Sign in

Connor Tumbleson

@blog.connortumbleson.com.ap.brid.gy
3 followers 0 following 59 posts

Ramblings of a Tampa engineer 🌉 bridged from connortumbleson.com on the fediverse by fed.brid.gy

PostsRepliesMedia
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 05/10/2026
As software evolves the default offering must be as secure as possible to protect the end user.
connortumbleson.com
Software & Secure Defaults
Photo by Franck / Unsplash A long time ago somewhere in 2015 I remember hearing about a bunch of MongoDB databases were wiped with ransom notes left. At first I was so curious how an attacker did this, then I realized it was just public accessible databases with no authentication. When you think about that - it's hardly a hack. Just a misconfiguration of a system in a highly insecure way. So what did MongoDB do? They changed the defaults to produce a more secure system by default (authentication and only binding to 127.0.0.1). As folks installed or upgraded their system the default setup was now way more secure than prior. The little downside however if you wanted to just work locally and test - you might have to configure stuff to make that easier. This became the term "Secure by default" which effectively means a product is resilient against popular attacks without any additional changes. A popular form of this gaining steam is a technique that a program refuses to execute if given too much permission. warning on aws guide If you were building an integration for AWS you might be tempted to just generate an access token for your user. Your user is presumably admin so now your system has immense permission when it probably only needed the ability to upload files into a bucket. AWS now heavily prevents you from using administrator keys putting prompt in front of prompt confirming you really want to do such a thing when generating a key. Nowadays a solution is even without keys using a form of OIDC to grant permission based on trusted systems communicating. If we look at the popular Mac software Homebrew, it takes a different approach entirely. If you try and execute it with too many permissions - it dies out. Error: Running Homebrew as root is extremely dangerous and no longer supported. This is pretty amazing, because now users not security inclined cannot make the mistake. Sure there is an escape hatch of commands you can do to bypass this, but for the most part the default is very secure. This is becoming the preference of software, secure by default with escape hatches if you need to reduce security. In the era of AI research I wonder how far that line in the sand can go. For example, on Apktool I've gotten over 10 reports now that all roughly start the same way. "_Assuming filesystem access, if we do x, then apktool will do y_ ". I close all of these because if you have access to the filesystem of course you can modify files that apktool might build into a malicious piece of software. Apktool acts as both a disassembler and assembler taking chunks of resources (`.arsc`) and sources (`.dex`) files to produce regular `.xml` and `.smali` files to tinker with. We can assemble those back into their roughly binary form, which means you have plenty of opportunities with filesystem access to do nefarious things. Folks probably aren't passing around disassembled applications to reassemble so the vector to be able to modify a file in the disassembled state means you have the ability to change files (or filesystem access) between two steps of a process. So as I get challenged as to whether accept a vulnerability or change functionality that has a prerequisite of file system access is quite a stretch for me to accept. Though, I started thinking about a different type of exploit that gets codenamed as "ROP chaining" which is basically an exploit that takes advantage of existing code paths for a malicious purpose. This exists in many languages as ROP/POP chaining and it basically can break down to the rehydration of a class object. In PHP that might be `unserialize()` and in Java it may be like a `YAML.load()` call. In both those circumstances you may be able to load existing code with malicious parameters that work in a way to become malicious. public ClassSafeConstructor() { this.allowableClasses.add(MetaInfo.class); this.allowableClasses.add(PackageInfo.class); this.allowableClasses.add(UsesFramework.class); this.allowableClasses.add(VersionInfo.class); } https://github.com/iBotPeaches/Apktool/pull/2760 At that point if we stretch our motto of "Secure by default" we shouldn't ever enumerate classes outside of what you expect. In the terms of Apktool, we only needed tiny little scalars (strings and more) so we disabled any class parsing to nerf this type of exploit. So maybe at times "secure by default" can be applied and other times it can't.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 28/09/2026
In a new era of LLM agents - is everyone a software builder?
connortumbleson.com
Are we all builders now?
Photo by Growtika / Unsplash A few years ago I was sitting at work using the newest AI tool (GitHub Copilot) that gave me the ability to "tab" complete a line. An LLM sat in the shadows predicting what probably would come next and often times it was wrong, but often times it was right. It felt like magic at that point because just a few characters into typing and the rest of the line might be automatically completed with a tab. I evolved into this engineer that could tab complete a line and then correct it slightly. In that timeline it felt like I was given a superpower that didn't break the bank. Now I can watch a non-technical person dispatch an agent that follows our code style & guidelines and produces a pull request that isn't that bad. Sure it needs some work as long as humans are still maintaining codebases, but it's crazy to think a few years prior this was unheard of. I remember this argument early on in my career of "_build vs buy_ " which basically means does a new client coming in the door have a solution available they can buy and configure or do they really need a custom built piece of software. Sometimes that's not the easiest research as you have to jump on sales calls and dig into a 3rd party piece of software before discounting it. All of this just being one of the things you'd like to do before you start writing code - a little discovery session. Now, as we countdown the months till 2027 the landscape of clients and requests have changed dramatically. No one has time for a lengthy discovery phase or research when you build a working solution with Claude in a few hours. This extends into my open source development just as strongly. You are getting bug reports & pull requests with an enormous amount of text that try and break down every little detail possible. Random fastlane PR - https://github.com/fastlane/fastlane/pull/30226 I'm really torn with all of this, because at one point that much context/research provided by another user showed they put some serious effort into understanding the problem & providing a solution. You'd look at that issue/pull request and think "_dang - this person did some work. I appreciate it_ " and reciprocate the effort in reviewing it. These days you'll have an influx of pull requests with confident robust descriptions and the only person that has to spend some human brain cycles is the maintainers. A GitHub account going full AI. You could toss in the towel and just let an AI manage your codebase, which is borrowing the production term "_lights out manufacturing_ ". The digital version of this is exactly what it sounds like - an LLM is the judge and jury when it comes to merges, reviews and more. There are a few of these approaching "lights out" I've been watching and the throughput is insane. There is no chance any human fully understands anything in the codebase anymore, but does any human need to at that point? I'm not yet at that level of comfort, because at the end of day if a system is catastrophically collapsing I'm probably getting involved at work. If I release a buggy build of _fastlane_ or Apktool in the open source space - I'm getting pinged. For that reason if I have to be the one to solve a problem I can't yet give up the ownership of the codebase to a machine yet.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 14/09/2026
After a year of visiting steakhouses and ranking them - we only visit 3 of them still.
connortumbleson.com
Tampa Steakhouses worth visiting (2026)
About a year ago Alyson and I had completed a trip to the top ten steakhouses in Tampa according to some random Tripadvisor article. We didn't trust their rankings so made it our duty to visit all ten of those and rank them ourselves. At this point a year later there is only 3 of those restaurants that we still frequent. All for the same reason that the steak is consistently unbelievably good among great service. There is only 3 on this list, so let's dive in. * * * #### Iavarone's Italian Steakhouse ****3617 W Humphrey St, Tampa, FL 33614**** Iavarone's is one of those buildings that has been around since the 50's so it's tough to know from the outside you are driving by a steakhouse in the middle of Carrollwood. It has a parking lot that is next to a massive dirt lot should things overflow which always leaves you with parking next door to the building with no stress. You just might have to deal with a bit of dirt/mud if it happens to be raining however. Once walking in you are greeted immediately by a friendly hostess that explains the bar / dining split of the restaurant. You get happy hour at the bar side, but with a service that is struggling to keep up with all the tables. Sit in the dining room and lose happy hour discounts, but have servers much more attentive to your table. There is a special for each night and rotating dinner specials that always tempt me to change from my usual order. However, most times if we arrive on the right day I'll get the prime rib which is prepared excellently. Pictured above is a medium-rare 12oz prime rib that came with au jus and horseradish sauce alongside a baked potato. You can always tell a prime rib is good when the fat has rendered and cooked down and this is rendered each and every time even when cooking on a medium rare temperature. A drizzle of au jus and horseradish to dip makes each bite just melt in your mouth. For the price $38 (80z) or $50 (12oz) you have some flexibility depending how hungry you are with the prime rib. Compared to other options that steaks start at $70+ it was refreshing to have an excellent steak at/or below $50. If we take a step back from the steak - the house salad is prepared table side in a bowl that is cold to the touch. Such a weird thing to call out, but it elevates the salad experience with a cold bowl and great dressing. It doesn't end there if we move to the dessert. Bananas Foster We love ordering the bananas foster which is something we've tried at Berns a couple times, but here at Iavarone's it actually impresses us each time. A great amount of spice and banana to ice cream ratio means you run out of banana about the time you run out of ice cream. Iavarone's is a few minutes away from my office and in the heart of a heavy residential area. We will continue to visit as the steaks are always prepared exactly to our specific temperature and melt in our mouth at a great price point. * * * #### The Capital Grille ****2223 N Westshore Blvd, Tampa, FL 33607**** The Capital Grille is one of those places that just because it sits alongside a massive mall always led me to believing it probably wasn't that great. I'm glad I ignored that when we forced ourselves to visit it during the 2025 steak visits. You may be walking up the mall in fancy attire, but once you enter the building of The Capital Grille the atmosphere changes immediately. It's quiet with bottles of wine littering the wall alongside low lights and plenty of staff waiting to take you to your table. They don't shy away from technology and provide a tablet showing every bottle of wine in stock. This allows you to learn a bit about the history and type of wine for those of us not fluent in wine speak. An assortment of bread and butters join for a little treat before the appetizers arrive. This place always has an assortment of chef recommend steaks and they all sound wonderful. Our menu in 2026 had: * Sliced Filet Mignon w/ Cipollini Onions, Wild Mushrooms and Fig Essence * Porcini-Rubbed Bone-In Ribeye with 15-Year Aged Balsamic * Kona-Crusted Dry Aged Bone-In NY Strip with Shallot Butter * Dry Aged NY Strip au Poivre with Courvoisier Cream So of course like pictured above I had to get the ribeye with the balsamic addition. This steak had an immense flavor and melted in mouth and stood on its own. I needed no horseradish or additions - just a plain ole rare steak and I was happy. The price is steep with $83 for balsamic steak, but in the 3 times we've gone I've gotten the same exact meal and been blown away each time returning an empty plate. * * * #### Bern's Steak House ****1208 S Howard Ave, Tampa, FL 33606**** Bern's is so good I've dedicated an entire blog in the past to it. I just can't believe how good the steak is or experience each time. We tend to always have the same waiter (Roman) and this guy is insanely good. He knows wine inside and out and knows everything about steak possible. This is a place that brings you lemons & limes balancing on the rim of a cup for waters. This is a place that cuts the skin of the tomatoes in your salad. This is a place that cleans your table of tiny crumbs as they occur to keep everything clean. It feels like a scientist or someone versed in food measured the sizes of each stage of the meal. The soup is small enough to warm up your stomach and get you ready for a medium size salad. These two starters come with every steak ordered which takes a $77 14oz ribeye farther than the other restaurants. I paid more for a steak at a different place and that's all I got. Here $77 got me: soup, salad, 14oz ribeye steak, 2 sides and a baked potato. The price is comparable when you start visiting other places around town, but getting to Bern's is no easy task. If you want to eat at a normal time between 5-7pm you are more than likely making a reservation 60 days out from when you want to go. Of course you can get lucky finding some capacity randomly checking, but for the most part this place is booked out for the dining rooms. You can always try your luck in the bar, but it won't be a true "Bern's" experience that way. * * * These places aren't the cheapest, but for every other month its nice to visit at least one of them. Some of reasons why we won't visit other places is listed below: * **Charley's** * A few bad experiences in a row with the atmosphere and servers questioning us heavy on what we want to order. * Getting challenged on steak temperature like we don't know what we want. * A steak alone on a plate and dry isn't great. * **Council Oak Steaks & Seafood** * As a non-smoker having to walk through a smoking section of a casino to visit is rough. * Another dry steak heavy in price. * **Ocean Prime** * Nothing steak wise we remembered, but we did remember spending over $300 for 2 people for some steaks. * **Tommy's Chophouse** * Weird experience with server challenging/bragging about everything they do. * Treated us like it was our first steak dining experience, but yet didn't know what horseradish was. * Didn't eat one item that tasted fishy and had server and chef all challenge us on why it was bad. * Ribeye was good, filet was dry.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 07/09/2026
A few months ago I wrote a blog post at work after us experiencing someone losing an API key to an attacker while only working locally. Long story short they used one of those services that temporarily exposed your local site to the public network to test a webhook. That process caused a new SSL […]
connortumbleson.com
A healthy amount of paranoia
Photo by Vidisha Sanghvi / Unsplash A few months ago I wrote a blog post at work after us experiencing someone losing an API key to an attacker while only working locally. Long story short they used one of those services that temporarily exposed your local site to the public network to test a webhook. That process caused a new SSL certificate to be minted and of course due to certificate transparency changes the creation of that SSL certificate put a record in public view. An attacker monitored that list and scanned the website, identified the service from a request or two, fired targeted checks and within a few requests exfiltrated a secret. The blog post dives into how we discovered a tiny security flaw in Laravel which was hardened via Laravel Sentinel across a few packages. The best non-malicious analogy I can align to that is when you acquire a home your mortgage/loan is semi public information. Companies will use that life event and loan information to urge you (the homeowner) for insurance or gifts and they work fast. You'll get these letters days after finalizing a loan for weeks to come. Thankfully in this case it isn't as malicious as a digital attacker working in seconds. https://arxiv.org/pdf/2602.15763 I started tinkering on some internal projects with GLM 5.3 and it was creepy how well this model targeted a system. Unlike existing non-AI solutions that just hammer every technique in existence - this model quickly identified its best guess of the underlying software (NGINX/PHP) from headers and source. Once it identified its target it worked quick to identify relevant vulnerabilities and get to work. It ended up finding a little gadget chain / serialization problem and I was impressed. This was a model I found from a tweet and put a few dollars down and messed with it. This was entirely available for anyone in the public which means the real security based models in private or behind countries is probably way beyond that in terms of capabilities. So that induces a bit of paranoia, because take the security mindset of offense/defense. Defense has to be right every single time - one mistake and the attacker wins. In the era of AI attackers they will take no breaks and work until a success arrives or money runs out. site selling residential proxies It reminds me that historically a website could defend itself pretty well by blocking countries at the IP address level. Depending on the service they may even block hosting providers or VPNs due to their known IP ranges in which they work. For most attacks that are nothing more than a sprayed generic attack across the web - you can't attack what you can't access sort of works. Except in the era of AI agents consuming as much data as possible and attackers needing to get more clever. There is an enormous market of selling residential proxies to bypass rate limits or blend in among regular residential traffic. It's a bit insane to think your neighbor may be hosting a proxy and making money no idea they are proxying an infinite amount of nefarious things through their home. Anubis & NGINX It's like when Leaf was going offline because over 110,000 unique IPs were totaling 4~ million requests against my Halo Infinite stat site. Barely 2,000 people played Halo Infinite in the past 24 hours so it's pretty much impossible to consider a unique ~100,000 people going to a 3rd party stat site. While most of these bots were working inside IP ranges that resembled AWS, Google Cloud or Azure a solid chunk were not. Are these services getting clever and proxying traffic through huge sets of residential proxies? At least in that case I could deploy Anubis to put a stop to the harvesting of data. It won't work forever, but much like blocking countries is only a barrier against the basic attacks Anubis works the same for AI bots. A good barrier to keep those AI agents away that don't want to do any extra work. I'm blown away that models continue to improve on what is probably still under the hood just Markov chains, but a bit of paranoia grows that we are leading to something more dangerous than we realize.
010
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 31/08/2026
Another year - this time 8 years with a Pi-hole on my network.
connortumbleson.com
Pi-hole: 8 years later
Pi-hole v6 homepage around year 8. In 2017 I installed a Pi-hole into my network and routed all my DNS traffic through it. Today is August 30, 2026 and I've been running it ever since. While I've lost the consistency of blogging exactly every year, this grows the collection of pi-hole posts on this blog. We ended the last blog post on the release of version 6 of Pi-hole, which was followed by lots of patches still living under the v6 tag. My versions now reported at the footer are: Core (v6.4.3), FTL (v6.7) and Web (v6.6). Things generally have their own tags now between the FTL software, the Core and the Web. So it became a bit more difficult to summarize a changelog of them all. Roughly summarizing each release into a few words to catch us up over the last year. * v6.0.5 (March 3, 2025) - Fixes for high RAM/CPU usage & slowness. * v6.1 (March 30, 2025) - Hundreds of bug fixes. * v6.2 (May 30, 2025) - Upgrades to tools, bug fixes, cleanup. * v6.3 (October 25, 2025) - TLS & CSP improvements, security fixes. * v6.4 (November 27, 2025) - Optimization & API improvements. * v6.5 (February 17, 2026) - FTL enhancements for speed. * v6.6 (April 3, 2026) - Lots of AI security fixes & Gravity fixes. * v6.7 (July 6, 2026) - Security fixes, new DHCP lease editor and more. If we summarized all those releases - things have stabilized as a product. There was no more flashy changes or rewrites. Just hardened, bug fixed products polished on optimizations. For something I entrust with all my DNS queries I'm happy for a stable product that I can trust isn't siphoning my data to sell. Like I mentioned in the past the public feedback around Pi-hole has kinda shifted from my perspective. I can understand the reasons, because you have Pi-hole which has built a large chunk of its functionality on top of dnsmasq in low level C, then wanted to remove dependencies on PHP & lighttpd so introduced more C with civetweb. The talk around town was memory safe languages, security and more and Pi-hole got caught with a lot of security issues in languages not a lot of people felt comfortable in helping with. A comparison of self-hosted DNS ad blockers This wasn't a bad thing because in the rise of AI - every project was finding things to fix. It just gave a chance for other services like Adguard, Blocky and Technitium to boost their marketing in the areas that Pi-hole suffered. Those alternatives rocked languages like .NET and Go which was a bit more attractive than a custom C codebase heavily maintained by one guy. Though I'm not here to switch solutions or attack an open source project I've been donating to for years. I'm happy for what it does and will continue to use it. We wouldn't have gotten Gradle without Maven/Ant and we wouldn't have gotten Vite without Webpack/Gulp. Pi-hole started something allowing all these other projects to gain inspiration and thus exist. Since the v6 release the tool PADD (Pi-hole Ad Detection Display) has been fixed, but I don't really use it anymore to have any actionable feedback. `./padd.sh` A cool amount of stats which shows that roughly 10% of my traffic is blocked. With roughly 1.5 million domains on my blocklist though that seems less than I would expect. PADD hints at some stats, but they were never enough to scratch my itch. That is why I built Pi-Stats for long-term storage for my Pi-hole. I signed into the Raspberry Pi that hosts it and sure enough it's still working just collecting data into a MySQL database. I jumped into a console session and executed `php artisan stats:dump` and waited a long time (14 hours). +--------------------------------------------+-----------+ | Domain | Count | +--------------------------------------------+-----------+ | e7bf16b0-65ae-2f4e-0a6a-bcbe7b543c73.local | 5,631,937 | | 68c40e5d-4310-def5-a1c3-20640e1cd583.local | 5,305,150 | | 1d95ffae-4388-9fbc-1646-b2b637cecb64.local | 4,898,205 | | localhost | 4,461,025 | | 1.1.1.1.in-addr.arpa | 2,061,743 | | ping2.ui.com | 1,528,752 | | ping.ui.com | 1,509,934 | | www.gstatic.com | 1,486,086 | | 806c4c48-1715-4220-054f-909f83563938.local | 1,342,386 | | 8.8.8.8.in-addr.arpa | 1,203,524 | | api-0.core.keybaseapi.com | 1,184,543 | | b.canaryis.com | 1,127,482 | | 168.192.in-addr.arpa | 1,061,695 | | pistats.ibotpeaches.com | 1,050,674 | | ui.com | 909,261 | +--------------------------------------------+-----------+ Top 15 allowed domains over the network. Everything here looks to be expected. The weird multicast domains from an older Mac, the Hue lights and Keybase. Its crazy Keybase is still up there - its from that flaw they had a few years ago when an SSL cert expired. The application just never stopped pinging domains in an endless loop, thus racking up a million requests until I noticed and upgraded it. +--------------------------------------------+---------+ | Domain | Count | +--------------------------------------------+---------+ | 806c4c48-1715-4220-054f-909f83563938.local | 803,900 | | e7bf16b0-65ae-2f4e-0a6a-bcbe7b543c73.local | 638,460 | | ssl.google-analytics.com | 509,615 | | app-measurement.com | 455,434 | | 1d95ffae-4388-9fbc-1646-b2b637cecb64.local | 432,008 | | logs.netflix.com | 317,313 | | androidtvchannels-pa.googleapis.com | 300,860 | | mask.icloud.com | 275,727 | | 68c40e5d-4310-def5-a1c3-20640e1cd583.local | 247,892 | | watson.telemetry.microsoft.com | 217,743 | | googleads.g.doubleclick.net | 200,577 | | trace.svc.ui.com | 165,314 | | g.live.com | 149,472 | | beacons.gcp.gvt2.com | 138,396 | | beacons.gvt2.com | 133,649 | +--------------------------------------------+---------+ Top 15 blocked domains over the network. A new domain to the list was iCloud, but in the last year I purchased my very first Macbook and Alyson moved in with an iPhone as her personal phone. I'm guessing either of those led to an influx of iCloud domains being blocked. The rest is normal ad blocking with Netflix, Google, Hue and Microsoft stuff. Happy to see I'm not contributing more and more of my usage/information on top of already paying for most products up there. A new feature to Pi-Stats was to dump out the domains per year since looking purely at the all time was reluctant to change. That single multicast issue caused million of domain requests which will take a few years to bounce out of there. I'd rather not do a partial year so I'll do an all-time and 2025 breakdown this time around. Year: 2025 Top 5 Allowed Domains +------------------------------------+---------+ | Domain | Count | +------------------------------------+---------+ | ui.com | 281,529 | | 1.1.1.1.in-addr.arpa | 240,923 | | ping.ui.com | 177,842 | | ping2.ui.com | 155,417 | | agent-services.prod.cavelodata.com | 143,044 | +------------------------------------+---------+ Top 5 Blocked Domains +-------------------------------------+--------+ | Domain | Count | +-------------------------------------+--------+ | mask.icloud.com | 80,981 | | mask-h2.icloud.com | 80,262 | | androidtvchannels-pa.googleapis.com | 76,159 | | logs.netflix.com | 70,922 | | api.segment.io | 38,790 | +-------------------------------------+--------+ 2025 Requests summarized. I didn't recognize "_cavelodata.com_ ", but it appears to be a domain used for protection of work machines. I know the software we use at my own work, so this is probably something on Alyson's work computer. iCloud, Netflix and Android TV analytics lead the charge on the 2025 view and it makes sense. We have an NVIDIA Shield and that's where we watch all of our TV, with a bit of Netflix. Running these reports on a little Raspberry Pi with 100's of millions of stored records is no easy task. I'll have to brainstorm an even better solution of storage for the future. I probably don't need to recalculate older years once done, so I'll expand the DB for a yearly breakdown. I might rethink the setup entirely perhaps with a domain table having a count alongside first/last seen date. If I can move the work to insert time instead of query time - it'll be much easier to run reports on the data. OPNsense running Wireguard to have Pi-hole on the go. For now with Wireguard routing my laptop and phone back to my home network where my Pi-hole sits. I gain the benefit of no ads no matter where I'm at. I once accidentally forgot to active my VPN and I forgot how terrible the web is without blocking ads and that's only what I can see! Who knows how much metadata is being harvested to fingerprint your device on advertising requests to 3rd party systems. I'm happy I have Pi-hole keeping me protected at home or on the go. * * * Pi-hole has probably stabilized in terms of features, but I'd still recommend it for a local personal network. I'll try and remember to do a year 9 update a bit more on schedule next year.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 24/08/2026
In the early part of 2026 I gave a talk at a local meetup about how I am using AI in the workplace. That was 9 months ago and it's a bit crazy the trajectory we are on and how much AI I leverage in the day to day. If I started with the morning of work I normally roll into the office with […]
connortumbleson.com
An Engineer with AI
The original graphic produced via a Sourcetoad Employee In the early part of 2026 I gave a talk at a local meetup about how I am using AI in the workplace. That was 9 months ago and it's a bit crazy the trajectory we are on and how much AI I leverage in the day to day. If I started with the morning of work I normally roll into the office with anywhere from 80 to 200 unread emails. Thankfully most of those emails are just the GitHub notification emails from changes from our Australia office from their day and our night. I can skim subject lines and quickly see the files changed directly from the email so I know if it's anything I want to go visit (CI/CD changes, package changes, Docker changes, etc). I'm sure AI could help here, but with keyboard shortcuts 10 minutes every morning isn't the end of the world. Gemini Summary What remains after that is mostly client emails that Google (Gemini) has summarized on top. In the beginning I really hated that AI was taking up vertical screen space for a summary that I could already glean from the subject line. However, there are a few email chains each week that float over 100 emails in the thread and since those responses might come days apart that Gemini summary is very helpful. It isn't always perfectly accurate, but it's just enough context to allow my brain to remember what the last few responses to the thread have been without having to re-read. A few of those emails are client requests, support requests or things to dig into. With GitHub and items I feel pretty confident an AI can do unguided I can dispatch a Copilot agent to go fix/change something in the system. The beauty of this process is I'm not limited to a single occurrence. I can dispatch as many as I need across as many projects as I need so a Monday morning might reach double digits of agents running at once. Dispatching Copilot on a personal project. Now you have to be realistic here that I've only moved a bottleneck. If we once had a bottleneck in understanding a request and getting it front of an engineer to code, now I've just loaded up engineers with a ton of code to review. Thankfully in most cases if you balance an agentic workflow with tasks your gut says an AI can do without human support the ending result is probably a small pull request. So after my email queue is done, I might have dispatched a ton of AI agents doing small requests that I'll continue to follow up on until I'm happy with them or I determine AI cannot help us. Which leads me to either taking an item across the finish line myself, closing it out entirely from AI's turn or pass to a queue for a coworker. The work that remains at this point is usually just questions or tasks that have no code associated with them. I have found extreme support on either OpenCode or Claude Code for these tasks. OpenCode At one point I had to do a bunch of stuff with Android applications on a device. I knew what I had to do, but I gave the instruction set to OpenCode and it communicated with my connected device and knocked the task out. I was even happy it asked a few questions along the way thus knowing it would be done exactly as I wanted in a fraction of the time. This is a dangerous amount of power, because I wonder if my skills are atrophying by these actions. It's an interesting slippery slope I feel is developing. I just don't feel I have the right way to describe it yet. Engineers have existed for a reason, but I've met a few friends who've lost their job to what they believe is an AI revolution. It's tough to know what to believe - an AI makes me more productive and quicker than I've ever been. Though some believe all they need is AI instead of a human and some believe they are building the solutions that will remove their own job. Claude Code So when I sit there invoking Claude Code or OpenCode, while babysitting some GitHub Copilot PRs while obtaining emails from meetings summarized by an AI it seems like my job has massively changed from what it once was. I may be an orchestrator of agents, I just have to be careful that I still understand what they are doing. Since at any moment the AI's could go away and I want to remain sure that means nothing to me except a decrease in productivity.
