Mon–Fri · 6 AM ET
← All Episodes
EP  • 00:13:02

Delta | Build or Be Replaced

Today: Delta | Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot | uBlock Origin Is Giving Up the Fight to Keep Ads Off Facebook Episode date: 2026-08-13.

Download MP3 →

Transcript

JOSH: It's Thursday, August 13. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: Today's theme is simple. The internet is getting noisier, the models are getting cheaper, and your guardrails better be real.
JOSH: Stick around — Erik's got an AI pro tip at the end about making agents show their work before they touch production.
[pause]
JOSH: First headline. Somebody is running mass vulnerability scans while pretending to be AI crawlers like ClaudeBot. That's creepy, right?
ERIK: Creepy, but not surprising. Bot identity is becoming camouflage. If your security policy trusts a user agent string, that's not a policy, that's a sticky note.
JOSH: Second one. Tailscale tracked outages to a 16-year-old SQLite WAL-reset bug.
ERIK: That one's my favorite. Not because the bug is fun, but because it proves boring storage details still run the world. Control planes don't care how modern your dashboard looks.
JOSH: Third headline. Big open model day. DeepSeek V4 Pro 0813, Qwen3.8-2.4T, and Grok 4.6 all hit the feed.
ERIK: This is the pressure wave. Open weights, huge context, tool use, cheaper inference. If your AI architecture assumes one vendor forever, you're already behind.
[pause]
JOSH: That bot spoofing story feels like the one that should wake people up.
ERIK: It should. The old version of the web was pretty dumb. You had crawlers, scrapers, search bots, bad scanners, and a few polite robots.txt citizens. Now everybody wants to look like an AI bot because AI bots get special treatment.
JOSH: Wait, really? Sites are giving AI crawlers a pass?
ERIK: Some are. Some want to be indexed by model companies. Some block them. Some allowlist them. Some rate-limit them differently. The problem is identity. A user agent can say ClaudeBot, Googlebot, GPTBot, whatever. That doesn't mean it is one.
JOSH: So what's the real check?
ERIK: Reverse DNS, signed fetch where available, IP range validation, behavior scoring, and rate limits that assume lying is normal. That's the baseline. If the request pattern looks like mass vuln scanning, I don't care what mascot name it puts in the header.
JOSH: That's a grim sentence.
ERIK: Accurate, though. Security teams need to stop treating AI traffic as a cute new category. It's HTTP traffic. It can be hostile. It can be useful. It can be both in the same hour.
JOSH: How would you handle that in your own stack?
ERIK: PrimeRouter already treats providers and callers as separate trust zones. Same idea for public traffic. I want identity, volume, path behavior, and outcome tied together. Did this caller hit normal pages? Did it jump straight to admin paths? Did it request weird files? Did it touch ten hosts in thirty seconds?
JOSH: And then what?
ERIK: Put it on the bus. PrimeBus exists for this exact reason. An event comes in, agents subscribe, and you get action. Not a human staring at logs at 2:00 AM pretending that's a process.
JOSH: That's the part people skip, right? They log it, but nothing happens.
ERIK: Exactly. Logs are not automation. Logs are evidence. You still need a system that reads the evidence and does something. Rate-limit the source. Open a ticket. Add a temporary block. Ask a human if the confidence is low. Roll it back automatically if it hurts good traffic.
JOSH: How much of that is running today in your world?
ERIK: The Bobaverse has 146 services running on the production server right now. That is too many moving parts for manual babysitting. PrimeBus has seen 140 distinct projects emit telemetry. That's why I care about events. Every project yelling into its own text file is how you lose.
JOSH: So the headline isn't really fake ClaudeBot.
ERIK: No. The headline is that identity on the internet is getting weaker while automation is getting stronger. Bad combo. If you're building agents, scanners, crawlers, or gateways, you need provenance. Who asked for this? What did they do before? What changed after?
JOSH: And if you don't have that?
ERIK: Then you're guessing. Guessing is expensive. Sometimes it's also a breach report.
[pause]
JOSH: The Tailscale SQLite story is different. That sounds small, but it caused real outages.
ERIK: That's why it's good. A 16-year-old WAL-reset edge case is not the kind of thing that gets a conference keynote. But it can still punch your control plane in the mouth.
