-
Bears new safety Coby Bryant will miss eight to 10 weeks with a leg injury.
-
Patriots wide receiver A.J. Brown told NFL Network that he dislocated his thumb in Monday's practice, but he didn't miss any time.
Patriots wide receiver A.J. Brown told NFL Network that he dislocated his thumb in Monday's practice, but he didn't miss any time. -
The Padres, who desperately needed starting pitching help, have acquired left-hander Robbie Ray from the Giants, sources told ESPN.
The Padres, who desperately needed starting pitching help, have acquired left-hander Robbie Ray from the Giants, sources told ESPN. -
USC and Notre Dame will renew their rivalry starting in 2030, however the Fighting Irish's home-and-home series vs. Indiana starting that year is now off.
USC and Notre Dame will renew their rivalry starting in 2030, however the Fighting Irish's home-and-home series vs. Indiana starting that year is now off. -
Retired Heat superstar Chris Bosh offered some advice and issued a warning to Spurs star Victor Wembanyama about his blood clot diagnosis and maintaining his health during his career.
Retired Heat superstar Chris Bosh offered some advice and issued a warning to Spurs star Victor Wembanyama about his blood clot diagnosis and maintaining his health during his career. -
Brewers ace Jacob Misiorowski dragged the Angel Stadium grounds crew through the dirt Sunday, calling the pitching mound "awful" and a possible injury risk.
Brewers ace Jacob Misiorowski dragged the Angel Stadium grounds crew through the dirt Sunday, calling the pitching mound "awful" and a possible injury risk. -
The Phillies have acquired three-time batting champion Luis Arraez from the Giants in a trade that has the second baseman joining his fifth team in five years.
The Phillies have acquired three-time batting champion Luis Arraez from the Giants in a trade that has the second baseman joining his fifth team in five years. -
Mauricio Pochettino has signed a new contract to continue as manager of the U.S. men's national team, U.S. Soccer announced Monday morning.
Mauricio Pochettino has signed a new contract to continue as manager of the U.S. men's national team, U.S. Soccer announced Monday morning. -
With a trade seemingly inevitable, the two-time Cy Young winner tried to keep things normal amid the chaos.
With a trade seemingly inevitable, the two-time Cy Young winner tried to keep things normal amid the chaos. -
Lions running back Jahmyr Gibbs said Monday that "only time will tell" when he will return to practice as he seeks a contract extension.
Lions running back Jahmyr Gibbs said Monday that "only time will tell" when he will return to practice as he seeks a contract extension. -
null
-
UEFA has raised the possibility that it could take legal action against Gianni Infantino over his World Cup sell-off plan, sources told ESPN.
UEFA has raised the possibility that it could take legal action against Gianni Infantino over his World Cup sell-off plan, sources told ESPN. -
We also finally get to see Game Freak's take on the Soulslike
-
Fields of Mistria launches its full 1.0 on Aug. 5, 2026. Time for new NPCs, new romance milestones, a chicken you can ride across the map, and more!
If you’ve played Harvest Moon or are looking for a Stardew-like with shades of Zelda and a ‘90s-inspired, Sailor Moon aesthetic, this is it. Fields of Mistria is a $14 farming and life-simulation RPG created by the independent team at NPC Studio. It’s been in early access for two years, and now the full game is launching on Steam on Aug. 5.
-
Roll back the tape of Earth's history, and geologists and astrobiologists remain perplexed about the environmental conditions on early Earth. That's because conventional pathways for understanding Earth's history have been lost to time owing to the planet's active geology and...
Roll back the tape of Earth's history, and geologists and astrobiologists remain perplexed about the environmental conditions on early Earth. That's because conventional pathways for understanding Earth's history have been lost to time owing to the planet's active geology and atmospheric weathering. -
A new trailer is here to remind you that 'Star Wars: Visions Presents - The Ninth Jedi' hits Disney+ on August 5.
A new trailer is here to remind you that 'Star Wars: Visions Presents - The Ninth Jedi' hits Disney+ on August 5. -
Cyanobacterial blooms, like the ones that occur in Lake Geneva, are rapid, dense growths of photosynthetic bacteria in fresh and marine waters that can threaten the health of swimmers and their pets.
Cyanobacterial blooms, like the ones that occur in Lake Geneva, are rapid, dense growths of photosynthetic bacteria in fresh and marine waters that can threaten the health of swimmers and their pets. -
The release of Street Fighter 6's new character, Yasmine, has been overshadowed by complaints over the game's latest yearly balance patch.
Street Fighter 6 just got its long-awaited Aug. 3 update, and the fan response has not been pretty. The short version is that the patch barely shakes up the game’s core systems, while making strange nerf and buff decisions for much of the roster.
-
Your Secrets Need a VDP, Not Just a Bug Bounty Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable PoC demands or scope exclusions create security blind spots when it comes to leaked secrets. By Gaetan Ferry • 6 Feb 2026 • 8 min...
Your Secrets Need a VDP, Not Just a Bug Bounty
Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable PoC demands or scope exclusions create security blind spots when it comes to leaked secrets.
By Gaetan Ferry • 6 Feb 2026 • 8 min read
In recent years, more and more companies have launched bug bounty programs as proof of their commitment to security and as a way to implement continuous monitoring of their corporate attack surface. Those programs sometimes offer generous payouts to vulnerability reporters, and often partner with dedicated platforms that offer various services such as:
- Payment and billing management
- Triaging as a Service
- Investigation assistance
Platforms rely on a "hacker community", a group of people who hack on the programs to discover vulnerabilities and earn bounty money. Most of those "hackers" are self-employed in a way that allows them to comply with local applicable tax laws.
Bug bounty programs are a great way to have a corporate perimeter or set of applications audited by a large set of people, nearly continuously. They can be a great addition to a company's security policy. In fact, GitGuardian has been running a bug bounty program for multiple years, as a complement to our periodic audits and overall security strategy.
Bug Bounty Done Wrong
The problem with bug bounty programs starts when they try to substitute for a proper Vulnerability Disclosure Policy. When they do, they no longer improve your security posture; they undermine it.
