Shellsharks Blogroll - BlogFlockhttps://blogflock.com/list/xJ8yq2026-10-05T05:39:54.000ZBlogFlockshellsharksMCP server 'move in' is live - Johnny.Decimalhttps://johnnydecimal.com/blog/0255-mcp-move-in-service/2026-10-05T05:39:54.000ZJohnny.Decimal<p>Speaking of MCP servers, <a href="https://johnnydecimal.com/jdhq/mcp-server">our server</a> now has a 'move in' service. Just ask it to help you move in to the <a href="https://johnnydecimal.com/las">Life Admin</a> or <a href="https://johnnydecimal.com/sbs">Small Business</a> systems and it'll do that. You need at least a Pro account.</p>
<p>It's hard to test this sort of thing without having a bunch of mess to organise. As you might imagine, my laptop's pretty neat. But testing on a realistic sample data set is kinda mind-blowing. It's <em>really good</em>.</p>
<p>Here's a <a href="https://youtu.be/XTGbKJUMmvw">rough-cut video</a> showing the process. This is all in active development, so there's lots more to come.</p>
<div class="youtube-embed" data-astro-cid-nizrgmoa=""> <iframe src="https://www.youtube-nocookie.com/embed/XTGbKJUMmvw" title="Your mess, organised by AI, in an afternoon" loading="lazy" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" referrerpolicy="strict-origin-when-cross-origin" data-astro-cid-nizrgmoa=""></iframe> </div>Life Admin MCP access now requires a Pro account - Johnny.Decimalhttps://johnnydecimal.com/blog/0254-mcp-las-gated-to-pro/2026-10-05T04:18:25.000ZJohnny.Decimal<p>I launched the <a href="https://johnnydecimal.com/jdhq/mcp-server">MCP server</a> in August, and it's proved <em>very</em> popular. So popular, it's a problem – because it costs me money to run. It isn't a fortune, but the impact of the extra compute on my hosting bill isn't zero, nor is my time to keep it all working.</p>
<p>Previously a <a href="https://johnnydecimal.com/products"><strong>Personal</strong></a> account meant you could use the MCP server with your agent to ask it questions about the <a href="https://johnnydecimal.com/las">Life Admin System</a>, and have it download and install your system. Those things now require a <a href="https://johnnydecimal.com/products"><strong>Pro</strong></a> account.</p>
<p>With a <strong>Personal</strong> account, you get the Life Admin System and the same <a href="https://johnnydecimal.com/documentation#utilities">free open-source utilities</a> available to anyone. So your AI agent can still read your local files and JDex (augmented by my <a href="https://johnnydecimal.com/documentation/agent-skills">skills</a>) and help you manage your system. It can still read the site documentation via the MCP server or by <a href="https://johnnydecimal.com/documentation/your-llm-can-read-this-website">appending <strong>.md</strong> to any URL</a>.</p>
<p>With a <strong>Pro</strong> account, you get this plus full MCP server access, API access, 20+ hours of video at Johnny.Decimal University, and soon the Mac app I'm developing.</p>
<p>This is much simpler and easier to explain. <a href="https://johnnydecimal.com/jdhq">JDHQ</a> now means 'software and server features that cost money'. <a href="https://johnnydecimal.com/jdu">Johnny.Decimal University</a> means 'all our video training'. You get them both with <strong>Pro</strong>. Clean.</p>
<p>A <strong>Pro</strong> account is how you support us. It's how two people are able to work on this full time. We keep adding value to it: it started out as the <a href="https://johnnydecimal.com/jdu/workshop">Workshop</a>. Then we added the 5-hour <a href="https://johnnydecimal.com/jdu/taskpm">Task and Project Management</a> course. Then the MCP server, and soon an app. All provided to existing members, all for no additional cost.</p>
<p>I hope that's okay. Thanks for understanding.</p>
<p>– j.</p>
Kodak Charmera Review
- Robb Knight • Posts • Atom Feedhttps://rknight.me/blog/kodak-charmera-review/2026-10-04T19:43:52.000ZRobb Knight<p><a href="https://ruminatepodcast.com/217/">Over a year ago</a> I bought a Kodak Charmera keyring mini camera; it's a tiny little camera that takes photos at 1440x1080 and I was lucky enough to get the best design. It's taken me until now to actually try it out at <a href="https://www.forestryengland.uk/alice-holt-forest">Alice Holt forest</a> today — we went because they have <a href="https://www.forestryengland.uk/alice-holt-forest/gruffalo-sculptures-alice-holt">Gruffalo sculptures</a> and the Knightlings are obsessed.</p>
<figure><img src="https://cdn.rknight.me/site/2026/kodak-chamera-size-comparison.jpg" alt="A small keyring camera next to a toy car and a sharpie" /><figcaption>Here it is compared to a Renault 5 and a Sharpie</figcaption></figure>
<p>The photos are about as good as I expected which is not good at all but it is a fun camera to use. I think I'll stick with the Camp Snap.</p>
<blockquote>
<p>A mouse took a stroll though the deep dark wood,<br />
The mouse took photos with his Kodak Charmera and they were not good.</p>
</blockquote>
<figure><img src="https://cdn.rknight.me/site/2026/kodak-chamera-mouse.jpg" alt="A wooden sculture of the mouse from The Gruffalo book" /></figure>
<figure><img src="https://cdn.rknight.me/site/2026/kodak-chamera-gruffalos-child.jpg" alt="A wooden sculture of the Gruffalo's child" /></figure>
<figure><img src="https://cdn.rknight.me/site/2026/kodak-chamera-baby-knight.jpg" alt="A child holding a pink camera in front of their face" /></figure>Would You Like to Write to Me? - Kev Quirkhttps://kevquirk.com/would-you-like-to-write-to-me2026-10-04T15:17:00.000ZKev Quirk<p>I <em>really</em> enjoy writing. Not typing - <strong>writing</strong>. With a fountain pen on good quality paper. I find the whole process cathartic; putting pen to paper demands far more use of my grey matter than hammering away at a keyboard.</p>
<p>I mentioned in a <a href="https://kevquirk.com/its-never-too-late-to-learn">recent post</a> that when I finished an English course many years ago, I was hunting for creative reasons to type. Similarly, over the last 6 months or so I've gotten into fountain pens, and now I'm looking for ways to <em>write</em> creatively.</p>
<p>I thought about handwriting some text then scanning/photographing it to publish it here, but that feels too convoluted. Plus, I feel like writing with a pen is more of a personal endeavour.</p>
<p>Then it struck me - <em>why not get a few pen pals!</em></p>
<p>So I'm throwing this out into the wild - <strong>does anyone fancy exchanging letters with me?</strong></p>
<p>The only real requirement is that you can read and write in English (sadly, it's the only language I speak). I'm looking for perhaps 3–5 people to swap letters with. Naturally, we'll need to share postal addresses so we can send our prose back and forth.</p>
<p>There’s zero pressure when it comes to frequency, either. Just write back whenever life allows. If a month or so passes without hearing from you, no hard feelings. I'll just assume our correspondence has naturally run its course.</p>
<p>If you're interested, please fill out the short form linked below. Since I can only manage 3–5 pen pals, submitting the form doesn't guarantee we'll write, but if we seem like a good match and share common ground, I'll reach out by email to swap details and get things going.</p>
<p class="notice warning"><strong>I won't be publishing these letters online - these are purely offline, private conversations. I'd ask that you keep them private, too.</strong></p>
<p>If you prefer not to use Google Forms, feel free to <a href="https://kevquirk.com/contact">email me</a> with the following:</p>
<ul>
<li>Your name</li>
<li>Preferred email address</li>
<li>Which country/city you live in</li>
<li>A little bit about yourself and why you want to write to me</li>
<li>Some topics you'd like to discuss</li>
</ul>
<p><a class="button" href="https://forms.gle/dLyhTzCFmeF1tDc26" target="_blank">Sign up to become a Pen Pal</a></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Would%20You%20Like%20to%20Write%20to%20Me%3F">reply to this post by email</a>, or <a href="https://kevquirk.com/would-you-like-to-write-to-me#comments">leave a comment</a>.</p>
</div>My Pitch for the New Season of Doctor Who - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=727022026-10-04T11:34:50.000ZTerence Eden’s Blog<p>With the news that <a href="https://www.bbc.co.uk/commissioning/news/doctor-who-invitation-to-tender-september-2026/">the BBC are tendering for a new series of Doctor Who</a>, I thought I'd write down what I want from the show. This is, to be fair, pure fan-service wankery with zero chance of being made. I've based it on the oft-made observation that Hollywood is obsessed with remaking successful films rather than trying to remake unsuccessful ones.</p>
<p>Do we really need another Spider-Man origin story? No. Do we need the umpteenth remake of "The Italian Job"? Boring! Why don't producers take a film which was <em>nearly</em> a hit and see if a better director, crew, and cast can make it into something magical?</p>
<p>Let's apply the same thinking to Doctor Who.</p>
<!--
👋👋👋👋👋👋👋👋👋
Welcome to Comment Club! This content is only available to people who read my HTML comments.
This is a very silly post born out of some late night chats. To be honest, it has probably already been done in one of the Big Finish stories - but I don't have time to listen to all those. Still, I'm really looking forward to seeing what the (eventual) new series will be like.
Anyway, the three rules of Comment Club are…
1. You must not tell anyone about Comment Club - let them find out about it themselves.
2. You *must* add some Comment Club Content to at least one of your blog posts. Doesn't have to be much, just a little note will do.
3. You should drop an email to anyone whose comments you've read. Start by sending me a friendly message at comment.club@shkspr.mobi
Keep your eyes peeled for more comments in future blog posts 😃
TTFN.
