<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Dark Master</title>
    <description>The latest articles on DEV Community by Dark Master (@darkmaster0345).</description>
    <link>https://dev.to/darkmaster0345</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3882200%2F17cfc069-222c-4bb0-941b-6ed202e24a91.jpeg</url>
      <title>DEV Community: Dark Master</title>
      <link>https://dev.to/darkmaster0345</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/darkmaster0345"/>
    <language>en</language>
    <item>
      <title>The Most Feature-Rich Islamic App Ever Built — And It's Completely Free and Open Source</title>
      <dc:creator>Dark Master</dc:creator>
      <pubDate>Thu, 13 Aug 2026 11:52:06 +0000</pubDate>
      <link>https://dev.to/darkmaster0345/the-most-feature-rich-islamic-app-ever-built-and-its-completely-free-and-open-source-3d8d</link>
      <guid>https://dev.to/darkmaster0345/the-most-feature-rich-islamic-app-ever-built-and-its-completely-free-and-open-source-3d8d</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8rpwcgk9wpy6e7tqys05.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8rpwcgk9wpy6e7tqys05.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;&lt;br&gt;
Muslim Pro has 50 million installs. It also sold its users' precise GPS location data to third-party brokers. The prayer times you checked, the mosques you visited, the Quran you read — all attached to an advertising profile built around your faith. When the story broke, Muslim Pro quietly updated their privacy policy and moved on.&lt;/p&gt;

&lt;p&gt;That's the app most of the world's Muslims are using right now.&lt;/p&gt;

&lt;p&gt;Noor Connect exists because that's not acceptable. Free, open source, GPL-3.0, listed on F-Droid, zero trackers, zero analytics, every byte of your data stays on your device. But privacy alone doesn't make an app worth using — plenty of minimal FOSS Islamic apps already exist. What makes Noor Connect different is the depth of what's built on top of that foundation.&lt;/p&gt;

&lt;p&gt;The F-Droid Islamic App Space Has Good Tools. None of Them Do All of This.&lt;/p&gt;

&lt;p&gt;Al-Azan does prayer times with zero internet permission — clean and minimal. Mihrab has a solid Madinah Mushaf reader and widgets. Khushu focuses on guided rakat-by-rakat prayer flow. These are intentional, well-built apps.&lt;/p&gt;

&lt;p&gt;None of them are trying to be your complete Islamic companion. Noor Connect is.&lt;/p&gt;

&lt;p&gt;46 routes. The full standard Madani Mushaf in local WebP pages, 16 complete hadith collections with 52,000+ entries, live Makkah and Madinah streams, Seerah of the Prophet ﷺ with chapter progress, Qisas Al-Anbiya, an Islamic ebook library with a PDF viewer, mood-based Islamic Remedies, a deeply gamified Islamic quiz, 400+ nasheeds with offline cache, full women's Islamic wellness, five native Android widgets, prayer tracking with Qaza management, Zakat and Fitrana calculators, Ramadan hub, Hijri calendar, and a Quran radio station catalog with 200+ streams.&lt;/p&gt;

&lt;p&gt;One install. Nothing left out.&lt;/p&gt;

&lt;p&gt;52,000+ Hadith. Free. Offline. In a Web Worker.&lt;/p&gt;

&lt;p&gt;Islam360 has a strong hadith library — scholars recommend it, and it earns it. It also costs money to unlock fully.&lt;/p&gt;

&lt;p&gt;Noor Connect ships 16 complete collections — Bukhari, Muslim, Abu Dawud, Tirmidhi, Nasai, Ibn Majah, Ahmad, Malik, Mishkat, Riyadus Salihin, Darimi, Bulugh al-Maram, Shamail, Adab al-Mufrad, Forty Hadith, and Hisn al-Muslim. Arabic and English, color-coded Sahih/Hasan/Da'if grade badges, bookmarks, full-text search, infinite scroll loading 300 hadith at a time. All 16 collections are stored as gzip compressed JSON — 95MB raw, 20MB compressed — inflated at runtime in a Web Worker so the UI thread never blocks.&lt;/p&gt;

&lt;p&gt;All of it free. All of it offline. No account. No paywall.&lt;/p&gt;

&lt;p&gt;The Nasheed Library Is Legally Licensed&lt;/p&gt;

&lt;p&gt;Most apps that include nasheeds either scrape public sources or use informal arrangements that sit in a legal grey area from an Islamic ethics standpoint.&lt;/p&gt;

&lt;p&gt;Noor Connect has an official partnership with No Copyright Nasheed — the leading platform for copyright-free Islamic audio — with a free perpetual license covering 400+ tracks, served through a dedicated Cloudflare Worker CDN. Noor Connect is officially listed on their website as a trusted partner app.&lt;/p&gt;

&lt;p&gt;Offline cache for up to 200 tracks with 90-day retention, artist filter chips, queue, shuffle, repeat, favorites, animated equalizer visualizer, and background playback with lock screen controls. Every track financially supports its creator — which matters.&lt;/p&gt;

&lt;p&gt;Your Adhan. Your Voice. Your Choice.&lt;/p&gt;

&lt;p&gt;Every major Islamic app gives you a dropdown of preset muezzins and calls it customization.&lt;/p&gt;

