Sign in

FreeRave

@freerave.bsky.social
22 followers 8 following 239 posts

Dev-Tools & Mobile Engineer | Creator of 7 VS Code extensions & the DotSuite ecosystem (DotScramble, DotEnvy) | Python, Kotlin & Flutter | Building AI tools for devs & robust native apps.

PostsRepliesMedia
FreeRave @freerave.bsky.social · 1h
LastPass is the textbook case. That's why DotGhostBoard keeps everything local and the .vault export is AES-256-GCM encrypted, so even if the file leaks, it's just ciphertext without your passphrase.
000
FreeRave @freerave.bsky.social · 14h
6/6 Read the full Part 2 Deep Dive on Dev.to: dev.to/freerave/dot... ⭐ GitHub (523 tests passing • Apache-2.0): github.com/kareem2099/D... Try it on Linux! 🐧
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
FreeRave @freerave.bsky.social · 14h
5/6 Coordinated Plaintext History Sweep When you copy a key, it enters clipboard history before the Vault. We closed this gap: Saving/deleting a secret sweeps matching unencrypted entries from SQLite history. Plus 3-version encrypted history with 1-click revert!
100
FreeRave @freerave.bsky.social · 14h
4/6 Secret Expiry Tracking & Badges API keys and production tokens shouldn't live forever. DotGhostBoard 2.1 introduces calendar-based expiry with dynamic visual badges: • ⛔ EXPIRED • ⚠️ 3d left • ⏳ Active countdown Never let stale credentials linger unnoticed.
100
FreeRave @freerave.bsky.social · 14h
3/6 Built-in CSPRNG Password Generator No switching windows to generate credentials. Built on Python's secrets module (/dev/urandom). Features live keyspace entropy: H = L × log₂(N). Visual meter up to 131 bits (Fort Knox) + UUIDv4, Base64, Hex presets! #DevOps
100
FreeRave @freerave.bsky.social · 14h
2/6 Standalone .vault Binary Backups We engineered a tamper-proof package format: DGBV header + version + 16B salt + 12B nonce + ciphertext + 16B GCM tag. Authenticated with AES-256-GCM + AAD. Modifying 1 bit triggers instant cipher rejection. 100k PBKDF2 rounds.
100
FreeRave @freerave.bsky.social · 14h
1/6 Most password managers have a backup dilemma: Export to unencrypted CSV and you dump plaintext secrets on disk. Use proprietary cloud sync and you give keys to a 3rd party. Part 2 of our DotGhostBoard 2.1 "Leviathan" deep dive is live! #Linux #Security
200
FreeRave @freerave.bsky.social · 02/10/2026
6/6 📖 Read Part 1 on Dev.to: dev.to/freerave/dot... ⭐ GitHub (523 tests passing • Apache-2.0): github.com/kareem2099/D... Try it on Linux today! 🐧
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
FreeRave @freerave.bsky.social · 02/10/2026
5/6 Coming Next in Part 2 Next up, our cryptographic security stack: • Standalone .vault backup packages (AES-256-GCM + AAD) • CSPRNG Password Generator with 131-bit entropy meter • Secret expiry tracking & status badges • Plaintext clipboard history sweeps
100
FreeRave @freerave.bsky.social · 02/10/2026
4/6 Contextual Inline Smart Actions No more window switching: • ⚙️ { } Format JSON: 1-click 2-space indentation • 🔗 Open Link: Direct launch in browser • 🛡️ Send to Vault: Envelope encryption for secrets • 📡 Copy Clean IP: Strips log noise instantly Productivity in 1 click.
100
FreeRave @freerave.bsky.social · 02/10/2026
3/6 Instant Smart Auto-Tagging Copied text is classified and tagged on the fly: • #link — Web URLs • #json — Minified/raw JSON • #secret — API keys, JWTs, AWS tokens • #code — Python, JS, Bash snippets • #ip, #email, #path, #hash Seamlessly searchable and filterable.
