<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: gia ly bui</title>
    <description>The latest articles on DEV Community by gia ly bui (@gia_lybui).</description>
    <link>https://dev.to/gia_lybui</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4014348%2Faed3682f-c18c-4684-832b-3748091e7b72.png</url>
      <title>DEV Community: gia ly bui</title>
      <link>https://dev.to/gia_lybui</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/gia_lybui"/>
    <language>en</language>
    <item>
      <title>Buy CS2 Skins or Open Cases? The Math Nobody Shows You</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Wed, 09 Sep 2026 01:08:29 +0000</pubDate>
      <link>https://dev.to/gia_lybui/buy-cs2-skins-or-open-cases-the-math-nobody-shows-you-1d45</link>
      <guid>https://dev.to/gia_lybui/buy-cs2-skins-or-open-cases-the-math-nobody-shows-you-1d45</guid>
      <description>&lt;p&gt;Every new CS2 player hits the same fork: buy the skin you want, or open cases and gamble for it. The case sites make opening look like a shortcut to a knife. The math says otherwise, and it's worth seeing the numbers before you deposit.&lt;/p&gt;

&lt;p&gt;Case drop odds are public, and they're brutal:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A covert (red) skin is about a 0.64% drop.&lt;/li&gt;
&lt;li&gt;A knife is about a 0.26% drop — roughly 1 in 384 cases.&lt;/li&gt;
&lt;li&gt;At a typical $2.50 per case, that's an expected cost around $960 per knife.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And here's the part most guides skip: the knife you finally unbox usually resells for less than that expected cost. The house edge is structural. Opening cases is entertainment with a lottery ticket attached — not a way to acquire skins cheaply.&lt;/p&gt;

&lt;p&gt;So when does opening make sense? Only when the value isn't the skin but the &lt;em&gt;experience&lt;/em&gt;, and only with free cases (several sites give one free daily case — that's pure expected value with zero deposit). When you want a specific skin, buying it directly is almost always cheaper.&lt;/p&gt;

&lt;p&gt;The honest rule of thumb: &lt;strong&gt;if you want a specific skin, buy it. If you want a few minutes of fun with a free daily case, open that.&lt;/strong&gt; Mixing the two — chasing a knife with paid cases — is how balances disappear.&lt;/p&gt;

&lt;p&gt;I ran the full comparison, including which cases have the best resale value and where the free daily cases are: &lt;a href="https://cs2caseguide.com/case-vs-buy" rel="noopener noreferrer"&gt;https://cs2caseguide.com/case-vs-buy&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cs2</category>
      <category>gaming</category>
      <category>beginners</category>
    </item>
    <item>
      <title>How to Make YouTube Videos Without a Camera (Full AI Workflow)</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Mon, 07 Sep 2026 23:24:23 +0000</pubDate>
      <link>https://dev.to/gia_lybui/how-to-make-youtube-videos-without-a-camera-full-ai-workflow-17cp</link>
      <guid>https://dev.to/gia_lybui/how-to-make-youtube-videos-without-a-camera-full-ai-workflow-17cp</guid>
      <description>&lt;p&gt;You don't need a camera, a mic, or editing skills to publish on YouTube in 2026. The whole faceless-channel stack has collapsed into a few tools, and the workflow is shorter than most people expect.&lt;/p&gt;

&lt;p&gt;Here's the exact flow I use:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Write the script first.&lt;/strong&gt; The video is only as good as the words. Aim for a tight, conversational script — under 500 words for a 3-minute video.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Turn the script into a talking head.&lt;/strong&gt; Paste it into an AI avatar tool and pick a stock presenter. The tool lip-syncs the avatar to your script in 140+ languages. This is the step that used to require a face on camera; now a stock avatar reads it naturally enough that most viewers never flag it.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Generate b-roll if you want movement.&lt;/strong&gt; For explainer-style content, a few generated clips between talking-head sections keep retention up. Skip this if you're doing pure commentary.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Add captions.&lt;/strong&gt; Burned-in captions are the single biggest retention lever for short content. Most platforms auto-generate them; a quick cleanup pass is all it takes.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Publish and repurpose.&lt;/strong&gt; One video becomes a Short, a TikTok, and a Reel with minimal extra work.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The biggest mistake beginners make is buying a text-to-video generator when they actually needed an avatar — those are two different jobs. For a faceless talking-head channel, the avatar tool is the one that matters.&lt;/p&gt;

