A lot of links this week... And I did not have the time to read them all! Enjoy!
Managing scheduled posts on Linkedin changed during the past weeks. I finally got my answer from the documentation. To have access to the scheduled posts, one should start to write a new post, at the bottom of the window, a calendar icon should be present (with a number on right). Click on it and you will be able to see your scheduled post. I think Linkedin is looking for UI/UX engineers.
ribs is probably one of the most fascinating functional library available for Dart and Flutter. I started to play with it last week, but there are so many things to say about it, I don't even know how to start. cranst0n did an amazing work, but the learning curve is crazy.
One of my past interview for a Senior Elixir Backend Developer position was successful, but a technical interview including a coding test is required. My Elixir skill is rusty, my last professional usage of this language was 3 years ago, and during the past years, Erlang was my main programming language. The crust of rust is even bigger because during the past months, Dart and Flutter were my targets... Anyway, if you are reading these messages, you already know I code in Elixir (my last article on standalone http server with Bondy is a proof), but it can be hard to remove the habits from a very similar language like Erlang, even more during an interview. The backend of my main mobile application will use Elixir and Phoenix, but it is the right time... but I have an issue.
Last week, my VPNs got some issues related to certificate, and the way I manage them is a bit crappy (easy_rsa from openvpn toolbox). This certificate management issue is recurrent, and every 2 or 3 years, it cost me few hours to cleanup and update things. Why not storing those certificates in a postgresql database managed by Elixir? In fact, it could also be a good way to receive alerts when a CA or a client certificate expires, and automatically renew them? Well, welcome to another project called expki. Again, it's not planned to be prod ready, but more to let me code like I want and relearn Elixir best practices. Perhaps you will find the source code interesting though... right?
In fact, my 2 or 3 coding sessions on this project were very interesting. For example, I thought the interoperability with Erlang with smooth, but it's not the case for everything. Here a concrete use case (a post will be published about that). The public_key Erlang module is in charge of dealing with all the asymmetric cryptography algorithms (e.g. RSA, DSA, DSS, ECC...) and their format (PEM, DER). Because this code is fully in Erlang, it also uses a lot of macros and records.
The records can "easily" be used in Elixir with the help of the Record module, except if those records are starting with an uppercase character. Indeed, the Record module will convert the records into a function, but the functions in Elixir can't use a name starting with an uppercase character. How to fix this problem then, because the public_key module defines more than 150 records following this pattern. Well, I did my own implementation, and instead of creating a function, it extends a module. The example below creates a Expki.PublicKey.RSAPrivateKey using the Expki.PublicKey module as template.
defmodule Expki.PublicKey.RSAPrivateKey do
use Expki.PublicKey, name: :RSAPrivateKey, pem: true
end
When executed, this snippet will create an Elixir Struct called %Expki.PublicKey.RSAPrivateKey{} containing the fields from the Erlang records and also creates few helper functions:
RSAPrivateKey.name/0: returns the name of the record as anatom();RSAPrivateKey.length/0: returns the full length of the record including its name;RSAPrivateKey.fields/0: returns record's fields and their default value;RSAPrivateKey.keys/0: returns record's keys;RSAPrivateKey.convert/1: convert a%RSAPrivateKey{}Elixir truct into a#RSAPrivateKey{}Erlang record, and vice versa;RSAPrivateKey.convert!/1: same than the previous function, but throw an error in case of issues;RSAPrivateKey.is_valid?/1: check if a record is valid or not;RSAPrivateKey.pem_entry_encode/1: extra-function added to help encoding a%RSAPrivateKey{}into a PEM entry;RSAPrivateKey.pem_entry_decode/1: extra-function added to help decoding a PEM entry and convert it into a%RSAPrivateKey{}struct.
Then the macros. This part is a challenging one, because the macros, and especially the -define annotations, are dynamically loaded when epp (the Erlang PreProcessor) is reading the source code. The macros are then expended, but never really returned. The only way to have a list of available macros is to call the epp server started with epp:open/1 function, and sending an undocumented message to it. Yeah, that's a bit dirty... and why do I would like to do that? Well, because, again, the public_key module is using a lot of -define macros to store X509-like standard informations for the certificates.
All my researches and notes can be seen in the repository, in the notes directory.
