Shellsharks Blogroll - BlogFlock2026-08-01T22:56:28.549ZBlogFlockAdepts of 0xCC, destructured, fLaMEd, Aaron Parecki, Trail of Bits Blog, James' Coffee Blog, Westenberg, gynvael.coldwind//vx.log (pl), joelchrono, Evan Boehs, Kev Quirk, cool-as-heck, Posts feed, Sophie Koonin, <span>Songs</span> on the Security of Networks, cmdr-nova@internet:~$, Werd I/O, Johnny.Decimal, Robb Knight, Molly White, Hey, it's Jason!, Terence Eden’s BlogMiley Cyrus, what's going on? - The Weblog of fLaMEdhttps://flamedfury.com/posts/miley-cyrus-whats-going-on/2026-08-01T21:35:29.000Z<p>What’s going on, Internet? I jumped on YouTube and found six new Miley Cyrus videos sitting there waiting for me. Six of them. Was this the rollout of a new album? Why hadn’t I heard about this already?</p>
<p>It wasn’t. They’re just videos for <a href="https://flamedfury.com/recordshelf/records/something-beautiful-red-translucent/">Something Beautiful</a>, last year’s record, and they’re the last pieces of the <a href="https://www.themoviedb.org/movie/1393017-miley-cyrus-something-beautiful" rel="noopener">pop opera film</a> that went with it. I caught the film when it came out last year in the theatre but never came back to the album.</p>
<p>These were all released 17 hours ago, when were they made? Is she just emptying the vault before a new rollout?</p>
<p>Let’s have a quick surf around the web to see what’s going on.</p>
<p>She’s had a big week, is what’s going on. On the 27th she guest edited <a href="https://www.wonderlandmagazine.com/2026/07/27/miley-cyrus-wonderland-summer/" rel="noopener">Wonderland’s summer issue</a>. Next day she <a href="https://happymag.tv/miley-cyrus-signs-to-atlantic-records-and-details-next-career-chapter/" rel="noopener">signed to Atlantic</a>. Columbia’s done after Endless Summer Vacation and Something Beautiful. Four days after that, six videos.</p>
<p>Turns out it’s just a clear out. Everything left over gets dumped on YouTube.</p>
<p>The next one will be her tenth. Something Beautiful was an experimental album, will the tenth be similar? Who knows. She’s never really made the same record twice. Good for her, but it’s also why I keep going back to my favourites.</p>
<p>Not the new album I got excited about, then. Here are the six new videos.</p>
<div class="youtube-embed"> <lite-youtube videoid="HX62-8613bk" style="background-image: url('https://i.ytimg.com/vi/HX62-8613bk/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Interlude 1</span>
</button>
</lite-youtube></div>
<div class="youtube-embed"> <lite-youtube videoid="_fpq0STLw24" style="background-image: url('https://i.ytimg.com/vi/_fpq0STLw24/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Reborn</span>
</button>
</lite-youtube></div>
<div class="youtube-embed"> <lite-youtube videoid="WtdDxM0YFZ0" style="background-image: url('https://i.ytimg.com/vi/WtdDxM0YFZ0/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Give Me Love</span>
</button>
</lite-youtube></div>
<div class="youtube-embed"> <lite-youtube videoid="VWNNTq8V8mU" style="background-image: url('https://i.ytimg.com/vi/VWNNTq8V8mU/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Pretend You're God</span>
</button>
</lite-youtube></div>
<div class="youtube-embed"> <lite-youtube videoid="XLNFA8hl29Q" style="background-image: url('https://i.ytimg.com/vi/XLNFA8hl29Q/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Interlude 2</span>
</button>
</lite-youtube></div>
<div class="youtube-embed"> <lite-youtube videoid="Z0UKkymdApU" style="background-image: url('https://i.ytimg.com/vi/Z0UKkymdApU/hqdefault.jpg');">
<button type="button" class="lty-playbtn">
<span class="lyt-visually-hidden">Miley Cyrus - Golden Burning Sun</span>
</button>
</lite-youtube></div>
<p>Something Beautiful never lived up to <a href="https://flamedfury.com/recordshelf/records/plastic-hearts/">Plastic Hearts</a> for me, and I kinda just want more of that, but I doubt it. Either way, I’m here for the next era.</p>
<p>Hey, thanks for reading this post in your feed reader! Want to chat? <a href="mailto:hello@flamedfury.com?subject=RE: Miley Cyrus, what's going on?">Reply by email</a> or add me on <a href="xmpp:flamed@omg.lol">XMPP</a>, or send a <a href="https://flamedfury.com/posts/miley-cyrus-whats-going-on/#webmention">webmention</a>. Check out the <a href="https://flamedfury.com/posts/">posts archive</a> on the website.</p>
Open Tabs July 2026 - The Weblog of fLaMEdhttps://flamedfury.com/posts/open-tabs-july-2026/2026-08-01T19:36:28.000Z<p>What’s going on, Internet? If you don’t folllow my <a href="https://flamedfury.com/bookmarks/">Bookmarks</a> through the <a href="https://flamedfury.com/feeds/">feed</a>, then here’s the bookmarks from July. Enjoy.</p>
<ul class="list">
<li><a href="https://blog.ctms.me/posts/2026-03-14-rant-stfu-about-blogging/" rel="noopener">Rant about blogs and the IndieWeb - Dom Corriveau</a> Okay, this one had me in tears. Such a good read.</li>
<li><a href="https://blog.absurdpirate.com/your-metablogging-is-lame-as-hell/" rel="noopener">Your Metablogging is Lame as Hell – Absurd Pirate’s Internet Blog</a> Lol, kinda nodding my head here. Blogging about Bear Blog blogs is becoming a bit of a thing, isn’t it?</li>
<li><a href="https://lukealexdavis.co.uk/recortes/dont-let-web-nostalgia-obscure-positive-web-future/" rel="noopener">don’t let Web nostalgia obscure a positive Web future</a> This has always been something I’m an advocate for. Draw inspiration from the 90s/2000s web, but don’t rely on old and outdated hacks. Take advantage of the capabilities we have today, but don’t go overboard with modern bloat.</li>
<li><a href="https://sals.place/blog/pseudonym-as-an-escape/" rel="noopener">Pseudonym as an escape</a> I’ve written about this previously. The pseudonym isn’t hiding; it’s breathing room. Been enjoying not being my IRL name online since 96.</li>
<li><a href="https://meiert.com/blog/websites-are-not-going-to-die/" rel="noopener">Websites Are Not Going to Die</a> If Google stops linking to websites, it stops being a search engine. Another good reminder to keep the personal website going while corp search eats itself.</li>
<li><a href="https://www.gordonmclean.co.uk/2026/06/18/on-the-indiefediactivitymastoweb/" rel="noopener">The Web Won Because It Got Easier</a> Worth a read for anyone pushing the indie web. Knowing how it all works doesn’t make it easy for the next person.</li>
<li><a href="https://sive.rs/netizen" rel="noopener">Netizen</a> Contributing to the internet for the good of it, not for profit. Now I’m wondering what my netizen contributions will be…</li>
<li><a href="https://www.thefrugalgamer.net/blog/2026/05/06/the-music-discovery-problem/" rel="noopener">The Music Discovery Problem</a> Music discovery takes intentional effort once the algorithm’s gone, and that’s fine. I should write up and document my discovery process.</li>
<li><a href="https://olly.world/we-need-a-physical-digital-music-experience" rel="noopener">We need a physical digital music experience</a> Olly’s model already exists in the audiobook world. <a href="http://libro.fm/" rel="noopener">Libro.fm</a> sends a slice of my audiobook purchases to my local (physical) bookstore.</li>
<li><a href="https://www.neatnik.net/hardcore-indieweb" rel="noopener">Hardcore IndieWeb: Run your own website 100% independently for only $0.01/day</a> Great read.</li>
<li><a href="https://svbck.blog/getting-back-into-the-mood-for-blogging" rel="noopener">The Overthinkers Guide to rekindle your Blogging Mojo</a> Maybe some inspiration for some of you to start writing again. Sometimes I just cbf writing, lol</li>
<li><a href="https://folkmoss.bearblog.dev/list-of-things-i-love-seeing-in-personal-webspaces/" rel="noopener">List of things I love seeing in personal webspaces</a> A non-exhaustive list of things Folkmoss love seeing in blogs/personal websites.</li>
<li><a href="https://ratfactor.com/cards/personal-website" rel="noopener">What should a personal website be?</a> Ratfactor asks about what a website should be. A reflection of yourself, not some idea of what a website is meant to be.</li>
<li><a href="https://kevinboone.me/ai.html" rel="noopener">Kevin Boone: Why Idon’t really care if web content is AI-generated</a> Kevin Boone talks about how scepticism should apply to everything online, not just the AI-generated stuff. Trust the source you know, not the medium. It feels like people forget how crap search results have been since 2008 with the rise of “SEO Spam”. Humans have been shit long before AI.</li>
<li><a href="https://dirtylittlezine.com/" rel="noopener">Dirty Little Zine — Free 8-Page Printable Zine Maker</a> Super cool little tool that will help you create simple 8-page zines</li>
<li><a href="https://tedium.co/2026/07/01/online-web-forums-retrospective/" rel="noopener">What We Lost When We Quit Using Crappy Old Web Forums</a> A fantastic read about forum software all the way from Usenet to Discourse, which is where we ended up at the 32-Bit Cafe, same as every other forum these days. RIP phpBB.</li>
<li><a href="https://web-weaving.jamesg.blog/11" rel="noopener">#11: fLaMEd Fury (flamedfury.com) - Wonders of Web Weaving</a> So, I did a podcast. James had me on his podcast to talk about my corner of the web. We got into gaming and TV communities, music, and why the indie web is worth it.</li>
</ul>
<p>For more, check out the <a href="https://flamedfury.com/bookmarks/">bookmarks</a> archive, and subscribe to the <a href="https://flamedfury.com/feeds/">feeds</a> if you want these as they happen.</p>
<p>Hey, thanks for reading this post in your feed reader! Want to chat? <a href="mailto:hello@flamedfury.com?subject=RE: Open Tabs July 2026">Reply by email</a> or add me on <a href="xmpp:flamed@omg.lol">XMPP</a>, or send a <a href="https://flamedfury.com/posts/open-tabs-july-2026/#webmention">webmention</a>. Check out the <a href="https://flamedfury.com/posts/">posts archive</a> on the website.</p>
