Shellsharks Blogroll - BlogFlock https://blogflock.com/list/xJ8yq 2026-09-07T08:32:09.000Z BlogFlock shellsharks Skiing in Tūroa - The Weblog of fLaMEd https://flamedfury.com/posts/skiing-in-turoa/ 2026-09-07T08:32:09.000Z fLaMEd <p>What’s going on, Internet? This is a later post. It’s been a minute since <a href="https://flamedfury.com/posts/whakapapa-ski-trip/">I’ve been skiing</a>. We left the kids at home with their aunty and headed south to Ohakune.</p> <p>Was made aware before the trip that Ohakune’s main water pipe was recently damaged during an earthquake. Repairs were being made but this weekend the township was without water. Restaurants had to close, hotels and motels had to close and cancel reservations.</p> <p>We wanted to stay at the Powderhorn this trip for two nights, but the Monday night was fully booked so we couldn’t. Ended up working in our favour as they had to cancell all bookings.</p> <p>We ended up in a rental house that was owned and managed by a local couple. No running water, but we were able to flush the toilets with water from the spa pool and was hands etc with bottled water supplied by the council.</p> <figure slot="image"><picture> <source type="image/webp" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-480w.webp 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-800w.webp 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-1200w.webp 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /> <source type="image/jpeg" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-480w.jpeg 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-800w.jpeg 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-1200w.jpeg 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /><img src="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-06-1200w.jpeg" width="1200" height="675" alt="Snow-covered Mt Ruapehu under a streaky blue sky, seen over trees and the roof of a house in Ohakune." loading="lazy" decoding="async" eleventy:ignore="" /></picture><figcaption>The view of the mountain from the rental house.</figcaption></figure> <p>Not much was open in town for food but a few of the takeaways were open so we were able to get a decent feed.</p> <p>Weather wasn’t looking too flash for Monday up the mountain but it held out in the end. Sure visibility was rubbish off and on during the day, it snowed around lunch time, a great time to take a break, but the snow was pretty good up there.</p> <p>Like I mentioned, it had been a while (three years) since my last time up the mountain, I went up the top of the Movenpick chair lift and had a rough time getting down. The visibility was horrible up there for the first run.</p> <figure slot="image"><picture> <source type="image/webp" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-480w.webp 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-800w.webp 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-1200w.webp 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /> <source type="image/jpeg" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-480w.jpeg 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-800w.jpeg 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-1200w.jpeg 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /><img src="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-01-1200w.jpeg" width="1200" height="675" alt="A near whiteout on the snow, with only a tow rope line and a red safety net visible through the fog." loading="lazy" decoding="async" eleventy:ignore="" /></picture><figcaption>Visibility for the first run.</figcaption></figure> <p>I made it down to the top of the Park Lane chairlift and spent the morning at the Wintergarden tow rope and it’s gentle slop getting familiar with the skiis again.</p> <figure slot="image"><picture> <source type="image/webp" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-480w.webp 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-800w.webp 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-1200w.webp 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /> <source type="image/jpeg" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-480w.jpeg 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-800w.jpeg 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-1200w.jpeg 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /><img src="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-03-1200w.jpeg" width="1200" height="675" alt="Looking up at the chairlifts from the Wintergarden under heavy grey cloud, with the tow rope running up the right and skiers in the foreground." loading="lazy" decoding="async" eleventy:ignore="" /></picture><figcaption>The view from the Wintergarden, tow rope on the right.</figcaption></figure> <p>After lunch I head back up to the top of Park Lane and spent the next couple hours heading down the Park Lane chairlift.</p> <p>Once I was confident with that run I headed back up to the top of the Movenpick. The first part of the slope was a bit of a challenge but I struggled through and made it back to the top of Parklane to finish the run.</p> <figure slot="image"><picture> <source type="image/webp" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-480w.webp 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-800w.webp 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-1200w.webp 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /> <source type="image/jpeg" srcset="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-480w.jpeg 480w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-800w.jpeg 800w, https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-1200w.jpeg 1200w" sizes="(max-width: 480px) 100vw, (max-width: 800px) 80vw, 1200px" /><img src="https://flamedfury.com/assets/images/2026-08-13-skiing-in-turoa-05-1200w.jpeg" width="1200" height="675" alt="The base of the mountain with skiers gathered around the lift station, a snow cannon beside it, and the Movenpick and Parklane chairlifts climbing the rocky slope behind." loading="lazy" decoding="async" eleventy:ignore="" /></picture><figcaption>The base of the mountain, with the Movenpick and Parklane chairlifts heading up.</figcaption></figure> <p>One day up the mountain is not enough. Next trip I want to spend at least three days on the slopes, a couple hours of private lessons would do me well.</p> <p>Hey, thanks for reading this post in your feed reader! Want to chat? <a href="mailto:hello@flamedfury.com?subject=RE: Skiing in Tūroa">Reply by email</a> or add me on <a href="xmpp:flamed@omg.lol">XMPP</a>, or send a <a href="https://flamedfury.com/posts/skiing-in-turoa/#webmention">webmention</a>. Check out the <a href="https://flamedfury.com/posts/">posts archive</a> on the website.</p> Standard zero .05 now reserved for 'AI' - Johnny.Decimal https://johnnydecimal.com/blog/0246-standard-zero-05/ 2026-09-07T04:58:04.000Z Johnny.Decimal <p><a href="https://johnnydecimal.com/documentation/the-standard-zeros">Standard zero</a> <code>.05</code> has until now been reserved for expansion. I am claiming it for use by your AI agent. I'll duplicate the section from that page below.</p> <blockquote> <p>⚠️ This blog post is frozen in time. If you're reading this later than September 2026, <a href="https://johnnydecimal.com/documentation/the-standard-zeros#05-ai">view the latest text on the standard zeros page</a> in case it has been updated.</p> </blockquote> <h2 id="05-ai">.05 AI</h2> <p>A place for your AI agent.</p> <p>Agents work best when you write things down. Your JDex is an amazing communication tool: both you and your agent can read and write anything in it. Best memory ever.</p> <p>Sometimes it's useful to have a <em>dedicated</em> space that the agent controls. This is a place that it can store persistent information for recall across sessions.</p> <p>You can also use it to provide per-system instructions to your agent. For example at <code>00.05</code> I have a 'style guide' that tells it how I like my frontmatter properties to be organised (alphabetically).</p> <p>The <a href="https://johnnydecimal.com/jdhq/agent-skills">skills</a> and <a href="https://johnnydecimal.com/jdhq/mcp-server">MCP server</a> both assume they have control over <code>AC.05</code>.