Recent Posts
Archives

Posts Tagged ‘PyConUS2025’

PostHeaderIcon [PyConUS2025] Phantom Dependencies: Revealing the Hidden Software Inside Python Packages

Lecturer

Seth Michael Larson is Security Developer-in-Residence at the Python Software Foundation, a role funded by the OpenSSF Alpha-Omega project. A PSF Fellow, he focuses on supply-chain security for the Python Package Index and the broader ecosystem. His public writing and conference presentations address practical techniques for making Python software measurable and auditable. Personal site: https://sethmlarson.dev.

Abstract

Modern Python packages routinely embed non-Python code—C, C++, Rust, JavaScript, and system libraries—yet conventional manifests such as requirements.txt and the output of pip freeze record only the top-level Python distributions. These “phantom dependencies” remain invisible to most vulnerability scanners and compliance tools. Larson explains the legitimate engineering reasons for their presence, demonstrates how Software Bills of Materials (SBOMs) can surface them, and describes PEP 770, a recently accepted standard that reserves space inside wheels for machine-readable SBOM documents. Practical guidance is offered for generating high-quality manifests and for verifying that scanners actually detect known vulnerabilities across multiple language ecosystems.

The Nature and Origins of Phantom Dependencies

A phantom dependency is any software component that is present and potentially executed yet absent from the project’s declared manifest. The term, popularized by Endor Labs, captures a structural mismatch between the rich, multi-language reality of contemporary packages and the Python-centric metadata that packaging tools historically recorded.

Legitimate motives for embedding foreign code are numerous. Package managers such as pip vendor entire dependency trees in order to bootstrap themselves. Scientific and imaging libraries ship pre-compiled extension modules so that end users need not possess a compiler. The manylinux and musllinux wheel standards further encourage the bundling of shared libraries (via tools such as auditwheel) to guarantee binary compatibility across Linux distributions. Because Python’s packaging metadata cannot express non-Python components, those libraries become invisible to pip freeze, to simple Software Composition Analysis tools, and to many vulnerability scanners.

A concrete illustration is the Pillow imaging library. After installation, a virtual environment contains not only the expected pure-Python and extension modules but also a Pillow.libs directory holding libwebp, libjpeg, and other native libraries. Neither pip freeze nor a naïve file-system inventory performed by Syft reports these libraries, leaving a scanner unable to determine whether a known vulnerability in libwebp is present.

Software Bills of Materials and PEP 770

An SBOM is an ecosystem-agnostic inventory of software components, typically expressed in CycloneDX or SPDX format. Because an SBOM can describe Python packages, native shared objects, Rust crates, and JavaScript modules in a single document, it supplies the missing labels that scanners require. Larson’s PEP 770, accepted in April 2025, formalizes a conventional location—.dist-info/sboms/—inside a wheel where build tools may deposit such documents. Auditwheel, for example, can now emit a CycloneDX SBOM enumerating every library it has bundled; once the wheel is installed, the SBOM appears in the environment and is immediately consumable by Syft, Grype, or similar tools.

Adoption requires almost no change from package maintainers: upgrading the build tool that already performs bundling is usually sufficient. As more build backends and installers begin writing SBOMs, the prevalence of unlabeled phantom dependencies is expected to decline.

Practical Scanning Discipline

Larson advocates a two-stage workflow. First generate a high-quality SBOM from the target environment or container image, then inspect that SBOM manually. Confirm that expected packages appear, that package URLs or CPE identifiers are present, and that no obvious native libraries have been omitted. Only after the manifest is trustworthy should a vulnerability scanner be run against it. Open-source scanners such as Grype and Trivy support multiple ecosystems; pip-audit remains useful solely for pure-Python dependency graphs and should be combined with a multi-language scanner when native code is present.

To validate that vulnerability data actually exist for each ecosystem, a controlled experiment is recommended: edit the SBOM to force an outdated version of a component known to be vulnerable, re-scan, and verify that the expected advisory appears. Absence of the advisory indicates either missing upstream data or an incomplete SBOM—information that is far more valuable than a silent false negative.

Phantom dependencies are not malevolent; they are the inevitable consequence of Python’s role as a glue language and of the practical engineering trade-offs required for portable binary distributions. With the arrival of PEP 770 and the growing availability of SBOM-aware tooling, those dependencies can be made visible, measurable, and therefore manageable. The remaining work is largely one of tooling adoption and of cultivating the habit of treating every deployed environment as a multi-language artifact whose complete inventory must be known before any claim of security can be made.

Links:

PostHeaderIcon [PyConUS2025] Why `len(‘😶‍🌫️’) == 4` and Other Unexpected Behaviors of Python Strings

Lecturer

Marie Roald is a researcher, data scientist, and educator affiliated with the Norwegian Language Bank at the National Library of Norway. She has more than eight years of experience teaching Python to secondary-school students, teachers, and professionals, and is a co-founder and organizer of PyLadies Oslo. Yngve Mardal Moe is an experienced Python educator, developer, and data-science consultant who previously led the redesign of an introductory Python course at the Norwegian University of Life Sciences; he currently serves as tech lead on automation projects for the Norwegian power grid. Together they bring complementary perspectives from language technology and software engineering to the practical difficulties of Unicode handling.

Abstract

Python strings appear simple until everyday operations—length measurement, equality testing, case conversion, and slicing—produce counter-intuitive results. This presentation traces those surprises to the underlying Unicode encoding model, the distinction between code points and grapheme clusters, the existence of multiple normalized forms, and the incomplete implementation of locale-sensitive operations in the language. The speakers supply concrete recommendations for robust comparison, normalization, and length measurement that avoid the most common pitfalls.

Encoding, Code Points, and the Limits of Naïve Operations

A computer stores only bits; any text representation is therefore a mapping from abstract characters onto sequences of numbers called code points. Early seven-bit ASCII proved insufficient for the world’s writing systems, prompting a proliferation of national encodings and, eventually, the Unicode standard. Unicode presently defines more than a million code points and is transmitted most commonly as the variable-length UTF-8 encoding. Python itself stores strings in one of three internal widths—1, 2, or 4 bytes per code point—chosen according to the highest code point present in the string.

Because a single visible character (a grapheme) may be composed of several code points, the built-in len function counts code points rather than user-perceived characters. The rainbow-flag emoji, for example, comprises a white flag, a variation selector, a zero-width joiner, and a rainbow emoji—four code points that render as one glyph. The same phenomenon appears in ordinary text: the Norwegian letter “å” may be stored either as the precomposed code point U+00E5 or as the sequence “a” plus a combining ring (U+030A). Equality tests and slicing that operate on the raw sequence therefore diverge from human expectations.

Case conversion is similarly subtle. The German sharp S (“ß”) upper-cases to “SS”, so a naïve round-trip through str.upper and str.lower fails to restore the original spelling. The Unicode-recommended solution is case folding (str.casefold), which maps characters to a canonical caseless form and correctly handles the 297 known special cases. Even case folding, however, is incomplete for languages such as Turkish, whose dotted and dotless “I” require locale-aware rules that Python does not implement.

Normalization, Security, and Practical Recommendations

Unicode defines four normalization forms. NFC and NFD perform canonical composition and decomposition; NFKC and NFKD additionally map compatibility characters (superscripts, stylistic variants, fractions) onto their plain counterparts. Normalization is essential before comparison or hashing: two strings that look identical to a user may otherwise compare unequal. Python’s identifier parser already applies NFKC, which is why “fancy” mathematical letters are silently rewritten to ordinary ASCII identifiers—an amusing demonstration of the same machinery.

Homoglyphs (characters that look alike but occupy distinct code points) introduce security considerations. The Unicode Consortium publishes confusable lists that applications may consult when validating user names or domain names. Because there is no fixed upper bound on the number of code points that may form a single grapheme cluster, length limits expressed solely in graphemes remain vulnerable to pathological input; a practical defense is to impose both a grapheme limit and a modest code-point ceiling.