It was not really planned, but I also worked a bit on the Awesome Erlang List via Erlang Punch. Managing with so many resources is a huge issue, and it's not easy to manage a simple markdown file. 2 years ago, I started to write a solution using a text-like database, but it was just not the right way to do. Then, I started to move those resources into Erlang Terms, again, it was hard to maintain. Finally, I decided to use yaml for now. A db.yaml is now available at the root of the project, it contains the whole list of resources and will be used to generate also README.md file and few JSON files for indexing purpose.
The concept behind the Awesome List is great, but it's hard to update, and not a lot of people have the time to do it. What could be nice is to provide a simple web interface (with authentication) allowing creators to put their project easily. The awesome directory is containing an Erlang application/release with the goal of doing that, but it was never finished. Hopefully one day I will have more free time to do it.
Coding
๐ Instant-Launch Erlang Executables - Peer Stritzinger | Code BEAM Lite Stockholm 2026: a talk about rebar3 calzone module to create Erlang binaries and speeding-up the boot process. The idea is to preload the data and store them in the memory using mmap. It's an alternative to escript.
โถ๏ธ Going CPU Bound - David Klemenc | Code BEAM Lite Stockholm 2026: a quick review and history of optimizing logging in Elixir.
๐๏ธ BootLife: Conway's Game of Life running directly from a 512-byte x86 boot sector, using VGA memory as the simulation grid. By Alex Kuleshov.
๐๏ธ PON-BEAM โ Notification-Oriented BEAM Virtual Machine: PON-BEAM is a complete re-architecture of the Erlang/OTP Virtual Machine (ERTS โ Erlang Run-Time System) using the Notification-Oriented Paradigm (PON).
๐ beeceptor: a service to mock API, easy to use, fast. Perfect to implement and test http clients.
๐ AsmGrid: a complete list of all opcode from x86, amd64 and ARM, from AsmJit, the library used by the BEAM for its JIT.
๐ How I converted GenLatte to fullstack Dart: A quick feedback regarding nodejs/javascript conversion to Dart. Discovered the freezed package while reading this post.
๐ Turning the HEIC decoder into a SHA-256 computer: a crazy post about the method to decode HEIC format. An HEIC decoder can be seen as a machine, having its own instruction, in this article, the author use them to generate the SHA256 hash of the image itself. Impressive.
๐ Type Safe Generic Data Structures in C: adding type safety in C is possible, but it's usually hard. I think this post is proving me wrong.
๐ A Fast, Growable Array With Stable Pointers in C: another article by the previous author introducing a dynamic array with constant time indexing and stable pointers. Also known as "levelwise-allocated pile" or "segmented list".
System
๐ Simple Optimization For Linux 7.4 Can Open Files For Reading ~39% Faster: interesting optimization case.
๐ Linux Process and Thread Creation: System Call Architecture
๐ Netkit: Specializing Linux Packet Delivery for Container Networks: decreasing network latency for containers using ePBF optimization.
๐ DDB: Source-Level Interactive Debugging for Distributed Applications:
๐๏ธ AnyPS5:Convert PS5 executables to run natively on Linux and Windows. The PS5 is using the same architecture than a PC (same for the Nintendo Switch), it runs on a modified version of FreeBSD (same for the Nintendo Switch), so, it was a matter of time before having a project porting games on Linux/Windows. A good thing, to be honest! Wait and see!
Hardware
๐ "Supply Shortage Problem Has Disappeared": Acer CEO Says Memory Prices To Decline In 2027 As CXMT Starts Mass Production Of New Chip Platform: RAM price could decrease during the next coming months.
Network
๐ DIY Router On X86 E-Waste: OpenWrt And OPNsense: Ah! A refreshing article on old-hardware reused to create routers! OpenWrt and OPNsense are the easy solution, if one want to really use a small system (but doing everything by hands), it should use FreeBSD, NetBSD or OpenBSD directly. This article reminds me when I was looking for old computers in the trashes... Nice!
Database
๐๏ธ postgrex: the official postgresql connector used by Ecto. Putting the link here because I'm writing about that right now.
๐๏ธ db_connection: the official database connector used by Ecto, especially used for the pool. Again, putting that here because I'm writing on this topic right now.
