Rachel
banner
rachel.transitory.social.ap.brid.gy
Rachel
@rachel.transitory.social.ap.brid.gy
Still trying to figure things out.
(In general, like, life I guess ​:trans:​?)

Profile pic is filter of faceapp

Mostly techposting. Occasional mountains […]

🌉 bridged from ⁂ https://transitory.social/@rachel, follow @ap.brid.gy to interact
The best part about finally becoming who you have always wanted to be is the additional item slots you unlock as you level up
January 1, 2026 at 6:54 PM
Happy new years from the East Coast

2025 was a fuck

Here is hoping for a better 2026 🎉​:trans_fire:​
January 1, 2026 at 5:04 AM
Reposted by Rachel
2025 was a wild, and often shitty year. The were some bright moments almost the darkness and chaos. For me, it was a mostly catalyst. I just hope that the reaction that it enables leads to good things.
December 31, 2025 at 6:06 AM
December 31, 2025 at 5:34 AM
AaaaaaaaaaAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA ​:neocat_scream:​
December 31, 2025 at 5:23 AM
Ok, noon, I should probably get out of bed
December 30, 2025 at 5:03 PM
There are hospital grade outlets but hear me out: airport grade outlets, with significantly improved springs so they don't wear out in a year
December 29, 2025 at 1:17 PM
I gotta say the ads here are probably the second most sinister I've seen at transit/airports
December 29, 2025 at 4:41 AM
https://nesbitt.io/2025/12/27/how-to-ruin-all-of-package-management.html

