<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on Bobby's Headspace</title><link>https://blogs.bobbysmiles.xyz/posts/</link><description>Recent content in Posts on Bobby's Headspace</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>smiles@bobbysmiles.xyz (Bobby Smiles)</managingEditor><webMaster>smiles@bobbysmiles.xyz (Bobby Smiles)</webMaster><lastBuildDate>Wed, 02 Sep 2026 08:13:47 +0530</lastBuildDate><atom:link href="https://blogs.bobbysmiles.xyz/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Is The Customer The Enemy?</title><link>https://blogs.bobbysmiles.xyz/posts/right_to_repair/</link><pubDate>Wed, 02 Sep 2026 08:13:47 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/right_to_repair/</guid><description>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;If buying isn&amp;rsquo;t owning, then piracy isn&amp;rsquo;t stealing.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This phrase has gained a &lt;em&gt;&lt;strong&gt;MASSIVE&lt;/strong&gt;&lt;/em&gt; amount of popularity online, mainly due to the unpopular policies recently implemented by big tech companies. Recently, Sony announced that paying for a game doesn&amp;rsquo;t mean that you gain ownership of the game, it simply means that you buy a limited-time license to it.&lt;/p&gt;
&lt;p&gt;There have already been similar discussions surrounding the hardware industry, especially around laptops. Many people have reported that companies actively make it harder for a user to repair their own hardware, or even get their hardware repaired by a licensed service centre, usually by charging exorbitant costs for repairing the item or straight-up denying repairs on said item, citing that it&amp;rsquo;s either outdated or that there is a shortage of parts. This has brought up discussions regarding the &lt;em&gt;Right to Repair&lt;/em&gt;, especially in regions like the EU.&lt;/p&gt;</description><content>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;&lt;em&gt;&amp;ldquo;If buying isn&amp;rsquo;t owning, then piracy isn&amp;rsquo;t stealing.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This phrase has gained a &lt;em&gt;&lt;strong&gt;MASSIVE&lt;/strong&gt;&lt;/em&gt; amount of popularity online, mainly due to the unpopular policies recently implemented by big tech companies. Recently, Sony announced that paying for a game doesn&amp;rsquo;t mean that you gain ownership of the game, it simply means that you buy a limited-time license to it.&lt;/p&gt;
&lt;p&gt;There have already been similar discussions surrounding the hardware industry, especially around laptops. Many people have reported that companies actively make it harder for a user to repair their own hardware, or even get their hardware repaired by a licensed service centre, usually by charging exorbitant costs for repairing the item or straight-up denying repairs on said item, citing that it&amp;rsquo;s either outdated or that there is a shortage of parts. This has brought up discussions regarding the &lt;em&gt;Right to Repair&lt;/em&gt;, especially in regions like the EU.&lt;/p&gt;
&lt;p&gt;What&amp;rsquo;s really undercutting all these talks is the eroding trust in companies to safeguard the customer&amp;rsquo;s interests. But why are companies suddenly antagonizing the customer? Is this really a new pattern in businesses or is it gaining prominence only now? I think this is worth looking at a little closer before forming an opinion.&lt;/p&gt;
&lt;h1 id="video-game-ownership"&gt;Video Game Ownership&lt;/h1&gt;
&lt;p&gt;I personally think the topic of video game ownership is what brought the seemingly spurious practices of companies to light. It all started with &lt;a href="https://in.ign.com/prince-of-persia-the-lost-crown/200594/news/ubisoft-exec-says-gamers-need-to-get-comfortable-not-owning-their-games-for-subscriptions-to-take-of"&gt;Ubisoft&amp;rsquo;s infamous claim&lt;/a&gt; &lt;em&gt;&amp;ldquo;Gamers should get comfortable with the idea of not owning their games&amp;rdquo;&lt;/em&gt;. While at the time it didn&amp;rsquo;t cause as much of a stir as we see nowadays in the video game industry, it still had enough of an effect to sour the image of Ubisoft among the general gaming populace.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fi.programmerhumor.io%2F2026%2F01%2F4ea2a16b7ff9599649b91b1f7690cedf151ee3927ebb3588a97b93e017f37057.jpeg&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=633425079467235490546b29ef78dcb0c72bd271e76a1d1a835271d5b2ea1d58" alt=":(" style="border-radius: 8px; width: 399px; height: 541px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;This saw a resurgence earlier this year with the recent email from Sony, that reminded players that games are &lt;em&gt;&amp;quot;&lt;a href="https://www.playstation.com/en-in/legal/software-usage-terms_archived/"&gt;licensed, not sold&lt;/a&gt;&amp;quot;&lt;/em&gt; and that the license is limited, non-exclusive, non-transferable, and personal license to use the software privately on the intended system or device. This has left players fearing that Sony could revoke their license at their own discretion, because the license is revocable.&lt;/p&gt;
&lt;p&gt;This email was sent after another unpopular announcement by Sony, which stated that they aim to &lt;a href="https://blog.playstation.com/2026/07/01/physical-disc-production-ending-in-january-2028-for-new-games-releasing-on-playstation-consoles/comment-page-120/"&gt;phase out physical games by the year 2028&lt;/a&gt;. These 2 announcements, coupled with other unpopular video game policies by Sony soured their image in the eyes of people, with many people reporting switching to Xbox due to their more customer friendly approach to the video games industry.&lt;/p&gt;
&lt;h1 id="right-to-repair"&gt;Right to Repair&lt;/h1&gt;
&lt;p&gt;The &lt;a href="https://govfacts.org/money/consumer-protection/consumer-rights-laws/right-to-repair-why-you-cant-fix-your-own-stuff-and-whats-being-done-about-it/"&gt;right to repair&lt;/a&gt; simply refers to us, the customers, having the ability to repair the things we buy. More and more people are becoming aware of the fact that companies &lt;strong&gt;do&lt;/strong&gt; in fact make it intentionally difficult for users to &lt;a href="https://govfacts.org/rights-freedoms/family-personal-rights/parental-rights/parents-bill-of-rights-a-new-movement-explained/"&gt;repair&lt;/a&gt; their own items. This practice is seen in almost every industry ranging from farming equipment all the way to the consumer electronics industry.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fi.imgflip.com%2F9ey0cm.jpg&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=5d618fd6dabb5cca5d7241d4b60fa4b69c3999dc0878351c79b9175039cdbf0a" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;In brief, the movement demands that consumers and independent repair shops must be provided with access to various provisions to repair the things they buy. This includes design schematics, parts and manufacturing of the product such that it is easy to repair. They also argue that this plays into preserving the environment by promoting sustainable development through a &lt;em&gt;&amp;quot;&lt;a href="https://en.wikipedia.org/wiki/Circular_economy"&gt;circular economy&lt;/a&gt;&amp;quot;&lt;/em&gt; and reducing e-waste. It also helps in saving costs, because instead of buying a whole new item in case it is damaged, we can just replace the damaged components.&lt;/p&gt;
&lt;p&gt;But where am I going with all this?&lt;/p&gt;
&lt;h1 id="but-why-does-this-happen"&gt;But Why Does This Happen?&lt;/h1&gt;
&lt;p&gt;A business is, at the end of the day, incentivized to make a profit. So it is not surprising when we see businesses look at multiple options to maximize their profit margins. One of these tactics is cutting costs. But what I believe made businesses provide better services back in the day was one simple thing - &amp;ldquo;&lt;strong&gt;competition&lt;/strong&gt;&amp;rdquo;.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fwww.botkart.com%2Fwp-content%2Fuploads%2F2022%2F11%2Ffunny-customer-meme-04.jpg&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=f0ab9edc304fe5bc1a8c964910de8adb7d4880f5db2fa51319cece1b16e60bc6" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;a href="https://localandglobaleco.com/2025/03/15/how-declining-competition-is-reshaping-the-economies/"&gt;Declining competition&lt;/a&gt; in the modern era is one of the primary factors due to which businesses have the leeway to get away with a lot more than they did previously. And it makes sense, since the businesses which dominate the markets now, beat their previous competition by providing superior products and better customer acquisition and retention. Just look at the &lt;a href="https://duckduckgo.com/?q=console&amp;#43;wars&amp;amp;t=brave&amp;amp;ia=web"&gt;console wars&lt;/a&gt;. I don&amp;rsquo;t think it is a stretch for me to say that the PlayStation beat out all of its competition in the end, with a majority of console gamers opting for a PS5 over an Xbox Series X.&lt;/p&gt;
&lt;p&gt;But with the slew of unpopular policies that Sony introduced, Xbox has managed to make something of a comeback, under their current CEO Asha Sharma. They&amp;rsquo;ve implemented policies and features that keep gamers at the forefront such as the &lt;a href="https://news.xbox.com/en-us/2026/08/26/your-discs-now-also-digital/"&gt;Disc to Digital&lt;/a&gt; program, which allows gamers to convert their physical discs into a digital license for free.&lt;/p&gt;