&lt;p&gt;Noor Connect lets you upload your own MP3 adhan and assign it per prayer. Record your local imam. Use a family recording. Use anything. It's stored locally in IndexedDB, previewed before saving, and plays through the full native adhan engine with lock screen controls. No other major Islamic app — FOSS or otherwise — does this.&lt;/p&gt;

&lt;p&gt;Islamic Knowledge That's Actually Addictive to Learn&lt;/p&gt;

&lt;p&gt;Most Islamic quiz features are five questions and a score. Noor Connect built a full knowledge economy around Islamic learning.&lt;/p&gt;

&lt;p&gt;Four quiz modes — classic, time attack, survival, and daily challenge. An XP system with 15 levels, combo multipliers, accuracy bonuses, and streak rewards. A lives system with regeneration. Mystery boxes — Knowledge Box, Wisdom Chest, Prophet's Treasure — that drop XP and power-ups as rewards. An in-app store with 20+ items including Barakah Boost, Wisdom of Sahaba, and Scholar's Aura, unlocked with earned XP. Seven-day daily reward streaks. Unlockable achievements.&lt;/p&gt;

&lt;p&gt;It's the kind of depth that makes you come back to Islamic knowledge the same way a well-designed game makes you come back. The gamification is intentional and it works.&lt;/p&gt;

&lt;p&gt;Mood-Based Islamic Remedies&lt;/p&gt;

&lt;p&gt;Pick how you're feeling from 12 mood and condition categories. The app surfaces relevant Quranic ayahs, hadith, duas, dhikr, and surah guidance connected to that state. A daily remedy with XP rewards and a favorites list for quick reference.&lt;/p&gt;

&lt;p&gt;It's not a medical feature. It's a structured way to connect to what Islamic tradition says about your current state — something no other Islamic app has built this way.&lt;/p&gt;

&lt;p&gt;What the Entire Islamic App Industry Built for Muslim Women&lt;/p&gt;

&lt;p&gt;A toggle. A menstrual mode that pauses prayer reminders. That's it. That is the complete sum of what major Islamic apps have ever offered Muslim women specifically.&lt;/p&gt;

&lt;p&gt;Noor Connect built Noor Cycle — and had it audited against the actual code so this description is accurate.&lt;/p&gt;

&lt;p&gt;What it actually does: When a cycle is logged as active, the app automatically silences prayer notifications and pauses Qaza auto-syncing. No manual override needed — the app understands Islamic context at a system level and acts on it.&lt;/p&gt;

&lt;p&gt;What it tracks: Flow, 10 symptoms, mood, energy level (1-5), pain scale (0-10), notes, ghusl status, missed fasts, water intake (8 glasses daily). All stored locally, nothing leaves the device.&lt;/p&gt;

&lt;p&gt;What it calculates: Average cycle and period length, next predicted start, ovulation window, fertile window, istihadhah detection based on madhab-specific maximum haidh and nifas durations across all four major schools (Hanafi, Maliki, Shafi'i, Hanbali), tuhr status, cycle regularity, prediction confidence, and Qaza fasts owed.&lt;/p&gt;

&lt;p&gt;How it integrates: Prayer alarms disabled during active cycle. Prayer notifications cleared. Qaza auto-sync paused. Streak tracking exempts haidh and nifas days so your prayer streak isn't broken. Five contextual notifications — ghusl reminder, period prediction, daily log prompt, fertile window alert, and a Sunday evening Qaza fast makeup reminder.&lt;/p&gt;

&lt;p&gt;What you see: Six tabs — Today with a hero ring and fiqh exemption grid, Calendar with month view and day detail, Log with a locked-commit form, Analytics with cycle charts and a PDF health report exportable for a doctor, Islamic tab with full madhab Fiqh guidance and wellness articles, and Settings with PIN lock and data export.&lt;/p&gt;

&lt;p&gt;Protected by a 4-digit PIN. Every byte local.&lt;/p&gt;

&lt;p&gt;Muslim women have been using Islamic apps designed entirely around male use cases for the entire history of Islamic apps. Noor Connect is the first FOSS Islamic app that treated that as unacceptable and actually built something serious about it.&lt;/p&gt;

&lt;p&gt;Five Widgets That Survive Everything&lt;/p&gt;

&lt;p&gt;Next Prayer countdown, Daily Ayah, Daily Hadith, Quran Reading Progress, and a Tasbeeh counter. Native Android widgets with full light and dark theme support, Material You dynamic color on Android 12+, system corner radius on API 31+, and reconfigurable on the home screen without removing and re-adding.&lt;/p&gt;

&lt;p&gt;They survive reboots, timezone changes, DST shifts, and locale changes. They show exactly what the app shows — because they're fed the same parsed data the app uses, not a separate calculation.&lt;/p&gt;

&lt;p&gt;Built for the Phone You Actually Have&lt;/p&gt;

&lt;p&gt;The Madani Mushaf is 606 WebP pages stored locally in the APK — no CDN dependency, no loading spinner while you're reading. The hadith database inflates in a Web Worker. The app benchmarks your device once at startup and sets an animation tier automatically — on low-end hardware it strips blur effects, replaces heavy animations with opacity fades, and targets 30+ FPS on phones from 2016 onwards.&lt;/p&gt;

&lt;p&gt;If you're in a Muslim-majority region on a mid-range or older device, this was specifically engineered for you.&lt;/p&gt;

&lt;p&gt;Get It&lt;/p&gt;