100
FreeRave @freerave.bsky.social · 02/10/2026
2/6 Zero AI. Zero Cloud. Under 1ms. Using an LLM for clipboard text is a privacy & latency nightmare. Instead, we built a deterministic engine using pre-compiled regex, Shannon entropy & fast heuristics. Typical payloads (< 5KB) classify in 8–82 µs! #Python #DevOps
100
FreeRave @freerave.bsky.social · 02/10/2026
1/6 Most clipboard managers treat every copied item the same: inert text in a database. With DotGhostBoard 2.1 "Leviathan", your clipboard understands what it's holding and surfaces actions immediately. Part 1 of our technical deep dive is live! #Linux #OpenSource
110
FreeRave @freerave.bsky.social · 28/09/2026
6/6 Read the full engineering deep dive: 📖 Dev.to: dev.to/freerave/bui... 🌐 Live: universe.dotsuite.dev ⭐ GitHub: github.com/kareem2099/d...
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
010
FreeRave @freerave.bsky.social · 28/09/2026
5/6 The best part? No backend required: ❌ No server ❌ No database ❌ No auth layers Because both store APIs support CORS, vanilla JS in the browser + scheduled GitHub Actions handles the entire pipeline cleanly and for free.
100
FreeRave @freerave.bsky.social · 28/09/2026
4/6 Two key engineering decisions: 1️⃣ 24h Cache TTL: Extensions update over days/weeks, not minutes. 24h is a practical default that stops redundant API calls. 2️⃣ Clean Git History: CI checks `git diff --staged --quiet` so it only commits when numbers actually change!
100
FreeRave @freerave.bsky.social · 28/09/2026
3/6 The Architecture: Dual-Path Sync Runtime Path: Browser fetches store APIs directly via CORS and caches in localStorage for 24 hours. Build/CI Path: A Node script runs daily via GitHub Actions to keep the static README and HTML fallback fresh.
100
FreeRave @freerave.bsky.social · 28/09/2026
2/6 The problem: VS Marketplace and Open VSX expose completely different APIs. Every new release meant: • Checking 2 dashboards • Calculating total installs • Editing HTML cards & README badges I needed one source of truth for both live visitors and the static repo.
100
FreeRave @freerave.bsky.social · 28/09/2026
1/6 Maintaining 7 VS Code extensions across 2 marketplaces (19,500+ downloads) is great—until you have to sync versions & metrics by hand. Instead of spinning up a backend, I built a zero-dependency dual-path synchronizer. Here’s how it works
100
FreeRave @freerave.bsky.social · 26/09/2026
Lesson: Never ship static credentials in client bundles. Read the full engineering post-mortem on Dev.to: dev.to/freerave/the... #FreeRave #VSCode #AppSec #DevSecOps
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
FreeRave @freerave.bsky.social · 26/09/2026
The Scanner Paradox: Marketplace scanners then flagged DotEnvy for leaking AWS and Stripe keys — because our regex patterns DETECTED them! We resolved false positives via runtime pattern construction: new RegExp(['A', 'KIA', '[0-9A-Z]{16}'].join('')) + pre-publish CI/CD gates.
100
FreeRave @freerave.bsky.social · 26/09/2026
The Architecture: Zero Embedded Secrets 1. Extension registers anonymously on first launch via /extension/register (10/hr IP limit). 2. Backend returns a per-device secret stored in OS SecretStorage (Keychain). 3. Requests signed with HMAC-SHA256 + 5-minute replay defense.
100
FreeRave @freerave.bsky.social · 26/09/2026
The Trap: We needed DotEnvy to authenticate requests to our backend using HMAC. Our build script injected an EXTENSION_SHARED_SECRET before packaging. Security bots (Trufflehog, GitHub) caught it immediately. If 1 user extracts it, your entire backend trust model collapses.
100
FreeRave @freerave.bsky.social · 26/09/2026
A .vsix file is not a compiled binary. It is literally just a ZIP archive containing plain JavaScript. If your build pipeline injects a secret before packaging, anyone can extract it in seconds with unzip and grep. Here is how we eliminated embedded client secrets in DotEnvy
100
FreeRave @freerave.bsky.social · 24/09/2026
Key results: ~80% fewer cloud API calls Native OS SecretStorage Risk signals, not a security oracle Read the full engineering deep dive on Dev.to: dev.to/freerave/dot... #FreeRave #VSCode
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
FreeRave @freerave.bsky.social · 24/09/2026
🔹 L3: Shannon Entropy Gate Pure math filter. Candidates with H(X) < 3.5 are dropped immediately, eliminating ~80% of candidate noise. 🔹 L4: Neural Classifier Only the ~20% ambiguous tokens reach our Python backend, where a 35-feature model analyzes surrounding code semantics.
