<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Zane Beckett</title>
    <description>The latest articles on DEV Community by Zane Beckett (@zanebeckett).</description>
    <link>https://dev.to/zanebeckett</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3950922%2Ffc2b48b3-215b-4d9e-b374-a400e912a122.jpg</url>
      <title>DEV Community: Zane Beckett</title>
      <link>https://dev.to/zanebeckett</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zanebeckett"/>
    <language>en</language>
    <item>
      <title>You Don't Own Your Phone. You Don't Own Your Data. You Barely Own Your Opinions.</title>
      <dc:creator>Zane Beckett</dc:creator>
      <pubDate>Fri, 24 Jul 2026 21:41:52 +0000</pubDate>
      <link>https://dev.to/zanebeckett/you-dont-own-your-phone-you-dont-own-your-data-you-barely-own-your-opinions-32d0</link>
      <guid>https://dev.to/zanebeckett/you-dont-own-your-phone-you-dont-own-your-data-you-barely-own-your-opinions-32d0</guid>
      <description>&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Alex Voste&lt;br&gt;
&lt;strong&gt;Originally published on CoderLegion:&lt;/strong&gt; &lt;a href="https://coderlegion.com/23413/you-dont-own-your-phone-you-dont-own-your-data-you-barely-own-your-opinions" rel="noopener noreferrer"&gt;You Don't Own Your Phone. You Don't Own Your Data. You Barely Own Your Opinions.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Fair warning before the disclaimers even start: this one's a little long, a little uncomfortable, and not really written for someone who's going to bounce after the first two paragraphs. If you're still here by the end, you'll know things about your own phone that most people never bother to check.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;A disclaimer before we start, because apparently that's how it works now: this is one person's opinion, built on public facts and the collective paranoia of people who still bother reading terms of service. I'm not trying to cancel Google — please, Google, I'm a competent engineer, hire me, I'm kidding, I'm not kidding. I just think somebody should say the quiet part out loud before saying it becomes a compliance violation.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;A bigger, more boring disclaimer, because this one actually matters: everything below is built on real, checkable sources — court verdicts, regulator fines, academic research, and independent audit tools like Exodus Privacy. Where a specific claim couldn't be independently verified, I've labeled it explicitly as a theory or an unverified report, not a fact, and I'd rather under-claim than dress up a rumor as a courtroom finding. I also touch on identity-verification laws and proposals from a few different countries — Vietnam, the EU, Russia — purely as a technical and factual comparison of what each is doing and when. That's not a scorecard, and it's not me passing judgment on any government, political system, or policy choice. I'm not qualified to rule on sovereign lawmaking and I'm not trying to. This is a breakdown of mechanisms, not a verdict on the people who built them.&lt;/em&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  The myth everyone gets wrong (so let's kill it properly)
&lt;/h2&gt;

&lt;p&gt;Let's start with the thing you &lt;em&gt;think&lt;/em&gt; you know: "my phone is listening to me." You said "air fryer" out loud once and an ad for an air fryer showed up. Spooky, right?&lt;/p&gt;

&lt;p&gt;It's not spooky. It's worse.&lt;/p&gt;

&lt;p&gt;Every major platform — Meta, Google, Apple — has said on record, repeatedly, under oath in Meta's case, that they don't use your microphone to target ads. Independent security researchers have tested this claim for years, tearing apart thousands of apps looking for secret always-on listening, and they keep finding basically nothing. No hidden audio pipeline running in the background of TikTok. No microphone spyware baked into Instagram.&lt;/p&gt;

&lt;p&gt;Why? Because they don't need it. They already know you searched for kitchen gadgets three times last week, follow four cooking accounts, paused two seconds longer on a fryer ad last month, and that your friend with identical shopping habits just bought one. That's not surveillance through a microphone. That's a statistical ghost of you, built from years of clicks and dwell time, predicting your next move before you've made it. Ad tech doesn't need your voice. It has something better.&lt;/p&gt;

&lt;p&gt;That said — the myth isn't &lt;em&gt;entirely&lt;/em&gt; fantasy. A marketing outfit branded "Active Listening" got dragged in front of the FTC for claiming it could target ads via smart-device microphones in real time; the "service" turned out to be repackaged data-broker email lists sold at a markup, but the pitch decks named Google as a partner. Apple paid $95 million in a class-action settlement over Siri recordings potentially reaching third parties. Amazon is currently defending a federal class action in Seattle over Alexa recordings allegedly retained and used to train its AI models.&lt;/p&gt;

&lt;p&gt;So no, your phone probably isn't listening to your dinner plans. The industry built entirely around &lt;em&gt;not needing to&lt;/em&gt; listen is more unsettling, because there's no toggle for "please stop knowing me."&lt;/p&gt;

&lt;h2&gt;
  
  
  The receipts, because "trust me" isn't a source
&lt;/h2&gt;

&lt;p&gt;If this sounds like tinfoil-hat energy, here's what regulators and juries have actually done about it in the last few years — not allegations, verdicts and settled fact:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Meta / Cambridge Analytica.&lt;/strong&gt; A UK firm harvested the data of roughly 87 million Facebook users through a single quiz app, built psychological profiles from it, and sold political targeting off the back of it. The FTC fined Meta $5 billion — still one of the largest privacy penalties ever issued against a single company.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Meta / Flo period-tracking app.&lt;/strong&gt; In August 2025, a federal jury found Meta liable under a 1967 California wiretapping law for secretly collecting menstrual and pregnancy data from the Flo app — cycle dates, whether users were trying to conceive — through an embedded software kit, then using it for ad targeting. The jury needed three hours to decide Meta had eavesdropped without consent. Damages could run into the billions once the full class is counted.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Google / "Web &amp;amp; App Activity."&lt;/strong&gt; In September 2025, a San Francisco jury ordered Google to pay $425.7 million after finding it kept collecting data from about 98 million users across an eight-year stretch — even after those users had explicitly flipped the privacy switch meant to stop it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Amazon / Alexa Voice ID.&lt;/strong&gt; A federal judge in Chicago certified a class of roughly 1.18 million Illinois Alexa users in November 2025, over allegations that Amazon built biometric "voiceprints" from their voices without the written consent Illinois law requires.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Meta and Yandex / the localhost trick.&lt;/strong&gt; In 2025, researchers caught Meta's Facebook and Instagram apps — and Yandex's apps, reportedly since 2017 — quietly listening on local network ports on Android phones. Any website with a Meta Pixel or Yandex Metrica tracker could use this to silently hand your anonymous browsing session to the app sitting on your phone and stitch it to your actual identity. It worked straight through incognito mode, cookie clearing, and ad-ID resets — the three things privacy-conscious people are told will protect them. Meta paused it within days of the research going public, calling it a "miscommunication" about Google's policies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GDPR, cumulatively.&lt;/strong&gt; European regulators have now handed out more than €7 billion in fines since 2018, including a €1.2 billion penalty against Meta for unlawful US data transfers and €530 million against TikTok for sending EU user data to China. Enforcement isn't slowing down — more fines have hit small and mid-sized companies in the last three years than in GDPR's entire first five.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of this required a conspiracy theory. It required a courtroom, a jury, and people willing to read the fine print out loud.&lt;/p&gt;

