{
    "version": "https://jsonfeed.org/version/1.1",
    "title": "Weekly Retro  dade",
    "description": "  Weekly Retro  dade",
    "home_page_url": "https://0xda.de/",
    "feed_url": "https://0xda.de/tags/weekly-retro/index.json",
    "language": "en",
    "authors": [
        {
            "name": "0xdade",
            "url": "https://0xda.de",
            "avatar": "https://0xda.de/img/dade-transparent-logo.png"
        }
    ],
    "items": [
        {
            "title": "Weekly Retro 2025-W17",
            "date_published": "2025-04-28T10:06:41-07:00",
            "date_modified": "2025-04-28T10:48:06-07:00",
            "id": "https://0xda.de/blog/2025/04/weekly-retro-2025-w17/",
            "url": "https://0xda.de/blog/2025/04/weekly-retro-2025-w17/",
            "content_html": "\u003cp\u003eIt\u0026rsquo;s been a very eventful time since my last retro. I went home and spent some time with my family and had a good time getting to have a family holiday meal for the first time in several years. But I also found out the company I\u0026rsquo;ve been working at is being acquired, and this has me feeling some type of way.\u003c/p\u003e\n\u003cp\u003eSo let me tell you a little bit about my first startup experience.\u003c/p\u003e\n\u003ch2 id=\"it-was-a-liquidity-event-just-not-for-me\"\u003eIt was a liquidity event, just not for me\u003c/h2\u003e\n\u003cp\u003eSo this was my first time working at a startup. Today is even my 4 year anniversary at the company, and it\u0026rsquo;s generally been great. I\u0026rsquo;ve accomplished a lot, I\u0026rsquo;ve grown a lot as an engineer and as a lead. I\u0026rsquo;ve gotten to work with very talented engineers and worked on a wide range of things that I had basically never worked on before. My team has been absolutely fantastic and my boss has been the best I\u0026rsquo;ve had in my career.\u003c/p\u003e\n\u003cp\u003eI was in it for the long haul. I specifically said I was interested in more stock options for compensation, because I felt like my role was directly attached to the success of the company. I turned down a red team role at Meta, with a higher tcomp, in order to take this job.\u003c/p\u003e\n\u003cp\u003eJoining in 2021 was interesting, because I feel like we were still in the stages where raising money wasn\u0026rsquo;t crazy difficult. It was the tail end of the ZIRP times. So we were super focused on growth. The team size grew significantly during my first year, it felt like nearly 100% growth.\u003c/p\u003e\n\u003cp\u003eThen interest rates started rising, raising funds started getting harder, and the layoffs started occurring across the whole tech industry. During the layoffs in 2023 and 2024, someone on my team was impacted each time, but I survived. But the company was reorienting from growth at all costs towards \u0026ldquo;how do we become profitable and sustainable\u0026rdquo; - a business value that I personally resonate with quite a lot. So I was hopeful.\u003c/p\u003e\n\u003cp\u003eBut the week before last, we learned of an acquisition. I don\u0026rsquo;t have the full context on the decisions that led to the sale, but it was clear that we were being acquired. Unfortunately for me and my large pile of mostly-vested Incentive Stock Options, the sale price was less than the strike price on even my cheapest traunch.\u003c/p\u003e\n\u003cp\u003eMy upside at the startup went from \u0026ldquo;could be worth a decent amount if we go public\u0026rdquo; to literally 0 in one email.\u003c/p\u003e\n\u003cp\u003eThis was a known risk going into the startup - it could always end up not being worth anything. So from a pure business perspective, I think the sale was the right decision. But personally, I feel like I would have rather rode out either until profitability or until we have to close our doors. To really know that we gave it our all, you know?\u003c/p\u003e\n\u003cp\u003eMy experience so far with the new company has been\u0026hellip; suboptimal. But I\u0026rsquo;ll save that rant for another time. Things might change, and I don\u0026rsquo;t want to stir the pot.\u003c/p\u003e\n\u003ch2 id=\"bsides-sf\"\u003eBSides SF\u003c/h2\u003e\n\u003cp\u003eI missed the first day of BSides SF this past weekend, but I was able to attend on Sunday and I had a really great time. It was nice catching up with so many people that I haven\u0026rsquo;t seen in quite a while, or that I\u0026rsquo;ve only seen briefly in passing and haven\u0026rsquo;t had time to catch up with. I got to chat with people about some of the projects I\u0026rsquo;m working on, got feedback on it, talked about some upcoming opportunities, and just generally had a good time.\u003c/p\u003e\n\u003cp\u003eWhile the work situation has been a bit of a bummer, attending BSides helped revitalize me and give me energy.\u003c/p\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I\u0026rsquo;ve submitted to the call for artists, and I\u0026rsquo;m really going to buckle down in the next week or so to get this soundtrack song ready.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eI want to do more live shows at hacker cons.\u003c/strong\u003e I\u0026rsquo;ll do it for the cost of getting to the con and the hotel room. If you, or someone you know, is organizing hacker cons or hacker parties and wants some new live nerdy rap shows, \u003ca href=\"https://0xda.de/\"\u003eplease reach out via any of the platforms on my page\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W15",
            "date_published": "2025-04-14T19:08:18-07:00",
            "date_modified": "2025-04-14T19:43:31-07:00",
            "id": "https://0xda.de/blog/2025/04/weekly-retro-2025-w15/",
            "url": "https://0xda.de/blog/2025/04/weekly-retro-2025-w15/",
            "content_html": "\u003cp\u003eI\u0026rsquo;m a day late, and it\u0026rsquo;s going to be a erratic one. You see, I spent most of my weekend away from the computer, which included not setting aside the time to write this that I normally would. I can\u0026rsquo;t say it was entirely intentional, at least not at first. But by the end of Sunday, it was definitely a conscious choice I was making, to not jump on the computer. To not feel the pressure I put on myself with great frequency to be \u0026ldquo;productive.\u0026rdquo;\u003c/p\u003e\n\u003cp\u003eInstead, I spent the weekend relaxing. I binge watched both seasons of \u003ca href=\"https://www.imdb.com/title/tt10405370/\"\u003eSAS Rogue Heroes\u003c/a\u003e, which I enjoyed quite thoroughly. It was a nice mix of \u0026ldquo;feels like history\u0026rdquo; and entertainment. I haven\u0026rsquo;t historically enjoyed watching many things that take place around World War 2, but I feel like this one was great. It\u0026rsquo;s from the makers of Peaky Blinders, which I also haven\u0026rsquo;t watched, but that I might watch now that I watched and enjoyed this.\u003c/p\u003e\n\u003cp\u003eWhen I wasn\u0026rsquo;t relaxing watching this show, I took time to go outside and enjoy the weather. I went out for multiple walks, both weighted and not, and got about 10 miles in between Friday and Sunday.\u003c/p\u003e\n\u003cp\u003eI feel like this was an important thing to do, because for the last several weeks I have been working practically non-stop, in order to finish some projects I set out to do. I am heading home to see my family next week, and I wanted to get as much done as I could before I leave for that. And so I spent probably 60 hours a week for the last month working on things. I would not recommend it, but I will say that I always feel a remarkable sense of accomplishment when I\u0026rsquo;m able to buckle down like that and really get things done.\u003c/p\u003e\n\u003cp\u003eSpeaking of that, I\u0026rsquo;m a day late on this post and I will unfortunately be skipping the retro slated for April 20th, since I won\u0026rsquo;t have any of my personal computers with me, and I keep a hard boundary between work and personal devices, so won\u0026rsquo;t be writing this post on my work laptop.\u003c/p\u003e\n\u003cp\u003eI also found myself, earlier in the week, thinking about my personal values. I don\u0026rsquo;t think I\u0026rsquo;m ready to expound on these too much at this time, but when I was younger I would sometimes think about this idea of personal values to live by, and felt like I had none. I didn\u0026rsquo;t know who I was at 17, 18, 19 years old. I\u0026rsquo;m not so sure I know now, either, but I do feel like I can look back and identify certain themes that have been consistent. I thought this was sort of unexpected, as it\u0026rsquo;s not something I\u0026rsquo;d thought of in quite a long time. But it was nice to capture some of my thoughts on it when the moment struck, even if it was nearly 1am and I was trying to sleep.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cp\u003eHonestly I don\u0026rsquo;t think I really read much of anything to share this week, which might be the first time I\u0026rsquo;ve left this section blank.\u003c/p\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I\u0026rsquo;ve submitted to the call for artists, but unfortunately still haven\u0026rsquo;t made much progress on my soundtrack song. The verse I have is okay, but I feel like it\u0026rsquo;s not my best work.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eI want to do more live shows at hacker cons.\u003c/strong\u003e I\u0026rsquo;ll do it for the cost of getting to the con and the hotel room. If you, or someone you know, is organizing hacker cons and wants some new live nerdy rap shows, \u003ca href=\"https://0xda.de/\"\u003eplease reach out via any of the platforms on my page\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W14",
            "date_published": "2025-04-06T13:15:17-07:00",
            "date_modified": "2025-04-06T14:23:49-07:00",
            "id": "https://0xda.de/blog/2025/04/weekly-retro-2025-w14/",
            "url": "https://0xda.de/blog/2025/04/weekly-retro-2025-w14/",