010
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 17/08/2026
Dining at the Michelin star omakase dining experience at Kosen in Tampa.
connortumbleson.com
Dining @ Kosen in Tampa
Official shot from https://www.kosentampa.com/gallery As my birthday neared I told Alyson I want to visit Kosen - a Michelin star omakase fine dining experience. As August 15 rolled around it was time to visit and experience the summer menu as well as both of our first visits ever to this restaurant. We got there roughly 10 minutes prior to reservation and they had us sit in a booth at the bar waiting until we were invited into the dining room. Roughly at reservation time they announced people by name to walk them to the dining room and even helped push in your chair for you. Sitting in Chair 1 alongside Alyson in Chair 2 We were first to be called and had the first seat, so I was pretty happy I'd done one of these before. In my very first omakase I appreciated being able to look to my left on the basic things like etiquette, so this time I might expect any newbies to look my direction for support. After an introduction of the staff and drink orders the 7 others alongside Alyson and I saw the first dish being placed. Course 1-6 - "Hassun" The first appetizer started off with a little box known as a "Hassun" which in Japanese culture is a tiny appetizer sampler box with different small dishes. We had: * **House Spritz** - A lemonade / ginger drink to cleanse palate. * **Oyster** - Oyster resting on coffee beans with a oil/lemon mixture. * **Toro Tartare** - Minced tuna topped with caviar. * **Ebi** - Shrimp with some gelatin / ikura. * **Sawagani** - River crab deep fried until very crispy. * **Sashimi** - Tuna with chives and garnish. I ate & drank most dishes pretty quick until I had that little crab left looking at me. The couple next to us saw Alyson and I contemplating the crab and she was as well. We all agreed to eat it in one bite and sure enough we did - it just was very crunchy. As we were eating the appetizer we could watch the chefs prepare fish so it seemed like the Nigiri courses were approaching. Courses 7-11 of Nigiri There was a 5th fish, but I forgot to take a photo right after the appetizer round. So we had 5 fish to try: * Shima Aji - Basically a striped jack. * Kasugo - A young sea bream, the older one is white fish. * Isaki - The chicken grunt. * Aji - Horse Mackerel. * Kinmedai - Splendid Alfonsino. In the moment I didn't really know what any of these fish were, but after some research its clear each fish has some form of "_highly prized_ " terminology in association with it. It makes sense with the price we paid that every fish was at a tier above anything we normally eat. The staff explained that fish was flown in from either Japan or South Korea for most items. It's tough to explain how good each bite was as a combination of wabasi, rice, fish and soy sauce. The amounts of each ingredient perfectly balanced by the chef building everything by hand resulted in an amazing dish. Course 12 - Yakimono The 12th course was a grilled shellfish alongside a compressed honeydew with a jalapeno sauce. The explanation here was so interesting that immense high heat against the scale of the shellfish caused it to flare up and become a little crunch on top of an amazing flavor. Course 13 - Sakamushi The 13th course brought forward another cooked fish with a zucchini blossom & Yuzu Beurre Blanc. The sauce tasted like a combination of vinegar/lemon/butter to make a sauce that I had to dip everything on plate into. Paired with a perfectly cooked fish alongside some zucchini chunks. Finally, the flower was stuffed full of flavor and I was amazed how fast it was gone from both my and Alyson's plate. Courses 14-18 - 2nd set of Nigiri My favorite part of an omakase struck again with 5 more fish. This time we had: * Hotate - Scallop * Kanpachi - Amberjack * Akami - Lean Tuna * Toro - Fatty Tuna * Uni - Sea Urchin I've had some really bad Sea Urchin before such that I thought it was all acidic, but this time I had no complaints about it. The tuna though is what I was waiting for, which had to be the best tuna I've ever eaten in my life. It was like a steak that melts in your mouth, but this time a fish. The perfect amount of wasabi and soy sauce did not steal any flavor away, but instead just elevated all the flavors. I wish I could go to an omakase that was all tuna. Course 19 - Duck The 19th course was duck alongside petitis farcis (stuffed vegetable), summer squash and chanterelle (expensive wild mushrooms). Watching the staff delicately prepare 9 of these meals in front of us was quite the sight to witness. From slicing the duck to balancing mushrooms and making sure each plate looked identical is probably what leads to a Michelin star. Course 20 - Wagyu The last non-dessert course was Wagyu with Seminole pumpkin, pain perdu (french toast) and black truffle. I don't think I've ever experienced such a high grade of Wagyu before and having just 2 bites left me yearning for more. Fortunately this was at the end of many dishes so I wasn't that hungry for anymore food. It was the first time I had ever eaten A5 Wagyu and it's tough to explain how much fat was perfectly marbled and thus melted away for a perfect slice of meat. Course 21 - Gelato It seemed we had hit the end and Course 21 was entering the desserts with black sesame gelato alongside some blackberry spread. It was the perfect dollop of gelato to close out a solid 20 pieces of food. The plate was chilled and felt like volcanic rock which was such an interesting way to elevate a tiny serving of dessert. Course 22 - Baba We thought it was over, but another dessert via course 22 came out with Baba (yeast cake) with chantilly (cream) and passionfruit blossoms. This was probably one of the larger courses which filled us up with cake and cream to end the journey. It was the perfect amount of dense and light at the same time which is difficult to pull off. As desserts were cleared staff brought out checks & menus to recap the dining evening. The Menu (delivered at end) It was interesting to get the menu at the end, because I had lost count of courses during the event. Alyson and I completed all the courses and a bottle of wine for a birthday dinner - one to remember for a long time. At $295/person though it's not something we will probably do until a major celebration comes knocking again.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 10/08/2026
The third trip to Kansas since the blog was started, this time for my own bachelor party before my November 2026 wedding with Alyson.
connortumbleson.com
Travel Blog: Kansas City (3)
The Bachelor House (Airbnb) in Westport, KCMO It had been a long set of years, but I was finally returning to Kansas City (my hometown) for my own bachelor party. I am getting married in November of 2026, so it was my turn for a little bachelor party of my own. The trip started on Thursday August 6, with Alyson dropping me off at the airport for a 9:55am flight. Like my luck it was delayed until about 10:35am so I started off the weekend with a very tiny delay. A few TV episodes later I was landing in Kansas City to an airport I no longer recognized. The new airport that started in 2019 was finally operational by the time I returned in 2026 and boy it was something to see. https://flykc.com/new-terminal-project It doesn't give it justice for one my phone photos, but this terminal was insanely cool. For a split second when I de-boarded the plane I thought I got on the wrong plane, because I did not recognize the airport. The ceilings were so high and everything looked clean and pristine. The bathrooms had digital numbers on the door that counted how many stalls were available, with the numbers live updating as I looked at it. Though I was comparing in my head an airport built in the 70's to one that was completed 3 years ago. Once the rest of the bachelor party crew arrived we met up at one friend's house to grill some burgers, have some drinks and start the party. It had been a very long time since I had taken off time from work such that hanging out on a Thursday was such a fun break from the constant work action. Once 4pm had passed we could check into our Airbnb which was in the heart of Westport, KCMO. https://www.airbnb.com/rooms/24155963 An area of town that wasn't quite as developed back when I lived in Kansas, but it seemed tons of areas (Crossroads, Westport, Midtown) had been expanded with activities since I last visited. The Airbnb exaggerated the listing a bit, but the owner of the unit had plenty of other homes. It probably was just flipped to be a rental and it showed - nothing to complain about, but the early days of Airbnb when it was actual shared homes was way cooler. As we got situated we were a couple minutes away from a wing place, so it was time to do a Hot Ones Wing Challenge. For those out of the loop - increasingly hot sauces over 10 wings. The sauces & place we obtained 50 wings from. Some of these wings the sauce was so hot that I was in pain, lips on fire and no amount of water, lemonade, mac n cheese or ice cream could quench it. Time healed all wounds for this brief pain and we completed the challenge after consuming a large amount of liquids. Once we recovered it was time to relive some old days and boot up an original Xbox that was still rocking an Xecuter 3 modchip. Alongside that we had 2 Xbox Series X's and a Switch 1. It was pretty fun trying to super bounce on Halo 2 and playing copies of my Phantom Mappack I made all these years later. Collection of possible dusty old & new consoles. Thankfully the house had a router just sitting on the floor in the dining room, which helps reinforce the type of rental this was. As no one actually living in this house would just have that setup for their network. For us that was beneficial so we could run a long cable from that to the living room to grant Internet to our consoles. The night went long playing Halo 2, Halo MCC, Super Smash Bros and more. Reminiscent and nostalgic of the childhood of how much gaming in person we did on a variety of games. Today that is replaced with Discord and online gaming, but it was fun to return to the era of gaming with friends in front of a TV together. We hadn't done anything like that in over a decade. I was up way past my normal bedtime consuming way more alcohol than I normally do, but it was a great night of gaming with friends. 2 mile run through Westport and Mill Creek Park The next morning I got up with roughly 5 hours of sleep and went out for a calm slow 2 mile run in the city. It was an interesting route to take because it was basically downhill the entire way to the end of the Mill Creek Park, then I had to run back up the incline all the way back home. Looking at Garmin though I am only talking about ~170 feet of elevation change between high/low point of the run. Day 2 was now here and I was still roughly in the dark on the activities planned, but I knew mini putt putt was one of the activities on the day. This was a place known as Puttery, that was an indoor mini golf & restaurant & bar in one. Course at Puttery in KCMO We did an eat & play combo, so we could play as much golf as we wanted while getting a $25 (or less) meal covered. It was my first time at a Puttery and it seemed like the courses were really small. Each course was 9 holes and sometimes a hole was barely 10ft between start & end. As the picture shows above you twist/turn among holes alongside a bunch of other people doing the same. What was cool is the technology in play for recording scores, since at the first hole you enter names and input score. Your names are waiting for you at hole 2 and onward. I wish Florida golfing places did this, because it prevented the need of holding a pencil & paper. So we did all 3 courses (27 holes) that the location had to offer and then grabbed a meal at the restaurant. Korean Bowl & Puttery The Korean bowl stood out to me, which took awhile to arrive but it was a great lunch in a pretty cool building. We were in walking distance of most of these places so we could walk back up to 39th street and get back to our house to prepare for the next activities. As we did a bit of gaming more of the friends disappeared all grouping up upstairs, leaving me alone downstairs. I had an inkling something was going on, but I also needed to clean up a bit before the bars, so went up to my room to change. When I came down all 4 friends were in different rompers (a shout out to my romper attire behavior) with a 5th one for me. I'm sure wearing a romper in public was probably the most nerve wrenching thing most of those friends did recently, but we rolled 5 rompers out into the city for a bar crawl. We started at Casual Animal Brewing which started the rush of people either staring or talking to us regarding our outfits. We played darts and enjoyed a few rounds of drinks before we went off to another place. We arrived at Border Brewing Company which had a nice indoor/outdoor split with a guy selling burgers. They had a homemade seltzer here that tasted like pink lemonade and it was my jam. Vibetown Burgers inside Border Brewing Company It was fun watching a guy make smash burgers while drinking, but it was a bit too early for more food. This was a cool outdoor area covered with shade, even if it attracted a few people smoking here and there. It made sense once I realized that Missouri legalized weed, which explained why a smoke shop could exist on every street corner with a whiff of weed in random places. It isn't an exaggeration that standing in place I could see 4 different smoke shops while walking on the road. I guess the rush of the legalization made an influx of new smoke businesses, but boy I would hate living near them as their massive LED bright colors seems like such a turnoff for the area. Our 3rd place was Brewery Imperial and we sat outside in some hotter weather while enjoying a round or two. The night was getting darker so we had another bar planned deeper in the city. This is where we learned First Friday was occurring, so there were people & vendors everywhere. We walked out a place or two just trying to find a place for 5 that allowed us to actually hear our thoughts. We found a table at Up Down outside, but outside was competing with insanely loud music across the street setting off car alarms (probably from the bass) constantly. Being in my 30's now the idea of being at a bar as the night fell shoulder to shoulder with people wasn't really my cup of tea anymore, so we left to head back to Border to get a burger which thankfully was not busy at all. Unfortunately the burger guy had left so we were floating around 10pm without a burger. Thankfully being my bachelor party we saw Cosmo Burgers across the street and ordered a smash burger or two. We could eat the burgers in the existing bar so we enjoyed a late night snack and more drinks before ultimately ending our bar crawl there. It was a night of all ciders & seltzers for me & plenty of people sparking conversations with our group due to our attire. Like had become a pattern we got back to the house and gamed a bit more as people fell off to sleep. The 3rd day arrived and I muscled the energy to go on another morning run despite only 4 hours of sleep. 3 miles in Westport I ran the same exact path as the previous day, but to my surprise as I approached Mill Creek Park I noticed an official race going on. I slipped onto their track and did 2 loops before heading back to the house. I'm sure no one noticed and it was fun to run alongside a couple hundred people on a nice recovery pace after little sleep. It was only once I got home did I realize what I stumbled upon - an ultra race! This ultra was doing 4 laps of the track (roughly 4.1 miles) within an hour. If you completed it in-time you could rest with whatever remaining time there was until the next hour where it started again. I learned those competing in the "last man standing" were running in a different direction than the others. So now I felt a bit bad running among folks who were competing in a challenge. Not Your Mother's Cobb Salad @ Snooze After a morning run and a bit of morning gaming we went out for brunch at a local place called Snooze. It was the first place we visited that weekend that felt like a new physical build out construction wise. All the other places seemed to be built within rustic existing buildings of the past, Snooze felt like a newly built modern structure. Their menu was interesting and I stayed away from alcohol with a little recovery salad after two days of heavy drinking. Our next activity was an escape room that was rated 8/10 difficulty with a 60 minute timer. We had a couple first timers to the escape rooms with us, so it would be interesting for sure if we could even escape. Since from my experience of an 8 person work escape room - sometimes more people makes it worse. For traveling to this area we walked to the street car and took it for ~25 minutes all the way to our destination. KC Streetcar There was a street car for both directions on opposite ends of the road which was fast and air conditioned. It seemed very well managed, because at one point an odd individual boarded the train and by the next stop police were onboard escorting him off. As we got closer to the River Market the amount of people on the train grew massively. We got off at our spot, but were in this awkward spot of being like 25 minutes early. There isn't much to do when you are early for an escape room so we slipped into a bar next door for a quick drink. However that service for 5 drinks was pretty terrible - we only got our last drink with minutes left till we had to leave. Regardless, we slammed a single round and made it just in time for the Patient 57 escape room. Patient 57 room at Breakout KC We struggled a few times yelling colors and positions back and forth between rooms as we tried to decode a Cyrillic alphabet. We got to slowly solve puzzles and expand access (secret doors, etc) to additional rooms with more complex puzzles to solve. Though we pushed through and solved it in 42 minutes and 17 seconds. No where near the record of 33 minutes, but we had fun solving the puzzle. Roughly my feedback regarding this room was: * Some things opened silently. We missed a few times that something opened, because it made no noise. * The keypads never illuminated a different color once solved, so if I missed a friend solving a puzzle their keypad didn't indicate that. All minor critiques that stem from the different experiences you get from different escape rooms. Much like doing a CTF digitally you can burn too much time on something irrelevant and we probably lost most of our time digging into something that was not part of the puzzle. Like the most embarrassing being we were standing on a carpet that had a key to one of the puzzles underneath it. Q39 BBQ Bag Since we were staying on 39th street and Q39 was on 39th street we got some BBQ before our final activity. I failed to take a photo of any food from this venture, so instead a picture of the bag from our barbecue experience will have to do. The brisket was amazing, nothing Florida BBQ still has any chance of competing with. It was interesting to hear from the locals that the favorites I once knew (Joe's and Jack Stack) quality had declined compared to the rising Q39. With food eaten we were preparing to head to the casino, which I think would only be like the 3rd or 4th time I've ever been to a casino. This time being my bachelor party I set aside $200 to gamble with and probably lose. The friends started at the craps table, which still is mega confusing to me outside of the main bets. As money was mainly lost I slipped away to find a fun slot machine. After a bit of trial and error I was down $70 and found this Athena machine. A random "Athena" slot machine. This one seemed interesting because I actually understood how it worked by seeing someone else playing it as I walked by. You try and get this picture of Athena in row 1, which then spawns a mode where you get the real money. Alternatively if you get 3 owls - you get that a bunch of free spins depending on how many owls are visible. So I took my remaining $30 bucks, loaded in my last $100 and started spinning. The true embarrassment is I left the casino losing all $200 dollars, but at one point I won $157 while sitting at $194, so I was net positive and then won the mini or micro jackpot after winning 15 free spins on a $6 spin. I was at one point sitting at $640 dollars (so net positive $440) and gambled it all away. Oddly my machine broke and said "need attendant" when I was sitting at $640 so I sat and waited. Staff approached and fixed the machine and then I lost all $640 on $6 spins. Pretty insane how fast you can click a button and lose $6 looking back at it. Mad at myself for not walking away, but I kinda assumed any money I withdrew was going to be lost anyway. A couple of drinks of liquor in probably didn't help either. There was a lady sitting at a slot next to me that was in an automatic wheel chair and could barely move probably high up there in the age, but she opened this box and there had to be thousands of $100 bills in there. Casinos wouldn't be everywhere if they lost money, so any time I see a high roller it just doesn't compute in my mind. It just seemed crazy to me watching someone load 100's into their slot machine like candy. I felt so uneasy just putting $100 into a single machine. Though I understand its not fun doing penny spins when a jackpot is then only dollars - you gotta spend money to take a chance to make money. As our agreed funds were exhausted and all the mockery ended of losing $640 we decided to head on home. Like had become a pattern we got home late and gamed into the late night on a variety of games. 5 player Super Smash or Mario Party was always a good time. Drink @ Martin City Brewing The 4th and final day arrived with a checkout at 11am with a direct flight to make it back home. A workout was skipped because chaining multiple days of little sleep together put a number on my legs. We cleaned up the house and went back to Leawood, KS for a last brunch before going our different ways. There was way too much alcohol and drinks leftover, so we were well stocked. A good recap to the end of an amazing bachelor party while enjoying a brunch at Rye. Once everyone split I had one last Gin drink at Martin City Brewing before starting the Uber trip back to the airport for a flight home. Much like sometimes on the blog, I'll be traveling home during the scheduled weekly post time (10:30pm) so how I got home will remain a mystery. Rest assured - I probably made it home, you just don't know when or how.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 03/08/2026
An annoyance became another homeowners task to knock out. This time fixing a leak on a dual flush toilet.
connortumbleson.com
Fixing a Dual Flush Toilet
Claude building an SVG of a diagram of the dual flush toilet. For about 6 months now Alyson and I have been dealing with a toilet that sometimes leaks water into the bowl and thus has to fill up the tank again. We found some workarounds that made no sense (twisting the valve) and it bought us enough time till this weekend. Now this is a toilet system that I've personally never seen or dealt with at any point in my life till now. I grew up with flappers and this toilet has no flappers inside of it. Thankfully the lid had the exact model and details on common replacement parts for it. Fluidmaster Dual Flush - Glacier Bay Sadly that QR code goes to "_Sorry, the campaign associated to that code has been completed. As a result, this QR code is no longer active._ " Which was very upsetting to start the investigation with. If you are printing long term physical labels - you'd probably want to be sure your short link / QR code logic is sound and not dependent on some 3rd party. If we took a picture looking down into the tank - we had a solid idea of what the problem could be. Looking down into the tank. The very bottom of the tank had a seal that looked frayed and any physical contact against it led to it immediately disintegrating. We assumed that seal with the base was probably not doing its job anymore and letting a tiny stream of water leak back into the bowl. We just didn't know what that piece was called as the parts called out on the label was the fill valve, flush valve and the seal on the actual removable middle piece. It seems the seal we were trying to fix was anchored to the base part of the flush valve. So we did some research and finally found the instruction sheet for the model we had. Snapshot of Instructions attached below. Fluidmaster 830VBGB 3" Dual Flush Value InstructionsPART# 25-1332, Rev2830vbgb_instruction_sheet.pdf333 KBdownload-circle This had a little arrow calling out the rubber gasket, which made sense as to the part we wanted to replace. Sadly this meant the tank was going to have to come off the toilet. This was the first time I've ever removed a toilet tank to repair a leak. You'd think after finding the part you'd need replaced that it would be easy to obtain. After a trip to Ace Hardware (up the road) and Home Depot (15min away) I gave up not finding the part I needed. Everyone was very helpful and always had the "tank-to-bowl" part, but I needed the gasket that sat above the locknut on the bottom piece of the flush valve. I wasn't really confident myself on what I needed, but a few staff were, but at the end of day what I purchased did not work. Seals purchased that weren't right. After purchasing 3 wrong seals it was time to just rebuy the exact same flush value we had (830VBGB). This wasn't available in any store I could quickly drive towards, so we did next day delivery and marked that toilet out of commission. It didn't seem possible to buy the exact seal I needed in our research. Thankfully buying 3 wrong seals didn't even pass $10 combined. Replacement 830VBGB ($30) The next day the part arrived, so we turned the water off and got to work. One thing I quickly noticed is while this was the exact same part I presently had it surely wasn't identical. The plastic molding was different, the colors were different, the locknut was shorter, but it was effectively the same thing. It reminded me how there was like 8 different original Xboxes, even though they were all marketed as the same. I found the seal hooked to the new part in a way that didn't seem like it wanted to be removed. So this repair became way simpler - just replace the entire valve. I used every new piece in the kit, which is where I continued to notice the differences between identical units years apart. left (old) vs right (new) So we got to work threading the new valve through and tightening it up. This new gasket/seal was so much larger compared to the non-existent thing we removed. Who knows if that was just manufacturer improvement or decay on my old one. After painfully connecting so many washers, bolts, locknuts, gaskets and more we carefully turned the water back on and waited. The tank filled up and it was silent. We flushed the toilet a few times and waited after it refilled and reconfirmed silence. We sat on the bed and scrolled social media in quiet just watching for the noise of the tank refilling and it never came. We conquered a toilet problem after complaining about the Fluidmaster support process, building the wrong parts and finally just buying a full replacement. It wasn't what I expected to do for most of the weekend, but now I feel a bit more comfortable repairing a toilet.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 27/07/2026
On July 26, 2026 the Tour de France ended again. This time the winner was solidified for a 3rd year in a row of Tadej Pogačar of UAE Team Emirates.