&lt;p&gt;The EU has also &lt;a href="https://www.cnbc.com/2026/04/10/google-meta-big-tech-6-billion-euros-eu-fine.html"&gt;fined&lt;/a&gt; multiple companies like Apple, Google, YouTube, Meta and Amazon for their &amp;ldquo;&lt;em&gt;anti-competitive&lt;/em&gt;&amp;rdquo; practices, demonstrating governments&amp;rsquo; increasing concern over the excessive market power wielded by some businesses. Now I&amp;rsquo;ll be real here, I am not quite sure why the EU had suddenly gone after these companies with no precursor when they seemed completely fine with the same companies and the same practices just a couple of years back, but I&amp;rsquo;ll take the win I guess 😂.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fi.kym-cdn.com%2Fphotos%2Fimages%2Foriginal%2F002%2F842%2F099%2F18f.png&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=2f32c969b7e177d62da697907d0f295db7caf8ddb56ad7032c6440697c5cd525" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;The Norwegian Consumer Council put out a &lt;a href="https://www.youtube.com/watch?v=T4Upf_B9RLQ"&gt;video&lt;/a&gt; trolling the &lt;a href="https://en.wikipedia.org/wiki/Enshittification"&gt;enshittification&lt;/a&gt; of products, taking jabs at big tech companies like google, apple, etc. In the same vein, businesses like steam have always provided excellent services, therefore keeping their customers happy. Steam&amp;rsquo;s customer support has gained great reputation because it has consistently shown that it genuinely &lt;a href="https://www.reddit.com/r/Steam/comments/1d96l9v/i_just_want_to_publicly_thank_steam_support_im_an/"&gt;helps customers out in any way they can&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Companies like &lt;a href="https://frame.work/"&gt;Framework&lt;/a&gt; have also started gaining momentum due to the modularity of their laptops and their inherent adherence to the Right to Repair movement. It allows customers the freedom to customize their hardware and upgrade it as they see fit. This modularity and customizability offer a great competitive advantage, because it genuinely does cost less than just switching out the entire device.&lt;/p&gt;
&lt;p&gt;Essentially, what I am trying to say is that businesses have no inherent incentive to be anti-customer, many businesses have had these so-called &amp;ldquo;anti-customer&amp;rdquo; practices for ages, but now we are noticing it better. We notice because there aren&amp;rsquo;t as many options to choose from, so we notice the shortcomings of the options we do have a lot more.&lt;/p&gt;
&lt;h1 id="before-we-conclude"&gt;Before we Conclude&lt;/h1&gt;
&lt;p&gt;A few things we should note about competition between businesses and the lack of options is that, it is not entirely about competition alone. See as consumers, we get locked into certain product ecosystems, which makes switching out of it a pricey affair. Let&amp;rsquo;s take an example here. Say that I own the entire collection of apple products, from the mac to the iphone to all the peripherals that apple provides. One thing that this does, is that it gives us a buttload of convenience. The ecosystem is centralized, all the products integrate well with one another and our workflows are consistent.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fi.kym-cdn.com%2Fphotos%2Fimages%2Foriginal%2F002%2F705%2F435%2Fb68.jpg&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=5b8eea61da8b406c550ac4497b4bdef5cc041f4b4baf781d0a91e255e5cbc8c3" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="left" &gt;random meme lol&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Now if we want to switch out to something like android, it will inevitably take a lot of time and money to do so, since we&amp;rsquo;ve worked with a certain ecosystem with its set of conveniences, which ends up discouraging the switch from apple. This is pretty much what happens with other products as well. We have switching costs, network effects and our own digital artifacts that we&amp;rsquo;ve gathered up, some of which might be transferable from one ecosystem to another, making switching impractical. This is where the &lt;em&gt;Right to Repair&lt;/em&gt; movement and other similar talks come in, so that we can save money there, rather than spend more to stay within the same ecosystem.&lt;/p&gt;
&lt;p&gt;One other thing we have to address is the convenience of digital libraries. It is pretty much the same argument as &lt;a href="https://www.historytools.org/reviews/streaming-vs-physical-media"&gt;streaming vs physical movies&lt;/a&gt;. Digital libraries offer convenience, better portability and accessibility. And it can be argued that it is &lt;em&gt;&lt;strong&gt;MUCH&lt;/strong&gt;&lt;/em&gt; easier to have digital copies of hundreds of games instead of a whole treasure trove of physical discs.&lt;/p&gt;
&lt;p&gt;There are many more arguments to be made as such but to keep this article from becoming a huge wall of text I have listed out one or two important ones. But what I am getting at here is not the fact that digitizing something is inherently bad, but rather that we are losing reason to trust that it will be handled well by the people managing these digital libraries for us.&lt;/p&gt;
&lt;h1 id="conclusion"&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;At the end of the day businesses have been and always will be profit centric. They are going to optimize their spendings in any way they can, because it will contribute to the growth of their profit margins. This is the same reason why AI seemed appealing initially and also why businesses are silently &lt;a href="https://www.thehrdigest.com/companies-are-rehiring-people-they-replaced-during-ai-layoffs/"&gt;re-hiring human engineers&lt;/a&gt;. What we should be aiming for is not for businesses to suddenly become charitable saints, but rather we should aim for businesses to have to &lt;em&gt;compete&lt;/em&gt; for our money.&lt;/p&gt;
&lt;p&gt;Hope you enjoyed the article :)&lt;/p&gt;</content></item><item><title>Is This The End of Cybersecurity?</title><link>https://blogs.bobbysmiles.xyz/posts/ai_cybersecurity/</link><pubDate>Sat, 18 Jul 2026 07:41:05 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/ai_cybersecurity/</guid><description>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;Ever since the promotion of Claude Mythos and Opus before it (if my memory serves me right), AI has been hyped up to be able to compete with cybersecurity researchers and even surpassing them in some areas. Exploits like the copy-fail exploit were discovered through the AI and recently DirtyFrag exploit are all discovered with the help of AI. But what does this really mean? Does it mean that manual vulnerability analysis, and cybersecurity at large is finally obsolete? Do we even need humans in this field anymore? I think the picture isn&amp;rsquo;t all that it seems.&lt;/p&gt;</description><content>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;Ever since the promotion of Claude Mythos and Opus before it (if my memory serves me right), AI has been hyped up to be able to compete with cybersecurity researchers and even surpassing them in some areas. Exploits like the copy-fail exploit were discovered through the AI and recently DirtyFrag exploit are all discovered with the help of AI. But what does this really mean? Does it mean that manual vulnerability analysis, and cybersecurity at large is finally obsolete? Do we even need humans in this field anymore? I think the picture isn&amp;rsquo;t all that it seems.&lt;/p&gt;
&lt;h1 id="ctfs-and-automation"&gt;CTFs and Automation&lt;/h1&gt;
&lt;p&gt;One of the major areas in cybersecurity that has seen a drastic shift due to the rise of AI are CTFs. AI has completely changed the game, by allowing players and researchers to find exploits easier and faster than ever. CTF creators and the wider cybersecurity community at large is quite split on how exactly one should be handling this sudden shift in the game.&lt;/p&gt;
&lt;p&gt;In my time playing CTFs this year, I&amp;rsquo;ve seen 3 common approaches. The first one is a more extremist one, with AI being almost completely banned from the competition. Frankly, I think this is a pretty impractical approach because people are going to use AI whether you like it or not. It is, in many ways &lt;strong&gt;VERY&lt;/strong&gt; convenient. Which leads me to the second approach.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQK1vCfo5GrIk34Mqx3eXVIfipqZXBG8GzieuaRnYULLHn_lASdZ_SLipc&amp;amp;s=10" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;The second approach, allows AI to be used, but by segregating those who use AI from those who do not use AI. This is done in many ways, for example in DEFCON Quals 2026, I saw a pledge system, where you brand yourself as a team who uses AI or not. I think this is a balanced approach compared to the first one considering that we&amp;rsquo;re leaving it up to the historically good nature of the CTFers to clarify whether they&amp;rsquo;re using AI or not. However people also tend to have 2 separate divisions for the non-AI users and the AI users, which I think is quite a faithful leap to take, considering that I can just use AI in the human division and win big 😂.&lt;/p&gt;