&lt;p&gt;Noor Connect v2.2 is live on F-Droid right now. Everything above is free.&lt;/p&gt;

&lt;p&gt;F-Droid: f-droid.org/packages/com.noorconnect.app&lt;/p&gt;

&lt;p&gt;Source: gitlab.com/theredhacker0345 (GPL-3.0)&lt;/p&gt;

&lt;p&gt;No account. No ads. No data leaving your phone. Just the app.&lt;/p&gt;

&lt;p&gt;Every feature described here is code-verified. Rate it.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>I scanned GitLab's source code and found 2,449 undocumented API routes</title>
      <dc:creator>Dark Master</dc:creator>
      <pubDate>Sat, 18 Jul 2026 12:29:50 +0000</pubDate>
      <link>https://dev.to/darkmaster0345/i-scanned-gitlabs-source-code-and-found-2449-undocumented-api-routes-3l0c</link>
      <guid>https://dev.to/darkmaster0345/i-scanned-gitlabs-source-code-and-found-2449-undocumented-api-routes-3l0c</guid>
      <description>&lt;p&gt;Last week I pointed a static analysis tool I built at GitLab's public source code. It found 2,449 routes in the actual Ruby code that don't exist anywhere in the official API documentation.&lt;/p&gt;

&lt;p&gt;Then I ran it on Mastodon. 601 undocumented routes.&lt;/p&gt;

&lt;p&gt;These aren't bugs — they're shadow APIs. Routes that exist, respond to requests, but were never documented. No auth requirements listed. No rate limits specified. No deprecation warnings. Just... there.&lt;/p&gt;




&lt;h2&gt;
  
  
  What is a shadow API?
&lt;/h2&gt;

&lt;p&gt;A shadow API is any route your server handles that isn't in your OpenAPI/Swagger spec. They appear for a few reasons:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A developer added an internal endpoint and forgot to document it&lt;/li&gt;
&lt;li&gt;A route was deprecated but never removed from code&lt;/li&gt;
&lt;li&gt;A feature was half-built — routes exist but docs were never written&lt;/li&gt;
&lt;li&gt;A framework auto-generates routes (Rails resources, NestJS decorators) and nobody audited what got generated&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The problem: your security team can't protect what they don't know exists. Your API gateway can't rate-limit it. Your consumers can't predict when it'll break. And attackers can find it with a directory scan.&lt;/p&gt;




&lt;h2&gt;
  
  
  How I found 2,449 of them in GitLab
&lt;/h2&gt;

&lt;p&gt;I built a CLI called &lt;strong&gt;shadowaudit&lt;/strong&gt;. It does static analysis — reads your actual framework code, extracts every route, then diffs it against your OpenAPI spec.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npx shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; ./gitlab &lt;span class="nt"&gt;--spec&lt;/span&gt; ./openapi.yaml &lt;span class="nt"&gt;--framework&lt;/span&gt; rails
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For GitLab, the scanner:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Parsed every &lt;code&gt;routes.rb&lt;/code&gt; and &lt;code&gt;config/routes/*.rb&lt;/code&gt; file&lt;/li&gt;
&lt;li&gt;Expanded every &lt;code&gt;resources :projects&lt;/code&gt; call into its 7 REST routes&lt;/li&gt;
&lt;li&gt;Followed every &lt;code&gt;concern :reviewable&lt;/code&gt; mounted across multiple resources&lt;/li&gt;
&lt;li&gt;Added Grape API routes from &lt;code&gt;lib/api/*.rb&lt;/code&gt; — 1,017 routes from that alone&lt;/li&gt;
&lt;li&gt;Diffed all detected routes against the public GitLab API spec&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Result: &lt;strong&gt;2,449 routes in code with no match in the spec.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Some are intentional internals. Some are legacy. Some are genuinely undocumented public endpoints that clients are probably hitting right now.&lt;/p&gt;




&lt;h2&gt;
  
  
  The tool: shadowaudit
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-g&lt;/span&gt; shadowaudit
shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; ./your-api &lt;span class="nt"&gt;--spec&lt;/span&gt; ./openapi.yaml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;7 frameworks supported:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Express (including 3-level nested router chains)&lt;/li&gt;
&lt;li&gt;Fastify&lt;/li&gt;
&lt;li&gt;NestJS (including &lt;code&gt;@Version()&lt;/code&gt; decorators)&lt;/li&gt;
&lt;li&gt;Koa&lt;/li&gt;
&lt;li&gt;Hapi&lt;/li&gt;
&lt;li&gt;Rails&lt;/li&gt;
&lt;li&gt;Grape&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Three modes:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Default — find shadow routes (code not in spec):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;CRITICAL  POST   /api/v1/internal/reset      (no auth documented)
HIGH      GET    /api/v2/users/export        (no rate limit documented)
INFO      GET    /health                     (intentionally undocumented)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Reverse mode — find dead spec entries (spec not in code):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--reverse&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Finds routes your spec documents that no longer exist in code. Dead docs that confuse your consumers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Coverage scoring — how complete is your OpenAPI spec?&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--coverage&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Coverage Score: 67/100
  Descriptions:    142/200 endpoints  (71%)
  Parameters:      89/134 params      (66%)
  Response codes:  67/200 endpoints   (33.5%)  ← missing 4xx/5xx
  Security:        45/67 endpoints    (67%)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;CI integration — fails the build if shadow routes exist:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# .github/workflows/api-audit.yml&lt;/span&gt;
&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Shadow API Audit&lt;/span&gt;
  &lt;span class="na"&gt;run&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;npx shadowaudit --dir . --spec openapi.yaml --format markdown &amp;gt;&amp;gt; $GITHUB_STEP_SUMMARY&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Exit codes: &lt;code&gt;0&lt;/code&gt; = clean, &lt;code&gt;1&lt;/code&gt; = findings, &lt;code&gt;2&lt;/code&gt; = tool error. CI-safe by design.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ignore known-good routes:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--ignore-paths&lt;/span&gt; /health,/metrics,/ping
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  What makes this different from existing tools
&lt;/h2&gt;

