Sunday, December 28, 2025

Trump-class BBG? It's Either the Best Trump Joke ever or End of US Navy

Recently, the announcement of "Trump-class" BBG USS Defiant started a bunch of analysts all with different ideas. 

I am not a naval analyst. I am a bull**** detector. And I detect a huge amount of bull****. Thus the title here: it's either the best Trump joke ever, or this is the end of the US Navy as we know it. In other words, China won't destroy our navy in a conflict in the Pacific. We're doing it to ourselves. 

Let's start with the joke part. Why do I think this is a joke? 

* The class name. Everybody who knows navy knows, the first ship of the class is what the class is named after. So why is the ship called USS Defiant, but Trump-class? This is a press-release ship, vaporware. There is no real plan to design it, much less build it. It's not even a concept. It's a wishlist. 

* There are currently NO SHIPYARD IN THE US capable of building this ship. That's right, NONE. You need to upgrade a few of the existing yards to even THINK about building them. 

* The current form of this ship is VERY INEFFICIENT as a missile bank. It barely has more VLS cells than the retired Ticonderoga-class CG (guided missile cruiser), yet costs two to three times more, with presumably 2-3 times more crew, and probably takes 2-3 times longer to build... (see above)  At this rate, even if we start upgrading the yards now, we won't see even the prototype until the 2030s as a hull, muchless commissioned and accepted into service. 

* It doesn't address the problem of US Navy is being outnumbered on VLS cells by the Chinese Navy, i.e. PLAN (People's Liberation Army Navy), whose Type 55 "Destroyer" (which is larger than our Ticonderoga "cruisers") is already in service and already has nearly 100 VLS cells per ship. Remember, we're RETIRING Ticos. We barely have Arlieigh Burkes, We planned for 2 dozen Zumwalts. We got 3 instead. The Littoral combat ships are disasters. And we just CANCELLED Constellations. 

But what if the Navy was serious, that they really intend to build this thing, by diverting all the money planned for Constellation and DDG(X) into this BBG, and the half-baked FF(X) idea, which is bolting some VLS cells onto the Coast Guard Legend-class cutters? 

* It doesn't help (rehash of the last point), even if they find the budget, and Congress rubber-stamp the proposals, because, as mentioned, it's NOT an efficient missile platform. Adding the guns and whatnot doesn't help. This is a floating wishlist, as it can do a little of this, a little of that. It's a little of everything... master of none. It looks great ON PAPER, and it'll definitely sooth DJT's ego, but it doesn't help USN address the growing hull and VLS disparity between USN and PLAN. 

* They actually said this will be the "best-looking" ship. No joke. and DJT himself even said he wants it that way because "I'm very aesthetic". Since when do warships care about "looking good"? This is just a concept rendering, Heck, it even has the front RAILGUN spitting flame like a conventional cannon!?!  Not even the Iowa spit flame out the barrel! Huge plumes of smoke, sure... But this is official press release from the US Navy itself?!

* There doesn't seem to be any actual Navy people at the announcement (Hegseth doesn't count).     

Friday, September 19, 2025

How MAGA is Dishonoring Charlie Kirk's Legacy

Charlie Kirk's assassination has shocked the nation. While I do not agree with his views on many things, I believe the vast majority of us would agree that we do not wish him death, or even maimed. We can agree to disagree on many things. While his death will silence him, his ideas will live on, and you can't silence an idea. 

However, MAGA's current clumsy attempt to maximize the propaganda value of Kirk's death by trying to venerate him, and the various overreaction to anything about Kirk that's NOT complimentary (posters of Kirk as a "saint", Trump floated the idea of giving Kirk a posthumous Medal of Freedom, FCC bullied Disney into suspending Jimmy Kimmel for a joke about Kirk, WaPo fired a black female reporter who cited an uncomplimentary quote by Kirk on black females for "endangering colleagues"...), IMHO, is dishonoring Kirk's legacy. 

You don't get it? Let me walk you through this. 

Why did Kirk's assassin do it? 

To stop Kirk from speaking out, right? 

So how does MAGA and those organizations kowtowing to MAGA (such as Disney, WaPo, etc.) react? 

By stopping anything that's not "nice" about Kirk from being aired or even spoken on public media. 

MAGA used the death of an outspoken man... as an excuse to CENSOR other people! 

Oh, the irony. 

Rant: Child Dead in LA is Just a Sign of Things to Come

When Trump nominated RFK Jr to CDC Head, things are going to get bad, and the latest news is merely a sign to come. 

