Started working on a new fun side project that involves lots of procedural image generation and hopefully ends up with launching my first Kickstarter.
Mike Buckbee
@buckbee.bsky.social
Dev+Founder+Dad -> Wafris, SendCheckIt, Knowatoa, ExpeditedWAF. Mostly post about cybersecurity and AI SEO stuff. Discover how your brand ranks in ChatGPT, Perplexity, and Gemini at knowatoa.com/bsky
Hit my Claude Code Max + Fable limits for the week so I'm trying Codex for the day. Any tips?
Added a cool little Referrer-Policy security feature to Expedited WAF this morning.
Today's experiment in model behavior: how well do frontier models actually follow directions? I gave GPT-5.6 Sol, Claude Fable 5, and Kimi K3 the same writing task with explicit rules, then added more rules each round: exact word counts, banned words, required phrasings.
Smartphones replaced a whole closetful of devices and now I think we're seeing the same with AI tools where they are directly consolidating big chunks of the software industry. I think we are going to see them become the primary "interface" for things going forward.
I've got a m2 air with 24gb ram, but it keeps feeling very constrained resources wise as I have a ton of virtual spaces and projects going in each. Should I just bite the bullet and get a mac studio and keep the m2 air for travel?
"Token Efficiency" is a scam. Take this comparison of glm-5.2, opus and sol. GLM is 3x faster and 10x cheaper...so why would you care even if it burned 100x tokens? (Made with Evvl)
Is it cheating to look up what something is in Connections or do you have to only go off your working knowledge?
Just shipped one-click unsubscribes for SendCheckIt's emails. Gmail and Yahoo have required this from bulk senders since 2024, and Microsoft's Outlook rules from last May expect an easy unsubscribe too. The entire feature is two email headers:
Ran the pelican-on-a-bicycle test across five generations of Claude on Evvl: Opus 4.6, 4.7, 4.8, then Fable 5 and Sonnet 5. Same prompt, one screen.
Codex + their security review skill has been really great at shrinking the surface area of my apps. Really helped slim down the number of unused framework features and extra packages that have snuck in over the years.
I've always depended on the ability to just pop down to the Apple store and buy a new mac if my Air ever died, but the weeks maybe months delays to get a new one are making me think I need a hot standby Mac?
Been orchestrating Codex security reviews across all my repos from inside Claude Code. Sounds like overkill. Is actually great — apart from the occasional "wait, am I hacking myself?" refusal.
Pretty sure DNS Is Beautiful (my lil side project) got mentioned in the Last Week in AWS newsletter, as the only other explanation for this graph is that someone is very, very gently DDoSing me. 370 unique visitors this week, up 825%. A month of flatline, then a cliff.
Cool to see that nearly 10 year old post on AWS in Plain English made it into the HN hall of fame.
One of the cool new features of DNS is Beautiful is that you can do TCP trace routes from around the globe on one page.
Spammers ruin everything. I've now had to silently block all email to sms gateway domains on SendCheckIt because of abuse issues. If you run an email service I suggest you do the same.
There are two different things happening at Google right now and search marketers keep mashing them together:
Can a visitor complete the task they came for on your site within 30 seconds of landing?
Most people, unsurprisingly, are not search professionals. They don't parse a SERP finely enough to tell an AI Overview from a featured snippet, a knowledge panel, or a "People also ask" box. They're all just gray boxes Google puts above the links.
Years ago I ran DemandGen at an enterprise cybersecurity company that was genuinely best in class for their niche, and we explicitly didn't publish side-by-side comparisons with competitors.
I see a lot of overlap between AI model hallucinations and the new paper that was just released on UGC and Reddit manipulation. Hallucinations are caused by a lack of data, and manipulation works for the same reason.
Search Disrupted Issue 37 is out 5 stories inside. AI hallucinations and Reddit manipulation share the same root cause. Lily Ray's data: self-promotional listicles recommend competitors 69% of the time. Pew says 60% of Americans read AI summaries (the real number is closer to everyone).
I've always liked Nick LeRoy's SEO writing and his SEO Lunch newsletter.
Matthew Prince, Cloudflare CEO, states that bot traffic is now 57.4% of HTTP requests on Cloudflare's network, versus 42.6% from humans.
SEO's need a new new mental model. For decades search was basically Google and I think a lot of people fell into a bad habit of describing search as a monolith. We're now at a point where you can't give generic advice for "search" you need to spell out exactly which system you're talking about.
It's kind of funny that in a world of ever-larger data centers, databases, data lakes, and AI-generated data, Google so rarely shares any new kind of search data. So it's noteworthy when they do.
We shipped a new guide this week: Knowatoa for Paid Ads Research. It walks through using the questions Knowatoa already tracks for your brand and your competitors as the starting point for paid campaigns, instead of a blank keyword planner and the same generic targeting your competitors are using.