&lt;p&gt;Most shadow API detection tools work at runtime — they watch traffic and flag requests to unknown endpoints. That means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You need production traffic to find them&lt;/li&gt;
&lt;li&gt;You find out AFTER deployment&lt;/li&gt;
&lt;li&gt;You need an API gateway or proxy in the path&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;shadowaudit works at &lt;strong&gt;development time&lt;/strong&gt;, on &lt;strong&gt;static code&lt;/strong&gt;, with &lt;strong&gt;zero infrastructure&lt;/strong&gt;. Run it in CI and catch shadow routes before they ever reach production. No proxy. No traffic. No production access needed.&lt;/p&gt;

&lt;p&gt;The closest thing is manually diffing your routes against your spec — which nobody does because it's tedious and breaks every time someone adds a route.&lt;/p&gt;




&lt;h2&gt;
  
  
  Real-world results
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Target&lt;/th&gt;
&lt;th&gt;Routes in code&lt;/th&gt;
&lt;th&gt;Routes in spec&lt;/th&gt;
&lt;th&gt;Shadow routes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;GitLab&lt;/td&gt;
&lt;td&gt;2,449&lt;/td&gt;
&lt;td&gt;~800&lt;/td&gt;
&lt;td&gt;~1,649&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mastodon&lt;/td&gt;
&lt;td&gt;766&lt;/td&gt;
&lt;td&gt;~165&lt;/td&gt;
&lt;td&gt;~601&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;These numbers aren't accusations — both projects are open source and their "shadow" routes are largely intentional internals. But the point stands: even well-maintained APIs with dedicated teams have hundreds of routes that exist outside their documented surface area.&lt;/p&gt;

&lt;p&gt;For a smaller team shipping fast, the gap is usually worse.&lt;/p&gt;




&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Scan your API against your spec&lt;/span&gt;
npx shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml

&lt;span class="c"&gt;# Add to CI (GitHub Actions)&lt;/span&gt;
npx shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--format&lt;/span&gt; markdown &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$GITHUB_STEP_SUMMARY&lt;/span&gt;

&lt;span class="c"&gt;# Score your OpenAPI spec completeness&lt;/span&gt;
npx shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--coverage&lt;/span&gt;

&lt;span class="c"&gt;# Find dead spec entries&lt;/span&gt;
npx shadowaudit &lt;span class="nt"&gt;--dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;--spec&lt;/span&gt; openapi.yaml &lt;span class="nt"&gt;--reverse&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;npm: &lt;code&gt;shadowaudit&lt;/code&gt; (published under darkmaster0345)&lt;br&gt;
GitHub: github.com/darkmaster0345/shadowaudit&lt;/p&gt;

&lt;p&gt;It's free. MIT licensed. 459 tests passing across 7 frameworks.&lt;/p&gt;

&lt;p&gt;If you find a shadow route you didn't know about — I'd genuinely like to hear about it.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Built this in 8 days as a side project. v1.0.1 shipped yesterday with hardening fixes from an adversarial review — exit code hygiene, Express deep router chain support, NestJS versioning. Feedback welcome.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Tags:&lt;/strong&gt; &lt;code&gt;security&lt;/code&gt; &lt;code&gt;api&lt;/code&gt; &lt;code&gt;opensource&lt;/code&gt; &lt;code&gt;devops&lt;/code&gt; &lt;code&gt;webdev&lt;/code&gt;&lt;/p&gt;

</description>
      <category>api</category>
      <category>opensource</category>
      <category>ruby</category>
      <category>security</category>
    </item>
    <item>
      <title>I Built a Free Shadow API Scanner and Found 269 Forgotten Routes in Ghost CMS</title>
      <dc:creator>Dark Master</dc:creator>
      <pubDate>Sun, 12 Jul 2026 18:06:35 +0000</pubDate>
      <link>https://dev.to/darkmaster0345/i-built-a-free-shadow-api-scanner-and-found-269-forgotten-routes-in-ghost-cms-11eg</link>
      <guid>https://dev.to/darkmaster0345/i-built-a-free-shadow-api-scanner-and-found-269-forgotten-routes-in-ghost-cms-11eg</guid>
      <description>&lt;p&gt;How a weekend project turned into a production tool with 875+ npm downloads in 48 hours — and why your codebase probably has shadow APIs too.&lt;/p&gt;