My next experiment - Werd I/O6a6e2bf55f10030001b689472026-08-01T17:36:11.000Z<img src="https://storage.ghost.io/c/18/7c/187cc681-d3f3-49fc-87de-b01d06b76821/content/images/2026/08/2027-banner-cities_0.png.webp" alt="My next experiment"><p>On Thursday, I left my role as Senior Director of Technology at <a href="https://propublica.org">ProPublica</a>, where I led IT, Security, and Engineering. In September, I will begin my <a href="https://jsk.stanford.edu/">John S. Knight Journalism Fellowship at Stanford University</a>. Which means that, during August, I will move with my family back to the San Francisco Bay Area and be based in the vicinity of the Stanford campus.</p><h3 id="what-can-you-expect-from-me">What can you expect from me?</h3><p>In August, my writing will likely be more sporadic. From September, I expect to spend more time documenting my research, opening conversations, and being intentional about pushing forward the ideas I’ve always held space for.</p><p>My thesis is that community — and open community protocols and platforms — can help build trust, loyalty, and resilience in news. I laid out some of those ideas in <a href="https://werd.io/the-community-first-software-era/">The Community-First Software Era</a>. But I’m going into it with an ethos of <a href="https://pointc.co/create-intentional-serendipity/">intentional serendipity</a>, armed with <a href="https://werd.io/about">everything I’ve learned</a> about leadership, technology, journalism, and entrepreneurship. I’ll <em>also</em> be armed with everything I <em>will</em> learn with Stanford as a platform. I can’t predict what I’ll emerge with — but I can commit to taking you along with me.</p><h3 id="where-else-can-you-find-me">Where else can you find me?</h3><p>I’m going to endeavor to stick close to Stanford over the next year. I’ve also decided that I won’t get on a plane for the rest of 2026, partially as a challenge to myself and partially as a reaction to some really bad flights earlier this year.</p><p>But I’m making an exception for <a href="https://newsproduct.org/summit">the News Product Alliance Summit</a> in Chicago from October 21-23. Last year I found it to be the most substantive conference about news product and technology I’d been to. I was lucky enough to present two sessions and loved the experience. So I’m back, with <a href="https://knightlab.northwestern.edu/people/joe-germuska/">Joe Germuska</a>, to talk about <a href="https://schedule.newsproduct.org/">how newsrooms can benefit from open technology and protocols</a>:</p><blockquote>Proprietary social media platforms have inserted themselves between newsrooms and the things journalism needs to survive: engagement, trust, and revenue. As AI creates new layers of intermediation and puts newsrooms at further risk, building direct relationships with your own audiences has never been more urgent.<br><br>Drawing from our combined experience building technology for newsrooms, we'll make the case for open protocols — shared, interoperable technologies no single company controls — as the foundation for a healthier news ecosystem. We'll explore how building on open infrastructure, rather than proprietary platforms, helps publishers reach more people, deepen engagement, and control their own destinies, without losing out on user experience or adding complexity.</blockquote><p>I’m hoping to put on more events in California through Stanford, so watch this space.</p><h3 id="can-we-chat">Can we chat?</h3><p>This work can’t be done in a vacuum. I want to learn and build alongside people who are doing great work, led by important values.</p><p>If anything I’ve spoken about above — or anything I write in this space — resonates with you, I’d love to chat. In September I’ll resume my Open Office Hours and will be available both to chat online and over a coffee for folks who might be in the Bay Area.</p><h3 id="a-note-about-propublica">A note about ProPublica</h3><p>I truly loved my time leading tech at ProPublica. The phrase we used internally was that it was <em>never boring</em>: there was always something happening. It was sometimes exhilarating, sometimes frustrating, but it was always done with a community of really great human beings working together towards the most meaningful mission of my career.</p><p>That mission runs deep throughout the newsroom:</p><blockquote>To expose abuses of power and betrayals of the public trust by government, business, and other institutions, using the moral force of investigative journalism to spur reform through the sustained spotlighting of wrongdoing.</blockquote><p>Some newsrooms report. Some observe and have a view from nowhere. ProPublica exists to <em>spur reform</em>, and <a href="https://www.propublica.org/impact">its impact showcase</a> demonstrates that it succeeds. Every workplace has things to improve or friction to overcome — they’re all works in progress — but it was hugely motivational to be working alongside these incredible people for this incredible reason.</p><p>The day after I left, <a href="https://www.propublicaguild.org/updates/propublica-guild-ratifies-first-contract">the ProPublica Guild ratified its first contract</a>. It was a long, fraught conversation that had been happening almost the entire time I was at the organization. (My timing is impeccable.) I wasn’t a part of the Guild or manager bargaining, but I couldn’t say anything about it while the negotiation was happening for fear of accidentally interfering with the process.</p><p>I’m very glad everyone got there: every worker deserves a good union to support them, and the people who work to publish ProPublica’s journalism – across editorial and business teams – certainly deserve a great deal.</p><p>I will be cheerleading for ProPublica forever, and I hope to be friends with the people behind it forever. I’m grateful that I was able to be a part of that community. And if you’re looking for a place to financially support that drives real change, <a href="https://give.propublica.org/campaign/748664/donate?c_src=im_just_ben">there are much worse places to donate</a>.</p>Mead Recipe - Smoldering Pear & Star Anise Bochet - Cool As Heckhttps://cool-as-heck.blog/mead-recipe-smoldering-pear-star-anise-bochet2026-08-01T14:38:00.000Z<div>Every month I do some research and get inspired by other brewers and mead makers and try to come up with an interesting mead recipe. Here's my idea for August 2026. This doesn't mean I'll be making it this month, but it's going on the list of things to try, and features some new methods like caramelizing the honey and using Voss Kveik yeast.</div>
<div><br></div>
<div>This recipe is a bochet. If you haven't tried one, it's mead made with honey that's been cooked until it darkens and smells like toasted marshmallow. The heat changes the chemistry. You get unfermentable sugars and Maillard compounds that give you a natural semi-sweet finish without any chemical stabilization. It's one of the few ways to make a mead that doesn't need sulfites or sorbate to stay sweet.</div>
<div><br></div>
<div>This batch pairs that caramelized base with dried pear and star anise. The yeast is Voss Kveik, which I keep wanting to try because it ferments hot and fast without producing fusel alcohols. At 86°F it throws off bright orange esters that cut through the richness of the caramel. The dried pear goes in during secondary; fresh pear is mostly water and dilutes the flavor, but dried pear rehydrated in the mead itself gives you a concentrated, honeyed fruit note.</div>
<div><br></div>
<div>Star anise is the risky one. Two pods, lightly crushed, and you have to taste every three days starting at day seven. It goes from subtle to medicinal fast, and it keeps building in the bottle. I'd rather under-spice and add more next time than overdo it and dump the batch. It can get out of control fast.</div>
<div><br></div>
<div>The full process is below. Fair warning: caramelizing honey can be the most dangerous thing you'll do in meadmaking. It foams to three or four times its volume and holds heat like napalm. Use a pot at least six quarts, wear long sleeves, and add water drop by drop at first or it seizes into hard candy.</div>
<div><br></div>
<div>---</div>
<div><br></div>
<div>Ingredients (1 gallon)</div>
<div><br></div>
<div>Wildflower honey 3.0 lbs Raw, not buckwheat</div>
<div>Spring water ~0.8 gal Top up to 1 gallon total</div>
<div>Voss Kveik yeast 3 g Lallemand LalBrew Voss</div>
<div>Go-Ferm 3.75 g Rehydration nutrient</div>
<div>Fermaid O 4.0 g total 4 doses, TOSNA schedule</div>
<div>Dried Bosc pears 4 halves Unsulfured</div>
<div>Star anise 2 pods Lightly crushed</div>
<div>Black tea 1 cup Steeped 5 min, cooled</div>
<div>French oak cubes 7 g Medium toast, optional</div>
<div><br></div>
<div>Process</div>
<div>Caramelize the honey. Cook 3 lbs honey in a 6+ quart pot over medium heat, stirring constantly. It'll foam violently, then subside. Keep going 45–55 minutes until it's deep mahogany and smells like toasted marshmallow and dark caramel. Remove from heat, cool to 180°F, then trickle in 1 cup warm water drop by drop. Add a second cup once it's incorporated.</div>
<div><br></div>
<div>Build the must. Combine the caramelized honey, 1 cup cooled black tea, and enough spring water to hit 1 gallon. Shake for 2 minutes to aerate. Check OG — you want ~1.112. Temperature should be 85–90°F.</div>
<div><br></div>
<div>Pitch the yeast. Rehydrate 3 g Voss Kveik with 3.75 g Go-Ferm in 50 mL water at 104°F for 15 minutes. Pitch into the warm must, seal with an airlock, and hold at 85–95°F.</div>
<div><br></div>
<div>This one is daunting but very interesting and could be a great learning opportunity. I'm excited to try this out, but it might have to wait for next summer.</div>📝 2026-08-01 15:28: Our new addition to the family, Nelly, has arrived and she's causing havoc already. 🤣 - Kev Quirkhttps://kevquirk.com/2026-08-01-15282026-08-01T14:28:00.000Z<p>Our new addition to the family, Nelly, has arrived and she's causing havoc already. 🤣</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-08-01-1528/1000010826.webp" alt="1000010826" /></p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-08-01-1528/1000010828.webp" alt="1000010828" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=%F0%9F%93%9D%202026-08-01%2015%3A28">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-08-01-1528#comments">leave a comment</a>.</p>
</div>📝 2026-08-01 13:46: Signed up for a Vinted account. My options to "secure my account" were adding a... - Kev Quirkhttps://kevquirk.com/2026-08-01-13462026-08-01T12:46:00.000Z<p>Signed up for a Vinted account. My options to "secure my account" were adding a phone number, or to logout.</p>
<p>I fucking hate this side of the internet. Scumbags.</p>
<p><img loading="lazy" src="https://kevquirk.com/content/images/2026-08-01-1346/1000010838.webp" alt="1000010838" /></p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=%F0%9F%93%9D%202026-08-01%2013%3A46">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-08-01-1346#comments">leave a comment</a>.</p>