-->
<p>My pitch is simple - remake some of the original stories which were let down by shoddy effects, naff music, indifferent direction, and hammy acting. There are loads of great stories which are stretched too thin over six episodes with clunky cliffhangers. So let's give them a fresh lick of paint, trim each story down to two episodes, and give them modern direction<sup id="fnref:Whooooo"><a href="https://shkspr.mobi/blog/2026/10/my-pitch-for-the-new-season-of-doctor-who/#fn:Whooooo" class="footnote-ref" title="To be 100% clear, I know this is never going to happen. The BBC's tender document specifically says:
> Iconic, established villains are a mainstay of the series over 60 years and we invite you to use…" role="doc-noteref">0</a></sup>.</p>
<p>One story from each of the original Doctors' run. But here's the twist - there's a different actor playing The Doctor for each story! The Doctor's companion stays the same throughout. As the ~14 episodes play out, The Doctor gradually becomes aware that some malevolent force is compelling them to relive their previous adventures.</p>
<p>Very roughly, this is what I'd do:</p>
<ol>
<li>The Web Planet - with Patrick Stewart as The Doctor. Imagine proper CGI ants! Menoptra floating through the air! It's fair to say <a href="https://shkspr.mobi/blog/2020/09/review-doctor-who-the-web-planet/">I disliked the original version</a>, but it is easy to imagine how it <em>could</em> work.</li>
<li>Fury From The Deep - with Miranda Hart. A fine story but with so-so delivery. The environmental angle would resonate well today.</li>
<li>Invasion of the Dinosaurs - with Sean Pertwee. Look, who else are you going to get to play him? The original story is probably the epitome of shoddy FX work! Everyone loves dinosaurs and having them rampage around the UK (rather than a spaceship) would be thrilling.</li>
<li>The Talons of Weng-Chiang - with Benedict Wong. Is it possible to rewrite this to be less racist? There's a great story to be told, but the original suffers from "yellowface".</li>
<li>Earthshock - with Riz Ahmed. Time to get in a "classic baddie" with the Cybermen running rampage on a ship.</li>
</ol>
<p>At this point, The Doctor realises who has been driving him through his past lives. Forcing him to confront his sins. Sending him mad through endless regenerations.</p>
<p>Adric.</p>
<p>Someone, or some<em>thing</em>, has resurrected Adric. His "noble sacrifice" was little more than a suicide attempt after the relentless bullying by The Doctor and his companions. Driven to vengeance, he is determined to keep The Doctor trapped in a never-ending cycle of death and destruction.</p>
<ol start="6">
<li>The Twin Dilemma - with Michaela Coel. A hugely problematic and violent story. As The Doctor realises her companion is a villain, can she keep her reactions under control? Should she?</li>
<li>Survival - with Alex Horne. The Doctor has to face not The Master but a furious Adric hellbent on purging the Universe of the Time Lords. All the strands of the previous stories come together in an epic climax.</li>
</ol>
<p>Get J. Michael Straczynski to run the thing, a bunch of chiptune/electronica/glitch musicians to give each episode a unique sound, and - crucially - show it in autumn/winter. There's no point having scary sci-fi on when it is bright outside and people want to go out and play. This needs to be hug-your-mum-for-warmth-not-because-you're-scared TV.</p>
<p>Right, I'm off to the Beeb to deliver the pitch! TTFN.</p>
<div id="footnotes" role="doc-endnotes">
<hr aria-label="Footnotes">
<ol start="0">
<li id="fn:Whooooo">
<p>To be 100% clear, I know this is never going to happen. The BBC's tender document specifically says:</p>
<blockquote><p>Iconic, established villains are a mainstay of the series over 60 years and we invite you to use them, but we will want to begin to get an understanding of the original characters, aliens and themes that producers wish to bring to the show and are keen not to be overly reliant on existing Doctor Who lore. We are looking for a new perspective that ensures Doctor Who remains relevant, surprising, brave and inspiring for both long-standing fans and new audiences.</p></blockquote>
<p><a href="https://shkspr.mobi/blog/2026/10/my-pitch-for-the-new-season-of-doctor-who/#fnref:Whooooo" class="footnote-backref" role="doc-backlink">↩︎</a></p>
</li>
</ol>
</div>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=72702&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">Amazon tries to placate data center protesters - Werd I/O6ac127d7d546d400012019132026-10-03T16:05:43.000ZWerd I/O<p>Link: <a href="https://www.geekwire.com/2026/amazon-pledges-1b-to-data-center-communities-warns-that-local-opposition-threatens-u-s-ai-lead/"><em>Amazon pledges $1B to data center communities, warns that local opposition threatens U.S. AI lead, by Todd Bishop in GeekWire</em></a></p><p>This is a sign that protests are working:</p><blockquote>“Amazon says it will spend more than $1 billion over five years in the U.S. communities where it builds and operates data centers, responding to a growing backlash across the country against the tech industry’s massive AI infrastructure buildout.”</blockquote><p>But I’d consider this a <em>settlement</em> rather than a <em>win</em>: companies like Amazon need the data centers to be built in order to continue their growth. Communities opposing them should be able to keep pressing and get bigger, ongoing concessions at the very least.</p><p>The objections here follow a predictable playbook: claims about widespread foreign interference (because surely no <em>real</em> American could oppose data centers in their communities) and a warning that America will lose to China if it doesn’t keep building. It’s a scaremongering technique designed to keep people in line without offering further benefits to communities. America won’t lose; <em>Amazon</em> might.</p><p>The current concessions over five years represent 0.1% of Amazon’s annual capital spending. It’s less than pocket change — <em>and</em> Amazon isn’t forgoing tax breaks, so it may get it all back anyway.</p><p>And it seems odd that these benefits are set up as something like an altruistic program through Amazon’s own “Built Together” program. Really it should be money that flows directly into towns and cities, on an ongoing basis, with zero strings attached and no involvement from the company. Those towns can do the same things Amazon is claiming to do, but on their terms, and in a way that doesn’t tie them to Amazon’s infrastructure and isn’t a weird PR win for the company.</p><p>There’s more to do. This is a sign that the protesters can get much more for their communities.</p>Privacy and Webmentions - Kev Quirkhttps://kevquirk.com/privacy-and-webmentions2026-10-03T13:46:00.000ZKev Quirk<p>Following my recent post about <a href="https://kevquirk.com/i-dont-remember-the-last-time-i-checked-mastodon">not checking Mastodon</a>, a reader raised an interesting privacy concern regarding Webmentions. They explained that they had stopped using Webmentions altogether because Fediverse users often don't realise - or explicitly consent to - their replies being republished on an external blog.</p>
<p>This surprised me, as I'd never considered that Webmentions could be a privacy concern.</p>
<p>To my mind, a <em>public</em> post on an open platform like Mastodon is precisely that: public. The Fediverse is decentralised by design. When you reply to someone, your message doesn't remain isolated on your home instance; it federates across countless independent servers. Pulling a public reply onto <code>kevquirk.com</code> via a Webmention bridge is conceptually no different from <code>fosstodon.org</code> relaying a reply originally posted on <code>mastodon.social</code>.</p>
<p>Unless the concern is about deletion persistence (e.g. cached mentions remaining if a post is deleted), I struggle to see where the privacy violation lies when republishing content that was broadcast publicly to the open web in the first place.</p>
<p>Am I missing a subtlety here? I'd love to hear your thoughts.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Privacy%20and%20Webmentions">reply to this post by email</a>, or <a href="https://kevquirk.com/privacy-and-webmentions#comments">leave a comment</a>.</p>
</div>
Weeknote #2020
- Robb Knight • Posts • Atom Feedhttps://rknight.me/blog/weeknote-2020/2026-10-03T08:08:00.000ZRobb Knight<p>Dave is doing important work here, <a href="https://heroes.daveliddament.co.uk">holding Cadbury Heroes to account</a>.</p>
<p>MacOS 27 broke the drivers for my thermal printer but thankfully someone <a href="https://github.com/glaucusec/4barcode-macos-driver">made a new driver</a>.</p>
<p>I'm on board with <a href="https://brand.io/article/spymarks/">Spymarks, not watermarks</a>.</p>
<p>The <a href="https://www.thisiscolossal.com/2026/08/pure-street-photography-awards-2026-contest-winners/">winners of the street photography awards</a> are fantastic (obviously).</p>
<p>Side-eyeing projects like <a href="https://unawatch.com">Una</a> to try and get away from my Apple Watch at some point.</p>
<p><a href="https://www.youtube.com/watch?v=pV6MWmXo_Ss">Hannah Fry's favourite fountain pens</a>. Love this.</p>
<p>There's no world in which I can watch <a href="https://www.youtube.com/watch?v=eY_8SyndC10">this documentary about Elon Musk</a> but I'm glad it exists.</p>
<p>A <a href="https://www.flickr.com/groups/419512@N22/pool/with/55127153425">gallery of control rooms</a> on Flickr via <a href="https://simplebits.shop">SimpleBits</a>.</p>
<p>While looking for an example of a Geordie accent, I came across <a href="https://www.youtube.com/watch?v=Ei1DnFdJrww">this supercut</a> of a "Geordie" character who has an accent that is so ridiculous I can't even work out what he thinks he's doing. They even brought in translator as a plot point. This whole thing is wild.</p>
<p>This <a href="https://mastodon.social/@finnvoorhees/117360552143405957">monstrosity from Finn</a> for the iPhone Duo.</p>
<p><a href="https://bastardica.mitpit.com">Barstardica</a> mixes different fonts into one for...reasons. I love and hate it.</p>
<p><a href="https://github.com/Gissio/font_tiny5?ref=simplebits.com">This Tiny5 font</a> is amazing and I need somewhere to use it as soon as possible.</p>
<p>Tyler has got me thinking about an old MacBook Pro we have at home with his post about <a href="https://tylersticka.com/journal/repurposing-a-15-year-old-macbook-air/">repurposing a 15-Year-Old MacBook Air</a>.</p>
<p><a href="https://lazygit.app/#install">Lazygit</a> is very nice but not something I have a need for.</p>
<p><a href="https://littlefedi.org/deploy.html">littleFedi</a> is a "<em>small ActivityPub server written in Go</em>". It's a single binary, designed to run on basically everything, and supports the Mastodon API.</p>2026-10-03 09:04: Took the dogs out on the field this morning. All the dewey spider webs were... - Kev Quirkhttps://kevquirk.com/2026-10-03-09042026-10-03T08:04:00.000ZKev Quirk<p>Took the dogs out on the field this morning. All the dewey spider webs were beautiful in the morning sun.</p>
<p>I'm no Jack Baty, but they're good enough.</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-10-03-0904/1000012231.webp" alt="1000012231" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-10-03-0904/1000012228.webp" alt="1000012228" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-10-03-0904/1000012227.webp" alt="1000012227" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-10-03-0904/1000012233.webp" alt="1000012233" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=2026-10-03%2009%3A04">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-10-03-0904#comments">leave a comment</a>.</p>