๐ NOT IN can be executed as an Anti-Join (NOT EXISTS) in PG19: huge performance gains in most of the use case. Best way to improve an application performance using postgresql: upgrade it.
๐ We ported the original Doom to SQL: another proof doom can run everywhere, probably more portable than NetBSD. If you like crazy hardcore SQL queries, you will have lot of fun reading this article.
Security
๐ Design and Verification of Secure Systems (1981): an old paper about design/verification for secure systems, still good to know.
๐ pwndbg: Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
๐๏ธ Awesome Cybersecurity List: personal collection of awesome blog posts, write-ups, and papers focusing on cybersecurity.
๐๏ธ Wi-Fi Hacking: Testing Routers with Wifit3: it looks like wifit3 is a nice tool. Need to check that.
๐๏ธ VM guest escape via 9p filesystem exploit: LLMs are really great as fuzzers.
Security/Cryptography
๐๏ธ CHAMP Hash Implementation by veorq: CHAMP Hash Function and CHAMP Public-key algorithm. A future post-quantum algorithm.
๐ RSA-896: RSA challenge solved by using Claude with 2048 GPUs. Waiting to see the real process.
๐ Forging 1024-bit RSA signatures in nearly SNFS time: from Forging 1024-bit RSA signatures in nearly SNFS time paper, an attacker can in essence steal the secret key (in that they can forge signatures/decrypt offline), without actually factoring the public key, and using much less computation than factoring the public key would have taken.
๐ Quantum Encryption Resilience Score (QERS): A System-Level Evaluation Framework: a (very) long publication about post quantum cryptography algorithms and about a new framework/benchmark. Need to read that later more deeply, it looks interesting.
๐ Practical-Cryptography: exercises and courses on cryptography.
๐ The AEGIS Family Of Authenticated Encryption Algorithms: AEGIS was selected by the IRFC/IETF and added in RFC10032. AEGIS is based on AES round functinons. AEGIS is faster than AES and offers high security. Suitable for network communication. It includes both authentication and encryption.
๐ Shielded Bitcoin: (yet another?) protocol to make bitcoin L1 transfer private. IIRC, it was already made in the past... right? or perhaps not.
Security/RedTeam
๐ Turn a Rooted Android Phone into an NFC Authenticator and Automation Tool for Your PC: The series on NFC is great. In this post, they are explaining how to use an Android phone with NFC to inject and play with NFC connections.
Embedded
๐ Extending Scapy for Hardware Reverse Engineering: at the beginning of my career I was using scapy, and reading this post about using it to use it with hardware (SPI in this case) is so cool! It is possible to extract a firmware directly with scapy from an eeprom/flash using SPI traffic inspection. Really great.
โถ๏ธ Quick way to find a connection on a PCB: great method to find a track on a PCB using a kind of brush. Smart.
Update/Upgrade
๐ Qubes OS 4.3.2-rc1 is available for testing
๐ Erlang/OTP 29.1.1: security issues and bug fixes
๐ NetBSD 10.2 Releases: bug and security fixes.
๐ Tor Project Forum: Security Release 0.4.9.13: security patches. more info here.
๐ hackney 4.8.0: a new version of the hackney http client in Erlang is available.
Leaks of the week
๐ Faktus victime dโune fuite de donnรฉes : 53,7 Go et des donnรฉes...
๐ Biocoop : 2,76 Go de donnรฉes internes et prรจs de 6 900 personnes concernรฉes par une fuite de donnรฉes: 6900 people impacted (name, emails, phones and identifiers) mostly from the company itself but also the customers.
๐ฆ China Mobile Subscribers Data Leak: over 850 million subscriber records offered for sale.
๐ฆ South Korea's National Health Insurance Service Data Leak: over 51 million records offered for sale
๐ Rรฉparโstores piratรฉ: 340GB of data, 7500 files, and over 1.8 millions impacted.
Misc
๐ Inside the Very Human Origin of the Term โArtificial Intelligenceโ
๐ฆ 2,500 PRs last month to production: feedback regarding a huge amount of PR puts in production using Grok Bot. The trust is the most important issue (present on the first slides). In fact, it's the whole point of this talk. Tooling is important, including static analysis, test suite and so on. They used Dune (not sure if it's the right project though). a summary here.