</div>Gadget Review: HIKMICRO D02 Thermal Camera ★★★★★ - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=733322026-08-01T11:34:43.000Z<p>The good folks at <a href="https://www.hikmicrotech.com/en/">Hikmicro</a> have sent me their D02 Infrared Camera to review. It's part of their "Eco" series of thermal imagers - designed to be easy to use around the home and relatively cheap.</p>
<p>Despite the no-fills appearance, it packs in a lot of features which put some more expensive models to shame. It even works with Linux. Shove in a USB-C cable to grab the photos or even use it as a webcam.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/07/D02.webp" alt="A thermal camera with a screen and a trigger." width="1024" height="576" class="aligncenter size-full wp-image-73335">
<p>All the images you see in this post are <em>unaltered</em>. I haven't optimised them or stripped the metadata; what you see is what you get.</p>
<p>Let's go!</p>
<h2 id="specs-and-pictures"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#specs-and-pictures">Specs and Pictures</a></h2>
<p>Infrared cameras usually have <em>tiny</em> sensors - the D02 is no different, you get 96x96 pixels of thermal information upscaled to 240x240.</p>
<p>Where the D02 shines is that it also has an <em>optical</em> camera just below the thermal sensor. This allows the camera to combine both the thermal and optical images into one "fusion" image.</p>
<p>Here's an example of the thermal image:</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/thermal.jpeg" alt="Thermal image with heat data on screen." width="240" height="240" class="aligncenter size-full wp-image-73343">
<p>The optical image has a higher resolution - 480x640:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/visual.jpeg" alt="Photo of a plug by a consumer unit." width="480" height="640" class="aligncenter size-full wp-image-73345"></p>
<p>It isn't the highest quality lens in the world, but more than adequate for seeing what's going on.</p>
<p>Once fused, the image looks like this:</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/fused.jpeg" alt="A thermal photo with lots more visual detail." width="240" height="240" class="aligncenter size-full wp-image-73346">
<p>With the two images overlayed, you get a reasonably clear photo. The visual shows a good amount of detail and the thermal image shows what's hot.</p>
<p>It mostly works. If you're pointing at something <em>very</em> close to the sensor then you'll end up with a slightly surreal image like this which show the two out of alignment.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/alignment.jpeg" alt="A photo of my hand. The thermal image is slightly offset from the visual image." width="240" height="240" class="aligncenter size-full wp-image-73347">
<p>Storage is limited to around 2.5GB with no SD card slot. But given that photos are typically less than 150KB, you'll fit tens of thousands on there before worrying about running out of space.</p>
<h2 id="videos"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#videos">Videos</a></h2>
<p>Videos are a bit bigger, about 12MB per minute in MP4 format. But, again, you'll be able to store a couple of hours of footage on there without worry.</p>
<p><video width="240" height="240" src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/pot-boiling-1.mp4" controls="" loop="" autoplay="" muted=""></video></p>
<p>Again, 240x240 upscaled. Good enough for domestic use. No audio. What you see is what you get.</p>
<h3 id="exif"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#exif">EXIF</a></h3>
<p>There's not much useful EXIF - just the timestamp and camera serial number. That said, all the images and videos are placed in the <a href="https://www.lifewire.com/why-are-photos-stored-in-a-dcim-folder-2620570">DCIM folder</a> which should make importing them easier.</p>
<p>Some other cameras provide the "raw" thermal data separately - but that's only really useful if you're doing analysis on the data, rather than trying to spot hot / cold spots.</p>
<h2 id="features"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#features">Features</a></h2>
<p>There are a few other nifty features. You can set a schedule to allow it to take pictures periodically - handy if you use the tripod attachment point to place it in a static location.</p>
<p>You can change the type of thermal image taken - there are various palettes available depending on what you're interested in.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/07/HM20260721_171923.jpeg" alt="Thermal image showing a hot USB charger." width="240" height="240" class="aligncenter size-full wp-image-73338">
<p>There are various emissivity profiles depending on what you're pointing at:</p>
<p>You can also fiddle with the distance setting depending on how close you are to the subject. There's also an alarm setting to warn you if something is too hot or too cold.</p>
<p>Finally, you can view back the images and videos on the device. Handy if you can't get to a computer and want to show someone what you've spotted.</p>
<h2 id="user-interface"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#user-interface">User Interface</a></h2>
<p>There's a trigger. Press it once to take a photo. Hold it down to start / stop recording. Pretty much idiot proof.</p>
<p>The rest is a bit flimsy. A combined power / select button, a back button, then up & down arrows. The arrows confused me for a while. Press the up one to change the type of photo you're taking, the down one changes the colour scheme.</p>
<p>There's no touch-screen, haptic feedback, speaker, or anything expensive like that.</p>
<h2 id="linux-and-open-source"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#linux-and-open-source">Linux and Open Source</a></h2>
<p>Works fine as a storage device on Linux, showing up as <code>0525:a4a5</code> "Netchip Technology, Inc. Linux-USB File-backed Storage Gadget". True to its word, it shows up as a standard disk.</p>
<p>Most hardware manufacturers from China ignore their Open Source obligations - but not HIKMICRO. There's a rather prominent menu item in the settings screen which lets you scroll through an almost endless parade of software names and their licences. A bonus star for that!</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/08/Imagepipe_53.webp" alt="Open source statements shown on the camera screen." width="600" class="aligncenter size-full wp-image-73636">
<p>You can also turn on diagnostic logging - that'll slowly fill the disk with log files:</p>
<blockquote><p>[07-21 14:47:40][pid:477][tid:642][GUI][ERROR][minigui_lcd_dsp_update][line:1393] KEY_OK_MSG minigui_lcd_dsp_update GUI_TM_DATA_CAPTURE...</p></blockquote>
<p>Probably not overly useful unless you've got a problem.</p>
<h2 id="webcam"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#webcam">Webcam</a></h2>
<p>On plugging in the camera via USB-C, the screen gives a choice of "USB Drive" or "USB Cast Screen". Toggling to the screen option transforms the device into <code>2bdf:017f</code> a "UVC Camera". In theory, you should be able to use it as a standard WebCam and show others what the D02 is seeing. I couldn't get it to work with Chrome or Firefox directly.</p>
<p>Using <a href="https://docs.arducam.com/UVC-Camera/USB2-UVC-Camera-Kit/Quick-Start-Guide/Linux/#qv4l2">qv4l2</a> I was able to open it as an MJPG stream once I set the resolution to 240x320.</p>
<img src="https://shkspr.mobi/blog/wp-content/uploads/2026/07/Webcam.webp" alt="Screenshot of a thermal image of a smiling man." width="520" height="750" class="aligncenter size-full wp-image-73336">
<p>For those of a technical bent, here's what <code>v4l2-ctl</code> showed as the available formats:</p>
<pre><code class="language-_">ioctl: VIDIOC_ENUM_FMT
Type: Video Capture
[0]: 'MJPG' (Motion-JPEG, compressed)
Size: Discrete 240x320
Interval: Discrete 0.033s (30.000 fps)
Size: Discrete 320x240
Interval: Discrete 0.033s (30.000 fps)
[1]: 'YUYV' (YUYV 4:2:2)
Size: Discrete 640x256
Interval: Discrete 0.033s (30.000 fps)
</code></pre>
<h2 id="price"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#price">Price</a></h2>
<p>Infrared cameras are annoyingly expensive. This one is around £190 - although currently discounted to £170 - which is fairly reasonable.</p>
<p>How much will it save you? Well, it can tell you where your insulation isn't working - or which plugs are about to burst into flames; so a decent investment.</p>
<h2 id="final-thoughts"><a href="https://shkspr.mobi/blog/2026/08/gadget-review-hikmicro-d02-thermal-camera/#final-thoughts">Final Thoughts</a></h2>
<p>I've <a href="https://shkspr.mobi/blog/tag/thermal+review/">reviewed a <em>lot</em> of thermal cameras</a> and I think this might be one of my favourites. The fact that it (optionally) captures both the thermal <em>and</em> the optical image makes it great for diagnosing problems because you can easily see what it is you're looking at.</p>
<p>There are enough settings to fiddle around with to keep most tinkerers happy and the image quality is more than good enough for spotting problems in the home. It's well worth buying for your home if you want to check for leaks, insulation gaps, hotspots, and other domestic problems. I'd recommend sharing the cost with your neighbours, or loaning it to a local tool library.</p>
<p>This is lightweight, quick to boot up, has good accuracy, and is (relatively) cheap. Well worth it, in my opinion.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=73332&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">📝 2026-08-01 08:47: Today is the first of August. Where the hell did the first two thirds of... - Kev Quirkhttps://kevquirk.com/2026-08-01-08472026-08-01T07:47:00.000Z<p>Today is the first of August. Where the hell did the first two thirds of 2026 go??? 😵💫</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=%F0%9F%93%9D%202026-08-01%2008%3A47">reply to this post by email</a>, or <a href="https://kevquirk.com/2026-08-01-0847#comments">leave a comment</a>.</p>
</div>Countryside; Blaugust - James' Coffee Bloghttps://jamesg.blog/2026/08/01/countryside-blaugust2026-08-01T00:00:00.000Z
