{
    "archive_path": "archive/1782706242.602333",
    "base_url": "blog.glyph.im/2026/06/adversarial-communication.html",
    "basename": "adversarial-communication.html",
    "bookmarked_date": "2026-06-29 04:10",
    "canonical": {
        "archive_org_path": "https://web.archive.org/web/blog.glyph.im/2026/06/adversarial-communication.html",
        "dom_path": "output.html",
        "favicon_path": "favicon.ico",
        "git_path": "git/",
        "google_favicon_path": "https://www.google.com/s2/favicons?domain=blog.glyph.im",
        "headers_path": "headers.json",
        "htmltotext_path": "htmltotext.txt",
        "index_path": "index.html",
        "media_path": "media/",
        "mercury_path": "mercury/content.html",
        "pdf_path": "output.pdf",
        "readability_path": "readability/content.html",
        "screenshot_path": "screenshot.png",
        "singlefile_path": "singlefile.html",
        "warc_path": "warc/",
        "wget_path": null
    },
    "domain": "blog.glyph.im",
    "downloaded_at": "2026-06-29T04:10:48.671563+00:00",
    "downloaded_datestr": "2026-06-29 04:10",
    "extension": "html",
    "hash": "ZY3YXM38PRTYSTFZ3N9F",
    "history": {
        "archive_org": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://web.archive.org/save/https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-06-29T04:12:18.313363+00:00",
                "index_texts": null,
                "output": "https://web.archive.org/web/20260629041158/https://blog.glyph.im/2026/06/adversarial-communication.html",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:47.315957+00:00",
                "status": "succeeded"
            }
        ],
        "dom": [
            {
                "cmd": [
                    "/usr/bin/chromium-browser",
                    "--proxy-server=socks5://tor-socks-proxy:9150",
                    "--disable-features=DarkMode",
                    "--run-all-compositor-stages-before-draw",
                    "--hide-scrollbars",
                    "--autoplay-policy=no-user-gesture-required",
                    "--no-first-run",
                    "--use-fake-ui-for-media-stream",
                    "--use-fake-device-for-media-stream",
                    "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'",
                    "--headless=new",
                    "--no-sandbox",
                    "--no-zygote",
                    "--disable-dev-shm-usage",
                    "--disable-software-rasterizer",
                    "--disable-sync",
                    "--window-size=1440,2000",
                    "--user-agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "--user-data-dir=/data/personas/Default/chrome_profile",
                    "--profile-directory=Default",
                    "--dump-dom",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "131.0.6778",
                "end_ts": "2026-06-29T04:11:20.686029+00:00",
                "index_texts": null,
                "output": "output.html",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:11.334716+00:00",
                "status": "succeeded"
            }
        ],
        "favicon": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--output",
                    "favicon.ico",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://www.google.com/s2/favicons?domain=blog.glyph.im"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-06-29T04:11:02.377118+00:00",
                "index_texts": null,
                "output": "favicon.ico",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:10:48.896081+00:00",
                "status": "succeeded"
            }
        ],
        "git": [],
        "headers": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-06-29T04:11:02.659509+00:00",
                "index_texts": null,
                "output": "headers.json",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:02.462810+00:00",
                "status": "succeeded"
            }
        ],
        "htmltotext": [
            {
                "cmd": [
                    "(internal) archivebox.extractors.htmltotext",
                    "./{singlefile,dom}.html"
                ],
                "cmd_version": "0.8.5rc51",
                "end_ts": "2026-06-29T04:11:39.429334+00:00",
                "index_texts": [
                    "(https://login.launchpad.net/+openid) (https://login.launchpad.net/+id/GLCYheW) (https://login.launchpad.net/+openid) (https://login.launchpad.net/+id/GLCYheW) (https://blog.glyph.im/images/favicon.ico) (https://blog.glyph.im/feeds/all.atom.xml) (Deciphering Glyph Atom Feed) Deciphering Glyph ::\n        Adversarial Communication  (https://blog.glyph.im/theme/css/main.css?34c71978)  (https://blog.glyph.im/) Deciphering   Glyph    (https://blog.glyph.im/pages/about.html) About  (https://blog.glyph.im/archives.html) Archives  (https://mastodon.social/@glyph) Mastodon  (https://github.com/glyph) GitHub  (https://blog.glyph.im/pages/patrons.html) Patrons     (https://blog.glyph.im/2026/06/adversarial-communication.html) (Permalink to Adversarial Communication) Adversarial Communication  \u201cAI\u201d turns every conversation into a fight, because fighting is what\nthey are good at.  (/tag/ai.html) ai (/tag/llm.html) llm (/tag/programming.html) programming  (https://blog.glyph.im/2026/06/adversarial-communication.html) (Permalink to Adversarial Communication) Tuesday June 23, 2026     As I have discussed in (https://blog.glyph.im/2025/08/futzing-fraction.html) previous posts , \u201cAIs\u201d can make mistakes .  