RSSAmplifier

Blog

Making Software on Tales about Software Engineering

Recent content in Making Software on Tales about Software Engineering

beny23.github.ioRSS feed ↗105 posts

Latest posts

Agile on the Beach 2026: Field of princes

This is a post about my travel to Cornwall for Agile on the Beach, a fantastic conference. So why do I talk about fields of princes? You’re going to have to bear with me. But this will involve big questions about why we are here, what life is all about, an awe-inspiring keynote by a mad Viking witch from the Dutch railways and some Austrian folk music. And no, it probably won’t get any less weird.

Weakly Link 26/21: Control Failures

Apologies for the tardiness, when I started this set of posts, I squarely aimed to do this once a week. Of course, I never fully committed to that, it was more of a weakly held belief that I would hold out. So, unfortunately dead reader, I’ve failed. I didn’t have enough control over my schedule and before I know it some weeks have passed. Let’s fix that. In this edition…

Weakly Link 26/19: Local Escalations

It’s been a busy few weeks in security. You wait for ages for a local privilege escalation vulnerability and then two come along at the same time. We find out that just because it’s rust, doesn’t mean it’s secure. GitHub security was bypassed and Gemini scored a perfect 10. Let’s dive in. Copy Fail Copy Fail is probably something that if you’ve been remotely…

Weakly Link 26/17: AI stutters

This week we’re linking together links that give a bit of a picture of some stuttering in the AI world. We’ve got Firefox overhyping Mythos. We’ve got indications that GenAI vendors think they need to show some way of putting the right numbers on the balance sheet and look at simpler times. Both in the past and in the future. Let’s dive (no not delve) in. Days not numbered…

Weakly Link 26/16 - Quantum Mythos Special

A slightly delayed episode of the weakly link. This time, we have a bit of a special outlook on the future in security to do with Quantum and AI. There were a couple of links that really caught my eye and could make a compelling case for usage of the phrase “everchanging landscape…” - stop it Gerald - this is not AI generated! Let’s start with the big announcement:…

Weakly Link 26/14

This week we have a look at the current chaos. Be it political or technical, we’re going through some radical changes. And I can’t help but think, if this is what progress looks like, oh crap. Supply Chain Chaos We start by having a look at an article by Ian about the Mad Emperor. No prizes for guess who is meant there. From the outside in, it really looks like there’s no plan or…

Weakly Link 26/12

This week it gets all too depressing. We start by the fact that AI didn’t in fact change everything but just made it more important to do the right thing. How politicians may not have the right kind of understanding to make decisions that actually make sense. How one (orange) politician doesn’t understand how the world actually works and how we can all laugh and point at McKinsey for…

Weakly Link 26/11

This week we’re looking at zero days, zero reason for wearing Meta Glasses, zero reason to like AI slop. Let’s dive in. Look What You Made Us Patch The Google Threat Intelligence Zero-Day review came out at the beginning of March and I thought it was interesting for a good few reasons: The number of zero days actively exploited looks to be fairly steady over the last few years Security…

Weakly Link 26/09

This week we’re looking at how some of the traditional thinking on security (detect it, patch it, monitor it) is no longer quite cutting it. It is interesting how cyber threats have very much moved on from malware. In my opinion, the latest CrowdStrike threat report can be used to argue that security is not something that can be fixed by buying a shiny security tool. It’s not a…

Weakly Link 26/08

This weak we’re looking at supply chains. We look at how AI is both a blessing and a curse for open source, how there’s a new sandworm attacking the npm ecosystem, how de-Americanisation of cloud is not easy and we also learn about an exciting new Agile certification. Sarcasm may be involved. Semantic Ablation But let’s start with something that puts a name to that feeling you…

Weakly Link 26/07

This week we’re looking at the impact of drugs on viruses, drugs on AI models, drug-addled bot behaviour and how the mainstream is catching up with AI Agent concerns. Oh, and some badly-drawn horses. Drugs The first bit of news comes from over the pond, where it looks like the Trumpian regime is looking to piss away vaccine advances. Flu vaccines are saving millions of lives, and an…

Weakly Link 26/06

This week, we’re having a bit of a wild west theme to the GenAI related links. There’s continuing hype around OpenClaw - though it looks more like a hangover than a party. We’ve also got some interesting use cases for GenAI that are directly not related to coding and we’ll end up with a cryptic warning from a siren. The Good I’d like to start off with a couple of…

Weakly Link 26/05

This was the week when the autonomous AI bots went a bit crazy and decided to burn tokens on social media. Moltbook is so hot it leaves behind molten agents. Well, no, stop there Gerald, people will start thinking you are using an LLM to do your writing. Of course, there’s a decent sprinkling of security issues where once again the usual suspects prove that security vendors are bad at…

