Commit b021de29f4

b021de29f432927a1af200efb4b7a8fa54cdebb6

parent: bfb90af03c

Unsigned

cmc <hello@cleberg.net> · 2025-08-20 03:39 UTC

summary of commits from minimal-enhancements

Layout: unified · split

content/about/index.org added +27
@@ -0,0 +1,27 @@
1#+title: About
2#+slug: index
3
4Hey, I'm */~cmc/*.
5
6I'm a technology audit manager, working on financial statement audits (SOX/MAR),
7SOC 1-3 reports, and other attestations for KPMG.
8
9Read up on my [[https://cv.cleberg.net][CV]] or [[https://cleberg.net/salary/][salary]] for more information.
10
11In my spare time, I like to:
12
13- Run linux servers
14- Enhance my home lab network
15- Write personal programs, mostly in Python
16- Research various topics (history, geography, science, etc.)
17- Write blog posts and general documentation
18- Converse with others on IRC and Matrix
19- Play video games and watch television
20
21If you want to chat, you can find me in the following spaces:
22
23- [[mailto:hello@cleberg.net][hello@cleberg.net]] ([[https://cleberg.net/gpg.txt][GPG]])
24- [[https://lemmy.cleberg.net/u/cmc][@cmc]] on Lemmy
25- [[https://matrix.to/#/@cmc.:matrix.org][@cmc.:matrix.org]] on Matrix
26- @cmc.01 on [[https://signal.org/][Signal]]
27- [[https://sr.ht/~cxc][~cxc]] on Sourcehut
content/blog/2025-06-02-private-ios-apps.org +111 −127
@@ -4,16 +4,14 @@
44#+slug: private-ios-apps
55#+filetags: :ios:privacy:security:
66
7In a world where our phones are extensions of ourselves, balancing convenience
8with privacy can feel like a losing battle — especially on iOS, where platform
9restrictions narrow the options. But it's not impossible. There's a growing
10ecosystem of privacy-respecting apps, tools, and communities focused on helping
11iPhone users take back some control.
7The world is evolving into a privacy nightmare, where our own devices are being
8used by numerous parties to constantly track and report on our activities. This
9is especially prevalent on iOS, where platform restrictions leave users without
10many options to lock down their data.
1211
13Below is a curated list of privacy resources, directories, and testing tools
14specifically useful for iOS. Whether you're looking for a better email client, a
15trustworthy VPN, or simply places to learn more, these links are a solid
16starting point.
12However, there are apps that exist that can help enhance the privacy of an iOS
13device. The post below details a number of privacy resources, directories, and
14tools for iOS.
1715
1816**Resource Table**
1917
@@ -36,38 +34,28 @@ starting point.
3634
3735#+begin_quote
3836*Note*: This list focuses solely on iOS-compatible resources and tools. No
39Android comparisons here — just options for those of us living in Apple's walled
40garden.
37Android comparisons here as I have not used Android in many years.
4138#+end_quote
4239
4340* Email
4441
45First and foremost, I like to consider email as my first app on a new device.
46However, the iOS market lacks a wealth of open-source and private email clients.
47There are a few options, such as Proton Mail and Tuta, which are open source and
48private, but they lock you into their ecosystem. Tuta doesn't allow for custom
49domains and neither allows SMTP/IMAP access.
50
51Canary Mail is a decent option, as it is a classic SMTP/IMAP client - and does
52more than most as it's one of the only PGP email clients on iOS - but is closed
53source and the company behind it seems more focused on AI than privacy.
54
55- [[https://proton.me/mail][Proton Mail]] - A more mainstream-feeling app with PGP support built-in. Good if
56 you're looking for something that feels like Apple Mail but with privacy
57 upgrades.
58- [[https://tuta.com/][Tuta]] - Tuta (formerly Tutanota) takes privacy a step further by encrypting
59 subject lines, message content, attachments, and calendar events. It also
60 avoids using phone numbers or third-party services for registration. The iOS
61 app is reliable for the basics. Downsides: no IMAP/SMTP support, so you can't
62 plug it into your own mail clients, and notifications require a premium plan
63 if you want them in real-time. Great if you care about metadata exposure.
64- [[https://canarymail.io/][Canary Mail]] - A more polished, user-friendly email client that supports
65 end-to-end encryption using PGP and their own “SecureSend” feature for
66 encrypted messages. Canary works with multiple mail providers (Gmail, Outlook,
67 etc.), so it's more of a privacy enhancement for existing services rather than
68 a private mail provider itself. Downsides: it's a proprietary, closed-source
69 app, and some privacy features require a subscription. Better than stock Mail
70 for security, but you're still trusting their implementation.
42First, I like to consider email as my first app on a new device. However, iOS is
43\extremely\ lacking in this area. Certain options are private, such as Proton
44Mail and Tuta, but they have certain restrictions and ecosystem lock-in methods
45that I try to avoid.
46
47Canary Mail was a decent option for a while, although a bit mysterious, but they
48have recently leaned into the AI hype pretty heavily, which is concerning.
49However, it's still one of the only options for PGP emails on iOS.
50
51- [[https://proton.me/mail][Proton Mail]] - One of the more popular private email options available on iOS.
52 Allows custom domains, but does not allow for IMAP/SMTP usage, so you're
53 locked into using their apps. Open source.
54- [[https://tuta.com/][Tuta]] - Tuta also locks you into their clients and they do not allow you to use
55 custom domains. Open source.
56- [[https://canarymail.io/][Canary Mail]] - Closed source, so you can't verify anything about what they are
57 building into the app. However, it's one of the only options for PGP mail on
58 iOS. Advanced features are locked behind a paywall.