In fact, they do make mistakes, and their\nmistake-making patterns are such that where and how they will make mistakes is\nboth uncertain and constantly changing. Thus, in any scenario where you want to attempt to make \u201cproductive\u201d use of\n\u201cAI\u201d, you must have a system in place for checking every result.  Not checking some results; checking every result.  If each result might have a\nconsequence for you (and if it didn\u2019t have a consequence, why bother automating\nit?) and you cannot predict in advance which kinds of results will need\nverification, then verification is always required. The verification often ends up being just as expensive as doing the work in the\nfirst place, which means that if you want your usage of \u201cAI\u201d to be personally\nprofitable, you have to find someone else to externalize the cost of\nverification onto.  This person becomes your adversary, and, if you are\nsuccessful, your \u201cAI\u2019s\u201d victim. The Ladder-Climber And Their Reverse-Centaur Rungs One way that this constellation of facts can straightforwardly assemble\nthemselves into a dystopian nightmare is the phenomenon, described by Cory\nDoctorow, of the (https://locusmag.com/feature/commentary-cory-doctorow-reverse-centaurs/) reverse\ncentaur .\nThis is when your employer non-consensually turns you into the verification\nsystem.  The \u201cAI\u201d does the fun part of initially performing the work, and then\nyou do the boring part where you check if the robot is right and clean up its\nmesses, even if (https://fortune.com/article/why-is-the-cost-of-ai-higher-than-human-workers-nvidia-executive/) everyone already knows that it would, in aggregate, be cheaper\nfor you to do the work in the first\nplace . Reverse centaurs can be made from any automation, not only \u201cAI\u201d automation.\nI think that there is a reason that this term happens to have emerged in the\n\u201cage of AI\u201d, though, and not with earlier automation technologies (even those\nwhich were (https://en.wikipedia.org/wiki/Cotton_gin#Effects_in_the_United_States) considerably more (https://victorianweb.org/technology/ir/capuano.html) viscerally\nhorrific ).  That reason\nis: the wrongness of \u201cAI\u201d output is not merely a technical feature that must\nbe compensated for, it is a generalized externality. As I mentioned above, if you are responsible for the entirety of the work, both\nextruding the \u201cAI\u201d output and checking it, it\u2019s usually cheaper to have\nhumans do the entirety of the work to begin with.  When humans do the writing\ndirectly, we can check as we go, and thus verification doesn\u2019t need to be as\ncomprehensive. When \u201cAI\u201d coding advocates say \u201ccode review is the (https://lucumr.pocoo.org/2026/2/13/the-final-bottleneck/) bottleneck \u201d, what\nthey are observing is that the LLM is still rolling the dice for each PR, and a\nhuman is still necessary to verify that each of those rolls is a winner.  But\ncalling this process \u201ccode review\u201d is a bit of a (https://blog.glyph.im/2026/03/what-is-code-review-for.html) misnomer ; it\u2019s not really \u201ccode\nreview\u201d in the traditional sense, it\u2019s human understanding . Before the advent of \u201cAI\u201d, the human understanding was implicit in the process\nof writing the code in the first place1  , and the code review was a way of\ndiffusing and extending that understanding.  Now that the code can be authored\nwith no initial understanding taking place, that cost has not gone away, it has\nmoved. Human understanding was always the bottleneck. However, this is taking a collaborative view of a software project, where\nsatisfying the needs and solving the problems of your customers are the goals.\nWe can see that \u201cAI\u201d is a bad tool to satisfy those goals, because all it\u2019s\ndoing is converting the first half of the work, that of understanding the code\nas you write it, to understanding the agent\u2019s output as you read it. What if, instead, we were to take the view that every software company is a\nHobbesian nightmare, red in tooth and claw? In this view, the only goal of a\nsoftware project is for the individual developers to make their promo cycles\nand get their bonuses.  Given that there is only a certain amount of money to\ngo around, this is a zero-sum game where each programmer wants to look more\nproductive than their colleagues. Pretty much every organization finds it easy to reward \u201cproductivity\u201d as\nexpressed by lines of code emitted, but the benefits of doing\nthorough and thoughtful design, analysis, and code review very difficult to\nreward.  In this world, an LLM is an invaluable tool for the sociopathic\nladder-climber, particularly if your legacy organization is still structuring\ntheir workflows as if the person prompting the bot is \u201cwriting\u201d the code, and\nthen they get to foist off the act of \u201creviewing\u201d the code onto someone else. Here, the prompter effectively externalizes the cost of the LLM\u2019s failures but\ninternalizes any benefits.  The prompter will vibe-code a big feature, so large\nthat the assigned reviewer can\u2019t possibly comprehend it all effectively. When\nthis happens, the reviewer will, eventually , be pressured to approve it, even\nif they can try to spot a few problems along the way.  The reviewer has their\nown work to get back to, after all, the obligation to review the prompter\u2019s\n(read: the bot\u2019s) code is a drain on their time that they are not going to get\nrewarded for. If this feature is a big success, the prompter gets a promotion.  