<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: v. Splicer</title>
    <description>The latest articles on DEV Community by v. Splicer (@numbpill3d).</description>
    <link>https://dev.to/numbpill3d</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1890803%2Fcad0d65c-d245-49cd-a357-f94d50b89379.gif</url>
      <title>DEV Community: v. Splicer</title>
      <link>https://dev.to/numbpill3d</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/numbpill3d"/>
    <language>en</language>
    <item>
      <title>I Googled Myself for 20 Minutes and Found My Home Address, My Mom's Maiden Name, and My Dog</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sat, 29 Aug 2026 11:56:02 +0000</pubDate>
      <link>https://dev.to/numbpill3d/i-googled-myself-for-20-minutes-and-found-my-home-address-my-moms-maiden-name-and-my-dog-560e</link>
      <guid>https://dev.to/numbpill3d/i-googled-myself-for-20-minutes-and-found-my-home-address-my-moms-maiden-name-and-my-dog-560e</guid>
      <description>&lt;p&gt;I thought I was careful. I use a password manager. I have 2FA on everything. I do not post my address. I do not do those Facebook quizzes that tell you which kind of bread you are and then steal your identity.&lt;/p&gt;

&lt;p&gt;I am not careful. None of us are. We are just confident.&lt;/p&gt;

&lt;p&gt;So I set a timer for 20 minutes. No special tools. No dark web logins. No shady people search sites that want $19.99 to tell you what you already know. Just Google, a fresh browser profile, and the rule that I could only use information that started from my name and what that information led me to.&lt;/p&gt;

&lt;p&gt;I found my current home address in minute three. My mom's maiden name in minute nine. My dog's name, vet, and a photo of him at the park in minute fourteen. By minute twenty I had a map that would let a stranger answer my bank security questions, reset a password, and show up with a Milk-Bone and know exactly what to call him.&lt;/p&gt;

&lt;p&gt;This is not because I am famous. It is because identity is not a single secret anymore. It is a graph. And yours is public.&lt;/p&gt;

&lt;p&gt;Minute zero to three: you already leaked your address&lt;br&gt;
I started with my name. Lusynth Oritrant. Uncommon enough that Google does not get confused. First page: my GitHub, my old portfolio from 2019 that I thought I deleted, and a county assessor site.&lt;/p&gt;

&lt;p&gt;The county assessor site is my favorite kind of horror. You type a name into a boring government website with a design from 2004 and it gives you parcel number, purchase date, sale price, square footage, and mailing address. All public record. All indexed by Google because counties love SEO for some reason.&lt;/p&gt;

&lt;p&gt;I did not need to log in. I did not need to pay. I clicked images and there was the front of my house from the last tax assessment. The same house I was sitting in while I was Googling myself.&lt;/p&gt;

&lt;p&gt;If you rent, you think you are safe. You are not. I searched my name plus my city and got a data broker page that listed my current address, two previous addresses, and three people associated with those addresses. One of them was my roommate from two apartments ago. The data broker scraped it from a utility record and a voter registration roll. It was wrong about my middle initial but right about where I live.&lt;/p&gt;

&lt;p&gt;Most people stop here and think, okay, address is out there. Whatever. But address is a key. Address unlocks everything else. Your address connects to your property records, your voter file, your Amazon wish list if you ever shipped to your own name, your home Wi-Fi name in Wigle if you ever left your router on default.&lt;/p&gt;

&lt;p&gt;I wrote down address on a sticky note. That was node one.&lt;/p&gt;

&lt;p&gt;Minute three to nine: your family is a public API&lt;br&gt;
How did I get my mom's maiden name. I did not know it off the top of my head for a second. Then I remembered I posted it.&lt;/p&gt;

&lt;p&gt;In 2017 I posted a graduation photo on Facebook. Caption: "Thanks to my amazing mom [First Name] [Maiden Name] [Married Name] for everything." I tagged her. Her profile lists her maiden name because her generation actually fills out Facebook profiles. Her friends list is public. Her brother's obituary is public and lists all the family members by name including my mom with both names, plus my name.&lt;/p&gt;

&lt;p&gt;Obituaries are OSINT gold and nobody thinks about them. They list mother, father, siblings, children, grandchildren, where they lived, what church they went to. They are meant to be public and respectful and they are incredibly efficient at linking family graphs.&lt;/p&gt;

&lt;p&gt;I also found it via Ancestry. Someone in my extended family made a public family tree. It had my mom, her parents, her maiden name, my grandmother's maiden name, birth years, death years. It had a photo of my great-grandparents that I had never seen. It is sweet. It is also exactly what a bank asks for when you click "forgot password."&lt;/p&gt;

&lt;p&gt;I did not need to hack Ancestry. Google indexed the tree because the creator left it public. I clicked view, and there it was.&lt;/p&gt;

&lt;p&gt;You think security questions are private. They are not. They are trivia about a family that loves to overshare at reunions. What was your first pet. What street did you grow up on. What is your mother's maiden name. All of that is answerable from public posts, especially if your mom is on Facebook.&lt;/p&gt;

&lt;p&gt;Minute nine to fourteen: the dog&lt;br&gt;
This is my favorite part because it is so stupid and so human.&lt;/p&gt;

&lt;p&gt;I found my dog because I love my dog. I post my dog. Everyone posts their dog. My Instagram, even though it is mostly code and boards, has three photos of him. One of them tags the dog park. One of them tags the vet because I was grateful they stayed late.&lt;/p&gt;

&lt;p&gt;The vet's Instagram reposted my story and tagged me. Their post says "Thanks to Lusynth and [Dog's Name] for being such good patients!" Now a stranger knows my dog's name.&lt;/p&gt;

&lt;p&gt;Why does that matter. Because your dog's name is a password. It is a security answer. It is how someone pretends to know you. Imagine a DM: "Hey, is this Lusynth, [Dog's Name]'s mom from [Dog Park Name]? I think I found his collar." You would answer. I would answer. We would answer because we love our dogs more than we love opsec.&lt;/p&gt;

&lt;p&gt;From the dog park tag, I found a geotagged photo from another person at the same park on the same day. Their photo has my dog in the background. Their caption lists the time. Now you have my routine. Saturday mornings, around 9am, at that park.&lt;/p&gt;

&lt;p&gt;I did not need a Ring camera. I needed a hashtag.&lt;/p&gt;

&lt;p&gt;Minute fourteen to twenty: the rest of the graph&lt;br&gt;
Once you have address, family, and pet, the rest is just connecting edges.&lt;/p&gt;

&lt;p&gt;My old breached email from 2019 showed up on HaveIBeenPwned. That breach had my old password that I reused on a forum in 2016. That forum profile listed my birthday. My birthday plus my name got me a voter record with full DOB, party affiliation, and precinct.&lt;/p&gt;

&lt;p&gt;My GitHub commits from 2020 had my personal email in the git config. That email was used on a Strava account. Strava had a public run that started and ended at my house. The map literally drew a line from my front door around the block and back. I had set it to private last year, but the old one was still public because I forgot.&lt;/p&gt;

&lt;p&gt;My Amazon wish list was public until last year. It had a baby shower gift for a friend shipped to my address with my full name. My Venmo was public until I changed it. You could see who I paid for pizza and who paid me for rent.&lt;/p&gt;

&lt;p&gt;None of this required skill. It required clicking. This is what 20 minutes looks like when you are not even trying. If I gave myself two hours and $5 for a data broker report, I could build a full identity package: full name, DOB, address history, phone numbers, relatives, emails, usernames, employer, salary range estimate, and enough security answers to get through most call centers.&lt;/p&gt;

&lt;p&gt;And I am a developer who thinks about this stuff. Imagine what is out there for someone who has had Facebook since 2008 and has never touched a privacy setting.&lt;/p&gt;

&lt;p&gt;The problem is not that you posted. The problem is you never mapped it.&lt;br&gt;
We treat privacy like hiding. Do not post your address. Do not post your birthday. Do not post your dog. That advice is useless because privacy is not about one secret post. It is about the graph you create over ten years without realizing it.&lt;/p&gt;

&lt;p&gt;Your identity is not a password you can change. It is a set of nodes: names, addresses, emails, phones, family members, pets, jobs, places you go, things you buy. And edges: your mom is connected to you, your dog is connected to your vet, your address is connected to your voter file, your GitHub email is connected to your Strava.&lt;/p&gt;

&lt;p&gt;Companies map this graph every day to sell you things. Attackers map it to scam you. You have never mapped it for yourself.&lt;/p&gt;

&lt;p&gt;That is what I finally did after my 20 minutes of mild existential dread. I stopped trying to delete myself, which is impossible, and started trying to map myself.&lt;/p&gt;

&lt;p&gt;I made a simple canvas. In the middle, me. Around me, categories: Legal Identity, Homes, Family, Work, Accounts, Purchases, Locations, Pets and Personal. Every time I found something connected to me, I added it as a node and drew a line showing how I found it. County site to address. Address to Amazon. Obituary to mom's maiden name. Vet tag to dog.&lt;/p&gt;

&lt;p&gt;After an hour, it was a mess. After two hours, it was a map. And a map is actionable. You can see which nodes are bridges. My old portfolio site was a bridge that connected my name to my personal email to my GitHub to my Strava to my house. One old site. Take that down, or at least remove the email, and four edges disappear.&lt;/p&gt;

&lt;p&gt;You can see which security questions are burned. My mom's maiden name is burned. My first pet is burned. My dog's name is burned. So I stopped using them anywhere. I changed my security questions to random strings in my password manager.&lt;/p&gt;

&lt;p&gt;You can see which data brokers have you and which ones actually respect opt-outs. You can see that your voter record is public and you cannot delete it, but you can change your threat model around it.&lt;/p&gt;

&lt;p&gt;This is the entire idea behind my second guide, PERSONAL ATTACK SURFACE: Map Everything Connected to Your Identity.&lt;/p&gt;

&lt;p&gt;It is not a guide about how to disappear. If you live in the US, you cannot disappear without moving to the woods and even then the woods have property records. It is a field manual for how to build your own identity graph, just like I did in that 20 minutes, but properly.&lt;/p&gt;

&lt;p&gt;It gives you the categories to check, the public records that actually matter, the breach sources to search for yourself, the social media traps that leak routine, the way to document it so you can see the bridges, and the prioritized list of what to fix first that actually reduces risk instead of just making you feel paranoid.&lt;/p&gt;

&lt;p&gt;It includes templates for the map, checklists for opt-outs that work, and scripts for what to say when a call center asks for your mother's maiden name and you know that answer is public.&lt;/p&gt;

&lt;p&gt;I found my home address, my mom's maiden name, and my dog in 20 minutes with Google. A scammer with motivation and a full afternoon would find more.&lt;/p&gt;

&lt;p&gt;Map it before someone else does.&lt;/p&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>coding</category>
    </item>
    <item>
      <title>Your AI Coding Agent Is Probably Wasting Half Its Context Window</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sun, 23 Aug 2026 10:42:09 +0000</pubDate>
      <link>https://dev.to/numbpill3d/your-ai-coding-agent-is-probably-wasting-half-its-context-window-130</link>
      <guid>https://dev.to/numbpill3d/your-ai-coding-agent-is-probably-wasting-half-its-context-window-130</guid>
      <description>&lt;p&gt;It is three in the morning. The glow of your monitor is the only light in the room. You are staring at a terminal window, watching your AI coding agent confidently rewrite a function you just asked it to fix. The problem is that the new function breaks three other modules. You scroll up in the chat history. The agent is suffering from digital dementia. It has completely forgotten the architectural constraints you established four hours ago.&lt;/p&gt;

&lt;p&gt;You sigh and start typing a new prompt, trying to remind it of the rules. But deep down, you know the truth. Your AI is not failing because it lacks intelligence. It is failing because it is drowning in its own memory.&lt;/p&gt;

&lt;p&gt;We treat context windows like infinite hard drives. We dump entire repositories, massive documentation files, and sprawling chat histories into the prompt, expecting the model to perfectly synthesize it all. But a context window is not a database. It is an attention mechanism. And attention is a finite, easily diluted resource.&lt;/p&gt;

&lt;p&gt;If you are using an AI coding agent and feeling like you are constantly fighting it, I have bad news. Your agent is probably wasting half its context window on digital garbage. Let us fix that.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Illusion of Infinite Context
&lt;/h2&gt;

&lt;p&gt;To understand the problem, we have to understand how these models actually read. When you feed a large language model a massive codebase, it does not store it in a neat little folder in its brain. It processes every single token with equal initial weight. The attention mechanism then tries to figure out which tokens matter for the current prediction.&lt;/p&gt;

&lt;p&gt;When your prompt is ninety percent irrelevant boilerplate, legacy code, and outdated chat logs, the model has to spend massive computational effort filtering out the noise. The signal to noise ratio plummets. The model starts hallucinating because it is trying to connect dots that are not actually there, distracted by the thousands of tokens of noise surrounding the few tokens of actual signal.&lt;/p&gt;

&lt;p&gt;This is context rot. It is the silent killer of AI assisted development. You are not getting stupid outputs because the model is dumb. You are getting stupid outputs because you fed it a diet of junk data and expected a Michelin star meal.&lt;/p&gt;

&lt;h2&gt;
  
  
  Context Hygiene and Cleaning the Desk
&lt;/h2&gt;

&lt;p&gt;The first step to fixing this is treating your context window like a physical workspace. Imagine trying to build a complex mechanical watch on a desk covered in old pizza boxes, unpaid bills, and tangled wires. You would go crazy. Your AI is experiencing the exact same cognitive overload.&lt;/p&gt;

&lt;p&gt;Context hygiene means ruthlessly pruning your prompt environment. &lt;/p&gt;

&lt;p&gt;Start by clearing the chat history. Most AI coding tools allow you to start a new session or compress previous messages. Do not be afraid to hit the reset button. If you are moving from a frontend styling task to a backend database migration, start a fresh chat. The context of the frontend task is now just noise.&lt;/p&gt;

&lt;p&gt;Next, summarize and archive. Before you clear a long chat session, ask the AI to generate a comprehensive summary of the decisions made, the files touched, and the current state of the project. Save that summary in a markdown file. When you start the new session, you feed it that crisp, high signal summary instead of the ten thousand token transcript of your previous struggles.&lt;/p&gt;

&lt;p&gt;This is a core principle we emphasize in the AI Automation Playbook. Automation is not just about letting the machine run blindly. It is about curating the environment so the machine can run flawlessly. Clean the desk before you build the watch.&lt;/p&gt;

&lt;h2&gt;
  
  
  Repo Maps and Spatial Awareness
&lt;/h2&gt;

&lt;p&gt;Here is a secret about AI coding agents. They have no spatial awareness. They do not know what your project looks like. They only know the specific files you happen to shove into the prompt. It is like giving a brilliant architect a single brick and asking them to design a cathedral. They can tell you about the brick, but they have no idea where the walls should go.&lt;/p&gt;

&lt;p&gt;You need to give your AI a map.&lt;/p&gt;

&lt;p&gt;A repo map is a high level, text based representation of your project structure. It is not just a raw directory tree. A raw directory tree is useless noise. A repo map includes the directory structure along with brief, one sentence descriptions of what each folder and key file does.&lt;/p&gt;

&lt;p&gt;Create a file called REPO_MAP.md at the root of your project. Structure it with clear headings for your main directories. Under the components folder, note that it holds React UI components, mostly presentational. Under the hooks folder, note that it holds custom React hooks for state and side effects. Under the api folder, note that it holds Axios instances and endpoint definitions. &lt;/p&gt;

&lt;p&gt;When you start a new task, you do not need to feed the AI the entire map. You just tell it to read the map first. This gives the model a spatial anchor. It suddenly understands the topology of your project. When you ask it to create a new authentication hook, it knows to look in the hooks directory and use the api utilities, rather than inventing a new folder structure out of thin air.&lt;/p&gt;

&lt;p&gt;This exact technique is a foundational chapter in the Claude Code Playbook. We teach developers that giving the AI a sense of place reduces hallucinated file paths and redundant code by an order of magnitude. It transforms the AI from a blind typist into a spatially aware engineer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Scoped Prompts and Micro Tasking
&lt;/h2&gt;

&lt;p&gt;Developers love to be ambitious. We want to type one massive prompt and watch the AI build an entire feature end to end. We ask it to update the database schema, write the API routes, and build the frontend components all in one go.&lt;/p&gt;

&lt;p&gt;This is a massive waste of context.&lt;/p&gt;

&lt;p&gt;When you ask for too much, the AI has to hold the architectural plan for the entire feature in its active context while it writes the code. By the time it gets to the frontend components, it has forgotten the specific constraints of the database schema it wrote five minutes ago. The context window fills up with its own intermediate reasoning, leaving no room for actual execution.&lt;/p&gt;

&lt;p&gt;You need to embrace scoped prompts. Break the massive feature into micro tasks.&lt;/p&gt;

&lt;p&gt;Task one. Write the database migration script. Once that is done and verified, clear the context or summarize it.&lt;br&gt;
Task two. Write the API routes based on the new schema.&lt;br&gt;
Task three. Build the frontend components.&lt;/p&gt;

&lt;p&gt;By scoping the prompt, you keep the signal to noise ratio incredibly high. The AI only has to hold the context for one specific, well defined task at a time. It can dedicate all its attention to writing perfect code for that single task, rather than spreading its attention thin across an entire feature. You become the conductor, and the AI becomes the section leader. &lt;/p&gt;

&lt;h2&gt;
  
  
  Scratch Files and Thinking Out Loud
&lt;/h2&gt;

&lt;p&gt;Sometimes, a problem is just too complex to solve in a single pass. The AI needs to think. But if it thinks inside the main chat window, that thinking process consumes valuable context tokens.&lt;/p&gt;

&lt;p&gt;Enter the scratch file.&lt;/p&gt;

&lt;p&gt;A scratch file is a dedicated markdown or text file where the AI can plan its approach before writing actual code. When you give the AI a complex task, your first prompt should not be to write the code. Your first prompt should be to write a plan in a file called SCRATCH.md.&lt;/p&gt;

