Timeline

explore river

Every post and feed across this instance

  • Your Site Is a Home

    This is an idea that I am very much in tune with. I’ve actually had on my to-do list for a while to write something similar (and I still will). I’m glad to see others have similar feelings of “home” and comfort on their personal web sites.
  • Scroll trīgintā quattuor

    Welcome to volume thirty-four of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we explore the everything web, chill in the Fediverse, and let the madness (AI) consume us.

    IndieWeb

    I welcome you back to the open old artisanal accidental useless annoying fun weirdeverything web. I guess it’s really hard to put a single name on what we’ve got here… There’s buttons though!

    I’m tired of the ensloppification of the ‘net. I want a web for humans, by humans. A place where people go—to write, and to share everything they are. Here’s some humans you can go interact with right nowAdam, Seth, Juhis, Gina and Bastian.

    🔥 It’s dangerous to go alone! Take these. 🔥
    (Some assorted tools for blogging and such.)

    • 🐒 Wild RSS for testing RSS feeds
    • 🛠️ FontCrafter for turning handwriting into a real font
    • 🧐 LENS checks your meta tags, icons and rss feeds
    • 🛍️ Feedgrab to help discover new feeds

    Small Web Finds and Features

    Here’s a bunch of other cool stuff from across the webz 👇

    Fediverse

    Ten years of the Fediverse and somethings never change—don’t be afraid to boop that lil’ favorite button for whatever you like, and it’s perfectly fine for Fedi to be that cozy, slow-growin’ corner of the ‘net. It’s just a good place to be. There’s more ways than ever to be part of the Fediverse too! Check out Madblog and Inkwell for example.

    Cybersecurity

    AI is tradecraft

        AI is a nightmare

            AI is chaos

                but can we secure it?

                    No.

    …here’s some other cyberstuff

    Thanks for reading Scrolls!

  • Scroll quattuordecim

    Welcome to volume fourteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we discuss the value of your personal web identity, we talk toot-mobility, and we automate our “no’s”.

    IndieWeb

    A personal web site can be a lot of things. Maybe most importantly though, it can (and should) serve as your canonical identity on the web. So whether you are a creator, or just a “regular” person on the web in this modern world. It’s important to claim a space for yourself, not to only rent space on some large platform that could disappear on a whim. Use this space to speak your mind, or at least, use it as a centralized place to archive what you’ve first-published elsewhere. I’m not saying it doesn’t take a little bit of work to get this set up. But the benefits are worth it!

    One of said benefits, which is really hard to measure, is the simple joy and pride that comes with building a space that is unique, and entirely you. With a personal site, you are free to tap into your creativity and the limitless canvas of the web, rather than being shoved into a box with a character-limit on a boring-looking site where you are nothing more than a “user”—a powerless @handle at the mercy of a faceless corporation. Why conform when you could be your unique self!

    Second, you are free to write (or share) whatever you’d like, styled to your exact specification. Writing itself isn’t always easy, but what you publish can be as long as you’d like, as trivial as you’d like (though you may be surprised to discover the value of things you thought to be trivial), styled however you want and in any format you can imagine.

    As I’ve said before, there are many goals served by having your own li’l personal space on the web. For many, it’s about tapping into the larger IndieWeb community. Though it may be hard to see it at first, this slice of the web is growing and becoming increasingly vibrant. Once here though, how do we “connect”? Email has of course remained a mainstay. Adding some level of Fediverse interoperability is also an option. Though it’s only one-way, RSS remains a popular (and unintrusive) way of getting your message out to people who want to hear it. The IndieWeb is a community—in fact it’s a community of communities—places where we can learn from and support one another.

    So flutter forth and meet some cool new people! To get ya started, check out the awesome sites I’ve shared below!

    Small Web Finds and Features

    Fediverse

    Alriiiight, let’s settle into the Fedi’ section with some sweet jams 🎶

    A lot of people see the IndieWeb, and for similar reasons, the Fediverse as somewhat of a “black hole” in terms of reach. Too often I see people refer to their posts as “shouting into the void”—and while I think there’s some truth to this, it is only the case because we’ve over-conditioned ourselves to be reliant on algorithms to serve as vehicles for said reach.

    Reach (and in the inverse, discovery) work a bit differently in an algo-less world. Here we rely on human-led curation, organic conversation, and authenticity over algorithm-driven click/engagement-bait and likes-fueled post favorabilty which has only ever served “influencer“-types. But make no mistake, even without a native “algorithm”, your posts on the Fediverse have real traveling potential, courtesy of the communities and relationships who value who you are and what you have to say.

    Speaking of which, in the course of publishing this newsletter each week, I have had the pleasure of featuring a LOT of awesome artists, ALL of whom I’ve discovered on the Fediverse. I encourage you to click on each of the images I share each week to check out their craft, give them a follow, let them know you appreciate their work and for many, you could even have some of your own art commissioned! Scrolls has always been the best of my web/social timelines—aggregated and synthesized by me. So though I have so many of you to thank, a disproportinate portion of the vibrancy of each “Scroll” can be credited to these super talented artists. Thank you! 🎨 🧡

    Here’s how I’ll send this section off…

    The Fediverse is not just one thing. It’s not perfect. But what it offers is a place to be you. To build meaningful relationships, that for real can’t be snatched away by a billionaire. Where your interactions, however small, can really mean something, and you can actually enjoy the time you spend scrollin’ your feed.

    Cybersecurity

    Yeehaw! Here’s this week’s cyber-roundup 🤠

    Shostack’s Appsec Roundup is absolutely overflowing with great links. I’ve bookmarked like 8 things out of there. Python went out and got a cryptographic makeover. Two “named vulnerabilities” debuted in the last week—AirBorne & OuttaTune.

    Tooling-wise, AWS Security Changes looks interesting for tracking minute security-related changes to AWS services, and NOVA can help detect adversarial (LLM) prompts. Want to automated your security team with a very old-school state of mind? Just redirect all security advisory requests to this handy-dandy API.

    IndieSec Blogs

    Thanks for reading Scrolls. Here’s a hug!

  • Why I email complete strangers

    It’s simple. Just send a message to the folks who you appreciate. They’ll really enjoy it. It’ll likely make their day! It takes virtually no time at all really, and you’ll feel good about it. It’s wins all around.
  • Scroll ūndecim

    Welcome to volume eleven of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we do whatever we want, the Fediverse is doomed (but less doomed than elsewhere), and we visit Hacking-town.

    Has your computer touching so far today made you happy? Maybe no? Well, hopefully this edition of Scrolls can turn that around for ya!

    IndieWeb

    This part of the web, the personal web, the “IndieWeb”, should be a place—noIS a place, you can just be you. Take a break from the like-seeking, engagement-farming, inauthentic, expectation-laden fakery that plagues the rest of the web (looking at you social media). Give yourself the space to be imperfect, to be creative, to be flawed, to be human, to be you. This part of the web is supposed to be fun. It’s supposed to be a happy space. It should feel like home (as it does for me). So don’t worry about being perfect here, sometimes it’s enough to just say hello.

    Since your site is your space. You can do whatever you want—and there is so much to do! Want to make your RSS feeds shimmer? We got somethin’ for that. Want to dress down your site for the day? Go do it. Make your site fully downloadable, build a shrine to the games you play, take on the blog questions challenge, share your manifesto, join a webring, put a ton of buttons on your site, then add more (and MOAR!)—just go do stuff. No one can stop you. Go create a ton of subdomains, just for the fun of it. You can literally put 10000 posts out on the Internet. You think you can write 10000 posts that are all bangers? Nope. But who cares? Just do what you want. (But please put publish dates on your posts!)

    Because how bad would the web be without the “you can’t stop me” attitude? What would the web be like? Without the writers. Without the dreamers. Without the sharers. Without the fearless. Without the women. It would be crap! That’s what.

    But luckily, we have a chance at something more like this…

    Featured Blogs

    Here’s a bunch of places on the web that are awesome!

    Fediverse

    All social media platforms are a bit cursed if you ask me. Even Fedi is doomed to many of the same ills—as much as I love it. But, for all its faults, the Fediverse survives, it continues to improve, and can be kinda magical sometimes. I personally believe that the Fediverse, of all the social networks, is best for us as humans. If you think so too, consider getting involved and supporting organizations like The Nivenly Foundation who’s Security Fund looks to help Fedi stay a safe and secure place for all.

    Cybersecurity

    Welcome back to the li’l “hacking” corner! This week I’m learning more about the terminal and how to bypass PowerShell execution policy. I also found an awesome resource for cybersecurity research and yet another vuln/exploit database (can never have enough of those now can we?)

    In a world plagued by inauthenticity (*cough* →this← *cough* 🤢), be more like Ricardo and Elma—who have awesome infosec blogs.

    Thanks for reading!

  • Captain's Log, Entry: January 30, 2026

    Phew! It’s been a minute since I’ve published one of these journal entries. Yep, I’m still alive. Just busy, sometimes unmotivated, and have just generally been elsewhere for a few months now. But I’ve been easing myself back into some of my old grooves and that includes my blogging and IndieWeb-related habits.

    Site News
    • Let’s see, in the new year I’ve been making some steady changes to the site, got Scrolls goin’ again and even put out a post or two. I’m back!
    • My GoToSocial instance’s hosting provider has gone kaput. So I need to download my archive and migrate somewhere. Have been really slacking on that though.
    TV
    • Binging the entirety of Stranger Things (Now finally in the last season)
    • Watching NBA
    Life

    👶 🏡 Kids. Kids make you busy. I’m super busy with the kids. Oh and having a house is work…. and money… and time… and more work. I don’t mean to complain. I’m lucky to have what I have, especially looking at the way the world is these days. It’s just me saying I’m busy. Did I mention the house costs me tons of time and money? We got plumbing surprises, the fridge is on the fritz, then the HVAC goes brrrr, the yard is a swamp, the windows leak air, and the list just goooooesssss. But hey! That’s life.

    ❄️ I’m sure I can speak for everyone in the DMV area atleast. I’m ready for the warm weather. We’re nearly a week after the “Snowcrete” event and I’m just dreaming about being out in the yard, doing some gardening, napping on the screened porch, enjoying the fireflies… ahhh

    🧙‍♂️ I need to sign up for PentesterLab and get back on my training/learning grind. It feels like it’s been forever (and it has).

  • Yeah, I Made It Lilac

    Did you know if you have your own website, you can do whatever you want with it? Like… it doesn’t have to be all snobby or professional. Or like… some of it can, but some of it could just not be, y’know?

    Check this s*** out for example. I went positively rogue on this page.

    Then, I slapped my derpy turtle shark thing there ⤴. For NO reason. Isn’t he breathtaking?

    Does this post look good? Stop. Don’t care. Doesn’t need to. It is what it is—and what it is, is just something I felt like doing in the moment. I’m going to publish this. Then… I might tweak it. Maybe I’ll add more ridiculous stuff to it. Y’know, when I feel like it. Or, maybe I’ll take it down sometime. Maybe I’ll change the background title and color. I’ma just vibe, cool?

    🚨 New font alert!! 🚨

    Yeah that's right. Out of nowhere we got this fancy-lookin' font goin' on. Dope.

    OK, we’re back.

    🎵 Doopa-choppa-doooo 🎶—what should I do now?

    I’m trying to send some sort of message here.

    The message is simple, yet ✨eloquence✨ may not be my forté. Your site is for you—to be you–and you’re almost certainly kinda weird, right? So own it! Stop worrying about making it “perfect” (whatever that means). Or making it professional (🤢). Or making it need to have this or that. It ain’t that serious. Be more like this page. Be Weird.

    Update!

    I told you I’d do this. I was munching on a block of extra sharp cheddar cheese thinking about this post and decided I had some more I wanted to say.

    You look at this page and you might think it’s “weird”. I mean I do. I’ve said as much throughout. But why? Was it really so long ago that almost all sites looked like this? Personalized. Amateur. Unique. Human—in a time of the “old web”. It does seem like it was a lifetime ago doesn’t it? It’s too bad that people’s blogs have become not like this. The substack-ification of people’s web presence is what’s grotesque if you ask me. I dunno… can you make just one of your pages on Substack lilac? 🌸

    probably not 😔

    Come here (the IndieWeb) and be weird with me. With us.

  • 100 Webmaster Questions

    Here’s a blogging challenge inspired by theresmiling. “100 webmaster questions”, let’s go!

    1. Please introduce yourself.

    I am shellsharks and shellsharks means me! (IRL, folks call me Mike.)

    2. How long have you been making websites?

    Since about May 2019.

    3. And what got you into the hobby?

    I really wanted to write this post and this post. Though my true passion for blogging and site-keeping as it is today was born when I first discovered the IndieWeb.

    4. What kind of website are you most interested in?

    There’s a lot of sites I like. I generally adore personal / IndieWeb sites and anything that shares interesting / educational or infosec / cybersecurity content. I enjoy all sites that are particularly unique. A better question may be what sites do I not like…. Anything with AI-generated content, anything plastered with ads, most of the “corporate”-web, anything malicious and any of these other annoying sites.

    5. What’s your workflow? Do you plan your websites out thoroughly or do you come up with the design as you go along?

    I don’t have a lot of websites outside of this one. I started in 2019 without much of a plan. I knew only that I had a few ideas for posts to write and the rest would come thereafter. If I were to make a new site today, I would have a lot of lessons learned that I could apply to how I would build said site.

    As it pertains to how this blog is currently set up / ran, here’s my site’s overall architecture & my blogging methodology.

    6. Please link to your biggest inspirations.

    Here’s some of my favorite site designs, and everyone else I have to thank for how my site has turned out thus far.

    7. What’s your favourite part about making websites?

    Great question! So hard to choose. I’ll name a few. To start, here’s some of my favorite things I’ve built for the site. But I’d say my favorite part about actually making the website has been turning it into a digital home, a place I really just like to spend time in and click around. Secondly, I’ve really enjoyed my site as a place that has helped, educated and inspired others across the ‘net.

    8. And the thing you struggle with the most?

    Probably these two things…

    • Finding the time and motivation to work-on / write-for the site.
    • Getting around some of the technical limitations of static site generators.

    9. Do you keep the same layout on all of your pages? Or do you use different ones?

    I have a few different layouts. Most of them are pretty similar but I have different layouts for different post types: posts vs. pages, there’s some special posts, etc…

    E.g. a page vs. a scroll vs. a note vs. a standard blog post vs. my screams etc…

    10. How confident are you with CSS?

    Once you’ve reckoned with the horror that is CSS, can you claim confidence in anything within this reality?

    11. Do you know how to correctly use <dl>?

    I guess not.

    12. What is your favourite HTML element?

    sup. I also love <li>sts.

    13. If you’re making a new web page from scratch, what is the first thing you do?

    If it’s for a new site, I gotta get the domain of course. Coming up with, and then actually finding the perfect domain name is really hard in my experience. Once I have my domain in hand, I try to get a wireframe up first.

    14. Do you know JavaScript?

    Does anyone? I know enough to get in trouble.

    15. How about PHP?

    The basics. Nothing less. Nothing more.

    16. Does your website have a theme that you stick to?

    Pretty much.

    17. Are you more focused on content or design?

    Content is probably the correct answer. Though I go through stretches where I am more keenly fixated on sprucing up the site’s design / aesthetic / ux / etc…

    18. Do you own a domain name? If not, would you ever want to?

    Yes! Many. Though shellsharks.com is probably the only one I am really using right now.

    19. What do you think of nostalgia-focused or “retro” websites?

    Love ‘em 🧡

    20. Is your HTML valid? Do you even check?

    Just checked this and I have 112 findings. So I guess not 😬.

    21. What are your opinion on buttons and banners?

    Love buttons. I have a bunch of them here. Banners are ok? I don’t like anything too visually distracting, and I certainly don’t like anything that is just an ad.

    22. What do you think of button walls in particular?

    I think they can be done tastefully (i.e. at the bottom of the page), and there’s lots of cool buttons to show off!

    23. If you started over again, would you make something similar or completely different?

    I’d make something similar for sure. But there’s a lot of things I would do better, or slightly different.

    • I’d comment my site’s source code a lot more.
    • There would be a lot less in-line JS and CSS.
    • In fact, I might try to make it JS-free.
    • I’d design with accessibility more in mind.
    • Though I’m on the fence with certain features, I might use an SSG or platform that would more easily allow for me to add federation capabilities, webmentions, and other IndieWeb functionality.
    • I have a lot of other ideas I might incorporate from the beginning too.

    24. Are you envious of other people’s websites?

    I wouldn’t say that, no. There are a lot of websites that I think are really cool though. They inspire me. Sometimes I steal good ideas when I see them. But I really like my website. I think it is unique, and in its sum, the best. It feels like home.

    25. What text editor do you use?

    Visual Studio Code.

    26. Why do you use that one?

    It’s cross-platform, I’m familiar with it, it has the Git functionality I want. I’m not super attached to it. But just haven’t tried other things.

    27. Do you host your image files on your web server, or on another host?

    Some of my images are in my GitHub repo, but most of them are in an AWS S3 bucket.

    28. This might not be relevant to you, but what’s your opinion on the Neocities vs. Nekoweb debate?

    Not aware of the debate. So no opinion.

    29. How much server space would you estimate your main website takes up?

    Not sure. I suppose I don’t really care.

    30. Do you keep local backups of your files?

    Yep!

    31. Do you prefer simple or highly visual websites?

    I see the beauty and merit in both. But have you seen my site? Very info-dense.