&lt;p&gt;The third approach, and one that is gaining widespread traction is to just &lt;em&gt;use&lt;/em&gt; AI as you please. HackTheBox had conducted a &lt;a href="https://www.hackthebox.com/blog/ai-vs-human-ctf-hack-the-box-results"&gt;CTF&lt;/a&gt; where AI agent teams were pitted against human teams to compete for the top spot. What they found is that AI tends to be a more general type of problem solver, whereas humans tend to achieve high levels of skill in specialized domains. The AI teams started by taking the lead but soon, were just short of top 20 due to them not solving 1 question out of the 20 that were presented. What this study did find out is that, AI is just as competent as humans when it comes to problem solving, and definitely quite faster (initially at least).&lt;/p&gt;
&lt;h1 id="bug-bounty-and-vulnerability-assessment"&gt;Bug Bounty and Vulnerability Assessment&lt;/h1&gt;
&lt;p&gt;I had previously made a &lt;a href="https://blogs.bobbysmiles.xyz/posts/ai_bugbounty/"&gt;post&lt;/a&gt; around one year back, speaking of AI and its usage in finding bugs and other cybersecurity related activies. Since then however, AI has evolved to the point where it can find bugs in modern software that were otherwise not uncovered by cybersecurity engineers. As I had already mentioned above, 2 popular bugs are the &lt;a href="https://copy.fail/"&gt;Copy-Fail bug&lt;/a&gt; and the &lt;a href="https://github.com/V4bel/dirtyfrag"&gt;DirtyFrag exploit&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The reason these gained so much traction is that they are not recently added bugs, but rather bugs that were overlooked for many years that were hidden in the Linux Kernel. Other bugs in many other popular pieces of software have been discovered and this number only continues to rise. It&amp;rsquo;s even getting to the point where large companies like Microsoft are using AI to fix bugs in their own code.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQHR4bOBhcFpeBD1FZk5OrhsKfCoYyj13cmi4CGNN04lw46sw_JguJnL_Aa&amp;amp;s=10" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;There are, however, statements put out about these being able to hack stuff like the pentagon or break out of its own servers and things. I&amp;rsquo;d take those with a &lt;strong&gt;MASSIVE&lt;/strong&gt; grain of salt considering that they are unverified claims coming from companies that stand to gain &lt;strong&gt;A LOT&lt;/strong&gt; of benefits from people believing these things.&lt;/p&gt;
&lt;p&gt;Bug Bounty has seen a similar situation as described in &lt;a href="https://cybernews.com/ai-news/ai-break-bug-bounty-programs/"&gt;this article&lt;/a&gt; where AI is finding a lot of valid bugs and reporting them at a very high rate, to the point where it&amp;rsquo;s getting very difficult for maintainers to keep up.&lt;/p&gt;
&lt;p&gt;However tempting it might seem to assign this to the so-called &lt;em&gt;smartness&lt;/em&gt; of AI, I think there&amp;rsquo;s a more technical reason for this.&lt;/p&gt;
&lt;h1 id="ai-and-its-strengths"&gt;AI and its Strengths&lt;/h1&gt;
&lt;p&gt;I recently came across &lt;a href="https://www.youtube.com/watch?v=ty1IGU9U8_o"&gt;this video&lt;/a&gt; by &lt;a href="https://www.youtube.com/@LowLevelTV"&gt;Low Level&lt;/a&gt; that explains the increased proficiency of AI quite well. Essentially he boils the strengths of AI down to three things:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Static Analysis&lt;/li&gt;
&lt;li&gt;Vulnerability Research&lt;/li&gt;
&lt;li&gt;General Automation&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="static-analysis"&gt;Static Analysis&lt;/h2&gt;
&lt;p&gt;Static Analysis simply refers to analysing a piece of software to find a bug, without actually running it. This can be done via code reviews, data flow analysis, etc. At its core, AI is a text predictor. This means that it has the ability to take a piece of text and output some data with respect to it. It also can ingest &lt;strong&gt;MASSIVE&lt;/strong&gt; amounts of code as opposed to a human being. This allows it to be way &lt;em&gt;faster&lt;/em&gt; than a human when it comes to understanding an underlying codebase.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fsubstackcdn.com%2Fimage%2Ffetch%2Ff_auto%2Cq_auto%3Agood%2Cfl_progressive%3Asteep%2Fhttps%253A%252F%252Fsubstack-post-media.s3.amazonaws.com%252Fpublic%252Fimages%252F74672ad2-9703-42ac-acbe-8e0cd409d5f1_551x453.jpeg&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=f3c6ba93adf4a7ce1b1120adcf563da38133c05ee2a4b9009406061a1c7466a1" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;Another thing that has to be factored in here, is the training data of the AI. This data contains countless codebases and its associated issues or vulnerabilities, which allows AI to also easily detect these patterns. Combined with the fact that it already ingests large amounts of code and understands it at a very high speed, it stands to reason that it&amp;rsquo;ll be able to detect bugs quicker than humans can.&lt;/p&gt;
&lt;h2 id="vulnerability-research"&gt;Vulnerability Research&lt;/h2&gt;
&lt;p&gt;This is pretty much an off-shoot of the capabilities of AI in static analysis. When people write code, they focus on getting the task done with a reasonable amount of efficiency. In this process, a common thing that can occur is that a few edge-cases are not accounted for. This results in bugs popping up, which the AI is very good at detecting, because of the data it is trained on, as I mentioned in the &lt;strong&gt;Static Analysis&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2 id="general-automation"&gt;General Automation&lt;/h2&gt;
&lt;p&gt;AI agents are also capable of automating tasks through the use of internal tools and MCP servers, as seen with the rise of Agentic AI. This allows the AI to automatically analyse code, decide the best course of action, and proceed to test further. This has resulted in massive increases in productivity and the ability to test and analyse code. This increased security capability became apparent with the release of tools like &lt;a href="https://github.com/LaurieWired/GhidraMCP"&gt;Ghidra MCP&lt;/a&gt;, Snyk Code, etc.&lt;/p&gt;
&lt;h1 id="do-we-need-humans-then"&gt;Do We Need Humans Then?&lt;/h1&gt;
&lt;p&gt;Yes. Yes humans are still required for cybersecurity, and if anything, now more than ever. Humans still possess the ability to discover novel types of bugs and very convoluted zero-days. While AI is &lt;em&gt;very&lt;/em&gt; good at cybersecurity, it is still not the pinnacle of what it can be. As different studies have shown, AI does things faster, but humans still are better at the job.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fpleated-jeans.com%2Fwp-content%2Fuploads%2F2024%2F05%2Ffunny-ai-memes-11.webp&amp;amp;f=1&amp;amp;nofb=1&amp;amp;ipt=b07ff7381a82dd5c0fd3563d5761e7f53659310b0ff0d19761be5382e9814faa" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;With all this said, it would be insensible to pretend that AI is not going to be stealing jobs or anything. In fact, it already has automated most of the low level jobs in the industry. But this is not a &amp;ldquo;&lt;strong&gt;loss-of-jobs&lt;/strong&gt;&amp;rdquo; issue, rather it is that the skill ceiling has increased, and now more than ever, companies are asking the question, &amp;ldquo;Can I automate what this person is offering to a good degree of effectiveness?&amp;rdquo;. This is what we must focus on, upskilling and using the tools at hand.&lt;/p&gt;
&lt;h1 id="closing-thoughts"&gt;Closing Thoughts&lt;/h1&gt;
&lt;p&gt;So, we do require humans in cybersecurity and humans still do play an integral role, not just in cybersecurity, but also tech jobs in general. So the point from my &lt;a href="https://blogs.bobbysmiles.xyz/posts/ai_bugbounty/"&gt;previous post on ai in cybersecurity&lt;/a&gt; still stands. If we don&amp;rsquo;t update our skillset with respect to the current market, or if we rely too much on tools that are ultimately meant to &lt;em&gt;enhance&lt;/em&gt; our workflow (like AI), we will be left behind.&lt;/p&gt;</content></item><item><title>Where Did All the Humans Go?</title><link>https://blogs.bobbysmiles.xyz/posts/dead_internet/</link><pubDate>Wed, 24 Jun 2026 13:59:40 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/dead_internet/</guid><description>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;The internet has come a long way since its inception as the &lt;a href="https://en.wikipedia.org/wiki/ARPANET"&gt;ARPANET&lt;/a&gt; in the year 1969. The modern internet we know today is powered primarily by algorithms, on one hand allowing us to curate our feeds with content that we prefer, and on the other allowing apps to have longer user engagement. But what if this was taken one step further? What if all our interactions on the internet are in some way curated for us? What if more than half of our interactions online are not with humans, but with AI bots? This is what the &lt;a href="https://en.wikipedia.org/wiki/Dead_Internet_theory"&gt;Dead Internet Theory&lt;/a&gt; proposes.&lt;/p&gt;</description><content>&lt;h1 id="background"&gt;Background&lt;/h1&gt;
&lt;p&gt;The internet has come a long way since its inception as the &lt;a href="https://en.wikipedia.org/wiki/ARPANET"&gt;ARPANET&lt;/a&gt; in the year 1969. The modern internet we know today is powered primarily by algorithms, on one hand allowing us to curate our feeds with content that we prefer, and on the other allowing apps to have longer user engagement. But what if this was taken one step further? What if all our interactions on the internet are in some way curated for us? What if more than half of our interactions online are not with humans, but with AI bots? This is what the &lt;a href="https://en.wikipedia.org/wiki/Dead_Internet_theory"&gt;Dead Internet Theory&lt;/a&gt; proposes.&lt;/p&gt;