RFK Jr is, for lack of better term, a so-called vaccine freedom-fighter... as in vaccine should NOT be mandatory. They claim the "risks" of vaccine means it should be a personal choice, when it *should* be public policy, because diseases affect everybody. Once RFK jr took office, one of the first things done was firing the entire vaccine advisory panel... and replaced it with a group composed of various vaccine denialists that were discredited during COVID. Since then, CDC has basically waived every school vaccine mandate, claiming it's a state-level issue or personal freedom issue. As a result, childhood diseases such as measles, which was nearly eradicated decades ago (back in Year 2000), and used to be only counted in the teens, except for a few cases in isolated communities where vaccine denialists congregate, is making a major comeback. Measles case count per year is at a 33 year high. 

And this new child death in Los Angeles is a sign of things to come. 

To keep a long story short, Los Angeles County Health has reported a death of a child from a measles-related brain disorder called SSPE, which was basically "delayed measles". The child probably contracted measles while very young (less than 1 year old). While it is notable that this is probably BEFORE the child could be vaccinated for measles (generally MMR vaccine is given between 12-15 months old), but unvaccinated people are often protected by "herd immunity" (low chance of encountering the disease due to high percentage of vaccinated people around them). SSPE means measles virus entered the brain, and lay dormant until months or even years later. The child appears to have recovered, then the symptoms started appearing, as the virus started to destroy the brain and nerves from within. First memory starts to go, then mood changes, then muscle coordination deteriorates. Mental acuity lessens. All this, in the course of a few months... and the body lives on... And there is no cure and no treatment. 

Los Angeles County Health officer Muntu Davis released a statement, from which I quote: "Infants too young to be vaccinated rely on all of us to help protect them through community immunity. Vaccination is not just about protecting yourself—it's about protecting your family, your neighbors, and especially children who are too young to be vaccinated."

And yet RFK jr is proposing that we do away with vaccines because of "freedom". 

Would you not sacrifice a little bit of YOUR freedom to lessen the health risks for your children and your children's children? 

Friday, July 11, 2025

Self-Hosting Discoveries: Part 1 of ???

Recent random surfing and curiosity got me into "self-hosting" a few apps that normally I would have left up to the big cloud companies like Google and Microsoft and others...

Generally, that means 

1) Install "Windows Subsystem for Linux" or WSL on your Windows 11 Home PC

2) Install Docker Desktop and register for a free tier membership

3) Download and configure whatever app you want to self-host available in Docker container form

4) Install Tailscale distributed VPN and register for a free tier membership, then setup your nodes (i.e. your host PC, and whatever peripheral you want to access it from, probably your smartphone)

5) Test if everything works! 

However, there are a LOT of little niggles that causes a lot of problems in practice, at least on my personal desktop (Win11, NOT Pro), which I guess I *could* have solved by using an old PC to host these apps...

a) startup sequence

The startup sequence was kinda screwed up, as the Docker Desktop refused to initialize properly, which means none of the containers (apps) works either. Keeps complaining about not "signed in", even though it just opens up my browser, and my browser *is* signed into Docker. Had to close Docker Desktop completely, then reopen it. 

THEN the services won't open, kept complaining about port not open. Had to Powershell admin mode, then net stop hns to fix that. THEN the containers in Docker Desktop will start normally. 

b) Can't resume from sleep? 

This may be my PC's own fault, but the net effect is if my PC went to sleep I can't be sure this thing will keep running. 

c) Containers are still a mystic art

There are many ways to configure a container, and many of them require the use of CLI, or editing a Docker Compose file (YAML). 

There are more, but I am figuring them out... slowly. 


Monday, June 23, 2025

Condiment Review: Frank's RedHot | Nashville Hot Wings Sauce

I personally find my food bland and boring, but one can only eat Sriracha hot sauce for so long. Thus, I have amassed a collection of condiments to be added to my food, and this is going to be first of various condiment reviews. 

Frank's Red Hot is a whole family of hot sauces, and this one is supposed to be good on chicken wings. Personally, it goes well on everything. 

From the back of the bottle: "hot 'n spicy with a touch of sweet" and "kicked-up flavor from Aged Cayenne Red Peppers, Mack pepper, and a hint of sweet molasses". According to the ingredients list, the primary ingredient is distilled vinegar, and you do taste the tartness. Next is aged cayenne red peppers, then sugar, canola oil, and water. 

