@admin — following

Follow buttons here act as you, not as @admin.

@admin follows

LabelKindStateAction
@ricardolocal
@rmdeslocal
@paullocal
news.rss.chatsource
scripting.comsource
euwatch.micro.blogsource
www.techdirt.comsource
simonwillison.netsource
www.manton.orgsource
feeds.kottke.orgsource
rss.beehiiv.comsource
www.404media.cosource
brilliantmaps.comsource
shellsharks.comsource
www.platformer.newssource
podstandards.orgsource
zacharykai.netsource

Timeline

  • Make a Fucking Website

    What are you waiting for!
    Reply source
  • AI Vulnerability Names

    Some vulnerability name suggestions perfect for the current times:

    • SlopBleed
    • Slopsploit
    • SlopShell
    • ETERNALSLOP
    • SLOPwn
    • SlopShock
    • Slopocalypse
    • SlopFlood
    • SLOPpySeconds
    • SlopStrike
    • SlopHell
    • SlopLeak
    • Sloppageddon
    • BadSlop
    • SlopHole
    • DeathSlop
    • Slop4Shell
    • Slop of Death
    • GhostSlop
    • SlopNightmare
    • DirtySlop
    • SlopFool
    • SlopStorm
    • SlopScream
    • SlopFault
    • Slopperoasting
    • LeakySlop
    • Slop2Root
    • Slop Sad
    • SlopFAIL

    These come free. You’re welcome vuln researchers 🤗

    Reply source
  • Scroll vīgintī trēs

    Welcome to volume twenty-three of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we make the web better, learn “how to Fedi”, and feed our infosec-hungry minds.

    Speaking of food, who’s excited about pumpkin pie? 🙋‍♂️

    IndieWeb

    Given everything being done (by AI and corporations in general) to make the web worse, what can we do to make the web better? One idea—make the web webbier. That’s right! If you find something good, something that makes you smile, something interesting, something human, share a link to it. But don’t stop there! If you find a site that you enjoy, try subscribing to it, so it doesn’t get lost and you can continue to enjoy new content as it is published.

    The web is for reading. The web is for writing. The web is for sharing. It’s a lot less difficult to make a website than you think. Once you’ve got one, you might think that writing for it is hard. Maybe you think no one will read it or care what you have to say. Or you think that you have nothing interesting or novel to share. Forget all that. You’ll be surprised what you can produce, and who will find you if you stop worrying and just write. You can also publish pseudo-anonymously if you’re feeling a little shy about attaching your true identity to what you publish.

    Small Web Finds and Features

    Speaking of sharing links, here’s some cool stuff I’ve found over the past week…

    Fediverse

    Stop me if you’ve heard this before (and you definitely have if you’ve been reading this publication for any amount of time)—The Fediverse is the best. But just because it’s the best, doesn’t mean it’s the most intuitive or easiest to use. Things are… different around here, a strength to be sure. For example, we don’t really have an out-of-the-box algorithmic feed. Instead, you really need to follow a lot of people, and scale back individual accounts you don’t want from there. But this highly curated approach empowers you to build a feed that will make you smile, rather than endlessly doom-scroll. There’s no one right way to be here either. The Fediverse comes in so many interesting flavors. So join up, follow folks, do your li’l posting, and get ready to go fungal!

    Where the Fediverse may fall short in terms of raw numbers, it can make up for in its communities. The Fediverse has staying power, and with that comes the innate quality of communities built to last. A network of builders, thinkers and plain-ol’ normal folks invested in the Fediverse continue to strengthen this very aspect as well. Organizations on the Fediverse are actively catalogued, verification utilities are being developed, first-party “starter packs” are a-comin’, and community-based moderation continues to prove itself more robust than anything that “competing” networks have ever been able to provide.

    Cybersecurity

    Who’s hungry for some cyber this week? Let’s slap a little mayo diffie-hellmann’s on this secwich and get mind-munchin’!

    On the reading list for this week we’ve got Mozilla’s wiki on Supply chain attacks, a fascinating writeup on SATCOM Security related to eavesdropping on satellite communications, a lengthy guide on LLM Poisoning from SYNACKTIV, and an intro to The Clean Source Principle from SpecterOps (one of my favorite infosec blogs).

    Lastly, a few things to bookmark and add to your infosec tool belt…

    Thanks for reading Scrolls!

    Reply source
  • Captain's Log, Entry: March 30, 2026

    Spring has sprung, and with it a new garden 🌱 — the Vulnerability Garden 🪴! That’s been a big focus of mine the last week or so (and is still under development for my v1.0 release). I was in San Francisco earlier this month ✈️. Nothing else particularly noteworthy to highlight for March…

    Site News
    • Added a theme-color meta tag, which makes the color scheme more consistent on mobile device header bars and gives that pop of color when pulling down the page on certain browsers (e.g. Safari).
    • Signed up to host IndieWeb Carnival for April 2027. Stay tuned for that (need to come up with a prompt 🤔).
    • I’ve welcomed Vulnerability.Garden 🪴 to the shellsharks family!
    • I now have a human.json file published.
    TV
    • Knight of the Seven Nine Kingdoms: Season one was great! Only complaint is that it was too short 😢
    • Task: Kinda stopped watching this one…
    • Scrubs: It’s damn near pulling off the impossible—recapturing the humor and vibes of the original Scrubs seasons. Genuinely enjoying it.
    • NBA: The Lakers are on a roll. Still can’t believe the Mavs gave up Luka 😂
    • Paradise: Season two has still got it!
    • One Battle After Another: This movie was ok. I probably would never watch it again. It wasn’t confusing… but I did just have this vague sense of like.. what is going on, hanging over me throughout the entire flick.
    • Frankenstein (2025): There were parts of this movie I really enjoyed, other parts didn’t quite land. It does make me wonder about how exactly, from a physiological perspective, Frankenstein is so strong and impossible to kill.
    Life
    • 👨‍🌾 Spring! Soon (April) I’ll be executing on my (garden) plan.
    • ❤️‍🔥 Finally got my feelings about burnout off my chest & heart.
    • 🎁 My birthday came and went. It was fun! I went out antiquing (in a way) with my son (we bought a gigantic bird house), and then got hibachi (per usual) that night. Hibachi is the best. 🤤
    • ☀️ Porch weather is back! Porch weather is the best! Though this will be the first spring (a.k.a. pollen blasting season) my porch will be subjected to, so I need to figure out what I’m going to do in that regard…
    • 🌉 Was out in San Francisco for work early in the month, so of course I went to Mamas (twice)!
    Thoughtstream

    Just a stream of random thoughts…

    Paperclip

    I came across Paperclip on my feeds at some point and just… what? I’d love to see a writeup of someone earnestly using this and see what happened. AI has gotten out of control.

    Afraid of AI

    Rick’s piece titled “Am I Afraid of AI?” is a near-perfect encapsulation of my own feelings. Go read it and save me the hassle of writing up the same thing.

    Bluesky CEO transition

    Jay is out as CEO of Bluesky and Toni has stepped in. Woo. I’m kinda over talking about, criticizing, poking holes, or otherwise debating Bluesky-related things. Bsky is gon’ bsky y’know? I have my doubts about the networks long-term viability (and other things) but whatever. If people like being there then that’s great! If it lasts for years and years and finds meaningful success along the way then that’s awesome. If it crashes and burns and people have to “flee” elsewhere then we will deal with that then too. I’m focusing on more positive writing pursuits these days. 📖 *closes book* 📘 😁

    Reply source
  • Scroll vīgintī

    Welcome to volume twenty of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. In this quieter week, I ask, “why do we blog?”

    IndieWeb

    Why do we blog? What keeps us online? How do we find balance in it all? I suppose… for me it’s many things. I enjoy sharing what I find, what I learn and what I enjoy with others. Second, I find blogging helps me process, helps me remember, helps me decompress, helps me celebrate, and helps me further understand the variety of things I encounter throughout any given day/week. In this journey, I have also (somewhat surprisingly) found something I did not originally expect—community. So though I don’t consider a lot of what I write and share here particularly “important”, I do take the process of blogging, and site-owning in general, pretty seriously. And ya know what? I think you too can find the magic here.

    Enough with the why. Let’s talk about what we can do-with or add to-our sites this week. You don’t need anything fancy, an upgrade as simple as adding an email address to your RSS feed would make for an excellent improvement to your site! Let’s see what else… You could try a new blogging framework, learn about and then deploy some new CSS, add some Slash Pages, or collect and share some good links (y’know, like Fyr is doing!). If nothing else, you could simply write more.

    A few final things to share in this week’s somewhat-teeny Scroll…

    • Bonfire looks to be a promising place for future long-form content.
    • RSSRSSRSS can help combine RSS feeds.
    • Channel.org is here to help you take ownership of your presence, content and communities on the web.

    Thanks for reading Scrolls. Stay cool!

    Reply source
  • Scroll vīgintī duo

    Welcome to volume twenty-two of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we take a look at an IndieWeb journey that is yours for the taking, reflect on the power of (true) decentralization, and kit up on the cyber front.

    IndieWeb

    It’s fall! 🍂 Time to get hyper-weird with it.

    Ya gotta get started first—and for that, you gotta get your own domain name! Got it? Now write up an intro post (check this one out too!). You’ve now set off on your IndieWeb journey—there’s so much fun stuff to do from here! Write up your weekly thoughts, establish your favorite color, just write and be yourself! Sometimes, it’ll feel like you’re just scraping by—creatively or emotionally. But there’s lot of ways to get inspired and involved again. Five years from now you can look back at all you’ve done and know that you’ve become part of an awesome community.

    But why should we do this? Why blog? Why have a website? Well because they’re the best, that’s why! Humans are meant to communicate and connect, and the Internet makes this possible at an unimaginably grand scale. Don’t overthink it either. You don’t need to “build a following”. You don’t need to sell things. You don’t need to have a brand. You can literally just be you. Creating some “Slash Pages” (as Joe did) is a great place to start. You can construct your site however you want too. It doesn’t need to follow the same old boring template. Be creative! It also doesn’t mean you can’t use traditional social media, consider POSSE-ing.

    We (humans) should decide the future of the Internet. It can only slip away from us if we let it. It’s all already there too. It really always has been. Write, share, commune—we’re in this together. It’s not too late.

    Fediverse

    Decentralization is power, and in the face of malignant power, decentralization is resilience. So let’s descend further into the light of the abyss

    Some tools to light the way.

    Cybersecurity

    Sometimes cybersecurity is awesome. Oh so often it’s just kinda sad and failz

    Some good tips for staying out of that fail category—keep secrets out of your logs, understand REST API edge cases, lock down your supply chain and think twice before vibe coding!

    🔥 It’s dangerous to go alone! Take these. 🔥

    (Some useful tools and resources)

    Thanks for reading Scrolls!

    Reply source
  • Captain's Log, Entry: April 30, 2025

    April came and went it seems, but I’ve been up to a lot! Notably, I’ve got a lot interesting TV I’m watching these days, and my trip to NYC was a blast!

    Site News
    • In April I’ve published 6 notes, 11 blog posts, 0 devlogs, 4 scrolls, 1 captain’s log and shared 4 links on my site. That’s quite a few blog posts if you ask me.

    • Scroll 13 was late, but it got out none-the-less! The next edition should come at the normal time though. I really thought I’d be able to get it out while I was traveling, but as it turned out, I was just too tired at the end of the day to put the heart and energy required into writing it up. That said, I had all the content already so I was able to put it together rather quickly once I got back home. I really expected someone to message me wondering where the issue was, but no one did 😅. But, people seemed excited enough once it finally did drop! 🧡

    • The nerve of scam detector to give my site a 76.7 scam score 🤣

    Site References

    My site has been referenced and shared a bunch this month! Here’s some examples…

    TV

    I’m watching a lot of great stuff this month.

    • Finished Star Wars: Rebels and Reacher (season 3). Rebels was great, Reacher was meh
    • Started watching Last of Us (season 2), Andor (season 2) and Paradise
    • NBA playoffs are goin’ on (looking grim for the Lakers rn frfr)
    • Also randomly been watching episodes of Fixer Upper. Love that show
    Life

    What’s been goin’ on life-wise…

    • ⚡️ My much-anticipated screened porch build has stalled out waiting for the electrician to do his thing
    • 🌸 My cherry blossoms bloomed and then fell 😢. But, some other plants around the house have started to bloom which is nice. I’ve got a particularly nice Rhododendron that has started to pop this week
    • 🤧 Loving the temperature this time of year…but it’s kinda ruined by the pollen and thus the SNEEZING!! 😤
    • 🌆 The trip to NYC with the kids was a blast. I always forget how omni-present good food and coffee is there.
    • ☕️ Still making cold brew. It’s delicious.
    • 🍏 Speaking of drinks I’m into right now—I’m really in a hard cider phase.
    • ☠️ ALSO, speaking of things that are ruining Spring, I’ve got quite the crop of poison ivy that has started to take over certain parts of my backyard. I really despise poison ivy.
    • 🎶 Sleep Token is CRUSHING it with their new album releases. Absolutely love the first three songs they have dropped.
    Reply source
  • What's a newsletter?

