Blog
Technical write-ups: filesystem internals, storage hardware, reverse engineering, and home infrastructure.
- 2026-10-01 The Camera That Served Me Its Own Firmware I could not find firmware for my Anpviz IP cameras anywhere, so the cameras handed it to me over unauthenticated HTTP, then the admin password in plaintext, then root via a "strong" per-device password that turns out to be one line of Python.
- 2026-09-23 A Klingon Dictionary Fell Out of My Taskbar Learning Ghidra on uBar, a Mac dock replacement, I went looking for a license check and found a base64-encoded Klingon dictionary wired to a randomized time bomb, a piracy flag disguised as an accessibility status, and a marker split in two so it never shows up in the binary.
- 2026-09-15 252 Megabytes in a 64 Gigabyte Trenchcoat Two counterfeit microSD cards hold 252 MiB, not 64 GB. The interesting part is what they return past the end: a deterministic, address-keyed, statistically perfect random stream, identical on both cards.
- 2026-08-26 Who Owns Your Computer? Secure boot, signed operating systems and sandboxing are good engineering. Making them unsupersedable is a statement about ownership, not security.
- 2026-08-21 Updating HP/Samsung PM9B1 NVMe Firmware on Linux (Because I Refused to Boot Windows) HP ships PM9B1 firmware as a Windows-only updater. Reverse engineering it in Ghidra yielded a verified, rebootless update via nvme-cli and a sysfs controller reset.