            "content_html": "\u003cp\u003eRefocusing my priorities, and a handful of improvements to my website, including a share button and a js-free collapsible menu.\u003c/p\u003e\n\u003ch2 id=\"protocol--projects\"\u003eProtocol \u0026amp; Projects\u003c/h2\u003e\n\u003cp\u003eThere was no new \u003ca href=\"https://www.youtube.com/playlist?list=PL7-g2-mnZwSF7uNEzb05BBxeaTYPvcglS\"\u003eProtocol\u003c/a\u003e episode this week. There will be no new Protocol episode next week. The amount of work that goes into making scripted YouTube videos is deceptively high. While I very much had fun making them, and I still love the idea for the series, it\u0026rsquo;s simply not tenable for me to write, record, and edit 4 videos a month and still have time for other projects.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;ve been quite busy with my day job the past 2-3 weeks, and I am taking on more critical projects at work that are likely to keep the level of activity pretty high for a while. On top of this, I was trying to research, write, record, and edit my YouTube series, making animations and everything. I have also been working on an album, and working on a SaaS product for Internet security research.\u003c/p\u003e\n\u003cp\u003eUnfortunately, I found myself having to spend all of my free time forcing myself to work on Protocol. Despite loving the idea, and really wanting to make it, it felt like a chore that left no time for any other things I wanted to do. I could get an editor, or get someone to help with research. But my best video barely did 100 views, I\u0026rsquo;m not ready to start paying a team for the project yet. I do hope I can do that in the future, but at the moment it\u0026rsquo;s just not viable.\u003c/p\u003e\n\u003cp\u003eInstead, I am giving myself time back to work on other things that I want to work on. Writing music, working on my little slice of the internet, and building software.\u003c/p\u003e\n\u003cp\u003eShould I find myself working full time on my own projects, I hope to pick Protocol back up. I legitimately have over 200 video ideas I want to make. But to execute them to the standards I set for myself requires more time than my full time job + other hobbies currently allow.\u003c/p\u003e\n\u003ch2 id=\"website-improvements\"\u003eWebsite improvements\u003c/h2\u003e\n\u003cp\u003eI didn\u0026rsquo;t really mean to spend several hours working on improvements for my website over the last couple days, but I saw an article about the web share API and I wanted to add a native share button to my posts (which I did, you can see it down below!)\u003c/p\u003e\n\u003cp\u003eI wrote yesterday about \u003ca href=\"https://0xda.de/blog/2025/04/hiding-elements-that-require-javascript-without-javascript/\"\u003ehiding elements that require JavaScript without needing JavaScript\u003c/a\u003e. It\u0026rsquo;s basically just a clever (in my opinion) use of a utility class and a bit of \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e. Turns out \u003ca href=\"https://news.ycombinator.com/item?id=43602688\"\u003esomeone posted me on HN\u003c/a\u003e, so that\u0026rsquo;s cool. I went and checked out some of the conversation and it is exactly as I expected it to be. A few very vocal people saying it\u0026rsquo;s dumb to bother not supporting JavaScript, and some other people talking about prior art in the space or talking about alternative ways to accomplish it. One person even mentioned that \u003ca href=\"https://news.ycombinator.com/item?id=43603120\"\u003ethere\u0026rsquo;s a CSS media query for whether scripting is available or not\u003c/a\u003e, which I find fun and frustrating, because I literally googled whether I could solve the problem with a media query or not lol. But it does exist!\u003c/p\u003e\n\u003cp\u003eToday I was trying out some of the ways my site responds to various NoScript extension configurations, and realized that my menu got a little jank. It relied on javascript to collapse when on mobile, and just rendered over content when JS was disabled on mobile. In an effort to fix it, I accidentally made it so that the menu doesn\u0026rsquo;t show up at all on mobile devices without JS. No good deed, etc.\u003c/p\u003e\n\u003cp\u003eBut this reminded me that in another project, I had built a JS-less collapsible menu through creative use of CSS selectors and an \u003ccode\u003e\u0026lt;input\u0026gt;\u003c/code\u003e checkbox. So I just ripped out the JS-requiring menu and replaced it with the CSS+input powered collapsible menu. Works just the same, except now with 100% less JavaScript.\u003c/p\u003e\n\u003cp\u003eSo the only features that actually need JavaScript on my site now are:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe Share button (replaced with just an easy-to-select link when not available)\u003c/li\u003e\n\u003cli\u003eThe theme switcher (uses system preference when JS is not available)\u003c/li\u003e\n\u003cli\u003eThe \n\n\u003ckbd\u003ectrl\u003c/kbd\u003e\u003cspan\u003e+\u003c/span\u003e\u003ckbd\u003ek\u003c/kbd\u003e\n search (sorry, no way to use this one without JS, I\u0026rsquo;m not going to run a search backend for my personal website)\u003c/li\u003e\n\u003cli\u003eThe annoying background fill (which is just not done when JS isn\u0026rsquo;t available, which one could argue makes the experience better)\u003c/li\u003e\n\u003cli\u003eMy self-hosted \u003ca href=\"https://plausible.0xda.de/0xda.de\"\u003ePlausible Analytics\u003c/a\u003e (which I\u0026rsquo;m A-okay not getting analytics from you if you don\u0026rsquo;t want me to have them)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://pilledtexts.com/why-i-use-a-17-year-old-thinkpad/\"\u003eWhy I Maintain a 17 Year Old Thinkpad\u003c/a\u003e - I have an old ThinkPad sitting on the shelf next to me. I don\u0026rsquo;t maintain it anymore, but it absolutely still fires up and I\u0026rsquo;m sure I could use it if I wanted to. I think mine is only 12 or 13 years old, though.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://evanconnelly.github.io/post/hacking-call-records/\"\u003eHacking the Call Records of Millions of Americans\u003c/a\u003e - Isn\u0026rsquo;t it so neat how many people have our data, even if we\u0026rsquo;ve never heard of them? Neat.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://jamie.ideasasylum.com/2025/03/31/losing-our-taste\"\u003eLosing our taste\u003c/a\u003e - An interesting article about the potential future impacts of the proliferation of AI. I use ChatGPT from time to time, but I don\u0026rsquo;t think AI is going to take my job, and I don\u0026rsquo;t think AI is going to produce art. A facade of what art once was, maybe. This author discusses it through the lens of taste, but I have found myself thinking about it through the lens of soul.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - Okay this week I\u0026rsquo;m filling out the call for artists for the live performances. I still have an extra month for the soundtrack, which is good because at this rate I\u0026rsquo;m going to need it.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eI want to do more live shows at hacker cons.\u003c/strong\u003e I\u0026rsquo;ll do it for the cost of getting to the con and the hotel room. If you, or someone you know, is organizing hacker cons and wants some new live nerdy rap shows, \u003ca href=\"https://0xda.de/\"\u003eplease reach out via any of the platforms on my page\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W13",
            "date_published": "2025-03-30T22:02:05-07:00",
            "date_modified": "2025-03-30T23:10:57-07:00",
            "id": "https://0xda.de/blog/2025/03/weekly-retro-2025-w13/",
            "url": "https://0xda.de/blog/2025/03/weekly-retro-2025-w13/",
            "content_html": "\u003cp\u003eI\u0026rsquo;ve been reflecting a lot this week on the type of work I enjoy doing, and I\u0026rsquo;m starting my home energy monitoring journey.\u003c/p\u003e\n\u003cp\u003eI also make heavy use of images from \u003ca href=\"https://theprofoundprogrammer.tumblr.com/\"\u003eProfound Programmer\u003c/a\u003e in this weeks retro. It just felt fitting, given the topic.\u003c/p\u003e\n\u003ch2 id=\"reflections-on-my-love-for-shit-work\"\u003eReflections on my love for shit work\u003c/h2\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w13/img/debugging-will-continue-profound-programmer_hu_6055286d531957f.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w13/img/debugging-will-continue-profound-programmer.f31c7d3b25ebc1a39890139b8c5e774a.jpg\" alt=\"Debugging will continue until morale improves, with a man digging a deep hole that he\u0026rsquo;s standing in\" loading=\"lazy\" height=\"720\" width=\"1280\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003cp\u003eI genuinely love doing little tasks that on the surface don\u0026rsquo;t seem that important, don\u0026rsquo;t seem related to my role in security, or maybe seem disparate and disconnected from any primary goal. I am privileged in my position at work to get to pretty much choose my own work tasks and set my own projects, and I have accomplished a great deal thanks to this flexibility.\u003c/p\u003e\n\u003cp\u003eOne of the things I love the most is finding the little things that build up over time, the tech debt, the things other engineers say \u0026ldquo;I wish we could fix that\u0026rdquo;, and sweeping it up. A digital sanitation technician, if you will. The sole proprietor of the Tech Debt Collection Agency.\u003c/p\u003e\n\u003cp\u003eWhether that\u0026rsquo;s questionable decisions in database design, complicated code that is hard to follow and hard to modify, or even just code repos that haven\u0026rsquo;t been touched in a couple years \u0026ndash; if I look at it and think \u0026ldquo;I don\u0026rsquo;t like that\u0026rdquo;, I love getting to just\u0026hellip; fix it. I don\u0026rsquo;t deal with politics, I don\u0026rsquo;t wait for permission, I just see a problem and I do my part to make it better. One engineer I work with called this the \u0026ldquo;Campsite rule\u0026rdquo; \u0026ndash; leave it better than you found it, and I like that.