&lt;h1 id="the-dead-internet-theory"&gt;The Dead Internet Theory&lt;/h1&gt;
&lt;p&gt;Originally posted in &lt;a href="https://forum.agoraroad.com/index.php"&gt;Agora Road&amp;rsquo;s Macintosh Cafe&lt;/a&gt;, the Dead Internet Theory proposes that most of the internet activity is automated. That is, it says that most of the activity on the current iteration of the internet is not organic, but rather consists of automated content and bot activity, further pushed by curation algorithms.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://forum.agoraroad.com/index.php?media/agoraban54-gif.48006/full" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;One of the banners I really liked on the Agora Road's forum&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;With the rise of AI in recent years, this theory has seen a kind of resurgence, with many popular creators talking about it. Personally I believe there is some truth to this theory, but there are important caveats to this that I also want to point out, because it&amp;rsquo;s easy to tread past the facts, into the realm of conspiracy.&lt;/p&gt;
&lt;h1 id="ai-generated-content"&gt;AI Generated Content&lt;/h1&gt;
&lt;figure class="center" &gt;
&lt;img src="https://imgs.search.brave.com/RnTJuw2ZWedLwimNbwMQPqppEczx1nDJgN787l3HGRc/rs:fit:860:0:0:0/g:ce/aHR0cHM6Ly9wcmV2/aWV3LnJlZGQuaXQv/ZGVhZC1pbnRlcm5l/dC10aGVvcnktdjAt/bmF4dm1zaDBzd3Jl/MS5qcGVnP3dpZHRo/PTY0MCZjcm9wPXNt/YXJ0JmF1dG89d2Vi/cCZzPThhMTU0MzFh/NDgxY2UzODhhMmQ5/YWM0YWQ1YTQzYjQy/ZDY0NTVkMGE" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;One thing that I am sure of, and evidence being there for, is that AI generated content is &lt;strong&gt;more likely&lt;/strong&gt; to be recommended to the average consumer compared to human-created content. Almost all platforms use complex ranking systems to recommend the content that is most likely to be consumed. Ironically, this is &lt;strong&gt;EXACTLY&lt;/strong&gt; why AI generated content is more likely to rank higher, because AI is also trained on highly ranked content from the internet.&lt;/p&gt;
&lt;p&gt;But does this mean human generated searches are never encountered? No, not quite. Human generated content &lt;em&gt;can&lt;/em&gt; still rank high on search rankings. It is just that AI generated content ranks high consistently, which makes it harder to find organic content on the web.&lt;/p&gt;
&lt;h1 id="ai-bot-activity"&gt;AI Bot activity&lt;/h1&gt;
&lt;p&gt;This one is a little harder to quantify. In all honesty, there is some good evidence indicating that a lot of activity on the internet is in fact bot activity. For example, a cybersecurity company called &lt;a href="https://www.imperva.com/resources/resource-library/reports/2024-bad-bot-report/"&gt;Imperva&lt;/a&gt; found that almost 30% of all website visits on the internet are bot visits. They also found that over half of all internet activity was performed by bots or automated software applications. Many of these actions came from malicious bots, designed to steal information or compromise systems.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcTu4OXwSlohEji87LmHxyWAnV9POAet1K5UWejfPB4WAHpadcV4qLV-teQ&amp;amp;s=10" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;One thing that must be kept in mind, however, is that this accounts for the internet as a whole, so it&amp;rsquo;s not like every single forum is just a wasteland of bot activity. It&amp;rsquo;s just that across a majority of the internet, bots do indeed contribute to a majority of the activity.&lt;/p&gt;
&lt;h1 id="are-higher-powers-controlling-us-through-this"&gt;Are Higher Powers Controlling Us Through This?&lt;/h1&gt;
&lt;p&gt;There is an aspect of this theory I haven&amp;rsquo;t mentioned yet, and that is the fact that many interpretations of this theory tread into conspiratorial waters. It alleges that governments and big tech try to control us through this bot traffic by intentionally soliciting our feeds with certain types of content. One of the drivers of this solicitation is the bot activity in certain forums. It also alleges that this has been the case since 2016 (frankly, I don&amp;rsquo;t know how they arrived at this exact year).&lt;/p&gt;
&lt;p&gt;Looking at it objectively, I would say that we don&amp;rsquo;t have any evidence. From recent events, it &lt;strong&gt;IS&lt;/strong&gt; most likely that we are under constant surveillance but I am not sure how much of this aspect of the theory can be proven, if at all it is true. Many comment sections and social platforms have caught bots posing as humans, and in some extreme cases even posting political opinions. But how much of this is just some random person being too lazy to type out his own stuff vs it actually being a political power trying to steer public opinion remains to be seen.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://www.meme-arsenal.com/memes/53a0552a45f6853eb84e73a69a353157.jpg" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;Also there are in fact many places which are still mostly composed of human activity. Sites like &lt;a href="https://reddit.com/"&gt;Reddit&lt;/a&gt; and other small internet forums still are composed mostly of organic, human activity. Of course these sites have their fair share of AI slop content but it is low for now. Even &lt;a href="https://forum.agoraroad.com/index.php"&gt;Agora Road’s Macintosh Cafe&lt;/a&gt; is still home to quite a bit of organic activity when I last checked.&lt;/p&gt;
&lt;p&gt;So what can we conclude from this? While the conspiracy theories do seem outlandish, I wouldn&amp;rsquo;t entirely dismiss them, mostly considering recent events. I can only say that there is no convincing evidence from either side for me to form an actual opinion.&lt;/p&gt;
&lt;h1 id="but-what-can-we-do"&gt;But What Can We Do?&lt;/h1&gt;
&lt;figure class="center" &gt;
&lt;img src="https://media.tenor.com/wfIU8MrRhAoAAAAM/dead-chat-dead.gif" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;Unfortunately here, I can&amp;rsquo;t provide a possible solution. The maximum we can do is try and verify our sources the best we can, but really how far can we go? How much can we verify each and every source for what is possibly a simple online interaction? It would be very difficult, and dare I say, kind of &lt;em&gt;tedious&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The best we can do in the end, is to curate our own knowledge, maintain a few trusted sources that we know have minimal bot interaction, and do our best to bring these sources out to the mainstream. As I mentioned in my &lt;a href="https://blogs.bobbysmiles.xyz/posts/modern_privacy/"&gt;article on privacy&lt;/a&gt;, we can try and switch to smaller providers and platforms in order to reduce the impact of an increasingly artificial internet.&lt;/p&gt;
&lt;h1 id="conclusion"&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;AI is unfortunately making it harder to distinguish between automated and organic interactions online, whether this is online content, or a random thread on &lt;a href="https://x.com"&gt;X&lt;/a&gt; or a simple &lt;a href="https://instagram.com"&gt;Instagram&lt;/a&gt; comments section. In the coming future, it remains to be seen how much of our activity online will be with real humans, and how much will be just algorithmic AI slop that is served to us, creating a personalized echo chamber online.&lt;/p&gt;</content></item><item><title>Privacy in the Modern Digital Landscape</title><link>https://blogs.bobbysmiles.xyz/posts/modern_privacy/</link><pubDate>Thu, 21 May 2026 12:53:04 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/modern_privacy/</guid><description>&lt;h1 id="the-current-scenario"&gt;The Current Scenario&lt;/h1&gt;
&lt;p&gt;The modern internet feels like a mess. From the overly &lt;em&gt;enshittified&lt;/em&gt; quality of products to AI being stuffed down our throat at every turn, the internet has, in many ways, lost its initial charm and simplicity. Lately a &lt;strong&gt;LOT&lt;/strong&gt; of privacy violations have come our way too, from AI crawlers indiscriminately taking online content without consent, to sites like LinkedIn &lt;em&gt;literally&lt;/em&gt; tracking user activity and selling it off to cybersecurity companies, the list just doesn&amp;rsquo;t end.&lt;/p&gt;</description><content>&lt;h1 id="the-current-scenario"&gt;The Current Scenario&lt;/h1&gt;
&lt;p&gt;The modern internet feels like a mess. From the overly &lt;em&gt;enshittified&lt;/em&gt; quality of products to AI being stuffed down our throat at every turn, the internet has, in many ways, lost its initial charm and simplicity. Lately a &lt;strong&gt;LOT&lt;/strong&gt; of privacy violations have come our way too, from AI crawlers indiscriminately taking online content without consent, to sites like LinkedIn &lt;em&gt;literally&lt;/em&gt; tracking user activity and selling it off to cybersecurity companies, the list just doesn&amp;rsquo;t end.&lt;/p&gt;