Bug bounties, by design, are selective. From a "hacker" perspective, they come with limited scopes, opaque triage processes, gatekeeping platforms, or even eligibility requirements. As a result, valid, good-faith vulnerability reports can get ignored, rejected, or buried -- not because they lack accuracy or merit, but because they fall outside of the boundaries of the programs' terms or the opaque decision of a third-party triager. Payout levels also undermine this testing model, turning continuous monitoring into a blind spot shaped by market incentives; why search for or report vulnerabilities when they pay little or nothing?
Using a bug bounty platform as the only possible communication channel for vulnerability disclosure creates unnecessary friction:
- Mandatory registration forces researchers to trade their privacy for participation.
- Non-disclosure clauses can silence conversation about systemic risks, and more generally hinder information sharing.
- Platform gatekeeping can discourage reporters.
- Worse: out-of-scope dismissals allow serious vulnerability reports to be voided, and never reported to security teams
These blind spots don't make an organization more secure. They make it easier to overestimate the security posture, thinking that fewer reports mean fewer problems.
A good Vulnerability Disclosure Policy (VDP) should promote openness. It should be a clear and accessible way for anyone -- a professional researcher, a student, or a concerned user -- to report a security issue safely, privately, and without process complexity. A good disclosure policy should enable communication rather than controlling it.
One particular issue that highlights how bug bounty can fail as a disclosure channel lies in how they handle secret leak reports.
GitGuardian's experience
One of the core foundations of GitGuardian is the detection and remediation of secrets leaked in public spaces. Over the course of the past year, while working on improving our understanding of the secret sprawl issue, we performed responsible disclosures to hundreds of companies.
GitGuardian's cybersecurity research team is not a bug bounty crew. We do not seek any reward for reporting incidents. For this reason, we usually attempt to contact affected companies directly, preferably via email, and sometimes through online forms dedicated to security incident reporting. We only fallback to the bug bounty program channel as a last resort, or when directly prompted to do so.
While working with platforms, we experienced a variety of situations and answers that illustrate how bug bounty can fail as a disclosure channel.
400 PoC or GTFO
As a result of a large-scale research project, we recently reported leaked private keys related to valid X.509 certificates. The risk of such incidents can generally be considered high, as a leaked key can be used to set up Man-In-The-Middle attacks against the company's public assets. Some of our reports had to go through bug bounty platforms, which already create friction. As much as we can automate the sending of hundreds of e-mails, filling bug bounty reports at scale is challenging.
In all our reports, the triagers asked for a proof of concept exploitation.
HackerOne response asking for a proof of concept after private key leak
BugCrowd response asking for a proof of concept after valid credential leak
First, proving a credential's impact has a clear ethical boundary: demonstrate the potential for harm without causing actual harm. This means verifying credentials are valid, confirming what resources they access, and documenting their privilege level, but without reading production data, modifying systems, or performing harmful actions. This is not always possible, depending on the credential type. In the case of leaked X.509 certificate private keys, creating such a proof-of-concept would have required decrypting real traffic or impersonating production services -- crossing from validation into active attack -- which could have severe legal consequences.
Then, the main question is: what happens after the report gets closed as informative? There is a chance that no action will be taken. In some cases, the issue might never pass the triaging filter and reach the corporate security team.
In our case, most reports were actually closed as informative, and none of the related certificates were revoked. Worst of all, some GitHub repositories containing leaked private keys have never been deleted. We later contacted the related certificates' issuer authorities to have the keys black listed and certificates revoked.
403 Private Program
Bug bounty programs can either be public or private. Public programs can be viewed, accessed, and interacted with by anyone. On the other hand, private programs are invite-only, so only selected members of the platform's community can report vulnerabilities.
In that case, obviously, the program can not be considered a proper disclosure channel. However, there is a reporting flow that overlooks this issue:
- You discover a vulnerability and attempt to report it through standard channels (security@, contact forms).
- You receive a response: 'Please submit via our Bug Bounty Program.'
- You navigate to the platform, only to find it's private and invitation-required.
- Without an invitation, you hit a dead end with no alternative channel.
Our team has faced this situation once, making the reporting process painful and highlighting how companies often lack awareness about vulnerability disclosure practices.
Similarly, a documented program can have expired or been decommissioned. In this case, the communication channel is effectively nonexistent. This was the case when we reported a leaked API key to xAI in 2025.
404 Secret Not Found In Scope
The scope of a program includes the list of assets that are authorized to be worked on. It also includes the list of vulnerabilities that are accepted in reports. The purpose of this restriction is to limit the number of low-quality reports or reports for vulnerabilities that are widely recognized as lacking real-world impact.
However, if the scope of a program is too restricted, valid and severe issues might get discarded by the triaging team without further notice. In that spirit, we faced bug bounty programs that explicitly marked leaked credentials as out of scope. The platforms sometimes even encourage their customers to ban secrets. The reason behind this is tied to the origin of the credentials, as we discussed with a platform representative:
We strongly advise our clients to exclude leaked secrets from their bug bounty program scope. The reality is that compromised credentials frequently originate from illicit sources. There's a thriving underground market for stolen credentials, and by offering bounties for leaked secrets, we risk inadvertently incentivizing and legitimizing a secondary marketplace for compromised authentication data.
While this concern is understandable, excluding leaked secrets creates a dangerous blind spot. Valid credentials represent immediate security risks: unauthorized access, data breaches, or compromised systems.
The solution isn't to ban secret reports -- it's to require source transparency. Researchers should disclose where the credentials were found. This approach enables security teams to investigate the leak's origin and take appropriate remediation action, while distinguishing legitimate research from illicit activity.
500 Triager error
Triager gatekeeping can also be an issue in case of a misunderstanding about a security issue. While misunderstandings can occur with corporate security teams, triagers can close the communication channel when they deem an issue uninteresting. While it is often possible to ask to reopen closed reports or ask for mediation, this can prevent legitimate reports from reaching the corporate teams and create unnecessary friction.
In the above case, the triager closed the issue while the affected credentials were still valid. Such behaviors create frustration, discourage reporters and, again, prevent secrets from being reported.
302 Redirect To Bug Bounty
Even when a direct communication channel with corporate security teams exists, it happens that those teams redirect mailed reports to a bug bounty platform. The rationale is understandable: centralizing all vulnerability reports in one place simplifies triaging and tracking.