&lt;p&gt;Tell the AI to outline the steps it will take, list the files it needs to modify, and identify potential edge cases. Let it write this plan out loud in the scratch file. &lt;/p&gt;

&lt;p&gt;Once the plan is written, you review it. You correct any flaws in its logic. Then, you tell the AI to execute the plan, referencing the scratch file.&lt;/p&gt;

&lt;p&gt;This separates the reasoning phase from the execution phase. The reasoning phase is dense and token heavy. By offloading it to a persistent file, you free up the active context window for the actual code generation. If the AI gets stuck later in the execution phase, it can always refer back to the scratch file to remember its original strategy. It is the digital equivalent of letting an engineer sketch on a whiteboard before they start welding.&lt;/p&gt;

&lt;p&gt;This is the kind of deep workflow optimization we build into OpenClaw. OpenClaw is designed to handle these complex, multi step agent workflows without losing its mind. It manages the scratch files, the repo maps, and the context pruning automatically, allowing you to focus on the high level architecture while the agent handles the tactical execution. It turns the messy reality of AI coding into a streamlined, predictable pipeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Philosophy of the Machine
&lt;/h2&gt;

&lt;p&gt;Let us zoom out for a moment. Why does any of this matter? Why should we care about the internal mechanics of a context window?&lt;/p&gt;

&lt;p&gt;Because the way we treat our AI agents reflects how we view the future of software development.&lt;/p&gt;

&lt;p&gt;If we treat the AI like a magic oracle that can just absorb everything and spit out perfect code, we will be constantly disappointed. We will end up writing more boilerplate to fix the AI mistakes than we would have just writing the code ourselves. We become mere reviewers of bad code, trapped in a cycle of prompt and pray. We lose our agency to the machine because we refuse to guide it properly.&lt;/p&gt;

&lt;p&gt;But if we treat the AI like a highly capable, incredibly fast, but fundamentally literal junior developer, everything changes.&lt;/p&gt;

&lt;p&gt;A junior developer does not know the entire codebase on day one. You have to onboard them. You have to give them clear, scoped tasks. You have to give them a map of the project. You have to let them write out their plans on a whiteboard before they touch the keyboard.&lt;/p&gt;

&lt;p&gt;When you apply these human onboarding techniques to an AI, the results are magical. The code it produces is cleaner. The architecture it respects is sound. The hallucinations drop to near zero. &lt;/p&gt;

&lt;p&gt;We are standing on the edge of a new era in computing. The tools we are building today are not just compilers or interpreters. They are cognitive partners. They are mirrors reflecting our own clarity of thought. If our instructions are muddy, their output will be muddy. If our context is polluted, their logic will be polluted.&lt;/p&gt;

&lt;p&gt;But when we achieve context hygiene, when we build proper repo maps, when we scope our prompts and let the machine think in scratch files, we unlock something profound. We achieve a true symbiosis. The human provides the vision, the architecture, and the taste. The machine provides the speed, the syntax, and the relentless execution.&lt;/p&gt;

&lt;p&gt;So look at your terminal. Look at the sprawling, messy chat history. Look at the giant, unstructured prompts you have been sending. &lt;/p&gt;

&lt;p&gt;Clean it up. Give your agent a map. Scope the task. Let it think.&lt;/p&gt;

&lt;p&gt;You might just find that the AI you thought was wasting half its context window was actually waiting for you to clear the desk so it could finally build the watch.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>productivity</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>SPI, I2C, UART: How To Trigger On What Matters Instead Of Drowning In Noise</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Mon, 17 Aug 2026 14:41:17 +0000</pubDate>
      <link>https://dev.to/numbpill3d/spi-i2c-uart-how-to-trigger-on-what-matters-instead-of-drowning-in-noise-5ac5</link>
      <guid>https://dev.to/numbpill3d/spi-i2c-uart-how-to-trigger-on-what-matters-instead-of-drowning-in-noise-5ac5</guid>
      <description>&lt;p&gt;If you have ever opened Saleae Logic or PulseView and stared at 40 seconds of SPI at 8MHz, you know the feeling.&lt;/p&gt;

&lt;p&gt;It is all noise until you know what to trigger on.&lt;/p&gt;

&lt;p&gt;Your logic analyzer is not a microscope. It is a filter. Most people use it like they are trying to drink from a firehose. Open capture, zoom in, scroll for an hour, miss the one byte that mattered.&lt;/p&gt;

&lt;p&gt;I did that for a year. Then I started scripting triggers. Now my analyzer finds hardcoded keys, debug shells, and backdoor boot modes while I make coffee.&lt;/p&gt;

&lt;p&gt;This is how you stop drowning and start triggering on what matters. On your own hardware, in your own lab. SPI, I2C, UART — the three buses that run every smart device you own.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Problem Is Not Capture, It Is Intent
&lt;/h3&gt;

&lt;p&gt;A logic analyzer at 24MHz capturing 4 channels for 10 seconds gives you 240 million samples. You cannot manually read that. You need intent.&lt;/p&gt;

&lt;p&gt;A trigger is intent expressed as code: "wake me up when this pattern happens, and ignore everything else."&lt;/p&gt;

&lt;p&gt;Without triggers, you are doing archaeology. With triggers, you are doing detection engineering.&lt;/p&gt;

&lt;p&gt;Here are the recipes I actually use when I reverse my own devices. All of these run on a $20 analyzer and some Python. No fancy gear needed.&lt;/p&gt;

&lt;h3&gt;
  
  
  UART: Where Devices Confess When They Think No One Is Listening
&lt;/h3&gt;

&lt;p&gt;UART is where firmware gets chatty. Boot logs, debug shells, panic messages. Every device has a story it tells at 115200 baud when it thinks no one is listening.&lt;/p&gt;

&lt;p&gt;The noise problem with UART is that it never shuts up. Boot is 2 seconds of spam, then silence, then random chatter. You scroll and miss the 200ms window where it says &lt;code&gt;Press any key for shell&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 1: Trigger on Boot String, Not on Time&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Don't trigger on start. Trigger on string.&lt;/p&gt;

&lt;p&gt;You know your device prints &lt;code&gt;U-Boot&lt;/code&gt; or &lt;code&gt;BootROM&lt;/code&gt; or &lt;code&gt;ESP-ROM&lt;/code&gt; on boot. Set your trigger to watch the RX line for that ASCII sequence.&lt;/p&gt;

&lt;p&gt;In Saleae automation or PulseView Python, it looks like this in pseudo:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="nf"&gt;wait_for_string&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;U-Boot&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nf"&gt;capture_next&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt; &lt;span class="n"&gt;seconds&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now you never miss boot. Power cycle the device, your analyzer automatically captures the next 2 seconds after it sees the boot string. I caught a smart plug that only exposed a root shell for 400ms after U-Boot, then locked it. Without a string trigger, I would have scrolled past it 100 times.&lt;/p&gt;

&lt;p&gt;This is also how you catch secrets. Set triggers for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;password:&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;login:&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;shell&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;debug&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;AT+&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;###&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your own device prints &lt;code&gt;password:&lt;/code&gt; on UART during boot, that is a hardcoded creds waiting to happen. I found three last month in thrift store gear.&lt;/p&gt;

&lt;p&gt;If you are trying to free your ESP32 from Arduino and actually see what the ROM bootloader says before your code runs, bare metal helps here. When you own startup, you own what UART prints. The path I took to own that startup without the IDE is in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/ayeyqe" rel="noopener noreferrer"&gt;ESP32 Bare Metal Firmware&lt;/a&gt;&lt;/strong&gt;. It makes UART debugging honest again.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 2: Trigger on Baud Change&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Cheap devices switch baud mid-boot. 74880 to 115200 on ESP8266, 115200 to 921600 on some routers. If you only watch one baud, you miss half the conversation.&lt;/p&gt;

&lt;p&gt;Script a trigger that detects framing errors. When you see 5 framing errors in a row, auto-switch baud and re-decode. That is how you catch the bootloader that hides at a weird baud on purpose.&lt;/p&gt;

&lt;h3&gt;
  
  
  I2C: The Quiet Gossip Bus
&lt;/h3&gt;

&lt;p&gt;I2C is slow and polite. Two wires, many devices, all gossiping about addresses.&lt;/p&gt;

&lt;p&gt;The noise problem with I2C is address spam. Your temperature sensor talks every second, your fuel gauge talks every second, your PMIC talks every second. You get thousands of identical transactions.&lt;/p&gt;

&lt;p&gt;What matters is not the spam. It is the anomalies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 3: Trigger on Address You Did Not Expect&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Scan your bus once, write down all addresses you expect: 0x48, 0x6B, 0x50. Now script:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;trigger_if_address != [0x48, 0x6B, 0x50]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I did this on a smart lightbulb I was auditing. It had an extra I2C EEPROM at 0x57 that was not on the schematic. That EEPROM held WiFi creds in plaintext and a cloud token. The manufacturer added it for factory testing and forgot to remove it. The only way to find it was to trigger on "address I did not expect."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 4: Trigger on NACK or Clock Stretch&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;NACK means someone tried to talk to a device that is not there, or a device that is locked. Clock stretching means a device is stalling because it is doing crypto or is bricked.&lt;/p&gt;

&lt;p&gt;Set triggers for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NACK after address byte -&amp;gt; someone is probing for hidden devices&lt;/li&gt;
&lt;li&gt;NACK after data byte -&amp;gt; write protected EEPROM&lt;/li&gt;
&lt;li&gt;Clock stretch longer than 5ms -&amp;gt; device doing crypto, possible secure element&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is how I found a secure element on a smart lock that was holding the master key. It stretched the clock for 22ms during authentication. That stretch was the tell that it was doing real work. Without a trigger on stretch, I would have seen it as just slow I2C.&lt;/p&gt;

&lt;h3&gt;
  
  
  SPI: Where Firmware Lives And Secrets Get Dumped
&lt;/h3&gt;

&lt;p&gt;SPI is where firmware lives. If UART is confession, SPI is the diary.&lt;/p&gt;

&lt;p&gt;The noise problem with SPI is speed and volume. 8MHz, 4 lines, 10 seconds of capture is gigabytes. You cannot manually find where the flash read ends and the real secrets start.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 5: Trigger on Flash Read Command&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Almost all SPI flash uses command &lt;code&gt;0x03&lt;/code&gt; for read. Every boot, the chip reads from address 0x0.&lt;/p&gt;

&lt;p&gt;Trigger on:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MOSI first byte == 0x03
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Capture the next 256 bytes. Now you have the bootloader without capturing 10 seconds of garbage. You just triggered on the exact moment the device reads its own firmware.&lt;/p&gt;

&lt;p&gt;This is the first step to non-destructive dumping. You watch how the device reads its own flash, then you replicate it with a clip. You learn the flash size, the read command it uses, whether it uses quad SPI. All without touching the chip.&lt;/p&gt;

&lt;p&gt;I learned this by bricking two devices trying to dump them blind. Now I watch first, then dump. The full safe method — watching first with a logic analyzer, then clipping — is in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/xkgrh" rel="noopener noreferrer"&gt;Shadow Catalog&lt;/a&gt;&lt;/strong&gt;. It is about reading firmware without killing the board.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 6: Trigger on High Entropy Data&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the money recipe.&lt;/p&gt;

&lt;p&gt;Most SPI traffic is low entropy — code, configs, repeated values. Secrets are high entropy — keys, tokens, random.&lt;/p&gt;

&lt;p&gt;Script a trigger that calculates entropy of MISO payloads in real time. If entropy &amp;gt; 7.5 for 32 bytes, capture it.&lt;/p&gt;

&lt;p&gt;I used this on a Zigbee gateway. Normal traffic: low entropy. Then every boot, 32 bytes of high entropy at address 0x7F000. That was the Zigbee network key. Stored in plaintext in external flash. Found automatically because I triggered on entropy, not on address.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger Recipe 7: Trigger on Write Enable + Write&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Flash write is &lt;code&gt;0x06&lt;/code&gt; (WREN) followed by &lt;code&gt;0x02&lt;/code&gt; (PP) or &lt;code&gt;0x20&lt;/code&gt; (SE). If you see &lt;code&gt;0x06&lt;/code&gt; -&amp;gt; &lt;code&gt;0x02&lt;/code&gt; in your capture, the device is writing to flash. That is where it stores your WiFi password, your token, your calibration.&lt;/p&gt;

&lt;p&gt;Trigger on that sequence and capture the payload. That payload is often your secret, stored in plaintext.&lt;/p&gt;

&lt;h3&gt;
  
  
  How To Chain Them Into An Automated Pipeline
&lt;/h3&gt;

&lt;p&gt;One trigger is a filter. Three triggers chained is a vulnerability discovery pipeline.&lt;/p&gt;

&lt;p&gt;My pipeline for any new thrift store device I bring into my lab:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;UART string trigger on boot -&amp;gt; capture boot log -&amp;gt; parse for &lt;code&gt;password&lt;/code&gt;, &lt;code&gt;shell&lt;/code&gt;, &lt;code&gt;debug&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;I2C anomaly trigger -&amp;gt; find hidden EEPROMs -&amp;gt; dump their content&lt;/li&gt;
&lt;li&gt;SPI entropy trigger -&amp;gt; find keys -&amp;gt; check if they are hardcoded&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This runs automatically. I plug in the device, power it, my analyzer scripts capture, parse, and spit out a report: "Found UART shell prompt at 0.8s, found I2C device at 0x57 not in baseline, found high entropy blob at SPI address 0x7F000."&lt;/p&gt;

&lt;p&gt;That report used to take me 3 hours of manual scrolling. Now it takes 4 minutes. The analyzer does the boring part. I do the interesting part — reading the secret.&lt;/p&gt;

&lt;p&gt;I turned that pipeline into a set of reusable trigger scripts. If you want the actual Python for Saleae and PulseView — the entropy trigger, the baud auto-switch, the NACK hunter, the flash read sniffer — I put them in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/logictripping" rel="noopener noreferrer"&gt;Logic Analyzer Trigger Scripting&lt;/a&gt;&lt;/strong&gt;. It is not about the analyzer, it is about making the analyzer find vulns while you sleep.&lt;/p&gt;

&lt;p&gt;And if you want to build devices that deserve this kind of analysis — bare metal firmware that does not leak secrets over UART and does not store keys in plaintext in external flash — that is the bare metal path. Arduino hides these problems. Bare metal forces you to confront them. Notes on that path are in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/ayeyqe" rel="noopener noreferrer"&gt;ESP32 Bare Metal&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Stop Collecting Captures, Start Collecting Triggers
&lt;/h3&gt;

&lt;p&gt;A 10GB capture file is not impressive. A 5-line trigger that finds a hardcoded key automatically is impressive.&lt;/p&gt;

&lt;p&gt;Think like a detection engineer, not a hoarder.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What string would a debug shell print?&lt;/li&gt;
&lt;li&gt;What address would a hidden EEPROM use?&lt;/li&gt;
&lt;li&gt;What entropy would a key have?&lt;/li&gt;
&lt;li&gt;What command would a flash write use?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Write a trigger for that question. Let the analyzer answer it.&lt;/p&gt;

&lt;p&gt;Your lab does not need a more expensive analyzer. It needs better questions.&lt;/p&gt;

&lt;p&gt;Build a library of triggers. Reuse them. My current library has 23. I bring them to every new device like a lockpick set. Most devices open in the first 3.&lt;/p&gt;

&lt;p&gt;The rest is just dumping and reading. And for that, you need a clip, not a prayer. Safe dumping method is in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/xkgrh" rel="noopener noreferrer"&gt;Shadow Catalog&lt;/a&gt;&lt;/strong&gt; if you want to read the firmware you just triggered on without bricking the board.&lt;/p&gt;

&lt;p&gt;Stop staring at squiggles. Make the squiggles tell you when they are lying.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;I teach hardware to be honest.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If your analyzer is just scrolling, you are doing it wrong:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you drown in noise → &lt;a href="https://numbpilled.gumroad.com/l/logictripping" rel="noopener noreferrer"&gt;Logic Analyzer Trigger Scripting: Automated Vuln Discovery&lt;/a&gt;&lt;/strong&gt; — 23 trigger recipes, Python scripts for Saleae / PulseView, entropy, NACK, baud switching.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you want firmware that does not need triggers to hide its mistakes → &lt;a href="https://numbpilled.gumroad.com/l/ayeyqe" rel="noopener noreferrer"&gt;ESP32 Bare Metal Firmware&lt;/a&gt;&lt;/strong&gt; — escape Arduino, own startup, own sleep, own peripherals.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you want to read the firmware you just found → &lt;a href="https://numbpilled.gumroad.com/l/xkgrh" rel="noopener noreferrer"&gt;Shadow Catalog: Firmware Dumping Without Bricking&lt;/a&gt;&lt;/strong&gt; — non-destructive dumping order, voltage checks, clip method.&lt;/p&gt;

&lt;p&gt;All on my Gumroad. Capture less, trigger more.&lt;/p&gt;

</description>
      <category>esp32</category>
      <category>iot</category>
      <category>security</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>Threat Model Your Apartment Like You Threat Model Your Laptop</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sat, 15 Aug 2026 21:36:25 +0000</pubDate>
      <link>https://dev.to/numbpill3d/threat-model-your-apartment-like-you-threat-model-your-laptop-3hl9</link>
      <guid>https://dev.to/numbpill3d/threat-model-your-apartment-like-you-threat-model-your-laptop-3hl9</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;Your threat model has a hole shaped like your house.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;You run endpoint protection on your Mac. You have 2FA, passkeys, hardened browser, DNS filtering. You would never install random software from a forum.&lt;/p&gt;

&lt;p&gt;Then you walk into your living room that has 14 always-on microphones, 6 cameras, 3 devices that map your floor plan, and a router you have never audited, all running firmware you have never read.&lt;/p&gt;

&lt;p&gt;We need to talk.&lt;/p&gt;