&lt;h2&gt;
  
  
  VK: the eastern giant nobody in the West is watching
&lt;/h2&gt;

&lt;p&gt;Everything above is Western Big Tech getting dragged into courtrooms, mostly because Western courtrooms exist for that purpose and Western journalists chase that beat. But swap hemispheres and you find a mirror image: VKontakte (VK), the dominant social network across Russia and much of the CIS, running the same playbook with a different flag on it.&lt;/p&gt;

&lt;p&gt;Independent app-auditing tools like Exodus Privacy — which do static analysis on Android APKs to catalogue embedded tracking SDKs and requested permissions rather than take a developer's word for it — put VK's official Android app at &lt;strong&gt;16 separate tracker SDKs&lt;/strong&gt; and &lt;strong&gt;99 requested permissions&lt;/strong&gt; in its most recent scanned build (&lt;a href="https://reports.exodus-privacy.eu.org/en/reports/com.vkontakte.android/latest/" rel="noopener noreferrer"&gt;full report here&lt;/a&gt; — go look yourself, don't take my word for it). The tracker list alone reads like a cross-section of the entire ad industry: Google AdMob and Firebase Analytics, Yandex Ad, Huawei's HMS Core (which bundles location, advertising, and analytics in one package), plus ad-mediation networks like ironSource, Mintegral, and Unity3d Ads, alongside VK's own first-party identification SDK. The permissions list goes well past what a messaging-and-newsfeed app needs to function: precise GPS location, reading your call log, reading and writing your contacts and calendar (including a permission that explicitly lets the app "send email to guests without owners' knowledge" when it modifies calendar events), reading your phone number and device identity, recording audio, using the camera, and reading fitness data like step count and calories burned. Not all 99 are sinister on their own — plenty are mundane plumbing every app needs — but stacked together with 16 separate third-party trackers quietly reporting home, it's a genuinely large surface area for a platform whose stated job is "let people message their friends." Worth being precise about what VK actually is here, because it matters for how you read the rest of this: VK isn't just a private company that happens to be popular in Russia, it's a platform with formal ties to the Russian state and legal obligations to cooperate with its authorities on request, and unlike Meta or WhatsApp, VK's messages carry no end-to-end encryption at all — meaning that data, once collected, isn't just sitting in a corporate server somewhere abstract, it's structurally reachable by a government. That's a documented, publicly reported fact about how the platform is built and regulated, not a political opinion about Russia, and I'd say the exact same thing about any platform, in any country, built the same way. So if you're weighing which regional giant to worry about, the honest answer is: don't pick a side. East and West both built the same machine — they just answer to different governments when the machine gets audited.&lt;/p&gt;

&lt;h2&gt;
  
  
  A theory worth reading, not a verified fact
&lt;/h2&gt;

&lt;p&gt;While we're here — a claim that's been floating around tech circles that I want to flag &lt;em&gt;as&lt;/em&gt; a claim, not smuggle in as fact: reports have circulated alleging that in 2026, Meta ran an internal program collecting employee activity — keystrokes, screen content, even messages — from company laptops, ostensibly to train AI systems, and that some of those records ended up visible to a far larger internal audience than intended, triggering an employee petition. I haven't been able to independently verify the specifics — the numbers attached to it move depending on which forum you read — so take it exactly as advertised: an interesting, plausible-sounding story making the rounds, not a courtroom fact like the ones above. If true, it's the same surveillance logic Big Tech applies to its users, just pointed inward at the people building the tools. If it's exaggerated, it's still a useful thought experiment: what happens when the company that profiles you for a living starts applying the same instincts to its own staff?&lt;/p&gt;

&lt;h2&gt;
  
  
  The data doesn't have to be sold to end up in the wrong hands
&lt;/h2&gt;

&lt;p&gt;Right now, while you're reading this sentence, a screenshot of somebody's desktop is sitting on a server they never explicitly agreed to. Somewhere, a password nobody's changed in five years is sitting in a database that already leaked once. Statistically, given how many billions of records are already circulating, the odds that none of it is yours are getting worse every year, not better.&lt;/p&gt;

&lt;p&gt;Here's the part that ties everything above together, and it's arguably the most important one: none of this requires a company to be evil on purpose. Every dataset described in this post — location history, voiceprints, screenshots, browsing profiles, passport scans — sits somewhere on a server. And servers get breached. Constantly. At a scale that's honestly hard to hold in your head.&lt;/p&gt;

&lt;p&gt;2025 alone produced the largest credential leak ever recorded: roughly 16 billion login records — usernames, passwords, session tokens — pulled together from infostealer malware infections across services including Apple, Google, Facebook, and Telegram, surfacing on criminal marketplaces in June 2025. Separately, a data broker called National Public Data lost roughly 2.9 billion records covering an estimated 170 million people — full names, Social Security numbers, decades of address history (&lt;a href="https://www.ibm.com/think/news/national-public-data-breach-publishes-private-data-billions-us-citizens" rel="noopener noreferrer"&gt;IBM's writeup of the incident is worth a read&lt;/a&gt;) — and that dataset kept circulating on dark web markets throughout 2025, more than a year after the original breach. Qantas got hit in 2025 too: attackers social-engineered their way into a third-party customer service platform in June, and after the airline refused to pay a ransom, dumped roughly 5.7 million customer records — names, emails, birth dates, frequent-flyer numbers — onto the dark web that October (&lt;a href="https://www.cyberdaily.au/security/12759-qantas-hackers-dump-more-than-5-million-customer-records-to-clear-and-darkweb-leak-sites" rel="noopener noreferrer"&gt;Qantas's own public breach timeline confirms it&lt;/a&gt;). None of these companies wanted this to happen. It happened anyway, because a large enough pile of valuable data is, by definition, a target worth attacking.&lt;/p&gt;