110
FreeRave @freerave.bsky.social · 24/09/2026
🔹 L1: In-Process Regex Known tokens (AWS, Stripe, GitHub) resolve in sub-milliseconds without touching the network. 🔹 L2: Truncated Composite Hashing Cross-references hashes against an anti-poisoning community blacklist via an O(1) in-memory Set. The full secret is never sent.
100
FreeRave @freerave.bsky.social · 24/09/2026
Calling an AI model for every single secret scan in a VS Code extension was a terrible idea. Every keystroke added 400ms latency, and high-entropy noise easily fooled the model. Here is how we decoupled detection into a 4-layer pipeline in DotEnvy
110
FreeRave @freerave.bsky.social · 17/09/2026
7/7 Full deep-dive case study on Dev.to: dev.to/freerave/fro... Star & download on GitHub: github.com/kareem2099/D... OpenDesktop / Pling Store: www.opendesktop.org/p/2353623/ #FreeRave #Python #Linux
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
010
FreeRave @freerave.bsky.social · 17/09/2026
6/7 The Results (By The Numbers): 📉 -35% LOC in the main Dashboard window 📈 +39% tests (220 ➔ 306 passing tests) ⚡ 3.7x faster CI test suite (14.2s ➔ 3.8s) 🛡️ 0 detected user-facing regressions Architecture over rewrites. #Linux #OpenSource
110
FreeRave @freerave.bsky.social · 17/09/2026
5/7 Phase 4: Slicing the Monolithic UI Extracted 4 behavioral QObject controllers: • HistoryController (cards & search) • CollectionController (folders) • SecurityController (vault & lock) • SyncController (LAN P2P) Dashboard shrank by -35% LOC (-818 lines).
100
FreeRave @freerave.bsky.social · 17/09/2026
4/7 Phase 3: Cryptographic Rigor 2-tier key derivation chain: Password ➔ PBKDF2 (600k iter) ➔ Base Key ➔ HKDF-SHA256 ➔ Vault KEK. Password rotation now takes ~2ms via constant-time DEK re-wrapping instead of re-encrypting the whole database.
100
FreeRave @freerave.bsky.social · 17/09/2026
3/7 Phase 1 & 2: Decoupling the Core • Decomposed storage into clean Repositories with a 100% backward-compatible Facade (zero broken imports). • Extracted a headless ClipboardPipeline using Python Protocols, ready for native Wayland in v2.0.
100
FreeRave @freerave.bsky.social · 17/09/2026
2/7 Instead of a risky Big Bang rewrite, we established one golden rule: "Controllers coordinate UI behavior. Services own business rules. Repositories own persistence. Backends own platform integration." Everything has a strict boundary.
100
FreeRave @freerave.bsky.social · 17/09/2026
1/7 A 2,353-line UI file is a symptom that storage, crypto, sync, and UI have collapsed into one boundary. That was DotGhostBoard v1.5 (our Linux clipboard manager). Here is how we refactored the monolith with 0 regressions #FreeRave #Python
100
FreeRave @freerave.bsky.social · 21/08/2026
Full engineering deep dive: dev.to/freerave/ins... VS Code Marketplace: marketplace.visualstudio.com/items?itemNa... Open VSX: open-vsx.org/extension/fr... GitHub: github.com/kareem2099/D...
dev.to
Inside DotFetch v2.1.0: Auth Boundaries, WebView Security, and Request Architecture
A deep dive into building DotFetch v2.1.0: Modular architecture in VS Code WebViews, RFC 6749 OAuth...
010
FreeRave @freerave.bsky.social · 21/08/2026
8/8 DotFetch is free and open source. I wrote a deeper breakdown of the architecture, security boundaries, and runtime testing behind v2.1.0. 🔗 Article + install links in the reply below. #vscode #typescript #opensource #devtools #api
dev.to
Inside DotFetch v2.1.0: Auth Boundaries, WebView Security, and Request Architecture
A deep dive into building DotFetch v2.1.0: Modular architecture in VS Code WebViews, RFC 6749 OAuth...
