Notes from the night shift.
A security scrapbook — writeups, the tools I build, and the half-formed thoughts I have at 1 a.m. I write things down so I actually understand them.
currently poking at: smart TVs, tunnels, and AI agents.
Latest
newest firsteBPF for the curious: watch a process without touching the kernel
eBPF lets you run small sandboxed programs inside the Linux kernel. It is the closest thing we have to a debugger for the whole machine.
How your smart TV phones home
The television is the one device in your house that watches you back. Here is the mechanism, and how to see it for yourself.
Treat the web like it's lying to you
We spent twenty years teaching developers not to trust user input. Then we built agents that trust every webpage they read.
The screwdriver test
I carry a screwdriver. Not as a bit, as a habit. Here is what it is actually for.
Opt-out is a feature, not a promise
There is a toggle in the menu that says you can turn the tracking off. I keep wanting to know whether the device believes it.
Things I built
small, sharp, open sourceHalf-formed
opinions subject to refactorTreat the web like it's lying to you
We spent twenty years teaching developers not to trust user input. Then we built agents that trust every webpage they read.
The screwdriver test
I carry a screwdriver. Not as a bit, as a habit. Here is what it is actually for.
Opt-out is a feature, not a promise
There is a toggle in the menu that says you can turn the tracking off. I keep wanting to know whether the device believes it.
$ whoami
Namaste — I'm Het. I'm a security researcher who learns by taking things apart, and this blog is where I write down the journey: the writeups, the tools, the dead ends, and the occasional idea worth keeping. Beginner or veteran, you're welcome here. Grab a coffee.