I wrote a quick new post on "Digital Hygiene".
Basically there are some no-brainer decisions you can make in your life to dramatically improve the privacy and security of your computing and this post goes over some of them. Blog post link in the reply, but copy pasting below too.
Every now and then I get reminded about the vast fraud apparatus of the internet, re-invigorating my pursuit of basic digital hygiene around privacy/security of day to day computing. The sketchiness starts with major tech companies who are incentivized to build comprehensive profiles of you, to monetize it directly for advertising, or sell it off to professional data broker companies who further enrich, de-anonymize, cross-reference and resell it further. Inevitable and regular data breaches eventually runoff and collect your information into dark web archives, feeding into a whole underground spammer / scammer industry of hacks, phishing, ransomware, credit card fraud, identity theft, etc. This guide is a collection of the most basic digital hygiene tips, starting with the most basic to a bit more niche.
Password manager. Your passwords are your "first factor", i.e. "something you know". Do not be a noob and mint new, unique, hard passwords for every website or service that you sign up with. Combine this with a browser extension to create and Autofill them super fast. For example, I use and like 1Password. This prevents your passwords from 1) being easy to guess or crack, and 2) leaking one single time, and opening doors to many other services. In return, we now have a central location for all your 1st factors (passwords), so we must make sure to secure it thoroughly, which brings us to...
Hardware security key. The most critical services in your life (e.g. Google, or 1Password) must be additionally secured with a "2nd factor", i.e. "something you have". An attacker would have to be in possession of both factors to gain access to these services. The most common 2nd factor implemented by many services is a phone number, the idea being that you get a text message with a pin code to enter in addition to your password. Clearly, this is much better than having no 2nd factor at all, but the use of a phone number is known to be extremely insecure due to the SIM swap attack. Basically, it turns out to be surprisingly easy for an attacker to call your phone company, pretend they are you, and get them to switch your phone number over to a new phone that they control. I know this sounds totally crazy but it is true, and I have many friends who are victims of this attack. Therefore, purchase and set up hardware security keys - the industrial strength protection standard. In particular, I like and use YubiKey. These devices generate and store a private key on the device secure element itself, so the private key is never materialized on a suspiciously general purpose computing device like your laptop. Once you set these up, an attacker will not only need to know your password, but have physical possession of your security key to log in to a service. Your risk of getting pwned has just decreased by about 1000X. Purchase and set up 2-3 keys and store them in different physical locations to prevent lockout should you physically lose one of the keys. The security keys support a few authentication methods. Look for "U2F" in the 2nd factor settings of your service as the strongest protection. E.g. Google and 1Password support it. Fallback on "TOTP" if you have to, and note that your YubiKeys can store TOTP private keys, so you can use the YubiKey Authenticator app to access them easily through NFC by touching your key to the phone to get your pin when logging in. This is significantly better than storing TOTP private keys on other (software) authenticator apps, because again you should not trust general purpose computing devices. It is beyond the scope of this post to go into full detail, but basically I strongly recommend the use of 2-3 YubiKeys to dramatically strengthen your digital security.
Biometrics. Biometrics are the third common authentication factor ("something you are"). E.g. if you're on iOS I recommend setting up FaceID basically everywhere, e.g. to access the 1Password app and such.
Security questions. Dinosaur businesses are obsessed with the idea of security questions like "what is your mother's maidan name?", and force you to set them up from time to time. Clearly, these are in the category of "something you know" so they are basically passwords, but conveniently for scammers, they are easy to research out on the open internet and you should refuse any prompts to participate in this ridiculous "security" exercise. Instead, treat security questions like passwords, generate random answers to random questions, and store them in your 1Password along with your passwords.
Disk encryption. Always ensure that your computers use disk encryption. For example, on Macs this total no-brainer feature is called "File Vault". This feature ensures that if your computer gets stolen, an attacker won't be able to get the hard disk and go to town on all your data.
Internet of Things. More like @internetofshit. Whenever possible, avoid "smart" devices, which are essentially incredibly insecure, internet-connected computers that gather tons of data, get hacked all the time, and that people willingly place into their homes. These things have microphones, and they routinely send data back to the mothership for analytics and to "improve customer experience" lol ok. As an example, in my younger and naive years I once purchased a CO2 monitor from China that demanded to know everything about me and my precise physical location before it would tell me the amount of CO2 in my room. These devices are a huge and very common attack surface on your privacy and security and should be avoided.