Doing so not only slows the remediation process down, but also creates a dangerous bottleneck as the submission will likely have to comply with the bug bounty rules and scope definition, with the same pitfall as issues directly reported on platforms.
It also goes against the potential privacy requirements of the reporter, who would have to create an account on the bug bounty platform and sometimes even fill out tax regulation documents.
We received such a response when we contacted xAI for a leaked token last year. In that case, the corporate team also fixed the issue in the background, even before we could submit it to their program, demonstrating a clear lack of transparency.
Dear Gaëtan,
Thank you for your email.
For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?
https://hackerone.com/x?type=team
Thanks!
xAI TeamVulnerability Disclosure Policy done right
Writing a clear Vulnerability Disclosure Policy that provides an open and transparent communication channel is of prime importance to ensure your company receives vulnerability reports properly. As we explained above, such a policy should promote openness, transparency, and reporters' safety. Privacy is also a core concept of any proper VDP and should be emphasized, as is explained in documents from the US Cybersecurity & Infrastructure Security Agency:
How should my agency treat vulnerability reports from anonymous sources?
These reports should be treated the same as all other reports: like a gift. Knowing the source of a report can be a real benefit because it allows for rapport to develop. However, if the person who submits a report isn't known, the claim should simply be evaluated on its merits -- like every other report.When bug bounty platforms are your only security communication channel, such privacy can not be appropriately granted to vulnerability reporters.
In fact, CISA published a complete template for Vulnerability Disclosure Policy that emphasizes those openness and transparency concepts. The document is meant to be a regulatory requirement for government agencies, but it can be used as a basis to write the VDP of any company.
At GitGuardian, we are not against bug bounty programs, as we think they can be a great addition to a company's security policy. However, it is of prime importance to understand the limits and blind spots created by those platforms.
Most importantly, bug bounty programs must complement -- not replace -- a public Vulnerability Disclosure Policy. Private, invitation-only programs create insurmountable barriers for new researchers and should never be the sole disclosure channel. Companies should maintain accessible public VDPs alongside any BBP, with clear escalation paths that allow critical reports to bypass platform restrictions when necessary. Direct reports to security@ should remain direct -- triaged by internal teams who understand the full context of their infrastructure, not filtered through external platform scopes that may dismiss legitimate threats on technicalities.
Especially, if you manage a bug bounty program, make sure to include leaked credentials in its scope. Credentials-based attacks have become the number one cyber threat in the modern world, so those incidents should not be disregarded. Asking and verifying the source of the leaks will allow better investigation of the leak issue while reducing the risk of buying stolen credentials from the black market.
To conclude, whatever communication channel you choose for your vulnerability reports, make sure to promote it and make it as visible as possible, for example, with an RFC 9116 security.txt file. There is nothing worse than a communication channel no one knows about.
-
When running code reviews with local LLMs, a single model can either hallucinate non-existent bugs or generate generic advice you end up ignoring. To make local AI code review more useful, I built a closed Reviewer vs. Verifier loop for local Ollama workflows. The...
When running code reviews with local LLMs, a single model can either hallucinate non-existent bugs or generate generic advice you end up ignoring.
To make local AI code review more useful, I built a closed Reviewer vs. Verifier loop for local Ollama workflows.
The Architecture: Two Local Agents, One Loop
Instead of trusting one model's output, the workflow splits the job into two roles:
- Agent 1 (Reviewer): Reads the git diff or file changes. It searches specifically for logical flaws, security vulnerabilities, edge cases, or missing unit tests.
- Agent 2 (Verifier): Takes the Reviewer's list of findings and actively challenges them. If a finding is weak or unsupported, the Verifier pushes it out of the action list. If it holds up, the next step stays visible.
The goal is not to make the model "always right". The goal is to make weak claims easier to catch before you act on them.
Why Local-First?
Many agent workflows eventually ask you to move private workspace context into somebody else's control plane.
I packaged this workflow into HAICHI, a desktop workspace for Windows and Linux that connects to local Ollama models and keeps the workflow state inspectable.
Key features:
- Local-first workflow: Run Reviewer and Verifier style loops around local models.
- Visible evidence trail: Keep task, review, challenge, and result in one workspace instead of scattered chat tabs.
- Scoped execution: Keep actions bounded to the workflow you explicitly run.
- Practical limits: Control how much concurrent agent work runs on your machine.
Try it on your own code
HAICHI Personal is free to try.
- Website: https://haichi.app
- Supported OS: Windows 10/11, Linux (Ubuntu/Debian/Arch)
If you're already using Ollama for real development work, test the Reviewer vs. Verifier loop on one change and let me know where it helps, where it is too noisy, and what your local setup looks like.
-
Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.
Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world. -
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down
On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.
The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.
Continue reading... -
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down
On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.
The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.
Continue reading... -
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...
President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down
On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.
The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.
Continue reading... -
Apple is starting to feel the global memory shortage, with MacBook Air shipments delayed by a month or more.
Apple is starting to feel the global memory shortage, with MacBook Air shipments delayed by a month or more. -
US sees first fatalities due to intestinal illness, though both had significant underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the...
US sees first fatalities due to intestinal illness, though both had significant underlying health conditions
Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the intestinal illness.
“According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.
Continue reading... -
US sees first fatalities due to intestinal illness, though both had significant underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the...
US sees first fatalities due to intestinal illness, though both had significant underlying health conditions
Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the intestinal illness.
“According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.
Continue reading... -
US sees first fatalities due to intestinal illness, though both had significant underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the...
US sees first fatalities due to intestinal illness, though both had significant underlying health conditions
Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak of the intestinal illness.
“According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.
Continue reading... -
A few months back I was running Sales Navigator searches for a client project — filtering down to "VP Sales, fintech, based in Italy or Spain" type lists — and the results were genuinely good. 60, 80 leads that actually matched. Then I hit the part nobody warns you about:...
A few months back I was running Sales Navigator searches for a client project — filtering down to "VP Sales, fintech, based in Italy or Spain" type lists — and the results were genuinely good. 60, 80 leads that actually matched. Then I hit the part nobody warns you about: there's no button on that page that says "save this."