    32. Do you stick to certain colours? Do you do that on purpose, or is it your subconscious?

    I have some thematic colors to be sure, but I also have different themes (e.g. light/dark/classic) you can toggle through depending on your preference or mood.

    33. Have you ever thought about quitting? Why?

    The site? No. I go through drought periods where I am less active, but I’ve never considered shutting the site off or completely walking away. The nice thing about a personal website is you can be as active, or inactive as you want and come back when you please.

    34. Do you have many webmaster friends, or is it a solitary hobby?

    There are a lot of people I have met online in the IndieWeb community and via the Fediverse that have their own sites. We are friendly in a digital kinda way. I have a few friends who have their own websites.

    35. Do people in your real life know about your website?

    They sure do.

    36. Do you update your website very often? How often is “very often”?

    I’d say my site is updated very frequently most of the time. These updates are typically small additions to some of the lists that I keep. When I am very active with the site you might also see multiple net new posts in a week.

    37. And the overall design, do you change that much? Why or why not?

    I’ve gone through a major design overhaul about every 2 years thus far.

    38. Is your website more you-focused, hobby-focused, or outside world-focused?

    It’s a bit of everything. I write about infosec, technology and “life in general”. I’ve given myself the space to write about whatever I want, from my professional pursuits to my personal life, and everything in between.

    39. Do you do web design professionally?

    Not at all.

    40. If not, would you like to? And if you’re comfortable answering, what do you do for work?

    At one point in time that was my dream. To work remotely + abroad and do web design / web building work. I never really went down that path in the end, opting instead for the cybersecurity field.

    41. Do you communicate with people by email very much?

    Occassionally. I do enjoy email correspondence, and try to contact IndieWeb folks from time to time via email just to chat.

    42. Some people reject social media and use websites as a replacement. Do you keep social media outside of your website?

    In a way, yes. My site isn’t “social”, in that it is not federated, it doesn’t support webmentions and there is no commenting system. I like what is on my site to be my content alone. But I write about social media a lot, link out to my social presences and even PESOS some social media content back into my site.

    43. How about instant messengers? Do you use a mainstream one like Discord or Telegram? Or something like Matrix? Do you avoid them?

    I do use them, but they don’t see much action day-to-day. I have and use Discord, Matrix and XMPP (shellsharks@xmpp.earth). I also have lots of traditional “text messaging”-type apps I use (e.g. Google Voice, WhatsApp, iMessage, etc…)

    44. Do you listen to music while you work on websites? If so, what kinds of artists?

    Sometimes. Just depends on my mood and what I’m doing. For some reason I can listen to music while reading, but not when I’m writing. I can listen to music while I code though. In these cases, I’ll mostly listen to instrumental versions of albums I like and metal.

    45. Do you keep everything you make on one website, or do you have more than one?

    Monolithic.

    46. On a similar note, do you keep to one topic on your site, or many?

    Any and all topics.

    47. Do you present your real self, or at least try? Or do you construct a persona on purpose?

    I pride myself on being genuine, both in my writing and in person.

    48. Have you ever made a good friend thanks to your website?

    Eh, I don’t know about that. But I have built a lot of cool relationships thanks to my site. So that’s neat!

    49. Are you happy with the way HTML and CSS currently work?

    I like the design and functionality of my site. But there’s A LOT I want to improve, some of which I need time to do, and in other cases I need to learn how to do it.

    50. What are practices that you think people should avoid?

    All these things. 😡

    51. What about under-utilised practices, or things you think people should do more?

    I don’t know if these are under-utilized per say, but here’s a bunch of things I recommend for folks to do while they are site building.

    52. Do you use a lot of semantic HTML? Or are you guilty of generic structure?

    I discovered the concept of semantic HTML somewhat recently, and certainly after the first few iterations of my site’s overall design. I’ve incorporated some semantic HTML since then, but it hasn’t yet permeated the entirety of the site’s bones.

    53. Do you consider different browsers?

    Consider? I use Chrome and Safari mostly.

    54. Speaking of, what’s your preferred browser? Convince your readers why they should use it.

    I use Safari on my personal computer and Chrome on the professional side.

    55. And what OS are you on?

    macOS.

    56. Do you have a strong opinion on that, or do you just happen to use it?

    I’m not a zealot or anything, but I love Mac and am not interested in anything else. Also, have you seen Windows lately? Complete dumpster fire. Aspirationally, I’d like to become a Linux user but in my few attempts to switch over I just haven’t found traction.

    57. Are your websites mobile-friendly?

    I think so. I’ve tried to make it so and done some testing. I have special mobile layouts too.

    58. What are your thoughts on autoplay?

    Don’t like.

    59. What are your thoughts on webrings? Are you in any?

    Love webrings! I’m in a bunch!

    60. Do you have any web shrines? What do you like to see in that sort of page?

    I’ve never considered any of my pages/posts a “web shrine”. But I do have some things maybe you could consider shrine-ey?

    61. Are your websites “cliche”, in your opinion?

    Nah.

    62. What is your ideal website? Are you striving for that, or for something else?

    Hmm… I’d say the “ideal” website has…

    My site has these things and is ideal for me.

    63. Are you an artist? Do you draw or design your own assets?

    Oh absolutely. Is it good art? Well, I’ll let you be the judge of that.

    64. What are your favourite resource sites?

    Not sure what this question means exactly. But I have a lot of IndieWeb resources I keep listed here.

    65. Is there a habit you just can’t get away from no matter how hard you try?

    Here’s a bunch of my writing mannerisms, some of which I try to get away from and others that are just unique to how I go about things.

    66. What’s your biggest advice for a new webmaster?

    Don’t worry about doing everything, or being perfect. Just add things little by little. Be yourself.

    67. Do you keep all your styling in CSS? Or do you hard-code some?

    Some of it is tucked away in CSS files, and unfortunately too much of it is still in-line.

    68. What do you think of frameset layouts?

    Don’t know much about ‘em.

    69. How about table-based layouts?

    Don’t know much about these either. I use a CSS grid kinda thing.

    70. Do you subscribe to the ideas of “one-column”, “two-column” and “three-column” layouts? Do you use any of these?

    Yes I like and use these in certain situations. My mobile layout is exclusively single-column. But as the device size gets bigger, you will see content start to spread across multiple columns, especially as it pertains to my home page. I like the idea of ToC’s and sidenotes populating side columns for post content too (though I haven’t gotten around to implementing this sort of thing yet).

    71. Do you spend longer on the HTML or the CSS?

    No idea. Probably the CSS though because it’s maddening.

    72. Have you ever made a page with no CSS? It’s useful for your thoughts.

    I have a number of .txt pages if that counts (e.g. humans.txt). Most of my site is styled though.

    73. Do you ever find yourself making layouts with nothing to put on them? Or do you only make layouts when the need arises?

    Don’t think I’ve ever made a layout I didn’t have something already in mind for.

    74. Would you consider yourself a beginner? Or advanced? Somewhere in the middle?

    In terms of having a site in-general, I’d say I’m upper-intermediate at this point. There are some aspects of site design / webmastering / site-building that I am still not so good at to be honest.

    75. Do you have a habit of looking at the source code of websites you visit?

    I wouldn’t say it’s a habit. But I do do it on occasion. It’s a good thing to do.

    76. How did YOU learn how to make websites?

    A long time ago I learned the old fashioned way, hand-jamming HTML tags directly into a notepad plaintext file. But in terms of my current site, I’ve learned kinda on-the-go. A mix of reading official documentation, W3schools, stack overflow, etc…

    77. Do you ever force elements to do things they’re not supposed to?

    Not sure. But I do use plenty of outdated HTML elements 😅.

    78. Thoughts on floating elements?

    Floating how? Like CSS floating things in one direction or not in a container? Or visually “floating” on page? Not sure how to answer this one.

    79. When you’re sizing stuff, what do you use first? Do you use px, em, %, or something else?

    Whatever works. All of the above.

    80. Do you have a favourite font?

    Not really. Maybe something in the Helvetica family?

    81. Would you run a website with another person? How would that work?

    Sure, for a project or something that we had a mutual interest in.

    82. Do you surf the Web to find new personal websites very often?

    Sometimes I’m very active in my surfing/exploring. Other times I’m not. My infosec sites, Scrolls and Linklog are a few examples of the product of this surfing though.

    83. Do you bookmark other people’s websites? How would you feel knowing someone else bookmarked yours?

    Yep! I bookmark them, subscribe via RSS, add to specific lists, etc… I love seeing when other people bookmark, reference, or add my site to theirs in some way too!

    84. What do you want people to be most impressed with when they see your website?

    Maybe these things?

    85. Are you interested in technology outside of websites? Do you collect?

    Yep. I’ve always been into Apple, desk setups, infosec, computing-in-general, that sorta thing. Can’t say I really have any tech-related collections.

    86. How often and for how long are you online?

    Too much. Basically all day except for when I’m at the gym, sleeping, or spending time with the family.

    87. When it comes to your website, who is your target audience?

    Everyone. I write about infosec, technology and life-in-general.

    88. Have you ever been interested in XHTML?

    Not specifically, no.

    89. Do you program in general? Have you ever written a program for use with or on your website, not counting simple JavaScript?

    I don’t have any “programs” on my site (unless you count some shoddy JS code as a “program”). I can program, but mostly have simple JS and Liquid stuff on the site.

    90. Speaking of programs that help you make websites, what do you think of static site generators (SSGs)? Have you ever used one?

    Yes. Love! I use Jekyll. 🧡

    91. Do you keep a hitcounter? Why or why not?

    No. Don’t care. I’m more interested in people directly messaging me.

    92. Do you frequent forums? Which ones?

    Not THAT frequently. But I am a patron of infosec.pub and 32-Bit Cafe.

    93. Do you write your page content directly into the editor, or do you prepare it elsewhere, like a text document or a Word document?

    I use VSCode and git. Here’s some other how-I-do-things-related docs…

    94. Do you think you appear cool to others? A more accurate answer now: do other people ever say you’re cool?

    I’m sure there’s someone out there who thinks the things I do are cool. Or maybe it’s just me.

    95. Are you embarrassed of your old work? Have you ever deleted everything out of shame?

    Nah. If there is any of my old work that I don’t like though I tend to update it, so that keeps the embarassing stuff to a minimum.

    96. Would you close down your website if you couldn’t update it, or would you leave an archive?

    I’d like to have my site available indefinitely.

    97. Do you reveal a lot about yourself on your website? Or are you more secretive?

    I’m relatively open book. I don’t put a lot of pictures of myself but I do post a fair bit about what I’m up to personally.

    98. Are you willing to reveal who your best online friend is, and/or if they have a website?

    I don’t think I have an online-specific “best friend”. I’ve started to build some friendlier online relationships thanks to projects like Scrolls though.

    99. And do you optimise the images on your website?

    I don’t really. Most of my images are stored in an S3 bucket and pulled in from there.

    100. We’re out of time! How do you feel after answering 100 questions? ….other than exhausted.

    It’s a lot! But once you get in the groove of things you can answer 100 questions pretty quickly.

  • Scroll trēdecim

    Welcome to volume thirteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. In this edition, we take part in the web revival, focus on Fedi community, and share urgent info with Dell owners.

    This issue is a few days late—oops! Unfortunately, I just wasn’t able to get it out at the usual time due to some travel conflicts. But, here it is!

    IndieWeb

    Welcome back to the IndieWeb corner of this li’l ol’ newsletter. A place where you (the larger IndieWeb community) publish into the ether—and the void screams back…

    It may not be BIG big (yet), but make no mistake, the “old web” revival is here. As they say, what’s old 1.0 is new again. There’s no one way to be a part of it. No one way to enjoy it. All that’s required is you get your own little space (no matter how silly), and put your stuff there. Let’s bring some whimsy back to the net—together!

    One of the best parts about the “IndieWeb” is how few “requirements” there really are. Your website being “good”, i.e. being well-coded, or having objectively “good” aesthetics, or whatever is not in that list of requirements. But, even so, you want your site to reflect who you are, and to help, there are TONS of resources these days—tools, frameworks, development kits, “construction kits”, static website hosting providers, and non-profit / community-oriented git hosting services to name a few! Heck, there’s even tools to help you old-webbify modern sites!

    I’ve said it before, I’ll say it again now, and I know I’ll mention it again in the future—there’s so much you can do with your site once you have it up. Tinker with typography (check out all these awesome sites for example), do some link-maxing (maybe start with a link directory?), set up your h-cards, be inspired by web antiquity, or simply get a li’l silly.

    Once you’ve got your site looking and functioning as you’d like (as much as one can before you want to tinker again), you can do a bit of writing! Looking for ideas? Maybe consider taking part in an IndieWeb carnival, write about anything notable from the past week or document the tools you use.

    Just remember though! ⬇️

    Want to find others on the IndieWeb? Check out IndieNews, the omg.lol directory and Hypertext TV. Or tune into what others on the IndieWeb are linking to and sharing, like I do here each week!

    Small Web Finds and Features

    Awesome sites and cool people I’ve discovered in the past week…

    Typography Inspo

    Rach Smith asked the Fediverse for examples of sites with cool typesetting/font choices and the Fediverse responded. Here’s some of my favorites! (in no particular order)

    Fediverse

    Let’s be real, the Fediverse is special. Here, it’s not about metrics or virality. Instead, it’s about communities (e.g. music!) and individuality. You don’t have to beg for likes, or followers—just be yourself and make real connections.

    Fedi’s no social panacea though, everyone has something they’d like to change about it if they could. Fortunately for all of us, there are A LOT of people contributing, building and working on making this place better each and every day. Tim has some ideas on url schemes for decentralized social, Panos has an update on Catodon (based on Iceshrimp), PieFed is a Lemmy alternative written in Python, Radicle is a decentralized Git-based code forge, Liaizon maintains an awesome Fediverse Iconography pack, technomancy has set up a little place for bots and Lemmy Federate is a cool tool for helping threadiverse communities grow!

    Cybersecurity

    Howdy cyber-friendos! If you haven’t already, come check out the cybersecurity community on infosec.pub! It’s one of the larger infosec-related Fedi communities and one that I can envision being incredibly vibrant in the not-too-distant future!

    What else is cyber-interesting this week… Here’s a cool tool for searching across /.well-known pages. Want to learn more about security-related web headers? Check this out from Semgrep Academy. Mattia has thoughts on effective documentation for certs, CTFs, pentests, etc… using Obsidian. Straithe wrote up a review of the (oft-asked about) Google Cybersecurity Professional Certificate. Oh and Update Yo Dell, foo!

    Thanks for reading Scrolls! Time to be movin’ on!

  • Scroll trīgintā

    Welcome to volume thirty of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we make the web beautiful, beat the drum of decentralization, and find a whole slew of cybergems.

    So get scrollin’. It’s good for ya!

    IndieWeb

    The web can be beautiful and fun, if we make it so. The future of the Internet is not fated, and you don’t need permission to inject a little good, a little humanity, into the world (wide web)—to shape it for better. Because the web evolves not on its own, but through the countless decisions we all collectively make. The consequence of not trying, could be the loss of what we hold dear.

    So start a blog! Use it to express yourself. Shout into the void—the void may be more conversational than you think. Show us your books. Make a button, and share it with friends. Write about your hobbies. Get Jekyll-ey (or 11ty-ey)—it’s a great way to blog! There’s no wrong answers here. It’s a blast to work on your site, and equally fun to explore other people’s li’l digital gardens. 🌱

    Small Web Finds and Features

    Every site on the IndieWeb is unique, that’s what makes it great! Here’s some cool sites I’ve found recently…

    Fediverse

    Ya know what we love to gripe about on the Fediverse? Other social media networks. One of the all-time favorite punching bags seems to be Bluesky. One thing you need to know about Fedi (or atleast a subset of relatively vocal individuals on Fedi) is that you ain’t nothin’ if you ain’t federated. Centralized social platforms are the enemy (mind the alternatives!), and you best beware of faux-decentralization as well. And since we’re on the subject of Bsky, understand that ATproto, despite it’s many flaws, is not completely meritless. I, and many others have applauded it’s approach to handling identity, and it’d be awesome to see the Fediverse solve for this issue as well.

    But enough about things we don’t like. Let’s talk about what we do like! For me, that continues to be the impressive innovation and sense of community the Fediverse brings. Lately I’ve been following the WebIntents, Holos and Fediway projects.

    Cybersecurity

    Some great reading coming out of the infosec community recently… 📖

    Thanks for reading Scrolls. Stay warm out there!

  • Make a Fucking Website

    What are you waiting for!
  • AI Vulnerability Names

    Some vulnerability name suggestions perfect for the current times:

    • SlopBleed
    • Slopsploit
    • SlopShell
    • ETERNALSLOP
    • SLOPwn
    • SlopShock
    • Slopocalypse
    • SlopFlood
    • SLOPpySeconds
    • SlopStrike
    • SlopHell
    • SlopLeak
    • Sloppageddon
    • BadSlop
    • SlopHole
    • DeathSlop
    • Slop4Shell
    • Slop of Death
    • GhostSlop
    • SlopNightmare
    • DirtySlop
    • SlopFool
    • SlopStorm
    • SlopScream
    • SlopFault
    • Slopperoasting
    • LeakySlop
    • Slop2Root
    • Slop Sad
    • SlopFAIL

    These come free. You’re welcome vuln researchers 🤗

  • Scroll vīgintī trēs

    Welcome to volume twenty-three of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we make the web better, learn “how to Fedi”, and feed our infosec-hungry minds.

