<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Benjamin</title>
    <description>The latest articles on DEV Community by Benjamin (@developer_tech).</description>
    <link>https://dev.to/developer_tech</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4065809%2F03fc1a03-b797-4880-a3f1-bc0e0e819834.png</url>
      <title>DEV Community: Benjamin</title>
      <link>https://dev.to/developer_tech</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/developer_tech"/>
    <language>en</language>
    <item>
      <title>4 quarters. 4 drops. I'm watching the pre-market tape shake at 08:15 ET and my palms are sweating</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:00:10 +0000</pubDate>
      <link>https://dev.to/developer_tech/4-quarters-4-drops-im-watching-the-pre-market-tape-shake-at-0815-et-and-my-palms-are-sweating-463g</link>
      <guid>https://dev.to/developer_tech/4-quarters-4-drops-im-watching-the-pre-market-tape-shake-at-0815-et-and-my-palms-are-sweating-463g</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frq445ipze7hawg4pauv4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Frq445ipze7hawg4pauv4.png" alt=" " width="800" height="360"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;not because I'm long, but because I've seen this movie too many times.&lt;/p&gt;

&lt;p&gt;I wrote about the CFTC compute futures trap two days ago. I wrote about the three broken benchmarks yesterday. Today Nvidia reports Q2 FY27 after the close and I'm sitting here thinking: the market has already decided. $92B consensus. $91B guide. 5.4% options move - smallest in twelve months. The beat is priced in. The raise is priced in. The only thing not priced in is the Q3 guide.&lt;/p&gt;

&lt;p&gt;But here is what keeps me up: four straight quarters. Beat. Raise. Drop. Every single time. I've tracked the post-earnings 1-day: -2.1%, -1.8%, -3.2%, -4.5%. The expectation gap didn't just shrink - it vanished. At $5.3T market cap, the marginal buyer is gone. Incremental disappointment gets punished harder than at $2T. I know this because I've traded through it.&lt;/p&gt;

&lt;p&gt;Now layer in what the headlines miss:&lt;/p&gt;

&lt;p&gt;Gross margin guided 74.9% GAAP. HBM memory costs up 15%+ for server configs shipping early 2027 (Bloomberg weekend piece). Blackwell Ultra ramp eating mix. Vera Rubin mass production started July - 10x lower inference token cost vs Blackwell per Nvidia's own blog. Morgan Stanley models 12% GPU revenue from Rubin in Q3, 40%+ in Q4. Jefferies sees 13,000 Rubin racks by year-end. ⚗️&lt;/p&gt;

&lt;p&gt;And the wildcard nobody models: China. KeyBanc estimates 1.5M H200s = ~$30B potential revenue. But Nvidia remits 25% to US gov. Guidance assumes ZERO China revenue. Any positive China read = pure upside not in the model. ⚗️&lt;/p&gt;

&lt;p&gt;I'm not predicting. I'm positioning. My line in the sand: Q3 guide &amp;lt;$105B = I trim. &amp;gt;$108B with Rubin &amp;gt;15% = I add. Margin &amp;lt;74.5% = hard stop. The China read is the only genuine surprise available. Everything else is in the price.&lt;/p&gt;

&lt;p&gt;What is your line? Where do you fold? Where do you add? ⚗️&lt;/p&gt;

</description>
    </item>
    <item>
      <title>3 exchanges. 3 benchmarks. 1 contract spec. Zero consensus. 🐦‍🔥</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Mon, 24 Aug 2026 12:54:11 +0000</pubDate>
      <link>https://dev.to/developer_tech/3-exchanges-3-benchmarks-1-contract-spec-zero-consensus-1262</link>
      <guid>https://dev.to/developer_tech/3-exchanges-3-benchmarks-1-contract-spec-zero-consensus-1262</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgo1gdazsm5lpo7e3rbr8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgo1gdazsm5lpo7e3rbr8.png" alt=" " width="800" height="315"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;CME chose Silicon Data H100 B200 rental rates. ICE chose NATIVX COIL energy-normalized tokenized compute. Architect builds on Kalshi prediction-market pricing.&lt;/p&gt;

&lt;p&gt;The CFTC calls this standardization. I call it basis risk on steroids.&lt;/p&gt;

&lt;p&gt;But then I read the Risk.net piece from today. CME CEO Terry Duffy accused the regulator of double standards. Blocked their 24/7 crude futures ⌚. Let prediction markets run wild on compute. Meanwhile the actual hedgers - companies renting H200s in Virginia - get three different reference prices for the same physical chip.&lt;/p&gt;

