<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Michael Asante </title>
    <description>The latest articles on DEV Community by Michael Asante  (@cybersense).</description>
    <link>https://dev.to/cybersense</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4114694%2Fa3cbebcf-0b85-4ac7-baff-08d1d10eca2b.jpeg</url>
      <title>DEV Community: Michael Asante </title>
      <link>https://dev.to/cybersense</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/cybersense"/>
    <language>en</language>
    <item>
      <title>How AI Is Being Used to Scam People in West Africa Right Now</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Mon, 28 Sep 2026 09:42:43 +0000</pubDate>
      <link>https://dev.to/cybersense/how-ai-is-being-used-to-scam-people-in-west-africa-right-now-3lco</link>
      <guid>https://dev.to/cybersense/how-ai-is-being-used-to-scam-people-in-west-africa-right-now-3lco</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;⚠️ CyberSense Ghana | Awareness Series&lt;/strong&gt; — This article is for educational&lt;br&gt;
purposes. Recognising these tactics is your first line of defence.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Artificial intelligence is no longer just a tool for developers and researchers.&lt;br&gt;
In 2024–2026, it has become a weapon — and nowhere is that more evident than&lt;br&gt;
across West Africa, where a new wave of AI-powered scams is targeting millions&lt;br&gt;
of everyday people through their phones, social media feeds, and mobile money&lt;br&gt;
wallets.&lt;/p&gt;

&lt;p&gt;Here is what is happening right now, and how to protect yourself.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. AI-Generated Voice Cloning ("The Family Emergency" Scam)
&lt;/h2&gt;

&lt;p&gt;Scammers are now using AI tools that can clone a person's voice from as little&lt;br&gt;
as &lt;strong&gt;three seconds of audio&lt;/strong&gt;. They scrape voice samples from TikTok videos,&lt;br&gt;
WhatsApp voice notes, or Facebook reels, then use that clone to call relatives.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it works:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
You get a call. It sounds &lt;em&gt;exactly&lt;/em&gt; like your sister or son. They say they are&lt;br&gt;
in trouble — arrested, hospitalised, or stranded — and beg you to send Mobile&lt;br&gt;
Money immediately. By the time you verify with a second call, the money is gone.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;This is happening in Ghana, Nigeria, and Côte d'Ivoire.&lt;/strong&gt; AI voice tools&lt;br&gt;
like ElevenLabs (misused outside its intended purpose) have made this alarmingly&lt;br&gt;
easy to deploy at scale.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Agree on a secret family code word that no scammer could know.&lt;br&gt;
Always call back on a number you saved yourself before sending any money.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Deepfake Video Scams on Social Media
&lt;/h2&gt;

&lt;p&gt;AI deepfake technology can now place a real politician's or celebrity's face&lt;br&gt;
onto a fabricated video body in minutes. Scammers use footage of well-known&lt;br&gt;
figures — pastors, MPs, musicians — to promote fake investment schemes,&lt;br&gt;
giveaways, or loan programmes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The typical script:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
"I invested GHS 500 and received GHS 4,000 in three days." The video looks&lt;br&gt;
authentic. The voice sounds genuine. The subtitles match. But every second of&lt;br&gt;
it is AI-generated.&lt;/p&gt;

&lt;p&gt;Victims in Ghana, Senegal, and Togo have reported losing savings after trusting&lt;br&gt;
what they saw in these videos on Facebook and TikTok.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Reverse-image-search any thumbnail. Real giveaways from&lt;br&gt;
credible sources are always announced on verified accounts with a long post&lt;br&gt;
history. If a face looks slightly blurry around the edges or the mouth movement&lt;br&gt;
feels slightly off — trust that instinct.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. AI-Powered Phishing Texts and Emails
&lt;/h2&gt;

&lt;p&gt;Previously, scam messages were easy to spot because of poor spelling and&lt;br&gt;
awkward phrasing. &lt;strong&gt;AI has erased that advantage.&lt;/strong&gt; Tools like ChatGPT can now&lt;br&gt;
generate flawless, contextually accurate phishing messages in Twi, Hausa,&lt;br&gt;
Pidgin, Yoruba, and French.&lt;/p&gt;