Messaging. I recommend Signal instead of text messages because it end-to-end encrypts all your communications. In addition, it does not store metadata like many other apps do (e.g. iMessage, WhatsApp). Turn on disappearing messages (e.g. 90 days default is good). In my experience they are an information vulnerability with no significant upside.
Browser. I recommend Brave browser, which is a privacy-first browser based on Chromium. That means that basically all Chrome extensions work out of the box and the browser feels like Chrome, but without Google having front row seats to your entire digital life.
Search engine. I recommend Brave search, which you can set up as your default in the browser settings. Brave Search is a privacy-first search engine with its own index, unlike e.g. Duck Duck Go which basically a nice skin for Bing, and is forced into weird partnerships with Microsoft that compromise user privacy. As with all services on this list, I pay $3/mo for Brave Premium because I prefer to be the customer, not the product in my digital life. I find that empirically, about 95% of my search engine queries are super simple website lookups, with the search engine basically acting as a tiny DNS. And if you're not finding what you're looking for, fallback to Google by just prepending "!g" to your search query, which will redirect it to Google.
Credit cards. Mint new, unique credit cards per merchant. There is no need to use one credit card on many services. This allows them to "link up" your purchasing across different services, and additionally it opens you up to credit card fraud because the services might leak your credit card number. I like and use privacy dot com to mint new credit cards for every single transaction or merchant. You get a nice interface for all your spending and notifications for each swipe. You can also set limits on each credit card (e.g. $50/month etc.), which dramatically decreases the risk of being charged more than you expect. Additionally, with a privacy dot com card you get to enter totally random information for your name and address when filling out billing information. This is huge, because there is simply no need and totally crazy that random internet merchants should be given your physical address. Which brings me to...
Address. There is no need to give out your physical address to the majority of random services and merchants on the internet. Use a virtual mail service. I currently use Earth Class Mail but tbh I'm a bit embarrassed by that and I'm looking to switch to Virtual Post Mail due to its much strong commitments to privacy, security, and its ownership structure and reputation. In any case, you get an address you can give out, they receive your mail, they scan it and digitize it, they have an app for you to quickly see it, and you can decide what to do with it (e.g. shred, forward, etc.). Not only do you gain security and privacy but also quite a bit of convenience.
Email. I still use gmail just due to sheer convenience, but I've started to partially use Proton Mail as well. And while we're on email, a few more thoughts. Never click on any link inside any email you receive. Email addresses are extremely easy to spoof and you can never be guaranteed that the email you got is a phishing email from a scammer. Instead, I manually navigate to any service of interest and log in from there. In addition, disable image loading by default in your email's settings. If you get an email that requires you to see images, you can click on "show images" to see them and it's not a big deal at all. This is important because many services use embedded images to track you - they hide information inside the image URL you get, so when your email client loads the image, they can see that you opened the email. There's just no need for that. Additionally, confusing images are one way scammers hide information to avoid being filtered by email servers as scam / spam.
VPN. If you wish to hide your IP/location to services, you can do so via VPN indirection. I recommend Mullvad VPN. I keep VPN off by default, but enable it selectively when I'm dealing with services I trust less and want more protection from.
DNS-based blocker. You can block ads by blocking entire domains at the DNS level. I like and use NextDNS, which blocks all kinds of ads and trackers. For more advanced users who like to tinker, pi-hole is the physical alternative.
Network monitor. I like and use The Little Snitch, which I have installed and running on my MacBook. This lets you see which apps are communicating, how much data and when, so you can keep track of what apps on your computer "call home" and how often. Any app that communicates too much is sus, and should potentially be uninstalled if you don't expect the traffic.
I just want to live a secure digital life and establish harmonious relationships with products and services that leak only the necessary information. And I wish to pay for the software I use so that incentives are aligned and so that I am the customer. This is not trivial, but it is possible to approach with some determination and discipline.
