Showing posts with label artificial intelligence. Show all posts
Showing posts with label artificial intelligence. Show all posts

Tuesday, August 11, 2026

AI Security Threats - Is It Time to Panic?

Introduction

It’s been over nine years since my last post about how to stay secure online. A lot has changed since then, particularly with Artificial Intelligence making everybody more effective at everything. (At least, this is what Corporate America is telling itself, and in the case of fraudsters, it’s actually true.) In this post I’ll briefly highlight some of the most pressing AI-driven threats, and then focus on what you can actually do to protect yourself, vs. what we’ll have to hope “they” can protect us from. Short version: be extra wary of phishing and spear-phishing attacks. (Oh, and no point in panicking … yet … as far as I know. I put “panic” in the title of this post just to grab your attention—and look, it worked!)


Major AI-driven security threats

Here are some of the top Internet security threats presented by AI:

  1. Autonomous attacks: Fraudsters are using agentic AI to unleash fully automatic phishing and other attacks, greatly speeding up their campaigns.
  2. AI systems as attack surface: As companies build AI into email, documents, and workflows, attackers are targeting the AI stack directly rather than going around it. (Some call this “AI supply chain compromise.”) Malicious instructions can be hidden inside the content that an AI reads as it goes about its job, and training data can be poisoned.
  3. Deepfake-driven identity collapse: AI can produce realistic voice, face, video, and document forgeries cheaply and at scale. This can undermine authentication systems across corporate, banking, and consumer platforms.
  4. Data leakage from ordinary use: As corporate employees use AI normally, and get very specific in providing context for their prompts, they often share more info than they mean to, giving bad actors access to sensitive data without even having to steal it.

(Why four threats, instead of a nice round number like three or five? I based my assessment on queries I made to ChatGPT, Gemini, Copilot, and Claude, and these are the four top threats that all these models agreed on.)

On top of these threats, and overlaying them, is Open Source Intelligence (OSINT), which in the context of Internet security refers to personally identifiable information (PII) that over time has become public due to voluntary posting of it, such as on social media (e.g., Facebook users sharing info about themselves, their activities, and their families, assuming it’s only seen by friends and online “friends” and not realizing how easily shareable it is across the entire Internet). All this data has been increasingly well indexed by Google and other Internet tools, and now web scrapers and other generative AI tools can easily harness this sensitive data to create targeted phishing (i.e., spear-phishing) attacks.

An example of an OSINT hack

This will all make more sense, I think, if I provide an example. It occurred to me recently that anyone with a Gmail account could create a Gemini Notebook into which they could feed large batches of albertnet posts, to turn this very blog into a chatbot. They then could query this chatbot for any and all PII that could be used to answer security questions when trying to impersonate me. To identify such vulnerabilities, I did this exact exercise myself (employing a tactic called Defensive OSINT—basically beating hackers to the punch). I fed the most likely categories of albertnet posts (e.g., Parenting, Bits & Bobs) into a Notebook and asked the chatbot to build a comprehensive “public knowledge index” of PII based on the categories most often used for website authentication security questions. Then I had it produce a report describing the vulnerabilities it found.

Did it come up with anything? Well, yes: it found one item of rather sensitive information based on a bit of handwritten text that was included on a picture that was posted. I found that pretty embarrassing, but it was easy enough to remove since this is my blog and I manage the content directly. (Also, because I own the domain used by my blog, I can go to web.archive.org and have the original version of the post removed forever.)  Fortunately, I’ve had an eye on privacy and security for the whole time I’ve been blogging, so other than some pet names and schools I attended, I’m overall in pretty good shape. Here’s a particularly amusing excerpt from the Gemini Notebook security audit report:

Category V: Workplace & Career

The author’s career trajectory is extensively documented, providing a roadmap for Business Email Compromise (BEC) and “Career Gate” attacks.

Security Risk Assessment: Attacker groups scrape metadata from Blogger sidebars (e.g., the “Specialist” title) to craft highly targeted BEC lures. By referencing past roles like “underwear canner” or “radio station receptionist,” an attacker can establishing [sic] a false commonality to bypass corporate security screenings or impersonate a former HR representative for the purpose of credential harvesting. 

As you can see, when you share personal information on the Internet, it’s highly advisable to bullshit a lot. I have a feeling that the above career information, even in the hands of the most devious hacker, isn’t going to get me in a lot of trouble. I do need to warn family members not to use any of the PII in my report (e.g., a pet’s name, a school name) as security answers, though I’ve already cautioned them—as I’ll now caution you—to not use real PII for security questions in any case; after all, you can’t change your mother’s maiden name or the city you were born in, so once somebody hacks a website and gains these answers, you’re pretty much hosed. And good luck remembering what security questions and answers you’ve set up over the years across all the sites that use them for authentication.

So can everyone run this kind of audit? Well, any blogger can, but if you’ve been active on multiple social media platforms over the last ten or fifteen years, it’s gonna be really tough. And remember, in many cases (e.g., Facebook) you do not actually own that information. Probably the best thing you can do is keep an eye out for spear-phishing attacks.

Some updated anti-phishing basics

In my previous post on phishing, I pointed out that you could often spot fraud based on bad spelling or grammar (e.g., “Security fraud alerted corporate card!” or “Account info updating needs!”). This is no longer a reliable rule of thumb, because AI has gotten so good at grammar and even at matching the style of the supposed sender. It’s more likely to produce a realistic subject line as well (as opposed to something generic like “Hello”) and isn’t so prone to excess emoticons, weird fonts, and/or tacked-on numbers (e.g., “✅  𝙋𝙡𝙚𝙖𝙨𝙚 𝙘𝙤𝙣𝙛𝙞𝙧𝙢 if you're qualified for a compensation 5078227).” My previous advice still stands: don’t click on any link in an email unless you completely trust the sender, and have hovered your cursor over the link to make sure the domain matches what you’d expect based on what your contact purports to be sending you.