7159
7260Another suggestion is to use a browser-based web client. You can install browser
7361mail clients as progressive web apps (PWAs). For example, I have been using
@@ -91,35 +79,29 @@ releases for iOS, I will probably use that.
9179
9280* Browsers
9381
94Your browser is basically the front door to the internet — and also the window,
95mailbox, and security camera. It's where trackers, ads, fingerprinting scripts,
96and data leaks happen most often. Even on a locked-down phone, if your browser
97isn't protecting your traffic, your personal info can quietly leak out through
98third-party scripts, embedded media, and background connections. Choosing a
99privacy-respecting browser is one of the most impactful decisions you can make
100for mobile privacy.
101
102- [[https://apps.apple.com/us/app/firefox-focus-privacy-browser/id1055677337][Firefox Focus]] - A stripped-down, no-nonsense browser from Mozilla. It
103 automatically blocks trackers, erases your browsing history with a tap, and
104 skips extras like tabs or bookmarks. Great for one-off searches and quick
105 visits to privacy-sensitive sites.
106- [[https://duckduckgo.com/app][DuckDuckGo]] - A full-featured private browser with built-in tracker blocking,
107 HTTPS upgrades, and a clear data button. It also integrates DuckDuckGo search
108 and email protection. Solid for daily use if you don't want your browsing
109 activity tied to a bigger tech company.
110- [[https://onionbrowser.com/][Onion Browser]] & [[https://orbot.app/][Orbot]] - Your best bet for anonymous browsing on iOS. Onion
111 Browser routes traffic over Tor, while Orbot can proxy other apps system-wide
112 through Tor. Slower than normal browsers, but excellent for masking your IP
113 and avoiding surveillance.
114- [[https://brave.com/][Brave]] - Privacy-focused with ad and tracker blocking built-in, Brave also runs
115 its own private search engine and supports things like Tor tabs (on desktop,
116 not iOS). On iOS, it's basically a privacy-enhanced Safari/WebKit shell —
117 better than nothing, but subject to Apple's browser engine limits.
118- [[https://www.apple.com/safari/][Safari]] (with caveats) - Surprisingly decent for privacy if you tweak the
119 settings. Enable “Prevent Cross-Site Tracking,” block all cookies, and disable
120 preload for best results. Still, it's tied to your Apple ID and iCloud syncing
121 unless you're careful, so don't treat it as anonymous. For a great baseline
122 configuration, read PrivacyGuide's [[https://www.privacyguides.org/en/mobile-browsers/#safari-ios][Safari]] section.
82Your choise of browser is very important if you're concerned with privacy. Any
83and all links you click will be opened in your default browser, so you need to
84make sure you choose the right browser and configure it properly. Trackers, ads,
85fingerprints, and data leaks are constant threats that should be avoided when
86possible.
87
88- [[https://apps.apple.com/us/app/firefox-focus-privacy-browser/id1055677337][Firefox Focus]] - In my opinion, the best option for privacy on iOS.
89 Automatically blocks trackers, erases data and history upon app close, and
90 focused on private usage. However, it won't support your bookmarks or keep you
91 logged into sites long-term.
92- [[https://duckduckgo.com/app][DuckDuckGo]] - Another good option, built on chromium. Like Focus, it allows you
93 to clear all data with a button tap.
94- [[https://onionbrowser.com/][Onion Browser]] & [[https://orbot.app/][Orbot]] - Tor - what can I say? It's been the most popular
95 privacy browser for ages for a reason and now it's available on iOS. Onion
96 Browser is a Tor browser and Orbot can proxy any number of iOS apps through
97 Tor. As with all Tor traffic, it will be slower than "regular" traffic.
98- [[https://brave.com/][Brave]] - Another chromium-based privacy browser. Can sync with other Brave
99 browsers via a secure linking process (no account). Fully-featured and great
100 privacy defaults. There have been some concerns in the past about the company
101 behind Brave, but I still think it's a decent option for most peoplel.
102- [[https://www.apple.com/safari/][Safari]] (with caveats) - Great option if the browsers above don't work for you.
103 Be sure to read PrivacyGuide's [[https://www.privacyguides.org/en/mobile-browsers/#safari-ios][Safari]] section for more information on what you
104 need to do to lock it down before relying on it full time.
123105
124106#+begin_quote
125107*I use*: Hardened safari in private mode for every day use, and Onion Browser
@@ -128,30 +110,26 @@ for anonymous browsing.
128110
129111* Messaging
130112
131If you're trying to keep conversations off surveillance infrastructure, choosing
132the right messaging app is crucial. Between metadata collection, insecure cloud
133backups, and shady server practices, most mainstream chat apps aren't
134privacy-friendly by design. On iOS, you're a little more limited than on
135Android, but there are still solid options built around end-to-end encryption
136and metadata minimization.
137
138- [[https://signal.org/][Signal]] - The gold standard for secure messaging. Open source, end-to-end
139 encrypted, and runs its own private push notification infrastructure so Apple
140 can't read your message content. Downsides: phone number required for signup
141 (a known metadata weak point).
113Next up are messaging apps. If you have an iPhone, it's a good bet that you will
114be messaging other people on it. The threats for messaging apps tend to be
115metadata/data collection from cellular providers, ISPs, and Apple itself. If you
116want to protect the privacy of your messages, who your messaging, and the
117metadata around those messages (time, method, location, etc.), you'll need to
118think about which apps you're using.
119
120- [[https://signal.org/][Signal]] - My personal favorite and still the gold standard for secure and
121 private messaging. Open source, end-to-end encrypted, and runs its own private
122 push notification infrastructure so Apple can't read your message content. A
123 phone number is required to sign up, but you can create a username immediately
124 after signing up and share that with others instead of sharing your phone
125 number.
