RSSAmplifier

Blog

re: nyman

blog.nyman.reRSS feed ↗25 posts

Latest posts

Blaugust-classifier

I like reading blogs and wanted to see if I can find a few new ones for my feeds from blaugust. There is the firehose but trying to read everything in there is a dead end. So I was thinking, is there is some (small) classifier nowadays that could categorise blog posts and allow me to subscribe to all blaugust posts about for example information security. So I asked GPT, who told me ModernBERT was…

Thoughts on better conference presentation formats

[disclaimer: this is a DRAFT post, anyone who read my last blaugust post will recognise this, they less edited and less coherent than the others, and in this case not even a full blog post, just the first part] If you have been at any conferences you have most likely encountered it. The talk, which is interesting but the speaker is a bit slow talking, and after 10 minutes it is really hard to not…

A few book recommendations

Its summer (still) which means book reading times for many. Here are a few books I remember from the top of my head (which means they must have been influential to me). No specific order. Title and something I remember from that book. Non-Fiction Factfullness - Hans Rosling Look at the biggest number first if you want to make an impact. The attention fix - Anders Hansen Our brains evolved for a…

Licenses suggestions for your vibe-projects

Rule number one when vibe coding is not to take yourself or your code too seriously. If you do, it’s not vibe coding; it’s software development, or vibe engineering. When it comes to licensing your slop code, we should first discuss whether it can even be licensed. But that is a complicated question, so let’s not worry about it. To embrace this uncertainty about licensing, or…

Searchtodon - some thoughts

I follow a lot of people on Mastodon and I see lots of toots fly by. Every now and then I want to find one I have seen at some point, but that is currently hard to do. This sounds like a problem more people might have yes? Yep, and to fix that Jan Lehnardt built Searchtodon. But there was a strong backlash. It might have been bad timing, as it was around the time of one of the mass migrations from…

Gell-Mann AI-mnesia

I try using an LLM to write something about information security, a subject I know very well. The result is generic and wrong in some places. I conclude that it is easier to throw it away and write it from scratch. Later the same day, I open one of the LLMs and ask it about some legal topic I’m wondering about. I read the answer and accept it as mostly correct. I might even make important…

Exercise your brain through practice lest it will decay

Human disclaimer - This post is written 100% by a human and there is zero LLM (ChatGPT, Claude etc, what they like to market as Artificial “Intelligence” but I disagree with that framing and will continue to refer to them as LLMs) contend or editing in it. It might contain bad grammar and spelling errors. This is not a statement against LLMs, which I believe can be useful, just a…

Reliably detect shai-hulud and similar worms

Supply chain attacks are all the rage nowadays, but detecting that you’ve had your credentials swiped by one is a lot of work because they are stealthy. They might have run once in your CI or a on a developer’s laptop, and you won’t know until you’re suddenly the one who is unwittingly pushing the next version of shai-hulud on all the open source repositories you maintain.…

passbolt - reviewing password managers for organisations

Testing Passbolt This is the first article in a longer series on testing password managers for organisations. I’m looking for a new password manager for a smaller team. While I will start focusing on open source and EU based alternatives neither are strong requirements. Conclusions While it looked promising from the start, backend by a well funded company that has been around for 10+ years I…

Magic links are not great but they are the right choice sometimes

LLM disclaimer: this post was written based on a discussion with claude and drafted by claude. I have edited it heavily but if you’re allergic to LLM’s feel free to skip it. The setup: we’re have a policy compliance system that employees use roughly once per year to check boxes confirming they’ve read our updated policies. The right solution is to integrate this with our…

Thank you for blaugust

This is the real end-of-blaugust post. I really enjoyed taking part, even if my partaking was very isolated. Now towards the end, I decided to check blog of this years blaugust host and… why the heck did I not do that earlier. Instead of trying to force out some micro blogs, I could taken inspiration from the massive amount of material available there. As none of my posts are ready to be…

Blaugust near the end thoughts

Second to last day This was going to be the launch of the new version of hasmypasswordbeenstolen.net, but my high standard got to me. It will be out soon-ish but not yet. As for blaugust, it has been great. Although one blog per day is clearly too much for me. It has still been a great encouragement to get a few old ones out, and some new ones also. I will try to keep up the posting, but without a…

