aistrophotography

AIstrophotography, get it! ahem, anyway.

The other night, while working on this moon shenanigans, I had a passing thought (mentioned in that post as well): how much of my astrophotography workflow in pixinsight could I task clippy with automating?

So, I fired up claude code (model Fable 5.1 in xhigh thinking mode) and gave it the parameters: a handful of folders with past imaging session data of mine (either RGB sony pics or mono LRGB image sets ready to be stacked) on my NAS and a github repo. As it happens, pixinsight’s project file format actually keeps a history of each step done to the data to reach the final product, so the natural progression would be to delineate all the steps I did in pixinsight and automate it. This was the most hands-off vibecoding session I’ve ever done (mostly cus it was late and i wanted to go to bed). I told it to create issues on the repo for every step we need to automate/recreate and asked it to iterate on each one till it was done and went to bed.

When I woke up in the morning, it had stopped (because my screensaver kicked in, which purges my ssh key, cutting off its access to github – “security first!” says the guy that handed clippy the keys and went to bed). I had it pick up where it left off and then had it run the full workflow on two targets:

Without exaggeration, it basically one-shot it (pun intended!):

Continue reading →

Claude and the moon

Last Thursday, I got a bit of bad news, so decided to deal with it as I normally do – poured a glass of bourbon and went to go stare at the stars. The only problem? The moon was up, shining bright, waxing gibbous. So I decided to point a camera at it, instead. Despite being an avid photographer and astrophotog (once upon a lifetime), i don’t actually have a particularly good setup for shooting the moon. I realized i did have an old sigma 600mm reflex (mirror) lens and after scrambling through half a dozen adapters I got it rigged up to my camera and started shooting. My impulse (laziness) was to just take a video and stack the frames – a strategy called “lucky imaging”, which is primarily advantageous for atmospheric turbulence (more on this later, highly relevant). So I took a few videos that are fairly enjoyable, but being paranoid I took a few bracketed exposures as well (also relevant).

Once I finished the fun part – staring at the sky, enjoying the nice weather, pressing a shutter button every 30 seconds – I got to the more annoying part: sitting at a computer and loading the usual tools and doing the processing. It’s been a while since I did any planetary body image processing, so I was rusty.. I vaguely recalled PIPP and autostakkert, and even how to do it the hard (but superior) way in pixinsight. But it occurred to me: you know who is really good at shit like this? clippy. So I fired up claude code and got to work. And it did great! Eventually. But first, the result:

Night 1 result as posted: 6 raw stills, RL40 deconvolution, toned in darktable Night 1 result as posted: 6 raw stills, RL40 deconvolution, toned in darktable

Not bad for a very blurry 40 year old reflex lens with a fixed aperture! And now, the gory details:

Continue reading →

asterism

tl;dr

  • I made a website you can upload a photo of the night sky (optimized for photos taken with a phonecam) and get an annotated version showing the identified stars, planets, and other solar system bodies. Primarily uses astrometry but some other fun things to add the solar system bodies, satellite tracks, etc.
  • live at: https://asterism.quietlife.net
  • repo: cwage/asterism — MIT license if you wanna run it yourself
  • no account needed, no location permission, no compass. it works out where the camera was pointing from the star pattern alone (usually. sometimes. disclaimers apply.)

Some real world examples:

Summer triangle featuring Jupiter and Saturn

Summer triangle featuring Jupiter and Saturn Summer triangle featuring Jupiter and Saturn

wide winter view featuring Pleiades (M45) and Andromeda (M31)!

Wide winter view featuring Pleiades (M45) and Andromeda (M31) Wide winter view featuring Pleiades (M45) and Andromeda (M31)

Continue reading →

Weekend project: I put a rubber on it

tl;dr

  • built a wrapper in go with a collection of sandboxing tools (bubblewrap, seccomp, et al) in order to contain various coding LLM cli tools: cwage/agentpen
  • forced (well, encouraged) its usage on my nix laptop so that invoking claude or codex actually executes it in this sandboxed tool

why?