&lt;p&gt;Scammers are sending messages that perfectly impersonate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;GRA (Ghana Revenue Authority) tax refund notices&lt;/li&gt;
&lt;li&gt;MTN MoMo security alerts&lt;/li&gt;
&lt;li&gt;Airtel Money transaction confirmations&lt;/li&gt;
&lt;li&gt;NHIS insurance renewal reminders&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The messages include correct logos, real-sounding reference numbers, and&lt;br&gt;
urgency — "Your account will be suspended in 24 hours." They link to near-perfect&lt;br&gt;
clone websites that harvest your PIN or ID details.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Never click links in SMS or email messages. Always go directly&lt;br&gt;
to the official app or website yourself. Organisations like GRA and MoMo will&lt;br&gt;
&lt;em&gt;never&lt;/em&gt; ask for your PIN via SMS.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Romance Scams Supercharged by AI Chatbots
&lt;/h2&gt;

&lt;p&gt;Traditional romance scams required a human operator available 24/7 to maintain&lt;br&gt;
conversation. Now, AI chatbots handle hundreds of victims simultaneously — day&lt;br&gt;
and night, in multiple languages.&lt;/p&gt;

&lt;p&gt;The bot builds trust over weeks through WhatsApp or Instagram. It learns your&lt;br&gt;
patterns. It sends good-morning messages. It asks about your family. Eventually,&lt;br&gt;
it introduces a "business opportunity" or a fake emergency requiring money.&lt;/p&gt;

&lt;p&gt;AI detection studies show that &lt;strong&gt;many victims cannot distinguish a chatbot from&lt;br&gt;
a human&lt;/strong&gt; after two weeks of interaction, especially when the scammer supplements&lt;br&gt;
with an occasional real voice call to reinforce the illusion.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Be alert if someone you met online is always "too busy" for a&lt;br&gt;
live video call, never available in real-time, or quickly steers conversations&lt;br&gt;
toward financial matters. Ask unexpected questions — AI chatbots struggle with&lt;br&gt;
deeply personal, spontaneous responses.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. AI Business Impersonation (The "Vendor" Scam)
&lt;/h2&gt;

&lt;p&gt;Fraudsters are using AI to create convincing fake businesses — complete with&lt;br&gt;
a generated logo, a professional-looking website, realistic product photos&lt;br&gt;
(AI-generated), and even fake customer testimonials written by an AI.&lt;/p&gt;

&lt;p&gt;They then approach SME owners on WhatsApp or by phone, posing as suppliers of&lt;br&gt;
goods — electronics, cocoa processing equipment, construction materials — offering&lt;br&gt;
a "limited-time" deal. Payment is requested upfront. The supplier disappears.&lt;/p&gt;

&lt;p&gt;This scam is particularly devastating for traders and small business owners&lt;br&gt;
in markets across Accra, Lagos, Abidjan, and Kumasi.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Always verify a supplier physically or through a known third&lt;br&gt;
party before making payments. Check whether their website domain is new (use&lt;br&gt;
&lt;code&gt;whois&lt;/code&gt; lookup tools). Be extremely cautious of any vendor who only communicates&lt;br&gt;
via WhatsApp with no physical address.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Bottom Line: Think. Check. Consider.
&lt;/h2&gt;

&lt;p&gt;AI has lowered the cost and raised the quality of deception. Scammers no longer&lt;br&gt;
need technical skill — they need a phone and a free AI account.&lt;/p&gt;

&lt;p&gt;Your defence is not technology. It is &lt;strong&gt;habit&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Think&lt;/strong&gt; before you act on any urgent request&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check&lt;/strong&gt; by verifying through a second, independent channel&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Consider&lt;/strong&gt; whether this situation makes sense&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Share this article with family members — especially older relatives and traders&lt;br&gt;
who may not be aware of these new tactics. The more people who understand how&lt;br&gt;
AI is being weaponised, the harder it becomes for scammers to succeed.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by @cybersense101 | CyberSense Ghana — Cybersecurity Awareness for&lt;br&gt;
West Africa. Follow us on TikTok, LinkedIn, and dev.to for more.&lt;/em&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  cybersecurity #AI #Ghana #WestAfrica #ScamAlert #CyberSenseGhana
&lt;/h1&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>africa</category>
      <category>scam</category>
    </item>
    <item>
      <title>What I Learned Building a Multi-Tenant SaaS as a Final Year Student</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Thu, 17 Sep 2026 13:57:11 +0000</pubDate>
      <link>https://dev.to/cybersense/what-i-learned-building-a-multi-tenant-saas-as-a-final-year-student-9ce</link>
      <guid>https://dev.to/cybersense/what-i-learned-building-a-multi-tenant-saas-as-a-final-year-student-9ce</guid>
      <description>&lt;p&gt;&lt;em&gt;By Bigwig |&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;Most final year CS students build a project that lives on a USB drive, gets presented to a panel, and is never opened again.&lt;/p&gt;

