1. I Think Rutger Bregman & the School for Moral Ambition Are Full of Shit

    Mon 08 June 2026

    Disclaimer: I'm just a random person on the internet and this article is my personal opinion. This article was written without AI.


    The first time I heard from Rutger Bregman was due to his remarks at Davos about taxing the billionaires. His speech went viral and I was rooting for him. Later on he got to troll Tucker Carlson about Carlson being a millionaire working for billionaires. Absolutely fantastic.

    A few books in, Bregman started the School for Moral ambition in 2024. Although he is a co-founder, he seems to be face of this non-profit organisation, doing a lot of high-visibility interviews and he's the author of the book "Moral Ambition".

    The idea behind the School for Moral Ambition (SMA) is quite simple: use your talent to address the world's biggest problems. To paraphrase: "don't become a consultant at McKinsey but do something more valuable and worthwhile with your talent". The argument is similar to what Steve Jobs said to John Sculley: "Do you want to sell sugar water for the rest of your life, or come with me and change the world?"

    It sounds all very noble, but I've become a skeptic for multiple reasons.

    Bregman rubbed me the wrong way in the last podcast episode of the "De Rudi & Freddie Show" in 2024. He confronted co-host and award-winning investigative journalist Jesse Frederik and openly questioned if his work really made a difference. Bregman implicated that Frederik could do other things that would be much more effective and be more impactful than his investigative journalism (I'm paraphrasing here).

    I'm absolutely comfortable with questions like these, although it can feel confrontational. Yet I really felt it came from a somewhat righteous and smug moral superiority. I felt this way because I haven't seen any evidence1 that SMA has done anything of substance that warrants all the money involved.

    Bregman drank the AI cool-aid

    Now I already learned that Bregman was really enamoured with AI, and I'm absolutely not, for the usual reasons. That said, fast forwarding to today, I truly believe he has lost the plot, and this recent video (June 2026) is evidence of it.

    He is comparing skepticism of artificial intelligence with climate change denial or climate skepticism. He sees AI as a tool that is beneficiary, just not in the hands of billionaires but in the hands of governments (as I understand it). He believes that AI will create an utopia where people can actually work less hours as Keynes 'wrongfully' predicted

    Unfortunately for Bregman, as far as I can tell, there is no (scientific) evidence that AI is actually capable of having such a huge impact. Meanwhile compare this to the mountains of evidence for human-caused climate change, it would be a different story. I would expect a different argument from a former journalist. To reiterate: the case for climate change is rooted in a vast body of scientific research. The case for AI creating a 15-hour work week seems mostly backed by wishfull thinking.

    I feel that Bregman isn't really aware of his own biases, fuelled by his own personal experience using AI. He paints all the AI critics as 'luddites'2 and that AI-skeptics are on the wrong side of history, just as the climate deniers are. Comparing AI skeptics to climate change skeptics feels like a cheap rhetoric trick that doesn't do justice to the criticism and skepsis surrounding AI.

    Bregman also believes that stopping AI or 'shutting it down' doesn't make sense. Because if we shut AI down in our countries, other countries or regimes will build AI and get an advantage over us (he shows China as an example). The age old "if we don't, somebody else will", that has excused bad behaviour for all of eternity.

    The reality is that voters and the larger public never had any say how this AI technology is deployed. That we take into account the impact on communities, people, the use of energy and other resources. We never had any say in this. The entire AI-push seems anti-social, anti-democracy.

    Yes, the companies now pushing AI upon us are so huge and valued so high they are dwarfing the GDP of entire nations within Europe as Bregman suggests. Yet, I think there is strong evidence these numbers are not real. I sense such a lack of critical thinking and healthy skepticism about his own claims. He is dismissing the work of people like Ed Zitron who has unearthed a ton of evidence that AI doesn't deliver (or not nearly as much as is widely claimed) and there's a bubble that may collapse at some point. As I see it, Bregman only has a well-produced narative, but nothing more: it seems pure rhetoric.

    And then I learned something about SMA that made me really disappointed.

    The School for Moral Ambition took money from Bill Gates

    Bregman has been quite positive about Bill Gates contributions to society, mainly pointing at his work on fighting malaria. Unfortunately, it seems that Bregman has not done his due diligence about Bill Gates and his foundation.

    Fortunately, Tim Schwab - an investigative journalist - has investigated the Bill Gates foundation and the result has been documented in the book "The Bill Gates Problem: Reckoning with the Myth of the Good Billionaire". In this book, Schwab has demonstrated how problematic Bill Gates and his foundation really is. Remember that Bill Gates had deep ties to Jeffrey Epstein, which was cited by his ex-wife as a reason to file for divorce.

    Tim Schwab had contact with Bregman about this and I think it doesn't look good for Bregman. It's really bad for a former journalist to cite a source as evidence for Bill Gates good work that has financial ties to Gates. Schwab repeatedly tried to contact Bregman about this, but got the statement through Bregman's agent Anne Strunk:

    “He’s not a fan of your style of journalism, which seems grounded in bad faith instead of curiosity,” Strunk noted in an email.