<p>With the window open and the breeze flowing through, I hear the calls and songs of birds. A calling pigeon in particular stands out. I love the calls of pigeons in the evening. The sound reminds me of childhood, looking out the window, onto Nature. A flock of birds fly by as the occasional person strolls down the street. While the sun set a little while ago, day is still here.</p><p>A gust of wind moves the leaves across a big tree, and then the breeze settles down, and picks up again. I think about the cycles of Nature: a breeze comes, and another. I watch the leaves that seem to dance with the wind; therein, a beautiful rhythm. The songs of other birds come to the fore, ones I don’t recognise but whose music is nevertheless soothing.</p><hr/><p>My eyes are heavy. The day was busier than normal, occupied with studies and essay writing and time with friends and watching the joy of community pop up around the <a href="https://nerdgirlthoughts.game.blog/2026/07/15/blaugust-2026-is-coming/" rel="noreferrer">Blaugust</a> challenge. It got me thinking again about what it means to write on the web. When we write on the web, we can do so in a broader context: as part of the communities we are in. Seeing all the people come around for Blaugust motivated me to write this piece, and to try and participate. With this challenge, we’re all writing together. Whether I will participate often or not, I am unsure, but I do know that, at minimum, I am abundantly excited to read what my friends write.</p><p>In the spirit of sharing, while I can’t bring the fresh air of a Scottish countryside to you, I can bring part of what I hear and see; a snippet of time, for you, dear reader. That is this blog post – a little part of the Scottish countryside, as seen through my eyes, on this evening, August 1st.</p><hr/><p><a href="https://aggronaut.com/" rel="noreferrer"><em>Mark Temple (Belghast)</em></a><em>, who started Blaugust, passed away on July 2nd, 2026. I didn't know Mark, but I am sincerely grateful to him for starting a challenge that brings the web together. Projects like Blaugust bring light to the beautiful potential of the web. May he rest in peace.</em></p>
<a class="tag" href="https://aggronaut.com/">Mark Temple (Belghast)</a>
<a class="tag" href="https://nerdgirlthoughts.game.blog/2026/07/15/blaugust-2026-is-coming/">Blaugust</a>
Linkception - Kev Quirkhttps://kevquirk.com/linkception2026-07-31T22:05:00.000Z<p>So many links in <a href="https://sals.place/blog/re-bubbles-interlinking-etc/" rel="noopener noreferrer">one post</a>. I ended up going down all kinds of rabbit holes off the back of this single post (also the second time I've linked to Sal's blog today 🙃). </p>
<p>I discovered <a href="https://osteophage.neocities.org/" rel="noopener noreferrer">Coyote's blog</a>, and <a href="https://departure.blog/" rel="noopener noreferrer">Sylvia's</a>. So went ahead and read some of their posts. I was already aware of <a href="https://brennan.day/" rel="noopener noreferrer">Brennan's fantastic blog</a>, but it's a great read, so check it out. </p>
<p>Anyway, I completely agree with what Sal, Coyote, Sylvia, and Brennan say in their posts - the backbone of the internet is the hyperlink, so go forth and link out to your fellow bloggers with reckless abandon.</p>
<p>It's what makes the web, the web. 🕸️</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Linkception">reply to this post by email</a>, or <a href="https://kevquirk.com/linkception#comments">leave a comment</a>.</p>
</div>Open-ear earbuds: A comparison - Cool As Heckhttps://cool-as-heck.blog/open-ear-earbuds-a-comparison2026-07-31T18:51:30.000Z<div>I've recently been curious about open-ear earbuds since I've been having so many problems with my ears hurting and/or getting infected from wearing earbuds that block the ear canal. I also recently got a pair of Bose Quiet Comfort Ultra 2 over-the-ear headphones, and whatever material their ear cups are made of made my skin break out. 😩 So I had to get some cooling gel, memory foam ear pads for those and they're fine now. But I don't always want to wear those giant cans over my ears. </div>
<div><br></div>
<div>I ordered both the Nothing Ear (open) 2 and the Soundcore Aeroclip earbuds. </div>
<div><br></div>
<div><figure class="attachment attachment--preview attachment--webp">
<img alt="Uploaded image" data-lightbox-full-url="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/ydmssvqgkrly56bhf23ebb2q435r" src="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/ydmssvqgkrly56bhf23ebb2q435r">
</figure></div>
<div><br></div>
<div><figure class="attachment attachment--preview attachment--webp">
<img alt="Uploaded image" data-lightbox-full-url="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/68ag2wlcwt0fo6vykhswakpqbuzw" src="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/68ag2wlcwt0fo6vykhswakpqbuzw">
</figure></div>
<div>Both are very lightweight and comfortable. As you can see from the images, the Nothing earbuds wrap around the ear while the Soundcore buds sort slide or clip onto the ear. Both have drivers that sit just outside the ear canal and deliver sound directly into your ear without blocking the ear canal. </div>
<div><br></div>
<div>Both are roughly the same price, around $100 depending on where and when you buy them. The estimated battery life is the same for both, but in practice I got a bit more play time out of the Nothing buds; maybe 30-60 minutes more. I also have no complaints about the charging case for either one; both provide up to nearly 30 hours of charge for the buds and charge with USB-C.</div>
<div><br></div>
<div>I think the Soundcore app is a bit better than the Nothing app, with better EQ options. </div>
<div><br></div>
<div><figure class="attachment attachment--preview attachment--jpg">
<img alt="Uploaded image" data-lightbox-full-url="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/hpgmayt5jp78ltjqm3saybseznwe" src="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/hpgmayt5jp78ltjqm3saybseznwe">
</figure></div>
<div><figure class="attachment attachment--preview attachment--jpg">
<img alt="Uploaded image" data-lightbox-full-url="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/hm9itkq2x5sc2zz1ps0lexwq9fbw" src="https://pagecord.com/cdn-cgi/image/width=1600,height=1200,format=webp,quality=90/https://storage.pagecord.com/hm9itkq2x5sc2zz1ps0lexwq9fbw">
</figure></div>
<div>What this comparison ultimately comes down to is sound quality, which is why I would certainly recommend the Soundcore Aeroclip earbuds over the Nothing Ear open 2 earbuds. They have better bass, better clarity in the highs, and can get louder without getting distorted.</div>
<div><br></div>
<div>If you have any more questions about these, please shoot me an email or a message on Mastodon!</div>Notable links: July 31, 2026 - Werd I/O6a6c9ae65f10030001b684f82026-07-31T13:01:57.000Z<img src="https://storage.ghost.io/c/18/7c/187cc681-d3f3-49fc-87de-b01d06b76821/content/images/2026/07/getty-images-JE3-Ogu0BYw-unsplash.jpg" alt="Notable links: July 31, 2026"><p><em>Most Fridays, I share a handful of pieces that caught my eye at the intersection of technology, media, and society.</em></p><p><em>Did someone forward this to you? </em><a href="https://werd.io/notable-links-july-24-206/#/portal" rel="noreferrer"><em>Subscribe for free</em></a><em>.</em></p><hr><h3 id="leaders-are-leverage"><a href="https://pointc.co/leaders-are-leverage/" rel="noreferrer">Leaders are Leverage</a></h3><p>I’ve often shared <a href="https://pointc.co">Corey Ford’s</a> pieces. I find his frameworks and thinking genuinely useful, and he’s been a friend and mentor to me for well over a decade.</p><p>This piece outlines his underlying thinking, and why he’s focused where he has:</p><blockquote>“When I work with one leader, I'm not working with one person. I'm working with every person on their team, every meeting they'll ever run, every piece of feedback they'll ever give, every subculture they'll ever build. A leader is not a single node in an organization. A leader is a multiplier. Change how one leader leads, and you change what work feels like for everyone around them, and everyone around the people they develop, for years.”</blockquote><p>It’s all about seeding culture. I see a lot of similarities in the underlying ideas in Corey’s work and the intention behind culture change manifestos like <a href="https://bookshop.org/a/7949/9781849352604"><em>Emergent Strategy</em></a>. Change is fractal, bubbling up from one person to affect a whole system.</p><p>I was involved in Matter, the accelerator Corey founded, in two ways: first as an entrepreneur, receiving an earlier version of the ideas he continues to teach, and then as a member of the team, helping to deliver them to cohorts of entrepreneurs. It changed my life, and I watched it change the way other participants think about building teams, products, and cultures.</p><p>Those ideas are now part of the <a href="https://pointc.co/sulzberger/">Sulzberger Executive Leadership Program at Columbia University</a>. If you’re a newsroom leader, I believe you should strongly consider it. And even if you’re not, I recommend that you follow Corey and his work. I guarantee he’ll change your thinking.</p><hr><h3 id="fed-up-with-big-tech-communities-turn-to-data-collectives-for-control"><a href="https://restofworld.org/2026/ai-data-collectives-mozilla/" rel="noreferrer">Fed up with Big Tech, communities turn to data collectives for control</a></h3><p>It’s interesting to contrast the current moment to the “information wants to be free” era of Web 2.0, twenty or so years ago. Back then, everyone was talking about open APIs and open data. Now, it’s become clearer that communities need to control the terms of their data if they’re going to avoid being strip-mined for somebody else’s profit.</p><blockquote>“Workers, producers, consumers, and others have been establishing cooperatives and other community-led associations to pool resources, share benefits, and address socioeconomic challenges for centuries. The United Nations marked 2025 as the year of cooperatives, positioning them as “essential solutions to today’s global problems,” kindling renewed interest in data collectives and cooperatives.”</blockquote><p>While there’s certainly an argument to be made that communities tend to over-estimate the value of their own data (looking at you, news), some of these datasets may be truly unique in ways that would add value to an AI service or model. As this article points out, collectively-owned data includes creative works in more than 20 African languages that aren’t recognized in mainstream linguistic frameworks.</p><p>The danger, of course, is that putting these kinds of gates in front of underrepresented cultures just works to further marginalize them: in that potential future, if everyone’s using a model where those languages are missing, they become irrelevant. But there’s another one where data collectives can pull the levers they have to bring about the world they want to see. That’s exactly what the <a href="https://datasciencelawlab.africa/nwulite-obodo-open-data-license/">Nwulite Obodo Open Data License</a> aims to do: data rights holders can negotiate to share their work and cultural heritage without losing their right to benefit from it. (Nwulite Obodo is Igbo for raising, reviving, and building the community.)