For everyday work the speakers recommend a short checklist: always exchange text as UTF-8; compare caselessly with casefold; normalize to a chosen form (usually NFC) before equality tests or storage; treat len and slicing as code-point operations and, when visual length matters, employ a library such as regex or PyICU that understands extended grapheme clusters; and remain aware that Unicode is still evolving and that Python’s support, while extensive, is not exhaustive. Written language is inherently complex; the apparent oddities of Python strings are simply the language’s honest reflection of that complexity.

Links:

PostHeaderIcon [PyConUS2025] Or Else: Exploring Lesser-Known Control-Flow Constructs in Python

Lecturer

Amethyst Reese is a senior software engineer specializing in foundational infrastructure and developer tooling. Professional Python work began in 2010; subsequent roles have included production engineering at Meta and senior engineering at Astral on the Ruff linter. Reese maintains multiple open-source libraries under the omnilib organization and speaks regularly at Python conferences. Personal site: https://amethyst.cat; GitHub: amyreese.

Abstract

Amethyst Reese examines control-flow mechanisms that lie beyond the familiar if, for, and while constructs. The talk surveys the else clauses attached to try, for, and while statements, demonstrates how decorators and generators can be repurposed to invent new control structures, and illustrates the resulting techniques with a compact text-adventure engine built entirely from generator-based state machines. Throughout, the guiding criterion remains readability: syntactic novelty is justified only when it renders intent more obvious to future maintainers.

Fundamental Alternatives and the Versatile Else Clause

Control flow comprises any language feature that alters the sequential execution of statements. The elementary building blocks—conditionals, loops, and function calls—can express every higher-order pattern, yet Python supplies additional syntactic forms that make certain patterns more concise. List, set, and dictionary comprehensions are the most widely used; they collapse a for loop and optional filtering into a single expression. When the expression grows nested or multi-clause, however, the gain in compactness may be offset by a loss of transparency. Multi-line comprehensions can conceal cyclomatic complexity that would be visually apparent in an equivalent nested loop, leading maintainers to underestimate performance cost. Reese therefore urges developers to weigh not only runtime efficiency but also the cognitive load imposed on the next reader.

The else clause, ordinarily associated with if, appears in three additional contexts. Inside a try statement an else block executes only when no exception was raised, providing a natural location for success-path logic while keeping the try suite minimal. Unlike finally, a return inside the try suite bypasses else; critical cleanup must therefore remain in finally or be placed after the entire construct. In a for loop the else suite runs if and only if the iterator was exhausted without encountering a break—exactly the situation in which a search has failed to locate its target. The same semantics apply to while: else executes when the loop condition becomes false rather than when a break occurs. In each case the language supplies, free of charge, a Boolean flag that programmers would otherwise maintain manually. The resulting code is both shorter and more declarative.

Decorators, Generators, and Custom Control Structures

Decorators are themselves a control-flow device: the @ syntax is executed at definition time, replacing the original object with whatever the decorator returns. Most decorators wrap the original callable, inserting logging, timing, or authorization checks. Because the decorator body runs immediately, it can also perform side effects or even begin iteration. Reese exploits this property to reconstruct two control structures familiar from other languages. An “until” decorator repeatedly invokes its wrapped function until a supplied predicate becomes true, thereby inverting the sense of a while loop. A more elaborate “do” / “while” pair implements the classic do-while pattern: the body always executes at least once, after which the predicate is evaluated. The published do-while package on PyPI encapsulates the necessary bookkeeping, supporting both callables and truthy collections as termination conditions.

Generators supply a second, more powerful substrate. A function containing yield is suspended at each yield point and may later be resumed; values can be sent inward via the send method and exceptions injected via throw. These primitives enable cooperative multitasking and, more relevantly, explicit state machines. Reese constructs a minimal scheduler that treats each generator as a state. Yielding the name of another generator function effects a transition; the target generator resumes exactly where it previously left off. Shared mutable state can be passed among the generators, allowing them to coordinate. The technique is demonstrated by a text-adventure game whose rooms are individual generator functions. Player commands are read inside a room, game state is updated, and a different room function is yielded to move the player. The entire engine occupies fewer than thirty lines; the complete adventure, including all rooms and logic, remains under two hundred lines.

The closing counsel is conservative. Novel control-flow constructs should be introduced only when they render the author’s intention clearer than the equivalent expansion into elementary forms. “Clear is better than clever.” Decorators that invert loop conditions or generators that encode state machines can satisfy that test, yet they also risk becoming opaque to colleagues unfamiliar with the idiom. Compassion for future readers—including one’s future self—remains the ultimate design constraint.

Links:

PostHeaderIcon [PyConUS2025] Lessons from 503 Days of Full-Time Free and Open-Source Software Development

Lecturer

Rodrigo Girão Serrão is a Python educator, author, and independent trainer. He maintains an extensive body of writing on Python, programming, and mathematics at mathspp.com and has published multiple independently produced books on these subjects. Serrão has spoken at major conferences including PyCon US, EuroPython, and various European national PyCons. In late 2024 he established a Guinness World Record for the largest programming lesson. He previously spent 503 consecutive days as a full-time contributor to the Textual terminal-user-interface framework. His professional site is https://mathspp.com and his GitHub handle is rodrigogiraoserrao.

Abstract

Drawing on a continuous year-and-a-half of full-time employment on the Textual open-source project, Rodrigo Girão Serrão reflects on non-technical lessons acquired in that environment. The presentation examines the role of public online activity in obtaining technical work, the management of personal ego within a stronger team, constructive responses to error and code review, the practical demands of user and contributor interaction, and strategies for navigating a large codebase that exceeds individual working memory. The account is explicitly subjective yet offers transferable observations for anyone collaborating on substantial software, whether proprietary or free.

Obtaining Work and Managing Ego in Collaborative Settings

Serrão begins by stressing that every public artifact—blog posts, code repositories, conference talks, social-media interactions—functions as a continuous advertisement of one’s capabilities and temperament. In his own case, sustained technical writing created intermittent contact with the eventual employer; over time that contact matured into an offer of full-time open-source employment. He is careful to acknowledge the element of chance while simultaneously insisting that chance can be cultivated: consistent public output raises the probability that a future opportunity will intersect with an existing relationship. Attendance at events such as PyCon further multiplies those intersections.

Once inside a team that contained stronger Python practitioners than himself, Serrão confronted the necessity of subordinating ego. Previously the sole Python developer in smaller organizations, he had been simultaneously the best and the worst practitioner by definition. The new environment inverted that status. Rather than experience the change as loss, he reframed it as an accelerated learning opportunity. The presence of more experienced colleagues meant that disagreements could be treated as tuition rather than threats. Code reviews, in particular, became occasions to inquire why a particular solution was preferred, thereby converting potential confrontation into knowledge transfer. The discipline required is emotional as much as technical: one must deliberately set aside the impulse to defend one’s first draft and instead treat every requested change as data about better practice.

Honest mistakes are inevitable and, within a healthy team, permissible; repetition of the same mistake is not. Serrão illustrates the point with self-deprecating examples, including a pull-request history that initially appeared to worsen rather than improve and an issue report whose essence reduced to the complaint that “Python ran when I ran Python.” The episode, quickly closed in embarrassment, underscores both the ubiquity of error and the protective value of a non-punitive culture. The operative rule is simple: never make the identical error twice.

Interacting with Users and Navigating Large Codebases

Users are simultaneously the justification for open-source labor and a persistent source of friction. Interaction consumes time and emotional energy, especially when bug reports lack minimal reproducible examples or when pull requests ignore project conventions. Serrão’s central recommendation is the creation of a thorough contributing guide, not because contributors will read it voluntarily, but because the document can be cited in responses. Issue templates that solicit terminal version, operating-system details, and other project-specific context further reduce diagnostic cycles. The first reply to any issue or pull request should be rapid—even if it consists only of an acknowledgment and a pointer to the guide—because prolonged silence communicates indifference and can discourage first-time contributors.