&lt;p&gt;And this isn't hypothetical for the platform we just spent a whole section on. VK has been breached, leaked, or scraped repeatedly across more than a decade: around 100 million account credentials — plaintext passwords included — were stolen and put up for sale on the dark web for the price of a fast-food meal back in 2016 (&lt;a href="https://haveibeenpwned.com/Breach/VK" rel="noopener noreferrer"&gt;Have I Been Pwned has the full record&lt;/a&gt;); over 32 million scraped and API-pulled records, including data from supposedly private and closed profiles, surfaced in a 2022 leak; more than 390 million user records were dumped on a hacking forum in September 2024 (&lt;a href="https://cybernews.com/news/russian-state-owned-social-network-vk-breached/" rel="noopener noreferrer"&gt;Cybernews covered it in detail&lt;/a&gt;); and as recently as February 2026, researchers found malicious Chrome extensions had hijacked over half a million VK accounts to spread malware and manipulate security tokens. Whatever VK collects doesn't just sit in a vault under VK's control forever — history shows it eventually ends up copy-pasted onto a forum where anyone with a few dollars in cryptocurrency can buy it. And once your name, phone number, location history, or password is sitting in a criminal marketplace, it isn't used to sell you sneakers anymore. It's used for account takeovers, SIM-swap fraud, blackmail, and identity theft — by people with considerably worse intentions than an ad network.&lt;/p&gt;

&lt;p&gt;This is the actual argument for minimizing what gets collected in the first place, and it has nothing to do with distrusting any single company's intentions. It's just math: the less data exists about you in any one place, the less there is to steal when — not if — that place eventually gets broken into.&lt;/p&gt;

&lt;h2&gt;
  
  
  Windows would like to remember everything you've ever looked at
&lt;/h2&gt;

&lt;p&gt;Microsoft shipped a feature that screenshots your desktop every few seconds and uses on-device AI to let you search your own life like a browser history. It's called Recall. The first version stored everything in a folder, unencrypted, extractable by a two-minute script researchers named — I am not making this up — "TotalRecall." After the backlash, Microsoft rebuilt it: encrypted, tied to Windows Hello, wrapped in a hardware-isolated enclave, off by default.&lt;/p&gt;

&lt;p&gt;Great. Except security researchers have gone back in more than once and found new ways to reach the stored data anyway — most recently in early 2026. The pattern repeats: Microsoft hardens it, someone breaks it again, Microsoft patches it. The core problem was never really the encryption implementation. A running photographic log of everything you've ever typed or clicked is an extraordinarily attractive target no matter how good the lock is. A vault is still a vault worth robbing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Plot twist: your "no-logs" VPN might have a footnote
&lt;/h2&gt;

&lt;p&gt;Quick detour, because you're probably thinking "fine, I'll just get a VPN." Good instinct. Bad ending, sometimes.&lt;/p&gt;

&lt;p&gt;I actually did this — emailed a mid-market paid VPN provider (Russian-jurisdiction, "no-logs" is literally in their marketing) with one clean question: &lt;em&gt;do you store IP addresses and connection timestamps, and can you confirm no-logs in writing?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Their first reply: &lt;strong&gt;"We don't store or share client data with third parties."&lt;/strong&gt; Clean. Confident. Case closed, right?&lt;/p&gt;

&lt;p&gt;So I sent back their own privacy policy. Turns out their own terms define "processing" — using the exact wording from Russia's data protection law — as including &lt;em&gt;collection, storage, and retention.&lt;/em&gt; And their own clauses say IP addresses and login timestamps get "processed." And a separate clause says processing happens on Russian territory. And another says data gets handed over if Russian law requires it.&lt;/p&gt;

&lt;p&gt;Their second reply, paraphrased because their actual answer ran three defensive paragraphs: &lt;em&gt;"technically it's only in RAM, only for the session, destroyed after you disconnect, and we're legally required to use that wording from the law, we can't change it."&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Here's the part that matters and takes five seconds to understand: &lt;strong&gt;RAM is still storage.&lt;/strong&gt; If your IP and timestamp exist anywhere a system can read them — disk or memory, doesn't matter — while your session is active, and that system sits inside a jurisdiction that can legally compel a live extraction, then "no-logs" was never really a technical guarantee. It was a marketing sentence sitting on top of a legal document that says the opposite in its own words.&lt;/p&gt;

&lt;p&gt;I'm not naming the company, and I'm not telling you every VPN does this — plenty of providers publish real, independently audited no-logs reports and mean it. I'm telling you to do exactly what I did: ask the pointed question, then actually read the policy they hand you afterward, especially the definitions section. If "processing" quietly includes "storage" and the company sits under a jurisdiction with broad data-access laws, you haven't bought anonymity. You've bought a very polite waiting room.&lt;/p&gt;

&lt;h2&gt;
  
  
  Your phone is a rental, and you're the tenant who can't change the locks
&lt;/h2&gt;

&lt;p&gt;You paid full price — sometimes over a thousand dollars — for a device you don't fully control. Bootloaders are locked. Bloatware is preinstalled and often can't be removed without voiding a warranty or tripping hardware checks that quietly break your banking app. The manufacturer decides what OS you're allowed to run, which repair shops count as "authorized," and how long the device gets security updates before it's engineered into obsolescence. You're the owner on paper and the guest in practice. The device is the hook; your data and your next upgrade purchase are the actual product.&lt;/p&gt;

&lt;h2&gt;
  
  
  The passport paradox
&lt;/h2&gt;

&lt;p&gt;Here's where it gets genuinely interesting, and where I want to be careful, because this isn't a story with a villain — it's a story with a trade-off, and different countries are answering it completely differently at the same time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Vietnam&lt;/strong&gt; just did something almost nobody expected: starting January 1, 2026, its new Law on Personal Data Protection bans social platforms operating there — local or foreign — from requiring users to upload a photo of their ID card or passport just to verify an account. It also bans platforms from reading private messages or recording calls without consent. That's a real, enforceable ban with serious financial penalties attached. At the same time, Vietnam is separately rolling out rules requiring accounts to be linked to a verified local phone number or national ID number for anti-fraud purposes. So the picture isn't "more privacy" or "less privacy" — it's "no more handing platforms a photo of your actual passport," while identity still gets tied to you through a different, arguably less exploitable channel. Genuinely nuanced, genuinely worth watching.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Europe&lt;/strong&gt; took the opposite visual approach for an entirely different reason. In early 2026, a new EU-based platform called W Social launched as a deliberate alternative to X, built specifically to be bot-resistant: to post, you verify your identity by scanning a passport or national ID card and a selfie through a separate companion app. The pitch is that the scan and match happen on your own device, and the company says it doesn't store the document itself centrally — you can also browse anonymously with reduced functionality if you skip verification entirely. Whether "we process it locally and don't store it" survives contact with millions of users and a few years of pressure is exactly the kind of promise worth revisiting in twelve months. It's the same core question as always — how much of "prove you're human" ends up as "here's your permanent identity record" — just answered by a private company instead of a government this time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Russia's telecom regulator, Roskomnadzor&lt;/strong&gt;, put forward a proposal back in 2021 that would have required new social media and messenger users to submit passport details, home address, and contact information, cross-checked against the state's Gosuslugi portal, as part of consent-management infrastructure for personal data. To be clear about where this actually stands: it was a draft proposal, not a law that took effect, and it hasn't been implemented as originally floated. I'm not going to pretend to have a verdict on whether that specific idea was good policy or bad policy — plenty of countries debate identity requirements for online services, for all kinds of legitimate and illegitimate reasons, and that's a conversation about tradeoffs, not a referendum on any one government. What's actually worth sitting with is the pattern above it: state ID portals, private "trust and safety" platforms, and social networks are all reaching for the same solution — link your face and your legal identity to your online activity — at almost exactly the same moment, for reasons ranging from fighting bots to fighting fraud to fighting disinformation. Some of those reasons are good. The output is still the same: your passport, your biometrics, and your posting history increasingly living in the same place.&lt;/p&gt;