If it causes\na big issue, well, the reviewer must not have been careful enough. This is why LLMs are \u201cgood for coding\u201d, and also why their biggest promoters (https://ap7i.com/posts/github-outages-vibe-coding-era/) keep (https://www.linkedin.com/posts/paulsf_last-weeks-massive-google-cloud-outage-activity-7340015235321278466-c0hz) having (https://www.ft.com/content/7cab4ec7-4712-4137-b602-119a44f771de) outages . The Generative Gish Galloper Coding is the biggest \u201csuccess story\u201d of this type of adversarial\ncommunication, but it is by far not the only instance of such a thing.  LLMs\ncreate a new form of leverage that can turn (https://en.wikipedia.org/wiki/Brandolini%27s_law) Brandolini\u2019s\nlaw from a linear advantage\ninto an exponential one.  If you are engaged in a political debate where you\nwant to overwhelm the other side in nonsense, an LLM can generate bullshit\nfaster than it is physically possible for a human being to type, let alone\nrespond thoughtfully.  There is an asymmetry to the utility of this weapon as\nwell: only one side of the political spectrum wants to (https://en.wikipedia.org/wiki/Flood_the_zone) flood the\nzone and destroy trust in\ninstitutions and the concept of truth.  There\u2019s a good reason that (https://newsocialist.org.uk/transmissions/ai-the-new-aesthetics-of-fascism/) the\nfascists love\nit . Straightforward Spam and Fraud This is kind of obvious, but LLMs can generate lightly-customized,\nplausible-looking text much more quickly than any human being. (https://withpersona.com/blog/llm-fraud) This\nfacilitates their use in fraud, spam, and\nscams. In a spamming or fraudulent\ninteraction, once again, the costs are externalized onto the victim: the\nrecipient of a spam message has to do all the work of \u201cchecking\u201d the LLM\u2019s\noutput.  Spammers already expect very low hit rates from boilerplate, and if the\nLLM can increase those percentages from 1% to 5% the technology will pay for\nitself; they don\u2019t need anything like reliable accuracy. Customer \u201cSupport\u201d If you have any kind of commercial relationship with a company, I probably\ndon\u2019t even need to mention this: customer \u201csupport\u201d bots are a misery. (https://www.forbes.com/sites/terdawn-deboe/2026/04/20/customers-hate-your-ai-chatbot-small-businesses-should-listen/) Everybody knows\nit at this point.  But customer support is usually conceptualized by businesses as\nan adversarial interaction, because it is a cost center.  They maintain\ninternal metrics on time-to-resolution and try to optimize them.  Implicitly,\nthis creates a dynamic where the goal of the customer service agent\u2019s job is\nnot to solve your problem, but to emit noise that will cause you to think your problem is resolved, or to give up, as fast as possible.  Unsurprisingly,\nLLMs can emit this noise faster than humans can, getting those customers off\nthe phone.  But those customers will remember those interactions, and the\nstory outside the TTR metrics is horrible. Similarly to the situation in software development, LLMs can look very good on\npaper for customer support, but mostly what they are doing is illuminating the\nproblems with the industry\u2019s existing metrics, by turning \u201cwinning the metrics\nbattle against the customer\u201d into a more obvious and immediate defeat for the\ncompany\u2019s long term reputation. \u201cEducation\u201d In 2026 it is sadly a fact of life that (https://www.nytimes.com/2026/06/18/us/ai-apps-students-cheat.html) students cheat all the time using\n\u201cAI\u201d , and\nthat this cheating is very successful, in that the teachers find it very hard\nto detect. LLMs are great for cheating on schoolwork because the student is externalizing\nthe work of the checking onto the teachers, who are often starting at a\ndisadvantage to begin with, at least in the US. My view is that this is happening because of a divergence in the way that\nstudents vs. teachers (or, more accurately, \u201cthe broader educational system\u201d)\nview grading. When a student is asked to write an essay, the teachers see the effort as both\nintrinsically worthwhile for the student, as well as useful as a pedagogical\ntool to evaluate and react to the student\u2019s progress.  The student, by\ncontrast, sees a stumbling block designed to knock them off the path to success\nand into a permanent underclass.  It is no wonder that the student sees \u201cAI\u201d as\nuseful to their own goals and has no compunction about deploying it. There is a bitter irony that the ability to understand the inherent value of\nactually writing the essay on their own is the sort of thing that students can\nreally only learn by writing a bunch of essays.  There\u2019s no way that I can\nthink of which makes the benefit legible as long as a shortcut is available. The net effect here is a downward spiral, where the already-wobbling\neducational system is sustaining an attack that it doesn\u2019t have the resources\nto recover from.  The individual students\u2019 attacks against their teachers and\ntheir schools\u2019 grading systems might appear to momentarily succeed, but they\nwill win the battle and lose the war. Spamming \u201cFor Good\u201d? Usually when we talk about someone unilaterally choosing to enter into an\nadversarial relationship, that\u2019s an \u201cattack\u201d and for good reasons we have a\nnegative impression of the attacker.  