&lt;p&gt;Mine is live. It has real businesses on it. Real transactions. Real data.&lt;/p&gt;

&lt;p&gt;I'm a final year Networking and Software Systems student at Presbyterian University Ghana (PUG), based in the Kwahu area of the Eastern Region. While preparing for my academic defense, I independently built and deployed &lt;strong&gt;StockMaster Ghana&lt;/strong&gt; — a multi-tenant SaaS POS and business management system serving small and medium businesses in my community.&lt;/p&gt;

&lt;p&gt;This is what I learned. Not from a tutorial. From actually doing it.&lt;/p&gt;




&lt;h2&gt;
  
  
  First, What Is Multi-Tenancy?
&lt;/h2&gt;

&lt;p&gt;Before I get into the lessons, let me explain what I mean by multi-tenant — because it took me a while to really get it.&lt;/p&gt;

&lt;p&gt;A &lt;strong&gt;single-tenant&lt;/strong&gt; app is like a house. One family lives there. Everything is built for them.&lt;/p&gt;

&lt;p&gt;A &lt;strong&gt;multi-tenant&lt;/strong&gt; app is like an apartment building. Many tenants share the same infrastructure — same roof, same plumbing, same electricity grid — but each tenant has their own private space and can't access anyone else's.&lt;/p&gt;

&lt;p&gt;In SaaS terms: one codebase, one database, many businesses — each seeing only their own data.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Single-tenant:    App A → Database A
                  App B → Database B  (separate deployments)

Multi-tenant:     App → Database
                          ├── Tenant A's data
                          ├── Tenant B's data
                          └── Tenant C's data  (one deployment)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Getting this architecture right is where most beginners (myself included, at first) trip up.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Stack I Chose and Why
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Frontend:&lt;/strong&gt; React + Vite&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Backend/Database:&lt;/strong&gt; Supabase (PostgreSQL)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auth:&lt;/strong&gt; Supabase Auth&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deployment:&lt;/strong&gt; Vercel&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Payments:&lt;/strong&gt; MTN MoMo API integration (for the Ghanaian market)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I chose this stack for one reason: &lt;strong&gt;I could move fast without a dedicated backend server.&lt;/strong&gt; Supabase gave me a full PostgreSQL database, authentication, Row-Level Security, and real-time subscriptions — all without spinning up a separate API server. For a solo student developer, that's a superpower.&lt;/p&gt;




&lt;h2&gt;
  
  
  Lesson 1: Row-Level Security Is Not Optional
&lt;/h2&gt;

&lt;p&gt;This was my biggest early mistake.&lt;/p&gt;

&lt;p&gt;I launched the first version of StockMaster Ghana without properly enabling Row-Level Security (RLS) on all my Supabase tables. Technically, each business had a &lt;code&gt;tenant_id&lt;/code&gt; column — but without RLS enforced at the database level, the only thing keeping Business A from seeing Business B's data was my frontend logic.&lt;/p&gt;

&lt;p&gt;Frontend logic can be bypassed. A database policy cannot.&lt;/p&gt;

&lt;p&gt;Here's the kind of RLS policy I ended up implementing:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="c1"&gt;-- Enable RLS on the sales table&lt;/span&gt;
&lt;span class="k"&gt;ALTER&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="n"&gt;sales&lt;/span&gt; &lt;span class="n"&gt;ENABLE&lt;/span&gt; &lt;span class="k"&gt;ROW&lt;/span&gt; &lt;span class="k"&gt;LEVEL&lt;/span&gt; &lt;span class="k"&gt;SECURITY&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="c1"&gt;-- Each tenant can only see their own sales&lt;/span&gt;
&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="n"&gt;POLICY&lt;/span&gt; &lt;span class="nv"&gt;"Tenants see own sales"&lt;/span&gt;
&lt;span class="k"&gt;ON&lt;/span&gt; &lt;span class="n"&gt;sales&lt;/span&gt;
&lt;span class="k"&gt;FOR&lt;/span&gt; &lt;span class="k"&gt;ALL&lt;/span&gt;
&lt;span class="k"&gt;USING&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;tenant_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;auth&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;uid&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After I enabled RLS across all 12 tables, I could sleep at night knowing that even if someone manipulated a request, the database itself would reject unauthorised access.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: Never trust the frontend to enforce data isolation. Do it at the database level.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Lesson 2: The Duplicate INSERT Bug That Almost Broke Everything
&lt;/h2&gt;

&lt;p&gt;At one point, I had a live business — MMAT Plus Hub, a coated peanuts production company — actively using the system. When they recorded a sale, it was occasionally being inserted into the database &lt;strong&gt;twice&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Two records. One transaction. Double the stock deduction. Chaos.&lt;/p&gt;