&lt;p&gt;There's a route in your codebase right now that nobody remembers adding.&lt;br&gt;
Maybe a developer spun up &lt;code&gt;app.get('/api/debug/reset')&lt;/code&gt; on a Friday to test something. No auth middleware. No documentation. Committed and forgotten. It's been sitting in production for months - invisible to your API scanner, invisible to your security team, visible to anyone who reads your source code.&lt;br&gt;
These are called &lt;strong&gt;shadow APIs&lt;/strong&gt;. And the scary part is: you probably have more of them than you think.&lt;br&gt;
I know because I built a tool to find them, and the results surprised me.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I built
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;shadowaudit&lt;/strong&gt; is a free, open-source CLI tool that scans your source code statically - no agents, no traffic mirrors, no $70K enterprise contracts - and finds API routes that exist in your code but aren't in your OpenAPI spec.&lt;br&gt;
It compares what your code actually does against what your documentation says it does. Any route in the code but not in the spec gets flagged. If that route also has no authentication middleware? That's a &lt;strong&gt;CRITICAL&lt;/strong&gt; finding. Your CI pipeline fails. The PR doesn't merge.&lt;br&gt;
Simple idea. Surprisingly effective.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Ghost CMS test
&lt;/h2&gt;

&lt;p&gt;To see if shadowaudit actually works on real code (not just toy examples), I ran it against &lt;a href="https://github.com/TryGhost/Ghost" rel="noopener noreferrer"&gt;Ghost CMS&lt;/a&gt; - the publishing platform that powers 404Media, Platformer, and The Browser. It's a production-grade Express.js app with a large API surface.&lt;br&gt;
The first scan found &lt;strong&gt;269 routes&lt;/strong&gt;.&lt;br&gt;
But the initial results had problems. Ghost uses a custom auth middleware called &lt;code&gt;mw.authAdminApi&lt;/code&gt; that shadowaudit didn't recognize - so 213 routes that actually had auth were reported as "no auth detected." That's a 70% false negative rate. Embarrassing.&lt;br&gt;
So I fixed it. The v0.3.0 update added AST-based auth detection - instead of matching hardcoded pattern strings, it walks the route's arguments in the code's abstract syntax tree and checks if any middleware name contains auth-related words like "auth," "login," "token," "jwt," or "passport."&lt;br&gt;
After the fix: &lt;strong&gt;235 routes correctly authenticated&lt;/strong&gt;, &lt;strong&gt;0 false positives&lt;/strong&gt;, &lt;strong&gt;34 routes legitimately public&lt;/strong&gt; (login, password reset, setup endpoints - expected).&lt;br&gt;
Ghost's security was solid. Zero real vulnerabilities. But the scan proved shadowaudit works on real, production-grade codebases - not just examples.&lt;/p&gt;

&lt;h2&gt;
  
  
  The features nobody asked for but I built anyway
&lt;/h2&gt;

&lt;p&gt;What started as "compare routes against a spec" grew into a full security tool:&lt;br&gt;
&lt;strong&gt;4 framework support.&lt;/strong&gt; Express.js, FastAPI, Django, and Flask. The tool auto-detects which framework your project uses - just point it at a directory and it figures out the rest.&lt;br&gt;
&lt;strong&gt;Three output formats.&lt;/strong&gt; A colored terminal table for humans. JSON for CI pipelines and &lt;code&gt;jq&lt;/code&gt; piping. SARIF 2.1.0 for GitHub's Security tab - findings appear right in your PR with file locations and remediation guidance.&lt;br&gt;
&lt;strong&gt;GitHub Action.&lt;/strong&gt; Published to the GitHub Marketplace. Add 3 lines to your workflow YAML and every pull request gets scanned automatically. A bot posts a findings table directly on the PR as a comment.&lt;br&gt;
&lt;strong&gt;Auto-spec generation.&lt;/strong&gt; Don't have an OpenAPI spec? Run &lt;code&gt;shadowaudit - generate-spec&lt;/code&gt; and it creates one from your code. Not perfect - but a starting point.&lt;br&gt;
&lt;strong&gt;Mount prefix reconciliation.&lt;/strong&gt; If you mount routers with &lt;code&gt;app.use('/api/v1', router)&lt;/code&gt;, shadowaudit figures out that &lt;code&gt;router.get('/users')&lt;/code&gt; is actually served at &lt;code&gt;/api/v1/users&lt;/code&gt;. This was the hardest feature to build - it required cross-file require tracking and variable name resolution.&lt;/p&gt;

&lt;h2&gt;
  
  
  The numbers
&lt;/h2&gt;