</div>Two data sovereignties - destructuredhttps://destructured.net/two-data-sovereignties2026-10-03T04:00:00.000Zdestructured<p>The topic of “data sovereignty” has been making the rounds lately, so it’s worth thinking about what that might mean. Broadly speaking, I see it being used to evoke two not-entirely compatible ideas:</p>
<ol>
<li>
<p>That individuals should retain control of the data they generate; and</p>
</li>
<li>
<p>That countries should have authority over the data generated by their citizens.</p>
</li>
</ol>
<p>Any conflation of those two notions ultimately serves the goals of data nationalists better than it does those of data individualists.</p>
<p>Both historically and linguistically, “sovereignty” is a concept grounded in state authority. It doesn’t map well to the idea of personal autonomy.<sup id="fnref:1"><a href="#fn:1" class="footnote" rel="footnote" role="doc-noteref">1</a></sup> But convincing people who are concerned about data privacy that it’s in their interest to talk favorably about sovereignty sure does help out those who are interested in reasserting state authority.</p>
<div class="footnotes" role="doc-endnotes">
<ol>
<li id="fn:1">
<p>The ideologies of so-called sovereign citizen movements are mostly incoherent, but often try to square their claims by presenting federal officials as agents of a foreign state. <a href="#fnref:1" class="reversefootnote" role="doc-backlink">↩</a></p>
</li>
</ol>
</div>Finished reading A Psalm for the Wild-Built - Molly White's activity feed6ac052ad0db40ecf5ef7ebc42026-10-03T00:56:13.000ZMolly White<article class="entry h-entry hentry"><header><div class="description">Finished reading: </div></header><div class="content e-content"><div class="book h-entry hentry"><a class="book-cover-link" href="https://www.mollywhite.net/reading/books?search=A%20Psalm%20for%20the%20Wild-Built"><img class="u-photo book-cover" src="https://m.media-amazon.com/images/S/compressed.photo.goodreads.com/books/1708515061i/208944365.jpg" alt="Cover image of A Psalm for the Wild-Built" style="max-width: 300px;"/></a><div class="book-details"><div class="top"><div class="series-info"><i>Monk & Robot</i> series, book <span class="series-number">1</span>. </div><div class="title-and-byline"><div class="title"><i class="p-name">A Psalm for the Wild-Built</i> </div><div class="byline">by <span class="p-author h-card">Becky Chambers</span>. </div></div><div class="book-info">Published <time class="dt-published published" datetime="2021">2021</time>. 151 pages. </div></div><div class="bottom"><div class="reading-info"><div class="reading-dates"> Started <time class="dt-accessed accessed" datetime="2026-09-30">September 30, 2026</time>; completed September 1, 2026. </div></div></div></div></div><img src="https://www.mollywhite.net/assets/images/placeholder_social.png" alt="Illustration of Molly White sitting and typing on a laptop, on a purple background with 'Molly White' in white serif." style="display: none;"/></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp">Posted: <time class="dt-published" datetime="2026-10-03T00:56:13+00:00" title="October 3, 2026 at 12:56 AM UTC">October 3, 2026 at 12:56 AM UTC</time>. </div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=cozy" title="See all books tagged "cozy"" rel="category tag">cozy</a>, <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=hopepunk" title="See all books tagged "hopepunk"" rel="category tag">hopepunk</a>, <a class="tag p-category" href="https://www.mollywhite.net/reading/books?tags=science_fiction" title="See all books tagged "science fiction"" rel="category tag">science fiction</a>. </div></div></footer></article>Noticing - James' Coffee Bloghttps://jamesg.blog/2026/10/03/noticing2026-10-03T00:00:00.000ZJames' Coffee Blog
<p>Walking through the Royal Mile, I noticed the faint – then increasing – scent of coffee in the air coming from a popular bakery. <em>It is morning.</em> I continued walking for a little while, en route to one of my preferred coffee shops. There, the baristas were laughing, one exchanging stories from Scottish history with a hint of humour, the other listening joyfully. Whereas in past weeks the sound of the espresso machine first piques my interest, today it was the sound of laughter, and the joy of seeing smiles so early in the morning.</p>
<p>The cafe was quieter than usual. Tourist season is ending. The weather is cooling. The morning is young. Perhaps it would get busy later. Revelling in the peace, I looked out the window to the world, watching people walk by for longer than usual. I was in no rush to do anything today. At one point, I saw three people – who I expect were friends – walk in exact lockstep. I have seen two people walk in lockstep before – even today – but never three to the best of my recollection. The feeling of friendship echoed through the air. I started thinking about my friends.</p>
<p>Back on my walk, I noticed something that, now I think about it, I must have walked past many times before: an electricity box painted by an artist. This stood out because I was having a conversation with a friend yesterday about a public arts programme in Washington, DC. where electricity boxes in the streets are painted. Here I was standing in front of one, but here in Scotland. <em>How many other pieces of art have I walked past and not noticed?</em> Or, alternatively, <em>How many pieces of art are there waiting to be noticed?</em></p>
<p>The box had a painted blue and silver background with many flowers in the foreground. The flowers had red, yellow, white, and blue-green petals. The stalks were red, green, purple, and blue. A bird soared in the sky of the artwork. In the bottom right corner there were white outlines of people on skateboards, a football pitch, and more. I wonder how long this work took to make. I took a picture so that I could appreciate the box later. I’m glad I did, for the picture helped me write this description.</p>
<p>Atop the box was another box, a green cage. A posted placed on top of the artwork below contained a QR code to see air quality levels. The station above must have been an air quality monitor. I love how the art not only caught my attention as art itself, but also drew my attention to the science above. <em>Friends help us notice the world around us,</em> I thought. With art in my heart, I went charity shopping, and then continued my walk.</p>
<p>Later on, I walked through a park, and sang along to one of my favourite songs. There were not many people around, and so my quiet, impassioned voice did not seem out of place. Indeed, the sound of my voice was no match for that of the birds singing in the background, and, later, the sound of a group of kids loudly playing tennis. I noticed that the adults playing were mostly quiet, save for the sound of the ball hitting the rackets.</p>
<p>Further on, people huddled by the yellow neon sign at the wooden hut from which coffees are served. I am sure many of them were looking for a beacon of liquid warmth to accompany their mornings, just as I had been an hour earlier. Here, surrounded by Nature, I could feel the cold in my notes and my eyes. I love how autumn makes me feel. I feel every part of myself. Whether it was from my walk or the cooler air or both, I felt I needed to take deeper breath – appreciating the autumn air.</p>
<p>A theme of the day was how places transform with the seasons: trees yellow, we wear more layers, outdoor seating moves indoors, we come closer for warmth. To end my walk, I saw two people laugh uncontrollably, in the way where even when there is a brief pause in the laughter you know that more will come. My morning started and ended with the resonance of laughter: of seeing joy in the air, just as I, too, felt joy sipping on my warm coffee, and then going out to appreciate art and Nature and the world.</p>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a44c1cfe8eb7eaf5',t:'MTc5MTAzMjI1Mw=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
September 2026 Summary - Joel's Log Fileshttps://joelchrono.xyz/blog/september-2026-summary2026-10-02T22:59:27.000Zjoelchrono<p>At last, another month we say good bye to, and all of a sudden, the year is on its final stretch, the days go by faster and faster, and I am getting old with everyone around me!</p>
<p>In any case, there’s plenty of stuff to go through here, media, movies, videogames, podcasts. You Know the usual stuff! I have decided I would highlight the best things on this little intro, in case you are bored or looking to just skim through.</p>
<ul>
<li><strong>Podcasts</strong>: The Play Station Episode of <em>Into The Aether</em>, The Wolf 359 podcast as a whole</li>
<li><strong>Manga</strong>: <em>Blame!</em> is simply awesome and terrifying.</li>
<li><strong>Movies</strong>: Ad Astra, Artificial Intelligence, Catch Me If You Can, War of the Worlds, Coyote vs. ACME.</li>
<li><strong>Videogames</strong>: <em>Final Fantasy IV</em> was a definite surprisei to return to. <em>Emio and the Smiling Man</em> was engagn</li>
<li><strong>TV Shows</strong>: <em>Lanterns</em> was pretty refreshing for a super hero show, if a bit too adult for my taste.</li>
<li><strong>Books</strong>: <em>The Left Hand of Darkness</em> and <em>The House on the Borderland</em> are still halfway through but I’m committed to both.</li>
</ul>
<figure>
<img src="/assets/img/blogs/2026-10-01-month.webp" />
<figcaption>Some artwork of my favorite media that showed up during the month! </figcaption>
</figure>
<h2 id="podcasts">Podcasts</h2>
<ul>
<li>
<p><strong>Into The Aether</strong> - With the release of the Play Station episode, my listening time for this podcast skyrocketed to a whooping 19 hours throughout the month! Fantastic set of episodes this time around.</p>
</li>
<li>
<p><strong>The Ten Minute Bible Hour</strong> - I listened to a dozen or so episodes of this one again, but they are like ten minutes each so it doesn’t amount to a lot compared to the rest of stuff here. Extremely interesting as always though.</p>
</li>
<li>
<p><strong>Dungeons and Daddies</strong> - A Dungeons & Dragons podcast. On a surprising turn of events, I finally returned to this podcast! I was able to pickup on the overall story again, thankfuly, so I plan to resume this crazy season 3, soon enough.</p>
</li>
<li>
<p><strong>The Rest is History</strong> - Some good stuff here, still all about the Great War, it was early in the month and I’m not I recall all of it though.</p>
</li>
<li>
<p><strong>Wonders of Web Weaving</strong> - I listened to a few episodes of this podcast by <a href="https://jamesg.blog">James</a> featuring different bloggers and stuff. Including me!</p>
</li>
<li>
<p><strong>Wold 359</strong> - I made progress and went through a couple more episodes, the finale feels closer now! Really looking forward to that.</p>
</li>
</ul>
<h2 id="manga">Manga</h2>
<h3 id="started">Started</h3>
<ul>
<li><strong>Blame!</strong> - Chapter 1-9. This a dystopian sci-fi story that happens inside some sort of mega-structure. We met one guy who is looking for a human with a special gene, which should be able to control the mega-structure itself. Each chapter is full of incredible architechture and a very intriguing atmosphere. Lots of questions lack answers right now, but I am kind of hooked by it. The chapters are a little long though, but they don’t have a lot of dialogue so, it’s all good.</li>
</ul>
<h3 id="ongoing">Ongoing</h3>
<ul>
<li>