However, I would be remiss if I did not\npoint out that there are some cases where the relationship was already\nadversarial; just because you\u2019re the attacker doesn\u2019t mean that you are evil. For example we might imagine use-cases like automatically filing appeals for\nprior authorizations against health insurance. It\u2019s relatively (https://en.wikipedia.org/wiki/Delay,_Deny,_Defend) well-known at this point\nthat the main way for-profit insurers maintain their margins is by denying\nclaims right up to the line of the policies themselves being fraud, so using a\nspamming tool to fight them might be entirely justifiable2  in that case. Similarly, using an LLM could be justified in a fight against a company\nrefusing to honor a warranty.  One could imagine using an LLM to immediately\ngenerate replies and escalations. However, even in imagined cases like these, the underlying problem is that the\ninsurers and the vendors already have a tremendous amount of structural power,\nso it is more likely that they will have the advantage in deploying a\ncommunications weapon like an LLM, as well as enacting policies to simply\nignore any LLM-based communication that you might submit.  Worse, if these\nstrategies were to become widespread, they might provide an excuse to reject any communications by feeding them into an unreliable \u201c(https://www.npr.org/2025/12/16/nx-s1-5492397/ai-schools-teachers-students) LLM\ndetector \u201d\nand issuing an automated \u201ccomputer says no\u201d even to hand-written\ncorrespondence. It is also worth stressing that these cases are imagined, as compared to the\nvery real coworker-abuse, spam, scam, fraud, and disinformation campaigns being\nwaged in real life today. Therefore, while legitimate uses might exist, it\u2019s hard to imagine that there\u2019s\nanywhere they would be genuinely valuable and sustainable.  In the best case\n\u201cAI\u201d will provide a temporary advantage for underdogs that will provoke an arms\nrace which the resource-advantaged adversaries will win in the long run, in the\nworst case the arms race itself will cement permanent structural change that\nwill make things worse. \u201cSearch\u201d By Stealing Most of the adversarial utility of \u201cAI\u201d is on the \u201cwrite\u201d side, since\nwrite-amplification is more obviously aggressive than reading.  But the \u201cread\u201d\nside of LLMs \u2014 summarization and question-answering \u2014 can be a form of attack\nas well. To begin with, (https://www.theregister.com/software/2025/08/29/ai-crawlers-destroying-websites-in-hunger-for-content/464120) the act of reading\nitself is currently enormously destructive, but that\u2019s arguably not a fundamental aspect of this technology.  They could set reasonable rate-limits and respect\nthings like robots.txt , as search engines have for decades now.  They could\nalso refrain from committing (https://www.npr.org/2025/09/05/nx-s1-5529404/anthropic-settlement-authors-copyright-ai) criminal\nlevels (https://www.theguardian.com/technology/2025/jan/10/mark-zuckerberg-meta-books-ai-models-sarah-silverman) of copyright\ninfringement .\nBut, today, using \u201cAI\u201d tools does suborn this sort of out-of-control crawling. More insidiously, consider the scenario described in (https://www.youtube.com/watch?v=8KQFgWdiudo) this YouTube\nvideo .  The LTT Bros decided to\ntry Linux again, and in the course of so doing, they had problems.  When trying\nto solve these problems, they were faced with a choice: they could consult\nReddit, or they could ask an LLM.  Asking an LLM would \u201cgaslight the heck out\nof\u201d them, but they still found it preferable, because they would at least get\nan answer without getting yelled at. Initially this sounds great.  But it also means that you want to extract\nknowledge from a community, while mechanically eliding any values or norms that\nthe community may want to impart as part of offering that knowledge.  As\nsomeone who spent many years in a community tech support role, this is\nworrying.  Many requests for support are people asking how to do things that\nwill momentarily solve a superficial problem but create a long-term reliability\nproblem or even an immediate security risk, that the question-asker doesn\u2019t\nwant to hear about.  Consider the question \u201cI\u2019m tired of entering my password\nso much, how do I make it so my laptop unlocks automatically\u201d.  An obsequious\nchatbot will helpfully tell you how to do this without pushback. But, this is also a sort of ethically murky area.  The Linux community is\nsomewhat famously, for (https://news.ycombinator.com/item?id=10332286) many years\nnow , a toxic cesspool of\ngeneral hostility, misogyny, etc.  It is certainly a good thing that people can\nget access to this knowledge without subjecting themselves to abuse.  But it\nalso means that the people with the power and the privilege to change the\ncommunity for the better can just quietly withdraw, rather than fixing the\nproblems.  It also means that the positive elements of culture cannot be\ntransmitted, and people will have no opportunity to learn about unknown\nunknowns. In this case, the \u201cadversarial\u201d communication is with society.  The thing that\nusing an LLM for search lets you do is withdraw from society and avoid forming\nany personal connections.  There are some personal connections which are\npainful and annoying, and so that can feel like a momentary balm.  But the need\nto make connections in general is, like, the concept of society itself. Who Am I Hurting? LLMs are good at adversarial communication.  They are so good at it, relative\nto their other benefits, that they will tend to make communications\nadversarial if you are not remaining vigilant about the possibility that it\nmight do so.  My request to you, dear reader, if you are going to use such\ntools, is to always ask yourself, \u201cwho might I be hurting, if I use an LLM for\nthis?\u201d If you\u2019re using an \u201cAI\u201d, who is its adversary?  