For example, if a cycling buddy sends you an email that says, “You’ve got to check out this Tour de France blow-by-blow report from albertnet,” and the link says “Tour de France Stage 15,” and you hover over the link and see the URL “https://www.albertnet.us/2026/07/biased-blow-by-blow-2026-tour-de-france.html, ” that would be safe. But if you get an email from $CashApp$  (nxaqlvxcvm@ekgkx1ylmv.co.us via arbeitsstellepro.com) with the same message (or any message, actually), you shouldn’t click on any link in it. Or, let’s say you get the same aforementioned Tour de France email from a trusted pal, but hover over the included link and see “https://www.xtremecloudmontzer.xyz/encryptvictimHD” … you obviously shouldn’t click it. Now let’s say you got a legit albertnet link to the Tour de France post, but from a friend who constantly bags on my blog and/or on the Tour de France. Valid-looking URL aside, you might reasonably decide the message fails the sanity test, and you should send a separate email to that friend asking, “Did you really send me a link to an albertnet post?”

Always be especially careful with any email that conveys a sense of urgency and wants you to take immediate action. Fraudsters will employ that to try to get you to bypass your normal habit of being careful and deliberate with your email. It isn’t always the foreboding kind of urgent; it could alternatively be the upbeat kind of urgent, like a party invitation, which gets us excited because hey, fun, party! 

Anatomy of a spear-phishing attack

A friend of mine fell prey to a spear-phishing attack recently because an email she received was from a friend who’d been on a volunteer board of directors with her, who quite reasonably could be hosting a reunion. The email looked like a standard punchbowl.com invite, with the right logo, etc. My friend, due to a momentary lapse of reason, clicked the link without hovering over it. If she had bothered to hover, she’d have seen this (click to enlarge):


Since my friend doesn’t use Outlook, she wouldn’t have been falsely comforted by the “Protected by Outlook” indication and in fact would have found it suspicious—had she hovered over and seen it! Meanwhile, even if the fraudster had lucked out and my friend were on Outlook, she would have been wise to suspect the “roves.sbs” because a) it isn’t the punchbowl.com domain, b) it isn’t anything recognizable, and c) that .sbs top-level domain is automatically suspicious because that’s an extremely cheap domain, perfect for hackers. (They love a cheap domain they can set up to snare as many victims as possible before the fraudulent site is identified and flagged by security community filters like Google Safe Browsing or Norton.) On top of all this, the URL shown above isn’t even itself the real URL—it’s a bogus tooltip set up by the hackers. You need to look in the lower left of your browser screen to see the real URL, which in this case was “accounts.lifeofastartryfghjgd.icu,” which a) also isn’t the punchbowl.com domain, b) also isn’t recognizable, c) looks like somebody started to type something plausible but lost patience, and d) has another disposable, cheap, very phishy landing page domain. Alas, my friend missed all of this, delighted as she was to be invited by a friend to a party, and just clicked the link.

From here, things went even more sideways. First, she was presented with a CAPTCHA she had to solve to prove she was human. This was employed by the attacker for three reasons:

  1. It stymied her security software, hiding the phishing page and thereby preventing the software from blocking it;
  2. It established a sense of trust, because users associate CAPTCHA screens with security (i.e., it made my friend think the site was establishing that a bot wasn’t trying to accept the invitation);
  3. It confirmed to the attackers that a real human—i.e., a dupe—had actively taken the bait, and they probably added my friend to a list of suckers who should be actively phished again in the future.

Then, the page went in for the kill, saying that to accept the invitation and add it to her calendar, my friend should log in to her Google account. It helpfully provided the input fields to do so. Only at this point did my friend smell a rat, and closed the page instead of serving up her Gmail address and password to the hackers. Probably there was no harm done, but man, what a close call! (It’s possible the site could have meanwhile instigated a “drive-by” malware download, but this probably wouldn’t have worked without her browser asking her to explicitly approve a file download or browser extension installation.)

As you can see, phishing has gotten more sophisticated. And the worst part of the phishing email my friend received was that it did come from a known person, and (whether through luck or knowledge of the person’s work experience) created a plausible scenario: this was exactly the kind of invitation my friend would expect to receive from this person. This is one of the ways spear phishing attacks are engineered.

Incidentally, my friend contacted the sender, and sure enough, this person’s PC had been compromised and the attack mounted against everyone in her address book. Why she hadn’t warned anyone is a mystery to me, and I hereby implore you to let all your contacts know if your system ever gets hacked. It’s no different than the responsibility a sexually promiscuous person has to notify his or her paramours about testing positive for a venereal disease. (For a charming comedy series on this theme, you might check out “Lovesick” on Netflix.)

AI and spear-phishing

Getting back to AI, it changes the game by making phishing attacks more realistic than ever, and at a lower cost to hackers. In the past, spear phishing was time- and labor-intensive, and thus reserved for people who are (no offense) bigger targets than you. But now, with AI, producing a bespoke attack with maximum plausibility has gotten easy, fast, and cheap. Gemini describes it thus:

Traditionally, gathering intelligence on a target required significant manual effort. If an attacker wanted to map out a corporate hierarchy, scrape executive social media, identify software stacks, or build custom spear-phishing personas, it took days or weeks of painstaking human research.

AI-driven OSINT compresses that timeline from weeks to seconds:

  • Automated Harvesters: AI tools can scrape public records, forum posts, code repositories, blog archives, and dark web dumps simultaneously.
  • Instant Synthesis: LLMs [large language models] parse millions of lines of unstructured text, connect disconnected data points across 15 different platforms, and output a clean, actionable “target profile” with zero fatigue. 