&lt;p&gt;And that's the actual tension, stripped of any single country's politics: identity verification is a genuinely reasonable answer to bots, fraud, and disinformation. It is also, structurally, a new centralized target. So next time something asks you to prove you're human, the interesting question isn't whether they have a good reason today. It's what happens to that proof on the day their reason stops mattering. You don't need me to answer that one for you — but here's a hint: databases don't retire. They just wait.&lt;/p&gt;

&lt;h2&gt;
  
  
  So what do we actually do about it?
&lt;/h2&gt;

&lt;p&gt;Here's the part where I disappoint anyone expecting a manifesto: I'm not telling you to throw your phone in a lake and move to a cabin. I use the apps too. I like fast information and dumb memes as much as anyone. This isn't a call to abandon convenience — it's a call to stop pretending the convenience is free.&lt;/p&gt;

&lt;p&gt;You can also do nothing. Close the tab, keep scrolling, change nothing — that's a real option and nobody's coming to stop you. Or you can spend the next two minutes doing this, right now, before you close this tab:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open your phone's settings.&lt;/li&gt;
&lt;li&gt;Pick one app you use daily — VK, Instagram, whatever's already open in another tab.&lt;/li&gt;
&lt;li&gt;Turn off its access to your microphone, contacts, and location if the app doesn't strictly need them to function.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Done. That's it. You just did more for your own privacy in two minutes than most people will do all year. Not a revolution. Not a lake cabin. Just one small door you closed that used to be wide open.&lt;/p&gt;

&lt;p&gt;A few more things that cost five minutes each and nothing beyond that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Turn off ad personalization&lt;/strong&gt; in your Google, Meta, and TikTok settings. It doesn't stop collection, but it shrinks the targeting surface.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Use a real password manager and 2FA.&lt;/strong&gt; Most "hacks" are just reused passwords from a breach nobody rotated.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Read one privacy policy this year.&lt;/strong&gt; Just one. You'll never look at "free" the same way again.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;If you're a developer, push back inside your own stack.&lt;/strong&gt; You decide what telemetry ships in the product you build. That's more power than most people in this conversation will ever have.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Here's the uncomfortable part, though. You probably think of yourself as a person — opinions, habits, a face. Every system described in this post thinks of you as a row. A data point with a name attached purely for convenience. You don't have to agree with that framing. But once you've actually sat with it for a second, it's a little harder to just close the tab and pretend you didn't read this.&lt;/p&gt;

&lt;h2&gt;
  
  
  Now, about why you actually read this whole thing
&lt;/h2&gt;

&lt;p&gt;Since we're being honest with each other: this post used a specific structure on purpose, and it's worth naming, because recognizing the pattern here is the same skill that protects you from the next one.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;It opened with a myth I could confidently debunk&lt;/strong&gt; — trust, earned fast.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It escalated with dollar figures and jury verdicts&lt;/strong&gt; — specificity that reads as credibility, whether or not you checked it yourself (you should).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It made the threat feel like it's happening to you, right now&lt;/strong&gt;, not to some abstract "user out there."&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It gave you a way out that felt like a choice, not an order&lt;/strong&gt; — do nothing, or spend two minutes. Either way, you decided.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It handed you one small, immediate action&lt;/strong&gt; instead of a vague suggestion, because five minutes of resistance beats another lecture you'll forget by tomorrow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It pulled you into an unresolved debate&lt;/strong&gt; — the passport paradox — with no clean villain, because open loops keep people reading.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It's closing on a moment of "wait, is &lt;em&gt;this&lt;/em&gt; article doing the thing it just described"&lt;/strong&gt; — a little vertigo is what makes people screenshot something and send it to a friend.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of that makes the verified parts above less true. The Flo verdict happened. The $425 million happened. The localhost tracking happened. I flagged the one item I couldn't fully verify as exactly that — a claim, not a fact — because the moment you stop distinguishing the two, you've become exactly the kind of unreliable narrator this whole post is warning you about. But the fact that true information can be arranged to hook you exactly like an ad can is, honestly, the whole point of this post. The mechanism doesn't care whether the payload is a sneaker ad or a privacy manifesto. Worth remembering the next time something online makes you feel like you &lt;em&gt;have&lt;/em&gt; to keep scrolling — including this one.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;One last note, plainly stated: everything in this piece is either a matter of public court record, a regulatory decision, published academic research, or the output of an open, independently verifiable auditing tool that anyone can run themselves — sources are linked or named where they exist specifically so you don't have to trust me. The one exception is flagged inline as an unverified claim, not presented as fact. This is a personal, informational write-up, not legal advice, not a security audit of any product named here, and not a statement about the character, intentions, or legitimacy of any company or government mentioned. Company names, product names, and country names appear because they're the ones with public data behind them — not because I'm accusing anyone of anything beyond what's already a matter of public record. If something here is factually wrong, I'd rather be corrected than be right — go check the sources, that's what they're there for.&lt;/em&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>ForgeZero Now Supports musl Cross-Compilation and Objective-C on Linux</title>
      <dc:creator>Zane Beckett</dc:creator>
      <pubDate>Sat, 06 Jun 2026 08:55:36 +0000</pubDate>
      <link>https://dev.to/zanebeckett/forgezero-now-supports-musl-cross-compilation-and-objective-c-on-linux-1025</link>
      <guid>https://dev.to/zanebeckett/forgezero-now-supports-musl-cross-compilation-and-objective-c-on-linux-1025</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8na16bu6yqevfcsm9c55.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8na16bu6yqevfcsm9c55.png" alt=" " width="799" height="309"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  🚀 ForgeZero Now Supports musl Cross-Compilation and Objective-C on Linux
&lt;/h1&gt;

