OAuth 2.1 for a Personal MCP Server: What Three Months in Production Changed | aliasunder How an open-source MCP server for one Obsidian vault does OAuth 2.1: the threat model, each decision and its trade-off, and what three months in production changed.
The holy grail of nixpkgs: version ranges Update You can try this live at fzakaria.github.io/grail and query nixpkgs version ranges in your browser, the same solver, compiled to WebAssembly.
Sharing Application State in a URL How to store application state in a URL fragment without a backend, including Base64url encoding, compression benchmarks, browser history, and URL limits.
Singularity Rootkit: Evading Elastic Defend Module Load Detection Elastic Defend 9.5 added taint_flags to the module_load BPF event and a new detection rule on top of it. Here is how Singularity loads clean: source obfuscation for YARA, trusted_pids insertion for the BPF hook, and OBF_OUT=/var/lib/dkms for the .ko creat...
You're Not in the Loop Anymore. You're Running the Loops. AI agents can do real engineering work now. The bottleneck is no longer typing. It's coordination and judgment, and one person can now run a dozen loops at once.
Complicated vs. Complex One of the hardest parts of moving from software engineer into leadership wasn't that the problems got harder. It was that I could no longer tell afterwards whether I'd got them right - which is roughly the difference between a complicated problem and a c...
rooting a fire hd 10 because apparently i have problems rooting a fire hd 10 because apparently i have problems
Why I run Claude Code on a server (box) How I moved Claude Code off my laptop onto a Hetzner box behind Tailscale, with mosh, tmux, scoped credentials instead of permission prompts, and what broke.
The index was lying and the eval knew — Gil Neto Six weeks after I fixed capture with hooks, my second brain was still confidently wrong. The nightly test had been saying so for a month. Nobody read the number.
Learnings from the Codex repo I’ve been fascinated recently at what the best practices in the new age of engineering look like. But it’s hard to find real data on best practices. For example, X has a ton of …
1Password with an unbelievable own goal Andrew Lilley Brinker: 1Password Supports the Ethnic Cleansing of Europe Omarchy is a Linux distribution created and controlled by David Heinemeier Hansson, usually known as DHH. DHH is the founder and CTO of 37signals (formerly Basecamp) and creator of ...
Platform Adoption: Tooling, Training, Buy-In Building a fleet platform is one half. The other half is teaching people to use it: self-serve tools, repeated training.
Why Spec-Driven Development Tools Fail in the Enterprise - Martinelli The spec-driven development (SDD) movement is gaining momentum. Tools like Amazon Kiro, GitHub Spec Kit, and BMad Method promise to bring structure to AI-assisted coding. And they deliver on that promise, as long as you start from scratch.
My practical approach to surfing the web safely – How I use browsers for privacy and security How I use browsers for privacy and security
Why is Staff Scheduling Hard? Summary of why employee scheduling and staff planning is harder than it might seem.
9000 RPM is faster than your screen refreshes An animation to show how a sports engine actually moves at 9000 RPM: 150 crankshaft revolutions per second, on an inline-4, V6, boxer-6 or flat-plane V8.
Slicing Chrome's Zucchini Patches in Half Chrome's own updater ships a 5.9 MB patch between two stable releases. A prediction-based differ gets the same pair to 2.3 MB, byte-for-byte exact.
Muse Spark 1.3 | Meta Trained for agentic workflows and optimized for competitive coding performance.
How to protect yourself from workslop “Workslop” is when your colleagues or bosses communicate with you by pasting big chunks of AI-generated text. The core problem with workslop is that the effort…