    When Schwab wrote his article in 2025, it wasn't known that Bregman and his School for Moral Ambition was funded in part by Bill Gates, Schwab discovered this by accident. (It's now disclosed on the website at the bottom).

    bill gates funds the school for Moral ambition

    Now for the life of me, I can't fathom boasting about moral ambition and accepting money from Bill Gates. I just can't. And they know it looks bad because if an organisation omits (at first) mentioning receiving funding from Bill Gates, you know they know how bad that looks. Lying by omission.

    If SMA had any actual moral ambition, I think it would have been a cooperative. (Now it's just a typical hierarchical and opaque organisational structure with the 'owners' including Bregman, at the top.) I would expect that this organisation would also be extremely transparent where the money is spent on exactly. The impact report didn't really clarify anything for me. It's all testimonials, stories and anecdotes.

    It gets so much worse

    My jaw dropped when I read this article by Anita Naidu. I learned that Dutch journalist Marieke Kuypers discovered that the USA branch of SME runs out of the offices of crypto billionaire Mike Novogratz and that Novograt's sister sits on the SMA's board. Mike Novogratz donated a milion dollars to Trump.

    At this point, I think that both Bregman and SME are absolutely unredeemable.

    Accusations of racism and elitism

    In interviews I've noticed that Bregman talks a lot about 'talented' people. For him, talented people are highly educated people. To get a fellowship with SMA, there are all kinds of criteria a candidate needs to hit and one of them is academic credentials, work experience and so on.

    A picture does arise of a very elitist, and also tightly controlled organisation where the founders determine - based on criteria they pulled out of thin air - if you are a good candidate or not. And they alone decide what is moral, which topics should be spend time and effort on.

    This is what Anita Naidu articulates in an article from 2025 where she states:

    Let’s be clear about who it’s built for. SMA isn’t for people organizing at the grassroots, risking safety to confront systems of oppression. It’s for the already credentialed: Ivy League grads, McKinsey consultants, social entrepreneurs. People groomed to lead—just not to surrender power. The School doesn’t ask them to reckon with injustice. It teaches them how to perform reckoning without threatening their position.

    She continues later on:

    Instead of interrogating capitalism, colonialism, or white supremacy, SMA asks: how can we make these systems feel more ethical? How can we reframe domination as duty? Structural violence becomes a backdrop for personal growth. Justice becomes self-improvement. Revolution becomes résumé fodder.

    Meanwhile, Payal Arora wrote a critical piece on Bregmans article (an adapted excerpt from his book 'Humankind' ) written in 2020. She critisizes Bregman for simplifying the story, leaving out important context about colonialism and racism, showing that the story is actually a counter-example to his hypothesis that people are good by nature3.

    According to Payal in this article, because of her criticism, she got into a 'twitter war' with Bregman about her criticism.

    I also found a critical article and a follow up article from (yet again) Tim Schwab about how Bregman handled the uncovering and critique on hist past racist remarks about Rihanna.

    Closing words

    At this point I can only ask the reader not to get involved with the School for Moral Ambition as I think SME isn't moral at all. I believe there is nothing of substance to SME and I don't see anything tangible this organisation has achieved with the money spent.


    Disclosure: I have no affiliations with tobacco producers or processors, I'm not a wealthy person trying to evade taxation and I'm also not in any way affiliated with food or meat production. In short, SMA isn't working on anything that would affect me personally in a negative way.


    1. Objectively verified by independent trusted third-parties 

    2. The luddite story was never about the technology itself, but the actual social context and impact, as is with AI. 

    3. not to say that this proves if people are good by nature or not, just that the story doesn't support Bregmans narative. 

    If you have any comments email me, see the About page for contact details.
  2. DNS Is for People - Not for IT Infrastructure

    Wed 03 June 2026

    The Domain Name System exists because it's difficult for people to remember IP addresses (185.15.59.224) and much easier to remember domain names (wikipedia.org).

    Regarding internet-accessible services, it makes sense to publish websites, API endpoints or similar services using DNS, as people have to interfact with them. The added benefit of a domain name is that the associated IP address can change without the client being affected.

    This article isn't against DNS for public services, but it questions if we should use DNS for internal IT infrastructure (independent of cloud vs. onprem)

    It's always DNS

    Although DNS can be a very beneficial service, it can also become a liability. If you want a reliable system, you want as little components as possible. Every additional component adds a potential risk of failure. In addition, more components may create unforeseen behaviour and interactions that can cause outages (circular dependancies, and so on). If you can avoid adding components, you'll have a better chance of building a reliable system.

    Within the IT operations space, DNS has made a bit of a name for itself. Many may remember this little haiku.

    It’s not DNS
    There’s no way it’s DNS
    It was DNS
    

    (source)

    There are multiple(1) high-profile(2) incidents where DNS was involved. In these linked cases, the root-cause of the incident isn't the DNS system itself. Yet, because the root-cause affects the DNS service - which is in the critical path for virtually all services - the incident has such a huge impact.