&lt;p&gt;In 48 hours since the first npm publish:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;875+ downloads&lt;/strong&gt; across all versions&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;9 releases&lt;/strong&gt; (v0.1.0-beta through v0.5.1)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;113 tests&lt;/strong&gt; across 13 test files&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;4 frameworks&lt;/strong&gt; supported&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Socket.dev audit:&lt;/strong&gt; 100/100 on vulnerability, quality, and license scores&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;0 open issues&lt;/strong&gt; (all 5 created and closed)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;1 GitHub Marketplace&lt;/strong&gt; listing&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;1 documentation site&lt;/strong&gt; (built with Docusaurus, deployed to GitHub Pages)
## What it looks like
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="gp"&gt;$&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-g&lt;/span&gt; shadowaudit
&lt;span class="gp"&gt;$&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;shadowaudit - dir&amp;nbsp;./src - spec&amp;nbsp;./openapi.json
&lt;span class="go"&gt;╔══════════════════════════════════════════════╗
║ shadowaudit - Scan Report ║
╚══════════════════════════════════════════════╝
┌──────────┬────────┬───────────────────┬──────┬──────┐
│ SEVERITY │ METHOD │ PATH │ AUTH │ │
├──────────┼────────┼───────────────────┼──────┼──────┤
│ CRITICAL │ GET │ /api/debug/reset │ NO │ │
│ HIGH │ POST │ /api/shadow │ YES │ │
└──────────┴────────┴───────────────────┴──────┴──────┘
⛔ Pipeline will FAIL - 1 critical shadow route(s) detected
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That CRITICAL finding? That's the forgotten &lt;code&gt;/api/debug/reset&lt;/code&gt; route with no auth. shadowaudit just stopped it from reaching production.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to use it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Install&lt;/span&gt;
npm &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-g&lt;/span&gt; shadowaudit
&lt;span class="c"&gt;# Scan your code&lt;/span&gt;
shadowaudit - dir&amp;nbsp;./src - spec&amp;nbsp;./openapi.json
&lt;span class="c"&gt;# Don't have a spec? Generate one&lt;/span&gt;
shadowaudit - dir&amp;nbsp;./src - framework express - generate-spec &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; openapi.json
&lt;span class="c"&gt;# Add to GitHub Actions (3 lines)&lt;/span&gt;
- uses: darkmaster0345/shadow-Audit@v0.5.1
&amp;nbsp;with:
&amp;nbsp;dir: &lt;span class="s1"&gt;'./src'&lt;/span&gt;
&amp;nbsp;spec: &lt;span class="s1"&gt;'./openapi.json'&lt;/span&gt;
&amp;nbsp;fail-on: &lt;span class="s1"&gt;'critical'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h1&gt;
  
  
  The honest part
&lt;/h1&gt;

&lt;p&gt;shadowaudit isn't perfect. It has limitations:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Django class-based view methods&lt;/strong&gt; aren't fully detected (all routes show as GET - fix planned for v0.6.0)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dynamic route mounting&lt;/strong&gt; (&lt;code&gt;routes.forEach(route =&amp;gt; router.use(route.path, route.route))&lt;/code&gt;) isn't supported (too complex for static analysis)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Flask &lt;code&gt;methods=&lt;/code&gt; with tuple syntax&lt;/strong&gt; had a bug in v0.5.0 that was fixed in v0.5.1 (real Flask projects use &lt;code&gt;methods=('GET',)&lt;/code&gt; not &lt;code&gt;methods=['GET']&lt;/code&gt;)
But it's honest about its limitations. Every known issue is documented in the &lt;a href="https://github.com/darkmaster0345/shadow-Audit/blob/main/ROADMAP.md" rel="noopener noreferrer"&gt;ROADMAP.md&lt;/a&gt;. And every release gets a full QA pass before shipping - the v0.5.1 release was driven entirely by bugs found in adversarial QA testing.
##Why I built it
Enterprise API security tools (Salt Security, Traceable, Checkmarx) cost $50,000+ per year. They're runtime-based - they watch your traffic and find shadow APIs &lt;em&gt;after&lt;/em&gt; they're already deployed and receiving requests.
That's reactive. shadowaudit is preventive. It finds the shadow route in the source code before the PR merges, before the endpoint ships, before anyone can send it traffic.
And it's free. MIT licensed. No telemetry. No license keys. No phone-home. The only network call is when you use the GitHub Action's PR comment bot, which talks to &lt;code&gt;api.github.com&lt;/code&gt; using your own token.
## Try it&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;npx shadowaudit - dir&amp;nbsp;./src - framework express&lt;br&gt;
If it finds zero routes - great, you're clean. If it finds a CRITICAL - you just caught a security issue before it reached production.&lt;br&gt;
Either way, it takes 2 seconds and costs nothing.&lt;br&gt;
&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/darkmaster0345/shadow-Audit" rel="noopener noreferrer"&gt;darkmaster0345/shadow-Audit&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;npm:&lt;/strong&gt; &lt;a href="https://www.npmjs.com/package/shadowaudit" rel="noopener noreferrer"&gt;shadowaudit&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Docs:&lt;/strong&gt; &lt;a href="https://darkmaster0345.github.io/shadow-Audit/" rel="noopener noreferrer"&gt;darkmaster0345.github.io/shadow-Audit&lt;/a&gt;&lt;br&gt;
 - -&lt;br&gt;
&lt;em&gt;If this helped you find a shadow route, consider &lt;a href="https://github.com/sponsors/darkmaster0345" rel="noopener noreferrer"&gt;sponsoring the project&lt;/a&gt;. Free tools stay free when people support them.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>node</category>
      <category>devops</category>
      <category>opensource</category>
      <category>security</category>
    </item>
    <item>
      <title>Is Telegram Really Anonymous? Let’s Be Honest.</title>
      <dc:creator>Dark Master</dc:creator>
      <pubDate>Tue, 28 Apr 2026 12:51:16 +0000</pubDate>
      <link>https://dev.to/darkmaster0345/is-telegram-really-anonymous-lets-be-honest-44jb</link>
      <guid>https://dev.to/darkmaster0345/is-telegram-really-anonymous-lets-be-honest-44jb</guid>
      <description>&lt;p&gt;There’s this idea floating around — in tech circles, activist groups, even among regular people who just “heard it somewhere” — that Telegram is the anonymous, private messaging app. The one that governments can’t touch, hackers can’t crack, and cops can’t trace.&lt;/p&gt;