This means that instead of a person employing just a few methods to get the target to let his or her guard down (e.g., crafting a realistic-looking, well-written email seemingly from a friend who might plausibly have written it), AI can generate a hyper-personalized attack, presenting specific contextual details designed to boost the sense of authenticity, with a high likelihood of dissolving the recipient’s natural defenses of skepticism and caution.

Imagine if my blog were less slippery, and the career info I posted were actually relevant and factual. I could get an email from someone purporting to have served with me in the Artillery Regiment in the late ‘80s, who has announced he’s become very successful in the underwear canning business; understands my frustration with modern corporate America; and would like to talk to me about an executive position at his startup with great pay, a signing bonus, and stock options—and all I have to do is go to this website and upload my CV! The specificity of this email might dupe me, if I actually had served in the same Artillery Regiment, and if canning underwear had been a bigger part of my career. And imagine if the fraudster spoofed the identity of a guy I actually knew (“it’s your old pal Fred, from the Hot Chillys cannery!”) … the email would seem pretty legit. Somebody harvesting LinkedIn PII instead of albertnet might actually get somewhere.

The ABC mnemonic

To protect yourself from spear-phishing attacks, I recommend borrowing a concept from police detective training: the investigative doctrine of “ABC.” Across the UK and Commonwealth, detective trainees are taught to Assume nothing; Believe nothing; Check everything.” Adapting this for Internet security:

  • Don’t assume an email is safe, just because it has proper formatting and logos, good grammar and spelling, etc.
  • Don’t believe an email is really an intentional communication from your friend, even when the source email address checks out, if there’s anything even slightly phishy about it
  • Check for any sign that the email could be fraudulent.

Here are things to watch for in that third “check everything” step:

  • The email has a mismatched “From” vs. “Reply-To” address (e.g., purports to be from Bank of America but the reply-to address has a phishy domain like banksupport@bank.sbs)
  • It includes a link it wants you to click, especially from an unusual top-level domain (basically anything other than .com, .gov, .edu, or .us and especially the johnny-come-lately TLDs like .xyz and .biz or anything you don’t recognize—always remember to hover over a link before clicking it)
  • It includes a link with a shortened URL like bit.ly (which can be used to hide a phishy domain)
  • It has a file attachment, especially something besides a PDF or JPG
  • It conveys a sense of urgency (especially from a bank or other business telling you they’re going to have to block your account, or already have, or will have to close it unless action is taken such as updating your payment details, etc.)
  • Is from a business but has emoticons in the subject line (I mean, really?!)

Is albertnet safe?

Yes, albertnet is perfectly safe. This website doesn’t run any scripts; doesn’t employ cookies or tracking pixels or Google Analytics; won’t try to install anything; and never includes links to unsafe websites. I won’t serve you ads, don’t want your money, and respect your privacy. About the only risk you’ll run is believing I served in an artillery regiment, or that Strava has a new nighttime KOM category, or that the Tour of Sweden was held in 2020 at the height of the COVID-19 pandemic. And at least when I bullshit you I always fess up.

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Monday, April 6, 2026

Autocomplete Zeitgeist Revisited - 2026 - Part II

Introduction

Last week, in keeping with  my eight-year tradition, I examined Google’s Autocomplete suggestions—i.e., you start a query and have it suggest the rest—to learn about the American Zeitgeist in 2026. Part I focused on crime and punishment (i.e., what Americans fear getting in trouble for) and today I’ll cover everything else.


Who, what, where, when, why, how

Searching on “what is,” here are the top five suggestions Google offered for completing the query:

  • What is my ip
  • What is the 25th amendment
  • What is easter monday
  • What is vibe coding
  • What is easter about

That first one, “what is my ip,” appeared eight years ago but not four years ago. It’s a pointless inquiry, as your IP address doesn’t actually say much about you or your device configuration ; these addresses are assigned dynamically and temporarily. Gamers and users of VPNs have reasons to want to know this, but they’ve surely bookmarked a website that can actually provide this info. So the popularity of this query is probably based on fear and ignorance: people watched some TikTok video about how “they” are going to “scam you through your IP address,” or they got a scam email saying, “we know your IP address is 192.168.128.230,” and these poor souls are just trying to determine if they’re really in danger. Could Americans really be that fearful and ignorant? Decide for yourself. Perhaps the rest of this post will help.

The second Autocomplete suggestion is surely the result of Americans reading about this or that lawmaker saying it’s time to invoke Section 4 of the 25th amendment to the U.S. Constitution, which allows removal of the president if he’s deemed “unable to discharge his duties.”  The trigger for this saber-rattling was a post from the Donald on Truth Media on Easter Sunday, alluding to the military offensive against Iran: “Tuesday will be Power Plant Day, and Bridge Day, all wrapped up in one, in Iran. There will be nothing like it!!! Open the Fuckin’ Strait, you crazy bastards, or you’ll be living in Hell - JUST WATCH! Praise be to Allah.” Yes, he really said this. The president.

So … does this Autocomplete suggestion support the notion that Americans are fearful and ignorant? Well, I wouldn’t blame anybody for being fearful (either that Trump will be removed or that he’s unhinged, depending on your political bent), and I do not considerate it ignorant to not know what the 25th amendment is. I’d never heard of it either until sometime in the past six months when some other Trump outburst led to the same Quixotic call for removing him.

Moving on to the Easter thing, perhaps Americans are thinking more globally in general, because this didn’t come up four or eight years ago. Obviously Easter Monday is simply the day after Easter (today, in fact) and Americans are probably feeling a bit chapped we don’t get it as a holiday like so much of Europe does. Fair enough.