    Speaking of food, who’s excited about pumpkin pie? 🙋‍♂️

    IndieWeb

    Given everything being done (by AI and corporations in general) to make the web worse, what can we do to make the web better? One idea—make the web webbier. That’s right! If you find something good, something that makes you smile, something interesting, something human, share a link to it. But don’t stop there! If you find a site that you enjoy, try subscribing to it, so it doesn’t get lost and you can continue to enjoy new content as it is published.

    The web is for reading. The web is for writing. The web is for sharing. It’s a lot less difficult to make a website than you think. Once you’ve got one, you might think that writing for it is hard. Maybe you think no one will read it or care what you have to say. Or you think that you have nothing interesting or novel to share. Forget all that. You’ll be surprised what you can produce, and who will find you if you stop worrying and just write. You can also publish pseudo-anonymously if you’re feeling a little shy about attaching your true identity to what you publish.

    Small Web Finds and Features

    Speaking of sharing links, here’s some cool stuff I’ve found over the past week…

    Fediverse

    Stop me if you’ve heard this before (and you definitely have if you’ve been reading this publication for any amount of time)—The Fediverse is the best. But just because it’s the best, doesn’t mean it’s the most intuitive or easiest to use. Things are… different around here, a strength to be sure. For example, we don’t really have an out-of-the-box algorithmic feed. Instead, you really need to follow a lot of people, and scale back individual accounts you don’t want from there. But this highly curated approach empowers you to build a feed that will make you smile, rather than endlessly doom-scroll. There’s no one right way to be here either. The Fediverse comes in so many interesting flavors. So join up, follow folks, do your li’l posting, and get ready to go fungal!

    Where the Fediverse may fall short in terms of raw numbers, it can make up for in its communities. The Fediverse has staying power, and with that comes the innate quality of communities built to last. A network of builders, thinkers and plain-ol’ normal folks invested in the Fediverse continue to strengthen this very aspect as well. Organizations on the Fediverse are actively catalogued, verification utilities are being developed, first-party “starter packs” are a-comin’, and community-based moderation continues to prove itself more robust than anything that “competing” networks have ever been able to provide.

    Cybersecurity

    Who’s hungry for some cyber this week? Let’s slap a little mayo diffie-hellmann’s on this secwich and get mind-munchin’!

    On the reading list for this week we’ve got Mozilla’s wiki on Supply chain attacks, a fascinating writeup on SATCOM Security related to eavesdropping on satellite communications, a lengthy guide on LLM Poisoning from SYNACKTIV, and an intro to The Clean Source Principle from SpecterOps (one of my favorite infosec blogs).

    Lastly, a few things to bookmark and add to your infosec tool belt…

    Thanks for reading Scrolls!

  • Captain's Log, Entry: March 30, 2026

    Spring has sprung, and with it a new garden 🌱 — the Vulnerability Garden 🪴! That’s been a big focus of mine the last week or so (and is still under development for my v1.0 release). I was in San Francisco earlier this month ✈️. Nothing else particularly noteworthy to highlight for March…

    Site News
    • Added a theme-color meta tag, which makes the color scheme more consistent on mobile device header bars and gives that pop of color when pulling down the page on certain browsers (e.g. Safari).
    • Signed up to host IndieWeb Carnival for April 2027. Stay tuned for that (need to come up with a prompt 🤔).
    • I’ve welcomed Vulnerability.Garden 🪴 to the shellsharks family!
    • I now have a human.json file published.
    TV
    • Knight of the Seven Nine Kingdoms: Season one was great! Only complaint is that it was too short 😢
    • Task: Kinda stopped watching this one…
    • Scrubs: It’s damn near pulling off the impossible—recapturing the humor and vibes of the original Scrubs seasons. Genuinely enjoying it.
    • NBA: The Lakers are on a roll. Still can’t believe the Mavs gave up Luka 😂
    • Paradise: Season two has still got it!
    • One Battle After Another: This movie was ok. I probably would never watch it again. It wasn’t confusing… but I did just have this vague sense of like.. what is going on, hanging over me throughout the entire flick.
    • Frankenstein (2025): There were parts of this movie I really enjoyed, other parts didn’t quite land. It does make me wonder about how exactly, from a physiological perspective, Frankenstein is so strong and impossible to kill.
    Life
    • 👨‍🌾 Spring! Soon (April) I’ll be executing on my (garden) plan.
    • ❤️‍🔥 Finally got my feelings about burnout off my chest & heart.
    • 🎁 My birthday came and went. It was fun! I went out antiquing (in a way) with my son (we bought a gigantic bird house), and then got hibachi (per usual) that night. Hibachi is the best. 🤤
    • ☀️ Porch weather is back! Porch weather is the best! Though this will be the first spring (a.k.a. pollen blasting season) my porch will be subjected to, so I need to figure out what I’m going to do in that regard…
    • 🌉 Was out in San Francisco for work early in the month, so of course I went to Mamas (twice)!
    Thoughtstream

    Just a stream of random thoughts…

    Paperclip

    I came across Paperclip on my feeds at some point and just… what? I’d love to see a writeup of someone earnestly using this and see what happened. AI has gotten out of control.

    Afraid of AI

    Rick’s piece titled “Am I Afraid of AI?” is a near-perfect encapsulation of my own feelings. Go read it and save me the hassle of writing up the same thing.

    Bluesky CEO transition

    Jay is out as CEO of Bluesky and Toni has stepped in. Woo. I’m kinda over talking about, criticizing, poking holes, or otherwise debating Bluesky-related things. Bsky is gon’ bsky y’know? I have my doubts about the networks long-term viability (and other things) but whatever. If people like being there then that’s great! If it lasts for years and years and finds meaningful success along the way then that’s awesome. If it crashes and burns and people have to “flee” elsewhere then we will deal with that then too. I’m focusing on more positive writing pursuits these days. 📖 *closes book* 📘 😁

  • Scroll vīgintī

    Welcome to volume twenty of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. In this quieter week, I ask, “why do we blog?”

    IndieWeb

    Why do we blog? What keeps us online? How do we find balance in it all? I suppose… for me it’s many things. I enjoy sharing what I find, what I learn and what I enjoy with others. Second, I find blogging helps me process, helps me remember, helps me decompress, helps me celebrate, and helps me further understand the variety of things I encounter throughout any given day/week. In this journey, I have also (somewhat surprisingly) found something I did not originally expect—community. So though I don’t consider a lot of what I write and share here particularly “important”, I do take the process of blogging, and site-owning in general, pretty seriously. And ya know what? I think you too can find the magic here.

    Enough with the why. Let’s talk about what we can do-with or add to-our sites this week. You don’t need anything fancy, an upgrade as simple as adding an email address to your RSS feed would make for an excellent improvement to your site! Let’s see what else… You could try a new blogging framework, learn about and then deploy some new CSS, add some Slash Pages, or collect and share some good links (y’know, like Fyr is doing!). If nothing else, you could simply write more.

    A few final things to share in this week’s somewhat-teeny Scroll…

    • Bonfire looks to be a promising place for future long-form content.
    • RSSRSSRSS can help combine RSS feeds.
    • Channel.org is here to help you take ownership of your presence, content and communities on the web.

    Thanks for reading Scrolls. Stay cool!

  • Scroll vīgintī duo

    Welcome to volume twenty-two of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we take a look at an IndieWeb journey that is yours for the taking, reflect on the power of (true) decentralization, and kit up on the cyber front.

    IndieWeb

    It’s fall! 🍂 Time to get hyper-weird with it.

    Ya gotta get started first—and for that, you gotta get your own domain name! Got it? Now write up an intro post (check this one out too!). You’ve now set off on your IndieWeb journey—there’s so much fun stuff to do from here! Write up your weekly thoughts, establish your favorite color, just write and be yourself! Sometimes, it’ll feel like you’re just scraping by—creatively or emotionally. But there’s lot of ways to get inspired and involved again. Five years from now you can look back at all you’ve done and know that you’ve become part of an awesome community.

    But why should we do this? Why blog? Why have a website? Well because they’re the best, that’s why! Humans are meant to communicate and connect, and the Internet makes this possible at an unimaginably grand scale. Don’t overthink it either. You don’t need to “build a following”. You don’t need to sell things. You don’t need to have a brand. You can literally just be you. Creating some “Slash Pages” (as Joe did) is a great place to start. You can construct your site however you want too. It doesn’t need to follow the same old boring template. Be creative! It also doesn’t mean you can’t use traditional social media, consider POSSE-ing.

    We (humans) should decide the future of the Internet. It can only slip away from us if we let it. It’s all already there too. It really always has been. Write, share, commune—we’re in this together. It’s not too late.

    Fediverse

    Decentralization is power, and in the face of malignant power, decentralization is resilience. So let’s descend further into the light of the abyss

    Some tools to light the way.

    Cybersecurity

    Sometimes cybersecurity is awesome. Oh so often it’s just kinda sad and failz

    Some good tips for staying out of that fail category—keep secrets out of your logs, understand REST API edge cases, lock down your supply chain and think twice before vibe coding!

    🔥 It’s dangerous to go alone! Take these. 🔥

    (Some useful tools and resources)

    Thanks for reading Scrolls!

  • Captain's Log, Entry: April 30, 2025

    April came and went it seems, but I’ve been up to a lot! Notably, I’ve got a lot interesting TV I’m watching these days, and my trip to NYC was a blast!

    Site News
    • In April I’ve published 6 notes, 11 blog posts, 0 devlogs, 4 scrolls, 1 captain’s log and shared 4 links on my site. That’s quite a few blog posts if you ask me.

    • Scroll 13 was late, but it got out none-the-less! The next edition should come at the normal time though. I really thought I’d be able to get it out while I was traveling, but as it turned out, I was just too tired at the end of the day to put the heart and energy required into writing it up. That said, I had all the content already so I was able to put it together rather quickly once I got back home. I really expected someone to message me wondering where the issue was, but no one did 😅. But, people seemed excited enough once it finally did drop! 🧡

    • The nerve of scam detector to give my site a 76.7 scam score 🤣

    Site References

    My site has been referenced and shared a bunch this month! Here’s some examples…

    TV

    I’m watching a lot of great stuff this month.

    • Finished Star Wars: Rebels and Reacher (season 3). Rebels was great, Reacher was meh
    • Started watching Last of Us (season 2), Andor (season 2) and Paradise
    • NBA playoffs are goin’ on (looking grim for the Lakers rn frfr)
    • Also randomly been watching episodes of Fixer Upper. Love that show
    Life

    What’s been goin’ on life-wise…

    • ⚡️ My much-anticipated screened porch build has stalled out waiting for the electrician to do his thing
    • 🌸 My cherry blossoms bloomed and then fell 😢. But, some other plants around the house have started to bloom which is nice. I’ve got a particularly nice Rhododendron that has started to pop this week
    • 🤧 Loving the temperature this time of year…but it’s kinda ruined by the pollen and thus the SNEEZING!! 😤
    • 🌆 The trip to NYC with the kids was a blast. I always forget how omni-present good food and coffee is there.
    • ☕️ Still making cold brew. It’s delicious.
    • 🍏 Speaking of drinks I’m into right now—I’m really in a hard cider phase.
    • ☠️ ALSO, speaking of things that are ruining Spring, I’ve got quite the crop of poison ivy that has started to take over certain parts of my backyard. I really despise poison ivy.
    • 🎶 Sleep Token is CRUSHING it with their new album releases. Absolutely love the first three songs they have dropped.
  • What's a newsletter?

    @darius@t54r4n1 I’ve never thought of a “newsletter” as being defined by its transmission medium, though I understand the instinct to associate the “letter” suffix with e-“MAIL”. I’ve always emphasized the “news” part of newsletter (w/ “letter” referring to the fact that newsletters were written, i.e. not videos or podcasts). In this way, newsletters would be defined more as written pieces that focus on recent topics (i.e. news), regardless of how it is delivered.

  • Computers can be understood

    I love this piece. In my line of work (infosec), it’s easy to go up against some random complex system and feel a little intimidated. But if you just take a breath, lean on foundational understanding, and then just get to work reading documentation, experimenting with the system, and piecing together an understanding of the system component by component, it really doesn’t have to be as daunting. A good read.
  • Scroll duodecim

    Welcome to volume twelve of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, we’re brewing web-potions, celebrating the Fediverse, and scrapping some funeral plans (for now).

    IndieWeb

    Welcome back to my charming li’l sanctum on the ‘net—here we remain spellbound, pressing ever deeper into the enchanting realm(s) of the IndieWeb. I’ve always ascribed magical metaphors to my site, hence the “Scrolls” wordplay. While others tend to their gardens 🪴, or furnish their homes 🏡, I always see this site as a place for incantations 🪄, potion making 🧪 and all manner of digital sorcery 🧙‍♂️.

    Don’t get it twisted though, blogging is more than mere cosplay. Blogging helps us think and explore our own understanding of things. It helps us reflect and process. It helps us concentrate, extracting even more joy from the things we already love. Our web-gardens, homes and wizard hollows are quite literally “personal infrastructure”. What do you expect to get out of blogging—why do you do it? For me, it’s always been these things. Maybe it’s simple attention you seek, or a bit-o-money (just keep it classy won’t ya?). It doesn’t have to be one thing, it needn’t be shallow—but one thing it should be, is you.

    It’s not shameful to seek attention though. To want others to see, and enjoy what you have created. As much as the IndieWeb is about you, it’s just as much about the larger community of personal sites—of real people, jus’ doin’ their thang and bein’ themselves. It should go without saying, we love blogs here. We really want you to start one. We want to read, save and share your blog(s) on our own sites. You’re not alone. Get out there! Network and participate in some good ol’ fashioned writing events. IndieWeb Carnival is a good place to start. In fact, I just got in on my first-ever carnival!

    Some folks shy away from creating a personal website because they “aren’t strong writers”, or they feel they “don’t have anything interesting to say”. Let me just say, you don’t need to be some perfect writer, nor do you have to have literally anything novel or particularly interesting to say to have a blog. ‘Nuf said. More to the point though, having a personal website is so much more than just blogging! It’s about expressing yourself, and having fun. Here’s some ideas for things you could do on your site that are not just writing. Elle crafted up a custom 404 page, Ruben has a /museum page for all of their websites-of-yore, Éric coded up some cool text-rendering visualization, while Jeremy simply streams his life away. Just get creative! Break the “rules”. Do whatever you like. Share a recipe you love, or haul off and rewrite your whole dang site. Enjoy the journeythere is no “destination”. Your site can be forever!

    Small Web Finds and Features

    Looking for more inspiration or just want some awesome sites to add to your RSS feed? I’ll trade you some of my finds—send me yours!

    Fediverse

    Happy belated Fediverse Day everyone! 🥳 (In case you missed it, Korean-Fedi pioneered the idea for April 11th). Keep bein’ awesome!

    Every week there’s lots to celebrate here if you ask me though. We’ve come a long way afterall—with even more exciting roadmaps ahead! So if you haven’t already, join the Fediverse, get in on the conversation, add your color—because things are positively blowin’ up right now!

    Stormy Skies ⛈️

    While the Fediverse parties on and continues to live up to its promise, I can’t say the same for ol’ Bluesky. Look, I don’t like to make this publication about any level of negativity—and believe me, there’s plenty I could “report” on in terms of Fedi-related drama each week. But I think it’s important to drive home the ever-salient point that Bluesky is not the panacea it claims to be. Specifically, around its claim of decentralization and that it is some safe haven from billionaires and oppressive governments. It’s not.

    So here’s the story—in short. Reports indicate that Bluesky is capitulating to Turkish government demands to take down certain Bluesky posts. Since Bluesky is not decentralized, and subject to governmental orders from regions they wish to operate within, this means all members of the network are affected by such requests. In a true decentralized model, i.e. what the Fediverse has, you may have single instances subject to regional jurisdiction, but the wider network, which is spread across the globe would remain relatively unaffected. I.e. a Turkish Fedi instance could/would be vulnerable to these demands, but instances in say, the Netherlands could just ignore them. That’s one of the benefits of actual decentralization. So, be careful where you’re placing your social chips these days.

    Cybersecurity

    The big story this week is undoubtedly what’s been goin’ on with cve.org. I’ve got a whole writeup about CVE’s near-death experience if you’re interested in catching up or hearing my thoughts.

    Beyond that, kinda a light week. I discovered a few cool detection rules resources—Rulehound & AttackRuleMap. Writeups.xyz looks like a great collection of bug-bounty writeups and Talos has published their year in review.

    IndieSec Blogs

    Much like the greater IndieWeb community, IndieSec too has so much to discover. Check these awesome sites out!

    Thanks for reading Scrolls! Now back to my potions. 🧪 😃

  • Scroll ūndēvīgintī

    Welcome to volume nineteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, we pick up the scraps, help others join the Fediverse and get a li’l phreaky.

    Three issues in one week!? Yep, I’m back. Y’know, from time to time you just gotta recharge a bit I guess, and I’m not the only one! Sometimes, you don’t blog, you just blob.