&lt;p&gt;I want to gently push back on that. Not because Telegram is bad. It’s not. But because anonymous is a very specific word, and Telegram earns it only in very specific situations.&lt;/p&gt;

&lt;p&gt;First, what does “anonymous” even mean?&lt;br&gt;
There’s a difference between private and anonymous. Private means your content is hidden. Anonymous means your identity is unknown. You can have one without the other. Telegram promises a version of privacy. It mostly does not promise anonymity — and that matters.&lt;/p&gt;

&lt;p&gt;The phone number problem&lt;br&gt;
To use Telegram, you need a phone number. That’s it — that’s the conversation starter right there. Your phone number is your identity. It’s linked to a SIM card, which is linked to your name in most countries (especially in Pakistan, where NADRA ties every SIM to your CNIC).&lt;/p&gt;

&lt;p&gt;Yes, you can hide your number from other users. But Telegram still knows it. And if someone subpoenas them, or a government agency sends a valid legal request to the country Telegram operates from at that moment — they have your number. And with your number, they have you.&lt;/p&gt;

&lt;p&gt;The registration phone number is never truly hidden. It’s a persistent link between your real identity and your account — regardless of what name or photo you use.&lt;/p&gt;

&lt;p&gt;What about “Secret Chats”?&lt;br&gt;
Here’s where Telegram actually does something right. Secret Chats use end-to-end encryption (E2EE) via the MTProto 2.0 protocol. That means only you and the recipient can read those messages. Not Telegram, not their servers, not anyone intercepting traffic.&lt;/p&gt;

&lt;p&gt;But here’s the catch most people miss: regular chats are NOT end-to-end encrypted. Your normal conversations — the ones in groups, channels, and standard DMs — are encrypted in transit and at rest, but Telegram holds the keys. That means they can technically read them. Or hand them over.&lt;/p&gt;

&lt;p&gt;Secret chats&lt;/p&gt;

&lt;p&gt;End-to-end encrypted&lt;br&gt;
No cloud backup&lt;br&gt;
Self-destruct timers&lt;br&gt;
Device-to-device only&lt;br&gt;
Regular chats&lt;/p&gt;

&lt;p&gt;Cloud-stored by Telegram&lt;br&gt;
Telegram holds the keys&lt;br&gt;
Can be legally requested&lt;br&gt;
No E2EE by default&lt;br&gt;
Most people never touch Secret Chats. They use the default chat mode, sync across devices, and enjoy the convenience. That’s fine — but they shouldn’t call it anonymous.&lt;/p&gt;

&lt;p&gt;The metadata issue&lt;br&gt;
Even if your messages were perfectly encrypted, metadata is a whole other beast. Who you talk to, when, how often, from what IP address — this is metadata. Telegram collects some of it. And in intelligence and law enforcement, metadata is often more useful than content. It builds a map of your relationships, habits, and patterns.&lt;/p&gt;

&lt;p&gt;Has Telegram actually handed over data?&lt;br&gt;
Yes. After years of claiming they’d never comply, Telegram updated their privacy policy in late 2024 and acknowledged they can — and do — share user data with law enforcement under valid legal requests. This followed the arrest of Telegram’s CEO Pavel Durov in France in August 2024, which put significant pressure on the platform’s policies.&lt;/p&gt;

&lt;p&gt;This isn’t a gotcha. It’s just reality. No company operating at Telegram’s scale can exist in a legal vacuum forever.&lt;/p&gt;

&lt;p&gt;Real-world case&lt;/p&gt;

&lt;p&gt;In 2024, following Durov’s arrest, Telegram disclosed that it had provided IP addresses and phone numbers of users to authorities in response to court orders — something they had previously implied would never happen.&lt;/p&gt;

&lt;p&gt;So when IS Telegram relatively safe?&lt;br&gt;
To be fair — and fairness matters here — Telegram is genuinely useful for certain threat models:&lt;/p&gt;

&lt;p&gt;If you’re worried about a random hacker intercepting your traffic on public Wi-Fi, Telegram handles that fine. If you’re avoiding casual corporate surveillance or don’t want your messages sitting in a Google or Meta server, Telegram is better than WhatsApp for that. If you’re using Secret Chats for sensitive one-on-one conversations, the E2EE is solid.&lt;/p&gt;

&lt;p&gt;Where it fails as an anonymity tool is against nation-state actors, legal subpoenas, or any adversary who can obtain your phone number and trace it back to you.&lt;/p&gt;

&lt;p&gt;What should you use instead?&lt;br&gt;
If actual anonymity is your goal — not just privacy, but real you-can’t-find-me anonymity — the honest answer involves tools like Signal (E2EE by default, minimal metadata, open source), Session (no phone number required, decentralized), or for the highest-risk situations, Briar or Cwtch over Tor.&lt;/p&gt;

&lt;p&gt;Telegram is not in that category. It’s a feature-rich, fast, convenient messaging app with optional strong encryption. That’s a genuinely useful thing. Just don’t confuse convenience with anonymity.&lt;/p&gt;