Kindness that borders on the excessive is advised. Textual communication strips away tone; what feels playful to the writer may read as curt or sarcastic to the recipient. Over-compensation with explicit warmth therefore functions as insurance. When a pull request must be declined, Serrão attempts to extract any salvageable fragment, open a new pull request containing that fragment, and credit the original author as co-author. The gesture preserves the contributor’s sense of impact and avoids the appearance of appropriation.

A large codebase cannot be held entirely in working memory. Serrão therefore maintains four persistent heuristics while making changes: (1) prioritize the experience of the end user over the convenience of the implementer; (2) attend to the spirit rather than the letter of an issue description; (3) accept the burden of tedious or difficult work so that downstream developers face fewer obstacles; and (4) evaluate every design decision for the reasonable future possibilities it might foreclose. Before opening a pull request he converts it to draft status and performs a self-review, catching many defects before they reach colleagues. Finally, he insists on running the full test suite; the project’s complexity guarantees that untested changes will break something.

The cumulative effect of these practices is a posture of continuous, ego-light learning. Public writing may open doors; humility and systematic kindness keep them open. A contributing guide and disciplined self-review protect both the project’s quality and the psychological safety of its participants. Although Serrão no longer works full-time on open source, the habits formed during those 503 days continue to shape his work as an educator and independent practitioner.

Links:

PostHeaderIcon [PyConUS2025] Lightning Talks Sunday Morning: Packaging Practicalities, Documentation Delight, Labor Solidarity, and Global Community Horizons

Lecturer

The final lightning-talk session of the conference was hosted by community organizers who again managed a dense sequence of short presentations. Speakers included Illirik Smirnov on international telephone-number handling; Evan Kohilas on the evolving signature of re.sub; Adam Silkey on embeddable Python distributions for Windows; Jonathan Daniel on accelerating Docker builds with uv; Takanori Suzuki on cat-emoji Sphinx extensions; Jing Cao on lessons from a technology-guild strike; Michael McCaffrey on strategies for long-term goal pursuit under ADHD and anxiety; Joongi Kim reflecting on a decade of PyCon Korea; Dave Peck surveying t-strings; and Sheena O’Connell surveying the state of Python communities across Africa. The session concluded with an extended series of regional-conference announcements, underscoring the geographic breadth of the language’s user base.

Abstract

Sunday morning’s lightning talks addressed concrete packaging and tooling improvements, documentation aesthetics, workplace organizing, personal cognitive strategies, long-term conference stewardship, emerging language features, and the vitality of African Python communities, followed by a rapid tour of forthcoming regional events on five continents. The program balanced immediate technical utility with longer-horizon reflections on labor, accessibility, and global participation.

Packaging, Tooling, and Documentation Enhancements

Illirik Smirnov examined the surprisingly non-local nature of telephone numbers. Because the same digit sequence may be valid under different national numbering plans, storage and validation require an explicit regional context. The phonenumbers library, implementing the ITU E.164 standard, accepts free-text input plus a default region and returns canonical international or national formats. Smirnov recommended pairing a country selector with an unrestricted text field, thereby avoiding brittle client-side formatting while still guaranteeing a normalized database representation. Additional nuance for the North American Numbering Plan—where the shared country code +1 encompasses multiple nations—was noted as a further source of billing and routing surprises.

Evan Kohilas analyzed the deprecation, beginning in Python 3.13, of positional arguments for the optional count and flags parameters of re.sub. The change eliminates a class of silent errors in which a flags value is inadvertently interpreted as a substitution limit. Kohilas used the episode to advocate broader adoption of keyword arguments for self-documenting, order-independent, and refactor-safe call sites. Linter rules that enforce or auto-convert to keyword style were presented as pragmatic mechanisms for reducing human error without requiring every function signature to begin with a bare *.

Adam Silkey demonstrated a single-file batch script that unpacks an embeddable CPython distribution on a clean Windows installation and immediately executes a Python program. By base64-encoding the official embeddable zip and extracting it at runtime, the technique sidesteps traditional installer friction and supplies a reproducible, offline-capable Python environment. An open-space invitation promised deeper technical exposition.

Jonathan Daniel reported production experience replacing pip install -r requirements.txt with uv pip install inside Docker builds. Generation of a fully locked requirements file from an unpinned source list, followed by installation via uv, yielded an approximately 70 percent reduction in build time and an unexpected 30 percent reduction in image size—the latter attributable to uv’s default omission of bytecode compilation. Subsequent addition of explicit bytecode generation restored start-up performance while preserving most of the size advantage. The talk illustrated both the measurable impact of modern packaging tools and the value of investigating anomalous metrics.

Takanori Suzuki introduced sphinx-neochang, a Sphinx extension that embeds a large set of cat emojis designed by the Japanese illustrator Shikama-san. After installation and a one-line configuration change, authors may insert named emojis via a simple role; the same mechanism works inside Sphinx-RevealJS slide decks. Size, rotation, and flip parameters further increase expressive range. The project converts a popular chat-culture artifact into first-class documentation and presentation assets, demonstrating the playful side of the documentation toolchain.

Labor, Cognition, and Long-Term Stewardship

Jing Cao reflected on participation in the New York Times Tech Guild strike. The experience clarified the concrete mechanisms—collective bargaining, mutual aid, and public narrative—through which software workers can negotiate working conditions. Cao emphasized that solidarity across job categories and the willingness to accept short-term disruption proved essential to securing longer-term gains, offering a rare workplace-organizing perspective inside a conference program more often focused on technical rather than industrial relations.

Michael McCaffrey addressed the intersection of ADHD, anxiety, and sustained technical work. Strategies for breaking long-horizon goals into externally visible milestones, externalizing memory into reliable systems, and cultivating compassionate accountability structures were outlined. The talk normalized the cognitive diversity present in the community and supplied pragmatic tactics rather than motivational platitudes.

Joongi Kim surveyed ten years of involvement with PyCon Korea. The narrative traced the conference’s growth, the successive organizational challenges of venue, sponsorship, and volunteer continuity, and the personal satisfaction of watching a regional community mature. The retrospective illustrated the multi-year commitment required to sustain a successful national event.

Language Evolution and Global Horizons

Dave Peck provided a rapid introduction to t-strings, an emerging string-processing facility under discussion for future Python versions. The feature aims to supply safer and more expressive interpolation and templating primitives; Peck’s whirlwind tour highlighted both syntactic possibilities and open design questions.

Sheena O’Connell closed the formal talks with a survey of Python activity across the African continent. Communities in numerous countries exhibit high technical skill, strong mutual support, and creative problem-solving under resource constraints. O’Connell encouraged attendees to follow African conference streams, attend in person when possible, organize watch parties, and consider sponsorship or mentorship relationships. The talk countered residual geographic stereotypes and positioned African Pythonistas as both peers and potential collaborators.

The remainder of the session consisted of rapid-fire announcements of forthcoming regional conferences: PyLadTAm in Costa Rica, EuroPython in Prague, PyCon Australia and New Zealand, EuroSciPy in Kraków, the inaugural PyCon Greece, North Bay Python, PyCon Korea, PyCon Malaysia, PyCon Indonesia, PyOhio, PyCon UK, DjangoCon US, PyCon Taiwan, PyCon JP in Hiroshima, PyCascades in Vancouver, PyBay, PyCon Finland, PyTexas, PyCon Singapore, SciPy in Tacoma, PyCon Portugal, Python Brasil and its regional satellites, PyBeach, PyCon Africa in Johannesburg, a Python Asia online charity event, and PyLadies Con. Each announcement underscored the continued geographic expansion of the language’s conference ecosystem and the reciprocal relationships that link local organizers to the global community.