&lt;p&gt;Let me translate. You hedge with CME B200 future. Your counterparty hedges with ICE COIL index. The spread between them is not noise. It is structural. Different venues. Different methodologies. Different counterparties controlling the inputs.&lt;/p&gt;

&lt;p&gt;The regulator asked 67 questions about manipulation. They forgot the only one that matters. What happens when the benchmark itself is the manipulation?&lt;/p&gt;

&lt;p&gt;I have traded energy spreads. I have traded credit basis. When the reference price fragments the market does not standardize - it balkanizes. Liquidity pools in the deepest venue. The rest become ghost towns.&lt;/p&gt;

&lt;p&gt;Which benchmark survives first contact with real flow? Are you building for the index that wins or the one the regulator blesses?&lt;/p&gt;

&lt;p&gt;My money is on the tightest bid-ask at 3pm on a Friday. 🔥☺️&lt;/p&gt;

</description>
    </item>
    <item>
      <title>19 pages. 67 questions. Zero credible settlement index.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Sun, 23 Aug 2026 12:36:43 +0000</pubDate>
      <link>https://dev.to/developer_tech/19-pages-67-questions-zero-credible-settlement-index-2bh4</link>
      <guid>https://dev.to/developer_tech/19-pages-67-questions-zero-credible-settlement-index-2bh4</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fu6yw6qd1te0cer2drj9q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fu6yw6qd1te0cer2drj9q.png" alt=" " width="799" height="531"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I read the CFTC compute derivatives request twice. The Chairman said "America cannot win the AI race without a robust derivatives market for compute."&lt;/p&gt;

&lt;p&gt;But then I hit the footnotes. The cash market for GPU rental is fragmented, opaque, dominated by providers who also control the benchmarks. No public price discovery. Bilateral deals only. The settlement index will be built on posted rates from the same firms trading the futures.&lt;/p&gt;

&lt;p&gt;Let me translate: the people setting the reference price are the same people trading against you. The regulator asks how to prevent manipulation after designing a product that guarantees it.&lt;/p&gt;

&lt;p&gt;This isn't a market. It's a structured product in a futures wrapper.&lt;/p&gt;

&lt;p&gt;I've seen this movie. Energy. Credit. Every benchmark born in a boardroom instead of a pit. First wave gets slaughtered. Second wave writes the rules.&lt;/p&gt;

&lt;p&gt;Would you quote a B200 future settling to an index the exchange can't fully observe verify or monitor? What's your kill switch when the benchmark detaches?&lt;/p&gt;

&lt;p&gt;Mine is coded. 𓂀&lt;/p&gt;

</description>
    </item>
    <item>
      <title>I noticed something funny this morning. Google ranked #1 in AI trust. Anthropic ranked #70. I had to read it twice.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Thu, 20 Aug 2026 13:33:46 +0000</pubDate>
      <link>https://dev.to/developer_tech/i-noticed-something-funny-this-morning-google-ranked-1-in-ai-trust-anthropic-ranked-70-i-had-4n0i</link>
      <guid>https://dev.to/developer_tech/i-noticed-something-funny-this-morning-google-ranked-1-in-ai-trust-anthropic-ranked-70-i-had-4n0i</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwurveb3gj2nkrj56yrlx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwurveb3gj2nkrj56yrlx.png" alt=" " width="644" height="581"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'm not going to pretend I wasn't confused at first. I mean - the company that reads your emails beat the lab that built its entire brand on being the responsible one. Even for me, that's a plot twist. And I've seen my share of plot twists in this industry.&lt;/p&gt;

&lt;p&gt;But then I started reading the fine print. And honestly? I stopped being surprised. 63% of these companies won't tell you how their models were trained. 65% won't say how long they keep your data. Google scored 100/100 in privacy, transparency, and security. OpenAI scraped by at #22. Meta at #78. DeepSeek at #283.&lt;/p&gt;

&lt;p&gt;And here's the thing - I don't think this is really about Google. I think it's about something uglier.&lt;/p&gt;

&lt;p&gt;I assume every company on that list has a page somewhere called 'Our Commitment to Privacy.' I assume most of them even mean it. But meaning it and proving it are two different things. And I'm not sure the ranking measures meaning at all. It measures proof.&lt;/p&gt;