    IndieWeb

    Before anything else, I wanted to share some sad news from the IndieWeb world. I found out from Adam that Anne Sturdivant (a.k.a. @anniegreens) has passed away. I enjoyed reading her posts and her WeblogPoMo was the first monthly writing challenge I ever participated in. She was a critical part of my early IndieWeb journey and for that I am thankful. Her spirit lives on through all the people, like myself, that she inspired—to bring kindness, humanity, creativity and individuality into the world through our digital gardens. 🌱

    As I have learned, and personally experienced, having a site and a blog is an extremely rewarding journey. In fact, it can even be all-consuming at times. Once you settle into a nice writing routine though, it just makes for a great habit in my opinion. A place you control, where you can share whatever you want, whenever you want, and in whatever form you want. You can add to it, edit it, delete it, change up the look—anything. It’s yours! For my more comprehensive advice on blogging, check this post out! Interested in what other people are up to? Take a trip to URL Town! 🚙

    Looking to make, upgrade or grow your current site? Here’s some ideas fresh from the IndieWeb-World! Axxuy, sainthood and Abhinav have all been tweaking their /links pages and Ross introduced his new “/connect” slashpage. Cool!

    But my favorite new thingy I’ve seen recently has been from fyr.io. Scrolls went on an unplanned hiatus for a few weeks, which seemed to have left a bit of void. Many folks reached out to me during that time, and since returning, saying they had really missed it. That has been extremely heartwarming to hear, and quite frankly, pretty energizing. But fyr took it one step further, coming out with their own Scrolls-like newsletter/roundup, dubbed “Scraps”.

    I love it, and speaking directly to Fyr, I hope you continue to publish it, in whatever form and cadence you like. These little roundups are one of my favorite blogging vehicles and if my experience with Scrolls has taught me anything, it’s this kinda human-curated boosting that really helps connect the broader IndieWeb community and supercharge discovery, especially in the face of rapidly declining search engine usefulness and increased fracturing of traditional social communities. You may have made Scraps to fill a Scrolls-shaped void, but I promise you we need as many of these things as we can get! 🧡

    Fediverse

    The Fediverse is, in my humble opinion, the best social platform on the web right now—and will continue to be for the forseeable future. Not because it has zero problems mind you, but because of all the unique benefits it has, that you simply can't get elsewhere. One issue stems from one of its benefits, that is, its decentralized nature. Specifically, it has proven difficult for many to decide what instance to join when they are first creating a Fedi presence. There are different instances, different platforms, and lots to consider between all of them. To help navigate this, StartHereSocial or suggestions from folks who have been here a while are great places to start. I for example have my own list of Infosec Instances that you could check out if that is your thing.

    What else is happenin’ around Fedi’? FediCon is comin’ up for those near Vancouver, Bonfire has an Install Party you can check out and Tim Chambers has dropped his The Seven Deadly Fediverse UX Sins Part 2 which is 100% worth the read!

    Cybersecurity

    Gotta real grab-bag of cyber-ey things this week…. ‘ere we go!

    I’ve got a lot of infosec certs, so I feel somewhat qualified in telling you that what you get out of most of them is really not much. But y’know what, I’ll let CrankySec explain instead 😈. Want some actual credentials? Or real skills? You don’t have to look far, and you don’t have to spend much (if anything). Just look around! The Internet is bursting at the seams with free resources, writeups, trainings, tools, everything! Wanna learn how to forge passkeys? Got you. Want to write secure Rust code? Boom! Wanna fingerprint some network devices? Here ya go. Wanna take a trip down memory lane ya li’l phreak? Everything is here (i.e. the Internet), if you know how to find it, and have the will to just dive in and start learning, tinkering and building. Get out there!

    Thanks for reading Scrolls. Now, it’s coffee time!

  • Conflagration

    I don’t think I really know when it happened—the “burnout”. It’s not something that happens all at once. Maybe you see it coming, you start to spot the signs. Or, if you’re like me, you don’t know it’s happened until months or years after being mired in the after-effects. I would slipin… and out, of the conscious realization that I was indeed burned out. There were times I found myself very lucid, entirely aware of how burned out I had become. Through other spans of time I managed to disassociate entirely. How long was I there? I can’t honestly say. The entire lifecycle from burning out, to burned out, to realizing I was burned out, to recovery, is not a straight path, and not one that has some known, or widely-accepted timescale. Come to think of it, I really haven’t seen many accounts of severe burnout. I suppose that’s because those who experience it are likely too burned out to write about it. So, am I back? Hah! It’s not that simple unfortunately. But I am in a place where I feel that I can share my experience.

    Notice: This is a particularly personal accounting of my real-life experience with burnout, and everything that comes with it.

    Look, I’m not going to lie to you. I haven’t come here to say that I’ve unequivocally “recovered from burnout”. A nasty thing about burnout is that it isn’t some obvious, precipitous decline. It isn’t necessarily marked by some singular, triggering event. What causes burnout from one person to the next is never the exact same, and each of our paths can look wildly different and result in varying levels of burnout—the manifestations of which can also be quite variegated. Similarly, the path out is not straightforward. It is not an extrapolatable line upward and outward. This is an upswing for me, sure—writing this post. But I’ve been here before. I first thought about and started drafting this post nearly two years ago, around early May of 2024. This too would have been sometime well after I first realized I was “burnt out”—when I finally had enough energy to even give the notion of writing about it some thought. I can’t point to a day, or to a moment, or to a thing-that-happened and say “that’s when the burnout began”. However, I suspect that my own case of burnout began accelerating in early 2022, with “full burnout” finally happening in mid 2023 when my daughter was born, at which point I stepped away from it all on leave. I’ve been torched ever since.

    How did it happen? Gah, I don’t know. There’s any number of things I can point to and say were contributing factors. The pandemic, too much work, not enough recognition at work, friendships lost, parenting stress, stress from the world at large, stretching myself too thin with side projects, the list goes on… We’re all conditioned to work, work, work. Reach higher, stretch into that role, stretch for those goals, get a better title, get more money, post our travel photos online, more, more, more! It’s just kinda… exhausting, y’know? In those 18 months from early 2022 to July 2023 I was pretty busy. I was in a demanding role at well-known big tech company, I had some side projects going on, I was publishing this blog + my podcast—all while doin’ the parenting thing. I pushed and pushed to do more and more, and did so in a way that was in hindsight, entirely aimless. Yes, I did a lot of things, but to what end? Were they in pursuit of something specific? Did those things make me happy? When my daughter was born I was just, tired. It was time to step away from the work and focus on those early months with a new baby. Eventually, I came back to work. But I didn’t really come back—not entirely. I had lost the drive and the motivation. Things that once interested me no longer did, and I’m not just talking about work stuff. I wasn’t as active on the blog, a lot of my hobbies just completely died, I was in battery-saving mode—just doing the bare minimum. I did what I had to at work, I ate, I went to the gym, I played with my kids and I slept. There were other hours in the day, but I’m not sure what I did with them.

    I don’t want to misrepresent things here either. I didn’t spend my days doing “just the essentials”, keeping the lights on, and doing them well. No, no, no. In my haze, I’m not sure I did anything with the focus and enthusiasm that it deserved. My time spent at work was unfocused, often unproductive, and from my perspective, entirely meaningless and unfruitful. I got things done sure, but they didn’t seem to matter. No one said “good job”. I never felt accomplished. I could go days, or even a week or more without talking to a single person. I didn’t feel like I was learning anything. I felt that what I did there didn’t matter. That I didn’t matter. No one needed me and I had nothing to offer. While I stood alone and still, everyone else seemed busy, effective—happy. I would see proud messages of others in my team and across the company achieving promotions, or completing highly-visible, impactful projects. Sometimes I was jealous, but more often I felt nothing. I wasn’t inspired, I just continued on. At first it was just a month lost, or a quarter lost. But eventually it became this awful gap. A year or more where I’d been entirely stuck. Even if I could get moving again, look how far I’ve gotten behind.

    My podcast fell to the wayside. My blog lie unupdated and dormant for months at a time, gathering cobwebs. I had aspired to a great many other things in the larger world of “shellsharks”, but I forgot about all of them. I announced >Shark Week in multiple years only to completely ignore it when the time came. I never conciously “gave up” on the blog… I just stopped. This wasn’t a purposeful attempt to reclaim time for work, or for parenting, or for my sanity. I was no longer in the drivers seat. I had simply, unpurposefully, disconnected. Sometimes I would remember it was there. I would think about writing something. Or I would catch up on a few things I wanted to update—breathing a little bit of life into the site. But for a long while, it didn’t amount to more than that. Folks who I came to know through my site, or through social media reached out to me. Wondering where I had gone. Wondering if I was OK. Eventually I saw the messages. I let them know that I was fine. Things were just busy. This was true. But it wasn’t the entire truth.

    Even as a parent, and a full-time job-haver, I still have hobbies. Or I did. Through these darker days I still tried to go to the gym… but those sessions never got my full focus. I had projects in the yard, or around the house, but I never really got to them. If there’s anything that I managed to still be kinda “good” at, it was playing with and having fun with my kids. But even while doing that, I still often worried about work, never being able to fully be happy in the moment. Too often I sacrificed time I should have spent with my wife or family because I felt guilty about work. Then at work I felt circularly miserable about a perceived degraded home life. Vicious, some say.

    That feeling of being behind on things, of feeling unfocused, of feeling unneeded, of feeling unimportant, bled into every corner of my life. I wasn’t just useless at work. I also started to see myself fail at home—and forget about my friendships, these had seemingly entirely disintegrated. I felt at this point, universally alone.

    Burnout is one of those things that you try to shrug off. Everyone is burned out right? Everyone has any number of things stressing them out at any one time. Sure I may feel “burned out”, but it isn’t anything especially problematic! I found myself routinely ignoring or trivializing these feelings. I chalked them up to the routine stresses of the world, rather than fully appreciating the gravity of the state I was in. Because the difference between chronic burnout and run-of-the-mill stress is that with burnout you just can’t find your way back to a healthy “normal”. You stay unproductive and uneffective. It takes a more concerted effort to pull yourself out of the rut.

    You see, I knew I was “burned out”, and looking back now, it’s easy to see I had become depressed too, thanks in part to the burnout. Some days I would manage to pop my head above the clouds with proclamations of how I was going to “get serious”, or “lock in”, or some other way of crawling out of this quagmire. But as some of my friends and family can attest, those words were either empty or simply did not provide adequate propulsion. I fell right back into the bad habits—that same fog. In some ways, I’m still trying to really understand what I want. I think having a clear idea of what you want is key. Only then can you try and reverse engineer the steps to get there, prioritize, and make time for everything. As it turns out, there’s just not enough time in the day for everything. Compromises, or full-on sacrifices have to be made. This is the reality.

    So am I through it now? Am I OK? Am I no longer “burned out”. I don’t know. Probably not. I’ve been kinda here before to tell you the truth—“seeing the light”. I have clearer vision these days I’ll give you that. My hobbies have started to return, my outlook on work has improved dramatically, I’m using my time much more effectively. I think I’m happier these days. But it’s easy to slip back. I try to catch myself, to right the ship and to stay on course, but some days it seems the margin for error is just too thin. To lose a day in pursuit of everything is to knock myself off track indefinitely. But I remind myself that I don’t need to be perfect. I don’t need to operate at 100% efficiency. I need to understand my goals and work towards them, and not be discouraged when I falter. Success is a grind—a lot of little steps that in aggregate move us to a target destination. A step backwards, or a rest day doesn’t mean I’m back at the beginning.

    Oh, and as if burnout alone wasn’t enough, there’s a lot of other career-related blights I (and I’m sure many readers of this post) experience—often manifesting into a devilish syzygy of occupational dilemmas. Let me talk about those for a minute too…

    Demonology for the Professional World

    There’s more to the fiendish nature of our “careers” than burnout alone. We the workers, tend to be plagued and posessed by a great many evils. Consider the list below a Lanterne of Light—traditionally a classification system for (actual) demons, but in this context, the hellions of the working world.

    1. Burnout
    2. Impostor Syndrome
    3. Climbing the Ladder
    4. Professional Vitality (i.e. boredom, finding interesting work)
    5. Finding Meaning/Purpose
    6. Maintaining Relevance & Skill Erosion
    7. Isolation (e.g. remote work)

    I’m sure there are more items to include on this list, but these are the ones I’ve observed most, at least in my own career history.

    For now, this post will be limited to my experience with burnout alone. Perhaps one day I’ll expand it with tales of other such things, or maybe they’ll end up as separate posts sometime in the future. The fact is, everything in that list can contribute to burnout, and in turn, burnout and other things on that list can equally contribute to impostor syndrome. See where I’m going with this? That cursed list of professional afflictions can all feed into each other. So be weary!

    Burnout

    I told my story about burnout at the beginning of this post. Here, I want to be a bit more technical/scientific in terms of defining what burnout is, what causes it, how it manifests and how to mitigate or address it.

    “Burnout is a syndrome conceptualized as resulting from chronic stress that has not been successfully managed. It is characterized by three dimensions: 1) feelings of energy depletion or exhaustion; 2) increased mental distance from one’s job, or feelings of negativism or cynicism related to one’s job; and 3) a sense of ineffectiveness and lack of accomplishment.”

    Burnout is interesting, and scary. A lot of things can cause it, it can be hard to see it happening in real-time, and it’s even hard to tell if you’ve reached some form of final-stage “burn out”. Like, what does that even mean? How burnout can manifest itself, the symptoms themselves, can easily be attributed to other things, non-burnout related. How one experiences it, and what effects they experience can vary greatly from person to person. Similarly, treating, or recovering from burnout is not a known science. Some even suggest that you might never recover from burnout. So much about how you treat it, can probably be mapped to how it happened in the first place, which again is hard to understand as burnout tends to creep up on you slowly, over a great span of time.

    Burnout Causes

    There’s a lot of things that can trigger or ultimately contribute to “burnout”. Here’s a list… 1, 2

    • Unclear mission & expectations
    • Lack of control
    • Opaque management
    • Resource starvation
    • Lack of agency / autonomy
    • Overwhelming scope
    • (Lack of) job security
    • Long hours
    • Dwindling pay
    • Lack of recognition or reward
    • Excessive workload
    • No sense of community, kinship or camaraderie
    • False urgency
    • Unfair treatment
    • Relentless change
    • Limited growth
    • No work / life balance
    • Micromanagement
    • Performance pressure
    • Toxicity
    • Lack of support
    • Bad communication
    • Monotonous work

    There’s more to this list to be sure, but that’s a lot already.

    Burnout Symptoms & Manifestations

    Burnout manifests itself in a myriad of ways. Each person will experience it differently and at varying levels of severity. Some things you might experience are listed below…

    • Exhaustion
    • Activities, particularly social ones, drain you faster than usual
    • More venting / complaining
    • Hopelessness
    • Demotivation
    • Disengagement
    • Over-sleep
    • Feeling of never being inspired
    • Craving to work on projects but can’t
    • Stress
    • Depression
    • Laziness
    • Depersonalization (i.e. loss of sense of self)
    • Physical health issues (e.g. gastrointestinal, cognitive decline, heart palpitations, pain, etc…)
    • Guilt
    • Job switching
    • Procrastination
    Treating and Mitigating Burnout

    Probably the least understood thing about burnout is how to actually recover from or treat it. Sustained triggers are simply not easy to reverse and not easy to do a root cause analysis for. And even if you could identify everything that ultimately led to being burned out, is it realistic to expect that each of these things can be removed? How do we treat burnout while often having to continue being exposed to some subset of the same triggers that caused it in the first place?

    One study attributed burnout, and in reverse, treating burnout to 6 main sources: workload, values, reward, control, fairness, and community. Another study suggested a framework known as “I Believe, I Belong, I Matter” as a path towards avoiding burnout. 4, 5

    In both cases, we are directly treating the initial triggers or feelings-caused by said triggers. I don’t know what works. I think these things all sound great, but what actually works—who knows.

    I think time is important. Sometimes you just need to step away. But time alone isn’t enough. I for example spent quite a bit of time away. Sure, I wasn’t able to completely shield myself from the burnout triggers, so maybe that time away wasn’t “pure” in the recovery sense, but I feel like the time I had was as good as anyone can really expect. Afterall, if you’re a parent, or if you live in the real world, it’s just not overly practical to step away from your kids, or from your job, etc…

    An important step is (and I mentioned this earlier) to think about and solidify what matters to you. What makes you happy? What do you really want to accomplish? Once you have this down, you can start to put together some semblance of a plan for getting there. Your goals need to be the composite of tasks that are realistic and actionable which amount to achieving said goals. You also need to give yourself room to fail, so you won’t be entirely discouraged if you aren’t perfect. Because you won’t be. You’ll never be—and thats OK.

    The Way Forward

    So what’s next? Well I’m still working on climbing out of the burnout hole. I have some ideas for how to kickstart myself professionally, and I am working on a more defined plan for the other things in my life. It’s not going to be a straight shot up and out, and burnout isn’t something you “defeat”. It’s something you manage. I’ve seen how it can manifest, I understand some of my triggers, and I know a few things that can help me treat and mitigate it. That’s enough for now.

    Thanks for reading. Take care of yourself out there!

    References & Resources

    Other burnout stories from the field:

    Fun fact! The original draft for this post was May 3, 2024.

  • Gardenlog: Blueberries, Blackberries, Oh My!

    OK! Checking in now on all things garden-ey from the past few weeks…


    Tomato Updates

    The Cherokee Purple’s have really gotten tall! Some yellow flowers here and there but no sign of fruiting as of yet. Just gotta keep on waterin’ ‘em and see what they do. 🍅

    Blueberries, Blackberries, Oh my!