More mailinator thoughts

Continuing the trend of praising mailinator, turns out one of the reasons feature creep did not get to it, was that it was or maybe is still “just” a side project, this interview with the creator has a bunch of interesting details. The interview is a few years old by now, but still interesting. nathanlatkathetop.libsyn.com/703-the-a… Also this presentation from a few years later…

Setting up your own mailinator domain

Mailinator is one of those great forever services which I seriously hope will never disappear, it has saved me from so much “newsletters” and other things I don’t want in my mailbox. Sadly it for some reason people think it’s a good idea to block it sometimes. Which makes absolutely no sense to me. I mean, I am clearly indicating that I do not want email from you. If you…

Reviewing the charities annual reports

This is a follow up to [this]( blog.nyman.re/2025/08/2… and this . So we’re continuing the quest to figure if it’s realistic for a normal person in the tech industry to do a life-saving donation. Let’s look closer at the charities listed last time by reading their yearly reports. Medeor’s report for 2024 Overall a very good report. Very transparent. From this we can…

Dishonest game developers

Note This is a very old blog draft, all the way from 2019 when you could still download Fortnite on your iPad (which you can again but it’s a bit harder and you need to live in EU). But the point still stands I need to publish something. Enjoy, or not :-) I recently tried Fortnite for the first time, thinking I would check out what the fuzz was about. So I install it on the iPad and get…

box-art.css

Today we’re onto something lighter again. A box-art/nfo-style css, in as part of experimenting with a new look for this blog. This is harder than it looks to do in CSS, but I enjoyed the challenge. This is also something the LLM’s failed quite hard, but at least claude wrote me a simple javascript page where I could tweak the parameters until it worked. Also.. I just found this,…

Finding a charity where you can see the impact

This is a follow up to the previous one where we defined the question. Read that first Can I make a direct life saving impact to someone, where my action, with a high degree of probability, leads to the survival of someone who might otherwise not have survived. If the action is a donation, and the answer is Yes, and I have the means. Then I want to do it. But let’s clarify what this means in…

What can YOU do?

The world is a big place. Really big. There are a lot of people in it . And because there are so many people, it means there are a lot of people who, at this moment needs help. So what can you do? A lot. That’s a too wide question. Let’s narrow it down to a very specific question. Can you save the life of someone in need? Again, yes, there are lots of ways you could, but also a lot of…

(untitled)

vibecoding feels very productive, but often I’ve noticed it’s just a feeling, I actually know better than the LLM what the problem is, and could fix it faster, but for some reason I get stuck prompting it again and again not sure why Hopefully the psychology departments are looking at this

My favourite podcasts

Security Podcasts I Enjoy In special order, roughly in the order of which I remembered them which says something about how much I listen to them. Risky Business - the main feed, compact and respects my time. I haven’t missed in on a long time. They have expanded and have other great podcasts now, including a news bulletin. I listen to those sometimes. Three Buddy Problem - Quite new podcast,…

A simple devcontainer for your agent with eyes (browser and screenshot capabilities)

These instructions have been tested on a M1 MacBook with podman, your mileage may vary. Note that running playwright/chrome as root might be dangerous so don’t use this for scraping or untrusted content unless you know what you’re doing. Actually, never feed untrusted content into your LLM and always sandbox it as much as possible. Otherwise you will sooner or later be a sad panda.…

You cannot hide on the internet

At least not on the IPv4 network, but I would not trust the IPv6 network either, and you have not been able to for a long time. If you open a port to the whole world, it will get probed. If it’s a popular port like 443 or a sensitive one like 9200, it will get scanned really-fast. Same goes if you announce it by creating a TLS certificate with a ACME service like Let’s Encrypt. When…

LUKS on NVMe: From 40 GiB/s to 4, Then Back to 20 GiB/s

Note: This testing described in this post was done over a year ago. It might be that things changed since then. At work, we recently upgraded our PostgreSQL servers. This time, however, we encountered an unexpected roadblock when attempting to enable full disk encryption (FDE) with LUKS - our standard deployment. In past benchmarks, enabling LUKS full-disk encryption cost us ~10%. This time, it…

Internet is big but we humans are not ready for it

I thought it was crazy to think about all the 8.2 billion people. A even crazier thought is how many internet users there are, who in theory can talk to anyone else. From an information point of view it’s just a amazing amount of informationand potential available. Of course, not everyone has something to say to every other user. But the fact that people who are interested in a subject can…