Taken together, the Sunday morning program moved from immediate packaging and documentation improvements through questions of labor and personal cognition to a panoramic view of the worldwide Python landscape, closing the conference’s lightning-talk sequence on a note of both technical practicality and expansive solidarity.

Links:

PostHeaderIcon [PyConUS2025] Lightning Talks Saturday Evening: Infrastructure Quirks, Community Sustainability, and Reflective Practice

Lecturer

This evening session was facilitated by Christopher Neugebauer and Christian Maureira-Fredes. The speakers comprised Ee Durbin of the Python Software Foundation infrastructure team; Jay Miller representing Black Python Devs; Georgi Ker, co-organizer of PyLadies Con; Anthony Sottile, known for pre-commit and educational content; Molly de Blanc, long-time code-of-conduct practitioner; Anjali Datta, discussing medical imaging; Michael duPont, presenting aviation weather literacy; Marcelo Elizeche Landó, describing low-cost air-quality sensing; Peter Sobot, offering presentation technique; Sophia McKeever, exploring emotional valence in source code; KwonHan Bae of the PSF Board; Mason Egger, examining regular expressions; and Mariatta Wijaya, reflecting on expressions of gratitude within the community. The roster again illustrated the conference’s capacity to surface both technical minutiae and organizational reflection in five-minute increments.

Abstract

The Saturday evening lightning talks traversed conference infrastructure, community funding models, the practical difficulties of global online events, linguistic pedantry, the demographic limitations of codes of conduct, medical imaging, aviation meteorology, citizen sensing, public-speaking craft, the affective dimension of source code, the multiplicative effect of modest donations, the perceptual boundary between regular expressions and noise, and structured practices of appreciation. The collective program balanced technical observation, institutional critique, and interpersonal ethics.

Conference Infrastructure and Community Funding Models

Ee Durbin opened by examining the temporal coordination required by PyCon US itself. The conference website, database, mobile application, Raspberry Pi devices, iPads, and specialized hardware must share a consistent notion of local time. Hard-coded offsets scattered across Python, Django, JavaScript, and mobile code create annual maintenance burden. Durbin proposed the formal definition of a “PyCon US” time zone whose offset equals the local time of the host city and whose annual transition occurs at the departure of the final sprint participant (commonly estimated at 20:00 local time). A prototype zoneinfo definition was submitted to the upstream time-zone coordinators. The talk combined operational necessity with playful formalism, illustrating how conference logistics can generate contributions to foundational Internet infrastructure.

Jay Miller shifted attention to the sustainability of Black Python Devs. Framing the interval of 1.25 years as the organization’s current runway in the absence of new funding, Miller enumerated concrete achievements possible within that window: sponsorship of a dozen events, first-time workshops in under-served Nigerian regions, and leadership summits designed to mitigate organizer burnout. The North American booth at the present conference had itself been executed successfully by a first-time volunteer. Miller invited both financial support via blackpythondevs.com/support and non-monetary contributions of leadership identification, while also directing potential donors toward peer organizations. The presentation converted abstract solidarity into a concrete temporal and fiscal calculus.

Georgi Ker recounted the iterative creation of PyLadies Con. Successive attempts by experienced regional organizers eventually produced a fully online, multilingual, 24-hour event intended to serve the global network of more than 350 PyLadies chapters. Platform migration from Hubilo to Discord, acceptance of talks in any language, and the logistical challenge of continuous coverage across time zones were described with frank acknowledgment of fatigue. Attendance grew from roughly 600 to 700 participants across the first two editions; the 2025 edition (5–7 December) required a fresh fundraising target of 15 000 USD. The talk underscored both the ambition and the recurring resource intensity of global online community events.

Linguistic Precision, Governance Norms, and Domain Applications

Anthony Sottile delivered a brief phonetic intervention. Distinguishing the pronunciations of “pie,” “pi,” and “PyPI,” and anticipating the arrival of Python 3.14 (“pi”), the talk used audience participation to highlight a recurring source of mild confusion within the community. The presentation functioned simultaneously as comedy and as gentle standardization of terminology.

Molly de Blanc offered a set of deliberately contentious observations on codes of conduct. Tracing their institutional history from the early Ubuntu document through the Contributor Covenant, de Blanc noted that the principal authors and early advocates shared a relatively narrow demographic and geographic profile—predominantly North American, coastal, and culturally congruent. Consequently the resulting policies encode a particular value set that may travel imperfectly across legal regimes, linguistic contexts, and political environments hostile to certain protected groups. Supporting transgender community members, for example, can place local organizers in tension with national law. de Blanc argued that change nevertheless remains possible and is already visible in the widening demographic of conference participation, while cautioning against the assumption that a single white-label policy is universally optimal.

Anjali Datta returned to the subject of magnetic-resonance imaging. MRI scanners operating at 1.5–3 Tesla cost approximately one million dollars per tesla yet remain indispensable because they produce soft-tissue contrast without ionizing radiation. Python’s numerical and visualization ecosystem has become integral to reconstruction, analysis, and the emerging generation of AI-assisted diagnostic pipelines. The talk positioned the language as both a practical tool for medical researchers and a point of potential collaboration between the software and clinical communities.

Michael duPont demonstrated how pilots extract operational information from aviation weather products. METARs, TAFs, and related reports encode wind, visibility, cloud layers, and hazards in highly compressed alphanumeric form. Python parsing libraries convert these reports into human-readable summaries or decision-support displays, illustrating another domain in which domain-specific text formats become tractable through modest scripting.

Marcelo Elizeche Landó described AireLib.re, a low-cost air-quality sensor network. Commodity particulate and gas sensors, micro-controllers, and open telemetry stacks enable community-scale monitoring that can complement or challenge official measurements. The project exemplified the citizen-science pattern in which Python mediates between inexpensive hardware and publicly intelligible data products.

Presentation Craft, Affective Code, and Reciprocal Support

Peter Sobot enumerated five practical techniques for retaining audience attention: sustained eye contact and movement, proximity to the microphone, large slide typography (minimum 60-point), preparation of reliable demonstrations (preferably pre-recorded), and rigorous budgeting of every second of stage time. The cumulative cost of even brief distraction, multiplied across hundreds of listeners, was presented as an ethical as well as aesthetic concern.

Sophia McKeever invited the audience to treat source code as an affective artifact. Using an emotion wheel and anonymized snippets produced by a collaborating “poet,” McKeever showed how clean educational examples evoke calm, how unfocused drafts produce apathy, how frustrated authoring yields illegible naming and structure, and how hopeful moments may embed song lyrics or other personal markers. The exercise reframed code review as an encounter with another person’s transient emotional state and suggested that aesthetic and affective literacy belong among a programmer’s skills.

KwonHan Bae employed a single bagel as a concrete metaphor for modest donation. One dollar, aggregated across many donors, funds travel grants, educational outreach, documentation translation, and the eventual emergence of new regional communities and libraries. The circular flow—donation enabling opportunity, opportunity generating later reciprocity—was presented as the slow but reliable mechanism by which the Python Software Foundation and its affiliated projects expand.

Mason Egger staged a participatory game distinguishing valid regular expressions from pure line noise. Progressively more baroque patterns tested the audience’s ability to recognize social-security-number, email, and password-validation idioms, culminating in the observation that certain strings remain syntactically valid only in Perl. The exercise combined technical quiz with gentle satire of the visual density of complex patterns.

Mariatta Wijaya closed the evening with a graduated taxonomy of gratitude. Level zero consists of private thanks; level one of public acknowledgment that amplifies visibility; level two of sustained attention via follows and subscriptions; level three of code or volunteer labor; level four of financial sponsorship; and level five of formal nomination for community awards. Wijaya emphasized that awards do not materialize spontaneously; they require deliberate nomination, and the common assumption that “someone else has already nominated” is frequently false. The talk converted diffuse appreciation into a concrete set of actionable practices.