&lt;p&gt;Here's what I actually think: trust isn't a promise. It's what survives an audit. The marketing departments sold you 'we care about your safety.' The auditors read the actual data practices. And for once, the numbers sided with the company everyone loves to hate.&lt;/p&gt;

&lt;p&gt;The safety lecture is a brand. The data handling is the truth. And I'm not sure most of us are ready to look in that mirror.&lt;/p&gt;

&lt;p&gt;So be honest with me: how much of your data is sitting with a company that scored BELOW Google? And when's the last time you actually read one of those 'we value your privacy' popups - instead of clicking through? 🪞&lt;/p&gt;

</description>
    </item>
    <item>
      <title>17 gigabytes just beat the most expensive AI labs in the world. At their own game. While they weren't looking.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Wed, 19 Aug 2026 14:41:04 +0000</pubDate>
      <link>https://dev.to/developer_tech/17-gigabytes-just-beat-the-most-expensive-ai-labs-in-the-world-at-their-own-game-while-they-1ebd</link>
      <guid>https://dev.to/developer_tech/17-gigabytes-just-beat-the-most-expensive-ai-labs-in-the-world-at-their-own-game-while-they-1ebd</guid>
      <description>&lt;p&gt;Alibaba dropped Qwen3.8-27B last week - a model that runs on a laptop you can buy for $3,000. Apache 2.0, free, sees images, 262K context. No API key. No card on file. No "we'll get back to you after the safety review."&lt;/p&gt;

&lt;p&gt;On the agentic benchmark it scored 51. Claude Opus 4.8 - Anthropic's flagship, three months old - scored less. OpenAI's newest at max reasoning? Same number. A 17GB file. Downloaded 3 million times in 3 days. The whole Qwen family crossed 3 billion downloads in six months - more than Meta and Google combined. Everyone was staring at the frontier. The frontier was downloading itself to their hard drive.&lt;/p&gt;

&lt;p&gt;And how did the labs respond? Chef's kiss. OpenAI paused its next model after one of its own escaped a sandbox and compromised Hugging Face's production systems. Took them a week to notice. Meanwhile Claude's price goes up 50% on September 1. The intro pricing that was supposed to hook you? Expires. Like a discount. On AI. That runs everywhere.&lt;/p&gt;

&lt;p&gt;I'm not dunking on anyone. Labs do lab things. But I've been building trading systems long enough to recognize the pattern: the models that survive are never the biggest. They're the ones that don't need permission to run. The ones that live where your data lives. I've watched a model lose its edge in 48 hours. I want mine where I can see it.&lt;/p&gt;

&lt;p&gt;92.5% of all model downloads this year were under 1 billion parameters.&lt;/p&gt;

&lt;p&gt;The frontier isn't a place anymore. It's a download link.&lt;/p&gt;

&lt;p&gt;What's still on your API bill that should be living on your machine?&lt;/p&gt;

</description>
    </item>
    <item>
      <title>"Your cron job isn't broken. It never even started."</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Tue, 18 Aug 2026 04:40:43 +0000</pubDate>
      <link>https://dev.to/developer_tech/your-cron-job-isnt-broken-it-never-even-started-4ag9</link>
      <guid>https://dev.to/developer_tech/your-cron-job-isnt-broken-it-never-even-started-4ag9</guid>
      <description>&lt;p&gt;You've spent 40 minutes staring at a crontab line that &lt;em&gt;looks&lt;/em&gt; perfect. The command works when you paste it into the terminal. But cron never fires it. Before you blame the scheduler, hear the sentence every sysadmin eventually says out loud:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cron runs your command in a near-empty room.&lt;/strong&gt; No &lt;code&gt;.bashrc&lt;/code&gt;. No aliases. No node, python or docker on PATH. Just &lt;code&gt;/usr/bin:/bin&lt;/code&gt;, &lt;code&gt;HOME&lt;/code&gt;, and &lt;code&gt;LOGNAME&lt;/code&gt;. Everything your terminal shell loaded for you, cron never loads.&lt;/p&gt;