<p><strong>Centuria</strong> - Chapter 48-80. A lot of pretty cool action and great moments happened, but I have kind of realized that this manga, while entertaining and still promising, is taking its time to deliver actually interesting plot points. I still enjoy it, because it lets me fill about ten minutes of my time with neat drawings to look at.</p>
</li>
<li>
<p><strong>Smoking Behind the Supermarket with You</strong> Chapter 63-64. Now this is still going to some interesting places. A lot of introspection during these couple chapters, after a pretty heavy and difficult situation, a conflict in need of resolution, which I’m looking forward to see. I love these characters!</p>
</li>
<li>
<p><strong>Blue Lock</strong> - Chapter 357-359. I was reading this with great interest, but decided to wait at least until I’m sure the England vs Japan match is completed, so I can enjoy it all in one go. Fun stuff!</p>
</li>
<li>
<p><strong>My Wife is from a Thousand Years Ago</strong> - Chapters 287-288. This is just a fun rom-com! No complaints, a nice pace and very fun moments, a little spicy but mostly wholesome, which I prefer.</p>
</li>
</ul>
<h2 id="movies">Movies</h2>
<p>I was going to like, write kinda proper reviews for these but, meh, they were all pretty decent except for <em>Mercy</em>, you can skip that one.</p>
<ul>
<li><strong>Avengers Endgame Encore</strong> - Fun to rewatch on the big screen at last! The extra scenes aren’t really worth it though.</li>
<li><strong>The Day the Earth Stood Still</strong> - An alien tells humanity to chill out <em>or else</em>. Seriously impressive for the time.</li>
<li><strong>War of the Worlds</strong> - Tom Cruise running from aliens from Mars. He also tries to be a good father at the same time.</li>
<li><strong>By Any Means</strong> - A bunch of racists face the consequences of their actions. A bit of a weird casting choice though.</li>
<li><strong>Mercy</strong> - Chris Pratt trapped by AI and staring at screens. The murder mystery was fine, the presentation not really.</li>
<li><strong>Artificial Intelligence</strong> - A robot wants the be a real boy and earn a mother’s love. That ending is wild though.</li>
<li><strong>Catch Me If You Can</strong> - Leonardo Di Caprio running from Tom Hanks. The movie is based on real events that turned out to be fake!</li>
<li><strong>Ad Astra</strong> - Brad Pitt running from the world itself, looking for his father. Surprisingly Hard Sci-Fi stuff here.</li>
<li><strong>Coyote vs. ACME</strong> - This one was funny and nostalgic and I loved it. No notes, it made me cry out laughing.</li>
</ul>
<h2 id="videogames">Videogames</h2>
<h3 id="started-1">Started</h3>
<ul>
<li><strong>Kirby and the Forgotten Land</strong> - A friend came over one time and we decided to start this one in 2-player mode. I decided it would be a pretty fun title to add to the multiplayer pile of games I mostly play with other people! It is extremely fun. The artstyle, the level design, the Switch performance and everything combined make for a very pleasant gaming experience.</li>
</ul>
<h3 id="ongoing-1">Ongoing</h3>
<ul>
<li>
<p><strong>Final Fantasy IV</strong> - This is the game that ended up being revisited the most, with about as much time played of it as <em>Emio</em>, but grinding and progressing through the last few challenges this game has to offer, and the final dungeon which is at my grasp at last. Final Fantasy IV may be the first ever Final Fantasy I complete, and I’m looking forward to it.</p>
</li>
<li><strong>Hollow Knight: Silksong</strong> - This game started strong in the month, playing it for about five hours in four days. I got into Act 3 and defeated some new bosses, I upgraded my needle and got more stuff from all that.</li>
<li>
<p><strong>Fire Emblem Awakening</strong> - I made significant progress completing chapters 19 and 20 without a lot of issues, after some grinding throughout many days. Loving the support scenes as well! Waiting for its time to shine some more.</p>
</li>
<li>
<p><strong>The Legend of Zelda: Ocarina of Time 3D</strong> - I only played this one time, but I made some initial progress as Adult Link, reaching the Forst Temple. I only need to focus and complete the dungeon itself and continue the story some more!</p>
</li>
<li>
<p><strong>Tomodachi Life: Living the Dream</strong> - Revisited my island a couple of times, but I haven’t really made a lot more with it. I should try to like, remodel everything or do something more creative, but the spark isn’t quite there for me right now.</p>
</li>
<li><strong>Super Smash Bros Ultimate</strong> - I had some very epic moments playing with friends this time around, it was awesome.
<h3 id="completed">Completed</h3>
</li>
<li><strong>Emio: The Smiling Man</strong> - I am yet to review this, a detective story with visual novel mechanics that really caught me for three days straight. Pretty much only paused to eat and sleep as soon as I started it! Amazing artwork, great music, intriguing plotline, fun characters, so many suspects! Loved it.</li>
</ul>
<h2 id="tv-shows">TV Shows</h2>
<ul>
<li><strong>Lanterns</strong> - I watched like four episodes of this in a single day and it was a pretty good detective story kinda thing. I wasn’t expecting to like it as much, although I kinda abandoned it halfway through. Will probably finish the season soon.</li>
</ul>
<h2 id="books">Books</h2>
<ul>
<li>
<p><strong>The House on the Borderland</strong> by William Hope Hodgson. Up to chapter 14. This is a very interesting horror novel, that deals with the existential, multiple dimensions, entities beyond our understanding, and whatever else. In the form of a diary written by an old man from long ago. It has been very gripping so far, but I paused it for the sake of the next book.</p>
</li>
<li>
<p><strong>The Left Hand of Darkness</strong> by Ursula K. Le Guin. Up to chapter 7. This was chosen for the TWGLK Book Club for September and… I didn’t manage to finish it, started too late. Anyway, I am enjoying it as is, and without the time pressure. This is a very interesting book featuring a couple points of view, but mostly focused on an envoy sent by an interplanetary force</p>
</li>
</ul>
<h2 id="finishing-thoughts">Finishing thoughts</h2>
<p>I wonder what the reading retention was on this one giving you a summary of summary of the month at the very beginning. I guess we’ll see over time.</p>
<p>It’s not like I should care about this stuff being read, it’s always more of a log for myself so I can lock down when some interesting movie or videogame showed up on my radar with a simple <code class="language-plaintext highlighter-rouge">grep</code> command on my terminal.</p>
<p>In any case. This year is flying by, and it’s pretty clear that the yearly recaps will require quite a lot of effort! Looking forward to that.</p>
<p>This is day 46 of <a href="https://100daystooffload.com">#100DaysToOffload</a></p>
<p>
<a href="mailto:me@joelchrono.xyz?subject=September 2026 Summary">Reply to this post via email</a> |
<a href="https://fosstodon.org/@joel/117374199881890755">Reply on Fediverse</a>
</p>Published on Citation Needed: "Issue 110 – The Clarity Act collapses" - Molly White's activity feed6ac0512b52b01ca28c3ff8832026-10-02T20:29:05.000ZMolly White<article class="entry h-entry hentry"><header><div class="description">Published an issue of <a href="https://www.citationneeded.news/"><i>Citation Needed</i></a>: </div><h2 class="p-name"><a class="u-syndication" href="https://www.citationneeded.news/issue-110" rel="syndication">Issue 110 – The Clarity Act collapses </a></h2></header><div class="content e-content"><div class="media-wrapper"><a href="https://www.citationneeded.news/issue-110"><img src="https://www.citationneeded.news/content/images/size/w2000/format/webp/2026/10/gillibrand-clarity-1.png" alt="Senator Gillibrand votes “no” on the motion to invoke cloture for the Clarity Act"/></a></div><div class="p-summary"><p>Regulators race to reassure the crypto industry as the industry’s flagship legislation collapses, SBF tries his luck with the Supreme Court, and crypto PACs unleash $30 million against Sherrod Brown</p></div></div><footer class="footer"><div class="flex-row post-meta"><div class="timestamp">Posted: <a class="u-url" href="https://www.citationneeded.news/issue-110"><time class="dt-published" datetime="2026-10-02T20:29:05+00:00" title="October 2, 2026 at 8:29 PM UTC">October 2, 2026 at 8:29 PM UTC</time>. </a></div><div class="social-links"> <span>Also posted to:</span><a class="social-link u-syndication mastodon" href="https://hachyderm.io/@molly0xfff/117374132542933307" title="Mastodon" rel="syndication">Mastodon</a><a class="social-link u-syndication bluesky" href="https://bsky.app/profile/molly.wiki/post/3mwwlnys7e227" title="Bluesky" rel="syndication">Bluesky</a></div></div><div class="bottomRow"><div class="tags">Tagged: <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/coinbase" title="See all feed posts tagged "Coinbase"" rel="category tag">Coinbase</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/crypto" title="See all feed posts tagged "crypto"" rel="category tag">crypto</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/crypto_lobby" title="See all feed posts tagged "crypto lobby"" rel="category tag">crypto lobby</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/law" title="See all feed posts tagged "law"" rel="category tag">law</a>, <a class="tag p-category" href="https://www.mollywhite.net/feed/tag/us_politics" title="See all feed posts tagged "US politics"" rel="category tag">US politics</a>.</div></div></footer></article>Gadget Review: Una Watch ★★★★☆ - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=760312026-10-02T11:34:48.000ZTerence Eden’s Blog<p>I've never been a huge fan of smart watches. My <a href="https://shkspr.mobi/blog/2025/08/i-bought-a-16-smartwatch-just-because-it-used-usb-c/">£16 smartwatch</a> is basically fine, but the OS is closed source and there's no way to add new functionality. Previously I had the <a href="https://shkspr.mobi/blog/2023/06/review-watchy-an-eink-watch-full-of-interesting-compromises/">eInk Watchy</a> which was a pain to use and really poorly designed. Even back in 2014 I was bemoaning the design compromises in the <a href="https://shkspr.mobi/blog/2014/11/disassembling-the-mykronoz-zewatch-smart-watch/">MyKronoz ZeWatch Smart Watch</a>.</p>
<p>So why did I pick up the Una Watch?</p>
<p>Firstly, the Una Watch is designed in Scotland <del>from girders</del>, and it's always nice to support local businesses.</p>
<p>Secondly, as a <a href="https://shkspr.mobi/blog/2026/07/im-a-usb-c-maximalist/">USB-C Maximalist</a> I want gadgets which can plug in to the same cables as all my other toys. No magnetic pucks here!</p>
<p>Thirdly, it is (almost) <a href="https://unawatch.com/pages/open-source">completely open source</a>.</p>
<p>Finally, it is repairable. You can easily unscrew it to replace the components. As my cheap smartwatch's dial has died after 12 months of use, that's a pretty compelling proposition!</p>
<p>Let's put it through its paces!</p>
<h2 id="first-impressions"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#first-impressions">First Impressions</a></h2>
<p>I bought mine second hand (yay for sustainability) and it arrived with a flat battery. The first charge from 0-100% took a little over an hour. My USB-C power monitor showed it taking in about 5V and 0.17 amps.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/Charging.webp" alt="Power monitor showing 0.84W." width="1024" height="576" class="aligncenter">