&lt;p&gt;The root cause? A React state update was triggering my form submission handler twice under certain conditions — a classic issue with &lt;code&gt;useEffect&lt;/code&gt; dependencies and event handlers not being properly cleaned up.&lt;/p&gt;

&lt;p&gt;The fix involved:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Adding a submission lock to prevent duplicate inserts&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;isSubmitting&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;setIsSubmitting&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;useState&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;handleSale&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;async &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;saleData&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;if &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;isSubmitting&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="c1"&gt;// Guard against double submission&lt;/span&gt;
  &lt;span class="nf"&gt;setIsSubmitting&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;supabase&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;sales&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;insert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;saleData&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;finally&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;setIsSubmitting&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
  &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But the deeper fix was adding a &lt;strong&gt;Postgres trigger&lt;/strong&gt; that automatically reconciled financial records on the production line — so even if a duplicate slipped through, the financial totals would self-correct.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: Optimistic UI is great. Idempotent database operations are essential.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Lesson 3: One 8,600-Line File Is a Time Bomb
&lt;/h2&gt;

&lt;p&gt;Early in the project, I had one massive file that did everything. Components, API calls, state management, utility functions — all 8,600 lines of it.&lt;/p&gt;

&lt;p&gt;It worked. Until it didn't.&lt;/p&gt;

&lt;p&gt;Adding a new feature meant scrolling through thousands of lines trying to remember where something lived. Fixing one bug would break something three sections down. Code reviews (even solo ones) became painful.&lt;/p&gt;

&lt;p&gt;I eventually did a full modular refactor — splitting the monolith into 13 named modules:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;src/
├── components/
│   ├── Sales/
│   ├── Inventory/
│   ├── Reports/
│   └── Dashboard/
├── hooks/
│   ├── useSales.js
│   ├── useInventory.js
│   └── useTenantData.js
├── lib/
│   ├── supabase.js
│   └── helpers.js
└── pages/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The refactor took a painful weekend. But after it, adding new features became genuinely fun again.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: Start with structure. Refactoring a live production app is far more stressful than getting the architecture right early.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Lesson 4: Building for Your Own Community Is a Cheat Code
&lt;/h2&gt;

&lt;p&gt;I'm from Kwahu. I built StockMaster Ghana for businesses in Kwahu. That context gave me advantages no amount of market research could replicate.&lt;/p&gt;

&lt;p&gt;I knew that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Many SMEs here deal in cash and MoMo, not card payments&lt;/li&gt;
&lt;li&gt;Business owners often share devices with staff — so role-based access control mattered a lot&lt;/li&gt;
&lt;li&gt;Debt tracking (customers buying on credit) is a core part of how local trade works&lt;/li&gt;
&lt;li&gt;Seasonal patterns (Kwahu Easter festival, for example) cause major inventory spikes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These weren't features I found in a product requirements document. They came from conversations with actual users — people I knew.&lt;/p&gt;

&lt;p&gt;When a business like MMAT Plus Hub (which processes coated peanuts for sale) needed a production line reconciliation feature, I could sit with the owner, understand the workflow, and build it in a week.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: Proximity to your users is a competitive advantage. Build for people you can actually talk to.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Lesson 5: Academic Projects and Real Products Need Different Hats
&lt;/h2&gt;

&lt;p&gt;Here's something nobody tells you: building a live product while also writing an academic proposal about it creates a tension you have to manage carefully.&lt;/p&gt;

&lt;p&gt;My department assigned me a different research topic for my final year project — a QR-Based Thesis Deposition System for PUG. That's a genuinely separate problem from StockMaster Ghana, and keeping them distinct matters for academic integrity.&lt;/p&gt;

&lt;p&gt;The lesson I learned: your real-world experience makes you a better researcher, but your research topic needs to stand on its own merits — with its own problem statement, methodology, and contribution to knowledge.&lt;/p&gt;

&lt;p&gt;Don't try to retroactively academise something you already built. Build something new, informed by what you've learned.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: Production experience sharpens your academic instincts. Keep the two outputs honest and distinct.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What I'd Tell My Past Self
&lt;/h2&gt;

&lt;p&gt;If I could go back to when I started StockMaster Ghana, I'd say:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Enable RLS on day one.&lt;/strong&gt; Not after you have real users.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Modularise early.&lt;/strong&gt; One file feels fast until it doesn't.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Write down every bug you fix.&lt;/strong&gt; Those are your best blog posts, conference talks, and interview stories.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ship to real users as fast as possible.&lt;/strong&gt; Feedback from a real business using your system daily is worth more than any tutorial.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Your geography is not a limitation.&lt;/strong&gt; Building in Kwahu, Ghana gave me a unique product with a real user base. That's more than most CS graduates can say.&lt;/li&gt;
&lt;/ol&gt;