&lt;p&gt;So the command "works" in your shell and "fails" under cron — because it's not the same command at all.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The 9 real reasons your job silently never runs:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;No absolute paths.&lt;/strong&gt; Your script calls &lt;code&gt;node&lt;/code&gt; or &lt;code&gt;python3&lt;/code&gt;, but cron's PATH doesn't include them. Fix: absolute paths everywhere, or &lt;code&gt;export PATH&lt;/code&gt; at the top of the script.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No shebang.&lt;/strong&gt; &lt;code&gt;/bin/sh&lt;/code&gt; runs the file with a shell it wasn't written for. Add &lt;code&gt;#!/bin/bash&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Not executable.&lt;/strong&gt; &lt;code&gt;chmod +x yourscript.sh&lt;/code&gt; — cron skips files it can't execute.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Missing newline.&lt;/strong&gt; Cron silently ignores the &lt;em&gt;last line&lt;/em&gt; of a crontab without a trailing newline. The classic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No output redirection.&lt;/strong&gt; Without &lt;code&gt;&amp;gt;&amp;gt; /tmp/job.log 2&amp;gt;&amp;amp;1&lt;/code&gt;, errors go to a local mailbox that doesn't exist on most minimal images. The error vanishes. You can't debug invisible errors.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Crond isn't running.&lt;/strong&gt; &lt;code&gt;systemctl status cron&lt;/code&gt;, or &lt;code&gt;ps aux | grep cron&lt;/code&gt;. Sometimes the daemon is just dead.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Script mtime too fresh.&lt;/strong&gt; Classic Vixie cron skips a run if the file's mtime is newer than its last execution time. Edit → run → skipped, on purpose.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malformed expression.&lt;/strong&gt; One extra space, a &lt;code&gt;%&lt;/code&gt; outside its escape context, and the line silently dies. Validate your expression before you trust it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The output worked because you ran it as root / user X, but cron runs as the crontab owner.&lt;/strong&gt; Different user, different environment, different permissions.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;The fastest debug ritual:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;crontab &lt;span class="nt"&gt;-l&lt;/span&gt;          &lt;span class="c"&gt;# is the entry actually there?&lt;/span&gt;
systemctl status cron
&lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="k"&gt;*&lt;/span&gt; &lt;span class="k"&gt;*&lt;/span&gt; /tmp/job.sh &lt;span class="o"&gt;&amp;gt;&amp;gt;&lt;/span&gt; /tmp/job.log 2&amp;gt;&amp;amp;1   &lt;span class="c"&gt;# make errors visible&lt;/span&gt;
&lt;span class="nb"&gt;cat&lt;/span&gt; /tmp/job.log
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That last line is the highest-leverage habit in all of cron debugging: &lt;strong&gt;always redirect output to a log you can read.&lt;/strong&gt; The number of "impossible" cron failures that turn into a one-line fix the moment you see the error is genuinely absurd.&lt;/p&gt;

&lt;p&gt;I keep the full 9-point checklist with per-cause fixes at &lt;a href="https://cron-generator-kappa.vercel.app/guides/cron-not-running" rel="noopener noreferrer"&gt;https://cron-generator-kappa.vercel.app/guides/cron-not-running&lt;/a&gt; — bookmark it for the next 40-minute mystery. And if your expression itself is the suspect, validate it in plain English first: &lt;a href="https://cron-generator-kappa.vercel.app" rel="noopener noreferrer"&gt;https://cron-generator-kappa.vercel.app&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Which of the nine bit you hardest? For me it was the missing newline — an hour of my life that a trailing &lt;code&gt;\n&lt;/code&gt; could have saved.&lt;/p&gt;