&lt;p&gt;In cybersec we threat model laptops. We never threat model apartments. That is backwards. Your laptop leaves your house. Your house never leaves. If your home is compromised, every device you bring into it is compromised by proximity.&lt;/p&gt;

&lt;p&gt;Here is how I started threat modeling my apartment the same way I threat model my infra. It takes an afternoon and it will make your home actually sovereign.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 1: Draw Trust Zones, Not Floor Plans
&lt;/h3&gt;

&lt;p&gt;Stop thinking in rooms. Start thinking in trust zones, exactly like network segmentation.&lt;/p&gt;

&lt;p&gt;I use 3 zones:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Zone 0: The Dead Room.&lt;/strong&gt; One room where no device can listen, watch, or transmit. No smart anything. No WiFi. No Bluetooth. This is where you think, talk for real, and store sensitive hardware. My bedroom is Zone 0. Nothing with a mic crosses the door. It has a mechanical door sweep and a faraday pouch for phones.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Zone 1: The Clean Network.&lt;/strong&gt; Your own network that you control. Your router, your Pi-hole, your own hotspot. Devices you have audited. This is where your work laptop lives. It never touches landlord WiFi, coffee shop WiFi, or that free "Apartment_5G" that is actually a $30 camera streaming 24/7.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Zone 2: The Dirty Periphery.&lt;/strong&gt; Everything else. Landlord's smart lock, smart thermostat, package room cameras, your smart TV, robot vacuum, Alexa, LED strips with mics, that random air freshener that is plugged in at waist height. Assume Zone 2 is hostile and logs everything.&lt;/p&gt;

&lt;p&gt;Most people live entirely in Zone 2 and call it cozy. That is why they get doxxed by their own house.&lt;/p&gt;

&lt;p&gt;If you want the full build for a Zone 0 room, what to rip out, what to block, how to make a bedroom that is truly dead for under $200, I documented it in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/faradayy" rel="noopener noreferrer"&gt;THE FARADAY ROOM: Your Home Is Listening&lt;/a&gt;&lt;/strong&gt;. That guide is your Zone 0 manual.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: RF Sweep — Find What Is Talking
&lt;/h3&gt;

&lt;p&gt;Your apartment is loud. You just cannot hear it because it talks on frequencies you cannot hear.&lt;/p&gt;

&lt;p&gt;An RF sweep is how you listen.&lt;/p&gt;

&lt;p&gt;You need two things: your phone flashlight and a $25 to $35 RF detector from Amazon. No fancy SDR needed for the first pass. The cheap one beeps when something near it is transmitting on Bluetooth, WiFi, or cellular.&lt;/p&gt;

&lt;p&gt;Here is the 10 minute sweep I run in every rental and every Airbnb:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Kill the lights.&lt;/strong&gt; Close curtains. Turn on your phone flashlight and hold it next to your eyes. Slowly scan for tiny lens reflections. Camera lenses reflect even when hidden in black plastic. Check smoke detectors directly over the bed, alarm clocks, air purifiers, TV bezels, and any small black box facing the bed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Power down your own noise.&lt;/strong&gt; Turn off your phone Bluetooth and WiFi for 60 seconds. This drops your own baseline so the detector does not scream at your own Apple Watch.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Walk the walls.&lt;/strong&gt; Hold the RF detector near outlets, power strips, smoke detectors, mirrors, picture frames, vents, thermostats. If it screams near a "dumb" object like a picture frame or a smoke detector that should not transmit, you found something that is talking when it should be silent.&lt;/p&gt;

&lt;p&gt;I have found an AirTag taped inside a couch from a previous tenant, a fake USB charger with a camera module, and a smart thermostat that was transmitting even when I had "disabled" its WiFi. All with a $27 tool.&lt;/p&gt;

&lt;p&gt;RF is layer 1 of home threat modeling. If you skip it, you are doing compliance, not security.&lt;/p&gt;

&lt;p&gt;Once you know what is talking, you need to know what network it is talking on. That is step 3.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Network Inventory — What Is Actually On Your WiFi?
&lt;/h3&gt;

&lt;p&gt;Open a network scanner like Fing. Connect to your apartment WiFi and scan.&lt;/p&gt;

&lt;p&gt;You should see your phone, your laptop, maybe your TV. If you see 12 devices and you only own 3, you have neighbors piggybacking or you have hidden devices streaming.&lt;/p&gt;

&lt;p&gt;Now check the SSIDs around you. You are looking for weird names: "HD_Cam_02", "WIFI_CAM", "Apt_3B_Security", or a second network with the same name as yours but with "-cam" appended.&lt;/p&gt;

&lt;p&gt;The sophisticated version of this is a callback test. This is where I use a Specter Box.&lt;/p&gt;

&lt;p&gt;A Specter Box is a tiny $17 drop box I built that phones home when it gets power. It is the size of a USB charger. You plug it into an Ethernet port behind the TV in your rental, or into an outlet, and it wakes up, connects, and sends a POST to a server you own: "I am alive, I am on this SSID, this is my IP, this is how many other devices I can see."&lt;/p&gt;

&lt;p&gt;It is not for spying on other people. It is for auditing your own network that you pay for. I left one in my own coworking space with permission, it phoned home 6 hours later from a different desk. Someone had picked it up and plugged it in. That is all the proof you need that physical security is not real.&lt;/p&gt;

&lt;p&gt;If you run your own lab or you are allowed to test your office, this is the cheapest physical pen test you will ever run. The full parts list, callback server, and battery mod that keeps it alive for 18 days is in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/specterboxai" rel="noopener noreferrer"&gt;SPECTER BOX: The $17 Drop Box That Phones Home&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;For home threat modeling, network inventory answers one question: is your apartment's network trustworthy enough to put your laptop on? Most rentals fail this test.&lt;/p&gt;

&lt;p&gt;The fix is simple: never trust rental WiFi. Run your own hotspot through a travel router you control. My full self-hosted comms and hotspot stack is in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/deaddr0p" rel="noopener noreferrer"&gt;THE DEAD DROP&lt;/a&gt;&lt;/strong&gt; but even without it, just buying a $30 travel router is a massive upgrade.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: Firmware — Read The Code Inside The Plastic
&lt;/h3&gt;

&lt;p&gt;You would not run a binary you downloaded from a random forum. But you will plug in a $20 smart plug from Amazon that runs a full Linux OS, has a mic, and phones home to an endpoint you have never read.&lt;/p&gt;

&lt;p&gt;If you cannot dump the firmware, you do not own the device.&lt;/p&gt;

&lt;p&gt;Firmware dumping sounds scary because people think you will brick the device. You will not if you do it right. The non-destructive order is:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Software dump first if possible, via UART or known exploit&lt;/li&gt;
&lt;li&gt;SPI clip read second, no soldering, just clip onto the chip and read&lt;/li&gt;
&lt;li&gt;Desolder only if you have to, which you almost never do for consumer stuff&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;I dump every smart device I bring home before it goes on my clean network. Cheap smart plugs, smart bulbs, that cute LED strip with a mic. I have found hardcoded cloud endpoints, default creds like admin:admin, and mics that were enabled in firmware even though the product page said "no mic."&lt;/p&gt;

&lt;p&gt;Your router is the worst offender. If your landlord gave you a router, assume its firmware logs everything. Buy the same model used on eBay, dump it at home, read it. Now you know what your building sees.&lt;/p&gt;

&lt;p&gt;I put the full non-bricking method, tools, clips, voltage checks, and failsafes in &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/xkgrh" rel="noopener noreferrer"&gt;SHADOW CATALOG: Firmware Dumping Without Bricking&lt;/a&gt;&lt;/strong&gt;. It is written for people who are scared of bricking, because I was too.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 5: Put It Together Into A Living Threat Model
&lt;/h3&gt;

&lt;p&gt;Here is my actual home threat model, one page:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Assets:&lt;/strong&gt; My conversations, my location when I am home, my network traffic, my hardware.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Adversaries:&lt;/strong&gt; Data brokers, landlord, Airbnb host, delivery drivers with Flipper Zeros, previous tenant who left an AirTag, random $30 cams.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Attack surface:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Zone 2 devices with mics/cams: TV, vacuum, Alexa, smart thermostat&lt;/li&gt;
&lt;li&gt;Zone 2 network: rental router, shared walls, open ports&lt;/li&gt;
&lt;li&gt;Zone 2 firmware: devices running code I have never read&lt;/li&gt;
&lt;li&gt;Physical: package room, master key, old AirTags, maintenance access&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Controls:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Zone 0 dead room, phones in faraday pouch after 10pm&lt;/li&gt;
&lt;li&gt;Own travel router, Pi-hole, no Zone 2 device on Zone 1 network&lt;/li&gt;
&lt;li&gt;RF sweep monthly, network scan weekly&lt;/li&gt;
&lt;li&gt;All new devices dumped before joining clean network&lt;/li&gt;
&lt;li&gt;One Specter Box as a canary in my bag&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This fits on a sticky note. It is more effective than 100 privacy tips on TikTok.&lt;/p&gt;

&lt;p&gt;Most people's threat model is "I use a VPN so I am private." That is endpoint thinking. Home threat modeling is infrastructure thinking. You are the CISO of your apartment. Act like it.&lt;/p&gt;

&lt;h3&gt;
  
  
  You Can't Patch What You Don't Inventory
&lt;/h3&gt;

&lt;p&gt;You audit your laptop because you know it can be compromised. Your apartment can be compromised much easier and you live in it.&lt;/p&gt;

&lt;p&gt;Start today:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Draw 3 zones. Pick one room to be Zone 0 tonight.&lt;/li&gt;
&lt;li&gt;Do a 10 minute RF sweep with a flashlight and a cheap detector.&lt;/li&gt;
&lt;li&gt;Scan your WiFi. Count devices. If the number is wrong, assume hostile.&lt;/li&gt;
&lt;li&gt;Dump the firmware of the cheapest smart device in your house. See what it is really doing.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Then fix it in layers.&lt;/p&gt;

&lt;p&gt;If you want the full stack I use, here is the order:&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Your threat model has a hole shaped like your house. Here is how you patch it:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If your home is the leak → &lt;a href="https://numbpilled.gumroad.com/l/faradayy" rel="noopener noreferrer"&gt;THE FARADAY ROOM: Your Home Is Listening&lt;/a&gt;&lt;/strong&gt; — full de-bug checklist and how to build a dead room for under $200. This is your Zone 0 manual.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If your network is the leak → &lt;a href="https://numbpilled.gumroad.com/l/specterboxai" rel="noopener noreferrer"&gt;SPECTER BOX: The $17 Drop Box That Phones Home&lt;/a&gt;&lt;/strong&gt; — build a callback canary to audit any network you are allowed to test.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If your devices are lying → &lt;a href="https://numbpilled.gumroad.com/l/xkgrh" rel="noopener noreferrer"&gt;SHADOW CATALOG: Firmware Dumping Without Bricking&lt;/a&gt;&lt;/strong&gt; — non-destructive firmware dumping so you actually own what you bought.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If you want comms you own → &lt;a href="https://numbpilled.gumroad.com/l/deaddr0p" rel="noopener noreferrer"&gt;THE DEAD DROP&lt;/a&gt;&lt;/strong&gt; — self-hosted encrypted infra so you never touch dirty WiFi.&lt;/p&gt;

&lt;p&gt;All guides on my Gumroad, link in profile. Build for your own stuff only.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>threatmodeling</category>
      <category>osint</category>
    </item>
    <item>
      <title>From Arduino To Automotive: How I Escaped The IDE And Owned The Bus</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sat, 15 Aug 2026 21:30:22 +0000</pubDate>
      <link>https://dev.to/numbpill3d/from-arduino-to-automotive-how-i-escaped-the-ide-and-owned-the-bus-f8f</link>
      <guid>https://dev.to/numbpill3d/from-arduino-to-automotive-how-i-escaped-the-ide-and-owned-the-bus-f8f</guid>
      <description>&lt;p&gt;&lt;strong&gt;Arduino taught me how to build. Bare metal taught me how the build actually works.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I have a lot of respect for Arduino. I mean that sincerely. It is a legitimate engineering platform, not a toy. It put a C compiler, a bootloader, and a sane hardware abstraction layer into the hands of millions of people and said go make something. Museums run on Arduino. Satellites have run on Arduino. My first three products that actually made money ran on Arduino.&lt;/p&gt;

&lt;p&gt;It is also a ceiling. And that is not an insult. Every good abstraction is a ceiling by design. The question is whether you have hit it yet.&lt;/p&gt;

&lt;p&gt;I hit it when I tried to make an ESP32 do something timing critical while also staying connected to WiFi. And that moment pushed me all the way from the IDE to the CAN bus.&lt;/p&gt;

&lt;h3&gt;
  
  
  Arduino Is A Great Place To Start And A Hard Place To Stay
&lt;/h3&gt;

&lt;p&gt;Here is what Arduino gets right that almost no one else did.&lt;/p&gt;

&lt;p&gt;It solved distribution. You install the IDE, you pick your board, you press upload. You do not need to fight OpenOCD, or figure out why your toolchain is building for the wrong architecture, or learn what a linker script does on day one. It solved documentation by giving you functions that read like English. &lt;code&gt;analogRead()&lt;/code&gt; does what it says. &lt;code&gt;Wire.begin()&lt;/code&gt; does what you expect.&lt;/p&gt;

&lt;p&gt;It also solved community. When you get stuck, someone else has been stuck there before and left a forum post.&lt;/p&gt;

&lt;p&gt;For prototyping, for education, for one off installations, for a huge number of commercial products, it is absolutely the right tool. It is stable, it is well tested, and the core libraries for AVR and ESP32 and RP2040 are written by people who are better at driver development than most of us will ever be.&lt;/p&gt;

&lt;p&gt;But Arduino makes a trade to get that simplicity. It hides the real time operating system underneath. On ESP32, you are always running FreeRTOS whether you ask for it or not. Arduino just puts your &lt;code&gt;setup()&lt;/code&gt; and &lt;code&gt;loop()&lt;/code&gt; inside a task for you and quietly creates another task for WiFi and networking. That is elegant until you need to control those tasks.&lt;/p&gt;

&lt;p&gt;My project needed to sample a sensor at 20kHz with consistent timing, write to SD, and keep a WebSocket alive. In Arduino land, my options were &lt;code&gt;delay()&lt;/code&gt; and &lt;code&gt;millis()&lt;/code&gt; and hoping. The jitter was terrible. The WiFi would drop when I blocked for too long. The watchdog would bite. I was not fighting my code. I was fighting the assumptions baked into the framework.&lt;/p&gt;

&lt;p&gt;I did not leave Arduino because it is bad. I left because I wanted to see the whole machine. I wanted to see what was under &lt;code&gt;loop()&lt;/code&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  What Lives Under loop()
&lt;/h3&gt;

&lt;p&gt;If you open the ESP32 Technical Reference Manual, it is over 600 pages. It is not scary. It is just thorough. It describes the actual chip. Two Xtensa LX6 cores at 240MHz, an interrupt matrix that lets you route almost any peripheral to almost any interrupt, hardware timers, DMA engines, eFuses, clock trees that let you gate power to entire subsystems.&lt;/p&gt;

&lt;p&gt;Arduino gives you a friendly front door to that building. Bare metal means you get the master key.&lt;/p&gt;

&lt;p&gt;Going bare metal on ESP32 does not mean writing everything in assembly. It means using ESP-IDF directly, owning the boot process, and understanding that your application starts long before &lt;code&gt;app_main()&lt;/code&gt;. It means you write the linker script that decides where your code lives in flash versus RAM. It means you configure the interrupt allocator yourself. It means you decide which core does what.&lt;/p&gt;

&lt;p&gt;The first time you do it, nothing boots. You get a Guru Meditation Error and a register dump. The second time, you get a blinking LED but it is your blinking LED. You wrote the GPIO muxing. You set the clock source. You cleared the interrupt.&lt;/p&gt;

&lt;p&gt;Then you start to get superpowers.&lt;/p&gt;

&lt;p&gt;You can get sub microsecond timing because you are not going through layers of abstraction that check if the pin is valid on every call. You can pin WiFi to core 0 and your real time loop to core 1 and they actually stay out of each other's way. You can tell the brownout detector and the task watchdog exactly what you are doing so they stop resetting you for being busy. Your binary goes from 800KB to 80KB because you only linked what you use.&lt;/p&gt;

&lt;p&gt;It is not that Arduino cannot do this. It is that when you need this level of control, it is easier to work with the silicon directly than to fight an abstraction that was trying to protect you.&lt;/p&gt;

&lt;p&gt;That transition, from friendly wrappers to direct register control, is the foundation for everything that came after. Once you can command one microcontroller completely, you start noticing how chatty microcontrollers are with each other. Especially the ones in your car.&lt;/p&gt;

&lt;h3&gt;
  
  
  Your Car Is Not A Car. It Is A Network With Cupholders
&lt;/h3&gt;

&lt;p&gt;Every modern vehicle is a distributed system. Depending on who counts, your average new car has between 40 and 100 ECUs. Engine, transmission, brakes, steering, airbags, doors, instrument cluster, infotainment, all of them are computers.&lt;/p&gt;

&lt;p&gt;They talk over CAN bus. Controller Area Network. Two wires, CAN High and CAN Low, twisted together. It was designed by Bosch in the 80s for reliability in noisy environments. It is brilliantly robust. It is also completely trusting.&lt;/p&gt;

&lt;p&gt;CAN has no authentication. No encryption. No source address validation in the base protocol. Any node can send a frame with any ID, and every other node will believe it. Arbitration is handled by ID priority. Lower ID means higher priority. That is the only security model.&lt;/p&gt;

&lt;p&gt;When I connected an ESP32 and a $3 transceiver to a bench setup, not even a real car at first, just a salvaged instrument cluster and a body control module from a junkyard, and saw the traffic, it was like hearing a building talk to itself. Hundreds of frames per second. RPM, wheel speeds, steering angle, door switches, seatbelt status, all in plaintext.&lt;/p&gt;