&lt;h2&gt;
  
  
  What's Next
&lt;/h2&gt;

&lt;p&gt;StockMaster Ghana is live and growing. My final year project (the QR-Based Thesis Deposition System) is in proposal stage. And I'm documenting all of it here on dev.to and on CyberSense Ghana's platforms.&lt;/p&gt;

&lt;p&gt;If you're a student developer — especially one building in Africa — I'd love to connect. The problems here are real, the users are real, and the opportunity to build something that matters is very real.&lt;/p&gt;

&lt;p&gt;Drop a comment. Let's talk.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Follow CyberSense Ghana &lt;a href="https://tiktok.com/@cybersense101" rel="noopener noreferrer"&gt;@cybersense101&lt;/a&gt; on TikTok, Instagram, and Facebook for cybersecurity awareness content built for West Africa.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;code&gt;#saas&lt;/code&gt; &lt;code&gt;#webdev&lt;/code&gt; &lt;code&gt;#beginners&lt;/code&gt; &lt;code&gt;#programming&lt;/code&gt; &lt;code&gt;#supabase&lt;/code&gt; &lt;code&gt;#react&lt;/code&gt; &lt;code&gt;#africa&lt;/code&gt;&lt;/p&gt;

</description>
      <category>saas</category>
      <category>webdev</category>
      <category>beginners</category>
      <category>programming</category>
    </item>
    <item>
      <title>SIM Swap Attacks: What They Are and How to Protect Your Number</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Wed, 16 Sep 2026 23:38:27 +0000</pubDate>
      <link>https://dev.to/cybersense/sim-swap-attacks-what-they-are-and-how-to-protect-your-number-4335</link>
      <guid>https://dev.to/cybersense/sim-swap-attacks-what-they-are-and-how-to-protect-your-number-4335</guid>
      <description>&lt;p&gt;&lt;em&gt;By CyberSense Ghana |&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;Someone in Ghana woke up one morning, checked their phone, and had no network signal.&lt;/p&gt;

&lt;p&gt;They assumed it was MTN acting up. By the time they figured out what had actually happened, their MoMo wallet was empty, their email had been accessed, and their bank account had been drained.&lt;/p&gt;

&lt;p&gt;That's a SIM swap attack. And it's happening right here in West Africa — more than most people realise.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Is a SIM Swap Attack?
&lt;/h2&gt;

&lt;p&gt;A SIM swap (also called SIM hijacking or SIM porting) is when a scammer convinces your mobile network to transfer your phone number to a SIM card they control.&lt;/p&gt;

&lt;p&gt;Once they have your number, every SMS-based OTP (One-Time Password) that your bank, MoMo wallet, email, or social media sends — goes to &lt;strong&gt;them&lt;/strong&gt;, not you.&lt;/p&gt;

&lt;p&gt;With that one move, they can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Reset your email password&lt;/li&gt;
&lt;li&gt;Log into your mobile money account&lt;/li&gt;
&lt;li&gt;Bypass two-factor authentication on your bank app&lt;/li&gt;
&lt;li&gt;Take over your WhatsApp and scam your contacts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It sounds like something from a hacking movie. It's actually shockingly simple to pull off.&lt;/p&gt;




&lt;h2&gt;
  
  
  How Does It Actually Happen?
&lt;/h2&gt;

&lt;p&gt;Here's the typical attack chain in the West African context:&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 1: They gather your personal info
&lt;/h3&gt;

&lt;p&gt;Scammers collect your name, phone number, date of birth, and sometimes your Ghana Card or NIA details. This comes from:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Data breaches (leaked databases sold online)&lt;/li&gt;
&lt;li&gt;Social engineering (calling you pretending to be your network provider)&lt;/li&gt;
&lt;li&gt;Your own social media posts (yes, that birthday post with your full name and photo helps them)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 2: They call your network provider
&lt;/h3&gt;

&lt;p&gt;The attacker calls MTN, Telecel, or AirtelTigo customer care pretending to be you. They say something like:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;"I lost my SIM card, I need a replacement on a new SIM."&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;They answer security questions using the info they already gathered. If the agent isn't careful, your number is ported to their SIM within minutes.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Your phone loses signal
&lt;/h3&gt;