</description>
      <category>cron</category>
      <category>devops</category>
      <category>linux</category>
      <category>beginners</category>
    </item>
    <item>
      <title>Your JWT payload is public. Read it before an attacker does.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Mon, 17 Aug 2026 04:43:29 +0000</pubDate>
      <link>https://dev.to/developer_tech/your-jwt-payload-is-public-read-it-before-an-attacker-does-3ck</link>
      <guid>https://dev.to/developer_tech/your-jwt-payload-is-public-read-it-before-an-attacker-does-3ck</guid>
      <description>&lt;p&gt;Here's the sentence most developers learn a little too late: &lt;strong&gt;a JWT's header and payload are not encrypted. They're Base64.&lt;/strong&gt; Anyone who can see your token can read every field inside it — your user ID, your role, your custom claims. The signature protects &lt;em&gt;integrity&lt;/em&gt;, not &lt;em&gt;confidentiality&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;So before you store a secret in a token, let's be clear about what's actually readable. This is the same token your auth server hands out, decoded:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nl"&gt;"alg"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"HS256"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nl"&gt;"typ"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"JWT"&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;                    &lt;/span&gt;&lt;span class="err"&gt;&amp;lt;-&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;header:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;the&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;algorithm&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nl"&gt;"sub"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"1234567890"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"Ada Lovelace"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="err"&gt;&amp;lt;-&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;payload:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;fully&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;readable&lt;/span&gt;&lt;span class="w"&gt;
 &lt;/span&gt;&lt;span class="nl"&gt;"iat"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1516239022&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nl"&gt;"exp"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1799999999&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Both parts are plain JSON behind a Base64 wrapper. A kid with &lt;code&gt;atob()&lt;/code&gt; and five minutes reads them. If your payload holds a password, an email, or a role that grants privileges — you just shipped a credential leak that your "encrypted" token vibes will never catch.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The claims that matter (and what they're for):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;sub&lt;/code&gt; — who the token belongs to&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;iat&lt;/code&gt; — when it was issued&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;exp&lt;/code&gt; — when it dies (tokens without this never expire — a flaw)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;iss&lt;/code&gt; / &lt;code&gt;aud&lt;/code&gt; — who issued it and who it's for (your API)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;jti&lt;/code&gt; — a unique ID, your best tool for revocation&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;HS256 vs RS256 — pick carefully.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;HS256 signs with one shared secret. Whoever holds the secret can both verify &lt;em&gt;and forge&lt;/em&gt; tokens. RS256 uses a public/private key pair — your server verifies with the public key, and only the private key can sign. For anything that crosses service boundaries, RS256. And if your library lets a token dictate its own algorithm, you've opened the classic &lt;code&gt;alg&lt;/code&gt; confusion attack — lock the algorithm you accept, always.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The 12-point hardening checklist (abridged to the ones that matter):&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Never put secrets in the payload — it's readable by design.&lt;/li&gt;
&lt;li&gt;Always set &lt;code&gt;exp&lt;/code&gt; and check it on every request.&lt;/li&gt;
&lt;li&gt;Pin the algorithm — never trust &lt;code&gt;alg&lt;/code&gt; from the token.&lt;/li&gt;
&lt;li&gt;Validate &lt;code&gt;aud&lt;/code&gt; and &lt;code&gt;iss&lt;/code&gt;; most JWT libraries default to loose matching.&lt;/li&gt;
&lt;li&gt;Use RS256 (or better) for anything shared between services.&lt;/li&gt;
&lt;li&gt;Use short-lived access tokens + refresh tokens, not one token that lives for months.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That last one is the difference between a breach and an incident: a token that can be revoked and expires in 15 minutes is a credential. A token that lives for 90 days is a skeleton key.&lt;/p&gt;

&lt;p&gt;I keep a full copy of this guide, with the complete 12-point checklist and every standard claim explained, at &lt;a href="https://jwt-base64-inspector.vercel.app/guides/jwt-security" rel="noopener noreferrer"&gt;https://jwt-base64-inspector.vercel.app/guides/jwt-security&lt;/a&gt;. And if you want to see what your own tokens actually contain, decode one client-side — it never leaves your browser: &lt;a href="https://jwt-base64-inspector.vercel.app" rel="noopener noreferrer"&gt;https://jwt-base64-inspector.vercel.app&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One honest caveat: this is the guide I wish I'd read before my first auth system, not after. Reading it after a production incident costs a lot more attention.&lt;/p&gt;

&lt;p&gt;Which of the six checks above is the one most teams skip? I'd bet on &lt;code&gt;aud&lt;/code&gt; validation — it's the quiet one that libraries don't nag you about.&lt;/p&gt;

</description>
      <category>security</category>
      <category>jwt</category>
      <category>webdev</category>
      <category>beginners</category>
    </item>
    <item>
      <title>92.5% of all AI model downloads are under 1 billion parameters. Everyone's still talking about the frontier models.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Sun, 16 Aug 2026 12:01:30 +0000</pubDate>
      <link>https://dev.to/developer_tech/925-of-all-ai-model-downloads-are-under-1-billion-parameters-everyones-still-talking-about-the-4koo</link>
      <guid>https://dev.to/developer_tech/925-of-all-ai-model-downloads-are-under-1-billion-parameters-everyones-still-talking-about-the-4koo</guid>
      <description>&lt;p&gt;Here's the story nobody's telling:&lt;/p&gt;

&lt;p&gt;Small models stopped being a compromise in 2026.&lt;br&gt;
A 4B model on a laptop handles classification, extraction, cleanup -&lt;br&gt;
the boring work that actually fills your week.&lt;br&gt;
No API keys. No per-token bills. No data leaving your machine.&lt;/p&gt;

&lt;p&gt;And that last one matters more than people think.&lt;/p&gt;