&lt;p&gt;I wrote the full step-by-step setup, including which avatar tool to start with and how to avoid burning your monthly credits: &lt;a href="https://aivideotest.com/no-camera" rel="noopener noreferrer"&gt;https://aivideotest.com/no-camera&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>contentcreation</category>
      <category>beginners</category>
    </item>
    <item>
      <title>Online Dating Scams Are Getting Smarter. Here's How to Spot Them</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Sat, 05 Sep 2026 08:29:09 +0000</pubDate>
      <link>https://dev.to/gia_lybui/online-dating-scams-are-getting-smarter-heres-how-to-spot-them-2ndf</link>
      <guid>https://dev.to/gia_lybui/online-dating-scams-are-getting-smarter-heres-how-to-spot-them-2ndf</guid>
      <description>&lt;p&gt;Online dating is convenient, but the scams on these platforms have gotten noticeably more sophisticated. They target the same thing: your trust, then your money.&lt;/p&gt;

&lt;p&gt;The red flags to learn first:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;They won't video-call. A real person can jump on a call. Scammers always have an excuse — broken camera, bad signal, "not ready yet."&lt;/li&gt;
&lt;li&gt;They need money fast. The story varies (medical emergency, travel to meet you, business deal), but the ask is the same: an urgent transfer, usually untraceable.&lt;/li&gt;
&lt;li&gt;They push you off-platform. Moving to WhatsApp or Telegram fast is a red flag — they want to get outside the app's safety features.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Privacy rules that protect you: keep your full name, address, and workplace off your profile until you've met in person, and never send money to someone you've only met online, no matter the story.&lt;/p&gt;

&lt;p&gt;A few platforms do a better job of verifying identities than others — that alone filters out a meaningful chunk of the fake accounts. I put together the full checklist of red flags and the safer platforms here: &lt;a href="https://safeadultguide.com/hub/dating-safety-complete-guide" rel="noopener noreferrer"&gt;Online Dating Safety Guide 2026: Avoid Scams &amp;amp; Stay Safe — Honest Adult Lifestyle Reviews&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>privacy</category>
      <category>safety</category>
      <category>internet</category>
    </item>
    <item>
      <title>I Tracked 500 CS2 Case Openings. Here's What the Math Actually Says</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Fri, 04 Sep 2026 08:35:31 +0000</pubDate>
      <link>https://dev.to/gia_lybui/i-tracked-500-cs2-case-openings-heres-what-the-math-actually-says-13he</link>
      <guid>https://dev.to/gia_lybui/i-tracked-500-cs2-case-openings-heres-what-the-math-actually-says-13he</guid>
      <description>&lt;p&gt;CS2 case opening &lt;em&gt;feels&lt;/em&gt; like it should be profitable — the big wins get all the attention. So I tracked 500 openings across official and third-party cases to see what actually comes back.&lt;/p&gt;

&lt;p&gt;The short version: opening cases is entertainment, not an investment. Here's the math.&lt;/p&gt;

&lt;p&gt;Official cases are the worst value. The $2.50 key fee alone means $50 opens roughly 20 cases, and the published drop rates are brutal — a knife is about 0.26% (roughly 1 in 385), a red covert about 0.64%.&lt;/p&gt;

&lt;p&gt;Third-party sites change the math by removing the key fee and adding deposit bonuses. My tracking showed $50 on a third-party site returns about $30–45 of skins, versus $12–18 on official cases.&lt;/p&gt;

&lt;p&gt;But here's the part nobody frames well: if you want a &lt;em&gt;specific&lt;/em&gt; skin, opening cases for it is a losing game. Buying it directly means $50 buys exactly $50 of value — and on third-party marketplaces you often get $65–70 worth below Steam Market price.&lt;/p&gt;

&lt;p&gt;The sane strategy is a hybrid: use free daily cases for the thrill, buy the skins you actually want directly. Full ROI comparison with the exact numbers: &lt;a href="https://cs2caseguide.com/case-vs-buy" rel="noopener noreferrer"&gt;CS2 Case Opening vs Buying Skins — ROI Comparison 2026&lt;/a&gt;&lt;/p&gt;