Weakly Link 26/04

It’s been a busy week, hasn’t it. Fascism is on the rise and AI too. But it’s not all bad news… (touches earpiece) I’m receiving new information. Aaaanyway. This week we’re looking at mad and bad. We’re looking at how magic strings and parameter injection can be bad, how mad AI coding is and how bad people make me mad. Telnet? In 2026? First of all,…

Weakly Link 26/03

This week’s installment of my LinkBlog covers old tech that is new, operational tech that is secure, observability that is not expensive and a series of vulnerabilities for us to snigger at, then take a breath and take seriously. Mainframes are not dead I have often said that learning COBOL is on my bucket list and that my advice for young people in the software engineering sector is that…

Weakly Link 26/02

My post is a little late this week as I went away with the scouts. Everyone else was in the bunkhouse, I was in a tent. Something about ratios. And I brought the summer sleeping bag. Freezing. Alone. Kind of like America must feel like. What does America have to do with tents, I hear you ask? Well, now that the US has abandoned an inclusive big tent approach and focuses more on pissing on everyone…

Weakly Link 26/01

Like any blog post at New Year’s, we’ll be looking to the future. We’ll also check our assumptions and we’ve got some security content before looking at a website to destroy all websites. I did like this piece on The Register which looks at four potentially game changing technologies without mentioning AI. The oxygen of publicity this year has mostly been consumed by our…

Weakly Link 25/52

To those who celebrate the festivals either end of the last 7 days of the year: Happy <insert here>! This time round, there&rsquo;s not one, but two bleeding fails in security, some interesting protections, how slowing down is not only speeding up, but also making things more enjoyable. So without further ado, and much less waffle, let&rsquo;s jump right in: GPG fail Our first fail is from the…

Weakly Link 25/51

This week we&rsquo;re looking through a mix of security and AI once more. Because tech is nothing but those two topics, right? Right? Anyway, I am often travelling on the train or stay in hotels these days, I find myself working on public wifis. Of course, one look on LinkedIn will immediately warn you of the dangers of public wifi. Seemingly, as soon as you connect a hacker will automatically…

Weakly Link 25/50

Let&rsquo;s start this week with many happy returns for Let&rsquo;s Encrypt! It&rsquo;s been 10 years since free TLS certificates made it much more common that things go via HTTPS rather than HTTP. When anyone and everyone was able get a cert, it certainly reduced the barriers to adoption. These days it is almost unimaginable to have some web traffic that doesn&rsquo;t use TLS. Now, if only we…

Weakly Link 25/49

This week, we&rsquo;re talking about React4shell. The latest in the 4shell family of vulnerabilities. What does 4shell mean? Usually that it&rsquo;s possible to do RCE (Remote Code Execution) based on an application vulnerability and typically, attackers will leverage that to get a remote shell. And now, for something completely different My first link is not related to react4shell, but it&rsquo;s…

Weakly Link 25/48

This week is an odd mixture about sandworms, supply chains and basically how everything is broken anyway. And then (after all the naughtiness) let&rsquo;s end on something nice. Thumped by a Sandworm Sha1 Hulud came back for another go at supply chain attacks. Patient zero of this wave appears to have been Posthog - an analytics platform a bit like Mixpanel. According to their postmortem, their…

Weakly Link 25/47

This week there have been some interesting bugs. Or interest in bugs. Bugs It was Cloudflare&rsquo;s turn to break the internet. As per usual, the transparency on display is rather cool. It was rather interesting that for once, the problem wasn&rsquo;t DNS or BGP, neither was it a cyberattack. Though indirectly, the threat of bots was responsible. As a subtle change in the handling of queries…

Weakly Link 25/46

This week&rsquo;s edition of the weakly link has got some fire in it: First on the menu we&rsquo;ve got a report that tries to tell us that if there&rsquo;s an AI bubble, that&rsquo;s a good thing: The AI Wildfire Is Coming. It&rsquo;s Going to Be Very Painful and Incredibly Healthy Instead of a bubble, the post tells us of one dinner guest at a CEO dinner in Silicon Valley who argues that instead…

Vibe hacking a padding oracle

This post is a mixture of AppSec, vibe coding and cryptography. SPOILER ALERT: This post describes how to complete the Capture-The-Flag exercise &ldquo;Encrypted Pastebin&rdquo; (Hard) on Hacker101. Over the last few days I have had a lot of fun with a padding oracle. But let&rsquo;s take a step back: I have been looking at Hacker101 CTF exercises. The premise is simple: You&rsquo;re given a…

Weakly Link 25/45

Every week I come across some interesting, ridiculous or astounding content related to security and tech around software engineering. And I post it on the company Slack, sometimes on LinkedIn and often on BlueSky or Mastodon. (I deleted my Twitter account a long time ago. No Nazi bar for me.) And yet, I often forget all about the content. And because I closed my browser with 200ish open tabs once…