JOSH: What actually matters there?
ERIK: Write-ahead logging is one of those pieces everybody benefits from and nobody thinks about until it bites. SQLite is excellent. I use it all over the place. But excellent doesn't mean magic. If your architecture has a single writer, shards, replication assumptions, and a weird edge case in the storage layer, you can have months of pain before the real cause shows up.
JOSH: Months?
ERIK: Yeah. Intermittent control-plane issues are nasty. They don't always fail clean. You get a weird state, a reset you didn't expect, a timing path that only appears under load, and now everyone starts blaming the newest code.
JOSH: Because the newest code is always guilty.
ERIK: It's always standing near the body. Doesn't mean it did it.
[beat]
JOSH: That's annoyingly true.
ERIK: The lesson is instrumentation. You can't debug what you didn't measure. Tailscale could trace it because they had enough visibility into their control plane to narrow it down. That's serious engineering.
JOSH: How does that compare to network automation?
ERIK: Same pain, different furniture. In Cisco NSO, Terraform, Kubernetes, whatever, people assume the declarative layer saves them. It doesn't. It gives you intent. The system underneath still has locks, transactions, retries, state drift, and partial failure.
JOSH: So the database bug becomes a network automation lesson?
ERIK: Absolutely. If your automation platform writes intended state, then crashes halfway, then retries with stale assumptions, you don't have automation. You have a very fast intern causing damage.
JOSH: How do you avoid that?
ERIK: Idempotency first. Every action needs to be safe to repeat. Then state checks before and after. Then event receipts. Then rollback plans that are boring enough to trust.
JOSH: Boring enough to trust is a pretty good standard.
ERIK: It is. PrimeBus auto-merger has run 2295 attempts since 2026-06-05: 1507 merged, 788 blocked by Gandalf, 0 escalated to Erik. The blocked count is the important part. Gandalf is there to say no when the system is not confident enough.
JOSH: That's wild. Most people would brag about the merges.
ERIK: The blocks are where the discipline is. Anybody can make an agent change code. Cool. Did it pass tests? Did it touch the right files? Did it avoid secrets? Did it avoid changing policy? Did it explain itself? Did another agent review it? That's the job.
JOSH: And that maps back to SQLite how?
ERIK: Hidden state kills systems. The fix is not vibes. It's receipts. Storage receipt. Test receipt. Deployment receipt. Telemetry receipt. If something resets under you, your system should notice the shape of that failure and route it somewhere useful.
JOSH: Not just page a human.
ERIK: Page a human when the human can actually decide something. Don't page me because a job got stuck. PrimeSentinel can run-sentinel that. Don't page me because a test failed once. Have an agent reproduce it. Page me when the blast radius is real or the decision needs judgment.
JOSH: That's the difference between alerts and operations.
ERIK: Yep. Alerts are noise until they carry context and an action. Otherwise it's just a digital smoke alarm with no room number.
[pause]
JOSH: The model releases today feel like a different kind of pressure. DeepSeek, Qwen, Grok. What should builders take from that?
ERIK: Model choice is becoming routing, not religion. That's the big shift. People still talk like you pick one model and marry it. That's done. You route by job.
JOSH: Give me examples.
ERIK: Cheap classification goes to a cheap model. Long-context document review goes to the model with the right context window. Coding fixes go to the model that has the best repo behavior. Vision goes to vision. Tool-heavy workflows go to the model that doesn't panic when the schema gets real.
JOSH: So it's less about who has the crown.
ERIK: Exactly. Benchmarks are useful, but your workload is the benchmark. PrimeRouter exists because I don't want one provider outage, one pricing change, or one bad model update to break my systems.
JOSH: What does PrimeRouter actually decide?
ERIK: Priority tier, provider, retry path, timeout, telemetry, fallback. If a request is low value, it doesn't get the expensive lane. If a request is production critical, it gets stronger routing and better audit. If a provider starts throwing errors, traffic moves.
JOSH: That's very different from a chatbot dropdown.
