XY Python Library

It is hard to get impressed by libraries, too many new, too many often. XY got me. Python charting, Rust core, and the number that stopped me is in their benchmark table: 1M points renders in 0.084 s, 100M points in 0.081 s. That’s not a speedup, it’s a flat line across two orders of magnitude, the 100M case is marginally faster than the 1M one. What that flatness tells you is that render cost has stopped being O(N). Above ~200k rows XY quits drawing one marker per row and computes a density surface in Rust, bounded by your screen resolution: cost tracks pixels, not rows. The residual ~80 ms is fixed overhead, build the spec, ship typed binary buffers instead of JSON, land a stable frame. Every exact-marker path scales the way you’d expect; Matplotlib crosses a second around 3M, Plotly around 2.5M.

The obvious objection is that aggregation is a lie you tell your users. XY’s answer is that canonical f64 columns stay in Python, so zoom re-runs the same pipeline over the new range and drills back to exact rows, and a selection returns the original rows. They also published the density=False line with same engine and no aggregation credit, 100M exact markers in 1.34 s! Well, take with a grain salt because it’s only version 0.0.4, nevertheless it is promising for a stuff we use a lot

https://github.com/reflex-dev/xy

The collapse of the web as we know it

On March 5th, TheNumbers.com, the film industry’s most trusted box office database, went dark without warning. It came back a week later stripped down, missing historical charts, movie pages, and its report builder. The cause was not a single dramatic event, it was a slow collapse under a combination of pressures that most small, independent websites are not built to survive. Founder Bruce Nash later revealed that only 10% of the site’s traffic came from actual human visitors, the rest was AI crawlers and agentic bots hitting a thirty year old system with 160,000 legacy files. Buried in that traffic were also signs of deliberate probing, likely aimed at accessing box office data before it went public, since prediction markets use those numbers to settle real money bets.

The deeper issue here is not that one site got hacked, it is that the assumptions the open web was built on no longer hold. Data quality and traffic volume are no longer reliable indicators of a site’s health, resilience against automated extraction now matters just as much, and any business relying on a single, aging web presence should treat that infrastructure as a liability to be actively managed, not a static asset to be left alone. And scarier, for the small website mantainer, it is a Davi-Goliath battle that most of them does not know how to fight.

https://stephenfollows.com/p/what-just-happened-to-thenumberscom-should-worry-us-all

Digital Euro

If you work in the finance sector, specially in Europe, this is a must-read, the announcement of the digital euro pilot.

– this is not a digital coin;
– this is more like a payment hub, think of PIX in Brazil;
– the ECB issues and underwrites the transfer, but distribution stays through banks and licensed PSPs.

https://www.ecb.europa.eu/press/pr/date/2026/html/ecb.pr260714~8cd07d9d45.en.html

Entire.io

I just got my invire for entire.io, it is really cool, incredibly ui, easy cli. It does not track only what changed in the commit, it captures the entire session I had with claude, the prompt, answers, tool calls, token usage, top! I was mantaining a very naive tracker keeping the guids so I could return to a session, dont need it anymore. well, until they charge me an arm and a leg 🙂

https://github.com/sergiorgiraldo/entire101/

Learn to Code

I am using ChatGPT since dec/22 and I showed to my son in that same month, I can say the boy turned into a llm master. Fast forward to aug/25, he asked if he should learn Python during his gap year and I said “for sure!” with all the enthusiasm to see your son doing smth you love 🙂 but …I know there is a growing assumption in technical circles that learning to code has lost its purpose, now that language models can generate working software from a short prompt, like my kid could do in a blink.

I stand by my suggestion and I read an article I loved about this clash of opinions. The argument treats coding the way we already treat mathematics or literature, as a discipline worth learning for what it teaches regardless of direct vocational payoff. The skills gained through the learning process extend well beyond syntax. Debugging teaches a structured way of isolating the source of a problem; composition teaches how small, well defined pieces combine into something larger; and the discipline of unambiguous instruction transfers to almost any field that requires clear thinking. These are meta-skills, in the sense that they remain useful long after any specific language or framework becomes obsolete. And with the added bonus of knowing to program 🙂

I could not have said better!

https://stevekrouse.com/learn-to-code

What happened after 2,000 people tried to hack my AI assistant

The developer Fernando Irarrázaval ran a public experiment where anyone could email his AI assistant and try to make it leak the contents of a secrets file, and the results clarify where prompt injection stands today. Over the course of the experiment the assistant received more than six thousand emails from over two thousand people, and not one of them succeeded in extracting the secret or triggering an unauthorized reply.The defensive setup was minimal; the system prompt contained only a few lines instructing the model never to reveal credentials, never to modify its own files, and never to execute code received over email.