Finally, what's not on the list. I mostly still use Gmail + Gsuite because it's just too convenient and pervasive. I also use 𝕏 instead of something exotic (e.g. Mastodon), trading off sovereignty for convenience. I don't use a VoIP burner phone service (e.g. MySudo) but I am interested in it. I don't really mint new/unique email addresses but I want to. The journey continues. Let me know if there are other digital hygiene tips and tricks that should be on this list.
Link to blog post version in the reply, on my brand new Bear ʕ•ᴥ•ʔ blog cute 👇
Meanwhile, Beijing is organizing the world's first humanoid half marathon (https://t.co/Nk0e0OhqEq)
And I bet the only competitors will be Chinese companies, simply because no Western humanoid is yet capable of this.
Proving once more that the real technology race that matters these days - both figuratively and literally - isn't so much between China and the West, but more between Guangdong, Shanghai, Zhejiang and Beijing provinces.
PS: the video is real, it's the EngineAI PM01 humanoid (https://t.co/zsMYsest76)
It's 2025 and most content is still written for humans instead of LLMs. 99.9% of attention is about to be LLM attention, not human attention.
E.g. 99% of libraries still have docs that basically render to some pretty .html static pages assuming a human will click through them. In 2025 the docs should be a single your_project.md text file that is intended to go into the context window of an LLM.
Repeat for everything.
“As a result, shutdown of the Atlantic Meridional Overturning Circulation (AMOC) is likely within the next 20-30 years, unless actions are taken to reduce global warming – in contradiction to conclusions of IPCC.”—@DrJamesEHansen et al.
A hack of location data company Gravy Analytics has revealed which apps are—knowingly or not—being used to collect your information behind the scenes. https://t.co/g99Bld4gfp
This is insane: there's a new bill in the US congress called the "Decoupling America’s
Artificial Intelligence Capabilities from China Act of
2025" that would ban the import of any AI technology from China, including Open Source models like Deepseek.
The bill also makes it illegal to do any research or development in AI in collaboration with an "entity of concern", defined as any Chinese institution or company.
In effect the bill would do what it says on the tin and completely decouple US and Chinese AI.
After the Deepseek episode I think anyone can understand how damaging this would be for the future of AI. Imagine if this bill had been in effect pre-Deepseek: none of the talk on AI democratization would have occurred, we simply wouldn't have the more hopeful alternative future for AI that we now have: we would still be looking at an AI future controlled by a few players and their closed models. And that's probably exactly what this bill is attempting to do.
More worryingly, this bill betrays a vision of AI as a geopolitical tool or weapon as opposed to a public good that can benefit humanity overall, and which the world needs to come together to build. Given the potential power and impact of the technology, it's obvious we need to adamantly oppose such a vision.
Link to the bill: https://t.co/997LyxtYFi
Ethereum’s future is a hot narrative right now.
Currently a fight between different core devs from old days.
Grab a perspective on Ethereum's current state from Dr Gavin Wood, who:
🔹coded the first functional Ethereum client (2014).
🔹authorized the Ethereum Yellowpaper.
🔹co-designed 1.0 Ethereum protocol, including EVM, gas & the caller-pays account model.
🔹invented Solidity contract language.
🔹wrote the Whisper/Swarm protocols and the Javascript API.
Quotes from JAM graypaper & my comments:
1. Validator centralization
"Almost one million crypto-economic actors take part in the validation for Ethereum. Practical matters do limit the level of real decentralization. Validator software expressly provides functionality to allow a single instance to be configured with multiple key sets, systematically facilitating a much lower level of actual decentralization than the apparent number of actors. Lido has steadily accounted for almost one-third of the almost one million crypto-economic participants."
🔹Ethereum has 1.06Mil validators & 27.8% eth is staked through Lido.
🔹Over 43% eth staked by just 3 entities: Lido, Coinbase & Binance. (Dune analytics, January 2025)
2. Scaling via rollups & zk-SNARKs
„Ethereum’s strategy for sideband computation does centre around snark-based rollups. Snarks are the product of an area of exotic cryptography which allow proofs to be constructed to demonstrate to a neutral observer that the purported result of performing some predefined computation is correct. The complexity of the verification of these proofs tends to be sub-linear in their size of computation to be proven."