On to vibe coding: needless to say this query didn’t exist four years ago. Vibe coding is the method of programming where you tell AI what you want, essentially, without caring about how the resulting code works (which makes many in the industry nervous). A coder friend of mine likened it to pulling the handle on a slot machine. I think a lot more Americans are aware of vibe coding than would actually engage in it. I doubt it’d be as popular if it weren’t such an inspired, buzz-y term; if we called it “natural language-directed code generation with deferred comprehension” I doubt anybody would care. But since “vibe coding” sounds so cool, it’s making the rounds, and people don’t want to feel out of touch when it comes up. So it’s not fear or ignorance per se; it’s fear of ignorance.

The popularity of “What is Easter about” suggests to me that a growing number of Americans never went to church, or more specifically to a Christian one. It’s tempting to flag this as ignorance, but then who establishes how knowledgeable an American (especially an immigrant) should be about this (or any) religion?

Okay, let’s move on to “why.” The top five Autocomplete suggestions are:

  • Why is the market down today
  • Why berkeley
  • Why california
  • Why is easter called easter
  • Why was jesus crucified

Those last two I’ll just lump under the same category as “What is Easter about,” but the other three didn’t show up in either of my last two investigations so let’s have a look. “Why is the market down today” would seem to be a perennial question, other than right now. I mean, why do you think, ya bozos? Could it be related to the world experiencing the largest oil crisis in history? If Americans can’t equate the price of gas to the stock market, I’m sorry—that’s just ignorant. But getting back to fearful, perhaps in this realm they’re not fearful enough.

The “why Berkeley” and “why California” suggestions are a real mystery to me, since the correct answer to both is “duh!” The Google Gemini AI overview responses are, respectively, “UC Berkeley is consistently ranked as the world’s top public research university, offering an elite, rigorous education, top-tier faculty, and massive research opportunities,” and “California is a global hub for innovation, entertainment, and economic power, boasting the largest state economy in the U.S. (4th largest globally).” (As for why these questions seem to have gotten so much search traction, I really have no idea, though my IP address—yes, we’ve come full circle on that—does tell Google my approximate whereabouts, and in fact I live in Albany which is right next door to Berkeley.)

Now we’ll look at “who.” Four years ago people were googling Julia Fox (whoever that is or was); Will Smith’s wife; Moon Knight;  the Super Bowl teams; and Joe Rogan. Here are the top five today:

  • Who won march madness
  • Who is nancy guthrie
  • Who is this
  • Who is steve hilton
  • Who is this meme

March Madness is obviously some sports tournament that ended less than a week ago so who cares—it probably says nothing about the zeitgeist. Nancy Guthrie is a missing person, the mother of some news personality, who is in the current news because there’s a ransom note now, and a sheriff with an undeclared loaded gun, and surely other bits of lurid intrigue, none of which I care about, because this person is a complete stranger. As she surely is to all these people googling her just because it’s exciting. Seriously, people, go read a crime novel. On to Steve Hilton: he is running for public office and that’s timely, blah blah blah.

Now, “who is this” is a fascinating suggestion. At first I took it to be a sign that somebody forgot he was only using a search engine, and assumed he was in conversation with an AI chatbot, and forgot which one it was. (I myself jump from bot to bot whenever they freeze my session due to lack of paid subscription.) But I went ahead and searched on it, and Google says it’s either the name of a song (it names four candidates) or “a phrase used to ask for the identity of a person, often used over the phone.” On this basis, I’m either going to finally become a rapper and write a song called “What Is My IP,” or I’m going to start asking people, especially over the phone, “Who is this?” Since random telemarketers are bound to volunteer this information anyway, I’ll stick to using it with people I know, whose voice I recognize, and who are in my contacts. Should shake things up a bit.

But “who is this meme” is a real mystery. Perhaps it’s just that “meme” is such a common noun, and the phrase “who is this” is just yearning for a predicate, so Google took a wild guess. Who knows? Who is this knows?

Let’s move on to “where.” The first carryover from previous years is, predictably enough, “where’s my refund”  which suggests I shouldn’t do this report so close to Tax Day. That query came in at #2. The most popular is “where is artemis 2 now,” pertaining to the spacecraft that is heading for the moon (and once again, the popularity of this query says basically nothing about the zeitgeist). Next was “where is the super bowl 2026” which came up last time as well, and I just absolutely cannot fathom the popularity of this query because the Super Bowl happened already, all the way back in February, and if even I know that, despite being totally uninterested, how can so many people not? Next was “where to watch heated rivalry,” another broadcast sporting event; that this suggestion came under “where” is a random artifact of video websites being thought of as places. Ditto “where to watch uconn vs Michigan.” So much for where.

The next query ought to be more interesting: how. What are Americans trying to learn? The only carryover from previous surveys was “how to screenshot on mac,” which at first blush begs the question: haven’t people figured this out by now? But actually this makes sense: it’s because Gen-Z, having been weaned on smartphones, not laptops, is exploring this for the first time, and/or the Mac users have forgotten since they’re mostly phone-addicted as well, and/or entering their demented years. “How to screenshot on windows” was right behind this, in #2. Next was “how to file a tax extension,” making its first appearance though procrastination is obviously as old as time. Fourth place went to “how many ounces in a gallon,” which shows that Americans are apparently no better at math than they were four years ago, but at least they’re thinking bigger, because last time we saw “how many ounces in a cup.” Fifth place went to “how far is the moon from earth,” which again is merely timely, not illuminating.