&lt;p&gt;You notice your phone has no service. You assume it's a network issue. Meanwhile, the attacker is already receiving your OTPs.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: They clean you out
&lt;/h3&gt;

&lt;p&gt;In the time it takes you to visit a service centre and figure out what happened, they've already:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Withdrawn everything from your MoMo&lt;/li&gt;
&lt;li&gt;Transferred money from your linked bank accounts&lt;/li&gt;
&lt;li&gt;Locked you out of your email&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Real Talk: Why Ghana and West Africa Are High-Risk Targets
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MoMo is everything.&lt;/strong&gt; Mobile money is deeply embedded in daily transactions across Ghana, Nigeria, Senegal, and beyond. A compromised number = a compromised wallet.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SMS OTP is still the dominant 2FA method.&lt;/strong&gt; Most banks and fintech apps in the region rely heavily on SMS for verification — making SIM swap attacks particularly devastating.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Customer service verification gaps.&lt;/strong&gt; Not all telecom agents follow strict identity verification protocols consistently.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low public awareness.&lt;/strong&gt; Most victims don't know what hit them until it's too late.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  How to Protect Yourself: Practical Steps
&lt;/h2&gt;

&lt;h3&gt;
  
  
  ✅ 1. Add a SIM Lock / Port Lock to Your Number
&lt;/h3&gt;

&lt;p&gt;Call your network provider and ask them to add extra protection to your account — some providers allow you to set a PIN or password that must be provided before any SIM replacement is done.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MTN Ghana:&lt;/strong&gt; Visit a service centre and request a SIM swap lock&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Telecel / AirtelTigo:&lt;/strong&gt; Ask customer care about account-level PIN protection&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  ✅ 2. Move Away from SMS-Based 2FA
&lt;/h3&gt;

&lt;p&gt;Wherever possible, switch from SMS OTP to an authenticator app:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://support.google.com/accounts/answer/1066447" rel="noopener noreferrer"&gt;Google Authenticator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://authy.com/" rel="noopener noreferrer"&gt;Authy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.microsoft.com/en-us/security/mobile-authenticator-app" rel="noopener noreferrer"&gt;Microsoft Authenticator&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These generate codes locally on your phone — even if someone steals your number, they can't get these codes.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;❌ Less secure:  SMS OTP → your phone number
✅ More secure:  Authenticator app → your physical device
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  ✅ 3. Use a Separate "Silent" Number for Financial Accounts
&lt;/h3&gt;

&lt;p&gt;Consider having a dedicated SIM that you use &lt;em&gt;only&lt;/em&gt; for banking and MoMo — one you never share publicly, never post online, and never use for regular calls or social media sign-ups.&lt;/p&gt;

&lt;h3&gt;
  
  
  ✅ 4. Set Up Email Recovery That Doesn't Depend on SMS
&lt;/h3&gt;

&lt;p&gt;If your email recovery method is your phone number, you've created a single point of failure. Add a recovery email address instead, and store your backup codes somewhere safe offline.&lt;/p&gt;

&lt;h3&gt;
  
  
  ✅ 5. Be Stingy With Your Personal Information Online
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Don't post your full phone number on Facebook or TikTok&lt;/li&gt;
&lt;li&gt;Be careful with "fun" quizzes that ask for your name, date of birth, hometown — these are data collection tools&lt;/li&gt;
&lt;li&gt;Limit what's publicly visible on your social media profiles&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  ✅ 6. Act Fast If You Lose Signal Unexpectedly
&lt;/h3&gt;

&lt;p&gt;If your phone suddenly loses signal and you haven't changed anything:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Immediately call your network provider from another phone&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Tell them you suspect a SIM swap&lt;/li&gt;
&lt;li&gt;Ask them to freeze your account&lt;/li&gt;
&lt;li&gt;Alert your bank and MoMo provider&lt;/li&gt;
&lt;li&gt;Change your email passwords from a trusted device&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Speed is everything. The faster you act, the less damage is done.&lt;/p&gt;




&lt;h2&gt;
  
  
  For Developers: What You Should Know
&lt;/h2&gt;

&lt;p&gt;If you're building apps that serve Ghanaian or West African users, &lt;strong&gt;SMS OTP should not be your only authentication option.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Consider implementing:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="c1"&gt;// Instead of relying solely on SMS OTP&lt;/span&gt;
&lt;span class="c1"&gt;// Offer TOTP (Time-based One-Time Password) support&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;speakeasy&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;require&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;speakeasy&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="c1"&gt;// Generate a secret for the user&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;secret&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;speakeasy&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;generateSecret&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;length&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;

