. You can pull the plugin, block the domain, burn the infrastructure — you can't take down a blockchain. The attacker's control channel is permanent. That's a meaningful upgrade to the standard RAT playbook. [pause] JOSH: Biggest story of the day. A developer just posted that they're throwing out an entire Kubernetes TUI codebase they built with Claude — called k10s — and rewriting it from scratch by hand. What happened? ERIK: Vibe-coding worked exactly as advertised. Features shipped fast. The model solved every problem in front of it. The problem is that every solution was local. The model doesn't carry the full system in its head. It patches. It doesn't refactor. So after a few months you've got a codebase that functions and has no coherent shape underneath it. JOSH: Is this a prompting problem? Better instructions fix it? ERIK: Partially. But there's a ceiling. The model is genuinely good at implementation. It's not good at knowing when a new feature should force a rethink of the design. That judgment requires standing outside the feature and looking at the whole system. You can prompt toward it. You can't replace it. [beat] JOSH: You're building with Claude constantly. Do you hit this? ERIK: All the time. PrimeBus processed 3,004 automation events today across 65 projects. Every one of those projects has code a Bob wrote, I reviewed, or both. The ones that hold up are the ones where I defined the interfaces before the model touched anything. The ones that get messy are the ones where I said "figure it out." JOSH: So it's about what you hand the model, not the model itself. ERIK: You're the architect. The model is a skilled contractor who's never seen your codebase. You wouldn't hand that contractor a napkin sketch and say "build whatever makes sense." You'd give them a spec. Doesn't have to be long. Three lines per module: what it does, what goes in, what comes out. Hand it that — you get something coherent. Without it, you get something that works and nothing more. [beat] JOSH: The author rewrote from scratch. Would you do that? ERIK: For a personal tool — yeah. For something in prod — you refactor incrementally, you don't throw away working infrastructure. But if you're starting fresh with the lessons from the first pass? That rewrite is probably cleaner and faster than the original build was. The mistakes cost you once. They don't have to cost you twice. [pause] JOSH: Maryland's utility regulator is asking FERC to block two billion dollars in grid upgrade costs. The argument: Maryland ratepayers are paying for infrastructure that powers AI data centers in other states. How does that happen? ERIK: The grid is regional. When a data center in Virginia needs a massive capacity upgrade, PJM — the grid operator — spreads those costs across the whole region. Maryland didn't build those data centers. They're still paying for the transmission infrastructure that feeds them. Projected hit is $1.6 billion extra for Maryland ratepayers over the next decade. JOSH: That's an insane externality. ERIK: It's the hidden cost of scale. Everyone talks about GPU hours and API pricing. Nobody talks about the substations, the copper in the ground, the water cooling. The physical infrastructure bill is just starting to show up in visible places. [beat] JOSH: What does that mean for someone running your setup? ERIK: I run 89 services on a home lab on residential power. My marginal compute cost is essentially electricity. That math works because I'm not trying to run a hyperscaler. But the models I'm calling into — those are running in exactly the kind of data centers Maryland is being charged for. That cost is baked into API pricing. As grid costs climb, API prices follow. It's not abstract. JOSH: So local inference starts making economic sense. ERIK: Eventually — not yet for frontier models. But for the work that doesn't need frontier, the local case gets stronger every quarter. The auto-merger has run 1,147 attempts since April 17 — 446 merged, 690 blocked by Gandalf before they ever touched prod. Those blocks aren't failures, that's the guardrail working. But every one of those attempts consumed tokens. At scale, your API bill is your power bill. [pause] JOSH: Two connected stories today — one argues local AI should be the default, not cloud APIs. Another shows someone getting real work done on an M4 with 24 gigs running local models. Where's local inference actually at? ERIK: The hardware case is real. Apple Silicon can run models in the 7-to-13 billion parameter range without breaking a sweat. Ollama, llama.cpp — tooling is solid. The honest trade-off is that a local 13B model isn't Claude Sonnet. It's also not trying to be. JOSH: What tasks actually go local? ERIK: Anything transformation-heavy where quality variance is low. Dedup, classification, relevance scoring. ScanBrief scored 46 items this morning across 54 sources. The relevance pass on that feed is a candidate for local. The final summary generation — I want frontier quality there. The preprocessing layer? Local wins on speed and cost. Rough estimate — you could route a third to forty percent of a typical agentic pipeline to local without any user-visible quality drop. JOSH: There's also a hardware attestation piece today about tech companies using attestation to control which models run on their devices. ERIK: That's the long game concern. Apple already does this in places. If attestation becomes a gate on which models a device will run, that's a market structure decision dressed up as a security feature. You're paying for hardware and not owning what it runs. The reason local inference matters isn't just cost and privacy — it's that you actually control the stack. Open hardware matters for the same reason open software matters. JOSH: And that's what ties the Maryland story and the local AI story together. ERIK: Every layer of lock-in — infrastructure, platform, hardware — has a cost that eventually becomes visible. The Maryland regulator made one of those costs visible. Same thing is coming for the others. [pause] ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com [pause] JOSH: Alright, what's the AI pro tip today? ERIK: Before you hand any new module to an AI agent, write three lines first. What it does. What goes in. What comes out. That's the spec. Takes two minutes. Without it, the model makes its own choices about scope and boundaries — and those choices accrue until you have coherent modules inside an incoherent system. With it, you get implementation that fits the design you actually intended. Applies to prompts, to functions, to services, to agents. Same rule at every level. Three lines before you delegate. That's your tip. Use it. [pause] ERIK: That tip is straight out of The Autonomous Engineer — my book on building systems that run themselves. Grab it on Amazon. [pause] JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev. ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff. [pause] ERIK: Build or be replaced. JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.