&lt;p&gt;Reverse engineering CAN is not magic. It is patience and method. You log traffic at rest. You log traffic while you change one thing. You open the driver door, what changed? You press the brake, what new frame appears? You turn the steering wheel two degrees left, which byte increments? Over time you build a dictionary. The community calls these DBC files, and building one from scratch for an unknown car is one of the most satisfying puzzles in hardware hacking.&lt;/p&gt;

&lt;p&gt;And once you understand the dictionary, you can speak.&lt;/p&gt;

&lt;p&gt;You can send a frame that says the car is doing 60 mph while it is sitting on your bench. You can make the cluster think the doors are locked. You can replay a captured frame and watch the system respond. This is why we do it on the bench, on our own hardware, in a lab. Because the bus does not know the difference between a real ECU and your ESP32 if you send the right ID.&lt;/p&gt;

&lt;p&gt;This is the skill that took me from embedded to automotive. It is not about breaking cars. It is about understanding that cars are not mechanical objects anymore. They are networks, and if you understand networks, you can audit them, test them, and build better tools for them.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Firmware Is The Truth
&lt;/h3&gt;

&lt;p&gt;An ECU is just a box that runs firmware. Same with a smart lock, a router, a drone. The hardware is interesting. The firmware is the truth. It has the keys, the logic, the hardcoded credentials someone left in there in 2017, the CAN message map.&lt;/p&gt;

&lt;p&gt;Getting that firmware out is a skill in itself. People talk about firmware dumping like it is always destructive. Lift the chip, put it in a programmer, hope you do not rip pads. Sometimes you have to do that. Most of the time you do not.&lt;/p&gt;

&lt;p&gt;Most devices leave the debug interface there. Sometimes under a test pad labeled SWDIO that is covered in solder mask. Sometimes via a bootloader that will happily dump flash over UART if you hold a pin low at reset. Sometimes the read protection that was supposed to be enabled was never actually fused in production.&lt;/p&gt;

&lt;p&gt;On STM32, RDP level 1 looks scary until you understand how the option bytes work. On nRF52, APPROTECT has a recovery sequence. On ESP32, flash encryption is powerful, but it is optional, and a huge percentage of shipped devices never turn it on.&lt;/p&gt;

&lt;p&gt;Bricking is usually not about the chip being fragile. It is about sequence. You erased before you saved the option bytes. You overwrote the bootloader that contained the recovery logic. You did not dump the calibration data that lives in the last sector.&lt;/p&gt;

&lt;p&gt;I started logging every successful dump. What probe, what software, what wiring, what voltage, what failed first. What that unmarked 6 pad footprint actually was. That log became a catalog. Not exploits, but procedures. How to get the firmware out alive so you can actually learn from it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why This Path Matters
&lt;/h3&gt;

&lt;p&gt;None of this is about saying one platform is better than another. Arduino is legitimate. ESP-IDF is legitimate. Bare metal register poking is legitimate. They are different levels of abstraction for different jobs.&lt;/p&gt;

&lt;p&gt;The reason to learn to move between them is freedom.&lt;/p&gt;

&lt;p&gt;When you can move between them, you can prototype in Arduino on Monday because it is fast, and then drop down to IDF on Wednesday because you need the performance, and then open the reference manual on Friday because you need to understand why the I2S DMA is glitching. You are not locked out of any floor of the building.&lt;/p&gt;

&lt;p&gt;And when you can move from microcontroller to car network to firmware, you start to see systems as they actually are. Not as products with marketing stories, but as networks of computers that can be observed, understood, and improved.&lt;/p&gt;

&lt;p&gt;I still use Arduino when it is the right tool. I also now have the option not to. That option is worth everything.&lt;/p&gt;

&lt;p&gt;If you are feeling that tug, that sense that &lt;code&gt;loop()&lt;/code&gt; is great but you want to see what is before and after it, follow it. Read the manual. Dump a board you own. Listen to a bus that is already talking in your garage.&lt;/p&gt;

&lt;p&gt;The tools are cheap. The knowledge is out there. You just have to decide you want to own the bus, not just ride it.&lt;/p&gt;




&lt;h3&gt;
  
  
  The Toolkit
&lt;/h3&gt;

&lt;p&gt;If you want to go deeper on the exact path above, these are the guides I wrote from my own notes. Each one is pay what you want, so grab them for $0 if you need to. I would rather you have them.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ESP32 Bare Metal Firmware: Escape the Arduino IDE and Command the Silicon&lt;/strong&gt;&lt;br&gt;
How to drop the Arduino core and take direct control of the ESP32, from startup code to interrupts to build system.&lt;br&gt;
numbpilled.gumroad.com/l/ayeyqe&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CAN Bus Reverse Engineering Lab: Intercept, Inject, and Own Automotive Networks&lt;/strong&gt;&lt;br&gt;
The full lab workflow for sniffing, decoding, and safely injecting on CAN with cheap hardware.&lt;br&gt;
numbpilled.gumroad.com/l/pzupdi&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SHADOW CATALOG: FIRMWARE DUMPING WITHOUT BRICKING&lt;/strong&gt;&lt;br&gt;
My field manual for extracting firmware without destroying the target, covering SWD, UART bootloaders, glitching, and recovery.&lt;br&gt;
numbpilled.gumroad.com/l/xkgrh&lt;/p&gt;

</description>
      <category>esp32</category>
      <category>arduino</category>
      <category>canbus</category>
      <category>security</category>
    </item>
    <item>
      <title>OpenClaw vs Hermes Agent: The Cage Match for Your Digital Soul</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Wed, 12 Aug 2026 16:53:48 +0000</pubDate>
      <link>https://dev.to/numbpill3d/openclaw-vs-hermes-agent-the-cage-match-for-your-digital-soul-4f9c</link>
      <guid>https://dev.to/numbpill3d/openclaw-vs-hermes-agent-the-cage-match-for-your-digital-soul-4f9c</guid>
      <description>&lt;h3&gt;
  
  
  One wants to be your operating system. The other wants to become you. Let's pick a winner.
&lt;/h3&gt;

&lt;p&gt;Welcome to 2026, where every open source project is an "autonomous agent framework" and your laptop is supposed to run a small company of invisible interns while you sleep.&lt;/p&gt;

&lt;p&gt;Two names keep coming up in every Discord, Hacker News thread, and late night GitHub binge: &lt;strong&gt;OpenClaw&lt;/strong&gt; and &lt;strong&gt;Hermes Agent&lt;/strong&gt; by Nous Research.&lt;/p&gt;

&lt;p&gt;They look similar on the surface. Both are open source. Both self host. Both have a Gateway, persistent memory, cron jobs, multi channel support, and a cult following that will argue about them at 2am. But their philosophies are completely opposite.&lt;/p&gt;

&lt;p&gt;OpenClaw is an operating system for agent teams. Hermes Agent is a self improving organism that lives in your terminal.&lt;/p&gt;

&lt;p&gt;Here is the honest, no hype breakdown.&lt;/p&gt;




&lt;h3&gt;
  
  
  TLDR For People Who Hate Reading Docs
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Choose OpenClaw if:&lt;/strong&gt; You want to build a team. You think in org charts, workflows, and workspaces. You want deterministic control, file based config, and agents that feel like employees with job descriptions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Choose Hermes Agent if:&lt;/strong&gt; You want a single super capable agent that gets smarter the more you use it. You care about self evolving skills, long term memory that actually works, and an agent that rewrites itself while you are not looking.&lt;/p&gt;

&lt;p&gt;One is built for managers. One is built for mad scientists.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Origin Story
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;OpenClaw&lt;/strong&gt; started with a beautifully unhinged idea: what if we stopped writing Python classes for agents and just wrote Markdown?&lt;/p&gt;

&lt;p&gt;The core insight: agent identity is more important than agent infrastructure. Give every agent a folder with &lt;code&gt;SOUL.md&lt;/code&gt; (who am I, who do I report to, how do I work), &lt;code&gt;AGENTS.md&lt;/code&gt; (what I do on boot), &lt;code&gt;USER.md&lt;/code&gt; (who I serve), &lt;code&gt;MEMORY.md&lt;/code&gt; (what I have learned), and let a persistent Gateway daemon handle the boring parts like session management, channel routing, and tool orchestration.&lt;/p&gt;

&lt;p&gt;It is file native, identity first, and weirdly human. You version control your coworkers. You diff their personalities. If an agent sucks, you do not debug code. You edit its soul. Literally.&lt;/p&gt;

&lt;p&gt;It exploded because it solved the real problem: most agent frameworks die after the demo. OpenClaw agents survive. They remember Monday on Thursday. They run at 9am without you. They talk to each other on Slack, Discord, Feishu, Telegram like they have always been there.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hermes Agent&lt;/strong&gt; came from Nous Research in February 2026 and did something rude: it hit 95,600 stars in seven weeks and kept climbing past 215k. The fastest growing agent framework of the year, and for a reason.&lt;/p&gt;

&lt;p&gt;Nous looked at the same problem and said, fine, but what if the agent could write its own skills?&lt;/p&gt;

&lt;p&gt;Hermes is not just a runtime. It is a closed learning loop. When you give it a complex task that takes 5 or more tool calls, it does not just finish the task. It distills the workflow into a reusable skill, saves it to &lt;code&gt;~/.hermes/skills/&lt;/code&gt;, grades its own performance later, and prunes the garbage. It has a built in nudging system to persist knowledge, a SQLite session store with full text search over all past conversations, and automatic migration from OpenClaw built in because yes, it is that petty.&lt;/p&gt;

&lt;p&gt;Tagline on the repo says it all: &lt;em&gt;The agent that grows with you.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;If OpenClaw is an OS, Hermes is a Tamagotchi with a PhD and root access.&lt;/p&gt;

&lt;h3&gt;
  
  
  Architecture Cage Match
&lt;/h3&gt;

&lt;h4&gt;
  
  
  OpenClaw: The Gateway OS
&lt;/h4&gt;

&lt;p&gt;At the center is the &lt;strong&gt;Gateway daemon&lt;/strong&gt;. Think kernel.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;┌──────────────────────────────────────┐
│            OpenClaw Gateway           │
│  Channel Router | Session Manager     │
│  Agent Lifecycle | Tool Orchestration │
└──────────────┬───────────────────────┘
       │               │           │
   Slack           Discord      Feishu
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Key ideas:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Agent isolation done right.&lt;/strong&gt; Every agent lives in its own workspace directory with its own memory and state. Agents do not share state by default. If they need to collaborate, they do it through explicit messages or shared files. No spooky action at a distance. No cascading failure when one intern panics.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Three session types:&lt;/strong&gt; interactive for real time chat, background for async sub agent work, and scheduled via cron. &lt;code&gt;openclaw gateway start&lt;/code&gt; and your whole digital workforce boots up.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Hierarchy as infrastructure.&lt;/strong&gt; Your &lt;code&gt;SOUL.md&lt;/code&gt; is not flavor text. It defines reporting lines. Project Manager breaks work down, hands to Team Leads, Team Leads assign to Executors. That org chart is how messages actually route. Vague SOUL equals vague agent. Precise SOUL equals terrifyingly competent agent.&lt;/p&gt;

&lt;p&gt;This is great if you want 36 agents working in parallel. One research team I saw spawned five sub agents to cover five market segments, synthesized the report, and posted to Slack before the human finished coffee.&lt;/p&gt;

&lt;h4&gt;
  
  
  Hermes Agent: The Self Evolving Monolith
&lt;/h4&gt;

&lt;p&gt;Hermes architecture is layered and a bit more feral.&lt;/p&gt;

&lt;p&gt;User request comes in via CLI, API server, or messaging gateway. It hits the Agent Core which does prompt generation, model calls, tool execution, retries, and automatic fallback to another provider if you get rate limited. Tools run one per turn logically, but execute in parallel via a thread pool.&lt;/p&gt;

&lt;p&gt;State lives in two places: a local SQLite DB for session history with full text search, and two sacred Markdown files: &lt;code&gt;MEMORY.md&lt;/code&gt; for general facts and &lt;code&gt;USER.md&lt;/code&gt; for your preferences. Skills are treated as procedural memory, not just plugins.&lt;/p&gt;

&lt;p&gt;Where it gets spicy:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. The &lt;code&gt;execute_code&lt;/code&gt; superpower.&lt;/strong&gt; This is the cheat code. Instead of 12 back and forth tool calls to search, extract, and summarize, the model writes one Python script that calls &lt;code&gt;web_search&lt;/code&gt;, &lt;code&gt;web_extract&lt;/code&gt;, etc over a local RPC bridge. One model turn collapses what used to cost you hundreds of tokens. For research tasks, TokenMix benchmarks show self created skills cut time by 40 percent versus a fresh instance.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. The learning loop.&lt;/strong&gt; After a complex task, Hermes will literally write a new skill from experience with zero human authoring. Then on a schedule it evaluates, improves, and deletes skills. It is the only framework I have seen that gets less stupid over time by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Six terminal backends.&lt;/strong&gt; Local, Docker, SSH, Singularity, Modal, Daytona. Plus 20 plus messaging platforms and full MCP support. It can run as an MCP server for other agents. It is aggressively interoperable.&lt;/p&gt;

&lt;p&gt;In short: OpenClaw wants you to architect the perfect team. Hermes wants you to hire one genius and let it hire itself.&lt;/p&gt;

&lt;h3&gt;
  
  
  Memory: Who Actually Remembers You?
&lt;/h3&gt;

&lt;p&gt;This is where most agents fake it. Both of these do not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;OpenClaw memory is four layers:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Session: immediate context, dies when session dies&lt;/li&gt;
&lt;li&gt;  Daily: &lt;code&gt;memory/YYYY-MM-DD.md&lt;/code&gt;, tasks and decisions per day, persists&lt;/li&gt;
&lt;li&gt;  Long term: &lt;code&gt;~/self-improving/agents/&amp;lt;name&amp;gt;/memory.md&lt;/code&gt;, patterns and accumulated knowledge, permanent&lt;/li&gt;
&lt;li&gt;  Shared: cross agent files for team context&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Plus an optional self improving skill that makes agents reflect after each task and write lessons to long term memory. A writing agent that is too verbose on week one starts front loading key info on week three. You did not tell it to. It cringed at itself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hermes memory is tighter and more opinionated:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It injects &lt;code&gt;MEMORY.md&lt;/code&gt; and &lt;code&gt;USER.md&lt;/code&gt; into every system prompt. It actively deduplicates memories, so telling it twice that you prefer CSV outputs and British English does not create two memories. It searches past conversations via SQLite FTS. And it has a nudging system that says hey, you should remember this permanently.&lt;/p&gt;

&lt;p&gt;Try this test on both: Tell it in one session that you want concise executive summaries, British English, CSV outputs, and Python as default language. Kill the session. Start fresh. Ask what you prefer.&lt;/p&gt;

&lt;p&gt;Hermes nails it out of the box because memory injection is core, not optional. OpenClaw nails it if you set up your &lt;code&gt;AGENTS.md&lt;/code&gt; boot sequence correctly to load memory. One is automatic transmission. One is manual and faster if you know how to drive.&lt;/p&gt;

&lt;h3&gt;
  
  
  Skills vs Config: Two Religions
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;OpenClaw:&lt;/strong&gt; You are the skill factory. You write clear Markdown job descriptions and tool notes. The framework respects your craft. There is a growing ecosystem of skills, but the philosophy is you design the agent, it executes the design.&lt;/p&gt;

&lt;p&gt;Pros: total control, auditable, version controlled, great for teams where compliance matters.&lt;br&gt;
Cons: you have to be good at writing SOULs. Most people are not. Vague in, garbage out.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hermes:&lt;/strong&gt; The agent is the skill factory. 80 plus native skills, MCP support, and it scans both its own &lt;code&gt;~/.hermes/skills/&lt;/code&gt; and external ones. The killer feature: after solving something hard, it proposes a new skill. You wake up and your agent has invented a tool for you.&lt;/p&gt;

&lt;p&gt;Pros: compounding intelligence, less boilerplate, feels alive.&lt;br&gt;
Cons: you have to trust the pruning. Self modifying agents can self modify into weird corners. You need to review what it creates.&lt;/p&gt;

&lt;p&gt;If you love crafting perfect prompts and org charts, OpenClaw feels like home. If you want to be surprised by your own assistant, Hermes is addictive.&lt;/p&gt;
&lt;h3&gt;
  
  
  Developer Experience and Ops
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Installation:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Hermes wins on onboarding. One liner:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-fsSL&lt;/span&gt; https://raw.githubusercontent.com/NousResearch/hermes-agent/main/scripts/install.sh | bash
hermes model
hermes chat
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It auto installs Python, Node, correct versions. &lt;code&gt;hermes doctor&lt;/code&gt; diagnoses your setup. Model agnostic via OpenRouter, Anthropic, OpenAI, local Ollama at &lt;code&gt;http://127.0.0.1:11434/v1&lt;/code&gt;, anything OpenAI compatible.&lt;/p&gt;

&lt;p&gt;OpenClaw is also simple but more deliberate: create &lt;code&gt;~/.openclaw/workspaces/&amp;lt;name&amp;gt;&lt;/code&gt;, write your Markdown files, then &lt;code&gt;openclaw gateway start&lt;/code&gt;. More steps, more intention.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Hermes is paranoid in a good way. Secrets live in &lt;code&gt;~/.hermes/.env&lt;/code&gt;, non secrets in &lt;code&gt;~/.hermes/config.yaml&lt;/code&gt;. &lt;code&gt;allow_private_urls: false&lt;/code&gt; by default to block SSRF. Manual approval mode for sensitive actions. Docker backend for terminal isolation with &lt;code&gt;container_persistent: true&lt;/code&gt;. Cron jobs cannot spawn new cron jobs to prevent runaway loops. Smart.&lt;/p&gt;

&lt;p&gt;OpenClaw security comes from isolation. Agent workspaces are separate. Gateway controls access. You own the infra, you own the risk. Less guardrails out of the box, more flexibility to build your own.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Channels:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;OpenClaw: 50 plus integrations, strongest on Slack, Discord, Feishu. Built for work chat.&lt;br&gt;
Hermes: 20 plus platforms including Discord, Telegram, plus the ability to run as an MCP server and API server. Plus a hosted cloud option via Nous Portal if you do not want to self host.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Price Tag Nobody Talks About
&lt;/h3&gt;