<p>It happily charged from a PD plug, but didn't get any faster than about 0.84W. Basically, I can fully charge it on most public transport in London.</p>
<p>The time seemed accurate, there were options to play about with, the vibrations for notifications were easy to feel. There is an option to make it beep with every button press - I turned that off sharpish!</p>
<h2 id="disclaimer"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#disclaimer">Disclaimer</a></h2>
<p>I am <em>not</em> <a href="https://shkspr.mobi/blog/2026/09/are-you-a-smartwatch-power-user/">a smartwatch power user</a>. I'm not using this to minutely track all my exercise or calculate if my heart is going to explode. I don't need cm level precision of my GPS. I didn't sync this with Strava or anything else.</p>
<h2 id="apps"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#apps">Apps</a></h2>
<p>The official Android app (which, sadly, isn't Open Source) worked fine on GrapheneOS. It found the watch, updated its GPS almanac, and let me browse the app store & install apps. Obviously early days, but there are a variety of community developed apps to play with.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/apps.webp" alt="List of apps." width="504" height="728" class="aligncenter">
<p>Annoyingly the watch needs to be restarted after every app is installed - but that only take a handful of seconds.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/Restart-watch.webp" alt="Message telling me the watch needs to restart." width="504" height="640" class="aligncenter">
<p>There are some <em>strange</em> error messages.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/error-message.webp" alt="birthday must be a valid ISO 8601 date string country must be a valid ISO31661 Alpha2 code." width="504" height="426" class="aligncenter">
<p>That isn't the sort of message which should be shown to users.</p>
<p>But, on the plus side, you can install Doom!</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/Doom.webp" alt="App store listing showing Doom on the watch." width="504" height="550" class="aligncenter">
<h2 id="the-screen"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#the-screen">The Screen</a></h2>
<p>Oddly for a modern smartwatch, the screen stays on <em>all the time!</em> But this isn't some power-hungry OLED, nor is it static eInk. Instead it is a <a href="https://www.andersdx.com/memory-in-pixel-displays/">memory in pixel</a> display - black background with orange, blue, and white pixels. The backlight remains off most of the time and is easy enough to see in daylight. It is <em>slightly</em> reflective - but not too bad.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/Reflective.webp" alt="Watch showing notifications, there is a bit of a reflection." width="1024" height="576" class="aligncenter">
<p>Note the <code>??</code> on the notifications - more on that later.</p>
<p>Annoyingly, there's no "raise wrist to light" option. You have to interact with the watch to get the screen on. The accelerometer should allow this functionality - so perhaps it just needs to be activated in the firmware? It is bright enough to see in the dark, but not so bright it will dazzle you or people nearby.</p>
<p>There's no touchscreen - instead there are four buttons around the face. Up, down, select, back. I did find myself repeatedly jabbing at the screen to no avail.</p>
<p>So, to light it, press the back button or hold one of the other buttons.</p>
<p>The colour scheme is pleasant enough. I miss having a full colour display so I can see a photo of my wife whenever I glance at the screen. But the low power usage can't be argued with.</p>
<h2 id="notifications"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#notifications">Notifications</a></h2>
<p>I couldn't get notifications working at first. The app just refused to let me toggle them on. Eventually I found an app in the app-store which claimed to enable them. That didn't work either.</p>
<p>Unpairing, repairing, and reinstalling the app made them spring to life.</p>
<p>There's no notification history. Once you've clicked to read it, that's it. Gone forever. Considering this has 4GB storage, that's an odd decision.</p>
<p>Some of the notifications were slightly corrupt - showing question marks in place of (I assume) esoteric Unicode.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/09/Question-Mark-notification.webp" alt="A notification on screen with a question mark before the user's name." width="1024" height="768" class="aligncenter">
<p>There's no way to customise the vibrate pattern - so everything "feels" the same on your wrist.</p>
<p>At the moment, the Una Watch sends <em>every</em> notification to your phone. You can't tell it to ignore certain WhatsApp groups, or only allow text messages from your spouse. The only way to get fine-grained notifications is with a third-party app like…</p>
<h2 id="gadgetbridge"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#gadgetbridge">Gadgetbridge</a></h2>
<p>You're not tied to the official app. <a href="https://gadgetbridge.org/gadgets/wearables/una/">Gadgetbridge support is excellent</a>. There are a few things missing (you can't install apps or set alarms) - but if you want to measure your heart rate, send notifications, etc you'll be fine.</p>
<h2 id="linux-compatibility"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#linux-compatibility">Linux Compatibility</a></h2>
<p>The Una Watch plugs in to USB-C and shows up as 3.5GB of exFAT formatted storage.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/10/Una-Filesystem.webp" alt="Filesystem view showing various JSON files." width="500" height="649" class="aligncenter">
<p>You can manually edit the JSON files if you like. I think you can copy off your workout data. Or you can just use it as portable storage.</p>
<p>Under <code>lsusb</code> it describes itself as <code>0483:52a4 STMicroelectronics UNA Watch</code></p>
<h2 id="battery-life"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#battery-life">Battery Life</a></h2>
<p>After a full day of use the battery was at around 95% - that was with a bit of GPS, several notifications, heart rate monitoring, step counting, and a bunch of fiddling. With more GPS use, that's going to be heavier on the battery.</p>
<p>But the joy of USB-C is that I can thwack in the same cable as I use for all my other gadgets. I can even plug it into my phone and leach a bit of power from there.</p>
<h2 id="development"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#development">Development</a></h2>
<p>The watch comes will a full <a href="https://github.com/UNAWatch/una-sdk">Open Source SDK</a> including lots of assets. There are several tutorials and a friendly community board.</p>
<p>Of course, everything has to be done in C++ - an accurs'd language which I learned in the last century and wish I'd forgotten.</p>
<p>Annoyingly, the <a href="https://github.com/UNAWatch/una-sdk/blob/main/Docs/sdk-setup.md">TouchGFX GUI designer</a> only works in Windows.</p>
<p>I'm going to try to build my own watch faces and a few niche apps.</p>
<h2 id="downsides"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#downsides">Downsides</a></h2>
<p>There are a few things this watch <em>doesn't</em> do - some of these may be deal-breakers for you, but weren't for me.</p>
<ul>
<li>No payments. There's no tap-to-pay, NFC, or anything like that.</li>
<li>No microphone. You cannot speak into your Una Watch or take calls on it.</li>
<li>No speaker. There's a little buzzer which can make squeaks and squawks - but you won't be playing your music through it.</li>
<li>While the apps and SDK are fully open, the firmware isn't (yet).</li>
<li>Can't reply to notifications.</li>
<li>No maps or directions (yet).</li>
<li>Step counter only shows the full day - no hour-by-hour view.</li>
</ul>
<p>Some of these things can and will be fixed in software. Others are limitations of the hardware.</p>
<h2 id="final-thoughts"><a href="https://shkspr.mobi/blog/2026/10/gadget-review-una-watch/#final-thoughts">Final Thoughts</a></h2>
<p>The Una Watch has dropped in price to £180. I grabbed mine 2nd hand from eBay for £120. At either price, it's decent value <em>if</em> you're happy to play with alpha / beta quality technology.</p>
<p>If you're a serious athlete, you'll probably want a more expensive and polished experience. If you are tied into the Apple or Google ecosystems, you'll probably want one of their watches.</p>
<p>If you like tinkering, want to experiment with new technology, or simply want to support a British company trying to build something open - then this is the watch for you. Yes, there are some rough edges, but I fundamentally believe that technology should be Open Source, repairable, and give control to its users.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=76031&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">SequenceHash: multihashing for the rest of us - Trail of Bits Bloghttps://blog.trailofbits.com/2026/10/02/sequencehash-multihashing-for-the-rest-of-us/2026-10-02T11:00:00.000ZTrail of Bits Blog<p>Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a <a href="https://blog.trailofbits.com/2024/08/21/yolo-is-not-a-valid-hash-construction/#yolomultihash">common stumbling point</a> when cryptographers try to use hashes.</p>
<p>As part of our goal to “fix software, not bugs,” Trail of Bits is introducing <a href="https://github.com/C2SP/C2SP/blob/main/sequencehash.md">SequenceHash and its sister function SequenceMAC</a>, a pair of related hash constructions that bring secure multihashing to developers using hash functions other than Keccak. We hope SequenceHash and SequenceMAC will help cryptographers avoid attacks that take advantage of ambiguous input encodings. The specification is open source, and is now a <a href="https://github.com/C2SP/C2SP/blob/main/sequencehash.md">part</a> of the Community Cryptography Specification Project (C2SP).</p>
<p>SequenceHash and SequenceMAC behave similarly to NIST’s <a href="https://csrc.nist.gov/pubs/sp/800/185/final">TupleHash</a>, but have the advantage of not being tied to a single hash function. They also don’t require developers to implement fiddly computations that aren’t byte-aligned. Instead, SequenceHash and SequenceMAC work out of the box with nearly any secure cryptographic hash function you care to use, including SHA256/384/512, BLAKE, and RIPEMD. SequenceMAC supports keys 32 bytes or longer (up to the ridiculous limit of ${2}^{128}-1$ bytes).</p>
<p>(It’s worth noting: SequenceHash and SequenceMAC rely on the security of the underlying hash for their own security. SequenceHash and SequenceMAC can’t magically make MD4 or SHA0 secure again. For the purposes of this document, it’s assumed that you have chosen a reasonable hash function like SHA256, not CRC32.)</p>
<p>To make SequenceHash and SequenceMAC easy to use, we’re releasing three initial implementations of SequenceHash and SequenceMAC: one each in Rust, Go, and Python. We’re also releasing a large set of test vectors that cover multiple hash functions and include intermediate values to help developers debug and verify their implementations.</p>
<h2 id="wait-multihashing">Wait, “multihashing”?</h2>
<p>Yeah, it’s a weird term, but the idea is pretty simple. “Multihashing” means “hashing a bunch of values together.” If you’ve ever read a cryptography paper, and there’s a step that says something like “compute the shared authenticator <code>N=Hash(X, Y, Z, A, B)</code>,” that’s multihashing. You need to create a hash that incorporates the inputs <code>X, Y, Z, A</code>, and <code>B</code>. Unfortunately, the simple “solution” of concatenating the inputs and hashing the result can lead to serious security problems.</p>