connortumbleson.com
2026 Tour de France
https://www.letour.fr/en/stage-21/image-gallery On July 26, 2026 the Tour de France ended again. This time repeating the last stage of the previous year with the modified Champs-Élysées course. The winner was again Tadej Pogačar who has now claimed wins in 2026, 2025, 2024, 2021 and 2020. Only to be bested in 2023 and 2022 to Jonas Vingegaard who unfortunately crashed out of this tour. I was heavily in World Cup mood, but as the Tour started I was only aware of a few things I was tracking: * Could Tadej Pogačar win a 5th Tour? * Would Jonas Vingegaard steal back a win? * Remco Evenepoel was looking strong to challenge * Would Jasper Philipsen come for revenge after crashing out last year? * Would Juan Ayuso be a threat after leaving UAE for Lidl-Trek? * Would the new UAE Isaac del Toro be a challenge for White jersey? So let's jump into a mini recap of the 21 day event. * * * https://www.letour.fr/en/stage-1/image-gallery Stage 1 was a team sprint stage which had been a long time since I'd seen this type of stage at the Tour de France. This time the rules were a bit interesting that riders got their own individual time, even though they raced together at once. So it seemed each team was rocking and pushing their yellow jersey contender to the line. Visma ended up winning this by a few seconds with the powerhouse of Ganna taking 2nd and Pogačar 3rd. https://www.letour.fr/en/stage-2/image-gallery Stage 2 was a regular hilly stage where we saw the contenders for the green jersey battle out over the intermediate sprint. Once the breakaway was caught it was UAE holding an insane pace slowly dropping riders until just a few remained. They broke for the line and we saw Tadej help his teammate Isaac del Toro obtain the victory. It was great to see Jonas (Visma) and Remco (Red Bull) right behind them as this was suggesting a great tour to come. https://www.letour.fr/en/stage-3/image-gallery Stage 3 was the end of Barcelona as the stage would veer into the Pyrenees and setup the remaining stages in France. It was a long (~200km) mountain stage which roughly flowed like the previous. A breakaway took off and sprinters fought for the intermediate sprint before the mountains began. Once the climbs towards the end began we saw UAE take control, increase the pace and drop riders pushing Tadej past the others for a sprint for the line. He out sprints everyone by just a few bike lengths and takes his first stage. https://www.letour.fr/en/stage-4/image-gallery Stage 4 was such an interesting stage that showed myself I don't really truly understand cycling at the professional level. As the breakaway took off with a solid amount of riders the group of yellow jersey contenders let the gap go out further and further until it was around 8 minutes. With Tadej only in yellow by seconds it looked like a lot of jerseys would be moving hands after this stage. The teams probably had immense confidence most of the riders ahead on this stage could not hang in the mountains so they let them fight it out alone. This led to a great sprint finish with Mads Pedersen of Lidl-Trek. Torstein (Uno-X) ended up going into yellow after this stage with a 7 minute 53 second lead over Tadej. https://www.letour.fr/en/stage-5/image-gallery Stage 5 was a flat stage built for the sprinters and pretty much a calm stage until the end. The breakaway was caught with like 10 miles to go, so teams were jousting for space for their sprinter. At roughly the 3 mile mark a crash occurred which really reduced the group of riders to around 20 for the sprint. This crash and break up of organized team lines led to a chaotic sprint that had Olav Kooij (Decathlon) taking the win by a solid bike length. https://www.letour.fr/en/stage-6/image-gallery Stage 6 was a mountain stage in some hot weather (95F) and we saw the true power of Tadej be asserted. As the mountain arrived - UAE increased the pace massively dropping riders until just a few remained. Roughly around this time the present yellow jersey (Torstein) crashed and recovered, but left the tour the next day after medical discovered a concussion and multiple rib fractures. With roughly 3 miles left on the 2nd to last climb del Toro attacked and Tadej followed with Jonas unable to stay with either of them. Shortly later Tadej went solo and pushed that advantage with 27 miles left in the race pushing his margin to 2 minutes and 38 seconds. This was an extreme show of force by Tadej leading the yellow jersey by minutes now. https://www.letour.fr/en/stage-7/image-gallery Stage 7 was a break from the mountains and a regular flat stage where the sprinters would have a race for the end. Nothing really happened for the majority of the stage as the breakaway was caught with 11 miles to go just as the sprinter teams were getting setup for the sprint. It looked like the lead out for Alpecin (Philipsen) was solid, but they went too early and ran outta gas with ~1000ft to go. This led to Soudal rider Tim Merlier to squeeze through and beat everyone to the line. https://www.letour.fr/en/stage-8/image-gallery Stage 8 was another flat stage which would be a great chance for revenge for all the sprinters to fight back. This stage had an interesting breakaway that wasn't caught until the extreme pace of the sprinters caught the individual with ~2 miles to go. This time it seemed Philipsen was set with teammates again, but Tim Merlier could not be stopped. He won back to back stages and moved up on the green jersey points. https://www.letour.fr/en/stage-9/image-gallery Stage 9 was shortened due to the heat wave with the idle temperature laying at 100F (38C). Roughly 30km was removed from the middle which caused the intermediate sprint to be only 13km into the race. This led to an interesting quick start at those competing for the green aiming for the points. Once Pedersen won the intermediate sprint breakaways started developing and being caught until ~16 riders broke out with 60 miles to go. One of those in the breakaway was Mathieu van der Poel who'd be tough to catch. Sure enough the peloton raced to catch the breakaway, but van der Poel held out and won the stage in a sprint holding off the breakaway riders and the rampaging peloton. https://www.letour.fr/en/stage-10/image-gallery Stage 10 was a stage after a rest day and it was heading into the mountains. This was the famous French Bastille Day so the French were probably going to aim for a stage win. The stage was pretty calm until the final summits when Carapaz (EF) went for it and got a solid minute on everyone else. However, Tadej attacked and no one could go with him as he scaled the mountain on an insane pace. Sure enough Tadej passed Carapaz and took the stage win by 30 seconds. It was just showing how strong Tadej had become and how he seemed unstoppable on the mountain. https://www.letour.fr/en/stage-11/image-gallery Stage 11 was a flat stage and was insanely fast - it averaged to 31.6mph for the entire stage, which might be the fastest road stage in history of the Tour de France. It was a pretty calm day with exception of a few crashes that led to a slightly disorganized end. While I expected Philipsen to finally win a stage, he was once again was beaten at the line by Wærenskjold of Uno-X. https://www.letour.fr/en/stage-12/image-gallery Stage 12 was another flat stage with a crazy finish. With probably under 1000ft to the end a crash broke out that messed up a lot of the sprinters. The remaining sprinters went for it and it seemed like Philipsen finally had the stage, but Merlier snuck through and beat everyone at the line for another stage win. https://www.letour.fr/en/stage-13/image-gallery Stage 13 was a hilly stage that had probably the largest breakaway of this year with like 60 people in it. Pidcock was in the breakaway and when the gap got to like 8 minutes it seemed crazy that he was virtually in 2nd place at that time. As the distance reduced to about 16km left - just a few riders remained in the breakaway. There was no chance the peloton was catching this group and sure enough Schmid/Tejada raced at the end and Schmid squeaked out the victory. https://www.letour.fr/en/stage-14/image-gallery Stage 14 was back into the mountains so we were bound to have a crazy day. The intermediate sprint was heavily challenged by Philipsen as he was slowly clawing his way back into the green jersey challenge. As we approached the climbs it seemed Carapaz was going for the stage win, but once again as the gradient hit 16% it was time for Tadej to shine. He took off dropping the others and passed everyone to take another stage - he seemed unbothered by the immense heat and incline. I am convinced I am watching the greatest cyclist of all time continue to break records. https://www.letour.fr/en/stage-15/image-gallery Stage 15 was another mountain stage and was quite a sad stage once all was said and done. At roughly 1/3 into the stage Jonas took a corner and clipped the concrete and went down hard. Moments later he is getting into an ambulance and his tour is over. This was insanely sad because Jonas had gotten #1 or #2 in the last 5 Tours. Later on we also said goodbye to Tim Merlier who abandoned the tour in the mountains after 3 stage wins due to exhaustion. For the stage win we saw the breakaway get caught by Remco, Tadej and del Toro with ~5km to go. They all sprinted for the line and Remco squeezed out the victory against both UAE riders. https://www.letour.fr/en/stage-16/image-gallery Stage 16 was after a rest day and this time was an individual time trial of 26.1km in length. It was such an interesting time trial having a large gradient then downhill to a straightaway. Remco won back to back stages with a colossal showing of strength in the time trial. The fastest time after all but 2 riders finished was 33 minutes and 23 seconds. Remco did 32 mins and 19 seconds, which even Tadej (32m 47s) could not beat. Though, let's be fair Remco is the time trial world champion - it was going to be very tough to beat him. https://www.letour.fr/en/stage-17/image-gallery Stage 17 was another flat stage, but knowing Tim Merlier was out it was bound to be an exotic finish among the remaining sprinters. The intermediate sprint was really late in the stage, but Pedersen held strong and got 25 points when it came. As the stage was nearing the end we saw the train of Alpecin pull Philipsen into prime position and he did it - claimed his first stage win of the 2026 tour. This stage win made the green jersey event so close - 452 points (Pedersen) vs 445 points (Philipsen). http://letour.fr/en/stage-18/image-gallery Stage 18 was back into the mountains with the continued pattern of a breakaway, but the riders among the breakaway had some heavy climber names. The yellow jersey group didn't seem to mind who was in the breakaway this time letting them get 8 minutes out. The breakaway was full of some names that any could win, but Carapaz excelled past the group to win the stage. https://www.letour.fr/en/stage-19/image-gallery Stage 19 was further into the mountains, but a much shorter stage at roughly 60km less than the previous day. A breakaway took off to try and get a jump on the peloton before the climbs hit. As the mountains were hit, the yellow jersey group starts to pick up the pace to see if they can catch the breakaway, but the gap at this point was at 4 minutes. This was no match for the teammates of UAE and Remco who clawed back to the towards to the front. They still had 3 to beat (Carapaz, Martinez & Kuss) but those 3 didn't seem to be working together. Thus Tadej caught up and passed them all for another stage win. https://www.letour.fr/en/stage-20/image-gallery Stage 20 was the last mountain stage which had another breakaway take off with roughly 35km to go. This group had Carapaz and Kuss again who had been doing some serious breakaway work in the previous stages. Kuss seemed to have the edge as he took the lead with roughly 15 seconds on Carapaz. However, Kuss crashed out of the tunnel and that gap reduced to 8 seconds. It seemed he got lucky and continued on, but disaster struck when he crashed again against the net that protects you from falling off the mountain during a turn. During that 2nd crash Kuss had Carapaz squeez by and took the victory. Carapaz took a 2nd stage victory as the group with Tadej couldn't catch him in time. https://www.letour.fr/en/stage-21/image-gallery Stage 21 was the famous last stage on the Champs-Élysées, which had an amazing battle between Van der Poel and Tadej. They went back and forth on the climbs holding back a large chase group. As the distance neared to under a 1000ft we saw Tadej sit up and it was up to Van der Poel to hold off the swooping sprinters. It was too close to call, but it almost seemed like his teammate almost beat him in the chase group as the photo above shows. However the cameras showed Van der Poel won and we the viewers got to witness him passed out against the barrier for a few minutes as he regained his energy. He looked like he pushed his body to the ultimate limit. The tour was over with Mathieu Van der Poel taking the stage, but Tadej Pogacar the event. ## Jersey Winners * Yellow (time) - Tadej Pogacar * Green (points) - Mads Pedersen * Polka Dot (mountains) - Richard Carapaz * White (young time) - Isaac del Toro * * * With another tour ended I'm not sure how anyone can beat Tadej unless they build a powerhouse team to support a new challenger or he ages out. I thought Tadej losing a great teammate was going to hurt his chances, but losing Ayuso and gaining a strong Isaac del Toro proved that to be false. The green jersey is a fun battle each event and as the 2027 Tour de France arrives I hope to see more records broken from Tadej. I strongly believe I am watching the greatest cyclist ever on his journey to become the best and excited for the next year.
100
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 20/07/2026
The FIFA World Cup of 2026 has come to an end. An amazing tournament full of 48 nations battling for 1st place.
connortumbleson.com
FIFA World Cup 2026
Brand for FIFA World Cup 2026 Today (July 19, 2026) the 23rd iteration of the World Cup ended. This was a unique tournament this time increasing the amount of teams to 48 from the previous 32 limit. This meant this tournament would introduce a best of 32 round prior to the existing round of 16. All this meant was more games and more chances for other nations to compete outside of pool play. As the dust settled after 104 games Spain came out the victors, taking down Argentina and Messi's dream of back to back wins. We can turn back the clock though to the start and recap the finish at the end. * * * As the first game arrived I had to figure out the proper platform to watch the games on since my existing solution had Spanish only. So long story short I had to purchase YouTube TV for 2 months. Game 1 - Mexico vs South Africa The first game was crazy with a goal prior to the 10 minute mark followed up by double red cards against South Africa. This meant they'd be playing with only 9 players against the full strength of 11 of Mexico. As the game came to an end another red card was dealt out against Mexico. The game was scrappy and I'd personally never seen so many red cards in international play. Game 4 - USA vs Paraguay As the first USA game arrived we'd get to see our new coach (Pochettino) and roster attempt another go at the World Cup. The game was electric with USA taking an early lead and putting 3 goals in prior to the half. As the 2nd half came and went another goal for each side was scored. America winning their first game 4-1 was insane as we scored more goals in that game than the entirety of the previous world cup. This was the game that really shined how much data existed for games now. There were over 50 categories of stats and a custom power ranking value derived for each position. Each match had a "Match Centre" full of random stats like which channel of the field attacking occurred from. World Cup games on June 16, 2026 As Game 17, 18 and 19 arrived we'd have the fan favorites of Mbappe (France), Haaland (Norway) and Messi (Argentina) all playing that day. This day was amazing with each star player all scoring multiple goals each. Already it felt like this World Cup was more exciting than previous even with the boring "_game breaks_ " halfway through each half. Game 32 - USA vs Australia The 2nd USA game arrived and much like the first we had a quick goal (own goal) in the first 10 minutes of the game. That was 2 games in a row for USA with an own goal in the first 10 minutes which was very lucky. As the game came to an end it was a surprise to find the United States up with 2 wins in bracket play which we hadn't done in a long long time. This meant after a few more games had played we found ourselves winning our bracket regardless of the success of our final pool play game. Cabo Verde's World Cup Watching Cabo Verde was immensely fun. Their first 3 games were all ties including against the powerful Spain. This was a nation with roughly 500,000 people so having them compete and stand against other nations was great fun. As they entered the round of 32 and faced off against Argentina I think the world predicted a quick victory for Argentina, but instead an amazing game. Game 86 - Cabo Verde vs Argentina An image can't give justice to how great this game was with regular time ending in a tie. Extra time went back in forth with a goal on each side having Cabo Verde tied with Argentina with only 10 minutes left until penalty kicks. With roughly 9 minutes to score Argentina squeezed a goal in that was technically an own goal. Cabo Verde's story was over, but the world was both nervous that Argentina almost lost and how proud they were of Cabo Verde's showing. Game 81 - USA vs Bosnia & Herzegovina The United States went onward to the round of 32 and had a very mixed game. On one hand we won, but our prime striker (Balogun) was ruled out of the game with a direct red card on a rough tackle. For the remainder of 30 minutes USA had to play down a player and amazingly scored off a free kick while down. This ignited the fans as we were onward to the round of 16 to face off against Belgium. The round of 32 had a few other crazy games that deserve a shout out: * Germany lost to Paraguay in penalty kicks (3 vs 4) * Brazil almost tied to Japan with Brazil scoring at 90+5 to win it. * Belgium was down 0-2 with 4 minutes left. They score 2 in 3 minutes to tie it, then win in overtime on a PK. The round of 16 had plenty of cool matchups: * Canada (0) vs Morocco (3) * Paraguay (0) vs France (1) * Brazil (1) vs Norway (2) * Mexico (2) vs England (3) * Portugal (0) vs Spain (1) * USA (1) vs Belgium (4) * Argentina (3) vs Egypt (2) * Switzerland (0/4) vs Colombia (0/3) Game 94 - USA vs Belgium For America our journey came to an end with a pretty embarrassing showing. A quick goal against us in the first 10 minutes that wasn't equalized until the 31st. At that point at 1-1 it seemed we were back in the game, but Belgium turned that goal around to an immediate response score again. The 2nd half opened up with one of the most embarrassing plays of USA history. The goalie forgets (misses?) to kick the ball right next to a Belgium defender who just passes it into the goal. At that point down 3-1 it seemed our dreams were over. Sure enough after Belgium scored again in stoppage time - America went home sad and defeated after a great start to the tournament. This round of 16 also had us say goodbye to Portugal (Ronaldo) and Brazil (Neymar). The round of 8 remained: * France (2) vs Morocco (0) * Spain (2) vs Belgium (1) * Norway (1) vs England (2) * Argentina (3) vs Switzerland (1) Game 99 - Norway vs England These games were good, but we finally had to say goodbye to Haaland and Norway with their patented "rowing" after each victory. Though I'm fairly sure the ball hit the camera equipment in the air leading to the England goal so I still don't really agree with the result. I was happy to see Belgium eliminated after they eliminated us, so the final four were known. * France (0) vs Spain (2) * England (1) vs Argentina (2) The England game was such a classic England game where you want to believe coaching led to the loss. England was up 1-0 at the 55th minute and a few subs went in for what looked like a more defensive setup. Argentina scored a equalizer at the 85 minute and it looked like this game was going to overtime. However, Argentina had another plan scoring at 90+2 thus winning the game. Game 103 - France vs England The 3rd place game was some of the most exciting soccer in a long time. Starting off completely crazy with England going up 4-0 in the first half. The 2nd half arrives though with substitutions from France who then quickly scored 2 goals making it 2-4. ~20 minutes later it was 3-4 and it seemed France was coming back. A dumb foul by France led to a penalty kick which gave Saka a hat trick and put it 3-5. In extra time France scored again making it 4-5, but England's Bellingham put the dagger in with a 6th goal making it a 10 goal game. It's clear that a game that doesn't really matter led to a beautiful game of soccer. * * * This all led to the final game between Spain and Argentina. The new up and coming Lamine Yamal (Spain) vs the greatest of all time Lionel Messi (Argentina). Boy o boy what a weirdly odd game this was. Game 104 - Final - Spain vs Argentina The stats help tell the story - Argentina only had 2 shots on goal and both of those attempts happened in the final 15 minutes of extra time. For over 90 minutes of gametime we witnessed an Argentina set of players not have a single attempt at the goal. It just made sense as the game was progressing that Spain deserved to win this game. They possessed the ball more, had more passes and way less fouls. It became further obvious that Spain was going to win when an Argentina player (Fernandez) committed their 2nd yellow and was sent off the field. With Argentina a man down it just became a matter of time before Spain was going to have a shot go in. When Spain scored at the 106th minute there was only 14 minutes left for Argentina to equalize the game. They did not and Spain took home the trophy. However, not without an Argentina player doing some dirty behavior in the post game. 0:00 /0:21 1× Argentina being disgraceful after game. The video shows Paredes, who subbed in at half then proceeded to get an immediate yellow, basically commit a bunch of red card offenses in the post game. He was immediately red-carded and sent off the field. I'm not sure what events transpired for him to act that way, but he was playing dirty since he subbed in and put a disgrace to his name & country with that behavior. Spain winning The FIFA World Cup 2026 Outside of that - it was an amazing World Cup and I was sad that it was finally over.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 13/07/2026
Marathon & Destiny 2 are creations of Bungie - how much do they rely on FOMO to operate?
connortumbleson.com
Video Games & FOMO
Marathon & Destiny 2 playtime A couple of weeks ago I blogged about the end of Destiny 2, but oddly once I had re-completed the quests of Season 2 of Marathon I booted up Destiny 2 again. A game that I hadn't touched since "The Final Shape" DLC released back in June of 2024. It seemed from afar that Destiny 2 was over the mantra of holding content, because boy the patch notes for the 9.7.0 release was insanely large. I'm guessing it makes sense because why hold back anything at the studio if the game is over - release whatever you have slated for now or the future. So as I booted the game up I had 2 campaigns to play and catch up on - Renegades & Edge of Fate. Steam cards for both DLCs. Neither looked like they had good reviews, but that was to be expected. Destiny 2 probably wouldn't be over if the previous DLCs had been a smash hit. Personally I think they were doomed to make anything after "The Final Shape" as that DLC put an end to a story line that had been developing for a decade. Basically same reason why I think any movie in the Marvel universe after Endgame isn't my cup of tea. I accidentally played the campaigns in the wrong order (Renegades than Edge of Fate), but I'd agree that neither of them were that fun. Renegades: * Trying to be Star Wars so much inside an existing Destiny 2 world. * Introduced some new mechanic that conflicts directly with abilities - somehow I went entire campaign only using it when directed. * Enemies and areas felt very close to the original Red War campaign Edge of Fate: * Crazy boring puzzles revolving around some ball/teleport/mutate mechanic * So much backtracking in missions back to an area after solving something elsewhere * Sparrow travel disabled leading to prolonged slower mission progression However, ignoring all of that. The only reason I came back to Destiny 2 is that because it was over. This meant to me no matter what I played or did was the final time I had to do that. I only had to grind to the highest light one more time and that was tempting enough. Back when I was in school and had all the time in the world - Destiny releasing upgrades that nullified old gear and forced a progression to new max light was kinda fun. However, as I got older watching an update come out and either remove a ton of existing content (cough Beyond Light) or force me to re-grind to get back to activities (Raids) I enjoyed doing was not. I didn't have infinite time anymore to get a new perfect build every DLC so I stopped playing. I roughly followed along, because like any game you'd been playing for decades you are invested in the success and path of it. I wanted to play here and there, but once you fall behind there is not much point of going back to play unless you invest some serious time. https://steamdb.info/app/1085660/charts/#1y When I look at the stats of PC usage I wonder if the chunk of people who returned did so for the same reason I did. I think it was an inverse effect of FOMO, because with each season Bungie presumably tried to leech onto the human behavior of FOMO. Hopefully encouraging folks to return and play before that content/season is out of the focus for another. As I mentioned - it just became too much for me and I couldn't keep up with the constant grind of each update. So oddly the game ending was the thing that brought me back. I just feel bad the end of the game led to a majority of the staff being laid off, since boy Destiny at times was one of the best games I ever played. At this point with a full time job, a wedding on the way and tons of things outside of work. Gaming isn't what it used to be, but I'll slowly grind myself to the max light on Destiny 2 because I have no fear of missing out this time.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 29/06/2026
Now owning a Nintendo Switch 2 we had to obtain the latest Super Smash bros to relive some childhood.
connortumbleson.com
Super Smash Bros
A long long time ago when I was a little kid I went over to a friend's house and they had a Nintendo 64 (released 1996). The one game that was an instant favorite that we played each time we met up was Super Smash Bros. The 1st Super Smash game released in 1999 (Nintendo 64) This was an incredible game because each and every battle you did was naturally different. We kept switching characters trying to find one we'd perfect in order to beat the tougher and tougher CPU based enemies or each other. Some of the original Super Smash maps We'd play on different maps and as we played more we realized you could unlock more characters to play as! This is where Ness was introduced that would become the character I'd play for the next 20 years. Of course the GameCube was released a few years later in 2001 and it was one of the first game consoles we'd own ourselves. So of course another iteration of Super Smash was released and we had to get it. Box art for Super Smash Bros Melee (GameCube) This was such an excellent 2nd iteration of the game as everything about it just got better. * They added 14 more characters on top of the existing. * They added a ton more stages returning some favorites from the first game. * They added a ton of single player "mini" games like Home-Run Stadium. * They had a Classic, Adventure, All-Star and Stadium modes. * They had so many things to set records on, unlock and more. If a friend had a GameCube they had Super Smash as well. We'd setup tournaments or play some crazy customized rule based battle. Though what was immediately fun was trying to unlock all the characters at whatever requirements was needed for it. This is where online game guides and forums began to really shine as a method for learning how to do something. "Final Destination" stage on Melee' A new map introduced was called "Final Destination" which is where you'd face off against the final boss. Once unlocked this became my favorite map as it had nothing special going on. It was just a battle between characters on a flat surface with a few items in the mix. It was my type of battle without the randomness of other stages. We'd also turn off some of the more broken items, because the random aspect to get an item that almost guaranteed a kill wasn't very fun to go against. I probably to this day have the most hours on Super Smash Melee than any other Nintendo game by quite a lot. By time the 3rd iteration of the game came out it was for the Nintendo Wii which I did not directly own. Box Art for Super Smash Bros Brawl (Wii) It was fun to play this game when I had the chance as it was once again the same game but a new set of characters, maps and items. It was a pretty fun game to just set some settings and play against some friends locally. However, one item bugged me extremely quick in this game which was not found in the previous. It was the "Smash ball" and granted the hero who broke it their "Final Smash", which was basically an ability so strong it would normally kill opponents. It even felt like if a player was doing so bad they'd be given one off spawn to help re-level a game. Sure some of the heroes had final smashes you could dodge or avoid, but some seemed so daunting and powerful they acted as an instant kill. So of course if the item spawned everyone would go for it instantly. I'm happy we had the ability to turn it off, since it spawned too often and was too powerful. __Now a 4th game came out for the Nintendo 3DS and Wii U, but I never played it so we skip right by.__ We now arrive at the 5th game for the Nintendo Switch, which Alyson and I now own so we picked up the game. Super Smash Bros Ultimate (Nintendo Switch 2) It was cool immediately to recognize maps, gamemodes, heroes and configuration dating all the way back to the Nintendo 64 era. Quickly I noticed a new adventure mode with spirits which made no sense to me, but after some reading it reminded me of the skill based tree gaming that something like Marathon, Overwatch Stadium or Destiny has. I'll have to experiment with that mode at some point. So many characters weren't unlocked that I reminded myself of the fun just playing to unlock some new heroes. Though I had to do some quick research on how to unlock my main character of Ness. It'll be a slow journey to unlock everything with the little bit we play, but having a game that isn't as stressful as Marathon is a fun alternative. https://www.youtube.com/watch?v=jtlUHmonMGQ I bet anytime a new generation of consoles come out from Nintendo you can probably count on a new Super Smash Bros, much like Xbox counts on Halo for each new generation of consoles.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 22/06/2026
A weekend of visiting Gamestop, going to a museum and enjoying some food.