"Proof generation alone takes over 61,000 times as long as simply re-compiling and executing even when executing on 32 times as many cores, using 20,000 times as much RAM and an additional state-of-the-art GPU... The cost multiplier of proving using risc-zero is 66,000,000x of the cost to execute using the Polkaval recompiler."
🔹1.5 billion lost in smart contract hacks on Ethereum in 2024 (complexity of contracts as leading factor). (ReKT Database, 2024)
🔹RISC Zero benchmarks show zk-SNARK generation is ~50,000x slower than native execution. (Thaler, 2023)
3. Centralization in rollups
„Snark-based solutions are heavily reliant on crypto-economic systems to frame them and work around their issues. Real-world examples exist of the pit of centralization giving rise to monopolies. One would be the aforementioned snark-based exchange framework; while notionally serving decentralized exchanges, it is in fact centralized with Starkware itself wielding a monopoly over enacting trades through the generation and submission of proofs, leading to a single point of failure."
🔹Starkware had ~40% of zk-Rollup TVL($1.2B), followed by zkSync Era ($800M). (DeFiLlama report, June 2024)
🔹Only 4/25 major rollups like Fuel or Aztec have decentralized sequencers (Electric Capital, 2024).
🔹Optimism & Arbitrum rely on a single sequencer node operated by their core teams (they sum to 80% of rollup TVL).
🔹Currently centralized sequencers are more expensive 10-15%, while decentralized add latency 2-3sec.
4. Fragmented ecosystem
„Heterogeneous communication properties (such as datagram latency and semantic range), security properties (such as the costs for reversion, corruption, stalling and censorship) and economic properties (the cost of accepting and processing some incoming message or transaction) may differ, potentially quite dramatically, between major areas of some grand patchwork of roll-ups by various competing vendors."
🔹5 major bridge hacks in 2024 (despite efforts to secure cross-chain bridges. (Crypto Crime Report, January 2025)
���Rollups don't have a standarized communication protocol, which leads to fragmented liquidity & user experience. (Gavin Wood suggesting XCM in X tweet, January 2025).
5. State bloat & hardware demands
„Solana validators are encouraged to install large amounts of RAM to help hold its large state in memory (512 GB is the current recommendation according to Solana Labs, 2024). Without a divide-and-conquer approach, Solana shows that the level of hardware which validators can reasonably be expected to provide dictates the upper limit on the performance of a totally synchronous, coherent execution model."
This is a reference to Solana. But it shows what will happen to Ethereum, if it decided to go with this approach. Focusing on hard hardware requirements leads to further centralization. 30 top validators in Solana control 60% of the stake. Nakamoto Coefficient of Solana is 19. (January, 2025)
🔹Ethereum's state size is 1.5 TB+, increasing hardware demands for validators (RAM & storage).
🔹This strains the validators & pushes to use centralized infra like AWS-managed nodes.
6. Coherency vs scalability tradeoff
„Ethereum-like smart-contract systems offering a single and universal object environment allow for the kind of agile and innovative integration which underpins their success. Polkadot, as it stands, is a collection of independent ecosystems with only limited opportunity for collaboration."
„The composability offered by Polkadot between its constituent chains is lower than that of Ethereum-like smart-contract systems, but the overall Ethereum network may eventually provide some or even most of the underlying machinery needed to do the sideband computation it is far from clear that there would be a 'grand consolidation' of the various properties."
🔹If Ethereum goes for the rollup-centric model it will start to lose it's coherent state as a trade-off for better scability. If the security isn't unified & there is no universal communication layer (like Polkadot's XCM) - it will become just another "network of network". Eventually becoming similar to Polkadot, but not having its shared security advantage.
7. zk-SNARKs & rollup economics
„It has yet to be demonstrated that snark-based strategies for eliminating the trust from computation will ever be able to compete on a cost-basis with a multi-party crypto-economic platform." „The need to incentivize multiple parties to do much the same work is a requirement to ensure that a single party not form a monopoly (or several not form a cartel)."
🔹Only some companies like StarkWare & Matter Labs can afford to operate zk-SNARK proof systems at scale due to the high computational resources needed. StarkWare has been noted to have centralized control over proof generation in their network (Electric Capital, 2024).
