Agents are making infrastructure owners rewrite assumptions that held for years. Elsewhere, the plumbing of trust, from DNS keys to TLS certificates to AI watermarks, is getting tested in public.

1. GitHub’s replica model punishes the busiest repos, so it’s being replaced

GitHub’s old scaling trick turns out to be a trap at the top end. Each repository sits in full on five fileservers, and every replica takes part in every write. So adding replicas to absorb reads makes pushes slower, and losing quorum stops writes entirely. GitHub says that ceiling is why it is rebuilding Git’s backend while the service keeps running.

The numbers explain the urgency. By GitHub’s count, developers and agents made 7.38 billion commits in September, more than five times a year earlier. Pushes grew 4.9x to 3.35 billion a month, and the busiest repository took roughly a billion requests in August. Note what the post does not say: it never splits agent commits from human ones, so a claim that agents now write most commits is not supported here.

The fix separates durability from serving. Authoritative data moves to Azure Blob Storage, and cheap cache-like workers answer reads. Only the reference update needs coordination, and maintenance leaves the serving hosts. GitHub claims up to 35x write throughput in internal benchmarks. That is an unverified vendor figure, and the real test is whether branch protections and audit trails survive the move. The Register’s teaser on an agent-coded Rails bakeoff is only a headline, so it adds nothing here.

GitHub Blog · The Register

2. The internet’s root DNS key changes October 11, and you can test it

Most people can ignore this. If you run a DNSSEC-validating resolver, you can’t. On October 11 the DNS root switches to a new key-signing key, KSK-2024, only the second time ever. A resolver that doesn’t trust it could fail to validate answers, and healthy sites under any top-level domain could become unreachable.

Cloudflare says website operators generally need to do nothing, and that its own 1.1.1.1 and Gateway DNS already trust the new key. The risk is on the resolver side. In the 2018 rollover, resolvers lost their learned trust during software upgrades or machine moves. The new key has been published since January 2025, but automatic learning only works if the state survives.

What’s new is a way to check. RFC 8509 trust-anchor sentinels let a resolver report whether it trusts key tag 38696, and Cloudflare built a test at dnstest.dev/ksk-2024. Read results carefully: a failure on the not-ta query is the correct outcome when the key is trusted, and a resolver without sentinel support gives an inconclusive result, not a failing grade. Also, the browser test checks whatever resolver your VPN or Secure DNS picked.

Cloudflare Blog

3. Fadell says AI gadgets flopped. OpenAI’s agent shows why trust is the hard part

Tony Fadell turned down the founders who called him. At MIT Future Fest he showed slides of the Rabbit R1, Humane AI Pin and Limitless pendant, all now discontinued, and said none met a real need. His sharper point is about trust. Fewer than 0.01% of people have ever had a human assistant, he said, and it took him years to hand one his bank access and sensitive data.

WIRED’s test of OpenAI’s Dots suggests the problem is not purely hypothetical. The agent got the reviewer’s name wrong, offered to solve a captcha it couldn’t, and answered a muffled mumble with ‘I love you too.’ It also produced a detailed couch shortlist that improved with feedback. That’s a software agent, not a gadget, and it costs $100 a month. But it asks for Gmail access, which is exactly where Fadell says the trust gap lives.

His prescription is debatable. He bets on-device agents and doubts the data-center-conquers-all story, and he names Apple as nearly the only candidate, even though Siri’s new AI runs on custom versions of Google’s Gemini. The tension is worth watching: the company with the trust and hardware lacks the model, and the companies with models are building gadgets to get at your sensors.

TechCrunch · WIRED

4. Google opens SynthID checking to everyone, and rivals already plug in

The interesting part of Google’s new SynthID site isn’t that it exists. It’s that the watermark is becoming shared. Google says anyone can now upload images, video or audio to check for AI generation, after a limited trial at last year’s I/O. TechCrunch reports OpenAI, Nvidia and Kakao support SynthID, and Apple is said to be joining. Ars’s headline says the site can flag content from Google, OpenAI and others; we only have its summary line.

Scale already exists: Google says people make 1 million verification requests a day, and checking is built into Gemini and Chrome. The sobering detail comes from the competition. Microsoft and Meta run their own standards, and TechCrunch notes those tools often fail to identify content from their makers’ own models.

One inference from that: a detector can only vouch for media that carries a participating watermark. A negative result doesn’t prove something was made by a human. The tool is most useful where platforms agree on one mark, and the open question is whether Microsoft and Meta join, or whether the market stays split across checkers.

Ars Technica · TechCrunch

5. Three compromised domain registries yielded fake certificates for Google

Ars Technica reports that hackers obtained counterfeit TLS certificates for Google and other large services, after compromising three domain registries. That is all we have: we only have a headline and a one-line summary, because the full article wasn’t retrievable.

So the open questions matter. We don’t know which registries were hit, how many certificates were issued, which authorities issued them, or whether any were used against real users. Don’t read this as proof of a coordinated campaign.

Still, the shape of the attack deserves attention. Certificates are issued on proof of control over a domain, so tampering at the registry layer can turn that check against the real owner. That is an inference from how issuance works, not a detail from the report. If you run infrastructure, watch for the full write-up and check certificate transparency logs for certificates you didn’t request.

Ars Technica