An Identity is What You Do

I think of Identities as Forever Goals that I might never fully achieve or could always “be more of”. So, while I am definitely a “Programmer” and am proud of that ability and my accomplishments, I can see that there is a lot I could still learn and achieve. My other aspirational identities like “Writer” or “Spanish speaker” might never be realized. I’m ok with that as long as keeping trying.

To me, my identity is what I do, not what I am. If I keep writing, even on this blog, even if no one reads it, then I am doing what a writer does. That’s enough.

I have to keep reminding myself because I am struggling with Spanish, and it’s mostly because I don’t do the work. It won’t matter how much I want it or think about it or hope I get better. The truth is that I haven’t fully embraced the work I need to do. Yet.

The Inner Game of Spanish

In my post reviewing The Inner Game of Tennis, I wrote that I thought the book applied to any physical activity. I also think it could apply to language acquisition, because we speak and listen with our automatic mind. You don’t want a judging mind to be evaluating how well you are pronouncing words and understanding. But if it’s not judging, then what?

The trick described in The Inner Game is to give your judging mind something to do. In tennis, Gallwey recommends having your thinking, judging self track the ball’s spin or think “bounce”, “hit” when appropriate. You could have it just track the position of your arm right before you hit. The key is that it is something objective.

I want to use this technique to get better at Spanish comprehension. One way I do that is to watch Dreaming Spanish videos to get comprehensible input (native language without translation, just above my level). It’s hard. I can feel my mind wander as it judges that I am not doing well enough.

Here are some things I am going to try out to give my thinking mind something to do:

  • Observe the mouth of the speaker: I am hoping I’ll see some connections to the sounds they are making. This is easier with a video than in real life, of course.
  • Sketchnote the content of the video: I am specifically trying to avoid translation. I want the Spanish words to evoke pictures in my mind.
  • Transcribe: Not every word, but phrases here and there. I will probably combine this with sketchnoting.

The goal is to get my mind to stop doing meta-thinking about how well I am understanding, and if that’s good enough. I want it to provide neutral, objective information to my automatic brain. I’ll share more after I’ve been trying it a while.

Review: The Inner Game of Tennis

I just finished The Inner Game of Tennis [ad] by Timothy Gallwey, which has been on my reading list for over a decade. I happened to see a copy featured in a bookstore and bought it as a plane read. It’s short and sweet at under 200 pages, which I love.

I should say to start that it’s not about tennis. Well, it is, but everything in this book is applicable to every sport and possibly every physical activity. I’m not sure if it applies to mental activities yet, but it might. I definitely think it applies to language learning. The thesis is that your inner self judges you while you try to do something and causes you to do it poorly. The “Inner Game” is a set of techniques to quiet this voice (he calls it Self 1) so that the body (Self 2) can play and get into a flow state.

I think it works for language learning because you should just be engaged in the conversation or content, not judging your accent or fretting over whether you got every word. It’s possibly a more physical than mental activity. Gallwey’s methods, which are based on observing experts and yourself is similar to the comprehensible input method of language acquisition (which is how we all learned our native language, so we know it works).

This book reminded me of Thinking, Fast and Slow [ad] by Daniel Kahneman, which also separates the self into System 1 and System 2 thinking, but with the line drawn in a slightly different place. To start with, he reverses the numbers, making System 1 the automatic system and System 2 the more conscious, logical, methodical system. Even so, they are not exactly the same, but close enough.

Gallwey’s book is about the things that the automatic system does well (sports) because it’s fast. Kahneman’s book is more about suppressing the automatic, heuristic-using System 1 when you should be doing the work to understand and analyze using System 2. His worry is that the fast system will give you a plausible (but incorrect) answer, and then you won’t do the work to find the right one. Gallwey thinks your judging self will slow down the automatic response you need at the speed of sports. Or, in my case, language acquisition.

I am sure that this book is the most important one I read this year (maybe in multiple years). I suspect that it will have the same kind of lasting impact on my thoughts and behavior as 4DX [ad] and Thinking in Systems [ad] have.