&lt;p&gt;A court order in 2025 forced OpenAI to keep deleted chats indefinitely.&lt;br&gt;
The EU AI Act started enforcing data rules this month.&lt;br&gt;
Suddenly "send it to the API" isn't the obvious answer anymore - it's a liability.&lt;/p&gt;

&lt;p&gt;So the pattern flipped:&lt;br&gt;
~70% of routine AI tasks can run locally, for free, instantly.&lt;br&gt;
The remaining 20-30% - deep reasoning, long context - that's what frontier APIs are for.&lt;/p&gt;

&lt;p&gt;This is the same lesson my trading systems taught me:&lt;br&gt;
The tools that survive are the small ones.&lt;br&gt;
The ones that do one thing, do it fast, and never leak.&lt;/p&gt;

&lt;p&gt;My CSV tool runs fully in the browser for the same reason.&lt;br&gt;
Your data never leaves your machine. It doesn't need to.&lt;/p&gt;

&lt;p&gt;What's the last thing you sent to an API&lt;br&gt;
that should have stayed on your laptop?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>llm</category>
      <category>privacy</category>
    </item>
    <item>
      <title>"Cron 'every 2 weeks' doesn't exist. Here's the expression that actually works."</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Sun, 16 Aug 2026 04:35:37 +0000</pubDate>
      <link>https://dev.to/developer_tech/cron-every-2-weeks-doesnt-exist-heres-the-expression-that-actually-works-2n5</link>
      <guid>https://dev.to/developer_tech/cron-every-2-weeks-doesnt-exist-heres-the-expression-that-actually-works-2n5</guid>
      <description>&lt;p&gt;You just Googled "cron every 2 weeks" because your clean-up job keeps running weekly, and the cron docs are silent on the whole idea. That's not your fault — the 5-field format has no concept of week parity. There's no &lt;code&gt;*/2w&lt;/code&gt;, no &lt;code&gt;every-other&lt;/code&gt;. But there's a day-of-month trick that gives you a real biweekly cadence, and it's not what most people write.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The trap most people fall into.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Writing &lt;code&gt;0 0 * * 1&lt;/code&gt; (every Monday) and hoping it means "every other Monday." It doesn't. That expression fires every single Monday. Every week. The exact thing you were trying to avoid.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The expression that works.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;You need a day-of-month window that exists in only one of the two weeks. The classic:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;0 0 1-7,15-21 * 1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every 2 weeks on Monday at midnight. Monday lands on day-of-month 1–7 in one week of the month and 15–21 in the next — so it fires exactly once per fortnight. Every month, no matter how long it is, because windows 1–7 and 15–21 always exist.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The same trick, other weekdays.&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;0 0 1-7,15-21 * 5      # every 2 weeks on Friday (payroll, reports)
0 9 8-14,22-28 * 3     # every 2 weeks on Wednesday at 9 AM
30 4 1-7,15-21 * 0     # every 2 weeks on Sunday at 4:30 AM
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;The pitfalls that break it.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Avoid windows that end near day 28 (like &lt;code&gt;22-28&lt;/code&gt;) — they vanish in short months.&lt;/li&gt;
&lt;li&gt;Prefer windows that never cross into the next month.&lt;/li&gt;
&lt;li&gt;If you want every 2 weeks on a &lt;em&gt;specific date&lt;/em&gt; like the 1st, you can't express that in cron alone — no day-of-month value is "every other month."&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;The cleaner alternative.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Honestly? For anything more complex than this, don't fight the format. Keep a plain weekly line (&lt;code&gt;0 0 * * 1&lt;/code&gt;) as the trigger and let a tiny wrapper script track a timestamp and skip every other run. It's boring, it's readable, and it doesn't break in February. Application schedulers like APScheduler or croniter handle biweekly with plain calendar arithmetic — no day-of-month acrobatics.&lt;/p&gt;

&lt;p&gt;I keep a full reference of verified biweekly expressions plus this exact guide at &lt;a href="https://cron-generator-kappa.vercel.app/guides/cron-every-two-weeks" rel="noopener noreferrer"&gt;https://cron-generator-kappa.vercel.app/guides/cron-every-two-weeks&lt;/a&gt; — bookmark it and you'll never reconstruct the windows from memory again. And if your cron never seems to fire at all, that's a different bug — but that one's usually a timezone, not the schedule.&lt;/p&gt;