&lt;p&gt;In light of such situations, it becomes more crucial than ever to secure our own data and not let these companies have their way. In this article, I want to highlight the current landscape and talk about some of the things I personally do to ensure I am not being tracked through every step of my internet activity.&lt;/p&gt;
&lt;h1 id="the-linkedin-debacle"&gt;The LinkedIn Debacle&lt;/h1&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/modern_privacy/meme1.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;I&amp;rsquo;ll start this off with the recent LinkedIn controversy that was making the rounds on the internet. Basically, LinkedIn users found out that they are being tracked by the site, for the use of over 6000 common extensions, ranging from job-search extensions to productivity software. This was dubbed BrowserGate, and you can get a lot of the information I&amp;rsquo;m about to detail from &lt;a href="https://browsergate.eu/"&gt;the official site&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The thing is, its already a known fact that LinkedIn tracks browser extensions. So why is this causing so much outrage? It is the simple fact that LinkedIn actually never mentions &lt;strong&gt;ANY OF THIS&lt;/strong&gt; in its privacy policy. They just run the embedded JS that does the tracking, and just &lt;em&gt;track&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This is blatantly illegal under laws and regulations. To keep it brief, most laws and regulations state that it is fine to take data like the name, email and other basic information, but beyond that the company &lt;em&gt;&lt;strong&gt;MUST&lt;/strong&gt;&lt;/em&gt; ask for consent. This is absolutely not done by the site and worse, the data is transmitted to third-party companies, again without the consent of the user.&lt;/p&gt;
&lt;p&gt;But which browsers are affected? It was reported that all chromium based engines were especially susceptible to this script but firefox and Firefox-based browsers weren&amp;rsquo;t.&lt;/p&gt;
&lt;p&gt;So just use Firefox :)&lt;/p&gt;
&lt;h1 id="telemetry-and-data-collection-in-big-tech"&gt;Telemetry and Data Collection in Big Tech&lt;/h1&gt;
&lt;p&gt;Data collection in major applications has existed for a long time. By now its a known fact that products like the Google Search Engine, Windows, Amazon, Instagram, and other popular services all collect user data either for advertising purposes or for monetization. What&amp;rsquo;s worse is that many of these services are taking our data to train their proprietary AI models, which runs a very real risk of leaking said data through jailbreak or prompt-injection attacks. This is compounded by the use of AI agents like OpenClaw, which poses a major security risk to data privacy as AI models are just prone to leaking data under certain conditions, as observed in the &lt;a href="https://pushsecurity.com/blog/unpacking-the-vercel-breach"&gt;Vercel Data Breach&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;But where am I going with all this?&lt;/p&gt;
&lt;h1 id="privacy-focused-tooling"&gt;Privacy Focused Tooling&lt;/h1&gt;
&lt;p&gt;There are quite a few alternative services that we can make use of to improve our privacy. I&amp;rsquo;ll be talking about some of the tools that I commonly use, for web browsing, emails, cloud storage and more. I want to mention beforehand that I am not going to be talking about self-hosting services here, just the already existing online services that you can use.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/modern_privacy/meme2.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;h1 id="web-browsing"&gt;Web Browsing&lt;/h1&gt;
&lt;p&gt;This might be the easiest and most simple switch to make. Just yesterday, Google held &lt;a href="https://io.google/2026/"&gt;Google I/O&lt;/a&gt;, where they announced that Google Search will be pushing AI generated content higher on the search results. What brought them to cook-up this &amp;ldquo;amazing&amp;rdquo; idea I don&amp;rsquo;t know, but I think it&amp;rsquo;s all the more reason to start switching.&lt;/p&gt;
&lt;p&gt;Personally, I recommend either &lt;a href="https://search.brave.com/"&gt;Brave Search&lt;/a&gt; or &lt;a href="http://duckduckgo.com/"&gt;DuckDuckGo&lt;/a&gt;. Brave tends to deliver slightly better search results since it ranks pages based on popularity, but its index size is smaller than DuckDuckGo.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Index Size here simply means the amount of pages the search engine indexes. It requires a lot of computing power so really only the Tech Giants actually have the entire internet indexed.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;DuckDuckGo, on the other hand uses a combination of multiple indices. So its index size is &lt;em&gt;way&lt;/em&gt; bigger and it delivers a pretty decent search result quality. But it is slightly worse than Brave at delivering results and sometimes you&amp;rsquo;ll have to be a bit more specific with your search to get what you want. For absolute privacy though, DuckDuckGo search seems to be a bit better than Brave. I use DuckDuckGo a bit more frequently than Brave because of a couple of features it offers which you&amp;rsquo;ll see as you read on :)&lt;/p&gt;
&lt;h1 id="cloud-storage"&gt;Cloud Storage&lt;/h1&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/modern_privacy/meme2.webp" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;a href="https://proton.me/drive"&gt;Proton Drive&lt;/a&gt; and &lt;a href="https://mega.nz/"&gt;Mega.nz&lt;/a&gt; are good options in this space. Proton drive is slightly better if you want an experience as close to google drive as possible, with its free tier offering 5GB of storage. Mega.nz offers 20GB of storage in its free tier and if you&amp;rsquo;re willing to learn the slightly different interface, it&amp;rsquo;s probably the better option, in terms of pure storage capacity.&lt;/p&gt;
&lt;p&gt;However, Proton is much more generous when you hit the limits on the free tier account, while Mega is reported to just freeze your account with no warning. So if you&amp;rsquo;re good at managing and tracking your storage well, use Mega otherwise I&amp;rsquo;d recommend Proton.&lt;/p&gt;
&lt;h1 id="web-browsers"&gt;Web Browsers&lt;/h1&gt;
&lt;p&gt;This is a popular topic in many mainstream forums so I&amp;rsquo;d imagine if you&amp;rsquo;re reading this article, you&amp;rsquo;d be aware of the options I present here. &lt;a href="https://brave.com/"&gt;Brave Browser&lt;/a&gt; is a very accessible, privacy-focused browser to use. It features a built-in adblocker and a TOR mode to browse the web using onion routing.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://duckduckgo.com/windows"&gt;DuckDuckGo browser&lt;/a&gt; is also one that I quite like though I personally feel features-wise it lags a little bit behind Brave. The real selling point for me with the DuckDuckGo browser is the fire button. It deletes all open tabs, sessions, web caches and other data the website or browser may store. This helps ensure that our digital footprint is erased with pretty much no ambiguity.&lt;/p&gt;
&lt;h1 id="emails"&gt;Emails&lt;/h1&gt;
&lt;p&gt;This is the part I had the most fun setting up. I use a less well-known email called &lt;a href="https://cock.li/"&gt;cock.li&lt;/a&gt; (hilarious name I know 😂) paired with &lt;a href="https://duckduckgo.com/email/"&gt;DuckDuckGo Email Protection&lt;/a&gt; for forwarding emails. It is quite easy to setup and DuckDuckGo also allows you to reply through the &lt;code&gt;@duck.com&lt;/code&gt; email address you setup for forwarding which is just crazy 😨. One thing I have observed from time-to-time though is that messages sent through the forwarding address can take an unusually long time to reach the recipient. It&amp;rsquo;s not frequent whatsoever but it could happen.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/modern_privacy/meme4.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;/figure&gt;
&lt;p&gt;For the email client, you either have the option of self-hosting a webmail client like &lt;a href="https://roundcube.net/"&gt;RoundCube&lt;/a&gt; (I know that I said I wouldn&amp;rsquo;t talk about self hosting, but in this case it would be remiss of me not to mention it since this is a VERY popular option), or using a desktop client like &lt;a href="https://eppie.io/"&gt;Eppie&lt;/a&gt;. I personally use a terminal-based client that I built myself using Go. If you guys like, I could show you how to build one yourself :)&lt;/p&gt;
&lt;h1 id="conclusion"&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;At the end of the day, privacy is taking a backseat on the internet, especially in the hands of many of the major tech providers. It isn&amp;rsquo;t in our hands to control the decisions that are taken at the very top, but what we can do is take preventative and mitigative steps to ensure that we, as users, stay in control of our data.&lt;/p&gt;
&lt;p&gt;Hope you enjoyed reading this article :)&lt;/p&gt;</content></item><item><title>Bellingcat Open Source Challenge: Back In Time - Walkthrough</title><link>https://blogs.bobbysmiles.xyz/posts/cbc_back_in_time/</link><pubDate>Fri, 09 May 2025 22:23:16 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/cbc_back_in_time/</guid><description>&lt;h1 id="bellingcat---back-in-time-walkthroughs"&gt;Bellingcat - Back In Time walkthroughs&lt;/h1&gt;