    The Facebook / Meta outage was so significant because it locked people out of buildings (physical access) due to 'circular' dependancies on DNS being available. Again, it can be said that the circular dependancy is the root-cause, but the blast radius of DNS is in many cases so enormous that it may be difficult to have a clear end-to-end picture of potential risk.

    The case against DNS for internal IT infrastructure

    From the perspective of IT operations, DNS has a drawback: DNS clients cache DNS records based on TTL. Different DNS client implementations can behave differently, but even if you have a fairly homogenous environment, the only way to assure clients (in this case other servers) use the updated IP address, is to control them and force a DNS refresh.

    That got me thinking, why would we use DNS for infrastructure services? It isn't necessary for machine-to-machine communication. Instead of configuring domain names that may not resolve, we can just directly inject the appropriate IP address(ess) into configuration files. It's easy to configure systems with tools like Ansible or pyinfra at scale.

    The counter argument could be that DevOPS / platform engineers are also humans, and it's much easier to spot misconfigurations or to troubleshoot if domain names are configured Instead of IP addresses.

    Fortunately, we still have /etc/hosts, which we can easily provision. Still no DNS service required! This way, we can configure domain names and pretend to use DNS. I also suspect that DNS queries against /etc/hosts are quite responsive.

    DNS as generic security risk

    As of today, most network traffic is encrypted by default, or tunneled through an encrypted channel. DNS is - by default - the exception. Regarding internal IT infrastructure (cloud or 'onprem'), the network may be considered as a secure environment. An attack on the DNS service, spoofing packets, and so on, can be very disruptive though. Setting up DNSSEC may alleviate this problem, but that also introduces another administrative burden with it's own risk of misconfiguration. It's yet another layer of complexity. And we assume that internal infrastructure supports DNSSEC.

    DNS as an Egress Exfiltration risk

    Because egress filtering (filtering of outbound connections) can be cumbersome, it's often omitted, because the systems involved are 'trusted'. This is unfortunate as this makes life easier for an attacker. Any kind of resource required for an attack can be acquired on the vulnerable system with a simple outbound query towards the internet. Proper egress filtering of network traffic can be the difference between a succesfull and unsuccessful hacking attempt.

    A lack of egress filtering also makes it much easier for an attacker to exfiltrate data. And the thing is: any IP protocol can be used to exfiltrate data, including DNS1.

    This is how: the attacker gets a domain runs their internet-accessible authoritative nameserver for this domain. Now the attacker can make DNS requests to said domain like sensitivedata.evil.domain from the hacked system and you can extract all the data from the rogue DNS server logs2.

    Although a hacked server may not be able to directly interact with the attacker-controlled DNS server, by issuing DNS requests for the attacker-controlled domain, these requests will pass the local forwarding DNS server and be forwarded towards the attacker-controlled authoritative DNS server. See also tools like dnscat2 or iodine

    Due to this risk, there is a case to be made, to - at least - not allow systems to query public DNS records. As servers may need to interfact with services on the internet (update servers, APIs, and so on), such access can be facilitated by a proxy server using allow-listed domains.

    Evaluation and closing words

    In the end, everything is a tradeoff, where people must balance benefits and drawbacks against the context of their infrastructure, their particular risk appetite and even organisational structure and culture.

    That said, I think it's reasonable to explore if DNS can be avoided altogether within the IT infrastructure to increase reliability and robustness.

    Feel free to share your thoughts and feelings about this if you feel so inclined. Maybe leave a comment on the Hacker News thread.

    Postscript on HN response (update)

    Update: I do find the responses on the HN thread very interesting from an antropological perspective. How people respond and what implicit assumptions they make. One thing that I found interesting is how many people implicitly assume an environment is 'kubernetes-like', and they focus on 'service discovery'. Problems do arise if you have many IP address mutations for your infrastructure, especially at scale. Because I was thinking about very old-fashioned virtual machine or bare-metal style environment at a small to medium scale (a scale that is much more common I believe, most environments aren't Facebook/Google or even 1/100000 that size).

    I realised that I should have given more context in this article, under which conditions I think my 'DNS alternative' could work well and acknowledge where it would not. Anyway, acknowledging my fault for not creating enough context, I do find the knee-jerk responses, hostility and sometimes personal attacks curious. Only very few* people seem to pause, stay calm, think about my article, and acknowledge that it could work, within specific circumstances. Also many skipped a core part of the article which was thinking about risk and complexity, in some sense it wasn't only about DNS.

    I also just realise that I made a very important mistake. Servers hosting applications don't need DNS resolving for the internet. I got a feeling from some responses that I was proposing that /etc/hosts would be updated with thousands of DNS records for external internet-facing services. I was only talking about internal infrastructure where internal services, like other servers, or NTP, SMTP, or whatever is configured. I think I did address this assumption in the article, but not nearly explicitly enough.


    1. Don't forget about services like NTP or ICMP. 

    2. I have demonstrated this attack using this exact method with a domain I own for a customer that thought they had properly prevented egress traffic, including blocking NTP and ICMP. 

    If you have any comments email me, see the About page for contact details.

Page 3 / 115