    After some serious snipping, I was able to remove all of the invasive honeysuckle that had managed to grow in-between the two blueberry bushes that it turns out I have on the side of my house. Between the two of them, there seemed to be 100’s of berries! They ripened at various times and it was a blast hand-picking them with the kids and eatin’ them on the spot. But it’s not just kids that like berries—birds and squirrels do too—and they came for them… So, I bought a little tulle to try and protect the berries (as shown below). Has it worked? Hard to say. I don’t think I did the best job wrapping the bushes to begin with so inevitably the little critters found their way in. Now I’ve just got one bush wrapped and I think it’s doin’ a decent job at this point. The other bush is just about picked clean.

    Next to my blueberries, I’ve got this other berry plant. For a while I thought it was some kind of blackberry, but it could be a raspberry too perhaps? Take a look at the following two pictures and let me know what you think…

    Either way, delicious berries are in my future. No complaints!

    Other stuff

    Here’s some other random things to report from the garden/yard…

    My porch project is nearly done, and here’s the current status of my future garden bed location. It’s all clear of pavers! Some work will need to be done to dig it out from here and lay in some suitable soil. Haven’t decided what all I want to grow here, but I think some cucumbers for sure (amongst other things).

    Also, as part of the larger future layout of my yard/gardening area, I’ve put in some infrastructure for a future potting bench that would sport a working sink. Cool!

    I bought a pair of potted hydrangeas. Just waiting for some flowers now…

    Finally, checking in on the wild blackerries I’ve got out back… the fruit is struggling a bit…

    Until next time! 🧑‍🌾

  • Beep, Boop, Sad 🤖 😞

    “AI” is making me, and a lot of other people sad. This collection of links will give you an idea why…

    ⚠️ WARNING!: Click on these links at your own peril. They’re likely to make you even more sad.

    I’ll update this list as articles continue to pour in. Did AI make you sad today? I’m truly sorry about that 😕. Here’s a hug 🤗. Feel free to send me a note about it and I can add it to this wall-of-sad.

    Pivot to AI is also a great upsetting compendium of such links.

  • Over/Under with Shellsharks

    Here’s my submission to lazybea.rs series Over/Under. The idea is simple, Hyde gives me some topics and I state whether those things are overrated or underrated, with some text about why. Here were my chosen topics…

    Go read this post over at lazybea.rs!

    Over/Under with Shellsharks

    IndieWeb

    By most, the IndieWeb is severely underrated—by the enlightened few, consider it adequately-rated. It’s probably of no surprise to anyone who has followed my writing for the last two-ish years—I love the IndieWeb, and personal blogging in general. I frequently write on the subject, have built many-a-reference dedicated to collecting resources and educating others, and I somewhat recently started a “newsletter”-type thingy dubbed “Scrolls”, which heavily features content and personalities from across the IndieWeb. I love me some IndieWeb.

    Slash Pages

    Though I have to give all credit to Robb for the creation and maintenance of the venerable Slashpages.net, I can give myself a tiny nod as Robb did consult me prior to the site going live on what my thoughts were on how they should be defined and what pages should/could be included. He was even nice enough to give me a named credit on the site and include my silly /chipotle slash-page 🌶️ 😆.

    Slash Pages are just fun. They are an emodiment of the IndieWeb experiment. They are meant to share something about you, the individual behind the site. They exist in a place (the root of your site) that should be relatively common across other IndieWeb sites—which leads to improved discoverability and a greater sense of community. They are also just quirky, silly and very human—something the web, and the world, desperately need more of.

    In the weeks and months since Robb launched the site, I’ve noticed a really promising level of adoption across my own IndieWeb circles. I hope to see more people have fun with this idea, add Slash Pages to their site, come up with new ones, etc… For now, I believe it is still vastly underrated!

    Sharks are Dangerous

    I maintain a healthy respect for all wild animals. They deserve as much if you ask me. They are also all equipped with a dizzying assortment of defensive capabilities. So for your own protection, I suggest everyone maintain safe distances and treat all life with respect. This is doubly-true concerning creatures that are of-the-sea.

    I’m a land-walker. On-land, I feel like I can hold my own well-enough. I can see things that approach me, I can hear them, I can run pretty fast for a human, I can even pick up something to defend myself if I needed to. Not saying I could tussle with, and win, against any manner of land-faring beast, but I can do something. When it comes to the water though? I’m completely defenseless. I can swim, yeah—but that’s about it. I can’t really see underwater, I have no means to really detect if something is about to “get me”. I don’t think my futile punches or kicks would amount to much, especially against something like a shark.

    All this to say, I do think Sharks are dangerous—or rather they can be. If you don’t have that healthy respect for them. They are apex predators afterall, and they dominate in a world that humans, just naturally don’t. You’ve probably seen that statistically, sharks aren’t particularly harmful to humans. This is probably true. As such, I think the danger of sharks is probably properly rated. Humans aren’t natural prey for sharks (thankfully), and we as humans do some things to avoid sharks where we can. Sharks are innately curious, and infinitely cool. I mean, I have a lot of shark-themed stuff on my site, so you know I have somewhat of an affinity.

    Ransomware

    I’m (professionally) in infosec, so I have an appreciation and technical understanding of Ransomware—how it can happen, how to defend against it, and the impacts of an incident. Ransomware is consistently placed at the top of “things to worry about” lists (e.g. Verizon’s DBIR) and yet, remains inadequately defended against time after time, across all observable sectors. I think it’s impossible to overrate the financial impact of a serious ransomware-related breach. Entire companies have been snuffed out of existence thanks to them—and ransomware-as-a-business in and of itself is measured in the billions, if not trillions, yearly.

    Octopus Dishes

    Fried, and then dipped in some sort of sauce? Sure. Otherwise? Ehhhh, not really my thing. Not a big tentacle guy I suppose. I gotta say overrated.

  • Scroll vīgintī quattuor

    Welcome to volume twenty-four of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we discuss the point of blogging, what social media is (and isn’t), and drop a lot of awesome infosec tools/resources.

    Scrolls isn’t dead yet. Let’s go!

    IndieWeb

    What’s the point of blogging? Who’s a blog for? I’ve always said my blog is a place for myself, but it can of course be so much more. These days, people really don’t think much about “blogging” in the classic sense. Instead, we’ve grown accustomed to shoving our thoughts into small, character-constrained boxes owned by [INSERT BIG TECH COMPANY NAME HERE]. We’ve gone from surfing to scrolling, and we lost the web along the way. This is where the IndieWeb comes into play—as a means to reclaim digital independence, and the beauty that once was.

    So what should you do with your site? (Y’know, once you’ve got one up.) You can really do anything, but I like the idea of making your site a digital home of sorts. Your site, as it exists on the web, doesn’t need to conform, or have any specific things, or be “a part” of anything. It can just kinda be there, at an address you own. You can put whatever you like there. That said, as the owner of a site, at a domain you own, you are in many ways already part of something larger known as the “IndieWeb”. So where can you go with that? Honestly, I think just writing, and publishing said writing on your site is a great place to start. If you’re looking for inspiration, community, or prompts, check out the various writing months (e.g. TILvember) or the IndieWeb Carnival. Not sure you know what you want to write? Maybe try replanting some older, or forgotten articles on your site. Or, you can help connect the web by sharing sites you love on your own site, through something like a blogroll.

    One thing you should absolutely do for your site, especially if you have, or plan to have, any type of “posts” there, is have an RSS feed—because RSS is awesome. RSS is important, it is the tried and true, reliable way to share your content with others, and consume a variety of content from across the web. Simple. Easy. Free. Do it.

    Lastly, don’t forget. AI sucks.

    Small Web Finds and Features

    Here’s a handful of cool sites I’ve enjoyed recently…

    • mcyoung has an extremely eye-pleasing indie site 🤩.
    • HISVIRUSNESS has an awesome hackery/indie feel to it.
    • This site—I’m honestly not sure what is going on with it, but it looks amazing.

    Fediverse

    What we’ve seen in the social media landscape over the past 4 years or so should be enough to convince you that you shouldn’t rely on big tech, or any social media platform to function as your “identity” on the web. But that doesn’t mean social media isn’t as important as ever, as a place for community, news, organization and more. Carefully consider where you decide to set down roots in terms of social media and building a community. No one platform is going to give you everything, but many will have certain dealbreakers that you must consider. Obviously I make the case often about the Fediverse and why it is where you should invest, but other options do technically exist. But really, how can those other options even compare when Fedi has stuff like this?!

    Cybersecurity

    New year, same cyber. Let’s see what we’ve got…

    A few interesting writeups to check out—CSP for Pentesters, Breaking Trusted Execution Enironments via DDR5 Memory Bus Interposition and The Normalization of Deviance in AI.

    The infosec community continues to pump out all manner of free tools and resources. I’ve catalogued a few I’ve recently discovered below…

    Looking to build your own infosec news feed? To get ya started, I recommend following Tim on Mastodon (specifically checking out his weekly link roundups like this one). You can also sub to the new, and cool, Hacklore Project.

    Finally, I’ll leave you with some things to ponder… Why are there so few women in infosec & why folks are leaving the security industry?

    IndieSec Blogs

    Thanks for reading Scrolls! Off to brew some zen…

  • The Cybersecurity Workforce Crisis

    Much digital ink has been spilt on the plight of the cybersecurity workforce. Is there a talent shortage? A skills gap? Other, darker issues? Here’s what I think…

    The “Talent Shortage”

    First, some back story… When I was getting started in infosec, back in 2010-ish, I remember the on-radio campaigns which spoke of endless opportunity in the up-and-coming “cybersecurity” field. Over time, the messaging became that of a severe shortage of people to staff in these roles. Even back then though, despite all the claims of a “shortage”, getting an actual infosec job wasn’t easy—even for someone with a relevant degree and a few certifications. In the years since, interest in cybersecurity as a profession has surged. You can thank the above-average pay, remote work, and other intrinsic benefits I suppose. These days, you could argue that we’ve hit some level of saturation, especially in the entry- and junior-level ranks. This is evidenced by the countless stories of aspiring infosec pros who go months on end, applying to 100’s of jobs and do countless interviews with nothing to show for it. Mind you, these are more often than not, individuals who have 4-year degrees, who have multiple certifications, and who have done many other things to prepare and boost their qualifications to best pitch themselves for mere entry-level roles. To me, I think this contradicts the theory that there is some sort of talent (pool) shortage. We’ve got plenty of people interested—raw and unrefined—but there, ready to get to work. So the question is then, if the cybersecurity workforce crisis isn’t one of a talent shortage, what is the issue? Does the existing and aspiring workforce suffer from a “skills gap”? To this, I think the answer is a resounding “yes”, but maybe not for all the reasons you might believe…

    The “Skills Gap”

    As I’ve already stated, even the entry-level aspirants and lucky receivers-of-jobs these days almost uniformly have 4-year degrees, one or more certifications, and plenty of other worthy accomplishments. Yet, this has not seemed to make a meaningful dent in the aforementioned “skills gap”. Consider now the slightly more tenured infosec pro. One who (if fortunate enough) not only has a few years of “experience” but also may have attended several trainings at this point and could then hold multiple certifications. Likely, many of those certs are from vendors like SANS, ISC2 and EC-Council. Yet again, the skill deficiencies persist. How is it that we have so many college-educated, multi-cert wielding, many-a-year-on-the-job-having infosec pros still having so little to show when it comes to real-world, applicable infosec skills and know-how? Let’s play the blame game…1

    Weak Blames

    One of my weaker blames is that of training budgets. I think a lot of companies, and thus the industry as a whole, do an abysmal job providing adequate time and budget to train their infosec workforce. But, as you’ll see in a minute, access to what passes as “training” is hardly the problem, as the training, even if made SUPER-available, is just not closing the skills gap anyway.

    Strong Blames

    My stronger blames lie with the tenured infosec community, the cybersecurity vendors, and corporate infosec programs themselves. Let’s start with the grizzled veterans of infosec—the folks with the skills. First, I want to point my finger there. There is real opportunity for mentorship, but I think as a whole, we have failed to build these bridges. We grumble and complain about “script-kiddies”, and “paper tigers” and whatever, but do we take the time to mentor and train? Nah.

    Now let’s talk about what it means to get “experience” in infosec. I think overwhelmingly, infosec professionals are put on rails with respect to their job responsibilities. Here’s some tools you are expected to know how to operate, but not expected to know how they work under the hood. Here’s a framework you are expected to audit your IT program or business against. Here’s your corporate, technical “swim lane”, that you must operate within, and never stray outside of. That sorta thing. I don’t think infosec tools are inherently “bad”, or useless in terms of providing value or reducing risk, but as you can tell from the state of cybersecurity in the world, they are in no way the silver bullet. We continue to have breach after breach, security failure after security failure due to infosec 101 type-of-stuff—stuff the tools are not stopping. These companies have tools. We have personnel that operate them. That (buying and running tools), if anything, is what we’ve become good at. But it clearly isn’t enough! The infosec industry, we as engineers, were never meant to be exclusively put behind the limited capabilities of these tools. What if we could do something different? Like, look at these problems and come up with practical solutions based on a found understanding of infosec principles.

    But herein lies the problem. The modern infosec “pro” is no longer conditioned to solve ad-hoc problems, or problems of complexity. We’ve been on rails too long. If the tool can’t solve it, how could we? If it’s not one of the exact usecases covered in the Day 4 lab of our latest SANS course, what’re we supposed to do about it! If it doesn’t fit neatly into one of our precious CISSP knowledge domains then oh no! We’ve lost our way, and with it, we’ve abstracted too much of the basics, the real engineering away. It should be expected that all infosec pros are able to do some relatively basic stuff—across operating systems, with standard networking protocols, with industry-standard, open-source tooling. We should be able to hack together basic scripts to do simple things. We should understand the tech stack and supporting protocols of any run-of-the-mill web application. But can you really say that even 20% of infosec “professionals” know these things? I’d say not. But I sure as hell would bet that each of us know one or more enterprise tools super-duper good. How many infosec folks out there can operate Splunk with medium-to-advanced proficiency but can’t actually pull and decipher a packet capture? How many VM analysts can pull off all sorts of wizardry with Tenable, but couldn’t practically exploit a real vulnerability? We’ve become too reliant on tools, and we’ve creatively and technically boxed in our security workforce as a result.

    Training vendors aren’t closing the skills gap. “Work experience” is not closing the skills gap. Those of us with useful knowlege, and wisdom to share, are not helping to close the skills gap. The skills gap is real my friends, and there is blame to go ‘round.

    Just Look At Me

    I feel I can speak on this topic because I’m a product of it. Get this cert. Get that cert. Use this tool. Use that tool. Getting certs and knowing how to use tools has been pretty great for my career, but what have I learned? Have I really advanced my knowledge? The issue with so many “trainings” these days too is that they don’t teach core concepts. They don’t cover fundamentals. They like to focus on the shiny things. The abstractions. The tools. The practical, yet hyper-specific usecases. They hold your hand through exercises and labs, giving you a false sense of know-how, but when you are turned loose in a real-world, corporate setting, you are left wondering “what do I do?”. That’s if you even get a chance to use what limited skills you may have picked up in training on the job. For most, I feel like they’ll go get training for something, and then return back to their routine daily job responsibilities, which require no practical usage of what they had learned in training. So that knowledge, when not practiced, will fade away. Plus, we’ve all just been conditioned to pick up certs, and put fancy letters in our email signatures and LinkedIn bios, entirely discounting the journey that got us there. Get a cert, get a better job. Rinse and repeat.

    Let’s Adapt

    We need to adapt. Let’s open up the cyber-swim-lanes. Let’s establish lines of mentorship from professional generation to professional generation. Let’s build training into our corporate culture and then give professionals the space to practice it, to operate with creative license, to solve problems—not with tools, but through the application of actual security fundamentals. I mean we all learn it. It’s really not arcane magic. We all have the “CIA Triad” etched into our cyber-brainz. We can all do a risk assessment—we just have become so vendor-tool-addled and compliance-pilled that we’ve forgotten how to look at things holistically, do actual root-cause analysis, troubleshoot at a low level—really solve issues, in the bespoke and tailored manner in which we otherwise could. The answer to your next cybersecurity issue shouldn’t immediately be a phone call to <INSERT VENDOR NAME> to add-on another paid module in some tool. What if instead, you engaged your cybersecurity workforce, and I mean the actual engineers, not the “cyber leadership”, and asked, “how do we solve this problem”? Then, give them the space to actually do it. I’ve seen it work—honestly, I have. The knock-on effects can be wondrous too. Save money on tooling subscriptions, have a more engaged infosec team, actually reduce risk, build a real culture of engineering, that sorta thing.

    I don’t want to trivialize the difficult nature of the infosec industry at large. If things were so easy, I imagine it would have been solved—right? But I think it’s safe to say that a crisis does exist. It’s also fair to say that the way we’ve been doing things just isn’t working. More SANS training isn’t bridging the gap (no offense SANS!). More team charters and vendor tools hasn’t bridged the gap. It’s time to do things differently.

    Look, maybe it’s just me. Maybe I’m just projecting my own shortcomings. Not everyone suffers the same, and not every company has the same all-around deficiencies. This is just the way I see things. Looking “across the industry” though, I’m seeing some of the same patterns, and I don’t think I’m terribly far off.

    1. New SANS Report Finds Cyber Talent Crisis Isn’t About Headcount. It’s About Skills. 

  • Scroll trīgintā quīnque

    Welcome to volume thirty-five of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, if you haven’t already, you should make a fuc**ng website. Y’know what? That’s it. Just go do that.

    jk jk — I also discuss some shortfalls of social media (yes, even the Fediverse), and lament the many broken computer-ey things in the world.