142126- [[https://simplex.chat/][SimpleX]] - A decentralized, phone-number-free messaging system. Uses anonymous
143 message relays and asymmetric keys. Great for pseudonymous chats or if you're
144 tired of number-based identity systems.
127 message relays and asymmetric keys.
145128- [[https://getsession.org/][Session]] - A fork of Signal's protocol that eliminates phone numbers entirely.
146 Routes messages through a decentralized onion network (like Tor). Excellent
147 for metadata resistance, though message delivery can sometimes lag.
129 Routes messages through a decentralized onion network (like Tor).
148130- [[https://element.io/][Element]] - Based on the Matrix protocol, offering decentralized, federated
149 chat. Great for groups and communities, with optional end-to-end encryption. A
150 little heavier on resources than the others.
151
152Privacy-friendly messaging isn't perfect on iOS — background sync restrictions
153and notification relay challenges exist — but these tools will cover most needs
154while keeping your data away from corporate servers.
131 chat. Great for groups and communities, with optional end-to-end encryption.
132 Other client options are available for Matrix on iOS, as well.
155133
156134#+begin_quote
157135*I use*: Signal for private chats with known people, and Matrix for group chats.
@@ -160,8 +138,8 @@ while keeping your data away from corporate servers.
160138* VPNs & Networking
161139
162140Network traffic is where most surveillance happens. Even with encrypted
163messaging and browsers, your IP address and DNS queries reveal a lot. A good VPN
164or alternative network routing tool masks this, but not all VPNs are
141messaging and browsers, your IP address and DNS queries reveal a lot about you.
142A good VPN or alternative network routing tool masks this, but not all VPNs are
165143trustworthy. Avoid “free” services or those lacking transparency.
166144
167145- [[https://mullvad.net/][Mullvad]] - A no-logs VPN that doesn't require an email or personal info to
@@ -174,10 +152,10 @@ trustworthy. Avoid “free” services or those lacking transparency.
174152 polished for mobile but useful for hobbyists or building private networks
175153 between devices.
176154
177If you can't self-host or build your own mesh, Mullvad is hands-down the
178cleanest option here. There are other VPN options available, but I haven't
179tested them all so I will simply put my vote for Mullvad here and let you
180research other options if you don't want to use Mullvad.
155If you can't self-host or build your own mesh, Mullvad is hands-down the easiest
156option here. There are other VPN options available, but I haven't tested them
157all so I will simply put my vote for Mullvad here and let you research other
158options if you don't want to use Mullvad.
181159
182160#+begin_quote
183161*I use*: Mullvad for 24/7 usage, and Tor when anonymity is required.
@@ -185,12 +163,12 @@ research other options if you don't want to use Mullvad.
185163
186164* Password Management
187165
188Weak, reused passwords are still one of the biggest risks for personal security.
189A good password manager makes it possible to use strong, unique credentials
166Weak and reused passwords are still the biggest risks for personal security. A
167good password manager makes it possible to use strong, unique credentials
190168without memorizing them all.
191169
192- [[https://bitwarden.com/][Bitwarden]] - Open source, audited, and free to self-host. The iOS app
193 integrates with system autofill and Face ID. Solid for most users.
170- [[https://bitwarden.com/][Bitwarden]] - Open source, audited, and free to self-host (e.g., Vaultwarden).
171 The iOS app integrates with system autofill and Face ID.
194172- [[https://keepassium.com/][KeePassium]] - A KeePass-compatible client for iOS. Local database storage,
195173 optional cloud sync, and no external accounts. Excellent if you want full
196174 control over your credential store.
@@ -198,8 +176,8 @@ without memorizing them all.
198176 your database with a secure method like [[https://cryptomator.org/][Cryptomator]]-protected cloud storage,
199177 Syncthing, or local-only transfers.
200178
201Good password hygiene matters more than people realize, and these apps give you
202control over your vault.
179Good passwords matter are extremely important, and these apps give you control
180over your vault.
203181
204182#+begin_quote
205183*I use*: Bitwarden Families ($40/year) to protect passwords, passkeys, TOTP
@@ -210,17 +188,20 @@ myself, I would prefer KeePassXC + Syncthing.
210188* Multi-Factor Authentication (MFA)
211189
212190MFA is essential, but relying on SMS codes or untrusted proprietary apps defeats
213the point. Use open, local, encrypted authenticators where possible.
191the point. Use open, local, encrypted authenticators where possible. Also, use
192passkeys if you can! I prefer passkeys, then TOTP, and then SMS/email, if other
193options are not possible.
214194
215- [[https://bitwarden.com/products/authenticator/][Bitwarden Authenticator]] - Integrates with the password manager or works
216 standalone. Encrypted backups through Bitwarden.
195- [[https://bitwarden.com/products/authenticator/][Bitwarden Authenticator]] - Integrates with the password manager or works as a
196 standalone TOTP app. Optional encrypted backups through your Bitwarden
197 account.
217198- [[https://ente.io/auth/][Ente Auth]] - Open source, end-to-end encrypted TOTP manager. Syncs encrypted
218199 via Ente's infrastructure.
219200- [[https://www.tofuauth.com/][Tofu]] - Minimal, offline-first TOTP app. No cloud, no telemetry.
220201- [[https://raivo-otp.com/][Raivo OTP]] - Open source, native iOS app with secure iCloud backups. Clean
221202 interface.
222203- [[https://apps.apple.com/us/app/otp-auth/id659877384][OTP Auth]] - A longstanding, trusted TOTP manager with encrypted backups and
223 Apple Watch support. Not open source.
204 Apple Watch support. *Not open source.*
224205
225206I recommend pairing one of these with strong passwords and a VPN for everyday
226207security.
@@ -231,9 +212,8 @@ security.