Visually, the sauce is a very orange and thick sauce with a LOT of flecks of black pepper. If you taste the sauce alone, your tongue will feel the tartness of vinegar first, then the individual pepper bits as if you hit specks of sand. THEN the heat of the cayenne pepper hits the back of your throat and tongue. But the heat is relatively subtle, yet it will make you feel you are sweating somewhat, but the sweetness counterbalances the heat. 

If you put it on meat or other food, the thickness of the sauce allow it to cling to various surfaces, which is very helpful in retaining the sauce where they are needed. However, one tablespoon is 30 calories, and 340mg of sodium (about 15% of DV), and you probably need a bit more than that. 

Better than Tabasco or similar type sauces, IMHO. 4/5

Sunday, June 22, 2025

App Discovery: Karakeep (aka Hoarder) a web clip manager

If you go on the web a lot, you often come across articles that you want to reference later. So do you bookmark it, email it to yourself, or do something else? (Evernote? OneNote? Obsidian? Pocket?)

I personally had used various services including one called Omnivore, but that shut down a few months back. Then I read somewhere that if you host your own, you don't have to be EVER at the mercy of some other service provider.

As I find clipping to Evernote way too slow (up to 15 seconds per clip), I decided to look for something else. 


How KaraKeep Works


KaraKeep is both an app and a service. It takes clippings of articles you can transfer to it via bookmarks, Android app, app share, iOS app, Chrome or Firefox extensions, and so on. It will take whatever you sent it (and optionally, run it against an LLM to extract keywords) so later you can go back and browse or search through via regular search and keywords. 

How to Install / Self-Host KaraKeep


What's great about Karakeep: it runs via a Docker Container, so there is minimal configuration if you already have Docker Container all set up. You simply download the whole package, and "run" it. Done. They have documentation online, and Discord channel as well.  

To make KaraKeep server available to you from almost anywhere, you setup a Tailscale distributed VPN, and enroll both your PC (whichever that runs the Docker container) and your smartphone (where you plan to clip from) to make sure they can see each other. And really, that's it. 

From now on, when you see an interesting article on the smartphone, simily do share >> KaraKeep. No need to choose keywords, no need to choose specific labels, no need to specify title... Share it, and forget it. It's clipped almost instantly, no matter where you are, and whether you're on cellular data or wifi. 

Run the app itself (or if you're at home, go to the machine running KaraKeep and browse to http://localhost:3000) and you can see what you've clipped, and use search and keywords to find what you clipped on that subject. 

If you want to use LLM to automagically pull out keywords for your searches, you need to configure KaraKeep (server, on your PC) by following this guide

Troubleshooting


Oh, and if you ever run into a problem with Docker, something about port 3000 is already taken, you need to restart hns, with "net stop hns" then "net start hns". You may also need to restart the Docker Container for Karakeep. Then it should work. 

If it fails on the smartphone side, make sure Tailscale is RUNNING. Obviously Tailscale needs to run for the VPN to work, and send your traffic back to your network to the KaraKeep "server". 

Now go have fun clipping everything you needed. 

Tuesday, June 17, 2025

Watch Out for LEGAL Scams: App that Cost WAY TOO MUCH on Subscription

For those who don't operate multiple phones... Androids use JPEG (or JPG), but iPhones use HEIC. The two standards are NOT compatible. If you share a photo from iPhone straight to Android, it will not be viewable. So what do you do? 

You convert it. 

Except the first convert I ran into is... essentially a scam. It basically won't do anything unless you engage the "free trial" which means you'll be charged in 3 days. It didn't exactly mention what's the cost. Then I looked at the email I just got:

Auto-renew subscription of $14.99 PER WEEK for an image converter?!

This app subscription costs $14.99 PER WEEK. 

Not per year. Not per month. PER WEEK?!

And this app doesn't even do HEIC to JPG, despite its name, "Image Converter Premium". 

Needless to say, I cancelled ASAP. 

Saturday, June 14, 2025

Some Quick "Spending Money" Side Gigs in San Francisco (6/14/2025)

Need some spending money in San Francisco, but don't have a lot of time? Here are two things I've tried and gotten money for, 2 hours at a time, pay starts at 17.50 per hour and up, for VERY simple work:

A) Condu.it

Want to help a company that wants to create a headset that turns your THOUGHTS into typed words on a computer? Condu.it is working on that, and they need help of people who can type without looking at the keyboard, wear this heavy headset, and spend two hours looking at a screen and type responses without looking. You get paid $50 for two hours, and you can do up to 10 hours total. Beware... they are so booked, they are paying extra $10/hr if you can go extra early or extra late. That's $25+ PER HOUR (not counting any cost to get there, but there's a bus that go within 2 blocks)

However, beware, there are a couple caveats:

* You need some neck strength, because the headset is heavy and they provide a "chin rest"

* You do the two hours in the dark, as they need the laser to align properly. If you need a break, ring the bell

* You REALLY need to know how to type without looking at the keyboard, because you can't see the keyboard! 