If you haven\u2019t given it one\nyet, who might the \u201cAI\u201d turn into an adversary?  Who might you overwhelm with\nan asymmetric amount of output, or, if you\u2019re receiving information and not\nsending it, who are you taking that information from without consulting? Figure out the answers to these questions and conduct yourself accordingly; the\nanswer might be \u201cyourself\u201d. Acknowledgments Thank you to (/pages/patrons.html) my patrons who are supporting my writing on\nthis blog.  If you like what you\u2019ve read here and you\u2019d\nlike to read more of it, or you\u2019d like to support my (https://github.com/glyph/) various open-source\nendeavors , you can (/pages/patrons.html) support my work as a\nsponsor ! One of the reasons that software developers tend to prefer (https://en.wikipedia.org/wiki/Greenfield_project) greenfield development\nis that when you are given a blank page, you can project your own specific understanding onto it.  You can structure the codebase in a way\nthat works for your brain, down to the variable naming conventions and the\nmodule layouts.  LLM-assisted development makes everything into instant\nbrownfield work, which makes developers instantly miserable; even those who\nare excited about the technology will frequently complain about how it\nfeels like their agency has been stolen and their joy in the work has been\ndiminished.  But I digress. (Jump back to footnote 1 in the text) \u21a9   Modulo the massive amount of other externalities involved in using\nLLMs, of course, but I don\u2019t have the time or energy to get into those\nhere. (Jump back to footnote 2 in the text) \u21a9         \u00a9 Glyph 2025; All Rights Reserved Excepting Those Which Are Not.  See (https://blog.glyph.im/pages/disclosures.html) my disclosure statements for information on my interests, financial and otherwise.   (https://mastodon.social/@glyph) Mastodon   "
                ],
                "output": "htmltotext.txt",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:39.409708+00:00",
                "status": "succeeded"
            }
        ],
        "media": [
            {
                "cmd": [
                    "/usr/local/bin/yt-dlp",
                    "--restrict-filenames",
                    "--trim-filenames",
                    "128",
                    "--write-description",
                    "--write-info-json",
                    "--write-annotations",
                    "--write-thumbnail",
                    "--no-call-home",
                    "--write-sub",
                    "--write-auto-subs",
                    "--convert-subs=srt",
                    "--yes-playlist",
                    "--continue",
                    "--no-abort-on-error",
                    "--ignore-errors",
                    "--geo-bypass",
                    "--add-metadata",
                    "--format=(bv*+ba/b)[filesize<=750m][filesize_approx<=?750m]/(bv*+ba/b)",
                    "--skip-download",
                    "--cache-dir=/data/yt-dlp-cache/",
                    "--cookies=/data/yt-dlp-cache/cookies.txt",
                    "--proxy=socks5://tor-socks-proxy:9150",
                    "--no-playlist",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "2024.10.7",
                "end_ts": "2026-06-29T04:11:47.247504+00:00",
                "index_texts": [],
                "output": "media/",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:41.347903+00:00",
                "status": "succeeded"
            }
        ],
        "mercury": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/postlight-parser",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "2.2.3",
                "end_ts": "2026-06-29T04:11:39.370541+00:00",
                "index_texts": null,
                "output": "mercury/",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:36.628316+00:00",
                "status": "succeeded"
            }
        ],
        "pdf": [],
        "readability": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/readability-extractor",
                    "/tmp/tmpvbbtbc3d",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "0.0.11",
                "end_ts": "2026-06-29T04:11:26.254843+00:00",
                "index_texts": [
                    "As I have discussed in previous posts,\n\u201cAIs\u201d can make mistakes.  In fact, they do make mistakes, and their\nmistake-making patterns are such that where and how they will make mistakes is\nboth uncertain and constantly changing.\nThus, in any scenario where you want to attempt to make \u201cproductive\u201d use of\n\u201cAI\u201d, you must have a system in place for checking every result.  Not checking\nsome results; checking every result.  If each result might have a\nconsequence for you (and if it didn\u2019t have a consequence, why bother automating\nit?) and you cannot predict in advance which kinds of results will need\nverification, then verification is always required.\nThe verification often ends up being just as expensive as doing the work in the\nfirst place, which means that if you want your usage of \u201cAI\u201d to be personally\nprofitable, you have to find someone else to externalize the cost of\nverification onto.  This person becomes your adversary, and, if you are\nsuccessful, your \u201cAI\u2019s\u201d victim.\nThe Ladder-Climber And Their Reverse-Centaur Rungs\nOne way that this constellation of facts can straightforwardly assemble\nthemselves into a dystopian nightmare is the phenomenon, described by Cory\nDoctorow, of the reverse\ncentaur.\nThis is when your employer non-consensually turns you into the verification\nsystem.  