231212
232213* Notes & Personal Data
233214
234iCloud Notes and Google Keep aren't exactly privacy havens. If you're storing
235sensitive personal notes, account details, or journal entries, opt for
236encrypted, local-first apps.
215If you're storing sensitive personal notes, account details, or journal entries,
216opt for encrypted, local-first apps.
237217
238218- [[https://beorgapp.com/][Beorg]] - An Org-mode-compatible outliner and task manager for iOS. Great for
239219 Emacs fans and those managing plaintext files.
@@ -248,15 +228,15 @@ These options help decouple your data from major cloud platforms while keeping
248228notes portable and encrypted.
249229
250230#+begin_quote
251*I use*: Beorg, since I love org-mode and no longer use markdown.
231*I use*: Beorg, since I love org-mode.
252232#+end_quote
253233
254234* Photos & Media
255235
256Your camera roll quietly feeds metadata and images to iCloud by default. If you
257want to self-host or encrypt your photo library, here's what works on iOS. At a
258minimum, I suggest disabling iCloud for the Photos app, so the data stays local
259on your device.
236If you're using iCloud Photos, your camera roll quietly feeds metadata and
237images to iCloud by default. If you want to self-host or encrypt your photo
238library, here's what works on iOS. At a minimum, I suggest disabling iCloud for
239the Photos app, so the data stays local on your device.
260240
261241- [[https://immich.app/][Immich (self-hosted)]] - Open source, feature-rich, self-hosted photo manager
262242 with facial recognition and live photo support. Requires a home server.
@@ -290,14 +270,12 @@ require Instant PGP since Migadu's webmail client (SnappyMail) supports PGP.
290270
291271* News & Social
292272
293Mainstream news and social apps leak all kinds of usage metadata, even when
294you're just lurking. These tools let you follow content with less exposure.
273News and social apps leak all kinds of usage metadata, even when you're just
274lurking. These tools let you follow content with less exposure.
295275
296- [[https://netnewswire.com/][NetNewsWire]] - Free, open source RSS reader for iOS. Follow sites without
297 tracking.
298- [[https://www.talklittle.com/three-cheers/][ThreeCheers]] - Privacy-friendly Reddit client for iOS. No official API calls,
299 built-in filtering.
300- [[https://getvoyager.app/][Voyager]] - Clean, independent Mastodon client.
276- [[https://netnewswire.com/][NetNewsWire]] - Free, open source RSS reader for iOS.
277- [[https://www.talklittle.com/three-cheers/][ThreeCheers]] - Privacy-friendly Tildes client for iOS.
278- [[https://getvoyager.app/][Voyager]] - Clean, independent Lemmy client.
301279- [[https://joinmastodon.org/][Mastodon]] - Federated, open source alternative to Twitter.
302280- [[https://joinpeertube.org/][PeerTube]] - Decentralized video platform, accessible via web or PWA.
303281- [[https://pixelfed.org/][Pixelfed]] - Federated, open source alternative to Instagram.
@@ -305,17 +283,23 @@ you're just lurking. These tools let you follow content with less exposure.
305283If you're going to be online, at least let it be on your terms.
306284
307285#+begin_quote
308*I use*: NetNewsWire (via FreshRSS) for RSS feeds, and Voyager for Lemmy. I have
309used all of these apps and they are great, but I am not very active on social
310sites.
286*I use*: NetNewsWire (via FreshRSS) for RSS feeds, Voyager for Lemmy, and Three
287 Cheers for Tildes. I have used all of these apps and they are great, but I am
288 not very active on social sites.
311289#+end_quote
312290
313291* Final Thoughts
314292
315This isn't about paranoia — it's about awareness. Every app you use, every
316service you sign into, quietly collects and trades your data. iOS makes true
317anonymity harder than other platforms, but these tools and services give you a
318fighting chance to keep your personal life personal.
293Whether you just want to improve your privacy in small steps or you're
294fashioning a tinfoil hat as we speak, moving to privacy-focused services and
295apps does two things:
296
2971. It protects your privacy by ensuring that your data is being protected
298 through the many methods mentioned above; and
2992. It provides money (for paid apps), support (in terms of download count,
300 reviews, ratings, etc.), and motivation for the developers and companies
301 behind these apps that provide a privacy haven for users on iOS.
319302
320If you have other privacy-friendly iOS tools you enjoy, [[mailto:hello@cleberg.net][email me]] — I'm always
321looking for new things to test.
303Every app you use, every service you sign into, quietly collects and trades your
304data. iOS makes true anonymity harder than other platforms, but these tools and
305services give you a fighting chance to keep your data private.
content/blog/2025-06-27-how-blockchain-works.org deleted −197
@@ -1,197 +0,0 @@
1#+date: <2025-07-07 Mon 00:00:00>
2#+title: Blockchain Series #1: How Blockchain Works Under the Hood: Hashes, Keys, and Signatures Explained
3#+description: Dive into blockchain's cryptographic foundations. Explore how hash functions, Merkle trees, and digital signatures secure distributed, tamper-resistant ledgers.
4#+slug: how-blockchain-works
5#+filetags: :blockchain:encryption:
6#+draft: t
7
8/This is Part 1 of a series I'm writing on blockchain. Stay tuned for further
9editions./
10
11Blockchain is one of those technologies that seems to generate more marketing
12buzz than real understanding. Everywhere you look, people talk about
13decentralization, trustless systems, and the next big disruption. But beneath
14the hype, blockchain systems rely on well-understood cryptographic building
15blocks to do something very specific: maintain a secure, tamper-resistant ledger
16without needing a central authority.
17
18If you're serious about understanding blockchain, it's critical to understand
19the cryptographic primitives that make it work. Hash functions, digital
20signatures, and public-key cryptography aren't just jargon—they're the core
21mechanisms that let a distributed network agree on a shared history no one can
22easily rewrite.