\u003c/p\u003e\n\u003cp\u003eIn my old roles as a red teamer, I really enjoyed getting to look for problems and help people understand why they were problems and how they could fix them. But ultimately, the success of my work boiled down to whether or not the problems I found would actually get fixed, and often times this could take months, or even years, and it was completely out of my control. I felt a lot like this guy, pretending to be a criminal and cheering on the nearby tire fire.\u003c/p\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w13/img/im-pretty-sure-im-helping-profound-programmer_hu_57fa2ec90985d297.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w13/img/im-pretty-sure-im-helping-profound-programmer.85267ba398efd250bf8a89fe2bce2fdc.jpg\" alt=\"I\u0026rsquo;m pretty sure I\u0026rsquo;m helping, as I cheer on a nearby tire fire\" loading=\"lazy\" height=\"720\" width=\"1280\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003cp\u003eThis week I inadvertently spent the whole week rewriting our core authentication code. Due to a mistake early on in the lifetime of our Django application, we had to make a large number of compromises to achieve the behaviors we wanted. This all happened well before I joined the company, but the effects were felt years later, nonetheless. Our login process involved several custom classes that subclassed other classes that were provided by third party plugins, used a custom django authentication backend, and did a whole bunch of things just to result in \u0026ldquo;can we set a session cookie for this user\u0026rdquo; - a feature that django has supported out of the box for, idk, well over a decade.\u003c/p\u003e\n\u003cp\u003eIt was hard to understand, and worse, it was hard to modify safely. There were tests, but they didn\u0026rsquo;t account for a bunch of edge cases. It was just a hairy mess. With no offense to the engineers who got us there \u0026ndash; it was the constraints they were working with at the time, and they came up with a solution. I just happen to have the privilege of hindsight and can say \u0026ldquo;yeah how about no.\u0026rdquo; I have some new security related features in development, and those features required being able to easily look at and understand how a user authenticates to our system, what criteria must be true, what criteria must be false, etc.\u003c/p\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w13/img/who-let-you-do-this-profound-programmer_hu_7fb2f3e41b986043.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w13/img/who-let-you-do-this-profound-programmer.c7d5fc7ac6992a6239ef3b887d93f266.jpg\" alt=\"Who let you do this, a photo of a utility pole with a ton of messy cables coming off it in every direction\" loading=\"lazy\" height=\"720\" width=\"1280\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003cp\u003eBut this is just one example that happens to be directly related to security. I have also done a whole bunch of things that are indirectly related to security. I rewrote our dependency management, twice \u0026ndash; not for security reasons, but because determinism in builds is important for developer experience and for system reliabilty.\u003c/p\u003e\n\u003cp\u003eI introduced flake8 and other linters to our code base and almost single-handedly brought our 400k-loc python project into pep8 compliance. I have engaged heavily in the adoption of mandatory strict mypy checking in our code, often spending hours scouring the code for type ignores and doing whatever I can to fix them, often fixing a wide variety of bugs along the way. I rewrote multiple lambdas that were used in production but that were in a language that isn\u0026rsquo;t standard for our company, simply to make it easier for other engineers to then make changes later.\u003c/p\u003e\n\u003cp\u003eThese things are not particularly related to security, but I have the privilege of getting to work on them, because I look at security as a pretty holistic process. Security is not the features I bolt onto our code base, bolt onto our infrastructure, bolt on to our product. Security is not the policies we write or the processes we make everyone else go through. Security is the daily grind of finding things that aren\u0026rsquo;t quite right, and putting in the effort to make them better, before they become a problem. Making them easier to understand. Making it less risky to make changes in the future. Making it harder to write bugs, security or otherwise. Moving the needle, slowly but surely, towards an environment that embraces velocity, but not without regard for safety.\u003c/p\u003e\n\u003cp\u003eI genuinely love finding some code that makes me go \u0026ldquo;who even wrote this and why did we let them?\u0026rdquo; and then developing a plan to make that suck less. Asking myself \u0026ldquo;how do we solve this problem in a way that is easy to understand and doesn\u0026rsquo;t do more than we need?\u0026rdquo; I finish the work and can look back and feel like it\u0026rsquo;s genuinely better than how I found it.\u003c/p\u003e\n\u003cp\u003eAt least until a little time goes by\u0026hellip; and then I look back and the whole process repeats itself.\u003c/p\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w13/img/but-im-good-at-computers-profound-programmer_hu_b4a99c04f6ec2f16.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w13/img/but-im-good-at-computers-profound-programmer.dbcf43d79c3f48adf8de546aa558288b.jpg\" alt=\"But I\u0026rsquo;m good at computers, by Profound Programmer\" loading=\"lazy\" height=\"720\" width=\"1280\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003ch2 id=\"home-energy-monitoring-w-athom-smart-plugs\"\u003eHome Energy Monitoring w/ Athom Smart Plugs\u003c/h2\u003e\n\u003cp\u003eI received 6 \u003ca href=\"https://www.athom.tech/blank-1/no-relay-power-monitoring-us-plug-for-esphome\"\u003eAthom Smart Plugs for ESPHome\u003c/a\u003e in the mail today that I had ordered maybe a month ago or so. I\u0026rsquo;ve been desparately hunting for the source of our 500 kWh power bills, and while I made some progress by switching our thermostat into eco mode and relying on opening the windows more often, it only ended up reducing our actual bill by maybe 15%.\u003c/p\u003e\n\u003cp\u003eSince I live in an apartment, I have somewhat limited options for smart power monitoring. My friend Adam has written in the past about his \u003ca href=\"https://technowizardry.net/2023/02/local-energy-monitoring-using-the-emporia-vue-2/\"\u003econdo energy monitoring with the Emporia Vue 2 system\u003c/a\u003e, and this idea does really appeal to me. But unfortunately I\u0026rsquo;m a scaredy cat when it comes to working with electricity, and probably more unfortunately, I don\u0026rsquo;t have access to the main breaker for my apartment without coordinating with the building management. So installing something like this into my rental seems like maybe more effort than it\u0026rsquo;s worth, especially since I also don\u0026rsquo;t know when we\u0026rsquo;re planning to move out of here.\u003c/p\u003e\n\u003cp\u003eSo instead, I sought smart plugs that I could use. My criteria was, I thought, pretty simple. I wanted the data to be available \u003cem\u003eonly\u003c/em\u003e locally, I wanted to integrate with Home Assistant, and I wanted to be able to add the smart plug to both spots for any given outlet. This ruled out things like the Kill-a-watt, which are cool, but gigantic, and the per unit price is also kind of absurd compared to the smart plugs I ended up with.\u003c/p\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w13/img/athom-smart-plugs_hu_4d18caa8a347befd.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w13/img/athom-smart-plugs.ec603ab6e4926e1796593561447f32f3.png\" alt=\"Photo of an Athom smart plug\" loading=\"lazy\" height=\"800\" width=\"800\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003cp\u003eI ended up with the Athom plugs for about $13/ea, and they came pre-flashed with ESPHome. They were a breeze to setup and I\u0026rsquo;ve got them monitoring my complete desk setup now. I\u0026rsquo;m going to expand out to also monitoring the server rack in the closet where all the network gear is, the entertainment system in the living room, and then I\u0026rsquo;ll probably explore some of the kitchen outlets that might benefit from them.\u003c/p\u003e\n\u003cp\u003eAt this point, I don\u0026rsquo;t even think I\u0026rsquo;m going to take much action if I do find the cause. It\u0026rsquo;s just been haunting me that our power usage is so high each month for our apartment and it doesn\u0026rsquo;t seem to change that much when I\u0026rsquo;m gone for a week and my computer is off. It does drop considerably when we\u0026rsquo;re both gone for a week, in which case we usually unplug both of our desks, the TV, air fryer, etc, and the thermostat goes into eco mode even more aggressively it seems. But I just want to know where the power is going, and with these plugs, maybe I\u0026rsquo;ll finally start to figure out the answer.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=cR9hiMFRkmQ\"\u003eSimple Mail Transfer Protocol\u003c/a\u003e - My 8th PROTOCOL video, in which I did a lot of animation with excalidraw exports to explain how sending an email works. I\u0026rsquo;m proud of this one.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://libre.computer/\"\u003eLibre Computer\u003c/a\u003e - A company that specializes in open source single board computers. I haven\u0026rsquo;t ordered one, but they look like a pretty cool company.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://utensils.io/articles/10-things-i-hate-about-nixos\"\u003e10 Things I Hate about NixOS\u003c/a\u003e - I agree, the worst part about NixOS is how insufferable I\u0026rsquo;ve become about it.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://dbushell.com/2025/03/29/et-tu-grammarly/\"\u003eEt Tu, Grammarly?\u003c/a\u003e - A fun diagnosis of the Grammarly browser extension breaking a website\u0026rsquo;s styles. Bonus second link, you can use \u003ca href=\"https://argyle.ink/css-emoji-convention\"\u003eemojis as CSS variables\u003c/a\u003e. Unfortunately, the website does not in fact mean \u0026ldquo;dbus hell\u0026rdquo;, which was a slight letdown.