The \u201cAI\u201d does the fun part of initially performing the work, and then\nyou do the boring part where you check if the robot is right and clean up its\nmesses, even if everyone already knows that it would, in aggregate, be cheaper\nfor you to do the work in the first\nplace.\nReverse centaurs can be made from any automation, not only \u201cAI\u201d automation.\nI think that there is a reason that this term happens to have emerged in the\n\u201cage of AI\u201d, though, and not with earlier automation technologies (even those\nwhich were\nconsiderably\nmore viscerally\nhorrific).  That reason\nis: the wrongness of \u201cAI\u201d output is not merely a technical feature that must\nbe compensated for, it is a generalized externality.\nAs I mentioned above, if you are responsible for the entirety of the work, both\nextruding the \u201cAI\u201d output and checking it, it\u2019s usually cheaper to have\nhumans do the entirety of the work to begin with.  When humans do the writing\ndirectly, we can check as we go, and thus verification doesn\u2019t need to be as\ncomprehensive.\nWhen \u201cAI\u201d coding advocates say \u201ccode review is the\nbottleneck\u201d, what\nthey are observing is that the LLM is still rolling the dice for each PR, and a\nhuman is still necessary to verify that each of those rolls is a winner.  But\ncalling this process \u201ccode review\u201d is a bit of a\nmisnomer; it\u2019s not really \u201ccode\nreview\u201d in the traditional sense, it\u2019s human understanding.\nBefore the advent of \u201cAI\u201d, the human understanding was implicit in the process\nof writing the code in the first place1, and the code review was a way of\ndiffusing and extending that understanding.  Now that the code can be authored\nwith no initial understanding taking place, that cost has not gone away, it has\nmoved.\nHuman understanding was always the bottleneck.\nHowever, this is taking a collaborative view of a software project, where\nsatisfying the needs and solving the problems of your customers are the goals.\nWe can see that \u201cAI\u201d is a bad tool to satisfy those goals, because all it\u2019s\ndoing is converting the first half of the work, that of understanding the code\nas you write it, to understanding the agent\u2019s output as you read it.\nWhat if, instead, we were to take the view that every software company is a\nHobbesian nightmare, red in tooth and claw? In this view, the only goal of a\nsoftware project is for the individual developers to make their promo cycles\nand get their bonuses.  Given that there is only a certain amount of money to\ngo around, this is a zero-sum game where each programmer wants to look more\nproductive than their colleagues.\nPretty much every organization finds it easy to reward \u201cproductivity\u201d as\nexpressed by lines of code emitted, but the benefits of doing\nthorough and thoughtful design, analysis, and code review very difficult to\nreward.  In this world, an LLM is an invaluable tool for the sociopathic\nladder-climber, particularly if your legacy organization is still structuring\ntheir workflows as if the person prompting the bot is \u201cwriting\u201d the code, and\nthen they get to foist off the act of \u201creviewing\u201d the code onto someone else.\nHere, the prompter effectively externalizes the cost of the LLM\u2019s failures but\ninternalizes any benefits.  The prompter will vibe-code a big feature, so large\nthat the assigned reviewer can\u2019t possibly comprehend it all effectively. When\nthis happens, the reviewer will, eventually, be pressured to approve it, even\nif they can try to spot a few problems along the way.  The reviewer has their\nown work to get back to, after all, the obligation to review the prompter\u2019s\n(read: the bot\u2019s) code is a drain on their time that they are not going to get\nrewarded for.\nIf this feature is a big success, the prompter gets a promotion.  If it causes\na big issue, well, the reviewer must not have been careful enough.\nThis is why LLMs are \u201cgood for coding\u201d, and also why their biggest promoters\nkeep\nhaving\noutages.\nThe Generative Gish Galloper\nCoding is the biggest \u201csuccess story\u201d of this type of adversarial\ncommunication, but it is by far not the only instance of such a thing.  LLMs\ncreate a new form of leverage that can turn Brandolini\u2019s\nlaw from a linear advantage\ninto an exponential one.  If you are engaged in a political debate where you\nwant to overwhelm the other side in nonsense, an LLM can generate bullshit\nfaster than it is physically possible for a human being to type, let alone\nrespond thoughtfully.  There is an asymmetry to the utility of this weapon as\nwell: only one side of the political spectrum wants to flood the\nzone and destroy trust in\ninstitutions and the concept of truth.  There\u2019s a good reason that the\nfascists love\nit.\nStraightforward Spam and Fraud\nThis is kind of obvious, but LLMs can generate lightly-customized,\nplausible-looking text much more quickly than any human being.  This\nfacilitates their use in fraud, spam, and\nscams. In a spamming or fraudulent\ninteraction, once again, the costs are externalized onto the victim: the\nrecipient of a spam message has to do all the work of \u201cchecking\u201d the LLM\u2019s\noutput.  Spammers already expect very low hit rates from boilerplate, and if the\nLLM can increase those percentages from 1% to 5% the technology will pay for\nitself; they don\u2019t need anything like reliable accuracy.\nCustomer \u201cSupport\u201d\nIf you have any kind of commercial relationship with a company, I probably\ndon\u2019t even need to mention this: customer \u201csupport\u201d bots are a misery.