</description>
      <category>gaming</category>
      <category>data</category>
      <category>statistics</category>
      <category>analysis</category>
    </item>
    <item>
      <title>How I Make Videos With No Camera, No Mic, and No Editing Skills</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Thu, 03 Sep 2026 14:18:27 +0000</pubDate>
      <link>https://dev.to/gia_lybui/how-i-make-videos-with-no-camera-no-mic-and-no-editing-skills-2k22</link>
      <guid>https://dev.to/gia_lybui/how-i-make-videos-with-no-camera-no-mic-and-no-editing-skills-2k22</guid>
      <description>&lt;p&gt;I used to think making videos required a camera, decent lighting, and hours in an editor. Then I built a full faceless channel without any of it.&lt;/p&gt;

&lt;p&gt;The workflow comes down to three jobs, and the #1 mistake people make is buying a tool for the wrong job.&lt;/p&gt;

&lt;p&gt;Job 1: The talking head. You don't need a camera — AI avatar tools let you type a script and a realistic digital presenter reads it. One tool (Synthesia) has the most natural stock avatars I've tested across 140+ languages; its main competitor is the pick if you want to clone your own face and voice from a 2-minute video.&lt;/p&gt;

&lt;p&gt;Job 2: The b-roll. Instead of shooting footage, text-to-video models generate it from a prompt. The cinematic-grade option here produces clips creators use for music videos and ads.&lt;/p&gt;

&lt;p&gt;Job 3: The captions. Most people watch short-form on mute, so auto-captions are non-negotiable.&lt;/p&gt;

&lt;p&gt;My actual stack: one avatar tool for the talking head, one generation tool for b-roll, and auto-captions on top. That's the whole pipeline — no camera, no mic, no manual editing.&lt;/p&gt;

&lt;p&gt;I broke down the full ranking of every tool I tested, with real pricing and what each is actually good for: &lt;a href="https://aivideotest.com/" rel="noopener noreferrer"&gt;Best AI Video Generators 2026 — Ranked &amp;amp; Compared&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>tools</category>
      <category>productivity</category>
    </item>
    <item>
      <title>How to Withdraw CS2 Skins from Any Case Site (and the Steam Guard Trap)</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Fri, 28 Aug 2026 14:00:07 +0000</pubDate>
      <link>https://dev.to/gia_lybui/how-to-withdraw-cs2-skins-from-any-case-site-and-the-steam-guard-trap-id0</link>
      <guid>https://dev.to/gia_lybui/how-to-withdraw-cs2-skins-from-any-case-site-and-the-steam-guard-trap-id0</guid>
      <description>&lt;p&gt;If you've ever opened CS2 cases and hit a wall trying to get your skins out, you're not alone — the search logs are full of "how to withdraw from X" for a hundred different sites. The good news: the process is the same everywhere. The bad news: one Valve rule trips up almost everyone.&lt;/p&gt;

&lt;p&gt;Here's the universal withdrawal flow, step by step:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Enable Steam Guard Mobile Authenticator&lt;/strong&gt; — this is the step that decides whether you wait minutes or 7 days.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log in with official Steam OpenID&lt;/strong&gt; (steamcommunity.com, never a lookalike domain).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Open your inventory&lt;/strong&gt;, select the skins, and accept the trade offer from the site's bot.&lt;/li&gt;
&lt;li&gt;Confirm with your mobile authenticator, and the skins land in your Steam inventory.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The #1 thing players get wrong is skipping Steam Guard Mobile. Steam's 7-day trade hold is a Valve anti-fraud rule — no case site can bypass it. Enable the mobile authenticator (not just email guard) at least 7 days before you plan to withdraw, and your trades clear in minutes.&lt;/p&gt;

&lt;p&gt;The bigger question is &lt;em&gt;which&lt;/em&gt; site you trust. There are sites with real track records (Hellcase has run since 2016 with 5M+ users), and there are parked domains and clones buying ads on popular names.&lt;/p&gt;