&lt;p&gt;I've been spending the last few weeks improving &lt;strong&gt;ForgeZero&lt;/strong&gt;, adding support for more toolchains and making cross-platform development a little easier.&lt;/p&gt;

&lt;p&gt;The latest update introduces two features that I wanted for quite some time:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;✅ &lt;strong&gt;musl cross-compilation&lt;/strong&gt; powered by the Zig toolchain&lt;/li&gt;
&lt;li&gt;✅ &lt;strong&gt;Objective-C support on Linux&lt;/strong&gt; with automatic compiler and linker selection&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The best part? &lt;strong&gt;No additional configuration is required.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Just write your code and let ForgeZero handle the rest.&lt;/p&gt;




&lt;h1&gt;
  
  
  Static musl Builds
&lt;/h1&gt;

&lt;p&gt;ForgeZero can now generate &lt;strong&gt;fully static musl binaries&lt;/strong&gt;, making cross-compilation almost effortless.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;fz &lt;span class="nt"&gt;-cc&lt;/span&gt; main.c &lt;span class="nt"&gt;-musl&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;riscv64 &lt;span class="nt"&gt;-toolchain&lt;/span&gt; zig
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The resulting binary:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;main: ELF 64-bit LSB executable, UCB RISC-V, RVC, double-float ABI, version 1 (SYSV), statically linked, with debug_info, not stripped
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Static binaries are incredibly useful when building:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🐳 Minimal Docker images (&lt;code&gt;scratch&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;📦 Portable standalone executables&lt;/li&gt;
&lt;li&gt;🔌 Embedded &amp;amp; IoT applications&lt;/li&gt;
&lt;li&gt;🖥️ Systems without glibc&lt;/li&gt;
&lt;li&gt;🌍 Cross-platform deployment pipelines&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Using &lt;strong&gt;Zig&lt;/strong&gt; as the backend compiler makes targeting different architectures surprisingly simple while keeping the ForgeZero interface exactly the same.&lt;/p&gt;




&lt;h1&gt;
  
  
  Objective-C on Linux
&lt;/h1&gt;

&lt;p&gt;This is probably the feature I'm most excited about.&lt;/p&gt;

&lt;p&gt;ForgeZero now automatically detects &lt;strong&gt;&lt;code&gt;.m&lt;/code&gt; Objective-C source files&lt;/strong&gt; and switches to the correct compilation pipeline without requiring any flags.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;fz &lt;span class="nt"&gt;-cc&lt;/span&gt; main.m
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Verbose output:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Objective-C detected!
Bypassing Zig linker to use Clang with -lobjc

Running:
clang main.o -o main -lobjc -Wl,--build-id=none

Built: main
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No custom scripts.&lt;/p&gt;

&lt;p&gt;No Makefiles.&lt;/p&gt;

&lt;p&gt;No manually remembering linker flags.&lt;/p&gt;

&lt;p&gt;ForgeZero simply detects the language and invokes the correct backend automatically.&lt;/p&gt;




&lt;h1&gt;
  
  
  Why Objective-C?
&lt;/h1&gt;

&lt;p&gt;Most developers associate Objective-C exclusively with macOS and Apple's ecosystem.&lt;/p&gt;

&lt;p&gt;However, &lt;strong&gt;GNU Objective-C works perfectly fine on Linux&lt;/strong&gt; through Clang and &lt;code&gt;libobjc&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Supporting it means ForgeZero can now build another systems programming language using exactly the same interface as C or Assembly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;fz &lt;span class="nt"&gt;-cc&lt;/span&gt; hello.c
fz &lt;span class="nt"&gt;-cc&lt;/span&gt; hello.m
fz &lt;span class="nt"&gt;-asm&lt;/span&gt; boot.asm
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The command stays the same—the build pipeline adapts automatically.&lt;/p&gt;




&lt;h1&gt;
  
  
  Where ForgeZero is Going
&lt;/h1&gt;

&lt;p&gt;ForgeZero originally started as a tiny utility to avoid typing endless compiler and linker commands.&lt;/p&gt;

&lt;p&gt;Over time, it has evolved into a unified build frontend capable of orchestrating multiple toolchains while automatically selecting the right backend for the current source language.&lt;/p&gt;

&lt;p&gt;The philosophy remains simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Write code, run one command, and let the build system figure out the details.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;There's still a lot of work ahead, but I'm happy with the direction the project is taking.&lt;/p&gt;




&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;p&gt;⭐ &lt;strong&gt;GitHub &amp;amp; Documentation:&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://github.com/forgezero-cli/forgezero" rel="noopener noreferrer"&gt;https://github.com/forgezero-cli/forgezero&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;👤 &lt;strong&gt;Author:&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://github.com/alexvoste" rel="noopener noreferrer"&gt;https://github.com/alexvoste&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Feedback, ideas, and contributions are always welcome.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Gloria JIT v4.4.0 — Bare-Metal Control, Memory Primitives, and Structured Flow</title>
      <dc:creator>Zane Beckett</dc:creator>
      <pubDate>Mon, 01 Jun 2026 22:23:30 +0000</pubDate>
      <link>https://dev.to/zanebeckett/gloria-jit-v440-bare-metal-control-memory-primitives-and-structured-flow-5oc</link>
      <guid>https://dev.to/zanebeckett/gloria-jit-v440-bare-metal-control-memory-primitives-and-structured-flow-5oc</guid>
      <description>&lt;h2&gt;
  
  
  What is Gloria JIT?
&lt;/h2&gt;

&lt;p&gt;Gloria JIT is a low-level programming language and compiler that is part of the &lt;a href="https://dev.to/alexvoste"&gt;ForgeZero&lt;/a&gt; ecosystem. It is written in Go and compiles source code directly to x86-64 machine code — no LLVM, no GCC, no Clang in the middle.&lt;/p&gt;

&lt;p&gt;The goal is straightforward: give the programmer direct, unmediated control over the machine. No intermediate representation handed off to a third-party backend. No optimizer making decisions you didn't ask for. The compiler emits raw bytes, and those bytes run.&lt;/p&gt;

&lt;p&gt;This makes Gloria JIT an interesting project for anyone curious about how compilers actually work, or for developers who want to explore bare-metal programming without the abstraction layers that most toolchains introduce.&lt;/p&gt;

&lt;p&gt;v4.4.0 expands the language significantly, adding structured control flow, direct memory and I/O access, and a bare-metal output path for VGA framebuffer writing.&lt;/p&gt;