&lt;p&gt;Bellingcat recently released their &lt;code&gt;Back In Time&lt;/code&gt; series of challenges authored by &lt;a href="https://gralhix.com/list-of-osint-exercises/"&gt;Sofia Santos&lt;/a&gt;. I had a lot of fun solving these and I hope you did too. Here&amp;rsquo;s a walkthrough of how I tackled each of these challenges.&lt;/p&gt;
&lt;p&gt;Hope you learn through these walkthroughs as much as I did solving these challenges.&lt;/p&gt;
&lt;h2 id="fresh-faced-finding-the-founder"&gt;Fresh Faced: Finding the Founder&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_1-BplhodW_.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So the question tells us that the founder of Bellingcat, Eliot Higgins, was featured on many news outlets for his groundbreaking discoveries in the year 2013. We need to find the YouTube video from which the newspaper clipping was taken.&lt;/p&gt;</description><content>&lt;h1 id="bellingcat---back-in-time-walkthroughs"&gt;Bellingcat - Back In Time walkthroughs&lt;/h1&gt;
&lt;p&gt;Bellingcat recently released their &lt;code&gt;Back In Time&lt;/code&gt; series of challenges authored by &lt;a href="https://gralhix.com/list-of-osint-exercises/"&gt;Sofia Santos&lt;/a&gt;. I had a lot of fun solving these and I hope you did too. Here&amp;rsquo;s a walkthrough of how I tackled each of these challenges.&lt;/p&gt;
&lt;p&gt;Hope you learn through these walkthroughs as much as I did solving these challenges.&lt;/p&gt;
&lt;h2 id="fresh-faced-finding-the-founder"&gt;Fresh Faced: Finding the Founder&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_1-BplhodW_.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So the question tells us that the founder of Bellingcat, Eliot Higgins, was featured on many news outlets for his groundbreaking discoveries in the year 2013. We need to find the YouTube video from which the newspaper clipping was taken.&lt;/p&gt;
&lt;p&gt;The first and most obvious lead we have is the caption in the image. Let&amp;rsquo;s put this into &lt;a href="https://translate.google.com/?sl=auto&amp;amp;tl=en&amp;amp;op=translate"&gt;Google Translate&lt;/a&gt; to see what language it is.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss1.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Google translate for the caption in the image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We can see that the language was detected as &lt;strong&gt;Croatian&lt;/strong&gt;. Now from here, I didn&amp;rsquo;t find any leads, so I looked into the &lt;a href="https://en.wikipedia.org/wiki/Eliot_Higgins"&gt;Wikipedia page on Eliot Higgins&lt;/a&gt;. Reading this page, we can see that Wikipedia mentions some &lt;a href="https://brown-moses.blogspot.com/2013/04/the-brown-moses-blog-fundraiser-launches.html"&gt;non-English sources&lt;/a&gt;. Let&amp;rsquo;s check this page out and see what&amp;rsquo;s in it&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss2.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Non-English sources listed in brown-moses&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Over here, we can see a &lt;a href="https://www.vecernji.hr/vijesti/kako-sam-otkrio-da-hrvati-salju-oruzje-u-siriju-532428"&gt;Croatian news article&lt;/a&gt;, which aligns with our earlier finding of the language on the news clipping. The site didn&amp;rsquo;t contain any sort of link to a YouTube video, just the same picture as we were given in the question.&lt;/p&gt;
&lt;p&gt;So the next thing I did was to check the journalist who interviewed Eliot Higgins. His name was &lt;strong&gt;Tomislav Krasnec&lt;/strong&gt;. So I just searched &lt;code&gt;Tomislav Krasnec Eliot Higgins&lt;/code&gt; in the Google videos section and got the interview.&lt;/p&gt;
&lt;p&gt;The answer is simply the video code.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss3.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Search result for Tomislav Krasnec's interview with Higgins&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;hr&gt;
&lt;h2 id="training-time-theres-a-lot-to-learn"&gt;Training Time: There&amp;rsquo;s a lot to learn.&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_2-BWtvTpYQ.jpeg" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So we&amp;rsquo;re asked to do some cool indoor geolocation on this image. We have to find the room in which this picture was taken. Another hint is that the image is credited to &lt;strong&gt;ARIJ network&lt;/strong&gt;. We are also told that this workshop was conducted in 2017 so that&amp;rsquo;s gonna be a cool lead as well.&lt;/p&gt;
&lt;p&gt;So just googling, &lt;code&gt;Christiaan Triebert Workshop 2017&lt;/code&gt; yielded this &lt;a href="https://x.com/trbrtc/status/928688231549423616"&gt;post&lt;/a&gt; on X.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss4.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Searching for Christiaan Higgins workshop in 2017&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This didn&amp;rsquo;t give much information. So instead I tried using Google Dorks to find the workshop.&lt;/p&gt;
&lt;p&gt;By Google dorking this &lt;code&gt;intext:&amp;quot;December&amp;quot; intext:&amp;quot;2017&amp;quot; intext:&amp;quot;Christiaan Triebert&amp;quot; intext:&amp;quot;workshop&amp;quot;&lt;/code&gt; I found that the event was &lt;em&gt;ARIJ 10th Annual Forum&lt;/em&gt; and in their website we had an address of &lt;strong&gt;Mövenpick Resort &amp;amp; Spa Dead Sea | Dead Sea Road, 11180&lt;/strong&gt;&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss5.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;https://arij10thannualforum2017.sched.com/list/simple&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So from finding this I looked at the rooms available in the hotel in this &lt;a href="https://movenpick.accor.com/en/middle-east/jordan/dead-sea/resort-dead-sea/meeting-rooms.html"&gt;part&lt;/a&gt; of their website. Through that I found the answer to be &lt;code&gt;The Grand Ball room&lt;/code&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="creating-community-a-new-place-to-connect"&gt;Creating Community: A new place to connect.&lt;/h2&gt;
&lt;figure class="center" &gt;
&lt;img src="https://challenge.bellingcat.com/assets/Sofia_Santos_3-B0DbysB3.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Problem Image&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Ok, so here we will have to do a &lt;em&gt;&lt;strong&gt;little&lt;/strong&gt;&lt;/em&gt; bit of scripting, nothing too complicated, just some copying and pasting.&lt;/p&gt;
&lt;p&gt;By just using this Google dork &lt;code&gt;intext:'We finally got around to creating a bellingcat Discord server&amp;quot;&lt;/code&gt; we can find the &lt;a href="https://x.com/bellingcat/status/1260211332437213184?lang=en"&gt;post&lt;/a&gt; on X. get this time: &lt;code&gt;7:42 PM · May 12, 2020&lt;/code&gt;. Note that this time will be displayed differently based on what timezone you fall under.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss6.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Twitter post containing the bellingcat server announcement&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;So once I found the post, I joined the Discord and used this &lt;a href="https://www.reddit.com/r/discordapp/comments/5wl8ny/how_to_find_the_age_of_your_server/"&gt;method&lt;/a&gt; to get the age of the server.&lt;/p&gt;
&lt;p&gt;So, this method has the following steps:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enable developer mode on your Discord.&lt;/li&gt;
&lt;li&gt;Open Discord in your browser and open the Inspector tab on your browser.&lt;/li&gt;
&lt;li&gt;Paste the following code snippet in your browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;new&lt;/span&gt; Date(&lt;span style="color:#e6db74"&gt;&amp;#34;709752884257882135&amp;#34;&lt;/span&gt;&lt;span style="color:#f92672"&gt;/&lt;/span&gt;&lt;span style="color:#ae81ff"&gt;4194304&lt;/span&gt;) &lt;span style="color:#f92672"&gt;+&lt;/span&gt; &lt;span style="color:#ae81ff"&gt;1420070400000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss7.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the js code&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This gives us this timestamp: &lt;code&gt;Tue May 13 1975 18:34:34 GMT+0530 (India Standard Time)1420070400000&lt;/code&gt;
Now, this will be different according to your timezone, but on doing the math we get the time to be 68.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="future-plans-a-timely-document"&gt;Future Plans: A timely document.&lt;/h2&gt;
&lt;p&gt;So we&amp;rsquo;re told that Bellingcat published a document nearly 2 years after they registered.&lt;/p&gt;
&lt;p&gt;So I found the pdf by using this Google Dork: &lt;code&gt;intext:&amp;quot;bellingcat&amp;quot; intext:&amp;quot;future plans&amp;quot;&lt;/code&gt;. Since bellingcat was registered in 2018, it tracks that this &lt;a href="https://www.bellingcat.com/app/uploads/2020/06/Bellingcat-Policy-Plan-2019-2021.pdf"&gt;result&lt;/a&gt; was the right one.&lt;/p&gt;
&lt;p&gt;Now there is no author explicitly listed in the pdf, neither do I wanna read the whole pdf. So, I decided to take a look at the &lt;a href="https://www.pdfyeah.com/view-pdf-metadata/"&gt;pdf metadata&lt;/a&gt;, which revealed that the author was &lt;strong&gt;Aric Toler&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Great, so we have one part of the challenge solved. Now let&amp;rsquo;s see if we can get all the articles he published around 2019-2020.&lt;/p&gt;