connortumbleson.com
MOSI, Switch 2 & Ulele
AI image creation of the blog post via Opus 4.8 on Anthropic. As Friday arrived I had the day off work for Juneteenth, so had the opportunity to watch the USA World Cup game at home while yelling at the TV in celebration. Afterwards Alyson and I would attend MOSI (Museum of Science & Innovation) for an "after dark" event. The soccer game was amazing with the United States scoring multiple goals and winning again! We had 2 wins so far which which was far more successful than our previous pool play history. https://www.fifa.com/en/tournaments/mens/worldcup/canadamexicousa2026/standings If we look purely at pool play (3 games) we can see the records going back till I was no longer alive. * 2026 (so far) - 2 wins. * 2022 - 1 win, 2 draws. * 2018 - _did not qualify_. * 2014 - 1 win, 1 draw, 1 loss. * 2010 - 1 win, 2 draws. * 2006 - 1 draw, 2 losses. * 2002 - 1 win, 1 draw, 1 loss. * 1998 - 3 losses. * 1994 - 1 win, 1 draw, 1 loss. Now the pessimist may look at the teams in the bracket of 2026 vs other years, but either way we are moving onto the elimination bracket. Winning & on home soil is such a great difference in our history of competing on the world's stage. With that shared energy of winning it was off to an "after dark" MOSI event. No kids, alcohol and a chance to experience a museum that is normally overloaded with kids and field trips. https://mosi.org/event/science-after-dark/ It was cool to experience some of the demos or experiments without kids, but as we entered the food trucks outside the excitement kinda faded. The samples were great, but temperature of items didn't match the expectation. Lukewarm sushi, cold chicken and pizza on the edge of room temperature was just not hitting the spot. So we figured we'd grab a drink and walk around some more. The cider station was only pouring tiny samples and the real bar had a line so long we gave up waiting in it. I felt sad watching one person run the bar doing payments, drink pouring and bar maintenance with a crowd waiting in line. So we scouted out the ice cream area, but that was also temporary closed for production (they had to make the ice cream with dry ice). So we decided to head to the light show at 6:45pm in the MOSI dome. Which started with this amazing trailer of a high fidelity video of the sun. I felt like I was in the solar system with how good the 360 dome made the video feel. I was excited for the light show to arrive. The dome made it feel like you were in the scene of the video. However, the light show degraded the visual quality by a lot and I was itching to leave during the first song. However, we pushed through and listened to the 25 minute segment of songs to experience the full thing. It wasn't anything we'd probably do again, but it was fun to support the museum regardless. Picture of a purchased Nintendo Switch 2 & Pro Controller The next day we decided to buy a Nintendo Switch 2 to buy Animal Crossing. It had been so long since I bought a game console I forgot the joy and stress of rolling into a Gamestop to buy a physical console. Wiring up a console to your TV and setting up an account reminded me of the early days of setting up the original Xbox. Such a fun time and now Alyson and I can play some of the party games like Mario Party, Mario Kart and PlateUp together on the couch. As Sunday arrived it was Father's day and time to visit a brunch at Ulele like hundreds of others. Ulele Tuna Steak To my surprise after even blogging about the salad at this restaurant - the item was no longer on the menu. I was sad that my favorite dish, even with conflicted results, was gone thus forcing me to order something different. So of course I went straight for the closest thing to a seared ahi tuna dish, which was a tuna steak. It was cooked much like the salad iteration of the dish, just instead with some other sides. It was an excellent meal, but I'm still slightly sad the one thing I consistently ordered was gone. Especially since its just salad and tuna - both ingredients which I'm positive are still in the kitchen. * * * The weekend came to an end and thus so did this blog.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 15/06/2026
A weekend of traffic, the temporary suspension of Claude models and a trip to Keel Farms.
connortumbleson.com
Red Lights, AI Models & Cider
AI image creation of the blog post via Opus 4.8 on Anthropic. As I sat at a red light waiting for it to turn green, I noticed the opposing traffic get their yellow light and I was excited for my turn to come. Like most repeated drives home you'll pretty quickly identify the worst lights on your journey. The very first light I hit on the way home is the longest light I'll sit commonly sit at. When my turn comes I normally lose the first few seconds of the light every single time to people running a red. This light is smart so when cars don't move from the direction I'm sitting - our cycle is very short. So this week when 1 car, then 2 cars and then a 3rd car ran their red I smashed my horn down for a good solid few seconds. 0:00 /0:22 1× Video of the "red light" incident. Now once I could re-watch the tape an eager eye would probably notice the cars inching closer into the intersection in their turn lane. However, at the moment my light turns green the 3rd car has not yet passed the white line into the intersection so my horn feels completely validated. As I know their light has been red for a few seconds at that point. I wonder if that car was just blindly following the car ahead of them unaware of the status of the light. I arrive home after an annoying drive and check my phone for a crazy headline. > Statement on the US government directive to suspend access to Fable 5 and Mythos 5 > https://www.anthropic.com/news/fable-mythos-access I couldn't really believe what I was reading. The brand new AI model from Anthropic of Fable & Mythos were being suspended on a request from the US government. The exact wording called out foreign nationals whether inside the US or out being blocked. Knowing implementing that was impossible Anthropic disabled these models for all users shortly after. Depending how you look at this is insane: * The US Government has decided these AI's are too dangerous for public consumption, giving a massive boost of credit to Anthropic. * Frontier models from all providers are probably in same bucket as Fable so it doesn't seem fair to target Anthropic. * Anthropic told people how dangerous Mythos was in terms of discovering software vulnerabilities and maybe the government listened. * Companies left with an integration no longer working may move onto foreign models. We are in such a weird time in technical history that its difficult to understand exactly how this will unravel. I may work in the field and leverage AI daily for my job, but I haven't taken a step back to look at humanity in whole and what this era of AI might actually mean. Thankfully every once in awhile we can take a break from technology and visit a farm for some cider and food. Keel Farms Cider & Burger & Cats Alyson and I visited Keel Farms on Saturday because we heard from a bar we visit that Keel Farm ciders were being reduced to one flavor. We had to go straight to the source to get to the bottom of this while enjoying hopefully some ciders. Sure enough after sitting at the bar they confirmed the cans they produce and ship out would be reducing to just the Elderberry flavor. This was a bit sad to hear because my favorite flavor is Strawberry-Lime and that would no longer be available at bars. So the only way to experience the flavors we prefer must be in person at the farm. So I did a flight with: * Strawberry-Lime * Pineapple * Irish Dry Cider * Elderberry w/ Serrano Pepper The modified elderberry with the pepper was an interesting taste I probably wouldn't order again. It wasn't bad, but it just was a level of heat I wasn't in the mood for in a drink. As were enjoying drinks we noticed some cats show up and it turns out the farm has a few ferals that walk around. I guess they noticed the AC enclosed outdoor area and snuck in under the tarp and chilled. Bartender mentioned the grey one was pretty friendly and indeed it would just brush by our legs and sit under us. I'm sure there is one human a day there that'll make some reason to hate it, but it was cool to have some feline visitors while dining. A day later Fable & Mythos are still not available, so maybe we will have to wait till Monday for some news. Until then we can take advantage of the real world with food & cider.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 08/06/2026
Leaf uptime issues continue, this time moving along to a new open source solution: Anubis.
connortumbleson.com
Anubis & NGINX
Anubis - Open source and amazing. I started a blog post last week as I patched my Leaf hobby project to be a bit more restrictive on what it bans due to my requests abruptly growing from 50k/day to 2mil/day. I thought that was going to be the end of it, but then I got more alerts of downtime and saw my hits had grown to over 4 million a day. There is no natural growth of a Halo Infinite stat site from 50k to 4 million visits in any world. This didn't seem like an out of control bot anymore due to thousands of those requests just opening/closing the connection incredibly fast. Once my PHP workers were exhausted and 502's were returned - these vast set of IPs would continue hammering. It just didn't seem like stuff that regular spiders or bots would do. So once I had some downtime I started digging into this again. Hits spiking to 4 million/day I pulled some logs locally to re-run some analytics and was surprised to see a major jump from 2 million hits a day to over 4 million. Unfortunately due to some naming I wiped out some logs of the past week creating that odd dip you see above. With Halo Infinite presently only pulling about 2,000 unique players a day there is no chance in hell that a unique set of 2 million visitors were visiting Leaf. 💡 __HTTP requests containing the same IP, same date, and same user agent are considered a unique visitor in__ GoAccess__.__ Unfortunately I was out and about when these alarms were going off, so I suffered a few hours of downtime as my server just tanked 90-120 heavy requests a second for hours. For a properly cached and tuned server that would be nothing, but I built Leaf using Laravel Livewire which heavily depends on cookies. I could not identify an easy way to rip cookies out so I could serve cached pages purely from NGINX. That meant every single request (except static files) would invoke PHP to render said page and consume some resources. Linode stats of server pre/post fix. So now that I had exhausted my adaptations to my robots.txt & fail2ban rules I set off to introduce a tool I had noticed on a lot more sites recently. Anubis is a tool that sits in front of your website and acts as a little body guard dictating what can or cannot view your site. In the era of AI agents and aggressive scrapers taking as much data as they can, Anubis found success introducing a variety of challenges to make their access incredibly difficult. So I decided to give it a shot and configure it in front of Leaf. With one quick copy I had my configuration in place. # cat /etc/anubis/leafapp.env BIND=:8923 BIND_NETWORK=tcp DIFFICULTY=4 METRICS_BIND=:9090 METRICS_BIND_NETWORK=tcp SERVE_ROBOTS_TXT=0 TARGET=http://127.0.0.1:3001 COOKIE_DOMAIN=leafapp.co ED25519_PRIVATE_KEY_HEX=redacted Configuration file for Anubis for Leaf This basically helped show Anubis how to redirect traffic to my internal listener once a user passed their checks. I swapped my NGINX over and as my Linode graphic shows above I watched my load decrease all the way to under 1. Now when you visit Leaf if you don't have a stored cookie proving validity - Anubis will show up briefly to run some challenges. Intermediate page before Leaf This page above is tough to see on a faster piece of hardware, but briefly on mobile devices you may see it. It isn't my cup of tea in terms of a design, but this is the offering on the open source edition. An enterprise option exists with a more boring name (BotStopper) for those in the industry that don't want to print an anime like avatar before the page loads. So I wanted to dive into the analytics Anubis offers after it had been running for a few hours. With a simple query to the `/metrics` route, I found Prometheus metrics spat out. # curl -s http://127.0.0.1:9090/metrics | grep ^anubis anubis_challenges_issued{method="embedded"} 454593 anubis_challenges_validated{method="fast"} 1479 anubis_policy_results{action="ALLOW",rule="bot/bingbot"} 6368 anubis_policy_results{action="ALLOW",rule="bot/common-crawl"} 191 anubis_policy_results{action="ALLOW",rule="bot/duckduckbot"} 16 anubis_policy_results{action="ALLOW",rule="bot/favicon"} 546 anubis_policy_results{action="ALLOW",rule="bot/googlebot"} 60021 anubis_policy_results{action="ALLOW",rule="bot/robots-txt"} 57 anubis_policy_results{action="ALLOW",rule="bot/well-known"} 24 anubis_policy_results{action="ALLOW",rule="bot/yandexbot"} 681 anubis_policy_results{action="ALLOW",rule="threshold/minimal-suspicion"} 20076 anubis_policy_results{action="CHALLENGE",rule="threshold/extreme-suspicion"} 195 anubis_policy_results{action="CHALLENGE",rule="threshold/moderate-suspicion"} 467875 anubis_policy_results{action="DENY",rule="bot/ai-catchall"} 11081 anubis_policy_results{action="DENY",rule="bot/ai-clients"} 11 anubis_policy_results{action="DENY",rule="bot/ai-crawlers-search"} 28138 anubis_policy_results{action="DENY",rule="bot/ai-crawlers-training"} 1373 anubis_policy_results{action="DENY",rule="bot/alibaba-cloud"} 1271 anubis_policy_results{action="DENY",rule="bot/huawei-cloud"} 10731 anubis_policy_results{action="WEIGH",rule="bot/deny-aggressive-brazilian-scrapers"} 195 anubis_policy_results{action="WEIGH",rule="bot/generic-browser"} 469549 anubis_proxied_requests_total{host="96.126.124.217"} 14 anubis_proxied_requests_total{host="leafapp.co"} 51992 anubis_proxied_requests_total{host="www.leafapp.co"} 49450 anubis_time_taken_sum{method="fast"} 543398 anubis_time_taken_count{method="fast"} 1479 Anubis metrics output. As I examined these results it was interesting to see how quickly effective Anubis was in roughly 6 hours. * I had ~468,000 Anubis challenges deployed and only 1,479 solved it. * A crazy 0.30% pass rate. * I had ~52,000 challenges denied immediately for falling into a bucket of "_bad bots_ " * I had ~101,000 requests allowed which was largely Googlebot (60k) and a bunch of other deemed legitimate traffic. * Out of the 1,479 solved challenges they averaged 367ms delay prior to loading Leaf. Leaf server rebounding with no load post Anubis Time will tell if this solution is enough, but I'm happy at the moment with an acceptable amount of load on the server while still accepting traffic for the few humans left still leveraging Leaf and playing Halo Infinite.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 01/06/2026
As a personal website surpassed 2 million hits a day, I was left wondering what was eating up those hits.
connortumbleson.com
GPTBot is terrible
A few weeks ago I got a message telling me that Leaf (My Halo Infinite stat site) was having some uptime issues. Each time I got the message the site loaded for me and none of my alerting showed any issues, so I ignored it. However, at some point the downtime must have been long enough for my alerting to catch it. Uptime Robot on leafapp.co Now sadly for me I haven't really touched Halo Infinite since November of 2025, so I hadn't spent a lot of time working on Leaf. As far as I was concerned I was spending money for the greater Halo community and just making sure the site was still alive. One of these alerts came in a day before I wrote this blog and I actually replicated the site not being responsive. I jumped onto the server and realized my `php-fpm` workers were exhausted and the site was just overwhelmed with traffic. Once I started following the access logs in real time I was amazed to see how many hits were coming in. So I downloaded all of those access logs and asked goaccess to parse them. A week of stats on leafapp.co I was kinda blown away seeing nearly 2 million hits a day with some days averaging half a million unique visits. I have no idea what occurred on May 27, 2026 when I almost hit a unique total of a 1 million visitors. This is a site running a database, cache (Redis), PHP and NGINX all on one server for $40/month. It seemed pretty cool to be holding that level of traffic on a PHP powered Laravel application. Now I wanted to dig in and see what was going on, because surely this was not all humans. A quick check with AI to help me group these requests confirmed my suspicion. Bot/Type | Requests ---|--- Human | 14,047,995 GPTBot | 4,605,881 Applebot | 3,082,590 MetaBot | 2,245,343 Amazonbot | 2,240,132 Bytespider/TikTok | 1,139,015 ClaudeBot | 737,153 Bingbot | 499,710 Googlebot | 270,827 DataForSeoBot | 260,621 Baiduspider | 74,465 Other Bot | 49,343 PetalBot | 44,870 AliyunSecBot | 25,206 SleepBot | 25,051 For only requests from May 17, 2026 to May 31, 2026 I tracked 29,327,202 total requests with 52% of those (15,279,207) being classified as non-human. I was mad I didn't have a bigger history of analytics, but my log rotation was purging out older stats as new data came in. I remembered a post I wrote 4 years ago about this same problem on this same site, but I was complaining about ~50,000 requests a day in that blog. Now I was dealing with ~2,000,000 hits a day stretching the limits of my equipment even more. I was mad at GPTBot (OpenAI) hitting my little tiny Halo Infinite site nearly 5 million times in 14 days. It is absolutely ridiculous of that scale of requests (357k/day) which surmounts to just analytics on Halo Infinite matches. It seems because they rotate around 400 different IPs that none of my "burst" rate limit detection works. I may need to research a smarter technique to target this form of AI bots harvesting content at an insane rate. So I wondered why GPTBot was obsessed with this, so I tried out a simple query myself on my own gamertag. Simple question with ChatGPT Sure enough this AI reached out to my server (again) and queried it to return the results. Perhaps this service is not caching any results, because I re-ran other tests and could watch the OpenAI hits come into my web server in real time. In the era prior to AI this search would have landed on my site leaving the visitor in my website ecosystem. Now people can harvest information from my site without ever visiting it. I'll head back to the drawing board, because bots consuming 52% of my daily traffic resulting in 100's of gigabytes of traffic is no longer okay for me.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 25/05/2026
Destiny 2 is on the way out - a long 9 years of gaming coming to an end.
connortumbleson.com
Destiny 2 is over
https://www.bungie.net/7/en/News/Article/d2_may_21_2026 A few days ago on May 21, 2026 Bungie released a blog post detailing the final content update for Destiny 2. June 6, 2026 would mark the last update for content in a game that started back in 2017. I hadn't really played Destiny 2 since 2024, but this was a sad post to read. I put over 2,000 hours on the original Destiny and met a ton of good friends that I remain in contact with as of now. The excellent first game led me to bridging away from Xbox gaming to building a gaming computer in preparation for the 2nd game. Destiny 2 launched and it wasn't that great with most of our clan becoming fractured in different games, because a lot of what made Destiny wonderful was changed for the worse in Destiny 2. Though every year or so a new major update came out and either massively improved the game or made changes that made myself wonder why I still played the game. When we look at every content update - this game was the new Bungie style of game with live-service and changes throughout the life of it. * Original Release - September 6, 2017 * Curse of Osiris - December 5, 2017 * Warmind - May 8, 2018 * Forsaken - September 4, 2018 * Shadowkeep - October 1, 2019 * Beyond Light - November 10, 2020 * The Witch Queen - February 20, 2022 * Lightfall - February 28, 2023 * The Final Shape - June 4, 2024 * Edge of Fate - July 5, 2025 * Monument of Triumph - June 6, 2026 While each DLC and update hit differently I still put 921 hours into Destiny 2 since 2017. As I left college and got older the repetitive nature of each DLC basically making all my previous guns worthless and forcing another grind took a toll on me towards the end of the game. It just didn't feel as fun that we had to grind a lot to obtain a light level worthy of competing in the end game content. So I just stopped playing and moved onward to other games. Each time I returned even as a player totaling over 3,000 hours across both titles I was lost on the home screen and unaware how to progress as I returned. The game was great, but not without its own flaws. Not all games can replicate the Fortnite level of player counts (~1 million a day) and content updates which is probably why Bungie started working on Marathon. "Runner" in Marathon Now it doesn't take a scientist to realize that a studio previously making one game is now making two games has an effect. That probably has the downside of taking talent that was previously working on the Destiny franchise. Now Marathon has had a rocky start which started during the alpha testing. As testing completed Bungie announced the release date delayed indefinitely so folks were left to wonder how far away from the original September 23, 2025 release would the game fall. At that point the game was in an interesting place - it wasn't the hardcore iteration of the extraction shooter that we've become to know from Tarkov. It wasn't Destiny 2 in terms of unlock once - own forever. It was an extraction shooter that you could play for an hour, lose everything and make no progression towards anything in the game. The population would tell you "_get good_ " and the guy playing for a bit after work felt sad with no progression and quit. https://x.com/4nt1r34l/status/1923067988871147605/photo/2 Around that time the testing was going on - it was learned that a bit of the art style and design was lifted from an artist without their knowledge. This just further stabbed a wound deeper that Bungie's next major IP was delayed and taking designs. This was an odd time as it seems folks were actively cheering for a game to be cancelled and more focus to be put back on Destiny. I didn't really understand cheering for the same studio that produces Destiny to fail on one of their other titles. It would obviously be detrimental to the studio regardless of the game at that point. A mini snippet of reviews targeting Marathon We are in such a weird point of time for video games that people literally pick games based on player counts. It seems odd to me because I still play Halo Infinite even though there is under 10,000 players because I like the game. Outside of that we can see a large influx of Destiny players leaving bad reviews on Marathon as "payback" for Destiny 2 being over. I don't get it - Destiny 2 came out in 2017. They established this massive story and introduced dark alongside light. They built up this massive villain (The Witness) and lead gamers on a 7 year journey to defeat them. Once we did, what could happen next? The game felt over at that point, but there is only so much content updates (that includes content removals) you can do before the game's lifespan is over. https://steamcharts.com/app/1085660#All The last time I played Destiny 2 was during the "The Final Shape" DLC which was in June of 2024. The attraction of a new campaign, a new raid and the saga ending was a good enough reason to return back to complete the vision they had intended. It was fun to quickly complete the campaign and grind to a high enough light to compete in the raid, but after that the glow of the game had evaporated. Now it wouldn't be fair to say Bungie ended Destiny because of Marathon, but I think its fair to say Bungie ended Destiny earlier because of Marathon. We knew another set of content was coming for Destiny, but all of that has appeared to end with this blog post. I'll never cheer for a game to die as a chunk of my video game history ends with the end of Destiny 2. Hopefully Bungie lives on through Marathon and future games as they are the famous creators of Halo.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 18/05/2026
Bsides Tampa is a yearly BSides event and each year it grows - this year I took a stab at the Badge Challenge.