&lt;p&gt;I put together a &lt;a href="https://cs2caseguide.com/withdraw-directory" rel="noopener noreferrer"&gt;site-by-site withdrawal directory&lt;/a&gt; covering the sites players search for most — which ones are verified and which ones you should treat as "verify before you deposit." If you want the short version: the full walkthrough is in my &lt;a href="https://cs2caseguide.com/withdraw-guide" rel="noopener noreferrer"&gt;CS2 withdrawal guide&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>cs2</category>
      <category>gaming</category>
      <category>security</category>
      <category>beginners</category>
    </item>
    <item>
      <title>Stop Paying for 5 Video Tools — Here's the Only 3 You Actually Need</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Wed, 26 Aug 2026 10:18:21 +0000</pubDate>
      <link>https://dev.to/gia_lybui/stop-paying-for-5-video-tools-heres-the-only-3-you-actually-need-9ao</link>
      <guid>https://dev.to/gia_lybui/stop-paying-for-5-video-tools-heres-the-only-3-you-actually-need-9ao</guid>
      <description>&lt;p&gt;AI video tools exploded this year, but most people waste money on overlapping subscriptions.&lt;/p&gt;

&lt;p&gt;After testing a dozen, I keep coming back to three that cover 100% of use cases:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;a href="https://runway.com" rel="noopener noreferrer"&gt;Runway&lt;/a&gt; — best for text-to-video and motion editing. The Gen-4 model is the closest thing to "type a prompt, get a scene."&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://pictory.ai?fpr=gia-ly17" rel="noopener noreferrer"&gt;Pictory&lt;/a&gt; — best for turning blog posts into short-form videos. Paste a URL, get a talking-head video with captions.&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://synthesia.io?via=gia" rel="noopener noreferrer"&gt;Synthesia&lt;/a&gt; — best for avatar/explainer videos. 140+ languages, no camera needed.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The mistake isn't buying these — it's buying three tools that do the same thing.&lt;/p&gt;

&lt;p&gt;My rule: one for raw generation, one for repurposing content, one for explainers. Anything else is overlap.&lt;/p&gt;

&lt;p&gt;What's your stack? Drop it below.&lt;/p&gt;

&lt;p&gt;If you want the full comparison (pricing, use cases, which to skip), I put everything on one page: &lt;a href="https://aivideotest.com" rel="noopener noreferrer"&gt;aivideotest.com&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>productivity</category>
    </item>
    <item>
      <title>I Cloned Myself with AI — The Honest, Step-by-Step Breakdown</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Tue, 25 Aug 2026 02:12:53 +0000</pubDate>
      <link>https://dev.to/gia_lybui/i-cloned-myself-with-ai-the-honest-step-by-step-breakdown-3oaf</link>
      <guid>https://dev.to/gia_lybui/i-cloned-myself-with-ai-the-honest-step-by-step-breakdown-3oaf</guid>
      <description>&lt;p&gt;AI cloning sounded like sci-fi to me until I actually did it. Upload a two-minute video of yourself, and a digital twin does your on-camera work forever after. In 2026 this is not just real — it's shockingly easy.&lt;/p&gt;

&lt;p&gt;First, a clarification: you cannot physically clone yourself. What tools like HeyGen do is build an &lt;strong&gt;AI clone&lt;/strong&gt; — a digital twin that looks and sounds like you in videos. It's the closest thing to cloning yourself that exists today.&lt;/p&gt;

&lt;h2&gt;
  
  
  What you actually need
&lt;/h2&gt;

&lt;p&gt;Two minutes of footage. That's it. But those two minutes should be your best take, because the clone inherits how you look in that clip forever.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Good lighting — face fully lit, no harsh shadows&lt;/li&gt;
&lt;li&gt;A plain background — solid color, nothing distracting&lt;/li&gt;
&lt;li&gt;A stable camera — tripod or propped phone&lt;/li&gt;
&lt;li&gt;Clear audio — quiet room, minimal echo&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The workflow
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Create an account (avatar cloning requires a paid plan — not on the free tier)&lt;/li&gt;
&lt;li&gt;Record two minutes of yourself talking naturally, looking at the camera&lt;/li&gt;
&lt;li&gt;Upload it to the avatar builder — it processes the footage in minutes to an hour&lt;/li&gt;
&lt;li&gt;Test your clone with a short script and check the lip-sync&lt;/li&gt;
&lt;li&gt;Use it everywhere — talking-head videos, translated into 40+ languages&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  What it costs
&lt;/h2&gt;

&lt;p&gt;HeyGen starts around $24/month, and cloning consumes credits each time you generate. The clone isn't a one-time buy — it's tied to the plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it's good for (and not)
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Good for:&lt;/strong&gt; faceless YouTube channels, multi-language content, client work, course content.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Not good for:&lt;/strong&gt; emotional or personal content (a clone can't replicate genuine human warmth), and real-time interaction (clones are for pre-scripted video, not live).&lt;/p&gt;