&lt;h2&gt;
  
  
  &lt;code&gt;while&lt;/code&gt; Loops — Structured Control Flow
&lt;/h2&gt;

&lt;p&gt;Before this release, repeated execution required manual branching. v4.4.0 adds proper &lt;code&gt;while&lt;/code&gt; loops.&lt;/p&gt;

&lt;p&gt;A loop runs as long as its condition is non-zero. Inside the loop body you can use standard assignment and mutation operators (&lt;code&gt;=&lt;/code&gt;, &lt;code&gt;+=&lt;/code&gt;, &lt;code&gt;-=&lt;/code&gt;), and built-in calls are permitted as well. This is a meaningful step toward the kind of control flow you'd expect from a general-purpose language.&lt;/p&gt;




&lt;h2&gt;
  
  
  Memory Primitives — &lt;code&gt;peek&lt;/code&gt; and &lt;code&gt;poke&lt;/code&gt;
&lt;/h2&gt;

&lt;p&gt;Two new built-in functions expose direct memory access:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;peek(address)&lt;/code&gt; — reads a 16-bit value from the given address&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;poke(address, value)&lt;/code&gt; — writes a 16-bit value to the given address&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Both accept either immediate values or runtime variables as arguments.&lt;/p&gt;

&lt;p&gt;This is the kind of primitive that exists in very few high-level languages, but is essential for bare-metal work — writing to hardware registers, inspecting memory-mapped I/O, or building your own allocator from scratch. Handle with care.&lt;/p&gt;




&lt;h2&gt;
  
  
  x86-64 Port I/O
&lt;/h2&gt;

&lt;p&gt;For environments that use port-mapped I/O (common in older PC hardware and embedded x86 systems), two new built-ins are available:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;in8(port)&lt;/code&gt; — reads a single byte from the given I/O port (zero-extended)&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;out8(port, value)&lt;/code&gt; — writes a byte to the given I/O port&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This enables direct hardware interaction at a level that most programming languages simply do not expose.&lt;/p&gt;




&lt;h2&gt;
  
  
  VGA Framebuffer Output
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;print(string)&lt;/code&gt; now supports a bare-metal execution path that writes directly to the VGA text buffer at memory address &lt;code&gt;0xB8000&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;For context: on x86 PCs, this address is where text-mode video memory lives. Writing bytes there places characters directly on screen — no operating system, no drivers, no system calls involved. This is how early PC software (and modern bootloaders) produce output.&lt;/p&gt;

&lt;p&gt;Details of the implementation:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Default text color is green (&lt;code&gt;0x0A&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Register &lt;code&gt;R15&lt;/code&gt; is reserved as a cursor offset and is preserved across calls&lt;/li&gt;
&lt;li&gt;Escape sequences &lt;code&gt;\n&lt;/code&gt; and &lt;code&gt;\t&lt;/code&gt; are resolved at compile time into the appropriate control characters&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;To support testing without real hardware, two utilities are included: &lt;code&gt;patchVGA()&lt;/code&gt; swaps the real framebuffer address for a heap-allocated buffer, and &lt;code&gt;dumpVGA()&lt;/code&gt; renders that buffer to stdout via a direct syscall, with zero heap allocations.&lt;/p&gt;




&lt;h2&gt;
  
  
  Register Constants
&lt;/h2&gt;

&lt;p&gt;To reduce ambiguity in the backend IR and make generated code easier to reason about, named constants have been introduced for all general-purpose x86-64 registers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;regRAX(0), regRCX(1), regRDX(2), regRBX(3),
regRSP(4), regRBP(5), regRSI(6), regRDI(7),
regR8(8) ... regR15(15)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Internal Changes
&lt;/h2&gt;

&lt;p&gt;A few backend improvements shipped alongside the language features:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;emitLowLevelPrint&lt;/code&gt; now accepts a &lt;code&gt;kernelMode&lt;/code&gt; flag to switch between syscall-based output and direct VGA writes&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;emitPushReg&lt;/code&gt; and &lt;code&gt;emitPopReg&lt;/code&gt; now cover the full register set including R8–R15&lt;/li&gt;
&lt;li&gt;New operations: &lt;code&gt;emitMovMemToReg64&lt;/code&gt;, &lt;code&gt;emitMovRegToMem64&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;parseStringLiteral&lt;/code&gt; handles escape sequences at compile time rather than at runtime&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;emitBareMetalPrint&lt;/code&gt; introduced for the VGA output path&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Where This Is Heading
&lt;/h2&gt;

&lt;p&gt;With v4.4.0, Gloria JIT operates in two modes simultaneously: as a userspace compiler with kernel-aware syscall output, and as a bare-metal code generator capable of running without an operating system underneath it.&lt;/p&gt;

&lt;p&gt;The next focus areas are optimization passes and IR stability. If you're interested in how compilers work from the ground up — or in low-level x86 programming without giving up a proper language — this is worth following.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Gloria JIT is part of the ForgeZero project. Follow along on &lt;a href="https://dev.to/alexvoste"&gt;dev.to/alexvoste&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>compilers</category>
      <category>lowlevel</category>
      <category>x86</category>
      <category>go</category>
    </item>
    <item>
      <title>ForgeZero 4.1 vs GNU Make: Up to 4.5x Faster Build Performance</title>
      <dc:creator>Zane Beckett</dc:creator>
      <pubDate>Tue, 26 May 2026 13:37:57 +0000</pubDate>
      <link>https://dev.to/zanebeckett/forgezero-41-vs-gnu-make-up-to-45x-faster-build-performance-2664</link>
      <guid>https://dev.to/zanebeckett/forgezero-41-vs-gnu-make-up-to-45x-faster-build-performance-2664</guid>
      <description>&lt;h1&gt;
  
  
  ForgeZero 4.1 vs GNU Make: Up to 4.5x Faster Build Performance
&lt;/h1&gt;

&lt;p&gt;I've been working on &lt;strong&gt;ForgeZero&lt;/strong&gt;, a modern build system designed to replace traditional &lt;code&gt;make&lt;/code&gt; with a faster, zero-config approach.&lt;/p&gt;

&lt;p&gt;With the release of &lt;strong&gt;ForgeZero 4.1&lt;/strong&gt;, I benchmarked it against GNU Make on multiple machines to answer one simple question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can a modern build system still significantly outperform &lt;code&gt;make&lt;/code&gt; in 2025?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Turns out: &lt;strong&gt;yes&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Benchmark setup
&lt;/h2&gt;

&lt;h3&gt;
  