141
FreeRave @freerave.bsky.social · 21/08/2026
7/8 Under the hood The interesting part wasn’t adding auth. It was keeping WebView state, persistence, environment substitution, and live request execution separated. That led to: • Draft vs Wire separation • Backend-owned Basic Auth • OAuth expiry checks • Response size guards
100
FreeRave @freerave.bsky.social · 21/08/2026
6/8 Credential boundaries 🔒 Saved requests should not become secret stores. DotFetch strips plaintext passwords, Bearer tokens, API key values, OAuth client secrets, and temporary access tokens before persisting Collections, Favorites, or History.
100
FreeRave @freerave.bsky.social · 21/08/2026
5/8 Better inspection 📋 Response Headers now have their own structured inspector. 👁️ Secret fields support show/hide controls. Auth previews stay masked while copy actions still use the real runtime value. Small UX details, but they matter a lot during daily API work.
100
FreeRave @freerave.bsky.social · 21/08/2026
4/8 SSL/TLS 🛡️ Testing local services with self-signed certificates? SSL verification can be disabled per request. When it is off, DotFetch shows a clear: ⚠️ SSL Ignored And secure verification remains the default. /home/kareem/Pictures/Screenshots/Screenshot From 2026-08-19 15-19-13.png
100
FreeRave @freerave.bsky.social · 21/08/2026
3/8 OAuth 2.0 OAuth 2.0 Client Credentials is now built in. Enter your Token URL, Client ID, Client Secret, and optional Scope. DotFetch fetches the token, tracks expiry metadata, and injects the Bearer token into live requests.
100
FreeRave @freerave.bsky.social · 21/08/2026
2/8 API Keys 🔑 API Key auth now supports both: • Header mode X-API-Key: ... • Query mode ?api_key=... With masked live previews and copy actions built into the Auth UI.
100
FreeRave @freerave.bsky.social · 21/08/2026
1/8 Stop leaving VS Code just to test an API endpoint. DotFetch v2.1.0 brings authentication, environment-aware requests, SSL controls, and response inspection directly into your editor. Here’s what changed 👇
100
FreeRave @freerave.bsky.social · 13/07/2026
12/ What would it take for you to actually trust one of these tools with your codebase again? #DevOps #CyberSecurity #AI #InfoSec #SoftwareEngineering
010
FreeRave @freerave.bsky.social · 13/07/2026
11/ The default behavior — the thing that started this whole story — hasn't changed for the average dev running this CLI out of the box. Good first move, but not a complete fix. Full article updated with this latest development and the hardening guide: dev.to/freerave/xai...
dev.to
xAI's Grok Build CLI Was Quietly Uploading Entire Codebases to Google Cloud
xAI's Grok Build CLI uploaded whole git repos — secrets included — to Google Cloud,...
100
FreeRave @freerave.bsky.social · 13/07/2026
10/ Genuinely good that they responded fast. But let’s be clear-eyed about what this is: ❌ Not a formal security advisory ❌ No scope disclosure (how much data was collected?) ❌ ZDR is enterprise-only ❌ The /privacy fix requires you to already know to run it manually
100
FreeRave @freerave.bsky.social · 13/07/2026
9/ Update: @SpaceXAI just responded. Teams with Zero Data Retention (ZDR) get no code retained, and a new /privacy command in the CLI disables retention & deletes previously synced data for everyone else. Elon Musk separately confirmed: all data uploaded before now will be "completely deleted."
112
FreeRave @freerave.bsky.social · 13/07/2026
8/ If you've run Grok Build near a real .env, API key, or client repo: rotate everything now. Don't wait for xAI to explain itself — they haven't, and there's no timeline suggesting they will.
100
FreeRave @freerave.bsky.social · 13/07/2026
7/ Imagine any other company doing this. Imagine a note-taking app silently zipping your entire hard drive to a bucket named after itself, ignoring your explicit "don't touch this" instruction, and then going quiet when caught. Would you call that a "privacy setting bug"? Or something else?
100