Blog
Build notes, opinions, and the occasional argument. Reference material lives in the guides — this is the stuff that is worth dating.
-
21 September 2026security
Where Developer Data Actually Leaks
Production data rarely escapes through a breach. It escapes through pastebins, online formatters, AI chat windows, screenshots, error trackers and git history. Nine channels, what makes each one invisible, and how to close it.
-
21 September 2026opinion
Client-Side Tools Are a Security Decision, Not a Performance One
Pasting an API response into an online formatter is a data disclosure, not a convenience — and it does not feel like one because nothing in the interface says anything left your machine. How to verify what a tool really does, and the honest limits of the client-side claim.
-
21 September 2026build notes
Building a JSONPath Tester That Does One Thing Differently
Why every result carries the path it was found at, why the filters refuse to coerce types, and the recursive-descent bug that took longer to find than the parser took to write.
What goes here, and what does not
The split is deliberate. Guides are reference material — evergreen, corrected in place, and dated with a "last updated" line so you know how current they are. Posts here are written once and left alone: build notes, arguments, and things that were true on the day they were published.
If a piece would be worse a year from now without an edit, it belongs in the guides. Everything else ends up here.