dade's Avatar

dade

@0xda.de

Hacker, Rapper, Developer, dade. https://0xda.de

807
Followers
135
Following
458
Posts
06.06.2023
Joined
Posts Following

Latest posts by dade @0xda.de

OMG Tonight's NCIS opening makes fun of the "two idiots one keyboard" scene from much earlier in the show, which is made even better by it being written by McGee. Honestly hilarious.

04.03.2026 05:02 πŸ‘ 6 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Would that make you a void *

03.03.2026 07:46 πŸ‘ 8 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

You can tell how much power my ADHD has over me at any given time based on how deeply nested my parentheticals get (and how many I forget to close because I forgot I was in more than one (not that I would ever forget something like that).

01.03.2026 04:49 πŸ‘ 11 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Oh yeah operationally it’s useless πŸ˜‚

25.02.2026 05:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The CNN level events is a fun one that I actually really believe is valuable - specifically because so many security problems stem from poor technology choices.

24.02.2026 21:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I haven’t spent much time in Crowdstrike trying to build out useful metrics but I would love to do this.

24.02.2026 21:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

But then, on top of that, I want to see the stats on how accurate outputs are based on certain assumptions made by prompts. E.g. β€œfind the vulnerabilities” implies there are vulnerabilities, β€œare there vulnerabilities” would probably produce different results (even more different, that is)

24.02.2026 21:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Interesting thing I just thought about. LLMs are non-deterministic, but people keep inventing new ways of saying β€œa markdown file” to help create consistency.

What I’d like to explore is two completely separate accounts interacting the exact same way with the same inputs, at scale.

24.02.2026 21:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I think I have this somewhere after hearing someone mention it at Shmoocon many years ago. Or maybe a book with a similar title.

24.02.2026 05:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yeah I really don’t like ambiguous data lol. You’re absolutely right, but it’s really not gelling with my brain very well lol.

24.02.2026 03:43 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m finding this a fun and mildly annoying challenge about my transition from an IC focused purely on getting things done, to now trying to understand how to communicate all the work my team is getting done.

24.02.2026 03:41 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

But what I’m coming to find the most frustrating about metrics in general is that I think they often get too decoupled from their method of collection. You can’t just pick cool metrics that you don’t know how to reliably measure.

24.02.2026 03:39 πŸ‘ 3 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I also hate metrics for the sake of having numbers. If you collect numbers but can’t speak to whether they should go up or down, it’s not a good metric.

Appsec & offensive security metrics in general are a good example of ambiguous metrics. More vulnerabilities is… good? For your performance? What?

24.02.2026 03:37 πŸ‘ 4 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I’ve been researching a lot about metrics as I’m now responsible for tracking metrics for our enterprise security function. My historical take on security metrics is that they are all bad, because the metrics people default to are basically contingent on your ability to get other people to do work.

24.02.2026 03:35 πŸ‘ 9 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Preview
Joiners, Movers, Leavers - An IaC Problem I’m a huge proponent of infrastructure as code. What I mean when I say this is mostly Terraform – and for an important reason (and when I say Terraform, I mostly mean OpenTofu, for another important r...

In classic dade fashion, I hadn’t posted a blog post since April. Published 4 in a row over the last few days, mostly about self hosting and my pursuit of the ideal server.

But most recently: don’t use infra-as-code to manage user access. It’s not worth it.

0xda.de/blog/2026/02...

23.02.2026 15:27 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Do You Wanna Date My Avatar immediately stuck in my head, thanks for this Tay.

22.02.2026 17:45 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I didn’t plan to spend the rest of my weekend rewatching The Guild, but maybe it’s that time. Maybe next weekend I can go back and rewatch Pure Pwnage, while I’m at it.

22.02.2026 17:43 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Pronouncing β€œRetro” like Scooby Doo from now on.

Ret-roh!

22.02.2026 17:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

His build is ready, nodes weak, pods are heavy
There’s lagging in the cluster already, Kubernetes

21.02.2026 09:02 πŸ‘ 9 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Help @lookitup.baby, my kubernetes is spaghetti stained

21.02.2026 07:57 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A charmingly low-resolution photo of a ground-level kitchen cabinet. The door is open and there is a hodgepodge of various tupperware items, many looking like they belong to completely different sets. Some might be old sour cream containers, can't really tell.

It's a joke about how kubernetes is a container orchestrator and this is container chaos.

A charmingly low-resolution photo of a ground-level kitchen cabinet. The door is open and there is a hodgepodge of various tupperware items, many looking like they belong to completely different sets. Some might be old sour cream containers, can't really tell. It's a joke about how kubernetes is a container orchestrator and this is container chaos.

The kubernetes we have at home

21.02.2026 07:43 πŸ‘ 58 πŸ” 11 πŸ’¬ 5 πŸ“Œ 1

This also really helped drive away the fears of updating that existed before I joined the organization. Reproducible builds without the constant toil and noise of dependabot made people much less scared of updating regularly. Security updates were treated basically no different than any other.

20.02.2026 21:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

My rationale was that dependabot served as a good RSS feed of new major version updates, major version updates were more likely to introduce API changes, give them a little more effort.

Everything else, just update it every monday and forget about it.

20.02.2026 21:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

This is fairly in line with the decision I landed at with Python (for apps specifically, libraries are a bit different).

1. Dependabot turned on for major version updates only
2. Make heavy use of ~= markers, pin only where necessary
3. Weekly job to re-lock lock file (uv, pipfile, etc) & test

20.02.2026 21:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Deadmau5 is a huge nerd, and huge cat fan. I think most people only associate him with music but he is doing a lot of insane technical work under the hood. At defcon 2 years ago he stopped by the Hak5 booth and he was talking about some C++ rendering engine he was building, iirc.

16.02.2026 17:38 πŸ‘ 11 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Can’t believe it’s been 10 years of madness. I think in 10 years we’ve managed to get through maybe 40, 50 talks in total, and have probably had somewhere between 150 and 300 judges in that time.

Cant wait to see what you’re working on, buddy.

15.02.2026 05:35 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I’m at @wildwesthackinfest.bsky.social in Denver and we’re looking to hire for a wide variety of roles across IT and Security.

Did I mention we build Satellites? It’s pretty cool stuff.

If you’re here and looking for work, let’s chat. #WWHF #MileHigh2026

12.02.2026 21:13 πŸ‘ 6 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

I feel like my ability as an engineer unlocked when I accepted that, most of the time, everyone in the room knows a whole lot about things I don't, and I know a whole lot of things they don't. They just need my help because my expertise ended up becoming the foundation for them to do theirs.

11.02.2026 07:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The machines that may never be held responsible for the liabilities they create, no less.

11.02.2026 07:04 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Just had a moment of realization for my feelings about the push by VC-backed AI sycophants to "vibe code business apps"

They have not yet learned that lines of code go in the liability column, not the asset column. And they may never learn, because they've forfeited cognition to the machine.

11.02.2026 07:02 πŸ‘ 14 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0