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.chrbutler.com/digital-echoes-and-unquiet-minds\"\u003eDigital Echoes and Unquiet Minds\u003c/a\u003e - I enjoyed this essay a lot. I sometimes get overwhelmed by the sheer amount of data I leave behind in my wake.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://buyoncesoftware.com/\"\u003eBuy Once Software\u003c/a\u003e - A repository of software that you can buy once and not have to deal with being milked for recurring revenue. I\u0026rsquo;m happy to see people celebrating this, and I hope more people embrace it.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://refactoringenglish.com/chapters/write-blog-posts-developers-read/\"\u003eWrite Blog Posts that Developers Read\u003c/a\u003e - A post about how to write posts that actually attract readers. I may have tried my hand at this a little bit this time, but also the weekly retro isn\u0026rsquo;t a format I expect people to be seeking out.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://fly.io/blog/operationalizing-macaroons/\"\u003eOperationalizing Macaroons\u003c/a\u003e - A great post from Fly.io about how they\u0026rsquo;ve operationalized Macaroons as an authentication mechanism. It seems super cool, I hadn\u0026rsquo;t looked at them very much before, and I\u0026rsquo;ll probably stick with session cookies for most of my usage, but this is great, nevertheless.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I\u0026rsquo;ve made no progress on this since last week, I need to get it together or it\u0026rsquo;s going to be too late before I know it.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eI want to do more live shows at hacker cons.\u003c/strong\u003e I\u0026rsquo;ll do it for the cost of getting to the con and the hotel room. If you, or someone you know, is organizing hacker cons and wants some new live nerdy rap shows, \u003ca href=\"https://0xda.de/\"\u003eplease reach out via any of the platforms on my page\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e"
        },
        {
            "title": "Weekly Retro 2025-W12",
            "date_published": "2025-03-23T17:31:52-07:00",
            "date_modified": "2025-03-23T18:14:47-07:00",
            "id": "https://0xda.de/blog/2025/03/weekly-retro-2025-w12/",
            "url": "https://0xda.de/blog/2025/03/weekly-retro-2025-w12/",
            "content_html": "\u003ch2 id=\"building-a-saas-boilerplate\"\u003eBuilding a SaaS (Boilerplate)\u003c/h2\u003e\n\u003cp\u003eI\u0026rsquo;ve previously mentioned a few times that I have a side business, \u003ca href=\"https://room641a.com\"\u003eRoom 641A\u003c/a\u003e, where I\u0026rsquo;ve been doing some contracting and consulting. I haven\u0026rsquo;t had any work through that business yet this year, so I\u0026rsquo;ve been working on my longer term desire for the company \u0026ndash; a SaaS offering for curated red team intelligence.\u003c/p\u003e\n\u003cp\u003eBut I\u0026rsquo;m probably going about this in a very opposite way than most people would. I see a lot of people talking about how you should focus on the product part itself and then tack things on after that. But since I\u0026rsquo;m not in a hurry for getting sales (I mean, I\u0026rsquo;d love sales, but I\u0026rsquo;m not running out of money), I wanted to focus on getting things setup in a way that sets me up for success in the long term.\u003c/p\u003e\n\u003cp\u003eThis means I\u0026rsquo;m doing things like setting up all the more advanced auth features up front \u0026ndash; my app has no business logic, but you can use passkeys, TOTP, and recovery codes. There\u0026rsquo;s no business logic, but you can setup SAML to login. There\u0026rsquo;s no business logic, but I better write well-typed code.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m taking this slightly different strategy because I think once I get to a particular point, it will be easy to reuse this project layout for other projects and feel comfortable with the code right away. I\u0026rsquo;ve tried many other django boilerplate generators and they are all lacking things that I want, or are messy in ways I don\u0026rsquo;t like.\u003c/p\u003e\n\u003cp\u003eSpeaking of django projects, I also started working on a post discussing a bunch of bad Django advice I see people give, and why I think they are bad. The first and foremost is that a lot of Django developers seem to think that \u0026ldquo;app\u0026rdquo; is synonymous with \u0026ldquo;module\u0026rdquo; \u0026ndash; which is a misconception that can lead to a lot of pain in the future. Not sure when I\u0026rsquo;ll be ready to post it, but it\u0026rsquo;s something I\u0026rsquo;m working on.\u003c/p\u003e\n\u003ch2 id=\"deleting-old-code\"\u003eDeleting Old Code\u003c/h2\u003e\n\u003cp\u003eI\u0026rsquo;ve been spending quite a bit of time at work this last week, and will continue for the next few weeks, deleting old code that we\u0026rsquo;re no longer going to support, and simplifying things. This is my favorite thing to do. I have a PR open that deletes 31k lines of code, and that\u0026rsquo;s just the first delete out of many more coming. Reducing complexity and removing dead code is super satisfying, especially in an organization that has like 8 years of history behind it. It\u0026rsquo;s easy to keep building and keep adding new things, sometimes it\u0026rsquo;s important to look back and figure out what can be deleted.\u003c/p\u003e\n\u003ch2 id=\"hugo-upgrade\"\u003eHugo Upgrade\u003c/h2\u003e\n\u003cp\u003eI updated Hugo to the \u003ca href=\"https://0xda.de/colophon/\"\u003elatest version this week\u003c/a\u003e. My builds on my server are kinda slow, over 2 seconds per build (and I build twice, once for the tor site and once for 0xda.de), and I didn\u0026rsquo;t understand what was causing it.\u003c/p\u003e\n\u003cp\u003eWell, turns out it had nothing to do with the hugo version, but I\u0026rsquo;m updated nevertheless. The reason it\u0026rsquo;s slow is because, even with the cached image manipulations, the SSD on the server is just considerably slower than my NVMe SSDs at home. So even though the existing images don\u0026rsquo;t have to be manipulated again on every build, it takes multiple seconds to enumerate the images and make sure they don\u0026rsquo;t need to be manipulated. So that was a fun waste of time.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=CFcWvcYD8ps\"\u003eIntro to Secure Shell (SSH)\u003c/a\u003e - My 7th episode of PROTOCOL, an introductory look at Secure Shell and some of the fun you can have with it. I feel like this is some of my best editing yet, even though I had some mistakes in my pre-production.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://luj.fr/blog/how-nixos-could-have-detected-xz.html\"\u003eHow NixOS could have detected the XZ backdoor\u003c/a\u003e - An interesting look at the XZ backdoor and how using NixOS can help to detect unexpected inputs / avoid published code that isn\u0026rsquo;t in the repo.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://vincent.bernat.ch/en/blog/2025-offline-pki-yubikeys\"\u003eOffline PKI with Yubikeys\u003c/a\u003e - I have a soft spot in my heart for at-home PKI. Do I run one? Not at all. But I love the idea of setting one up, I think it\u0026rsquo;s a useful experience to understand securing sensitive keys. This is a 2025 version of running our own PKI.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.datagubbe.se/futui/\"\u003ePast and Present Futures of User Interface Design\u003c/a\u003e - Notes on the ways that we imagine the future of user interfaces.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.dshr.org/2025/03/archival-storage.html\"\u003eArchival Storage\u003c/a\u003e - A written version of a seminar about Archival Storage. Important takeaway - Archiving != backups.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.gimp.org/news/2025/03/16/gimp-3-0-released/\"\u003eGIMP 3.0 Released\u003c/a\u003e - I\u0026rsquo;ve been a long time GIMP user, and the 3.0 release is pretty great. Being able to stack layer effects in a non-destructive way is \u003cem\u003ehuge\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I\u0026rsquo;m going to submit to the Call for Artists soon, which is due before the soundtrack song. But I do need to revisit the soundtrack song, I\u0026rsquo;m still not happy with my verse.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eI want to do more live shows at hacker cons.\u003c/strong\u003e I\u0026rsquo;ll do it for the cost of getting to the con and the hotel room. If you, or someone you know, is organizing hacker cons and wants some new live nerdy rap shows, please reach out. You can contact me at any of the links on my homepage.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W11",
            "date_published": "2025-03-16T21:35:33-07:00",
            "date_modified": "2025-03-17T11:03:43-07:00",
            "id": "https://0xda.de/blog/2025/03/weekly-retro-2025-w11/",
            "url": "https://0xda.de/blog/2025/03/weekly-retro-2025-w11/",
