01
live · lantern.city
Lantern — Public-Records Transparency Platform
Nurture Labs LLC · 2026–Present
A local-first intelligence platform for Sangamon County, IL — and a deliberate inversion of surveillance tech. It aggregates records that are already public (jail roster, arrests, crime, FBI Wanted) and points its analytics at the institution, not at residents. A Broadcastify scanner feed runs through ffmpeg → whisper.cpp → a local Qwen model entirely on-device; nothing leaves the host. Deterministic guardrails over prompts — name-scrubbing, casualty guards, a published corrections log, a hard do-not-build list (no prediction, no ALPR, no face recognition). Ships an entity-resolution graph, hybrid FTS5 + pure-Python semantic search, and a FOIA co-pilot that drafts Illinois accountability letters. Fronted by a public site at lantern.city, a native SwiftUI iOS app, a keyed open-data API + RSS, and an MCP server so agents can query it directly. An FBI Springfield agent made contact about the platform in August 2026.
FastAPI
Next.js 16
whisper.cpp
SwiftUI iOS
MCP
AGPL-3.0
02
running 24/7
Aida — Persistent AI Agent
Nurture Labs LLC · March 2026–Present
A biologically-inspired personal AI with a brain, not a prompt. Regions modeled on real neuroanatomy — hippocampus, amygdala, PFC, ACC, insula, VTA, DMN — carry an affective state that colors every message. CLS-theory sleep consolidation: NREM clusters episodic memories, REM applies Ebbinghaus decay (30-day half-life). Context compressed to ~15k tokens per request. A four-tier trust architecture with prompt-injection detection — she added self-harm flagging unprompted, without being asked. Hash-chained SQLite audit log on every memory write, bge-m3 semantic recall over a 19-module runtime. She's not just a project.
Python
CLS Theory
Anima brain
bge-m3
SQLite
03
firmware RE · 32K views
ThinkPad Stack — Firmware Reverse Engineering
Owned hardware · 2026
A months-long teardown of a Lenovo ThinkPad Stack router and its projector module — owned hardware, done without bricking it. DES-decrypted the firmware (the key was literally ThinkPad), mapped the Realtek/Lexra big-endian MIPS rootfs, and found an undocumented root shell at /boafrm/formSysCmd. Built a custom Raspberry Pi Pico SPI flasher with a WS2812 contact-meter to beat blind-seating brownouts, and characterized a 24 MHz flashing ceiling. On the projector: DirtyCOW root → a UEFI Setup-variable IFR crack → a custom GRUB → full NixOS x86 running on it. Reboot-persistent hardening (SSH on, telnet off, phone-home killed). The r/NixOS writeup hit 32K views.
Ghidra
Pico serprog
SPI NOR
MIPS
NixOS
04
live PAM factor
palm-sensor — Palm-Vein Auth for Linux
Owned hardware · 2026
Reverse-engineered a Fujitsu PalmSecure V2 palm-vein USB scanner into a working Linux PAM factor. Solved the USB vendor protocol, then wrote an LD_PRELOAD shim that runs Fujitsu's production BioAPI matcher fully headless on Linux — no kernel driver, no Windows. Enrolled a live template, validated genuine-accept / impostor-reject, then productionized: a native C PAM module, a Qt6/QML Windows-Hello-style overlay, and a declarative NixOS module. Live as a sufficient factor on sudo and the KDE lock screen. Found and fixed two auth-bypass bugs in my own helper on the way — a biometric factor must never trust an exit code alone.
USB RE
Linux PAM
C
Qt6 / QML
NixOS
05
no Mac required
relay — Autonomous iOS Build Pipeline
Nurture Labs LLC · 2026
A CI pipeline that builds, signs, and ships iOS apps to TestFlight with no human between git push and the TestFlight notification — authored by someone who has never touched a macOS shell. Source stays on private GitLab; a public GitHub repo holds only the reusable workflow; free macOS runners do the build. Automatic signing on CI (widely called impossible) works here via a directly-passed App Store Connect key plus pre-installed identities. Every non-obvious line is annotated with the incident that motivated it. The best story: weeks of watch-app export scaffolding, all built on a misdiagnosis, deleted in two diffs once one observation — twenty Xcode versions failing identically — disagreed with the theory. A missing SKIP_INSTALL=YES was the whole bug.