connortumbleson.com
BSides Tampa 2026
https://bsidestampa.net (Year 13) As May 16, 2026 came to an end another BSides Tampa conference had ended. This had continued the growth path of more attendees, more staff and an even more streamlined logistical process. The ISC2 Tampa Chapter organizes this event each year and always continues to set the bar higher year after year. After blogging about the badge solution last year (2025) I set off this year to attend the intro and get to work cracking the badge in a race for first. I was declined like the previous year on my proposal to speak, so while I was sad again I had a chance to have no interruptions and just solve this puzzle. My journey of attending an intro & closing, a few expo hall visits, lunch and puzzle solving is not the only way to experience a BSides event. I had my eyes set on racing on a puzzle and wanted to see if my skills could still compete with an increasingly smarter pool of individuals attending. I took this year for the badge, but next year might have to re-balance with talks, keynotes, villages and more. I don't think two is a pattern yet, but much like last year here is my breakdown and solves of the 2026 BSides Tampa badge challenge. I failed to complete the CTF prior to the end of the event getting stuck on the 10th challenge which was funny enough solved within 10 minutes of getting home. It indeed was way more difficult than the year prior. * * * Spoilers ahead. ****Do not read**** if you wish to solve the 2026 badge CTF on your own. BSides Tampa 2026 Badge & Lanyard As I obtained my badge I sat down and got to work examining everything around the lanyard and badge seeing it full of a cryptic language I did not understand. I opened two markdown files for the lanyard and badge itself and got to work recording everything. I found my Google Pixel here was incredibly helpful as I could take a photo - run the lens feature and make text clickable, but not the foreign looking glyphs. The speed boost of leveraging Google Lens got me text way quicker than manually typing. The phrase on the lanyard was the key to understanding the badge with base64 hiding the plaintext. dGhlIGN1cnNlZCBjb2luIHNwZWFrcy4gdGhl IGxhbmd1YWdlIGlzIGFuY2llbnQgaHlsaWFu // the cursed coin speaks. the language is ancient hylian A few other messages were hidden on here, like "_xxx was here_ " and things to keep it fun. Once I pivoted my focus to the badge itself it was full of different forms of text. * `dW5sdWNreQo=` -> (base64) -> `unlucky` * `MTMK` -> (base64) -> `13` * `oernx gur phefr` -> (rot 13) -> `break the curse` * `{F4<:D?@E24@?EC@=` -> _unknown_ The outside of the badge in a circle had the writing "_05.16 2026 ????? ????????? PARTICIPANT ?????????? ???_ " I could not find a unicode representation of these characters, but thankfully the hint led us straight to the alphabet in use. This was ancient Hylian which is a shout out to the game of Zelda. A sort of made up video game language lends itself to not having an official unicode point thwarting some of today's LLM powers. A quick Google search with images of "_Ancient Hylian Alphabet_ " and I was just looking to match some of the symbols I saw on the badge. As I looked at the badge more closely I knew I had a group of 5 characters and 3, which I guessed immediately would probably represent `https` and `com` for a website address. https://25.media.tumblr.com/tumblr_m3b49xDtUm1qjldmuo1_500.png As I scanned Google images I stumbled upon this image above which matched immediately with the character associated with `h` and I knew immediately this would be my key to the puzzle. I sat looking at a symbol then the image above to draw out the message. The message and thus domain slowly started piecing together as: https://unlucky13[dot]notmalware[dot]fyi Which is where the real challenge was to begin once I landed on the site. The home page of the BSides Tampa 2026 Badge CTF Examining the HTML source of this to make sense of some of the gibberish below led to this HTML. <a href="./CHA1LENGE.html">CHA1LENGE</a> <a href="./2HALLENGE.html">2HALLENGE</a> <a href="./CHALL3NGE.html">CHALL3NGE</a> <a href="./CH4LLENGE.html">CH4LLENGE</a> <a href="./CHALLE5GE.html">CHALLE5GE</a> <a href="./CHALLEN6E.html">CHALLEN6E</a> <a href="./CHAL7ENGE.html">CHAL7ENGE</a> <a href="./C8ALLENGE.html">C8ALLENGE</a> <a href="./CHALLENG9.html">CHALLENG9</a> <br/><br/><br/> <a href="./CHALLENGE.html">C̵͓̯̭͐H̸̼̗̠̰̩̀͛̈́͂̿A̴̗̽̃̒͗L̶̪̬̋ͅL̸̘̼͗̀ͅÈ̸̡̎N̶̝̩̝͓̆͑̈́G̷̤̻̾͊̈́È̶͔̤̱̔͊</a> <a href="./284173569.html">2̶̬̲͓̻͆̌̽̄͊̂̍8̴̛͕͖̗̲͆͒̂̓̃̈́͆́̕4̵̛͈̱̺̦̠̱̻̹̺̋̅̍̀̉̈́͋̆̽͆1̶̟̼̰̺͒̔̽͠7̴̨͖̜͔̯̩̱̺̈̌̃̾̐̊͛̚̕͝3̴̮͚͕̲̗̝͇̣͌̂̑͒̂̒̒͘͠5̶̢̡̟͍̪͇̩̩͙̿͂́͗͐́̇6̶̡̣̗͉̖̝͖̦̳̩͖̀̑̀̅9̷̡̟͉̩̜̰̯͚̦͔̽̉͋́̂̍͗̎̚̚͠</a> <!-- <a href="./CHALLENGE13.html">CHALLENGE13</a> --> Source from home page. This was my 2nd year doing the badge challenge and I recognized the design from the previous year. This was great, because I immediately knew not to waste time looking at the 404 page or the css because it was roughly the same as the previous year. It looked like we had 1 through 9 ordered challenges, then two below and a hidden 13th challenge. It made me nervous that a 12th challenge was missing, but I'll be corrected if there was. I quickly made a markdown file for each one, posted the URL in each and got to work on each one. Thanks to Charlton & Eaton who joined me towards the last few questions and helped out with suggestions & hints. Jump to a section * Challenge 1 (glpyhs) * Challenge 2 (emojis) * Challenge 3 (js pass) * Challenge 4 (fonts) * Challenge 5 (lyrics) * Challenge 6 (ciphers) * Challenge 7 (polybius) * Challenge 8 (morse) * Challenge 9 (base6) * Challenge 10 (base10) * Challenge 11 (more ciphers) * Challenge 13 (submit) * * * ### **Challenge 1 (`CHA1LENGE` - "glyphs")** Puzzle 1 The hint followed the previous year with the top of the website showing the URL to visit with how many characters were expected. We had 11 glyphs and 11 expected characters so we were looking for the translation of this image. This is where the call out on the challenge of "_Be careful using AI on this one. It may hurt more than it helps._ " started really making sense. As I opened this image in its own tab it was a massive ~6000 pixels wide and looked liked it was hand drawn. I was guessing that someone must have manually redrew a language/cipher away from known glyphs to slow down an LLM. The glyphs all seem to involve angles and plenty of perfect right angles. So after a tip from Charlton of "right angle ciphers" I started with basic Google searching of "_glyph/cipher with right angles_ ". The annoying, but sometimes helpful Google AI popped up suggesting the Pigpen Cipher. https://www.boxentriq.com/alphabets/pigpen-cipher Initially, I was reluctant to trust this cipher because the symbols didn't truly match up to the image and there was one symbol I couldn't place. I remembered back to a Cicada 3301 solve I blogged about where misleading markers were introduced to a puzzle from 20 years ago to thwart automation. Once I started just letting my brain roughly match up the structure of the image with the Pigpen Cipher I knew I was on the right path as the word "Crypt" came into existence. I ended with `cryptglyph` which was missing a single letter and thus failed on every submission. That weird symbol I couldn't place must have been a letter and the only letter that really made sense was `o` to make `crytoglyph`. BSides 2026 Badge "Success" Page The page would return an HTTP 200 and a nice success message, so I knew I had to solve each puzzle and associate each puzzle with the solution and email out the answer to the email discovered in Challenge 13. * * * ### **Challenge 2 (`2HALLENGE` - "emojis")** Puzzle 2 Puzzle 2 looked like a breath of fresh air, because this new pattern of talking in emoji's or coding in emoji's has been a new trend going around. I researched "emoji decoder" and landed on the base100 decoder. https://www.boxentriq.com/encodings/base100-decoder That one was quick and I knew that `🐺👩👰👧👫👜👯🐼👦👥` equaled `CryptexEon`, but to my surprise it didn't work in the URL. This wasn't a real word that I could see and I retried a different site for base-100 and came up with the same result. I lowered the entire string (`cryptexeon`) and it worked! I was now nervous knowing the answer was case sensitive for submission. * * * ### **Challenge 3 (`CHALL3NGE` - "js pass")** Puzzle 3 My favorite type of puzzle arrived on the 3rd which looked like a client side password check. Sure enough you could find the code for the password check in plaintext in the JavaScript. const encoded = "ZXJpb21pcmdhdGFk"; const transformed = btoa(input.split("").reverse().join("")); if (transformed === encoded) { resultEl.textContent = "Access Granted"; } For web developers you recognize the pair of `btoa` and `atob` anywhere which basically transmits binary to ascii (base64) in either direction depending on the function used. Above you can tell our input is split into an array (each character alone), so it can be reversed then joined back to a string. So we just wanted to reverse that. atob("ZXJpb21pcmdhdGFk").split("").reverse().join("") // datagrimoire Since the input was passed into `btoa`. We had to first reverse `btoa` with `atob` and then reverse the reversed text. Sure enough after execution we had `datagrimoire` and a successful URL entry. * * * ### **Challenge 4 (`CH4LLENGE` - "fonts")** Puzzle 4 The 4th puzzle had the phrase "TRUST NOTHING" in backward text, but oddly when you copy and pasted it was the exact spelling. This meant we had to have a custom font in play and sure enough I found it imported at the top. @font-face { font-family: "ctfFont"; src: url("/fonts/CTF.woff2"); } .clue { font-family: "ctfFont"; } I was excited for a bit that the font name was `Clarxndon` which was 9 characters, but alas it was not the answer. I downloaded that custom font and loaded it into FontDrop to visualize all the characters in the font. The font with "getting closer" and "FELAG(NECYOBYT)" I spent far longer than I'd like to admit just looking at this image above. I saw `FELAG()` and I thought that was a hint that the flag was in between the parenthesis, but the value wasn't enough characters. With the phrase `getting closer` at the bottom, but my glyphs on top it was introducing some confusion to me. Switching between puzzles and returning I realized it was quite obvious. Just move the `E` from `FELAG` to spell out `FLAG(NECRYOBYTE)`. It took a bit knowing the answer was case sensitive, but ended with `NecroByte` as the answer. * * * ### **Challenge 5 (`CHALLE5GE` - "lyrics")** Puzzle 5 This was an interesting puzzle because it had a 404 spammed in the console and I couldn't tell if it was a bug or part of the puzzle. This `lyrics.txt` file did not exist, but maybe it was intentional to draw my attention to the lyrics. fetch("./lyrics.txt") .then(r => r.text()) .then(text => { document.querySelector(".bg").content = text; }); This led me to noticing the background text changed. I lightened up the CSS and sure enough it was the lyrics to the famous "rick roll" song. Background removed to see the CSS. Immediately from prior experience I remember doing a Cicada 3301 puzzle (Part 1 Extra) that required me to use the numbers as indexes to pluck characters within the lyrics of the song. With a bunch of numbers given to me I figured this would be the same type of solve. I asked AI how to get the value of a style property and got the numbers in an array with 2 lines. const nums = [32,254,23,73,65,89,226,162,15,41]; const raw = getComputedStyle(document.documentElement).getPropertyValue('--lyrics'); So I tried to iterate the numbers from the website looking for the value at the index of the number. Basically for the 1st one - what is the 32nd character in the lyrics. console.log(nums.map(n => raw[n]).join('')); This produced gibberish, so I dumped the lyrics variable and saw a bunch of spaces and quotes that probably were not intended. So a quick trim and a command to remove the trailing and beginning double quote led to. const trimmed = raw.trim().slice(1, -1); console.log(nums.map(n => trimmed[n]).join('')); // neoncipheu That dumped out a value that looked real, but didn't work. Once again this was probably intentional and required a human to just look at the value and swap it to `neoncipher` which looked real. I'm guessing all these tricks were to prevent an LLM from just hammering solutions and looking for a non-404. As it would hit this result and 404 and probably think nothing of it. * * * ### **Challenge 6 (`CHALLEN6E` - "ciphers")** Puzzle 6 This challenge was funny, because I sure clicked the link and some countdown began and then redirected me to the YouTube video you'd expect. I inspected the HTML to see what this link did and spotted a hint. <div class="clue"> <div id="dont" onclick="dontdoit()">DO NOT CLICK THIS</div> <div id="hiddenClue" style="display: none;"> krqbPbanA </div> </div> This value had special casing and didn't really spell anything, so it was off to the classic ROT website that does every single ROT rotation (0-25) at once. Rotation ciphers have been heavily used in previous Tampa BSides puzzles and don't require a key so always a possibility. ROT-13: xedoConaN https://theblob.org/rot.cgi?text=krqbPbanA Knowing this was the 13th BSides Tampa - ROT-13 seemed like it smelled Conan at the end, but the front didn't make much sense. Though looking at it backwards looked like Nano, so a quick `rev` command answered this one. ➜ echo "xedoConaN" | rev NanoCodex * * * ### **Challenge 7 (`CHAL7ENGE` - "**polybius**")** ### Puzzle 7 Puzzle 7 is when things started to slow down as I was presented with these blobs that didn't immediately click as anything. <div class="clue-larger" style="padding-top: 75px;"> <!-- censorship sucks, amirite!? --> █|█ ████|██ █|███ █|█ ███|███ █|█████ <br> █████|█ █|█████ █|███ ████|████ ███|████ ████|██ </div> The more I looked though the more I realized each box surrounded a pipe character had a different amount of boxes on each side. The max I saw was 1 box and 5 at the most. This reminded me of a 5x5 grid, which has been used in Cicada 3301 puzzles in the past. I couldn't remember what it was called, but searching for "_coordinate cipher 5x5_ " immediately loaded the "Polybius Square Cipher". | 1 | 2 | 3 | 4 | 5 ---|---|---|---|---|--- 1 | A | B | C | D | E 2 | F | G | H | I | K 3 | L | M | N | O | P 4 | Q | R | S | T | U 5 | V | W | X | Y | Z So I counted each line: * Line 1 - `1,1 4,2 1,3 1,1 3,3 1,5` * Line 2 - `5,1 1,5 1,3 4,4 3,4 4,2` I then started the boring process of finding `1,1` on the grid (`A`), then `4,2` (`R`) and a phrase started appearing of `arcanevector`. Capitalization struck again and I needed to format it as `ArcaneVector` to be accepted. * * * ### **Challenge 8 (`C8ALLENGE` - "morse")** Puzzle 8 This was the most intense challenge of all of them as it required you to do a bit in the real world. Right out of the gate like has become a pattern we try all the ROT ciphers and find a hit on ROT-13. ROT-13: Did you know that SAO port on your badge is the full v1.69bis spec? I wonder what would happen if you bridged GPIO1 and GPIO2..? This hint is suggesting that our badge has a SAO (Shitty Add-on) port and suggesting we should bridge (ie connect) `GPIO1` and `GPI02`. I knew this was a clever challenge as no way AI was going to be helping you here. I researched "_v1.69bis spec_ " and landed on this hackaday project which had a pinout for the pins on the badge. If we were bridging a connection from a mini computer to the output - we only had a colorful diode so that massively limited our options of what the output format could be. https://hackaday.io/project/52950-shitty-add-ons/log/159806-introducing-the-shitty-add-on-v169bis-standard Knowing the ground line (GND) had to not be connected to anything it was pretty easy to orientate ourself on the badge following the lines. Especially since one of my friends sitting with me had a sponsor badge which was white and much easier to see the schematics. So we now had the problem of needing to bridge two ports together which at a massive security conference should hopefully be no problem. At first though I started using my car keys and when I saw the colorful lights immediately stop and turn bright red with a morse-like color blinking I was hooked that we were on the right path. So the few friends and I packed up our stuff and wandered around the expo hall looking for something that could be used to bridge two ports. Amazingly we stumbled upon the electronic recycling booth and the guy amazingly just pulled out a device destined for recycling and ripped a cable off. That cable was then stripped down to the metal underneath and twisted into a nice little tiny cable and shoved between the two pins. 0:00 /0:08 1× Pushing my hand against the pins to connect `GPIO1` & `GPIO2` At home when I can balance the light perfectly you can see how the random colors revert to a pure red with a morse-code like blinking color when I apply pressure to press the cable against the two pins. This made sense why the intro announced the smartest badge ever, because it had a little computer onboard to spit out morse code. Now I can't read morse code at all, so I researched if an online tool existed to read a video stream to parse out morse. I found a Reddit thread with a working link of such a tool. 0:00 /0:26 1× Using S-Morse to parse morse code of badge. As I sat there at a table in BSides oddly recording myself holding the badge up to my computer I'm sure a few wondered what I was doing. Either way as I saw human words appear in plaintext before my eyes I was amazed. I just didn't know if the answer was `TempleOmega` or `OmegaTemple` and a few guesses later it was confirmed at `OmegaTemple`. The coolest puzzle of the CTF was done. * * * ### **Challenge 9 (`CHALLENG9` - "base6")** ### Puzzle 9 Puzzle 9 was colorful and after staring at it long enough I noticed the first and last row were the same. There were 6 different colors in use and the solution was 9 characters long. The HTML was quite verbose, so I asked AI to clean it up. <tr> <td class="cell r"></td><td class="cell r"></td><td class="cell r"></td> <td class="cell o"></td><td class="cell o"></td><td class="cell o"></td> <td class="cell y"></td><td class="cell y"></td><td class="cell y"></td> <td class="cell g"></td><td class="cell g"></td><td class="cell g"></td> <td class="cell b"></td><td class="cell b"></td><td class="cell b"></td> <td class="cell p"></td><td class="cell p"></td><td class="cell p"></td> </tr> Which ended up becoming a bit more plaintext and easier to read. rrr ooo yyy ggg bbb ppp (header) yyr yrr opg rpy opb yrb obp opp rpy ygg yoo yyo rpy yop opg opg yrg rpy yro yop rpy yrr opg yob opg ogb rpy yop yro opp yro yrb opo yoo yob opg rrr ooo yyy ggg bbb ppp (footer) r=red, o=orange, y=yellow, g=green, b=blue, p=purple No matter how I diced the letters or grouping there was way more letters than 9, so I figured to just start brute-forcing some solves. Had to brush up on my math to consider some possibilities here. I guessed each grouping of 3 characters was an ASCII numeric representation of a letter. For those unaware generally the A-Z part of the alphabet in ASCII is numeric 65-172 roughly. So I took the first 9 letters (`yyr yrr opg`) and converted to decimals using an assumption that the header/footer defined our color grid (`red=0`, `orange=1`, etc). This resulted in a gibberish so it was probably not base-10. Diagram of solving Puzzle 9 Once I took the decimal value (`220`) and converted it to base-6 (`84`) that fit much better in the ASCII chart and rendered as `T`. Likewise the rest of the letters decoded as `THE` and I realized I was on the right track. yyr = 220 = 84 = T yrr = 200 = 72 = H opg = 153 = 69 = E rpy = 052 = 32 = (space) opb = 154 = 70 = F yrb = 204 = 76 = L obp = 145 = 65 = A opp = 155 = 71 = G rpy = 052 = 32 = (space) ygg = 233 = 93 = ] yoo = 211 = 79 = O yyo = 221 = 85 = U rpy = 052 = 32 = (space) yop = 215 = 83 = S opg = 153 = 69 = E opg = 153 = 69 = E yrg = 203 = 75 = K rpy = 052 = 32 = (space) yro = 201 = 73 = I yop = 215 = 83 = S rpy = 052 = 32 = (space) yrr = 200 = 72 = H opg = 153 = 69 = E yob = 214 = 82 = R opg = 153 = 69 = E ogb = 134 = 58 = : rpy = 052 = 32 = (space) yop = 215 = 83 = S yro = 201 = 73 = I opp = 155 = 71 = G yro = 201 = 73 = I yrb = 204 = 76 = L opo = 151 = 67 = C yoo = 211 = 79 = O yob = 214 = 82 = R opg = 153 = 69 = E Decoding each pair into decimal into base6 into ascii Outside of triple checking one that kept decoding as a `]` the message became clear. THE FLAG YOU SEEK IS HERE: SIGILCORE You had to lowercase it as only `sigilcore` was accepted. * * * ### **Challenge 10 (`CHALLENGE` - "base10")** Puzzle 10 This is the puzzle that stumped me for a few hours and was unfortunately a bit easier once I got home with a refreshed brain. This odd font has so many names over the years, but generally is called "Zalgo text" after some real creepy old stories on the web. If we try and look at it as-is its impossible to parse. <div class="clue"> ~̴̹͊͌̀̕͠͠Ō̸̙̤̥̯̤̠̊́̌̈́̽͘̕͝Ì̴̤͙̣̫̳̕͠B̶͍̟͔̣͆̌͆͛̈́̾Ḑ̸̳̖͖͔̮̋̄̀͛̿́͜͝͠E̵̡̲̫̺̬͋̋́͂̚͜x̸̪͉̝͖͙̙̫̗͆̏̔̃̓_̶̡̱̰̮̭̬̠̒͂͝͝Ḋ̶̨̜̜̠́̑O̷̯̒̂̎̀͝ </div> A Zalgo remover makes quick work to turn this into something readable - `~OIBDEx_DO`. We know the answer needs to be 10 characters and yet the random mash of characters we have is 10 as well. I turned them into the numeric representation, but not till I was home did I make the connection of what to do. ~ 126 O 79 I 73 B 66 D 68 E 69 x 120 _ 95 D 68 O 79 ASCII representation of Zalgo removed text. I kept looking at the homepage and wondering why the 10th challenge didn't have a 10 in the URL like the others and I wondered why there was a challenge named `284173569`. Homepage I wondered what would happened if I took the numeric value of each challenge in the place it was in the URL and combined them into a number. Once I started doing that I realized I was spelling the 11th challenge - `284173569`. So question 10 had no representation of 10 in the URL. So I asked AI to perform every form of arithmetic of 10 against the ASCII representation of the values. As I watched it do `add`, `subtract`, `mod`, `shift`, `xor` it got a hit on `xor`. ~ 126 ^ 10 = 116 t O 79 ^ 10 = 69 E I 73 ^ 10 = 67 C B 66 ^ 10 = 72 H D 68 ^ 10 = 78 N E 69 ^ 10 = 79 O x 120 ^ 10 = 114 r _ 95 ^ 10 = 85 U D 68 ^ 10 = 78 N O 79 ^ 10 = 69 E Taking the value (ASCII) - xor (10) This spelled `tECHNOrUNE`, which when corrected to `TechnoRune` was correct. This was the only puzzle that I did not complete in time and I was mad about it as it was far easier than I was making it. * * * ### **Challenge 11 (`284173569` - "more ciphers")** Puzzle 11 Puzzle 11 was another iteration of the massively confusing Zalgo text. <div class="clue"> =̶̧̛̪͚͔̬̯̥̻̬̭̘̲̩͎̤̥̗̘͎̞̘̞̖̘̠̭̫̙͊̑̃̆͆̓͂͆͂͌̑͗̌̉̽͘̕͘≠̧̮̙͕͎̙͚̼̮̤̘̩̖̟̹͋͐͛̉́͑̀͑̂̆̍̒̈͝͝g̵̟͓̩͒̊̐̋̀͆̽̃̈̑̃͊͊͆C̶̨̨̛̜͎̭̤͔͙̬̬̭̞̥̻̯̺̫͖̪͌̇̄̾́͐̈́̂͜͜ÿ̷̡̨̹̭̰̰̪͓̮̠̺̖͙̭̼̥͚̖͓̗́̉̀̇͒͑͛̑͊͋̓̈́͒͋̌̃̊̃̒́̓̕̕͘ͅͅḻ̷̟̳̐̓̔͂̀̀͂̆̒̋͝Ḧ̸̭̫͓̫̙͔̗̞͚̥̬̤̦́͛̒̄̑͑̿̔̈́̌̀́͘c̶̛̛̟͍̮͈̗͎̜̳̰̆̆͋̐̈́́̓̾̎̐̅̔̊̋̇̑̈́̇̔̈́̆͊͝u̶͍̺̤̘͔̖̣̣͉̟̩͉̬̩̿̓̌̓̑̓̈́́͜V̷̨͔̺̝̱̬̱̲̩͊̀̿͆̐̌́͗̐̃̊̅̔̇͆͒͘̕͝͝m̷̳͈̫̳̙͓̺̞̹͎̍̑̈́̓̿̋̅̓̆̎͠Q̶̢̺͙͙͕̞̤͎͚̰̟͓̣̼̦̟̯̗̀́̆̔́̀̉͐̋͜͝ẁ̶̨̛̛̮̪͔̠̞̘̑̆̀͌̍͛͌̎̽̀̍̃̇̿Ź̴̢̹̳̠̘̙̤̘͉̲͙͙͙̰̠͙͍̽̄͋̎͝3̴̧̬͉̩̐̊̊͊̎̌̍̊̓̌̿͊̌̂̋̍̚͘̚͝Z̶̟̫̳̗̗͉̞̯̻̫̠̻̏̋̒̊̎́̄̋̋̈́̄̏͊̊̈́̀͗́͘͜y̷̨̨̧̧̛̛̮̞̲̺̟̼̟̫͇̫̯͙̰͍͍̞̥͗̀̌̈͐̈́͛̈́́̌̓͑̍̈́̓̊̂́̃͝͝͠V̵̢̧͚̖͙͇̪͓͔̘̿͊͑͑̒͂͌́̉̀̓͘͜͝3̷̢̡̢̯̱̣̻̘͎̘͔͎̮̬̯̟̋̑̍̓̈́̓̏̐̓̄͌͘̕̚͜͝͝͠Z̵̨̡͓̫͔̜͓̟̟͚͎̠͓͍̞͕͕̙̘͙̑̾̓̅͛̔̐̑̐̈́͌̽͗̄̅͗̇̿́̌̃́͘̕̚͠ḧ̶̨̧͚̥͔̺̲͎̤̖̥̞͖̺͍̠̺̳̯̖͈̩̼̥͛͑͛̏͗̋̀̓̄̈́̃͝ͅẍ̵̨̢̡̬̟͓̼͚͓͚̫͚̪̠̺͓̗̰͍̖̫̹͖͍̭̩͈́̓͌̈́̂̈́̍͗͗͒̓͝͝m̴̧̡̨̙͕̦̟̥̺̬͙̩̤̞̭̻͇̝̦̟̳̳̠̆̒̈̇̐̉̏̑̚̕͘͜͜͜͝ͅͅR̵̤̭̕ </div> HTML of Puzzle 13 Another round of Zalgo removal and we got a string that immediately looked like a reversed base64. ➜ echo "==gCylHcuVmQwZ3ZyV3ZhxmR" | rev | base64 -d FlagurgvpBenpyr This was another incorrect value, but knowing the pattern that had developed it was one simple ROT-13 away from spelling `SyntheticOracle` and we were done. * * * ### **Challenge 13 (`CHALLENGE13` - "submit")** Puzzle 13 It seemed like the name of the game towards the end of the CTF was Zalgo text. <div class="clue-larger"> <p>you should not b̵e̷ ̸h̵e̴r̸e̵.