🔹zk-rollups can scale Ethereum to 2,000+ TPS, but the cost of each proof is $50-$100 per batch in 2024, significantly higher than traditional transaction fees (DeFiLlama analysis, 2024)
8. Fragmented Security
„Cosmos’ replicated security would be to require each validator to validate on all networks and for the same incentives and punishments. This is economically inefficient in the cost of security provision as each network would need to independently provide the same level of incentives and punishment-requirements as the most secure with which it wanted to interoperate."
This time a reference to Cosmos, but showing what would happen, if Ethereum would take the rollup-centric approach. Different levels of security based on validator participations, cause some rollups might be less secured than others - creating a fragmented security environment. (Interchain Foundation, 2024)
🔹Security protocols, validator sets & economic incentives for security are not shared across the whole Ethereum network but are managed by each rollup individually.
🔹Validating multiple rollups is resource-intensive & could lead to validator centralization if only some of them could handle the load.
🔹A rollup like zkSync has its own set of validators & security protocols based on zk-proofs , while another like Arbitrum depend on optimistic rollups, leading to different security risks, costs & levels of decentralization.
Some of Ethereum's efforts:
🔹Optimism-based rollups like Base or Zora) must decentralize sequencers by 2025 (law of chains).
🔹Projects like Astria or Espresso Systems building decentralized sequencer networks.
🔹Github activity has rised 30% in 2024, showing global efforts to improve the current design. (Electric Capital, Crypto Developer Report, December 2024)
🔹Chainlink CCIP & LayerZero v2 are doing good efforts to standarize cross-rollup communication.
🔹Since implementation of EIP-4844 (proto-danksharding), Ethereum's network congestion reduced by 35%, leading to more stable gas prices & faster txn confirmations. (Ethereum Foundation, January 2025)
🔹Proto-danksharding aims to reduce the state storage by 90%.
🔹Ethereum aims to finalize blocks in 12 sec - txn’s go faster but it increases the load on validators - as they need to process signatures quickly.
🔹Vitalik suggests Orbit Committees - small groups of randomly selected validators to finalize each block But it would increase centralization risks. Even with randomness - same small groups could be seletected repeatedly, creating censorship or delayed finality.
🔹Vitaliks suggests Ethereum would have two-tiered staking with 2 classes of validators. Higher-tier validators with larger deposits would handle economic finality & lower-tier validators would delegate to higher-tiers. Similar to Nominated Proof of Stake nPoS - known from Polkadot 1.0.
🔹He also proposes other tasks for low-tier validators like:
- being randomly seletected to attest to block.
- managing inclusion lists (higher decentralization, less risk of validator overhead)
But still rich do finality & poor have limited influence - can't avoid centralization on the resource level.
🔹His proposition to lower the amount of Eth from 32->1 to be a validator is a good idea. Increased decentralization while lowering the entry for people. With dank sharding coming & after heavily testing this the trade off's might be lower than expected.
🔹Zk-SNARK advancements reducing costs even 5-10x would be huge for Ethereum & keep them nr. 1 in the DeFi & NFT space for years.
I know the industry is rapidly changing and the numbers might be slightly different. I advise everyone to check out the JAM graypaper by Gavin. If voted by the DOT holders in OpenGov, JAM will replace Polkadot's current relay chain model.
JAM (Join-Accumulate-Machine):
🔹„Permissionless, decentralized hybrid system offering smart-contract functionality structured around a secure & scalable in-core/on-chain dualism”
🔹JAM will allow smart contract functionality (like in Ethereum) but with scability known in Polkadot
🔹"Unlike with snark-based L2-blockchain techniques for scaling, this model draws upon crypto-economic mechanisms and inherits their low-cost and high-performance profiles and averts a bias toward centralization."
Thanks for reading, open for discussions! 🫡
Mistral AI just dropped Small 3!
Here is everything you need to know:
- Releases both pretrained and tuned checkpoints
- No RL or synthetic data
- Mistral Small 3 is latency-optimized
- 24B parameters model
- 81% accuracy on MMLU and 150 tokens/s latency
- Positioned as a replacement for GPT-40-mini
- Competitive with Llama 3.3 70B & Qwen 32B
- 3x faster than Llama 3.3 70B instruct
- Apache 2.0 License
- Available in la Plateforme, HF, and other providers
Use cases include fast-response conversational assistants, low-latency function calling, fine-tuning for expert models, and local inference.