            "content_html": "\u003ch2 id=\"red-team-summit\"\u003eRed Team Summit\u003c/h2\u003e\n\u003cp\u003eThis week was one of my favorite weeks in a long time. We had a very successful 9th annual Red Team Summit (but actually our 8th, due to Covid cancelling our 2020 event), and all the work I’d been putting in over the past months paid off. Due to the nature of the event, I won\u0026rsquo;t really say a whole lot about it, but it has been my favorite conference since the first one, and I\u0026rsquo;m so happy I get to be a part of it.\u003c/p\u003e\n\u003cp\u003eI also hosted my first sponsored conference social event for \u003ca href=\"https://room641a.com/\"\u003eRoom 641A\u003c/a\u003e and got to talk to people about what I’m working on. I don\u0026rsquo;t know if it led to any actual leads or not, which might make it more difficult to justify doing it again in the future unless I start bringing in more consistent income, but it was really cool to get to do that.\u003c/p\u003e\n\u003cp\u003eI was also given a surprise customized gift that made me feel super appreciated. Others involved with the conference/community made this customized ifixit kit for me, with a 1 of 1 embroidered version of my social media logo (which itself is from my first single, \u003ca href=\"https://open.spotify.com/album/5FIFcfMuQXv0dNlzXorizE\"\u003eRed Team\u003c/a\u003e). For everyone involved in this gift, I appreciate you all more than you could know, even if I\u0026rsquo;m a little awkward about showing it.\u003c/p\u003e\n\u003cp\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/blog/2025/03/weekly-retro-2025-w11/dade-ifixit-kit_hu_cf8c7fd052895866.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"img\" src=\"/blog/2025/03/weekly-retro-2025-w11/dade-ifixit-kit.b2f970e33e76c947b57f5d95aa63c66a.jpeg\" alt=\"A personalized ifixit kit with an embroidered version of my social media logo\" loading=\"lazy\" height=\"944\" width=\"676\" /\u003e\n\u003c/picture\u003e\n\u003c/p\u003e\n\u003ch2 id=\"dns-data-collection\"\u003eDNS Data Collection\u003c/h2\u003e\n\u003cp\u003eIn addition to Red Team Summit, I have been working on a lot of DNS related software work. I built a simple zone diffing tool in python that generates diffs day over day for a given TLD zone, and also built an automated process to fetch zone files from CZDS and streaming decompress them to an s3 bucket.\u003c/p\u003e\n\u003cp\u003eThe streaming Gzip decompression is cool, I didn’t really understand that it was possible but it was cool to try it out and get it working. Otherwise the .com zone in particular would be problematic, since it expands to over 22GB. Diffing the .com zone is also challenging since the diff requires comparing the before and after, which would naively require 44GB of memory. Instead, I’m doing a variation on a streaming diff to avoid loading each whole zone into memory. It\u0026rsquo;s not a perfect diff that could be applied with the patch tool, but it should help clarify what things are happening in the zones on a daily basis, without having to store many duplicates of the complete files.\u003c/p\u003e\n\u003cp\u003eAnyone have ideas on how to efficiently store timeseries data in a graph database? I\u0026rsquo;m constantly pushing the limit of my knowledge here 😅.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=x0gE5tyiaAs\"\u003ePROTOCOL - TELNET\u003c/a\u003e - My video on telnet released this past week. I didn\u0026rsquo;t post about it or anything, but here it is.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://soundcloud.com/0xdade/mess-with-the-best\"\u003eMess With The Best\u003c/a\u003e - A track I put out I guess more than a week ago at this point. I\u0026rsquo;m going to publish this one to streaming platforms, but soundcloud got it first.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.muni.town/atproto-isnt-what-you-think/\"\u003eATProto Isn\u0026rsquo;t What You Think\u003c/a\u003e - A post about ATProto, what decentralized means, and the value of the Personal Data Server.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://pippinbarr.com/it-is-as-if-you-were-on-your-phone/info/\"\u003eIt is as if you were on your phone\u003c/a\u003e - A fun site that draws attention to the patterns that we tend to exhibit while using our phones, and the pressure to be on them all the time. It reminds me of \u003ca href=\"https://thequietplaceproject.xyz/thequietplace\"\u003eThe Quiet Place Project\u003c/a\u003e, except almost in the exact opposite direction.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - Still working on it. Need to sit down and really focus on it a bit to get some progress on it, and collect some soundclips to use to really frame the concept.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W10",
            "date_published": "2025-03-09T19:06:05-07:00",
            "date_modified": "2025-03-09T20:04:43-07:00",
            "id": "https://0xda.de/blog/2025/03/weekly-retro-2025-w10/",
            "url": "https://0xda.de/blog/2025/03/weekly-retro-2025-w10/",
            "content_html": "\u003cp\u003e\u0026ldquo;You get paid for the seven and a half hours a day you put in here, but you get your raises and promotions on what you do in the other sixteen and a half hours.\u0026rdquo; - Mervin Kelly, Bell Labs\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"is-everything-a-graph-actually\"\u003eIs everything a graph, actually?\u003c/h2\u003e\n\u003cp\u003eWhereupon I find a hammer and every problem starts looking like a nail.\u003c/p\u003e\n\u003cp\u003eI accidentally got obsessed with graph databases this week. See, what had happened was\u0026hellip; I was sitting around trying to come up with a good way to model DNS data in postgres, and I realized that every solution I came up with would either require a lot of joins to answer questions I wanted to answer, or result in very sparse tables. I wondered if there was another tool for the job, and I remembered that neo4j was pretty cool, but I didn\u0026rsquo;t really know anything about how to use graph databases.\u003c/p\u003e\n\u003cp\u003eThe results, after several days of playing, is that I still don\u0026rsquo;t really understand them, but I have some code that will insert or update nodes that already exist for DNS names, insert or update nodes for new TXT records and IP addresses discovered, and map record types via relationships. It\u0026rsquo;s a long way from what I have in mind, but it\u0026rsquo;s very cool to play with and uncover interesting little patterns.\u003c/p\u003e\n\u003ch2 id=\"changing-my-macos-experience\"\u003eChanging my MacOS experience\u003c/h2\u003e\n\u003cp\u003eI don\u0026rsquo;t know what caused it, but this past week I decided I was tired of the chaos that was my MacOS user experience on my work laptop. I wanted to switch things up so that I could have a more consistent experience between my work macbook and my personal macbook, while having many of the benefits I like of using hyprland on my framework laptop.\u003c/p\u003e\n\u003cp\u003eEnter \u003ca href=\"https://github.com/nikitabobko/AeroSpace\"\u003eAerospace\u003c/a\u003e. It\u0026rsquo;s an i3-like tiling window manager for macOS. You may have already heard of other tiling window managers for macOS, like \u003ca href=\"https://github.com/koekeishiya/yabai\"\u003eyabai\u003c/a\u003e or \u003ca href=\"https://github.com/ianyh/Amethyst\"\u003eAmethyst\u003c/a\u003e. I ultimately went with Aerospace because I saw a video about it on youtube where someone walked through setting up their config and it just made sense to me. I also like that it is implemented entirely with its own implementation of virtual workspaces, since the macOS spaces feature kinda sucks. I don\u0026rsquo;t have any interest waiting that long to switch windows just so you can look pretty.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s not without it\u0026rsquo;s quirks, though. Periodically I will unlock my laptop and a bunch of my windows will get jumbled up onto different workspaces than I left them on. I\u0026rsquo;m not sure why this happens, but it\u0026rsquo;s usually not longer than a couple seconds to sort them out. It also only applies to the windows that I don\u0026rsquo;t have window bind rules setup for. E.g. I have chrome bound to B, for browser, and slack bound to S for, well, Slack. I have WezTerm bound to T for terminal, and Pycharm bound to P. It\u0026rsquo;s really just the random other windows I open but don\u0026rsquo;t use every day that seem to get jumbled up occasionally, which is mildly annoying but not the end of the world.\u003c/p\u003e\n\u003cp\u003eIn addition to this, I spent some time switching to \u003ca href=\"https://wezterm.org/\"\u003eWezTerm\u003c/a\u003e, away from iTerm2. I have used iTerm2 since I started on macOS back in 2018, but I haven\u0026rsquo;t really felt like I \u003cem\u003eliked\u003c/em\u003e it in many years. It was just there because it was familiar and because it was better than the built in terminal. WezTerm has been great so far, though the configuration has taken a little getting used to. Ultimately I think I want to move away from relying on the terminal emulator itself to do pane splitting and get myself a tmux or zellij configuration that I like. But for now, WezTerm was a pretty chill replacement for iTerm2.\u003c/p\u003e\n\u003cp\u003eAll these changes didn\u0026rsquo;t feel radical enough, so I also added Vimium to Chrome at work, and have been forcing myself to learn vim motions and commands. It\u0026rsquo;s slow going, but I\u0026rsquo;ll be damned if I don\u0026rsquo;t feel like a wizard when I do something cool. I\u0026rsquo;m also spending notably less time with my hand on the mouse, which I like. I\u0026rsquo;m probably only a few weeks away from being insufferable about using vim.\u003c/p\u003e\n\u003cp\u003eSpeaking of vim\u0026hellip; it\u0026rsquo;s kind of insane to me that the arrow keys are hjkl instead of jkl;. Does vim predate the standard qwerty keyboard home row positionining or something? Having to move my hands off their resting space to shift one over to use arrows is weird. But I\u0026rsquo;m told that once I get good, I won\u0026rsquo;t rely on the arrow keys as much. So maybe it\u0026rsquo;s fine.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m writing and editing this article in VS Code with the vim extension, so I guess you could say things are getting pretty serious.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.freaktakes.com/p/how-did-places-like-bell-labs-know\"\u003eHow did places like Bell Labs know how to ask the right questions?\u003c/a\u003e - I got absolutely nerd sniped by this article (essay? maybe?) about Bell Labs yesterday and spent hours reading it and other related stories about Bell Labs. there was one quote that i really liked by Mervin Kelly, which I included at the top of this article.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/geerlingguy/youtube/\"\u003eJeff Geerling\u0026rsquo;s Youtube repo\u003c/a\u003e - I love this idea. Jeff uses this repo to talk about sponsorships, equipment he uses, his philosophy and process on making videos. It\u0026rsquo;s so delightfully transparent.