&lt;h2&gt;
  
  
  The one rule that matters
&lt;/h2&gt;

&lt;p&gt;Clone quality depends entirely on your source footage. Garbage in, garbage out. If the lip-sync looks off, it's almost always a source-footage problem, not a tool problem.&lt;/p&gt;

&lt;p&gt;One compliance note if you publish to YouTube: flag realistic AI-generated content through YouTube's altered-content disclosure.&lt;/p&gt;

&lt;p&gt;Full step-by-step guide: &lt;a href="https://aivideotest.com/clone-yourself" rel="noopener noreferrer"&gt;https://aivideotest.com/clone-yourself&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>productivity</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Reverse Engineering Android Apps to Extract Private API Endpoints</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Fri, 21 Aug 2026 14:44:45 +0000</pubDate>
      <link>https://dev.to/gia_lybui/reverse-engineering-android-apps-to-extract-private-api-endpoints-16ng</link>
      <guid>https://dev.to/gia_lybui/reverse-engineering-android-apps-to-extract-private-api-endpoints-16ng</guid>
      <description>&lt;p&gt;Ever needed to integrate with an app that has no public API? Or test your own app and understand what it's actually sending over the wire? Here's how I approach it — from a static decompile all the way to working API calls.&lt;/p&gt;

&lt;p&gt;What you'll need&lt;br&gt;
jadx — static decompilation&lt;br&gt;
apktool — repackaging / resource inspection&lt;br&gt;
Frida — dynamic instrumentation&lt;br&gt;
mitmproxy or Burp Suite — traffic interception&lt;br&gt;
A rooted Android device (recommended, not always required)&lt;br&gt;
Step 1: Static analysis with jadx&lt;br&gt;
Start by decompiling the APK:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;jadx &lt;span class="nt"&gt;-d&lt;/span&gt; output/ app.apk
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Most Android apps use Retrofit or OkHttp. Grep the decompiled source for the telltale annotations:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="nt"&gt;-rE&lt;/span&gt; &lt;span class="s2"&gt;"@GET|@POST|@PUT"&lt;/span&gt; output/ | &lt;span class="nb"&gt;head&lt;/span&gt; &lt;span class="nt"&gt;-50&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This often surfaces endpoint paths, base URLs, and even parameter names in minutes. But here's the catch: modern apps encrypt or obfuscate the interesting parts, so static analysis alone will leave you with dead ends.&lt;/p&gt;

&lt;p&gt;Step 2: Intercept traffic with mitmproxy&lt;br&gt;
Point the device at your proxy and watch the real requests. You'll usually hit SSL pinning immediately — the app rejects your MITM certificate.&lt;/p&gt;

&lt;p&gt;Step 3: Bypass SSL pinning with Frida&lt;br&gt;
This is where dynamic analysis wins. Frida injects into the running process and patches the certificate validation at runtime. A short script hooks the trust managers and lets your proxy see the plaintext traffic.&lt;/p&gt;

&lt;p&gt;Static tools can't do this — the pinning logic only exists at runtime.&lt;/p&gt;

&lt;p&gt;Step 4: Reverse custom encryption&lt;br&gt;
Many apps sign their requests or encrypt the payload. The trick is to hook the encryption function with Frida, dump its input and output, and reconstruct the algorithm. Once you understand the signature generation, you can reproduce it in Python or any language you like.&lt;/p&gt;

&lt;p&gt;Step 5: Extract and document&lt;br&gt;
The output is a clean list of endpoints, their request/response schemas, and a reproducible script that makes working API calls. That's the difference between "here's a decompiled APK" and "here's something you can actually build on."&lt;/p&gt;

&lt;p&gt;A quick legal note&lt;br&gt;
Only do this on apps you own, or where you have explicit authorization. Reverse engineering third-party apps for unauthorized access is illegal in most jurisdictions.&lt;/p&gt;

&lt;p&gt;If you need this done professionally — private API extraction, custom encryption or protocol reverse engineering — I do this as a service: &lt;a href="https://www.fiverr.com/s/jyv78wa" rel="noopener noreferrer"&gt;www.fiverr.com/s/jyv78wa&lt;/a&gt;&lt;/p&gt;