    @darius@t54r4n1 I’ve never thought of a “newsletter” as being defined by its transmission medium, though I understand the instinct to associate the “letter” suffix with e-“MAIL”. I’ve always emphasized the “news” part of newsletter (w/ “letter” referring to the fact that newsletters were written, i.e. not videos or podcasts). In this way, newsletters would be defined more as written pieces that focus on recent topics (i.e. news), regardless of how it is delivered.

    Reply source
  • Computers can be understood

    I love this piece. In my line of work (infosec), it’s easy to go up against some random complex system and feel a little intimidated. But if you just take a breath, lean on foundational understanding, and then just get to work reading documentation, experimenting with the system, and piecing together an understanding of the system component by component, it really doesn’t have to be as daunting. A good read.
    Reply source
  • Scroll duodecim

    Welcome to volume twelve of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, we’re brewing web-potions, celebrating the Fediverse, and scrapping some funeral plans (for now).

    IndieWeb

    Welcome back to my charming li’l sanctum on the ‘net—here we remain spellbound, pressing ever deeper into the enchanting realm(s) of the IndieWeb. I’ve always ascribed magical metaphors to my site, hence the “Scrolls” wordplay. While others tend to their gardens 🪴, or furnish their homes 🏡, I always see this site as a place for incantations 🪄, potion making 🧪 and all manner of digital sorcery 🧙‍♂️.

    Don’t get it twisted though, blogging is more than mere cosplay. Blogging helps us think and explore our own understanding of things. It helps us reflect and process. It helps us concentrate, extracting even more joy from the things we already love. Our web-gardens, homes and wizard hollows are quite literally “personal infrastructure”. What do you expect to get out of blogging—why do you do it? For me, it’s always been these things. Maybe it’s simple attention you seek, or a bit-o-money (just keep it classy won’t ya?). It doesn’t have to be one thing, it needn’t be shallow—but one thing it should be, is you.

    It’s not shameful to seek attention though. To want others to see, and enjoy what you have created. As much as the IndieWeb is about you, it’s just as much about the larger community of personal sites—of real people, jus’ doin’ their thang and bein’ themselves. It should go without saying, we love blogs here. We really want you to start one. We want to read, save and share your blog(s) on our own sites. You’re not alone. Get out there! Network and participate in some good ol’ fashioned writing events. IndieWeb Carnival is a good place to start. In fact, I just got in on my first-ever carnival!

    Some folks shy away from creating a personal website because they “aren’t strong writers”, or they feel they “don’t have anything interesting to say”. Let me just say, you don’t need to be some perfect writer, nor do you have to have literally anything novel or particularly interesting to say to have a blog. ‘Nuf said. More to the point though, having a personal website is so much more than just blogging! It’s about expressing yourself, and having fun. Here’s some ideas for things you could do on your site that are not just writing. Elle crafted up a custom 404 page, Ruben has a /museum page for all of their websites-of-yore, Éric coded up some cool text-rendering visualization, while Jeremy simply streams his life away. Just get creative! Break the “rules”. Do whatever you like. Share a recipe you love, or haul off and rewrite your whole dang site. Enjoy the journeythere is no “destination”. Your site can be forever!

    Small Web Finds and Features

    Looking for more inspiration or just want some awesome sites to add to your RSS feed? I’ll trade you some of my finds—send me yours!

    Fediverse

    Happy belated Fediverse Day everyone! 🥳 (In case you missed it, Korean-Fedi pioneered the idea for April 11th). Keep bein’ awesome!

    Every week there’s lots to celebrate here if you ask me though. We’ve come a long way afterall—with even more exciting roadmaps ahead! So if you haven’t already, join the Fediverse, get in on the conversation, add your color—because things are positively blowin’ up right now!

    Stormy Skies ⛈️

    While the Fediverse parties on and continues to live up to its promise, I can’t say the same for ol’ Bluesky. Look, I don’t like to make this publication about any level of negativity—and believe me, there’s plenty I could “report” on in terms of Fedi-related drama each week. But I think it’s important to drive home the ever-salient point that Bluesky is not the panacea it claims to be. Specifically, around its claim of decentralization and that it is some safe haven from billionaires and oppressive governments. It’s not.

    So here’s the story—in short. Reports indicate that Bluesky is capitulating to Turkish government demands to take down certain Bluesky posts. Since Bluesky is not decentralized, and subject to governmental orders from regions they wish to operate within, this means all members of the network are affected by such requests. In a true decentralized model, i.e. what the Fediverse has, you may have single instances subject to regional jurisdiction, but the wider network, which is spread across the globe would remain relatively unaffected. I.e. a Turkish Fedi instance could/would be vulnerable to these demands, but instances in say, the Netherlands could just ignore them. That’s one of the benefits of actual decentralization. So, be careful where you’re placing your social chips these days.

    Cybersecurity

    The big story this week is undoubtedly what’s been goin’ on with cve.org. I’ve got a whole writeup about CVE’s near-death experience if you’re interested in catching up or hearing my thoughts.

    Beyond that, kinda a light week. I discovered a few cool detection rules resources—Rulehound & AttackRuleMap. Writeups.xyz looks like a great collection of bug-bounty writeups and Talos has published their year in review.

    IndieSec Blogs

    Much like the greater IndieWeb community, IndieSec too has so much to discover. Check these awesome sites out!

    Thanks for reading Scrolls! Now back to my potions. 🧪 😃

    Reply source
  • Scroll ūndēvīgintī

    Welcome to volume nineteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, we pick up the scraps, help others join the Fediverse and get a li’l phreaky.

    Three issues in one week!? Yep, I’m back. Y’know, from time to time you just gotta recharge a bit I guess, and I’m not the only one! Sometimes, you don’t blog, you just blob.

    IndieWeb

    Before anything else, I wanted to share some sad news from the IndieWeb world. I found out from Adam that Anne Sturdivant (a.k.a. @anniegreens) has passed away. I enjoyed reading her posts and her WeblogPoMo was the first monthly writing challenge I ever participated in. She was a critical part of my early IndieWeb journey and for that I am thankful. Her spirit lives on through all the people, like myself, that she inspired—to bring kindness, humanity, creativity and individuality into the world through our digital gardens. 🌱

    As I have learned, and personally experienced, having a site and a blog is an extremely rewarding journey. In fact, it can even be all-consuming at times. Once you settle into a nice writing routine though, it just makes for a great habit in my opinion. A place you control, where you can share whatever you want, whenever you want, and in whatever form you want. You can add to it, edit it, delete it, change up the look—anything. It’s yours! For my more comprehensive advice on blogging, check this post out! Interested in what other people are up to? Take a trip to URL Town! 🚙

    Looking to make, upgrade or grow your current site? Here’s some ideas fresh from the IndieWeb-World! Axxuy, sainthood and Abhinav have all been tweaking their /links pages and Ross introduced his new “/connect” slashpage. Cool!

    But my favorite new thingy I’ve seen recently has been from fyr.io. Scrolls went on an unplanned hiatus for a few weeks, which seemed to have left a bit of void. Many folks reached out to me during that time, and since returning, saying they had really missed it. That has been extremely heartwarming to hear, and quite frankly, pretty energizing. But fyr took it one step further, coming out with their own Scrolls-like newsletter/roundup, dubbed “Scraps”.

    I love it, and speaking directly to Fyr, I hope you continue to publish it, in whatever form and cadence you like. These little roundups are one of my favorite blogging vehicles and if my experience with Scrolls has taught me anything, it’s this kinda human-curated boosting that really helps connect the broader IndieWeb community and supercharge discovery, especially in the face of rapidly declining search engine usefulness and increased fracturing of traditional social communities. You may have made Scraps to fill a Scrolls-shaped void, but I promise you we need as many of these things as we can get! 🧡

    Fediverse

    The Fediverse is, in my humble opinion, the best social platform on the web right now—and will continue to be for the forseeable future. Not because it has zero problems mind you, but because of all the unique benefits it has, that you simply can't get elsewhere. One issue stems from one of its benefits, that is, its decentralized nature. Specifically, it has proven difficult for many to decide what instance to join when they are first creating a Fedi presence. There are different instances, different platforms, and lots to consider between all of them. To help navigate this, StartHereSocial or suggestions from folks who have been here a while are great places to start. I for example have my own list of Infosec Instances that you could check out if that is your thing.

    What else is happenin’ around Fedi’? FediCon is comin’ up for those near Vancouver, Bonfire has an Install Party you can check out and Tim Chambers has dropped his The Seven Deadly Fediverse UX Sins Part 2 which is 100% worth the read!

    Cybersecurity

    Gotta real grab-bag of cyber-ey things this week…. ‘ere we go!

    I’ve got a lot of infosec certs, so I feel somewhat qualified in telling you that what you get out of most of them is really not much. But y’know what, I’ll let CrankySec explain instead 😈. Want some actual credentials? Or real skills? You don’t have to look far, and you don’t have to spend much (if anything). Just look around! The Internet is bursting at the seams with free resources, writeups, trainings, tools, everything! Wanna learn how to forge passkeys? Got you. Want to write secure Rust code? Boom! Wanna fingerprint some network devices? Here ya go. Wanna take a trip down memory lane ya li’l phreak? Everything is here (i.e. the Internet), if you know how to find it, and have the will to just dive in and start learning, tinkering and building. Get out there!

    Thanks for reading Scrolls. Now, it’s coffee time!

    Reply source
  • Conflagration

    I don’t think I really know when it happened—the “burnout”. It’s not something that happens all at once. Maybe you see it coming, you start to spot the signs. Or, if you’re like me, you don’t know it’s happened until months or years after being mired in the after-effects. I would slipin… and out, of the conscious realization that I was indeed burned out. There were times I found myself very lucid, entirely aware of how burned out I had become. Through other spans of time I managed to disassociate entirely. How long was I there? I can’t honestly say. The entire lifecycle from burning out, to burned out, to realizing I was burned out, to recovery, is not a straight path, and not one that has some known, or widely-accepted timescale. Come to think of it, I really haven’t seen many accounts of severe burnout. I suppose that’s because those who experience it are likely too burned out to write about it. So, am I back? Hah! It’s not that simple unfortunately. But I am in a place where I feel that I can share my experience.

    Notice: This is a particularly personal accounting of my real-life experience with burnout, and everything that comes with it.

    Look, I’m not going to lie to you. I haven’t come here to say that I’ve unequivocally “recovered from burnout”. A nasty thing about burnout is that it isn’t some obvious, precipitous decline. It isn’t necessarily marked by some singular, triggering event. What causes burnout from one person to the next is never the exact same, and each of our paths can look wildly different and result in varying levels of burnout—the manifestations of which can also be quite variegated. Similarly, the path out is not straightforward. It is not an extrapolatable line upward and outward. This is an upswing for me, sure—writing this post. But I’ve been here before. I first thought about and started drafting this post nearly two years ago, around early May of 2024. This too would have been sometime well after I first realized I was “burnt out”—when I finally had enough energy to even give the notion of writing about it some thought. I can’t point to a day, or to a moment, or to a thing-that-happened and say “that’s when the burnout began”. However, I suspect that my own case of burnout began accelerating in early 2022, with “full burnout” finally happening in mid 2023 when my daughter was born, at which point I stepped away from it all on leave. I’ve been torched ever since.

    How did it happen? Gah, I don’t know. There’s any number of things I can point to and say were contributing factors. The pandemic, too much work, not enough recognition at work, friendships lost, parenting stress, stress from the world at large, stretching myself too thin with side projects, the list goes on… We’re all conditioned to work, work, work. Reach higher, stretch into that role, stretch for those goals, get a better title, get more money, post our travel photos online, more, more, more! It’s just kinda… exhausting, y’know? In those 18 months from early 2022 to July 2023 I was pretty busy. I was in a demanding role at well-known big tech company, I had some side projects going on, I was publishing this blog + my podcast—all while doin’ the parenting thing. I pushed and pushed to do more and more, and did so in a way that was in hindsight, entirely aimless. Yes, I did a lot of things, but to what end? Were they in pursuit of something specific? Did those things make me happy? When my daughter was born I was just, tired. It was time to step away from the work and focus on those early months with a new baby. Eventually, I came back to work. But I didn’t really come back—not entirely. I had lost the drive and the motivation. Things that once interested me no longer did, and I’m not just talking about work stuff. I wasn’t as active on the blog, a lot of my hobbies just completely died, I was in battery-saving mode—just doing the bare minimum. I did what I had to at work, I ate, I went to the gym, I played with my kids and I slept. There were other hours in the day, but I’m not sure what I did with them.

    I don’t want to misrepresent things here either. I didn’t spend my days doing “just the essentials”, keeping the lights on, and doing them well. No, no, no. In my haze, I’m not sure I did anything with the focus and enthusiasm that it deserved. My time spent at work was unfocused, often unproductive, and from my perspective, entirely meaningless and unfruitful. I got things done sure, but they didn’t seem to matter. No one said “good job”. I never felt accomplished. I could go days, or even a week or more without talking to a single person. I didn’t feel like I was learning anything. I felt that what I did there didn’t matter. That I didn’t matter. No one needed me and I had nothing to offer. While I stood alone and still, everyone else seemed busy, effective—happy. I would see proud messages of others in my team and across the company achieving promotions, or completing highly-visible, impactful projects. Sometimes I was jealous, but more often I felt nothing. I wasn’t inspired, I just continued on. At first it was just a month lost, or a quarter lost. But eventually it became this awful gap. A year or more where I’d been entirely stuck. Even if I could get moving again, look how far I’ve gotten behind.