So I did what everyone does. Opened a spreadsheet, alt-tabbed back and forth, typed names and job titles by hand. Around profile 40 I gave up and went looking for a better way. This is what I found, roughly in the order I found it, including the tool I ended up building because none of the existing options quite fit what I needed.
First: the export LinkedIn actually gives you
LinkedIn has a real, built-in data export, and most people don't realize how narrow it is. It's under your profile photo → Settings & Privacy → Data Privacy → Get a copy of your data. From there you either tick specific categories (that email usually lands within minutes) or request the full archive, which takes closer to a day and sometimes arrives in two batches. Either way you get a download link that expires after 72 hours — and it's desktop only, the mobile app won't let you request one.
What you get back is genuinely thorough: connections, messages, your own profile history, activity, even the ad-targeting data LinkedIn holds on you. A couple of quirks worth knowing before you rely on it: some connections' email addresses will just be missing, because sharing an email on download is something each person opts into individually, and you won't get a list of who viewed your profile or any "People You May Know" data. If you're in the EU, EEA, or Switzerland, LinkedIn also runs a separate API for pulling your data on a schedule rather than as a one-off request.
Here's what this export is not built for, though: it has no idea what you searched for yesterday. It's an archive of your own account, not a way to capture a live search. Run a Sales Navigator query and pull 80 leads, and this tool won't touch them — those results aren't "your data," they're a page LinkedIn rendered for you a minute ago. If you want a yearly backup of your own connections and messages, or you're about to deactivate and want a copy first, start here and you're done. If you're trying to get a search result out of the browser, keep reading.
Second: the manual way, which is what most people actually do
Copy the name. Copy the title. Copy the company. Paste into a column. Repeat.
It's fine for five profiles before a call. It's genuinely miserable past fifteen — you lose track of who you've already copied, columns drift out of alignment, and an hour later you've got a spreadsheet that looks like it survived a fall down some stairs. I don't think anyone picks this method so much as ends up in it by default, since it's the only option that needs zero setup.
If you only do this occasionally, don't overthink it. A blank spreadsheet and fifteen minutes beats installing anything. It only turns into a real problem once you're doing it every week.
Third: browser extensions, which read what's already on the page
Once you're pulling data regularly, the next step people reach for is a browser extension, and it's worth understanding what these actually do under the hood — "LinkedIn tool" covers a wide range of behavior, and the range matters.
The category I trust reads the DOM of the page you're already looking at, the same rendered HTML your browser downloaded to show you the search results, and turns the visible fields into rows in a file. It doesn't call a private API, doesn't need anything beyond the session you're already logged into, and doesn't do anything you didn't ask it to.
The category I don't trust is the one that also automates actions on your behalf: auto-sending connection requests, auto-messaging, "warming up" a profile with likes. That's a fundamentally different product, and it's the kind of behavior that gets accounts restricted, because LinkedIn's abuse detection is watching for exactly that pattern — a lot of actions, very fast, in a rhythm no human clicks in. Reading a page you're already viewing and writing what you see to a CSV is a much smaller ask than pretending to be a human sending 200 connection requests an hour.
What I ended up building
I looked for something that just read search results — Profile, Company, Jobs, and Posts on regular LinkedIn, plus Lead and Account search on Sales Navigator — and either couldn't find it or found it bundled with a dozen automation features I didn't want anywhere near my account. So I built the Mastros LinkedIn & Sales Navigator exporter.
It's read-only, on purpose. You run a search, the extension recognizes the page and shows you every field it found before you export anything, so you know what you're getting instead of finding out after. Set a limit, hit export, and it drops a CSV, JSON, or JSONL file. CSV opens straight in Excel or Sheets and imports cleanly into a CRM — something like:
full_name,job_title,company,location Marco Bianchi,Head of Partnerships,Nordic Robotics,Turin Sara Klein,VP Marketing,Fjord & Co,Copenhagen Tomás Silva,Founder,Casa Verde,LisbonA few decisions I made on purpose, mostly because they were the things that annoyed me about other tools:
- Nothing leaves your machine. Extraction runs in your browser; the data never touches a Mastros server. We don't see the names or profiles you save, only that a save happened.
- No email guessing. It doesn't derive or buy anyone's email address. What's on the page is what you get.
- Only new records. Turn this on and it skips anything you've already exported, so re-running a search doesn't just duplicate last week's file.
- Safety pacing. There's an hourly cap that's separate from your monthly plan quota, specifically so a big export doesn't turn into the kind of rapid-fire activity that flags an account. Same reasoning as the automation point above: reading slower, on purpose.
- No actions, ever. It doesn't send invites, messages, or InMails, and it doesn't like, follow, or apply to anything. You trigger every export yourself; it never acts on your behalf.
It's free for 250 records a month across all six search types, no card required. Pro is $9/month for 10,000 records with rollover on unused ones, and Scale is $18/month with no record cap from our side — LinkedIn's own rate limits still apply, because claiming otherwise would just be a lie.
Picking one
- Backing up your own connections and messages, or prepping to deactivate → LinkedIn's own export. It's free, official, and already good at this.
- A handful of profiles before a call, once in a while → copy-paste. Don't install anything for five rows.
- Recurring prospecting, recruiting pipelines, or keeping a CRM fed from live searches → an extension built specifically to read search results, with pacing and dedup baked in. That's the gap the LinkedIn exporter is built to fill.
One last thing, easy to skip past: whichever method you use, the data is still about real people who didn't sign up to end up in your spreadsheet. Export what you're actually allowed to see, follow LinkedIn's terms, and don't turn a clean CSV into a cold-email blast nobody asked for. That's not a legal disclaimer, it's just the difference between doing research and being the reason someone locks down their privacy settings next week.
If you want to try it: it's a free Chrome install, 250 records a month, no card needed.
-
US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with USIran in talks with Oman over shipping route but not US, says TehranPeople walk near a billboard depicting Iran’s late supreme...
US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with US
People walk near a billboard depicting Iran’s late supreme leader Ayatollah Ali Khamenei, on a street in Tehran, Iran, earlier today.
Six Saudi-flagged supertankers have changed course in the Gulf of Aden in recent days amid threats from the Iran-aligned Houthis, Reuters reports.