<p>For example, consider what happens when you hash three inputs using “raw” SHA256:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">import</span> <span class="nn">hashlib</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">hashlib</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">hexdigest</span><span class="p">())</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">hashlib</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">hexdigest</span><span class="p">())</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">hashlib</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">''</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">update</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">hexdigest</span><span class="p">())</span></span></span></code></pre>
</figure>
<p>This produces the following output:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">4fce0a9940a42b5c9d1bcbfc9a6ddd6de20d731d584a0acf5bda6de86483641c
</span></span><span class="line"><span class="cl">4fce0a9940a42b5c9d1bcbfc9a6ddd6de20d731d584a0acf5bda6de86483641c
</span></span><span class="line"><span class="cl">4fce0a9940a42b5c9d1bcbfc9a6ddd6de20d731d584a0acf5bda6de86483641c</span></span></code></pre>
</figure>
<p>Even though inputs are fed in through separate calls, they’re not separated from the perspective of the hash function—under the hood, the inputs are just concatenated.</p>
<p>As with many things in cryptography, multihashing is harder than you think. That’s a big problem because multihashing is a critical component of one of the most important tools in zero-knowledge proofs: the <a href="https://blog.trailofbits.com/2021/02/19/serving-up-zero-knowledge-proofs/">Fiat-Shamir transform</a>. When you get multihashing wrong, you introduce the risk of forgeries into your zero-knowledge proofs. Given that zero-knowledge proofs play a major role in cryptocurrency nowadays, that sort of mistake is sometimes measured in millions of dollars.</p>
<p>But Fiat-Shamir transforms aren’t the only place where you might want to use multihashing. It’s not uncommon to need to hash a collection of related objects, where both the objects <em>and</em> the collection are variable in size. Think of authenticating the files in an archive, grouping multiple cryptocurrency transactions into a single hash, or hashing something as <a href="https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/">“simple” as somebody’s name</a>.</p>
<p>Multihashing is also used when generating cryptographic commitments to values. In some protocols, one party must perform calculations using secret values, only to reveal them to other parties for later verification. Often, this is done by hashing the secret value along with a random “blinding” value and broadcasting the result to other parties as the commitment. If the boundary between the secret value and the blinding value isn’t clear, a “commitment” can sometimes be opened several different ways.</p>
<p>Unfortunately, nobody seems to have landed on a consistent, standard solution to this problem. Instead, across the open-source ecosystem and in our private audits, we find developers solving the problem in wildly different ways. Some of these solutions are insecure, like using separator characters that can also appear in the inputs. Others encode their data in a way that makes their separators unambiguous, but the encoding is unnecessarily complex and introduces subtle timing risks. Think of stuff like Base64-encoding byte strings and separating the results with dollar signs. We often see situations where <em>some</em> hash inputs are length-encoded, but not <em>all</em>. It’s the wild west out there.</p>
<p>There are tools specific to Fiat-Shamir transforms, like <a href="https://merlin.cool/">Merlin</a> and our own <a href="https://github.com/trailofbits/decree">decree</a>, but they don’t work so well for <em>general</em> multihashing.</p>
<p>The most widely known standard for multihashing is TupleHash, defined in <a href="https://csrc.nist.gov/pubs/sp/800/185/final">NIST SP 800-185</a>. To be clear, TupleHash is great. It solves the multihashing problem in a straightforward way (length-prefix encoding), and it handles inputs of <em>effectively</em> unlimited size (if you’re regularly hashing more than ${2}^{2040}-1$ bits of input, Trail of Bits wants to party with you and your disrespect for physics). As a bonus, it naturally operates as an XOF. If TupleHash is available for you, it’s a <em>great</em> tool.</p>
<p>TupleHash has a downside, though: it’s only defined to work with Keccak, the function that underpins SHA3. If you replace Keccak with another hash function, several of the important security features (like length-extension resistance) can go away. If you don’t have a Keccak implementation handy, you’re out of luck. Given that SHA3 and Keccak adoption have been pretty lackluster over the last decade, that leaves a lot of cryptographers out in the cold. This is especially true in the government contracting sector, where <a href="https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF">CNSA 2.0</a> has mandated SHA384 and SHA512 for nearly everything.</p>
<p>This is a problem that cries out for a standardized solution. It calls for a complete specification. It begs for ready-to-use implementations available in multiple languages.</p>
<h2 id="enter-sequencehash">Enter SequenceHash</h2>
<p>SequenceHash is a hash-agnostic multihashing construct, similar to the way HMAC is a hash-agnostic MAC construct. You can use SequenceHash with your favorite hash functions, including the entire SHA2 family, BLAKE, RIPEMD, and more.</p>
<h2 id="what-does-sequencehash-offer">What does SequenceHash offer?</h2>
<p>SequenceHash offers four key features that prevent your hashed values from being mixed, extended, or replayed across contexts.</p>
<h3 id="unambiguous-input-encoding">Unambiguous input encoding</h3>
<p>Given two inputs $\left({A,\ B}\right)$, you are guaranteed that there is no other sequence of inputs $\left({{I}_{1},\ldots ,{I}_{t}}\right)$, for any length $t$, that will result in the same input to the underlying hash function.</p>
<p>In other words, the values you hash are guaranteed to be “semantically distinct.” There’s no chance of playing games with the beginnings and endings of inputs, and there’s no opportunity to mix up parts of $A$ with $B$ or vice versa.</p>
<p>SequenceHash helps cryptographers follow <a href="https://en.wikipedia.org/wiki/Horton_principle">the Horton principle</a>: you are hashing what you mean, and meaning what you hash.</p>
<h3 id="length-extension-prevention">Length-extension prevention</h3>
<p>Several popular hash functions, including SHA256 and SHA512, are vulnerable to length extension attacks. If Alice has a secret value $A$ and sends $H\left({A}\right)$ to Bob, then Bob can craft a value $B$ such that he can compute $H\left({A||B}\right)$, even though he doesn’t know $A$.</p>
<p>SequenceHash doesn’t have that issue. It uses a double-hash construction that prevents Bob from learning the information he needs to compute $H\left({A||B}\right)$.</p>
<h3 id="built-in-customization-strings">Built-in customization strings</h3>
<p>If you’re developing cryptographic protocols, it’s often important to bind hashed values to a particular step in the protocol, or to a specific <em>instance</em> of the protocol, in order to prevent replay attacks or other problems related to reusing values.</p>
<p>SequenceHash makes this easy with built-in customization strings. Assuming you’re using a good hash function, applying SequenceHash or SequenceMAC to the same inputs with different customization strings will lead to unrelated outputs, allowing you to easily and predictably bind your hashes to particular uses. If you don’t need a customization string, don’t worry. They’re completely optional.</p>
<p>As an added bonus, the customization strings are incorporated only into the outer layer of the double-hash construction. If you need to hash the same value with multiple customization strings, the inner hash can be reused!</p>
<h3 id="mac-mode">MAC mode</h3>
<p>One final cool feature of SequenceHash is that it has a keyed mode, SequenceMAC. SequenceMAC is structurally similar to HMAC, and offers the same features as SequenceHash: unambiguous encoding, customization strings, and length-extension protection. It also incorporates metadata about the key and customization strings to prevent the key pseudocollision issues present in HMAC.</p>
<h2 id="how-does-sequencehash-work">How does SequenceHash work?</h2>
<p>Like TupleHash, SequenceHash uses length encoding to unambiguously encode its inputs. However, SequenceHash uses a simplified encoding. Instead of writing the number of bits to be hashed as a variable-length integer, SequenceHash encodes the number of bytes into a fixed-length, 128-bit integer. SequenceHash uses a length-suffix encoding for inputs. Like the length-prefix encoding system used by TupleHash, length-suffix encoding is unambiguous; however, suffix encoding allows implementers to develop streaming APIs when they need to support hashing data with length that isn’t known ahead of time.</p>
<p>We chose a 128-bit length encoding for simplicity of implementation on 32- and 64-bit systems (padding with zeroes is easy), and because a ${2}^{128}-1$ byte limit exceeds all practical considerations for the time being <em>and</em> the foreseeable future. Two of the most popular hash functions in use today, SHA256 and SHA512, limit their inputs to ${2}^{61}$ and ${2}^{125}$ bytes, respectively, meaning that a ${2}^{128}-1$-byte limit exceeds the specified limits of the most popular underlying hash functions, anyway. If you’re pushing the edges of SequenceHash, you’ve already blown past the limits of SHA256 and SHA512.</p>
<p>We use byte counts for simplicity. Nearly all hashing today is performed in software on strings of 8-, 16-, 32-, or 64-bit values. Systems using non-byte-length strings are very rare nowadays, and we believe it should be up to implementers of such systems to provide their own byte padding if they want to use SequenceHash.</p>
<p>Like HMAC, SequenceHash uses a double-hash construction to prevent length extension attacks. This structure also allows us to support a keyed variant, SequenceMAC, which accepts keys up to ${2}^{128}-1$ bytes in length.</p>
<p>One downside of the original HMAC construction is that it’s subject to what are known as “key pseudocollisions.” HMAC keys can be any length, but if they’re longer than a certain cutoff value (that depends on the hash), they get hashed before use. This means that every “long” key has a “short” representation that produces the exact same outputs. If you’re careful about specifying and enforcing key lengths in protocols, you can guard against this sort of problem, but if you’re not careful, somebody could present two versions of the “same” key in different contexts, allowing them to engage in shenanigans.</p>
<p>Another form of key pseudocollision is key extension. As far as HMAC is concerned, the 8-bit key <code>0xff</code> is the same as the 16-bit key <code>0xff00</code> and the 128-bit key <code>0xff000000000000000000000000000000</code>. Appending zeroes to a key doesn’t actually change it (unless it goes beyond the length cutoff, at least). This sort of pseudocollision is a bit more insidious, because it’s the sort of thing that can show up accidentally; it’s not hard to imagine unintentionally passing a 128-bit key instead of a 256-bit key, or incorrectly setting a length indicator somewhere.</p>