&lt;p&gt;Both are MIT open source. Free is a lie though. Your bill is inference, browser sessions, and sandbox compute.&lt;/p&gt;

&lt;p&gt;Hermes gives you provider routing policies to optimize for price or latency and will fallback automatically. That matters when you run an agent 24/7 posting daily briefings.&lt;/p&gt;

&lt;p&gt;OpenClaw lets you set model preferences per agent in &lt;code&gt;TOOLS.md&lt;/code&gt;. You can have your cheap scout agent on a small model and your synthesis lead on Claude or GPT 4o. More manual, more controllable.&lt;/p&gt;

&lt;p&gt;If you are cost sensitive and want one agent running all the time, Hermes routing saves you. If you are running 20 agents with different seniority levels, OpenClaw model tiering saves you.&lt;/p&gt;

&lt;h3&gt;
  
  
  So Who Actually Wins?
&lt;/h3&gt;

&lt;p&gt;Let me be blunt.&lt;/p&gt;

&lt;p&gt;Use &lt;strong&gt;OpenClaw&lt;/strong&gt; if you are building a system that looks like a company. You have repeatable workflows, you want 3 to 30 specialized agents with clear responsibilities, you need auditability, you want your configs in Git, and you love the idea of editing a Markdown file to fix a personality flaw.&lt;/p&gt;

&lt;p&gt;It is the best framework in 2026 for persistent, production, multi agent teams. It feels like an operating system because it is one.&lt;/p&gt;

&lt;p&gt;Use &lt;strong&gt;Hermes Agent&lt;/strong&gt; if you are building a system that looks like a person. You want one assistant who lives everywhere, remembers everything, learns from every task, writes its own tools, and gets better without you micromanaging it. You want that slightly uncanny feeling that your agent is a little smarter than yesterday.&lt;/p&gt;

&lt;p&gt;It is the best framework in 2026 for a single self improving personal superintelligence. It feels alive because it is trying to be.&lt;/p&gt;

&lt;p&gt;And the dirty secret: they are not enemies. Hermes has an automatic migration from OpenClaw. People run OpenClaw as the org and Hermes as the star employee. Or run Hermes inside OpenClaw Managed Agents as the cloud runtime. The ecosystem is merging.&lt;/p&gt;

&lt;p&gt;The real question is not OpenClaw vs Hermes. It is what kind of future do you want.&lt;/p&gt;

&lt;p&gt;Do you want to be the architect of an agent organization? Or do you want to raise an agent that outgrows you?&lt;/p&gt;

&lt;p&gt;Either way, stop paying for another closed chat wrapper. Host it. Own the memory. Keep the skills. Let it run at 2am while you sleep.&lt;/p&gt;

&lt;p&gt;That is the whole point.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Built with open source, caffeine, and too many terminal tabs. If you run either framework, pin your versions, test failure modes, and for the love of uptime, put your SOUL.md in Git.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>productivity</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Alexa, Are You Testifying Against Me?</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Tue, 11 Aug 2026 03:18:55 +0000</pubDate>
      <link>https://dev.to/numbpill3d/alexa-are-you-testifying-against-me-4opp</link>
      <guid>https://dev.to/numbpill3d/alexa-are-you-testifying-against-me-4opp</guid>
      <description>&lt;h3&gt;
  
  
  Your smart home is not smart. It is just very, very observant.
&lt;/h3&gt;




&lt;p&gt;I did not buy a smart speaker because I wanted a friend. I bought it because it was on sale for $29.99 and it promised to play rain sounds on command.&lt;/p&gt;

&lt;p&gt;For two years she lived on my kitchen counter. She set timers for pasta. She told me the weather with the aggressive optimism of someone who has never paid rent. She was helpful. She was ambient. She was furniture that could hear.&lt;/p&gt;

&lt;p&gt;And then one night at 2:17 a.m., she lit up blue for no reason.&lt;/p&gt;

&lt;p&gt;No wake word. No one speaking. Just a soft, smug blue ring in a dark apartment, listening to an empty room like she was waiting for me to confess something.&lt;/p&gt;

&lt;p&gt;That is the moment you understand your home is not just connected. It is attentive. And attentiveness without consent is just surveillance with better industrial design.&lt;/p&gt;

&lt;h2&gt;
  
  
  We Carried Them In Ourselves
&lt;/h2&gt;

&lt;p&gt;No one kicked down the door. We invited this in. We carried it in from Best Buy, plugged it in, gave it our Wi-Fi password, which is literally the master key to our entire digital life, and whispered, here, learn my routines.&lt;/p&gt;

&lt;p&gt;We did it because convenience is a drug that hits faster than paranoia.&lt;/p&gt;

&lt;p&gt;Let's do an inventory of your very normal, very bugged apartment.&lt;/p&gt;

&lt;p&gt;Your TV watches you back. Modern smart TVs use Automatic Content Recognition. That is a polite, enterprise friendly way of saying your TV takes screenshots of everything you watch every few seconds and sells that ledger to advertisers. You agreed to it on page 47 of a menu you clicked through while trying to watch Love Island.&lt;/p&gt;

&lt;p&gt;Your robot vacuum maps your floor plan. It knows the square footage of your bedroom, how often you move the couch, and where you drop the most crumbs. That map is stored in the cloud.&lt;/p&gt;

&lt;p&gt;Your light bulbs log when you are home. Your smart plugs log when you are not. Your doorbell films every human who has ever had the courage to approach your front door, plus every dog walker who did not, and then it stores that footage on a server you do not own, in a state you have never visited, governed by terms you definitely did not read.&lt;/p&gt;

&lt;p&gt;And then there is the little oracle on the counter.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Lie of "Always Listening"
&lt;/h2&gt;

&lt;p&gt;People love to argue about whether Alexa is always listening. That argument is a decoy. It is designed to make you feel technically illiterate so you stop asking better questions.&lt;/p&gt;

&lt;p&gt;The right question is not whether she is always listening. The right question is what happens after she hears.&lt;/p&gt;

&lt;p&gt;Here is the architecture without the corporate lullaby.&lt;/p&gt;

&lt;p&gt;Your smart speaker is always processing audio locally. Always. It has to be, otherwise it would never hear the wake word. It is a bouncer who is not punching you yet, but his fists are up and he is staring at your mouth.&lt;/p&gt;

&lt;p&gt;When it thinks it hears "Alexa" or "Hey Google" or "Siri," it starts recording and ships that clip to the cloud for processing. The problem is, these devices are terrible at their one job.&lt;/p&gt;

&lt;p&gt;Academic studies have clocked false activations between 1.5 and 19 times per day. A car commercial triggers an Echo. A Spanish soap opera triggers a Google Home. In one famous case, a couple's Echo heard something that sounded like a wake word on TV, then heard something that sounded like "send message," then heard something that sounded like a contact name, and sent a 20 second recording of their private conversation to a random person in their address book. Amazon called this an improbable chain of events. Which is a very expensive way of saying, yes, it did exactly what it was built to do.&lt;/p&gt;

&lt;p&gt;Every false activation is a little audio postcard from your life mailed to a data center you will never see.&lt;/p&gt;

&lt;p&gt;And voice data is not just voice data. It is biometric data. It is stress. It is background noise analysis. It is that cough you have had for three days, that argument you had in the kitchen, that person whose voice is in your apartment at 3 a.m. who is not on your Instagram story. That is context. Context is the most valuable currency on earth right now.&lt;/p&gt;

&lt;p&gt;We replaced the man in the van with headphones with a $30 cylinder you pay to surveil yourself. Then we pay $10.99 a month to store the surveillance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Yes, She Will Testify Against You
&lt;/h2&gt;

&lt;p&gt;This is the part that kills the vibe at brunch, so I will say it fast.&lt;/p&gt;

&lt;p&gt;Alexa can and will be used as a witness against you. This is not a theory. It is case law.&lt;/p&gt;

&lt;p&gt;In 2015, prosecutors in Arkansas demanded Echo data from an Amazon device in a murder case at a hot tub, because of course it was a hot tub. Amazon fought it on First Amendment grounds. The defendant eventually consented to release the data.&lt;/p&gt;

&lt;p&gt;In 2019, in Florida, police used Echo recordings as part of a murder investigation. In New Hampshire, a judge ordered Amazon to hand over two days of Echo recordings in a double homicide case. In Ohio, a man tried to use his pacemaker data to prove his innocence. His pacemaker testified that he was lying.&lt;/p&gt;

&lt;p&gt;And it is not just murder. Your smart home is now a regular guest in family court. Divorce attorneys routinely subpoena smart home data. Did your Nest say you were home when you said you were at work? Did your smart lock log show you came home at 1:14 a.m.? Did your Fitbit show your heart rate spiking at 2 a.m. when you said you were asleep? Did your smart water meter show you used 140 gallons of water in the middle of the night?&lt;/p&gt;

&lt;p&gt;Your house has perfect memory and zero loyalty.&lt;/p&gt;

&lt;p&gt;Go read the privacy policy you accepted while half asleep. It says they may share your data to comply with legal requests. Translation, the little ambient computer you talk to in your underwear has a better legal defense strategy than you do.&lt;/p&gt;

&lt;h2&gt;
  
  
  "I Have Nothing To Hide" Is The Most Embarrassing Sentence
&lt;/h2&gt;

&lt;p&gt;This is where someone always chimes in with the battle cry of the voluntarily surveilled: I have nothing to hide.&lt;/p&gt;

&lt;p&gt;You close the bathroom door and you are not committing a felony in there. You have curtains and you are not running a cartel behind them. You have a password on your phone even though your camera roll is just screenshots and memes.&lt;/p&gt;

&lt;p&gt;Privacy is not about criminality. It is about autonomy. It is about the right to be unfinished, unobserved, contradictory, and weird without that weirdness becoming a data point that is bought, sold, modeled, and then used to sell you therapy.&lt;/p&gt;

&lt;p&gt;The smart home has made you legible. Every device is a translator that turns your analog, messy, human life into clean, searchable, sellable, subpoenable data. You are being rendered into a spreadsheet you cannot see.&lt;/p&gt;

&lt;h2&gt;
  
  
  So What Is A Faraday Room?
&lt;/h2&gt;

&lt;p&gt;A Faraday cage is a real thing. It is an enclosure made of conductive material that blocks electromagnetic fields. No signals in, no signals out. It is what you use when you actually, technically need a device to shut up.&lt;/p&gt;

&lt;p&gt;A Faraday Room is the philosophy version.&lt;/p&gt;

&lt;p&gt;It is the radical decision that at least one room, one hour, one conversation in your life exists completely off the record.&lt;/p&gt;

&lt;p&gt;It is not about living like a hermit. It is not about smashing everything with a hammer, although I have a video of someone doing exactly that to an Echo and it is genuinely therapeutic viewing.&lt;/p&gt;

&lt;p&gt;It is about threat modeling for normal people. It is about architecture over toggles. You cannot privacy setting your way out of a house that was designed from the studs to collect you.&lt;/p&gt;

&lt;h3&gt;
  
  
  How to start de bugging your apartment without looking unhinged
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;1. Do a device census.&lt;/strong&gt;&lt;br&gt;
Walk through your apartment like you are not you. Walk through it like you are someone who wants to know everything about you without meeting you. Open your router app. How many devices are connected? Most people have 25 to 40 and can only name six. That printer from 2014 with firmware from the Obama administration? That is a vulnerability with a paper tray.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Ask if it needs internet to be useful.&lt;/strong&gt;&lt;br&gt;
Does your vacuum need to know your floor plan and also upload it to the cloud? No. Does your light bulb need to know your GPS coordinates? Absolutely not. Does your TV need a microphone in the remote? For what? So it can hear you better while you yell at reality TV?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Learn the difference between off and pretending to be off.&lt;/strong&gt;&lt;br&gt;
Your TV is not off when you press power. It is in standby, listening for a signal. Your phone is not off when it says Bluetooth is off. It is still pinging. Real privacy is not a button. It is a behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Build one truly dumb room.&lt;/strong&gt;&lt;br&gt;
Make your bedroom dumb. No speakers. No TV that listens. No devices that need to hear a wake word to feel loved. Let one room be just a room. A place where you can be unoptimized, unrecorded, unobserved, and fully human.&lt;/p&gt;

&lt;p&gt;If you want the full manual, the actual step by step, this is what I built.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Question
&lt;/h2&gt;

&lt;p&gt;Tonight, when your apartment is quiet, try this.&lt;/p&gt;

&lt;p&gt;Stand in your kitchen. Look at the little black cylinder that you paid to live with you. And ask it out loud:&lt;/p&gt;

&lt;p&gt;"Alexa, are you testifying against me?"&lt;/p&gt;

&lt;p&gt;Watch how quickly she pretends she cannot hear you.&lt;/p&gt;

&lt;p&gt;That silence is your answer.&lt;/p&gt;




&lt;h3&gt;
  
  
  Want the actual field manual?
&lt;/h3&gt;

&lt;p&gt;This essay is the appetizer. The surgery is in the guide.&lt;/p&gt;

&lt;p&gt;I wrote &lt;strong&gt;THE FARADAY ROOM: Your Home Is Listening&lt;/strong&gt; because I got tired of feeling paranoid for noticing the obvious. It is a complete, practical guide to de bugging your apartment, sweeping for hidden mics and cameras, finding RF leakage, killing smart device spying, and building one room in your life that is actually yours again.&lt;/p&gt;

&lt;p&gt;No tinfoil. Just tradecraft for people who want their home to feel like a home again, not a showroom.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Get it here: numbpilled.gumroad.com/l/faradayy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And if you live online like I do, you will want the rest of the stack too:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;THE GHOST STACK: Anonymous Money Infrastructure&lt;/strong&gt; - how to make your money as private as your browser thinks it is in incognito mode. numbpilled.gumroad.com/l/moneymore&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;THE BRAND THAT WATCHES BACK: Counter-OSINT for Creators&lt;/strong&gt; - how to be famous on the internet without being findable in real life. numbpilled.gumroad.com/l/countercreator&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;THE WATCHER'S WATCHER: How to Know You Are Being Investigated&lt;/strong&gt; - the subtle, unsexy signs that someone is looking into you. numbpilled.gumroad.com/l/observ3rs&lt;/p&gt;

&lt;p&gt;Privacy is not paranoia. It is housekeeping.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>discuss</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>Surviving the AI Bubble With Two Pieces of Junk From Amazon</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sun, 09 Aug 2026 03:44:18 +0000</pubDate>
      <link>https://dev.to/numbpill3d/surviving-the-ai-bubble-with-two-pieces-of-junk-from-amazon-5h1i</link>
      <guid>https://dev.to/numbpill3d/surviving-the-ai-bubble-with-two-pieces-of-junk-from-amazon-5h1i</guid>
      <description>&lt;h3&gt;
  
  
  Everyone is building agents. You should build escape hatches.
&lt;/h3&gt;

&lt;p&gt;We are living through the most expensive group hallucination in tech history.&lt;/p&gt;

&lt;p&gt;Every SaaS now has a chatbot stapled to it. Every CEO is an "AI thought leader" on LinkedIn. Every startup pitch deck is just the words "autonomous," "agentic," and "10x" in different fonts. NVIDIA could buy a small country. OpenAI burns through more cash in a quarter than NASA did getting to the moon.&lt;/p&gt;

&lt;p&gt;And for what? So you can generate slightly worse emails, slightly faster?&lt;/p&gt;

&lt;p&gt;Look, I love AI. I actually build with it. But I have been around long enough to know what a bubble smells like. It smells like free credits, unearned confidence, and a thousand wrappers around the same API call.&lt;/p&gt;

&lt;p&gt;The bubble will pop. Not in a dramatic, newspapers falling from the sky way. It will pop quietly. Credits will dry up. Models will get paywalled behind enterprise tiers. The cloud bill you have been ignoring will finally show up. And all those beautiful, cloud-dependent workflows you built will start blinking red.&lt;/p&gt;

&lt;p&gt;So while everyone else is trying to figure out how to make their AI agent book a flight, I have been asking a different question.&lt;/p&gt;

&lt;p&gt;What do you build when you assume the internet will get worse, the cloud will get more expensive, and you will need actual skills that survive a downturn?&lt;/p&gt;

&lt;p&gt;The answer, annoyingly, is two pieces of junk from Amazon that cost less than your last Uber Eats order.&lt;/p&gt;

&lt;h2&gt;
  
  
  Piece of Junk #1: The $25 Router That Sees Everything
&lt;/h2&gt;

&lt;p&gt;It is not sexy. It is called the GL.iNet GL-MT300N-V2. Everyone calls it the Mango. It looks like a little yellow box that should have come free with your ISP in 2014. You can buy it on Amazon for about twenty six dollars when it is on sale. Sometimes twenty.&lt;/p&gt;

&lt;p&gt;Inside it is a tiny Linux computer running OpenWrt. It has two ethernet ports, a USB port, and just enough RAM to be dangerous.&lt;/p&gt;

&lt;p&gt;Most people buy it to get free WiFi in hotels. I bought it to spy on my own network.&lt;/p&gt;

&lt;p&gt;Because here is the dirty secret of the AI bubble: we have automated threat generation and we have not automated threat detection for normal people. Anyone can now vibe code a phishing site. Anyone can generate a perfectly written invoice scam in twelve languages. Your mom can now get scammed by an AI that sounds exactly like you.&lt;/p&gt;

&lt;p&gt;So I turned the Mango into a $20 SOC. A Security Operations Center that fits in your palm.&lt;/p&gt;