23
24This post is Part 1 of a multi-part series on blockchain. Here, we'll focus on
25these fundamental building blocks—how they work, why they're used, and how they
26fit together to provide the security and trust that blockchain promises.
27
28* What is Blockchain?
29
30At its core, a blockchain is a distributed, append-only ledger shared among
31participants in a network.
32
33What does this mean? Essentially, we can think of a standard, non-technical
34ledger (book of accounts where transactions are recorded against accounts). When
35introductin the idea of a blockchain, let's extend the idea of a standard ledger
36and make a few connections:
37
38- Each block of transactions is connected cryptographically to the block before
39 it, via a [[https://en.wikipedia.org/wiki/Cryptographic_hash_function][cryptographic hash]]. This is what forms a =chain= of blocks, or
40 records.
41- Each block consists of:
42 - A list of validated transactions
43 - A timestamp
44 - A cryptographic hash of the previous block (ensuring immutability)
45- Each transaction within a block is initiated between addresses, signed with
46 cryptographic keys, and sent to the blockchain for validation (e.g.,
47 proof-of-work, proof-of-staking, etc.).
48- The blockchain is shared amongst nodes in the network, who agree on the state
49 of the blockchain through consensus mechanisms.
50
51As we can see, the decentralized nature and cryptographic linking of
52transactions and blocks ensures that modifying the history is infeasible.
53
54If you're more of a visual person, here's a very basic diagram of a standard
55blockchain structure.
56
57#+begin_example
58+------------+ +------------+ +------------+
59| Block 1 | -> | Block 2 | -> | Block 3 |
60|------------| |------------| |------------|
61| Data | | Data | | Data |
62| Prev Hash: | | Prev Hash: | | Prev Hash: |
63| 00000000 | | <hash1> | | <hash2> |
64| Hash: | | Hash: | | Hash: |
65| <hash1> | | <hash2> | | <hash3> |
66+------------+ +------------+ +------------+
67#+end_example
68
69* What Problems is Blockchain Trying to Solve?
70
71I will be diving into the technical details of blockchains later in this post,
72but what exactly is the reason blockchain exists?
73
74You may know of cryptocurrencies, such as Bitcoin, but that is only one of many
75use cases for blockchains.
76
77As we learned in the section above, a blockchain can be equated to a ledger.
78With this in mind, let's dive into a few interesting use cases:
79
80** Immutable record-keeping
81
82If you simply need a ledger that cannot be modified easily and can establish a
83decentralized network to support that, blockchain is a great technology.
84
85** Trust without central authority
86
87The use of a decentralized system means that we do not need to rely on a
88centralized authority (e.g., Social Security, a bank, etc.) to store and provide
89access to information you need to record.
90
91Think of the US Social Security Number (SSN) system. Each time you want to
92perform actions that require verifying your identify (e.g., opening bank
93accounts, investment accounts, child birth, etc.), you are currently required to
94provide your SSN.
95
96However, this is a singular number - which means that if someone learns it, they
97can (essentially) now act as you.
98
99Now imagine a scenario where the SSN system is a blockchain where you have both
100your private key for providing evidence to people that you are you. For example,
101you open a bank account and sign your form with your private key. Now, the bank
102can take that and use your public key to decrypt the message and verify that you
103are you, without needing to know your private key.
104
105Another scenario is that, during a background check, a company could use your
106public key and consult the related blockchain to validate specific pieces of
107information. For example, if your identity alone is in one block, you could
108provide that information to your employer without providing your full SSN and
109all related personal information for as long as they keep your SSN on file.
110
111** Double-spending problem
112
113With the introduction of digital assets, such as cryptocurrencies and
114non-fungible tokens, a new risk is introduced: without control, these assets
115could be copied and reused at-will.
116
117To solve this problem, digital assets are transacted on a blockchain to ensure
118that the decentralized system of nodes provide consensus on validating
119transactions, transactions are recorded in a transparent and tamper-resistant
120manner, and cryptographic functions are performed to order the transactions
121logically on chain.
122
123* The Role of Cryptography in Blockchain
124- Why cryptography matters
125- Confidentiality vs. integrity/authenticity
126- Core goals:
127 - Tamper-evidence
128 - Secure identification
129 - Non-repudiation
130
131* Hash Functions
132- What is a cryptographic hash?
133- Properties:
134 - Collision resistance
135 - Pre-image resistance
136- How blockchain uses hashes:
137 - Chaining blocks together
138 - Block headers
139 - Transactions
140- Example command:
141 #+begin_src bash
142 echo -n "Hello, Blockchain" | sha256sum
143 #+end_src
144- Optional diagram: chain of blocks with hashes
145
146* Merkle Trees
147- Summarizing many transactions in a single root hash
148- Use case: efficient inclusion proofs
149- Example diagram (ASCII art if desired)
150- Why Merkle roots are in block headers
151
152* Public Key Cryptography
153- Quick refresher
154- Public/private keypairs
155- Addresses derived from public keys
156- Importance of keeping private keys secret
157
158* Digital Signatures
159- Purpose: proving authorship without revealing private key
160- Mention ECDSA / EdDSA
161- How transactions are signed
162- Example snippet:
163 #+begin_example
164 Alice signs transaction with her private key
165 → Anyone can verify with her public key
166 #+end_example
167- Why signatures prevent forgery
168
169* Bringing it All Together: Blockchain Data Structures
170- Block structure:
171 - Block header with previous block's hash
172 - Merkle root
173 - Timestamp, nonce
174- How the chain ensures immutability
175- Example flow:
176 1. User creates a transaction
177 2. Signs it
178 3. Transaction included in block
179 4. Block hash links to previous block
180
181* Proof of Work (Optional)
182- Hash puzzles to add blocks
183- Why it's hard to modify history
184- Keep this section simple
185
186* Conclusion
187- Summarize how these primitives work together
188- Tease next post: "Next, we'll explore security threats and how blockchain
189 networks mitigate them."