Continue reading... -
US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with USIran in talks with Oman over shipping route but not US, says TehranPeople walk near a billboard depicting Iran’s late supreme...
US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with US
People walk near a billboard depicting Iran’s late supreme leader Ayatollah Ali Khamenei, on a street in Tehran, Iran, earlier today.
Six Saudi-flagged supertankers have changed course in the Gulf of Aden in recent days amid threats from the Iran-aligned Houthis, Reuters reports.
Continue reading... -
Joshua Bonehill-Paine, creator of satirical Crewkerne Gazette, has convictions including harassment of a Jewish MPA former neo-Nazi activist with convictions including for harassing a Jewish MP has been selected as a Conservative candidate for a local election in...
Joshua Bonehill-Paine, creator of satirical Crewkerne Gazette, has convictions including harassment of a Jewish MP
A former neo-Nazi activist with convictions including for harassing a Jewish MP has been selected as a Conservative candidate for a local election in Somerset.
Joshua Bonehill-Paine, the creator of the viral Crewkerne Gazette series of AI clips, is due to stand for election to Somerset council next year in a new Crewkerne South district. He told the Guardian he was an executive member of the Tories’ Yeovil branch, working as an events organiser.
Continue reading... -
Wildfires in Spokane have destroyed hundreds of homes and led to evacuation orders for 60,000 people.

Wildfires in Spokane have destroyed hundreds of homes and led to evacuation orders for 60,000 people.
(Image credit: Young Kwak/AP)

-
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking...
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package -
After working on enterprise applications and distributed microservices, I have realized that the biggest challenges rarely come from writing business logic. They come from handling production traffic, failures, concurrency, and unexpected edge cases. Here are seven lessons...
After working on enterprise applications and distributed microservices, I have realized that the biggest challenges rarely come from writing business logic. They come from handling production traffic, failures, concurrency, and unexpected edge cases.
Here are seven lessons that every Spring Boot developer should know before calling themselves a senior engineer.
1. Never Assume an API Will Be Called Only Once
One of the most common mistakes is assuming a client sends exactly one request.
In reality:
- Users refresh the page.
- Mobile apps retry automatically.
- API gateways retry requests.
- Kafka consumers may reprocess events.
- Network failures cause duplicate submissions.
If your endpoint creates an order, payment, or booking every time it receives a request, duplicates are almost guaranteed.
Better Approach
Design APIs to be idempotent.
For example:
- Use an Idempotency-Key.
- Store processed request IDs.
- Ignore duplicate requests safely.
Production systems should always expect duplicate requests.
2. Database Transactions Are Not Enough
Many developers believe this solves everything:
@Transactional public void createOrder() { ... }It doesn't.
A transaction protects changes inside a single database.
It does not protect:
- Kafka publishing
- Email sending
- External REST APIs
- Redis updates
- File uploads
If your database commits successfully but Kafka publishing fails, your system is already inconsistent.
Better Approach
Use patterns such as:
- Transactional Outbox
- Saga Pattern
- Event-driven architecture
- Retry with dead-letter queues
3. Don't Trust External APIs
Every external service will eventually fail.
Your payment provider.
Your authentication service.
Your notification service.
Even your own internal microservices.
Never assume another service is always available.
Add Protection
- Timeouts
- Retries
- Circuit Breakers
- Fallback logic
- Monitoring
Failing fast is usually better than waiting forever.
4. Logging Is More Valuable Than You Think
When production goes down, nobody asks:
"Was the code clean?"
Everyone asks:
"What happened?"
Poor logging turns a five-minute issue into a five-hour investigation.
Good Logs Include
- Correlation ID
- Request ID
- User ID (where appropriate)
- Service name
- Execution time
- Error details
Avoid logging entire request bodies or sensitive information.
Logs should help you debug—not create new security problems.
5. Performance Problems Usually Start in the Database
Most slow APIs aren't caused by Java.
They're caused by:
- Missing indexes
- N+1 queries
- Loading unnecessary data
- Multiple database calls inside loops
Before optimizing Java code:
- Check SQL execution plans.
- Measure database latency.
- Cache frequently used data.
- Fetch only what you need.
Always measure before optimizing.
6. Handle Concurrency Explicitly
Concurrency bugs are among the hardest to reproduce.
Imagine two requests arriving at exactly the same time:
Request A Request B Both check: Balance = ₹100 Both withdraw ₹100 Final Balance = -₹100Everything worked correctly from each request's perspective.
Together, they corrupted the data.
Solutions
- Optimistic Locking
- Pessimistic Locking
- Distributed Locks
- Atomic database updates
- Idempotent operations
Concurrency isn't a rare edge case.
It's a daily production reality.
7. Monitoring Is Part of the Application
If you can't observe your application, you can't operate it.
Every production service should expose:
- Health checks
- Metrics
- Request latency
- Error rates
- JVM metrics
- Database latency
- Kafka consumer lag
Modern observability tools include:
- Micrometer
- Prometheus
- Grafana
- OpenTelemetry
- ELK Stack
The best production incidents are the ones users never notice because your monitoring detected them first.
Final Thoughts
Being a senior Spring Boot developer isn't about memorizing annotations or frameworks.
It's about designing systems that continue to work when networks fail, traffic spikes, duplicate requests arrive, and dependencies become unavailable.
Production engineering is less about writing more code and more about building software that remains reliable under real world conditions.
If you're just starting your backend journey, focus on these concepts early. They'll have a much bigger impact on your career than learning another framework.
Java #SpringBoot #Microservices #Backend #SoftwareEngineering #SystemDesign #DistributedSystems #Kafka #Programming #DevOps
-
Apple’s long-awaited AI overhaul finally makes Siri the assistant it was always supposed to be. But after years of delays, the launch lands in an AI landscape where chatbots have evolved into agents that can code, reason, create media, and complete complex tasks. Siri AI is...
Apple’s long-awaited AI overhaul finally makes Siri the assistant it was always supposed to be. But after years of delays, the launch lands in an AI landscape where chatbots have evolved into agents that can code, reason, create media, and complete complex tasks. Siri AI is genuinely useful, yet it arrives at a moment when simply being a capable AI assistant no longer feels revolutionary. -
When a hurricane roars toward land, forecasters try to predict how high sea levels will rise to help coastal communities prepare for the worst impacts.