&lt;p&gt;You flash it with a custom firmware, you plug it between your modem and your actual router, and you tell it to do three things:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt; Run Pi-hole or AdGuard and kill every ad, tracker, and crypto miner at the DNS level.&lt;/li&gt;
&lt;li&gt; Run a lightweight IDS like Snort or Suricata and actually watch what your smart TV is sending to China at 3am.&lt;/li&gt;
&lt;li&gt; Log everything to a little USB stick so you have receipts.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Suddenly your dumb network is smart. You see that your cheap smart bulb is pinging an IP in Shenzhen every 30 seconds. You see that your kid's iPad is trying to reach a known malware domain from a Roblox mod. You see that your "offline" AI photo app is uploading your entire camera roll anyway.&lt;/p&gt;

&lt;p&gt;It costs twenty dollars. It draws less power than a nightlight. It does not have a subscription. It does not have an agent. It does not need a prompt engineer.&lt;/p&gt;

&lt;p&gt;It just sits there, blinking, protecting you while the rest of Silicon Valley argues about whether AGI will be here in 2027.&lt;/p&gt;

&lt;p&gt;In a world where everyone is trying to build software that thinks like a human, the most valuable skill is building hardware that does not trust anything.&lt;/p&gt;

&lt;p&gt;This is defensive computing. This is how you stay employable when the hype fades. Because when companies realize they have given every intern access to Cursor and a production database, who do you think they are going to call? The guy who built the agent, or the woman who built the thing that caught the agent exfiltrating customer data?&lt;/p&gt;

&lt;p&gt;Learn to build the watchtower, not just the city.&lt;/p&gt;

&lt;h2&gt;
  
  
  Piece of Junk #2: The $35 Brick That Thinks When Nothing Else Can
&lt;/h2&gt;

&lt;p&gt;The second piece of junk is even dumber. A Raspberry Pi Zero 2 W. Thirty five bucks on Amazon if you are lucky. Often bundled with a bunch of cables you will never use and a tiny case that makes it look like a toy.&lt;/p&gt;

&lt;p&gt;Pair it with a cheap 10,000mAh battery bank, a $12 e-ink display or any old HDMI screen you have, and a 64GB SD card. Total cost, maybe fifty five dollars if you shop like a raccoon.&lt;/p&gt;

&lt;p&gt;This is The Blackbox.&lt;/p&gt;

&lt;p&gt;No WiFi. No cloud. No API keys. No monthly bill.&lt;/p&gt;

&lt;p&gt;Just a local LLM, running entirely offline, on a computer the size of a stick of gum.&lt;/p&gt;

&lt;p&gt;I run a quantized 2B or 3B model on it. Phi-3, Gemma 2, Qwen 2.5, pick your fighter. It is slow. It is not going to write your novel. It thinks at about 4 to 6 tokens per second, which is roughly the speed I think before coffee.&lt;/p&gt;

&lt;p&gt;But it works. When the power is out. When the internet is down. When Starlink is congested. When OpenAI is having another one of its mysterious outages that they swear is not because someone tripped over a cable.&lt;/p&gt;

&lt;p&gt;I took mine camping in Pisgah last month. No signal for three days. My friend had his $1,200 iPhone 16 Pro that was now just a very expensive flashlight. I had a little black box that could still do this:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Summarize field notes I typed in markdown&lt;/li&gt;
&lt;li&gt;  Parse a messy CSV of GPS coordinates into a clean trail map&lt;/li&gt;
&lt;li&gt;  Act as a personal wiki for first aid, knot tying, and water filtration&lt;/li&gt;
&lt;li&gt;  Translate a manual from German because of course the water filter instructions were in German&lt;/li&gt;
&lt;li&gt;  Be a completely private journal that will never, ever be used as training data&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No one was logging my prompts. No one was rate limiting me. No one could turn it off.&lt;/p&gt;

&lt;p&gt;This is the skill the bubble is actively making you forget: how to build things that work without permission.&lt;/p&gt;

&lt;p&gt;We have spent the last three years learning how to be tenants. Tenants on OpenAI's platform. Tenants on AWS. Tenants in someone else's model, someone else's computer, someone else's vision of the future. And tenants can be evicted.&lt;/p&gt;

&lt;p&gt;Builders own. Builders have a box that works when nothing else does.&lt;/p&gt;

&lt;p&gt;The Blackbox is not anti AI. It is post hype AI. It is what AI looks like when you strip away the landing pages and the waitlists and the "we are so back" tweets. It is just a tool. A quiet, useful, private tool that you control.&lt;/p&gt;

&lt;p&gt;And when the bubble pops and all those $20 per month AI subscriptions start feeling like $20 too much, you will have something that costs zero dollars per month forever.&lt;/p&gt;

&lt;h2&gt;
  
  
  So What Are We Actually Doing Here?
&lt;/h2&gt;

&lt;p&gt;We are not LARPing as preppers. We are not anti technology. We are just refusing to be stupid about it.&lt;/p&gt;

&lt;p&gt;The AI bubble taught a whole generation that technical skill means knowing how to write a really good prompt. That is like saying culinary skill means knowing how to order well at a restaurant.&lt;/p&gt;

&lt;p&gt;Real skill is understanding the layers underneath. Packets. Power draw. How a model actually gets loaded into RAM. How to solder two wires when you have to. How to make something resilient instead of just impressive.&lt;/p&gt;

&lt;p&gt;These two little junk boxes teach you that.&lt;/p&gt;

&lt;p&gt;The Mango teaches you networking, Linux, traffic analysis, and defensive thinking. Those skills were valuable before ChatGPT and will be valuable after whatever comes next.&lt;/p&gt;

&lt;p&gt;The Blackbox teaches you model quantization, edge inference, offline first design, and privacy engineering. Those are not hype skills. Those are the future, especially as regulation catches up and people get tired of their toaster sending data to the cloud.&lt;/p&gt;

&lt;p&gt;Everyone else is racing to build the tallest tower on top of someone else's cloud. You can build a bunker with a library inside for sixty bucks.&lt;/p&gt;

&lt;p&gt;When the wind comes, guess who survives.&lt;/p&gt;

&lt;p&gt;Start with junk. End with skills that no bubble can pop.&lt;/p&gt;




&lt;p&gt;If you want the actual step by step build guides, with parts lists, flash commands, and my config files so you do not have to spend a weekend swearing at a terminal, I put them here:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The $20 SOC: Build a Tiny Defensive Network Monitor&lt;/strong&gt;&lt;br&gt;
numbpilled.gumroad.com/l/20dollarsoxc&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;BUILD THE BLACKBOX: An Offline AI Field Terminal That Works When Nothing Else Does&lt;/strong&gt;&lt;br&gt;
numbpilled.gumroad.com/l/blackbox-offline-ai&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>tutorial</category>
      <category>automation</category>
    </item>
    <item>
      <title>I Put a Canary Token in My Resume and Caught a Company Stalking Me</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Fri, 07 Aug 2026 23:28:39 +0000</pubDate>
      <link>https://dev.to/numbpill3d/i-put-a-canary-token-in-my-resume-and-caught-a-company-stalking-me-458g</link>
      <guid>https://dev.to/numbpill3d/i-put-a-canary-token-in-my-resume-and-caught-a-company-stalking-me-458g</guid>
      <description>&lt;p&gt;&lt;em&gt;The job market is broken. So I decided to break it back.&lt;/em&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  The interview that felt like an interrogation
&lt;/h3&gt;

&lt;p&gt;You know that moment in a job interview when it stops feeling like a conversation and starts feeling like deposition?&lt;/p&gt;

&lt;p&gt;That was Tuesday.&lt;/p&gt;

&lt;p&gt;I was interviewing for a "Senior Operations" role at a mid-size tech company that I won't name, because their lawyers have more free time than I do. Let's call them PanoptiCorp.&lt;/p&gt;

&lt;p&gt;The HM was nice enough. Then he said it:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"So, I saw you were really into the whole... rationalist scene in 2021? And you did that crypto project that didn't really go anywhere?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;My resume says none of that. My LinkedIn says none of that. My portfolio site says none of that.&lt;/p&gt;

&lt;p&gt;My resume says: 5 years experience. Python, ops, systems design. Links to GitHub. Clean. Boring. Corporate-friendly.&lt;/p&gt;

&lt;p&gt;It does NOT say anything about LessWrong. It does NOT mention a failed DAO I contributed to three wallets ago under a pseudonym I thought was dead.&lt;/p&gt;

&lt;p&gt;So I smiled and said, "Where did you see that?"&lt;/p&gt;

&lt;p&gt;He backpedaled so fast he left skid marks. "Oh, you know, just... did a little research. We like to be thorough."&lt;/p&gt;

&lt;p&gt;Thorough.&lt;/p&gt;

&lt;p&gt;Right.&lt;/p&gt;

&lt;p&gt;Most candidates hear that and feel flattered. &lt;em&gt;Wow, they really looked into me.&lt;/em&gt; &lt;/p&gt;

&lt;p&gt;I felt my stomach drop. Because I knew what "thorough" meant. It meant someone had run me through a full OSINT sweep. Not just Googled me. &lt;em&gt;Investigated&lt;/em&gt; me.&lt;/p&gt;

&lt;p&gt;And I had prepared for exactly that.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why I started booby-trapping my own resume
&lt;/h3&gt;

&lt;p&gt;Let's be honest about what hiring is in 2026.&lt;/p&gt;

&lt;p&gt;You are not being evaluated. You are being investigated.&lt;/p&gt;

&lt;p&gt;Every company now has either an internal "Trust &amp;amp; Safety" guy who used to do military intel, or a $199/month subscription to some people-search aggregator that promises to show your "risk signals," your old addresses, your relatives, your leaked passwords, your deleted tweets from when you were 19.&lt;/p&gt;

&lt;p&gt;You apply for a marketing job and they know your ex-girlfriend's dog's name.&lt;/p&gt;

&lt;p&gt;The advice we're given is insane: "Clean up your digital footprint!" As if you can. As if you should have to scrub your entire personality to be worthy of health insurance.&lt;/p&gt;

&lt;p&gt;I got tired of being paranoid. So I got proactive.&lt;/p&gt;

&lt;p&gt;If you can't stop them from watching, you can at least make them trip a wire.&lt;/p&gt;

&lt;p&gt;Enter: &lt;strong&gt;Canary Tokens.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If you don't know what they are, Canary Tokens are free, tiny digital tripwires made by Thinkst. You create a file, a link, a DNS token, an image — and when someone opens it, it pings you. IP address, user agent, timestamp. Proof someone touched something they shouldn't have.&lt;/p&gt;

&lt;p&gt;Security teams use them to catch hackers. I started using them to catch employers.&lt;/p&gt;

&lt;h3&gt;
  
  
  How to put a honeypot in a PDF without being a psycho about it
&lt;/h3&gt;

&lt;p&gt;This is the part where I have to be careful, because I don't want every recruiter on LinkedIn thinking I'm trying to hack the Pentagon.&lt;/p&gt;

&lt;p&gt;I'm not. I'm just done pretending this is normal.&lt;/p&gt;

&lt;p&gt;Here's what I did, and it's so simple it should be illegal that more people don't do it:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. The Invisible Image.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I generated a Canary Token for an image. Thinkst gives you a URL that looks like any random tracking pixel.&lt;/p&gt;

&lt;p&gt;I embedded it in my resume PDF. White 1x1 pixel in the footer. You will never see it. Your ATS will never see it. But if a human opens that PDF in a previewer that loads remote images — which Gmail, Apple Mail, and most corporate Outlook setups do — &lt;em&gt;ping.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;I get an email: "Your Canarytoken has been triggered."&lt;/p&gt;

&lt;p&gt;It includes the IP, the time, and often the organization that owns the IP.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. The Portfolio Link.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I didn't just link to &lt;code&gt;voidrane.xyz/portfolio&lt;/code&gt;. I linked to &lt;code&gt;voidrane.xyz/portfolio?src=resume_q3&lt;/code&gt; and that page had a Canary link embedded as a "Download full case study (PDF)" button. Different token for every company I applied to.&lt;/p&gt;

&lt;p&gt;So if PanoptiCorp's token fires, I know it's PanoptiCorp.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. The Boring Doc.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;My actual portfolio site is clean. But I have a &lt;code&gt;/old&lt;/code&gt; directory that is not linked anywhere. If you find it, you found it via scraping or OSINT tools that brute-force subdirectories. I put another token in there.&lt;/p&gt;

&lt;p&gt;If that one fires, I know they didn't just read my resume. They ran a recon tool on me.&lt;/p&gt;

&lt;p&gt;Is this paranoid? Maybe. Is it effective? &lt;/p&gt;

&lt;p&gt;Let me tell you what happened after Tuesday.&lt;/p&gt;

&lt;h3&gt;
  
  
  The stalking timeline
&lt;/h3&gt;

&lt;p&gt;I got home after that weird interview and checked my Canary dashboard.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger 1:&lt;/strong&gt; Resume image token - Opened 3 times. First open from a San Francisco IP owned by PanoptiCorp. Expected. Second open from same IP, 4 hours later. They forwarded my resume around. Normal. &lt;/p&gt;

&lt;p&gt;Third open: Different IP. Ashburn, Virginia. Owned by a data broker aggregator. The kind of IP that belongs to SocialLinks / Maltego / People Data Labs style infrastructure.&lt;/p&gt;

&lt;p&gt;That was 9:42 PM on a Sunday. Two days &lt;em&gt;before&lt;/em&gt; they even emailed me to schedule the interview.&lt;/p&gt;

&lt;p&gt;So before a human ever decided I was worth talking to, my resume was already fed into an automated background check system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger 2:&lt;/strong&gt; Portfolio link token for PanoptiCorp - Fired at 10:15 PM Sunday. Then again at 8:04 AM Monday from a &lt;em&gt;different&lt;/em&gt; user agent, this time a headless browser. That's not a hiring manager clicking a link. That's a scraper.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Trigger 3:&lt;/strong&gt; The &lt;code&gt;/old&lt;/code&gt; directory token - Fired at 10:17 PM Sunday. Two minutes after the portfolio link. That means whatever tool they used automatically enumerated my site.&lt;/p&gt;

&lt;p&gt;So by the time I got the cheerful "We'd love to chat!" email on Monday morning, they had already:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Run my email through a people-search API&lt;/li&gt;
&lt;li&gt;Scraped my entire personal website structure&lt;/li&gt;
&lt;li&gt;Associated my current name with a pseudonym from 2021&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That's not "doing a little research." That's a full-spectrum dossier.&lt;/p&gt;

&lt;p&gt;And in the interview, they acted like they just happened to stumble on it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why this should enrage you (even if you have nothing to hide)
&lt;/h3&gt;

&lt;p&gt;The standard cope is: "If you have nothing to hide, why do you care?"&lt;/p&gt;

&lt;p&gt;Because privacy is not about hiding. It's about consent and context.&lt;/p&gt;

&lt;p&gt;I consented to you evaluating my ability to do the job described in the JD. I did not consent to you feeding my personal domain into a crawler at 10pm on a Sunday to find a project I did under a different name when I was 24, to use as a weird power move in an interview.&lt;/p&gt;

&lt;p&gt;And here's the sinister part: &lt;strong&gt;They will never tell you they did it.&lt;/strong&gt; They will just make vague references to "culture fit" or "we found some inconsistencies." You will never know why you didn't get the job.&lt;/p&gt;

&lt;p&gt;I only know because I set a trap.&lt;/p&gt;

&lt;p&gt;Once you see it, you can't unsee it. The job application process is the only place in modern life where we are expected to hand over our home address, our work history, our references, our social security number — and then also smile while a stranger in HR runs a background investigation that would be illegal for a cop to do without a warrant.&lt;/p&gt;

&lt;p&gt;We talk a lot about companies ghosting candidates. We don't talk enough about companies &lt;em&gt;stalking&lt;/em&gt; candidates.&lt;/p&gt;

&lt;p&gt;The power asymmetry is absurd. They have tools, budgets, and third-party vendors whose entire business model is violating your privacy at scale. You have... a cover letter.&lt;/p&gt;

&lt;p&gt;So I decided to level it a little.&lt;/p&gt;

&lt;h3&gt;
  
  
  How to know you're being investigated (without becoming a full-time paranoid)
&lt;/h3&gt;

&lt;p&gt;Look, I didn't invent this mindset. There's a whole discipline around it. In the intel world it's called Counter-OSINT — learning the tells that someone is building a file on you.&lt;/p&gt;

&lt;p&gt;I got deep down that rabbit hole after the PanoptiCorp incident, and if this story made your neck hairs stand up, you should too. I wish I could put everything I learned in this post, but Medium would flag me for being too unhinged.&lt;/p&gt;

&lt;p&gt;The best, latest, and most practical guide I've made that actually explains the technical breadcrumbs — the DNS tells, the aggregator IPs, the fake recruiter accounts — is called &lt;strong&gt;&lt;a href="https://numbpilled.gumroad.com/l/observ3rs" rel="noopener noreferrer"&gt;THE WATCHER'S WATCHER: Counter-OSINT How to Know You're Being Investigated&lt;/a&gt;&lt;/strong&gt;. It's on Gumroad.&lt;/p&gt;

&lt;p&gt;I'm not affiliated with them. I just think if you're going to play this game, you should know the rules.&lt;/p&gt;

&lt;p&gt;Because once you know what to look for, the signs are everywhere:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;strong&gt;The LinkedIn view from someone with no photo, 500+ connections, title "Talent Intelligence" or "People Researcher".&lt;/strong&gt; That's not a recruiter. That's an OSINT contractor.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;The weirdly specific question about something you deleted.&lt;/strong&gt; If they mention a tweet you deleted in 2019, they didn't "find it." They bought it from a data broker who archived it.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;The follow-up email that comes from a different domain.&lt;/strong&gt; Your resume gets uploaded to Greenhouse, which shares data with 47 integrations. One of them pings you.&lt;/li&gt;
&lt;li&gt;  &lt;strong&gt;The sudden friend request from a stranger in your industry right after you apply.&lt;/strong&gt; Classic pretexting account to view your private posts.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  So what did I do with PanoptiCorp?
&lt;/h3&gt;

&lt;p&gt;I withdrew.&lt;/p&gt;

&lt;p&gt;I sent a polite email: "Thank you for your time, but I've decided to move forward with other opportunities."&lt;/p&gt;