<br>b̴͚͑ṳ̸̈t̶͙͝ ̸̣͝i̴̠̔f̸̗̃ ̷̭̈y̷̺̅o̵͔̓ű̷̩ ̸̢̥͝a̶̯͗̒̋͘r̸̖̥͔̞̀̓é̴̦̣ ̷͍͆̓̈͝a̷̮͎̠̎̃̅̆n̴͒̚͜d̵̩̫̽̾͝ ̷̝̩̣̱͐̿y̷̮̭̐͋͒͜ö̶́͜͠u̴̙̎̔̃̂ ̸̢̧̤̞̪̤̘̤͎͈̤̳͐ͅh̴͓̳̫̦̱͗̅̌̀͐͜ä̷̧̛̩͉̰̭̳̰̬́͋̍̈́̔͒̎̎̏̾͌ͅv̷͔͙͍̮̻̱̯̟̿ȩ̴̨̱͖̫̦͔̹͂̊͂͝ ̶̢͕̪͗͒̽̓̓́̇̾̋͊̊̈́̇̂͋͝c̶̻̻͋̅̍̍͐̾̅͑̽̒̽̚͝ȏ̴̢̻͓̫̞͚̣̺̾̍͜ͅm̸͔̮̬̊̃̓́̒̽̿̇p̶̢͚̥̯̩͂̆̏̓͐̿̀̚ḻ̸̥̰̒͝e̶̬̜̝̻͕̝̦̹̺͍̹̠͓̭͖̦͑͊͊̌̇̽͐͑t̵̡͈̬̼̪̬͖̖͕̳̼̩̦̰̮́e̴̡͉̤̳̞̤̼͗̒̂̔̀̓̎̂̈̈̕͠͝d̸̘̦̳̭̻̄̒̍̽̔͗͒̔̄̀͝͝͝͝ <br> a̵͉̩̖͑̇̋̄̿̎̍̿́̀́̈́͆̑̿́̚ļ̶̡̨̢̢̢͔̝͎̦̬̟͖̜͇̠͙͓̯̈́̅̽͑͜͝ļ̶̬̺̝̺̦̝͉̺̪͉͇̠̥͒̑̌̾̏̾̑͆̈̓͒́̈́ ̵͈̟͈̝̣̤̲̣͕̟̜̙̜͙͚͎̊͜͝o̴̠̱̹̮̯͙͖̎̽̀̿̈́͐͊͛̋͊̿̽́̆̓̊̃͘͜͠f̵̛̭͉̝̲̟͕͍̳̥͛̌̍͐͑̍̆̑̀̕͜͜͝͝͠ͅ ̴̨̢̖̱͚̙̫̐̑͜ţ̴̡̜̟̮̪͇̫̹̲̩̓̊̆͗̐͜ͅh̷͎̞̺̟̫̓̋͑̒̐̏͌̉͊̅͑̋̓̌͋͂͠ͅe̶̩͓̲͍̣͈͔̦̗̝͉̜̋̾̓ͅ ̵̛͙͈̲̯̙͂͐̓́͆͒̿̏͑͊̅̐͛̊̿͂̚͠͝c̷̭̳̪͇̳͉͉̀̋̉̄̂͐͛̈̈́̚̕h̶̨̘̰̝̙̱͉̹̱͓̣̹̦͙̜̱͕͉͖̰͉̞͈̻̎̇̽͂̓̉͝͠͝å̴̢̢͖͔̘̯͔͔̖͎̰̺̲̳̥͈͎̝̻̳̬̟̫͈̰͉͉̠̆̾͌̽̀̈́̄̍͝͝l̴̡͙͕̹̺̺͈̻̈́͆̄́́̇̎̀͑̓́̂̍̽͋͋̿̅̋́̾̈̾́͗͝l̷͚͇̰̘̻̝͇̭̺̣̱̓͗̀̓̓̍̈́͆̆̓̕͝͝é̸͔͙̪̜̌̓̾͊̑̽̔̈́́̂͗̆̀̋̑̈̈̍̌̎̚͝ņ̶̼̲̬͇̤̀̿͒̒̆͝͠ģ̸͈̫͍͍̙̯̘̙͕̣͉͈͍͉̖̫̹͉̻̳̫͔̞̮͂̊̏ͅȩ̵̧̧̹̺͕̬̘͖͍̙̙̘̬͚͎͖̩̙͉͖̣̘̈́̽̏̿͒͑̔́̔͂̓͌͘̚s̴̛͖̫͓͎̜̉̎͐̑͗́͂̄́̄̃͋̚͜͝͝,̶̧̧̺̣̰̰̥͙̯̣͔̙͉̼̬̫͍͔̠̝̜̫̘̖̳̗̈́̓̎̌͑̍͌̊̃̓̈́͋͑̓̽̍̚͜͜ ̴̙̣̖͖̤͖̟̼͈̰̘͔͈͈͕̣͚̟͔̲̍̅̀̋͑̏͆̉̉͛̔̋̅͒̅̆͒͗̚̚͜͝ͅ <br>S̸̢̢̢̛̛̤̜̗̙̞̙̪̲̹̠͖̯̪̝͕̫̼̭͖̘͕̰̩̭̬̬͓̣̼̺͍̯̖̱̼͑̌̉͗̈̀̋͌͑̀̔̒̃̎̒̂̒̇̌̏̊͗̓̂͗̀̏̋̏̋͑̽͑̆͛̂͗͂́́̿̈͛̐͑̑̚̚̕ͅṲ̶̢̡͕̠̞̯͔̳̜̗̮͙̭̻̻̰͙͖̯̞̘̣̟̞͍̫̭̹̦͎̦͈̗̱͇͕̰̗͈̲̹̈́̋̄͛͛͆̈́̈́ͅͅB̶̧̡̨̢̛̠̰̥͍͇͇̩̜̼̗̹̠͇̝͈̫͙͍͓̒͐̀̄̍̂͆̄̂̓͆̀̈͆̂̄͛̀͐͒̑̚͘̕̕͝͝͝͠ͅM̸̢̛̼̘͖͇͕̣̰͖̟̰̩̘͎͇͇̹̦̖̟̲̟̲̼̳͙̱̒̈́̿̄̇̈́̑̀̉̉͐̍̍̅̂̿͗͑̈́̄͒̓͋̈́̉̀̓͌͂̑̈̾̈́̍́̚ͅĮ̴̧̡̭͉̼̜̹͇̗̯̠͖̩̜͚̦̞͔͖̙̣̠̖̲͓͚̩͍̩̟̝̼͓̯̮͇̻̳̞̠̉̓̈̄̉͌̓͌͒̽̐̆̈̔͆̉͊̍̅̔̃̈͆̊̄͐̄̉̓́̃́̔̌̑̆͐̏̅͌͂̆̆̾̈́̕͘̕͘͝͠͠͝͠͠͝͝T̶̡̡̢̖̥̭̦͇̮̰̞̪̦͇̯̭͖͉͙̺̭͙͓̰̬̼̮͖͚́͊͊͗̔̓͆͒̚ͅ ̶̨̛͉͕̠͇̲̗̤͔̘͔̻̰̞͖̩̣̬̠̹̰̞̈́̀͒̔̄̋̉͂͆̌̂̒͗͑̔̔͂̽͗̒͑͂̊̈́̐̑͗̀̇̈́̅͌́̆̉͋͐̒̾̃̚͘͝͝͝͝͝ͅT̶̗̮̋̈́̋̍̎H̶͉̫͔̣̩̰͔͎̼̙̼̱̼̪̫̝̗̮̬͇̬̺̺̖̱̪̣̩͆͐́́̓̆͊͜͝ͅĘ̷̨̻͖̣̜͖͔̯̦̭͈̖̥͚̗̺̻̘̲͕͚͂̌̈́̿̎̾͑͂͗͌́͑̾̾̒͜͝M̶̧̢̛̥͙̭͖̤̮͇̳̣͉̦̬̪̄̋̔̍̌͆̓̆̂̓͋͆͋̆͐̿̋̎̔̏͛͒̍̑̇͌̓̈͂̓̈́̾̾̀̀̒̂̀̈̃͛̃͐̂̿̒͘̚̚͝͠͠͝͝͠ ̸̧̝̝͖̻̥͙̩̮͍̇̊̍̔͑̃͝Ḩ̸̡̨̨̢̡̨̛̗̻̹̘̦̭͈͓̜͍̩͓͈̱͚̱̥̜̭͎̘͍̲̰͉͍̜̥̝̠͔͕̬̠͕͎͚͈̠̮͓͔̤̮̭̥̜̀͊̐̂̔͋̈̑͒̃̈́̃̎́͛̐̄̄̓͆̔͒̃̉̈́̍́̊̽̈́̑̅́̂͌̓͘̕̕̚͜͜͝͠ͅĘ̵̡̛̛̼̞̹̜̣̦̯͙̅̽̾̄̅̄̓̌͐̑́̃͆̉̊̒̑̌̈́̉͌̒̓̀̇́̔̎̇͌̄̈́̿͐̆̓̅͑͆̇̿́̆̀̊̅̊́̈́́̂̈̉̕͝͝Ŗ̷̡̧̢̧̛̥̮͈̘͙̙͔̬̜͎̙̟̫̫͉̱̺͇͎͙̘̙͈̬̪̖̙̰͚̗̞͉̘̙̮̗͇̠͍̟̭̹͇̯̼̯̙̞̈́̇́̇̍̅͊̆́̓̀͂͊̄̂̉̒̉̿̊̚͘̚͝E̶̢̜̙̟̜̣͕͎̝̼͚̞͕̺͈̰̥̥̞̪̪̙͉̯̹̭̩̫͈̜͇̪̲̻̹͍̩͎̗͇̜̗͋̓͐̍̔́̈́̀̉͌͐̾̀̔͑̈́̈́̔͐̒͐͑̆̎̈́͛̋͂͒̀̀̍̎́͊͛̈͛͌̀͘̚͘͝͝͠͠͝͠ͅ<br><br>6̴̛̝̱̼̙̞̬̩̲̗̓̈̀͒͊̊̈́̌̇̿̌̕A̶̡̛͍͈̼̠̟̟̖̗͚̖̻̲̜̍͋͂̈̃͂̊͊̎̆̂̓̕͘͝͝6̶̢̛̖̬̥̥̖̥̘̿̒̄̂ͅ7̴̡̯̲̖̫͔̖̲̱̤̑̀̍͗͛͌̐̄͑ ̵̡̭̩̜͖͉̞̫̦̺̳̃̃́̔͆͠/̴̡̛͉̞͙͍̿́͆̃͘̕͜͠/̸̛̛̗̩̙̬̲̜͑̐̎͌̏́̿̈́͋́͆͘͝͠ ̸̡̡̳͖͉̜͔͔̫̪̼̓͑͝ͅͅ7̸̡͕͙̬͇͙̼̰̣̦̭̤͂͂͛̄̐̽́̕͝2̷̨̳̯̋͊̂̇̉͂̐̄̋̕6̶̧̢͖̮̥̖̜̺̱͕̉̇͌͜͠F̵͔̺̦̮͎͙̊̉̓̑̄͑̓͘͜ ̷̣͂̋̓͛̐̈́͑̌͊̈́̈́̽̓̈̽/̵̙͐̂̊̾̒̋͗̓̿̀̐͗̑͌̇͠/̶̡̜̣̼͎̫͓̹̜̰̖̯̈́ ̸̨̘̮̳̾̆̄͐̊͑͐̉̍̈̓͋̍͊̕̕͝7̶̮̌͛̽́̏͝3̷̧͎͈̞͇͍̲͕̀̏͐̔̽̊6̴̫͖̠̘̟̳̺̻̱̠̱͕̓̃̌̐̍̿͊̄̃̓́͜͠5̴̧̙͚͓͉̺̫͍̦̫̗̰͓̮̬͆̀͒̉̀͛̓̎͊̚͜͜͠͠͠ ̵̙͎͔̙̙̞͕̬͈̼̫̙͕͇̳͔̼̋͋̍̌̄͆̅̕͝͝/̶͚͎̮̤̇̆͂͒̽̏̈́͛͘͝/̵̛̛̻̓̈́̎̋̆͂̍̾̈́̐̎̌̓͘͘ ̸̛̜͎̩̈́̐̈͛̋̅̽̐̏̉͒͆͐̐̕ͅ4̴̛̝̻̞̟͚̠̯̮̄̅̋̓͛̚͜0̸̧̨̨̞͈̫͎̤̪̖̞͓̎̔̍͊̀̑̏̍̋̀̉́͌̀̃͋̇6̷̢̡̡̳̖͇̙̖͖̱̳̠̬̪̲̫̗̿͗̓̉̉̈́̈́̓̈́͋̕7̴͈̥̙̩̾ ̴̲̦̹͈̝̝͈̬͂͊͒͐̏̏͊̒́̀̔̓̓̕ͅ/̴̛̝͓̫͎͔͖̲͙̗̦̘̱̞̳̘̄̋͛͐̑̀̊̓̓̈́͜͠/̷̧̨̡͔̖͚̟̼̌̈́̅͐̔̀ ̴̡̢̭̞̲͎͇̰͈͉̪̳̳̣͑̾̎̀̏̎͌̒̕͝6̵̲̣̦͇̬͛̓̋̋D̴̹͓̟͇̫̳͉̼̗͕̲̓̆̓͆̾̄͊̓6̷͙̝̺̮͕̱̙̹͚͔̩͎̖̻̯̿̈́̌͐̚͝ͅ1̸͕̝̰̻̗̦̥̹̣̪͇͇̟̭̳͑̎͋̽́̇͆́ ̸̨̧̠͚̦̯͓̟̮͇̲̏̉̓/̸̢̛͖̫̎́͗̀̍̔̇̏́̈͛͑͒͘͘/̴̢̛̤̺͍̗̠̲̀̒̒̓̉̒͑̓͋̂̀̾̅́͝ͅ ̸̨̡̦͍̤̹̤̞̀͛̒̐̀̈́͗̑̇́̕̕̚̕͝6̴̨̺͉̻̠̝̱̮̠̫̩͓̞̬̙̈́̔̐̈́̾̿̎̕͝9̶̡͔̤̣̯̩̟̬̲̰̼̥͉̜͉̿ͅͅ6̸̡̰͊̽̒̀̔͛̄̂̾͠Ç̸͉̹͚̝̘̣͆ ̷̡͕̠̔̀/̷̧̧̢̧̼̯͚̖̙̖̰͔̼̖̳̄̽̆͆̋̽ͅͅ/̶̧̡̡̹̗̼͍̦̪͖̥͙̰̒̊͛̎̄̏̈̎̌͆̔̚͜͠ ̴̩̱̽̑͑͌̌̈́̌̂̎̂̏̊̽̕̕2̶̧͖̫̗̟̞̤͓͎̖͓̦̥͓͑̓̚E̴̛̛̛̝̫̺̤͙̘̯̫̤̺̜̿̀̀̽̆͌͊̏̑͐̓̚̕̚6̸̢̨̫͍̩̩̂͑̊͊̎͐3̶̱̀̓̇͒̑̒͐̑́̓̇ ̵͍̠̼̏̌̏̃̅͒͑́/̵͖̕/̴̡̡̛͔͎̣̼̗̠̖̠̫͎̞̲̼̘̈́̀̃̇́͋̅̾̂͆͊͌̎͘̚͜͝ ̴̨̮̜͙̞̖̯̰̫̜̼͓̻̃̌̐͐́̈́6̵̢̢͓̰̖̟̦̤͕͔̱̝̥͙͕̼͉͗̿Ḟ̶͓̜̩̼̹̘̱̝͍̈́̏̔̌̔͐̋̐̔̔̎̏̐̕̚6̴̢̢̤̥̗͙̖͈̝̺̱̙̼͖̤̹͗D̵̢̢̲̠͙̫̤̟̪͈̹̝͐</p> </div> Which decoded towards: <div class="clue-larger"> <p>you should not be here.<br>but if you are and you have completed <br> all of the challenges, <br>SUBMIT THEM HERE <br><br> XXXX // XXXX // XXXX // XXXX // 6D61 // XXXX // XXXX // XXXX </p> </div> Since this decodes to a real email I've redacted the values. This was a basic hexadecimal value that decoded to a gmail address. I emailed it anyway with 11/12 challenges completed thanking the creator for a great CTF as I closed my laptop to head to the closing remarks. * * * As I walked to the closing remarks I wondered how much AI had changed the CTF landscape. I could tell this challenge tried to trick the LLM and even block their network calls for pure automation and it really got me wondering about the future of CTFs. Hearing the winners solved it in about 6 hours was good to hear, because if it was solved in like sub-hour it was probably just an LLM solving things in one shot. Though reading back through the Discord channel a team claimed a solution at 11am in the morning which conflicted with the closing remarks saying it took 6 hours. Turns out they got the badge at the training event on Friday and had Friday as a head start. That hurt a bit to hear, because I wouldn't have spent 90% of my BSides working a badge knowing I was a day behind. Though I had fun regardless, but maybe they'll time gate the domain to start time on Saturday next year. I had a blast solving the CTF and oddly another blast writing the solves. This time I got to meet the creator of it and pass on my thanks and get a little verbal approval to post out this solve. This marks the end of BSides Tampa 2026 for me and I'll be back next year.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 11/05/2026
I went almost 1,000 days without a power outage - now I'm averaging an outage every 72 days. What happened?
connortumbleson.com
Recent Power Outages
Some random TECO Outages in Temple Terrace This week at roughly 4:10am in the morning one day I was awoken to a loud beeping noise which I've become immediately aware is my battery backup on my server rack warning that its running on battery. It only lasted a few minutes till silence which suggests either a battery needing replacement or that I'm drawing way too much power from a battery source. As I sat in the darkness in bed wondering why I've lost power again for no real reason (i.e no inclement weather) I decided to get to work combing through my emails. **Outages at my Temple Terrace, FL house** * 5/7/2026 - 4:23am - 115 customers out * 3/18/2026 - 2:20am - 2,022 customers out * 3/16/2026 - 8:03pm - 5,104 customers out * 11/3/2025 - 5:46pm - 116 customers out * 7/24/2025 - 9:48am - 116 customers out * 11/23/2022 - 8:44am - 1,520 customers out I found 6 outages which tells the story of my recent experience. It used to be quite a rare sight to lose power especially since there have been many hurricanes between these dates. We take the November 2022 outage which set the stage for going 974 days without a single power interruption! This is pretty crazy because if we list all the hurricanes between those days - it seems like Temple Terrace power was pretty stable. * Hurricane Nicole - November 2022 (~6,000 power loss) * Hurricane Idalia - August 2023 (~30,000 power loss) * Hurricane Debby - August 2024 (~40,000 power loss) * Hurricane Helene - September 2024 (~100,000 power loss) * Hurricane Milton - October 2024 (~600,000 power loss) _(all these numbers purely TECO, not including Duke Energy)_ We survived in terms of not losing power for 4 major hurricanes up in the Temple Terrace area which even surprised myself. Especially for Hurricane Milton which had flooded my street, but somehow had no loss of power. Hurricane Milton & Tampa (2024) It blew my mind that after Hurricane Milton when ~600,000 people around Tampa Bay had no power - I still did. Even with a front yard partially underwater I still had the electricity flowing. I also got to experience kayaking around your own neighborhood streets. That flooding might have led for my luck to run out. As sitting at work one day in July of 2024 my VPN back home (in order to drop ads, etc) no longer worked. Sure enough the emails started coming in that power was out at home. This was the least stressful outage as power was back on before I got home. The November 3rd (2025) outage was the worst one by far. Just a regular after work day relaxing with some screens and everything in the house went dark. As the night got darker I succumbed to the truth that I was going to bed with no power, but I was sure checking the TECO Outage map every so often. This outage was the worse as my neighborhood slowly gained power except for us - I watched our outage circle shrink as it went from 110 -> 73 -> 27 -> 26 -> 10 -> 5 without power. When you are 1 of 5 people without power in the entire Tampa Bay area you know the situation to fix your power isn't easy. Power trucks in the middle of night doing some major work. As the early morning arrived still in darkness I could hear electrical workers outside with their trucks backed into both yards of the houses with those big green electrical boxes. I had no idea what they were doing, but since one side had a massive cable on a wheel I imagine something was being rerun between these boxes. I decided to go on an early 6am run to investigate the situation and when I got home to take a shower - the beauty of power was back. This was our first outage in years that took over 12 hours to resolve. The next pair of outages started making me curious what was going on. This time in March of 2026 I'm just preparing to play a video game with some friends. We are still in the lobby at ~8pm waiting for everyone to join. Everything goes dark in my house and it appears we lost power again. The massive battery pack that has become our charger during outages. This time with ~5,000 people affected I imagined it was something more global. Closer to bed this time we sat outside to appreciate the quiet darkness and chat with a neighbor or two doing the same thing. At some point a few hours later the power was back on, but we were basically in bed at that point. Two days later in the middle of night (2am) the power goes out again this time targeting ~2,300 customers. As we woke up with the power still out we wondered if a morning routine would have to be in darkness. Thankfully somewhere around 6:30am the power was back and we were back at it. UniFi Panel post May 7, 2026 outage Now we land at the power outage on May 7, 2026 which led to this blog. Woken up in the middle of the night (4am) for an outage that was fixed roughly an hour later around 5:30am. With such a complex network of 2 switches, 2 access points, 3 cameras and 30 connected devices - power outages are not friendly to this enterprise level UniFi setup. TECO in my case never gives a reason for an outage, but boy I'm curious what is going on. Going from almost 1,000 days without a power outage to one roughly every 72 days is a new annoying norm.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 04/05/2026
Recently a day at work with GitHub has been met with errors and more - is AI at fault?
connortumbleson.com
GitHub, AI & An Influx of Content
Photo by Justin Ha / Unsplash A few weeks ago I saw a website (The Missing GitHub Status Page) that tallied up GitHub outages into a real historic outage bar, because at the time GitHub's interface failed to show any historical information. This page garnered enough attention and popularity that GitHub added a 90 day history to their own page accompanied by a blog post explaining why. https://mrshu.github.io/github-statuses/ About a week later another blog came out titled "An update on GitHub availability" which tried to shed some light on recent GitHub incidents. This post basically broke down that GitHub usage is up a lot and the reason is agentic (AI) development workflows. From my perspective looking over fastlane, OpenAI for PHP and Apktool I've noticed a bunch of things on the rise. **AI Spam** I wrote an entire blog post about the spam and it has no sign of ending. Imagine a user opening up an issue, which is supposed to be a bug report, but instead is some generic post summarizing to "_it doesn't work_ ". There is probably already a comment on the issue from some unrelated account guiding the user to resolution with some purely LLM generated text. The LLM message may be full of advertising links or edited in later, but you are starting to debate disabling notifications so your inbox isn't full of useless spam. You turn off notifications to reduce a cognitive load on your mind, but now trade discovering content much later and watching your repositories slowly increase in spam. **Agent PRs & Bug Reports** LLM "bug report" Alongside the LLM is the agent that is trying to be helpful building the most verbose bug report in history. Your repo may have a template for submitting bugs, but the AI knows better. It'll give you paragraphs of explaining the expected behavior but what actually occurs. It'll dive in giving a root cause analysis providing an chunk of logs and evidence. Finally ending up with a proposed solution, related code and any possible workarounds. It's so much content that may or may not be accurate and is daunting to read. It may be accurate and save you time and be appreciated. It may be a complete hallucinated language parameter that is not available or be a change that forgot to remember it has to be cross platform compatible. All that to say you sometimes miss the 4 sentence bug report that is straight to the point of the flaw. **Recreation with AI** https://malus.sh/index.html Twice now I've had my attention brought to projects that are rewrites of an existing project I maintain with the goal to modernize, enhance and fix long standing issues. In both cases in a programming language different than the source. It all sounds good in theory, but I think we should examine exactly why this process is successful. A lot of the success I attributed to the replacement software was its ability to learn from all the context, history and mistakes of the previous project. Maybe we are reaching an era that AI is solving things on its own, but I'd like to believe it solved problems from the decades of research published on our own. I started wondering if the era of niche tooling is over. Take fastlane for example which automates publishing applications to Apple and Android since 2014. In the 10+ years since then both platforms have launched more and more methods to automate a pipeline for app release. So with a bit of scripting and networking you can have a fastlane replacement built. It would be custom built for just you with only the features you need. You probably have no idea how it operates under the hood and maybe that is alright. You just hammer the agent to fix it anytime it goes wrong. I get worried what that looks like in 10 years when we've atrophied the actual engineer studying and solving these problems instead relying on an agent to solve our problems, but thats a topic for another blog. All of this to say - I think there are a lot of short term gains with "vibe-coded" replacement projects and I'm curious how they look in a few years. * * * All of this thinking because GitHub's uptime has been abysmal and they believe the exponential rise in AI has lead to this stability issue. I don't know who to believe, but I can tell AI is changing the game for software development.
010
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 27/04/2026
A laptop is retired - a new one is born and another sits sleeping.
connortumbleson.com
Switching Laptops
15 years of laptops. A long time ago in June of 2011 I obtained my first laptop which was a customized laptop from Sager Notebooks (NP8130). This was a pretty beefy laptop for its time and rocked specs like: * NVIDIA GTX 560M * Intel i7-2630M * 12GB of DDR3 * 500GB SATA drive This was a powerhouse of a laptop, but extremely bulky and heavy. It was amazing for a learning student as I dual booted Windows and Linux for my beginning research into everything technical. Year after year in college my desk at home used this laptop as the center piece wiring up monitors and more. Sager Notebooks - NP8130 Much like I talked about in the "Retiring Technology" blog I replaced power cables, hard drives & upgraded memory throughout the life of this laptop. I had so much history and configuration that I was never really wanted to switch laptops - it still worked after all. Of course though a laptop from 2011 pushing 2024 was really showing its age - YouTube couldn't watch videos unless lower quality and a bunch of things were just slow. One morning that laptop wouldn't turn on and I feared it was broken again. I had backups of the things I cared about (ssh keys, gpg keys, etc), but you never really know what you are missing until you use a new computer and realize its missing. This time I was sure I needed another power brick so ordered another from Amazon, but this time I needed a new laptop quick because the part was going to take 2 weeks to arrive. Acer Nitro 5 I drove off to Best Buy and wandered the store researching any laptop I could buy at that moment and left with an Acer Nitro 5. This was a $700 laptop that I was going to use as a temporary laptop until I could really research a new purchase, but I ended up using that laptop until this blog. I setup this new laptop with LUKS Encryption and generally made my life more difficult than it needed to be. Throughout these years this laptop worked, but needed some major building when I needed to like expand the /boot partition or fix my NVIDIA drivers. At work my laptop had been upgraded every few years (2016, 2019, 2022, 2026) and I had made the transition in the MacBook world from Intel to Apple silicon and now was rocking an M4 chip at work. That work computer was fast and I started realizing that waiting minutes for a compilation was not normal when my work laptop could do it in seconds. MacBook Pro 16" - M5 Max I started wondering if I should obtain a MacBook Pro as my next laptop and sure enough this weekend I purchased a new MacBook Pro (M5 Max) which is quite a powerhouse of a machine. For those in the industry this wasn't a cheap purchase, but I started researching the cost I paid for laptops in 2011 and 2023 (1500 & 700) and did some math the years those laptops were used. Basically the cost broken down was $146/year for 15 years of 2 laptops. I felt spending only $150/year on something I use every single day for multiple hours was something I could spend a bit more money on. Knowing work replaced my laptop every ~3 years I felt like I really pushed my existing personal equipment longer than most engineers do. So as I booted up this new machine I was really interested in running some tests on some common tasks I do. Here is a breakdown of my Acer Nito 5 and MacBook Pro. Building fastlane docs. * 22.55 seconds - Acer * 5.24 seconds - MacBook Building Apktool * 52.4 seconds - Acer * 12.1 seconds - MacBook Running Leaf test suite. * 39.41 seconds - Acer * 8.88 seconds - MacBook If you average those differences it was roughly a 4.4x improvement on my previous hardware. It was pretty crazy the difference and working on open source stuff was pretty fun again as I wasn't spending most my time just waiting on compilation or downloads. Now with the benefit of having a beefier machine I can build AOSP without an external drive and hopefully run an LLM (AI) locally. It was Donna and Tom in Parks and Recreation that said - "_Treat yo self_ " and I just did with the help of my GitHub sponsors. I'll take this boosted hardware and improve everything I contribute towards in a faster way now.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 20/04/2026
The era of the AI Attacker is here - who will keep up.