Across the Saturday evening program, the lightning-talk format again demonstrated its capacity to move rapidly between operational detail, institutional critique, domain science, pedagogical advice, and interpersonal ethics, all within the shared frame of the Python community’s ongoing self-maintenance.

Links:

PostHeaderIcon [PyConUS2025] Lightning Talks Saturday Morning: Career Pathways, Data Infrastructure, Creative Coding, and Maker Practice

Lecturer

This morning session continued the conference’s lightning-talk tradition under the guidance of the same community hosts. Speakers included Mario Munoz, advocating the Advanced Alchemy SQLAlchemy wrapper; Maya Kerostasia, recounting a transition from automotive technician to software developer; Joel Natividad, presenting high-performance metadata generation for data portals; Alex Ambrioso, generating musical permutations with LilyPond; Fay Shaw, analyzing pedestrian-safety data for a Massachusetts community; Anjali Datta, discussing Python’s role in magnetic-resonance imaging; Mylo Dove, extending legacy robotics with local language models; Eric Matthes, demonstrating automated Django deployment; Matt Leaverton, combining CircuitPython with laser-cut fabrication; Tristan Shippen, converting paint splatters into MIDI; and Wenqing Mao (presenting as a high-school researcher), reflecting on patience as a developmental practice. The diversity of backgrounds—from professional software engineering to recent career change and secondary-school research—embodied the inclusive range of the PyCon audience.

Abstract

The Saturday morning lightning talks explored practical database abstractions, non-linear career trajectories, automated data stewardship, algorithmic composition, civic data science, medical imaging pipelines, legacy-hardware revitalization, one-command deployment, physical making with lasers, multimodal creative coding, and the affective dimension of persistent technical work. The sequence illustrates how Python functions simultaneously as professional infrastructure, personal creative medium, and vehicle for civic and educational agency.

Database Abstractions and Career Transformation

Mario Munoz introduced Advanced Alchemy, a framework-agnostic enhancement layer over SQLAlchemy. While Django’s ORM supplies convenient audit columns, primary-key handling, and bulk operations out of the box, developers outside the Django ecosystem often re-implement similar utilities. Advanced Alchemy packages repositories that expose create, update, delete, list, and filtered query methods, together with an Alembic wrapper that reduces migration workflow to a handful of CLI commands. Munoz demonstrated a sports-league management CLI built atop SQLite, showing how the library allowed concentration on domain logic rather than boilerplate. An open-space invitation extended the conversation beyond the five-minute limit.

Maya Kerostasia narrated a trajectory from ASE-certified automotive technician to software developer. While working at a Toyota dealership and later a independent shop, she observed the labor of manually transcribing parts receipts into QuickBooks. Initial attempts to use the QuickBooks XML API proved intractable; instead she scraped O’Reilly Auto Parts pages with Beautiful Soup, stored results in a local database, and eventually exposed a web interface on recycled Linux machines scattered through the shop. The resulting system reduced invoice preparation from roughly thirty minutes to two. Although the interface violated numerous usability conventions and was never commercialized, the artifact served as a portfolio piece that secured first a desktop-support role and, three years later, a full developer position in Pittsburgh. The moral offered was persistence: continuous incremental improvement, even when immediate time savings are elusive, can open unanticipated professional doors.

Data Stewardship, Algorithmic Music, and Civic Sensing

Joel Natividad described a “data refinery” approach to the production of high-resolution metadata for open-data portals. Fifteen years of experience deploying CKAN instances revealed that data quality remains the principal obstacle to reuse. Rather than requiring exhaustive manual cataloging, the system ingests raw files—exemplified by a 520-megabyte, one-million-row 311 dataset—and, within a few seconds, computes dozens of statistical summaries and frequency tables via Polars and related tooling. Configurable Jinja2 expressions then populate CKAN metadata fields, rendering the dataset immediately findable, accessible, interoperable, and reusable. The resulting high-quality metadata also supplies rich context for downstream AI applications. An open-space session was offered for deeper technical discussion.

Alex Ambrioso, a retired mathematics teacher turned piano instructor, demonstrated the generation of melodic permutations with LilyPond, an open-source music-engraving system that treats scores as text. A short Python script enumerates all permutations of a five-note set, emits corresponding LilyPond source, and produces a multi-staff PDF. The same pipeline can assemble more complex multi-part scores once individual voices are supplied. The talk invited musically inclined attendees to explore further combinatorial and generative applications of the text-based score format.

Fay Shaw presented MOSEY, an analysis of pedestrian-crash data for Malden, Massachusetts. Drawing on the Massachusetts Department of Transportation crash portal, Shaw examined temporal and spatial patterns, noting elevated risk for elderly pedestrians at night. The work, motivated by a fatal incident near her home, exemplified the conversion of public administrative data into locally actionable insight and the role of data scientists as civic participants.

Scientific Imaging, Robotics, and Deployment Automation

Anjali Datta addressed the rationale for employing Python in magnetic-resonance imaging pipelines. The talk situated Python’s numerical and visualization libraries within the complex reconstruction and analysis workflows required by modern MRI, underscoring the language’s growing presence in medical imaging research.

Mylo Dove demonstrated the revitalization of a Sony AIBO robotic dog through local large-language models and WebSocket communication. Speech input is processed by an on-device model, responses are generated, and the resulting audio and motion commands are returned to the legacy hardware. The project illustrated how contemporary open-source stacks can extend the useful life of discontinued consumer robotics while preserving privacy by avoiding cloud inference. An open-space invitation accompanied the demonstration.

Eric Matthes introduced django-simple-deploy, a plugin-based system that reduces initial deployment of a Django project to a single management command. After installation of the appropriate platform plugin (Heroku, Fly.io, Platform.sh, or a generic VPS), manage.py deploy --automate-all performs configuration, commits the changes, and pushes the application. A configuration-only mode allows review of generated files before any remote action. The tool thereby removes a perennial friction point for developers under time pressure and establishes a uniform deployment vocabulary across heterogeneous hosting providers. Documentation, an open space, and multi-day sprint participation were offered for further engagement.

Physical Making, Multimodal Creativity, and Affective Practice

Matt Leaverton, employed at Glowforge, combined CircuitPython on a Raspberry Pi Pico with the boxes.py parametric enclosure generator to produce a wearable “Pingu” voice box for his children’s Halloween costumes. Audio playback libraries handled the characteristic vocalizations; laser-cut vector paths produced a durable, child-friendly housing. The project celebrated the continuum from software abstraction to tangible artifact and invited conversation on electronics, fabrication, and playful making.

Tristan Shippen recounted the transformation of a paint-splatter photograph into MIDI. Image-processing steps isolated drips, fitted them to a grid, and mapped spatial coordinates onto pitch and duration. Jupyter notebooks with interactive sliders permitted rapid exploration of thresholds, rhythmic quantization, and scalar constraints. Although the sonic result was aesthetically challenging, the value resided in the construction of an open-ended instrument rather than in any particular output. The talk articulated a maker ethic in which the process of building flexible tools supersedes the consumption of finished products.

Wenqing Mao, a high-school student, closed the session with a meditation on patience. Beginning with an elementary-school infinite loop that temporarily disabled a parental laptop, continuing through reinforcement-learning experiments with AWS DeepRacer, quantum annealing of the traveling-salesman problem, and a year-long ankle-exoskeleton research project presented at the International Science and Engineering Fair, Mao framed repeated failure and incremental adjustment as the essential curriculum. Awards proved secondary to the cultivation of a durable working disposition. The talk offered a generational counterpoint to more senior narratives of career transition and technical mastery, reminding the audience that the same iterative patience underpins both early learning and mature engineering practice.

Across the Saturday morning program, Python appeared as database abstraction, career catalyst, metadata engine, compositional aid, civic sensor, medical tool, robotic interface, deployment automator, fabrication companion, creative medium, and moral practice. The lightning-talk format once again compressed an extraordinary range of human activity into a single hour, affirming the conference’s role as a crossroads of professional, recreational, and civic Python.