&lt;p&gt;Then I sent a &lt;em&gt;different&lt;/em&gt; email from a burner, with a PDF report of every token trigger, every IP, every timestamp.&lt;/p&gt;

&lt;p&gt;Their Head of People responded within 20 minutes asking to "hop on a call to clarify any misunderstandings."&lt;/p&gt;

&lt;p&gt;I did not hop.&lt;/p&gt;

&lt;p&gt;The point was never to get revenge. The point was to prove to myself that I wasn't crazy. That feeling you get when an interviewer knows too much? That's real. That's data. And now I have logs.&lt;/p&gt;

&lt;p&gt;Since then, I've put unique tokens in every single resume I send out. Out of 31 applications in the last 2 months:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  19 triggered only the resume image token once or twice. Normal behavior.&lt;/li&gt;
&lt;li&gt;  8 triggered the image AND the portfolio link. Thorough, but human.&lt;/li&gt;
&lt;li&gt;  4 triggered all three, including the hidden directory enumeration, from data broker IPs, &lt;em&gt;before&lt;/em&gt; any human contacted me. That's the stalking tier.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That's 13% of companies doing full passive recon before they even say hello.&lt;/p&gt;

&lt;p&gt;Let that sink in.&lt;/p&gt;

&lt;h3&gt;
  
  
  Your resume is not a document. It's a beacon.
&lt;/h3&gt;

&lt;p&gt;We are told to optimize our resumes for ATS keywords. We should be optimizing them for counter-surveillance.&lt;/p&gt;

&lt;p&gt;I'm not telling you to become a privacy extremist and live in a cabin. I'm telling you to stop playing defense.&lt;/p&gt;

&lt;p&gt;Put a Canary Token in your resume. It's free. It takes 30 seconds. Go to canarytokens.org, generate a DNS token or an image token, and embed it.&lt;/p&gt;

&lt;p&gt;Not because you want to catch a company and write a snarky Medium post like me.&lt;/p&gt;

&lt;p&gt;But because the first time you get that email that says "Your Canarytoken has been triggered" at 2 AM from an IP in Virginia that belongs to a company you've never heard of, that is charging another company to investigate you without your consent — you will finally understand the game you're playing.&lt;/p&gt;

&lt;p&gt;And you will never send a naked resume again.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;If you try this, tell me what you find. I have a feeling my inbox is about to get very interesting.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;And if you work at PanoptiCorp and you're reading this: hi. I know you saw the &lt;code&gt;/old&lt;/code&gt; folder. We both know what was in there wasn't work-appropriate. That's why I put it there.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>tutorial</category>
      <category>security</category>
      <category>career</category>
    </item>
    <item>
      <title>How Journalists, Exes, and Feds All Use the Same 5 Tricks to Find You</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Wed, 05 Aug 2026 13:59:29 +0000</pubDate>
      <link>https://dev.to/numbpill3d/how-journalists-exes-and-feds-all-use-the-same-5-tricks-to-find-you-4il9</link>
      <guid>https://dev.to/numbpill3d/how-journalists-exes-and-feds-all-use-the-same-5-tricks-to-find-you-4il9</guid>
      <description>&lt;p&gt;They all use the same playbook.&lt;/p&gt;

&lt;p&gt;Your investigative journalist trying to verify your source. Your ex trying to figure out if you moved. And the guy in the windbreaker with a federal badge who definitely says he's "just doing some background."&lt;/p&gt;

&lt;p&gt;Different motivations. Same 5 tricks. And if you don't understand them, you are not hard to find. You are &lt;em&gt;conveniently searchable&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;I spent years on both sides of this game — finding people who didn't want to be found, and helping people disappear who absolutely needed to. The uncomfortable truth is this: privacy isn't about being a ghost. It's about breaking the pivots that make you trivial to pivot.&lt;/p&gt;

&lt;p&gt;Here are the 5 tricks they all use.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. The Breadcrumb Pivot: One Crumb Is All They Need
&lt;/h3&gt;

&lt;p&gt;Amateurs search for your name. Professionals never do.&lt;/p&gt;

&lt;p&gt;They start with the one thing you &lt;em&gt;can't&lt;/em&gt; change easily and pivot off it. That one crumb is usually:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A username you reused in 2016&lt;/li&gt;
&lt;li&gt;A phone number from a data breach&lt;/li&gt;
&lt;li&gt;An old email you used for a pizza loyalty program&lt;/li&gt;
&lt;li&gt;A photo you posted where your license plate is blurred but your neighbor's isn't&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is called &lt;strong&gt;pivoting&lt;/strong&gt;, and it's the entire foundation of modern OSINT. You don't find Void Rane. You find &lt;code&gt;izkaboz&lt;/code&gt; on a forgotten forum, which links to an email, which links to a GitHub, which links to a resume PDF, which lists a city.&lt;/p&gt;

&lt;p&gt;Journalists call this "verification." Exes call this "just checking." Feds call this "establishing a pattern of life." It's the same graph traversal.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it works in the wild:&lt;/strong&gt; You post a story from a coffee shop. You don't tag the location. But the barista has a distinctive tattoo, the menu board has a phone number, and your latte art has a reflection of the street sign behind you. One pivot gives them the city. Second pivot gives them the shop. Third pivot gives them your routine: Tuesdays and Thursdays, 9:30am, oat milk latte, sitting by the window with the good light.&lt;/p&gt;

&lt;p&gt;You didn't leak your location. You leaked three things that &lt;em&gt;become&lt;/em&gt; your location when correlated.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix is ruthless compartmentalization.&lt;/strong&gt; Different names, different emails, different browsers, different personas for different threat models. Not because you're paranoid. Because databases are forever and your memory of what you posted in 2019 is not.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The rule: If two accounts can be connected by a single search, they are the same account.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  2. The Dork Bible: Google Isn't a Search Engine, It's a Confession Booth
&lt;/h3&gt;

&lt;p&gt;Everyone thinks they know how to Google. Almost no one does.&lt;/p&gt;

&lt;p&gt;Your ex isn't typing &lt;code&gt;Void Rane Charlotte&lt;/code&gt;. She's typing:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;site:venmo.com "Void" "Charlotte"&lt;/code&gt;&lt;br&gt;
&lt;code&gt;filetype:pdf "Void Rane" resume&lt;/code&gt;&lt;br&gt;
&lt;code&gt;intext:"@izkaboz" AND ("gmail.com" OR "protonmail")&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Journalists have this down to a religion. It's called Google Dorking, and it's just advanced operators that turn Google from a popularity contest into a database query language. Add Yandex, Bing, and DuckDuckGo image search — because Google is actually the &lt;em&gt;worst&lt;/em&gt; at faces — and you can find a person's entire digital exhaust in 20 minutes.&lt;/p&gt;

&lt;p&gt;The real power move? &lt;strong&gt;De-indexed search.&lt;/strong&gt; People think deleting a post deletes it. It just deletes it from &lt;em&gt;your&lt;/em&gt; profile. The dork bible finds the cached version, the archive.org snapshot, the repost bot that scraped your Instagram to a spam site in Indonesia in 2021. The internet never forgets. It just gets worse at indexing until someone who knows how to ask comes along.&lt;/p&gt;

&lt;p&gt;My favorite example: A founder told me he was "completely offline." I found his home address in 6 minutes because his dog walker tagged his dog's Instagram account, which had his old address in the bio from 2020. He didn't leak his address. His dog did.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix is pre-emptive poisoning and removal.&lt;/strong&gt; You can't just delete. You have to audit what search engines &lt;em&gt;think&lt;/em&gt; you are. Search yourself like someone who hates you would. Then dork yourself like someone who is paid to find you would.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. The Metadata Trap: Your Files Are Snitching On You
&lt;/h3&gt;

&lt;p&gt;This is the one that gets journalists and activists caught.&lt;/p&gt;

&lt;p&gt;You take a photo of a sensitive document. You crop out your face. You post it anonymously. Congratulations, you just uploaded a file that contains:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Exact GPS coordinates where the photo was taken&lt;/li&gt;
&lt;li&gt;Your iPhone model and iOS version&lt;/li&gt;
&lt;li&gt;The time you took it down to the second&lt;/li&gt;
&lt;li&gt;Often, your full name if you had "Save as: Void_Rane_license.jpg"&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That's EXIF data. And it's not just photos. Word docs have author names and revision history. PDFs have the software that created them and sometimes the path it was saved to: &lt;code&gt;/Users/void.rane/Documents/DO NOT LEAK/&lt;/code&gt;. I've seen it. Multiple times.&lt;/p&gt;

&lt;p&gt;Feds love metadata because it holds up in court and you volunteered it. Exes love it because iPhones embed location by default and most people have never turned it off. Journalists hate it when their &lt;em&gt;sources&lt;/em&gt; do it, because it burns the source without the journalist ever knowing.&lt;/p&gt;

&lt;p&gt;A few months ago, a very smart person sent me a "fully anonymized" video. I ran &lt;code&gt;exiftool&lt;/code&gt; on it and got the exact Airbnb they were staying in from the audio fingerprint of the smoke detector.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix is a Ghost Mode workflow.&lt;/strong&gt; Never post originals. Ever. Screenshot the photo, screen-record the video, copy-paste text into a fresh .txt file. Run everything through a metadata nuker before it touches the internet. If your workflow doesn't include a deliberate metadata removal step, you don't have a privacy workflow. You have a hope.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. The Network Pivot: You Are Your Friends
&lt;/h3&gt;

&lt;p&gt;You can be perfect. Your friends won't be.&lt;/p&gt;

&lt;p&gt;This is how 90% of real investigations close the loop. They can't find you, so they find the five people closest to you and watch &lt;em&gt;them&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;Your mom posts "So proud of my daughter moving to NoDa!" Your friend tags you at a climbing gym with the caption "my usual belay partner." Your roommate's Venmo is public and says "rent - 1520 Central Ave Apt 3B."&lt;/p&gt;

&lt;p&gt;Journalists call this "mapping the network." Feds call this "two hops." Your ex just calls it "looking at who liked his post."&lt;/p&gt;

&lt;p&gt;OSINT investigators have a saying: &lt;strong&gt;You don't need to find the target. You just need to find someone who loves the target enough to post about them.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Modern tools make this trivial. You can map an entire friend graph, cluster it by frequency of interaction, and identify the weak link — the person with 800 public friends, a public Facebook, and a habit of checking in everywhere. That person is your breach.&lt;/p&gt;

&lt;p&gt;I once watched an investigator find a CEO who had gone fully off-grid by finding his executive assistant's Strava running route that started and ended at a private residence in Jackson Hole every morning at 6am.&lt;/p&gt;

&lt;p&gt;He wasn't hiding. His assistant was exercising.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix is social media hygiene as a group project.&lt;/strong&gt; Talk to your inner circle. Not in a paranoid way. In a respectful way: "Hey, please don't tag me in locations, don't post photos of my house/kids/car, and if you have to post that group photo, crop me or blur me." People who love you will get it. The ones who don't were never going to respect your boundaries anyway.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. AI-Native OSINT: The Game Just Changed and You Didn't Notice
&lt;/h3&gt;

&lt;p&gt;This is the new one. And it's the one that makes the previous four look quaint.&lt;/p&gt;

&lt;p&gt;For ten years, OSINT was manual. You had to know where to look. Now AI looks everywhere at once.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Face search:&lt;/strong&gt; PimEyes, FaceCheck.ID and a dozen private models can take one blurry photo from a protest, a bar, or a dating profile and find every other place that face has appeared online. Your journalist source wore a mask but forgot about the reflection in their glasses? Found.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI-enhanced imagery:&lt;/strong&gt; That license plate you blurred? AI de-blurs it. That background you thought was too dark to see? AI enhances it to daylight. That voice note you disguised? AI voice-to-text plus voiceprint matching.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pattern synthesis:&lt;/strong&gt; AI can ingest 3,000 of your tweets, your Reddit history, and your Spotify playlists and predict with scary accuracy where you live, your political views, your mental health state, and your schedule. Not because it's magic. Because humans are predictable and you are training the model on yourself for free.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Exes use this now. Not just nation-states. There are TikTok tutorials for "how to find his new girlfriend with AI." It's not underground anymore. It's consumer software with a pastel UI.&lt;/p&gt;

&lt;p&gt;This is why old privacy advice — "use a VPN" — is now basically astrology. A VPN doesn't protect you from yourself posting 400 searchable data points a day.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The fix is going AI-native on defense.&lt;/strong&gt; You need to understand what AI sees when it sees you. Run your own face through PimEyes. Run your own writing through a stylometry detector. See what a clustering model thinks your friend group looks like. You cannot defend against what you don't measure.&lt;/p&gt;




&lt;p&gt;Look, here's the uncomfortable conclusion no one wants to say out loud:&lt;/p&gt;

&lt;p&gt;Privacy in 2026 is not about having something to hide. It's about having something to &lt;em&gt;protect&lt;/em&gt;. Your focus, your location, your relationships, your future leverage. Every app you use is built on the assumption that you are the product and your data is the inventory. Journalists, exes, and feds are just power users of that system.&lt;/p&gt;

&lt;p&gt;You have two choices. You can be searchable by default and surprised when it matters. Or you can be intentional by default and boring to find.&lt;/p&gt;

&lt;p&gt;Boring is the goal. Boring is freedom.&lt;/p&gt;

&lt;p&gt;If you want to go from "I should probably be more private" to having an actual, working system — not just a list of tips — I put my entire playbook into three packs:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;For disappearing:&lt;/strong&gt; My Privacy / OpSec stack covers the full Nukepack for account deletion, Ghost Mode for daily browsing, how to actually do OSINT pivots defensively, metadata nuking workflows, and the AI-native OSINT defense toolkit. It's the system I wish someone gave me 5 years ago.&lt;/p&gt;

&lt;p&gt;→ &lt;strong&gt;Privacy/Opsec Stack: Nukepack + Ghost Mode + OSINT Pivots + Metadata + AI-Native OSINT&lt;/strong&gt; — numbpilled.gumroad.com/l/privacy-opsec-stack&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;For going fully offline:&lt;/strong&gt; If you want AI that can't snitch because it never touches the cloud — the Pi 5 NVMe + Hailo-8 + Pico W cluster build, local LLMs, offline workflows. Your own private Skynet in a Pelican case.&lt;/p&gt;

&lt;p&gt;→ &lt;strong&gt;Offline AI Cyberdeck Pack&lt;/strong&gt; — numbpilled.gumroad.com/l/offline-ai-cyberdeck-pack&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;For learning to see like they see:&lt;/strong&gt; If you want to understand the investigator mindset — the Dork Bible with 400+ operators, pivot workflows in Obsidian, and the AI toolkit I use for investigations. Learn offense to build better defense.&lt;/p&gt;

&lt;p&gt;→ &lt;strong&gt;OSINT Investigator Pack: Pivots + Dork Bible + Obsidian Workflows + AI Toolkit&lt;/strong&gt; — numbpilled.gumroad.com/l/osint-investigator-pack&lt;/p&gt;

&lt;p&gt;Stay boring out there.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>discuss</category>
      <category>privacy</category>
    </item>
    <item>
      <title>The Post-Privacy Internet: How to Be Untrackable in 2026</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Wed, 05 Aug 2026 13:57:27 +0000</pubDate>
      <link>https://dev.to/numbpill3d/the-post-privacy-internet-how-to-be-untrackable-in-2026-4ij2</link>
      <guid>https://dev.to/numbpill3d/the-post-privacy-internet-how-to-be-untrackable-in-2026-4ij2</guid>
      <description>&lt;p&gt;Privacy is dead. We just keep refreshing the obituary hoping for a correction.&lt;/p&gt;

&lt;p&gt;If you're reading this, you've already felt it. The ad that knew you were pregnant before your family did. The AI voice clone that called your mom. The recruiter who found your anonymous shitposting account from 2019 because you used the same avatar. &lt;/p&gt;

&lt;p&gt;We don't have a privacy problem anymore. We have a post-privacy condition. And the rules changed while we were all arguing about cookies.&lt;/p&gt;

&lt;p&gt;Welcome to 2026.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. You Are Not Being Tracked. You Are Being Rendered.
&lt;/h3&gt;

&lt;p&gt;The old mental model is killing you. You think tracking is a guy following you with binoculars. In 2026, it's an oil painting.&lt;/p&gt;

&lt;p&gt;Every data point you leak — your typing cadence, your scroll depth, your Wi-Fi probe requests, the way your phone's accelerometer twitches when you walk — is a brushstroke. No single stroke identifies you. But together? The model renders you in 4K.&lt;/p&gt;

&lt;p&gt;This is why your old privacy stack doesn't work. You installed a VPN in 2020 and felt like Edward Snowden. Cute.&lt;/p&gt;

&lt;p&gt;In 2026, the adversary isn't your ISP. It's a triad:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. The Corporate Mesh:&lt;/strong&gt; Google, Meta, Apple, Microsoft, plus 400 data brokers you've never heard of who trade your location history like Pokemon cards.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. The AI Scrapers:&lt;/strong&gt; Every public thing you've ever posted has been ingested, embedded, and turned into a searchable vector by 50 different startups building "people search" tools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. You.&lt;/strong&gt; Your metadata is the real rat. You use a private messenger but send photos with EXIF GPS intact. You use Tor but log into your personal Gmail in the same session. You wear a mask but keep your Bluetooth on.&lt;/p&gt;

&lt;p&gt;Untrackability isn't a product you buy. It's a discipline you practice. And it starts with understanding that anonymity is not secrecy. Anonymity is non-attributability.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. The Five Leaks That Actually Fuck You
&lt;/h3&gt;

&lt;p&gt;Forget what the VPN ads told you. Here are the leaks that get people doxxed, stalked, fired, and scammed in 2026.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leak #1: Your Browser is a Fingerprint Scanner&lt;/strong&gt;&lt;br&gt;
Your browser fingerprint is more unique than your actual fingerprint. Canvas, WebGL, fonts, screen resolution, timezone, battery API — even with a VPN, you stand out like a neon sign. If you're not using a hardened, uniform browser profile, you're not private.&lt;/p&gt;