&lt;span class="c1"&gt;// Verify the token the user enters&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;verified&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;speakeasy&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;totp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;verify&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
  &lt;span class="na"&gt;secret&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;secret&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;base32&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;encoding&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;base32&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;token&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;userInputToken&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="na"&gt;window&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Libraries like &lt;a href="https://github.com/speakeasy/speakeasy" rel="noopener noreferrer"&gt;speakeasy&lt;/a&gt; (Node.js) or &lt;a href="https://github.com/pyauth/pyotp" rel="noopener noreferrer"&gt;pyotp&lt;/a&gt; (Python) make TOTP implementation straightforward. Pair it with a QR code so users can scan it into their authenticator app.&lt;/p&gt;

&lt;p&gt;Your users deserve more than a one-point-of-failure SMS system.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;SIM swap attacks aren't a distant, foreign threat. They're happening right now in Accra, Kumasi, Lagos, and Abidjan. And because mobile money is the financial backbone of millions of West Africans, the stakes are incredibly high.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The good news:&lt;/strong&gt; awareness is your first line of defence. Share this with someone who uses MoMo. It might save them from a very bad morning.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article is part of the CyberSense Ghana series — cybersecurity education built for Ghanaians and West Africans. Follow &lt;a href="https://tiktok.com/@cybersense101" rel="noopener noreferrer"&gt;@cybersense101&lt;/a&gt; on TikTok, Instagram, and Facebook for more.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>webdev</category>
      <category>beginners</category>
      <category>africa</category>
    </item>
    <item>
      <title>Pocket Infrastructure: Building a Localized Database Environment with Termux</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Thu, 10 Sep 2026 23:48:56 +0000</pubDate>
      <link>https://dev.to/cybersense/pocket-infrastructure-building-a-localized-database-environment-with-termux-24he</link>
      <guid>https://dev.to/cybersense/pocket-infrastructure-building-a-localized-database-environment-with-termux-24he</guid>
      <description>&lt;h2&gt;
  
  
  Pocket Infrastructure: Building a Localized Database Environment with Termux
&lt;/h2&gt;

&lt;p&gt;When you are architecting a mobile-first retail application, you quickly realize that relying entirely on a constant cloud connection during development and field testing can be a massive bottleneck. Whether you are building an inventory management prototype or testing offline data syncs, having a portable, localized database is a strategic advantage.&lt;/p&gt;

&lt;p&gt;Here is how to turn an Android device into a secure, pocket-sized infrastructure environment using Termux to host a dedicated database instance for tracking inventory.&lt;/p&gt;

&lt;h3&gt;
  
  
  The "Vibe Coder" Mobile Stack
&lt;/h3&gt;

&lt;p&gt;Termux is a terminal emulator that brings a robust Linux environment directly to Android—no rooting required. To build this localized backend, we need:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;An Android Device:&lt;/strong&gt; Your standard smartphone or tablet.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;Termux:&lt;/strong&gt; Downloaded via F-Droid (the Google Play Store version is deprecated).&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;MariaDB:&lt;/strong&gt; A lightweight, highly efficient SQL database server.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step-by-Step Terminal Setup
&lt;/h3&gt;

&lt;p&gt;Deploying this environment is remarkably straightforward. Open your Termux terminal and execute the following setup commands:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Update and Upgrade Packages&lt;/strong&gt;&lt;br&gt;
Before installing anything, ensure your environment repositories are current:&lt;br&gt;
&lt;code&gt;pkg update &amp;amp;&amp;amp; pkg upgrade -y&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Install the Database Server&lt;/strong&gt;&lt;br&gt;
Pull down the MariaDB package to serve as your relational database:&lt;br&gt;
&lt;code&gt;pkg install mariadb -y&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Initialize the Database Directory&lt;/strong&gt;&lt;br&gt;
Set up the necessary system tables and data directories to allow the database to run locally:&lt;br&gt;
&lt;code&gt;mysql_install_db&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Spin Up the Instance&lt;/strong&gt;&lt;br&gt;
Start your localized database server in safe mode:&lt;br&gt;
&lt;code&gt;mysqld_safe &amp;amp;&lt;/code&gt;&lt;br&gt;
&lt;em&gt;(Tip: The &lt;code&gt;&amp;amp;&lt;/code&gt; runs the process in the background so you can continue using the terminal).&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Secure the Installation&lt;/strong&gt;&lt;br&gt;
Lock down your environment. Even on a local device, security is paramount. Run the security script to set a root password and remove test databases:&lt;br&gt;
&lt;code&gt;mysql_secure_installation&lt;/code&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Why This Architecture Wins
&lt;/h3&gt;