</description>
      <category>android</category>
      <category>reverseengineering</category>
      <category>security</category>
      <category>frida</category>
    </item>
    <item>
      <title>CS2 Case Odds: The Real Drop Rates and Which Cases Are Worth Opening (2026)</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Thu, 20 Aug 2026 04:01:29 +0000</pubDate>
      <link>https://dev.to/gia_lybui/cs2-case-odds-the-real-drop-rates-and-which-cases-are-worth-opening-2026-2e3d</link>
      <guid>https://dev.to/gia_lybui/cs2-case-odds-the-real-drop-rates-and-which-cases-are-worth-opening-2026-2e3d</guid>
      <description>&lt;p&gt;Everyone wants to know which CS2 case has the "best odds." Here's the actual math, because most of what you read online is wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  The fixed odds (they never change)
&lt;/h2&gt;

&lt;p&gt;Every standard case — official or third-party — uses the same published drop rates:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Rarity&lt;/th&gt;
&lt;th&gt;Color&lt;/th&gt;
&lt;th&gt;Odds&lt;/th&gt;
&lt;th&gt;1 in&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Mil-Spec&lt;/td&gt;
&lt;td&gt;Blue&lt;/td&gt;
&lt;td&gt;79.92%&lt;/td&gt;
&lt;td&gt;1.25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Restricted&lt;/td&gt;
&lt;td&gt;Purple&lt;/td&gt;
&lt;td&gt;15.98%&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Classified&lt;/td&gt;
&lt;td&gt;Pink&lt;/td&gt;
&lt;td&gt;3.20%&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Covert&lt;/td&gt;
&lt;td&gt;Red&lt;/td&gt;
&lt;td&gt;0.64%&lt;/td&gt;
&lt;td&gt;156&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Special / Knife&lt;/td&gt;
&lt;td&gt;Gold&lt;/td&gt;
&lt;td&gt;0.26%&lt;/td&gt;
&lt;td&gt;385&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Read that last line again: &lt;strong&gt;roughly 1 knife per 385 cases.&lt;/strong&gt; That's the cold math behind every "I'll just open until I get a knife" plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  So what actually determines ROI?
&lt;/h2&gt;

&lt;p&gt;The odds are fixed, so ROI swings on two things:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The market price of the coverts and knife inside&lt;/strong&gt; — a case whose red is a $2,000 AK-47 has far higher expected value than one whose red is a $50 pistol.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Case cost&lt;/strong&gt; — a cheap discontinued case with expensive skins is the best situation; an expensive new case with cheap skins is the worst.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That's why &lt;strong&gt;discontinued cases with high-value coverts&lt;/strong&gt; dominate the ROI rankings over time. Once a case stops dropping, its skins stop entering the market and appreciate.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest part
&lt;/h2&gt;

&lt;p&gt;The house edge is built into those odds. Over enough openings, the skins you pull are worth less than what you paid to open. You can improve your position by:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Opening only high-ROI (discontinued, high-value covert) cases&lt;/li&gt;
&lt;li&gt;Using free daily cases and deposit bonuses&lt;/li&gt;
&lt;li&gt;Treating it as entertainment with a budget, not an income strategy&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Chasing a knife at 1-in-385 will lose you money over time. Play smart, not desperate.&lt;/p&gt;

&lt;p&gt;Full breakdown with a ranked ROI list and the expected-value math: &lt;a href="https://cs2caseguide.com/cs2-case-odds" rel="noopener noreferrer"&gt;https://cs2caseguide.com/cs2-case-odds&lt;/a&gt;&lt;/p&gt;

</description>
      <category>gaming</category>
      <category>tutorial</category>
      <category>beginners</category>
    </item>
    <item>
      <title>I built a faceless YouTube channel with AI video tools — here's the workflow</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Tue, 18 Aug 2026 15:02:07 +0000</pubDate>
      <link>https://dev.to/gia_lybui/publish-test-gm</link>
      <guid>https://dev.to/gia_lybui/publish-test-gm</guid>
      <description>&lt;p&gt;I wanted to publish videos without showing my face or filming anything. After a month of experimenting, here's the workflow that actually works — and the one thing most people get wrong.&lt;/p&gt;

&lt;p&gt;The workflow&lt;br&gt;
Every AI video starts with a script. The tool can't fix bad writing, so I spend most of my time there: short sentences, written for the ear, roughly 150 words per minute of video.&lt;/p&gt;