If you can do all that, you will make easy $50 for 2 hours, up to 10 hours total ($500). They will hand you a check right at the end, which you can remote deposit into your bank via your banking app. Click on link above to book. If you click through, tell them "Kasey Chang" sent you. :) We both get a small bonus.  

B) Reflex

Reflex is working on something similar, albeit, they want to use your jaw's micromovements via subvocalization and turn that into typed words. What does that mean? Can you "say" things without actually making the sounds? That's subvocalization. At the study, you wear a headset with some extra sensors (more like a regular headset), and read both out loud and subvocalize a bunch of nonsense phrases to calibrate the sensors. Once you got it calibrated, you read aloud a book of your choice, for the remainder of the time. If you go back, you get to keep reading the book, or choose any ebook for under $10 on Amazon and they'll buy it for you to read into the machine to train their AI on the words and your jaw muscle patterns.

Their pay is $35 for 2 hours to read a book out loud. However, they only pay via Paypal, so you *do* need a Paypal account (at Paypal.com)  You can keep booking more time, but no more than twice a day.  

Sounds interesting? Click here to book time with Reflex $35 for two hours. You'll be paid within hours of finishing your session. 

https://www.jotform.com/assign/250627963837166/251757097262060

Any way, hope you earn some extra money!

Friday, May 16, 2025

Restaurant Review: Kokio Republic (via Grubhub)

Hadn't had a meal delivered in a LONG time, decided on fried chicken. Apparently, nearest KFC does NOT deliver to my area (a few blocks too far?) so I had to pick someone else, and seems Kokio Republic was highly rated. 

Ordered combo 1: 4 pieces Korean Fried Chicken (hot and sweet flavor, mixed bone-in and bone-out), + 3 kimchi balls, which is just under $20. Added a pickled korean radish as side, and a bulgogi beef taco. Add driver fee, Grubhub charge, minus discount, plus tax, plus $3 tip, comes out to be just about $30. 

Delivery was fast, tried the food, felt as if I ordered the wrong thing, due to my changing taste buds. 

Kimchi balls: eh... didn't really taste like kimchi, a bit of grain, probably rice. I just had kimchi yesterday, and this doesn't taste like kimchi. 

Korean Fried Chicken: I did ask for mixed (half bone-in, half-boneless), and I probably should have just asked for all boneless. I did ask for hot and sweet, but it tastes mostly sweet, very little spice. I probably should have specified "fiery" (3 spice level vs 1). The chicken is nice and tender, not dry, but delivery means outside isn't crispy any more. 

Pickled Korean Radish: this is pickled? It just tastes like cubed with a little vinegar. It is crispy, and it does counter the saltiness of the chicken. But I probably should have ordered Persian cucumber instead. 

Bulgogi beef taco: hmmm... street taco (tiny little tortilla) with some better in the middle, tastes pretty good, but $5 for that little thing? A bit overpriced, IMHO. 

I probably should have ordered 6 pieces Korean Fried Chicken, fiery flavor, boneless, and instead of the bulgogi taco, something like kimchi beef risotto or noods, or tteokbokki skeweyer. 

For the price I paid, I just feel I didn't quite get my money's worth. It's not bad, but it's not that good either.     

Kokio Republic, 711 Geary, San Francisco

Thursday, May 15, 2025

Cybersecurity: Seems Most People Think Most Cybercriminals are Uberhackers... They aren't!

One of the things I do on Reddit is hang out in /r/cybersecurity_help, and tell people what they claim was impossible. Like "I got hacked through ______". 

I don't mind people not believing me. Honest truth is sometimes hard to believe, or let's use Chinese proverb, 忠言逆耳. 

Two MONTHS ago, someone decided to post a portion of their iPhone's log, believing it contains evidence of them being monitored. Except it contained no such thing. It's quite easy to Google all the suspicious keywords like "tracked" and "proactiveHarvesting"... They are all built by Apple. So I replied there's nothing here that indicates anything about you being monitored. 