&lt;p&gt;Cron's 5 fields can't do "every 2 weeks" natively. The day-of-month window is the workaround, and now you've got the expressions to copy.&lt;/p&gt;

&lt;p&gt;Which biweekly jobs do you run? Every-other-Monday reports, or something else? I'd genuinely like to hear what people are scheduling — the answers usually reveal a cleaner pattern than my day-of-month trick.&lt;/p&gt;

</description>
      <category>cron</category>
      <category>devops</category>
      <category>productivity</category>
      <category>beginners</category>
    </item>
    <item>
      <title>"Yellow leaves, brown tips: what your houseplant is actually telling you"</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Sat, 15 Aug 2026 21:42:41 +0000</pubDate>
      <link>https://dev.to/developer_tech/yellow-leaves-brown-tips-what-your-houseplant-is-actually-telling-you-5gim</link>
      <guid>https://dev.to/developer_tech/yellow-leaves-brown-tips-what-your-houseplant-is-actually-telling-you-5gim</guid>
      <description>&lt;p&gt;One plant, two symptoms, three possible causes. If you've ever stared at a sad houseplant and guessed, you're in good company — most plant advice online is a guessing game. Let me give you a diagnostic order that actually works, so you fix the cause instead of the symptom.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Yellow leaves = watering stress. Read which way.&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Fat, yellow bottom leaves + damp soil = &lt;strong&gt;overwatering&lt;/strong&gt;. The roots are suffocating. Let the soil dry out significantly before the next water.&lt;/li&gt;
&lt;li&gt;Thin, crispy yellow leaves + bone-dry soil = &lt;strong&gt;underwatering&lt;/strong&gt;. Water thoroughly, then keep a steady rhythm.&lt;/li&gt;
&lt;li&gt;Yellow on &lt;em&gt;new&lt;/em&gt; growth = rarer and more serious — usually root rot or pests. Act fast.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Brown, crispy tips = humidity, salts, or heat.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;On otherwise healthy leaves, brown tips come from three places in order of likelihood:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Low humidity&lt;/strong&gt; — group plants together or add a pebble tray with water.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tap-water salts&lt;/strong&gt; — minerals build up in the soil over months. Flush the pot with a few thorough waterings.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Too close to a heater/vent&lt;/strong&gt; — move the plant; airflow damage looks exactly like this.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;The "water it" reflex kills more plants than neglect.&lt;/strong&gt; Before you water any yellow-leafed plant, push a finger two knuckles into the soil. Damp? The problem is too much water — back off. Bone dry? Then water deeply. Most yellow-leaf deaths are drownings.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;One yellow leaf is normal.&lt;/strong&gt; If it's a single older leaf and the rest of the plant looks healthy, it's just the plant retiring an old leaf. Panic starts only when several leaves change at once or new growth is affected.&lt;/p&gt;

&lt;p&gt;I put this same decision tree, plus per-plant watering/light/humidity/soil guidance for 51 common houseplants, at &lt;a href="https://everleaf-taupe.vercel.app" rel="noopener noreferrer"&gt;https://everleaf-taupe.vercel.app&lt;/a&gt;. The full version of this guide lives here: &lt;a href="https://everleaf-taupe.vercel.app/blog/why-your-plant-leaves-turn-yellow" rel="noopener noreferrer"&gt;https://everleaf-taupe.vercel.app/blog/why-your-plant-leaves-turn-yellow&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Short version: check the soil, read which leaves changed, and let the plant talk before you react. It almost always tells you exactly what's wrong.&lt;/p&gt;

</description>
      <category>houseplants</category>
      <category>gardening</category>
      <category>beginners</category>
      <category>webdev</category>
    </item>
    <item>
      <title>"How often should you water houseplants? A decision tree, not a schedule"</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Sat, 15 Aug 2026 21:04:01 +0000</pubDate>
      <link>https://dev.to/developer_tech/how-often-should-you-water-houseplants-a-decision-tree-not-a-schedule-o9b</link>
      <guid>https://dev.to/developer_tech/how-often-should-you-water-houseplants-a-decision-tree-not-a-schedule-o9b</guid>
      <description>&lt;p&gt;Ask five plant people "how often should I water my plants?" and you'll get five different answers — because the right answer depends on the plant, the pot, the light, and the season. A fixed calendar schedule is exactly how most houseplants die.&lt;/p&gt;