&lt;p&gt;So on searching &lt;code&gt;bellingcat.com aric toler&lt;/code&gt; I found this &lt;a href="https://www.bellingcat.com/author/arictoler/"&gt;link&lt;/a&gt;. I scoured every article until I got &lt;a href="https://www.bellingcat.com/resources/how-tos/2020/04/15/how-not-to-report-on-russian-disinformation/"&gt;this one&lt;/a&gt;. The last word of this article is the answer.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="toolkit-tracing-tool-tips-new-and-old"&gt;Toolkit Tracing: Tool tips new and old.&lt;/h2&gt;
&lt;p&gt;This was the easiest question of this release. We are asked to find a missing document in an older edition of the Bellingcat Online Investigations toolkit released in the year 2020.&lt;/p&gt;
&lt;p&gt;I used this Google dork to search it up: &lt;code&gt;intext:&amp;quot;Guides &amp;amp; Handbooks&amp;quot; intext:&amp;quot;2020&amp;quot; intext:&amp;quot;Bellingcat&amp;quot;&lt;/code&gt;&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss8.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the Google dork&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;You can find the actual document mentioned in the question &lt;a href="https://p.avmedianow.com/b/e/bellingcat-s-online-investigation-toolkit-242.pdf"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this document, in the &lt;code&gt;Guides &amp;amp; Handbooks&lt;/code&gt; section, you can find this &lt;a href="https://docs.unocha.org/sites/dms/Documents/FEAT_Version_1.1.pdf"&gt;document&lt;/a&gt;. As it turns out, it is inaccessible. So the obvious first step was to simply check for a snapshot of this document in the &lt;a href="https://web.archive.org/"&gt;WayBack Machine&lt;/a&gt;.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://ik.imagekit.io/LazyCSE/back_in_time_cbc/cbc_back_in_time/ss9.png" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Result of the wayback machine search&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Once I got to the wayback machine, I simply entered the URL and voila! there it was. So we&amp;rsquo;ll simply navigate to page 39 of the document and get the first hazard listed.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Hope you found this as useful as I did.&lt;/p&gt;
&lt;p&gt;Have a nice day! :)&lt;/p&gt;</content></item><item><title>The Rising use of AI in Cybersecurity</title><link>https://blogs.bobbysmiles.xyz/posts/ai_bugbounty/</link><pubDate>Thu, 08 May 2025 16:31:48 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/ai_bugbounty/</guid><description>&lt;h1 id="ai-in-cybersecurity"&gt;AI in Cybersecurity&lt;/h1&gt;
&lt;p&gt;Ever since the ChatGPT was released on the 30th of November 2022, it was inevitable that AI would become a crucial part of our lives. Nowadays (even though its been only 3 years since it came out), we see AI used everywhere. We write code with AI, generate images and videos with AI, summarize our meetings with AI, and with the recent introduction of tools like &lt;code&gt;Ghidra MCP&lt;/code&gt;, we are seeing its increased use in Cybersecurity. But is this entirely as evil as the recent situation on HackerOne makes it out to be? I wouldn&amp;rsquo;t be too quick to judge.&lt;/p&gt;</description><content>&lt;h1 id="ai-in-cybersecurity"&gt;AI in Cybersecurity&lt;/h1&gt;
&lt;p&gt;Ever since the ChatGPT was released on the 30th of November 2022, it was inevitable that AI would become a crucial part of our lives. Nowadays (even though its been only 3 years since it came out), we see AI used everywhere. We write code with AI, generate images and videos with AI, summarize our meetings with AI, and with the recent introduction of tools like &lt;code&gt;Ghidra MCP&lt;/code&gt;, we are seeing its increased use in Cybersecurity. But is this entirely as evil as the recent situation on HackerOne makes it out to be? I wouldn&amp;rsquo;t be too quick to judge.&lt;/p&gt;
&lt;h1 id="the-hackerone-bug-report"&gt;The HackerOne Bug Report&lt;/h1&gt;
&lt;p&gt;Before I continue, I recommend checking out the actual bug report &lt;a href="https://hackerone.com/reports/3125832"&gt;here&lt;/a&gt;. To quickly summarize, there is a critical bug in HTTP/3 capabilities of curl, which can be leveraged to corrupt the memory, hence leading to &lt;strong&gt;Remote Code Execution&lt;/strong&gt;, or &lt;strong&gt;RCE&lt;/strong&gt; in short.&lt;/p&gt;
&lt;p&gt;In the initial stages of reading this report, all seems normal and it seems like a standard report for a high severity bug. But reading further, it begins to seem more and more suspicious (to say the least). Firstly the curl staff member mentions that the patch is not applicable here and asks a question, to which the reply looks &lt;em&gt;&lt;strong&gt;SUSPICIOUSLY&lt;/strong&gt;&lt;/em&gt; like it&amp;rsquo;s AI generated markdown. The user provides the steps to &lt;em&gt;&lt;strong&gt;APPLY&lt;/strong&gt;&lt;/em&gt; a patch, without actually providing the patch in question.&lt;/p&gt;
&lt;p&gt;Some more discourse later, one of the other curl staff members drops a banger about this part of the report:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;Analysis shows:
- Return address overwritten
- Stack recursion at ngtcp2_http3_handle_priority_frame
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Staff comments:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;There is no function named like this in current ngtcp2 or nghttp3.
Please clarify what you talk about. Which versions of ngtcp2 and nghttp3
did you find the problem in?
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The function he was talking about, &lt;code&gt;ngtcp2_http3_handle_priority_frame&lt;/code&gt; does not exist. This, reveals the fundamental problem with relying completely on AI to do the heavy lifting on a high-skill job.&lt;/p&gt;
&lt;h1 id="so-whats-the-issue"&gt;So What&amp;rsquo;s the Issue?&lt;/h1&gt;
&lt;p&gt;AI generated reports are nothing new. There have been many reports, made using AI over the years and so far, according to the founder of the curl project, Daniel Stenberg, no valid bugs have been reported by these so-called &lt;code&gt;AI generated slop&lt;/code&gt; reports (read his full linkedin post &lt;a href="https://www.linkedin.com/posts/danielstenberg_hackerone-curl-activity-7324820893862363136-glb1?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAFdg9CQBp_M-Tja0o8oTrYihjhutFcn-XHw"&gt;here&lt;/a&gt;). It is not uncommon to run into situations where the AI hallucinates things that do not exist in order to fulfill the task given to it by a user.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://assets.aboutamazon.com/dims4/default/e73bc85/2147483647/strip/true/crop/4093x2304&amp;#43;7&amp;#43;0/resize/1240x698!/quality/90/?url=https%3A%2F%2Famazon-blogs-brightspot.s3.amazonaws.com%2F36%2F59%2Feba4adcc4f88a972b5639ed1dde0%2Fadobestock-712831308.jpeg" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;Generic AI concept art I randomly found online&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This is a worrying trend as in the recent years, the number of these reports have only been increasing. The problem is that the people behind triaging and validating a submission are human, and, it takes time. Triaging a submission is no simple task and people put a lot of time into this. Simply spamming AI-generated reports on these platforms only makes this job harder, as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The report cannot be ignored in the off-chance that it reports an actual exploit.&lt;/li&gt;
&lt;li&gt;Producing these kinds of reports takes very little time and the staff will not be able to keep up with the speed of incoming reports, resulting in lesser security.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The curl founder called it a &lt;code&gt;DDoS Attack&lt;/code&gt; against curl due to this. And, he&amp;rsquo;s not wrong.&lt;/p&gt;
&lt;h1 id="what-causes-this-issue"&gt;What Causes this Issue?&lt;/h1&gt;
&lt;p&gt;I think the major problem with all this, is rooted in the fact that many people, beginners and professionals alike, have begun to &lt;strong&gt;SUBSTITUTE&lt;/strong&gt; their workflow with AI, as opposed to &lt;strong&gt;AUGMENTING&lt;/strong&gt; their workflow with AI.&lt;/p&gt;
&lt;p&gt;AI is not 100% accurate, it never has been nor will it ever be, as it stands. AI is trained to give answers that &lt;strong&gt;SEEM&lt;/strong&gt; correct. Obviously, this is not intentional, rather it is a consequence of how the current methods of training these AI models work. At the end of the day, the AI is only doing it&amp;rsquo;s job. It is us, as humans, whose job it is to validate this before making a submission.&lt;/p&gt;
&lt;h1 id="but-is-ai-completely-evil"&gt;But is AI completely Evil?&lt;/h1&gt;
&lt;p&gt;No, absolutely not. I am not going to pretend that I never use AI for my tasks. I do, and I think the benefits to having something like an LLM enhancing your workflow shouldn&amp;rsquo;t be slept on. However, the key distinction is that AI &lt;strong&gt;ENHANCES&lt;/strong&gt; my workflow, it is not my &lt;strong&gt;ENTIRE&lt;/strong&gt; workflow. What I mean is that say, for example, in a project, I won&amp;rsquo;t be &lt;em&gt;vibe coding&lt;/em&gt; that whole project using some random LLM, I would rather be using it to write boilerplate code, find resources online, or as a last resort, suggest fixes to bugs in the code.&lt;/p&gt;