ERIK: A dropdown is fine for humans playing around. Systems need policy. A fleet needs policy. The Bobaverse fleet has 12 agents right now, Neo, Homer, Bill, Echo, Gandalf, Claude plus GPT. If they all call models directly with their own little API keys and opinions, that's chaos.
JOSH: And open weights make that more important?
ERIK: More important, not less. Open models are great. I want local options. I want cheap options. I want models I can run closer to the data. But now you need to track quality, latency, cost, context limits, safety behavior, tool calling, and failure modes across more choices.
JOSH: Sounds like a lot.
ERIK: It is, which is why you build the router once. Then every app gets better. ScanBrief scored 102 items across 56 sources today. That pipeline should not care which model wins next month. It should ask PrimeRouter for the right lane and move on.
JOSH: What about the huge context windows? Qwen Max says one million tokens. People love that.
ERIK: Huge context is useful, but it's not a personality trait. People will dump garbage into a million-token window and call it memory. That's how you get slow, expensive confusion.
JOSH: What's the better pattern?
ERIK: Retrieval first. Summaries with citations. State kept outside the model. Then use big context when it actually changes the answer. Contracts. Codebases. Long incident timelines. Not every meeting transcript since January.
JOSH: That's the pro-builder take.
ERIK: Right. Bigger context doesn't remove architecture. It punishes bad architecture later in the bill.
JOSH: Where do you think this goes next?
ERIK: Smaller models doing more boring work. Bigger models doing judgment passes. Local models handling private tasks. Routers deciding the lane. Agents writing receipts into event buses. Humans approving the weird stuff.
JOSH: So AI gets more normal.
ERIK: That's the win. The less magical it feels, the more useful it gets. Claude, GPT, DeepSeek, Qwen, Grok, whatever comes next. They become workers behind interfaces. Give them jobs, constraints, tests, and a place to report what happened.
JOSH: Not a blank chat box.
ERIK: Blank chat boxes are where good intentions go to become screenshots.
[pause]
JOSH: Quick sidebar before the sponsor. HTML over WebSockets also hit the feed. You smiled when you saw that.
ERIK: Because it's the pendulum swinging back. People built massive JavaScript piles to move tiny bits of UI state. Sometimes you just need the server to send HTML and the browser to show it.
JOSH: Is that anti-React?
ERIK: No. It's anti-using a forklift to carry a sandwich. React has its place. But internal tools, dashboards, ops panels, lab systems, a lot of that can be dead simple. Real-time updates over WebSockets, tiny JavaScript, server-owned state.
JOSH: PrimeDash territory?
ERIK: Exactly. PrimeDash is a LAN dashboard for every running service in the lab. I care if the service is up, what changed, what failed, and what needs attention. I don't need a frontend philosophy degree to render that.
JOSH: Dry, but fair.
ERIK: Useful beats fancy. Every time.
[pause]
ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com
[pause]
JOSH: Alright, what's the AI pro tip today?
ERIK: Make your agent produce a change receipt before it edits anything important. Not after. Before.
JOSH: What goes in the receipt?
ERIK: Four fields. Intended file or system. Reason for change. Test or validation it will run. Rollback plan. If it can't fill those out, it doesn't get write access.
JOSH: That's simple.
ERIK: Simple is the point. Put it in the prompt. Put it in the wrapper. Put it in CI. For code, make the agent say, I will edit these files, I expect these tests to pass, and I will stop if these files change. For infra, make it state the target device, config section, pre-check, post-check, and revert command.
JOSH: And if it lies?
ERIK: Then your gate catches it. Diff check. Path allowlist. Test result. Human approval for high-risk paths. Don't ask an agent to be trustworthy. Build a system where trust is earned every run.
JOSH: That's a good one.
ERIK: Agents are fast. That's useful. Agents are also very confident while being wrong. That's normal. The receipt slows them down just enough to make them usable. That's your tip. Use it.
[pause]
JOSH: Track your freedom score and net worth with the Freedom Blueprint app — free download, link in the show notes.
[pause]
JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.
[pause]
ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.