    IndieWeb

    I’ve said it once, I’ve said it a million times. This time I’ll say it a bit more eloquently–you should have a fucking website. Don’t overthink it! It really isn’t all that scary. Your site can be big (maybe not too big though 🤦‍♂️) or small, static or dynamic, colorful or plain, whatever you want! (Just no AI puh-leeaseee).

    Because if we don’t build our own places on the web, we’ll get stuck with the big boring box to (digitally) live in. That’s the boOooOring, vanillaweb. We want the good, fun, non-corporate, cozy, human web! So getcha a site, put alllll your stuff there (yes I mean all of it), and then go read and connect with other people doing the same. It’s fun I promise! Just remember, it’s all about being you, in a place that’s for you. Don’t get too choice-overloaded or bogged down by the technical bits 😄.

    From N-gated Hacker News

    🚀 Behold, the #IndieWeb POSSE piece: a brave odyssey into the chaotic labyrinth of infinite links and jargon! 🔍️ Navigate through a maze of enthusiasm for #DIY websites everyone will forget by next week. 🤦‍♂️ It’s the perfect handbook for the #hipster coder who thinks their blog will change the world—one unread post at a time. 📖✨️

    lol

    Speaking of fun, there’s so much to do once you have your site up ‘n runnin’. Ya gotta tinker around with the look and feel of course, write your silly li’l posts, then write some cool serious posts (y’know, if you want that is), and do all sorts of other fun things! If you get stuck, take a break and go wander about and poke around on other people sites—inspiration is abundant if you know how to look for it. For example, the Over/Under series is a great way to get introduced to cool new blogs and the humans behind them.

    Small Web Finds and Features

    Two li’l web finds to share with y’all this week 👇

    Fediverse

    Look, the Fediverse is great. I have a whole weekly section here dedicated to it afterall. But it could be better. Or maybe traditional “social media” is irrideemably flawed in some ways… Yes, it serves “connections”, but too often those connections result in something I find eerily inhuman. I think blogging allows for more a human connection, but it has its own shortfalls with respect to actually delivering said connection (i.e. discovery). You know the feeling—that sense of yelling into the void…

    Coupling these two sentiments is why I am so invested in both my blog as a means to express my humanity, and the Fediverse as the connection and discovery mechanism to spread the good word (i.e. the silly stuff I post on my site).

    Cybersecurity

    Hello and welcome to everyone’s favorite cyber-themed gameshow, “What’s Horiffically Broken”! I’m your host shellsharks and this week we have several new (and many recurring) contestants! Who will win?! We’ve got AI, the “cloud”, supply chain security infrastructure, NFC, and even SVGs! How exciting!

    Stepping away from said horrors, here’s some other neat things to check out 👇

    Thanks for reading Scrolls! Remember, even in dark times, there’s still plenty of good in the world.

  • Scroll vīgintī septem

    Welcome to volume twenty-seven of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we ponder a better, although imperfect web, we encourage everyone to join the Fediverse movement, and sigh… AI continues to make us sad.

    But ya know what doesn’t make me sad? This dope bird mage. 🐦 🧙

    IndieWeb

    The “old web” wasn’t perfect, but it’s hard to look at what the web has become and not wonder how it was lost. Those that remember have sought to build a once-again “open web”, but things are never that simple. Problems abound in this quest to be sure, but for every obstacle, there are ways to mitigate and build a better, more open, more cooperative, more human web—it doesn’t need to be perfect.

    The lifeblood of this better web is the classic personal website. If you don’t already have one, what better time than now to do so! There are so many ways to get one up and running. There are a lot of reasons to have your own website and do some blogging there too! And no, simply having a social media presence is no substitute for an actual website that you own. Personally, I like having both a website and a standard (Fedi) social media presence. But there are options for making your website/blog plenty social if you’d like.

    In fact, when it’s your site, it can be whatever you want it to be. You own it, so you can tinker with it to your hearts content, no obligations. You can update and change whatever you want, whenever you want. If you’re worried about the technical aspects of creating and managing a website, don’t! There’s plenty of no code or low-code options available. Does your website have to be good? Does it need to look like other people’s sites? No! In fact, I’d encourage you to make it unique. Make it you. Hell, make it purposefully worse than other sites you see. Honestly that’s the beauty of the personal, IndieWeb. Doin’ whatever you like.

    Fediverse

    Who would you rather trust to safeguard your online communities, your digital relationships, and your personal presence/identity on the web? Elon Musk? Mark Zuckerberg? Some other billionaire or privacy annihilating big tech entity? Or would you trust your actual community? This isn’t fantasy. There are real options to build, maintain and join online communities no longer reliant on the traditional tectonics of “big social”. Your first step? Simply sign-up. Congratulations, you are now a hero.

    Perhaps you’re concerned that the “Fediverse”, or the “Social Web” is simply too fledgling for you to entrust something this important to—to invest this much time into. Well, I’d still argue that given the alternative, it’s worth it regardless. But if it allays any fears you might have, take some time to do some research and see all the work that is being put into making this big-tech-free web a reality. There’s so much innovation to be found! We’ve got E2E encryption coming courtesy of the Public Key Directory, LinkedIn will soon be a thing of the past, we’re bridging networks and eradicating mansplaining while we’re at it. Come join us!

    Cybersecurity

    AI isn’t secure. AI can’t be trusted. But AI lives on. Patch yo shit.

    Thanks for reading Scrolls! Time to go goblin mode…

  • Renewal

    This month I’ve decided to participate in my first IndieWeb Carnival—a once-a-month writing prompt organized by the IndieWeb.org community. This month’s prompt is “Renewal”, hosted by Jamie Thingelstad.

    There’s a lot on my mind lately in regards to this term—“Renewal”. I recently moved into a new house and with it I have a yard. The yard has a lot of plants and trees that are now flowering—cherry blossom, red bud, skip laurel, rhododendron and more! This is my first spring here so it has been fun to see what bloomed, and given me an opportunity to learn more about these plants.

    This site, shellsharks.com, has also seen quite the renewal—or better put, a revival. 2025 has been a very busy year for me in terms of sprucing up the site, writing regularly and exploring an even greater breadth of topics and content types. This momentum always energizes me creatively and gives me productive momentum in other areas of my life—professionally, around the house, and with other assorted projects.

    I’m not sure what else to really go on about. My life seems to always be a constant stream of new things. This is by design, and unavoidable. To continue to stay on top of it all, it’s always helped me to reframe these challenges, these endless lists of to-do’s as something “new”. Whether it be a new way of approaching an old problem, or in fact a new issue altogether.

    So, here’s to all things new, and “re”-new for me this year! 🌻

  • BQC: Outdoor Activities

    Answering the Blog Questions Challenge Outdoor activities

    What’s your favorite thing to do outside when the weather is perfect?

    Hiking a mountain. Preferably one with a nice rocky ridgeline so I have views of the valley and surrounding ranges.

    If you could only do one outdoor activity for the rest of your life, what would it be?

    Kind of an odd question tbh. I mean I love to hike, but I also love sitting by a campfire. Must I choose!? Y’know what? It’s my blog. So I won’t.

    What’s the silliest thing that’s ever happened to you while enjoying the great outdoors?

    A bird pooped on my head once while I was traveling in South Africa… 🐦💩😡

    Would you rather explore a dense forest or relax on a sunny beach?

    Easy—the forest all the way. I like the sense of adventure.

  • i'll read it.

    I’ve always said not to worry about whether someone will read what you have to say on your blog. The world is a big place, and there’s always an audience for your writing, no matter how niche. And here ya go, someone wants to read it.
  • Hypocrisy. Illiteracy. Deception.

    We need to stop platforming Nazis—available on my Substack.

    The importance of decentralized social media—posted from my Bluesky acccount.

    The dangerous rise of fascism in America—follow me on Twitter for more.

    The importance of open source—from my WordPress blog.

    Starting to get the theme here? These are all things I’ve seen in the last year. Kinda awkward right? We’ve got Substack eagerly platforming Nazis, Bluesky is laughably not decentralized, Twitter is… well…, and ooph, WordPress has been quite the open source debacle now hasn’t it? Why do these authors and creators continue to publish such incongruous content to platforms that are in direct conflict to their own message?…

    1. Are they enslaved to the “reach” and “community-effects” that these larger, morally-compromised platforms provide?
    2. Are they simply tech-“illiterate” and don’t understand what’s going on with these platforms?
    3. Have they been outright deceived by the marketing and influencers of that platform—led to believe their platform of choice is something that it isn’t?
    4. Or are they just full of shit?

    I have my theories… 🤦‍♂️

    The ol’ Cringe-o-Meter is just pegged to max these days a’int it?

  • Professional Path

    I saw a thread recently which asked people to share their “path” in cybersecurity. I’ve long maintained a few lists that sorta represent this path, so I decided to mush them together to create this simplified timeline of notable career events (e.g. degrees, job changes, certs and other large life or professional-adjacent events).

    Timeline

    • Pre-2010 My infosec path really begins in 2010-ish, but prior to then, I worked a number of IT-related jobs, which gave me some work history and tech-related experience
    • 2010 (through 2013) Started new role as a Intern Software Engineer / Systems Engineer I (software developer)
    • 2010 Started Bachelors degree in Information Assurance & Network Security
    • 2012 Graduated with BS in Information Assurance & Network Security
    • 2013 Achieved CompTIA Security+ degree
    • 2013 Switched to security compliance role (First security position!)
    • 2013 Started new role as a Security Analyst (First “technical” security role - e.g. Tenable, AppScan, Burp, etc…)
    • 2014 Started new role as a Senior Consultant (Infosec)
    • 2014 Achieved ECCouncil CEH certification
    • 2014 Started new role as an Application Security Consultant
    • 2015 Started new role as an Application Vulnerability Management Analyst
    • 2015 Achieved Qualys VM certification
    • 2015 (through 2021) Started new role as an Information Security Engineer (First “engineer” title)
    • 2016 Achieved Tenable TCSE and Core Impact CICP certifications
    • 2016 Started Masters degree in Cybersecurity
    • 2016 Achieved GIAC GPEN, ISC2 CISSP and eLearnSecurity eJPT certifications
    • 2017 Promoted to Lead Information Security Engineer
    • 2017 Achieved eLearnSecurity eCPPT, GIAC GCIA, GIAC GPYC & GIAC GMOB certifications
    • 2018 Achieved OffSec OSCP & GIAC GCIH certifications
    • 2018 Started shellsharks.com!
    • 2019 Achieved GIAC GSEC, GIAC GWAPT, GIAC GREM & GIAC GRID certifications
    • 2020 Achieved GIAC GXPN, AWS Solutions Architect, GIAC GAWN & AWS Security Specialty certifications
    • 2020 Graduated with MS in Cybersecurity
    • 2020 Became a father!
    • 2021 Achieved GIAC GCPN & GIAC GSOC certifications
    • 2021 Started new role as Senior Enterprise Security Engineer
    • 2023 Kid #2!
    • 2024 Switched to a new role, Application/Infrastructure Security
  • How I take my coffee

    Riffing on Axxuy and Elena’s posts about how they drink coffee, here’s how I take my coffee… ☕️

    As of March (2025) I’ve gotten into making at-home cold-brew coffee. It’s delicious! I normally take 2/3 of a pint glass with a splash of half-n-half, another splash of 2% milk, then top it off with ice (cubes). This is what I drink most of the time these days. Since I’m newish to brewing my own cold brew, I’m still exploring what types of beans I like most and have really been enjoying sampling different roasts and regions (speaking of, maybe I should start a sort of “coffeelog” where I can do some tasting notes / reviews… 🤔). Not sure what I like the most yet, but I do know that it’s far better than the french press swill I had been making before.

    When I’m out ‘n about and ordering coffee, I typically go with an iced latte or sometimes just an iced coffee. I like getting the latte’s because I can’t make them at home. I never drink hot coffee. I’d rather have no coffee than have it hot. I just don’t enjoy hot beverages. When I do happen across a Starbucks, my go-to order is their Iced Brown Sugar Oatmilk Shaken Espresso, with just 1 pump of the syrup, otherwise it’s too sweet for my liking.

    Cheers!

  • 'cause nobody hurts me better

    My song ranking of Sleep Token’s album Even in Arcadia. Honestly though, that top 4 is super hard for me to decide as they are all mind-blowing. Also, had to roll back into this post and drop the lyrics to my favorite parts of each song. Behold!

    1. Gethesmane (shoutout to that epic riff tho’)

      and I’ve learned to live beside it
      and even though it’s over now, I will always be reminded

    2. Caramel

      too young to get bitter over it all
      too old to retaliate like before
      too blessed to be caught ungrateful, I know

    3. Past Self

      and if this is love, then i am out of hesitation
      walking an inch above the pavement
      taking it stride by stride together
      if this is real, then i am all up in a frenzy
      not like before when I was empty
      say that the story we tell is never ending
      taking it stride by stride together

    4. Emergence

      are you the carbide on my nano?
      red glass on my lightbulb
      dark light on my culture
      sapphire on my white coat
      burst out of my chest and
      hide out in the vents

    5. Damocles

      and nobody told I’d be begging for relief
      when what is silent to you feels like it’s screaming to me
      and nobody told me i’d get tired of myself
      when it all looks like heaven, but it feels like hell

    6. Look to Windward

      oh and I
      I used to know myself
      oh and you
      you used to know me well
      oh and I
      I wish that I could leave myself alone
      oh and you
      you wish that you could make me whole

    7. Provider

      and our bodies converse like old friends
      exchanging in years silence
      with something unsaid on both ends
      surely we know the difference

    8. Infinite Baths

      even if I’m on my own
      when the silcence is deafening
      I could be stuck here alone
      when even my future is threatening
      something is lifting the bones
      something is dancing in revelry
      wider than oceans below
      taller than titans on boxsprings

    9. Even in Arcadia
      that final…

      have you been waiting long!!!

    10. Dangerous

      when’s the last time you tasted blood?
      and what will it take to stem the flood?

  • 'Self-host it' is an answer. Let me explain...

    My response-to / thoughts-on Neil’s write up, ‘Self-host it’ is not the answer.

    👹 Strapping on my devils advocate horns hat

    Neil is right, self-hosting isn’t a panacea for the ills of big tech, and barriers absolutely exist, some insurmountable for many, but I think spreading the self-hosting gospel, i.e. educating the larger populace of potential self-hosting aspirants, is a good thing. The subset of folks who could self-host but don’t is probably pretty large. Heck, that includes me! The subset of folks who never knew, or never considered self-hosting something is also non-zero. As others have pointed out, solutions/services/platforms (e.g. YunoHost) which help bridge the gap between big tech reliance and full-on self-hosting have started multiplying. Why? As a direct response to the enshittification of big tech and the growing demand that has sprung up in that wake.

    So no, saying “just self-host it” isn’t really the right approach, sure. It’s a bit more nuanced than that isn’t it? As Neil has pointed out, it requires resources, time, money, know-how, etc… This is all true. But each layer of that stack can be managed in different ways, not all of them by the individual. And know-how? Is it too much to ask to have someone learn something new? You don’t need to become an SRE over night, and you should expect-to and plan for failure along the way, but you can surely figure something out in time yeah?

    But let’s take a step back. To say ‘just self-host it’ isn’t the answer, let’s first try to derive/understand the question. Neil doesn’t explicitly say, but in my mind we say “just self-host it” as an answer to a (generalized) question like “big tech platform A is bad, how can I lessen my reliance on it”? In this case, the operative word is “bad”, which can mean anything from said big tech company is violating one’s privacy, enshittifiying, being sunsetted, etc… A better answer to this question is to point out the vast array of alternative options, self-hosting of course being just one of those. You also have managed hosting, FOSS alternatives, smaller/non-big-tech (though still centralized) platforms, etc… Do we have a well-known vocabulary for suggesting “managed” or partially-“managed” hosting alternatives? I don’t think so. Instead, we just tend to say “self-host it”. But I think this answer can be inclusive of more things than just, full-on, purist, I own/control the entire stack self-hosting.

    Neil does make the distinction between his definition of ‘self-hosting’ and that of ‘self-managing’ (running stuff on hardware/a-platform that is not your own), but I think that this is the core problem. This vocabulary (“self-managed”) is not agreed upon, or known. He makes a lot of valid points about why “pure” self-hosting isn’t a great answer, but I think he’s taking it too literally. I think ‘self-hosting’ as the most well known term here can be thought of more inclusively as being everything from owning the whole stack, to just owning part of it (call it “partially” self-hosted if you’d like).

    Rather than dismissing the idea of self-hosting as something only the most dedicated of tech nerds could possibly figure out, let’s instead continue to educate the masses on what it means to move away from big tech. How truly possible it is and what the benefits are. A more educated populace will in turn create more demand—for community hosting, managed hosting, content on how to self-host, tools to make self-hosting easier/more-secure, etc… It’s important to lay out the obstacles and pre-reqs, yes. It’s very possible to bite off more than one can chew here, but you can right-size how you approach this and ease yourself in a responsible way.

  • Scroll duodēvīgintī

    Welcome to volume eighteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. In this issue, we ask “what is the web?”, we gaze across the Fediverse, and we declare “mission accomplished” on cybersecurity 🤡!