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://usher.dev/posts/2025-03-08-kill-your-feeds/\"\u003eKill Your Feeds\u003c/a\u003e - A reminder that algorithmic feeds are designed to drip feed our attention, keeping us coming back for more, one drip at a time. Skip the feeds, go to the source.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.xmox.nl/\"\u003exmox\u003c/a\u003e - An all-in-one mailserver. I don\u0026rsquo;t need another mailserver, and I don\u0026rsquo;t know if I love or hate the idea of a single project basically attempting to do everything needed to run a mailserver today. But I\u0026rsquo;m interested to see it\u0026rsquo;s development.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.freaktakes.com/p/a-scrappy-complement-to-fros-building\"\u003eA Scrappy Complement to Focused Research Organizations\u003c/a\u003e - As part of my fall into Bell Labs reading yesterday, I also read this article by the same author about BBN-model orgs, named after Bolt, Beranek, and Newman. It\u0026rsquo;s an interesting idea that I hadn\u0026rsquo;t really considered, but then again I haven\u0026rsquo;t spent a lot of time considering research organizations in general.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=CFRhGnuXG-4\"\u003eWhy you shouldn\u0026rsquo;t nest your code\u003c/a\u003e - I discovered this channel this week, and it\u0026rsquo;s incredible. He only has 8 videos, has amassed over 400k subscribers, and his content is well written and well presented. I recommend this one and \u003ca href=\"https://www.youtube.com/watch?v=hxGOiiR9ZKg\"\u003eThe Flaws of Inheritance\u003c/a\u003e. I\u0026rsquo;m an inheritance hater, and I will preach against it every chance I get, but now I can just link this video instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I\u0026rsquo;m still working on this track, I wrote a verse but am revisiting whether I like the approach I took.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W09",
            "date_published": "2025-03-02T10:46:21-08:00",
            "date_modified": "2025-03-03T11:06:55-08:00",
            "id": "https://0xda.de/blog/2025/03/weekly-retro-2025-w09/",
            "url": "https://0xda.de/blog/2025/03/weekly-retro-2025-w09/",
            "content_html": "\u003cp\u003eThis week I spent a lot of time working on writing more Protocol episodes. The fourth episode went out, covering an \u003ca href=\"https://www.youtube.com/watch?v=oBsWmSnhs6A\u0026amp;list=PL7-g2-mnZwSF7uNEzb05BBxeaTYPvcglS\u0026amp;index=4\"\u003eintro to DNS\u003c/a\u003e, and I didn\u0026rsquo;t have the next episode ready to go yet. I also spent a bit of time customizing my MacOS experience to use \u003ca href=\"https://github.com/nikitabobko/AeroSpace\"\u003eAerospace\u003c/a\u003e, \u003ca href=\"https://www.raycast.com/\"\u003eRaycast\u003c/a\u003e, and \u003ca href=\"https://wezterm.org/index.html\"\u003eWezterm\u003c/a\u003e.\u003c/p\u003e\n\u003ch2 id=\"march-video-schedule\"\u003eMarch Video Schedule\u003c/h2\u003e\n\u003cp\u003eIn March, I am releasing four episodes of Protocol, as follows:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMarch 5th, 2025: Intro to Hypertext Transfer Protocol (HTTP)\u003c/li\u003e\n\u003cli\u003eMarch 12th, 2025: Telnet\u003c/li\u003e\n\u003cli\u003eMarch 19th, 2025: Secure Shell (SSH)\u003c/li\u003e\n\u003cli\u003eMarch 26th, 2025: Intro to Simple Mail Transfer Protocol (SMTP)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAdditionally, I would like to publish one video about a red teaming topic, of which I have several backlogged ideas to work on. I feel like I got a system in place for Protocol episodes, but doing other videos now feels harder because its less clear the direction I want to take. So hopefully I can get some done and remove some of the weight of uncertainty.\u003c/p\u003e\n\u003ch2 id=\"replacing-a-failing-disk-in-truenas\"\u003eReplacing a failing disk in TrueNAS\u003c/h2\u003e\n\u003cp\u003eSome months ago I set up TrueNAS on my HL15 from 45 Home Lab, and I added 7 20TB drives to it. 3 were brand new drives from western digital, and 4 were Seagate Manufacturer Recertified drives from ServerPartDeals. I started using rsync to copy all my data from my Synology over to it, and all was good.\u003c/p\u003e\n\u003cp\u003eUntil about 3 weeks ago, I noticed that my HDD ZFS pool was degraded. Apparently one of the disks was already having read errors in the smart tests. I didn\u0026rsquo;t have extra drives ready to go to fix this, but thankfully the drives were in a RAIDZ2 vdev, so I could tolerate two drives failing before risking data loss.\u003c/p\u003e\n\u003cp\u003eI ordered another drive, as well as started the RMA process with ServerPartDeals. I got both drives towards the beginning of the week and replaced them on Thursday evening. Resilvering took a little over a day, but now we\u0026rsquo;re back to a healthy state. I also added one hot spare vdev to the pool so that if I have another immediate issue, I won\u0026rsquo;t have to worry as much about waiting for another drive to be delivered.\u003c/p\u003e\n\u003cp\u003eData hoarding is an expensive hobby. But I feel like I\u0026rsquo;ve really up-leveled my game since getting the TrueNAS machine setup.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=oBsWmSnhs6A\"\u003eIntro to Domain Name System (DNS)\u003c/a\u003e - Another plug for my own video, intro to DNS.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/o2sh/onefetch\"\u003eOnefetch\u003c/a\u003e is a fetch-like tool for git repositories. I think the various fetch tools are kinda silly, but they are fun.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.autodidacts.io/troubleshooting/\"\u003eOn Troubleshooting\u003c/a\u003e - An absolutely huge guide on how to troubleshoot effectively.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.athom.tech/\"\u003eAthom Tech Smart Plugs\u003c/a\u003e - I ordered a handful of these that I\u0026rsquo;d like to use to help identify where I\u0026rsquo;m losing so much power at home, and get a better understanding of things like \u0026ldquo;how much power is my rack consuming\u0026rdquo; and \u0026ldquo;how much power is my desktop consuming.\u0026rdquo; I won\u0026rsquo;t get them til the end of the month, but supposedly they integrate nicely into home assistant, as well.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.vaxry.net/articles/2025-hyprlandMatures\"\u003eHyprland\u0026rsquo;s development isn\u0026rsquo;t what it used to be\u003c/a\u003e - An article from the creator of Hyprland and talking about how the development has slowed down, and why that isn\u0026rsquo;t necessarily a bad thing.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ggerganov/ggwave\"\u003eggwave\u003c/a\u003e - A tiny data-over-sound library. I don\u0026rsquo;t personally have any practical uses for this, but I think it\u0026rsquo;ll be a valuable tool in future CTF challenge development.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I intend to submit as a performing artist as well as submit a soundtrack track again this year. The beat structure is finalized and it\u0026rsquo;s time to start writing.\u003c/li\u003e\n\u003c/ul\u003e\n"
        },
        {
            "title": "Weekly Retro 2025-W08",
            "date_published": "2025-02-23T12:38:51-08:00",
            "date_modified": "2025-02-23T14:28:06-08:00",
            "id": "https://0xda.de/blog/2025/02/weekly-retro-2025-w08/",
            "url": "https://0xda.de/blog/2025/02/weekly-retro-2025-w08/",
            "content_html": "\u003cp\u003eI got obsessed with a problem at work this week - how do you build a useful audit log framework, where the audit logs are useful and the framework is easy for developers to integrate with. Boy what a rabbit hole. This weekend I spent a good chunk of time workin on my Natlas rewrite in Django, keeping in mind some of my immediate learnings about audit logs.\u003c/p\u003e\n\u003ch2 id=\"designing-an-audit-log-framework\"\u003eDesigning an Audit Log Framework\u003c/h2\u003e\n\u003cp\u003eBefore diving into this topic, I want to caveat that I had absolutely no prior knowledge on designing audit logs before this past week. With that in mind, I set out to figure out what makes a good audit log framework. The right amount of structure, the right amount of flexibility, and hopefully something that integrates well with the application.\u003c/p\u003e\n\u003cp\u003eInitial attempts at the audit log had some of the basic ideas in place. From the beginning, I had this idea that audit logs were made up of 3 things \u0026ndash; actors, subjects, and events. The actor is the entity that triggered the event. The subject is the entity that is being acted upon. The event is the details unique to the thing that happened. We stored the id and type of each actor and subject, as well as an event type and some arbitrary metadata.\u003c/p\u003e\n\u003cp\u003eBut there were a few problems. The event was super flat, mixing concerns between actor, subject, event, and request metadata all as top level keys. Second, our first approach took a \u0026ldquo;hydrate useful user-facing information at query, rather than at emit\u0026rdquo; \u0026ndash; so to render audit logs required \u003cem\u003eat least\u003c/em\u003e two additional database queries for each audit log entry.\u003c/p\u003e\n\u003cp\u003eI could, and probably will, create a whole blog post on this topic, because I think there\u0026rsquo;s a lot to consider. In fact, my friend Adam has already published a \u003ca href=\"https://www.technowizardry.net/2022/05/how-to-build-a-useful-service-data-change-audit-log/\"\u003euseful post about building audit logs\u003c/a\u003e, though his focus was a little different than what I am working towards building. Some of the concepts absolutely overlap, though.