&lt;p&gt;By building this dedicated database instance directly on the hardware, you can test smartphone scanning features, user roles, and spreadsheet integrations with zero latency. It bridges the gap between raw web development and clever network engineering. You get a fully functional SQL environment to design data flow frameworks without paying for cloud hosting or exposing your early-stage prototypes to the open web.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Note: The core architecture and technical strategies in this post are my own, drafted with the assistance of AI tools to optimize structure and clarity.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>termux</category>
      <category>database</category>
      <category>mobile</category>
      <category>linux</category>
    </item>
    <item>
      <title>Stop pasting proprietary application code into public cloud AI endpoints.</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Thu, 10 Sep 2026 14:12:58 +0000</pubDate>
      <link>https://dev.to/cybersense/stop-pasting-proprietary-application-code-into-public-cloud-ai-endpoints-100a</link>
      <guid>https://dev.to/cybersense/stop-pasting-proprietary-application-code-into-public-cloud-ai-endpoints-100a</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng" class="crayons-story__hidden-navigation-link"&gt;Stop Leaking Code: How to Refactor Offline with Local AI&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/cybersense" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4114694%2Fa3cbebcf-0b85-4ac7-baff-08d1d10eca2b.jpeg" alt="cybersense profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/cybersense" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Michael Asante 
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Michael Asante 
                
                
              
              &lt;div id="story-author-preview-content-4624505" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/cybersense" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4114694%2Fa3cbebcf-0b85-4ac7-baff-08d1d10eca2b.jpeg" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Michael Asante &lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Sep 10&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng" id="article-link-4624505"&gt;
          Stop Leaking Code: How to Refactor Offline with Local AI
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/architecture"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;architecture&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/webdev"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;webdev&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              1&lt;span class="hidden s:inline"&gt;&amp;nbsp;comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>llm</category>
      <category>security</category>
    </item>
    <item>
      <title>Stop Leaking Code: How to Refactor Offline with Local AI</title>
      <dc:creator>Michael Asante </dc:creator>
      <pubDate>Thu, 10 Sep 2026 13:27:51 +0000</pubDate>
      <link>https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng</link>
      <guid>https://dev.to/cybersense/stop-leaking-code-how-to-refactor-offline-with-local-ai-25ng</guid>
      <description>&lt;h3&gt;
  
  
  Stop Leaking Code: How to Refactor Offline with Local AI
&lt;/h3&gt;

&lt;p&gt;The biggest security risk for modern developers isn't just bad routing or weak passwords—it is pasting proprietary application logic into public cloud AI endpoints. If you are building complex, multi-tenant business systems, data privacy is non-negotiable.&lt;/p&gt;

&lt;p&gt;Here is how to bridge that gap by deploying a 100% local, offline AI environment to analyze and refactor your codebase securely.&lt;/p&gt;

&lt;h3&gt;
  
  
  The "Vibe Coder" Local Stack
&lt;/h3&gt;

&lt;p&gt;To build this secure architecture, we only need a few lightweight tools to get our local instance running smoothly on consumer hardware:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Ollama:&lt;/strong&gt; The engine that runs our local language models.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Open WebUI:&lt;/strong&gt; A clean, accessible frontend interface.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A Target Codebase:&lt;/strong&gt; Your existing PHP, Laravel, or C++ directories.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  The Secure Implementation Strategy
&lt;/h3&gt;

&lt;p&gt;Getting this running requires a slight shift from traditional web deployment, focusing purely on isolated, local data flow.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Initialize the Engine:&lt;/strong&gt; Install Ollama and pull a lightweight model specialized in coding (like &lt;code&gt;codellama&lt;/code&gt; or &lt;code&gt;phi-3&lt;/code&gt;) via your terminal.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deploy the Interface:&lt;/strong&gt; Spin up Open WebUI using Docker to create a secure, isolated frontend on your local host port.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Map the Directory:&lt;/strong&gt; Instead of copy-pasting code snippets, utilize the workspace features to point the local model directly at your application folder.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Execute Offline Refactoring:&lt;/strong&gt; Query the model to optimize your backend database routes or restructure your Tailwind CSS layouts without a single byte of data leaving your machine.&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  Why This Matters for Network Security
&lt;/h3&gt;

&lt;p&gt;By keeping your AI assistance strictly localized, you eliminate the risk of third-party data ingestion. You maintain absolute control over your infrastructure and network segmentation while still accelerating your creative workflow. That is the essence of building with cyber sense.&lt;/p&gt;




</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>architecture</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