A Game’s Fun Comes from Its Rules

Baseball’s infield fly rule seems strange at first. It says that when there are runners on first and second with less than two out, and the ball is popped up to the infield, then it’s an automatic out, even if the fielder drops it. Without the infield fly rule, the fielder might let the ball drop on purpose. Then they could turn an easy double-play at second and third base. A pop-up would turn into two outs in a way that isn’t fun for the players or fans because it takes no skill. The rule is there to make the game more fun.

Professional sports are filled with rules like this. Basketball has goal tending, soccer and hockey have offsides, and in football, you can’t catch a pass if you run out of bounds. Rules like this often come after their absence was exploited. For example, goaltending was introduced in 1944 to stop a 6’ 10” center from making the game less fun for everyone (else).

So, when designing an infinite game, you might need seemingly arbitrary rules. Probably it’s better to notice when the game is too easy and figure out a way to make it harder. Based on the examples above, you should also look for times when you play the game in an odd way that gets you rewards with no skill or work. It might seem fun at first, but easy games get boring, and then you’ll quit.

Forever Goals Aren’t SMART

In the last post, I wrote about Forever Goals, which are outcomes I will always want. It’s something I can approach or maintain, not achieve. They are not SMART goals (i.e. Specific, Measurable, Achievable, Relevant, and Time-Bound). For example, a SMART goal is phrased like this: “losing 5 pounds by the end of the year by doing 4 hours of cardio per week and tracking calories.” A Forever Goal is more like “be fit.” A Forever Goal could have a logo. It should make a good tattoo.

I think a SMART goal is more likely to succeed, especially in the short-term. But I fail a lot of personal SMART goals. For some of my aspirations, it hasn’t caused me to give up. I think it’s because I know I don’t really care about the SMART version of the goal. I care about the Forever version. If done right, a Forever Goal can succeed … forever.

Let’s compare the two.

In a SMART goal, the Relevancy is how much you want the goal. Relevancy is baked into the idea of a Forever Goals, so no difference there. Forever goals are also Measurable in the sense that there are measures that I want to increase or maintain, like my Personal Record (PR) lift or mile time. The difference is that the goal is the direction, not necessarily a number. A number can be achieved, but a direction is forever.

The similarities end there because Forever Goals aren’t Time-bound or Achievable and not particularly Specific. If you stop there, this is a good enough reason for them to fail. You could certainly support a Forever Goal with milestones that are SMART, which I have done. But now I prefer designing an infinite game instead.

The issue with SMART milestones is that failing them is de-motivating. If I do the cardio and track my calories, but don’t lose 5 pounds, I might be discouraged. This is true even if you become more fit. Personally, I fail almost all of my fitness milestones. But, I do still work out regularly. I do generally eat healthy. The measures of my fitness are mostly trending positive. I think the reason is that I have found a way to make doing the right things fun. Working out, cooking, and even grocery shopping are games to me.

I have also found programming to be incredibly fun and do it for enjoyment. I never made any kind of SMART milestone to get better at programming, but have no problem doing the work that makes me better at it.

SMART-like goals were imposed on me by employers, so I guess they were in the mix. If the only reason to program was to meet the goals of my employers, I think I would have given up a while ago (or not have been as successful or happy).

This is on my mind as I struggle to figure out a way to make learning Spanish more fun. I do the work (mostly), but it’s subject to wild swings in motivation. I have been relying on habits and discipline to make progress, which I’ll discuss next.

Forever Goals

I like infinite games. These are things you do over and over because they are fun and you want to get better at them. You want to get better so that you can make the game more fun and want to play it more. The game is the point. But I often do have a secondary reason to play them: to make progress on a forever goal.

My podcast, Write While True, is one example. Its name is even a nod to infinite games because it’s an infinite loop. The goal is not to get listeners or make money. The podcast’s forever goal is to make me into a better speaker. Now that I have a co-host, it’s also to make me a better listener and conversation partner.

This blog is another example. I mostly write just to write. But it has the secondary effect of making it more likely that I could express these opinions more eloquently later. The forever goal is something like: to organize my thoughts. This blog has also led to serendipitous opportunities, and I would always want that.

