Most people's digital security is a single point of failure with extra steps. Locking it down — password manager, two-factor authentication, recovery codes, tested backups — is a weekend project, not a lifestyle.
Most people's digital security is a single point of failure with extra steps. Locking it down — password manager, two-factor authentication, recovery codes, tested backups — is a weekend project, not a lifestyle.
Two fields in package.json both claim to pin your package manager. They can't both be satisfied, the tools that read them are moving in opposite directions, and picking wrong can lock you out of your own repo.
Every agent is, at heart, a loop: a model calling tools until the job is done. The interesting engineering question of 2026 is what happens when you wire many of those loops together into a graph — and when you shouldn't.
Chrome extensions are just web pages with superpowers — but the superpowers come with rules. This is the beginner's map: the parts, the permissions, why your popup can't see the page you're looking at, and the caveats that bite everyone exactly once.
You built the extension and it works with "Load unpacked". This is the map of everything between that and a public Chrome Web Store listing: the one-time $5 fee, the images the listing needs, the privacy paperwork, the review, and the maintenance that never quite ends.
Part 1 let the server reach the browser; Part 2 gave the browser an equal voice back. But in both, every byte still travels through a server. This final part is about the one browser technology that removes the server from the middle: WebRTC, which lets one browser talk straight to another — video, audio, and data, peer to peer.
In Part 1 the server learned to talk without being asked — but the browser could still only listen. A chat, a multiplayer game, a collaborative editor: these need both sides speaking freely over one connection. This is Part 2 of the series, and it's about the browser's true two-way channels — WebSockets, the workhorse, and WebTransport, its modern successor.
Plain HyperText Transfer Protocol (HTTP) has one stubborn rule: the browser asks, the server answers, and then the line goes dead. So how does a chat notification, a live score, or a stream of tokens from a language model reach a page that never asked again? This is Part 1 of a three-part tour of the browser's networking beyond request–response — and it starts with the three ways a server can reach you.
Every post on this blog needs two images that do completely different jobs: a social card that has to earn a click in a feed, and an inline hero that opens the article. This post is about how the blog makes both — a typographic default that costs nothing, an opt-in artificial-intelligence (AI) cover that costs about four cents, and the little Model Context Protocol (MCP) server that wires an image model straight into Claude Code. The cover above was made by that exact pipeline.
You've seen this screen a thousand times: a dark page, the domain name in bold, "Performing security verification", and a lonely checkbox with the Cloudflare logo. It feels like a speed bump, but there's a surprisingly rich pipeline behind it — and, importantly, none of it runs on the website's own servers.