    My podcast fell to the wayside. My blog lie unupdated and dormant for months at a time, gathering cobwebs. I had aspired to a great many other things in the larger world of “shellsharks”, but I forgot about all of them. I announced >Shark Week in multiple years only to completely ignore it when the time came. I never conciously “gave up” on the blog… I just stopped. This wasn’t a purposeful attempt to reclaim time for work, or for parenting, or for my sanity. I was no longer in the drivers seat. I had simply, unpurposefully, disconnected. Sometimes I would remember it was there. I would think about writing something. Or I would catch up on a few things I wanted to update—breathing a little bit of life into the site. But for a long while, it didn’t amount to more than that. Folks who I came to know through my site, or through social media reached out to me. Wondering where I had gone. Wondering if I was OK. Eventually I saw the messages. I let them know that I was fine. Things were just busy. This was true. But it wasn’t the entire truth.

    Even as a parent, and a full-time job-haver, I still have hobbies. Or I did. Through these darker days I still tried to go to the gym… but those sessions never got my full focus. I had projects in the yard, or around the house, but I never really got to them. If there’s anything that I managed to still be kinda “good” at, it was playing with and having fun with my kids. But even while doing that, I still often worried about work, never being able to fully be happy in the moment. Too often I sacrificed time I should have spent with my wife or family because I felt guilty about work. Then at work I felt circularly miserable about a perceived degraded home life. Vicious, some say.

    That feeling of being behind on things, of feeling unfocused, of feeling unneeded, of feeling unimportant, bled into every corner of my life. I wasn’t just useless at work. I also started to see myself fail at home—and forget about my friendships, these had seemingly entirely disintegrated. I felt at this point, universally alone.

    Burnout is one of those things that you try to shrug off. Everyone is burned out right? Everyone has any number of things stressing them out at any one time. Sure I may feel “burned out”, but it isn’t anything especially problematic! I found myself routinely ignoring or trivializing these feelings. I chalked them up to the routine stresses of the world, rather than fully appreciating the gravity of the state I was in. Because the difference between chronic burnout and run-of-the-mill stress is that with burnout you just can’t find your way back to a healthy “normal”. You stay unproductive and uneffective. It takes a more concerted effort to pull yourself out of the rut.

    You see, I knew I was “burned out”, and looking back now, it’s easy to see I had become depressed too, thanks in part to the burnout. Some days I would manage to pop my head above the clouds with proclamations of how I was going to “get serious”, or “lock in”, or some other way of crawling out of this quagmire. But as some of my friends and family can attest, those words were either empty or simply did not provide adequate propulsion. I fell right back into the bad habits—that same fog. In some ways, I’m still trying to really understand what I want. I think having a clear idea of what you want is key. Only then can you try and reverse engineer the steps to get there, prioritize, and make time for everything. As it turns out, there’s just not enough time in the day for everything. Compromises, or full-on sacrifices have to be made. This is the reality.

    So am I through it now? Am I OK? Am I no longer “burned out”. I don’t know. Probably not. I’ve been kinda here before to tell you the truth—“seeing the light”. I have clearer vision these days I’ll give you that. My hobbies have started to return, my outlook on work has improved dramatically, I’m using my time much more effectively. I think I’m happier these days. But it’s easy to slip back. I try to catch myself, to right the ship and to stay on course, but some days it seems the margin for error is just too thin. To lose a day in pursuit of everything is to knock myself off track indefinitely. But I remind myself that I don’t need to be perfect. I don’t need to operate at 100% efficiency. I need to understand my goals and work towards them, and not be discouraged when I falter. Success is a grind—a lot of little steps that in aggregate move us to a target destination. A step backwards, or a rest day doesn’t mean I’m back at the beginning.

    Oh, and as if burnout alone wasn’t enough, there’s a lot of other career-related blights I (and I’m sure many readers of this post) experience—often manifesting into a devilish syzygy of occupational dilemmas. Let me talk about those for a minute too…

    Demonology for the Professional World

    There’s more to the fiendish nature of our “careers” than burnout alone. We the workers, tend to be plagued and posessed by a great many evils. Consider the list below a Lanterne of Light—traditionally a classification system for (actual) demons, but in this context, the hellions of the working world.

    1. Burnout
    2. Impostor Syndrome
    3. Climbing the Ladder
    4. Professional Vitality (i.e. boredom, finding interesting work)
    5. Finding Meaning/Purpose
    6. Maintaining Relevance & Skill Erosion
    7. Isolation (e.g. remote work)

    I’m sure there are more items to include on this list, but these are the ones I’ve observed most, at least in my own career history.

    For now, this post will be limited to my experience with burnout alone. Perhaps one day I’ll expand it with tales of other such things, or maybe they’ll end up as separate posts sometime in the future. The fact is, everything in that list can contribute to burnout, and in turn, burnout and other things on that list can equally contribute to impostor syndrome. See where I’m going with this? That cursed list of professional afflictions can all feed into each other. So be weary!

    Burnout

    I told my story about burnout at the beginning of this post. Here, I want to be a bit more technical/scientific in terms of defining what burnout is, what causes it, how it manifests and how to mitigate or address it.

    “Burnout is a syndrome conceptualized as resulting from chronic stress that has not been successfully managed. It is characterized by three dimensions: 1) feelings of energy depletion or exhaustion; 2) increased mental distance from one’s job, or feelings of negativism or cynicism related to one’s job; and 3) a sense of ineffectiveness and lack of accomplishment.”

    Burnout is interesting, and scary. A lot of things can cause it, it can be hard to see it happening in real-time, and it’s even hard to tell if you’ve reached some form of final-stage “burn out”. Like, what does that even mean? How burnout can manifest itself, the symptoms themselves, can easily be attributed to other things, non-burnout related. How one experiences it, and what effects they experience can vary greatly from person to person. Similarly, treating, or recovering from burnout is not a known science. Some even suggest that you might never recover from burnout. So much about how you treat it, can probably be mapped to how it happened in the first place, which again is hard to understand as burnout tends to creep up on you slowly, over a great span of time.

    Burnout Causes

    There’s a lot of things that can trigger or ultimately contribute to “burnout”. Here’s a list… 1, 2

    • Unclear mission & expectations
    • Lack of control
    • Opaque management
    • Resource starvation
    • Lack of agency / autonomy
    • Overwhelming scope
    • (Lack of) job security
    • Long hours
    • Dwindling pay
    • Lack of recognition or reward
    • Excessive workload
    • No sense of community, kinship or camaraderie
    • False urgency
    • Unfair treatment
    • Relentless change
    • Limited growth
    • No work / life balance
    • Micromanagement
    • Performance pressure
    • Toxicity
    • Lack of support
    • Bad communication
    • Monotonous work

    There’s more to this list to be sure, but that’s a lot already.

    Burnout Symptoms & Manifestations

    Burnout manifests itself in a myriad of ways. Each person will experience it differently and at varying levels of severity. Some things you might experience are listed below…

    • Exhaustion
    • Activities, particularly social ones, drain you faster than usual
    • More venting / complaining
    • Hopelessness
    • Demotivation
    • Disengagement
    • Over-sleep
    • Feeling of never being inspired
    • Craving to work on projects but can’t
    • Stress
    • Depression
    • Laziness
    • Depersonalization (i.e. loss of sense of self)
    • Physical health issues (e.g. gastrointestinal, cognitive decline, heart palpitations, pain, etc…)
    • Guilt
    • Job switching
    • Procrastination
    Treating and Mitigating Burnout

    Probably the least understood thing about burnout is how to actually recover from or treat it. Sustained triggers are simply not easy to reverse and not easy to do a root cause analysis for. And even if you could identify everything that ultimately led to being burned out, is it realistic to expect that each of these things can be removed? How do we treat burnout while often having to continue being exposed to some subset of the same triggers that caused it in the first place?

    One study attributed burnout, and in reverse, treating burnout to 6 main sources: workload, values, reward, control, fairness, and community. Another study suggested a framework known as “I Believe, I Belong, I Matter” as a path towards avoiding burnout. 4, 5

    In both cases, we are directly treating the initial triggers or feelings-caused by said triggers. I don’t know what works. I think these things all sound great, but what actually works—who knows.

    I think time is important. Sometimes you just need to step away. But time alone isn’t enough. I for example spent quite a bit of time away. Sure, I wasn’t able to completely shield myself from the burnout triggers, so maybe that time away wasn’t “pure” in the recovery sense, but I feel like the time I had was as good as anyone can really expect. Afterall, if you’re a parent, or if you live in the real world, it’s just not overly practical to step away from your kids, or from your job, etc…

    An important step is (and I mentioned this earlier) to think about and solidify what matters to you. What makes you happy? What do you really want to accomplish? Once you have this down, you can start to put together some semblance of a plan for getting there. Your goals need to be the composite of tasks that are realistic and actionable which amount to achieving said goals. You also need to give yourself room to fail, so you won’t be entirely discouraged if you aren’t perfect. Because you won’t be. You’ll never be—and thats OK.

    The Way Forward

    So what’s next? Well I’m still working on climbing out of the burnout hole. I have some ideas for how to kickstart myself professionally, and I am working on a more defined plan for the other things in my life. It’s not going to be a straight shot up and out, and burnout isn’t something you “defeat”. It’s something you manage. I’ve seen how it can manifest, I understand some of my triggers, and I know a few things that can help me treat and mitigate it. That’s enough for now.

    Thanks for reading. Take care of yourself out there!

    References & Resources

    Other burnout stories from the field:

    Fun fact! The original draft for this post was May 3, 2024.

    Reply source
  • Gardenlog: Blueberries, Blackberries, Oh My!

    OK! Checking in now on all things garden-ey from the past few weeks…


    Tomato Updates

    The Cherokee Purple’s have really gotten tall! Some yellow flowers here and there but no sign of fruiting as of yet. Just gotta keep on waterin’ ‘em and see what they do. 🍅

    Blueberries, Blackberries, Oh my!

    After some serious snipping, I was able to remove all of the invasive honeysuckle that had managed to grow in-between the two blueberry bushes that it turns out I have on the side of my house. Between the two of them, there seemed to be 100’s of berries! They ripened at various times and it was a blast hand-picking them with the kids and eatin’ them on the spot. But it’s not just kids that like berries—birds and squirrels do too—and they came for them… So, I bought a little tulle to try and protect the berries (as shown below). Has it worked? Hard to say. I don’t think I did the best job wrapping the bushes to begin with so inevitably the little critters found their way in. Now I’ve just got one bush wrapped and I think it’s doin’ a decent job at this point. The other bush is just about picked clean.

    Next to my blueberries, I’ve got this other berry plant. For a while I thought it was some kind of blackberry, but it could be a raspberry too perhaps? Take a look at the following two pictures and let me know what you think…

    Either way, delicious berries are in my future. No complaints!

    Other stuff

    Here’s some other random things to report from the garden/yard…

    My porch project is nearly done, and here’s the current status of my future garden bed location. It’s all clear of pavers! Some work will need to be done to dig it out from here and lay in some suitable soil. Haven’t decided what all I want to grow here, but I think some cucumbers for sure (amongst other things).

    Also, as part of the larger future layout of my yard/gardening area, I’ve put in some infrastructure for a future potting bench that would sport a working sink. Cool!

    I bought a pair of potted hydrangeas. Just waiting for some flowers now…

    Finally, checking in on the wild blackerries I’ve got out back… the fruit is struggling a bit…

    Until next time! 🧑‍🌾

    Reply source
  • Beep, Boop, Sad 🤖 😞

    “AI” is making me, and a lot of other people sad. This collection of links will give you an idea why…

    ⚠️ WARNING!: Click on these links at your own peril. They’re likely to make you even more sad.

    I’ll update this list as articles continue to pour in. Did AI make you sad today? I’m truly sorry about that 😕. Here’s a hug 🤗. Feel free to send me a note about it and I can add it to this wall-of-sad.

    Pivot to AI is also a great upsetting compendium of such links.

    Reply source
  • Over/Under with Shellsharks

    Here’s my submission to lazybea.rs series Over/Under. The idea is simple, Hyde gives me some topics and I state whether those things are overrated or underrated, with some text about why. Here were my chosen topics…

    Go read this post over at lazybea.rs!

    Over/Under with Shellsharks

    IndieWeb

    By most, the IndieWeb is severely underrated—by the enlightened few, consider it adequately-rated. It’s probably of no surprise to anyone who has followed my writing for the last two-ish years—I love the IndieWeb, and personal blogging in general. I frequently write on the subject, have built many-a-reference dedicated to collecting resources and educating others, and I somewhat recently started a “newsletter”-type thingy dubbed “Scrolls”, which heavily features content and personalities from across the IndieWeb. I love me some IndieWeb.