\u003c/p\u003e\n\u003cp\u003eThe last thing I will say about audit logs is that it is useful to have a single ID that can reference different entities in your data models. This is probably an auto-incrementing integer for most people using an RDBMS. In some cases maybe people are using a UUID instead of an auto-incrementing integer. But I don\u0026rsquo;t really like either of these options. UUIDs don\u0026rsquo;t contain any information about what the ID is for. Integers reveal potentially sensitive information about business velocity, in addition to not being useful to identify a particular object outside of context. E.g. if you sell widgets, and a customers audit log shows that they bought widget 123 on Monday and widget 124 on Tuesday, they can infer that you had no other widget sales during that time.\u003c/p\u003e\n\u003cp\u003eInstead, I think we should construct IDs for our database models that are based on the type of data they are. Stripe is a great example of this where they provide IDs for basically every resource you can fetch or reference, and they tend to all have a unique prefix. Just by looking at the ID, you can tell what kind of resource it is referencing. E.g. a user might have an ID in your database of \u003ccode\u003euser_8hWAb-kHmq5nmfE-xPggAA\u003c/code\u003e, or a widget might have an ID of \u003ccode\u003ewdgt_fwz7uz86mmt1Crr2D-jnPA\u003c/code\u003e. I personally think it should be used as the primary key, so that you really do have just one way to reference it. You \u003cem\u003ecould\u003c/em\u003e add an \u003ccode\u003eexternal_id\u003c/code\u003e or some way to derive an externally facing ID from an integer primary key, but now you have two different ways to refer to the same thing, which is likely to result in mistakes or confusion.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m sure some database admins hate this idea, I do think it has some drawbacks. For instance, IDs are no longer ordered, so you need another way to order objects (you should probably be timestamping your objects anyways). IDs also go from being allocated 32 or 64 bits of space per row to being allocated many bytes (my examples above are 27 bytes long, or 218 bits per row). But the space allocation doesn\u0026rsquo;t really matter if you have to come up with and store an external ID anyways.\u003c/p\u003e\n\u003cp\u003eAnyways, I\u0026rsquo;m kind of obsessed with this problem, and am even accounting for it in the initial designs of my Natlas django rewrite.\u003c/p\u003e\n\u003ch2 id=\"natlas-django-rewrite\"\u003eNatlas Django Rewrite\u003c/h2\u003e\n\u003cp\u003eAs mentioned last week, I talked about whether or not my scan data should just be stored in an RDBMS instead of in elasticsearch, and whether or not I want to rewrite it in Django.\u003c/p\u003e\n\u003cp\u003eFor all of it\u0026rsquo;s flaws (and by that I mean design decisions that I personally would do differently), Django provides a super useful framework for python web apps. It\u0026rsquo;s definitely more batteries-included than alternatives like Flask, FastAPI, Starlette, etc. At first I resisted this, but after working on Natlas again more with flask, I really missed the batteries that Django included by default, and even moreso, I missed the Django ecosystem.\u003c/p\u003e\n\u003cp\u003eI started the rewrite in Django yesterday. By simply adding a popular django app, \u003ca href=\"https://docs.allauth.org/en/latest/\"\u003edjango-allauth\u003c/a\u003e, I already have a more robust auth flow, with signup, MFA, email confirmation, session management forgot password, etc. Of course I have some work to do to style it and make it look how I want and feel integrated with the rest of the application, but that is child\u0026rsquo;s play compared to having to build that all out myself in a bespoke manner. And then there\u0026rsquo;s \u003ca href=\"https://anymail.dev/en/stable/\"\u003edjango-anymail\u003c/a\u003e, which lets me basically build my email system exactly once, but allow anyone who wants to run their own instance to setup any mail sending platform they want, by just swapping the backend with one that anymail already supports.\u003c/p\u003e\n\u003cp\u003eThis rewrite is going to take quite a while and basically completely abandon the old code. There are features I previously wrote that are broken now, features that I over-complicated, things that simply don\u0026rsquo;t scale well for the types of installations that I know natlas users have.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m using this framework switch as an opportunity to basically start fresh. Which basically means that it\u0026rsquo;s going to \u003cem\u003eappear\u003c/em\u003e that there\u0026rsquo;s no real movement on Natlas for quite a while. But then there\u0026rsquo;s going to be a ton of movement all at once.\u003c/p\u003e\n\u003ch2 id=\"what-im-reading\"\u003eWhat I\u0026rsquo;m Reading\u003c/h2\u003e\n\u003cdiv class=\"infobox bookbox\"\u003e\n    \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n  \n  \n    \n    \n    \n    \n    \n    \n    \n    \n  \u003cpicture\u003e\n    \u003csource srcset=\"/img/books/ChasingShadows-RonaldDeibert_hu_6aca9c0278ea3635.webp\" type=\"image/webp\" /\u003e\n  \u003cimg class=\"book-cover\" src=\"/img/books/ChasingShadows-RonaldDeibert.99eb242711d02fd63a723b933e89260f.jpg\" alt=\"Chasing Shadows: Cyber Espionage, Subversion, and the Global Fight for Democracy\" loading=\"lazy\" height=\"1996\" width=\"1400\" /\u003e\n\u003c/picture\u003e\n\n    \u003cdiv\u003e\n        \u003cspan class=\"book-details\"\u003e\n            \u003ch3\u003eChasing Shadows\u003c/h3\u003e\n            \u003ch4\u003eBy Ronald J. Deibert\u003c/h4\u003e\n            \u003cstrong\u003eISBN: 978-1-668-01404-2\u003c/strong\u003e\u003cbr\u003e\n            \u003ca href=\"https://www.simonandschuster.com/books/Chasing-Shadows/Ronald-J-Deibert/9781668014042\" title=\"Learn More About The Book\"\u003eLearn More\u003c/a\u003e\n        \u003c/span\u003e\n        \u003chr\u003e\n        \u003cspan class=\"book-details\"\u003eI haven\u0026rsquo;t been reading much lately, but I was excited to see this book announced and I picked it up immediately. I\u0026rsquo;m about 5 chapters in right now and I\u0026rsquo;m really enjoying hearing about Citizen Lab\u0026rsquo;s side of the stories that I\u0026rsquo;ve seen in the news. If you\u0026rsquo;re interested in the global surveillance and spyware market and how a small group of talented researchers have been fighting back for over a decade, I highly recommend picking this up.\u003c/span\u003e\n    \u003c/div\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=q47UJkD7tQw\"\u003ePROTOCOL - Internet Assigned Numbers Authority (IANA) \u003c/a\u003e - My third week in a row with another episode of PROTOCOL. This one covers the Internet Assigned Names Authority, or IANA, and whether or not assigned port numbers really means much these days.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.cape.co/\"\u003eCape MVNO\u003c/a\u003e - I saw these guys at Shmoocon, and in an \u003ca href=\"https://www.404media.co/i-dont-own-a-cellphone-can-this-privacy-focused-network-change-that/\"\u003earticle from Joseph Cox\u003c/a\u003e, and I\u0026rsquo;m really interested in their offering. Unfortunately I can\u0026rsquo;t switch unless I get a new number, and I\u0026rsquo;m not sure if I want to move my existing phone number over to Google Voice (where I already have 3 of my previous phone numbers). I\u0026rsquo;d like to rely \u003cem\u003eless\u003c/em\u003e on google. Are there good Google Voice alternatives for phone number forwarding?\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://jacobitesolutions.com/product/skeletonised-travelers-hook/\"\u003eSkeletonised Travelers Hook\u003c/a\u003e - I saw this in a Deviant Ollam post and would love to pick one up, but don\u0026rsquo;t know about the shipping costs right now. Will wait til I have a reason to order a few.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://startacomputer.club/\"\u003eStart A Computer Club\u003c/a\u003e - I\u0026rsquo;m a computer, you\u0026rsquo;re a computer, let\u0026rsquo;s computer computers together.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://trufflesecurity.com/blog/removing-jeff-bezos-from-my-bed\"\u003eRemoving Jeff Bezos from my Bed\u003c/a\u003e - Does a random startup engineer have ssh access to \u003cem\u003eyour\u003c/em\u003e bed?\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://cellularsecurity.org/ransacked\"\u003eRansacked\u003c/a\u003e - A whole bunch of cellular vulnerabilities. Cool to see research in this space being published, even if I don\u0026rsquo;t understand most of what this is talking about \u0026#x1f602;.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://jazco.dev/2025/02/19/imperfection/\"\u003eImperfect Systems are Good, Actually\u003c/a\u003e - An interesting post about Bluesky\u0026rsquo;s lossy timelines and how it improves the performance of writes significantly without degrading performance for users. I appreciate the level of transparency we get from the Bluesky team, and one day I\u0026rsquo;ll run my own PDS.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/\"\u003eReviewing the Cryptograhy Used by Signal\u003c/a\u003e - I have seen Soatok\u0026rsquo;s posts before, and I just wanted to call this one out \u0026ndash; I think more security people should review open source things and produce \u0026ldquo;reports\u0026rdquo; for general consumption. I am already looking at projects that I think could be interesting/useful to review \u0026ndash; though I\u0026rsquo;m not cryptographer so the likelihood of me finding a sick bug in Signal seems low \u0026#x1f602;.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://corrode.dev/blog/prototyping/\"\u003ePrototyping in Rust\u003c/a\u003e - An itneresting and useful post about prototyping in rust and how to make it more effective. Probably still not as quick to prototype as python, but far less likely to have a million runtime bugs, too.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I intend to submit as a performing artist as well as submit a soundtrack track again this year. I have a rough beat to work with and am very excited about the concept.\u003c/li\u003e\n\u003c/ul\u003e"