OP pivoted to a different theory, like "what if they hack me through Bluetooth or something else? I can find evidence of intrusion? "

I replied that you can't be hacked through Bluetooth nowadays, esp. if you have a modern iPhone and keep stuff updated. And evidence of intrusion had to be gathered by forensic analysis. It's not something regular folks can just run an app and "voila, evidence!". 

Then yesterday, some OTHER random guy decided to necro the topic from 2 months ago (and even OP had left the topic), and started blabbing about "Bluetooth hacking, just search for it."

As a cybersecurity professional, I am QUITE familiar with state of Bluetooth hacking. With noderm iPhones, the best you *can* do without some Zero-day exploit was Bluespam (keep popping up "trying to connect") 

There are other Bluetooth hacks, but they don't result in being able to control the iPhone. Just to summarize: 

Bluejacking -- the targeted user accepts the pairing attempt from a peripheral, which of course, results in the peripheral, acting as a keyboard and mouse, gaining some control of the iPhone. This is NOT done easily, as the user must ACCEPT the pairing attempt. It's not done invisibly or automatically. 

Bluesnarfing -- by using some exploits on VERY old firmware, hacker can transfer files the target phone. Again, only on very old firmware with problems. And most files "shared" this way are just regular stuff, like calendar, contacts, photos, texts, videos, and such. Stuff you normally use BT to transfer. They can't suddenly reach out into Banking app and take your account number and balance (at least, not with bluesnarfing alone). 

Bluebugging -- the most dangerous, but requires a VERY dangerous exploit that basically gave the attacker full control of the device through Bluetooth. You pretty much have to be running ANCIENT (like 5-10 year old) hardware and firmware with no security updates. 

Blueborne hacking -- a bunch of vulnerabilities discovered in 2017 (yes, 8 years ago) that got grouped together even though they are spread across iOS, Android, Windows, and even Linux, and some embedded OS, due to a Bluetooth problem. When it came to iOS, Blueborne problem was... an audio protocol over Bluetooth, called LEAP: Low Energy Audio Protocol. Guess what iOS was this fixed in? iOS 10. That's right. iOS 10. We're now on... iOS 18.5. 

Really, that's it. 

So I replied something like "Bluetooth hacking is from YEARS ago and usually doesn't even involve smartphones, but peripherals." 

His reply? "Those Flipper devices are something huh?"

Except there's only one: Flipper Zero, and while it *can* "hack" BT and BLE, the worst they can do to iOS is Bluespam. They are not capable of anything like Bluejack, Bluesnarf, Bluebug, or Blueborne. So it's completely irrelevant to the original topic. 

What was the purpose of the reply and who was he supposed to impress by mentioning a few keywords? I honestly have idea. Was he expecting to stump me? 

Frankly, to the average "civilian" (who's not in cybersecurity), the "hackers" seems like wizards, when most of them are actually scriptkiddo that can barely follow instructionss on a PC. They may be lead by someone who's somewhat more skilled, but they are hardly a "live in parents' basement" misunderstood genius stereotypical geek. 

Cybercriminals are usually NOT uberhackers. They can barely follow standard script. They are worse than scriptkiddies (or scriptkiddos). 

In fact, most civilians can't even distinguish device being hacked vs. account being hacked. 

Whether this is due to lack of compuiter literacy, I have no idea. 

And with the advent of AI, which can be used to further disguise the lack of compute literacy, things can only get worse. 

Guess that keeps us cybersecurity experts employed. 

Wednesday, May 14, 2025

App(s) Discovery: Files (Community) and FilePilot, two Explorer Replacements or Complements

Recently, I came across two different Windows Explorer "replacements or complements". Let's face it, Windows Explorer can get a facelift, but the codebase is ancient. What if someone started from scratch? And here we have two different visions... 

Please note that Microsoft never gave us a way to completely replace Windows Explorer, so there are various "hacks" including registry changes, call intercepts, and so on, but they all have pros and cons. Just beware. 

Files / https://files.community/

Files is a slick looking manager that's completely free. They do suggest you "purchase" it from the Microsoft store to enable auto-patching and thus support them with a bit of revenue, but it is optional. 

The interesting thing about this explorer replacement just about EVERYTHING visual is configurable. Want a background? No problem. Zoom, unzoomed, specific percentage, specific alignment, etc. etc? Can do. Color themes? No problem. Want certain UI elements to appear in a different location? No problem. 