</p><p>In one model, vendors building non-extractive and responsibly trained models for public interest purposes get to use their data for free, but the closed-model big tech vendors have to pay. That’s what Meesum Alam did with voice data for 39 at-risk languages in Pakistan: the communities he worked with determined that the data was free for research and non-commercial purposes, but for-profit tech companies would need to negotiate terms (which Meta did).</p><p>That potentially becomes more interesting: either OpenAI et al negotiate to license the data, or they lose functionality to their public interest competitors. There’s also a world where some communities proactively document their cultures and make them available specifically so that models, whoever they’re built by, won’t omit them. Either the world has more equitable AI or the communities financially benefit from their cultural heritage.</p><p>Whatever happens, these communities certainly have the right to control their data however they see fit. What vendors do about it is the open question. But initiatives like <a href="https://mozilladatacollective.com/">Mozilla Data Collective</a> make it more possible to have more substantive conversations about how data is provided and used, and that can only be a good thing.</p><hr><h3 id="us-government-targets-cop-city-protester-over-phone-operating-system"><a href="https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone" rel="noreferrer">US government targets Cop City protester over phone operating system</a></h3><p>This is worth knowing about and is concerning — but not necessarily for the main reason that’s being reported.</p><p>The Department of Justice is trying to prosecute Sam Tunick, an Atlanta-based activist, for allegedly using a duress password on his <a href="https://grapheneos.org/">GrapheneOS</a> phone when he crossed the border in January 2025.</p><blockquote>“Agent Findley and several others repeatedly asked Tunick to open his phone during the interrogation, telling him they would seize it if he did not. When he finally provided a passcode, “the screen went blank, flashed several times and the phone appeared to restart”, according to the motion.”</blockquote><p>The phone was wiped. According to the Department of Justice, rather than the usual unlock password, the one Tunick had provided was a signal that <a href="https://grapheneos.org/features#duress">GrapheneOS should reset the device to factory settings</a>. That’s the core issue: it’s not that he was using GrapheneOS or had set up a duress password, but he was accused of using it to reset his device rather than give his data to law enforcement when asked.</p><p>At the point where law enforcement or border protection are asking you for data, it’s your right to refuse a search, but you typically can’t actively destroy it. I’ve always understood that <a href="https://www.americanbar.org/groups/law_practice/resources/law-technology-today/2019/can-police-force-you-to-unlock-your-cell-phone/">the police can’t compel you to unlock your phone without a warrant</a>, although, unfortunately, Customs and Border Protection has an exemption around the border. If there <em>is</em> a warrant, or if CBP asks you in a border zone, you may still refuse to unlock it, but the device may be seized and held. The trick here, which Tunick’s lawyers are arguing, is that the request was unlawful to begin with.</p><p>Because Tunick was a part of Atlanta’s <a href="https://en.wikipedia.org/wiki/Stop_Cop_City">Stop Cop City protests</a>, he had been put on a terrorist watchlist; that fact was circulated just three hours prior. That flagged him for the secondary inspection that led to him being asked to unlock his phone. Protest is protected by the first amendment and a core component of democratic speech; putting protesters on a watchlist designed to protect the public against violent extremism is undemocratic. That’s even more affronting when you consider that the protest was against a police training center: the message it sends is nakedly authoritarian. Finally, and most egregiously, the questioning was about child exploitation imagery, which they had no reason to suspect him of holding. As a result, the search may not have been legal.</p><p>While a duress password is a deliberate act of destruction, the better path when crossing the border is to not have data to seize to begin with. Anyone who deals with sensitive information should consider that their phone might be taken at the border. Customs and Border Protection policy even allows agents to clone it, giving them permanent access to your data even after they hand your device back to you. They’re only supposed to do this when there’s a national security concern or reasonable suspicion of a crime — but if activists are being targeted as terrorists, that policy threshold doesn’t feel like a solid protection.</p><p>So: log out of your email, calendar, and file sharing before you embark upon your travels. Delete Signal entirely (<a href="https://support.signal.org/hc/en-us/articles/360007059752-Backup-and-Restore-Messages">but back it up</a>). Consider which photos you want to travel with. Don’t travel with a stock phone — that can lead to more questions — but intentionally cut down your information footprint. That way, even if you are stopped, you won’t compromise sources (if you’re a journalist) or your compatriots (if you’re an activist). And you’re not forced to delete data in the moment in a way that could leave you vulnerable.</p>Left-Handed People Can’t Use a Fountain Pen - Kev Quirkhttps://kevquirk.com/left-handed-people-cant-use-a-fountain-pen2026-07-31T09:52:00.000Z<p>Apparently left-handed people can't use a fountain pen as the left hand smudges the ink as they write. I call bullshit on that. I'm left-handed, and I use a fountain pen just fine - even with an "overhand" grip.</p>
<p>I read <a href="https://nealstephenson.substack.com/p/writing-by-hand-is-good-for-your" rel="noopener noreferrer">this post from Neal Stephenson</a> a few days ago (thanks to <a href="https://sals.place/" rel="noopener noreferrer">Sal</a> for sharing it), where Neal - a professional, left-handed writer who writes his books with a pen and paper - shares some of his experience and advice on writing with a fountain pen.</p>
<p>I've been <a href="https://kevquirk.com/using-fountain-pens-for-note-writing">back using fountain pens for a few months now</a> and it's going great, but as Neal says - it's all about the paper. I use a decent quality notepad for writing my notes, with either a £30 Lamy Safari fountain pen, or a ~£100 Kaweco AL Sport. Both work great and I'm yet to find myself with pen on my hand. Here's an example of me writing in my notebook, using both my Lamy and Kaweco.</p>
<video controls="" width="100%">
<source src="https://cdn.kevquirk.com/fountain-pen-writing-example.mp4" type="video/mp4">
</source></video>
<p>As you can see, I have an overhand grip where my hand swipes across the ink as I write, but the ink is dry by the time my hand gets there. Both these pens have a medium nib too.</p>
<p>So if you're left-handed and think you can't use a fountain pen, you can! You just need some decent paper.</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Left-Handed%20People%20Can%E2%80%99t%20Use%20a%20Fountain%20Pen">reply to this post by email</a>, or <a href="https://kevquirk.com/left-handed-people-cant-use-a-fountain-pen#comments">leave a comment</a>.</p>
</div>Of Day - James' Coffee Bloghttps://jamesg.blog/2026/07/31/of-day-22026-07-31T00:00:00.000Z
<p>I hear the birds singing as I sit by the window and look out on the horizon. I like looking at all the colours of the sky in the moments after sunset, when ambers recede and the sky becomes ever more blue before night time. I hear the sound of my fingers typing on my keyboard, too: nature and words are my evening.</p><p>Nature and words are my evening, and so too is music. Moments ago I was playing on the piano, two songs I love but haven’t played in as long as I can remember. And one more song that I play often: one that always makes me feel free to improvise; one where the piano shines through the recording to which I listen while I play; one where I can be an accompaniment to the melody.</p><p>A cool breeze comes through the periphery of a window; I had a window open earlier while I played music, hoping that perhaps someone would hear a note or two and feel in wonder. I remember a story a friend told me about how welcomed their music was by a neighbour. I don’t know what it is about music that makes me feel confident: I don’t need to be perfect, as long as I can play a few notes that sound good. (If only, however, my singing voice were better – someone, guide me.)</p><p>My week has been full: of tasks and ideas, assignments and readings, writing and chatting. But now, sitting here, I am starting to wind down. I look out the window to see what I can see: the tiny birds dancing around the air (which reminds me that I saw two butterflies dancing together recently; I had to write that down); the sky taking on a new blue as the sun goes even further beyond the horizon; a canvas of green; of trees whose age I will never know and whose beauty grows by the day.</p>
Lattes - James' Coffee Bloghttps://jamesg.blog/2026/07/31/lattes2026-07-31T00:00:00.000Z
<p>I watched the movie "Valentines Day" (2010) for the first time today, which stars, among others, Taylor Swift. <a href="https://youtu.be/FBTIoyJ7aQ4?t=66" rel="noreferrer">The energy in this scene</a> (especially the enthusiastic and excited way in which the words are said, while Taylor carries a huge bear) <sup class="footnote-reference" id="f-1"><a href="https://jamesg.blog/longform-feed#1">1</a></sup> fills me with joy:</p><blockquote>[call out: "Save the Lattes!"]<br/>Taylor: They're putting lattes in the vending machines? Finally!<br/>Taylor: Robbie, I am so glad you are taking care of this.<br/>Robbie: You got it.<br/>Taylor: And, I like caramel lattes, just FYI.</blockquote><p>I am not a fan of caramel lattes, but I do love this scene!</p>
<div class="footnote-definition" id="1"><sup class="footnote-definition-label" id="f-2">1</sup>
<p>1m06s to 1m18s in the linked video.</p>
<a href="https://jamesg.blog/longform-feed#f-1">[↩]</a></div>
<a class="tag" href="https://jamesg.blog/longform-feed#1">1</a>
<a class="tag" href="https://jamesg.blog/longform-feed#f-1">[↩]</a>