\nEverybody knows\nit\nat this point.  But customer support is usually conceptualized by businesses as\nan adversarial interaction, because it is a cost center.  They maintain\ninternal metrics on time-to-resolution and try to optimize them.  Implicitly,\nthis creates a dynamic where the goal of the customer service agent\u2019s job is\nnot to solve your problem, but to emit noise that will cause you to think\nyour problem is resolved, or to give up, as fast as possible.  Unsurprisingly,\nLLMs can emit this noise faster than humans can, getting those customers off\nthe phone.  But those customers will remember those interactions, and the\nstory outside the TTR metrics is horrible.\nSimilarly to the situation in software development, LLMs can look very good on\npaper for customer support, but mostly what they are doing is illuminating the\nproblems with the industry\u2019s existing metrics, by turning \u201cwinning the metrics\nbattle against the customer\u201d into a more obvious and immediate defeat for the\ncompany\u2019s long term reputation.\n\u201cEducation\u201d\nIn 2026 it is sadly a fact of life that students cheat all the time using\n\u201cAI\u201d, and\nthat this cheating is very successful, in that the teachers find it very hard\nto detect.\nLLMs are great for cheating on schoolwork because the student is externalizing\nthe work of the checking onto the teachers, who are often starting at a\ndisadvantage to begin with, at least in the US.\nMy view is that this is happening because of a divergence in the way that\nstudents vs. teachers (or, more accurately, \u201cthe broader educational system\u201d)\nview grading.\nWhen a student is asked to write an essay, the teachers see the effort as both\nintrinsically worthwhile for the student, as well as useful as a pedagogical\ntool to evaluate and react to the student\u2019s progress.  The student, by\ncontrast, sees a stumbling block designed to knock them off the path to success\nand into a permanent underclass.  It is no wonder that the student sees \u201cAI\u201d as\nuseful to their own goals and has no compunction about deploying it.\nThere is a bitter irony that the ability to understand the inherent value of\nactually writing the essay on their own is the sort of thing that students can\nreally only learn by writing a bunch of essays.  There\u2019s no way that I can\nthink of which makes the benefit legible as long as a shortcut is available.\nThe net effect here is a downward spiral, where the already-wobbling\neducational system is sustaining an attack that it doesn\u2019t have the resources\nto recover from.  The individual students\u2019 attacks against their teachers and\ntheir schools\u2019 grading systems might appear to momentarily succeed, but they\nwill win the battle and lose the war.\nSpamming \u201cFor Good\u201d?\nUsually when we talk about someone unilaterally choosing to enter into an\nadversarial relationship, that\u2019s an \u201cattack\u201d and for good reasons we have a\nnegative impression of the attacker.  However, I would be remiss if I did not\npoint out that there are some cases where the relationship was already\nadversarial; just because you\u2019re the attacker doesn\u2019t mean that you are evil.\nFor example we might imagine use-cases like automatically filing appeals for\nprior authorizations against health insurance. It\u2019s relatively\nwell-known at this point\nthat the main way for-profit insurers maintain their margins is by denying\nclaims right up to the line of the policies themselves being fraud, so using a\nspamming tool to fight them might be entirely justifiable2 in that case.\nSimilarly, using an LLM could be justified in a fight against a company\nrefusing to honor a warranty.  One could imagine using an LLM to immediately\ngenerate replies and escalations.\nHowever, even in imagined cases like these, the underlying problem is that the\ninsurers and the vendors already have a tremendous amount of structural power,\nso it is more likely that they will have the advantage in deploying a\ncommunications weapon like an LLM, as well as enacting policies to simply\nignore any LLM-based communication that you might submit.  Worse, if these\nstrategies were to become widespread, they might provide an excuse to reject\nany communications by feeding them into an unreliable \u201cLLM\ndetector\u201d\nand issuing an automated \u201ccomputer says no\u201d even to hand-written\ncorrespondence.\nIt is also worth stressing that these cases are imagined, as compared to the\nvery real coworker-abuse, spam, scam, fraud, and disinformation campaigns being\nwaged in real life today.\nTherefore, while legitimate uses might exist, it\u2019s hard to imagine that there\u2019s\nanywhere they would be genuinely valuable and sustainable.  In the best case\n\u201cAI\u201d will provide a temporary advantage for underdogs that will provoke an arms\nrace which the resource-advantaged adversaries will win in the long run, in the\nworst case the arms race itself will cement permanent structural change that\nwill make things worse.\n\u201cSearch\u201d By Stealing\nMost of the adversarial utility of \u201cAI\u201d is on the \u201cwrite\u201d side, since\nwrite-amplification is more obviously aggressive than reading.  But the \u201cread\u201d\nside of LLMs \u2014 summarization and question-answering \u2014 can be a form of attack\nas well.\nTo begin with, the act of reading\nitself\nis currently enormously destructive, but that\u2019s arguably not a fundamental\naspect of this technology.  They could set reasonable rate-limits and respect\nthings like robots.txt, as search engines have for decades now.  