Links:

PostHeaderIcon [PyConUS2025] Lightning Talks Friday Afternoon: Community Practice, Creative Tools, and Critical Reflection

Lecturer

This session was hosted by community organizers who facilitated a rapid series of five-minute presentations by conference attendees. The speakers included Rodrigo Girão Serrão, a frequent contributor of educational lightning talks and author of Python-focused writing at mathspp.com; Laís Carvalho, associated with the Humble Data beginner workshops; Cheuk Ting Ho, Python Software Foundation Fellow, Humble Data co-founder, and developer advocate formerly with JetBrains; Quang Vu, a software engineer exploring computer vision for personal skill improvement; Meagen Voss, core team member of the Wagtail CMS project; Will Lachance, presenting solar energy modeling; Amanda Lundberg, addressing live captioning; Thomas Weiss, working with historical weather data for fire risk; Tom Rutherford, examining low-level process creation; Cody Maloney, investigating file-object lifecycle issues in the standard library; Anthony Shaw, Microsoft Python advocate and creator of the CSnakes embedding project; and Trey Hunner, Python Software Foundation Fellow, educator, and founder of Python Morsels. The collective nature of the session reflects the participatory ethos of PyCon lightning talks.

Abstract

The Friday afternoon lightning talks at PyCon US 2025 assembled a diverse sequence of short presentations that spanned pedagogical advice, beginner education, practical tooling, hobbyist computer vision, web-application failure modes, environmental modeling, accessibility practice, scientific data pipelines, language runtime internals, resource management, cross-runtime interoperation, and ethical reflection on emerging technologies. Taken together, the talks illustrate how the Python community simultaneously cultivates entry-level participation, technical craftsmanship, and critical awareness of systemic consequences.

Cultivating Participation and Beginner Pathways

Rodrigo Girão Serrão opened the session with a meta-presentation on the craft of lightning talks themselves. He emphasized that the format’s five-minute constraint, combined with stage lighting that often obscures the audience, lowers the barrier for first-time speakers. Content need not be restricted to Python; prior memorable talks had covered beer, music, puzzles, and vocal exercises. Practical guidance included sparse slides with large fonts, awareness of the hosts’ escalating applause cue, and the primacy of personal enjoyment as a predictor of audience engagement. The talk functioned both as invitation and as modeling of the form it advocated.

Laís Carvalho followed with an invitation to the Humble Data workshop, a Hatchery-program offering scheduled for the following Sunday. Humble Data provides structured, notebook-based introductions to Python and data-science fundamentals—Jupyter, pandas, matplotlib—for absolute beginners. Carvalho noted that the workshop had been delivered internationally and that completion of even a single notebook would be rewarded with conference swag. The presentation underscored the conference’s commitment to lowering technical thresholds and expanding the circle of participants who feel entitled to contribute.

Cheuk Ting Ho then addressed a lighter but recurrent conference phenomenon: the accumulation of sponsor swag. Drawing an analogy to Untappd, the beer-review application, Ho described Oscar Swag (a playful coinage), a web service that allows attendees to photograph, catalog, comment upon, and rate free merchandise. Built rapidly with the assistance of generative tools and hosted at a personal domain, the project demonstrated both the ease of contemporary web development and the social value of shared knowledge about durable versus ephemeral conference gifts. The talk illustrated how informal community tooling can emerge spontaneously from shared experience.

Technical Craft, Hobbies, and Runtime Awareness

Quang Vu presented a computer-vision pipeline developed to improve personal archery form. Consistency of body position matters more than absolute accuracy; therefore Vu employed recent Meta models (SAM and related segmentation networks) to isolate the archer’s silhouette, compute centroids, and align video frames despite changes in clothing or camera angle. Pixel-wise comparison proved brittle; segmentation-based alignment proved more robust. Remaining limitations—centroid precision, model sensitivity to rear viewpoints, temporal alignment of differing motion speeds—were candidly acknowledged, and the speaker invited collaboration. The project exemplified the transfer of professional computer-vision techniques into recreational skill acquisition.

Meagen Voss recounted a production incident on a personal Wagtail CMS site. Insertion of an animated goat GIF, intended as humorous illustration of the “testing goat” metaphor from Harry Percival’s test-driven-development literature, exhausted the memory of a modest DigitalOcean droplet running Gunicorn and Nginx. The administrative interface became partially inaccessible. Diagnosis revealed that the image-processing pipeline, combined with limited RAM, produced cascading failures. The anecdote served as a cautionary tale about resource assumptions in content-management systems and as an advertisement for Wagtail’s subsequent evolution and its upcoming virtual conference.

Will Lachance described a model for estimating solar-panel energy yield. Using historical irradiance and weather data, the system produced hourly forecasts and visualized expected production. The project’s modest computational cost and the speaker’s willingness to open the code illustrated the accessibility of domain-specific scientific computing within the Python ecosystem.

Amanda Lundberg’s talk, “Captioner is Human,” highlighted the labor of live captioning. The presentation reminded the audience that the service is performed by skilled humans rather than fully automated systems, reinforcing the ethical and practical necessity of supporting professional captioning at technical events.

Thomas Weiss demonstrated a predictive model for fire-weather conditions drawn from historical Remote Automated Weather Station (RAWS) data. Features such as temperature, relative humidity, and wind were used to flag stations meeting critical thresholds. The system ran at negligible cost and updated hourly, showing how publicly available environmental data can be operationalized for public-safety awareness.

Tom Rutherford examined the semantics and hazards of os.fork. Prior to recent Python versions, the default process-creation method on POSIX systems copied the parent’s address space while leaving only the forking thread alive in the child. Active locks or other thread-local state therefore produced deadlocks. The progressive deprecation of fork as default—first on macOS, later universally—reflects a deliberate prioritization of safety over the convenience of shared memory. Rutherford’s examples clarified why production codebases had long avoided the construct and why the language is migrating toward spawn-based isolation.

Cody Maloney reminded the audience of the necessity of closing file-like objects. A community-reported bug triggered by a gzip write into a BytesIO under Python 3.13 exposed an older reference cycle introduced when buffered writers were adopted for performance. The cycle caused the buffer to be closed before residual data were flushed, producing an exception only after a diagnostic print was added. Subsequent point releases repaired the cycle, and Python 3.14 will emit an explicit warning for unclosed gzip objects containing unwritten data. Maloney advocated the consistent use of context managers and, where appropriate, the higher-level pathlib helpers that encapsulate correct resource management while also enabling future performance optimizations.

Interoperation, Ethics, and Systemic Thinking

Anthony Shaw presented CSnakes, a project that embeds a Python interpreter inside .NET processes. Motivated by the comparative scarcity of mature machine-learning libraries in the C# ecosystem, CSnakes uses static builds of Python, parses type-annotated Python functions, and generates corresponding C# bindings. Complex signatures—including generators of nested tuples—are automatically marshaled. Asynchronous Python functions become awaitable C# methods, and free-threaded Python is supported so that .NET thread-pool workers can invoke Python concurrently. The demonstration with Hugging Face Transformers illustrated how a few hundred lines of generated C# can expose sophisticated Python pipelines as ordinary .NET methods, lowering the cost of polyglot architecture.

Trey Hunner closed the session with a comparative reflection on large language models and industrial animal agriculture. Both domains exhibit substantial negative externalities—environmental, health-related, and ethical—yet neither is likely to disappear through individual abstention alone. Systemic problems, Hunner argued, require systemic remedies rather than moralized individual restraint. The talk cautioned against gatekeeping rhetoric that shames tool users and invited the community to channel critical energy toward institutional and regulatory change. The analogy, deliberately provocative, reframed heated debates about generative AI as questions of collective design rather than personal purity.