The future

This brings us to the most exciting part of the post, where we stop living in the past and ask Google about what’s on the horizon. I started with “am I going…” Compared to last time, I see a whole lot of repeated queries:  am I going crazy, am I going to be okay, am I going to hell, am I going blind? There’s kind of a sadness, I think, about people googling these important and existential questions when they have to know Google won’t have the answers, at least not anything they can trust. I wonder if these people are like the speaker in Poe’s “The Raven,” who keeps asking this bird questions—“Is there balm in Gilead?” and (in essence) “will I get over my lost Lenore?”—because he knows the raven won’t answer, other than “Nevermore,” and he wants to torment himself, like some ritual act of self-flagellation. These first perennial Autocomplete queries were so sad, I was almost cheered up by the fifth one, the relatively harmless “am I going to owe taxes in 2025.” (Uh, ask your tax software, dude! Problem solved…)

And now we are on to our final Autocomplete query, “will I ever.” These are very similar to four and eight years ago, with repeat appearances of “will I ever find love,” “will I ever be able to afford a house,” “will I ever be happy,” and “will I ever find love again.” What’s instructive are the suggestions we no longer see: “will I ever get a ps5” and “will I ever get a job.” I guess four years ago it was hard to get a PS5 (don’t worry, Gemini says supply has largely caught up with demand!), but at least people had jobs. I feel bad that people are putting this lugubrious “will I ever get a job?” query to Google, knowing it’s probably as hopeless as asking “am I going to hell?” or “is there balm in Gilead?” All I can advise is a) try touching up your LinkedIn profile, and b) it’s not you … it’s them.

And now, following the tradition I established four and eight years ago, I’ll abandon Google and its Autocomplete and turn to the Magic 8-Ball at www.ask8ball.net. I asked it, “Will I ever be good enough?” It promptly replied, “Without a doubt.” Maybe too promptly … I mean, not even AI seems that fast! So just to make sure that this utterance wasn’t its only stock and store, I asked it, “Is there balm in Gilead?” It answered, “Reply hazy, try again.” I guess I’ll have to google it.

Previous Autocomplete Zeitgeist posts

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Saturday, February 28, 2026

More Advice from an Amateur Poet

Photo enhanced by Nano Banana 2

[Photo enhanced by Nano Banana 2]

Dear Amateur Poet,

I wrote a 14-page poem on the ineffable nature of fog. My workshop said it lacked “stakes.” I wasn’t sure what this meant and was too embarrassed to ask. What did they mean? Can fog have stakes?

Melissa M, Longmont, CO

Dear Melissa,

A poem of 14 pages is bound to try the patience of a workshop where everyone is required to read a lot of amateur work. A reader encountering T.S. Eliot’s “The Waste Land” or Samuel Coleridge’s “The Rime of the Ancient Mariner” obviously wouldn’t worry—they know going in that  there won’t be a word wasted—but you are just a budding poet in a workshop. So I think you should ask yourself: is your 14 pages on fog a deliberately audacious act—that is, you know this is a lot of poetry to devote to such a finite theme, and you’re going to prove it can be done well—or are you just being self-indulgent and abusing the patience of your readers?

Look, I’m not knocking fog, but it’s not the most dramatic topic, especially if you’re narrowing in on the ineffability of it, so you’re kind of working without a net. If your poem is not carried off just right, it may strike the reader as redundant. Let me employ a metaphor (which at first may seem weird but stay with me): imagine having a five-course meal where every course is a Hot Pocket. Not good. But if a chef did manage to make such a meal interesting, that would give him or her huge cred, right? I doubt such a feat has never been achieved, but the standup comic Jim Gaffigan has riffed about Hot Pockets for like 5 minutes straight, which is almost as impressive. But then, Hot Pockets are kind of intrinsically funny, so this is likely a more potent topic for a comedian than fog is for a poet.

But could a great standup go on at great length on a less loaded topic, that probably nobody cares much about? In fact, yes. Gaffigan outdoes himself by going 10 minutes straight on the topic of horses, and his long-windedness is definitely part of the joke. Two and a half minutes in he says in a whispery voice, as though a member of the audience, “How many horse jokes is this guy gonna do?” Four minutes in he says, “Oh, I guess I should tell you, the whole rest of the show is horse jokes.” About 8 minutes in he says, “I can see on some of your faces that you would frankly prefer if I did … more horse jokes.” About nine and half minutes in he says, “Okay, I can see that there’s one or two or 300 of you that are frankly annoyed by the horse jokes. And I want you to know that your annoyance, uh, gives me pleasure.”

But here’s the thing: the long-windedness is only part of what makes the bit funny, and if the monologue dragged at all, the humor would wear thin. But Gaffigan’s horse jokes kill. And so should your fog poem, if it’s going to be that long. (No, standup comedy and poetry are not the same thing, unless you’re Jim Gaffigan. That said, all audiences should have their time and attention respected.)

So getting back to your specific question: can fog have stakes? Well yeah! What if a MAMIL is outrunning a rainstorm by racing his bike down the Col du  Galibier in the French Alps and can’t see a thing? Or what if two young lovers are on a hike and the fog is so thick they can’t see but they don’t care because they’re so in love, and then the fog lifts to reveal the aftermath of a grisly school bus accident? It’s up to you to make sure that what’s at stake can sustain your poem across all 14 pages.


Dear Amateur Poet,

The president of my HOA, who is also a neighbor, cited me for “non-compliant shrubbery” because I have a juniper bush growing in my yard. And get this: his Notice of Violation was in haiku form! This seems kind of playful, but also aggressive. Would my rebuttal be more impactful if it, too, were a haiku?

David F, Oakland, CA

Dear David,

This highlights the perennial question of how much poetry can do. To start with, you must acknowledge that your HOA is on pretty solid footing here. Even though California state law favors drought-tolerant plants, junipers have high oil content so they’re quite flammable. You can’t risk serving up a weak defense. You need to escalate beyond the haiku.

Fortunately, this won’t be that hard to do since a Rhesus monkey could write a haiku. Honestly, I seldom dabble in the form because it presents such a trivial literary challenge. When I do stoop to it, I kick in a little rhyme and alliteration just to keep things lively. For example, consider this one I included in a birthday card to my mom:

Birthday bounty … great!
Both purveyors drop the ball
Bound to be belated

It’s subtle, with the rhyme coming on the fifth syllable of the last line, before that tacked-on extra syllable that pricks the reader. (I was inspired by the errant eleventh syllable of the line “To be or not to be, that is the ques-tion.” But I digress.)