</p> <h3 id="emoji-">Emoji ✨</h3> <p>The standard emoji is – obviously – ✨</p> Note published on September 6, 2026 at 5:27 PM UTC - Molly White's activity feed 6a9da29452b01ca28c3ff3f4 2026-09-06T17:27:48.000Z Molly White <article><div class="entry h-entry hentry"><header></header><div class="content e-content"><p>make bad art</p><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609061327"><time class="dt-published" datetime="2026-09-06T17:27:48+00:00" title="September 6, 2026 at 5:27 PM UTC">September 6, 2026 at 5:27 PM UTC</time>. </a></div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117225270043571205" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3muujbbylss2w" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/art" title="See all micro posts tagged "art"" rel="category tag">art</a>. </div></div></footer></div></article> Deleted YouTube again - Joel's Log Files https://joelchrono.xyz/blog/deleted-youtube-again 2026-09-06T13:53:52.000Z joelchrono <p>For a little while I have been using YouTube way more, and even paid for the Lite subscription model, simply to test it out.</p> <p>Honestly, it hasn’t been too bad, and I actually really, really enjoy a lot of the videos I’ve gotten through the algorithm.</p> <p>But of course, YouTube Shorts have caught up with me and continue to be a very annoying problem, wasting seconds, minutes and hours of my time at every moment.</p> <p>The algorithm does show some interesting things, or funny content I enjoy, but things go downhill pretty quickly with the usual AI-generated slop videos and recycled content.</p> <p>A few of the saving graces I’ve seen is shorts made from genuinely awesome videos that came out like 5 years ago, so I think it’s an interesting way to bring life to evergreen videos about science and the like.</p> <p>With Outer Wilds playthroughs and essays running rampat, my feed slowly phased into more space and astronomy themed topics, which has been pretty fun to get into until I realize half the videos are way too long for what they have to say and use genAI graphics for everything.</p> <p>So whatever, I just deleted YouTube and cancelled my subscription now. I will continue to use it via <a href="https://f-droid.org/packages/org.mozilla.fennec_fdroid/">Fennec Browser</a> and <a href="https://github.com/TeamNewPipe/NewPipe">Newpipe</a>, though maybe a full YouTube detox would be a good idea to try.</p> <p>Yesterday alone I wasted almost 6 hours on the platform, and I think like 4 of them were just Shorts. Even now I just had to have a video on the background while writing this, what is going on?</p> <p>You know what, I will try it, I will limit my YouTube time to one hour a day for the rest of the month. It’s possible I’ll fail completely, but hey, at least you will know if that happens and you are free to bully me for it. The weeknotes next Monday will also be the last ones where I share YouTube links this month, as I also feel like a part of me watches more videos because I have a need to find stuff worth sharing here. The less excuses I have the better!</p> <p>Alright, let’s do this.</p> <p>This is day 30 of <a href="https://100daystooffload.com">#100DaysToOffload</a></p> <p> <a href="mailto:me@joelchrono.xyz?subject=Deleted YouTube again">Reply to this post via email</a> | <a href="https://fosstodon.org/@joel/117224497221371041">Reply on Fediverse</a> </p> The purpose of DNS is to spread scams - Terence Eden’s Blog https://shkspr.mobi/blog/?p=74588 2026-09-06T11:34:20.000Z Terence Eden’s Blog <p>I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak</p> <p>You know it is a scam. Most people just mark as spam and move on with their day. But a significant number of people don't. They hastily visit the site, tap in their credit card details, give it their mother's maiden name, confirm address, upload a nude selfie, and only then realise that they've been had.</p> <p>The Internet works at pretty close to the speed of light. You can register a .uk domain and a minute later it's accessible from the other side of the planet. Brilliant for users who want to quickly launch a website. Also brilliant for abusers who want to launch a spam campaign.</p> <p>By the time enough people have reported the scammers' domain as suspicious, it is too late. In the time it takes for a registrar to disable the domain, or for its name to make its way to the <a href="https://safebrowsing.google.com/">Safe Browsing List</a>, a million messages have already been sent and enough people have handed over their details.</p> <p>We're told that "<a href="https://en.wikipedia.org/wiki/The_purpose_of_a_system_is_what_it_does">the purpose of a system is what it does</a>". At the moment, the Domain Name System's purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate.</p> <h2 id="how-big-is-this-problem"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#how-big-is-this-problem">How big is this problem?</a></h2> <p>BIG!</p> <p>There's a great blog post by Andrew Campling which reports on this startling claim:</p> <blockquote><p>The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors <strong>may be closer to 20%</strong>.</p> <p><a href="https://labs.ripe.net/author/andrew_campling/dns-abuse-and-criminal-infrastructure-beyond-definitions-and-blocklists/">DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists</a> (emphasis added)</p></blockquote> <p>That links to a presentation by Interisle which contains some rather shocking statistics (<a href="https://www.icann.org/en/blogs/details/looking-beyond-the-numbers-understanding-malicious-domain-registration-data-10-08-2026-en">albeit with disputed methodology</a>). It looks at <em>generic</em> Top Level Domains (gTLD) - those are things like .com and .fun rather than country code TLDs (ccTLD) like .uk and .de.</p> <p>It says 85 million new registrations of gTLDs were made in 2025. Of those 8.5 million were added to blocklists by May 2025. It reckons that a 10% abuse rate is the likely floor for these numbers and it's probably closer to 20%. One in five newly registered domains with a gTLD are scams. That's a bloody crisis.</p> <p>13 TLDs had more than 50% of their registrations blocklisted.</p> <img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/gTLDs.webp" alt="Table listing the top 13 generic Top-Level Domains (gTLDs) with the highest percentage of blocklisted, malicious new domains created in 2025. Ranked from highest to lowest blocklist percentage, top entries include .LOCKER (72.9%), .LGBT (72.2%), and .TOWN (70.2%). The table detail includes TLD operators, registration totals, and specific malicious domain metrics." width="1162" height="954" class="aligncenter"> <p>I can understand why .bid and .loan are popular with scammers. But why .mobi?! What did I ever do to you, eh?</p> <p>Who are the scammers registering these through?</p> <img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/registrars.webp" alt="List of registrars. NameCheap, Gname, Dynadot, NameSilo, GoDaddy." width="910" height="390" class="aligncenter"> <p>Ah, our old friends at NameCheap. See <a href="https://shkspr.mobi/blog/2021/05/why-do-scammers-love-namecheap/">Why do scammers love NameCheap?</a></p> <p>If those five registrars had more effective policies, it might significantly dent the scammers' ability to ply their devious wares. Or they might just move on to other registrars.</p> <p>As the report points out:</p> <blockquote><p>suspension rates for blocklisted domains were 7.4% to 16.3%.</p></blockquote> <p><a href="https://interisle.net/s/FullReport_MaliciousRegistrationsintheDomainNameMarket_2026_rev.pdf">The full report is on the Interisle website</a>.</p> <h2 id="what-can-be-done"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#what-can-be-done">What can be done?</a></h2> <p>I don't know.</p> <p>In the first instance, it might make sense for registrars to do strong Know Your Customer (KYC) checks on anyone buying a domain. But that stops anyone who wants to anonymously register <code>I-Hate-Nintendo.whatever</code> without risking the wrath of Intellectual Property lawyers.</p> <p>Also, criminals have access to stolen money and stolen cards. They can convince a hapless mule to register a domain on the criminals' behalf.