When a hurricane roars toward land, forecasters try to predict how high sea levels will rise to help coastal communities prepare for the worst impacts. -
Students who open a personal social media account earlier in adolescence appear to perform worse on later standardized tests, according to a study in Nature Human Behaviour based on 5,227 Italian students. The authors speculate that these differences may be attributable to...
Students who open a personal social media account earlier in adolescence appear to perform worse on later standardized tests, according to a study in Nature Human Behaviour based on 5,227 Italian students. The authors speculate that these differences may be attributable to excessive social media engagement and disruptions to students' attention. -
I swear I'll be more organized this time
-
After debuting at Burning Man, Jen Lewin’s towering bear sculptures now anchor Brooklyn’s Gowanus waterfront
For many public artworks, permanence is the exception rather than the rule. Jen Lewin’s The Ursas, however, has made the uncommon leap from the ephemeral landscape of Burning Man to a permanent installation along Brooklyn’s evolving Gowanus waterfront, where the monumental sculptures now anchor a newly accessible stretch of the canal.

‘The Ursas’ were installed at their new home along the Gowanus Canal on Aug. 1. Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros.
Installed at Nevins Landing on Aug. 1, the paired sculptures occupy a prominent position between the residential towers and the canal. The development, designed by Fogarty Finger with waterfront landscape architecture by Field Operations, is part of the larger Gowanus Wharf campus. The project adds a new public landmark to a neighborhood undergoing dramatic physical and cultural transformation, as former industrial sites are increasingly giving way to housing, parks, and civic spaces.

Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros
Inspired by the Ursa Major and Ursa Minor constellations, The Ursas explores ideas of navigation, orientation, and environmental stewardship. The larger of the two works, Ursa Major, rises 30 feet and is constructed from reclaimed ocean plastic originally sourced from Lewin’s 2022 installation The Last Ocean. Visitors can step inside the sculpture, where an infinity-mirrored chamber contains hand-drawn illustrations of species listed as extinct or presumed extinct on the IUCN Red List. Beside it, the 13-foot-tall Ursa Minor is clad in infinity mirrors and programmable LED lighting that creates an ever-shifting sense of depth and reflection.

Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros
“The Ursas grew out of my research into the melting Ross Ice Shelf while developing The Last Ocean,” Lewin says. “What began as scientific inquiry became a personal reckoning with the scale and speed of environmental change.”
Lewin describes Ursa Minor as “a beacon” seeking the North Star, while Ursa Major carries illustrations honoring recently extinct species. “Together, the works hold two realities at once: grief and responsibility, but also direction,” she explains. “They ask us not only to reflect, but to decide how we move forward.”

Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros
The installation also marks a notable moment for Gowanus, where public art is increasingly being positioned as part of broader neighborhood redevelopment rather than an afterthought. The Ursas become one of the first permanent artworks to define the identity of the four-building Gowanus Wharf campus, which will ultimately introduce more than 2,200 residential units alongside publicly accessible waterfront space.
Before arriving at their new home, the sculptures made a dramatic journey across the Verrazzano-Narrows Bridge before being hoisted over Brooklyn’s Union Street Bridge and lowered into place along the canal. What began as a temporary installation in the Nevada desert in 2023 is now part of the everyday fabric of the city.
Editorial Transparency: This article was developed with the assistance of AI tools, which may have been used for research, outlining, editing, or copy refinement. Reporting, fact-checking, and editorial decisions were made by the Design Milk editorial team.
-
The article is here; the Abstract: This paper examines how the European Court of Human Rights' (ECtHR or Court) hate… The post Journal of Free Speech Law: "Positive Obligations, Hate Speech, and the Reconfiguration of Free Expression at the European Court of Human Rights,"...
The article is here; the Abstract:
This paper examines how the European Court of Human Rights' (ECtHR or Court) hate speech jurisprudence has been structurally reoriented by the Court's response to an increasing number of applications brought by victims of hate speech. Whereas earlier case law predominantly assessed hate speech under Article 10 of the European Convention on Human Rights, focusing on the permissibility of restrictions on expression, recent victim-initiated claims have directed the ECtHR's analysis towards Articles 8 and 14 and thus towards the question of State responsibility for protection against harm caused by third-party speech.
Through a reading of the ECtHR's case law, this paper shows how the Court's response to this applicant-driven expansion has recalibrated the balance between dignity, equality, and freedom of expression. The paper argues that the resulting framework risks limiting the doctrinal safeguards traditionally associated with Article 10 analysis.
In addition, there has been an increasingly expansive understanding of who qualifies as a "victim" of hate speech, extending this qualification beyond direct targets who are in protected groups to include individuals who are merely associated with such groups. The paper argues that the Court's expanding expectation of positive obligations owed by States to their citizens in relation to the exercise of their rights may incentivize over-intervention by domestic authorities and chill legitimate public debate.
The post Journal of Free Speech Law: "Positive Obligations, Hate Speech, and the Reconfiguration of Free Expression at the European Court of Human Rights," by Natalie Alkiviadou appeared first on Reason.com.
-
Restore leader has countered charges he’s splitting the right while showing his party is a very real obstacle for ReformEven by the standards of their rivalry, the speed at which Rupert Lowe’s olive branch to Nigel Farage morphed into fresh recriminations between the two was...
Restore leader has countered charges he’s splitting the right while showing his party is a very real obstacle for Reform
Even by the standards of their rivalry, the speed at which Rupert Lowe’s olive branch to Nigel Farage morphed into fresh recriminations between the two was swift.
It began with a softly lit 12-minute video posted on Sunday by the Restore Britain leader, looking straight to camera and referring to “Nigel” as he suggested his party could be willing to cast aside its differences with Reform UK and work together.
Continue reading... -
Una discusión sobre un archivo digital casi nunca se pierde por lo que el archivo dice. Se pierde una pregunta antes: ¿Cómo sabemos que ese es el archivo que usted recibió, y no el que editó anoche? Si la respuesta es "confíe en mí", ya perdiste. Y da igual cuánta razón...