<p>The keyed variant of SequenceHash, SequenceMAC, incorporates key lengths into a header block that is part of the hash. As a result, HMAC-style long-key pseudocollisions are hard to find: if a key needs to be preprocessed by hashing, supplying the hash of the raw key is <em>not</em> the same as supplying the raw key. Trailing zeroes in a SequenceMAC key are semantically significant.</p>
<p>SequenceHash and SequenceMAC support customization strings for domain separation, similar to TupleHash’s customization strings. Customization strings can be up to ${2}^{128}-1$ bytes in length, and they’re only integrated into the <em>outer</em> hash function, allowing developers to derive multiple hashes from the same set of inputs <em>without</em> rehashing everything.</p>
<h2 id="how-do-i-use-it">How do I use it?</h2>
<p>Glad you asked! We already have three implementations available: <a href="https://github.com/trailofbits/sequencehash-rs">Rust</a>, <a href="https://github.com/trailofbits/sequencehash-go">Go</a>, and <a href="https://github.com/trailofbits/sequencehash-py">Python</a>. We also have a <a href="https://c2sp.org/sequencehash">specification</a> available as part of the C2SP, with <a href="https://github.com/C2SP/CCTV/tree/main/sequencehash">test vectors</a> available in case you want to write your own implementation.</p>
<p>The main feature that distinguishes the SequenceHash API from other APIs is that all updates to SequenceHash and SequenceMAC objects are <em>atomic</em>. That is, each time you write a value to a hashing object, it will be added to the hash as an independent, length-encoded object.</p>
<p>We have worked to make sure that the SequenceHash and SequenceMAC APIs are similar, but not identical, to the standard APIs for each language. The Go cryptographic library’s <code>hash.Hash</code> interface incorporates the <code>io.Writer</code> interface, which guarantees that writing two values in sequence is the same as writing their concatenation. The Python hash library makes similar guarantees for the PEP 247 <code>update</code> function.</p>
<p>Let’s see what happens when we hash our example values above using SequenceHash:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">import</span> <span class="nn">sequencehash</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0Test 1Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1Test 2'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span></span></span></code></pre>
</figure>
<p>We get the following output:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">6eea7264b266d35bd5e483ef042189d2cebe51f9e8b764b90b0f9c82185de7ca
</span></span><span class="line"><span class="cl">1469d91e90c1d9c6189f576822e900f5cc8c3cdbd2ec51256df649d37c1688f7
</span></span><span class="line"><span class="cl">1800a2188e126c79dac8f7cf7e38a66e3f797654c15a5e49248a94d4e99bcaae</span></span></code></pre>
</figure>
<p>The three outputs are all unrelated. That’s because each of the inputs is length-encoded, meaning that feeding <code>Test 0</code> and <code>Test 1</code> into consecutive calls to SequenceHash is <em>not</em> the same as feeding <code>Test 0Test 1</code> into a single call.</p>
<p>We can also try hashing identical inputs with different customization strings:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">import</span> <span class="nn">sequencehash</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result_with_customizer</span><span class="p">(</span><span class="sa">b</span><span class="s1">'CUST 0'</span><span class="p">)</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result_with_customizer</span><span class="p">(</span><span class="sa">b</span><span class="s1">'CUST 1'</span><span class="p">)</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceHash</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result_with_customizer</span><span class="p">(</span><span class="sa">b</span><span class="s1">'CUST 2'</span><span class="p">)</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span></span></span></code></pre>
</figure>
<p>Again, we have three unrelated outputs:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">3e54b5cd60ef78773dcf14c5f65ed593726a981f2c80045db7fac03015cc07ad
</span></span><span class="line"><span class="cl">3c5b12ea6952714fed499796a743b103de97575fc938aab7d154cc6c605984a9
</span></span><span class="line"><span class="cl">706af798b32b12c9f508c16c3411b594227f79936a3cc521e6e1f362b1ef3a38</span></span></code></pre>
</figure>
<h2 id="sounds-cool-what-about-sequencemac">Sounds cool. What about SequenceMAC?</h2>
<p>SequenceMAC works like SequenceHash, but with a 32-byte or longer key. As with SequenceHash, we can see that shifting the boundaries between our inputs leads to different results:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-py" data-lang="py"><span class="line"><span class="cl"><span class="kn">import</span> <span class="nn">sequencehash</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">KEY</span> <span class="o">=</span> <span class="nb">bytes</span><span class="o">.</span><span class="n">fromhex</span><span class="p">(</span><span class="s2">"c5d6670f20adad622292a404dc5496cd6692fee636b5935a18451c985b7277bc9cacbc26e5473f85cfc6a64e96d0b98e7b9b604eaebc8899971e1a97dc3caa3a"</span><span class="p">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceMAC</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="n">KEY</span><span class="p">,</span> <span class="n">digestmod</span><span class="o">=</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceMAC</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="n">KEY</span><span class="p">,</span> <span class="n">digestmod</span><span class="o">=</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="n">hasher</span> <span class="o">=</span> <span class="n">sequencehash</span><span class="o">.</span><span class="n">SequenceMAC</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="n">KEY</span><span class="p">,</span> <span class="n">digestmod</span><span class="o">=</span><span class="s1">'sha256'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 0'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">''</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="n">hasher</span><span class="o">.</span><span class="n">add</span><span class="p">(</span><span class="sa">b</span><span class="s1">'Test 1'</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="nb">print</span><span class="p">(</span><span class="n">hasher</span><span class="o">.</span><span class="n">result</span><span class="p">()</span><span class="o">.</span><span class="n">hex</span><span class="p">())</span></span></span></code></pre>
</figure>
<p>This gives us the following output:</p>
<figure class="highlight">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">9a24e4209dad98d2e1f1eecd62aa2908234f1eed2963395292fd9718129fe258
</span></span><span class="line"><span class="cl">4e4b71b8bb7b2c80e9f9ca89cb8bff43cd77cc5b530fc5f163069e5dda2876cb
</span></span><span class="line"><span class="cl">6faf7818842f5a208dc306afe83ed7bea5b3fadc2a617c2208e836709f925889</span></span></code></pre>
</figure>
<p>Changing the key, or using <code>result_with_customizer</code> with different customization values, will also provide different outputs.</p>
<h3 id="some-notes-on-key-size">Some notes on key size</h3>
<p>One important point is that SequenceMAC has a <em>minimum</em> key size of 32 bytes (256 bits). Coupled with a good 256-bit hash function, this corresponds to about a 128-bit security level against forgery attacks. As with HMAC, key sizes should generally be at least as long as the output of the hash.</p>
<p>Additionally, while SequenceMAC supports keys up to ${2}^{128}-1$ bytes in length, it’s important to remember that “longer key” is not the same as “higher security.” The underlying hash function and the key-preprocessing step (which hashes keys longer than the underlying hash function’s block size) impose a hard cap on the total security SequenceMAC can provide. Using keys longer than the length of the hash output is generally not a good idea.</p>
<p>For hash functions with outputs smaller than 256 bits (such as SHA224 or RIPEMD160), the security level should be equal to about half the hash length (112 bits for SHA224 and 80 bits for RIPEMD160), which does not match the security of the minimum key size. While SequenceMAC can be used with such hash functions, the SequenceMAC specification only <em>prohibits</em> short keys and <em>strongly discourages</em> the use of hash functions with short outputs.</p>
<h2 id="what-about-extensible-output-functions-xofs">What about extensible output functions (XOFs)?</h2>
<p>Excellent question! We don’t have an answer yet!</p>
<p>We haven’t specified SequenceXOF, but it’s definitely something we’re thinking about. Right now, XOFs aren’t as widely used as hashes, so the APIs are a little less stable. We want to proceed carefully to ensure we cover all the relevant use cases.</p>
<h2 id="what-if-i-want-to-write-my-own-implementation">What if I want to write my own implementation?</h2>
<p>We love to see high-quality implementations! There are many languages where someone might find SequenceHash and SequenceMAC useful, and there are certainly ways to customize the current APIs to better fit your needs!</p>
<p>First, <a href="https://github.com/C2SP/C2SP/blob/main/sequencehash.md">check out the specification</a>. The document is kinda long, but the structure is straightforward. If you’ve implemented HMAC before, SequenceHash and SequenceMAC will feel like fancy versions of that.</p>
<p>Second, if your target language is similar to Rust, Go, or Python, consider porting over our initial implementations. We’ve tried to keep these implementations as clean as we can, so they’re easy to audit and other cryptographers can learn from them.</p>
<p>Finally, whatever you do, don’t forget to check your implementation against the <a href="https://github.com/C2SP/CCTV/tree/main/sequencehash">test vectors</a>. The test vectors aren’t simple known-answer tests, either: they include intermediate values that can be used to help debug and validate your implementation.</p>
<h2 id="some-minor-caveats">Some minor caveats</h2>
<p>SequenceHash provides for a specific set of needs: customization and domain separation, preventing length extension attacks where applicable, and—most importantly—ensuring that your inputs don’t get mixed together in a dangerous way. It’s a tool, not a panacea.</p>
<p>You still need to make sure you’re hashing <em>the right</em> inputs. Being able to decode a value doesn’t mean that two pieces of software will encode that value in <em>the same way</em>, and that can lead to compatibility issues among different servers, clients, and libraries. JSON and XML, for instance, don’t always guarantee field orderings. Even for strings, it’s important to make sure you’re using a consistent encoding method (“all the world is ASCII” isn’t true and never has been).</p>
<p>In the case of Fiat-Shamir transforms, you still have to be careful about <a href="https://eprint.iacr.org/2023/691">including <em>all</em> your inputs</a>. Schnorr proofs should always include the group descriptor (whether as individual values or named parameter sets), the generator element, etc. When the output is supposed to be interpreted as an integer modulo some other value, it’s also important to make sure that you select a hash with an output large enough to avoid modulo bias. Cryptography is subtle; there are always intricacies to consider.</p>