&lt;p&gt;Then I pick a tool based on what the video needs:&lt;/p&gt;

&lt;p&gt;A talking presenter? Use an AI avatar tool — you paste the script and a digital presenter reads it. (HeyGen clones your own face from a two-minute video; Synthesia offers a library of stock avatars.)&lt;br&gt;
Original footage? Use a text-to-video tool — describe each scene and it generates the clip.&lt;br&gt;
Repurposing an article? There are tools that turn a blog post into a video automatically.&lt;br&gt;
The trick is matching the tool to the job. A presenter tool can't generate b-roll, and a text-to-video tool can't make someone talk to camera. Most "which tool is best" confusion online comes from comparing tools that don't compete.&lt;/p&gt;

&lt;p&gt;What actually matters&lt;br&gt;
After the video is generated, three things decide whether anyone watches: a hook in the first three seconds, captions (most short-form is watched muted), and a clean vertical export. The AI handles the visuals — the distribution is still on you.&lt;/p&gt;




&lt;p&gt;I wrote up the full comparison and step-by-step setup here: &lt;a href="https://aivideotest.com/" rel="noopener noreferrer"&gt;https://aivideotest.com/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>video</category>
      <category>productivity</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>A Single Canonical Tag Was Crashing My Google Rankings</title>
      <dc:creator>gia ly bui</dc:creator>
      <pubDate>Tue, 18 Aug 2026 14:46:03 +0000</pubDate>
      <link>https://dev.to/gia_lybui/a-single-tag-was-crashing-my-google-rankings-4m28</link>
      <guid>https://dev.to/gia_lybui/a-single-tag-was-crashing-my-google-rankings-4m28</guid>
      <description>&lt;p&gt;I shipped a content site in a niche most devs don't build for — adult-lifestyle product reviews. The stack is boring on purpose: &lt;strong&gt;FastAPI + Jinja2 + JSON data files&lt;/strong&gt;, served from Fly.io's free tier behind Cloudflare. 68 pages, zero CMS, zero build step.&lt;/p&gt;

&lt;p&gt;Two months in, Google Search Console started emailing me something that explained &lt;em&gt;everything&lt;/em&gt; about my dead traffic:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"Duplicate without user-selected canonical"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Here's the bug, the fix, and what the data looked like before and after.&lt;/p&gt;

&lt;h2&gt;
  
  
  The stack
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;FastAPI + Jinja2Templates&lt;/strong&gt; — server-side rendering, no JS framework&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Content as JSON&lt;/strong&gt; — &lt;code&gt;hubs.json&lt;/code&gt;, &lt;code&gt;categories.json&lt;/code&gt;, &lt;code&gt;articles.json&lt;/code&gt;, versioned in git&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Standalone Jinja2 templates&lt;/strong&gt; per pillar page, plus a few pre-rendered static HTML files&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fly.io free tier&lt;/strong&gt; + Cloudflare, with a Python script that regenerates a static &lt;code&gt;sitemap.xml&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Why JSON + templates instead of a CMS? Because I wanted content in version control and zero database to babysit. 68 pages, no admin panel, no migration anxiety.&lt;/p&gt;

&lt;h2&gt;
  
  
  The bug that was tanking my rankings
&lt;/h2&gt;

&lt;p&gt;I opened one of the flagged pages and found &lt;strong&gt;two canonical tags&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight html"&gt;&lt;code&gt;&lt;span class="nt"&gt;&amp;lt;link&lt;/span&gt; &lt;span class="na"&gt;rel=&lt;/span&gt;&lt;span class="s"&gt;"canonical"&lt;/span&gt; &lt;span class="na"&gt;href=&lt;/span&gt;&lt;span class="s"&gt;"https://safeadultguide.com/hub/bdsm-gear-complete-guide"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;link&lt;/span&gt; &lt;span class="na"&gt;rel=&lt;/span&gt;&lt;span class="s"&gt;"canonical"&lt;/span&gt; &lt;span class="na"&gt;href=&lt;/span&gt;&lt;span class="s"&gt;"https://safeadultguide.com/"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The second one pointed at the &lt;strong&gt;homepage&lt;/strong&gt;. I'd left a "default canonical" line in the base template's &lt;code&gt;&amp;lt;head&amp;gt;&lt;/code&gt; and forgotten it existed. Every article on the site was telling Google: &lt;em&gt;"my canonical page is the homepage."&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Google did exactly what I asked it to: treated all 68 pages as duplicates of the homepage, collapsed their ranking signals, and parked me at an &lt;strong&gt;average position of 77.5 — page 8 of results&lt;/strong&gt;. Zero clicks across ~230 impressions.&lt;/p&gt;