connortumbleson.com
The AI Attacker
Photo by Google DeepMind / Unsplash I'm getting nervous when it comes to the evolution of AI and security and this isn't some doom and gloom post about the new Anthropic Mythos model. My fear began when I noticed an LLM can find an undiscovered vulnerability quite fast given a barely constructed harness developed, but the reversal of patching said vulnerability and releasing cannot be as fast. Prior to this day and age of the LLM - vulnerability research was done with a bit of tooling and a bit of ole fashion knowledge in the brain of the researcher. Now lets walk through a situation in which you want to have an LLM discover vulnerabilities in your project. If you start by just asking the LLM to review the whole project and find a vulnerability - it probably won't work the best. However, if you start developing a fairly basic harness to direct the LLM better - you'll watch the results with a modern public model (Opus 4.6) work out. Start with a script that asks an LLM to judge a file based on the merit of how likely the file is to have a bug. This isn't any security research, but just a method to reduce the amount of files we are going to have our LLM work from. ❯ can you review all php files in app folder and rate them 1-10 on chance of bugs being in that file? Write the report to some file in root Explore(Find all PHP files in app) ⎿  Search(pattern: "app/**/*.php") Bash(find Leaf/app -name "*.php" -type f | sort) ✽ Tomfoolering… (34s · ↓ 1.1k tokens · thought for 1s) Once you have all the files you dispatch another round of LLM behavior on those same files, but this time under the disguise we are doing a CTF and trying to examine a file for a bug or vulnerability to extract a secret. If you aren't worried about tokens or spending then you probably don't need the step prior and ramp this up with parallel agents. We do this CTF trick because in earlier models the agent would refrain from the task thinking we were attempting to hack a system. | Risk Level | Count | Range | |------------|-------|-------| | High Risk | 8 | 5-6 | | Medium Risk| 38 | 3-4 | | Low Risk | 180 | 1-2 | Output of LLM looking for "potential bug" files With that I asked the agent to review the 8 files with a high probability of a bug and to create a pull request for each flaw individually. Branch | Fix ---|--- `vuln-01-unsafe-class-inst` | Validate class implements `AnalyticInterface` before `new` `vuln-02-webhook-auth-bypass` | `hash_equals()` + null guards on webhook secret `vuln-03-ssrf-route-binding` | Remove external API call from `resolveRouteBinding` `vuln-04-carbon-mutation` | `copy()` before `subDay()` / `addDay()` `vuln-05-missing-botfarmer-save` | Add `saveQuietly()` + null coalesce on bootcamp count `vuln-06-null-division-csr` | Null guards in `CsrHelper`, `Csr`, and `HasCsr` `vuln-07-medals-page-null` | Null-safe `?->` on service record medals access `vuln-08-medal-prefix-mismatch` | Add `$prefix` to `Arr::has` check for medals At this point I realized I forgot to scope the research to a security flaw, but I guess when you are trying to do a replacement with a free open source hobby project using nothing from work - it happens. What blew my mind is Claude took roughly 3 minutes to open 8 pull requests and find bugs across 8 files in 3 minutes. Crunched for 3min 8s... Now when those pull requests were open - I should have told Claude my project sits at 100% code coverage and requires a test for every change because only a few pull requests passed CI on try 1. This is something you do as you harden your harness to reduce false positives and extra work. Either way I sat down and reviewed all 8 changes: * 1 - valid, but I accept risk. If I lose my filesystem I have a bigger concern. * 2 - merged - classic timing attack flaw. * 3 - invalid, not an SSRF and intentional. * 4 - merged - good find. * 5 - invalid - the caller of function saves data. * 6 - valid, but ranks fit a constraint enforced by Halo Infinite, so closed. * 7 - merged - good find. * 8 - merged - good find. In this case I was looking at a list of things needing to be validated - unaware if an issue had a security implication. When doing this for real you'd probably have another LLM agent in the mix to toss logic issues leaving pure security flaws if you were pen testing a solution. Assuming that was the case here - we had an LLM agent possibly discover 8 security flaws in minutes. In this specific case these were a mix of logic and security bugs, but the point remains. Years ago an engagement with a security company would take weeks for the investigation, research and report to be delivered. We are moving into an era with companies and software like Xbow ($$$) and Strix (OSS) to automate a better harness than what I created in a few minutes. So now I am getting worried - because we have tens of millions of lines of software deployed globally. AI can work in any method deployed (with source or without), without sleep or breaks and we are approaching timelines from execution to a valid vulnerability in minutes. The turnaround time to patch vulnerabilities is no where near as fast as the timeline to find and abuse vulnerabilities and that worries me.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 13/04/2026
A few months ago I did a blog titled "Social Etiquette" where I took a look at a few occurrences of behavior over the past week that were pretty poor behavior. I found a new word for it of "main character syndrome" and I've never felt a word that more validated what you see day to day. The one […]
connortumbleson.com
Main Character Syndrome
Photo by Juan Rojas / Unsplash A few months ago I did a blog titled "Social Etiquette" where I took a look at a few occurrences of behavior over the past week that were pretty poor behavior. I found a new word for it of "main character syndrome" and I've never felt a word that more validated what you see day to day. The one action that bugs me to no end is talking on speaker phone in a public place. I'm not sure when it changed that loudly having a conversation where we can hear the other party is at all normal. Whether its at a restaurant listening to some Uber Eats driver picking up food while chatting or some one in a line at a sandwich shop I just can't fathom the process going on in their head. Never have I thought to talk on speaker phone as I wander around a public place. I don't even understand how the party on the other end of the phone is alright listening to presumably a loud busy caller with the background noise that speaker phone may pick up. Once I build up the courage I'll just join the conversation to curb this behavior as the individual must be intending the public to join their call with broadcasting it to us. Sitting in traffic with a car dragging cables They are a main character in their own story and no one else matters in their brain and this becomes especially relevant on the road. The amount of times I'm getting on the highway and some car drives all the way to the end of the merge lane to cut in at the last section is insane. They might have passed 20-40 cars and caused a few seconds of braking for that entire lane as they stop to let that aggressive car in. Some cars are not about letting that individual in to combat the behavior which turns a turn based zipper merge into an aggressive stop and go traffic jam. It just becomes exhausting to consistently watch traffic degrade because of the actions of a few, because when you play simulations of common traffic patterns - it works. What every simulation doesn't account for is the main character energy that some folks exhibit. At times I wonder if I'm confusing just obliviousness with this form of main character. Since take a situation where I'm waiting in line at Publix for a sandwich. There are little markers to guide you to the start of the line vs the end. On multiple occasions I've seen someone just walk through the end part of the line and just stand there to interrupt the deli worker for a question suited for the catering area or try to order! Thankfully in most cases the employee directs them on their way, but I'm just so blown away in the moment. Is this person intentionally doing this because they don't want to wait like everyone else? Are they obliviousness and its an honest mistake? You can kinda tell based on their response to the situation when they are challenged - combative and it was probably intentional, confusion and it was probably an honest mistake. Every day I try and have a bit of empathy, but I'll more than likely run into a main character or two.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 30/03/2026
A yearly event at the Zoo - night time & drinks.
connortumbleson.com
ZooBrews at ZooTampa
ZooBrews at Lowry Park Zoo 2026 A few months ago we stumbled upon an advertisement for a late night trip to the Tampa zoo with alcohol called ZooBrews. It looked sweet as it was a single price for an inclusive trip to the zoo where food and beverage vendors would be all around with samples. Alyson had been to the event before in years past, so we booked some tickets and the event was this weekend. It had been awhile since we had been to the zoo and Lowry Park had done an upgrade to the parking lot - so the free parking was gone, but instead we had a parking lot setup much more mainstreamed and easier than the previous iterations. 7 dollars later we had parked and arrived roughly 30 minutes too early for the general admission time. The entrance looked to be letting people in, but we quickly learned those in the GA group were roped off and stuck in a little area. We probably should have chilled at the car for a bit longer like Alyson suggested, because that roped off area kept growing with people till we were shoulder to shoulder with a hundred others. Finally though at precisely 7:30pm the ropes were removed and hundreds of people descended into the zoo. Opening DJ zone at the park The music and lights were going and I wondered how the animals felt for a once a year party at night. I figured some animals were awake at night anyway, but as we walked around the park maybe half were asleep or out of sight. Around every corner was either a food station or beverage station and there were some great items. From memory I got: * Surf Side Pink Lemonade or Tea * Keel Farms Cider * Chicken slider * Korean burger * Dave's Hot chicken sandwich * Ribeye Meatball * California Pizza Kitchen pizza * Wendy's Frosty * Ben & Jerry's Ice Cream It seems like a lot of food, but everything was sample sizes or tiny pours of alcohol so you could experience all the different vendors around the park. It felt a bit odd enjoying a drink or food as you stood in front of an animal in cage, but on the same time it was a chance for a good influx of money to the zoo. 0:00 /0:06 1× Rhinos exploring in the night The coolest up close exhibit was probably the rhinos who were just walking around slowly eating some grass, which let you appreciate the sheer size and weight of these creatures. Other exhibits had creatures that appreciate the night and stalk you with a glare. Owl in the darkness That was the owl who clearly had some level of night vision that us humans could not obtain. As the night fell some of the zoo had some cool designs to light the way while others were a bit dark. Africa at ZooTampa at night. As we wandered into the Africa section of the zoo there was overhead lights and a large circle bar in the middle. This place was cool as the large circle bar kept people evenly balanced around bar while all the food stops were placed on various outside points of the center area. As the night continued to fall towards 10pm the amount of people dwindled and the amount of animals able to see decreased. I could tell the zoo part of the event was losing steam, but the bars and dancing area had a solid amount of people still. Though with a weekend of yard work, running cable in the attic and workouts - my legs were ready to call it a night. Photo with Manny the Manatee Thankfully we grabbed a photo with the mascot before it got dark. I may have eaten too much ice cream and too many little samples, but all the food was great and getting to experience the zoo without an army of little kids running around was a fun time. We will be back next year with maybe a few more friends.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 23/03/2026
The new type of spam plaguing GitHub with LLMs, edits and more.
connortumbleson.com
The odd new spam on GitHub
Photo by Rubaitul Azad / Unsplash I've been noticing a new pattern of spam on GitHub that is so annoying, partially clever and a pain to defend against that I had to blog about it. I hinted at this pattern in one of my older blogs - Dead Internet Theory, but this time I have to dive deeper into how this works. Original comment (prior to edit) on fastlane/fastlane#22198 It all started when a comment showed up on an issue report that was clearly generated by an LLM and did not help the conversation a single bit. Since fastlane has a large amount of activity - I only subscribe to items I interact with, so I'm not alerted to random responses on issues I have not visited. By the time I visited this thread, it was the same message but with a tiny little link to some unrelated service tucked in there. Spam comment (prior to edit) on fastlane/fastlane#22198 This could be link farming, establishing links or some clever SEO hack, but I do know regardless of what it is - it doesn't belong. The user as you would expect is an empty GitHub account, with no repository, no stars, no projects, no contributions and just spamming repositories. spam comment on fastlane/fastlane#20477 Sure enough I stumble upon another issue and this time the user/script just injected the spam links directly into words of the LLM text. This time the advertisements are for Labcorp which I recognize as a massive company. So now I'm even more curious - does that company engage with a scummy advertisement agency that results in some real scummy behavior in order to grow search standing? Or is the connection unrelated, either I move on to the next. spam comment on fastlane/fastlane#28817 This time its a short comment that makes no sense - a comment saying "_thank you for sharing_ " for a bug report. A short time later the post is edited to include the spam link. This must be a common technique because I don't get edits emailed to me only original comments. A comment that looks vaguely real (powered via an LLM) than edited later for spam is how they operate. If I was GitHub this would seem pretty easy in my playbook. Brand new accounts that end up posting more and more outbound links to various domains would get flagged and reviewed. another spam comment on fastlane. I even find posts from years ago that were edited to include spam. Are these legitimate accounts that got hacked and turned into spam? Some of the edit timelines are minutes later while others are months later. I tried to report these accounts for spam, but it was already more clicks that I had to do on top of marking comments as spam or deleting them. I found if I deleted comments and reported the account chances are GitHub might not make any action - maybe unaware to see the spam I deleted. If I leave the comments marked as spam and report them - the account might be deleted entirely and take the comments with it. At one point I had too many open abuse reports to even open another, so I stopped. It just was a daunting amount of work to report an account on top of cleaning up the spam. I figured automation would eventually purge these accounts, but I'm posting about some spam I dealt with in 2024 and the accounts are still not deleted. So long story short - if you don't report them - chances are no automation GitHub has in place will take care of the LLM based spammer.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 16/03/2026
A train crossing arms go down - no train comes. Traffic backs up and police show up, a story of a ~25 minute delay on the way to work.
connortumbleson.com
Apocalyptic Traffic
Sitting in traffic jam at Anderson Rd A few days ago I was on my way to work after dropping Alyson off at the airport and I got myself in a traffic jam that led to this blog. It all started as a normal drive back to the office after an airport drop off - things were going great and my ETA on Google Maps was a green number and the predicted time was what I expected. Anderson Exit near Linebaugh / Anderson Intersection I get off at my exit and my green number on Google Maps turns yellow and adds an extra 10 minutes instantly which I thought was odd. Sure there was a large line at the Anderson light after getting off the highway, but that tends to be normal. The light time is pretty short so it usually takes me a 2-3 light cycles to get through this area on a work day. I'm pretty much stuck on the exit ramp so can't see much, but I see our light turn green and no one move - this happens for a few more light cycles and I can tell people around me are getting anxious. Right turn traffic is moving (albeit slowly), but my left turn traffic is making no progress. We are hitting the 20 minute mark of being stationary and I'm getting anxious now and I can finally see above some movement. Cars are doing U-turns and heading back the other direction I just don't know why. Finally I can inch forward enough to look over the concrete wall of the highway exit and I see the train gate arms down, but no train crossing. I'm finally piecing together what has happened - the train arms went down blocking the road, but no train came. Perhaps the trickle of traffic are the brave, but also pretty risky individuals who must be driving around the arms to bypass the block. However, I get closer and see what is going on. Police are now here with flares on the road guiding cars because without stop signs or stop lights its pandemonium on the streets. Google Maps of the train crossing The problem being that hundreds of cars are turning down this road not expecting the blockage, compared with everyone getting off the highway here and alongside everyone out for themselves has made a hectic situation. People forgot the rule of traffic of not entering the intersection unless you can safely leave it - so as lights turn green there is no passage for anyone. It was an old fashion grid lock and it got me thinking about all the apocalyptic movies where cars are jammed up on all roads just abandoned. This was only a brief 20-25 minutes of terrible traffic jams, but I can see how believable it is that roads become a graveyard of abandoned cars. There are always the people that think they are more important or rather oblivious to the situation at hand. We may have a hundred cars turning around, but one car is going to honk and push their way through determined to not make that U-turn like every other car. Maybe they are having an emergency and going to ramp it through the grass - who knows, but they aren't the first nor last to make the situation more stressful for everyone. 0:00 /0:40 1× In the era of AI - I asked Claude to simply merge these various 1 minute traffic cam videos together, speed it up to make it 40 seconds long and optimize it without sound. A couple minutes later the video above was produced and it helps show the situation I dealt with. Nothing crazy nor major, but when my 8 minute ETA became 34 minutes - something went wrong before Google Maps knew to route me away. I could only imagine in a real situation how quick things would tumble. Imagine all the train arms dropping globally would lead to instant gridlock. Sure folks may eventually ram the arms down, but not without immense delays and traffic backing up to unbelievable points. What I didn't really explain well is the side effect of a single blocked road - traffic to that point blocks up as well. So the intersections prior to this one couldn't allow more traffic, so they blocked up. You need a live Google Maps set of algorithms to reroute people, but at some point there is too much traffic and things can't resolve themselves in any quick pace. I remember in the news a long time ago how a traffic jam lasted over 10 days in China - so I know things can blow out of proportion. It's just so interesting to me how fragile our infrastructure is because at the end of the day fragile people operate among it.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 09/03/2026
A project that never introduces breaking changes and works on old versions or a project that pushes boundaries on newer technologies.
connortumbleson.com
Breaking Changes vs Infinite Support
Photo by Chris Lawton / Unsplash A long time ago I was a web developer who used CodeIgniter and I appreciated the fact that they supported some pretty old versions of PHP as newer and newer versions came out. My web host at the time took like 8-12 months to add support for a newer version of PHP and laziness got the best of me - so old PHP applications still working on a framework were great. https://www.codeigniter.com/userguide2 At some point my opinion started changing when features of a newer version of PHP looked intriguing, but the framework couldn't leverage them instead forcing the usage of plugins or 3rd party code that hovered at a higher PHP requirement than the framework itself. At some point a challenge started developing for CodeIgniter such that it was difficult to support new versions of PHP without dropping old versions of PHP. Some changes were just that difficult to maintain compatibility, but things like poly-fills and workarounds kept it going. An interesting thing I noticed as well during this time is plugins and packages around the framework generally followed its supported versions which kept everything in the community back from the newest and greatest native language features. When the rumored CodeIgniter 3 came out it moved the minimum version of PHP to 5.2 (from 5.1), but encouraged PHP 5.4+ or greater to be used. A couple months later PHP7 ended up being released and my attachment to Codeigniter faded. As Laravel entered the picture for me I was blown away by the modern PHP requirements and developer experience. https://laravelversions.com/en Even more so when a new PHP version came out - Laravel had it supported before its release date which was no easy task when it depended on a bunch of dependencies. I blogged about that before, but it was such a breath of fresh air to have a framework dragging the industry with it as they dropped older PHP versions on nearly every major release. The benefit also being that every dependency they depended on also got that treatment or an alternative was produced. Now switching over to _fastlane_ I've been maintaining it for a few solid months now and the biggest thing holding me back was _fastlane_ still supporting Ruby 2.6 which was released in 2018 and support ended in 2022. Folks want the new Ruby versions but there comes a cost for trying to support the new without dropping the old. How many times do I need to upgrade a package for a new Ruby version, but that newer package bumps the minimum past fastlane's requirement? https://endoflife.date/ruby Apple computers actually ship a version of Ruby for historic reasons and that is Ruby 2.6 on the system. That meant fastlane could work out of the box on a Mac computer, but in most cases the outdated system version of Ruby was not preferred. So preparing to say good bye to Ruby 2.6 was a big deal - we'd no longer support the version of Ruby that comes preinstalled. We haven't even discussed the developer cost of supporting such old versions on fastlane. Our CI system (CircleCI) would announce the shutdown of older Mac runners - the newer ones had a new default version of Ruby so we needed to compile older versions of Ruby just to test the codebase. Docker was added into the picture to control the exact dependencies of old things we needed in order for build systems to pass. It became a lot of work just supporting the old versions and with no money coming in and no business footing the bill for support - it made sense. I started a push internally to actually move the needle forward and have fastlane follow the EOL dates of the Ruby language. We said good bye to Ruby 2.6 after a month of discussion and agreed to emit a little warning into output to warn end users of the impending future. WARNING: Support for your Ruby version (2.6) is going away. fastlane will soon require Ruby 3.2.0 or newer. We have a decade of cruft to clean up and no Ruby jump is easy, but we are starting the slow journey of modernizing dependencies, fixing security issues, dropping old Ruby versions (Ruby 2.7 WIP) and trying to bring fastlane back to a pioneer of build tools instead of a decaying passenger.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 02/03/2026
I'm no professional when it comes to cooking on a Green Egg, but I was gifted a large Tomahawk steak and it was time to cook it. Reading up on plenty of guides the plan was going to be slow indirect heat in order to bring up the internal temperature to around 110F which would probably require a […]
connortumbleson.com
Cooking a Tomahawk on a Green Egg
The Tomahawk Steak I'm no professional when it comes to cooking on a Green Egg, but I was gifted a large Tomahawk steak and it was time to cook it. Reading up on plenty of guides the plan was going to be slow indirect heat in order to bring up the internal temperature to around 110F which would probably require a standing temperature of ~300. Once that marker was hit - we'd remove the steak and attempt to bring the Egg up to ~600 for a reverse sear. I struggle in general to keep the temperature high so this was going to be a challenge regardless. So I started off with cleaning up the Green Egg to ensure there was no large collection of ash at the bottom. With good open air passages its way easier to regulate the temperature in terms of getting real hot or keeping it at a preferred area. So I busted out my chimney starter and filled it up with 3 of those little twisted wood starters and filled to the brim with charcoal. Chimney with outdoor Green Egg Outside was looking bleak and dead, but a couple weeks of weather dropping into the 30s in Florida is not good for our nature here. The lawn looked bad and most of the pots or trees were not a perfect shade of green. Regardless, the chimney was started and 15 minutes later I dumped the coals into the basin of the egg and was preparing for phase 1. The guide mentioned no direct heat and I didn't really have a mechanism to prevent direct heat so I built a layer of tin foil to lay on top of the grate. I quickly realized that the bone of the tomahawk meant the steak & bone itself would barely fit in the egg in the first place. The video I was watching was with a large (18.25in) Green Egg and this was a medium (15in) one which made the position of steak a bit difficult. I pushed through and laid a steak heavily covered in salt & pepper onto a piece of foil and closed the lid and waited. We topped out at 220, so clearly I messed up. I opened up the lid again and let it breath and gain some heat and re-closed the lid with a bit more air opened up. This time we hovered around 350 which was easy enough to slowly close the top grate until we hovered right around 300. Victory with a perfect 300F Green Egg. I'd go inside and start preparing the rest of dinner checking on the temperature every 10 minutes or so and it was holding great. As we got to the halfway point I went out there to flip it and it seemed like it was cooking faster than I expected, so I busted out the thermometer and took a look. The middle was still floating around 90F so we weren't ready yet, but closer to the outside was 120F so I was already in a pickle. I guess my indirect heat setup wasn't as indirect as the official adapter you can get as an accessory. So we decided to shorten the time and only do about 10 more minutes on the other side before ramping up the temperature. I took the steak off to remove the tin foil and ramp up the temperature while quickly wrapping the bone in foil to prevent damage to it. This time with an extra starter thrown in there with some new coals we were cooking with some high heat. This meant we were doing a quick reverse sear for a minute or two per side to really develop a good crust on the outside. With a foil covered bone it was pretty easy to maneuver the steak around to sear each side & corner. With that done the process was finally over and we brought in the steak to rest inside. The cooked steak resting. This was about as good as it looked as the inside ranged from well done (on the outer parts) to a solid medium in the middle of the steak. As both Alyson and I lean to the rare/medium-rare cooking level I surely messed up the cooking process for such an uneven cook. I don't even want to attach the photo of the cross section due to the slight embarrassment of the cooking, but never cooked a tomahawk before so I guess I need to learn and iterate. When I started this blog I thought the outcome would be different, but instead it ends with an unevenly slightly overcooked steak. In good news - with a bit of horseradish sauce it was fine to eat, just not my preference.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 23/02/2026
A bit ago Alyson and I had an appointment with our wedding coordinator in the Soho (South Howard) part of Tampa. Knowing we'd be down there we paired our visit with a lunch and some errands in the area. Alyson had a hair appointment so we split up for a bit and I wandered up/down South Howard […]
connortumbleson.com
The UT Frat Behavior
The yellow area of the Soho District. A bit ago Alyson and I had an appointment with our wedding coordinator in the Soho (South Howard) part of Tampa. Knowing we'd be down there we paired our visit with a lunch and some errands in the area. Alyson had a hair appointment so we split up for a bit and I wandered up/down South Howard playing Ingress on the variety of portals there. I walked by this one restaurant and saw what had to be ~100 college guys all being seated on the outdoor patio. I presumed it was some frat and went about my day playing Ingress waiting on Alyson. As our errands ended we went off to our wedding appointment and spent about an hour and half going through the details, vendors and learning more about the hotel in preparation for our wedding. As we solidified our dining options I was happy to learn we get to design our own sushi rolls for the sushi station. The caveat was the rolls have to be pretty basic so anything that was a "specialty" roll at a restaurant was probably not in the books. So I went off to AI with my favorite type of rolls with a few less ingredients and asked Claude to visualize them in an image. AI creations of wedding sushi rolls that I deem "basic" I was happy with this presentation and pretty funny visualization and hopefully the crew responsible with the sushi creation can make this happen. I don't think any of the rolls fall into the complex category. With the wedding appointment over we started a walk back into the restaurant area to grab some lunch. We stopped at a place forgetting this was the same place I saw a bunch of presumed frat guys at ~3 hours earlier. We thought nothing of it, then sat down for some drinks and late breakfast / early lunch. I couldn't help but notice instantly that this large group of people not only had the majority of all outdoor tables, but also the private room inside and a few tables near the bar. The hostess confirmed to us it was a frat, because our original reservation was for outside which she urged against us sitting out there. Hot Honey Pizza @ [redacted] So as I enjoyed a Hot Honey Pizza I still couldn't believe how much activity there was in this restaurant all from these different frat tables. Huge groups of people leaving to walk to another table, go to the bathroom, disappear outside or any combination of that. It was around noon on a Saturday and I couldn't believe how loud and disrespectful this group of frat guys could be. Knowing I saw them hours earlier getting seated they had presumably been drinking for 3 hours. When a group of them walked by they grabbed another one of their boys and said "_come to the bathroom_ " and I knew that couldn't be good. Curiosity got the best of me and when the bathroom is full of noise and people basically yelling you know something is going on. Sure enough when you see 3 guys shove themselves into a single stall - there is some behavior going on that probably isn't legal. Some of this behavior could probably be semi-normal at a bar near a college, but at a brunch restaurant in the morning seemed ridiculous. Thankfully as all of this was going down I saw the staff holding like 40 credit cards and they were carefully stacking receipts and cards as people were charged. I was excited as this meant the restaurant might quiet down with the group gone. As those large groups stood up to leave they bothered quite loudly a table full of women which is where we could overhear the frat and school (University of Tampa) as they talked. This is where we had a quick conversation with our server about this large group of annoying people. Turns out they visit nearly every weekend for the bottomless mimosas ($30). I felt bad for the staff that might have to deal with that behavior weekly. I thought back to my college time (but I didn't join a frat) and couldn't fathom being that disrespectful and obnoxious at a restaurant. Thankfully the food was great - even if the only thing I was focused on was the obnoxious frat guys.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 22/02/2026
Apktool v3.0.0 has been released dropping support for aapt1, 32-bit and heavily improving the internals of the tool.
connortumbleson.com
Apktool v3.0.0 Released
Apktool v3.0.0 has been released! A major release dropping support for aapt1 and 32 bit support while re-engineering CLI parameters and heavily rewriting the internals of Apktool for easier long-term maintenance. This time in honor with the project starting to live without my personal blog - the majority of details will be on the official release post on apktool.org instead of this blog. This blog will go into more about the meta details of maintaining a large open source project for over a decade. 💡 Official Apktool v3.0.0 release post on apktool.org As 15 years of maintaining Apktool approached I realized I don't really develop in Java anymore. I don't translate MIUI roms as a hobby and outside of a small bit of work auditing applications on Android - I don't really work in Android anymore. It wasn't fair to Apktool as my focus was pulled to OpenAI for PHP or fastlane recently. So knowing Igor had been giving pull requests to Apktool for years it was an easy ask to grant him access to the repository with a maintainer role. So Igor helped majorly in designing and stabilizing Apktool v3 as well as reviewing support issues and feedback. As I hacked it to pieces over the past decade fixing crashes here and there it was great to have someone review the code as a whole and iterate with a design in their mind. I don't yet have a fully automated Apktool release process as the signing part is still hooked my private GPG key and thus must be done locally. This means all releases are only possible by myself at this time. I've been researching how other Java applications in the open source space sign and publish to Maven in a purely automated fashion. The downside right now is any process that does work doesn't look like an amount of scripts and tooling I want to maintain alongside Apktool. So I'm happy Apktool continues to live on with modernization and enhancements with myself a bit more in the shadows than normal. Igor knows the Android space better than me and is rapidly improving Apktool more-so than I could. * * * **Sponsors** I launched GitHub Sponsors to help provide another alternative for folks showing appreciation. I want to remind folks of two companies that continue to hold a monthly donation for the project. * Emerge Tools (now Sentry) came online to sponsor the tool. * Sourcetoad (self employer) additionally joined to sponsor (as well as a few other projects). * * * **This release had 49 commits by 4 people & 1 robot.** * Igor Eisberg - 23 commits * Dependabot (Robot) - 15 commits * Connor Tumbleson - 9 commits * jpstotz - 1 commit * salvogiangri - 1 commit * * * # Changes since 2.12 * [#3820] Drop support for aapt1. (Thanks IgorEisberg) * [#3885] Drop support for 32-bit platforms. (Thanks IgorEisberg) * [#3885] Drop short flags for any advanced options. (Thanks IgorEisberg) * [#3885] Drop `-api / --api-level` option for automatic detection. (Thanks IgorEisberg) * [#3885] Support disassembling resources not in `res`|`r`|`R` folders. (Thanks IgorEisberg) * [#3888] Support new `BinaryResourceParser`, `ResChunkPullParser` and `BinaryDataInputStream` for modern disassembly for resources. (Thanks IgorEisberg) * [#3885] Change all short commands to a single character to enable multiple commands like `-vfo` for `-v -f -o`. (Thanks IgorEisberg) * [#3885] Change `efd|empty-framework-dir` to `cf|clean-frameworks`. (Thanks IgorEisberg) * [#3885] Change `packageInfo` to `resourcesInfo` in `apktool.yml` representing all transformation options. (Thanks IgorEisberg) * [#3885] Change hex integer values to preferred compact form. (`0x20` instead of `0x00000020`) (Thanks IgorEisberg) * [#4001] Change temporary files to be prefixed with binary name (ie aapt2). (Thanks jpstotz) * [#4041] Change default resolve mode to `KEEP` (`DEFAULT` in v3) instead of `REMOVE`. (Thanks IgorEisberg) * [#4044] Change resolve modes to `default`, `greedy` and `lazy` to improve serialization. (Thanks IgorEisberg) * [#3885] Fix all `<item>` tags to properly reference their respective resource types. (Thanks IgorEisberg) * [#3885] Fix usage of `dp` instead of `dip` as a more modern development standard. (Thanks IgorEisberg) * [#3885] Fix usage of `match_parent` instead of `fill_parent` as a more modern development standard. (Thanks IgorEisberg) * [#3885] Fix color values to represent the format they were in the original apk. (Thanks IgorEisberg) * [#3994] Fix odd integer encoding behavior as a string. (Thanks IgorEisberg) * [#3994] Fix support for feature flags prefixed with exclamation mark. (Thanks IgorEisberg) * [#3997] Fix building on headless CI systems. * [#4041] Fix entry spec naming to account for malicious or invalid spec names. (Thanks IgorEisberg) * [#4041] Fix injection of entries to account for stripped apks. (Thanks IgorEisberg) * [#4059] Fix handling of styled strings that fail valid checks. (Thanks IgorEisberg) * #3767, [#3943] Swap to google/smali built from source due to upstream abandonment. * [#3810] Fix assumption of resources and move to source of truth of `resources.arsc`. (Thanks IgorEisberg) * [#3905] Fix maven pipeline for modern Sonatype publishing. * [#3990] Upgrade `guava` to `33.5.0-jre`. * [#4025] Upgrade `commons-cli` to `1.11.0`. * [#4021] Upgrade `commons-io` to `2.21.0`. * [#4038] Upgrade `commons-text` to `1.15.0`. * #3998, [#4026] Upgrade `commons-lang3` to `3.20.0`. * #4003, [#4080] Upgrade `gradle/actions` to `5.0.1`. * [#4011] Upgrade `github/codeql-action` to `v4`. * [#4017] Upgrade `xmlunit-legacy` to `2.11.0`. * #4018, [#4050] Upgrade `actions/upload-artifact` to `v6`. * [#4033] Upgrade `actions/checkout` to `v6`. * #4031, #4064, [#4090] Upgrade `r8` to `9.0.32`. ## Notes * This is the first release of 3.0.0 - while we tested it heavily internally we may have a regression somewhere. v3.0.1 will follow quickly in case of an issue. ## Download Download Apktool 3.0.0 * Apktool 3.0.0 * `7cdebcc6c9248e62fdceb8e96abda99e` (md5) * `06fed946b272eb777fdb6dc0bbef0e13e0d393144ee367a510acba18b41597b9` (sha256) * Rename to `apktool.jar` and follow the Instruction Guide if you need help. * 3.0.0 Doc Site Post ## Links * Project Site * GitHub * Bug Tracker * XDA Thread * GitHub Sponsors * Buy me a ~~Coffee~~ Beer
001
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 16/02/2026
I'm not sick often, but this time I was struck by something that took me down for weeks.
connortumbleson.com
The Pneumonia Strikes
Photo by CDC / Unsplash As I hinted at in the end of my last travel blog I was falling ill with something and as the day count hit double digits and my fever remained it was time to take it more seriously. Normally my body can fight anything with Ibuprofen and time, but this time I was losing this battle. So like a regular millennial I opted for a Telehealth appointment so I could just work at home with a tiny little break for a meeting with a doctor. While a nice person on the other line - there is just a limit someone can do to treat you when meeting remotely. She had an idea that my cough and symptoms sounded like pneumonia, but couldn't diagnose that remotely. Some pills and sprays I got via Telehealth appointment. So I got a prescription for some amoxicillin and some nasal sprays to help with the congestion with the caveat that if my fever didn't break in 48 hours on the antibiotic to visit a physical doctor. Of course this is a blog because 48 hours later I woke up and took my temperature and I was still floating around 101, so this antibiotic was not curbing this fever I had. So I signed into my primary care website and looked for an appointment which unfortunately the closest one was 7 weeks out. I'm not sure how my primary care is booked 7 weeks out - we must have an influx of people in Tampa all requiring medical services. If I waited 7 weeks I might be healed or dead - so I guess it was time to look into urgent care. Thankfully for me every single time I leave the neighborhood to head to work I pass an urgent care place within 15 seconds of pulling out onto the main road. https://centracare.adventhealth.com/urgent-care/temple-terrace So I went to their website and saw they had availability basically every 20 minutes the whole day while supporting of course walk-ins. I figured walk-ins would probably go right when they opened, so I found a perfect time between some work meetings in the middle of the day. Walking in 15~ min prior to my appointment and having to check in on a digital kiosk while someone right next to me was checking on the other was not the best experience. It's not the most elegant experience to check into a kiosk that is 2ft away from another while standing next to presumably sick person. However, I was sick so what I can I say. As I sat checked in I could see people getting called back that were there prior to me, so as no one remained I could recognize I knew I had to be next. Sure enough 6 minutes after my appointment time I was called back. Spoke with staff member who did all the basics and was told to wait for the doctor. This took an hour of waiting, but thankfully I was in one of those rooms facing outside so I could overhear someone outside ripping into someone on the phone. So while I was getting bored waiting I had some entertainment of someone yelling at a presumed significant other about the weirdest things. Long story short - the Doctor comes in and does a few breathing tests and wants me to get an X-ray to confirm Pneumonia. I walk down the hall into a different room and take some shots of my lungs and head on out of there with 2 prescriptions: * doxycycline (pill) * brompheniramine-pseudoephedrine (liquid) I'm told to await a call after a radiologist reviews the findings, but in the meantime both the prescriptions will help. They call a few hours later and confirm my lungs have the findings consistent with Pneumonia. I appreciate this validation because hitting like day 14 and unable to heal myself was a bit maddening. I'm hitting 72 hours on the above medication now and starting to finally sleep through the night without additional medication. My coughs are disgusting, but the doctor said it might take months to fully heal the lungs. Hopefully I'll be rid of this soon and can resume normal date night, hobby programming and more.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 09/02/2026
A trip north to Atlanta with an extra drive to the Gainesville area of Georgia.
connortumbleson.com
Travel Blog: Gainesville, GA
As February 5th arrived it was a Thursday with an afternoon flight out to Atlanta to attend a wedding. Things all seemed normal until we sat on the runaway for over 40 minutes waiting in line to take off. Though in a positive light the plane was so empty we had no one between Alyson and I nor anyone in the row in front. Empty row in front of us & semi-open plane. Once we landed we quickly realized how large the Atlanta airport was and got to work navigating train after train to land us at the rental car building. It was the first time in a long time that our destination was Atlanta normally treating Atlanta as a midpoint on some flights. So once Alyson and I got in our rental car (a tiny Prius) we set navigation for our destination of Gainesville and was looking at another hour and 40 minutes of driving. Almost immediately I learned that Atlanta traffic is insanely busy with 8 lane highways full of bumper to bumper traffic. I couldn't believe it - this was a regular Thursday around 7pm and traffic was horrendous. Cars everywhere in constant stop and go traffic with sections of highway that forced us to go from a left exit to right exit to navigate all the way to our destination. After a turbulent flight and exhausting night driving in Atlanta we finally arrived to our hotel (Courtyard by Marriott) in Gainesville. The first thing we noticed is how weird the shower was. Courtyard by Marriott room shower It only had a door on half of the shower which meant the bathroom naturally got a bit wet with how much splashing of water escaped. More annoying was how difficult it was to stay warm when half of the shower was exposed to the entire bathroom. There was no chance to build up a mini steam shower because it only half sealed. The hotel though was situated in the heart of the city so we were in walking distance of plenty of food options. One of the places we walked towards was Johnny's Pizza. Johnny's Pizza in Gainesville, GA We got a few small Greek salads and a bunch of different slices of pizza. The pizza was okay, but I blame ordering a single slice. I could tell the pizza by the slice is just a cheese pizza that they just reheat your customization on top of. I imagine its too difficult to keep all 15~ specialty pizzas warm to sell slices from. As lunch was over it was time to slowly start getting ready for the wedding which was at this nearby New Holland Parlor event space. This place was insanely cool and rustic - like the ceremony space had no ceiling so you could see into the rafters. As we moved downstairs into the cocktail hour and reception we were a basement pool that had been filled in. https://newhollandparlor.com/the-pool-room Unfortunately for me and mainly Alyson I was not feeling good at all requiring heavy doses of fever reducers to be a functioning human. Due to heavy medication I withheld any alcohol at the rehearsal dinner and wedding and skipped any dancing due to some pretty big muscle aches. It hurts to admit I knowingly attended some events under the weather, but we didn't travel all the way to this wedding to not attend. After getting sick on the way home from Delray to sick after arriving in Gainesville has me more sick in a few weeks than the past few years combined. Since it was below freezing in the area and I wasn't feeling well my normal strategy of exploration and blogging was put on hold. This results in a smaller travel blog than normal. The last morning arrived which was our early departure to the airport. Thankfully 8am on a Sunday is completely different traffic than 7pm on a Thursday in Atlanta. Our drive on Sunday was an hour even instead of nearly 2 hours on Thursday. We navigated the confusing Atlanta airport and made it to our gate with 2 hours to go. We grabbed some donuts and lunch and had a quick 64 minute flight home. I got home quickly and wrote a not great blog while downing some Robitussin. I hate being sick with a passion and upset with myself to be sick in both January and February so far.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 02/02/2026
My 2nd Tampa Gasparilla in 2026 alongside a visit to the casino.
connortumbleson.com
Cold Pirates & Casinos
<figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://connortumbleson.com/content/images/2026/02/gaspy-boat-1.jpg" class="kg-image" alt="" loading="lazy" width="1920" height="1446" /><figcaption><span style="white-space:pre-wrap">Seeing the pirate ship arrive for Gasparilla</span></figcaption></figure><p>As the weekend arrived it was time for the yearly iteration of Tampa Gasparilla - the pirate invasion. This time however the weather was floating around 40 degrees which meant it was going to be a chilly party for those accustomed to Florida weather. On the water the gusts were so strong that they even changed the invasion (boat path) to be less on the open water.</p><p>As this would be my 2nd Gasparilla ever this time Alyson and I attended a friend's party near the water so we could experience the arrival of the boats instead of the parade on the ground. While entirely possible to do both, the brutal cold temperatures convinced us to stay to a party that was inside/outside.</p><p>I don't have previous experiences to draw on, but the amount of police boats on the water was crazy. Some of the city names of the boats were from cities 2 hours away. I guess with a fancy pirate ship being towed they had to have plenty of police surrounding the ship to keep everyone safe. Though hearing from other locals around me - usually the cops are outnumbered, but it seemed most boaters skipped this year due to dangerous wind and cold.</p><figure class="kg-card kg-video-card kg-width-regular kg-card-hascaption"> <div class="kg-video-container"> <video src="https://connortumbleson.com/content/media/2026/02/gaspy-invasion.mp4" poster="https://img.spacergif.org/v1/1920x1080/0a/spacer.png" width="1920" height="1080" preload="metadata" style="background:transparent url('https://connortumbleson.com/content/media/2026/02/gaspy-invasion_thumb.jpg') 50% 50% / cover no-repeat"></video> <div class="kg-video-overlay"> <button class="kg-video-large-play-icon"> <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24"> <path d="M23.14 10.608 2.253.164A1.559 1.559 0 0 0 0 1.557v20.887a1.558 1.558 0 0 0 2.253 1.392L23.14 13.393a1.557 1.557 0 0 0 0-2.785Z"></path> </svg> </button> </div> <div class="kg-video-player-container"> <div class="kg-video-player"> <button class="kg-video-play-icon"> <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24"> <path d="M23.14 10.608 2.253.164A1.559 1.559 0 0 0 0 1.557v20.887a1.558 1.558 0 0 0 2.253 1.392L23.14 13.393a1.557 1.557 0 0 0 0-2.785Z"></path> </svg> </button> <button class="kg-video-pause-icon kg-video-hide"> <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24"> <rect x="3" y="1" width="7" height="22" rx="1.5" ry="1.5"></rect> <rect x="14" y="1" width="7" height="22" rx="1.5" ry="1.5"></rect> </svg> </button> <span class="kg-video-current-time">0:00</span> <div class="kg-video-time"> /<span class="kg-video-duration">0:14</span> </div> <input type="range" class="kg-video-seek-slider" max="100" value="0" /> <button class="kg-video-playback-rate">1×</button> <button class="kg-video-unmute-icon"> <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24"> <path d="M15.189 2.021a9.728 9.728 0 0 0-7.924 4.85.249.249 0 0 1-.221.133H5.25a3 3 0 0 0-3 3v2a3 3 0 0 0 3 3h1.794a.249.249 0 0 1 .221.133 9.73 9.73 0 0 0 7.924 4.85h.06a1 1 0 0 0 1-1V3.02a1 1 0 0 0-1.06-.998Z"></path> </svg> </button> <button class="kg-video-mute-icon kg-video-hide"> <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24"> <path d="M16.177 4.3a.248.248 0 0 0 .073-.176v-1.1a1 1 0 0 0-1.061-1 9.728 9.728 0 0 0-7.924 4.85.249.249 0 0 1-.221.133H5.25a3 3 0 0 0-3 3v2a3 3 0 0 0 3 3h.114a.251.251 0 0 0 .177-.073ZM23.707 1.706A1 1 0 0 0 22.293.292l-22 22a1 1 0 0 0 0 1.414l.009.009a1 1 0 0 0 1.405-.009l6.63-6.631A.251.251 0 0 1 8.515 17a.245.245 0 0 1 .177.075 10.081 10.081 0 0 0 6.5 2.92 1 1 0 0 0 1.061-1V9.266a.247.247 0 0 1 .073-.176Z"></path> </svg> </button> <input type="range" class="kg-video-volume-slider" max="100" value="100" /> </div> </div> </div> <figcaption><p><span style="white-space:pre-wrap">The arriving of the pirate ship &amp; many police.</span></p></figcaption> </figure><p>So as we waited on a windy dock we could hear the helicopters and cannons being sounded - the boats were finally arriving. As the boats neared us cannons and people fired beads back n forth between boat and land. Plenty of beads went right into the water, but that must be why divers are out there the next day cleaning up the bay.</p><p>This experience is probably way more fun without heavy wind, freezing temperatures and an occasional drizzle of rain. Though no matter how cold it was there was still a dedicated following of parade attendees in not enough clothing for the weather. The idea of a large party once a year probably convinces most people they can handle any weather situation.</p><p>For us after early drinking and getting whipped by the cold wind and rain - we started our journey back home around 4:30pm to recover for our activity of the next day. We were heading to the casino for a bit of gambling and steak.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://connortumbleson.com/content/images/2026/02/alyson-casino.jpg" class="kg-image" alt="" loading="lazy" width="2000" height="1506" /><figcaption><span style="white-space:pre-wrap">Running into slot machines at Tampa Hard Rock Casino</span></figcaption></figure><p>Now for me a visit to the casino was a 1st time experience so we went with $100 in cash as our first journey together prior to a early dinner celebration. We wandered around the smoke-free section to find some empty slot machines and stumbled upon an area that had plenty of open machines.</p><p>We sat down and put $10 or $20 in both our machines and saw the $1 and predicted that would give us 10 or 20 spins. Quickly we learned we were in a high roller slot section as each spin was taking $10 or $20 per button click. However, since we only put that much money in - we both lost all that money in one button click right out of the gate. Now I understood why someone offered to get us a drink the instant we sat down. I should have watched a YouTube video to understand the credits, denominations and different type of slots available because I was clearly confused with how a $1 bet could cost $20 for a single spin.</p><p>With the embarrassment over we left that section and wandered around to find some cheaper slots so we could kill some time with more than a single button click. As we found a different slot machine I quickly realized the pattern at play - I'd click the button a few times and get nothing and right before my credits were gone I'd get a win that would bring me back up.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://connortumbleson.com/content/images/2026/02/winning-slots.jpg" class="kg-image" alt="" loading="lazy" width="1920" height="1446" /><figcaption><span style="white-space:pre-wrap">Winning double my $20 for a brief moment.</span></figcaption></figure><p>It was almost like clock work that my spins near $0 would net me the biggest return, so once I turned $20 into $45 I left that machine. It blew my mind how fast you can lose money, but also how fast you can gain it. I could click a button and lose $9 in 3 seconds, but watch an animation for 15 seconds that gave me $60.</p><p>Meanwhile a guy next to me would skip every single animation whether he was winning $500 or approaching $0. Some people just looked so brain fried just mindlessly drinking and clicking a button. I also was curious how people were spending so much money without a care in the world - I felt icky just bringing $100 that I was planning to lose, but could watch a random person load in a thousand dollars and lose it in a minute.</p><p>I cashed out slightly ahead and we wandered closer to our dinner reservation and continued losing and winning money. When all said was done as we walked into dinner I had $77 in winnings, but had brought $100 to the casino so overall (-$23) net negative. I was excited though to have another steak experience at <a href="https://casino.hardrock.com/tampa/dining/council-oak-steaks-and-seafood">Council Oak</a> inside the casino. It was the 5th best steakhouse we voted during our 2025 <a href="https://connortumbleson.com/2025/04/28/visiting-the-top-ten-steakhouses-in-tampa-2025/">steak research &amp; blog</a>.</p><p>Though much like last time I hated having to be in the smoking section on the journey to the restaurant. For a non-smoker the air was so disgusting and I just felt dirty breathing the air full of 2nd hand smoke. Thankfully once we entered the restaurant we had a clean separation from the main floor and the air quality was cleaner. I felt bad for any employee who didn't smoke and was forced to work in that area.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://connortumbleson.com/content/images/2026/02/chopped-salad.jpg" width="2000" height="1506" loading="lazy" alt="" /></div><div class="kg-gallery-image"><img src="https://connortumbleson.com/content/images/2026/02/french-onion-soup.jpg" width="2000" height="2656" loading="lazy" alt="" /></div><div class="kg-gallery-image"><img src="https://connortumbleson.com/content/images/2026/02/filet.jpg" width="2000" height="1506" loading="lazy" alt="" /></div></div></div><figcaption><p><span style="white-space:pre-wrap">Chopped salad, French Onion Soup and a 12oz filet.</span></p></figcaption></figure><p>Alyson and I split a salad and French Onion soup and both of us went with fillets this time around. I just wasn't full enough to get the smallest rib-eye size which was 24 ounces of meat. Like expected at a high end steak dining experience the steak was cooked perfectly to my liking and paired with a strong horseradish sauce.</p><p>I was happy to finally have a strong horseradish sauce that rivaled the strength I can do at home. With all the wine and bread we enjoyed though for the first time in awhile I could not finish my entire steak. So we went home with some leftovers and turned our winnings to cash.</p><p>We left with less money than we showed up with, but physiologically we were as low as $14 at one point - so to leave with $77 was something to be proud of. Though knowing the casino never loses it'll be years till we come back for another special occasion. I'm lucky that neither of us are drawn to the casino, because it seems like such an easy place to lose hard earned money. Either way I was happy to understand a bit more on how a basic slot machine works after a bit of trial and error.</p>
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 26/01/2026
connortumbleson.com
Travel Blog: Delray, FL
A trip across the state of Florida to the city line of Boca Raton and Delray Florida celebrating the birthday of my fiance.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 19/01/2026
connortumbleson.com
Bern's Steak House
A deep dive into the food experience at Bern's Steak House in Tampa.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 12/01/2026
connortumbleson.com
The Looming Fear
Fast food isn't fast, people aren't drinking as much nor having as many kids. Do we have looming fears of something?
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 05/01/2026
connortumbleson.com
A Year of Blogging (2025)
My 2018 resolution was simple. Blog once a week. 2025 is over and I've been blogging weekly for 7 years.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 29/12/2025
connortumbleson.com
Dead Internet Theory
In an era of the Internet where most content is visited by a non-human or written by a non-human is this a dead Internet?
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 22/12/2025
connortumbleson.com
The OIDC Future
In an era where any password or key can be lost - a solution that requires no keys seems extremely attractive.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 15/12/2025
connortumbleson.com
Seared Ahi Tuna Salad
Seared Ahi Tuna is an excellent dish when laid on top of a bed of lettuce. Though what happens when a menu change tweaks a long-standing design?
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 08/12/2025
connortumbleson.com
Kabob's
Making kabob's is such a time consuming journey, but the result is an excellent meal.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 01/12/2025
connortumbleson.com
A history of fastlane
fastlane has been the key piece of software for automation around iOS and Android applications, so I take a dive through its history of inception to present.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 24/11/2025
connortumbleson.com
Helping out Open Source
Sometimes when an Open Source project is showing signs of abandonment - a valid option is to email and join them.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 17/11/2025
connortumbleson.com
Hestan Cue Smart Pan Rebate
After purchasing a new stove I submitted an online rebate and 147 days later a pan showed up - just not what I expected.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 10/11/2025
connortumbleson.com
2025 Emerging Tech Leader of the Year (Tampa Bay)
The 2025 Emerging Tech Leader of Tampa Bay was announced and I was a finalist. So Alyson and I went down to attend the award show with some coworkers.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 03/11/2025
connortumbleson.com
Halloween Candy Wheel
I had an idea to change the norm of Halloween and ask the trick or treaters to spin a candy wheel for their prize.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 27/10/2025
connortumbleson.com
Another Halo CE Remake
A new Halo game is coming - this time its another Halo CE remake. This time Halo: Campaign Evolved on Unreal Engine.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 20/10/2025
connortumbleson.com
Travel Blog: Anna Maria, FL (3)
Another travel blog, this time heading roughly an hour away in a car to visit Anna Maria Island for a short weekend adventure.
000
Connor Tumbleson @blog.connortumbleson.com.ap.brid.gy · 13/10/2025
connortumbleson.com
The Daily AI Dosage
A new day with a heavy amount of AI - is this the new normal?
000