</p> <p>Registrars could ask for an escrow payment. Pay €9 for the domain name put €900 in escrow. If your domain appears on a blocklist within the year, you forfeit the money. Criminals with stolen funds are unlikely to care but it would probably put off lots of people from getting a new domain.</p> <p>There are various banned words and phrases depending on the TLD. For example, <a href="https://shkspr.mobi/blog/2024/07/ss-tld-opening-for-direct-registrations/">South Sudan</a> has a list of political words which they don't want associated with their .ss ccTLD.</p> <p>But if one gTLD bans a word, a different one might not. A scammer doesn't care if the gTLD is .arse or .elbow - they just want the start of the domain to look legitimate.</p> <p>Some registrars have strings that they don't allow. In fairness to NameCheap, when I tried to register <code>dwp-payments-gov-uk.pizza</code> it told me that domain was banned. It wouldn't let me get any gTLD with that name.</p> <p>But all it takes is one registrar to be slightly lax and the scammers get through. Increasing the complexity of the rules is also a hell of a burden on smaller registrars.</p> <p>Besides, it's pretty easy to get a generic enough looking domain and stick the confusing bit on a subdomain. Here are a clutch mentioned in the report:</p> <ul> <li><code>https://gov.uk-dwpaph.bond/uk/</code></li> <li><code>https://gov.uk-dwpcjh.bond/uk/</code></li> <li><code>https://gov.uk-dwpclc.bond/uk</code></li> <li><code>https://gov.uk-dwpclw.bond/uk</code></li> <li><code>https://gov.uk-dwpclj.bond/uk/</code></li> </ul> <p>Perhaps there ought to be a delay before a new domain goes live to allow people to object to it? That would give governments, banks, delivery companies, and a dozen more "important" organisations a right to veto any "dodgy" looking domain.</p> <p>But suppose someone wants to register <code>gov-uk-stole-my-horse.horse</code> to protest the government's cruel policy of stealing horses - is that a legitimate use of a domain? What if the Darwin Pensioner Divas - a group of elderly singers - want to take payments for their new album of goth/punk covers, can the DPD delivery company veto <code>dpd-payments.music</code>?</p> <p>Do we want a domain name system where powerful companies control exactly which domains we can register? If I have an idea for a domain on a Friday night do I have to wait until Monday before it can be launched? Are those companies realistically able to parse millions of domains per year and have a low false-positive rate?</p> <p>All of these things are possible - but all of them come with an impact on legitimate users. To be clear, I don't know what the right answer is.</p> <h2 id="what-is-icann-doing-about-it"><a href="https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/#what-is-icann-doing-about-it">What is ICANN doing about it?</a></h2> <p>Lots! It has been a few years since I've been to an ICANN meeting, but even back then the topic of abuse was high on the agenda. They appear to be looking at ways to coordinate abuse reports between various entities, along with some other policies which should hopefully work.</p> <p>There are two salient points from <a href="https://hosted-files.sched.co/icann86/b3/TRANSC_I86SQV_Mon08June2026__GNSO-DNS%20Abuse%20Mitigation%20PDP%201%20%281%20of%204%29-en.pdf">one of the discussions held at the recent meeting</a></p> <blockquote><p>If anybody thinks that in our current age of AI and as we move into different kinds of computing, DNS abuse is going to numerically stay steady and we will have a downward effect on that baseline 2027 number. I'm not sure that that's an accurate assumption. I think it's going to be the other thing, which is […] it's going to be easier to abuse the DNS.</p></blockquote> <p>And</p> <blockquote><p>Abusers are going to abuse because it's just too lucrative, because no matter what we do, they will find the way to make profit off of that, and will try to circumvent everything that we do. That is not a reason not to do it, though.</p></blockquote> <p>Quite!</p> <p>As I said, I don't know the answer to this. What I do know is, much like <a href="https://shkspr.mobi/blog/2025/08/is-it-possible-to-allow-sideloading-and-keep-users-safe/">Android's app ecosystem being a haven for scammers</a>, DNS is facing a crisis. When trust in a system goes, only chaos follows.</p> <p>I don't want to live in a world where I have to show my passport and pay thousands of pounds to register a domain which is only available after being vetted by private interests. But I also don't want to live in a world where scammers have effectively no deterrent from abusing millions of people.</p> <p>The purpose of a system is what it does. I hope DNS's purpose can become less dangerous while still remaining open.</p> <img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=74588&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager"> Complements: Art history, writing - James' Coffee Blog https://jamesg.blog/2026/09/06/complements-art-history-writing 2026-09-06T00:00:00.000Z James' Coffee Blog <p>Earlier this week I was chatting with a friend about the skills I am learning from art history. One of the most influential concepts I have learned is to “look closely”. The idea is to spend time with a single thing – to study it closely – and think about what you see in more depth. This helped formalise an experience I was already having in galleries: I didn’t want to see every piece as fast as I could, rather I wanted to slow down.</p><p style="text-align: center;">⁂ ⁂ ⁂ </p><p>Galleries, and the works within them, feel as if they have a certain magnetism, that magnetism sometimes varying over time. For instance, I was recently fascinated by a work of still life painted in the National Gallery of Scotland. I don’t usually gravitate toward still life paintings, but on that day I wanted to explore them more: to spend time with a genre with which I was less familiar, and to see what I could see.</p><p>Similarly, there are paintings that, no matter how many times I look, I see something new and beautiful: paintings that I only need to see in the corner of my eye before I stop and know I have to go over and look at the work in more detail. This year, the painting that has caught my attention the most is Turner’s sunrise over Norham Castle. The colours are transfixing. The scene is beautiful. The art is infinitely intriguing. I must have spent at least half an hour over several visits looking at this painting, and longer thinking about it.</p><p>I am studying both art history and creative writing next year. This is perhaps not as common of a mix as, for example, English Literature and creative writing, but mixing the study of art history and the theory and practice of creative writing feels right to me.</p><p>I haven’t coalesced a complete vision of the complements between these two subjects but, today, as I write, I feel like the concept – and application – of looking closely lends itself well to both my studies in art and my writing. Art history has helped me look closely. In writing, I similarly need to look closely at the world and capture as many details as possible, everything I see in the rhythm of the world, in Nature, in cities, and everything I feel, being a potential detail to use in a story.</p><p style="text-align: center;">⁂ ⁂ ⁂ </p><p>Studying art has helped me refine my visual description skills. This starts with thinking about the artwork. The kinds of questions I may end up answering are things like: What do I see? What is the art about? How do I know? How is a work composed? How do different parts within a work of art relate? How does the work at which I am looking compare to others I have seen? As I think, I enjoy writing down what I see. Other times, I enjoy just looking at a work, knowing that I don’t need to write anything to get something out of the experience.</p><p>These visual description skills blend in with my writing: the more I know what to look out for, the more details I know that I can write down, and the better I can incorporate those details into my writing. This connects with my creative writing where details about what I see can be an integral part of both life writing (an introspective kind of writing, which I enjoy) and creative writing (poetry, fiction, and more). Using written descriptions of art as part of storytelling even has its own term: <a href="https://en.wikipedia.org/wiki/Ekphrasis">ekphrasis</a>.