    Slash Pages

    Though I have to give all credit to Robb for the creation and maintenance of the venerable Slashpages.net, I can give myself a tiny nod as Robb did consult me prior to the site going live on what my thoughts were on how they should be defined and what pages should/could be included. He was even nice enough to give me a named credit on the site and include my silly /chipotle slash-page 🌶️ 😆.

    Slash Pages are just fun. They are an emodiment of the IndieWeb experiment. They are meant to share something about you, the individual behind the site. They exist in a place (the root of your site) that should be relatively common across other IndieWeb sites—which leads to improved discoverability and a greater sense of community. They are also just quirky, silly and very human—something the web, and the world, desperately need more of.

    In the weeks and months since Robb launched the site, I’ve noticed a really promising level of adoption across my own IndieWeb circles. I hope to see more people have fun with this idea, add Slash Pages to their site, come up with new ones, etc… For now, I believe it is still vastly underrated!

    Sharks are Dangerous

    I maintain a healthy respect for all wild animals. They deserve as much if you ask me. They are also all equipped with a dizzying assortment of defensive capabilities. So for your own protection, I suggest everyone maintain safe distances and treat all life with respect. This is doubly-true concerning creatures that are of-the-sea.

    I’m a land-walker. On-land, I feel like I can hold my own well-enough. I can see things that approach me, I can hear them, I can run pretty fast for a human, I can even pick up something to defend myself if I needed to. Not saying I could tussle with, and win, against any manner of land-faring beast, but I can do something. When it comes to the water though? I’m completely defenseless. I can swim, yeah—but that’s about it. I can’t really see underwater, I have no means to really detect if something is about to “get me”. I don’t think my futile punches or kicks would amount to much, especially against something like a shark.

    All this to say, I do think Sharks are dangerous—or rather they can be. If you don’t have that healthy respect for them. They are apex predators afterall, and they dominate in a world that humans, just naturally don’t. You’ve probably seen that statistically, sharks aren’t particularly harmful to humans. This is probably true. As such, I think the danger of sharks is probably properly rated. Humans aren’t natural prey for sharks (thankfully), and we as humans do some things to avoid sharks where we can. Sharks are innately curious, and infinitely cool. I mean, I have a lot of shark-themed stuff on my site, so you know I have somewhat of an affinity.

    Ransomware

    I’m (professionally) in infosec, so I have an appreciation and technical understanding of Ransomware—how it can happen, how to defend against it, and the impacts of an incident. Ransomware is consistently placed at the top of “things to worry about” lists (e.g. Verizon’s DBIR) and yet, remains inadequately defended against time after time, across all observable sectors. I think it’s impossible to overrate the financial impact of a serious ransomware-related breach. Entire companies have been snuffed out of existence thanks to them—and ransomware-as-a-business in and of itself is measured in the billions, if not trillions, yearly.

    Octopus Dishes

    Fried, and then dipped in some sort of sauce? Sure. Otherwise? Ehhhh, not really my thing. Not a big tentacle guy I suppose. I gotta say overrated.

    Reply source
  • Scroll vīgintī quattuor

    Welcome to volume twenty-four of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we discuss the point of blogging, what social media is (and isn’t), and drop a lot of awesome infosec tools/resources.

    Scrolls isn’t dead yet. Let’s go!

    IndieWeb

    What’s the point of blogging? Who’s a blog for? I’ve always said my blog is a place for myself, but it can of course be so much more. These days, people really don’t think much about “blogging” in the classic sense. Instead, we’ve grown accustomed to shoving our thoughts into small, character-constrained boxes owned by [INSERT BIG TECH COMPANY NAME HERE]. We’ve gone from surfing to scrolling, and we lost the web along the way. This is where the IndieWeb comes into play—as a means to reclaim digital independence, and the beauty that once was.

    So what should you do with your site? (Y’know, once you’ve got one up.) You can really do anything, but I like the idea of making your site a digital home of sorts. Your site, as it exists on the web, doesn’t need to conform, or have any specific things, or be “a part” of anything. It can just kinda be there, at an address you own. You can put whatever you like there. That said, as the owner of a site, at a domain you own, you are in many ways already part of something larger known as the “IndieWeb”. So where can you go with that? Honestly, I think just writing, and publishing said writing on your site is a great place to start. If you’re looking for inspiration, community, or prompts, check out the various writing months (e.g. TILvember) or the IndieWeb Carnival. Not sure you know what you want to write? Maybe try replanting some older, or forgotten articles on your site. Or, you can help connect the web by sharing sites you love on your own site, through something like a blogroll.

    One thing you should absolutely do for your site, especially if you have, or plan to have, any type of “posts” there, is have an RSS feed—because RSS is awesome. RSS is important, it is the tried and true, reliable way to share your content with others, and consume a variety of content from across the web. Simple. Easy. Free. Do it.

    Lastly, don’t forget. AI sucks.

    Small Web Finds and Features

    Here’s a handful of cool sites I’ve enjoyed recently…

    • mcyoung has an extremely eye-pleasing indie site 🤩.
    • HISVIRUSNESS has an awesome hackery/indie feel to it.
    • This site—I’m honestly not sure what is going on with it, but it looks amazing.

    Fediverse

    What we’ve seen in the social media landscape over the past 4 years or so should be enough to convince you that you shouldn’t rely on big tech, or any social media platform to function as your “identity” on the web. But that doesn’t mean social media isn’t as important as ever, as a place for community, news, organization and more. Carefully consider where you decide to set down roots in terms of social media and building a community. No one platform is going to give you everything, but many will have certain dealbreakers that you must consider. Obviously I make the case often about the Fediverse and why it is where you should invest, but other options do technically exist. But really, how can those other options even compare when Fedi has stuff like this?!

    Cybersecurity

    New year, same cyber. Let’s see what we’ve got…

    A few interesting writeups to check out—CSP for Pentesters, Breaking Trusted Execution Enironments via DDR5 Memory Bus Interposition and The Normalization of Deviance in AI.

    The infosec community continues to pump out all manner of free tools and resources. I’ve catalogued a few I’ve recently discovered below…

    Looking to build your own infosec news feed? To get ya started, I recommend following Tim on Mastodon (specifically checking out his weekly link roundups like this one). You can also sub to the new, and cool, Hacklore Project.

    Finally, I’ll leave you with some things to ponder… Why are there so few women in infosec & why folks are leaving the security industry?

    IndieSec Blogs

    Thanks for reading Scrolls! Off to brew some zen…

    Reply source
  • The Cybersecurity Workforce Crisis

    Much digital ink has been spilt on the plight of the cybersecurity workforce. Is there a talent shortage? A skills gap? Other, darker issues? Here’s what I think…

    The “Talent Shortage”

    First, some back story… When I was getting started in infosec, back in 2010-ish, I remember the on-radio campaigns which spoke of endless opportunity in the up-and-coming “cybersecurity” field. Over time, the messaging became that of a severe shortage of people to staff in these roles. Even back then though, despite all the claims of a “shortage”, getting an actual infosec job wasn’t easy—even for someone with a relevant degree and a few certifications. In the years since, interest in cybersecurity as a profession has surged. You can thank the above-average pay, remote work, and other intrinsic benefits I suppose. These days, you could argue that we’ve hit some level of saturation, especially in the entry- and junior-level ranks. This is evidenced by the countless stories of aspiring infosec pros who go months on end, applying to 100’s of jobs and do countless interviews with nothing to show for it. Mind you, these are more often than not, individuals who have 4-year degrees, who have multiple certifications, and who have done many other things to prepare and boost their qualifications to best pitch themselves for mere entry-level roles. To me, I think this contradicts the theory that there is some sort of talent (pool) shortage. We’ve got plenty of people interested—raw and unrefined—but there, ready to get to work. So the question is then, if the cybersecurity workforce crisis isn’t one of a talent shortage, what is the issue? Does the existing and aspiring workforce suffer from a “skills gap”? To this, I think the answer is a resounding “yes”, but maybe not for all the reasons you might believe…

    The “Skills Gap”

    As I’ve already stated, even the entry-level aspirants and lucky receivers-of-jobs these days almost uniformly have 4-year degrees, one or more certifications, and plenty of other worthy accomplishments. Yet, this has not seemed to make a meaningful dent in the aforementioned “skills gap”. Consider now the slightly more tenured infosec pro. One who (if fortunate enough) not only has a few years of “experience” but also may have attended several trainings at this point and could then hold multiple certifications. Likely, many of those certs are from vendors like SANS, ISC2 and EC-Council. Yet again, the skill deficiencies persist. How is it that we have so many college-educated, multi-cert wielding, many-a-year-on-the-job-having infosec pros still having so little to show when it comes to real-world, applicable infosec skills and know-how? Let’s play the blame game…1

    Weak Blames

    One of my weaker blames is that of training budgets. I think a lot of companies, and thus the industry as a whole, do an abysmal job providing adequate time and budget to train their infosec workforce. But, as you’ll see in a minute, access to what passes as “training” is hardly the problem, as the training, even if made SUPER-available, is just not closing the skills gap anyway.

    Strong Blames

    My stronger blames lie with the tenured infosec community, the cybersecurity vendors, and corporate infosec programs themselves. Let’s start with the grizzled veterans of infosec—the folks with the skills. First, I want to point my finger there. There is real opportunity for mentorship, but I think as a whole, we have failed to build these bridges. We grumble and complain about “script-kiddies”, and “paper tigers” and whatever, but do we take the time to mentor and train? Nah.

    Now let’s talk about what it means to get “experience” in infosec. I think overwhelmingly, infosec professionals are put on rails with respect to their job responsibilities. Here’s some tools you are expected to know how to operate, but not expected to know how they work under the hood. Here’s a framework you are expected to audit your IT program or business against. Here’s your corporate, technical “swim lane”, that you must operate within, and never stray outside of. That sorta thing. I don’t think infosec tools are inherently “bad”, or useless in terms of providing value or reducing risk, but as you can tell from the state of cybersecurity in the world, they are in no way the silver bullet. We continue to have breach after breach, security failure after security failure due to infosec 101 type-of-stuff—stuff the tools are not stopping. These companies have tools. We have personnel that operate them. That (buying and running tools), if anything, is what we’ve become good at. But it clearly isn’t enough! The infosec industry, we as engineers, were never meant to be exclusively put behind the limited capabilities of these tools. What if we could do something different? Like, look at these problems and come up with practical solutions based on a found understanding of infosec principles.

    But herein lies the problem. The modern infosec “pro” is no longer conditioned to solve ad-hoc problems, or problems of complexity. We’ve been on rails too long. If the tool can’t solve it, how could we? If it’s not one of the exact usecases covered in the Day 4 lab of our latest SANS course, what’re we supposed to do about it! If it doesn’t fit neatly into one of our precious CISSP knowledge domains then oh no! We’ve lost our way, and with it, we’ve abstracted too much of the basics, the real engineering away. It should be expected that all infosec pros are able to do some relatively basic stuff—across operating systems, with standard networking protocols, with industry-standard, open-source tooling. We should be able to hack together basic scripts to do simple things. We should understand the tech stack and supporting protocols of any run-of-the-mill web application. But can you really say that even 20% of infosec “professionals” know these things? I’d say not. But I sure as hell would bet that each of us know one or more enterprise tools super-duper good. How many infosec folks out there can operate Splunk with medium-to-advanced proficiency but can’t actually pull and decipher a packet capture? How many VM analysts can pull off all sorts of wizardry with Tenable, but couldn’t practically exploit a real vulnerability? We’ve become too reliant on tools, and we’ve creatively and technically boxed in our security workforce as a result.

    Training vendors aren’t closing the skills gap. “Work experience” is not closing the skills gap. Those of us with useful knowlege, and wisdom to share, are not helping to close the skills gap. The skills gap is real my friends, and there is blame to go ‘round.

    Just Look At Me

    I feel I can speak on this topic because I’m a product of it. Get this cert. Get that cert. Use this tool. Use that tool. Getting certs and knowing how to use tools has been pretty great for my career, but what have I learned? Have I really advanced my knowledge? The issue with so many “trainings” these days too is that they don’t teach core concepts. They don’t cover fundamentals. They like to focus on the shiny things. The abstractions. The tools. The practical, yet hyper-specific usecases. They hold your hand through exercises and labs, giving you a false sense of know-how, but when you are turned loose in a real-world, corporate setting, you are left wondering “what do I do?”. That’s if you even get a chance to use what limited skills you may have picked up in training on the job. For most, I feel like they’ll go get training for something, and then return back to their routine daily job responsibilities, which require no practical usage of what they had learned in training. So that knowledge, when not practiced, will fade away. Plus, we’ve all just been conditioned to pick up certs, and put fancy letters in our email signatures and LinkedIn bios, entirely discounting the journey that got us there. Get a cert, get a better job. Rinse and repeat.

