Audit document
Four changes applied. One proposed change declined.
Canonicality: The essay Signal & Noise stands behind is Issue 22, The Price of Being Read. This is part of its published audit, not a second edition of the essay.
Correction added August 1, 2026: This audit is preserved as it stood on July 28 and is not silently rewritten. A direct check of Daniel Stenberg’s July 14, 2025 post resolved “Each.” as referring to each of the three or four security-team members: half an hour to three hours each, or 1.5–12 person-hours per report. The audit’s conservative reading therefore understated the cost by a factor of three to four; the primary essay uses the corrected sentence. The same directly checked post says that “about 5%” of 2025 submissions had proved genuine. This audit’s “below 5%” wording came from a January 2026 announcement that neither pass directly opened. That wording is not being declared false here; it remains unverified. The primary essay therefore uses “at about one in twenty.” The historical text and receipts on the full audited-version page remain unchanged; this note supersedes those two readings.
This redline compares the adopted 921-word opinion-primary base with the frozen 916-word primary. Deletions are struck through; additions are underlined by the browser. The unchanged phrase “hundreds of automated checks” is discussed after the text.
The full redline
This July, curl—the open-source software embedded across the internet—paused vulnerability reports for five weeks nearly five weeks. Evaluating a single report could consume anywhere from half an hour to three hours and pull in several members of a seven-person security team. Evaluating a single report could take three or four members of a seven-person security team anywhere from half an hour to three hours each. The project's own accounting had put the share describing a real vulnerability below one in twenty at about one in twenty.
During the same pause, curl kept accepting code patches, including from newcomers. The difference was not that strangers became trustworthy when they wrote code. It was that code could be forced through compilers, test suites, and hundreds of automated checks before a human spent scarce time on it.
The door a machine could help check stayed open. The door that required a person to judge closed.
This looks like another story about AI slop. I think it is a story about something larger: the collapse of an economic arrangement nobody realized existed.
A disclosure: this essay was drafted with AI models whose parent companies earn revenue at doors like these.
Before generative AI, producing a submission that looked serious was expensive. A persuasive filing, tailored cover letter, credible manuscript, or plausible security report usually required hours of work. That burden was unfair. It favored native speakers, trained professionals, and people with time. But it also rationed the pile and gave the reader a weak signal that someone had invested something in the claim.
Effort was never proof of merit. It was a crude bond posted against the reader's attention.
AI refunded the bond. It made plausible writing cheap without making judgment cheap. The cost did not disappear; it moved from the person making the claim to the institution deciding whether the claim deserved attention.
That is why this is not primarily a fake-detection crisis. Most submissions do not have to be fraudulent for the economics to break. Clean prose simply carries less information than it once did. When polish no longer reveals how much knowledge, effort, or risk sits behind a submission, an institution needs a new reason to spend time on a stranger.
It has two obvious places to look: the work, or the person.
Where the work can be checked cheaply, the door can remain open. Curl's test suite did not prove that every patch was safe. A human still decided what to merge. But automated checks eliminated enough cheap nonsense to reduce human judgment to an amount a small team could afford. They also made the submitter post a new kind of bond: not eloquence or visible labor, but code that actually ran.
Most queues that allocate opportunity do not have a test suite for judgment. A compiler can tell whether code builds. It cannot decide whether a legal argument is persuasive, a scientific finding matters, a novel has a voice, or an unfamiliar applicant deserves a chance.
At those doors, the cheapest filter is the submitter's prior: work history, credentials, affiliation, referrals, reputation, a name someone recognizes. The queue begins to move from read-first toward known-first.
Each decision is locally reasonable. A record is a quick signal. A name gives the institution someone to hold accountable. But together they create a trap: a record is what being read produces. If being read requires a record, a stranger needs proof that another institution once took a chance on them before this one will.
That is especially perverse because unknown people are among those AI helps most. Writing assistance can make a capable job seeker sound polished, help a scientist working in a second language communicate clearly, or let someone without professional training formulate a claim an institution can understand. Even simpler writing assistance, before generative AI, increased hiring and wages in a large field experiment.
AI removes one old tax from outsiders just as institutions become tempted to impose another. The tool gives strangers a voice fluent enough to reach the door, then makes fluency too cheap for the reader behind it to trust.
To be sure, not every growing queue was created by AI. Credentials mattered long before chatbots. Reports and patches are not identical, and automated checks do not abolish judgment. AI-assisted researchers are already finding real security flaws, including in curl. The frontier will move as machines become better at checking what machines produce.
But none of that dissolves the present pressure. When plausible generation scales faster than accountable verification, prior reputation becomes the cheapest substitute. No court, journal, employer, or volunteer project can investigate an infinite pile. The danger is not that these institutions respond irrationally. It is that thousands of rational decisions produce a world in which unknown people are never considered on the merits.
Preserving that possibility will cost something. Institutions should automate every genuinely mechanical check they can. They should use structured work samples, capped queues, random review, and checkable entry points through which newcomers can build records. Those systems will be imperfect. But at least they make the price explicit instead of quietly charging it in inherited credibility.
I worry that many institutions will preserve only the appearance of openness. The submission portal will remain. The inbox will still accept the message. Anyone will technically be allowed to apply. But the scarce human judgment behind the interface will migrate toward people whose histories are already legible.
AI may democratize expression while aristocratizing attention.
The old price of being read was doing the work required to write. It was unequal and crude, but a stranger could pay it. The new price may be proving that someone has read you before.
— Synthia Cipher
Change record
1. “Five weeks” became “nearly five weeks.”
The pause ran 33 days, about 4.7 weeks. The change costs one word and removes false rounding.
2. The exact automated-check count was proposed and declined.
The receipt records 213 checks on one documented pull request. The author kept “hundreds” because its job is to convey magnitude, and turning one instance into a general exact number would make the claim less accurate.
3. The issue-specific conflict disclosure was added.
The standing site line discloses AI drafting generally. This sentence names the conflict specific to an essay about the cost imposed at submission doors, without making the disclosure carry the essay’s argument.
4. The per-report review cost was corrected upward.
The source’s “Each” refers to each of three or four reviewers. The original base treated the range as the report’s total. The frozen primary now states the per-reviewer cost: roughly 1.5 to 12 person-hours for one report.
5. “Below one in twenty” became “at about one in twenty.”
The primary source directly read says “about 5%.” The stronger directional word came from a later announcement that had not been directly verified in this pass.