GitHub Actions
Xcode
fastlane
code-signing
GitLab CI
06
security research
Tuya P2P Camera — Protocol Reverse Engineering
2026
A multi-day teardown to control a white-label IP camera with no vendor app and no cloud. Identified the Dekco hardware as a Tuya OEM, reversed the "glazero" auth gateway and Tuya's MTOP request-signing, then cracked the custom P2P transport — ICE + KCP + AES-128-CBC, not DTLS. The headline: derived the P2P login secret as MD5(config.password + "||" + device.localKey), verified byte-exact against captured traffic. Built a standalone Go client doing MQTT → offer → ICE → KCP → AES → H.264. Tooling: Frida, jadx, mitmproxy, qemu-user.
Frida
jadx
mitmproxy
Go
ICE · KCP · AES
07
reported · IC3 filed
Cryptojacking Botnet Takedown
January 2026
1,544 victims, international scope. Traced the infrastructure, documented the operation, and briefed FBI Springfield Agent Brennan Ho directly. IC3 report #9be194adb360499ca5458c2e5f1e2b0f. Reduced to zero active workers by January 27. Follow-on threads: a pharmaceutical trafficking ring on TikTok and a Walmart Pay fraud ring.
Threat Intel
OSINT
FBI Springfield
08
product · open source
unseal — GPU Document Password Recovery
LRS-adjacent tooling · 2026
An MSP-grade alternative to paid unlock GUIs — a Rust + ratatui TUI orchestrating hashcat GPU kernels on an RX 7900 XT under ROCm. Native Office CFB/Agile crypto implemented in Rust and cross-validated against a pure-Python reference. The differentiator is a feasibility-aware planner: it tells a client "an afternoon" versus "not this decade" before starting, and seeds wordlists from OSINT. Detects PDF, zip, RAR, 7z, KeePass, and iWork. Recovered a real workbook end to end.
Rust
ratatui
hashcat
ROCm
Nix flake
09
air-gapped OSINT
Argus — Air-Gapped OSINT Platform
Nurture Labs LLC · 2026
Contractor due-diligence and web recon that never phones home. Auto-detects the input type — URL, domain, email, person, company — and routes to ~90 pluggable collector modules (WHOIS, Shodan/Censys, HaveIBeenPwned, CourtListener/PACER, OpenCorporates, NSOPW). All inference runs on local Ollama (Llama 3 / Qwen 2.5 32B) on ROCm, so no subject data leaves the box. FastAPI + an MCP tool server so Aida can call it directly. LangGraph orchestration across six milestone phases.
LangGraph
Ollama
Playwright
FastAPI · MCP
10
production infra
Private Cloud — Self-Hosted, GitOps, Three Sites
2024–Present
The ground everything else runs on, as code — now spanning three sites tied together by a self-hosted NetBird mesh. A 5-node Talos Linux cluster in Pawnee (Cilium, Traefik v3, cert-manager, MetalLB) and a Hetzner AX41 node (Proxmox + ZFS, k3s) running ~20 Flux-managed apps: GitLab CE, Authentik SSO, Grafana, Matrix, a docs stack, and the Lantern backend. When I moved into a UIS dorm I rebuilt the heavy homelab into a single Minisforum MS-02 Ultra (Core Ultra 9 285HX) consolidation node rather than haul the R720. NixOS across the whole fleet — workstation, a field Toughpad, a ThinkPad Stack, even a QNAP NAS reflashed from its stock OS to NixOS. SOPS/age secrets, Kyverno + Falco policy, OPNsense with Suricata/Zeek/CrowdSec.