    IndieWeb

    What is “the web”? It’s damn sure not the corporate web I’ll tell ya that. The web is us. That’s right. People make the web—via the blogs we craft and those we discover. It may look less like it did in 1999, but this web persists, and it continues to regenerate and flourish each day. This, the good part of the Internet, is alive and well.

    The IndieWeb’s vibrancy comes not from pace of content, but rather from individuality and creativity. Here’s some cool stuff I’ve seen recently (great too if you’re looking for inspiration for your own site!) Immich shared some cursed knowledge, Ava is looking to trade blog post titles, Axxuy celebrates their bloggiversary, Nick Simson is hosting this months IndieWeb Carnival, Brad goes brain dumping, Kris is doin’ a little link cleanup and Will is making the blogiverse a bit healthier. With so many ideas, so many aesthetics, so many voices, the personal web can seem quite chaotic. But that’s just what makes it fun! So get out there and build. Write. Share. Haul off and redesign your entire blog y’know? If it’s already been redesigned… redesign it again! Keep tweaking and having fun with it.

    The other side of the IndieWeb-fun coin, beyond tinkering with and writing for your own site, is exploring everyone else’s sites. So go forth! Discover awesome sites and cool posts. Comment on them, comment on others comments, share them with your friends—with the world! If there’s no commenting mechanism, try contacting them through other means. Drop them a nice note about what you saw or what you read on their site. Trust me, it will make their day.

    Small Web Finds and Features

    Go check out these cool sites. Like, you could just leave this page right now and do it (but come back after 😉).

    • 🧑‍🍳 😘 Gail 👏 - IndieWeb perfection.
    • Speaking of perfection—Henry’s site is, in my opinion, the best looking site I’ve ever seen.
    • The awesome, and brand new, good internet magazine. 👉

    Fediverse

    How do you view the Fediverse? Sure, it may be quiet at times, but I think that can represent a greater opportunity for signal over noise. In my experience, there’s a substance here that is lacking on other microblogging platforms. But Fedi (as you may well know), is not just microblogging. It’s an ecosystem of decentralized platforms, which all communicate over a shared protocol. That’s how you can have a Facebook-like system which can interoperate with a microblogging platform, or a forum-based platform, etc… It’s not perfect here, but the ever-growing list of benefits are well-worth the time spent investing in building a community and a personal presence here on the Fediverse rather than elsewhere. Interested in owning your own little Fedi-parcel? Check out FediHost!

    Cybersecurity

    Ok everyone, pack it up. The war is over. Cyber is solved. All thanks to AI!

    But y’know if you can’t afford fancy-schmancy “world-saving” AI-based security capabilities. You might want to continue to learn up on the breadth of security issues that continue to face the industry. Y’know, like understanding logs, or linux process injection, or windows coercion techniques, things like threat intelligence, binary planting and the ongoing risks posed to DNS—to name a few.

    To help you on this quest, check out some of these tools I recently discovered. NERDCERT.EU is a cooperative-based letsencrypt, Wazuh has a free threat intelligence platform “Vulnerability Explorer”, The Vulnerable MCP Project is cataloguing MCP-related vulnerabilities/research/exploits, and the CIRT team at AWS has just launched their Threat Technique Catalog. Cool beans!

    IndieSec Blogs

    Finally, here’s some cool Indie folks of the cyber world for you to follow and read…

    Thanks for reading Scrolls. Hope you had a blast!

  • Scroll ūndētrīgintā

    Welcome to volume twenty-nine of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we’re keeping it real on the web, navigating our social crises, and goin’ through the cyberlist.

    Settle in, get cozy and start scrollin’!

    IndieWeb

    Who are you on the web? Do you keep it real or are you some other persona? Do you share openly or do you keep things close to the vest? Do you publish with confidence, or do you write with doubt? Don’t try to be something you’re not. You don’t need to push yourself beyond who and what you are. That way leads to burnout. Let yourself grow organically.

    Afterall, your site is meant to be fun! It’s a place for you to express yourself and share the things you love most. But as I’ve said before, it really can be whatever you want. So what should you do next? Why not share what you’re up to right now! Or you can add some sidenotes to your articles. Try getting into your blogging rhythm by hosting an IndieWeb Carnival. Maybe you’re not feelin’ your site and you want a change of scenery. Go do it!

    With so much you can and should do with your site, there’s always things you should just not do. Like, don’t use Substack, and don’t sloppify your site.

    Fediverse

    Social media might be a bit overplayed at this point. What we need now more than ever is community. But community doesn’t come without the effort it takes to build it. We need social networks that enable community-first principles. Mastodon may not be perfect in every technical aspect, but it’s living up to this crucial moment in time. So build and join communities on the Fediverse. Welcome the social media refugees who flee from elsewhere. We can do this!

    Cybersecurity

    It’s CYBERLIST time! (Fancy made-up word for a list of infosec stuff for you to check out…)

    Thanks for reading Scrolls! Now back to my various computerings… 👋

  • Intersecting Interests

    This month’s IndieWeb Carnival is Intersecting Interests. After giving it some thought, I’m not sure I have a particularly outstanding pair of intersecting interests, but there’s plenty of li’l junctions to speak of. Let’s see what I’ve got…

    • Travel x Food: An obvious one sure, but I do really love to travel and I think my favorite part has always been exploring the local cuisine. Some standouts from my travels have got to be belgians cooking various stews in their legendary beers, Tiroler Gröstl from Austria and Costa Rican casado. 🤤
    • Playing x Watching Basketball: I watch a number of different sports, but the only one I really play is basketball. I get plenty of ideas of how I might improve or tweak my game by watching what the pros are up to. Doin’ my best to copy that is!
    • Hiking x Frisbee Golf: These two go hand-in-hand. Especially if you’re not very good at frisbee golf and end up throwing it deep into the woods every time. Turns out I do a lot of extra hiking for every round of disc golf I play! 😅
    • Apple x Retro Gaming: I don’t do much modern gaming these days, but I still like to play some of the classics from time to time. Retro emulators on the iPhone/iPad are a great way to quickly enjoy some of these titles on the go. (This one in particular)
    • Blogging x ANYTHING!: Last but not least, there’s my blogging interest! Turns out you can (and should) blog about literally anything. So that’s what I do. I blog about all sorts of different things—infosec, technology, apple, gaming, travel, fediverse, music, sci-fi, gardening and much more!

    That’s it! Thanks for reading.

  • Just Put It On Your Blog

    If you’ve got something to say, something to share, something that others might be interested in—why not just put it on your blog?

    Someone ask a question on social media that you want to answer? Write about it on your blog and link to it in your reply thread.

    Post anything to social media? Archive it to your blog.

    Have an interesting, random thought? Write about it on your blog.

    Remember a weird dream? Document it in a dream journal on your blog.

    Find some other cool articles or web sites? Link to them from your blog.

    Have a great soup recipe? Share it on your blog.

    Have a bunch of resources related to one technical thing you know how to do well? Document those resources on your blog.

    Find yourself repeating the same thing a lot? Write a blog post about it and share that instead.

    What’re you up to right now? What’d you do yesterday? Get into anything cool last week? What about last month? Write about it on your blog.

    Like something a lot? Or maybe you really don’t like something? Go off about it—on your blog.

    Like to doodle? You know where to share ‘em.

    Saw a good movie or listened to a really great song? Talk about it on your blog.

    It’s great to have a place to share your thoughts. A place you can go back to when you want to remember something you had written or thought about before. A place you can refer people to when they have questions you’ve answered in the past. A place to be you. So, get a blog, and put all the things there.

  • So you've got a blog, now what?

    OK, so you’ve got a blog/website, but you’re wondering “now what”? Here’s some ideas for what to do next!

    Remember! Having a website isn’t about blogging, it’s about you.

  • The Death of CVE

    The CVE program is dying. Damn. 1

    What does this mean? What were CVEs (Common Vulnerabilities and Exposures) doin’ for us anyway? Are CVEs considered critical cybersecurity infrastructure? What are we gunna’ do now?! Panic!! Read on for more hyper-composed and ever-well-researched analysis! (Plus, plenty of related resources, per usual.)

    Disclaimer: It's more than likely I get something wrong in the analysis below. The situation is also very rapidly evolving. This is just my hot take on everything, and my perspective as someone who worked in the VM field for quite some time. Feel free to message me with any corrections! I reserve the right, and almost certainly will, return to this post and update it as I learn more. This is but a jumping off point!

    What is CVE All About?

    OK, a quick primer on the CVE program—from CVE.org

    The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

    Here’s an example of a single CVE record (for CVE-2014-6271, a.k.a. “ShellShock”)…

    As you can see, CVE records contain a wealth of data for known vulnerabilities: publish dates, descriptions, product status(es), references to supporting materials, exploit PoC’s, and more. The idea is to have a CVE record for any and all CVEs under the sun. Useful yeah? That’s about all I’ll cover about what the CVE program is here. For more info, just go check out cve.org (or some of the other resources if / when cve.org dies 💀).

    CVE in Practice

    So, how are CVEs used by the larger infosec industry? In many more ways than I’ll likely be able to cover here, but I want to touch on a few ways this information is embedded. Namely, in terms of vulnerability management and vulnerability scan-related operations.

    Here’s some basics on how CVE data makes it’s way to you, the infosec populace.

    1. Vendor releases crappy insecure software.
    2. Vulnerabilty Researcher identifies vulnerabilities in said software and discloses it to vendor.
    3. Vendors (often acting as official CNAs) assign CVE IDs to vulnerabilities and publish CVE records.
    4. CVE.org aggregates and publishes vulnerability records via a centralized database.
    5. Consumers of this data ingest newly published vulnerability records. (e.g. network/endpoint scanning vendors)
    6. Corporate IT Security teams run said scanning tools.
    7. Along the way, CVE Working Groups help improve CVE-related processes.

    To put simply, scanning tools are able to identify vulnerabilities because CVE records contain valuable software and version information. These tools can compare known versions of installed software with the database of vulnerabilities that tell us what sofware+versions are affected / vulnerable. So, without CVE data, vulnerability scanning fidelity craters.

    There is a lot of other infosec / vulnerability-related infrastructure that relies on the CVE program as a dependency. CISA’s KEV is one example. I’ve got to think that many threat intelligence sources also leverage a lot of CVE data too.

    None of this sounds great so far. So what’s next?

    Now What?

    Well, first of all, CVE is pretty important for a lot of things, so it looks like CISA has found a way to keep it afloat for now. 1

    There’s a lot of potential scenarios whereby CVE as we know it today just sticks around and keeps hummin’ along as it has. The government could come to its senses (lol), or it could find funding elsewhere. I don’t know how much it costs to run that whole operation, but it can’t be much compared to the revenue some of these companies that rely on it bring in.

    Some have started to argue that the loss of CVE could actually help the industry, and that the CVE model had run its natural course. Maybe they’re right?

    Even if CVE as we know it today keeps on keepin’ on, this should be a wakeup call for the world, and for IT and IT-security programs. What would it mean to have CVE vanish overnight? As it seemingly almost did. Would this mean the death of Vulnerability Management entirely? I don’t think so. Would it mean that vulnerability scanners would be completely dead in the water? Not exactly. Would we have any actionable vulnerability intelligence data without CVE? I believe so. Would this cripple the infosec industry? Nah. It’d be a gut punch for sure, but there’s some resiliency in play. Let me talk a bit about how VM programs and the larger scanning industry would need to adapt…

    The CVE program has done a lot to get us where we are, but I believe a lot of this infrastructure stays in-place regardless of what happens to cve.org itself. Vulnerability researchers are not staffed out of cve.org. So research can continue on as it always has. The vendors to which these researchers disclose vulnerabilities to also are unaffected. So vendors can continue to receive vuln disclosures and publish vulnerability data via their disclosure portals as they have been doing. The difference now is that there is no centralized repo by which all of these disparate vulnerability repos will be ingested. We can adapt to that it seems right? Scan vendors can go directly to these companies sites and pull vuln data in, and VM teams across the world can do the same. Not to trivialize the work it would take to fetch data in a decentralized manner, and then normalize all that data—but it’s all there!

    We as an industry may want to evaluate how hard-coded CVE data is into our regular operations, but I think we’d be fine without it in the worst case scenario. Hell, lessening our reliance on CVE could actually help improve security in some ways if it meant doing less “baseline” security and more critical thinking 🤔.

    Alternative Funding

    In light of the precacious funding situation of the CVE program, here’s some ideas on how else it could be funded…

    • The CVE Foundation was just launched to “Secure the Future of the CVE Program”. It was founded by a coalition of CVE Board members. More to come from them…
    • Given how many vulnerabilities are present in Adobe, Oracle and Microsoft products, maybe they should help support CVE! 😅
    • So much of the infosec vendor industry is reliant on CVE. It seems like they could put their heads (and wallets) together to help sustain CVE. Looking at you Tenable, Qualys, Rapid7, et al. 👀
    • Other governments have already started to step up to fill the gap. Check out ENISA.

    Vulnerabilty Catalogs

    I’ve long maintained a comprehensive list of Vulnerability Catalogs. Not all of these are one-for-one replacements for CVE.org, but it goes to show that vulnerability intelligence would still exist and other vulnerability databases are there to pick up the slack.

    Other Questions

    Some other related questions pertaining to this whole CVE potentially going-away debacle…

    • The suddenness of this whole situation is quite alarming. Given the importance of CVE, how was it that alarm bells only started going off literally the day before the entire site would have been shut down? I know things are crazy and volatiile in the government funding world right now, but yikes.

    • The extended funding is from CISA. The same CISA that has been under threat by the current administration. What’s to stop this same admin from pulling CISA funding or otherwise undercutting this latest effort to keep CVE on life support?

    Memes

    The hottest CVE meltdown memes, collected and made available here for you.

    News

    Journalist and news organization publications:

    Resources

    Other resources, posts, discussion and info related to this whole mess.

    1. No lapse in critical CVE services  ↩2

  • Scroll trīgintā duo

    Welcome to volume thirty-two of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we take a look at what it means to be part of the IndieWeb community, we advocate for the Fediverse, and we take a look at things more and less secure across the Internet.

    Now step in and scroll this hall of links…

    IndieWeb

    The Internet is deaddestroyed. Not really, but sadly it isn’t the same web some of us remember. It’s a lot more tiring these days isn’t it? There’s a much larger percentage of content on the web that’s absolutely not worth your time. But it’s not too late to help turn things around. You can still contribute that small amount of humanity to the larger, rapidly degenerating web. It really doesn’t cost much or take much effort either!

    Tucked away in the vastness of the cold, inhuman web, is a cozy corner we call the IndieWeb—filled with fun, loveable li’l websites made by a community of actual humans. Finding your neighbors on the IndieWeb isn’t always easy though. To help with this endeavour, there’s web directories, web rings, community-curated feeds, blogrolls and slash pages (e.g. /self-hosted). So get out there, join the community, and find cool stuff!

    Small Web Finds and Features

    Here’s a few cool things I’ve seen around the web of late…

    Fediverse

    The Fediverse is great! If you’ve not already joined in some way—you should. Why? There’s a lot of reasonsshared ownership, anti-attention media, and human curation over algorithms to name a few.. But advocating for the Fediverse is not always as simple it seems. It’s not just about denigrating the so-called competition. Instead, try to understand what prospective joiners are interested in getting out of a social network or what problems they’ve had with other platforms and explain how Fedi specifically solves (or doesn’t solve) for those needs.

    PSA: Higher prices aside, you may want to be wary of Hetzner.

    Cybersecurity

    5️⃣ Five cool cyber-things for this week’s issue…

    Thanks for reading Scrolls! Hope you enjoyed your stay in this cozy corner of the web.

  • Lessons Learned from 20 Years & Why You Should Blog

    So many great nuggets of advice here—on minimizing writing friction, owning your (domain) name, building a site rather than just a blog, ignoring analytics, writing referential content that can live beyond the week it was written, being authentic, writing with a focus on quality (over quantity), using copious links to things you’ve written in the past—it’s all here. If you have been thinking of creating a website (and you f***ing should!) or even if you already have one, go read this now.
  • Useful Pokémon

    Inspired by this post on Threads, I thought about which Pokémon would be the most useful to me in real life. Here’s what I came up with (in index order)…

    • Jigglypuff is a fluffy li’l guy who can help put my kids to sleep when it’s time. 😆
    • Diglett would be a great helper for my gardening tasks—tilling soil, digging, etc…
    • Meowth can literally produce coins/money, can talk, is playful, and hunts around at night finding treasures to bring back to me. All wins there.
    • Poliwrath seems like a good bro to have around. Strong swimmer and can be a useful, amphibious body guard.
    • Machoke’s are chill and can help with stuff around the house.
    • Chansey’s got eggs that are nutritious and delicious.
    • Lapras is a gentle chap that can ferry me around.
    • Meganium can legit bring dead plants back to life—need that given my not-so-green thumb.
    • Miltank can produce tasty, nutritious and healing milk. I’m sure it’s protein packed too.
    • Blissey brings good luck and healing powers. Gotta have one in your corner.
    • Gardevoir is a zealous protector and could also lift stuff with its mind which could be useful around the house.
    • Latias seems like a good option for flying and is gentle and can understand humans.
    • Rayquaza could be useful from time to time on bad weather days—though it seems a bit intense to have around…

    NOTE: I’m only really familiar with Pokémon up through Gen III so this list doesn’t consider anything beyond that.