190- Optional links to further reading:
191 - Bitcoin whitepaper
192 - Ethereum docs
193 - Cryptography references
194
195* Optional Extras
196- Glossary box with terms (hash, signature, Merkle tree)
197- External references (e.g., NIST docs on hashes)
publish.el +9
@@ -93,6 +93,15 @@
9393 :output ".build/now/{{ slug }}.html"
9494 :url "/now/{{ slug }}.html")
9595
96;; About page route
97(weblorg-route
98 :name "about"
99 :input-pattern "content/about/*.org"
100 :template "page.html"
101 :output ".build/about/{{ slug }}.html"
102 :url "/about/{{ slug }}.html")
103
104
96105;; RSS feed route
97106(weblorg-route
98107 :name "rss"
theme/static/styles.css +12 −341
@@ -1,318 +1,5 @@
11/*! normalize.css v8.0.1 | MIT License | github.com/necolas/normalize.css */
2
3/* Document
4 ========================================================================== */
5
6/**
7 * 1. Correct the line height in all browsers.
8 * 2. Prevent adjustments of font size after orientation changes in iOS.
9 */
10
11html {
12 line-height: 1.15;
13 /* 1 */
14 -webkit-text-size-adjust: 100%;
15 /* 2 */
16}
17
18/* Sections
19 ========================================================================== */
20
21/**
22 * Render the `main` element consistently in IE.
23 */
24
25main {
26 display: block;
27}
28
29/**
30 * Correct the font size and margin on `h1` elements within `section` and
31 * `article` contexts in Chrome, Firefox, and Safari.
32 */
33
34h1 {
35 font-size: 2em;
36 margin: 0.67em 0;
37}
38
39/* Grouping content
40 ========================================================================== */
41
42/**
43 * 1. Add the correct box sizing in Firefox.
44 * 2. Show the overflow in Edge and IE.
45 */
46
47hr {
48 box-sizing: content-box;
49 /* 1 */
50 height: 0;
51 /* 1 */
52 overflow: visible;
53 /* 2 */
54}
55
56/* Text-level semantics
57 ========================================================================== */
58
59/**
60 * Remove the gray background on active links in IE 10.
61 */
62
63a {
64 background-color: transparent;
65}
66
67/**
68 * 1. Remove the bottom border in Chrome 57-
69 * 2. Add the correct text decoration in Chrome, Edge, IE, Opera, and Safari.
70 */
71
72abbr[title] {
73 border-bottom: none;
74 /* 1 */
75 text-decoration: underline;
76 /* 2 */
77 text-decoration: underline dotted;
78 /* 2 */
79}
80
81/**
82 * Add the correct font weight in Chrome, Edge, and Safari.
83 */
84
85b,
86strong {
87 font-weight: bolder;
88}
89
90/**
91 * Add the correct font size in all browsers.
92 */
93
94small {
95 font-size: 80%;
96}
97
98/**
99 * Prevent `sub` and `sup` elements from affecting the line height in
100 * all browsers.
101 */
102
103sub,
104sup {
105 font-size: 75%;
106 line-height: 0;
107 position: relative;
108 vertical-align: baseline;
109}
110
111sub {
112 bottom: -0.25em;
113}
114
115sup {
116 top: -0.5em;
117}
118
119/* Forms
120 ========================================================================== */
121
122/**
123 * 1. Change the font styles in all browsers.
124 * 2. Remove the margin in Firefox and Safari.
125 */
126
127button,
128input,
129optgroup,
130select,
131textarea {
132 font-family: inherit;
133 /* 1 */
134 font-size: 100%;
135 /* 1 */
136 line-height: 1.15;
137 /* 1 */
138 margin: 0;
139 /* 2 */
140}
141
142/**
143 * Show the overflow in IE.
144 * 1. Show the overflow in Edge.
145 */
146
147button,
148input {
149 /* 1 */
150 overflow: visible;
151}
152
153/**
154 * Remove the inheritance of text transform in Edge, Firefox, and IE.
155 * 1. Remove the inheritance of text transform in Firefox.
156 */
157
158button,
159select {
160 /* 1 */
161 text-transform: none;
162}
163
164/**
165 * Correct the inability to style clickable types in iOS and Safari.
166 */
167
168button,
169[type="button"],
170[type="reset"],
171[type="submit"] {
172 -webkit-appearance: button;
173}
174
175/**
176 * Remove the inner border and padding in Firefox.
177 */
178
179button::-moz-focus-inner,
180[type="button"]::-moz-focus-inner,
181[type="reset"]::-moz-focus-inner,
182[type="submit"]::-moz-focus-inner {
183 border-style: none;
184 padding: 0;
185}
186
187/**
188 * Restore the focus styles unset by the previous rule.
189 */
190
191button:-moz-focusring,
192[type="button"]:-moz-focusring,
193[type="reset"]:-moz-focusring,
194[type="submit"]:-moz-focusring {
195 outline: 1px dotted ButtonText;
196}
197
198/**
199 * Correct the padding in Firefox.
200 */
201
202fieldset {
203 padding: 0.35em 0.75em 0.625em;
204}
205
206/**
207 * 1. Correct the text wrapping in Edge and IE.
208 * 2. Correct the color inheritance from `fieldset` elements in IE.
209 * 3. Remove the padding so developers are not caught out when they zero out
210 * `fieldset` elements in all browsers.