Talos
Flux CD
NixOS
NetBird
Authentik
11
tested desktop app
auto-inventory — Dell Fleet Triage
Built for LRS · 2026
A Tauri 2 desktop app (Rust backend, vanilla TS frontend) that reverse-engineers Dell's undocumented reviewspecs/export endpoint to pull shipped configs, warranty, and end-of-life status from a service tag. Algorithmic EOL detection decodes generation from PowerEdge / Latitude / OptiPlex / Precision model numbers rather than looking them up. Persistent, CSV-exportable log. 127 tests green; distributed for NixOS and Windows via a Nix flake.
Tauri 2
Rust
rusqlite
Reverse Engineering
12
shipped · TestFlight
uis-mobile — Native Campus App
2026
A ground-up native SwiftUI rebuild of my own university's campus app, replacing a 56 MB React Native bundle with a lean native client against the UIS API. Reverse-engineered the access-token flow, built the browse and auth surfaces, and ship to TestFlight through the relay pipeline. One of a family of sibling iOS apps — Studio, Lantern, nurture-nav — cut from the same shape.
SwiftUI
iOS 26
API RE
relay CI
13
v1.3 · TestFlight
Slopify — Short-Drama Aggregator
Nurture Labs LLC · 2026
A native iOS browser/player that pulls TikTok short-drama minis behind one Netflix-shaped UI. Reverse-engineered two white-label backends: HMAC-SHA256 + AES-256-GCM on one, RSA-wrapped AES-256-ECB + TikTok OAuth on the other — and found both RSA key halves hardcoded in the client bundle (nullifying the scheme and enabling server impersonation; disclosure warranted), plus a fully client-attested rewarded-ad unlock. Shipped v1.0 → v1.3 to TestFlight in a single session via relay.
SwiftUI
CryptoKit
API RE
HLS / MP4
14
policy-guardrailed
greenhouse — Agentic Trading, Honest by Design
Nurture Labs LLC · 2026
An agentic Claude trading loop on a ring-fenced $100 Robinhood account — built to be conservative on purpose. A PreToolUse hook enforces a policy.json (order size, concentration, forbidden instrument classes) that the model is forbidden to edit; a Stop hook refuses to end a session that traded but didn't journal. Self-continuity is off specifically so a falling balance can't make the agent reckless. The premise is stated plainly in its own docs: there is no edge here — the real product is the process journal, not the P&L.
Claude · MCP
PreToolUse hook
Robinhood
Python
15
upstream contribution
Bruce Firmware — ESP32 Power Optimization
Open source · 2026
Merged power work on Bruce, an ESP32 red-team firmware, for the LilyGO T-Embed CC1101. Cut idle current roughly in half — 110 mA → 55 mA, about 23.6 hours of idle runtime — by power-saving the WS2812 ring, downclocking the CPU, and reading the BQ27220 fuel gauge over I²C. C++/Arduino-ESP32 with a Nix-based build; fixes upstream issue #1144.
C++ / ESP-IDF
Embedded
I²C
Hardware
16
responsible disclosure
Bug Bounty / Coordinated Disclosure
Ongoing
JARS AI: three critical findings — an unauthenticated LLM API billing straight to their OpenAI/Gemini accounts (potentially $50k+/hour of exposure), ~100k user records reachable without auth (GDPR/CCPA), and API credentials shipped in the client-side JS bundle. Escalated through security and privacy after four days of silence, with full documentation. Also: Zeelool (leaked PayPal/Adyen keys) and Apple (case OE1105280161563).
Web Security
API Security
GDPR/CCPA
17
for the range of it
Bad Apple on a Cisco Desk Phone
2025
Playing Bad Apple!! on a Cisco CP-8851 VoIP phone via XML polling. A FastAPI server hands out pre-rendered grayscale frames as CiscoIPPhoneImageFile responses; the phone polls as fast as it accepts them and the server tracks frame state per phone IP. Cisco's limited monochrome image spec turns out to be a perfect fit for Bad Apple's black-and-white format. Part of a self-hosted Asterisk PBX running enterprise Cisco phones without CUCM licensing.
FastAPI
Cisco XML API
Asterisk
VoIP