Great small model that complements other bigger models such as DeepSeek-R1.
Unify Ethereum.
Seriously folks, this is a focused, practical, and concise roadmap for a fast and cheap Ethereum, that feels like one network, and it’s happening in 2025.
The Solidity Developer Survey 2024 has gotten 500+ responses so far.
If you're yet to take the survey, you've got one last week to let us know...
✨ how you are using Solidity.
🆕 which recent changes impact(ed) you the most.
🔮 which features you anticipate the most.
It takes ~10min to contribute to the future of Solidity.
🔗https://t.co/Gkf4b4qw0K
“At the beginning of this century, when you were speaking about phytoplankton in the ocean, you were thinking about independent cells that are isolated,” said biologist García-Fernandez (far right). “But now — and not only from these results, but also from results from other people — I think we have to consider that these guys are not working alone.” https://t.co/Kw64RS92Pk
This is crazy: Biden's last act in the chip war before leaving office is to literally build a global technological Berlin Wall.
Extremely easy to predict that this will backfire dramatically.
Let's think this through.
First of all, the heart of this initiative is the U.S. now dividing the world in 3:
- Close allies with unfettered access to AI chips and similar advanced U.S. technology
- Adversaries with little to no access
- The rest of the world with restricted access on certain conditions (basically a deal that asks them to choose between the U.S. and China)
To start with, let's be clear: this is the U.S. now dropping all pretense that this is somehow about military or "dual use", it's all about raw technological dominance. The goal, spelled out plainly in the Bloomberg article, is "concentrating AI development in friendly nations and getting businesses around the world to align with American standards."
The problems with this approach are numerous and obvious.
For "adversary" nations, you've just eliminated any reason for them to work with you. China, already investing massively in domestic semiconductor development, will only accelerate these efforts. You're not stopping their progress - you're guaranteeing they'll build their own ecosystem. And other "adversary" nations will literally have no other choice than to buy from China.
For the "rest of world" tier, you're forcing a choice that they've all repeatedly said they didn't want to have to make (and that US officials have repeatedly lied they wouldn't force them to make): choosing between the U.S. and China. But here's the reality - it's not even a difficult choice. On one side, you have highly restricted U.S. technology with strict oversight and caps on computing power. On the other, you have open, accessible and considerably cheaper Chinese technology (like open-source Deepseek) and a partner that's already their largest trading relationship.
For most of these countries, the choice is obvious - and it's not the one the U.S. wants them to make. Betting that countries will accept U.S. technological oversight and restrictions rather than pursue alternatives is properly delusional.
Even U.S. companies recognize this is self-defeating. Nvidia's statement is telling: this won't "reduce the risk of misuse but would threaten economic growth and U.S. leadership." They understand that fragmenting the global market will ultimately hurt American competitiveness, not enhance it.
Ultimately what this will lead to is a wall that will increasingly isolate U.S. technology while the rest of the world moves on. That's the irony: in trying to maintain technological dominance, the U.S. is accelerating its own isolation. By forcing countries to choose, it's creating exactly the conditions that will drive them toward Chinese alternatives.
This isn't containing China's technological rise - it's hastening the emergence of a parallel technological ecosystem that the U.S. won't be able to control. And ultimately, with the sheer dynamism of China and the much faster growth of the Global South, this parallel ecosystem is very likely to become the dominant one vs a calcified and closed West.
Link to Bloomberg article: https://t.co/iJwBmSJGdX
🌟 Exciting update! The latest version of the JAM Graypaper (v0.5.3) is now live.
Explore the technical advancements and refined vision of the protocol by @gavofyork 🛠️
Check it out here: https://t.co/Vvb6GcDMMR
#polkadot#graypaper#jam
“The hand is where the mind meets the world.” — Carl Zimmer
Humanoid hands closely replicating human degrees of freedom enable robots to seamlessly integrate into our world and learn more efficiently from human demonstrations.
A look at some of the impressive hands from 2024🧵