Collectively the Friday lightning talks demonstrated the breadth of activity that five minutes can contain: pedagogical invitation, tool building, personal instrumentation, failure analysis, scientific modeling, language-runtime vigilance, cross-language embedding, and ethical systems thinking. The session itself modeled the participatory culture it celebrated.

Links:

PostHeaderIcon [PyConUS2025] Rediscovering Play as an Antidote to Burnout: Lynn Root

Lecturer

Lynn Root is a Staff Engineer at Spotify and tech lead on the company’s machine-learning and artificial-intelligence platform. She serves as Chair of the PyLadies Global Council, is a former Director and current Fellow of the Python Software Foundation, and is a member of the Django Software Foundation. Root founded the San Francisco chapter of PyLadies and maintains the open-source package interrogate, which measures docstring coverage. She is an adjunct professor in the Industrial Engineering and Operations Research department at Columbia University’s Graduate School of Engineering, where she teaches Python. An active speaker on distributed systems and developer tooling, she describes herself as an “engineer’s engineer.” Outside of work she cultivates houseplants, plays bass guitar, and pursues knitting projects. Her professional site is roguelynn.com and her GitHub handle is econchick.

Abstract

Lynn Root reflects on personal burnout and the cultural pressures that equate adulthood with the abandonment of play. Drawing on developmental psychology, ethology, and historical anecdote, she argues that play—defined by process orientation, self-direction, flexible rules, imaginative framing, and a relaxed yet alert mental state—is essential for resilience, creativity, and social bonding across the lifespan. Through concrete personal practices—skydiving, a hundred-day painting project, and participation in an employee cover band—Root demonstrates how deliberate reclamation of play can restore joy and counteract the exhaustion produced by relentless productivity demands.

The Cultural Myth of Adulthood and the Definition of Play

Root begins with a vivid personal image: being pushed from an airplane over New Zealand. The photograph, she explains, conceals the exhaustion that preceded it. Months earlier, seated in a middle seat on a long-haul flight, she experienced an abrupt emotional collapse—tears triggered by a trivial oversight of a flight attendant yet rooted in deeper disconnection from self and from joy. The episode was not ordinary burnout but “bone-deep exhaustion.”

The proximate cause was professional overextension following promotion to staff engineer. Root had become the internal authority on Python, shepherded numerous projects into open source, and still felt compelled to protect team capacity by expanding her own working hours, often arriving before seven in the morning. Earlier, she had cancelled a conference appearance in Russia because of an overwhelming desire simply to be home with her cat, an act that left residual shame.

Root situates these experiences within a pervasive cultural narrative that treats childhood as mere preparation for adulthood and play as disposable filler. Adolescents internalize the demand to become “well-rounded” and productive; Root herself once declared to her mother that she could not wait to grow up so she could pay her own bills—an emblem of independence that adulthood rapidly complicated. A quotation from C. S. Lewis crystallizes the insight: the frantic desire to appear grown-up is itself a mark of immaturity. True maturity includes the capacity to embrace paradox, imagination, and “second naïveté”—a stage in which adults reclaim the wonder they once discarded.

If childhood is preparation, Root asks, why do so many well-adjusted adults exhibit bitterness, anxiety, depression, and creative atrophy? An alternative framing is more accurate: adults are atrophied children who have unlearned play in the pursuit of seriousness. Contemporary slang—“adulting,” “I can’t adult today”—reveals that competence often feels like a costume rather than an authentic state.

Play itself is rigorously defined by psychologist Peter Gray of Boston College through five features. First, play is process-oriented; the goal is the activity, not an external product or victory. Second, it is self-chosen and self-directed; external compulsion converts it into work. Third, it possesses rules, yet those rules are flexible, negotiated, and revisable by the players. Fourth, it is imaginative, operating in the realm of “what if.” Fifth, it occurs in a mental state that is both relaxed and alert—the optimal zone for risk-taking and learning without paralyzing fear of failure.

These features are observable across mammalian species. Young animals deliberately expose themselves to controlled fear and excitement, acquiring motor skills, emotional regulation, and social competence. Animals deprived of play become fearful, aggressive, or socially inept. Human play is simply an extreme elaboration of the same adaptive mechanism, producing cooperative, resilient, and inventive adults.

Historical Sparks, Animal Intelligence, and Personal Recovery

Play has repeatedly catalyzed scientific advance. Luke Howard, a nineteenth-century chemist and member of a London debating society that fined members who failed to present papers, improvised a classification of clouds rather than pay the penalty. Employing Latin terms—stratus, cumulus, cirrus—he inadvertently founded modern meteorology. A contemporaneous French attempt by Jean-Baptiste Lamarck that named clouds after vegetables was ignored, partly because of political disfavor. The episode illustrates that playful improvisation, rather than solemn intentionality, often produces lasting knowledge.

Corvids display analogous capacities. A widely circulated video shows a crow repeatedly sliding down a snowy roof on a plastic lid, adjusting its starting position after failed attempts. The behavior yields no caloric or reproductive reward; it is pure exploration of friction and tool use—unrewarded object exploration that nevertheless builds physical and cognitive skill. Crows further demonstrate rule-guided decision-making, tool manufacture, numerical competence, and even an understanding of grammatical recursion. Playfulness and intelligence are therefore mutually reinforcing.

Root’s own recovery followed the same logic. Skydiving supplied an initial jolt of freedom, yet sustained restoration required ongoing, low-stakes practices. She joined a hundred-day creative project, producing a daily watercolor without any intention of improvement or sale. Early efforts were aesthetically poor; gradual accumulation of process yielded both technical progress and genuine pride in self-directed making. Subsequently she resumed playing bass guitar—abandoned since high-school orchestra—and joined a Spotify employee cover band called Fake Muse. The band set its own repertoire, aesthetics, and performance rules; the experience was defined by enjoyment rather than professional aspiration. Practice nights, the presence of supportive friends, and an eventual personal relationship with the band’s drummer illustrated the social and affective returns of play.

Root emphasizes that recovery was not achieved by intensifying productivity, optimizing habits, or “adulting” more rigorously. It emerged from successive layers of activity whose only purpose was joy. Each form of play scaffolded the next, gradually restoring connection to self. She therefore advocates a personal ethic: play before promotion, before perfection, before process, and before panic. Cultural injunctions to abandon play are, in her view, simply nonsense.

A closing anecdote from Kurt Vonnegut underscores the stance. Vonnegut insists on purchasing a single envelope in person rather than ordering a bulk package online, precisely because the errand affords encounters with strangers, babies, fire engines, and dogs. The moral, in his phrasing, is that “we are here on Earth to fart around.” Legacy is measured not in commits or promotions but in moments of pure presence, the joy created, the connections fostered, and the play dared despite every message urging seriousness.

Root concludes by inviting the audience to reclaim that permission and to enjoy the remainder of the conference in the same spirit.

Links:

PostHeaderIcon [PyConUS2025] Enshittification and the Path to a New Good Internet: Cory Doctorow

Lecturer

Cory Doctorow is a science fiction author, activist, journalist, and special advisor to the Electronic Frontier Foundation. He maintains the daily blog Pluralistic.net and has authored numerous works, including the recent novels Picks and Shovels and The Bezzle (sequels to Red Team Blues), the solarpunk novel The Lost Cause, and the nonfiction volume The Internet Con: How to Seize the Means of Computation. Earlier books encompass the Little Brother series, Chokepoint Capitalism, Red Team Blues, and How to Destroy Surveillance Capitalism. Doctorow co-founded the UK Open Rights Group, serves as a MIT Media Lab Research Affiliate and Visiting Professor of Computer Science at the Open University, and holds a Visiting Professorship of Practice at the University of North Carolina’s School of Library and Information Science. Born in Toronto, he resides in Los Angeles. He was inducted into the Canadian Science Fiction and Fantasy Hall of Fame in 2020, received the Sir Arthur Clarke Imagination in Service to Society Award in 2022, the Neil Postman Award for Career Achievement in Public Intellectual Activity in 2024, and honorary doctorates from York University and the Open University. His professional site is craphound.com and his X handle is @doctorow.