        },
        {
            "title": "Weekly Retro 2025-W07",
            "date_published": "2025-02-16T15:30:41-08:00",
            "date_modified": "2025-02-23T14:17:19-08:00",
            "id": "https://0xda.de/blog/2025/02/weekly-retro-2025-w07/",
            "url": "https://0xda.de/blog/2025/02/weekly-retro-2025-w07/",
            "content_html": "\u003cp\u003eThis is going to be a pretty short one, I had an all-week event at work last week so I didn\u0026rsquo;t have a lot of time to do things that I would talk about on here.\u003c/p\u003e\n\u003ch2 id=\"sephiroth-updates\"\u003eSephiroth Updates\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/0xdade/sephiroth\"\u003eSephiroth\u003c/a\u003e is a tool I wrote many years ago to help build block lists for common server platforms that might want to behave differently for different IP addresses. It is so named because the main target was \u0026ldquo;I want to block the cloud\u0026rdquo;, and I liked Final Fantasy 7.\u003c/p\u003e\n\u003cp\u003eAnyways, this week saw a number of updates, including a new contributor. \u003ca href=\"https://github.com/DEVisions\"\u003eDEVisions\u003c/a\u003e added support for Caddy\u0026rsquo;s newer format, and I added support for \u003ca href=\"https://github.com/0xdade/sephiroth/issues/82\"\u003eblocking Vultr ip ranges\u003c/a\u003e as well as a meta \u0026ldquo;target\u0026rdquo; \u003ccode\u003e_all\u003c/code\u003e which will let you build a blocklist for all of the providers Sephiroth knows about.\u003c/p\u003e\n\u003cp\u003eI also did a bunch of work on setting up automatic deployments for the docker container as well as a trusted publisher workflow for PyPI, that way it\u0026rsquo;ll be easier for me in the future to come back, fix or add something, and cut a new release without having to remember how to do everything.\u003c/p\u003e\n\u003cp\u003eIf you know of authoritative first-hand ways to get IP ranges for IBM Cloud, Salesforce, various VPN providers, Tencent Cloud, Alibaba Cloud, etc, I would love if you opened an issue with the details. Specifically I want things that are more detailed than \u0026ldquo;here\u0026rsquo;s their ASN.\u0026rdquo;\u003c/p\u003e\n\u003ch2 id=\"natlas-on-my-mind\"\u003eNatlas On My Mind\u003c/h2\u003e\n\u003ch3 id=\"is-my-data-relational-after-all\"\u003eIs my data relational after all?\u003c/h3\u003e\n\u003cp\u003eI spent a decent amount of time this week thinking about changes to Natlas. I have a branch where I was working on cutting over to the elasticsearch-dsl library so that I could have object-mapped documents. But the more I thought about it, the more I thought maybe what I actually want is just\u0026hellip; to store my scan data in a relational database.\u003c/p\u003e\n\u003cp\u003eElasticsearch has been great, helpful, just shove files into it and worry about it later. Expose the query language directly to the user. No worries. But as I\u0026rsquo;ve evolved as a developer, and as I\u0026rsquo;ve looked into more advanced features, it\u0026rsquo;s become evident that this has been a limiting factor. For instance, it is hard to do port-level statistics with my current elastic document structure. I could break it out so that I have ports as individual documents, but now I have relationships in my elasticsearch data, but not explicitly.\u003c/p\u003e\n\u003cp\u003eThe biggest downside to this change would be that I wouldn\u0026rsquo;t have the elastic query language at my disposal anymore, so I\u0026rsquo;d need to come up with a query language / query builder to enable basically all the same things that I currently already get for free. But, there\u0026rsquo;s also an upside.\u003c/p\u003e\n\u003ch3 id=\"natlas-as-a-dns-recon-platform\"\u003eNatlas as a DNS Recon Platform\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;ve long been obsessed with DNS reconnaissance. I love it, and I specifically love the challenge of finding all the domain names that point to an IP address, given the distributed nature of the DNS hierarchy. I have access to a bunch of TLD zones now, and I would love to hook this up to Natlas and allow natlas to collect more domain-aware information. Screenshots of web services on different vhosts. Web fingerprints of those services. Etc.\u003c/p\u003e\n\u003cp\u003eIf I bring my port scan data into postgres, along with all of this DNS data, I could start to construct really interesting queries and do interesting research.\u003c/p\u003e\n\u003ch3 id=\"natlas-as-a-django-app\"\u003eNatlas as a\u0026hellip; Django app\u003c/h3\u003e\n\u003cp\u003eOne thing that has been weighing on me with Natlas is it\u0026rsquo;s usage of Flask. It\u0026rsquo;s been fun and challenging to rewrite a bunch of things to work with the modern sqlalchemy, and I generally like the batteries-not-included nature of flask. I like that there isn\u0026rsquo;t a lot of magic. Just functions that run when you make a GET request, or functions that run when you make a POST request, etc.\u003c/p\u003e\n\u003cp\u003eBut the flask ecosystem feels considerably less polished than the Django ecosystem, and a number of useful tools that I\u0026rsquo;d like to use are not availble except as django apps. Examples include django-anymail, dj-stripe, the django-debug-toolbar, and djangoql. Anymail alone feels like enough of a reason to switch, if I\u0026rsquo;m being honest.\u003c/p\u003e\n\u003cp\u003eAnother benefit of switching to django is that django is used by a lot of companies, so there are a lot of Django developers out there. So if, in the future, I\u0026rsquo;m able to turn this into an actual project that makes money, I\u0026rsquo;d be able to find developers who are familiar with the paradigm we\u0026rsquo;re working in.\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;d just ban the use of things like \u003ca href=\"https://0xda.de/blog/2024/02/why-i-hate-modelform-modelserializer/\"\u003eModelForm\u003c/a\u003e and enforce \u003ca href=\"https://0xda.de/blog/2024/03/untyped-python-sucks/\"\u003estrict typing\u003c/a\u003e from the beginning, to curb some of the problems I have with Django, I suppose.\u003c/p\u003e\n\u003cp\u003eBut I will say\u0026hellip; the thought of basically doing a complete framework rewrite (every view has to change, every database query has to change, every ORM model has to change, every template file has to change, etc), all to just get the project back to exactly where it is right now but with a different framework? That sounds terrible\u0026hellip; Stay tuned to see if I do it, I guess.\u003c/p\u003e\n\u003ch2 id=\"interesting-links\"\u003eInteresting Links\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=RG_RZi_6hwk\"\u003ePROTOCOL - Internet Engineering Task Force\u003c/a\u003e - My second episode of PROTOCOL is out, talking about the IETF and RFCs. It didn\u0026rsquo;t get as much attention as my first episode, but nevertheless I persist. My next episode is about IANA and will be out on Wednesday at 10am Pacific!\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://evilmartians.com/chronicles/oklch-in-css-why-quit-rgb-hsl\"\u003eOKLCH in CSS\u003c/a\u003e - CSS 4 introduces a new way to declare colors and color palettes. Pretty interesting stuff.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://techlog.jenslink.net/posts/ipv6-is-hard/\"\u003eIPv6 is Hard\u003c/a\u003e - IPv6 is hard, except it\u0026rsquo;s not \u003cem\u003ethat\u003c/em\u003e hard, and setting it up in a broken state is worse than not setting it up at all, because it contributes to the notion that it\u0026rsquo;s hard.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://neon.tech/postgresql/postgresql-tutorial/postgresql-upsert\"\u003ePostgresql Upserts\u003c/a\u003e - As I\u0026rsquo;m doing a lot of research into efficient database queries to deal with millions of updates a day, I found this article on the notion of an \u0026ldquo;upsert\u0026rdquo; really helpful.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://codepen.io/tijsvl/pen/pvoJoxM\"\u003eHTML Legends Example\u003c/a\u003e - This is just a cool codepen I saw that creates a nice effect for legends on form fields in HTML. Looks nice.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://brutecat.com/articles/leaking-youtube-emails\"\u003eLeaking Youtube Emails for $10,000\u003c/a\u003e - An interesting and elaborate attack to leak the email address associated with any youtube channel.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://kasmweb.com/\"\u003eKasm Workspaces\u003c/a\u003e - I saw this in a Lawrence Systems video and it seems super useful to host some virtual browsers and whatnot locally on my network. I haven\u0026rsquo;t tried it yet, but I really like the idea, and I\u0026rsquo;ll like it even more if I can setup different virtual browser profiles with different vpn settings, accounts, extensions, etc.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.quantamagazine.org/undergraduate-upends-a-40-year-old-data-science-conjecture-20250210/\"\u003eUndergrad upends 40-year-old data science conjecture\u003c/a\u003e - An undergrad student found an interesting way to search hash tables much faster than previously thought possible. No idea if we\u0026rsquo;ll see this in real application anytime soon, but it\u0026rsquo;s pretty interesting nonetheless.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"upcoming-projects\"\u003eUpcoming Projects\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://defconmusic.org/def-con-33-call-for-music-tracks/\"\u003eDefcon Call for Music/Tracks\u003c/a\u003e - I intend to submit as a performing artist as well as submit a soundtrack track again this year. I have a really fun idea for a track and am currently waiting on production.\u003c/li\u003e\n\u003cli\u003eI want to publish one non-PROTOCOL video this month. I think I might publish a video on invalid nameserver research, because I think it\u0026rsquo;s pretty interesting.\u003c/li\u003e\n\u003c/ul\u003e\n"
        }
        ]
}