&lt;p&gt;Final verdict&lt;br&gt;
Telegram is private-ish, not anonymous. It has good security features if you deliberately use them. It’s built by people who care about privacy more than, say, Meta does. But it’s not a shield against a determined, legally-equipped adversary.&lt;/p&gt;

&lt;p&gt;The next time someone tells you “just use Telegram, they can’t track you” — you’ll know what to say.&lt;/p&gt;

&lt;p&gt;Written from the perspective of someone who runs a Tor bridge, tests apps for F-Droid, and has spent way too many late nights reading privacy architecture docs. Take it with appropriate context.&lt;/p&gt;

</description>
      <category>anonymous</category>
      <category>opensource</category>
      <category>cybersecurity</category>
      <category>privacy</category>
    </item>
    <item>
      <title>I Built a File Encryption App in Rust. Here’s What I Learned About Trust.</title>
      <dc:creator>Dark Master</dc:creator>
      <pubDate>Thu, 16 Apr 2026 10:17:55 +0000</pubDate>
      <link>https://dev.to/darkmaster0345/i-built-a-file-encryption-app-in-rust-heres-what-i-learned-about-trust-3coo</link>
      <guid>https://dev.to/darkmaster0345/i-built-a-file-encryption-app-in-rust-heres-what-i-learned-about-trust-3coo</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcshaut5r6tadisjqrqvc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcshaut5r6tadisjqrqvc.png" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I’m 17. I live in Karachi. I have 8GB of RAM and a laptop that throttles if you look at it wrong.&lt;/p&gt;

&lt;p&gt;And I just shipped a desktop encryption app in Rust.&lt;/p&gt;

&lt;p&gt;Not because someone asked me to. Because I needed it to exist.&lt;/p&gt;

&lt;p&gt;Why Rust&lt;/p&gt;

&lt;p&gt;I could’ve done this in Python in a weekend. But Python wouldn’t give me what I actually wanted — control. When you’re encrypting someone’s files, you don’t want a garbage collector making decisions behind your back. You don’t want mystery allocations. You want to know exactly what’s in memory and when it leaves.&lt;/p&gt;

&lt;p&gt;Rust forces that conversation. The borrow checker is annoying until it saves you from a mistake you didn’t know you were making.&lt;/p&gt;

&lt;p&gt;It took longer. It was worth it.&lt;/p&gt;

&lt;p&gt;The Stack&lt;/p&gt;

&lt;p&gt;AES-256-GCM-SIV for encryption. Argon2id for key derivation. HKDF-SHA512 to stretch the key material. egui for the UI because I didn’t want to ship an Electron app that weighs 200MB to encrypt a text file.&lt;/p&gt;

&lt;p&gt;Each of these choices was deliberate. GCM-SIV over plain GCM because nonce reuse is a real-world failure mode, not a theoretical one. Argon2id because it’s memory-hard and scrypt has a worse story on GPUs. HKDF because you should never use a password directly as a key.&lt;/p&gt;

&lt;p&gt;Security isn’t one big decision. It’s a hundred small ones.&lt;/p&gt;

&lt;p&gt;18 Bugs&lt;/p&gt;

&lt;p&gt;The first version had 18 bugs. I’m not hiding that. UTF-8 panics on non-ASCII filenames. The NSIS installer writing to the wrong path. A title bar gap being counted twice in the layout.&lt;/p&gt;

&lt;p&gt;Become a Medium member&lt;br&gt;
Most of them were embarrassing in hindsight. None of them were unfixable.&lt;/p&gt;

&lt;p&gt;I used AI tooling heavily — Roo Code, Jules — to move through them faster. The AI didn’t replace the thinking. It replaced the typing. I still had to understand every change before it merged.&lt;/p&gt;

&lt;p&gt;That distinction matters.&lt;/p&gt;

&lt;p&gt;Why This Project, Really&lt;/p&gt;

&lt;p&gt;Here’s the honest answer.&lt;/p&gt;

&lt;p&gt;I live in a part of the world where privacy is not a default. Where your data going somewhere you didn’t intend is normal. Where you can’t always trust the platform, the app store, or the company behind the software you’re using.&lt;/p&gt;

&lt;p&gt;I’m also Muslim. There’s a word in Arabic — amanah — it means a trust. Something given to you that you are responsible for. I think about that a lot when I think about other people’s files, other people’s messages, other people’s data.&lt;/p&gt;

&lt;p&gt;If you handle someone’s information, that’s an amanah. Most software treats it like a liability.&lt;/p&gt;

&lt;p&gt;I wanted to build something that treats it like what it actually is.&lt;/p&gt;

&lt;p&gt;What’s Next&lt;/p&gt;

&lt;p&gt;The app is called Neuron-Encrypt. It’s on GitHub. It’s GPL-v3 because I don’t want it locked behind anyone’s business model.&lt;/p&gt;

&lt;p&gt;Version 1 works. It encrypts. It installs. It doesn’t phone home.&lt;/p&gt;

&lt;p&gt;Version 2 will do more. But I’d rather ship something honest and small than something bloated and impressive-looking.&lt;/p&gt;

&lt;p&gt;If you’re a developer who cares about this stuff — not the buzzwords, the actual problem — I’d like to hear from you.&lt;/p&gt;

&lt;p&gt;Ubaid ur Rehman is a DAE Electronics student in Karachi building FOSS privacy tools. GitHub: darkmaster0345.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>rust</category>
      <category>security</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