&lt;p&gt;And I feel that a similar approach must be adopted by the wider community at large. I am not saying my approach to this is perfect, not at all, but rather the knowledge of &lt;strong&gt;Enhancement&lt;/strong&gt; vs &lt;strong&gt;Substitution&lt;/strong&gt; must be more widespread.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://i.redd.it/lets-face-it-we-all-thought-auto-had-cared-about-wall-e-v0-bq3furftnb7e1.png?width=1600&amp;amp;format=png&amp;amp;auto=webp&amp;amp;s=710e4cbdf355ff8e96da8e07b1c80db3d9ef691d" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="right" &gt;The classic AI villain, AUTO from WALL-E&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;It is due to this same pitfall, that vibe coding (a term which I &lt;em&gt;absolutely&lt;/em&gt; hate by the way), is gaining more and more traction, when in reality, you can simply learn to code, put in the hours, and write &lt;strong&gt;FAR&lt;/strong&gt; better applications than an AI ever could. Even better, you could double that productivity, by &lt;em&gt;then&lt;/em&gt; finally using AI to enhance your already existing workflow, making this endeavour all the more worth it.&lt;/p&gt;
&lt;h1 id="closing-thoughts"&gt;Closing Thoughts&lt;/h1&gt;
&lt;p&gt;This situation on HackerOne clearly demonstrates the flawed mindset that many people have started to adopt with regards to the usage of AI and a shift in this mindset is necessary if the usage of AI in high-skill fields is to be a net-positive. However, not all of this is bad, and if anything, we should learn from the pitfalls clearly demonstrated by this incident and continue to improve in our respective disciplines.&lt;/p&gt;
&lt;p&gt;Have a nice day! :)&lt;/p&gt;</content></item><item><title>The Recent Resurgence of Linux</title><link>https://blogs.bobbysmiles.xyz/posts/linux_resurgence/</link><pubDate>Sat, 03 May 2025 17:33:45 +0530</pubDate><author>smiles@bobbysmiles.xyz (Bobby Smiles)</author><guid>https://blogs.bobbysmiles.xyz/posts/linux_resurgence/</guid><description>&lt;h1 id="the-os-disillusionment"&gt;The OS Disillusionment&lt;/h1&gt;
&lt;p&gt;A major sentiment among general audiences and tech enthusiasts alike is that popular operating systems like Windows are becoming more and more inaccessible as the days go by. Higher hardware requirements, lack of support for older OS versions and an overall decrease in quality are opening the masses to open source alternatives.&lt;/p&gt;
&lt;p&gt;With the end of support for Windows 10 fast approaching, many older devices will be rendered seemingly useless, and upgradation to a more modern piece of hardware might not be an option. In such cases, open-source comes to the rescue.&lt;/p&gt;</description><content>&lt;h1 id="the-os-disillusionment"&gt;The OS Disillusionment&lt;/h1&gt;
&lt;p&gt;A major sentiment among general audiences and tech enthusiasts alike is that popular operating systems like Windows are becoming more and more inaccessible as the days go by. Higher hardware requirements, lack of support for older OS versions and an overall decrease in quality are opening the masses to open source alternatives.&lt;/p&gt;
&lt;p&gt;With the end of support for Windows 10 fast approaching, many older devices will be rendered seemingly useless, and upgradation to a more modern piece of hardware might not be an option. In such cases, open-source comes to the rescue.&lt;/p&gt;
&lt;h1 id="linux-and-its-benefits"&gt;Linux and its Benefits&lt;/h1&gt;
&lt;p&gt;Linux needs no introduction. Almost all low level hardware runs some form of linux. Servers, wifi routers, smartphones, all are powered by a Linux distribution.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://static1.xdaimages.com/wordpress/wp-content/uploads/wm/2025/04/nintendo-switch-linux-feature-image.jpg" alt=":(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="left" &gt;Nintendo switch running Ubuntu&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Linux comes with many more benefits as well, like being less prone to cyberattacks, being fast and performant, high customizability, and a &lt;strong&gt;HUGE&lt;/strong&gt; and passionate community behind it.&lt;/p&gt;
&lt;p&gt;So where am I going with all this?&lt;/p&gt;
&lt;h1 id="the-recent-resurgence-of-linux"&gt;The Recent Resurgence of Linux&lt;/h1&gt;
&lt;p&gt;Recently I have observed that many big Content Creators are making the switch to Linux &lt;em&gt;&lt;strong&gt;AND&lt;/strong&gt;&lt;/em&gt; encouraging their community to give it a shot. For example, PewDiePie (in this &lt;a href="https://www.youtube.com/watch?v=pVI_smLgTY0&amp;amp;pp=ygUYc3dpdGNoIHRvIGxpbnV4IHBld2llcGll"&gt;video&lt;/a&gt;) recently switched to Linux, detailing his reasons for doing so (please watch the video it&amp;rsquo;s &lt;em&gt;excellent&lt;/em&gt;).&lt;/p&gt;
&lt;p&gt;Even before this video came out, my YouTube feed was already dotted with tech content titled something like &lt;em&gt;&amp;ldquo;I switched to Linux and I could never look at Windows the same again&amp;rdquo;&lt;/em&gt;, all of them detailing similar reasons for switching to Linux.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Customizability&lt;/li&gt;
&lt;li&gt;Performance&lt;/li&gt;
&lt;li&gt;Stability (ok this one&amp;rsquo;s a little debatable)&lt;/li&gt;
&lt;li&gt;Control&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class="center" &gt;
&lt;img src="https://preview.redd.it/gnome-gnome-is-my-place-v0-akydhqbpmkye1.png?width=1080&amp;amp;crop=smart&amp;amp;auto=webp&amp;amp;s=20edd39d33987d89e800bcb0fb5fe1f907ace41b" alt="Oops...." style="border-radius: 8px;" /&gt;
&lt;figcaption class="left" &gt;A fully customized GNOME desktop&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;A Linux nerd myself, seeing &lt;em&gt;regular&lt;/em&gt; people start to give Linux a shot sort of surprised me, considering that many times (coming from personal experience) I was told that Linux is too hard because it&amp;rsquo;s quite terminal centric and that&amp;rsquo;s intimidating for a guy who is not a &lt;em&gt;&amp;ldquo;basement-dwelling&amp;rdquo;&lt;/em&gt; nerd. Little did they know about Linux Mint, Ubuntu or Fedora.&lt;/p&gt;
&lt;hr&gt;
&lt;h3 id="personal-anecdote"&gt;Personal Anecdote&lt;/h3&gt;
&lt;p&gt;Due to the &lt;a href="https://www.youtube.com/watch?v=pVI_smLgTY0&amp;amp;pp=ygUYc3dpdGNoIHRvIGxpbnV4IHBld2llcGll"&gt;video&lt;/a&gt; made by PewDiePie, one of my friends (completely not into tech, has an age-old computer used only for watching movies and TV shows) asked me about switching over to Linux and was surprisingly open even to try Arch Linux. Now, to preserve both their sanity and mine, I told them to switch to something like Linux Mint first, to get a feel for the OS and it&amp;rsquo;s workflow, and to ease into the new ecosystem, and they were surprisingly receptive.&lt;/p&gt;
&lt;p&gt;As it stands, I am yet to hear back from them regarding how the switch went, but considering they seemed pretty satisfied with the computer last we spoke, I suspect it went quite well.&lt;/p&gt;
&lt;hr&gt;
&lt;h1 id="dont-fully-believe-the-hype"&gt;Don&amp;rsquo;t Fully Believe the Hype&lt;/h1&gt;
&lt;p&gt;Now, it might seem &lt;strong&gt;VERY&lt;/strong&gt; appealing to immediately switch to Linux after all the newfound buzz regarding the topic, but I would still ask that one consider this decision carefully. Despite its caveats, almost all software in the world is supported by Windows and Microsoft &lt;em&gt;still&lt;/em&gt; provides some of the best tools in the market.&lt;/p&gt;
&lt;p&gt;The Ms Office suite, boasting some of the best software for tasks like spreadsheets, text editing and presentations, for example, is not natively supported on Linux. It has to be run through a compatibility layer like &lt;em&gt;&lt;strong&gt;wine&lt;/strong&gt;&lt;/em&gt;, which does provide support for &lt;strong&gt;SOME&lt;/strong&gt; Windows applications, not to mention that wine in and of itself can be a little hard to setup.&lt;/p&gt;
&lt;figure class="center" &gt;
&lt;img src="https://garudalinux.org/assets/editions/garuda-mokka.webp" alt="Sorry :(" style="border-radius: 8px;" /&gt;
&lt;figcaption class="left" &gt;GNOME Desktop environment configured in Garuda Linux&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;There is also the issue with stability of certain distributions of Linux like &lt;strong&gt;Arch Linux&lt;/strong&gt;, which follows a rolling-release model. While you can always stay up-to-date with the latest updates and security patches, this can also cause instability in a system, affecting your workflow and productivity. In such cases, I would still recommend that you stick to Windows, or at least try a Linux distro on a VM or live boot before switching completely.&lt;/p&gt;
&lt;h1 id="closing-thoughts"&gt;Closing Thoughts&lt;/h1&gt;
&lt;p&gt;Linux has always been, and continues to be, a viable operating system to switch to—provided you know what you&amp;rsquo;re getting into. It is not like Windows, nor is it meant to be. Both operating systems serve their purpose, and both do it well.&lt;/p&gt;
&lt;p&gt;With Linux, you get speed, control, stability, and customizability. With Windows, you benefit from familiarity, broader software support, and ease of use.&lt;/p&gt;
&lt;p&gt;Whether or not you choose to switch to Linux is entirely up to you—but make sure to do your homework before making a decision.&lt;/p&gt;
&lt;p&gt;Have a nice day! :)&lt;/p&gt;</content></item></channel></rss>