When these LLM coding cli tools first emerged, I was cautious and skeptical. It didn’t take long for me to start being impressed, and eventually wanting to see what these things could truly do beyond trivial coding exercises.

cracks knuckles: --dangerously-skip-permissions

Using these tools without guardrails is incredibly impressive. Being able to fire up claude and be like “hey i think my jellyfin client is wedged playing The Magnificent Ambersons – can you ssh into the jellyfin container and make sure GPU passthrough is still working?”, and then watching it proceed to use my local deploy key to ssh in and do the needful is truly impressive. And terrifying. It’s all fun and games for me to YOLO with these tools on my own homelab or whatever, where I accept the risks (of both destructive actions and secrets exfiltration). But in a scenario where I’m running these tools at a company, in a project that touches many sensitive things? Claude’s uncanny ability to derive how to get access to what it needs (all while sending a firehose of any/all information it digs into in the meantime) is actually quite horrifying.

6 months later, i figured it was time to swing the pendulum the other direction and see what it’s like using these tools when you don’t trust them at all. claude and codex both provide their own sandbox options (which is good!), but even they historically haven’t been foolproof – and anthropic’s cli tool source is still weirdly obfuscated/not entirely OSS (despite being leaked). I wanted to build something that doesn’t really trust anyone involved – much like you’d sandbox actively malicious code (sortof).

Continue reading →

Weekend project: whoarewe

tl;dr

  • I used claude code to build an android app that lets two people prove they’re talking to each other using shared, rotating codes that only their devices can generate for identity confirmation
  • repo: https://github.com/cwage/whoarewe
  • OSS: MIT license
  • It’s not on the play store, and probably never will be, unless I can convince a handful of friends and family to at least try it, much less use it.
  • To try it: download the signed APK from the releases on the above github repo and either enable “Install unknown apps” in your Android settings and open it, or sideload it with adb install. If you don’t trust this (as you shouldn’t), but maybe kind of trust me, you can clone the repo, inspect the code and build it yourself. Have clippy review it!

The problem

Say that you get a phone call from a loved one. They’re panicked, crying, saying they’ve been in a car accident. They’re freakin out, you’re freakin out. They need money, now. It sounds exactly like them. What do you do? In a high pressure situation, there’s often not time (real or perceived) to establish verifiable identity confirmation. (“Tell me something only you’d know!”). People are often at their least rational or defensive in situations like this, and scammers are increasingly good at engineering precisely these situations to get your guard down. Stuff like this is starting to happen, with success.

I’m a pretty skeptical guy, and a year ago, I’d have rolled my eyes at this. Surely you can tell a fake voice from a real one, right? Turns out: not so much. Some studies put human detection of deepfake audio at roughly 48% accuracy (I can’t vouch for the methods and scientific rigor here, but seems plausible). Modern voice cloning tools need as little as a few seconds of sample audio, cost a pittance, and the source material is stuff that’s already out there for anyone with a modest public presence: earnings calls, conference talks, social media clips. Some examples:

  • AI-generated Biden robocall hit NH primary voters in 2024. Cost about a dollar to produce, took under 20 minutes.
  • Arup, $25.6M stolen – finance employee joined a video call where the CFO and several colleagues were all deepfakes. 15 wire transfers before anyone noticed.
  • Ferrari exec targeted by a deepfake of CEO Benedetto Vigna’s voice – accent and all. Got suspicious, asked a personal question the caller couldn’t answer. He was lucky.

Even before the advent of AI-supercharged techniques, social engineering scams were already bilking people out of their life savings regularly. The models are getting better and the detection tools (especially outside a lab) are getting worse.

The uncomfortable truth is that voice and video are no longer reliable signals of identity. They used to be (to an extent), not because they were cryptographically secure, but because faking them was hard. That’s no longer the case, so what do we do?

Continue reading →