    Let’s Adapt

    We need to adapt. Let’s open up the cyber-swim-lanes. Let’s establish lines of mentorship from professional generation to professional generation. Let’s build training into our corporate culture and then give professionals the space to practice it, to operate with creative license, to solve problems—not with tools, but through the application of actual security fundamentals. I mean we all learn it. It’s really not arcane magic. We all have the “CIA Triad” etched into our cyber-brainz. We can all do a risk assessment—we just have become so vendor-tool-addled and compliance-pilled that we’ve forgotten how to look at things holistically, do actual root-cause analysis, troubleshoot at a low level—really solve issues, in the bespoke and tailored manner in which we otherwise could. The answer to your next cybersecurity issue shouldn’t immediately be a phone call to <INSERT VENDOR NAME> to add-on another paid module in some tool. What if instead, you engaged your cybersecurity workforce, and I mean the actual engineers, not the “cyber leadership”, and asked, “how do we solve this problem”? Then, give them the space to actually do it. I’ve seen it work—honestly, I have. The knock-on effects can be wondrous too. Save money on tooling subscriptions, have a more engaged infosec team, actually reduce risk, build a real culture of engineering, that sorta thing.

    I don’t want to trivialize the difficult nature of the infosec industry at large. If things were so easy, I imagine it would have been solved—right? But I think it’s safe to say that a crisis does exist. It’s also fair to say that the way we’ve been doing things just isn’t working. More SANS training isn’t bridging the gap (no offense SANS!). More team charters and vendor tools hasn’t bridged the gap. It’s time to do things differently.

    Look, maybe it’s just me. Maybe I’m just projecting my own shortcomings. Not everyone suffers the same, and not every company has the same all-around deficiencies. This is just the way I see things. Looking “across the industry” though, I’m seeing some of the same patterns, and I don’t think I’m terribly far off.

    1. New SANS Report Finds Cyber Talent Crisis Isn’t About Headcount. It’s About Skills. 

    Reply source
  • Scroll trīgintā quīnque

    Welcome to volume thirty-five of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week, if you haven’t already, you should make a fuc**ng website. Y’know what? That’s it. Just go do that.

    jk jk — I also discuss some shortfalls of social media (yes, even the Fediverse), and lament the many broken computer-ey things in the world.

    IndieWeb

    I’ve said it once, I’ve said it a million times. This time I’ll say it a bit more eloquently–you should have a fucking website. Don’t overthink it! It really isn’t all that scary. Your site can be big (maybe not too big though 🤦‍♂️) or small, static or dynamic, colorful or plain, whatever you want! (Just no AI puh-leeaseee).

    Because if we don’t build our own places on the web, we’ll get stuck with the big boring box to (digitally) live in. That’s the boOooOring, vanillaweb. We want the good, fun, non-corporate, cozy, human web! So getcha a site, put alllll your stuff there (yes I mean all of it), and then go read and connect with other people doing the same. It’s fun I promise! Just remember, it’s all about being you, in a place that’s for you. Don’t get too choice-overloaded or bogged down by the technical bits 😄.

    From N-gated Hacker News

    🚀 Behold, the #IndieWeb POSSE piece: a brave odyssey into the chaotic labyrinth of infinite links and jargon! 🔍️ Navigate through a maze of enthusiasm for #DIY websites everyone will forget by next week. 🤦‍♂️ It’s the perfect handbook for the #hipster coder who thinks their blog will change the world—one unread post at a time. 📖✨️

    lol

    Speaking of fun, there’s so much to do once you have your site up ‘n runnin’. Ya gotta tinker around with the look and feel of course, write your silly li’l posts, then write some cool serious posts (y’know, if you want that is), and do all sorts of other fun things! If you get stuck, take a break and go wander about and poke around on other people sites—inspiration is abundant if you know how to look for it. For example, the Over/Under series is a great way to get introduced to cool new blogs and the humans behind them.

    Small Web Finds and Features

    Two li’l web finds to share with y’all this week 👇

    Fediverse

    Look, the Fediverse is great. I have a whole weekly section here dedicated to it afterall. But it could be better. Or maybe traditional “social media” is irrideemably flawed in some ways… Yes, it serves “connections”, but too often those connections result in something I find eerily inhuman. I think blogging allows for more a human connection, but it has its own shortfalls with respect to actually delivering said connection (i.e. discovery). You know the feeling—that sense of yelling into the void…

    Coupling these two sentiments is why I am so invested in both my blog as a means to express my humanity, and the Fediverse as the connection and discovery mechanism to spread the good word (i.e. the silly stuff I post on my site).

    Cybersecurity

    Hello and welcome to everyone’s favorite cyber-themed gameshow, “What’s Horiffically Broken”! I’m your host shellsharks and this week we have several new (and many recurring) contestants! Who will win?! We’ve got AI, the “cloud”, supply chain security infrastructure, NFC, and even SVGs! How exciting!

    Stepping away from said horrors, here’s some other neat things to check out 👇

    Thanks for reading Scrolls! Remember, even in dark times, there’s still plenty of good in the world.

    Reply source
  • Scroll vīgintī septem

    Welcome to volume twenty-seven of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we ponder a better, although imperfect web, we encourage everyone to join the Fediverse movement, and sigh… AI continues to make us sad.

    But ya know what doesn’t make me sad? This dope bird mage. 🐦 🧙

    IndieWeb

    The “old web” wasn’t perfect, but it’s hard to look at what the web has become and not wonder how it was lost. Those that remember have sought to build a once-again “open web”, but things are never that simple. Problems abound in this quest to be sure, but for every obstacle, there are ways to mitigate and build a better, more open, more cooperative, more human web—it doesn’t need to be perfect.

    The lifeblood of this better web is the classic personal website. If you don’t already have one, what better time than now to do so! There are so many ways to get one up and running. There are a lot of reasons to have your own website and do some blogging there too! And no, simply having a social media presence is no substitute for an actual website that you own. Personally, I like having both a website and a standard (Fedi) social media presence. But there are options for making your website/blog plenty social if you’d like.

    In fact, when it’s your site, it can be whatever you want it to be. You own it, so you can tinker with it to your hearts content, no obligations. You can update and change whatever you want, whenever you want. If you’re worried about the technical aspects of creating and managing a website, don’t! There’s plenty of no code or low-code options available. Does your website have to be good? Does it need to look like other people’s sites? No! In fact, I’d encourage you to make it unique. Make it you. Hell, make it purposefully worse than other sites you see. Honestly that’s the beauty of the personal, IndieWeb. Doin’ whatever you like.

    Fediverse

    Who would you rather trust to safeguard your online communities, your digital relationships, and your personal presence/identity on the web? Elon Musk? Mark Zuckerberg? Some other billionaire or privacy annihilating big tech entity? Or would you trust your actual community? This isn’t fantasy. There are real options to build, maintain and join online communities no longer reliant on the traditional tectonics of “big social”. Your first step? Simply sign-up. Congratulations, you are now a hero.

    Perhaps you’re concerned that the “Fediverse”, or the “Social Web” is simply too fledgling for you to entrust something this important to—to invest this much time into. Well, I’d still argue that given the alternative, it’s worth it regardless. But if it allays any fears you might have, take some time to do some research and see all the work that is being put into making this big-tech-free web a reality. There’s so much innovation to be found! We’ve got E2E encryption coming courtesy of the Public Key Directory, LinkedIn will soon be a thing of the past, we’re bridging networks and eradicating mansplaining while we’re at it. Come join us!

    Cybersecurity

    AI isn’t secure. AI can’t be trusted. But AI lives on. Patch yo shit.

    Thanks for reading Scrolls! Time to go goblin mode…

    Reply source
  • Renewal

    This month I’ve decided to participate in my first IndieWeb Carnival—a once-a-month writing prompt organized by the IndieWeb.org community. This month’s prompt is “Renewal”, hosted by Jamie Thingelstad.

    There’s a lot on my mind lately in regards to this term—“Renewal”. I recently moved into a new house and with it I have a yard. The yard has a lot of plants and trees that are now flowering—cherry blossom, red bud, skip laurel, rhododendron and more! This is my first spring here so it has been fun to see what bloomed, and given me an opportunity to learn more about these plants.

    This site, shellsharks.com, has also seen quite the renewal—or better put, a revival. 2025 has been a very busy year for me in terms of sprucing up the site, writing regularly and exploring an even greater breadth of topics and content types. This momentum always energizes me creatively and gives me productive momentum in other areas of my life—professionally, around the house, and with other assorted projects.

    I’m not sure what else to really go on about. My life seems to always be a constant stream of new things. This is by design, and unavoidable. To continue to stay on top of it all, it’s always helped me to reframe these challenges, these endless lists of to-do’s as something “new”. Whether it be a new way of approaching an old problem, or in fact a new issue altogether.

    So, here’s to all things new, and “re”-new for me this year! 🌻

    Reply source
  • BQC: Outdoor Activities

    Answering the Blog Questions Challenge Outdoor activities

    What’s your favorite thing to do outside when the weather is perfect?

    Hiking a mountain. Preferably one with a nice rocky ridgeline so I have views of the valley and surrounding ranges.

    If you could only do one outdoor activity for the rest of your life, what would it be?

    Kind of an odd question tbh. I mean I love to hike, but I also love sitting by a campfire. Must I choose!? Y’know what? It’s my blog. So I won’t.

    What’s the silliest thing that’s ever happened to you while enjoying the great outdoors?

    A bird pooped on my head once while I was traveling in South Africa… 🐦💩😡

    Would you rather explore a dense forest or relax on a sunny beach?

    Easy—the forest all the way. I like the sense of adventure.

    Reply source
  • i'll read it.

    I’ve always said not to worry about whether someone will read what you have to say on your blog. The world is a big place, and there’s always an audience for your writing, no matter how niche. And here ya go, someone wants to read it.
    Reply source
  • Hypocrisy. Illiteracy. Deception.

    We need to stop platforming Nazis—available on my Substack.

    The importance of decentralized social media—posted from my Bluesky acccount.

    The dangerous rise of fascism in America—follow me on Twitter for more.

    The importance of open source—from my WordPress blog.

    Starting to get the theme here? These are all things I’ve seen in the last year. Kinda awkward right? We’ve got Substack eagerly platforming Nazis, Bluesky is laughably not decentralized, Twitter is… well…, and ooph, WordPress has been quite the open source debacle now hasn’t it? Why do these authors and creators continue to publish such incongruous content to platforms that are in direct conflict to their own message?…

    1. Are they enslaved to the “reach” and “community-effects” that these larger, morally-compromised platforms provide?
    2. Are they simply tech-“illiterate” and don’t understand what’s going on with these platforms?
    3. Have they been outright deceived by the marketing and influencers of that platform—led to believe their platform of choice is something that it isn’t?
    4. Or are they just full of shit?

    I have my theories… 🤦‍♂️

    The ol’ Cringe-o-Meter is just pegged to max these days a’int it?

    Reply source
  • Professional Path

    I saw a thread recently which asked people to share their “path” in cybersecurity. I’ve long maintained a few lists that sorta represent this path, so I decided to mush them together to create this simplified timeline of notable career events (e.g. degrees, job changes, certs and other large life or professional-adjacent events).

    Timeline

    • Pre-2010 My infosec path really begins in 2010-ish, but prior to then, I worked a number of IT-related jobs, which gave me some work history and tech-related experience
    • 2010 (through 2013) Started new role as a Intern Software Engineer / Systems Engineer I (software developer)
    • 2010 Started Bachelors degree in Information Assurance & Network Security
    • 2012 Graduated with BS in Information Assurance & Network Security
    • 2013 Achieved CompTIA Security+ degree
    • 2013 Switched to security compliance role (First security position!)
    • 2013 Started new role as a Security Analyst (First “technical” security role - e.g. Tenable, AppScan, Burp, etc…)
    • 2014 Started new role as a Senior Consultant (Infosec)
    • 2014 Achieved ECCouncil CEH certification
    • 2014 Started new role as an Application Security Consultant
    • 2015 Started new role as an Application Vulnerability Management Analyst
    • 2015 Achieved Qualys VM certification
    • 2015 (through 2021) Started new role as an Information Security Engineer (First “engineer” title)
    • 2016 Achieved Tenable TCSE and Core Impact CICP certifications
    • 2016 Started Masters degree in Cybersecurity
    • 2016 Achieved GIAC GPEN, ISC2 CISSP and eLearnSecurity eJPT certifications
    • 2017 Promoted to Lead Information Security Engineer
    • 2017 Achieved eLearnSecurity eCPPT, GIAC GCIA, GIAC GPYC & GIAC GMOB certifications
    • 2018 Achieved OffSec OSCP & GIAC GCIH certifications
    • 2018 Started shellsharks.com!
    • 2019 Achieved GIAC GSEC, GIAC GWAPT, GIAC GREM & GIAC GRID certifications
    • 2020 Achieved GIAC GXPN, AWS Solutions Architect, GIAC GAWN & AWS Security Specialty certifications
    • 2020 Graduated with MS in Cybersecurity
    • 2020 Became a father!
    • 2021 Achieved GIAC GCPN & GIAC GSOC certifications
    • 2021 Started new role as Senior Enterprise Security Engineer
    • 2023 Kid #2!
    • 2024 Switched to a new role, Application/Infrastructure Security
    Reply source
  • How I take my coffee

    Riffing on Axxuy and Elena’s posts about how they drink coffee, here’s how I take my coffee… ☕️

    As of March (2025) I’ve gotten into making at-home cold-brew coffee. It’s delicious! I normally take 2/3 of a pint glass with a splash of half-n-half, another splash of 2% milk, then top it off with ice (cubes). This is what I drink most of the time these days. Since I’m newish to brewing my own cold brew, I’m still exploring what types of beans I like most and have really been enjoying sampling different roasts and regions (speaking of, maybe I should start a sort of “coffeelog” where I can do some tasting notes / reviews… 🤔). Not sure what I like the most yet, but I do know that it’s far better than the french press swill I had been making before.