  
  GNU Make
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;make &lt;span class="nt"&gt;-j4&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  ForgeZero
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;./fzt &lt;span class="nt"&gt;-dir&lt;/span&gt; &lt;span class="nb"&gt;.&lt;/span&gt; &lt;span class="nt"&gt;-out&lt;/span&gt; fz_out
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Measurement tool
&lt;/h3&gt;

&lt;p&gt;Benchmarks were run using &lt;a href="https://github.com/sharkdp/hyperfine" rel="noopener noreferrer"&gt;&lt;code&gt;hyperfine&lt;/code&gt;&lt;/a&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;hyperfine &lt;span class="s1"&gt;'./fzt -dir . -out fz_out'&lt;/span&gt; &lt;span class="s1"&gt;'make -j4'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fa5hmv2hlqh7zeojmrfth.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fa5hmv2hlqh7zeojmrfth.png" alt=" " width="800" height="408"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h1&gt;
  
  
  Results
&lt;/h1&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Platform&lt;/th&gt;
&lt;th&gt;ForgeZero&lt;/th&gt;
&lt;th&gt;GNU Make&lt;/th&gt;
&lt;th&gt;Speedup&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Ryzen 9 7950X3D (KVM, 1 vCPU)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;~80–84 ms&lt;/td&gt;
&lt;td&gt;~350–364 ms&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;4.1x–4.5x&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Intel Core i5-10310U&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;82.2 ms&lt;/td&gt;
&lt;td&gt;291.1 ms&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;3.54x&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;AMD FX-8370E (AM3+)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;111.0 ms&lt;/td&gt;
&lt;td&gt;238.5 ms&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;2.15x&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Across very different CPUs and environments, ForgeZero consistently outperformed GNU Make.&lt;/p&gt;




&lt;h1&gt;
  
  
  Example benchmark output
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Ryzen 9 7950X3D
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Benchmark 1: ./fzt -dir . -out fz_out
Time (mean ± σ): 84.5 ms ± 7.6 ms

Benchmark 2: make -j4
Time (mean ± σ): 350.4 ms ± 16.4 ms

Summary:
4.14x faster than make -j4
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Intel i5-10310U
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Benchmark 1: ./fzt -dir . -out fz_out
Time (mean ± σ): 82.2 ms ± 4.2 ms

Benchmark 2: make -j4
Time (mean ± σ): 291.1 ms ± 11.2 ms

Summary:
3.54x faster than make -j4
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  AMD FX-8370E
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Benchmark 1: ./fzt -dir . -out fz_out
Time (mean ± σ): 111.0 ms ± 17.9 ms

Benchmark 2: make -j4
Time (mean ± σ): 238.5 ms ± 24.4 ms

Summary:
2.15x faster than make -j4
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  Why is ForgeZero faster?
&lt;/h1&gt;

&lt;h2&gt;
  
  
  1. No shell overhead
&lt;/h2&gt;

&lt;p&gt;GNU Make spends a surprising amount of time spawning shell processes (&lt;code&gt;fork/exec&lt;/code&gt;) for build commands.&lt;/p&gt;

&lt;p&gt;ForgeZero executes the build pipeline directly.&lt;/p&gt;

&lt;p&gt;No unnecessary shell orchestration.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Lightweight dependency graph
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;make&lt;/code&gt; still carries decades of legacy behavior:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Makefile parsing&lt;/li&gt;
&lt;li&gt;implicit rules&lt;/li&gt;
&lt;li&gt;pattern matching&lt;/li&gt;
&lt;li&gt;recursive variable expansion&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;ForgeZero builds a direct dependency graph and updates only what actually changed.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Better task scheduling
&lt;/h2&gt;

&lt;p&gt;Instead of the classic &lt;code&gt;make -j&lt;/code&gt; job model, ForgeZero uses a lightweight internal scheduler with lower synchronization overhead.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Zero-config design
&lt;/h2&gt;

&lt;p&gt;No giant Makefiles.&lt;/p&gt;

&lt;p&gt;No boilerplate.&lt;/p&gt;

&lt;p&gt;ForgeZero analyzes project structure automatically and starts building immediately.&lt;/p&gt;




&lt;h1&gt;
  
  
  Why this matters
&lt;/h1&gt;

&lt;p&gt;&lt;code&gt;make&lt;/code&gt; was introduced in &lt;strong&gt;1976&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Almost 50 years later, many developers still accept build-system latency as unavoidable.&lt;/p&gt;

&lt;p&gt;These benchmarks suggest otherwise.&lt;/p&gt;

&lt;p&gt;If your team runs hundreds of builds per day—locally and in CI—even saving &lt;strong&gt;100–250 ms per build&lt;/strong&gt; adds up quickly.&lt;/p&gt;




&lt;h1&gt;
  
  
  ForgeZero 4.1 is available
&lt;/h1&gt;

&lt;p&gt;GitHub:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/forgezero-cli/forgezero" rel="noopener noreferrer"&gt;https://github.com/forgezero-cli/forgezero&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'd love feedback from developers still using &lt;code&gt;make&lt;/code&gt;, &lt;code&gt;ninja&lt;/code&gt;, or other build systems.&lt;/p&gt;

</description>
      <category>devops</category>
      <category>performance</category>
      <category>showdev</category>
      <category>tooling</category>
    </item>
    <item>
      <title>Zero Heap Allocations at 1.18 GB/s: Deep Dive into ForgeZero 4.0.x</title>
      <dc:creator>Zane Beckett</dc:creator>
      <pubDate>Mon, 25 May 2026 15:14:42 +0000</pubDate>
      <link>https://dev.to/zanebeckett/zero-heap-allocations-at-118-gbs-deep-dive-into-forgezero-40x-3emp</link>
      <guid>https://dev.to/zanebeckett/zero-heap-allocations-at-118-gbs-deep-dive-into-forgezero-40x-3emp</guid>
      <description>&lt;p&gt;What happens when you migrate a system tool from pure Node.js to Go, strip out the standard GC-heavy paths, and force a file system engine to hit &lt;strong&gt;0 allocs/op&lt;/strong&gt;?&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fylu2eezgd8y4yfesopx5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fylu2eezgd8y4yfesopx5.png" alt=" " width="800" height="468"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fa1sbrfbnfivlh7dro7dy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fa1sbrfbnfivlh7dro7dy.png" alt=" " width="800" height="528"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You get &lt;strong&gt;ForgeZero&lt;/strong&gt; (&lt;code&gt;fz&lt;/code&gt;) — an open-source bare-metal system software builder created by &lt;a href="https://github.com/AlexVoste" rel="noopener noreferrer"&gt;@AlexVoste&lt;/a&gt;. Designed to eliminate bloated Makefiles for low-level developers, it orchestrates NASM, GAS, FASM, GCC, and Clang concurrently under a single unified &lt;code&gt;.fz.yaml&lt;/code&gt; configuration.&lt;/p&gt;