But by default, it looks a lot like Explorer... multiple tabs, etc. That is, until you find the "settings" button at the bottom left. Then everything changes. 

This is free, so just go download it and give it a try, eh? 

FilePilot / https://filepilot.tech/

FilePilot is extremely speedy and free during the beta period. In fact, the download is LESS THAN 2 MB. While the visuals are not as configurable as Files, the UI is extremely slick, with the mouse wheel picking many of the options, such as the different views of files, from large, middle, small icons, to file list, details, and so on. It also supports command palette. EVERYTHING is lightning fast... 

In fact, why don't you just go give it a try? They probably will stop the beta sometime later this year, but in the meanwhile, the beta should still work fine. And you *may* find it useful enough to pay for the full version... even in the current beta state. 


Saturday, May 3, 2025

App Discovery: UnigetUI, the almost-universal Windows Patcher

Windows 10 and 11 actually has multiple methods of self-updating ASIDE FROM Windows Update. However, they are reserved for powerusers, not regular users, as most rely on command-line interface (CLI). Such as Winget, Scoop, Chocolatey, Pip, Npm, and more. Though to be honest, NPM is more for Node.js, and PIP is more for Python, but they are there, and they are used on Windows quite a bit. 

One user, Marti Climent, decided to change that, and came up with UnigetUI, which is a graphical interface for all those different sources, combined into one app. 

Between this and Patch My PC's Home Updater, they should update just about EVERY app you have on your PC. 

Now you have NO excuse to NOT keep your PC's apps updated. 

App Discovery: Patch My PC Home Updater, keep your apps updated easily!

I've touted many times before the 3 simple cyberhygiene rules of Brian Krebs, one of which is keep apps updated. But some apps update themselves (but you have to run them), some have external updaters, some relies on Windows update... 

Now, there is Patch My PC's Home Updater. That's right, there's an app that will scan your home PC, find the apps, and update them for you, with minimal headaches. 

While this doesn't replace ALL updaters, this will do about 80% of the updates. Just run it periodically (say, once a week)... Start it up, and just hit "update" and walk away. Come back in half an hour, and it should be done. 

How easy is that? 

You can also use this to FIND new apps to install by browsing the library of apps they scan for. These scan for mostly free alternatives to famous apps, and thus, you may discover apps that does what you pay monthly or yearly for. 

And of course, it will UNinstall apps you no longer want to use, which is another one of Kreb's cyberhygiene rules. 

So give it a try. 

For the few apps this won't update, there's another app I will recommend... in the next post. 

Sunday, April 27, 2025

Cybersecurity: AI Dulls Our Critical Thinking and Enables Scammers to be More Effective (Microsoft Warned Us!)

The rise of "AI" (mostly Large Language Models, or LLMs, like ChatGPT, Claude, Perplexity, and so on) does enable a lot of "productivity hacks". However, Microsoft had warned us back in Jan 2025 that the most you rely on them, the more atrophied your critical thinking skills. Most "knowledge workers" who admitted to using AI tools, only use their own critical thinking skills to "fact-check" the LLMs. This suggests that the "average user" may be doing even less than that. 

This bodes ill for the average user, as they seem to regard ChatGPT and LLMs as some sort of generic "expert", when it is nothing of the sort. Indeed, merely by browsing /r/cybersecurity_help there are a number of topics where the poster openly admitted to "I checked my logs with ChatGPT..." when they lacked even the skills to fact-check the LLM they used. They suspected something, and they wanted ChatGPT to confirm their suspicions. 

But that's not the actually worrying part. Instead, Microsoft security is ringing the alarm: scammers are using LLMs to craft their latest scams to enhance their social engineering... by leveraging every sort of fakery possible, from fake website to fake job posting to fake customer service chatbots, because making them is so much easier with LLMs consolidating such knowledge. 

Be wary out there. 

App Discovery: Cobalt.tools, the video downloader that just works

One of the biggest pet peeves about Youtube is it's impossible to simply transfer your video to a different channel, when you have several. You have to download your videos, then re-upload them to the other channel, then re-enter the information. 

While for channel owners there is an option to download individual videos, there is no mass download option, so you need to click on each one individually to download each file individually, and you are now at the mercy of your browser's downloader. And every once in a while, you run into a few videos that just refuse to download. You click on download, you somehow get dumped back to the content tab, or the download simply "failed" with no error given. 

Yes, there are all sorts of shady sites and apps that claims to download Youtube videos for you, many of them want money, subscription, or more. Just search for "Youtube downloader" on Google... They all look shady for one reason or another. 