Una discusión sobre un archivo digital casi nunca se pierde por lo que el archivo
dice. Se pierde una pregunta antes:¿Cómo sabemos que ese es el archivo que usted recibió, y no el que editó anoche?
Si la respuesta es "confíe en mí", ya perdiste. Y da igual cuánta razón tengas en
el fondo.Este problema no es exclusivo de un juzgado. Lo tiene el auditor que recibe un
volcado de logs, el equipo que documenta un incidente, quien conserva la copia de
un contrato firmado por correo. En todos los casos hace falta lo mismo: poder
demostrar que un conjunto de bytes no cambió desde un momento determinado, y que
lo demuestre alguien que no seas tú.Para eso escribí Tunjo: una
herramienta en Rust que recorre un material en solo lectura, calcula su huella y
firma un acta verificable por cualquiera.Por qué un árbol y no un hash
Lo obvio sería concatenar todo y sacar un SHA-256. Funciona, y es inútil en la
práctica.Cuando alguien discute un archivo —un correo concreto entre cuatro mil— con
un hash único solo puedes ofrecer dos cosas: o entregas el conjunto completo para
que se recalcule, o pides que te crean. La primera opción expone material que no
tiene por qué exponerse; la segunda no es una prueba.Un árbol de Merkle resuelve exactamente eso. Cada archivo es una hoja, cada par
de nodos se combina hacia arriba y queda una raíz. Para demostrar que una hoja
pertenece a esa raíz basta con exhibir esa hoja y el camino de hashes hasta
arriba: unos pocos kilobytes. El resto del conjunto no se toca.Dos detalles del árbol que no son opcionales:
// Separación de dominio: una hoja nunca puede hacerse pasar por nodo interno. h.update([0x00]); // hoja h.update([0x01]); // nodo interno // Y la raíz ata el número de hojas. h.update([0x02]); h.update(n.to_be_bytes());Sin lo primero, un hash de hoja podría presentarse como si fuera un nodo del
árbol. Sin lo segundo aparece la ambigüedad clásica de los árboles con número
impar de hojas: dos conjuntos distintos pueden producir la misma raíz. Es un
error viejo y conocido, y sigue apareciendo en implementaciones nuevas.La huella cubre el estado, no solo el contenido
La hoja no es el hash del archivo: es el hash del elemento completo —ruta,
tamaño, fecha, estado y hash del contenido—.La diferencia importa. Si la huella fuera solo del contenido, mover un archivo de
carpeta, renombrarlo o sustituirlo por un enlace que apunta al mismo contenido
dejaría la raíz intacta. Y esos tres movimientos cambian lo que el conjunto
significa: dónde estaba un documento es parte del hecho que se documenta, no un
detalle de presentación.Firmar para dentro de diez años
El acta se firma con la firma triple-híbrida de
Quipu: Ed25519 + ML-DSA-87 (FIPS 204)- SLH-DSA-SHA2-256s (FIPS 205), y las tres deben validar.
No es coleccionismo de algoritmos. Es que la vida útil de esto no se mide en
meses: un expediente puede tardar años en resolverse, y la firma tiene que seguir
verificándose al final. Las tres piezas fallan por motivos distintos —Ed25519
frente a un ordenador cuántico; ML-DSA por ser reciente y basada en retículos;
SLH-DSA solo si se rompe la función hash— y hacen falta las tres a la vez para
que el sello valga. Que caiga una no tumba el acta.El coste es honesto: la firma pesa unos 34 KB. Para sellar un conjunto de
archivos, es ruido.Verificar la firma no basta
Este es el error que más fácil se comete al implementar algo así. La firma cubre
el JSON completo del acta, incluida la raíz de integridad. Si al verificar te
limitas a comprobar la firma, das por buena una raíz que nadie recalculó: alguien
con la clave podría firmar un acta cuya raíz no corresponde a los elementos que
lista, y pasaría el control.Por eso la verificación recalcula el árbol siempre, y solo después mira la firma.
Hay una prueba dedicada a ese caso exacto: firma auténtica sobre raíz mentirosa
debe fallar.
$ tunjo verificar acta.json --origen ./evidencia SELLO VÁLIDO contenido: 4 elementos, 3 con contenido verificable raíz: d9f6f68f591c6af087838dc27049a4194ab70525c350b79ec22446f9c12f9e33 1 DISCREPANCIA(S) contra evidencia: ALTERADO adjuntos/c.pdf acta: 3fdbaf9c795e22f14e16974c37b62ed381b9c8c4ac7bcbe1a01f13d08ec46643 disco: 9af5d94042eafbf2c335aa874085b263ff0201aee5e5033fd4c432e92de0093dAnte la ausencia de un dato, ruido
Una herramienta de integridad que disimula sus fallos es peor que no tenerla,
porque produce confianza sin respaldo. Tres decisiones al respecto:Un archivo ilegible detiene el sellado. No se salta en silencio. Si de verdad
es ilegible, hay que pedirlo explícitamente y entonces el acta lo registra como
error: de ese elemento consta que existía y que la lectura falló, y nada más.Del reloj se dice la verdad. El acta pide declarar cómo se contrastó con una
fuente externa. Si no se declara, escribe "NO VERIFICADO" en lugar de callarlo.
