Radar Daily Briefings
A clearer signal for WordPress and engineering
/\_/\
(=^.^=)
(")_(")
/\_/\
(=^.^=)
(")_(")
Report details ChatGPT-linked cross-site tracking via OpenAI ad collector
A technical article reports that OpenAI’s __obi cookie can connect identifiers created during ChatGPT use with requests from advertiser websites. The author says the mechanism was reproduced on Chrome for Android.
The report describes short-lived RS256 JWTs, a one-year .openai.com cookie with SameSite=None, and advertiser SDK requests carrying the identifier. It also reports collection of page paths, location fields, and hashed identity values from page and tag-manager sources.
The author observed identifiers appearing across multiple advertisers, but did not directly observe server-side account resolution. Browser coverage was limited, and OpenAI Support did not answer the author’s stated questions.
Jane Street study finds non-monotonic sequence-weighting scaling
Jane Street researchers report a study of sequence weighting across two in-house language-model families and the open-weight Qwen 2.5 family. The study finds a non-monotonic effective sequence-weight exponent: it often rises from small to medium scales and falls at larger scales.
The metric estimates how loss reduction on training sequences depends on their assigned weights. Models were trained with log-uniform sequence weights, evaluated after multiple epochs, and compared across model sizes. More epochs shifted the observed peak toward smaller models.
The results caution against extrapolating data-weighting behavior from small models to large ones. The experiments use an internal text benchmark, and a proposed weighting-compensation approach remains untested.
Simon Willison publishes quotation criticizing Claude Code-driven shipping
Simon Willison published a quotation from “voxium” describing a workplace where Claude Code produces specifications, code, tests, PRDs, tickets, resolutions, and reports. The quotation portrays engineers working 12 to 13 hours daily while being pressured to ship more.
The account’s central concern is not a specific Claude Code feature, but an engineering process in which generated output is rarely read or reviewed. It says people across engineering levels are directed to “talk to Claude.”
For engineering leaders, the quotation is a warning about review capacity, accountability, and workload when code production is treated as the bottleneck. It is anecdotal, covers one reported team, and supplies no measurements or mitigation guidance.
Samsung plans to more than double HBM4-family output
Samsung Electronics is expected to more than double output of its HBM4 family, including HBM4 and HBM4E, next year. The report describes planned capacity expansion rather than a confirmed completed production change.
According to industry sources cited by Seoul Economic Daily, monthly outsourced glass-carrier cleaning is planned to rise from 20,000 to 50,000 sheets. Glass carriers support wafers during thinning and drilling, while the products being scaled use 12-layer and higher stacks.
Industry estimates also project higher wafer input and a larger HBM4-family shipment share as HBM4E production ramps. These figures remain projections, and the supplied article provides no independent confirmation.
Wordfence publishes weekly WordPress vulnerability report for September 7–13
Wordfence published its Intelligence Weekly WordPress Vulnerability Report for September 7–13, 2026. The report covers vulnerability disclosures added to the Wordfence Intelligence Vulnerability Database during that period.
The supplied excerpt says the report is intended to make vulnerability information accessible and directs site operators to review the disclosures to determine whether their sites are affected.
The excerpt is truncated, however, and does not identify vulnerabilities, counts, affected versions, severity, exploitability, or remediation steps. Engineers should treat this briefing as a pointer to the period-specific report rather than a complete exposure assessment.
WordPress draft proposes mini contributor sessions at Meetups
A WordPress community post proposes an early guide for running 30- or 60-minute mini contributor sessions at local Meetups. The draft is seeking feedback and organizers willing to test it.
The guide covers preparation, suggested session formats, required accounts and tools, activity instructions, expected outcomes, attendee support, and follow-up. Initial activities include suggesting a translation, submitting a photo to the WordPress Photo Directory, testing WordPress with Playground, and reporting a documentation issue.
The proposal is intended to help beginners make a first contribution without a full Contributor Day. It remains unvalidated: the post provides no pilot results, adoption data, or finalized implementation.
WordPress Training Team recap reports cohort results and review plans
The WordPress Training Team has published a meeting recap covering course maintenance, contributor coordination, accessibility exploration, and its first DACH guided-learning cohort. Six people enrolled and four completed the Learn WordPress course.
The cohort combined self-paced lessons with seven weekly 90-minute Zoom sessions and Slack communication. Organizers report that live sessions were valuable, but the schedule allowed too little hands-on practice. They plan a flipped-classroom format for the next cohort and are creating a glossary for terminology differences.
The recap also seeks feedback on text-to-speech prototypes and volunteers for issue, translation, handbook, and thumbnail work. The cohort results come from a small initial group.
datasette-explain 0.2.2 adds explain plans to read-only stored-query pages
Simon Willison’s release post announces datasette-explain 0.2.2, a new version of the Datasette plugin. The documented change is that explain plans now work on read-only stored-query pages.
The plugin is described as explaining and validating SQL queries while they are typed into Datasette. The release followed an upgrade of datasette.simonwillison.net to Datasette 1.0a40, which the post says inspired the update.
The change is relevant to engineers inspecting queries in Datasette’s stored-query interface. The supplied material does not provide implementation details, benchmarks, compatibility constraints, or broader database-system effects.
llm-keys-ui 0.1 releases web UI for LLM API keys
Simon Willison has released llm-keys-ui 0.1, a focused web interface for configuring LLM API keys on machines used by coding agents.
The documented workflow runs uvx --with llm-keys-ui llm keys-ui --all, after which the agent reports a URL for an interface reachable through local-network or Tailscale device IPs. Keys can later be retrieved in shell commands with llm keys get anthropic or similar commands.
The tool targets users controlling remote coding agents from a phone and avoids pasting keys into agent sessions. The supplied release description does not provide architecture, threat-model details, or security guarantees.
Wordfence 9 introduces passkey authentication
Wordfence says version 9 introduces passkeys, adding passwordless authentication to the product. The supplied announcement presents the feature as available in the released version.
According to Wordfence, passkeys reduce login friction because users no longer need to remember a password or retrieve and copy it from a password manager.
The excerpt does not explain configuration, browser or device compatibility, deployment requirements, or measured effects on engagement. Administrators should therefore treat it as a release announcement and seek product documentation before planning rollout.