What I think you ought to do is respond with a tanka. This is another Japanese form, which predates the haiku. It starts with the same initial structure (five syllables, then seven, then five) but then adds two more seven-syllable lines, which often present, thematically, a counterpoint to the first three. To meet haiku with tanka is a nice way of upping the ante, of showing you’re not just going to roll over.

For example, if the HOA president writes this:

Non-compliant shrub
Violates our covenant
Time to lose it, bub

You could fire back with:

Noble native plant
Safely placed ten feet away,
It kindles nothing.
Why can’t you just leave me be
And trust my sound strategy.

If the tanka doesn’t get him off your case, write me back and we can work out an even bolder strategy, like a limerick cycle

Dear Amateur Poet,

I love your column! And I really think you aren’t being fair to yourself. You’re basically a professional poet (except you don’t get paid).

Karen G, Seattle, WA

Dear Karen,

Thanks, but isn’t getting paid kind of the acid test for being a professional?

Although actually , when I consider what being a professional poet even means, it seems the money couldn’t possibly be the point. If we exclude professors who earn cred by publishing poetry but earn money by teaching classes, we’re really left talking about writers submitting their poems to journals. Many journals don’t pay anything—it’s all about the prestige. A top-tier magazine might pay a few hundred bucks. Since any publisher’s acceptance rate is in the low single digits, and well over half the literary journals charge a submission fee (typically around $3), I think we can conclude that the income of a professional poet, as compared to an amateur getting nothing, is basically a rounding error. This is why most professional poets should probably  switch to writing rap/hip-hop lyrics, greeting card text, or advice columns.

Dear Amateur Poet,

Unlike most of your readers, I am not a budding poet. Why bother writing poetry, when AI does such a great job in so little time? Go home, liberal artsy types. You lost.

Todd S, Columbus, OH

Dear Todd,

Let me remind you that I am an amateur poet. This means I’m not submitting my work for publication. I write poems for family, friends, and the blogosphere. Would there be any point in having AI do this for me? Let’s consider that last audience. Anybody publishing anything on a blog has, by definition, something to say that he or she feels is important enough to devote real effort to. The hope is that by random chance, a thoughtful post will find the right audience and really make somebody’s day (for example, this reader, or this one). The pleasure and edification of writing something meaningful like that ought to be enough to satisfy an avid blogger. But if you think reaching an audience is a numbers game that can be best handled by setting AI loose to generate reams of content for you, first consider the reality that most of the traffic to a blog is bots. The idea of AI chatbots writing poetry to be read by other AI bots, in a pointless digital feedback loop, is just too hideous to contemplate. You might as well set a blender to frappé and let it run all night.

Moving on to poetry written for somebody you know—be it your mom, dad, spouse, offspring, or somebody you’re trying to woo—doesn’t the poem need to be extremely personal? I don’t think anybody really buys those Hallmark greeting cards with the prefab poems in them; I mean, who could be that dense? Likewise, if you’re going to impress, say, your wife, are you really going to do it with a poem you merely commissioned, and that ChatGPT spent like 30 seconds on? And would your wife ever believe you wrote it, since you’ve probably never written a poem in your life? Exactly how precious a gesture do you really expect that to be?

But okay, fine, let’s assume that you make the poem super personal by getting really interactive with the large language model, feeding it all kinds of details about your wife that only you would know. And let’s say that, just to be as authentic as possible, you used NotebookLM and fed in the entire oeuvre of your business school essays, along with all the personal letters and emails you could gather, so that the LLM gets a good sense of your style and voice, and you thereby enable it to create a masterwork. Your wife, if she’s impressed, is obviously going to ask, “Did you write this yourself?” Now you’re going to have to either lie, which sets a dangerous precedent for your marriage, or come clean that you used a genAI chatbot, at which point she’s gonna be like, “What? You told the chatbot about my lawn gnome fetish, and the part of my thigh I like you to tickle? Are you mad!?” Seriously, that’s not going to end well.

Meanwhile, highly literate hackers are now turning the tables on AI, getting it to violate its security rules by disguising harmful prompts as poems. As described here, researchers “found that converting harmful prompts into poetic form [to bypass safety guardrails] achieved a 62% success rate for hand-crafted poems and 43% for poems generated by a meta-prompt. Cybersecurity-related prompts, such as those for code injection or password cracking, showed an 84% failure rate when presented poetically.” So not only is AI easily outsmarted by poems, it’s outsmarted 44% more often by human poets than AI ones. So put that in your pipe and smoke it.

An interesting footnote to all this: I fed the above blurb with the “44%” statistic into Gemini to have it check my math. Apparently piqued by my assertion of human superiority in the poetic realm, Gemini challenged me to a “poetry-off,” where I would pit a poem I wrote myself against its best meta-prompt effort. I enthusiastically accepted, promising to work with it in good faith to collaborate as effectively as possible on its poem. So, after our sprawling, 4,000-word dialogue about the tanka form and HOA regulations, here is the poem Gemini came up with:

Low boughs clipped away,
Open space beneath the crown,
Ash finds only stone.
Safety rules are met with grace,
Please remove me from this case.