I would also say that cooking is an infinite game for me. I enjoy the activity of cooking, and I do want to do it more to get better at it. But, of course, I have a forever goal of eating regularly and being healthy, which this game supports. Similarly, I go to Crossfit, which has lots of infinite games embedded in it and supports my forever goal of becoming fit.

I also have forever goals that I haven’t figured out a supporting infinite game. One that I struggle with right now is being fluent in Spanish. I started last year, and while I have gotten better, it’s a struggle. The studying I do is not a fun game.

To be clear, I am not looking for something like DuoLingo, which is gamified, but not a game. I use it, and it’s fine, but I wish I could turn off streaks, trophies, badges, leader boards, gems, and treasure chests. These features don’t make the app more fun. They are slapped on. This is also true of Fluent Forever, but not as much. Parts of that app are genuinely fun.

In the next post, I’m going to think out loud about this problem a little more.

My 2021 AI Coding Thoughts Revisited

In February 2021, I wrote Robotic Pair Programmers, which is my description of what I would want out of an AI coding assistant. I am pretty sure I was unaware of any “good” AI coding assistants, but a month later I took a look at Kite, which was an early attempt. I think there must have been something in the air. Copilot was released that June. ChatGPT would be released the next year.

It is now more than five years later, and we’re Approaching Infinity, where the doublings of computing are on a much larger base. We are past the bend in the exponential curve. But, still, there might be things that are constant (or at least aren’t immediately obsolete) in the three doublings we had since I wrote it.

The main thing I got wrong is that I thought the main way to use AI would be as a pair programmer, which was true for the first iteration. Now, it’s more as an independent co-worker that you manage. I still do a lot of pair programming with AI, but this won’t be true in the industry five years from now.

Here are sentences that I think still apply after five years.

Let’s say I index every Xcode project in GitHub, every iOS tutorial, every iOS question in Stack Overflow. Could that be distilled somehow and then shown to me at the right time?

Yup. And distilling is exactly the right word for this. This is how it works now, but that wasn’t clear to me then.

Whatever we do, we need to make sure that nearly every suggestion is useful.

I still think this is important. The ever increasing percentage of times that the agent is exactly correct has been the main thing driving usefulness in the last six months. It used to be true that you had to weigh whether it was better to correct wrong code versus writing it yourself. That ratio has tipped in AI’s favor.

Conserving flow should be the driver for how this works.

This is definitely true when you are coding with suggestions or doing smaller changes. It feels less important when doing a long agent run (or dark factory/loop engineering style systems). But, you see memes about how programmers are watching reels while agents do work, and it makes me sad. Part of the reason I make programs is to make me into someone that is better at making programs. This is true for the way I use AI, but I am not under pressure to be faster. Productivity is a goal, but not at the expense of my enjoyment.

26 for 26 Half Year Update

At the beginning of the year, I made a 26 for 26, which is a list of 26 mini-goals for 2026. Here they are with their status. I use ✅ for done, 👌 for easy, ⚠️ for hard but possible, 🛑 for probably will not get done.