    When I’m out ‘n about and ordering coffee, I typically go with an iced latte or sometimes just an iced coffee. I like getting the latte’s because I can’t make them at home. I never drink hot coffee. I’d rather have no coffee than have it hot. I just don’t enjoy hot beverages. When I do happen across a Starbucks, my go-to order is their Iced Brown Sugar Oatmilk Shaken Espresso, with just 1 pump of the syrup, otherwise it’s too sweet for my liking.

    Cheers!

    Reply source
  • 'cause nobody hurts me better

    My song ranking of Sleep Token’s album Even in Arcadia. Honestly though, that top 4 is super hard for me to decide as they are all mind-blowing. Also, had to roll back into this post and drop the lyrics to my favorite parts of each song. Behold!

    1. Gethesmane (shoutout to that epic riff tho’)

      and I’ve learned to live beside it
      and even though it’s over now, I will always be reminded

    2. Caramel

      too young to get bitter over it all
      too old to retaliate like before
      too blessed to be caught ungrateful, I know

    3. Past Self

      and if this is love, then i am out of hesitation
      walking an inch above the pavement
      taking it stride by stride together
      if this is real, then i am all up in a frenzy
      not like before when I was empty
      say that the story we tell is never ending
      taking it stride by stride together

    4. Emergence

      are you the carbide on my nano?
      red glass on my lightbulb
      dark light on my culture
      sapphire on my white coat
      burst out of my chest and
      hide out in the vents

    5. Damocles

      and nobody told I’d be begging for relief
      when what is silent to you feels like it’s screaming to me
      and nobody told me i’d get tired of myself
      when it all looks like heaven, but it feels like hell

    6. Look to Windward

      oh and I
      I used to know myself
      oh and you
      you used to know me well
      oh and I
      I wish that I could leave myself alone
      oh and you
      you wish that you could make me whole

    7. Provider

      and our bodies converse like old friends
      exchanging in years silence
      with something unsaid on both ends
      surely we know the difference

    8. Infinite Baths

      even if I’m on my own
      when the silcence is deafening
      I could be stuck here alone
      when even my future is threatening
      something is lifting the bones
      something is dancing in revelry
      wider than oceans below
      taller than titans on boxsprings

    9. Even in Arcadia
      that final…

      have you been waiting long!!!

    10. Dangerous

      when’s the last time you tasted blood?
      and what will it take to stem the flood?

    Reply source
  • 'Self-host it' is an answer. Let me explain...

    My response-to / thoughts-on Neil’s write up, ‘Self-host it’ is not the answer.

    👹 Strapping on my devils advocate horns hat

    Neil is right, self-hosting isn’t a panacea for the ills of big tech, and barriers absolutely exist, some insurmountable for many, but I think spreading the self-hosting gospel, i.e. educating the larger populace of potential self-hosting aspirants, is a good thing. The subset of folks who could self-host but don’t is probably pretty large. Heck, that includes me! The subset of folks who never knew, or never considered self-hosting something is also non-zero. As others have pointed out, solutions/services/platforms (e.g. YunoHost) which help bridge the gap between big tech reliance and full-on self-hosting have started multiplying. Why? As a direct response to the enshittification of big tech and the growing demand that has sprung up in that wake.

    So no, saying “just self-host it” isn’t really the right approach, sure. It’s a bit more nuanced than that isn’t it? As Neil has pointed out, it requires resources, time, money, know-how, etc… This is all true. But each layer of that stack can be managed in different ways, not all of them by the individual. And know-how? Is it too much to ask to have someone learn something new? You don’t need to become an SRE over night, and you should expect-to and plan for failure along the way, but you can surely figure something out in time yeah?

    But let’s take a step back. To say ‘just self-host it’ isn’t the answer, let’s first try to derive/understand the question. Neil doesn’t explicitly say, but in my mind we say “just self-host it” as an answer to a (generalized) question like “big tech platform A is bad, how can I lessen my reliance on it”? In this case, the operative word is “bad”, which can mean anything from said big tech company is violating one’s privacy, enshittifiying, being sunsetted, etc… A better answer to this question is to point out the vast array of alternative options, self-hosting of course being just one of those. You also have managed hosting, FOSS alternatives, smaller/non-big-tech (though still centralized) platforms, etc… Do we have a well-known vocabulary for suggesting “managed” or partially-“managed” hosting alternatives? I don’t think so. Instead, we just tend to say “self-host it”. But I think this answer can be inclusive of more things than just, full-on, purist, I own/control the entire stack self-hosting.

    Neil does make the distinction between his definition of ‘self-hosting’ and that of ‘self-managing’ (running stuff on hardware/a-platform that is not your own), but I think that this is the core problem. This vocabulary (“self-managed”) is not agreed upon, or known. He makes a lot of valid points about why “pure” self-hosting isn’t a great answer, but I think he’s taking it too literally. I think ‘self-hosting’ as the most well known term here can be thought of more inclusively as being everything from owning the whole stack, to just owning part of it (call it “partially” self-hosted if you’d like).

    Rather than dismissing the idea of self-hosting as something only the most dedicated of tech nerds could possibly figure out, let’s instead continue to educate the masses on what it means to move away from big tech. How truly possible it is and what the benefits are. A more educated populace will in turn create more demand—for community hosting, managed hosting, content on how to self-host, tools to make self-hosting easier/more-secure, etc… It’s important to lay out the obstacles and pre-reqs, yes. It’s very possible to bite off more than one can chew here, but you can right-size how you approach this and ease yourself in a responsible way.

    Reply source
  • Scroll duodēvīgintī

    Welcome to volume eighteen of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. In this issue, we ask “what is the web?”, we gaze across the Fediverse, and we declare “mission accomplished” on cybersecurity 🤡!

    IndieWeb

    What is “the web”? It’s damn sure not the corporate web I’ll tell ya that. The web is us. That’s right. People make the web—via the blogs we craft and those we discover. It may look less like it did in 1999, but this web persists, and it continues to regenerate and flourish each day. This, the good part of the Internet, is alive and well.

    The IndieWeb’s vibrancy comes not from pace of content, but rather from individuality and creativity. Here’s some cool stuff I’ve seen recently (great too if you’re looking for inspiration for your own site!) Immich shared some cursed knowledge, Ava is looking to trade blog post titles, Axxuy celebrates their bloggiversary, Nick Simson is hosting this months IndieWeb Carnival, Brad goes brain dumping, Kris is doin’ a little link cleanup and Will is making the blogiverse a bit healthier. With so many ideas, so many aesthetics, so many voices, the personal web can seem quite chaotic. But that’s just what makes it fun! So get out there and build. Write. Share. Haul off and redesign your entire blog y’know? If it’s already been redesigned… redesign it again! Keep tweaking and having fun with it.

    The other side of the IndieWeb-fun coin, beyond tinkering with and writing for your own site, is exploring everyone else’s sites. So go forth! Discover awesome sites and cool posts. Comment on them, comment on others comments, share them with your friends—with the world! If there’s no commenting mechanism, try contacting them through other means. Drop them a nice note about what you saw or what you read on their site. Trust me, it will make their day.

    Small Web Finds and Features

    Go check out these cool sites. Like, you could just leave this page right now and do it (but come back after 😉).

    • 🧑‍🍳 😘 Gail 👏 - IndieWeb perfection.
    • Speaking of perfection—Henry’s site is, in my opinion, the best looking site I’ve ever seen.
    • The awesome, and brand new, good internet magazine. 👉

    Fediverse

    How do you view the Fediverse? Sure, it may be quiet at times, but I think that can represent a greater opportunity for signal over noise. In my experience, there’s a substance here that is lacking on other microblogging platforms. But Fedi (as you may well know), is not just microblogging. It’s an ecosystem of decentralized platforms, which all communicate over a shared protocol. That’s how you can have a Facebook-like system which can interoperate with a microblogging platform, or a forum-based platform, etc… It’s not perfect here, but the ever-growing list of benefits are well-worth the time spent investing in building a community and a personal presence here on the Fediverse rather than elsewhere. Interested in owning your own little Fedi-parcel? Check out FediHost!

    Cybersecurity

    Ok everyone, pack it up. The war is over. Cyber is solved. All thanks to AI!

    But y’know if you can’t afford fancy-schmancy “world-saving” AI-based security capabilities. You might want to continue to learn up on the breadth of security issues that continue to face the industry. Y’know, like understanding logs, or linux process injection, or windows coercion techniques, things like threat intelligence, binary planting and the ongoing risks posed to DNS—to name a few.

    To help you on this quest, check out some of these tools I recently discovered. NERDCERT.EU is a cooperative-based letsencrypt, Wazuh has a free threat intelligence platform “Vulnerability Explorer”, The Vulnerable MCP Project is cataloguing MCP-related vulnerabilities/research/exploits, and the CIRT team at AWS has just launched their Threat Technique Catalog. Cool beans!

    IndieSec Blogs

    Finally, here’s some cool Indie folks of the cyber world for you to follow and read…

    Thanks for reading Scrolls. Hope you had a blast!

    Reply source
  • Scroll ūndētrīgintā

    Welcome to volume twenty-nine of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we’re keeping it real on the web, navigating our social crises, and goin’ through the cyberlist.

    Settle in, get cozy and start scrollin’!

    IndieWeb

    Who are you on the web? Do you keep it real or are you some other persona? Do you share openly or do you keep things close to the vest? Do you publish with confidence, or do you write with doubt? Don’t try to be something you’re not. You don’t need to push yourself beyond who and what you are. That way leads to burnout. Let yourself grow organically.

    Afterall, your site is meant to be fun! It’s a place for you to express yourself and share the things you love most. But as I’ve said before, it really can be whatever you want. So what should you do next? Why not share what you’re up to right now! Or you can add some sidenotes to your articles. Try getting into your blogging rhythm by hosting an IndieWeb Carnival. Maybe you’re not feelin’ your site and you want a change of scenery. Go do it!

    With so much you can and should do with your site, there’s always things you should just not do. Like, don’t use Substack, and don’t sloppify your site.

    Fediverse

    Social media might be a bit overplayed at this point. What we need now more than ever is community. But community doesn’t come without the effort it takes to build it. We need social networks that enable community-first principles. Mastodon may not be perfect in every technical aspect, but it’s living up to this crucial moment in time. So build and join communities on the Fediverse. Welcome the social media refugees who flee from elsewhere. We can do this!

    Cybersecurity

    It’s CYBERLIST time! (Fancy made-up word for a list of infosec stuff for you to check out…)

    Thanks for reading Scrolls! Now back to my various computerings… 👋

    Reply source
  • Intersecting Interests

    This month’s IndieWeb Carnival is Intersecting Interests. After giving it some thought, I’m not sure I have a particularly outstanding pair of intersecting interests, but there’s plenty of li’l junctions to speak of. Let’s see what I’ve got…

    • Travel x Food: An obvious one sure, but I do really love to travel and I think my favorite part has always been exploring the local cuisine. Some standouts from my travels have got to be belgians cooking various stews in their legendary beers, Tiroler Gröstl from Austria and Costa Rican casado. 🤤
    • Playing x Watching Basketball: I watch a number of different sports, but the only one I really play is basketball. I get plenty of ideas of how I might improve or tweak my game by watching what the pros are up to. Doin’ my best to copy that is!
    • Hiking x Frisbee Golf: These two go hand-in-hand. Especially if you’re not very good at frisbee golf and end up throwing it deep into the woods every time. Turns out I do a lot of extra hiking for every round of disc golf I play! 😅
    • Apple x Retro Gaming: I don’t do much modern gaming these days, but I still like to play some of the classics from time to time. Retro emulators on the iPhone/iPad are a great way to quickly enjoy some of these titles on the go. (This one in particular)
    • Blogging x ANYTHING!: Last but not least, there’s my blogging interest! Turns out you can (and should) blog about literally anything. So that’s what I do. I blog about all sorts of different things—infosec, technology, apple, gaming, travel, fediverse, music, sci-fi, gardening and much more!

    That’s it! Thanks for reading.

    Reply source
  • Just Put It On Your Blog

    If you’ve got something to say, something to share, something that others might be interested in—why not just put it on your blog?

    Someone ask a question on social media that you want to answer? Write about it on your blog and link to it in your reply thread.

    Post anything to social media? Archive it to your blog.

    Have an interesting, random thought? Write about it on your blog.

    Remember a weird dream? Document it in a dream journal on your blog.

    Find some other cool articles or web sites? Link to them from your blog.

    Have a great soup recipe? Share it on your blog.

    Have a bunch of resources related to one technical thing you know how to do well? Document those resources on your blog.

    Find yourself repeating the same thing a lot? Write a blog post about it and share that instead.

    What’re you up to right now? What’d you do yesterday? Get into anything cool last week? What about last month? Write about it on your blog.

    Like something a lot? Or maybe you really don’t like something? Go off about it—on your blog.

    Like to doodle? You know where to share ‘em.