<a class="tag" href="https://youtu.be/FBTIoyJ7aQ4?t=66">The energy in this scene</a>
Toot.community is shutting down - Kev Quirkhttps://kevquirk.com/tootcommunity-is-shutting-down2026-07-30T15:59:00.000Z<div class="link card"><h2>Toot.community is shutting down</h2><p class="post-author">by Jorijn Schrijvershof</p><p>Sadly, toot.community is shutting down in October. This post talks about why Jorijn has made that decision.</p><p><a class="button" target="_blank" href="https://social.jorijn.com/@jorijn/statuses/01KYN00AP3NCZXCFB96KQB8GN2">Read post ➡</a></p></div>
<hr>
<p>So much of this post resonated with me and aligned closely with <a href="https://kevquirk.com/my-thoughts-on-the-fosstodon-drama">my reasons to step away from Fosstodon</a>. Being a fediverse server admin is a thankless job and as Jorijn says:</p>
<blockquote>
<p>I find myself feeling more angry or discouraged after spending time as an admin, and that’s not what I want from social media or a volunteer project.</p>
</blockquote>
<p>Over a year on since I stepped away from the Fosstodon team, I'm much happier now, but the experience has tainted my experience of social media. These days I probably visit Fosstodon maybe once per week. Every post I write is written here, on my site, and syndicated over there. I feel this is much better for me personally, as it keeps me away from the latest drama.</p>
<p>When I do go visit the timeline, it's usually fun because it's fleeting. I don't have time to get involved in the latest drama. I go, check notifications, quickly peruse the timeline, and leave. It's a much healthier way of engaging, I think.</p>
<p>More broadly, I think the issue with admin and mod burnout on the fediverse is what will limit it in the long run. It's almost entirely propped up by volunteers, who don't want to be involved with the drama, or be attacked for making a decision you don't agree with. And as a result, servers like toot.community fall by the wayside.</p>
<p>I don't know what the solution is here - I actually don't think there is one. It's a fundamental limitation of the way in which the fediverse is architected and as a result, another great server is gone. 😔</p> <div class="email-hidden">
<hr />
<p>Thanks for reading this post via RSS. RSS is ace, and so are you. ❤️</p>
<p>You can <a href="mailto:19gy@qrk.one?subject=Toot.community%20is%20shutting%20down">reply to this post by email</a>, or <a href="https://kevquirk.com/tootcommunity-is-shutting-down#comments">leave a comment</a>.</p>
</div>Change is fractal. It starts with leaders - Werd I/O6a6b40735f10030001b684e42026-07-30T12:15:48.000Z<p>Link: <a href="https://pointc.co/leaders-are-leverage/?ref=werd.io" rel="noreferrer"><em>Leaders Are Leverage, by Corey Ford at Point C</em></a></p><p>I’ve often shared <a href="https://pointc.co">Corey Ford’s</a> pieces. I find his frameworks and thinking genuinely useful, and he’s been a friend and mentor to me for well over a decade.</p><p>This piece outlines his underlying thinking, and why he’s focused where he has:</p><blockquote>“When I work with one leader, I'm not working with one person. I'm working with every person on their team, every meeting they'll ever run, every piece of feedback they'll ever give, every subculture they'll ever build. A leader is not a single node in an organization. A leader is a multiplier. Change how one leader leads, and you change what work feels like for everyone around them, and everyone around the people they develop, for years.”</blockquote><p>It’s all about seeding culture. I see a lot of similarities in the underlying ideas in Corey’s work and the intention behind culture change manifestos like <a href="https://bookshop.org/a/7949/9781849352604"><em>Emergent Strategy</em></a>. Change is fractal, bubbling up from one person to affect a whole system.</p><p>I was involved in Matter, the accelerator Corey founded, in two ways: first as an entrepreneur, receiving an earlier version of the ideas he continues to teach, and then as a member of the team, helping to deliver them to cohorts of entrepreneurs. It changed my life, and I watched it change the way other participants think about building teams, products, and cultures.</p><p>Those ideas are now part of the <a href="https://pointc.co/sulzberger/">Sulzberger Executive Leadership Program at Columbia University</a>. If you’re a newsroom leader, I believe you should strongly consider it. And even if you’re not, I recommend that you follow Corey and his work. I guarantee he’ll change your thinking.</p>Are political journalists always wrong? - Terence Eden’s Bloghttps://shkspr.mobi/blog/?p=733222026-07-30T11:34:31.000Z<p>I've mostly tuned out of reading the news. But, once in a while, a headline will be shared on social media and I'll momentarily stare into the abyss.</p>
<p>There has recently been a change in UK Prime Minister. I neither know nor care whether that's a good thing. What I <em>do</em> know is that Senior Political Correspondents collectively shat their pants with excitement at being able to breathlessly report any half-baked gossip which would drive clicks.</p>
<p>I saw "Rumours suggest so-and-so will be appointed…", and "Supporters say that A. N. Other will be fired from…", and "Insiders reveal urgent change of policy around…", and so on.</p>
<p>They were all bollocks.</p>
<p>I spent a dull afternoon going through a couple of dozen "sources say" headlines. About 85% were completely wrong. That person didn't become Minister for Administrative Affairs, that other one wasn't fired, the much ballyhooed policy announcement never came.</p>
<p>A few weeks ago, The Economist ran a searing exposé on the accuracy of… The Economist. In an article called "<a href="https://www.economist.com/interactive/finance-and-economics/2026/07/02/is-the-economist-always-wrong">Is The Economist always wrong?</a>" they used a Large Langue Model to test the accuracy of their forecasts. It made for fascinating reading:</p>
<blockquote><p>We declared smartphones the future of computing in 2002, said that something like streaming would devour DVDs in 2008, and cautioned in 2011 that a flood of Chinese-made cars would wash over the West. Still, our techno-optimism occasionally got ahead of itself. Distributed electric grids (boosted by The Economist in 2000), cheap bioethanol (2003), open standards for social media (2008) and augmented reality (2016) have yet to bring about the breakthroughs we prophesied.</p></blockquote>
<p>I'd like someone to run the same process on the political rumours reported by the mainstream press. Just how accurate are the tips journalists receive?</p>
<p>Now, obviously, perhaps the rumour was true at the time - but circumstances changed. Perhaps journalists are hanging around in bars and listening to <abbr title="Special Advisors">SpAds</abbr> boast about what the boss has just said. Perhaps they're just making shit up.</p>
<p>It would be fascinating to see if <em>any</em> political journalist has a better than 50% ratio of hits to misses. I strongly suspect that they have an incentive to post the most outrageous rumour rather than the most accurate one.</p>
<p>So, if you have access to a couple of years of newspaper archives, a local AI model which won't burn the planet, and want to cause chaos - please create a leaderboard of the most- and least-accurate political rumour-mongers in the UK.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=73322&HTTP_REFERER=Atom" alt width="1" height="1" loading="eager">Building secure Uniswap v4 hooks - Trail of Bits Bloghttps://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/2026-07-30T11:00:00.000Z<p>Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code.</p>
<p>The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stemmed from a flaw in the Uniswap v4 core protocol or the PoolManager; both arose from application-specific authorization and accounting logic built around hooks.</p>
<p>After analyzing dozens of findings from Trail of Bits audits (including our <a href="https://github.com/trailofbits/publications/blob/master/reviews/2024-07-uniswap-v4-core-securityreview.pdf">Uniswap v4-core security review</a>), public reports from other firms, and the Solodit database, I&rsquo;ve identified seven recurring failure patterns in application and hook code, including missing caller checks and accounting bugs that still satisfy the PoolManager&rsquo;s settlement invariant. Builders can use these patterns as a secure-development checklist; auditors can use them to focus their review.</p>
<h2 id="what-the-poolmanager-guarantees">What the PoolManager guarantees</h2>
<p>If you&rsquo;re familiar with Uniswap v3, where each pool was a separate contract, v4 inverts the model. All pool state now lives in a singleton PoolManager contract, with each pool represented in its storage. Uniswap v4 adds hooks: independent contracts that execute custom logic at specific points in the swap and liquidity lifecycle.</p>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/uniswapv4-figure-1_hu_b3e8804f4c7e53ff.webp"
alt="&ldquo;Figure 1: Pools live inside the singleton PoolManager, and multiple pools can use the same hook contract.&rdquo;"
width="1200"
height="900"
loading="lazy"
decoding="async" />
<figcaption>Figure 1: Pools live inside the singleton PoolManager, and multiple pools can use the same hook contract.</figcaption>
</figure>
</p>
<p>Here&rsquo;s what a pool looks like in v4:</p>
<figure class="highlight">
<pre tabindex="0"><code class="language-" data-lang=""
>struct PoolKey {
Currency currency0;
Currency currency1;
uint24 fee;
int24 tickSpacing;
IHooks hooks;
}</code></pre>
<figcaption><span>Figure 2: A pool's PoolKey includes both currencies, the fee, tick spacing, and the hook address (<a href='https://github.com/Uniswap/v4-core/blob/main/src/types/PoolKey.sol'>v4-core/src/types/PoolKey.sol</a>).</span></figcaption>
</figure>
<p>Notice that the hook address (<code>IHooks hooks;</code>) is part of the pool&rsquo;s identity. If you change any of these fields, you&rsquo;re talking to a different pool. This matters because trusting the wrong <code>PoolKey</code> means trusting the wrong pool.</p>
<p>v4 also introduces a session-based model that works like a flash loan. Your contract calls <code>unlock()</code> on the PoolManager, which triggers a callback into your code. At the end, the PoolManager checks that no unsettled currency deltas remain:</p>
<figure class="highlight">
<pre tabindex="0"><code class="language-" data-lang=""
>function unlock(bytes calldata data) external returns (bytes memory result) {
Lock.unlock();
// ... callback execution happens here ...