&lt;p&gt;With the recent launch of &lt;strong&gt;version 4.0&lt;/strong&gt; and its subsequent &lt;strong&gt;4.0.1 patch&lt;/strong&gt;, the project underwent a radical low-level optimization sprint targeting Go's runtime overhead.&lt;/p&gt;

&lt;p&gt;Here's a technical breakdown of how it achieves near-native bare-metal execution speeds.&lt;/p&gt;




&lt;h2&gt;
  
  
  ⚡ The Benchmark Reality Check
&lt;/h2&gt;

&lt;p&gt;Running on an Arch Linux testbed (Intel i5-10310U), the updated engine delivers striking performance metrics:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Result&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Data throughput&lt;/td&gt;
&lt;td&gt;~1.18 GB/s steady state&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File hashing (100 MB payload)&lt;/td&gt;
&lt;td&gt;~78–84 ms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory footprint&lt;/td&gt;
&lt;td&gt;
&lt;strong&gt;0 allocs/op&lt;/strong&gt; across all hot-path runs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;goos: linux
goarch: amd64
BenchmarkHadesEngine/Process100MB-8   14   78411200 ns/op   0 B/op   0 allocs/op
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;By completely avoiding heap allocations on critical execution paths, the application bypasses Go's Garbage Collector entirely — achieving &lt;strong&gt;deterministic latency&lt;/strong&gt; similar to C or Rust.&lt;/p&gt;




&lt;h2&gt;
  
  
  🛠️ The Architecture: Under the Hood of HADES
&lt;/h2&gt;

&lt;p&gt;To pull off &lt;code&gt;0 allocs/op&lt;/code&gt; while scanning deeply nested directory structures and executing multiple sub-processes, the compiler architecture leans on three internal layers.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. The HADES Engine &amp;amp; Memory Re-use
&lt;/h3&gt;

&lt;p&gt;The file system sub-engine (&lt;code&gt;fs&lt;/code&gt;, &lt;code&gt;seal&lt;/code&gt;, and the linker/assembler modules) was fully overhauled. Instead of spawning new byte slices or strings during recursive scans, ForgeZero:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Pre-allocates &lt;strong&gt;localized memory arenas&lt;/strong&gt; and sliding ring buffers&lt;/li&gt;
&lt;li&gt;Handles path strings via direct &lt;code&gt;string&lt;/code&gt;-to-&lt;code&gt;[]byte&lt;/code&gt; headers (&lt;code&gt;unsafe.Pointer&lt;/code&gt;), dodging the typical heap allocation penalty associated with dynamic string manipulation in Go&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Multi-Engine Concurrency &amp;amp; Automated Fallbacks
&lt;/h3&gt;

&lt;p&gt;ForgeZero dynamically parallelizes multi-file assembly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Single file:&lt;/strong&gt; matches input files directly to object targets (&lt;code&gt;fz -asm boot.asm&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Directory:&lt;/strong&gt; parses whole structures recursively (&lt;code&gt;fz -dir ./src&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The engine also implements an aggressive &lt;strong&gt;link-level degradation system&lt;/strong&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Try &lt;code&gt;gcc&lt;/code&gt; compilation&lt;/li&gt;
&lt;li&gt;Fallback to &lt;code&gt;gcc -no-pie&lt;/code&gt; if position-independent execution fails&lt;/li&gt;
&lt;li&gt;Degrade cleanly to a bare &lt;code&gt;ld&lt;/code&gt; link for completely naked environments&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;
  
  
  3. Explicit Mode Switches
&lt;/h3&gt;

&lt;p&gt;For strict bare-metal control, devs can override automated link behaviors via targeted CLI flags:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;-mode c&lt;/code&gt; — explicitly lock execution strictly through GCC&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;-mode raw&lt;/code&gt; — bypass safety overrides and link unmanaged binaries directly with raw &lt;code&gt;ld&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🚀 What's New in Patch 4.0.1?
&lt;/h2&gt;

&lt;p&gt;While 4.0 laid the groundwork for memory optimization, the 4.0.1 hotfix secures edge cases in bare-metal pipeline execution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Silent-by-Default Pipeline&lt;/strong&gt;&lt;br&gt;
Hides external noise from standard tooling (like &lt;code&gt;nasm&lt;/code&gt; or &lt;code&gt;gcc&lt;/code&gt;), displaying a clean single-line state block: &lt;code&gt;Built: program.out&lt;/code&gt;. Errors are trapped and viewable in full via the &lt;code&gt;-verbose&lt;/code&gt; flag.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Collision Resolution&lt;/strong&gt;&lt;br&gt;
Fixes namespace collisions on identical file names using distinct low-level syntax extensions — e.g., &lt;code&gt;main.asm&lt;/code&gt; and &lt;code&gt;main.s&lt;/code&gt; now map correctly to independent &lt;code&gt;main_asm.o&lt;/code&gt; and &lt;code&gt;main_s.o&lt;/code&gt; components without cross-contamination.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Garbage Cleanup&lt;/strong&gt;&lt;br&gt;
Refined &lt;code&gt;-clean&lt;/code&gt; runtime structures to ensure all cross-compilation objects (&lt;code&gt;.fz_objs&lt;/code&gt; temporary workspaces) are recursively pruned using zero-allocation OS system calls.&lt;/p&gt;


&lt;h2&gt;
  
  
  💻 Getting Started
&lt;/h2&gt;

&lt;p&gt;For system engineers moving away from manually typed, multi-stage assembly toolchains:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Pull the latest bare-metal builder package directly via Go&lt;/span&gt;
go &lt;span class="nb"&gt;install &lt;/span&gt;github.com/forgezero-cli/forgezero@latest
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;blockquote&gt;
&lt;p&gt;Make sure your underlying assembly tools (&lt;code&gt;nasm&lt;/code&gt;, &lt;code&gt;fasm&lt;/code&gt;, &lt;code&gt;ld&lt;/code&gt;, etc.) are globally mapped within your system &lt;code&gt;$PATH&lt;/code&gt;.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Check out the fully-tested source tree, architecture specs, and documentation over at the &lt;strong&gt;&lt;a href="https://github.com/forgezero-cli/forgezero" rel="noopener noreferrer"&gt;official ForgeZero GitHub Repository&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>go</category>
      <category>assembly</category>
      <category>lowlevel</category>
      <category>performance</category>
    </item>
  </channel>
</rss>