</p><p style="text-align: center;">⁂ ⁂ ⁂ </p><p>Art galleries have also helped me wander more: to slow down.</p><p>When I am in a gallery, I like to go towards whatever stands out, and spend time with it – to wander a room and see what works appeal to me, to get up close with a piece and spend time with it, to walk closer and further away from a piece to see what I see. In many cases, I can see specific places I have seen paintings, my memories of the spaces being so vivid. Perhaps this is because I like to slow down in galleries. <sup class="footnote-reference" id="f-1"><a href="https://jamesg.blog/longform-feed#1">1</a></sup></p><p>Slowing down complements the pace at which I write and code. When it comes to writing and coding, I am often moving quickly: capturing ideas on paper, thinking about and formalising logic in code. I am moving fast because I love making things. In contrast, studying art invites me to slow down. Indeed, one of the most delightful experiences in galleries is when I have been looking at a piece for a few minutes and I notice something new. It is delightful to feel the process of seeing new things as you spend more time with something.</p><p>I am excited for the next year of my studies as a time to refine my visual description skills, to learn more foundations of the history of art, and to see and feel how writing and art history combine for me.</p> <div class="footnote-definition" id="1"><sup class="footnote-definition-label" id="f-2">1</sup> <p>If you are curious, I am the sort of person who likes to diligently look at every piece one by one in an art gallery, moving through the space slowly. I like slowing down.</p> <a href="https://jamesg.blog/longform-feed#f-1">[↩]</a></div> <script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a36f92870baa2660',t:'MTc4ODcxOTcxNA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script> <a class="tag" href="https://en.wikipedia.org/wiki/Ekphrasis">ekphrasis</a> <a class="tag" href="https://jamesg.blog/longform-feed#1">1</a> <a class="tag" href="https://jamesg.blog/longform-feed#f-1">[↩]</a> Note published on September 5, 2026 at 3:19 PM UTC - Molly White's activity feed 6a9c32ec52b01ca28c3ff367 2026-09-05T15:19:08.000Z Molly White <article><div class="entry h-entry hentry"><header></header><div class="content e-content"><div class="quote"><blockquote>Other platforms will soon follow, a senior administration official told POLITICO on Tuesday. “We got Lake America changed on Google Maps, and many other maps are changing in a couple days. And Wikipedia is going to change as well,” said the official, who was granted anonymity to speak frankly.</blockquote></div><p>A Wikipedia editor put it well: "You almost want to pat them on the head and say 'Yes, of course it will' in the same way you'd tell a small child that Santa Claus will be delivering their presents."</p><div class="related-post"><div class="article h-cite hcite"><div class="title"><a class="u-url u-repost-of u-in-reply-to" href="https://www.politico.com/news/2026/09/02/tech-lake-ontario-01062631" rel="bookmark">“<span class="p-name">Trump's Lake America push forces tech to pick a side</span>”</a>. </div><div class="byline"><span class="p-author h-card">Owen Dahlkamp</span> in <i class="p-publication">Politico</i>. <span class="read-date"></span></div><blockquote class="summary p-summary entry-summary">Other platforms will soon follow, a senior administration official told POLITICO on Tuesday. “We got Lake America changed on Google Maps, and many other maps are changing in a couple days. And Wikipedia is going to change as well,” said the official, who was granted anonymity to speak frankly.</blockquote></div></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609051118"><time class="dt-published" datetime="2026-09-05T15:19:08+00:00" title="September 5, 2026 at 3:19 PM UTC">September 5, 2026 at 3:19 PM UTC</time>. </a></div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117219107071552031" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3murrlnufd22w" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/trump_administration" title="See all micro posts tagged "Trump administration"" rel="category tag">Trump administration</a>, <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/wikipedia" title="See all micro posts tagged "Wikipedia"" rel="category tag">Wikipedia</a>. </div></div></footer></div></article> Note published on September 5, 2026 at 3:05 PM UTC - Molly White's activity feed 6a9c2fb352b01ca28c3ff32e 2026-09-05T15:05:23.000Z Molly White <article><div class="entry h-entry hentry"><header></header><div class="content e-content"><p>Huge congratulations to the US-based Wikimedia Foundation employees who voted with 92% support in favor of unionizing, and shoutout to the tireless work of the organizers.</p><div class="related-post"><div class="article h-cite hcite"><div class="title"><a class="u-url u-repost-of u-in-reply-to" href="https://wikiworkersunited.org/announcements/2026-09-04-us-wikimedia-foundation-workers-overwhelmingly-vote-to-form-union-with-cwa/" rel="bookmark">“<span class="p-name">Wikimedia Foundation Workers Overwhelmingly Vote to Form Union with CWA</span>”</a>. </div><div class="byline"><span class="p-author h-card">Wiki Workers United</span> in <i class="p-publication">Wiki Workers United</i>. <span class="read-date"></span></div><blockquote class="summary p-summary entry-summary">U.S. workers form first recognized unit as global union movement builds across Wikimedia Foundation</blockquote></div></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp-block"><div class="timestamp">Posted: <a class="u-url" href="https://www.mollywhite.net/micro/entry/202609051104"><time class="dt-published" datetime="2026-09-05T15:05:23+00:00" title="September 5, 2026 at 3:05 PM UTC">September 5, 2026 at 3:05 PM UTC</time>. </a></div></div><div class="social-links"> <span> Also posted to: </span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117219043199374157" title="Mastodon" rel="syndication">Mastodon, </a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3murqsajyls2w" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/wikimedia" title="See all micro posts tagged "Wikimedia"" rel="category tag">Wikimedia</a>, <a class="tag p-category" href="https://www.mollywhite.net/micro/tag/workers_rights" title="See all micro posts tagged "workers' rights"" rel="category tag">workers' rights</a>. </div></div></footer></div></article> Book Review: The Passing of the Dragon and Other Stories by Ken Liu ★★★★☆ - Terence Eden’s Blog https://shkspr.mobi/blog/?p=74686 2026-09-05T11:34:47.000Z Terence Eden’s Blog <img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/9781035929306.webp" alt="Book cover." width="200" class="alignleft"> <p>This is a gorgeous set of short stories - and a good deal more accessible than some of the heavyweight prose Liu has previously been involved with. Some of the stories contain sentences which are complex jewels to be savoured.</p> <p>What I particularly like is the way he moves between almost-prosaic Earth-bound stories to the the most extraordinary flights of fancy. One story might be set in a downtown art gallery, the next in the ice-rings of a far-off planet. The creeping feeling of senescence haunts the reader as they flit from story to story.</p> <p>Much like his full-length novel <a href="https://shkspr.mobi/blog/2025/09/book-review-all-that-we-see-or-seem-by-ken-liu/">All That We See or Seem</a>, Liu has an incredible knack for tapping in to modern fears and weaving tall tales around them. There's a tenderness in all his character - even when a couple of the stories go nowhere, it is still pleasant to spend time in the worlds he has created.</p> <p>It is, perhaps, missing a cohesive theme - the dragons come and go throughout the stories. Nevertheless, a compelling work chock full of fantastical ideas.</p> <p>If you're in the mood for a wide and varied selection of stories, this is well worth picking up.</p> <p>Many thanks to NetGalley for the review copy. Passing of the Dragon is available to buy now.