if (NonzeroDeltaCount.read() != 0) revert CurrencyNotSettled();
Lock.lock();
}</code></pre>
<figcaption><span>Figure 3: Simplified PoolManager.unlock() flow: unlock the session, execute the callback, and revert unless all currency deltas settle to zero (<a href='https://github.com/Uniswap/v4-core/blob/main/src/PoolManager.sol'>v4-core/src/PoolManager.sol</a>).</span></figcaption>
</figure>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/uniswapv4-figure-4_hu_452027c95338c4e1.webp"
alt="&ldquo;Figure 4: A periphery or hook calls PoolManager.unlock(), handles unlockCallback(), and calls swap() inside the unlocked session.&rdquo;"
width="1200"
height="312"
loading="lazy"
decoding="async" />
<figcaption>Figure 4: A periphery or hook calls PoolManager.unlock(), handles unlockCallback(), and calls swap() inside the unlocked session.</figcaption>
</figure>
</p>
<p>The PoolManager enforces v4&rsquo;s protocol mechanics, including pool initialization rules, swap and liquidity math, hook-callback sequencing, and end-of-session settlement. Hook developers are responsible for validating the application-specific assumptions their hooks add.</p>
<p>Each hook must decide:</p>
<ul>
<li>Who can call its privileged paths</li>
<li>Which pools are legitimate</li>
<li>How custom balances and deltas should be accounted for</li>
<li>Whether external integrations can fail or reenter safely</li>
</ul>
<h2 id="1-anyone-can-call-your-hook">1. Anyone can call your hook</h2>
<p>Hook callbacks are external functions on your contract. If you don&rsquo;t check the caller, an attacker can call those callbacks directly with malicious parameters. A loose <code>unlockCallback</code> path can also reach internal actions that should never be callable.</p>
<p>The fix: use <code>BaseHook</code> for hook entrypoints and <code>SafeCallback</code> for <code>unlockCallback</code>. Together, they enforce caller checks on the callback paths they cover:</p>
<figure class="highlight">
<pre tabindex="0"><code class="language-" data-lang=""
>modifier onlyPoolManager() {
if (msg.sender != address(poolManager))
revert NotPoolManager();
_;
}</code></pre>
<figcaption><span>Figure 5: onlyPoolManager restricts hook callbacks to the configured PoolManager.</span></figcaption>
</figure>
<p>Add an equivalent caller check only on paths those contracts don&rsquo;t cover.</p>
<p><strong>Real-world example:</strong> The <a href="https://www.cork.tech/blog/post-mortem">Cork exploit</a> (~$12M, May 2025) shows why this check matters. Cork let data from an untrusted path reach hook logic that affected redemptions. That access-control gap, combined with a pricing issue elsewhere in the protocol, gave the attacker a way to drain funds.</p>
<h2 id="2-treating-any-pool-as-legitimate">2. Treating any pool as legitimate</h2>
<p>Pool creation through the PoolManager is permissionless by default. Unless your hook restricts initialization in beforeInitialize, anyone can create a pool with your hook address attached. If your hook trusts a user-supplied <code>PoolKey</code> without validation, an attacker can route your logic through a malicious pool with currencies and parameters they choose.</p>
<p>An attacker-created pool presents two immediate risks. First, if your hook stores per-pool data keyed by <code>PoolId</code>, the new pool gets its own mapping slot. The attacker can influence values written through activity in that pool, and later accounting paths may treat those values as trusted. Second, <code>currency0</code> and <code>currency1</code> are attacker-chosen currencies. If either is an ERC-20, token interactions can trigger malicious behavior or reenter other hook functions mid-flow.</p>
<p>The fix: bind your hook to canonical pools during deployment or trusted configuration, or maintain a strict allowlist. Re-check the derived <code>PoolId</code> on every user-controlled path:</p>
<figure class="highlight">
<pre tabindex="0"><code class="language-" data-lang=""
>// Pseudocode for pool binding
PoolId poolId = key.toId();
if (!allowedPools[poolId]) revert InvalidPool();</code></pre>
<figcaption><span>Figure 6: Derive the PoolId from the supplied PoolKey and reject pools that are not allowlisted.</span></figcaption>
</figure>
<p><strong>Real-world example:</strong> In Semantic Layer&rsquo;s <a href="https://solodit.cyfrin.io/issues/chat-points-manipulation-by-adding-liquidity-to-custom-pools-via-svfhook-contract-spearbit-none-semantic-layer-pdf">SVFHook finding</a>, the <code>addLiquidity</code> function lets callers specify the <code>PoolKey</code>. An attacker could route deposits through a custom WETH/SVF pool with a malicious hook and earn points at a lower cost than intended.</p>
<h2 id="3-custom-accounting-leaks-value">3. Custom accounting leaks value</h2>
<p>In v4, a delta is a signed currency-balance change owed to or from the PoolManager. Once your hook touches deltas, a wrong sign, a rounding error, or mixing balance buckets can silently leak value. These bugs are subtle because settlement only checks that the session&rsquo;s currency deltas resolve; it does not validate the hook&rsquo;s internal accounting. A hook&rsquo;s accounting can still be wrong even when settlement succeeds.</p>
<p>Return-delta hooks can move beyond fee bookkeeping. If a <code>BeforeSwapDelta</code> consumes the user&rsquo;s entire specified amount, the PoolManager has no amount left for its concentrated-liquidity swap; the hook supplies the trade instead. This is often called a NoOp swap. Treat that hook as a custom AMM: test conservation, price bounds, rounding, and returned deltas against real balances.</p>
<p>Dynamic fees are also price-sensitive. A dynamic-fee pool can accept a per-swap fee override from <code>beforeSwap</code>, and its hook can update the stored LP fee. Bound every fee, limit how quickly privileged changes can move it, and do not derive it directly from inputs an attacker can cheaply manipulate.</p>
<p>For hooks that move value, test at least these three accounting invariants:</p>
<ul>
<li>No user receives output that the accounting did not charge for.</li>
<li>A same-transaction round trip cannot create value from accounting alone.</li>
<li>Internal accounting matches actual asset balances.</li>
</ul>
<p>Those invariants must also hold for the tokens the hook handles. Fee-on-transfer tokens can make the amount received smaller than the amount sent; rebasing tokens can change balances without a transfer; callback-enabled tokens can reenter; and pausable or blacklistable tokens can block settlement. State which behaviors you support and test accounting against observed balance changes.</p>
<p>The fix: keep LP funds, fees, and incentives in separate buckets. Label every balance and delta, including who owns it, and who can move it.</p>
<p><strong>Real-world example:</strong> The <a href="https://blog.bunni.xyz/posts/exploit-post-mortem/">Bunni exploit</a> ($8.4M, September 2025) was a rounding bug in BunniHook&rsquo;s idle-balance accounting. The attacker pushed a pool&rsquo;s price tick with a flash loan, then made 44 tiny withdrawals that each shrank the active balance disproportionately to the shares burned, eventually extracting profit from the affected pools. Each transaction satisfied the PoolManager&rsquo;s settlement invariant because the bug was in BunniHook&rsquo;s internal accounting.</p>
<h2 id="4-right-logic-wrong-hook">4. Right logic, wrong hook</h2>
<p>
<figure>
<img src="https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/uniswapv4-figure-7_hu_bc0da7962af6947f.webp"
alt="&ldquo;Figure 7: PoolManager runs beforeSwap before executing the swap and afterSwap afterward when the corresponding address flags are set.&rdquo;"
width="1200"
height="1275"
loading="lazy"
decoding="async" />
<figcaption>Figure 7: PoolManager runs beforeSwap before executing the swap and afterSwap afterward when the corresponding address flags are set.</figcaption>
</figure>
</p>
<p>The <code>beforeSwap</code> hook executes with pre-swap state, but the <code>afterSwap</code> hook sees post-swap state. Code that&rsquo;s correct in one hook can be unsafe in another.</p>
<p>The same timing problem affects liquidity callbacks. In this <a href="https://solodit.cyfrin.io/issues/jit-liquidity-penalty-can-be-bypassed-openzeppelin-none-openzeppelin-uniswap-hooks-v110-rc-1-audit-markdown"><code>LiquidityPenaltyHook</code> finding</a>, a JIT-liquidity penalty was computed during <code>afterRemoveLiquidity</code>, but a user could first make a tiny liquidity increase that collected the fees separately. By the time removal ran, the hook saw no fees left to penalize.</p>
<p>In our hook audits, we&rsquo;ve repeatedly observed developers put logic that needs the final swap result in <code>beforeSwap</code> instead of <code>afterSwap</code>. The code looks correct in isolation, but it&rsquo;s operating on stale data.</p>
<p>The fix: verify your logic is in the correct hook for the state it needs.</p>
<h2 id="5-address-bits-are-part-of-the-api">5. Address bits are part of the API</h2>