Then I found https://cobalt.tools , yes, that's the whole URL. 

No registration, no payment, no subscription. 

Simply paste in the URL of the video you want downloaded, and voila, it downloads. Even the ones previous you can't download from Youtube itself as the owner of the video. 

It has other options, like get audio only of a video, or download from other platforms (not just Youtube, but all the Chinese ones, like Bilibili, Xiaohongshu, as well as the Western ones). 

It just works. 



Friday, April 18, 2025

App Discovery: PyMacroRecord -- a completely free (no trial, no freemium, FREE!) macro recorder for Win10/11

Sometimes, you need to record a macro that will just copy data across multiple windows, move the mouse, and so on. However, when you search, you find... expensive options that has an fee... or an ANNUAL fee. 

Then you keep looking, and find PyMacroRecord. Completely free, source code in Python available on GitHub. One guy's passion project made available for all to you. 

And it works. 

I need to move some videos across my different Youtube channels. However, there is no such functionality on Youtube. The ONLY option is to re-upload. 

So I quickly whipped up a macro that copies title and description from one channel to the other. The rest, like keywords and such, can be handled by re-using an existing description. I have the videos available for re-upload (and the rest, I can download in batch). 

That's a TON of manual copy/paste saved. 30+ videos means probably closer to an hour saved. 

I am sure you have your own use case when you need such functions. Don't pay when this free tool will do. 


Tuesday, April 15, 2025

PC Hardware Discovery: One of the Best Mouse Bargains on Amazon -- Infinmind Mouse

Recently, I ended up buying two mice on Amazon. One I am okay with, but the other I am ecstatic with.

The latter is the Infinmind Mouse

NOTE: See long-term update later. 

It's a simple mouse, with 4 buttons (2 regular, 2 near the thumb), but it has a couple extra tricks. It is basically a clone or tribute of Logitech's Master Mouse. 

Instead of mouse wheel "tilting" (like Logitech) to scroll sideways, there's a separate mouse scroll roller next to the thumb. 

And the mouse wheel is METAL, and it's buttery smooth, yet has a distinctive step feedback if you scroll slowly. And it will let you spin on inertia alone so you will scroll a LONG way. It's hard to describe. 

The tracking is precise, as the built-in 4 different DPI setting, from 1000 to 3000 DPI, makes my scrolling on my triple-wide desktop (I use 3 x 24 inch monitors each at 1080p) very comfortably on a space that's barely twice as wide as my mouse. 

AND this mouse is both 2.4 Ghz wireless AND Bluetooth. In fact, it's 2 channel Bluetooth (can be paired to 2 different devices) AND available in both black and white. 

It even CAME with AA alkaline batteries, so it's ready to be used immediately. 

So what's the price of this amazing mouse? 

$18.99, and there's a 16% off coupon you can clip right now.  (As of 4/15/2025)

I daresay this is better than most Logitech mice I've used. We'll see how long it lasts. But in the meanwhile, this is one of the best mouse bargains on Amazon. 

LONG TERM UPDATE: It's now June 2025, and after 2 months of using it, it's... crap. It freezes up every few minutes, that I had to power cycle it to get it to work again. And that's USING the wireless dongle! I haven't tested Bluetooth mode yet. Will check later, but this is... not good. I had to power cycle the mouse multiple times a day. That's just... "no bueno".     

Friday, March 14, 2025

App Discovery: Spacedesk by Datronicsoft

As you use more and more tech, you object have extra old tech left over. If you have an old tablet left over, have you wondered what you should do with it? 

How about turn it into an extra display for your desk accesories that you don't want to take up extra desktop space? 

I have an old Nexus 7 (2nd gen) tablet, too old and too slow for 2025, but it's fast enough to act as a secondary display. I cleaned it up (removed all the old apps I don't use), uninstalled a bunch of crap, then went to 

https://www.spacedesk.net/

And downloaded the "driver" for the PC. Then went to Google Play Store (yes, my Nexus 7 can still access it) and downloaded the Spacedesk app.  I connected the USB cable between the 2, set the tablet on file transfer mode, fiddled with it a bit, the driver software saw the app, and voila, I have a 4th screen. 

This will also work in Wifi, but wired is more secure and faster. 

My triple-wide desktop, now with a small 4th display.
I stuck my desktop widgets and other stuff there.  