211 */
212
213legend {
214 box-sizing: border-box;
215 /* 1 */
216 color: inherit;
217 /* 2 */
218 display: table;
219 /* 1 */
220 max-width: 100%;
221 /* 1 */
222 padding: 0;
223 /* 3 */
224 white-space: normal;
225 /* 1 */
226}
227
228/**
229 * Add the correct vertical alignment in Chrome, Firefox, and Opera.
230 */
231
232progress {
233 vertical-align: baseline;
234}
235
236/**
237 * Remove the default vertical scrollbar in IE 10+.
238 */
239
240textarea {
241 overflow: auto;
242}
243
244/**
245 * 1. Add the correct box sizing in IE 10.
246 * 2. Remove the padding in IE 10.
247 */
248
249[type="checkbox"],
250[type="radio"] {
251 box-sizing: border-box;
252 /* 1 */
253 padding: 0;
254 /* 2 */
255}
256
257/**
258 * Correct the cursor style of increment and decrement buttons in Chrome.
259 */
260
261[type="number"]::-webkit-inner-spin-button,
262[type="number"]::-webkit-outer-spin-button {
263 height: auto;
264}
265
266/**
267 * 1. Correct the odd appearance in Chrome and Safari.
268 * 2. Correct the outline style in Safari.
269 */
270
271[type="search"] {
272 -webkit-appearance: textfield;
273 /* 1 */
274 outline-offset: -2px;
275 /* 2 */
276}
277
278/**
279 * Remove the inner padding in Chrome and Safari on macOS.
280 */
281
282[type="search"]::-webkit-search-decoration {
283 -webkit-appearance: none;
284}
285
286/**
287 * 1. Correct the inability to style clickable types in iOS and Safari.
288 * 2. Change font properties to `inherit` in Safari.
289 */
290
291::-webkit-file-upload-button {
292 -webkit-appearance: button;
293 /* 1 */
294 font: inherit;
295 /* 2 */
296}
297
298/* Misc
299 ========================================================================== */
300
301/**
302 * Add the correct display in IE 10+.
303 */
304
305template {
306 display: none;
307}
308
309/**
310 * Add the correct display in IE 10.
311 */
312
313[hidden] {
314 display: none;
315}
2html{line-height:1.15;-webkit-text-size-adjust:100%}main{display:block}h1{font-size:2em;margin:0.67em 0}hr{box-sizing:content-box;height:0;overflow:visible}a{background-color:transparent}abbr[title]{border-bottom:none;text-decoration:underline;text-decoration:underline dotted}b,strong{font-weight:bolder}small{font-size:80%}sub,sup{font-size:75%;line-height:0;position:relative;vertical-align:baseline}sub{bottom:-0.25em}sup{top:-0.5em}button,input,optgroup,select,textarea{font-family:inherit;font-size:100%;line-height:1.15;margin:0}button,input{overflow:visible}button,select{text-transform:none}[type="button"],[type="reset"],[type="submit"],button{-webkit-appearance:button}[type="button"]::-moz-focus-inner,[type="reset"]::-moz-focus-inner,[type="submit"]::-moz-focus-inner,button::-moz-focus-inner{border-style:none;padding:0}[type="button"]:-moz-focusring,[type="reset"]:-moz-focusring,[type="submit"]:-moz-focusring,button:-moz-focusring{outline:1px dotted ButtonText}fieldset{padding:0.35em 0.75em 0.625em}legend{box-sizing:border-box;color:inherit;display:table;max-width:100%;padding:0;white-space:normal}progress{vertical-align:baseline}textarea{overflow:auto}[type="checkbox"],[type="radio"]{box-sizing:border-box;padding:0}[type="number"]::-webkit-inner-spin-button,[type="number"]::-webkit-outer-spin-button{height:auto}[type="search"]{-webkit-appearance:textfield;outline-offset:-2px}[type="search"]::-webkit-search-decoration{-webkit-appearance:none}::-webkit-file-upload-button{-webkit-appearance:button;font:inherit}template{display:none}[hidden]{display:none}
3163
3174/* CUSTOM CSS */
3185:root {
@@ -340,7 +27,7 @@ body {
34027 Liberation Mono,
34128 Lucida Console,
34229 monospace;
343 font-size: clamp(0.95rem, 1vw + 0.5rem, 1.1rem);
30 font-size: 1rem;
34431 line-height: 1.5;
34532 max-width: 50em;
34633 margin: 0 auto;
@@ -353,17 +40,12 @@ body {
35340 }
35441}
35542
356main>*+* {
357 margin-top: 2rem;
358}
359
36043.site-nav,
36144footer {
36245 border-color: var(--fg);
36346}
36447
36548footer {
366 /* border-top: 1px dotted; */
36749 padding-top: 1rem;
36850 margin: 1rem 0;
36951}
@@ -376,10 +58,6 @@ ul {
37658 list-style-type: "- ";
37759}
37860
379/* .site-nav {
380 border-bottom: 1px dotted;
381} */
382
38361.site-nav ul {
38462 list-style-type: none;
38563 display: flex;
@@ -396,31 +74,25 @@ h2,
39674h3,
39775h4 {
39876 color: var(--fg);
399 text-transform: uppercase;