</p> <img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=74686&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager"> morning - James' Coffee Blog https://jamesg.blog/2026/09/05/morning-3 2026-09-05T00:00:00.000Z James' Coffee Blog <p>rabbits leaping, birds tweeting,<br/>the sun rising, hills welcoming,<br/>breeze blowing, paths winding,<br/>potential painting, colours calming:<br/>skies awakening, day breaking.</p><script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a365e60258622ca5',t:'MTc4ODYxODI3Ng=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script> Friendly names for private services using Headscale, CoreDNS and DNSimple - Posts feed https://www.coryd.dev/posts/2026/friendly-names-for-private-services-using-headscale-coredns-and-dnsimple 2026-09-04T20:44:00.000Z Posts feed <div class="e-content block-subcanvas"><p>When I started setting up private, self-hosted services one of the things I wanted to maintain was a pattern of friendly, human readable names to access them. I didn't want the overhead of bookmarking domains available via Tailscale's <a href="https://tailscale.com/docs/features/magicdns">MagicDNS</a> and I wanted real SSL certificates that were trusted and that clients wouldn't complain about.</p> <h1 id="the-tools">The tools</h1> <p>To accomplish this, I have <a href="https://dnsimple.com">DNSimple</a> managing the public zone (for things like this site, <a href="https://follow.coryd.dev/@cory">my Mastodon instance</a> and so forth).</p> <p>I have <a href="https://headscale.net/stable/">Headscale</a> set up as the control plane and I use Tailscale's apps to connect to it. It assigns addresses to each node, dictates what each node can reach and which resolver each uses for a given domain.</p> <p>I'm using <a href="https://coredns.io">CoreDNS</a> to map friendly names to mesh addresses:</p> <pre class="language-sh"><code class="language-sh">coryd.dev <span class="token operator">{</span> cache <span class="token number">300</span> hosts <span class="token operator">{</span> 100.xx.xx.xx music.coryd.dev 100.xx.xx.xx books.coryd.dev 100.xx.xx.xx photos.coryd.dev 100.xx.xx.xx git.coryd.dev fallthrough <span class="token operator">}</span> forward . 45.90.28.0 1.1.1.1 log errors <span class="token operator">}</span> </code></pre> <p><code>fallthrough</code> allows anything not defined above it in the hosts block to hit <code>forward</code>, returning the public answer.</p> <h1 id="connecting-things">Connecting things</h1> <p>Headscale distributes the resolver config to each client with the split DNS config looking like this:</p> <pre class="language-yaml"><code class="language-yaml"><span class="token tag">dns</span><span class="token punctuation">:</span> <span class="token tag">magic_dns</span><span class="token punctuation">:</span> <span class="token keyword">true</span> <span class="token tag">base_domain</span><span class="token punctuation">:</span> net.coryd.dev <span class="token tag">nameservers</span><span class="token punctuation">:</span> <span class="token tag">global</span><span class="token punctuation">:</span> - https://dns.nextdns.io/<profile> <span class="token tag">split</span><span class="token punctuation">:</span> <span class="token tag">coryd.dev</span><span class="token punctuation">:</span> - <span class="token number">100.</span>xx.xx.xx - <span class="token number">100.</span>xx.xx.xx </code></pre> <aside> <p>I'm using <a href="https://nextdns.io/?from=m56mt3z6">NextDNS</a> as my global resolver because NextDNS is awesome and it allows my network filters to remain in place.</p> </aside> <p>All members of the mesh route queries to <code>coryd.dev</code> through <code>CoreDNS</code> and send everything else upstream. I configure the mesh in the Tailscale client, connect and get access to everything.</p> <h1 id="certificates-you-can-trust">Certificates you can trust</h1> <p>Because everything here is private, <code>HTTP-01</code> challenges needed to obtain certs will fail. Thankfully, DNSimple supports <code>DNS-01</code>, which lets me prove domain ownership via a <code>TXT</code> record and obtain a wildcard cert (<code>*.coryd.dev</code>).</p> <p>On my Linux boxes I'm using <code>certbot</code> with the <code>dns-dnsimple</code> authenticator to write certs to <code>/etc/letsencrypt</code>. Caddy mounts this directory as read-only, has <code>auto_https</code> off and the file names are referenced explicitly. On my NAS, I'm running Caddy as a native binary with the DNSimple module handling the challenge.</p> <h1 id="breaking-things">Breaking things</h1> <p>Because I'm an idiot, I have the mesh running on the same domain CoreDNS resolves. If a client can't resolve a name, it can't connect to the mesh. I have a second instance of CoreDNS running on a separate server to mitigate this.</p> <p>If you're using MagicDNS, use separate subdomains. It'll refuse a base domain that's equal to, or a parent of, the control plane's hostname. The client would end up taking over the zone holding the server it needs. I used <code>mesh</code> and <code>net</code> as independent names.</p> <p>Point Docker's <code>dns</code> settings at the bridge address or you'll run into lookup delays with CoreDNS. CoreDNS listens on the mesh address, containers live on a bridge, so packets go in a loop, the resolver times out and then it tries the next resolver and succeeds.</p> <p>That CoreDNS binds to the mesh address created another issue — the address only appears after <code>tailscaled</code> registers with Headscale and Headscale is a container on the same host. I opened the socket first before the address was available by setting <code>net.ipv4.ip_nonlocal_bind = 1</code>.</p> <p>The other thing — the addresses behind these names spread out everywhere: they're in the Corefile, yes, but they're also in my ACL policy, port bindings, <code>extra_hosts</code>, <code>daemon.json</code> and deploy scripts, so documentation is crucial.</p> <hr/> <p>It works! It all works! So far, anyways. <em>Most</em> things I host are private and they have addresses I can remember. They have certificates so there are no complaints by clients and browsers when I access them. Better yet: if my family needs to access something, the address is intelligible. Adding a new subdomain is easy, changing the address tied to one is tedious given the myriad places they flow through.<sup id="fnref:1" class="footnote-ref">1</sup></p> <div class="footnotes" role="doc-endnotes"><hr/><ol><li id="fn:1"><p>There's probably a better way to do this, so <a href="https://www.coryd.dev/contact">enlighten me</a>. ↩︎</p> </li></ol></div></div> My phone number doesn't work anymore - Joel's Log Files https://joelchrono.xyz/blog/phone-number 2026-09-04T18:00:00.000Z joelchrono <p>Don’t worry, I can connect to Wi-Fi networks, I just lost mobile data access and phone calls with my current SIM chip.</p> <p>You see, the silly government of my beautiful country decided that the best way to stop scam, blackmail and other crimes via phone calls would be to force everyone into <a href="https://www.mexperience.com/all-mexico-cellphone-users-must-register/">registering their phone numbers</a> with their ID card and a face scan with the phone’s camera.</p> <p>A huge percentage of the population never did this on the original deadline and the plan utterly failed no phone company disabled any phone numbers because the monetary losses would be too much. So things were fine, at least for a little more time.</p> <p>They decided instead to give a different deadline to every phone number based on the last digit (0-9), a slower rollout that would make people more nervious, as the peer pressure would slowly build up. Since my phone ends with a 1, my line was deactivated on October 31st, 2026.</p> <p>Of course, I can still get my phone back, by doing the proper registration process, and everything would go back to normal in no time. But a part of me just doesn’t want that. I just don’t understand the need for this.</p> <p>First off, the criminals have already circumvented this, there are still scam calls, there are criminals who have registered phones on behalf of other people, this is doing absolutely nothing to actually stop crime.