The software is FREE for personal use. If you have Spotify or Stock Ticker or Weather, Clock, and so on, put in on that display for extra clean look of your desktop. 

And happy "Pi" Day. 

(3/14, get it?)

Sunday, March 9, 2025

Cybersecurity: Stop the Fake CAPTCHA Run Trap

Recently, there has been a spade of reports in Reddit's /r/cybersecurity of a "new" attack that relies on users being unaware of how their computer works, and tricked into executing a malicous script, by describing the attack as a CAPTCHA challenge. 

CAPTCHA stands for "completely automated Public Turing test to tell computers and Humans Apart". It's those picture tests where you need to answer certain question, such as "pick out the tiles in a segmented picture that contains a bus" or "which pictures has a motorcycle in it?" But later the term was genericized to mean any sort of "are you human" challenge test designed to weed out the automated scripts. 

The fake version asks the user to press Windows-R on their keyboard, followed by Control-V, to prove they're human. 

EDIT: The attack has been highlighted by KrebsOnSecurity and named "ClickFix" attack

If you didn't recognize these keystrokes, Windows-R (Win-R) brings up the Windows Run box, where you are supposed to enter a program to run. And Control-V (Ctrl-V) pastes what's in the clipboard into the whatever you have open. 

In other words, you just ran something, but you have no idea what. 

That is indeed... VERY bad. Because you basically just gave away control of your PC to the bad guys. And who knows what they'll do with it, probably download malware to your PC, steal all your accounts, and more. 

Given that 99% of the users will NEVER need to touch the Run box, you should disable it ASAP, esp. if you have computers being used by users who can be tricked into running this (very young, or very old)

To disable the Windows Run box, please follow this article: 

https://www.auslogics.com/en/articles/enable-or-disable-run-command-winr-box/

There are ways around it, but if you trained your users well (call me if you run into any errors you don't understand), you can stop them from trying to further compromise their PC. This is basically a barrier that says "are you sure what you're doing? Call me before you continue..." instead of blindly follow some malicious instructions. 

Conversation: Are You a Tattle-Tale?

Recently I ran into a couple scenarios that just annoyed the heck out of me, that I don't want to share any more info with that person, due to the negative reactions I got. I'll create a fictional but based on real life scenario below. Trust me, there's a lesson for everyone at the end. 

I have been going to the same barber for 20+ years. I know this barber is a bit expensive, ($25 for a haircut, vs the really cheap ones at like $8), esp. when you add some tip, but I don't really have to give any instructions or such. The guy and his wife (also a barber) know me. 

Anyway, ran into an acquaintance, who's a known miser, yet constantly ran out of money and had to borrow $30 from me. He paid me back, and I remarked, "Good, I just spent $30 on my haircut" since I also noticed he's sporting a new do as well. 

For the next five full minutes I get non-stop tsk-tsk about how I am wasting my money, his haircut was only 8 bucks, are you made of money, I make a lot more than you do yet so you're so spendy, you clearly don't need the money so can I borrow that $30 again, he got a free hair wash with that $8 too what a bargain, blah blah blah. Had he and I were not meeting more friends for lunch I would have ditched him right there. 

The harangue did not stop once other friends arrived and lunch started. He started replaying the entire "lecture" to every acquaintance within hearing distance, and he's not a quiet guy. "Oh, can you believe So-and-So spent $30 on a haircut? I only spend $8!"  You can probably hear him a couple tables away. 

I normally were not a cheerful guy, but I can hold a conversation in a group setting, do the social smalltalk, and so on. I am just not a social butterfuly, like the miser thought he was. But when I've been made the topic and the butt of the joke, I am sulking inside, starting to regret knowing this guy, and vowed never to talk to this guy again, and if I see him coming toward me I'd jaywalk to the other side of the street. 

So what's the takeaway? 

Don't be a tattle-tale. 

Miser may have thought he was offering useful advice or being helpful, but once he got started he failed to notice my counter-remark "I've been going there for years." And instead of leaving this between us, he turned it into a conversation topic with other people and I was made into a butt of a joke. 

Now that's just mean, and childish, and he's probably not even aware he's doing it. He's socially oblivious yet thought he's going sociable. 

Next time you receive some info, consider the context it was given. Don't be so quick to criticize, then repeat it to every acquaintance within reach. Not every piece of info you receive is meant to be replicated public knowledge, and you're not a broadcaster / newsreader (unless you actually are). 

Share something about yourself instead, not something you just learned about someone else. 

Thanks for coming to my TED Talk.