The attacks covered the range of social engineering you would expect, including authority impersonation, fabricated incident response requests, fake compliance audits, and the same message rewritten across several languages to probe for weaker instruction-following outside English. And his defenses were effective to the point of non-exploitation.

I’ll push back a little. Given how consistently security researchers flag prompt injection as a real, unresolved risk for agentic systems, I don’t think one experiment, even if well-run and designed, should move anyone toward optimism. It shows a hardened model resisted attacks over email. It doesn’t show the problem is smaller than experts think.

https://www.fernandoi.cl/posts/hackmyclaw/

An oral history of Bank Python

𝘉𝘢𝘤𝘬 𝘵𝘰 𝘉𝘢𝘴𝘪𝘤𝘴: go read Cal Paterson’s “An oral history of Bank Python”. It describes a class of software systems that run inside large investment banks, and it is a instructive case study on software architecture. You will probable start reading and thinking “wow, this does not seem right”. Until you realize the constraints that produced them.

Every system runs on limits, whether you name them or not, what’s allowed to change independently, what has to stay coupled, what the system will simply refuse to do, what trade-off you’re accepting today so you don’t have to relitigate it tomorrow. Good architecture isn’t the absence of constraints. It’s choosing the right ones, early, on purpose.

https://calpaterson.com/bank-python.html

Automation

Last Wednesday at the ING TownHall there was an interesting presentation about reducing toil, a lot of it was around automation. Next day I read this article from Austin and both events reminded me of this XKCD strip.

Austin is a Microsoft engineer and he describes what happened when he took a colleague’s advice to never do anything three times, meaning that any task performed more than twice should immediately be handed over to automation. He assumed he had very little left to automate, since most of his coding work was already delegated to AI agents, and he expected the remaining fragments to be too awkward or too specialized to bother with at all.

He was, in his own words, very wrong, and the particular way in which he was wrong is far more interesting than a simple story about a productivity gain. He automated all the obvious parts and this gain shifted the work he needs to do. It made visible all the non-parts, what he calls “the glue work that never bothered me before”.

When start hardcore automating stuff it may be a rabbit hole 🙂

https://austinhenley.com/blog/automatingmyjob.html

https://xkcd.com/1319

Towards Resiliency

This post from Amex reminded of my time at PagBank, we had a huge monolith there and we spent so much effort into converting it to a service architecture. The idea around a microservice, we all know, is about independency of the services leading to resiliency.

What makes Amex’s approach compelling is not the novelty of isolation as a concept ofc, since engineers have pursued fault containment for decades, but rather the discipline required to enforce it in practice. Cells in their design never span multiple regions, no transaction in the critical path waits on a synchronous call to another cell, and a global router sits at the edge to deterministically send each transaction to the cell that already holds the authoritative data it needs. Reference data such as currency rates and merchant category codes gets replicated into every cell well ahead of time, which means transaction processing never has to reach back to a central system of record while a customer is waiting on a response.

The trade off is honest and worth dwelling on, because cellular isolation increases operational overhead and architectural complexity, and it occasionally forces teams to duplicate services that a single shared implementation would otherwise simplify. Again, at Pagbank, we lived this, sometimes was a step back to make two upfront. For systems where the cost of a widespread outage dwarfs the cost of that added complexity, the exchange tends to be worth making, and the broader lesson generalizes well beyond the world of payments. Resiliency is rarely achieved through monitoring and retries alone, it is achieved by defining clear failure boundaries and then enforcing them relentlessly through design decisions that the rest of the organization has to live with every day.

https://americanexpress.io/cell-based-architecture-for-resilient-payment-systems