</p> <p>Then there’s the security of it all. We have no idea where that database is going, and as much as they promise that the face scan is a one-time thing that doesn’t get stored anywhere, we can’t actually be sure of it.</p> <p>This is honestly just messed up in many levels, but it’s also just ridiculous. It’s the government! They already have our IDs, they already could have all the data they want from us. Why exactly do they need another database for this? Some people even expose their numbers and address on their ID already.</p> <p>The registration process is also super badly implemented, and there’s people who have gotten around it with AI images and fake credentials, plus those using stolen information from other people and getting away with it. Seriously, it’s probably some vibecoded slop checker or something, I haven’t even bothered to open the page myself, I am just angry that it has to be like this.</p> <p>Ugh, this is also yet another form of surveillance isn’t it? Now that phones are directly linked to individuals (if the whole database and infrastructure works well), then that would mean any individual can easily be silenced by having their phone access blocked like this right? Just bad vibes everywhere.</p> <p>Our only hope is that telecommunication companies are still losing a lot of money, with people that are not paying their phone plans anymore and maybe realizing that they don’t even need a phone line at all nowadays.</p> <p>Many individuals are happily making phone calls via Wi-Fi with WhatsApp (I know, I know, but it’s how it’s) and other messaging apps, without relying on their SIM chip.</p> <p>Personally, since I have a work phone that was registered by my company, I simply use that as a hotspot and stay communicated with it when necessary.</p> <p>Look, I am super angry, but if more people start to register their phone I may have to give it up and register my face on their silly database that is probably stored in a publicly accesible AWS bucket or whatever. Who cares at this point?</p> <p>It will be one more of the many <a href="/blog/confessions-from-a-linux-user/">silly things</a> <a href="/blog/more-confessions-from-a-foss-enthusiast/">I do</a> despite being a privacy/FOSS/tech enthusiast, I guess.</p> <p>This is day 29 of <a href="https://100DaysToOffload.com">#100DaysToOffload</a></p> <p> <a href="mailto:me@joelchrono.xyz?subject=My phone number doesn't work anymore">Reply to this post via email</a> | <a href="https://fosstodon.org/@joel/idcomments">Reply on Fediverse</a> </p> New Design for Sept 2026 - Kev Quirk https://kevquirk.com/new-design-for-sept-2026 2026-09-04T16:19:00.000Z Kev Quirk <p>I decided I was bored with the previous design, but wanted something that was in keeping with the previous design (brutalist and using a monospace font) yet different.</p> <p>I abandoned the yellow accent and went back to blue, my favourite colour. I also changed the font to Victor Mono.</p> <p>I like how the new design draws from different versions of the site's history - lots of neo-brutalist design, clean colours and font, plus a bit of whimsy. If you're reading this via RSS, here's what the new design of the site looks like (although I'd recommend you head to the site and experience it properly):</p> <p><img loading="lazy" src="https://kevquirk.com/content/images/new-design-for-sept-2026/sept-2026-light.webp" alt="sept-2026-light" /></p> <p><img loading="lazy" src="https://kevquirk.com/content/images/new-design-for-sept-2026/sept-2026-dark.webp" alt="sept-2026-dark" /></p> <p>I love how <a href="https://pureblog.org" rel="noopener noreferrer">Pure Blog</a> makes it so easy to change things like this. All I really did was pick a new colour palette, then add some custom CSS. The rest is all default Pure Blog, pretty much.</p> <p>Hope you like the new lick of paint!</p> <div class="email-hidden"> <hr /> <p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p> <p>You can <a href="mailto:19gy@qrk.one?subject=New%20Design%20for%20Sept%202026">reply to this post by email</a>, or <a href="https://kevquirk.com/new-design-for-sept-2026#comments">leave a comment</a>.</p> </div> Weeknote #2016 - Robb Knight • Posts • Atom Feed https://rknight.me/blog/weeknote-2016-v2/ 2026-09-04T08:22:00.000Z Robb Knight <p>Our St Jude Fundraiser has blasted past $5k, and I had to make a an Obsidian base to keep track of all the drawings I need to do. The <a href="https://rknight.me/blog/drawing-for-st-jude-petrichor/">first one arrived yesterday</a> and if you want one for yourself there's one slot left right now. You can <a href="/stjude">donate here</a>.</p> <p>Thanks to Melanie pointing it out, I fixed a bug in <a href="https://lens.rknight.me">Lens</a> where it would catch SVG <code>title</code> elements when it shouldn't.</p> <p>It’s not for me but the detail on this <a href="https://www.lego.com/en-gb/product/wallace-gromit-21371">Wallace and Gromit set</a> is fantastic.</p> <p>Matt <a href="https://mattstein.com/thoughts/ulanzi-d100h/">reviewed the Ulanzi D100H</a>. I love buttons and knobs.</p> <p><a href="https://chrisburnell.com/ipb-badge-generator/">This project by Chris</a> generates an <a href="https://internetphonebook.net/">Internet Phone Book</a> 88x31 badge for you. I had my own version I'd made but the animated one from here is way better so I swapped it out.</p> <p>There's a <a href="https://w3c.github.io/webappsec-change-password-url/">proposal</a> for a <code>.well-known</code> URL for changing passwords which seems so obvious now I see it.</p> <p><a href="https://nate.spot/short-story-in-five-sentences/">How to write a short story in five sentences</a> — it does exactly what it says it will and nothing more.</p> <p>There is nothing better than a pencil manufacturing video and <a href="https://www.youtube.com/watch?v=fow-LsdaH2E">this one about how Blackwings</a> are made is great.</p> <p>An <a href="https://social.lol/@daveycraney/117202205701613704">art gallery using a slop poster</a> is so stupid I can't even.</p> <p>Terence Eden has a post about <a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/">verifying ActivityPub signatures</a> which was a colossal ballache when I did it previously.</p> <p><a href="https://anthonyhobday.com/sideprojects/saferules/">Visual design rules you can safely follow every time</a>. I love articles like this with simple and understandable actions I can take to make my sites better.</p> autumn, winter - James' Coffee Blog https://jamesg.blog/2026/09/04/autumn-winter 2026-09-04T00:00:00.000Z James' Coffee Blog <p>colours shimmering,<br/>sun lowering.</p><p>leaves leaving,<br/>seasons deepening.</p><p>trees lightening:<br/>branches preparing.</p><p>winds cooling,<br/>time wintering.</p><p><em>I wrote this poem with reference to a series of key words in the first edition of </em><a href="https://www.etsy.com/listing/1794798589/go-offline-zine-print-at-home-booklet" rel="noreferrer"><em>Planet Persephone's Go Offline zine</em></a><em>. I used "lightening", "time", "shimmer", "colour", "deep", "leaves", "wind", and "winter".</em></p><script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a35be817b8526e6f',t:'MTc4ODUxMzUwMw=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script> <a class="tag" href="https://www.etsy.com/listing/1794798589/go-offline-zine-print-at-home-booklet">Planet Persephone's Go Offline zine</a> 2026-09-03 14:47: Why do so many calendar apps offer Sunday as the first day of the week?... - Kev Quirk https://kevquirk.com/2026-09-03-1447 2026-09-03T13:47:00.000Z Kev Quirk <p>Why do so many calendar apps offer Sunday as the first day of the week? It's <strong>not</strong> the first day of the week, it's the last.</p> <p>Why is that even an option FFS?</p> <div class="email-hidden"> <hr /> <p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p> <p>You can <a href="mailto:19gy@qrk.one?subject=2026-09-03%2014%3A47">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-09-03-1447#comments">leave a comment</a>.</p> </div> A reasonably practical guide to validating RFC 9421 HTTP Signatures for ActivityPub in PHP - Terence Eden’s Blog https://shkspr.mobi/blog/?p=74429 2026-09-03T11:34:12.000Z Terence Eden’s Blog <p>If you're reading this, you've probably been hitting your head against a brick wall trying to parse and decipher the new HTTP Signatures sent by Mastodon and other Fediverse servers.