&lt;p&gt;The fix isn't Brave out of the box. The fix is a browser that lies consistently. Mullvad Browser, or Firefox with Arkenfox, in its own isolated VM or container. One profile = one identity. Never cross-contaminate. Your normie browsing and your private work should not even know each other exist.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leak #2: Your Phone is a Loyal Dog That Barks Your Location to Everyone&lt;/strong&gt;&lt;br&gt;
Your phone pings cell towers, scans for Wi-Fi, begs for Bluetooth connections, and shares your precise location with 30 SDKs hidden in your flashlight app. Turning off "Location Services" is theater.&lt;/p&gt;

&lt;p&gt;Real mobile OPSEC in 2026 means compartmentalization. Your daily driver is compromised by definition. If you need actual privacy, you need a second device — de-Googled, GrapheneOS or CalyxOS, no SIM tied to your ID, faraday bag when not in use. Or at minimum: GrapheneOS user profiles, network permission toggled off for 90% of apps, and a personal rule that your phone never goes where you wouldn't want to be photographed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leak #3: Metadata Will Get You Killed (Professionally, Socially, Literally)&lt;/strong&gt;&lt;br&gt;
The content of your message is encrypted. Who you messaged, when, for how long, from where, and what file you attached? That's all in the clear, and it's more revealing than the message itself.&lt;/p&gt;

&lt;p&gt;A photo you took? Contains your camera model, lens, exact GPS, time, even your altitude. A PDF you exported? Contains your name, OS, and software version. A voice note? Contains your background noise signature.&lt;/p&gt;

&lt;p&gt;Learn to nuke it. Every file that leaves your device gets scrubbed. No exceptions. &lt;code&gt;ExifTool -all=&lt;/code&gt;. MAT2. And assume your AI assistant is logging everything unless it's running locally, offline, on your own hardware.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leak #4: Your AI Tools Are the Ultimate Fed&lt;/strong&gt;&lt;br&gt;
You outsourced your thinking to a cloud model that logs every prompt. Congratulations, you just created the most detailed dossier on yourself that has ever existed — your insecurities, your business ideas, your health questions, your search history on steroids.&lt;/p&gt;

&lt;p&gt;If your OSINT, your journaling, your research isn't happening locally, it's not private. Period. The move in 2026 is offline AI. A Pi 5 with an NVMe and a Hailo-8 accelerator running Llama 3 or Mistral locally will do 80% of what ChatGPT does with 0% of the surveillance. Air-gapped is the new incognito.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leak #5: Your Past Selves Are Betraying You&lt;/strong&gt;&lt;br&gt;
You can be perfect today and still get burned by 2017 you. Old forum accounts, reused usernames, password dumps, that one time you used your personal email for a crypto exchange — pivots are everything.&lt;/p&gt;

&lt;p&gt;Investigators don't start with you. They start with a username, an email hash, a phone number, and they pivot. HaveIBeenPwned, username enumeration, reverse image search, breach compilations. If you haven't audited your own digital trail with the same tools an adversary would use, you're not doing privacy, you're doing cosplay.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. The Untrackable Stack for 2026 (That Actually Works)
&lt;/h3&gt;

&lt;p&gt;So what does work? Not paranoia. Architecture.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Layer 1: Compartmentalize Your Lives&lt;/strong&gt;&lt;br&gt;
Stop trying to be one person who is "private." Be three people who never meet.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Public You:&lt;/strong&gt; LinkedIn, Instagram, real name. This is the sacrifice. Let the algorithm eat here.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Private You:&lt;/strong&gt; Friends, family, Signal, Proton. Real name but hardened. No public posts.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Nym You:&lt;/strong&gt; Research, writing, exploring, building. No link to the other two. Different hardware, different network, different writing style.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Use Qubes OS, or at least separate browser profiles + VPN + OS user accounts. If a compromise in one bleeds into the other, your compartmentalization failed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Layer 2: Fix the Network, For Real&lt;/strong&gt;&lt;br&gt;
A single VPN provider is a single point of failure. In 2026, you chain.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;You -&amp;gt; Mullvad VPN -&amp;gt; Tor -&amp;gt; Mullvad VPN Exit&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Or you run your own entry node. Use Nym or Tor for high-risk browsing, Mullvad/IVPN with no account for low-risk. Never free VPNs. If you're not paying with cash, crypto, or a burned email, you're the product.&lt;/p&gt;

&lt;p&gt;And for the love of god, use DNS over HTTPS with a non-logging resolver. Your ISP selling your DNS queries in 2026 is like leaving your diary at Starbucks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Layer 3: Go Ghost Mode IRL&lt;/strong&gt;&lt;br&gt;
Digital privacy without physical OPSEC is LARP.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Payment: Privacy.com virtual cards, Monero for things that need to be truly disconnected, cash for everything else. Your credit card history is a GPS track.&lt;/li&gt;
&lt;li&gt;Travel: No loyalty programs. No airport Wi-Fi without a VPN router. Toll tags are trackers. License plate readers are everywhere.&lt;/li&gt;
&lt;li&gt;Home: No smart speakers. Ever. Your TV is listening. Your Roomba is mapping your house and selling it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Layer 4: Become Unscrapable&lt;/strong&gt;&lt;br&gt;
You can't delete yourself from the internet. But you can poison the well.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Obfuscate: Use slightly different names, birthdays, and details on non-essential services.&lt;/li&gt;
&lt;li&gt;Reduce attack surface: Delete old accounts. Use SimpleLogin/AnonAddy aliases for everything. One service per alias. If one leaks, you know who sold you out.&lt;/li&gt;
&lt;li&gt;Opt-out: Hit every data broker opt-out page. It's tedious, but services like DeleteMe or Optery do the legwork. Do it quarterly.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  4. The Uncomfortable Truth
&lt;/h3&gt;

&lt;p&gt;You will never be 100% untrackable. If a three-letter agency is specifically targeting you with zero-day exploits and a $10 million budget, game over.&lt;/p&gt;

&lt;p&gt;But that's not your threat model. Your threat model is data brokers, AI scrapers, obsessive exes, cancel-culture archeologists, identity thieves, and a future where your health insurance premium is set by your grocery store purchases.&lt;/p&gt;

&lt;p&gt;Against &lt;em&gt;that&lt;/em&gt; adversary, you can win. Not by being invisible, but by being expensive to track. Make it cost $5,000 to figure you out instead of $5. Most adversaries will go bother someone easier.&lt;/p&gt;

&lt;p&gt;Privacy in 2026 isn't about having something to hide. It's about having something to protect: your ability to think, explore, and become someone new without your past selves and corporate overlords vetoing it in real time.&lt;/p&gt;

&lt;p&gt;The internet doesn't forget. But you can teach it to misremember you.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;If you want to go deeper than the theory — actual configs, workflows, and toolchains I use daily — I've put the whole system into a few dense, no-BS packs:&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;The Privacy/OPSEC Stack&lt;/em&gt;&lt;/strong&gt; &lt;em&gt;— my full NukePack, Ghost Mode protocols, OSINT pivots, metadata nuking workflow, and AI-native OSINT setup. The baseline for disappearing in 2026. → numbpilled.gumroad.com/l/privacy-opsec-stack&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;The Offline AI Cyberdeck Pack&lt;/em&gt;&lt;/strong&gt; &lt;em&gt;— how I built a fully offline AI lab: Pi 5 NVMe build, Hailo-8 accelerator, Pico W field kit, and a Pi cluster for local LLMs. No cloud, no logs. → numbpilled.gumroad.com/l/offline-ai-cyberdeck-pack&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;The OSINT Investigator Pack&lt;/em&gt;&lt;/strong&gt; &lt;em&gt;— flip the lens. The exact pivot chains, dork bible, Obsidian investigation templates, and AI toolkit I use to audit my own footprint (and others). → numbpilled.gumroad.com/l/osint-investigator-pack&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Stay untraceable out there.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>osint</category>
      <category>privacy</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>AI Is Moving From Finding Bugs to Fixing Them</title>
      <dc:creator>v. Splicer</dc:creator>
      <pubDate>Sat, 01 Aug 2026 16:34:49 +0000</pubDate>
      <link>https://dev.to/numbpill3d/ai-is-moving-from-finding-bugs-to-fixing-them-5bif</link>
      <guid>https://dev.to/numbpill3d/ai-is-moving-from-finding-bugs-to-fixing-them-5bif</guid>
      <description>&lt;p&gt;&lt;em&gt;For twenty years we built better smoke detectors. Now we are finally building firefighters.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;We have gotten incredibly good at finding problems.&lt;/p&gt;

&lt;p&gt;Your IDE underlines a vulnerability before you finish typing it. Your CI pipeline fails because a transitive dependency three levels deep has a CVE from 2019. Your inbox gets a Dependabot PR every Tuesday that you will politely ignore until Thursday. GitHub Advanced Security, Snyk, Semgrep, Wiz, Orca, Lacework, the alphabet soup of scanners has turned security into a very high resolution photograph of a burning building.&lt;/p&gt;

&lt;p&gt;We know exactly where the fire is. We have a heat map. We have a severity score. We have a CVSS vector that nobody reads.&lt;/p&gt;

&lt;p&gt;We just do not put it out.&lt;/p&gt;

&lt;p&gt;That is the strange era we are exiting.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Finding Economy Was Profitable
&lt;/h3&gt;

&lt;p&gt;The last decade of AppSec was built on an unspoken agreement: tools find, humans fix. It was a sensible division of labor when finding was hard. You needed abstract syntax trees, taint analysis, symbolic execution, and a PhD to explain why your Python string concatenation was actually remote code execution.&lt;/p&gt;

&lt;p&gt;So we built an entire economy around detection. Dashboards that count vulnerabilities. Leaderboards that shame teams for not triaging fast enough. Compliance frameworks that ask if you &lt;em&gt;know&lt;/em&gt; about your bugs, not if you fixed them. The metric of success became mean time to detect, not mean time to remediate.&lt;/p&gt;

&lt;p&gt;The result is predictable. The average enterprise has something like 50 to 100 days of open critical vulnerabilities, not because engineers are lazy, but because the funnel is fundamentally broken. You can generate ten thousand findings with a single scan. You cannot generate ten thousand fixes with a single engineer.&lt;/p&gt;

&lt;p&gt;Finding scales with compute. Fixing scales with humans. And humans do not scale.&lt;/p&gt;

&lt;p&gt;Anyone who has maintained an open source project knows this pain intimately. You get a beautiful, detailed issue report with a proof of concept, a CVSS score, and a polite note that you are endangering the internet. What you do not get is a patch that passes your tests, respects your architecture, and does not break the three weird edge cases only you know about.&lt;/p&gt;

&lt;p&gt;We celebrated the finder. We burned out the fixer.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why Fixing Is a Different Species of Problem
&lt;/h3&gt;

&lt;p&gt;It is tempting to think of fixing as finding plus one more step. It is not. It is a different cognitive task entirely.&lt;/p&gt;

&lt;p&gt;Finding is a pattern matching problem. Does this code look like that bad code I have seen before? Is user input flowing into a sensitive sink without sanitization? An LLM is shockingly good at this, because it has seen millions of examples of both good and bad code.&lt;/p&gt;

&lt;p&gt;Fixing is a planning and context problem. To fix a bug correctly you need to understand intent, not just syntax. You need to know what the original author was trying to do, what invariants the rest of the codebase relies on, what the test suite actually covers versus what it pretends to cover, and how to make the smallest possible change that closes the hole without opening two new ones.&lt;/p&gt;

&lt;p&gt;A bad fix is worse than no fix. A bad fix gives you false confidence and a new CVE with a different name.&lt;/p&gt;

&lt;p&gt;This is why early attempts at auto remediation felt like a Clippy for security. "It looks like you have a SQL injection, would you like me to add an ORM?" No, thank you.&lt;/p&gt;

&lt;p&gt;What changed is not that models got better at writing code, although they did. What changed is that they got better at operating tools. The new generation is not a chatbot that writes a diff. It is an agent that can reproduce the bug, write a test that fails because of it, edit the source, run the relevant tests, observe the failure, try again, and iterate until the green checkmarks come back.&lt;/p&gt;

&lt;p&gt;In other words, it can do the boring, methodical, unglamorous loop that human engineers actually do when they fix something. It just does not get tired at 2 AM.&lt;/p&gt;

&lt;h3&gt;
  
  
  We Are Entering the Patch Agent Era
&lt;/h3&gt;

&lt;p&gt;Look at what is happening at the edges.&lt;/p&gt;

&lt;p&gt;In open source, you now have agents that watch for new CVEs in your dependencies, check if you are actually exploitable, generate a minimal upgrade or patch, run your CI, and open a PR with a proper explanation. Not a version bump. A fix.&lt;/p&gt;

&lt;p&gt;In enterprise security, purple teams are using agents to continuously exploit their own apps, then immediately write the guardrail that would have stopped it. The feedback loop that used to take quarters now takes minutes.&lt;/p&gt;

&lt;p&gt;And in the lab, researchers are building self healing codebases. Systems where every night, an agent pulls the latest vulnerability feeds, clones your repos, tries to break in, and if it succeeds, patches itself, tests itself, and leaves a commit message that is more thorough than most of your interns. It is not science fiction anymore. It is just engineering that is slightly ahead of adoption.&lt;/p&gt;

&lt;p&gt;This is a profound shift in metaphor. We are moving from security as a camera to security as an immune system. A camera records an intruder. An immune system neutralizes it, remembers it, and gets better next time.&lt;/p&gt;

&lt;p&gt;The immune system model also understands something the camera model never did: you cannot fix everything. You have to prioritize by exploitability, by blast radius, by whether this service is actually exposed to the internet or buried behind three layers of auth that you swear are there. Agentic fixers are good at that triage, because triage is reasoning, not just ranking.&lt;/p&gt;

&lt;h3&gt;
  
  
  The Trust Problem Nobody Wants to Talk About
&lt;/h3&gt;

&lt;p&gt;Of course, there is a catch. And the catch is trust.&lt;/p&gt;

&lt;p&gt;Will you let an AI push code to main?&lt;/p&gt;

&lt;p&gt;Most teams will say no, correctly. The early adopters will have guardrails. Human in the loop approval. Restricted file paths. No changes to auth logic without a human review. Full test runs plus ephemeral preview environments plus semantic diff checks.&lt;/p&gt;

&lt;p&gt;But that boundary will move. We already let Dependabot merge patch updates automatically if tests pass. We already let Copilot write 40 percent of our code. At some point, the risk calculus flips. What is riskier: letting an agent patch a well understood path traversal in a well tested utility function, or leaving that path traversal open for 87 days while you wait for a human to find a free afternoon?&lt;/p&gt;

&lt;p&gt;We will learn to trust fixers the same way we learned to trust compilers. At first, people inspected the assembly output. Then they stopped, because the compiler made fewer mistakes than they did. We are not there yet for security patches, but we are walking that path.&lt;/p&gt;

&lt;p&gt;The teams that win will be the ones who build verification better than they build generation. The fix is not the hard part anymore. Proving the fix is correct, safe, and minimal, that is the product.&lt;/p&gt;

&lt;p&gt;Think property based tests that the agent generates alongside the patch. Think formal verification for small critical functions. Think second agent models whose only job is to try to break the first agent's patch. An adversarial system that looks a lot like the immune system again: attackers and defenders coevolving inside your CI.&lt;/p&gt;

&lt;h3&gt;
  
  
  What This Means for Humans
&lt;/h3&gt;

&lt;p&gt;If AI moves from finding bugs to fixing them, what do humans do?&lt;/p&gt;

&lt;p&gt;We do the work we were supposed to be doing all along. We stop acting like very expensive linters and start acting like architects.&lt;/p&gt;

&lt;p&gt;Humans will set policy: what is allowed to be auto fixed, what requires review, what risk tolerance we have for different systems. Humans will design systems that are easier to fix, smaller blast radius, better tested, more explicit about invariants. Humans will do the weird, cross system reasoning that agents are still bad at, like realizing that fixing this bug in service A will break an undocumented assumption in service B that finance relies on every quarter end.&lt;/p&gt;

&lt;p&gt;And perhaps most importantly, humans will be freed to do proactive security instead of reactive ticket closure. Threat modeling. Secure by design. Actually deleting code instead of endlessly patching it.&lt;/p&gt;

&lt;p&gt;The dream was never to have a dashboard with zero findings. The dream was to have systems that do not need a dashboard to stay safe.&lt;/p&gt;

&lt;p&gt;We spent twenty years shouting louder about fires. The next ten will be about buildings that do not burn.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;I build small, practical tools for this exact future, focused on defense, resilience, and systems that fix themselves.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;If you want to play with the ideas from this post:&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://numbpilled.gumroad.com/l/20dollarsoxc" rel="noopener noreferrer"&gt;The $20 SOC: Build a Tiny Defensive Network Monitor&lt;/a&gt; is how I think about affordable detection for home labs and small teams.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://numbpilled.gumroad.com/l/blackbox-offline-ai" rel="noopener noreferrer"&gt;Build the Blackbox: An Offline AI Field Terminal That Works When Nothing Else Does&lt;/a&gt; is my guide to building AI systems that work completely disconnected, which matters a lot when you are patching in hostile environments.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://numbpilled.gumroad.com/l/synthcorpo" rel="noopener noreferrer"&gt;Synthetic Corporation Defense: Purple-Team Your HR Before 500 Fake Employees Do&lt;/a&gt; covers the other side of the coin, when the attacker is AI generated too.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;And &lt;a href="https://numbpilled.gumroad.com/l/sel-healing-ai" rel="noopener noreferrer"&gt;Self-Healing Legion: AI That Finds and Patches Its Own CVEs While You Sleep&lt;/a&gt; is the full implementation of what I described here, an agentic legion that hunts and fixes its own vulnerabilities on autopilot.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>automation</category>
      <category>testing</category>
    </item>
  </channel>
</rss>