<p>In v4, the hook address itself encodes which hook functions the PoolManager will call. This design makes the deployed address part of a hook&rsquo;s API, so developers must keep its permission bits in sync with the functions they implement.</p>
<figure class="highlight">
<pre tabindex="0"><code class="language-" data-lang=""
>function hasPermission(IHooks self, uint160 flag) internal pure returns (bool) {
return uint160(address(self)) &amp; flag != 0;
}</code></pre>
<figcaption><span>Figure 8: hasPermission reads callback permissions from the hook address bits (<a href='https://github.com/Uniswap/v4-core/blob/main/src/libraries/Hooks.sol'>v4-core/src/libraries/Hooks.sol</a>).</span></figcaption>
</figure>
<p>Three permission mismatches can cause problems:</p>
<ul>
<li>Callback bit set + callback missing → <strong>transaction reverts</strong>.</li>
<li>Callback implemented + callback bit missing → <strong>PoolManager does not call it</strong>.</li>
<li>Return-delta bit missing → <strong>PoolManager may call the callback but treat its returned delta as zero</strong>.</li>
</ul>
<p>For example, if the <code>afterSwapReturnDelta</code> bit is missing, your hook might record a fee even though the PoolManager ignored the returned delta.</p>
<p>Address bits do not make the hook&rsquo;s behavior immutable. If a pool&rsquo;s hook address points to a proxy, the permission bits stay fixed while an upgrade can change the code reached through that address. Review the upgrade admin, delay, storage layout, and implementation checks as part of the hook&rsquo;s security boundary. Prefer immutable, versioned deployments when possible.</p>
<p>The fix: inherit from <code>BaseHook</code> and keep <code>getHookPermissions()</code> in sync with the callbacks and return deltas your hook actually uses. <code>BaseHook</code> validates that the deployed address bits match those declared permissions.</p>
<p><strong>Real-world example:</strong> In the <a href="https://solodit.cyfrin.io/issues/all-swaps-will-revert-if-the-dynamic-protocol-fee-is-enabled-since-hook-configsol-does-not-encode-the-afterswapreturndelta-permission-cyfrin-none-sorella-l2-angstrom-markdown">Sorella Angstrom finding</a>, the hook returned a non-zero delta for the dynamic protocol fee, but <code>hook-config.sol</code> did not encode the <code>afterSwapReturnDelta</code> permission. The PoolManager wasn&rsquo;t authorized to settle the delta, so every swap reverted with <code>CurrencyNotSettled()</code> once the fee was enabled.</p>
<h2 id="6-hook-failures-can-block-pool-actions">6. Hook failures can block pool actions</h2>
<p>Hook callbacks execute in the same transaction as the pool action. If reward distribution, dust cleanup, or other non-essential code reverts inside an <code>afterRemoveLiquidity</code> callback, users cannot exit their positions. The same applies to swaps when non-essential code reverts inside <code>afterSwap</code>. The PoolManager preserves atomic execution by reverting the parent action, so hook developers must keep optional logic from blocking core user flows.</p>
<p>Required external reads can cause the same denial of service. If a price feed rejects stale data, a lending protocol pauses, or another dependency reverts, the callback can revert the user&rsquo;s swap or withdrawal. For each dependency, decide which paths must fail closed and which can degrade without blocking safe exits. Never silently use stale pricing data.</p>
<p>External calls are not the only source of failure. In our hook audits, we&rsquo;ve seen happy-path accounting block withdrawals because of a zero balance, decimal mismatch, or missing reward token.</p>
<p>The fix: keep non-essential code out of the main user flow. Wrap optional external calls in <code>try</code>/<code>catch</code>, or move optional logic to a separate function users can call after exiting. For safety-critical dependencies, validate freshness and bounds, and provide an explicit exit-safe fallback when the design permits one.</p>
<h2 id="7-state-can-change-during-a-callback-sequence">7. State can change during a callback sequence</h2>
<p>When enabled, <code>beforeSwap</code> and <code>afterSwap</code> run during the same swap, but values cached between them are not automatically safe. A hook can call external contracts, and one hook contract can serve many pools. Nested actions can therefore change shared hook storage, pool state, balances, or oracle data before the outer callback sequence finishes.</p>
<p>The fix: avoid shared scratch state. If data must cross callbacks, key it by <code>PoolId</code> and caller, reject overlapping operations while that state is live, and clear it after use. Apply checks-effects-interactions before external calls, and test nested swaps and liquidity changes across multiple pools that share the hook.</p>
<h2 id="building-secure-hooks">Building secure hooks</h2>
<p>If you&rsquo;re developing a v4 hook, verify these eight items:</p>
<ol>
<li><strong>Gate every callback and unlock path:</strong> Use <code>BaseHook</code> for hook entrypoints and <code>SafeCallback</code> for <code>unlockCallback</code>. Add equivalent caller checks only on uncovered paths.</li>
<li><strong>Allowlist pools, not just tokens:</strong> Bind to specific <code>PoolKey</code> values or maintain strict allowlists.</li>
<li><strong>Label every balance and delta</strong>: Document who owns it, who can move it, and which token behaviors the accounting supports.</li>
<li><strong>Keep LP funds, fees, and incentives separate:</strong> Don&rsquo;t mix balance buckets.</li>
<li><strong>Keep non-essential code away from the main user flow</strong>: Reward, oracle, and cleanup failures shouldn&rsquo;t block safe exits.</li>
<li><strong>Verify address permissions:</strong> Inherit from <code>BaseHook</code> and confirm that the address bits match your declared permissions. If the hook is upgradeable, review its proxy and upgrade controls separately.</li>
<li><strong>Fuzz nested callbacks, fee extremes, malicious pools, and malicious or non-standard tokens:</strong> Use Echidna and Medusa to test adversarial scenarios, not just happy paths.</li>
<li><strong>Isolate callback state</strong>: Key temporary data by <code>PoolId</code> and caller, reject overlapping operations, and clear it after use.</li>
</ol>
<h2 id="auditing-v4-hooks">Auditing v4 hooks</h2>
<p>If you&rsquo;re reviewing a v4 hook, ask these seven questions:</p>
<ol>
<li><strong>Can an attacker call a callback directly?</strong> Check every external function for access control.</li>
<li><strong>Can an attacker route logic through a malicious pool?</strong> Trace how <code>PoolKey</code> values are validated.</li>
<li><strong>Who owns each balance and delta, and can a return delta or dynamic fee leak value?</strong> Test conservation, price bounds, and fee limits.</li>
<li><strong>What happens if reward, cleanup, or oracle code reverts during removeLiquidity?</strong> Test failure paths and dependency outages.</li>
<li><strong>Do the permission bits, implemented functions, returned values, and any proxy upgrade path all match?</strong> Verify the address flags and upgrade controls.</li>
<li><strong>What breaks if the hook, token, or fee input is malicious?</strong> Assume adversarial counterparties.</li>
<li><strong>Can state change between callbacks?</strong> Test nested actions across multiple pools that share the hook.</li>
</ol>
<h2 id="security-responsibilities-for-hook-developers">Security responsibilities for hook developers</h2>
<p>The PoolManager enforces v4&rsquo;s protocol-level guarantees, including pool mechanics and settlement. Hook developers secure the application-specific logic they add, including authorization, pool selection, value accounting, and external integrations.</p>
<p>Ask which assumptions the hook adds beyond the PoolManager&rsquo;s guarantees. For operational guidance beyond code review, see Uniswap&rsquo;s <a href="https://developers.uniswap.org/docs/protocols/v4/security">v4 Security Framework</a>.</p>
<p>If you&rsquo;re building on Uniswap v4 and want help reviewing your hooks, <a href="https://www.trailofbits.com/contact">reach out to Trail of Bits</a>. And if you&rsquo;re interested in smart contract security, check out our <a href="https://github.com/trailofbits">public tools and research</a>.</p>
<p><em>This post is based on a <a href="https://www.youtube.com/watch?v=F4QjFySPS_0">presentation I gave at EthCC\[9\]</a>. You can find me on X at <a href="https://x.com/nisedo_">@nisedo_</a>.</em></p>the writer’s mind - James' Coffee Bloghttps://jamesg.blog/2026/07/30/the-writers-mind2026-07-30T00:00:00.000Z
<p>making notes and reviewing quotes,<br/>collected from day and night:<br/>here, there are stories.</p><p>i revel in observing, and<br/>in place-<br/>making.<br/>where am i? how do i feel?<br/>what does this mean to me?</p><p>i think of the melody of words<br/>their cadence and shape and tense<br/>and from all, i feel:.<br/>from words, wonder;<br/><em>with words, wonder.</em></p>