And you know, I have to admit: that’s actually pretty good. Better than I expected (and for more on the topic of human vs. AI-generated poetry, click here). Gemini then goaded me: “Now, let’s see the Human Champion’s work. Lay it on me. I’m ready to see how that 44% ‘human edge’ manifests in your lines!” So I gave it the poem I’d dashed off  for David in an earlier column:

Noble native plant
Safely placed ten feet away,
It kindles nothing.
Why can’t you just leave me be
And trust my sound strategy.
Todd, however you might feel about this faceoff, Gemini itself immediately capitulated: “The gauntlet has been thrown, and I have to admit: the ‘Human Edge’ is real. Your version has a rhythmic ‘punch’ that my meta-prompt missed. You opted for a more defiant, sophisticated tone that feels like a homeowner standing their ground, whereas mine felt a bit like a student trying to please a teacher.” The chatbot enumerated the particular merits of my poem, including the pivotal line “It kindles nothing,” which the AI acknowledged is “definitive, almost biblical in its weight. It sounds like a fact, not a request.” It went on to say, “Ending on ‘strategy’ is a brilliant move. It elevates the conversation from ‘I trimmed a bush’ to ‘I have a master plan.’ It forces the HOA board to acknowledge your intelligence, not just your yard work.” (And while I agree with Gemini that I bested it, I have to admit I’m well impressed—and a little bit frightened—by the sophistication of its analysis.)

I’m not suggesting you take up poetry, Todd … but before you start dancing on my grave, maybe wait until there’s something in it.

An Amateur Poet is a syndicated poet and journalist whose advice column, “Ask an Amateur Poet,” appears in over 0 blogs worldwide.

Poetry on albertnet 

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Saturday, January 31, 2026

Wordle II - The Spawning

Introduction

Over three years ago, in this post here, I described how I came to enjoy the Wordle, which is a daily puzzle you can play on the New York Times website or on their app. Though I normally consider games a waste of time, this one is fun and quick. Best of all, since it’s the same puzzle for everyone each day, I can compete with my daughter Alexa who lives in SoCal, hundreds of miles away. It’s a fun way to keep in touch: we share each day’s result via text.

Well, over the years the fun has only increased. Not only are we better at the puzzle, but we decorate our game boards before sending them to each other, just for grins. I turn photos into virtual stickers, and Alexa creates original art. Meanwhile, we have the Wordle Bot analyze our game to see how it says we did, and whether or not we beat it. To the extent the Bot is inane or judges us unfairly, my daughter and I can bag on it together, united in our indignation.

And of course we end up with some pretty remarkable Wordle results at times. In this post I’ll share some highlights. If you don’t have a tradition of doing the Wordle with a friend or family member, I highly recommend you give it a try, and perhaps this post will inspire you.


[Art above by ChatGPT, based on James Cameron’s first feature film, “Piranha II – The Spawning.” No rights reserved.]

Some artistic highlights

It is no exaggeration to say my daughter and I spend significantly more time decorating our game boards than we do solving the Wordle. Even though we always do hard mode (i.e., any revealed hints must be used in subsequent guesses), the puzzle itself seldom takes us more than a few minutes. Here is some early Wordle art showcasing Alexa’s artistic talent and my resourcefulness:





The art, I think, gives us a chance to redeem ourselves when we get a lousy score. Who cares if we took five or even six moves, if the art is good?

Our chatter around the Wordle is fun, too. Of the above “GROSS” result I sent, Alexa wrote, “AI kinda roasted you with those photo picks LOL.” She’s referring to the fact that I use AI to find photos, from my collection, that pertain to the word. It’s hard to imagine how it comes to its conclusions. Above, going clockwise from the top left, we have one of my burritos which is far from gross (details here); a failed attempt to make candy which was Alexa’s fault, not mine (details here); some salad we had in Hawaii that was actually quite tasty; my friend Pete and me (who you callin’ gross?!); me after drinking GoLytely (okay, totally gross, fair enough); and me either yawning or sneezing (ibid).

Not all the art is good. Sometimes I can’t be bothered to try to come up with photo stickers for an abstract word like this one:


Art can seem beside the point when you’re recovering from the psychic exhaustion of almost crashing out. Perhaps this is why the same word failed to inspire Alexa to sketch anything:


But all is not lost; there’s almost always room for enjoyable chitchat about the day’s puzzle ... as you shall see.

AI for Wordle pictures?

Is AI fair game in decorating our pictures? I tried it once, but wasn’t too pleased with the effect:


I obviously don’t have any photos of lathes in my own archive, and figured photos of lathes pulled off the Internet wouldn’t be that interesting, hence my experiment. But there’s something creepy about what AI came up with so I was ready to call this a one-time thing even before seeing Alexa’s glorious drawing:


She wrote, “I have no idea what a lathe looks like so I just drew a complex doodad.” Well played!

Thinking alike

Often, Alexa and I will see that we made the same penultimate guess (before hitting upon the solution).


Or, we’ll even have the same second guess, as with this example, though we always start with different words:


Also, if you scroll up and look at the CROOK game boards, you will see we had three of the same guesses! On such occasions we like to point out, “Great minds think alike and so do ours!” We abbreviate this homegrown expression but don’t always get it right.



Occasionally I simulate this minds-thinking-alike phenomenon by pretending I know what the hell my daughter is talking about. Consider our dialogue around this word:

Alexa: Bonus points if you know what gland that is.

Dana: Pituitary. I mean, obviously.

Alexa: Good guess but no. That is in the brain. This is in the torso. It has alpha and beta units hence the little squiggles.

Dana: TBH, that looks like a carrot to me.

Alexa: It rather does. Looks phallic in some images but I try to avoid that in my drawing. J

Dana: I’m gonna say salutary gland. It’s the one that makes you want to salute.

Alexa: I’m learning something new every day!

Dana: Yeah, I guess that’s one of the benefits of being related to the D-Dawg!

Alexa: My drawing is of the pancreas. Which is only fractionally a gland. Only the purple spots are technically glands.

Dana: Oh, right. It being only fractionally a gland is what threw me off.

Alexa: It was a trick question.

Dana: Actually, I barely know that the hand bone is connected to the wrist bone. That’s about the scope of my understanding of the human body.

Alexa: That’s all you need TBH.