BSides Newcastle 2025: Mission to Cyberspace

BSides Newcastle is probably one the most anarchic of the BSides I&rsquo;ve been to so far. So much so that the fascists organised a protest. Well, not really, but there was a far-right and counter-protest not far from where the conference was. Thankfully, the organisers were on top of it and kept is all up-to-date with advice: &ldquo;Punch Nazis&rdquo; (for the benefit of the tape, nobody…

Make it so: GenAI, OpenAPI and ZAP

Have you ever wondered how hard it is to make an AI talk to an API? Wouldn&rsquo;t it be great if I could talk to a machine like Captain Picard does to his computer? &ldquo;Tea. Earl Grey. Hot!&rdquo; would have to sent to the replicator subsystem with the correct instructions. But how would that actually work? I suppose, the Starship Enterprise-D made its first appearance on the airwaves in 1987.…

Scan Agile 2025: People Power

I&rsquo;m on the plane returning from a Scan Agile conference that was just joyful. What made it that way? Was it the setting in the gorgeous looking Paastorni conference centre, was it the fact that the hotel was next door or was it because the speaker dinner the night before the conference set just about the right tone? Erm, of course that all helped, but I think it was the people.

From engineer to head of engineering

In January 2024, my comfortable tenure at Equal Experts came to an end and I went from 6 years of being a Java/Scala/AppSec consultant to being a head of engineering at a Middle Eastern fintech. This piece of writing explores what this means. I had been a tech lead before and certainly had plenty of experience of sitting at the table where decisions are made and have never had any qualms about…

How to make time to talk?

Have you ever struggled to find time for a workshop or a decent conversation? Because when you open your calendar it looks like this? Is it full of 1:1s Status Update Calls Readiness Calls Syncs Standups Project Updates Weekly meetings Biweekly meetings Sometimes it feels like &ldquo;am I even doing any work&rdquo;? I jest of course, because all these things are important. Without 1:1s we…

AI is the enshittification of recruitment

I. Want. To. Scream. Not so long ago, I reviewed about 1,000 CVs (resumes). 500 for a frontend developer position, about 500 for a backend developer position. You might think I was crazy, why don&rsquo;t I let an agency do the sifting for me? Well, that wasn&rsquo;t the thing that made me scream. I spearheaded an initiative to reduce the TCO by 10.35% Or some such drivel.…

Lean Agile Scotland: Sustainability

This post is all about sustainablity. And communication. And agile. Let me start from the beginning. I&rsquo;m sat on the train, coming back from Lean Agile Scotland 2024 and I&rsquo;m thinking about what I&rsquo;ve heard, seen and done. The conference was great, and allowed for catching up with old and new friends, finding kindred spirits and having good food. Yes, the older you get, the more…

SteelCon 2024: It was acceptable in the 80s

Sheffield is the city of steel, and at the heart of it lies a lovely university building - the Owen building that hosted the North&rsquo;s premier hacker con And I had been accepted to talk at SteelCon about AppSec and Agile and who wouldn&rsquo;t want to drive over Snake Pass to cross into the wrong side of the Pennines. [Ducks]. Over the past year, I found myself going to quite a few community…

Agile on the Beach 2024: Vulnerabilities are cool

After the fantastic experience of speaking at Agile on the Beach 2023 a year before, I was back for more agile. This meant more driving: again I took the motorway barge for the long road trip from the North West to almost the tip of the South West. For international readers, when I say North West, I mean England, somewhere near Preston, and the South West is in pretty Falmouth, Kernow (Cornwall).

DevOpsDays Amsterdam 2024

Once again, I&rsquo;m sat at Schipol Airport typing up my thoughts about a few days of refreshing Dutch DevOps Goodness! Ok, I admit one or five alcoholic beverages might have been involved too. This was my first DevOpsDays and it did not disappoint. My day started at 3am to catch a flight at 6am but because I was still awake at 1:30 and had decided sleep is for wimps, I arrived a little bit…

Recall: the Amazonification of Office Work

Following a quip on LinkedIn about the introduction of Recall in Copilot+ and Kevin Beaumont&rsquo;s great piece about why this is a really bad idea from a security point of view, I got thinking: This is dystopian techno-fascism Kevin posited a disconnect in Microsoft that led to the creation of this feature and whether people really wanted it. Personally, I&rsquo;ve got a brain like a sieve and…

Agile Manchester 2024: agile is fragile

Many conferences have a hallway track, I loved that Agile Manchester had a jigsaw track. The organisers put out a jigsaw on a big table where attendees could mingle over searching through the 2000 pieces and chat at the same time. Such a great way of breaking the ice. And such a brilliant metaphor. A complex task is achieved through self organisation. Teams self-select and offer assistance all…