What in the fuck we are in the bad timeline for sure
How to Ruin All of Package Management
Prediction markets are having a moment. After Polymarket called the 2024 election better than the pollsters, the model is expanding everywhere: sports, weather, Fed interest rate decisions. The thesis is that markets aggregate information better than polls or experts. Put money on the line and people get serious about being right. Package metrics would make excellent prediction markets. Will lodash hit 50 million weekly downloads by March? Will the mass-deprecated package that broke the internet last month recover its dependents? What’s the over/under on GitHub stars for the hot new AI framework? These questions have answers that resolve to specific numbers on specific dates. That’s all a prediction market needs. Manifold already runs one on GitHub stars.1 Imagine you could bet on these numbers. Go long on stars, buy a few thousand from a Fiverr seller, collect your winnings. Go long on downloads, publish a hundred packages that depend on it, run npm install in a loop from cloud instances. The manipulation is mostly one-directional: pumping is easier than dumping, since nobody unstars a project. But you can still short if you know something others don’t. Find a zero-day in a popular library, take a position against its download growth, then publish the vulnerability for maximum impact. Time your disclosure for when the market’s open. It’s like insider trading, but for software security. The attack surface includes anyone who can influence any metric: maintainers who control release schedules, security researchers who control vulnerability disclosures, and anyone with a credit card and access to a botnet. Prediction markets are supposed to be hard to manipulate because manipulation is expensive and the market corrects. This assumes you can’t cheaply manufacture the underlying reality. In package management, you can. The entire npm registry runs on trust and free API calls. This sounds like a dystopian thought experiment, but we’re already in it. ### The tea.xyz experiment Tea.xyz promised to reward open source maintainers with cryptocurrency tokens based on their packages’ impact. The protocol tracked metrics like downloads and dependents, then distributed TEA tokens accordingly. The incentive structure was immediately gamed. In early 2024, spam packages started flooding npm, RubyGems, and PyPI. Not malware in the traditional sense, just empty shells with `tea.yaml` files that linked back to Tea accounts. By April, about 15,000 spam packages had been uploaded. The Tea team shut down rewards temporarily. It got worse. The campaigns evolved into coordinated operations with names like “IndonesianFoods” and “Indonesian Tea.” Instead of just publishing empty packages, attackers created dependency chains. Package A depends on Package B depends on Package C, all controlled by the same actor, each inflating the metrics of the others. In November 2025, Amazon Inspector researchers uncovered over 150,000 packages linked to tea.xyz token farming. That’s nearly 3% of npm’s entire registry. The Tea team responded with ownership verification, provenance checks, and monitoring for Sybil attacks. But the damage makes the point: attach financial value to a metric and people will manufacture that metric at scale. Even well-intentioned open source funding efforts can fall into this trap. If grants or sustainability programs distribute money based on downloads or dependency counts, maintainers have an incentive to split their packages into many smaller ones that all depend on each other. A library that could ship as one package becomes ten, each padding the metrics of the others. More packages means more visibility on GitHub Sponsors, more impressive-looking dependency graphs, more surface area for funding algorithms to notice. The maintainer isn’t being malicious, just responding rationally to how the system measures impact. The same dynamic that produced 150,000 spam packages can reshape how legitimate software gets structured. ### GitHub stars for sale Stars are supposed to signal quality or interest. Developers use them to evaluate libraries. Investors use them to evaluate startups. So there’s a market. A CMU study found approximately six million suspected fake stars on GitHub between July 2019 and December 2024. The activity surged in 2024, peaking in July when over 16% of starred repositories were associated with fake star campaigns. You can buy 100 stars for $8 on Fiverr. Bulk rates go down to 10 cents per star. Complete GitHub accounts with achievements and history sell for up to $5,000. The researchers found that fake stars primarily promote short-lived phishing and malware repositories. An attacker creates a repo with a convincing name, buys enough stars to appear legitimate, and waits for victims. The Check Point security team identified a threat group called “Stargazer Goblin” running over 3,000 GitHub accounts to distribute info-stealers. Fake stars become a liability long-term. Once GitHub detects and removes them, the sudden drop in stars is a red flag. The manipulation only works for hit-and-run attacks, not sustained presence. But hit-and-run is enough when you’re distributing malware. Add a prediction market and the same infrastructure gets a new revenue stream. ### Why it’s so easy to break Publishing a package costs nothing. No identity verification. No deposit. No waiting period. You sign up, you push, it’s live. This was a feature: low barriers to entry let unknown developers share useful code without gatekeepers. The npm ecosystem grew to over 5 million packages because anyone could participate. Downloading costs nothing too. Add a line to your manifest and the package manager fetches whatever you asked for. No verification that you meant to type that name. No warning that the package was published yesterday by a brand new account. The convenience that made package managers successful is the same property that makes them exploitable. Metrics are just counters. Downloads increment when someone runs `npm install`. Stars increment when someone clicks a button. Dependencies increment when someone publishes a `package.json` that references you. None of these actions require demonstrating that the thing being measured (quality, popularity, utility) actually exists. When the value of gaming these systems was low, the honor system worked well enough. That’s changing. Stars, downloads, and dependency counts were always proxies for quality and trustworthiness. When the manipulation stayed artisanal, the signal held up well enough. Now that package management underpins most of the software industry, the numbers matter for real decisions: government supply chain requirements, investor due diligence, corporate procurement. The numbers are worth manufacturing at scale, and a prediction market would just make the arbitrage efficient. ### AI has entered the chat AI coding assistants are trained on the same metrics being gamed. When Copilot or Claude suggests a package, it’s drawing on training data that includes stars, downloads, and how often packages appear in code. A package with bought stars and farmed downloads looks popular to an LLM in the same way it looks popular to a human scanning search results. The difference is that humans might notice something feels off. A developer might pause at a package with 10,000 stars but three commits and no issues. An AI agent running `npm install` won’t hesitate. It’s pattern-matching, not evaluating. The threat models multiply. An attacker who games their package into enough training data gets free distribution through every AI coding tool. Developers using vibe coding workflows, where you accept AI suggestions and fix problems as they arise, don’t scrutinize each import. Agents running in CI/CD pipelines have elevated permissions and no human in the loop. The attack surface isn’t just the registry anymore; it’s every model trained on registry data. Package management worked because the stakes were low and almost everyone played fair. The stakes aren’t low anymore. The numbers feed into government policy, corporate procurement, AI training data, and now, potentially, financial markets. When you see a package with 10,000 stars, you’re not looking at 10,000 developers who evaluated it and clicked a button. You’re looking at a number that could mean anything. Maybe it’s a beloved tool. Maybe it’s a marketing campaign. Maybe it’s a malware distribution front with a Stargazer Goblin account network behind it, it’s pretty much impossible to tell. 1. Thanks to @mlinksva for the tip. ↩
nesbitt.io
December 29, 2025 at 1:58 AM
Important fox news update: ​:neofox_notice:​