  • Captain's Log, Entry: February 26, 2026

    It’s been a busy month on the blog! So what’s goin’ on… I’ve added a bunch of new pages to the site, and have been publishing a variety of notes and posts. I’ve mused on how to get myself academically/professionally motivated once more and also appended a new thoughtstream section to the bottom of this here journal—a place for me to do mini-writeups/commentary on things that I don’t want in an isolated note/post/etc… Le’s go!

    Site News
    • I’ve made some big tweaks to my blogroll. It now features a lot more blogs/sites I really enjoy. I’ve added a .opml but not sure the best way to keep it reliably up to date as I add more sites to the list. I am also considering adding some descriptions for each entry.
    • I recently went through my archive of Scrolls, clicking through each link to find long-lost interesting blogs to add to my blogroll. In doing so, I discovered that there were a lot of dead links sprinkled throughout. There were fedi posts that had disappeared, blogs that had moved, and who knows what else. Just the nature of the web I guess!
    • My experimental GtS fedi instance is dead. Long live malici.ous.computer! Like a dumb-dumb I didn’t grab my archive in time before K&T Host went dark, so here I am. Not sure if I will attempt to revive it elsewhere. Time will tell. Until then, I’ve removed the redirect on @afterdark@shellsharks.social and will be using that account once more. 🌙
    • Inspired by Marijke, I now have a mentions page which lists all of the instances (atleast that I’ve found) of people mentioning me or my site on their own blog! I think I’ll limit this to just mentions on blogs, and not those on social media.
    • I’ve published a bunch of new slash pages/ai, /blank, /hello, /nope, /self-hosted, /top4 and /verify.
    • I got the idea from Burgeon Lab to publish an Indieweb.org profile page.
    • Reorganized my hamburger menu items. 🍔
    • I’ve (finally) made some significant styling tweaks to the site. I’ve moved from colored links to underlined links for both the light and dark themes (keeping the ‘classic’ theme the same for the most part). Hopefully this improves legibility/accessibility and gives it a slightly more pro look.
    • Upon request, I’ve made visited links in Scrolls have specialized styling. So folks can keep track of what links they’ve already visited. I’ve kept it to just Scrolls for now to reduce visual clutter elsewhere on the site.
    • I’ve changed up my welcome message at the top of the home page. For posterity, it now says…

    Greetings web traveler! My name is Mike. I am a security researcher and Internet homesteader (among many other things). Welcome to my digital garden — a florilegium of personal works across all things infosec, technology and life. This site also serves as the canonical identity (a veritable root system) for myself on the web. There’s a lot to discover here, so sit a spell, take some time to really dig around and explore. Wanna contact me? Don’t be shy now either! C’mon and say hi anytime.

    TV
    • Finished the Stranger Things binge. I had heard a sprinkling of folks saying they didn’t like how it ended, but I thought the final season was great and the ending was a perfect way to wrap things up.
    • Knight of the Seven Kingdoms has been thoroughly enjoyable. Didn’t see the Egg thing coming…
    • The Lakers need to stay healthy, but otherwise have been pretty exciting to watch. Being a DC-area native, the Wizards have really never been exciting to watch. Even in the Wall/Beal days they weren’t that compelling. But with the way the East looks + them adding AD & Trae Young, who knows… maybe I could get into watching Wizards ball too?
    • I’ve been rewatching a bunch of the X-Men movies on Disney+. Just for fun. They’re all OK.
    • I’ve also started watching Paradise (season 2) and Task.
    Self-Hosting

    I have a lot of things I want to self-host. Right now my Masto instance is run by MastoHost and that’s fine, but I want to get malici.ous.computer (my GtS instance) back up and running, I need a new bookmarks manager (since Pocket died), I want to self-host my RSS (and get off Feedly), and I’d like to put some Discord replacement up (who knows, something like Discourse or maybe even Matrix). There’s probably other stuff I want to self-host too. I’m taking a look at Hetzner and Yunohost. I’ve started documening this journey, and will add things to my /self-hosted slash page as they materialize.

    Career

    From ~2016-2022 I was incredibly prolific with respect to learning, doing infosec trainings and getting certifications. In the time since, that’s really fallen off a cliff. I haven’t gotten a cert in forever (for whatever that’s worth), I’ve tried and failed to get much traction on doing any kind of training (just go peruse my journal for all the times I’ve mentioned working on OSWE, eg. 8/21, 12/21, 4/22, 6/22, 12/22, 1/23, 2/23, 1/25), and I can’t say I’ve really added anything particularly significant to my knowledge base in that span either. Sure, I’ve been busy with kids, and the house, and w/e else, but I have to call it like it is—I’ve been stuck.

    So how do I get momentum again? I don’t know what will actually work. I don’t know if writing this up and publishing it here will serve as any spark. But I’m going to do a bit of ideation/brainstorming on how I can kickstart my learning and advancement right here (in no particular order).

    • I have a pro subscription to PentesterLab. This platform came highly recommended from some coworkers and has a lot of practical exercises targeting real-world CVEs and other commonly found web vulnerabilities. I just need to make time to work through the challenges and write up the solutions (responsibly of course).
    • I’ve been toying with the idea of producing a ~weekly “what-have-I-learned/read” stream or post that would contain links and mini-writeups related to all the things I learned and did in that period. Maybe said stream could live in this here journal, or maybe I’ll create a new content type, or perhaps it can go in Scrollstbd! (Maybe I could do something with the /TIL slash page idea?)
    • I’ve said it before, and now I’m saying it again—maybe I’ll try for one of those OffSec certs 😅. I’m particularly interested in OSWE (sound familiar?) or the upcoming OSAI training.
    • Learning topics of emphasis for me this year (vague but w/e) include AI (securing/pwning these systems to be clear), Cloud, Cryptography, Code Review and Web App Pentesting.
    • Generally I’d like to do more reading! I save a lot of articles, and have a lot of books on my shelf. I’d like to read more of this stuff and write about it where possible.
    • Finally, I need to do more writing about what I’m doing at work. This can help juice the work, cement knowledge in my mind and put more lovely content on the site!
    Life
    • Trying to make time for and build a long streak of going to the gym is always tough. But I do feel like I’m making slow and steady progress. Biggest issue right now is this nagging right shoulder soreness.
    • I’ll be heading to San Francisco in March! Always good to make my way out there and make my usual pilgrimage to Mama’s.
    • I’ve been thinking about trying to get out of my house to work a little more often. That change of scenery seems like it would help my focus.
    • I’m thinking this snowcrete will be here until May. Insane.
    • I took some time away from this site but now that I’m back I really want to put more effort into journaling. I went back and read through the archive of captains logs and really enjoyed time traveling through things I was thinking about and doing in months and years past.
    • I’ve started planning out my garden for 2026.
    Thoughtstream

    Just a stream of random thoughts…

    Resonant Computing

    I recently came across this “Resonant Computing Manifesto”, cosigned by famed Bluesky apologist and Techdirt founder Mike Masnick. Before I talk about “Resonant Computing” in isolation, let me start with Mike’s take on how ATproto enables Resonant Computing. In this piece, he waxes poetic about how ATproto (and thus Bluesky) fulfills/enables the 5 core principles of Resonant Computing. He also goes on in the comments of the post claiming that ActivityPub/the Fediverse enable at best, only the Plural tenant of Resonant Computing.

    …but I don’t think ActivityPub meets the criteria I’m talking about in the post. The only thing AP currently does is allow you to move and keep your social graph. The other features I discuss aren’t really possible with AP right now. That may change, and I hope it does. But, like already with ActivityPub I have an account on Mastodon, but I couldn’t use that same account or data from it on Lemmy. I had to create a separate account.

    Yeah ok, Mike

    I’ll go principle by principle here and be quite frank about how this don’t smell right…

    1. Private: ATproto is very famously not private in terms of what is visible to everyone. Mike explains however that he was against this specific term being used as the Resonant Computing Manifesto’s understanding of “Private” means that users own their data and determine how it is used. Well yes we know theoretically ATproto’s PDS concept enables this level of data ownership, and that’s great! So I’ll give ATproto a point here, but have to agree with Mike that it’s not the right word from the manifesto itself.

    2. Dedicated: “…You have to trust that there are no hidden agendas or conflicting interests.” omg really? With ATproto? The protocol behind Bluesky? The same organization with Muskian roots? The one that took VC cash from some blockchain firm? The same one that allows open Fascists to run rampant? Yeah sure… lots of trust there.

    3. Plural: No single entity should control digital spaces. Bluesky is pretty monolithic. Maybe the tide has started to turn a bit, and I know we’re trying to logically separate ATproto and Bluesky. But until there’s any significant amount of users off the main Bsky node, I don’t think ATproto can claim any success here.

    4. Adaptable: Software should be open ended. Well I think they’re just trying to claim that ATproto is open source. OK. Cool? So is like, all of the Fediverse pretty much…

    5. Prosocial: Technology should help us become better neighbors, collaborators, and stewards of shared spaces. Well in Blueskys’ case, they certainly are collaborators (derogatory) aren’t they?

    But don’t take it from me, I’m not the only one who this Resonsant Computing doesn’t make much sense.

    18 lessons from 18 years of blogging

    Some commentary on Ben’s 18 lessons from 18 years of blogging. I thought this was a great article and most of the points I think are really spot on. There were a few though that I disagreed with…

    2. Write about what you’re passionate about: Yes of course. But y’know, why limit yourself? I think you should just write about everything. I mean, start with your passions, but I think it’s fun, and a good way to expose yourself to other things, to write about other things, not just your “passions”.

    6. Hand writing drafts on paper can help the creative process: I’ve never done this, so maybe I shouldn’t comment on it. Don’t knock it ‘til you’ve tried it, and all that. But physically hand writing a lot of text is pretty exhausting in my opinion.

    11. Resist the urge to go back and edit old posts: This is the one I feel the strongest about. This is bad advice (in my humble opinion). This is your site. Your voice. Your site is a place for you. If you want to edit a post to be more accurate, or to add more context, or because you’ve learned something new, or changed your mind. You absolutely should. It’s your site, do what you want with it.

  • BQC: Ten Pointless Facts About Me

    Here’s a blogging challenge kicked off by Forking Mad. Here’s 10 “pointless” questions, and their answers, from me!

    Do you floss your teeth?

    Yes. Though not as routinely as I used to. You see, some time ago I had my top-back-molars on both sides of my mouth pulled. They had long bothered me—I couldn’t eat much of anything without food getting stuck inbetween those teeth and the set in front of them. This would cause serious discomfort which I could alleviate by flossing said food out. This meant I flossed at least once, but likely multiple times each day. Since having those teeth pulled, food does not get stuck in my teeth in the same way, so my flossing habit has suffered a bit. I still floss most days though.

    Tea, coffee, or water?

    These days, coffee for sure. In fact, I’ve recently gotten into making my own cold brew. It’s delicious! I’ll normally have some coffee at least once, but usually twice a day (a cup in the morning and another sometime in the afternoon). My coffee habit only started during the pandemic though (oddly enough). Before that, I was a sweet tea person all the way. I can thank my southern roots for that I suppose. But unfortunately, all the sweet tea I was drinking back in those days started to cause me some health issues so I had to change course a bit. Coffee is magical though, so not a bad replacement ☕️ 😁.

    I do drink a lot of water though, especially on days where I am at the gym (which is most days!)

    Footwear preference?

    I tried looking for the exact shoe, but perhaps they are no longer available? Anyways, my prefered shoe are these Salomon hiking shoes/boots (in black) that are kinda a hybrid “regular” hiking boot and sneaker. They are super comfortable, extremely versatile, waterproof, last forever and I like the way they look. I wear ‘em everywhere!

    Favourite dessert?

    This kinda depends on the situation—or my mood. Traditionally, my favorite dessert has been cheesecake. But I also love blueberry cobbler and rum cake. I have a rum cake every year for my birthday in fact 🎂.

    I also really love tiramisu 🤤

    The first thing you do when you wake up?

    I usually roll over and go back to sleep for a few more minutes 😴. Then, probably pick up my phone and check some combination of Apple News, Fedi, Email and other notifications that came in over-night.

    Age you’d like to stick at?

    Well for all the usual reasons it’d be nice to have some of the qualities that came with youth (~mid-20’s)—back when I didn’t get sleepy after one beer, had no knee pain and could recover from anything in ~48 hours. But aside from that, aging hasn’t been so bad for me. It’s brought me new and exciting professional challenges, I’m a father to two cute little nuggets, I’m in the best physical shape I’ve ever been in… I dunno, things aren’t so bad at this age…

    How many hats do you own?

    Own? 6-10 maybe. How many do I actually wear? Well I’m not much of a hat guy, but I do have a sun hat-kinda thing I’ll bust out when doing yard work sometimes 🤷‍♂️. All my other hats are ones I’ve picked up at security conferences 😂.

    Describe the last photo you took?

    The last thing in my photos app is actually a video. It’s the cutest thing really. Whenever my daughter (she’s 1) wants a snack, she grabs it from the pantry and then excitedly runs over and brings it to me. After she hands it to over, she’ll do this rapid fire series of li’l baby jumps. The cute hoppy anticipation is just the best 🥰.

    Worst TV show?

    Big Bang Theory. Just awful. I won’t be taking questions.

    As a child, what was your aspiration for adulthood?

    From what I remember, I had a few “what do I want to be when I grow up” phases. (In no particular order)…

    • Astronaut
    • Archaeologist
    • Paleontologist
    • Doctor

    I’m pretty sure all of these came after watching some relevant TV show or movie 😅.

  • Enquête sur Stérin, architecte réactionnaire de l’union des droites

    Il veut devenir « un saint ». Avec son projet Périclès, révélé par L’Humanité, il s’est mis en tête de faire gagner les droites extrêmes et l’extrême droite, de Bruno Retailleau à Marion Maréchal, en passant par le Rassemblement national.

    Son nom ? Pierre-Édouard Stérin. Fortune estimée ? 1,4 milliard d’euros. Exilé fiscal en Belgique depuis 2012, catholique mais aussi libertarien et très hostile à la gauche, il finance des initiatives politiques loin d’être transparentes.

    Mardi 20 mai, Pierre-Édouard Stérin était convoqué par une commission d’enquête de l’Assemblée nationale qui voulait l’entendre sous serment. Pour la troisième fois, il a refusé de venir : le président de la commission d’enquête a annoncé saisir la justice. Peine encourue : deux ans d’emprisonnement et 7 500 euros d’amende. 

    Pierre-Édouard Stérin est moins riche et moins connu que le milliardaire Vincent Bolloré, qui lui aussi rêve de porter l’extrême droite au pouvoir. Mais comme lui, il est le symbole d’une époque où les milliardaires se sentent pousser des ailes pour nous imposer leur vision du monde.

    Nos invité·es : 

    • Youmni Kezzouf, journaliste au pôle politique de Mediapart ;
    • Thomas Lemahieu, grand reporter à L’Humanité.

    Une émission préparée et animée par Mathieu Magnaudeix.

    Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

    audio.audiomeans.fr
  • Face à Trump et l’extrême droite : sortir de la sidération. Notre émission en direct.

    Ce n’est pas une surprise, mais ça sidère quand même. En moins d’un mois, Donald Trump, épaulé par l’homme le plus riche du monde, Elon Musk, a pris toutes sortes de décrets, de décisions et de positions qui commencent à changer les États-Unis. 

    Licenciements massifs de fonctionnaires, purges, mesures discriminatoires et transphobes, attaques contre les scientifiques : « un coup d’État » en direct, selon de nombreux observateurs. 

    Et dans le monde, un chaos annoncé, de Gaza à l’Ukraine, tandis qu’Elon Musk utilise son réseau social X pour doper l’extrême droite en Europe.

    Face à cette avalanche, nous pouvons être tétanisés. Mais que faire de cette sidération ? Comment la transformer en action ? Comment dire non à ce monde orwellien qui s’annonce ?

    Face à ce chaos, pourquoi les gauches françaises apparaissent-elles si désemparées et divisées, ballottées par un contexte médiatique de plus en plus concentré et hostile ? Ont-elles encore quelque chose à proposer ? Quelles politiques, quels imaginaires doivent-elles défendre ?

    Peut-être faut-il, déjà, commencer par comprendre ce qui se joue.

    Une émission en direct préparée par Imen Mellaz et Mathieu Magnaudeix, et présentée par Mathieu Magnaudeix. 

    Nos invité·es : 

    • Ludivine Bantigny, historienne, autrice de Battre l’extrême droite (éd. du Croquant) ;
    • François Bougon, journaliste à Mediapart ;
    • Léa Chamboncel, journaliste, autrice d’Au revoir Simone (éd. Belfond) ;
    • Arthur Delaporte, député socialiste du Calvados ;
    • Romaric Godin, journaliste à Mediapart ;
    • Laëtitia Hamot, maire de La Crèche (Deux-Sèvres), membre du réseau Actions Communes ;
    • Sarah Legrain, députée insoumise de Paris ;
    • Sylvie Laurent, historienne, autrice de Capital et Race (éd. Seuil) ;
    • Michèle Riot-Sarcey, historienne, autrice de Mais où est passée l’émancipation ? (éd. du Détour) ;
    • Nedjib Sidi Moussa, politiste, auteur de Le Remplaçant (éd. L’échappée) ;
    • Marine Tondelier, secrétaire nationale des Écologistes ;
    • Félix Tréguer, chercheur associé au CNRS, Technopolice (éd. Divergences).

    Hébergé par Audiomeans. Visitez audiomeans.fr/politique-de-confidentialite pour plus d'informations.

    audio.audiomeans.fr
Older posts