</p> <p>This is a basic and somewhat incomplete guide to accepting these signatures. I'm sure there are various gotchas, but it works with the signatures I've seen in the wild.</p> <h2 id="shut-up-and-show-me-the-code"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#shut-up-and-show-me-the-code">Shut Up And Show Me The Code!</a></h2> <p>OK, wow, no need to be a dick about it! Here's how I validated a real signature that my server received.</p> <pre><code class="language-php">$verified = openssl_verify( data: '"@method": POST "@target-uri": https://example.viii.fi/inbox "content-digest": sha-256=:tFdB/ENGczHMlZMDb66pXoUi2d0OqH2iBHdnN/WV1mc=: "@signature-params": ("@method" "@target-uri" "content-digest");created=1787780262;keyid="https://mastodon.social/users/Edent#main-key"', signature: base64_decode( "sIfmNsM/Q8iG6AJlne1IkZVjQSVFDEYIPsnoSOXQY+W3Eb4+SOn9o4J5SQmFOP+Jecjf3ioFwUdsrFjAGkUUOHPvSbNWkGKtNuGm+C6r3aI3JBCFGPqX3ITgZYV76CF7JJJ5hPGaG8YH/XdmxVIeFfD3M39FQCncMyyq7xJJvwKKP1mzS5s1vNQie8hbQ9owRjtqvoWcmM9GEYCUHNcMPLjZc+CBrj8sfBbNTYgIFI4UtirOaRJvYymxXjmXuzeVYxQujMjAjgobxQ8QFv0zlYsHk+gS5EYyafpJG9zmfCFSoF9+ZwqKNADmuADbISD9LZIH/bmkPoNXhxaeFPqYog==" ), public_key: "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsYMEs4waqk/6gaS+xn1T\nYygElTtNIFNkBcEdEBMaeoGVhyZiVKtSjJCS4z+X+394PKvcfSTcFILIt2GI2jOB\nHD0M2fFgxc8mmdSdCQkgEh9jF3bFI3kopDvzYf726iioYKlHXKpfPKvFt7EJgKH7\naCtS25NQkek3YUd6y3VBcT3R6Xhze9P3QNoZMIsFXklgXDKj+EllfbUqLf1vxt3s\nmD9ETxy2bJi9FheE0uY2WhARn49XAvwczM5Wzt+zqxVEtgpi5v2+ZZAVKhDnJkiC\nCCuI6hrSnKNIx/5mSlX0a0S5h5d03djrCkYsqmwelu01rhOXP2grsz4BXp0y2wrO\n3QIDAQAB\n-----END PUBLIC KEY-----\n", algorithm: "sha256" ); echo $verified; </code></pre> <p>Copy and paste that into PHP and you should see that <code>$verified</code> is true.</p> <h2 id="now-explain-the-code"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#now-explain-the-code">NOW EXPLAIN THE CODE</a></h2> <p>Say please.</p> <h2 id="please"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#please">PLEASE!!!</a></h2> <p>Along with the message sent to your server, you will have received HTTP headers like this:</p> <pre><code class="language-_">content-digest: sha-256=:tFdB/ENGczHMlZMDb66pXoUi2d0OqH2iBHdnN/WV1mc=: signature: sig1=:sIfmNsM/Q8iG6AJlne1IkZVjQSVFDEYIPsnoSOXQY+W3Eb4+SOn9o4J5SQmFOP+Jecjf3ioFwUdsrFjAGkUUOHPvSbNWkGKtNuGm+C6r3aI3JBCFGPqX3ITgZYV76CF7JJJ5hPGaG8YH/XdmxVIeFfD3M39FQCncMyyq7xJJvwKKP1mzS5s1vNQie8hbQ9owRjtqvoWcmM9GEYCUHNcMPLjZc+CBrj8sfBbNTYgIFI4UtirOaRJvYymxXjmXuzeVYxQujMjAjgobxQ8QFv0zlYsHk+gS5EYyafpJG9zmfCFSoF9+ZwqKNADmuADbISD9LZIH/bmkPoNXhxaeFPqYog==: signature-input: sig1=("@method" "@target-uri" "content-digest");created=1787780262;keyid="https://mastodon.social/users/Edent#main-key" </code></pre> <p>The <code>signature-input</code> tells you how to construct a "Signature Base". You have to build a text string which places the various components in the order specified and separated with a newline:</p> <pre><code class="language-_">"@method": POST "@target-uri": https://example.viii.fi/inbox "content-digest": sha-256=:tFdB/ENGczHMlZMDb66pXoUi2d0OqH2iBHdnN/WV1mc=: "@signature-params": ("@method" "@target-uri" "content-digest");created=1787780262;keyid="https://mastodon.social/users/Edent#main-key" </code></pre> <p>Where <code>@method</code> is the HTTP method used to send data to your server (usually <code>GET</code> or <code>POST</code>), and <code>@target-uri</code> is the URl the message was sent to (usually your inbox).</p> <p>The <code>publicKey</code> is slightly trickier. As you can see, the <code>signature-input</code> ends with <code>keyid="https://mastodon.social/users/Edent#main-key</code></p> <p>If you make a signed request to that URl, you'll get back an ActivityPub Actor document. It will look something like this:</p> <pre><code class="language-json">{ "@context": [ "https://www.w3.org/ns/activitystreams", "https://w3id.org/security/v1", ], "id": "https://mastodon.social/users/Edent", "webfinger": "Edent@mastodon.social", "type": "Person", "name": "Terence Eden", "publicKey": { "id": "https://mastodon.social/users/Edent#main-key", "owner": "https://mastodon.social/users/Edent", "publicKeyPem": "-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsYMEs4waqk/6gaS+xn1T\nYygElTtNIFNkBcEdEBMaeoGVhyZiVKtSjJCS4z+X+394PKvcfSTcFILIt2GI2jOB\nHD0M2fFgxc8mmdSdCQkgEh9jF3bFI3kopDvzYf726iioYKlHXKpfPKvFt7EJgKH7\naCtS25NQkek3YUd6y3VBcT3R6Xhze9P3QNoZMIsFXklgXDKj+EllfbUqLf1vxt3s\nmD9ETxy2bJi9FheE0uY2WhARn49XAvwczM5Wzt+zqxVEtgpi5v2+ZZAVKhDnJkiC\nCCuI6hrSnKNIx/5mSlX0a0S5h5d03djrCkYsqmwelu01rhOXP2grsz4BXp0y2wrO\n3QIDAQAB\n-----END PUBLIC KEY-----\n" }, </code></pre> <p>The <code>publicKeyPem</code> is the string you need. There's no need to convert the <code>\n</code> to literal newlines.</p> <h2 id="is-that-it"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#is-that-it">Is that it?</a></h2> <p>Not quite! All we've done so far is verify the headers. It is possible that these are genuine headers but attached to a fraudulent body.</p> <p>This takes us back to the header <code>"content-digest": sha-256=:tFdB/ENGczHMlZMDb66pXoUi2d0OqH2iBHdnN/WV1mc=:</code></p> <p>That says that the body of the message sent has a Base64 encoded SHA256 hash of <code>tFdB/ENGczHMlZMDb66pXoUi2d0OqH2iBHdnN/WV1mc=</code>.</p> <p>To calculate your own content digest in PHP:</p> <pre><code class="language-php">$digestCalculated = base64_encode( hash( algo: "sha256", data: $body, binary: true ) ); </code></pre> <p>Does your digest match the one sent along with the headers? If not, something dodgy is going on.</p> <h2 id="putting-it-all-together"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#putting-it-all-together">Putting it all together</a></h2> <p>The steps are:</p> <ol> <li>Get the headers.</li> <li>Get the body.</li> <li>From the headers' <code>content-digest</code> extract the algorithm and hash.</li> <li>Using the body, calculate your own hash using the algorithm from <code>content-digest</code>.</li> <li>Does your hash match the sent hash? If not, stop. If so, proceed.</li> <li>From the headers' <code>signature</code> extract the base64 encoded signature.</li> <li>From the headers' <code>signature-input</code> extract the signature-input string.</li> <li>From the signature-input string extract the order of the Signature Base.</li> <li>Construct the Signature Base.</li> <li>From the signature-input string extract the keyid.</li> <li>Get the Public Key from the keyid.</li> <li>Use <code>openssl_verify()</code> to verify the Signature Base and the base64 decoded signature, against the Public Key using SHA256.</li> </ol> <p>Note, <a href="https://docs.joinmastodon.org/spec/security/#http-message-signatures">Mastodon <em>only</em> uses SHA256</a>. I think it should explicitly say which algorithm it is using <a href="https://github.com/mastodon/mastodon/issues/29905#issuecomment-5440336919">and have raised the issue</a>.</p> <h3 id="in-code-form"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#in-code-form">In Code Form</a></h3> <p>This is how you do it in PHP. Please read this carefully as there are some hard-coded assumptions.</p> <pre><code class="language-php"><?php // Validate the Digest. // It is the hash of the raw input string, in binary, encoded as base64. // The format is content-digest => <algorithm>=:<base64 encoded hash>: $digestString = $headers["content-digest"]; // The Base64 encoding may have multiple `=` at the end. So split this at the first `=`. $digestData = explode( separator: "=", string: $digestString, limit: 2 ); // Hashes are in lowercase, but have a `-` in their name. // This is not what hash_algos() expects. $digestAlgorithm = str_replace( search: "-", replace: "", subject: $digestData[0] ); // The hash is surrounded by `:` characters. $digestHash = str_replace( search: ":", replace: "", subject: $digestData[1] ); // Check if the hash algorithm is one known about to PHP. // If not, reject and record an error. if ( !in_array( needle:$digestAlgorithm, haystack: hash_algos() ) ) { return false; } // Manually calculate the digest based on the data sent. $digestCalculated = base64_encode( hash( algo: $digestAlgorithm, data: $input, binary: true ) ); // Does our calculation match what was sent? if ( !