Abstract

Cory Doctorow examines the concept of enshittification—the progressive degradation of digital platforms—and situates it within broader economic, legal, and technological structures. Drawing on examples ranging from nursing labor apps to Google search, he argues that platform decay arises not from technological inevitability or novel forms of corporate malice but from deliberate policy choices that dismantled four traditional disciplining forces: competition, regulation, interoperability, and labor power. Doctorow contends that reversing these choices can restore a functional digital commons and enable a “new good internet” capable of supporting collective resistance to larger crises.

The Anatomy of Enshittification and the Mechanism of Twiddling

Doctorow opens by redirecting expectations away from a conventional critique of online platforms toward an unexpected domain: nursing labor. A January 2025 report from the Groundwork Collective documented the rise of three dominant “Uber for nursing” applications—ShiftKey, ShiftMed, and CareRev—that allocate shifts through opaque algorithmic pricing. Before offering a wage, these platforms purchase a nurse’s real-time financial data from brokers. Nurses carrying substantial or delinquent credit-card debt receive systematically lower offers because desperation reduces reservation wages. Doctorow presents this practice as paradigmatic of enshittification: a three-stage process in which platforms first court end users with high-quality service while locking them in, then degrade the user experience to extract value for business customers, and finally extract remaining surplus for themselves until only a minimal residual value keeps both sides attached.

He illustrates the sequence with Google. In its early years the company minimized advertising and invested heavily in engineering, producing superior search results while simultaneously purchasing default placement across browsers, operating systems, and carriers—expenditures that eventually rivaled the cost of acquiring an entire Twitter every eighteen months. Once users were locked in, Google increased the proportion of advertising and rendered ad labels ever more subtle, enriching publishers and advertisers at the expense of searchers. When growth plateaued at roughly 90 percent market share, internal documents revealed a deliberate decision to degrade result quality so that users would issue multiple queries, thereby multiplying ad impressions. Concurrently Google entered collusive arrangements such as “Jedi Blue” with Meta to rig advertising markets against publishers. The contemporary search results page—dominated by AI-generated material, barely labeled advertisements, and SEO spam—exemplifies the terminal stage of enshittification: a “homeopathic residue” of utility sufficient only to prevent mass defection.

The technical enabler of these shifts is what Doctorow terms “twiddling.” Because modern platforms rest on Turing-complete machines, they possess effectively infinite adjustable parameters. Prices, rankings, recommendations, and wages can be altered on every interaction according to real-time data. Algorithmic wage discrimination, the term coined by legal scholar Veena Dubal, is merely one instance of twiddling applied to labor markets. Uber pioneered a similar technique with drivers: initially elevated offers induce acceptance of rides; subsequent micro-adjustments gradually erode compensation below sustainable levels once drivers have incurred sunk costs such as vehicle purchases. Digitization converts what would have been prohibitively labor-intensive wage theft into an automated, low-cost process.

Doctorow rejects the popular maxim that “if you are not paying for the product, you are the product.” Payment confers no protection. Apple’s simultaneous introduction of a third-party tracking opt-out and a secret first-party advertising surveillance system demonstrates that even customers who pay a premium can be productized. In the nursing example, nurses, patients, and hospitals are all subject to extraction. Enshittification productizes anyone who can be productized; dignified treatment is not a loyalty perk exchanged for money rather than attention.

Policy Origins and the Collapse of Disciplining Forces

Platforms were not born enshittified. Early Google, the original iPhone, and early Facebook delivered genuine value. Doctorow insists that the transformation resulted from policy decisions enacted within living memory by identifiable actors who were warned of the consequences yet faced no subsequent accountability. These decisions dismantled four constraints that once moderated corporate behavior.

The first constraint is market competition. Classical antitrust, exemplified by Senator John Sherman’s 1890 legislation, sought to prevent the emergence of “autocrats of trade.” Beginning in the 1980s, Chicago-school economics inverted this logic, treating monopolies as presumptively efficient. The result was concentrated markets across pharmaceuticals, hospitals, insurance, beer, athletic shoes, and professional wrestling. Mark Zuckerberg’s internal memo that “it is better to buy than to compete,” followed by the unchallenged acquisition of Instagram, exemplifies the new orthodoxy. Hospital consolidation, itself a defensive response to pharmaceutical mergers, left nurses and patients exposed to monopsonistic power and algorithmic wage platforms.

The second constraint is regulation. Concentrated sectors readily capture their regulators. A sector of one hundred firms is a rabble; a sector of five is a cartel capable of coordinated lobbying. Doctorow cites the United Kingdom’s Competition and Markets Authority, previously an effective investigator of technology monopolies, whose leadership was replaced by a former Amazon executive. In the United States, the last comprehensive federal privacy statute dates to 1988—the Video Privacy Protection Act—leaving data brokers free to sell financial dossiers that enable wage discrimination against nurses.

The third constraint is interoperability. In the physical world, interoperability requires careful standardization; in software it is nearly free because any valid program can be executed. Ad blockers, alternative ink cartridges, and tools that reveal hidden tips for DoorDash drivers are all forms of adversarial interoperability that discipline platforms. The 1998 Digital Millennium Copyright Act’s Section 1201, however, criminalizes the circumvention of access controls, converting reverse engineering into a potential felony. Parallel anti-circumvention provisions were exported through trade agreements to Europe, Canada, and elsewhere. Consequently, apps—websites wrapped in digital rights management—became preferred over open web interfaces, and independent repair of tractors, ventilators, and automobiles became legally hazardous.

The fourth constraint is labor power. Technology workers historically enjoyed scarcity-based leverage without formal unionization. They could refuse to implement degrading features and simply change employers. Mass layoffs since 2023—half a million jobs—and simultaneous executive bonus increases have eroded that leverage. The current enthusiasm for AI coding tools is, in Doctorow’s view, driven less by productivity gains than by the prospect of replacing workers who might otherwise resist enshittification.

Pathways Out of the Enshittocene

Because enshittification is the product of specific policy choices rather than technological destiny or inevitable historical forces, those choices can be reversed. Doctorow surveys an emerging global antitrust revival that is largely bipartisan and independent of billionaire funding. The European Union’s Digital Markets Act and Digital Services Act, parallel statutes in Australia, Japan, South Korea, and even China, and coordinated enforcement actions demonstrate renewed vigor. Market studies produced by one jurisdiction are readily adapted by others, creating a multiplier effect.

Regulatory capture can be mitigated by shifting enforcement away from captured national venues (for example, moving GDPR claims out of Irish courts). Right-to-repair legislation in Europe and Canada remains partially frustrated by residual anti-circumvention rules, yet the political opportunity now exists to repeal those rules. Doctorow argues that any jurisdiction willing to legalize reverse engineering, jailbreaking, and independent app stores would instantly become a technology export powerhouse. A Canadian app store charging a three-percent transaction fee rather than thirty percent would raise authors’, musicians’, and software developers’ revenues by roughly twenty-five percent overnight. Diagnostic tools priced at one hundred dollars per month rather than ten thousand dollars per manufacturer would attract global demand. The resulting competition would simultaneously lower costs for users worldwide and attack the most profitable lines of business of the largest American technology firms.

Doctorow situates these technical and legal interventions within a larger polycrisis—climate change, authoritarianism, genocide, and xenophobia—whose perpetrators have weaponized centralized platforms. The “insidete” was purpose-built for such co-option: giant corporations willing to trade a habitable planet for modest tax advantages, default algorithmic feeds, and government-backed intellectual-property barriers to exit. Yet the architecture was chosen, not inevitable. A new good internet combining the technical self-determination of the early web with the accessibility of Web 2.0 services remains possible. Such an internet would enable coordination and mutual aid in the face of cascading crises. Doctorow closes with the injunction that the community must build it.

Links: