Sign in

Glenn 'devalias' Grant

@devalias.net
36 followers 26 following 64 posts

Hack. Dev. Transcend. // Polyglot Developer | Ethical Hacker | Biohacker | Youth Tech Advocate | Certified Human Potential Coach www.devalias.net twitter.com/_devalias github.com/0xdevalias

PostsRepliesMedia
Glenn 'devalias' Grant @devalias.net · 29/05/2026
I didn't look too deeply into it though, but I suspect that might hold some answers depending on what specifically you were looking for. Though might be a bit of a technical approach; and not even sure how best to figure 'what changed'; maybe extracting the relevant part + diffing between versions?
010
Glenn 'devalias' Grant @devalias.net · 29/05/2026
I can't remember where exactly I saw it, it was either when running strings on Serum 2.x vst, or maybe it was in some of the more reverse engineered stuff with Binary Ninja, but I remember seeing a bunch of stuff that looked like UI related config / XML / similar ages back.
110
Glenn 'devalias' Grant @devalias.net · 29/05/2026
Ah true, that's no fun. Not sure if it would be helpful / if you've already seen it, but I have another gist tracking the Serum changelog notes here: gist.github.com/0xdevalias/a... This was the entry for 2.0.19: gist.github.com/0xdevalias/a...
gist.github.com
Xfer Records - Serum - Changelog / Release Notes
Xfer Records - Serum - Changelog / Release Notes. GitHub Gist: instantly share code, notes, and snippets.
110
Glenn 'devalias' Grant @devalias.net · 28/05/2026
Given it took me like 6 months to reply; did you find a solution in the end?
100
Glenn 'devalias' Grant @devalias.net · 28/05/2026
Hey, sorry for the super slow reply; apparently I wasn’t getting notifications from Bluesky 😅 Glad you found the preset format gists interesting/helpful :3 Unfortunately I haven’t really looked too deeply into Serum skins; so can’t help with that.
110
Glenn 'devalias' Grant @devalias.net · 01/09/2025
Crossposted: x.com/_devalias/st...
x.com
000
Glenn 'devalias' Grant @devalias.net · 01/09/2025
Also, interested if anyone knows of research or benchmarks for assessing/scoring the quality of variable/function/identifier names? Goal: to rank/benchmark restored names after reversing minified code. Related: github.com/Ch3nYe/JsDeO...
github.com
Consider evaluating identifier naming in a future version of the benchmark · Issue #2 · Ch3nYe/JsDeObsBench
The following idea / note came from discussion on j4k0xb/webcrack#189: Afaik the evaluation metrics don't consider renamed identifiers so humanify would also have a pretty similar or the same score...
100
Glenn 'devalias' Grant @devalias.net · 01/09/2025
Anyone know of a good JavaScript Unminify benchmark by chance? (Or want to build one) I’m thinking of a similar vibe to JSDeObsBench: jsdeobf.github.io An issue I opened for it previously: github.com/Ch3nYe/JsDeO...
github.com
Are there any similar benchmarks / leaderboards for JS unbundling / unminification? · Issue #3 · Ch3nYe/JsDeObsBench
The following idea / question came from discussion on j4k0xb/webcrack#189: And for comparing wakaru it would be a better idea to use a dataset for minifiers, transpilers and bundlers. Yeah, that's ...
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
Crossposted: x.com/_devalias/st... www.linkedin.com/posts/glenn-...
x.com
Glenn 'devalias' Grant on X: "That feel when you ignore your 'notify on post' notifications for like 2 weeks, and then you finally go to procrastinate by catching up on them, and scroll and scroll, and then instead of actually reading them you start to wonder how you can count how many need triaging..." / X
That feel when you ignore your 'notify on post' notifications for like 2 weeks, and then you finally go to procrastinate by catching up on them, and scroll and scroll, and then instead of actually reading them you start to wonder how you can count how many need triaging...
000
Glenn 'devalias' Grant @devalias.net · 20/05/2025
Today's deepdive was probably also the most productive one yet for finding the bits and pieces I need to pull together a user script / Chrome extension to help make this 'keep up to date' / 'triage' process much less painful / time consuming... But that's a story for another day
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
...but by that stage you've run out of time in the day to actually look through them all... 😅 At least I can quantify how much effort it will take now; which should help remove the 'do I have enough time for this' paralysis and maybe actually process them more often.
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
...and then with all of that, you build up some little helper functions and gadgets to stitch the data together, then a few more to process that hydrated array and count the tweets per day/user/etc, and then finally end up knowing that you have ~560 tweets to look through...
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
...but then you remember about React fibres and start looking through those to see if you can find where the full list of notification tweets are, and you find it but it's just a list of IDs, so you crawl deeper into the rabbit hole until you get a reference to the datastore...
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
...so you accidentally find yourself in the familiar rabbit hole of skimming through the DOM looking for relevant bits to build selectors off, and then remembering that the timeline only renders a slice of the list to the DOM so you can't just count rendered elements...
100
Glenn 'devalias' Grant @devalias.net · 20/05/2025
That feel when you ignore your 'notify on post' notifications for like 2 weeks, and then you finally go to procrastinate by catching up on them, and scroll and scroll, and then instead of actually reading them you start to wonder how you can count how many need triaging...
100
Glenn 'devalias' Grant @devalias.net · 28/04/2025
Crossposted: x.com/_devalias/st... www.linkedin.com/posts/glenn-...
000
Glenn 'devalias' Grant @devalias.net · 28/04/2025
For now the code/extension is unpublished, but eventually will be made open source and probably published to the Chrome extension store as well
100
Glenn 'devalias' Grant @devalias.net · 28/04/2025
48 windows with 121 tab groups and a total of 954 open tabs is fine.. right? (Note: that 'open' is a bit nuanced, as I have Chrome features enabled that unload/freeze/etc closed tab groups / tabs that haven't been used recently, etc; without necessarily 'closing' those tabs)
100
Glenn 'devalias' Grant @devalias.net · 28/04/2025
This afternoon I decided to hack in a new feature to tell me how many Chrome windows, tab groups, and tabs I have open; so now I no longer need to guess/count how big of a problem it is!
100
Glenn 'devalias' Grant @devalias.net · 28/04/2025
A few weeks back I casually hacked together a PoC vibe coded chrome extension to help work around some of the annoyances I find with Chrome's Tab Group UX currently; and every now and then I've been making little tweaks to it to make it a bit nicer/more useful.
100
Glenn 'devalias' Grant @devalias.net · 22/04/2025
And similar to my original gist, to better direct people to the appropriate details in a slightly less scattered/chaotic way than in the past: Serum 1 Preset File Format (.fxp): gist.github.com/0xdevalias/5... Serum 2 Preset File Format (.SerumPreset): gist.github.com/0xdevalias/5...
011
Glenn 'devalias' Grant @devalias.net · 22/04/2025
I also added 2 new sections to my new gist, summarising the Serum 1 preset (.fxp) file format notes: gist.github.com/0xdevalias/1... And the Serum 2 preset (.SerumPreset) file format notes: gist.github.com/0xdevalias/1...
111
Glenn 'devalias' Grant @devalias.net · 22/04/2025
The Serum v1 .fxp file format hasn't been fully figured out yet, but I summarised links to my old notes/tools/progress on this in the following issue, in case it helps anyone else make further progress on it: github.com/KennethWussm...
github.com
Support for legacy Serum v1.x `.fxp` preset format · Issue #1 · KennethWussmann/serum-preset-packager
I know the README explicitly states that it isn't supported: The legacy .fxp is NOT supported. But I figured since sooner or later someone is probably going to ask about it anyway; I'd preemptively...
100
Glenn 'devalias' Grant @devalias.net · 22/04/2025
Speaking of the discussions in the comments on my gist, KennethWussmann was making good progress on the Serum 2 preset file format: gist.github.com/0xdevalias/5... And has since figured it out: gist.github.com/0xdevalias/5... And published a tool to decode it to JSON: github.com/KennethWussm...
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
Crossposted: x.com/_devalias/st...
x.com
Glenn 'devalias' Grant on X: "Speaking of old projects of mine; there's been some interesting discussion recently on one of my old gists that in part is about reverse engineering / figuring out the Serum VST preset file format." / X
Speaking of old projects of mine; there's been some interesting discussion recently on one of my old gists that in part is about reverse engineering / figuring out the Serum VST preset file format.
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
If reverse engineering / figuring out the Serum VST preset format is something you have any interest / insight in, I'd love to collaborate on it with anyone who's interested. (I find it hard to find the time to push forward all of my projects as quickly as I would like to)
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
Which I then summarised/mused over to fill in the context as best I could remember it in this comment back on the main gist: gist.github.com/0xdevalias/5...
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
This also inspired me to dig out some of my old notes and code (that I had forgotten where they were it had been that long.. 😅), and made a new gist to upload those to: gist.github.com/0xdevalias/1...
gist.github.com
Reverse Engineering Serum Preset Format - Supplementary Notes
Reverse Engineering Serum Preset Format - Supplementary Notes - 1-reverse-engineering-serum-preset-format-supplementary-notes.md
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
The main gist is here: gist.github.com/0xdevalias/5... But check the comments for recent discussions and insights, for both Serum v1 and v2 preset file formats: gist.github.com/0xdevalias/5...
100
Glenn 'devalias' Grant @devalias.net · 21/04/2025
Speaking of old projects of mine; there's been some interesting discussion recently on one of my old gists that in part is about reverse engineering / figuring out the Serum VST preset file format.
111
Glenn 'devalias' Grant @devalias.net · 21/04/2025
Made a few more tweaks to my PoC web app build diff minimiser script the other day. It now can de-noise my 33,399 line sample diff down to just 3,991 lines; much easier to review/see the salient changes. See the posts in this thread (on Twitter / X) for more details: x.com/_devalias/st...
x.com
000
Glenn 'devalias' Grant @devalias.net · 18/04/2025
Crossposted: x.com/_devalias/st...
x.com
Glenn 'devalias' Grant on X: "Does anyone know if there is anything like https://t.co/HWyFB1Nx9a / https://t.co/wvbBKZFfzK but for the @npmjs / JavaScript ecosystem?" / X
Does anyone know if there is anything like https://t.co/HWyFB1Nx9a / https://t.co/wvbBKZFfzK but for the @npmjs / JavaScript ecosystem?
000
Glenn 'devalias' Grant @devalias.net · 18/04/2025
This was the deep dive rabbithole of things I found when I was last looking into this sort of thing: gist.github.com/0xdevalias/3...
100
Glenn 'devalias' Grant @devalias.net · 18/04/2025
Does anyone know if there is anything like github.com/pypi-data / py-code.org but for the @npmjs.bsky.social / JavaScript ecosystem?
github.com
pypi-data
pypi-data has 348 repositories available. Follow their code on GitHub.
110
Reposted by Glenn 'devalias' Grant
Binary Ninja @binary.ninja · 07/04/2025
Kyle's talk at Insomni'Hack is live! youtu.be/I0PoE0IdtmE?... Check it out if you're interested in a slice of modern program analysis and try the latest version of Tanto as well, in the plugin manager or at github.com/Vector35/tanto
youtu.be
"A Slice Of" Modern Program Analysis - Kyle Martin
0116
Reposted by Glenn 'devalias' Grant
Insomni'hack @1ns0mn1h4ck.bsky.social · 25/02/2025
🗓️ We’re thrilled to announce Kyle Martin’s session at Insomni’hack 2025: "'A Slice of' Modern Program Analysis". 🔍 Discover the lineup and book your spot: insomnihack.ch/talks/a-slic... #INSO25 #Cybersecurity #EthicalHacking #Switzerland
022
Reposted by Glenn 'devalias' Grant
cts @gf256.bsky.social · 11/01/2025
Many YouTube videos lately are clickbait and stretch out a Wikipedia page into 30 minutes. Many videos are just questions with simple answers. So I built tldw.tube: put in the URL and save your time! (No hate on Veritasium, it just happened to work well for the screenshot)
96017
Glenn 'devalias' Grant @devalias.net · 28/03/2025
For publishing to arXiv they have a very clear page about who can submit (basically anyone), and the format/expectations they have around it: info.arxiv.org/help/submit/... Also added to my gist here: gist.github.com/0xdevalias/6...
info.arxiv.org
Submission Guidelines - arXiv info | arXiv e-print repositorycontact arXivsubscribe to arXiv mailingsReport an issue
000
Glenn 'devalias' Grant @devalias.net · 28/03/2025
Crossposted: Twitter / X: x.com/_devalias/st... Threads: www.threads.net/@_devalias/p... LinkedIn: www.linkedin.com/posts/glenn-...
110
Glenn 'devalias' Grant @devalias.net · 27/03/2025
I've also created a new gist for capturing and collating anything I learn in this space + related resources + etc: > How to Publish InfoSec and Software Engineering Research Papers as an Independent Researcher gist.github.com/0xdevalias/6...
gist.github.com
Some notes on how to publish InfoSec and Software Engineering research papers as an independent researcher
Some notes on how to publish InfoSec and Software Engineering research papers as an independent researcher - how-to-publish-tech-research-as-an-independent-researcher.md
100
Glenn 'devalias' Grant @devalias.net · 27/03/2025
Lately, the depth of some of my deep dives has started to feel like it warrants more lasting outputs than just a blog post—so I’ve been thinking more seriously about the idea of publishing proper research.
100
Glenn 'devalias' Grant @devalias.net · 27/03/2025
I end up doing a lot of deep dives into software dev/infosec things; and would usually write/release open source code or a blog about it, etc; but wanting to figure out how much extra effort is involved to package it all up/jump through the hoops to publis it for academia/related
100
Glenn 'devalias' Grant @devalias.net · 25/03/2025
Do I know anyone in the InfoSec / Software Engineering / similar space of things; who also have experience with academia, and what goes into writing / publishing a paper / research? I’d love to learn more about what goes into the process / how to do so.
121
Glenn 'devalias' Grant @devalias.net · 27/02/2025
Crossposted: x.com/_devalias/st... www.linkedin.com/posts/glenn-... gist.github.com/0xdevalias/3...
000
Glenn 'devalias' Grant @devalias.net · 27/02/2025
My initial debugging started here: github.com/jehna/humani... Upstream pkgroll bug report: github.com/privatenumbe... Minimal repro repo: github.com/0xdevalias/m...
100
Glenn 'devalias' Grant @devalias.net · 27/02/2025
tl;dr: The pkgroll update switched to using esbuild to transpile things it wasn't before. Humanify was set to use ES2017, which doesn't support import.meta A fix was made in pkgroll to tell esbuild to mark import.meta as explicitly supported when using ESM modules.
100
Glenn 'devalias' Grant @devalias.net · 27/02/2025
The results of my recent deep dive into exploring why humanify was broken by an update to @hirok.io 's pkgroll; which turned out to be related to how esbuild was transpiling import.meta usage when importing prettier stackoverflow.com/questions/77...
stackoverflow.com
prettier "createRequire" The argument 'filename' must be a file URL object, file URL string, or absolute path string. Received undefined
I am using prettier programmatically, in code, with the format(jsCodeString) function. The code works locally, but when I bundle it with esbuild, in production prettier fails when it tries to dynam...
100
Glenn 'devalias' Grant @devalias.net · 17/01/2025
gist.github.com/0xdevalias/0...
gist.github.com
Some notes on how to read GitHub notifications from the gh CLI.
Some notes on how to read GitHub notifications from the gh CLI. - reading-github-notifications-from-gh-cli.md
000
Glenn 'devalias' Grant @devalias.net · 17/01/2025
This afternoon's esoteric hyperfocus: crafting a convoluted GitHub CLI API command + JQ filter to reformat the output to view GitHub notifications in the CLI. Then a wrapper zsh script + gh alias to it.
100
Glenn 'devalias' Grant @devalias.net · 13/01/2025
Also there are a bunch of helpful utils functions that would have saved me a heap of hassle reinventing the wheel had I skimmed through the docs fully first.. eg. pandoc.org/lua-filters.... pandoc.org/lua-filters.... pandoc.org/lua-filters.... pandoc.org/lua-filters....
000