( $digestCalculated == $digestHash ) ) { return false; } // The signature format is signature => <signature name>=:<base64 encoded hash>: $signatureString = $headers["signature"]; // The Base64 encoding may have multiple `=` at the end. So split this at the first `=`. $signatureData = explode( separator: "=", string: $signatureString, limit: 2 ); $signatureName = $signatureData[0]; // The signature is surrounded by `:` characters. $signatureB64 = str_replace( search: ":", replace: "", subject: $signatureData[1] ); // The signature-input format is complicated! $signatureInputString = $headers["signature-input"]; // Get the parameters. Assume there is only one signature. $signatureParamsString = explode( separator: "=", string: $signatureInputString, limit: 2 )[1]; // Get the different elements of the signature. $signatureInputData = explode( separator: ";", string: $signatureInputString ); // Construct the data. $signatureInput = []; foreach( $signatureInputData as $signatureInputParts ) { $partsData = explode( separator: "=", string: $signatureInputParts ); // Strip quotes from keyid and parentheses from sig1. if ( "keyid" == $partsData[0] ) { $partsData[1] = str_replace( search: "\"", replace: "", subject: $partsData[1] ); } if ( $signatureName == $partsData[0] ) { $partsData[1] = str_replace( search: ["(", ")"], replace: "", subject: $partsData[1] ); } $signatureInput[ $partsData[0] ] = $partsData[1] ; } $signatureStructure = $signatureInput[$signatureName]; $signatureKeyID = $signatureInput["keyid"]; // Remove quotes. $signatureStructure = str_replace( search: "\"", replace: "", subject: $signatureStructure ); $signatureStructureData = explode( separator: " ", string: $signatureStructure ); // https://www.rfc-editor.org/info/rfc9421/#section-2.5 $signatureBase = ""; foreach ( $signatureStructureData as $signatureStructureParts ) { if ( "@method" == $signatureStructureParts ) { // https://www.rfc-editor.org/info/rfc9421/#name-method $signatureBase .= "\"@method\": " . strtolower( $_SERVER["REQUEST_METHOD"] . "\n" ); } if ( "@target-uri" == $signatureStructureParts ) { // https://www.rfc-editor.org/info/rfc9421/#section-2.2.2 // Change the domain name to your own. $signatureBase .= "\"@target-uri\": https://EXAMPLE.COM" . $_SERVER["REQUEST_URI"] . "\n"; } if ( "content-digest" == $signatureStructureParts ) { $signatureBase .= "\"content-digest\": $digestString\n"; } } // https://victoronsoftware.com/posts/http-message-signatures/#how-the-signature-is-created $signatureBase .= "\"@signature-params\": $signatureParamsString"; // Get the signing user's public key. // This is usually in the form `https://example.com/user/username#main-key` // This is to differentiate if the user has multiple keys. // This may need to be a signed request. You will need to write your own getDataFromURl() function to get the sending user's key. $userData = getDataFromURl( $signatureKeyID ); $publicKey = $userData["publicKey"]["publicKeyPem"]; // Verify the request $verified = openssl_verify( data: $signatureBase, signature: base64_decode( $signatureB64 ), public_key: $publicKey, algorithm: $digestAlgorithm ); // Convert the result to boolean. if ( $verified === 1 ) { $verified = true; } elseif ( $verified === 0 ) { $verified = false; } else { $verified = null; } return $verified; </code></pre> <h2 id="further-reading"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#further-reading">Further Reading</a></h2> <ul> <li><a href="https://www.rfc-editor.org/info/rfc9421/">RFC 9421 HTTP Message Signatures</a></li> <li><a href="https://victoronsoftware.com/posts/http-message-signatures/">Understanding HTTP message signatures: A developer's guide</a></li> <li><a href="https://www.otoroshi.io/docs/tutorials/http-message-signatures-rfc9421/">Sign and verify HTTP messages (RFC 9421)</a></li> <li><a href="https://darutk.medium.com/verification-of-http-message-signatures-501bbdc7dfec">Verification of HTTP Message Signatures</a></li> <li><a href="https://github.com/macgirvin/HTTP-Message-Signer">HTTP-Message-Signer in PHP</a></li> </ul> <h2 id="thanks-to-nlnet"><a href="https://shkspr.mobi/blog/2026/09/a-reasonably-practical-guide-to-validating-rfc-9421-http-signatures-for-activitypub-in-php/#thanks-to-nlnet">Thanks to NLnet</a></h2> <p>This blog post was funded in part by the work I'm doing for my NLnet NGI0 grant. Thanks!</p> <p><a href="https://nlnet.nl/project/ActivityBot/"><img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/NGI-logos.webp" alt="NLnet logo." width="900" height="200" class="aligncenter"></a></p> <img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=74429&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager"> Drawing for St Jude: Petrichor - Robb Knight • Posts • Atom Feed https://rknight.me/blog/drawing-for-st-jude-petrichor/ 2026-09-03T10:48:36.000Z Robb Knight <p>If you missed it, Adam and I are raising money for St Jude this month and you can <a href="/stjude">donate here</a>. One of the rewards I offered this year <a href="http://localhost:8084/blog/get-okay/">and last</a> is I will do a drawing of whatever the donator wants. These vary from the very simple "a horse" to the detailed like "a platypus on a unicycle in Japan at night". <a href="http://georgeprobably.omg.lol/">George</a> ordered one with this in the notes:</p> <blockquote> <p>Did you know, petrichor is "the smell of dirt after rain"? It's a pleasant smell that indicates that life is returning. Like Spring, but your smell. What's your petrichor?</p> </blockquote> <p>I don't think I'd ever heard of "petrichor" but it's nice to learn things. Not only is George making me draw he's making me think which is pretty rude. After a bit of clarification I thought on this for a day or two about what smell makes me the most happy it's Marmite on crumpets, no contest.</p> <figure><img src="https://cdn.rknight.me/site/2026/st-jude-drawings-petrichor.jpg" alt="A drawing of a plate of crumpets with a jar of marmite next to it" /></figure> Morning impressions - James' Coffee Blog https://jamesg.blog/2026/09/03/morning-impressions 2026-09-03T00:00:00.000Z James' Coffee Blog <p>Opening the window, a vivid dancing shadow of the trees between the glass and the sun appears the wall, illuminating yesterday’s ideas written across my whiteboard. The shadow is a temporary, moving work of art, detailing the contours of leaves and, when I stand in front, the stray hair from my head still unbrushed from having woken up half an hour prior. As the minutes pass, the impression of the trees becomes hazier, more abstract: the sun is moving. The limited conditions that made the art possible fade by the minute.</p><p>I think of all the possibilities of morning: of the songs to be sung by the birds – on the forefront of my mind as I hear the soothing, familiar call of a pigeon outside – and the way the light wakens both outside and inside. The artwork is intensifying again; perhaps one of the clouds outside was obscuring it temporarily. The trees once again dance, moving with the September wind. I stop and notice a faint breeze coming from the window; I, too, feel the September breeze, a cooling touch after a warm summer.</p><p>I take a sip of my warm tea whose temperature contrasts with the cool air outside, and, a moment later, look out the window, seeing amber leaves and rainy roads, and the peace of morning – essences of Day. I look forward to the day ahead.</p><script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a352f447cee666d1',t:'MTc4ODQxOTYzMQ=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script> fishing - James' Coffee Blog https://jamesg.blog/2026/09/03/fishing 2026-09-03T00:00:00.000Z James' Coffee Blog <p>trees and canopies<br/>shelter for the fisherman<br/>stoic as a river: he is still<br/>in movement<br/>engaged like a painter<br/>watching the moment.</p><p><em>This poem was inspired by Jules-Louis Dupré's "</em><a href="https://www.nationalgallery.org.uk/paintings/jules-louis-dupre-willows-with-a-man-fishing" rel="noreferrer"><em>Willows, with a Man Fishing</em></a><em>".</em></p> <a class="tag" href="https://www.nationalgallery.org.uk/paintings/jules-louis-dupre-willows-with-a-man-fishing">Willows, with a Man Fishing</a>