40077}
40178
40279h1 {
403 font-size: 2rem;
80 font-size: 1.5rem;
40481 font-weight: bold;
405 /* border-bottom: 1px solid var(--border); */
406 margin-top: 2rem;
407 margin-bottom: 1rem;
82 margin-top: 1rem;
83 margin-bottom: 0.75rem;
40884}
40985
41086h2 {
411 font-size: 1.5rem;
412 margin-top: 1.5rem;
413 margin-bottom: .75rem;
414}
415
416h3 {
41787 font-size: 1.25rem;
418 margin-top: 1.25rem;
419 margin-bottom: .5rem;
88 margin-top: 1rem;
89 margin-bottom: 0.5rem;
42090}
42191
422#text-table-of-contents li {
423 text-transform: uppercase;
92h3 {
93 font-size: 1rem;
94 margin-top: 1rem;
95 margin-bottom: 0.25rem;
42496}
42597
42698a,
@@ -481,7 +153,7 @@ code {
481153 Liberation Mono,
482154 Lucida Console,
483155 monospace;
484 font-size: inherit;
156 font-size: 0.9rem;
485157}
486158
487159pre {
@@ -537,7 +209,6 @@ blockquote p {
537209
538210.post-metadata {
539211 border: 1px dotted var(--border);
540 /* border-top: none; */
541212 padding: 1rem;
542213}
543214
theme/templates/base.html +5 −4
@@ -21,6 +21,7 @@
2121 <nav class="site-nav" aria-label="site-nav" role="navigation">
2222 <ul>
2323 <li><a href="/">Home</a></li>
24 <li><a href="/about/">About</a></li>
2425 <li><a href="/blog/">Blog</a></li>
2526 <li><a href="/services/">Services</a></li>
2627 <li><a href="/wiki/">Wiki</a></li>
@@ -28,16 +29,16 @@
2829 </nav>
2930 <main id="main">{% block main %}{% endblock %}</main>
3031 <footer>
31 <p>Donate: <a href="ethereum:0x7850b2Fe6be94f90F54A099C74126430C9CeB19e">ETH</a>
32 <p><a href="ethereum:0x7850b2Fe6be94f90F54A099C74126430C9CeB19e">ETH</a>
3233 | <a href="bitcoin:bc1qy74tcth6zwg88059ae9z3ghzk797fkav7zdx4k">BTC</a>
3334 | <a href="xrp:rJz78ahN1KmushjYjEnFd8CB5vCcreJ1EE">XRP</a>
3435 </p>
35 <p>Last build: &lt;<time datetime="{{ now() | strftime("%Y-%m-%d") }}">{{ now() | strftime("%Y-%m-%d %a %H:%M:%S") }}</time>&gt;</p>
36 <p>&lt;<time datetime="{{ now() | strftime("%Y-%m-%d") }}">{{ now() | strftime("%Y-%m-%d %a %H:%M:%S") }}</time>&gt;</p>
3637 <p>
3738 <a href="https://stats.uptimerobot.com/OwOWs7HU0z">Status</a> &middot;
3839 <a href="https://git.sr.ht/~cxc/cleberg.net" target="_blank"
39 rel="noopener">Source Code</a> &middot;
40 <a href="/feed.xml">RSS Feed</a> &middot;
40 rel="noopener">Source</a> &middot;
41 <a href="/feed.xml">RSS</a> &middot;
4142 <a href="/.well-known/security.txt">security.txt</a>
4243 </p>
4344 <p>
theme/templates/blog.html +2 −1
@@ -2,12 +2,13 @@
22main %}
33<h1>Blog</h1>
44<p>
5 Use <code>⌘ + f</code> (<code>Ctrl + f</code>) to search blog post titles for
5 Use <code>⌘ + f</code> (<code>Ctrl + f</code>) to search for
66 keywords.
77</p>
88<p>
99 You can also add the <a href="/feed.xml">RSS Feed</a> to your feed reader.
1010</p>
11<br>
1112{% for post in posts %}
1213<div class="post">
1314 <time datetime='{{ post.date | strftime("%Y-%m-%d") }}'
theme/templates/index.html +4 −15
@@ -1,22 +1,22 @@
11{% extends "base.html" %} {% block main %}
22<section>
3 <h1><i>~cleberg.net</i></h1>
3 <h1><i>~cmc</i></h1>
44 <pre>pub rsa4096 2022-11-16 [SC]
55 <a href="/gpg.txt">3917 973F B159 BBB8 6194 5385 6945 1A51 7AC0 CB37</a>
66uid [ultimate] Christian Cleberg &lt;hello@cleberg.net&gt;
77sub rsa4096 2022-11-16 [E]</pre>
88</section>
99<section>
10 <h2>Recent Blog Posts</h2>
10 <h2>Blog Posts</h2>
1111 <!-- BEGIN_POSTS -->
1212 <!-- END_POSTS -->
13 <br>
1413 <a href="/blog/">All Posts →</a>
1514</section>
1615
1716<section>
1817 <h2>Everything Else</h2>
19 <ul>
18 <ul>
19 <li><a href="/about/">About</a></li>
2020 <li><a href="https://cv.cleberg.net">Curriculum Vitae</a></li>
2121 <li><a href="/now/">Now</a></li>
2222 <li><a href="/salary/">Salary</a></li>
@@ -25,17 +25,6 @@ sub rsa4096 2022-11-16 [E]</pre>
2525 </ul>
2626</section>
2727
28<section>
29 <h2>Contact</h2>
30 <ul>
31 <li><a href="mailto:hello@cleberg.net">hello@cleberg.net</a> (<a href="https://cleberg.net/gpg.txt">GPG</a>)</li>
32 <li><a href="https://lemmy.cleberg.net/u/cmc">@cmc</a> on Lemmy</li>
33 <li><a href="https://matrix.to/#/@cmc.:matrix.org">@cmc.:matrix.org</a> on Matrix</li>
34 <li>@cmc.01 on <a href="https://signal.org/">Signal</a></li>
35 <li><a href="https://sr.ht/~cxc">~cxc</a> on Sourcehut</li>
36 </ul>
37</section>
38
3928<section class="hidden">
4029 <div class="h-card">
4130 <span class="p-name">Christian Cleberg</span>