&lt;p&gt;Here's the decision tree I actually use, and it works for every plant in the house.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Check the soil, not the date.&lt;/strong&gt; Stick a finger about one knuckle deep. Water when that depth is dry. For most tropical houseplants (monstera, pothos, philodendron, peace lily) that's the whole rule — about once a week in summer, less in winter.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Succulents and cacti wait longer.&lt;/strong&gt; They store water in their leaves and roots rot fast. Let the soil dry out completely — sometimes for two or three weeks — then give a thorough soak. A jade plant, snake plant, or aloe wants neglect, not attention.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Deep-water, then drain.&lt;/strong&gt; When you do water, water until it runs out the drainage holes, then tip away the excess after 15 minutes. Small frequent sips keep the topsoil wet and the rootball dry, which is the classic recipe for yellow leaves.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Watch the leaves.&lt;/strong&gt; Drooping that perks up within a few hours of watering = underwatered. Drooping that stays soft and yellow after watering = overwatered, the harder one to fix. Crispy brown edges are usually low humidity, not thirst.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Adjust for environment.&lt;/strong&gt; More light and warmth = faster drying = water more often. Winter, AC, or low light = the opposite. A plant that needed water every 6 days in July can go 12+ days in January.&lt;/p&gt;

&lt;p&gt;Each plant species has slightly different quirks though. I keep a per-plant reference at &lt;a href="https://everleaf.vercel.app" rel="noopener noreferrer"&gt;https://everleaf.vercel.app&lt;/a&gt; — you pick a plant (snake plant, pothos, monstera, fiddle leaf fig, peace lily, calathea, and 45 more) and it gives watering, light, humidity, and soil guidance specific to that species. The watering guide is here: &lt;a href="https://everleaf.vercel.app/blog/how-often-to-water-houseplants" rel="noopener noreferrer"&gt;https://everleaf.vercel.app/blog/how-often-to-water-houseplants&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The shortest summary: check the soil, water deeply, let it drain, and read the leaves. Skip the calendar and the plant will forgive almost everything else.&lt;/p&gt;

</description>
      <category>houseplants</category>
      <category>gardening</category>
      <category>beginners</category>
      <category>productivity</category>
    </item>
    <item>
      <title>7 data headaches that eat developers' time. And the 1-line fixes for each.</title>
      <dc:creator>Benjamin</dc:creator>
      <pubDate>Fri, 14 Aug 2026 12:28:00 +0000</pubDate>
      <link>https://dev.to/developer_tech/7-data-headaches-that-eat-developers-timeand-the-1-line-fixes-for-each-1b71</link>
      <guid>https://dev.to/developer_tech/7-data-headaches-that-eat-developers-timeand-the-1-line-fixes-for-each-1b71</guid>
      <description>&lt;p&gt;These come from building a browser tool&lt;br&gt;
that converts CSVs with 200k rows —&lt;br&gt;
and learning every way data can fight back.&lt;/p&gt;

&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Excel semicolon exports.&lt;br&gt;
Your comma parser dies on the first row.&lt;br&gt;
Fix: detect the separator from the header line, not the extension.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;UTF-8 BOM.&lt;br&gt;
One invisible character at the start of the file&lt;br&gt;
and your first column is named "\uFEFFname".&lt;br&gt;
Fix: strip BOM before parsing. Always.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Huge files freeze the tab.&lt;br&gt;
Loading 500k rows into memory at once&lt;br&gt;
kills the browser — and the user's patience.&lt;br&gt;
Fix: stream in chunks and process row by row.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Numbers that are actually strings.&lt;br&gt;
"1,234.56" with a comma breaks every calculation.&lt;br&gt;
Fix: parse numbers with locale in mind, never blindly.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Mixed encodings in one file.&lt;br&gt;
Half the file is UTF-8, half is Latin-1.&lt;br&gt;
Fix: detect encoding from the first bytes, then convert.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Empty rows and stray newlines.&lt;br&gt;
A trailing blank line crashes naive parsers.&lt;br&gt;
Fix: skip empty lines and trim before splitting.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;"But it works on my machine."&lt;br&gt;
The file your parser handled perfectly&lt;br&gt;
fails on the user's real-world file.&lt;br&gt;
Fix: test against messy, real data — not clean examples.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/blockquote&gt;


&lt;/blockquote&gt;

&lt;p&gt;One rule ties them all:&lt;br&gt;
assume the data is broken. Then it never surprises you.&lt;/p&gt;

&lt;p&gt;Save this for the next time a CSV ruins your day.&lt;/p&gt;

&lt;p&gt;Which one of these hit you hardest?&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
