- Hive Five
- Posts
- 🐝 Hive Five 204 - Make Change That Lasts
🐝 Hive Five 204 - Make Change That Lasts
The PlasticList report, I'm Loving It, Exposing the Honey Influencer Scam, Flare-On 2024 challenges walkthrough, New Spooky Terminal on the Block, Microsoft Embraces Markdown, and more...
`Hi friends,
Greetings from the hive!
As 2024 comes to an end, I want to highlight how AI has become embedded in my workflow, tackling both complex tasks and everyday challenges.
The key insight isn't just about speed and efficiency, it's about making previously daunting projects happen.
When I started using AI as a creative partner, I found myself completing tasks I'd normally avoid, from tweaking CSS themes to creating animated graphics.
The most significant change came from removing the initial friction that stops many projects before they start.
AI doesn't just accelerate work, it eliminates barriers that would typically prevent me from starting new projects.
What's particularly valuable is how it helps push through those final, often tedious stages of projects that typically cause me to abandon them.
The productivity boost is substantial, I'm completing significantly more work, and doing it faster than before. Another unlock is the leverage it provides while you only have access to your phone.
But the real transformation isn't in the speed, for me, it’s a portal into flow state and endless possibilities.
Let's take this week by swarm!
P.S. I wrote this one while walking on my new treadmill.
🐝 The Bee's Knees
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny. MORE
Exposing the Honey Influencer Scam. Was Honey a legitimate money-saving tool? Or just an affiliate marketing scam promoted by some of YouTube's biggest influencers? MORE
Watch @gf_256 reverse engineer all the Flare-On 2024 challenges from start to end. Commentary video featuring @SuperFashi1 included. A whopping 45 hours of content. MORE
The 2025 AI Engineering Reading List. 50 paper/models/blogs across 10 fields in AI Eng: LLMs, Benchmarks, Prompting, RAG, Agents, CodeGen, Vision, Voice, Diffusion, and Finetuning. MORE
The PlasticList report: Nat and team tested nearly 300 food products in the Bay Area for plastic chemicals. Thinking it would take them several weeks, it ended up taking half a year and cost about $500,000. MORE
Brought to you by →
Hive Store: For Hackers By Hackers
Support the Hive by becoming a swag-wearing cross-pollinator
Hack a life you love in style. We’ve got shirts, hats, mugs, mouse pads, and more.
Think witty AI jokes that'll make ChatGPT chuckle. Privacy puns so sharp, the EFF would hive five you.
Join the cross-pollinators already flexing these custom swag items.
Upgrade Yourself →
You're getting the free version. Members get more — including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
📰 Updates
🍯 My work
Don't tell me your priorities. Show me your @obsdmd Daily Note.
— Bee 🐝 (@securibee)
8:11 PM • Dec 29, 2024
✅ Changelog
Ghostty is a fast, feature-rich, and cross-platform terminal emulator that uses platform-native UI and GPU acceleration. MORE
WAFW00F, a tool for identifying and fingerprinting web application firewalls, has released version 2.3.0. MORE
Orion Browser by Kagi is a lightweight, WebKit-based browser that is native on Mac, iPhone, and iPad. It boasts incredible speed, a built-in ad blocker, and zero telemetry, along with support for web extensions. MORE
Whisk combines Imagen 3 and Gemini to let users easily remix subjects, scenes, and styles. MORE
Obsidian, the popular note-taking app, has undergone a second independent security audit by Cure53. MORE
💼 Work
💰 Career
🚀 Productivity
The Personal Productivity Playbook by CJ Casselli outlines a comprehensive guide to improving one's personal productivity, offering practical strategies and insights to help individuals achieve their goals more effectively. MORE
YearCompass is a free booklet that helps one reflect on the past year and plan for the next, using carefully selected questions and exercises to uncover patterns and design the ideal year. MORE
Python tool by Microsoft for converting files and office documents to Markdown. MORE
Struggling with a daunting to-do list can lead to procrastination. The hack is to focus on winning the first 10 minutes by tackling a small, manageable task instead of getting overwhelmed. MORE
Texts lets you send and receive messages from all major messaging platforms: iMessage. WhatsApp. Telegram. Signal. Messenger. MORE
🌎 Community
🎉 Celebrate
@TaelurAlexis is excited for the big move overseas and is eager to start this new chapter in life. MORE
@godiego_ had an amazing 2024! Finished top 3 in the @Hacker0x01 global leaderboard, more than doubling his 2023 income. Got a @GoogleVRP $31,1337 bounty! Won a @yeswehack LHE. Got a 6-digit bounty on @Bugcrowd. Visited many countries with friends. MORE
⚡️ Timeline
💛 Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@HackingEsports | Hacking Esports | Brazilian hacking CTF lives | Esports format | special guests - PT-BR / ENG
@NotDeGhost | Robert Chen | founder @osec_io | web/pwn with @redpwnctf + @dicegangctf | prev @dfsec_com
@0xDezzy | /dev/random | Dallas based security consultant | Anti-Social Social Engineer | High Tech Low Life
@timurguvenkaya | Timur Guvenkaya | Co-founder & CTO of (soon) | Building & Leading top engineering teams | Building and auditing protocols on EVM/@substrate_io/@NEARProtocol | Ex @HalbornSecurity
@stephsmithio | Steph Smith | Pod host @a16z | Dev | Nomad.
🍄 Level up
📰 Read
52 things Tom learned in 2024 is a unique and informative read. MORE
"The London Underground has a distinct form of mosquito, Culex pipiens f. Molestus, genetically different from above-ground mosquitos, and present since at least the 1940s."