<p>Still, as long as you’re careful to keep your inputs consistent and include all your values, SequenceHash and SequenceMAC make it easy to ensure nobody can pretend your inputs mean something other than what they’re supposed to mean.</p>
<p>The specification is live at C2SP, and our Rust, Go, and Python implementations are ready to use today, with test vectors available if you want to write your own. Try it out and let us know what you think!</p>A fair use argument for AI - destructuredhttps://destructured.net/fair-use-ai2026-10-02T04:00:00.000Zdestructured<p>Researchers have shown that you can <a href="https://arxiv.org/abs/2505.12546">substantively reproduce copyrighted materials</a> using a generative AI model that has been trained on that work. It stands to reason, then, that you cannot determine whether or not AI use is transformative at the training stage. Ergo, copying materials for AI training should not be considered fair use by default. The types of output made possible by that training bear too much on the question.</p>
<p>However, there is an argument to be made that <em>part</em> of a training model is transformative, and therefore fair use, namely the statistical data. LLMs work by deriving statistical relationships between slices of linguistic samples. Those statistics really are original work, which means that, on the fair use argument, model producers should be allowed to publish and/or monetize them. The catch is that those data are what allows for ad hoc reconstruction of the original, copyright-protected text.</p>
<p>By way of analogy, consider literary commentaries. Legally, I can publish a commentary for DeLillo’s <em>White Noise</em>. That commentary is a derived work, roughly analogous to the way AI companies derive statistical models from their training data, and is considered fair use. Subject to reasonable standards, I can even include portions of <em>White Noise</em> in my commentary as quotations; that’s also fair use. What I can’t do is include the entirety of the novel in my published commentary; that wouldn’t be fair use. <em>White Noise</em> is still under copyright, so if I want to publish the novel with my commentary, I have to license that text. By that logic, AI companies should be able to derive and publish their commentary (i.e. statistical data), but should be limited in how much they can include of the text from which they derived it.</p>
<p>Bible concordances make for an even closer analogy, since they come much closer to atomizing a text and attaching additional data to each atomic part. That’s pretty transformative, but doesn’t automatically trigger fair use. You can publish a concordance alongside a copy of the King James Version, but only because the KJV has been part of the public domain for centuries. You can’t publish it alongside the New International Version because that translation is more recent and still subject to copyright.</p>
<p>Let’s try a more technical hypothetical. Say I make a digital copy of <em>White Noise</em> and run it through a program that breaks the text into three-letter chunks, then scrambles those chunks. That’s a transformative process, making the original text practically unrecognizable. Would publishing the scrambled doc be fair use? Almost certainly.</p>
<p>Now suppose that I package it with a program that puts those chunks back in their original order. Well, that changes things. That sounds less like fair use than an exploit for circumventing copyright.</p>
<p>AI training models, as it turns out, are basically instruction sets for reconstructing chunked and scrambled materials. The producers of those models are entitled to the statistical data they derive from feeding them copyrighted training data, but packaging that training data with the statistical data and a parser capable of reassembling the copyrighted materials effectively invalidates fair use.</p>
<p>Generative AI companies could probably create fair use models if they were willing to sacrifice significant capabilities — for example, the ability to answer a question like, “What does Murray say about the barn in ch. 3 of <em>White Noise</em>?” If an LLM can answer that question correctly, it’s because the model contains both statistical data on the order of tokens in <em>White Noise</em> <em>and</em> the tokens to which they pertain. With enough of those two types of data, a breach of copyright is always possible, provided you can point the model <a href="https://destructured.net/ai-as-trebuchet">along the right trajectory</a>.</p>
<p>If, instead, the companies trained their models on <em>White Noise</em> to fine-tune its stats about English language token order in general, then disposed of any <em>White Noise</em>-specific in that training data, that would likely qualify as transformative, since reconstructing the novel would no longer be possible. It would also mean LLMs could no longer answer questions about copyrighted materials, which would seriously undercut their function as general knowledge machines, effectively decimating the industry’s current business model.</p>
<p>But that’s also not my problem.</p>Sunrise - James' Coffee Bloghttps://jamesg.blog/2026/10/02/sunrise2026-10-02T00:00:00.000ZJames' Coffee Blog
<p>At this time of year, the sun begins to rise around the time I wake up. This means I can see the colours of the sunrise; how the sunlight changes the sky. While autumn and winter can be cold, the colours bring the seasons to life. Lately, I have been motivated not only to start my day, but to start writing by the later-rising sun. <em>I can always write about the colours.</em></p>
<p>Standing by the window, I started writing.</p>
<p><em>When the sun first shines through the clouds and illuminates the tops of trees with a soft glow; small planes of light shine on the field nearby. The clouds in the other distance are glowing orange with a faint lavender; you can see the blue sky behind the light clouds. It is as if the world is saying hello.</em></p>
<p>The soft yellow light cast on the fields and trees was short-lived, only present at precisely the moment when there must have been a gap between the light grey clouds, one allowing the intense light to shine in the glowing way that it does. I haven’t seen enough cloudy sunrises to know whether when the clouds are glowing it means the sun is rising over the horizon, or whether the sun has already risen. I have a feeling it may be the former; I will have to study more sunsets to know for sure. Writing this brought to mind the feeling of being up early on a trip three years ago; so magnetic in memory is bright energy.</p>
<p>I am looking forward to the day ahead.</p>
<script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'a4420a281bcfaa8f',t:'MTc5MDkyNjYyNA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script>
I Was a Guest on The Pen Addict
- Robb Knight • Posts • Atom Feedhttps://rknight.me/blog/i-was-a-guest-on-the-pen-addict-736/2026-10-01T13:08:15.000ZRobb Knight<p>Brad is walking in Memphis this week for the <a href="https://www.youtube.com/live/y4PRZ4WanVI?si=tnMX2ZuL31LMfoCl">podcastathon</a> so we recorded this episode a couple of weeks ago.</p>
<p>We talked about the incentives we're both offering for St Jude and the work that goes into those as well as my progress as an "artist", and <a href="https://jimothy.rknight.me">Jimothy</a>. Then we discussed finishing notebooks and inks, and finished off with <a href="https://rknight.me/blog/analog-defaults/">my analog defaults</a>. There's still a few days to <a href="/stjude">donate to St Jude</a>.</p>
<p><a href="https://relay.fm/penaddict/689">Listen to The Pen Addict 736: I’ll Keep You All Knight</a></p>
My Inktober Setup
- Robb Knight • Posts • Atom Feedhttps://rknight.me/blog/my-inktober-setup/2026-10-01T12:41:59.000ZRobb Knight<p>It's <a href="https://inktober.com/">Inktober</a> again which means I'm drawing one thing a day, in ink, from the official<sup class="footnote-ref"><a href="#fn1" id="fnref1">[1]</a></sup> prompt list. I'm tagging my posts with <a href="/blog/tags/inktober">#Inktober</a> and <a href="/blog/tags/inktober2026">#Inktober2026</a> — these tag pages are flagged to render the images in a gallery instead of the usual notes pages. My <a href="https://rknight.me/notes/202610010735/">first drawing is up</a> as of this morning.</p>
<p>As much as I love Jeff the dinosaur from <a href="/blog/tags/inktober2025">last year</a><sup class="footnote-ref"><a href="#fn2" id="fnref2">[2]</a></sup> it's too easy to fall back on "Jeff does/interacts with whatever the prompt is" so this year will be mostly Jeff-free. Last year my drawings were all over the place in terms of size so this year I bought a 12x12 Sakura sketchbook — I'll be using this exclusively for Inktober for the next few years. Unlike last year when I used Uni Pins, I'm a big Sakura Micron boy now. I talk more about this on <a href="https://relay.fm/penaddict/736">this week's episode of The Pen Addict</a> which will be out in a few hours.</p>
<figure><img src="https://cdn.rknight.me/site/2026/inktober-setup.jpg" alt="A pink cutting board with a black square notebook on it. Next to it is a mechanical pencil with Pikachu on it and a Sakura micron fineliner" /><figcaption>I love my Pikachu Kuru Toga</figcaption></figure>
<p>One of the things with projects like this is I want to be consistent with how I'm posting stuff. Last year I would have to go back to the previous days post to see if I did a full stop or colon after the day number, did I put the prompt in quotes, what about the filename? So I set up two Alfred snippets — one for the filename and one for the post itself. Snippets is a feature <a href="https://rknight.me/blog/snippets-i-use-regularly/">I use a lot</a> for other things.</p>
<pre class="language-bash"><code class="language-bash"><span class="token comment"># INKtober Filename</span><br /><span class="token punctuation">;</span>inkf<br /><span class="token comment"># raw</span><br />inktober-2026-<span class="token punctuation">{</span>date:dd<span class="token punctuation">}</span>-<br /><span class="token comment"># becomes</span><br />inktober-2026-01-<br /><br /><span class="token comment"># INKtober Post</span><br /><span class="token punctuation">;</span>inkp<br /><span class="token comment"># raw</span><br />Day <span class="token punctuation">{</span>date:dd<span class="token punctuation">}</span> - <span class="token punctuation">{</span>cursor<span class="token punctuation">}</span><br /><br /><span class="token operator">!</span><span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token punctuation">(</span>https://cdn.rknight.me/site/2026/inktober-2026-<span class="token punctuation">{</span>date:dd<span class="token punctuation">}</span>-.jpg<span class="token punctuation">)</span><br /><span class="token comment">#becomes</span><br />Day 01 - <br /><br /><span class="token operator">!</span><span class="token punctuation">[</span><span class="token punctuation">]</span><span class="token punctuation">(</span>https://cdn.rknight.me/site/2026/inktober-2026-01-.jpg<span class="token punctuation">)</span></code></pre>
<hr class="footnotes-sep" />
<section class="footnotes">
<ol class="footnotes-list">
<li id="fn1" class="footnote-item"><p>I've heard some not great things about the official folks and "licensing" the name but nothing substantial so I'm sticking with it <a href="#fnref1" class="footnote-backref">⤾</a></p>
</li>
<li id="fn2" class="footnote-item"><p>And let's not even talk about <a href="https://rknight.me/blog/doodle-scan/">Knobgate</a> <a href="#fnref2" class="footnote-backref">⤾</a></p>
</li>
</ol>
</section>