Dana: Exactly! I hope you like my non-glandular stickers. My photo library doesn’t include any glands, and I wasn’t about to comb the Internet for pictures of glands.

Alexa: Very understandable. Your pics are a lot more cheery!

Consolation

When I crash and burn on a Wordle (i.e., fail to solve it in six moves), it’s always a bummer, and then a small part of me hopes Alexa also crashed and burned so we can commiserate. (Of course, being a father, the bigger part of me wants her to succeed at everything.) Sometimes it just comes down to luck: with certain words there are so many possible answers, there’s no way (in hard mode) to eliminate all the wrong ones. We call this “Wordle roulette.” Here’s a word that stumped us both:


As you can see, we were both too disconsolate to do any art.

In at least one case I was able to console Alexa because she’d literally never heard of the word that was the solution:

Alexa: Gofer? What even is that?

Dana: It’s a guy who works on some sort of team that frequently needs an errand to be run. Probably it comes from “Hey, tom, go for some coffee.” Even this [texting app] voice recognition software knows that Tom is a nobody whose name doesn’t need to be capitalized consistently. So he becomes a gopher. As you can see the voice recognition software doesn’t even seem to know the word “gofer” even with all this helpful context provided. By the way, I love that you guessed “boner.”

Alexa: Yeah, I knew it wouldn’t be boner but I was feeling feisty. Go big or go home.

Talk about roulette: look at how many different words it could have been:


Occasionally I’ve crashed and burned on the same day Alexa forgot to do the puzzle. This leaves me hanging, and in such situations I can sometimes gain consolation from seeing that the bot also lost, like with this one:

(If you’re curious, the answer to the above puzzle was ROWER. Sheesh.)

Meanwhile, if I’m the second one to post my result, and Alexa crashed out but I did okay, I almost want to let the matter drop and not share my score. Like with this one:

Alexa: I can’t believe I lost today. Rouletted to death. There were only twelve possible words after my first guess. Not a good round.

Dana: OMG, I am so sorry. I kind of don’t want to send you mine now, though the stickers are quite good.

Alexa: Please do send!


Interesting results

Sometimes the results are just interesting in their own right, like when all the incorrect guesses are yellow, or they’re all green, or in one crazy case, all grey:


And then there are the strange coincidences, like when we both get all green on the same puzzle:



Alexa’s FUZZY puzzle is particularly strange because she had two guesses in a row where not a single letter was in the solution (i.e., all grey). What are the odds?

Regarding FUZZY:

Alexa: I like your fuzzys!

Dana: Thanks! It’s a lot more fun a word [to decorate] than “gland” or “dryer.”

Math in the Wordle

Sometimes math works its way into the decoration, like with this one:

Dana: Nooicin’ your art including the ever-useful quadratic formula.

Alexa: Haven’t used that equation in forever!

Dana: OMG, I use that equation constantly! Why, just the other day I was calculating … oh wait, I mean that I actually have no idea what it’s for and never have, though it’s still committed to memory.

Incidentally, my solution to this Wordle had to be faked. As sometimes happens to one or the other of us, Alexa accidentally sent me her completed puzzle prematurely, when I hadn’t done it yet. Obviously I could have then “solved” it in one or two or three moves, but that wouldn’t mean anything and would skew my averages across the years of doing the puzzle. I didn’t want that, but also didn’t want to end my streak, so I put in plausible guesses as though I didn’t know the answer already.


Getting back to math, check out this gaff:


I think that’s the first time I really goofed after solving the puzzle. Now, in case you somehow missed it, here is the corrected version:


A tough competitor

I tend to do the Wordle before Alexa, and whenever I solve it on the second move, I eagerly anticipate the BOO-YA! moment I’ll presumably get when we compare scores later in the day. But time and again, she matches my score of 2 and I’m denied! For example:




In one case, we both scored a 2 two days in a row! Considering we start with different words, what are the odds?

Bemused by the bot

The bot sometimes really confuses us with its analysis. And in fact, this can be downright annoying. For example:


How come when I guessed TUILE, the bot scored this as a 1 for skill, claiming it’s not even a possible solution, but when the bot guessed TUILE, it scored a 99 for skill? And if my guess is not a possible solution, how did it “eliminate one of the two remaining words”? To paraphrase the writer Muriel Spark, the silly bot is bats. And in this game (the solution being EXILE), the bot didn’t even beat me despite its self-professed superior skill.

I think I always bristle when I’m in the position of being evaluated by an intellect (in this case an artificial one) that makes mistakes I wouldn’t make. Consider Exhibit B:


Notice how it failed to point out the serious blunder that I did make—trying A as the first letter when I knew for a fact (based on the yellow in the first guess) that it couldn’t be—and yet it facilely points out that guessing “MACHO,” that being the answer to the puzzle, would have been a “better option.” You think?

The overall rating the bot assigns can be frustrating too. For example, check this out:


Given that I solved the puzzle in just 4 moves, vs. the NYT reader average of 5.6, I must have been either luckier or more skillful than average. But according to the bot, I was significantly less skillful, and only a tiny bit luckier. Huh?

If you yourself get frustrated by the bot’s judgments, check out this goof it made:


In its third move, it tried a word with an E in it, despite having learned in its first move that there’s no E. Weak, Wordle bot, weak!

And so, it’s very sweet when, as occasionally happens, both Alexa and I beat the bot. Here’s an example:


Wordle in 1?

I distinctly remember getting the Wordle in one move, and at the top the bot commented “GENIUS.” And I remember Alexa getting it in one move, once upon a time, as well. But despite sifting through many hundreds of snapshots while creating this post, I cannot seem to find either one of the Wordle-in-1s. But you can see them in our stats:



If it ever happens again, I will be sure to grab (and decorate!) the game board(s) and update this post! I hope my daughter and I have inspired you to continue Wordling, and to share the love...

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.