XZ Backdoor: Not the End of Open Source

When I stumbled across a post that an encryption library offers a potential backdoor to SSH connectivity on Good Friday, my first thought was: why is it always on a Friday that these things drop? And then my second one: oh bugger, here goes my weekend. Now, I won&rsquo;t go into the technical details, there are many, many, many, many better resources out there, but I can&rsquo;t help thinking that…

Cyber Measures Up in Manchester

Peter Drucker said &ldquo;What gets measured, gets managed&rdquo;. When I turned up at Old Trafford, home of Manchester&rsquo;s red team (it&rsquo;s a security conference, geddit) for The Future of Cyber, I certainly was measurably impressed by the setting even though I&rsquo;m usually found more on the blue spectrum of infosec. But let&rsquo;s get into the talks! Measure, measure, measure First,…

Resisting compliance is futile

About two months ago I stumbled across a great YouTube video of a talk by Charity Majors called Compliance standards should be modern development practices. Now let&rsquo;s step back for a minute. Am I seriously suggesting that anything with the word &ldquo;compliance&rdquo; is going to be a riveting watch? Why, yes I am. And with good reason. I&rsquo;m a fan of good security and I like agile. And…

Victorification: Wiring the Winning Organisation Book Review

Last year was exciting, it was my first time going to a DevOps Enterprise Summit and meeting Gene Kim was very cool. The conference didn&rsquo;t actually start on Tuesday, there was a little session on Monday as people were trickling in from all over the world. And in said session, Gene presented his latest project. He was writing a book with Steven Spears called Wiring the Winning Organisation.…

AI-dvent of Code 2023: Day 4

After the glimmer of hope on day 3 I was quite optimistic for the day 4 puzzle. I kept going with the phind-codellama model. I continued with keeping the model on a fairly tight leash and just being very specific as to what I wanted it to do. What&rsquo;s the puzzle? So, for the first part, we had to parse a text file and then match up numbers and winning numbers.

AI-dvent of Code 2023: Day 3

My experimentation with LLMs on day 1 and day 2 of Advent of Code was a bit frustrating. For the day 3 puzzle, I decided to change model. Previously I had been using the codellama:13b model but wasn&rsquo;t really happy. I kept arguing with it and it just frustrated me. So let&rsquo;s try some others. codellama:34b So I thought maybe the model just wasn&rsquo;t big enough, so off we went

AI-dvent of Code 2023: Day 2

After day 1 of Advent of Code was only partially successful, I thought I would change my approach. Yesterday I tried to get the LLM to develop the whole solution in one go. But that was more like argumentative programming rather than conversational programming, so for the day 2 puzzle I start with small problems and hope to put it all together at the end. Let&rsquo;s get started The problem looked…

AI-dvent of Code 2023: Day 1

So it is that time of the year again. Advent of Code is back. Yey! This means I get to try to look at a new language again. This time, why not Kotlin? But as an extra challenge, I thought why not see how the vaunted LLMs would help. Is AI really the accelerator that would elevate a mere developer to a rockstar ninja (whatever that is)? I have to add that I am a bit of an AI sceptic and keep saying…

AppSec loves Agile

I describe myself as an Agile Fundamentalist because I really like the ideas of the Agile manifesto, and I also confidently state that I am an AppSec snooper, because in my day job I tend to look at other people&rsquo;s code, logs and systems and break them. I happen to think that agile and application security go together rather well! I had two different Slack conversations recently. One was on…

BSides Newcastle 2023: Chaos for the future

After BSides Lancs and Leeds, Newcastle was my third BSides, both of the year and ever. I got up early in the morning for a road trip from Preston to Newcastle, and setting off at 5:30 on Saturday turned out to be atmospheric and straightforward. So I was a bit early and got a glimpse of the chaos that is putting together a BSides. Later I found out that BSides Newcastle was traditionally more…

44CON 2023: It takes a Village

As I stare at my laptop after an intense few days at 44CON, I reflect on the experience. I went through a lot of different emotions. Excitement, trepidation, relief, bewilderment, pride, disappointment and hope had accompanied my visit to London to 44CON. We had an OSINT Capture The Flag competition happen right next to a round-table discussion on how the government should secure the country.…

Leave the badge at the door

I am wearing my Equal Experts hoodie. Often I&rsquo;ll be found on conference calls with my EE t-shirts, and I even have some socks. So the irony of writing an article about &ldquo;leaving the badge on the door&rdquo; is not lost on me. So what do I mean? Contracting Scum I am a contractor. I have been for the best part of 20 years. I&rsquo;ve worked in a variety of sectors (telecomms, finance,…