They could\nalso refrain from committing criminal\nlevels\nof copyright\ninfringement.\nBut, today, using \u201cAI\u201d tools does suborn this sort of out-of-control crawling.\nMore insidiously, consider the scenario described in this YouTube\nvideo.  The LTT Bros decided to\ntry Linux again, and in the course of so doing, they had problems.  When trying\nto solve these problems, they were faced with a choice: they could consult\nReddit, or they could ask an LLM.  Asking an LLM would \u201cgaslight the heck out\nof\u201d them, but they still found it preferable, because they would at least get\nan answer without getting yelled at.\nInitially this sounds great.  But it also means that you want to extract\nknowledge from a community, while mechanically eliding any values or norms that\nthe community may want to impart as part of offering that knowledge.  As\nsomeone who spent many years in a community tech support role, this is\nworrying.  Many requests for support are people asking how to do things that\nwill momentarily solve a superficial problem but create a long-term reliability\nproblem or even an immediate security risk, that the question-asker doesn\u2019t\nwant to hear about.  Consider the question \u201cI\u2019m tired of entering my password\nso much, how do I make it so my laptop unlocks automatically\u201d.  An obsequious\nchatbot will helpfully tell you how to do this without pushback.\nBut, this is also a sort of ethically murky area.  The Linux community is\nsomewhat famously, for many years\nnow, a toxic cesspool of\ngeneral hostility, misogyny, etc.  It is certainly a good thing that people can\nget access to this knowledge without subjecting themselves to abuse.  But it\nalso means that the people with the power and the privilege to change the\ncommunity for the better can just quietly withdraw, rather than fixing the\nproblems.  It also means that the positive elements of culture cannot be\ntransmitted, and people will have no opportunity to learn about unknown\nunknowns.\nIn this case, the \u201cadversarial\u201d communication is with society.  The thing that\nusing an LLM for search lets you do is withdraw from society and avoid forming\nany personal connections.  There are some personal connections which are\npainful and annoying, and so that can feel like a momentary balm.  But the need\nto make connections in general is, like, the concept of society itself.\nWho Am I Hurting?\nLLMs are good at adversarial communication.  They are so good at it, relative\nto their other benefits, that they will tend to make communications\nadversarial if you are not remaining vigilant about the possibility that it\nmight do so.  My request to you, dear reader, if you are going to use such\ntools, is to always ask yourself, \u201cwho might I be hurting, if I use an LLM for\nthis?\u201d\nIf you\u2019re using an \u201cAI\u201d, who is its adversary?  If you haven\u2019t given it one\nyet, who might the \u201cAI\u201d turn into an adversary?  Who might you overwhelm with\nan asymmetric amount of output, or, if you\u2019re receiving information and not\nsending it, who are you taking that information from without consulting?\nFigure out the answers to these questions and conduct yourself accordingly; the\nanswer might be \u201cyourself\u201d.\nAcknowledgments\nThank you to my patrons who are supporting my writing on\nthis blog.  If you like what you\u2019ve read here and you\u2019d\nlike to read more of it, or you\u2019d like to support my various open-source\nendeavors, you can support my work as a\nsponsor!"
                ],
                "output": "readability/",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:21.724677+00:00",
                "status": "succeeded"
            }
        ],
        "screenshot": [],
        "singlefile": [],
        "title": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://blog.glyph.im/2026/06/adversarial-communication.html"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-06-29T04:11:20.813474+00:00",
                "index_texts": null,
                "output": "Deciphering Glyph ::\n        Adversarial Communication",
                "pwd": "/data/archive/1782706242.602333",
                "schema": "ArchiveResult",
                "start_ts": "2026-06-29T04:11:20.771431+00:00",
                "status": "succeeded"
            }
        ],
        "wget": []
    },
    "icons": null,
    "is_archived": true,
    "is_static": false,
    "latest": {
        "archive_org": "https://web.archive.org/web/20260629041158/https://blog.glyph.im/2026/06/adversarial-communication.html",
        "dom": "output.html",
        "favicon": "favicon.ico",
        "git": null,
        "media": "media/",
        "pdf": null,
        "screenshot": null,
        "singlefile": null,
        "title": "Deciphering Glyph ::\n        Adversarial Communication",
        "warc": null,
        "wget": null
    },
    "link_dir": "/data/archive/1782706242.602333",
    "newest_archive_date": "2026-06-29T04:11:47.315957+00:00",
    "num_failures": 0,
    "num_outputs": 9,
    "oldest_archive_date": "2026-06-29T04:10:48.896081+00:00",
    "path": "/2026/06/adversarial-communication.html",
    "schema": "Link",
    "scheme": "https",
    "snapshot_abid": "snp_01KW8S51353F4C84AB01HHBT6G",
    "snapshot_id": "122bab0f-ac47-467f-a185-8d326315e8d0",
    "sources": [
        "/data/sources/1782706241-import.txt"
    ],
    "tags": null,
    "tags_str": "",
    "timestamp": "1782706242.602333",
    "title": "Deciphering Glyph ::\n        Adversarial Communication",
    "url": "https://blog.glyph.im/2026/06/adversarial-communication.html"
}