    Saw a good movie or listened to a really great song? Talk about it on your blog.

    It’s great to have a place to share your thoughts. A place you can go back to when you want to remember something you had written or thought about before. A place you can refer people to when they have questions you’ve answered in the past. A place to be you. So, get a blog, and put all the things there.

    Reply source
  • So you've got a blog, now what?

    OK, so you’ve got a blog/website, but you’re wondering “now what”? Here’s some ideas for what to do next!

    Remember! Having a website isn’t about blogging, it’s about you.

    Reply source
  • The Death of CVE

    The CVE program is dying. Damn. 1

    What does this mean? What were CVEs (Common Vulnerabilities and Exposures) doin’ for us anyway? Are CVEs considered critical cybersecurity infrastructure? What are we gunna’ do now?! Panic!! Read on for more hyper-composed and ever-well-researched analysis! (Plus, plenty of related resources, per usual.)

    Disclaimer: It's more than likely I get something wrong in the analysis below. The situation is also very rapidly evolving. This is just my hot take on everything, and my perspective as someone who worked in the VM field for quite some time. Feel free to message me with any corrections! I reserve the right, and almost certainly will, return to this post and update it as I learn more. This is but a jumping off point!

    What is CVE All About?

    OK, a quick primer on the CVE program—from CVE.org

    The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.

    Here’s an example of a single CVE record (for CVE-2014-6271, a.k.a. “ShellShock”)…

    As you can see, CVE records contain a wealth of data for known vulnerabilities: publish dates, descriptions, product status(es), references to supporting materials, exploit PoC’s, and more. The idea is to have a CVE record for any and all CVEs under the sun. Useful yeah? That’s about all I’ll cover about what the CVE program is here. For more info, just go check out cve.org (or some of the other resources if / when cve.org dies 💀).

    CVE in Practice

    So, how are CVEs used by the larger infosec industry? In many more ways than I’ll likely be able to cover here, but I want to touch on a few ways this information is embedded. Namely, in terms of vulnerability management and vulnerability scan-related operations.

    Here’s some basics on how CVE data makes it’s way to you, the infosec populace.

    1. Vendor releases crappy insecure software.
    2. Vulnerabilty Researcher identifies vulnerabilities in said software and discloses it to vendor.
    3. Vendors (often acting as official CNAs) assign CVE IDs to vulnerabilities and publish CVE records.
    4. CVE.org aggregates and publishes vulnerability records via a centralized database.
    5. Consumers of this data ingest newly published vulnerability records. (e.g. network/endpoint scanning vendors)
    6. Corporate IT Security teams run said scanning tools.
    7. Along the way, CVE Working Groups help improve CVE-related processes.

    To put simply, scanning tools are able to identify vulnerabilities because CVE records contain valuable software and version information. These tools can compare known versions of installed software with the database of vulnerabilities that tell us what sofware+versions are affected / vulnerable. So, without CVE data, vulnerability scanning fidelity craters.

    There is a lot of other infosec / vulnerability-related infrastructure that relies on the CVE program as a dependency. CISA’s KEV is one example. I’ve got to think that many threat intelligence sources also leverage a lot of CVE data too.

    None of this sounds great so far. So what’s next?

    Now What?

    Well, first of all, CVE is pretty important for a lot of things, so it looks like CISA has found a way to keep it afloat for now. 1

    There’s a lot of potential scenarios whereby CVE as we know it today just sticks around and keeps hummin’ along as it has. The government could come to its senses (lol), or it could find funding elsewhere. I don’t know how much it costs to run that whole operation, but it can’t be much compared to the revenue some of these companies that rely on it bring in.

    Some have started to argue that the loss of CVE could actually help the industry, and that the CVE model had run its natural course. Maybe they’re right?

    Even if CVE as we know it today keeps on keepin’ on, this should be a wakeup call for the world, and for IT and IT-security programs. What would it mean to have CVE vanish overnight? As it seemingly almost did. Would this mean the death of Vulnerability Management entirely? I don’t think so. Would it mean that vulnerability scanners would be completely dead in the water? Not exactly. Would we have any actionable vulnerability intelligence data without CVE? I believe so. Would this cripple the infosec industry? Nah. It’d be a gut punch for sure, but there’s some resiliency in play. Let me talk a bit about how VM programs and the larger scanning industry would need to adapt…

    The CVE program has done a lot to get us where we are, but I believe a lot of this infrastructure stays in-place regardless of what happens to cve.org itself. Vulnerability researchers are not staffed out of cve.org. So research can continue on as it always has. The vendors to which these researchers disclose vulnerabilities to also are unaffected. So vendors can continue to receive vuln disclosures and publish vulnerability data via their disclosure portals as they have been doing. The difference now is that there is no centralized repo by which all of these disparate vulnerability repos will be ingested. We can adapt to that it seems right? Scan vendors can go directly to these companies sites and pull vuln data in, and VM teams across the world can do the same. Not to trivialize the work it would take to fetch data in a decentralized manner, and then normalize all that data—but it’s all there!

    We as an industry may want to evaluate how hard-coded CVE data is into our regular operations, but I think we’d be fine without it in the worst case scenario. Hell, lessening our reliance on CVE could actually help improve security in some ways if it meant doing less “baseline” security and more critical thinking 🤔.

    Alternative Funding

    In light of the precacious funding situation of the CVE program, here’s some ideas on how else it could be funded…

    • The CVE Foundation was just launched to “Secure the Future of the CVE Program”. It was founded by a coalition of CVE Board members. More to come from them…
    • Given how many vulnerabilities are present in Adobe, Oracle and Microsoft products, maybe they should help support CVE! 😅
    • So much of the infosec vendor industry is reliant on CVE. It seems like they could put their heads (and wallets) together to help sustain CVE. Looking at you Tenable, Qualys, Rapid7, et al. 👀
    • Other governments have already started to step up to fill the gap. Check out ENISA.

    Vulnerabilty Catalogs

    I’ve long maintained a comprehensive list of Vulnerability Catalogs. Not all of these are one-for-one replacements for CVE.org, but it goes to show that vulnerability intelligence would still exist and other vulnerability databases are there to pick up the slack.

    Other Questions

    Some other related questions pertaining to this whole CVE potentially going-away debacle…

    • The suddenness of this whole situation is quite alarming. Given the importance of CVE, how was it that alarm bells only started going off literally the day before the entire site would have been shut down? I know things are crazy and volatiile in the government funding world right now, but yikes.

    • The extended funding is from CISA. The same CISA that has been under threat by the current administration. What’s to stop this same admin from pulling CISA funding or otherwise undercutting this latest effort to keep CVE on life support?

    Memes

    The hottest CVE meltdown memes, collected and made available here for you.

    News

    Journalist and news organization publications:

    Resources

    Other resources, posts, discussion and info related to this whole mess.

    1. No lapse in critical CVE services  ↩2

    Reply source
  • Scroll trīgintā duo

    Welcome to volume thirty-two of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity realms. This week we take a look at what it means to be part of the IndieWeb community, we advocate for the Fediverse, and we take a look at things more and less secure across the Internet.

    Now step in and scroll this hall of links…

    IndieWeb

    The Internet is deaddestroyed. Not really, but sadly it isn’t the same web some of us remember. It’s a lot more tiring these days isn’t it? There’s a much larger percentage of content on the web that’s absolutely not worth your time. But it’s not too late to help turn things around. You can still contribute that small amount of humanity to the larger, rapidly degenerating web. It really doesn’t cost much or take much effort either!

    Tucked away in the vastness of the cold, inhuman web, is a cozy corner we call the IndieWeb—filled with fun, loveable li’l websites made by a community of actual humans. Finding your neighbors on the IndieWeb isn’t always easy though. To help with this endeavour, there’s web directories, web rings, community-curated feeds, blogrolls and slash pages (e.g. /self-hosted). So get out there, join the community, and find cool stuff!

    Small Web Finds and Features

    Here’s a few cool things I’ve seen around the web of late…

    Fediverse

    The Fediverse is great! If you’ve not already joined in some way—you should. Why? There’s a lot of reasonsshared ownership, anti-attention media, and human curation over algorithms to name a few.. But advocating for the Fediverse is not always as simple it seems. It’s not just about denigrating the so-called competition. Instead, try to understand what prospective joiners are interested in getting out of a social network or what problems they’ve had with other platforms and explain how Fedi specifically solves (or doesn’t solve) for those needs.

    PSA: Higher prices aside, you may want to be wary of Hetzner.

    Cybersecurity

    5️⃣ Five cool cyber-things for this week’s issue…

    Thanks for reading Scrolls! Hope you enjoyed your stay in this cozy corner of the web.

    Reply source
  • Lessons Learned from 20 Years & Why You Should Blog

    So many great nuggets of advice here—on minimizing writing friction, owning your (domain) name, building a site rather than just a blog, ignoring analytics, writing referential content that can live beyond the week it was written, being authentic, writing with a focus on quality (over quantity), using copious links to things you’ve written in the past—it’s all here. If you have been thinking of creating a website (and you f***ing should!) or even if you already have one, go read this now.
    Reply source
  • Useful Pokémon

    Inspired by this post on Threads, I thought about which Pokémon would be the most useful to me in real life. Here’s what I came up with (in index order)…

    • Jigglypuff is a fluffy li’l guy who can help put my kids to sleep when it’s time. 😆
    • Diglett would be a great helper for my gardening tasks—tilling soil, digging, etc…
    • Meowth can literally produce coins/money, can talk, is playful, and hunts around at night finding treasures to bring back to me. All wins there.
    • Poliwrath seems like a good bro to have around. Strong swimmer and can be a useful, amphibious body guard.
    • Machoke’s are chill and can help with stuff around the house.
    • Chansey’s got eggs that are nutritious and delicious.
    • Lapras is a gentle chap that can ferry me around.
    • Meganium can legit bring dead plants back to life—need that given my not-so-green thumb.
    • Miltank can produce tasty, nutritious and healing milk. I’m sure it’s protein packed too.
    • Blissey brings good luck and healing powers. Gotta have one in your corner.
    • Gardevoir is a zealous protector and could also lift stuff with its mind which could be useful around the house.
    • Latias seems like a good option for flying and is gentle and can understand humans.
    • Rayquaza could be useful from time to time on bad weather days—though it seems a bit intense to have around…

    NOTE: I’m only really familiar with Pokémon up through Gen III so this list doesn’t consider anything beyond that.

    Reply source
  • Captain's Log, Entry: February 26, 2026

    It’s been a busy month on the blog! So what’s goin’ on… I’ve added a bunch of new pages to the site, and have been publishing a variety of notes and posts. I’ve mused on how to get myself academically/professionally motivated once more and also appended a new thoughtstream section to the bottom of this here journal—a place for me to do mini-writeups/commentary on things that I don’t want in an isolated note/post/etc… Le’s go!

    Site News
    • I’ve made some big tweaks to my blogroll. It now features a lot more blogs/sites I really enjoy. I’ve added a .opml but not sure the best way to keep it reliably up to date as I add more sites to the list. I am also considering adding some descriptions for each entry.
    • I recently went through my archive of Scrolls, clicking through each link to find long-lost interesting blogs to add to my blogroll. In doing so, I discovered that there were a lot of dead links sprinkled throughout. There were fedi posts that had disappeared, blogs that had moved, and who knows what else. Just the nature of the web I guess!
    • My experimental GtS fedi instance is dead. Long live malici.ous.computer! Like a dumb-dumb I didn’t grab my archive in time before K&T Host went dark, so here I am. Not sure if I will attempt to revive it elsewhere. Time will tell. Until then, I’ve removed the redirect on @afterdark@shellsharks.social and will be using that account once more. 🌙
    • Inspired by Marijke, I now have a mentions page which lists all of the instances (atleast that I’ve found) of people mentioning me or my site on their own blog! I think I’ll limit this to just mentions on blogs, and not those on social media.
    • I’ve published a bunch of new slash pages/ai, /blank, /hello, /nope, /self-hosted, /top4 and /verify.
    • I got the idea from Burgeon Lab to publish an Indieweb.org profile page.
    • Reorganized my hamburger menu items. 🍔
    • I’ve (finally) made some significant styling tweaks to the site. I’ve moved from colored links to underlined links for both the light and dark themes (keeping the ‘classic’ theme the same for the most part). Hopefully this improves legibility/accessibility and gives it a slightly more pro look.
    • Upon request, I’ve made visited links in Scrolls have specialized styling. So folks can keep track of what links they’ve already visited. I’ve kept it to just Scrolls for now to reduce visual clutter elsewhere on the site.
    • I’ve changed up my welcome message at the top of the home page. For posterity, it now says…

    Greetings web traveler! My name is Mike. I am a security researcher and Internet homesteader (among many other things). Welcome to my digital garden — a florilegium of personal works across all things infosec, technology and life. This site also serves as the canonical identity (a veritable root system) for myself on the web. There’s a lot to discover here, so sit a spell, take some time to really dig around and explore. Wanna contact me? Don’t be shy now either! C’mon and say hi anytime.