  1. ⚠️ Bench my weight: getting closer but at a plateau — might need to lose 10 pounds :)
  2. ⚠️ Be able to do 10 pull-ups: I think I might get there. Losing 10 pounds would also help this
  3. 👌 Make a meal with soy curls: Not done
  4. 👌 Find a place locally where I can get Fermented Bean Curd and Nattō: Farmer’s market had Nattō. Still looking for bean curd
  5. Add A+ Content to the Amazon page for my book: Done
  6. Try Amazon ads: Done (wasn’t worth it)
  7. Go to an intermediate Spanish meetup: I use iTalki instead, but I’ll probably try this too.
  8. Cook one new thing from each vegan cookbook I have: Done
  9. Leave 10 books in the donation mini-libraries around town: Done
  10. 👌 Hang pictures of my family in my guest room: Not done, but my excuse is that I moved apartments. Should be easy though.
  11. 👌 Go to a live musical: Not done yet, but did go to a play about Earth Kitt. Should be easy.
  12. Go to a NY Liberty game: Done. Went to opening day in NY.
  13. ⚠️ Go to at least one arena-sized concert: Not done.
  14. ⚠️ Have a coffee or lunch with someone who lives in my building (see Improving My Social Connection Index): Not done, which is a little embarrassing
  15. Join a gym that has a social component: Done. Crossfit.
  16. ⚠️ Host someone new for dinner at my place: Not done yet, but maybe doing #14 will fix this.
  17. Try three new restaurants for dinner in Sarasota: Done
  18. Try two new restaurants for dinner in NYC: Done
  19. ⚠️ Go for a weekend away to a new place in Florida: Not Done
  20. Attend a local political gathering: Done.
  21. 👌 Release something new to open-source: Not done, but my raylib game could either be a candidate or spawn off something.
  22. ⚠️ Get App-o-Mat on current Django and back to being a live server (not static pages): Not done.
  23. 🛑 Publish 10 articles on third-party sites: Not done, and probably will not happen.
  24. 🛑 Appear on 5 podcasts: Not counting my own, I’ve been on two.
  25. Publish 10 episodes of my podcast: Write While True Podcast: Done, and more are coming
  26. 👌 Write 10 Amazon Book reviews for books I love: Done some, should knock this off soon

So 11/26 done, which is less than 13 at the halfway point. Not horrible.

Siri AI is a Malware Vector

I hope you are able to use the latest Apple OSs with Siri AI completely turned off. I believe that, as described, it will be a fertile ground for malware reminiscent of Windows 20 years ago.

I would love if anyone has information about the details of Siri AI that refute this.

1. Stopping prompt injections is impossible right now.

To back this up, read Anthropic’s system card for Opus 4.8. Page 77 shows the various top model’s probability of stopping prompt injections. Opus 4.8 is just under 10% with 100 attempts. Gemini (which Siri is based on) is 45% with 100 attempts.

This may be an inevitable and unsolvable problem. So …

2. We must assume that any Agent that has been exposed to text that we don’t trust is under the control of an adversary.

This is a design constraint right now. The rest of the system must be architected around this assumption.

I would never run an agent on my personal machine, because …

3. There is a lot of untrusted text on my personal devices.

Here is a partial list: All incoming emails and texts, all documents I didn’t write, all e-books, sites I browse. Siri AI can “look” at apps I am running. If you code on your machine, then all dependencies (every README, skill, etc).

This means that any file type with text is potential malware, not just executables or scripts.

But that’s not the only thing on your machine …

4. There are also a lot of “secrets” on your machine

The partial list above also includes your trusted text with your secrets. Things like: your passwords (if you let Siri AI reset them as shown in the keynote), your emails and texts, photos, financial information, personal documents, and bitcoin wallets.

So, you have a high potential to let an AI Agent that is under an adversary’s control see a secret. This is not ok, because …

5. The Agent is able to “do things”

For example: form a URL and make a network request with it, control applications, show an image from the internet (which is a special case of requesting a URL).

Siri AI will likely ask for approval, but …

6. Approval-based permission models don’t work

There is no way to make an informed decision about what is safe for an AI Agent to do. Even so, you won’t likely be asked to approve URL requests. Also, approval fatigue is real.

Apple didn’t show any permission prompts, but I assume that there will be some because they are not using …

7. The “better” (not perfect) solution is sandboxes, firewalls, OS-level auth

My opinion is the best way to run agents is in sandboxes with their own accounts (not as you or super-user) with OS-level authorization and firewalls in place. And then … just let the agent go.

The agent will be exposed to prompt injections, but there are no secrets in the VM and I limit its actions the same way I would limit a logged in user on a shared machine. This is just normal system level user access control.

I wrote about this more in Escaping the Lethal Trifecta of AI Agents and Limiting the Chance of Code Agent Prompt Injections

Write While True Episode 57: Writing Tools for Publishing

Brian: And today, once again, we’re talking about tools, but this time focus on tools for publishing and collaboration in writing, which is all a bit more complicated than what text editor do you use? 

So, to start at the simpler end of the spectrum, though, there’s blogging and then there’s publishing things like books and pamphlets and whatnot. So let’s talk first about blogging tools, publishing to the internet.

Transcript