A live blog post on the Cyberhaven Extension Compromise as more is learned about the incident and attack. MORE | ANALYSIS
Security ProbLLMs in xAI's Grok: A Deep Dive. Grok is the chatbot of xAI. It’s a state-of-the-art model, chatbot, and recently also API. MORE
Ghostty is a brand new terminal emulator written from scratch with an unconventional tech stack and architecture: Zig for the core and platform-specific code for the GUIs. Read on for more details on the tech stack. MORE
Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150. MORE
"Algorithm confusion occurs when a system fails to properly verify the type of signature used in a JWT, allowing an attacker to exploit insufficient distinction between different signing methods."
💡 Tips
TV Shows:
1. Baby Reindeer
2. Fallout
3. House of the Dragon
4. Heeramandi
5. Shōgun
Cmd+shift+g in Finder opens a dialogue that provides a quick way to navigate to any desired location on the system. This keyboard shortcut simplifies file management and exploration within the macOS Finder. MORE
Here are a few Apple Watch tips you may not have heard before, even if you've used one for years. MORE
🧠 Wisdom
Maintaining a low cognitive load allows new hires to contribute to a codebase within hours of joining a company. MORE
I believe AI will play a big role in reducing this as well.
Proud to say that some of them were featured in the Hive Five previously! I love this quote from one of the resources "You can't hoard life" on Japanese tea ceremonies: "Great attention should be given to a tea gathering, which we can speak of as ‘one time, one meeting’ (ichigo, ichie). Even though the host and guests may see each other often socially, one day’s gathering can never be repeated exactly. Viewed this way, the meeting is indeed a once-in-a-lifetime occasion."
@nnwakelam observes that it is easy to take things for granted when they are present, but one learns that time does not wait, and things can change rapidly in the short span of one's life. MORE
📚 Resources
The Prompt Report examines a wide range of prompting techniques. MORE
OGP CTF 2024 is a web CTF built to train developers in secure coding while having fun. MORE
PugRecon allows one to query subdomains database containing 1.6 billion subdomains scrapped from multiple public (and private) sources. MORE
@ngalongc explores Salesforce from a bug bounty POV. MORE
I went with my trusted gruvbox set up.
Google's Gemini API Cookbook is a collection of guides and examples for the Gemini API, featuring quickstart tutorials for writing prompts and using different features, as well as examples of what can be built. MORE
🛠 Explore
Get $200 to try DigitalOcean — the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
🧰 Tools
CORS Anywhere is a NodeJS reverse proxy that adds CORS headers to the proxied request. MORE
AltTab is a macOS app that brings the Windows alt-tab functionality to Apple's operating system, allowing users to switch between open windows with ease. MORE
pass is a simple and Unix-friendly password manager. It stores each password in a GPG-encrypted file, with the filename corresponding to the resource requiring the password. MORE
The a16z Apps Unwrapped list showcases a diverse range of tools, from productivity apps to creative software. MORE
🎥 Watch
Ali Abdaal's 19 Incredible Books of 2024 cover productivity, business, entrepreneurship, health, and fiction, offering insights on getting things done, building successful companies, and achieving personal growth. MORE
A practical interview with João Moura, CEO of Crew AI, where they dive deep into how to build AI agent systems ranging from simple lead enrichment to complex content generation workflows. MORE
🎵 Listen
An interview with Dr. Rangan Chatterjee, a renowned physician, and one of Britain’s most influential medical voices. Author of the new book, “Make Change That Lasts.” MORE
Finding criticals on well-tested targets - Victor “doomerhunter” Poucheret. MORE
Mac Power Users podcast hosts discuss the hardware and software that served them well over the last year. MORE
Maggie Appleton, a visual essayist, discusses how we interact with computers and AI from an anthropological perspective. She has been pondering these questions longer than AI has been widely known. MORE
In this episode of Bug Bounty Podcast, Justin and Joseph delve into the vulnerabilities associated with ANSI codes and large language models (LLMs). MORE
🌐 Technology
e18e (Ecosystem Performance) is an initiative to connect the folks and projects working to improve JS packages performance. MORE
Aaron finds year-end reviews a helpful exercise to pause, reflect, and plan for the future, especially in the liminal space between Christmas and New Year's. MORE
When Meta launched Threads, it became the fastest-growing app in history, gaining 100 million users in only five days. The engineering team at Meta has shared insights on how they approach iOS performance for Threads. MORE
Open source LLM observability platform. One line of code to monitor, evaluate, and experiment. MORE
PaperMatch enables instant semantic search of ArXiv papers, empowering researchers to easily discover relevant work. MORE
👀 Interesting
The Moon, our closest celestial neighbor, has an ever-changing face, filled with light and darkness, yet a dependable presence in the sky. In this article, we’ll learn about the Moon and its path around our planet. MORE
A study on the physics of coffee spilling at low speeds, exploring the relationship between motion and liquid dynamics. The “claw-hand” method of carrying coffee appears to be highly effective. MORE
Choose any two people to see how they can be connected through encounters in time. MORE
1001tracklists is a comprehensive catalog of track names from nearly every DJ set ever recorded. MORE
Wikipedia's 2024 review examines the platform's role as a mirror of the world, with insights into the year's most popular articles. MORE
💭 Quote
"Feel overwhelmed? Think smaller. Feel bored? Think bigger."
📈 Learned something?
Upgrade Yourself →
You're getting the free version. Members get more — including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five →
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee 🐝
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.