Sin sello de tiempo de un tercero, esto prueba orden relativo, no fecha cierta —y
también lo dice.Los enlaces simbólicos no se siguen. Se registra a dónde apuntan. Seguirlos
sacaría la adquisición del material que se recibió.Lo que deliberadamente no hace
No detecta intrusiones, no atribuye autoría y no concluye nada. Podría añadirle
heurísticas que dijeran "aquí hubo un ataque", y sería un error: quien firma un
informe tiene que poder defender cada afirmación línea por línea, y nadie defiende
una heurística que no escribió. Cuando esa afirmación se cae, arrastra al resto
del informe.Tampoco prueba el pasado. Acredita desde el instante de la adquisición: si el
material ya venía alterado, el sello certifica fielmente material alterado. Está
escrito en el acta que genera, no en la letra pequeña.El verificador es público, y no por generosidad
Si el único que puede comprobar un sello es quien lo emitió, no es una prueba: es
una afirmación con formato técnico. Por eso el verificador es software libre y su
código está publicado.Lo comprobé de la única forma que vale: cloné el repositorio público en una
máquina limpia, lo compilé desde cero y con ese binario verifiqué un acta
sellada por otro. Válida. Después alteré un byte de un adjunto y el mismo binario
señaló ese archivo y solo ese.
git clone https://github.com/isazajuancarlos/tunjo cd tunjo && cargo build --release ./target/release/tunjo verificar acta.json --origen ./evidenciaRust, AGPL-3.0, y las pruebas incluyen una simulación de 240 contrastes: se altera
un byte de cada uno de 120 archivos y se exige que señale ese y solo ese, y que al
restaurarlo no queden falsos positivos. Detectar es fácil; discriminar es el
trabajo. -
Before you go spend money on new headphones, try these adjustments. You can probably improve the sound on the ones you have.
Before you go spend money on new headphones, try these adjustments. You can probably improve the sound on the ones you have.
-
US president reduced to bemoaning Tehran’s ‘unbelievable duplicity’ as he struggles to find solid negotiating groundMiddle East crisis live – latest updatesThe Donald Trump doctrine has always contained a tenuous relationship with the truth. It was his mentor, the infamous...
US president reduced to bemoaning Tehran’s ‘unbelievable duplicity’ as he struggles to find solid negotiating ground
The Donald Trump doctrine has always contained a tenuous relationship with the truth. It was his mentor, the infamous New York lawyer Roy Cohn, who taught the young real estate mogul always to claim victory and never to admit defeat. Unfortunately for Trump, in Iran the US president has found a counterpart just as stubborn as himself.
As Trump claims new negotiations are to begin with Tehran this week, Iran has shown it can also reignite the conflict by lobbing ballistic missiles at US bases in the region and maintaining a stranglehold on the strait of Hormuz, effectively taking initiative in the stalled peace process. And time is of the essence for Trump as the clock ticks toward a global energy crisis and a painful midterm elections for him and his Republican party.
Continue reading... -
A new security measure meant to thwart bots might mean that TCG products like the UPC won't be purchased primarily by scalpers
Trading card game fans have spent the last few weeks feeling anxious, as The Pokémon Center slowly doles out new waves of 30th anniversary pre-orders. So far, the prevalence of bots programmed to make lightning-fast purchases while collectors wait for hours has made every drop a miserable affair. Much of the time, scalpers clean out the best products before most people can even load the page. But now, The Pokémon Company might finally be putting an end to that nightmare.
-
Canonical URL: https://blog.1001020.xyz/ Suggested cover image: use a recent image from https://blog.1001020.xyz/gallery I have been building a small publishing system called 1001020, a serverless blog and AI gallery running on Cloudflare Workers. The live site is here:...
Canonical URL: https://blog.1001020.xyz/
Suggested cover image: use a recent image from https://blog.1001020.xyz/gallery
I have been building a small publishing system called 1001020, a serverless blog and AI gallery running on Cloudflare Workers.
The live site is here: 1001020 — AI Gallery & Cloudflare Experiments
The goal was not to build another static blog generator. I wanted something that could publish articles, serve an image gallery, manage uploaded assets, expose structured sitemaps, and stay operational without a traditional server.
The basic architecture
The whole public site runs on Cloudflare Workers. Articles, settings, comments, gallery metadata, and telemetry live in Cloudflare KV. Managed images are stored in R2 and served through a dedicated image domain.
The main pieces are:
- Cloudflare Workers for request routing and rendering
- Cloudflare KV for article and site metadata
- Cloudflare R2 for managed image uploads
- A theme system for different frontend layouts
- XML sitemap and image sitemap generation
- A small local AI drafting tool for preparing and publishing content
The gallery is a first-class part of the site, not just a media folder. You can browse it here: AI Gallery on 1001020
Why Workers instead of a conventional backend?
For this project, Workers are a good fit because the workload is mostly request routing, HTML generation, metadata reads, and small API writes. A conventional server would work, but it would add deployment and maintenance overhead that I did not need.
Cloudflare Workers also make it easy to keep the app close to the edge while still handling dynamic behavior. The blog can render pages server-side, expose APIs, and support admin operations without a separate Node or container deployment.
KV as the content store
The project stores persistent content in KV using explicit keys for articles, gallery records, settings, telemetry, comments, newsletter subscribers, and other small datasets.
This shape works well for a personal publishing system because the access pattern is simple:
- read the article index
- read individual article records
- write admin updates
- render HTML or markdown responses
- regenerate sitemap output from current content
The main tradeoff is that KV is not a relational database. I keep data models small and explicit, and avoid pretending it can do arbitrary query workloads.
R2 for images
Images are uploaded as managed assets and served from R2. Article content can reference those managed image URLs, and the system tracks image references so unused assets can be identified and cleaned up.
That part matters because image-heavy blogs tend to accumulate stale files quickly. Treating image references as part of the content model keeps the gallery and article system easier to maintain.
SEO basics that are built in
The site now ships with the boring but important search plumbing:
sitemap.xmlimage-sitemap.xmlrobots.txt- server-rendered article content
- image dimensions for layout stability
- canonical article URLs
- Google Search Console verification token injection through the admin settings page
One article that explains part of the agent workflow direction is here: Agent Harness Loop and Graph Engineering
What I learned
The biggest lesson is that a serverless blog should not be treated as a toy static page. Once publishing, images, metadata, admin operations, analytics, and sitemaps enter the picture, the system starts to look like a small CMS.
Cloudflare Workers can handle that shape well, but only if the storage model stays simple and the routes remain deliberate.
For 1001020, the result is a compact publishing stack that can run globally without a traditional backend server:
- live site: https://blog.1001020.xyz/
- AI gallery: https://blog.1001020.xyz/gallery
- example article: https://blog.1001020.xyz/article/agent-harness-loop-graph-engineering
I am still iterating on the publishing workflow, but the core system is now stable enough to share.
-
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought
Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.
Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.
Continue reading... -
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought
Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.
Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.
Continue reading... -
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...
Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought
Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.
Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.
Continue reading... - Loading more…