&lt;h2&gt;
  
  
  The fix
&lt;/h2&gt;

&lt;p&gt;Move the default canonical &lt;em&gt;inside&lt;/em&gt; the Jinja2 block so child templates can override it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight jinja"&gt;&lt;code&gt;&lt;span class="c"&gt;{# base.html #}&lt;/span&gt;
&lt;span class="cp"&gt;{%&lt;/span&gt; &lt;span class="k"&gt;block&lt;/span&gt; &lt;span class="nv"&gt;canonical&lt;/span&gt; &lt;span class="cp"&gt;%}&lt;/span&gt;
  &lt;span class="nt"&gt;&amp;lt;link&lt;/span&gt; &lt;span class="na"&gt;rel=&lt;/span&gt;&lt;span class="s"&gt;"canonical"&lt;/span&gt; &lt;span class="na"&gt;href=&lt;/span&gt;&lt;span class="s"&gt;"https://safeadultguide.com&lt;/span&gt;&lt;span class="cp"&gt;{{&lt;/span&gt; &lt;span class="nv"&gt;request.url.path&lt;/span&gt; &lt;span class="cp"&gt;}}&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="cp"&gt;{%&lt;/span&gt; &lt;span class="k"&gt;endblock&lt;/span&gt; &lt;span class="cp"&gt;%}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Pages with no override get a &lt;strong&gt;correct self-canonical&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Pages needing a fixed URL override the block&lt;/li&gt;
&lt;li&gt;Exactly &lt;strong&gt;one&lt;/strong&gt; canonical per page&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But a second bug was hiding behind the first. Four of my "hub" pages were served as &lt;strong&gt;pre-rendered static HTML files&lt;/strong&gt; via &lt;code&gt;open().read()&lt;/code&gt; — which bypasses Jinja2 entirely. My template fix didn't touch them; they still had the broken canonical baked into the file. I had to patch those four files individually.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lesson: if you mix template-rendered and pre-rendered static pages, a template fix silently does NOT propagate to the static ones.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Before and after
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Before:&lt;/strong&gt; ~230 impressions / 2 weeks, 0 clicks, average position 77.5&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;~1 week after deploy:&lt;/strong&gt; impressions up ~35%, and the &lt;strong&gt;first click&lt;/strong&gt; landed&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It's a slow climb — Google has to re-crawl 68 pages — but the direction finally flipped from "invisible" to "climbing."&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd tell past me
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Topic clusters beat thin sites.&lt;/strong&gt; 3–5 pillar articles (3,000+ words) + 30–50 cluster articles beats 68 disconnected pages. Google rewards depth over sprawl.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cloudflare "Always Use HTTPS" only works if DNS records are proxied&lt;/strong&gt; (orange cloud). Grey-cloud means traffic bypasses Cloudflare, and http/https serve duplicate content — feeding the exact "duplicate" flag above.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Fly.io's Jinja2 has a dict-hashing bug&lt;/strong&gt; with &lt;code&gt;TemplateResponse()&lt;/code&gt; — wrap it in a &lt;code&gt;render()&lt;/code&gt; helper or it crashes on deploy.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mine GSC query data to pick your next article.&lt;/strong&gt; Write for keywords already earning impressions, not a random list.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check your canonical tags right now.&lt;/strong&gt; One stray &lt;code&gt;&amp;lt;link&amp;gt;&lt;/code&gt; in a shared layout can silently de-index every page you own.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;You can see the site here: &lt;a href="https://safeadultguide.com" rel="noopener noreferrer"&gt;safeadultguide.com&lt;/a&gt; — and if you run a content site, go grep your own &lt;code&gt;&amp;lt;head&amp;gt;&lt;/code&gt; for duplicate canonicals. It's a 30-second check that might be costing you page one.&lt;/p&gt;

</description>
      <category>python</category>
      <category>seo</category>
      <category>webdev</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