You already know, I'm not a big fan of LLMs, but it will be the new norm. Like systemd (openrc fan) or kubernetes (nomad fan) before... The best tools are not always winning. When I created my first company project around 15 years ago, I did not trust my code. At this time, I learnt a lot of testing, but the problem was not about the testing, it was about the process. Extreme programming, Agile or scrums have been designed to deliver fast, but with risk of breaking things. On the other hand Cleanroom Software Engineering has been created to produce a small amount of bugs and high quality software. This process is expensive, and really strict, but it could be interesting to see if it could be integrated in a pool of LLMs workers.
๐ Atomic Chat: open-source agent for local models.
๐๏ธ laya-mix: Native MLX runtime for Laya typed decision models โ 7โ14 ms short decisions on M3 Max. No text generation, PyTorch, or cloud API.
๐ Jev Documentation: Jev is TypeSafeโs flagship model and the first System One model. Send state and typed questions; get structured answers your code can use directly.
๐ The โCโ word, Are humans conscious? Not all LLMs agree: this post reminds me a tweet I posted few months ago. LLMs are huge database containing statistics about knowledge. More knowledge accumulated, means more accuracy. Most of the private LLMs (if not all) have been created by collecting copyrighted-data without the authorization of their author(s). Their is a reason why, now, many publishers are protected the access of their publication, to avoid this kind of abuse. The author of this article is exactly saying the same.
What caught everyone by surprise is that if you make the model big enough โ i.e., if you pirate enough books and pilfer enough blog posts โ it becomes eerily good at acting like a human. It can hold a fluent natural-language conversation on any topic, manipulate the language to produce previously-unseen outputs, and complete a variety of open-ended tasks. It can also speak convincingly about emotions it never experienced in a physiological sense: fear, love, pain.
Too many people are being fooled by that, because they don't understand how LLMs are working, and in fact, they don't even really what consciousness, nor thinking, nor what a mind is... Because no one teaches them and they have lost spiritually, replaced by ultra-materialism. Anyway, some people will answer LLMs are intelligent because they can have good score at exams or by solving complex cases in court for example. Well, again, if the LLM has been correctly specialized using the correct amount of books on these subjects, it will be able to answer most of those questions, because they are not requiring innovation, simply knowledge. Anyone with enough time and effort can do the same. When it comes to real-world problems, requiring more complex decisions, or original ideas, LLMs can fix that.
An LLM exists in a nihilistic netherworld devoid of death, injury, purpose, or consequence. It canโt go to prison if it lies or steals; we donโt train it to believe it could.
In the end, the over-usage of LLMs everywhere will drive down everything, because most of the resources assimilated by the LLMs are average. In fact, it can be even worse, they can also reproduce the same errors everywhere, without knowing it, because it was found on many publications, books or... blogs and stackoverflow. Anyway, a good post we should all read.
๐ The Kekulรฉ Problem: another post about consciousness.
We dont know what the unconscious is or where it is or how it got thereโwherever there might be [...] The log of knowledge or information contained in the brain of the average citizen is enormous. But the form in which it resides is largely unknown. You may have read a thousand books and be able to discuss any one of them without remembering a word of the text.
๐ How to keep enjoying programming in a world of LLMs: I'm thinking a lot of that. Few friends told me they are starting to hate programming due to LLMs, in fact, it's also my case. The ad-nauseam advertisement campaign about LLMs make me sick. The world "evolves", and if LLMs is becoming the new norm, then, we must adapt. My idea is to still code by myself on my own personal projects, and let the LLMs do the rest for my job. That's all. Maybe companies will understand one day fast production means also huge pile of legacy code and instability... But they are so greedy and they have been so blinded by this technological "progress", it will take a while. Anyway, lot of good rules in this post
๐ฆ Andrea Albrizio powned: some of you asked me why, in France, so many services got hacked recently. Well, my answer is simple: lack of responsibilities and overdose of incompetencies. Security is a process and a mindset.The process without the mindset will not work, and the mindset without the process will not work as well. Security is also about discipline and training. New attack methods are created every day. Anyway, this tweet is an example why people data are available on few dark forum, because those "entrepreneur" think they can just deploy an application, make millions and be safe. The web was never ever a safe place.
Cover Image by Rosalie Barley on Unsplash











Top comments (0)