The back yard fox is back ​:neocat_aww:​
December 26, 2025 at 12:04 AM
Oooh, Talos 1.12 is released, a bunch of new features that I've been looking forward to

Notably the ability to assign different routing tables, will pair great with cilium egress policies to send select container traffic out over wireguard VPNs which will let me re-engineer my content […]
Original post on transitory.social
transitory.social
December 22, 2025 at 8:59 PM
Fox news update! ​:neofox_notice:​

A fox has been sighted walking past the house!
December 21, 2025 at 7:14 AM
Ok, looking at ssh certs a bit more...

using step-ca, ssh cert can be issued, but I would need a different provisioner to do it, since annoyingly ACME can't issue ssh certs.

That means clients will need the step CLI installed to request certs, not that big of a deal, but which provisioner? […]
Original post on transitory.social
transitory.social
December 19, 2025 at 6:59 PM
huh, I think I got passkeys working with everything but

keepassxc flatpack<->firefox flatpack

not bad tbh
December 19, 2025 at 6:33 PM
Discord: we have detected a new audio output named MacBook Air (5) do you want to switch to it

Chat, I do not in fact own a MacBook Air
December 16, 2025 at 8:59 PM
Back at my bullshit

Gonna see if I can use this local CA for SSH certs
December 16, 2025 at 8:00 PM
Congratulations to Mozilla, who has a new dick smasher in chief ready to wield the hammer
December 16, 2025 at 6:58 PM
* Jellyfin upgrade applied ​:neocat_nervous:​
* Jellyfin upgrade ___Failed_ __ ​:neocat_floof_explode:​
* Jellyfin restoring from backup: ​:neocat_sweat:​

Oookay gonna let them cook a bit more
December 15, 2025 at 3:15 PM
Reposted by Rachel
New Blog Post: Hybrid Cloud with Talos and Wireguard

https://blog.transitory.social/posts/2025-12-13-hybrid-cloud-with-talos-and-wireguard/

Follow along as I add a remote note to the cluster, and add three more layers of complexity. The end result is the ability to serve external facing pages […]
Original post on transitory.social
transitory.social
December 14, 2025 at 3:25 AM
New Blog Post: Hybrid Cloud with Talos and Wireguard

https://blog.transitory.social/posts/2025-12-13-hybrid-cloud-with-talos-and-wireguard/

Follow along as I add a remote note to the cluster, and add three more layers of complexity. The end result is the ability to serve external facing pages […]
Original post on transitory.social
transitory.social
December 14, 2025 at 3:25 AM
Oh neat Dr office let me canncel via replying to their text reminder that saves an awkward phone call I was avoiding
December 11, 2025 at 2:33 PM
Ok yeah there it is

So the main Homelab repo is the "kubernetes" repo, which is a monorepo for the entire cluster. Arguably it is for the whole Homelab except cloud and some network services are in their own repos.
The question is how to manage ansible?

There is a subdir for:
* The Talos […]
Original post on transitory.social
transitory.social
December 10, 2025 at 3:15 PM
ok fiiiiiine I will start using ansible more
December 10, 2025 at 12:08 AM
I got the mutual TLS working with rsyslog ​:neocat_floof:​

Except now 3/5 of the endpoints have various DNS issues causing problems with ACME, oops ​:neocat_flop:​

One of those is the DNS server itself lmao #homelab
December 9, 2025 at 7:07 PM
It works! ​:meowbongo:​

Ok so this helm chart is a total mess for the use case that I have, but, I got it working!

I can issue certs in-cluster via cert-manager, and hosts outside of the cluster can use certbot to obtain a locally signed cert via ACME!

Next up:
* Get traefik to trust the root […]
Original post on transitory.social
transitory.social
December 8, 2025 at 8:04 PM