    TV
    • Finished the Stranger Things binge. I had heard a sprinkling of folks saying they didn’t like how it ended, but I thought the final season was great and the ending was a perfect way to wrap things up.
    • Knight of the Seven Kingdoms has been thoroughly enjoyable. Didn’t see the Egg thing coming…
    • The Lakers need to stay healthy, but otherwise have been pretty exciting to watch. Being a DC-area native, the Wizards have really never been exciting to watch. Even in the Wall/Beal days they weren’t that compelling. But with the way the East looks + them adding AD & Trae Young, who knows… maybe I could get into watching Wizards ball too?
    • I’ve been rewatching a bunch of the X-Men movies on Disney+. Just for fun. They’re all OK.
    • I’ve also started watching Paradise (season 2) and Task.
    Self-Hosting

    I have a lot of things I want to self-host. Right now my Masto instance is run by MastoHost and that’s fine, but I want to get malici.ous.computer (my GtS instance) back up and running, I need a new bookmarks manager (since Pocket died), I want to self-host my RSS (and get off Feedly), and I’d like to put some Discord replacement up (who knows, something like Discourse or maybe even Matrix). There’s probably other stuff I want to self-host too. I’m taking a look at Hetzner and Yunohost. I’ve started documening this journey, and will add things to my /self-hosted slash page as they materialize.

    Career

    From ~2016-2022 I was incredibly prolific with respect to learning, doing infosec trainings and getting certifications. In the time since, that’s really fallen off a cliff. I haven’t gotten a cert in forever (for whatever that’s worth), I’ve tried and failed to get much traction on doing any kind of training (just go peruse my journal for all the times I’ve mentioned working on OSWE, eg. 8/21, 12/21, 4/22, 6/22, 12/22, 1/23, 2/23, 1/25), and I can’t say I’ve really added anything particularly significant to my knowledge base in that span either. Sure, I’ve been busy with kids, and the house, and w/e else, but I have to call it like it is—I’ve been stuck.

    So how do I get momentum again? I don’t know what will actually work. I don’t know if writing this up and publishing it here will serve as any spark. But I’m going to do a bit of ideation/brainstorming on how I can kickstart my learning and advancement right here (in no particular order).

    • I have a pro subscription to PentesterLab. This platform came highly recommended from some coworkers and has a lot of practical exercises targeting real-world CVEs and other commonly found web vulnerabilities. I just need to make time to work through the challenges and write up the solutions (responsibly of course).
    • I’ve been toying with the idea of producing a ~weekly “what-have-I-learned/read” stream or post that would contain links and mini-writeups related to all the things I learned and did in that period. Maybe said stream could live in this here journal, or maybe I’ll create a new content type, or perhaps it can go in Scrollstbd! (Maybe I could do something with the /TIL slash page idea?)
    • I’ve said it before, and now I’m saying it again—maybe I’ll try for one of those OffSec certs 😅. I’m particularly interested in OSWE (sound familiar?) or the upcoming OSAI training.
    • Learning topics of emphasis for me this year (vague but w/e) include AI (securing/pwning these systems to be clear), Cloud, Cryptography, Code Review and Web App Pentesting.
    • Generally I’d like to do more reading! I save a lot of articles, and have a lot of books on my shelf. I’d like to read more of this stuff and write about it where possible.
    • Finally, I need to do more writing about what I’m doing at work. This can help juice the work, cement knowledge in my mind and put more lovely content on the site!
    Life
    • Trying to make time for and build a long streak of going to the gym is always tough. But I do feel like I’m making slow and steady progress. Biggest issue right now is this nagging right shoulder soreness.
    • I’ll be heading to San Francisco in March! Always good to make my way out there and make my usual pilgrimage to Mama’s.
    • I’ve been thinking about trying to get out of my house to work a little more often. That change of scenery seems like it would help my focus.
    • I’m thinking this snowcrete will be here until May. Insane.
    • I took some time away from this site but now that I’m back I really want to put more effort into journaling. I went back and read through the archive of captains logs and really enjoyed time traveling through things I was thinking about and doing in months and years past.
    • I’ve started planning out my garden for 2026.
    Thoughtstream

    Just a stream of random thoughts…

    Resonant Computing

    I recently came across this “Resonant Computing Manifesto”, cosigned by famed Bluesky apologist and Techdirt founder Mike Masnick. Before I talk about “Resonant Computing” in isolation, let me start with Mike’s take on how ATproto enables Resonant Computing. In this piece, he waxes poetic about how ATproto (and thus Bluesky) fulfills/enables the 5 core principles of Resonant Computing. He also goes on in the comments of the post claiming that ActivityPub/the Fediverse enable at best, only the Plural tenant of Resonant Computing.

    …but I don’t think ActivityPub meets the criteria I’m talking about in the post. The only thing AP currently does is allow you to move and keep your social graph. The other features I discuss aren’t really possible with AP right now. That may change, and I hope it does. But, like already with ActivityPub I have an account on Mastodon, but I couldn’t use that same account or data from it on Lemmy. I had to create a separate account.

    Yeah ok, Mike

    I’ll go principle by principle here and be quite frank about how this don’t smell right…

    1. Private: ATproto is very famously not private in terms of what is visible to everyone. Mike explains however that he was against this specific term being used as the Resonant Computing Manifesto’s understanding of “Private” means that users own their data and determine how it is used. Well yes we know theoretically ATproto’s PDS concept enables this level of data ownership, and that’s great! So I’ll give ATproto a point here, but have to agree with Mike that it’s not the right word from the manifesto itself.

    2. Dedicated: “…You have to trust that there are no hidden agendas or conflicting interests.” omg really? With ATproto? The protocol behind Bluesky? The same organization with Muskian roots? The one that took VC cash from some blockchain firm? The same one that allows open Fascists to run rampant? Yeah sure… lots of trust there.

    3. Plural: No single entity should control digital spaces. Bluesky is pretty monolithic. Maybe the tide has started to turn a bit, and I know we’re trying to logically separate ATproto and Bluesky. But until there’s any significant amount of users off the main Bsky node, I don’t think ATproto can claim any success here.

    4. Adaptable: Software should be open ended. Well I think they’re just trying to claim that ATproto is open source. OK. Cool? So is like, all of the Fediverse pretty much…

    5. Prosocial: Technology should help us become better neighbors, collaborators, and stewards of shared spaces. Well in Blueskys’ case, they certainly are collaborators (derogatory) aren’t they?

    But don’t take it from me, I’m not the only one who this Resonsant Computing doesn’t make much sense.

    18 lessons from 18 years of blogging

    Some commentary on Ben’s 18 lessons from 18 years of blogging. I thought this was a great article and most of the points I think are really spot on. There were a few though that I disagreed with…

    2. Write about what you’re passionate about: Yes of course. But y’know, why limit yourself? I think you should just write about everything. I mean, start with your passions, but I think it’s fun, and a good way to expose yourself to other things, to write about other things, not just your “passions”.

    6. Hand writing drafts on paper can help the creative process: I’ve never done this, so maybe I shouldn’t comment on it. Don’t knock it ‘til you’ve tried it, and all that. But physically hand writing a lot of text is pretty exhausting in my opinion.

    11. Resist the urge to go back and edit old posts: This is the one I feel the strongest about. This is bad advice (in my humble opinion). This is your site. Your voice. Your site is a place for you. If you want to edit a post to be more accurate, or to add more context, or because you’ve learned something new, or changed your mind. You absolutely should. It’s your site, do what you want with it.

    Reply source
  • BQC: Ten Pointless Facts About Me

    Here’s a blogging challenge kicked off by Forking Mad. Here’s 10 “pointless” questions, and their answers, from me!

    Do you floss your teeth?

    Yes. Though not as routinely as I used to. You see, some time ago I had my top-back-molars on both sides of my mouth pulled. They had long bothered me—I couldn’t eat much of anything without food getting stuck inbetween those teeth and the set in front of them. This would cause serious discomfort which I could alleviate by flossing said food out. This meant I flossed at least once, but likely multiple times each day. Since having those teeth pulled, food does not get stuck in my teeth in the same way, so my flossing habit has suffered a bit. I still floss most days though.

    Tea, coffee, or water?

    These days, coffee for sure. In fact, I’ve recently gotten into making my own cold brew. It’s delicious! I’ll normally have some coffee at least once, but usually twice a day (a cup in the morning and another sometime in the afternoon). My coffee habit only started during the pandemic though (oddly enough). Before that, I was a sweet tea person all the way. I can thank my southern roots for that I suppose. But unfortunately, all the sweet tea I was drinking back in those days started to cause me some health issues so I had to change course a bit. Coffee is magical though, so not a bad replacement ☕️ 😁.

    I do drink a lot of water though, especially on days where I am at the gym (which is most days!)

    Footwear preference?

    I tried looking for the exact shoe, but perhaps they are no longer available? Anyways, my prefered shoe are these Salomon hiking shoes/boots (in black) that are kinda a hybrid “regular” hiking boot and sneaker. They are super comfortable, extremely versatile, waterproof, last forever and I like the way they look. I wear ‘em everywhere!

    Favourite dessert?

    This kinda depends on the situation—or my mood. Traditionally, my favorite dessert has been cheesecake. But I also love blueberry cobbler and rum cake. I have a rum cake every year for my birthday in fact 🎂.

    I also really love tiramisu 🤤

    The first thing you do when you wake up?

    I usually roll over and go back to sleep for a few more minutes 😴. Then, probably pick up my phone and check some combination of Apple News, Fedi, Email and other notifications that came in over-night.

    Age you’d like to stick at?

    Well for all the usual reasons it’d be nice to have some of the qualities that came with youth (~mid-20’s)—back when I didn’t get sleepy after one beer, had no knee pain and could recover from anything in ~48 hours. But aside from that, aging hasn’t been so bad for me. It’s brought me new and exciting professional challenges, I’m a father to two cute little nuggets, I’m in the best physical shape I’ve ever been in… I dunno, things aren’t so bad at this age…

    How many hats do you own?

    Own? 6-10 maybe. How many do I actually wear? Well I’m not much of a hat guy, but I do have a sun hat-kinda thing I’ll bust out when doing yard work sometimes 🤷‍♂️. All my other hats are ones I’ve picked up at security conferences 😂.

    Describe the last photo you took?

    The last thing in my photos app is actually a video. It’s the cutest thing really. Whenever my daughter (she’s 1) wants a snack, she grabs it from the pantry and then excitedly runs over and brings it to me. After she hands it to over, she’ll do this rapid fire series of li’l baby jumps. The cute hoppy anticipation is just the best 🥰.

    Worst TV show?

    Big Bang Theory. Just awful. I won’t be taking questions.

    As a child, what was your aspiration for adulthood?

    From what I remember, I had a few “what do I want to be when I grow up” phases. (In no particular order)…

    • Astronaut
    • Archaeologist
    • Paleontologist
    • Doctor

    I’m pretty sure all of these came after watching some relevant TV show or movie 😅.

    Reply source
  • John Oliver Dares Buc-ee’s To Sue Him Over Trademark Infringement

    I will admit it’s always a special kind of fun when a topic we cover here at Techdirt gets the John Oliver treatment. He and his writing team generally gets things right, which helps. And I’m not saying that Oliver and his crew are definitely Techdirt readers, but, well, hi John and crew! Readers here […]
    Reply source
  • Trump FCC Hilariously Bungles Chinese ‘Drone Ban’

    Earlier this week we noted how the Trump administration’s unpopular ban on Chinese drones had become a crony capitalist mess, with Brendan Carr and his FCC struggling to fine or ban companies for violations. The ban is a stupid, protectionist mess that has far more to do with coddling the president’s sons’ drone investments than […]
    Reply source
  • What 20 Million Bans Reveal About The Stress On Wikipedia’s Volunteers

    This article is republished from The Conversation under a Creative Commons license. Read the original article. This year, Wikipedia is celebrating 25 years as the Internet’s encyclopedia that anyone can edit. In its first decade, the quirky experiment for passionate nerds exploded in popularity. It became a ubiquitous information resource and a homework helper for schoolkids, much to the dismay of skeptical […]
    Reply source
  • People and Blogs: Melanie Richards

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Melanie Richards. Do go visit their blo...
    Reply source
  • People and Blogs: David Cain

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with David Cain. Do go visit their blog and ...
    Reply source
  • People and Blogs: Stefano Verna

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Stefano Verna. Do go visit their blog a...
    Reply source
  • People and Blogs: Eetu

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Eetu. Do go visit his blog and say hell...
    Reply source
  • People and Blogs: Dominik Schwind

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Dominik Schwind. Do go visit their blog...
    Reply source
  • People and Blogs: Patrick Rhone

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Patrick Rhone. Do go visit their blog a...
    Reply source
  • People and Blogs: Eric Schwarz

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Eric Schwarz. Do go visit their blog an...
    Reply source
  • People and Blogs: Nikhil Anand

    People and Blogs is a series by Manuel Moreale featuring the people behind personal blogs and the stories of their corners of the web. This conversation is with Nikhil Anand. Do go visit their blog an...
    Reply source
  • A Hidden 'Dark Dimension' Could Rewrite Our Understanding of the Universe

    The nature of dark matter and dark energy are among the biggest mysteries in science. Scientists think an extra “dark dimension” could explain both, and they are putting the idea to the test.
    Reply source
Older posts